Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
wnGDKyXdAo.exe

Overview

General Information

Sample name:wnGDKyXdAo.exe
(renamed file extension from none to exe, renamed because original name is a hash value)
Original sample name:3fe5fd377ea9bde5ca15723d214916b9a8e1b780bd49fab6e75412315c155b52
Analysis ID:1540690
MD5:65265a6752011edf039bdeafeb4e1551
SHA1:7414c76369b2e5762c93936a22ba530d80488d10
SHA256:3fe5fd377ea9bde5ca15723d214916b9a8e1b780bd49fab6e75412315c155b52
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Extensive use of GetProcAddress (often used to hide API calls)
Found evaded block containing many API calls
Found evasive API chain (date check)
Found potential string decryption / allocating functions
Program does not show much activity (idle)

Classification

  • System is w10x64
  • wnGDKyXdAo.exe (PID: 5016 cmdline: "C:\Users\user\Desktop\wnGDKyXdAo.exe" MD5: 65265A6752011EDF039BDEAFEB4E1551)
    • conhost.exe (PID: 2872 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: wnGDKyXdAo.exeAvira: detected
Source: wnGDKyXdAo.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C835B0 recv,0_2_00007FF6B9C835B0
Source: wnGDKyXdAo.exeString found in binary or memory: https://http://Mozilla/5.0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CCDA9C0_2_00007FF6B9CCDA9C
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C9E0530_2_00007FF6B9C9E053
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CC20200_2_00007FF6B9CC2020
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CD6F640_2_00007FF6B9CD6F64
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CC26440_2_00007FF6B9CC2644
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C91A000_2_00007FF6B9C91A00
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C839F00_2_00007FF6B9C839F0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CE5CC80_2_00007FF6B9CE5CC8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CBDBB40_2_00007FF6B9CBDBB4
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C9FB3E0_2_00007FF6B9C9FB3E
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C9CB400_2_00007FF6B9C9CB40
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CB1B380_2_00007FF6B9CB1B38
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C8CB600_2_00007FF6B9C8CB60
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C96F320_2_00007FF6B9C96F32
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CCCE740_2_00007FF6B9CCCE74
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C9BE200_2_00007FF6B9C9BE20
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C88DD00_2_00007FF6B9C88DD0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CB1DC40_2_00007FF6B9CB1DC4
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CB51240_2_00007FF6B9CB5124
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C950500_2_00007FF6B9C95050
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CC00100_2_00007FF6B9CC0010
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CE1FE40_2_00007FF6B9CE1FE4
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CC0FB00_2_00007FF6B9CC0FB0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CB8F9C0_2_00007FF6B9CB8F9C
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C85F700_2_00007FF6B9C85F70
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CC52FC0_2_00007FF6B9CC52FC
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CD42D80_2_00007FF6B9CD42D8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C9F2980_2_00007FF6B9C9F298
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CC12480_2_00007FF6B9CC1248
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C851900_2_00007FF6B9C85190
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C941600_2_00007FF6B9C94160
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C925000_2_00007FF6B9C92500
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C8E4800_2_00007FF6B9C8E480
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C854A00_2_00007FF6B9C854A0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CD14500_2_00007FF6B9CD1450
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C934700_2_00007FF6B9C93470
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CE54740_2_00007FF6B9CE5474
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C873600_2_00007FF6B9C87360
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CC56AC0_2_00007FF6B9CC56AC
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CEB6980_2_00007FF6B9CEB698
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C965D00_2_00007FF6B9C965D0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C9A5940_2_00007FF6B9C9A594
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C865900_2_00007FF6B9C86590
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CCB59C0_2_00007FF6B9CCB59C
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CD48FC0_2_00007FF6B9CD48FC
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CDF8F80_2_00007FF6B9CDF8F8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C947B00_2_00007FF6B9C947B0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C8A7400_2_00007FF6B9C8A740
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CBE7640_2_00007FF6B9CBE764
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: String function: 00007FF6B9CA4AE0 appears 36 times
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: String function: 00007FF6B9CAC040 appears 144 times
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: String function: 00007FF6B9CB0700 appears 63 times
Source: classification engineClassification label: mal48.winEXE@2/1@0/0
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2872:120:WilError_03
Source: wnGDKyXdAo.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeFile read: C:\Users\user\Desktop\wnGDKyXdAo.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\wnGDKyXdAo.exe "C:\Users\user\Desktop\wnGDKyXdAo.exe"
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeSection loaded: wininet.dllJump to behavior
Source: wnGDKyXdAo.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: wnGDKyXdAo.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: wnGDKyXdAo.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: wnGDKyXdAo.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: wnGDKyXdAo.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: wnGDKyXdAo.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: wnGDKyXdAo.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CD227C EncodePointer,__crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_00007FF6B9CD227C
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CDCB44 GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,0_2_00007FF6B9CDCB44
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: malloc,GetAdaptersInfo,free,malloc,GetAdaptersInfo,free,sprintf,free,0_2_00007FF6B9C84030
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeEvaded block: after key decisiongraph_0-43575
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeEvaded block: after key decisiongraph_0-43513
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeEvaded block: after key decisiongraph_0-43514
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeEvasive API call chain: GetSystemTimeAsFileTime,DecisionNodesgraph_0-44463
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: wnGDKyXdAo.exe, 00000000.00000002.1698080885.00000264FF860000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeAPI call chain: ExitProcess graph end nodegraph_0-43966
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CB72E0 IsDebuggerPresent,__crtUnhandledException,GetCurrentProcess,TerminateProcess,0_2_00007FF6B9CB72E0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CD227C EncodePointer,__crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_00007FF6B9CD227C
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CD227C EncodePointer,__crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_00007FF6B9CD227C
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CC04E8 GetProcessHeap,0_2_00007FF6B9CC04E8
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CC3868 SetUnhandledExceptionFilter,0_2_00007FF6B9CC3868
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CBC73C SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6B9CBC73C
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CBF8B8 cpuid 0_2_00007FF6B9CBF8B8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _getptd,EnumSystemLocalesW,0_2_00007FF6B9CD4D28
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _getptd,EnumSystemLocalesW,0_2_00007FF6B9CD4C74
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: __crtGetLocaleInfoA,GetLastError,__crtGetLocaleInfoA,_calloc_crt,__crtGetLocaleInfoA,_calloc_crt,free,free,__crtGetLocaleInfoEx,_calloc_crt,__crtGetLocaleInfoEx,free,__crtGetLocaleInfoEx,_invoke_watson,0_2_00007FF6B9CBEB88
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: __getlocaleinfo,_malloc_crt,_calloc_crt,_calloc_crt,_calloc_crt,_calloc_crt,GetCPInfo,__crtLCMapStringA,__crtLCMapStringA,__crtGetStringTypeA,free,free,free,free,free,free,free,free,free,0_2_00007FF6B9CB7EF4
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _getptd,_getptd,LcidFromHexString,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,TestDefaultLanguage,0_2_00007FF6B9CD4DBC
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _calloc_crt,_malloc_crt,free,_malloc_crt,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__free_lconv_num,free,free,free,0_2_00007FF6B9CD2DB8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _getptd,_getptd,LcidFromHexString,GetLocaleInfoW,TestDefaultLanguage,0_2_00007FF6B9CD4FEC
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: __crtDownlevelLocaleNameToLCID,GetLocaleInfoW,0_2_00007FF6B9CBCFE0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: EnumSystemLocalesW,0_2_00007FF6B9CBCF9C
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _getptd,__crtGetLocaleInfoEx,__crtGetLocaleInfoEx,TestDefaultCountry,__crtGetLocaleInfoEx,TestDefaultCountry,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_getptd,__crtGetLocaleInfoEx,_invoke_watson,0_2_00007FF6B9CD42D8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _getptd,_getptd,TranslateName,GetLcidFromLangCountry,GetLcidFromLanguage,TranslateName,GetLcidFromLangCountry,GetLcidFromLanguage,_getptd,EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,__crtDownlevelLCIDToLocaleName,__crtDownlevelLCIDToLocaleName,GetLocaleInfoW,GetLocaleInfoW,_itow_s,0_2_00007FF6B9CD5290
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _getptd,__lc_wcstolc,__get_qualified_locale_downlevel,__get_qualified_locale,__lc_lctowcs,__crtGetLocaleInfoEx,GetACP,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,0_2_00007FF6B9CC1248
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _getptd,GetLocaleInfoW,0_2_00007FF6B9CD51E8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF6B9CD5138
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: __crtGetLocaleInfoEx,malloc,__crtGetLocaleInfoEx,WideCharToMultiByte,free,0_2_00007FF6B9CD24F8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,0_2_00007FF6B9CD2654
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: __getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,0_2_00007FF6B9CD3540
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _getptd,TranslateName,GetLocaleNameFromLangCountry,GetLocaleNameFromLanguage,TranslateName,GetLocaleNameFromLangCountry,ProcessCodePage,IsValidCodePage,__crtGetLocaleInfoEx,__crtGetLocaleInfoEx,__crtGetLocaleInfoEx,_itow_s,GetLocaleNameFromLanguage,__crtGetUserDefaultLocaleName,_invoke_watson,_invoke_watson,_getptd,_getptd,LcidFromHexString,GetLocaleInfoW,0_2_00007FF6B9CD48FC
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: __crtGetLocaleInfoEx,0_2_00007FF6B9CD47F8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: _calloc_crt,_malloc_crt,free,_malloc_crt,free,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__getlocaleinfo,__free_lconv_mon,free,free,free,free,0_2_00007FF6B9CD282C
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: __crtGetLocaleInfoEx,__crtGetLocaleInfoEx,GetACP,0_2_00007FF6B9CD4744
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CB7BB8 GetSystemTimeAsFileTime,0_2_00007FF6B9CB7BB8
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9C837C0 GetUserNameA,0_2_00007FF6B9C837C0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CCAD54 GetVersionExW,Concurrency::details::platform::InitializeSystemFunctionPointers,Concurrency::details::WinRT::Initialize,std::bad_exception::bad_exception,_CxxThrowException,std::bad_exception::bad_exception,_CxxThrowException,0_2_00007FF6B9CCAD54
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CE10A0 Concurrency::details::VirtualProcessor::ThrowVirtualProcessorEvent,Concurrency::details::InternalContextBase::SwitchOut,Concurrency::details::SchedulerBase::GetInternalContext,Concurrency::details::WorkItem::ResolveToken,Concurrency::details::WorkItem::BindTo,Concurrency::details::SchedulerBase::ReleaseInternalContext,Concurrency::details::InternalContextBase::SwitchTo,Concurrency::details::SchedulerBase::ReleaseInternalContext,Concurrency::details::WorkItem::Bind,0_2_00007FF6B9CE10A0
Source: C:\Users\user\Desktop\wnGDKyXdAo.exeCode function: 0_2_00007FF6B9CE0158 Concurrency::details::SchedulerBase::GetInternalContext,Concurrency::details::WorkItem::ResolveToken,Concurrency::details::WorkItem::BindTo,Concurrency::details::SchedulerBase::ReleaseInternalContext,Concurrency::details::WorkItem::Bind,Concurrency::details::SchedulerBase::GetInternalContext,0_2_00007FF6B9CE0158
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts3
Native API
1
DLL Side-Loading
1
Process Injection
1
Process Injection
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
LSASS Memory31
Security Software Discovery
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Obfuscated Files or Information
Security Account Manager1
Account Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDS1
System Owner/User Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
System Network Configuration Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials24
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1540690 Sample: wnGDKyXdAo Startdate: 24/10/2024 Architecture: WINDOWS Score: 48 10 Antivirus / Scanner detection for submitted sample 2->10 6 wnGDKyXdAo.exe 1 2->6         started        process3 process4 8 conhost.exe 6->8         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
wnGDKyXdAo.exe100%AviraHEUR/AGEN.1319794
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://http://Mozilla/5.0wnGDKyXdAo.exefalse
    unknown
    No contacted IP infos
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1540690
    Start date and time:2024-10-24 01:02:57 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 2m 18s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:2
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:wnGDKyXdAo.exe
    (renamed file extension from none to exe, renamed because original name is a hash value)
    Original Sample Name:3fe5fd377ea9bde5ca15723d214916b9a8e1b780bd49fab6e75412315c155b52
    Detection:MAL
    Classification:mal48.winEXE@2/1@0/0
    EGA Information:
    • Successful, ratio: 100%
    HCA Information:
    • Successful, ratio: 99%
    • Number of executed functions: 23
    • Number of non-executed functions: 87
    Cookbook Comments:
    • Stop behavior analysis, all processes terminated
    • Not all processes where analyzed, report is missing behavior information
    • VT rate limit hit for: wnGDKyXdAo.exe
    No simulations
    No context
    No context
    No context
    No context
    No context
    Process:C:\Users\user\Desktop\wnGDKyXdAo.exe
    File Type:ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):1555
    Entropy (8bit):4.710273607729329
    Encrypted:false
    SSDEEP:24:w3GSdNffPmFMqFh4im3S1emA26uuMj4/4rku3MkHtXDe98vO++ly+Npy+tbDZAd1:9SdkJPAke5uuMqo3ltTI+Z+y+4W+t
    MD5:F028EC760D3B3F8A0B9DB4CF6ED0BD85
    SHA1:229C305A97F890BF2EB66D9B5A0FB60FE79A3258
    SHA-256:96EC03AE0A7A7233F01D904F60AACC43A748B32190B7232CAB74A4349236B8A9
    SHA-512:32883789EFAA3375782ED6D9699838F4587F6BBC952115AFDB74C7ED00F4DFE90E93FD402798AD013FABB8F0B56578C47828304BD3A1DD87C0AEC261A38DDCB3
    Malicious:false
    Reputation:low
    Preview:aescriptsLicTool_Verbose v4.1.43 (20241006) / AESCRIPTSLICLIB 4.1.3....usage: aescriptsLicTool_Verbose productName privNum [licString] [version]..'productName' is the name of the product to be validated or licensed (this is the filename of the license file without extension)..'privNum' is the private number of the product (can be set to - to ignore for certain actions)..'licString' is the license string of the product to be licensed..('licString' can be set to - to unlicense a product)..('licString' can be set to -content to retrieve the current content of the license file as a string)..('licString' can be set to PID@REMOTE to request a floating license - replace PID with the product ID on the server)..'version' is the optional version of the product to be licensed....The tool can also be run in 'licenser' or 'license checker' mode..Licenser mode call syntax:..aescriptsLicTool_Verbose productName - [licString] [version] -license..License checker mode call syntax:..aescriptsLicTool_Verb
    File type:PE32+ executable (console) x86-64, for MS Windows
    Entropy (8bit):6.129641582558878
    TrID:
    • Win64 Executable Console (202006/5) 92.65%
    • Win64 Executable (generic) (12005/4) 5.51%
    • Generic Win/DOS Executable (2004/3) 0.92%
    • DOS Executable Generic (2002/1) 0.92%
    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
    File name:wnGDKyXdAo.exe
    File size:645'776 bytes
    MD5:65265a6752011edf039bdeafeb4e1551
    SHA1:7414c76369b2e5762c93936a22ba530d80488d10
    SHA256:3fe5fd377ea9bde5ca15723d214916b9a8e1b780bd49fab6e75412315c155b52
    SHA512:6356f085894624e61a8dc67b19fc27ebf4c17b75b4cda970f120edc80d63946527ca845224c8b71d2d65a12efe5bfff7d781c050c382a517a958c0d3959afe63
    SSDEEP:12288:y6UPqQaO4tv82UlCKIMBnD1pnS8nWy9i4elej:y6jOK8GKIM5bWy9zj
    TLSH:25D46B59B39440E5D067C279CA574516F3B278460B3A9BDB03A0876B1F37AE09F3EB21
    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........O};.!.;.!.;.!..|..4.!..|....!..|....!.....6.!.;. ...!..U..:.!.]T..:.!.]T..:.!.Rich;.!.........PE..d......g.........."........
    Icon Hash:90cececece8e8eb0
    Entrypoint:0x140037e30
    Entrypoint Section:.text
    Digitally signed:false
    Imagebase:0x140000000
    Subsystem:windows cui
    Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
    DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
    Time Stamp:0x67021889 [Sun Oct 6 04:56:41 2024 UTC]
    TLS Callbacks:
    CLR (.Net) Version:
    OS Version Major:6
    OS Version Minor:0
    File Version Major:6
    File Version Minor:0
    Subsystem Version Major:6
    Subsystem Version Minor:0
    Import Hash:3ee642cb8c343ab97cf5b604d88a461f
    Instruction
    dec eax
    sub esp, 28h
    call 00007FA49C8C3EE8h
    dec eax
    add esp, 28h
    jmp 00007FA49C8B7CA7h
    int3
    int3
    dec eax
    sub esp, 28h
    call 00007FA49C8C07C8h
    dec eax
    mov ecx, dword ptr [eax+000000C0h]
    dec eax
    cmp ecx, dword ptr [0005C965h]
    je 00007FA49C8B7E78h
    mov eax, dword ptr [eax+000000C8h]
    test dword ptr [0005CAD3h], eax
    jne 00007FA49C8B7E6Ah
    call 00007FA49C8C0C7Dh
    dec eax
    mov ecx, eax
    mov eax, dword ptr [ecx+04h]
    dec eax
    add esp, 28h
    ret
    int3
    dec eax
    sub esp, 28h
    call 00007FA49C8C0790h
    dec eax
    mov ecx, dword ptr [eax+000000C0h]
    dec eax
    cmp ecx, dword ptr [0005C92Dh]
    je 00007FA49C8B7E78h
    mov eax, dword ptr [eax+000000C8h]
    test dword ptr [0005CA9Bh], eax
    jne 00007FA49C8B7E6Ah
    call 00007FA49C8C0C45h
    dec eax
    mov ecx, eax
    dec eax
    lea eax, dword ptr [ecx+00000128h]
    dec eax
    add esp, 28h
    ret
    int3
    dec eax
    sub esp, 28h
    call 00007FA49C8C0754h
    dec eax
    mov ecx, dword ptr [eax+000000C0h]
    dec eax
    cmp ecx, dword ptr [0005C8F1h]
    je 00007FA49C8B7E78h
    mov eax, dword ptr [eax+000000C8h]
    test dword ptr [0005CA5Fh], eax
    jne 00007FA49C8B7E6Ah
    call 00007FA49C8C0C09h
    dec eax
    mov ecx, eax
    mov eax, dword ptr [ecx+000000D4h]
    dec eax
    add esp, 28h
    ret
    int3
    int3
    dec esp
    mov ebx, esp
    Programming Language:
    • [RES] VS2012 UPD4 build 61030
    • [LNK] VS2012 UPD4 build 61030
    NameVirtual AddressVirtual Size Is in Section
    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IMPORT0x914240x8c.rdata
    IMAGE_DIRECTORY_ENTRY_RESOURCE0xa00000x1e0.rsrc
    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x9a0000x50c4.pdata
    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
    IMAGE_DIRECTORY_ENTRY_BASERELOC0xa10000xfbc.reloc
    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x812900x70.rdata
    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IAT0x710000x4d0.rdata
    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
    .text0x10000x6f7890x6f8008a8e32c0d99c274fc8002dc11f45bcaaFalse0.505165271160314data6.372737146819066IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    .rdata0x710000x213de0x21400f7ca2b641a4baf725e5feea0e55d4344False0.354984140037594data4.614733432030153IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .data0x930000x6a600x3a0071fce75483d7bb8ef829447188123647False0.2231950431034483data3.9381026450080876IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
    .pdata0x9a0000x50c40x5200be34dba8af943daf4f72a01864fb08c0False0.4907583841463415data5.750850673396023IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .rsrc0xa00000x1e00x200584568d783300e149a02ddab2f14ce0fFalse0.525390625data4.692060940173397IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .reloc0xa10000x3a920x3c00fa960895ca86a7d9e8087af3dc53212fFalse0.1248046875data2.177846270977989IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
    NameRVASizeTypeLanguageCountryZLIB Complexity
    RT_MANIFEST0xa00600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
    DLLImport
    WS2_32.dllinet_ntop, ioctlsocket, gethostname, connect, WSAStartup, getaddrinfo, select, WSAGetLastError, setsockopt, WSACleanup, recv, socket, freeaddrinfo, __WSAFDIsSet, closesocket, send
    IPHLPAPI.DLLGetAdaptersInfo
    KERNEL32.dllGetThreadPriority, CreateFileW, SetEnvironmentVariableA, WriteConsoleW, SetStdHandle, ReadConsoleW, CreateTimerQueue, RegisterWaitForSingleObject, GetNumaHighestNodeNumber, ChangeTimerQueueTimer, SetEndOfFile, QueryDepthSList, LoadLibraryW, UnregisterWait, CreateFileA, SystemTimeToFileTime, FormatMessageA, SetFileTime, Sleep, CreateDirectoryA, GetLastError, SetFileAttributesA, CloseHandle, GetSystemTime, UnregisterWaitEx, GetStartupInfoW, InterlockedFlushSList, InterlockedPushEntrySList, InterlockedPopEntrySList, InitializeSListHead, ReleaseSemaphore, DuplicateHandle, VirtualProtect, VirtualFree, VirtualAlloc, GetVersionExW, WideCharToMultiByte, GetCurrentThreadId, EncodePointer, DecodePointer, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, GetSystemTimeAsFileTime, MultiByteToWideChar, GetStringTypeW, ExitProcess, GetModuleHandleExW, GetProcAddress, AreFileApisANSI, HeapFree, HeapAlloc, IsDebuggerPresent, IsProcessorFeaturePresent, GetCommandLineA, GetCPInfo, RtlPcToFileHeader, RaiseException, RtlLookupFunctionEntry, RtlUnwindEx, InitializeCriticalSectionAndSpinCount, TlsGetValue, CreateTimerQueueTimer, RtlCaptureContext, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, SetLastError, GetCurrentProcess, TerminateProcess, TlsAlloc, TlsSetValue, TlsFree, SignalObjectAndWait, GetModuleHandleW, CreateSemaphoreW, CompareStringW, LCMapStringW, GetLocaleInfoW, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, GetStdHandle, GetFileType, WriteFile, GetModuleFileNameW, FreeLibrary, LoadLibraryExW, IsValidCodePage, GetACP, GetOEMCP, GetProcessHeap, GetCurrentThread, ReadFile, SetFilePointerEx, FlushFileBuffers, GetConsoleCP, GetConsoleMode, HeapSize, CreateDirectoryW, GetModuleFileNameA, QueryPerformanceCounter, GetCurrentProcessId, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetFilePointer, HeapReAlloc, DeleteTimerQueueTimer, GetProcessAffinityMask, SetThreadAffinityMask, OutputDebugStringW, SwitchToThread, CreateThread, GetThreadTimes, FreeLibraryAndExitThread, GetModuleHandleA, SetEvent, WaitForSingleObject, CreateEventW, SetThreadPriority, GetTickCount
    ADVAPI32.dllGetUserNameA
    SHELL32.dllSHGetFolderPathA
    WININET.dllHttpSendRequestA, HttpOpenRequestA, InternetCloseHandle, InternetReadFile, InternetConnectA, HttpQueryInfoA, InternetSetOptionA, InternetOpenA
    Language of compilation systemCountry where language is spokenMap
    EnglishUnited States
    No network behavior found

    Click to jump to process

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:19:03:51
    Start date:23/10/2024
    Path:C:\Users\user\Desktop\wnGDKyXdAo.exe
    Wow64 process (32bit):false
    Commandline:"C:\Users\user\Desktop\wnGDKyXdAo.exe"
    Imagebase:0x7ff6b9c80000
    File size:645'776 bytes
    MD5 hash:65265A6752011EDF039BDEAFEB4E1551
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    Target ID:1
    Start time:19:03:51
    Start date:23/10/2024
    Path:C:\Windows\System32\conhost.exe
    Wow64 process (32bit):false
    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Imagebase:0x7ff7699e0000
    File size:862'208 bytes
    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:high
    Has exited:true

    Reset < >

      Execution Graph

      Execution Coverage:4.7%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:32.5%
      Total number of Nodes:1199
      Total number of Limit Nodes:11
      execution_graph 43069 7ff6b9c9e053 43085 7ff6b9c9e05d memchr 43069->43085 43070 7ff6b9c9e271 43180 7ff6b9c9e30a memchr _wsetlocale_set_cat 43070->43180 43304 7ff6b9cac040 43070->43304 43074 7ff6b9cac040 283 API calls 43075 7ff6b9c9e29c 43074->43075 43314 7ff6b9cac3d0 43075->43314 43078 7ff6b9cac040 283 API calls 43079 7ff6b9c9e2ba 43078->43079 43080 7ff6b9cac040 283 API calls 43079->43080 43082 7ff6b9c9e2c9 43080->43082 43081 7ff6b9c9ee27 43342 7ff6b9c9d640 43081->43342 43083 7ff6b9cac040 283 API calls 43082->43083 43086 7ff6b9c9e2d8 43083->43086 43085->43070 43348 7ff6b9ca4ae0 43085->43348 43088 7ff6b9cac040 283 API calls 43086->43088 43090 7ff6b9c9e2e7 43088->43090 43089 7ff6b9c9d640 283 API calls 43091 7ff6b9c9ee4c 43089->43091 43324 7ff6b9ca1bd0 43090->43324 43094 7ff6b9cac040 283 API calls 43091->43094 43095 7ff6b9c9ee70 43094->43095 43097 7ff6b9ca1bd0 283 API calls 43095->43097 43099 7ff6b9c9ee7b 43097->43099 43101 7ff6b9ca1e30 283 API calls 43099->43101 43100 7ff6b9ca1bd0 283 API calls 43102 7ff6b9c9e302 43100->43102 43103 7ff6b9c9ee83 43101->43103 43104 7ff6b9ca1e30 283 API calls 43102->43104 43105 7ff6b9cac040 283 API calls 43103->43105 43104->43180 43106 7ff6b9c9ee96 43105->43106 43107 7ff6b9ca1bd0 283 API calls 43106->43107 43108 7ff6b9c9eea1 43107->43108 43109 7ff6b9ca1e30 283 API calls 43108->43109 43111 7ff6b9c9eea9 43109->43111 43110 7ff6b9c9e978 43114 7ff6b9ca4ae0 283 API calls 43110->43114 43112 7ff6b9cac040 283 API calls 43111->43112 43113 7ff6b9c9eebc 43112->43113 43115 7ff6b9ca1bd0 283 API calls 43113->43115 43116 7ff6b9c9e9c6 43114->43116 43117 7ff6b9c9eec7 43115->43117 43358 7ff6b9cabed0 283 API calls 43116->43358 43119 7ff6b9ca1e30 283 API calls 43117->43119 43120 7ff6b9c9eecf 43119->43120 43122 7ff6b9cac040 283 API calls 43120->43122 43121 7ff6b9c9e9e1 43359 7ff6b9c81f70 283 API calls 3 library calls 43121->43359 43123 7ff6b9c9eee2 43122->43123 43125 7ff6b9ca1bd0 283 API calls 43123->43125 43127 7ff6b9c9eeed 43125->43127 43126 7ff6b9c9ea3e 43128 7ff6b9c9ecce 43126->43128 43360 7ff6b9cabcc0 283 API calls 2 library calls 43126->43360 43129 7ff6b9ca1e30 283 API calls 43127->43129 43387 7ff6b9ca1590 283 API calls 43128->43387 43132 7ff6b9c9eef5 43129->43132 43135 7ff6b9cac040 283 API calls 43132->43135 43133 7ff6b9c9ecdd 43136 7ff6b9ca1bd0 283 API calls 43133->43136 43134 7ff6b9c9ea73 43361 7ff6b9ca4210 283 API calls 2 library calls 43134->43361 43138 7ff6b9c9ef08 43135->43138 43139 7ff6b9c9ece8 43136->43139 43141 7ff6b9ca1bd0 283 API calls 43138->43141 43142 7ff6b9ca1e30 283 API calls 43139->43142 43140 7ff6b9c9ea90 43143 7ff6b9c9eaa6 43140->43143 43362 7ff6b9ca49b0 43140->43362 43146 7ff6b9c9ef13 43141->43146 43147 7ff6b9c9ecf0 43142->43147 43378 7ff6b9ca4210 283 API calls 2 library calls 43143->43378 43145 7ff6b9c9d640 283 API calls 43145->43180 43150 7ff6b9ca1e30 283 API calls 43146->43150 43154 7ff6b9cac3d0 283 API calls 43147->43154 43303 7ff6b9c9ed30 43147->43303 43149 7ff6b9c9eabc 43152 7ff6b9ca4ae0 283 API calls 43149->43152 43153 7ff6b9c9ef1b 43150->43153 43151 7ff6b9ca1590 283 API calls 43151->43180 43157 7ff6b9c9ead1 43152->43157 43158 7ff6b9cac040 283 API calls 43153->43158 43159 7ff6b9c9ed1d 43154->43159 43155 7ff6b9cac040 283 API calls 43155->43180 43156 7ff6b9cb65a0 283 API calls 43156->43180 43379 7ff6b9ca4210 283 API calls 2 library calls 43157->43379 43161 7ff6b9c9ef2e 43158->43161 43162 7ff6b9ca1bd0 283 API calls 43159->43162 43165 7ff6b9ca1bd0 283 API calls 43161->43165 43166 7ff6b9c9ed28 43162->43166 43163 7ff6b9cac3d0 283 API calls 43163->43180 43164 7ff6b9c9eae7 43169 7ff6b9ca4ae0 283 API calls 43164->43169 43167 7ff6b9c9ef39 43165->43167 43168 7ff6b9ca1e30 283 API calls 43166->43168 43170 7ff6b9ca1e30 283 API calls 43167->43170 43168->43303 43172 7ff6b9c9eaff 43169->43172 43173 7ff6b9c9ef41 43170->43173 43171 7ff6b9ca1bd0 283 API calls 43171->43180 43177 7ff6b9c9eb46 43172->43177 43380 7ff6b9ca4210 283 API calls 2 library calls 43172->43380 43174 7ff6b9cac040 283 API calls 43173->43174 43181 7ff6b9c9ef54 43174->43181 43175 7ff6b9ca1e30 283 API calls 43175->43180 43178 7ff6b9c9ebac 43177->43178 43381 7ff6b9ca4210 283 API calls 2 library calls 43177->43381 43183 7ff6b9c9ebf3 43178->43183 43382 7ff6b9ca4210 283 API calls 2 library calls 43178->43382 43179 7ff6b9ca4ae0 283 API calls 43179->43180 43180->43081 43180->43110 43180->43145 43180->43151 43180->43155 43180->43156 43180->43163 43180->43171 43180->43175 43180->43179 43356 7ff6b9ca1560 283 API calls 43180->43356 43357 7ff6b9ca2650 283 API calls __ExceptionPtr::_CallCopyCtor 43180->43357 43185 7ff6b9ca1bd0 283 API calls 43181->43185 43182 7ff6b9c9eb30 43182->43177 43191 7ff6b9ca49b0 283 API calls 43182->43191 43190 7ff6b9c9ec3d 43183->43190 43383 7ff6b9ca4210 283 API calls 2 library calls 43183->43383 43189 7ff6b9c9ef5f 43185->43189 43196 7ff6b9ca1e30 283 API calls 43189->43196 43199 7ff6b9c9ec8c 43190->43199 43384 7ff6b9ca4210 283 API calls 2 library calls 43190->43384 43191->43177 43192 7ff6b9c9ebdd 43192->43183 43201 7ff6b9ca49b0 283 API calls 43192->43201 43193 7ff6b9c9ec27 43193->43190 43202 7ff6b9ca49b0 283 API calls 43193->43202 43198 7ff6b9c9ef67 43196->43198 43197 7ff6b9c9eb9a 43203 7ff6b9ca4ae0 283 API calls 43197->43203 43204 7ff6b9cac040 283 API calls 43198->43204 43385 7ff6b9c8a740 297 API calls 3 library calls 43199->43385 43201->43183 43202->43190 43203->43178 43208 7ff6b9c9ef7a 43204->43208 43207 7ff6b9c9ec9f 43386 7ff6b9ca8970 283 API calls 43207->43386 43211 7ff6b9ca1bd0 283 API calls 43208->43211 43209 7ff6b9c9ec76 43209->43199 43212 7ff6b9c9ec7b 43209->43212 43214 7ff6b9c9ef85 43211->43214 43215 7ff6b9ca49b0 283 API calls 43212->43215 43213 7ff6b9c9ecc2 43213->43128 43216 7ff6b9ca1e30 283 API calls 43214->43216 43215->43199 43217 7ff6b9c9ef8d 43216->43217 43218 7ff6b9ca1bd0 283 API calls 43217->43218 43219 7ff6b9c9ef99 43218->43219 43220 7ff6b9ca1e30 283 API calls 43219->43220 43221 7ff6b9c9efa5 43220->43221 43222 7ff6b9cac040 283 API calls 43221->43222 43223 7ff6b9c9efb8 43222->43223 43224 7ff6b9ca1bd0 283 API calls 43223->43224 43225 7ff6b9c9efc3 43224->43225 43226 7ff6b9ca1e30 283 API calls 43225->43226 43227 7ff6b9c9efcb 43226->43227 43228 7ff6b9cac040 283 API calls 43227->43228 43229 7ff6b9c9efde 43228->43229 43230 7ff6b9ca1bd0 283 API calls 43229->43230 43231 7ff6b9c9efe9 43230->43231 43232 7ff6b9ca1e30 283 API calls 43231->43232 43233 7ff6b9c9eff1 43232->43233 43234 7ff6b9cac040 283 API calls 43233->43234 43235 7ff6b9c9f004 43234->43235 43236 7ff6b9ca1bd0 283 API calls 43235->43236 43237 7ff6b9c9f00f 43236->43237 43238 7ff6b9ca1e30 283 API calls 43237->43238 43239 7ff6b9c9f017 43238->43239 43240 7ff6b9cac040 283 API calls 43239->43240 43241 7ff6b9c9f02a 43240->43241 43242 7ff6b9ca1bd0 283 API calls 43241->43242 43243 7ff6b9c9f035 43242->43243 43244 7ff6b9ca1e30 283 API calls 43243->43244 43245 7ff6b9c9f03d 43244->43245 43246 7ff6b9cac040 283 API calls 43245->43246 43247 7ff6b9c9f050 43246->43247 43248 7ff6b9ca1bd0 283 API calls 43247->43248 43249 7ff6b9c9f05b 43248->43249 43250 7ff6b9ca1e30 283 API calls 43249->43250 43251 7ff6b9c9f063 43250->43251 43252 7ff6b9ca1bd0 283 API calls 43251->43252 43253 7ff6b9c9f06f 43252->43253 43254 7ff6b9ca1e30 283 API calls 43253->43254 43255 7ff6b9c9f07b 43254->43255 43256 7ff6b9cac040 283 API calls 43255->43256 43257 7ff6b9c9f08e 43256->43257 43258 7ff6b9ca1bd0 283 API calls 43257->43258 43259 7ff6b9c9f099 43258->43259 43260 7ff6b9ca1e30 283 API calls 43259->43260 43261 7ff6b9c9f0a1 43260->43261 43262 7ff6b9cac040 283 API calls 43261->43262 43263 7ff6b9c9f0b4 43262->43263 43264 7ff6b9ca1bd0 283 API calls 43263->43264 43265 7ff6b9c9f0bf 43264->43265 43266 7ff6b9ca1e30 283 API calls 43265->43266 43267 7ff6b9c9f0c7 43266->43267 43268 7ff6b9cac040 283 API calls 43267->43268 43269 7ff6b9c9f0da 43268->43269 43270 7ff6b9ca1bd0 283 API calls 43269->43270 43271 7ff6b9c9f0e5 43270->43271 43272 7ff6b9ca1e30 283 API calls 43271->43272 43273 7ff6b9c9f0ed 43272->43273 43274 7ff6b9cac040 283 API calls 43273->43274 43275 7ff6b9c9f100 43274->43275 43276 7ff6b9ca1bd0 283 API calls 43275->43276 43277 7ff6b9c9f10b 43276->43277 43278 7ff6b9ca1e30 283 API calls 43277->43278 43279 7ff6b9c9f113 43278->43279 43280 7ff6b9cac040 283 API calls 43279->43280 43281 7ff6b9c9f126 43280->43281 43282 7ff6b9ca1bd0 283 API calls 43281->43282 43283 7ff6b9c9f131 43282->43283 43284 7ff6b9ca1e30 283 API calls 43283->43284 43285 7ff6b9c9f139 43284->43285 43286 7ff6b9cac040 283 API calls 43285->43286 43287 7ff6b9c9f14c 43286->43287 43288 7ff6b9ca1bd0 283 API calls 43287->43288 43289 7ff6b9c9f157 43288->43289 43290 7ff6b9ca1e30 283 API calls 43289->43290 43291 7ff6b9c9f15f 43290->43291 43292 7ff6b9cac040 283 API calls 43291->43292 43293 7ff6b9c9f172 43292->43293 43294 7ff6b9ca1bd0 283 API calls 43293->43294 43295 7ff6b9c9f17d 43294->43295 43296 7ff6b9ca1e30 283 API calls 43295->43296 43297 7ff6b9c9f185 43296->43297 43298 7ff6b9cac040 283 API calls 43297->43298 43299 7ff6b9c9f198 43298->43299 43300 7ff6b9ca1bd0 283 API calls 43299->43300 43301 7ff6b9c9f1a3 43300->43301 43302 7ff6b9ca1e30 283 API calls 43301->43302 43302->43303 43388 7ff6b9cb4a30 43303->43388 43305 7ff6b9cac073 43304->43305 43306 7ff6b9ca1e30 283 API calls 43305->43306 43310 7ff6b9cac0dc 43305->43310 43306->43310 43308 7ff6b9cac248 43309 7ff6b9c9e28d 43308->43309 43425 7ff6b9ca8630 283 API calls 43308->43425 43309->43074 43311 7ff6b9cac0f3 43310->43311 43397 7ff6b9ca2540 43310->43397 43311->43308 43401 7ff6b9c81920 43311->43401 43315 7ff6b9cac414 43314->43315 43316 7ff6b9ca1e30 283 API calls 43315->43316 43317 7ff6b9cac456 43315->43317 43316->43317 43322 7ff6b9cac46d 43317->43322 43323 7ff6b9ca2540 283 API calls 43317->43323 43318 7ff6b9c81920 283 API calls 43319 7ff6b9cac5c8 43318->43319 43320 7ff6b9c9e2ab 43319->43320 44186 7ff6b9ca8630 283 API calls 43319->44186 43320->43078 43322->43318 43322->43319 43323->43322 43325 7ff6b9ca1c08 43324->43325 43326 7ff6b9ca1c2c 43325->43326 43327 7ff6b9ca1e30 283 API calls 43325->43327 43328 7ff6b9ca1c43 43326->43328 43333 7ff6b9ca35e0 283 API calls 43326->43333 43327->43326 43329 7ff6b9c81920 283 API calls 43328->43329 43330 7ff6b9ca1cca 43328->43330 43329->43330 43331 7ff6b9c9e2f2 43330->43331 44187 7ff6b9ca8630 283 API calls 43330->44187 43334 7ff6b9ca1e30 43331->43334 43333->43328 43335 7ff6b9c9e2fa 43334->43335 43336 7ff6b9ca1e51 43334->43336 43335->43100 44188 7ff6b9ca6440 283 API calls 43336->44188 43338 7ff6b9ca1e5e 43339 7ff6b9ca1e9f 43338->43339 43341 7ff6b9c81920 283 API calls 43338->43341 43339->43335 44189 7ff6b9ca8630 283 API calls 43339->44189 43341->43339 43343 7ff6b9c9d65a 43342->43343 43345 7ff6b9c9d665 _Mtx_unlock 43343->43345 44190 7ff6b9cb0368 283 API calls std::_Throw_Cpp_error 43343->44190 43346 7ff6b9c9d687 43345->43346 44191 7ff6b9cb0368 283 API calls std::_Throw_Cpp_error 43345->44191 43346->43089 43349 7ff6b9ca4afd 43348->43349 43350 7ff6b9ca4b61 43349->43350 43351 7ff6b9ca4c05 43349->43351 43353 7ff6b9ca8510 _RunAllParam 283 API calls 43350->43353 43355 7ff6b9ca4b79 __ExceptionPtr::_CallCopyCtor 43350->43355 44192 7ff6b9cb0700 283 API calls 2 library calls 43351->44192 43353->43355 43355->43085 43356->43180 43357->43180 43358->43121 43359->43126 43360->43134 43361->43140 43363 7ff6b9ca4ab4 43362->43363 43364 7ff6b9ca49da 43362->43364 44194 7ff6b9cb0738 283 API calls 2 library calls 43363->44194 43365 7ff6b9ca49e9 43364->43365 43366 7ff6b9ca4a18 43364->43366 43368 7ff6b9ca4ac0 43365->43368 43369 7ff6b9ca49f7 43365->43369 43370 7ff6b9ca4acd 43366->43370 43371 7ff6b9ca4a22 43366->43371 44195 7ff6b9cb0738 283 API calls 2 library calls 43368->44195 44193 7ff6b9ca10e0 283 API calls __ExceptionPtr::_CallCopyCtor 43369->44193 44196 7ff6b9cb0700 283 API calls 2 library calls 43370->44196 43376 7ff6b9ca8510 _RunAllParam 283 API calls 43371->43376 43377 7ff6b9ca4a13 __ExceptionPtr::_CallCopyCtor 43371->43377 43376->43377 43377->43143 43378->43149 43379->43164 43380->43182 43381->43197 43382->43192 43383->43193 43384->43209 43385->43207 43386->43213 43387->43133 43389 7ff6b9cb4a39 43388->43389 43390 7ff6b9ca0e25 43389->43390 43391 7ff6b9cb732c IsProcessorFeaturePresent 43389->43391 43392 7ff6b9cb7343 43391->43392 44197 7ff6b9cbc0f8 RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 43392->44197 43394 7ff6b9cb7356 44198 7ff6b9cb72e0 5 API calls 2 library calls 43394->44198 43398 7ff6b9ca25d9 43397->43398 43399 7ff6b9ca2569 __ExceptionPtr::_CallCopyCtor 43397->43399 43398->43311 43399->43398 43426 7ff6b9ca35e0 43399->43426 43402 7ff6b9c8195d 43401->43402 43403 7ff6b9c81af8 43401->43403 43404 7ff6b9c8196b 43402->43404 43406 7ff6b9cb87f8 _CxxThrowException 2 API calls 43402->43406 43405 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 43403->43405 43407 7ff6b9c81a0a 43404->43407 43410 7ff6b9ca4ae0 283 API calls 43404->43410 43408 7ff6b9c81b05 43405->43408 43406->43404 43409 7ff6b9c81a83 43407->43409 43412 7ff6b9ca4ae0 283 API calls 43407->43412 43408->43308 43411 7ff6b9ca4ae0 283 API calls 43409->43411 43413 7ff6b9c819a8 43410->43413 43414 7ff6b9c81a96 43411->43414 43415 7ff6b9c81a21 43412->43415 44183 7ff6b9cb4d0c 283 API calls std::exception::_Copy_str 43413->44183 44185 7ff6b9cb4d0c 283 API calls std::exception::_Copy_str 43414->44185 44184 7ff6b9cb4d0c 283 API calls std::exception::_Copy_str 43415->44184 43419 7ff6b9c819c8 43422 7ff6b9cb87f8 _CxxThrowException 2 API calls 43419->43422 43420 7ff6b9c81ab6 43423 7ff6b9cb87f8 _CxxThrowException 2 API calls 43420->43423 43421 7ff6b9c81a41 43424 7ff6b9cb87f8 _CxxThrowException 2 API calls 43421->43424 43422->43407 43423->43403 43424->43409 43425->43309 43429 7ff6b9ca3626 43426->43429 43439 7ff6b9ca361f 43426->43439 43427 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 43428 7ff6b9ca38bf 43427->43428 43428->43399 43430 7ff6b9ca36a5 43429->43430 43433 7ff6b9ca36c4 43429->43433 43429->43439 43442 7ff6b9cb4a50 43430->43442 43432 7ff6b9ca3882 43435 7ff6b9cb4a50 fputc 283 API calls 43432->43435 43432->43439 43433->43432 43437 7ff6b9ca3863 43433->43437 43433->43439 43440 7ff6b9ca386f 43433->43440 43460 7ff6b9cb76c8 283 API calls 4 library calls 43433->43460 43461 7ff6b9ca8510 43433->43461 43435->43439 43467 7ff6b9cb0700 283 API calls 2 library calls 43437->43467 43439->43427 43468 7ff6b9cb0700 283 API calls 2 library calls 43440->43468 43443 7ff6b9cb4a8f 43442->43443 43444 7ff6b9cb4a77 43442->43444 43469 7ff6b9cb5b20 43443->43469 43496 7ff6b9cb66c8 283 API calls _getptd_noexit 43444->43496 43447 7ff6b9cb4a7c 43497 7ff6b9cbd340 14 API calls _invalid_parameter_noinfo 43447->43497 43448 7ff6b9cb4b1f 43451 7ff6b9cb4b2b 43448->43451 43475 7ff6b9cbd39c 43448->43475 43506 7ff6b9cb5bbc LeaveCriticalSection 43451->43506 43453 7ff6b9cb4a87 43453->43439 43458 7ff6b9cb4b14 43505 7ff6b9cbd340 14 API calls _invalid_parameter_noinfo 43458->43505 43460->43433 43462 7ff6b9ca8544 43461->43462 43465 7ff6b9ca8595 43462->43465 43466 7ff6b9ca85a2 __ExceptionPtr::_CallCopyCtor 43462->43466 43801 7ff6b9cb7c18 43462->43801 43465->43466 43845 7ff6b9cb06bc RtlPcToFileHeader RaiseException _CxxThrowException Concurrency::details::platform::__GetLogicalProcessorInformationEx 43465->43845 43466->43433 43470 7ff6b9cb5b75 EnterCriticalSection 43469->43470 43471 7ff6b9cb5b35 43469->43471 43471->43470 43472 7ff6b9cb5b41 43471->43472 43507 7ff6b9cb929c 43472->43507 43474 7ff6b9cb4a97 43474->43448 43498 7ff6b9cbd528 43474->43498 43476 7ff6b9cbd528 _fileno 283 API calls 43475->43476 43477 7ff6b9cbd3be 43476->43477 43478 7ff6b9cbd3e0 43477->43478 43479 7ff6b9cbd3c9 43477->43479 43480 7ff6b9cbd3e5 43478->43480 43491 7ff6b9cbd3f2 _flsbuf 43478->43491 43624 7ff6b9cb66c8 283 API calls _getptd_noexit 43479->43624 43625 7ff6b9cb66c8 283 API calls _getptd_noexit 43480->43625 43483 7ff6b9cbd457 43484 7ff6b9cbd4ef 43483->43484 43485 7ff6b9cbd464 43483->43485 43600 7ff6b9cc2564 43484->43600 43487 7ff6b9cbd480 43485->43487 43493 7ff6b9cbd499 43485->43493 43488 7ff6b9cc2564 _flsbuf 283 API calls 43487->43488 43490 7ff6b9cbd3ce 43488->43490 43490->43451 43491->43483 43491->43490 43492 7ff6b9cbd44b 43491->43492 43626 7ff6b9cd13f0 43491->43626 43492->43483 43634 7ff6b9cc1f70 283 API calls _malloc_crt 43492->43634 43493->43490 43635 7ff6b9cc2314 43493->43635 43496->43447 43497->43453 43499 7ff6b9cbd531 43498->43499 43500 7ff6b9cb4aaa 43498->43500 43799 7ff6b9cb66c8 283 API calls _getptd_noexit 43499->43799 43500->43448 43504 7ff6b9cb66c8 283 API calls _getptd_noexit 43500->43504 43502 7ff6b9cbd536 43800 7ff6b9cbd340 14 API calls _invalid_parameter_noinfo 43502->43800 43504->43458 43505->43448 43508 7ff6b9cb92cb EnterCriticalSection 43507->43508 43509 7ff6b9cb92ba 43507->43509 43513 7ff6b9cb9368 43509->43513 43514 7ff6b9cb939e 43513->43514 43515 7ff6b9cb9385 43513->43515 43517 7ff6b9cb92bf 43514->43517 43518 7ff6b9cb93b6 43514->43518 43543 7ff6b9cbe6f0 283 API calls 2 library calls 43515->43543 43517->43508 43536 7ff6b9cb5020 43517->43536 43546 7ff6b9cbae18 283 API calls malloc 43518->43546 43519 7ff6b9cb938a 43544 7ff6b9cbe764 283 API calls 9 library calls 43519->43544 43522 7ff6b9cb93c0 43524 7ff6b9cb93c8 43522->43524 43525 7ff6b9cb93d7 43522->43525 43523 7ff6b9cb9394 43545 7ff6b9cb5008 GetModuleHandleExW GetProcAddress ExitProcess __crtCorExitProcess 43523->43545 43547 7ff6b9cb66c8 283 API calls _getptd_noexit 43524->43547 43528 7ff6b9cb929c _lock 281 API calls 43525->43528 43529 7ff6b9cb93e1 43528->43529 43531 7ff6b9cb93fd 43529->43531 43532 7ff6b9cb93ec InitializeCriticalSectionAndSpinCount 43529->43532 43530 7ff6b9cb93cd 43530->43517 43548 7ff6b9cb5a10 43531->43548 43533 7ff6b9cb9403 LeaveCriticalSection 43532->43533 43533->43517 43535 7ff6b9cb9402 43535->43533 43555 7ff6b9cbe6f0 283 API calls 2 library calls 43536->43555 43538 7ff6b9cb502d 43574 7ff6b9cbe764 283 API calls 9 library calls 43538->43574 43540 7ff6b9cb5034 43556 7ff6b9cb51f8 43540->43556 43543->43519 43544->43523 43546->43522 43547->43530 43549 7ff6b9cb5a15 RtlFreeHeap 43548->43549 43551 7ff6b9cb5a45 free 43548->43551 43550 7ff6b9cb5a30 43549->43550 43549->43551 43554 7ff6b9cb66c8 283 API calls _getptd_noexit 43550->43554 43551->43535 43553 7ff6b9cb5a35 GetLastError 43553->43551 43554->43553 43555->43538 43557 7ff6b9cb929c _lock 275 API calls 43556->43557 43558 7ff6b9cb5226 43557->43558 43559 7ff6b9cb524d DecodePointer 43558->43559 43562 7ff6b9cb5314 doexit 43558->43562 43559->43562 43563 7ff6b9cb526b DecodePointer 43559->43563 43565 7ff6b9cb534a 43562->43565 43594 7ff6b9cb9484 LeaveCriticalSection 43562->43594 43564 7ff6b9cb5290 43563->43564 43564->43562 43567 7ff6b9cb529e EncodePointer 43564->43567 43571 7ff6b9cb52b2 DecodePointer EncodePointer 43564->43571 43568 7ff6b9cb5045 43565->43568 43593 7ff6b9cb9484 LeaveCriticalSection 43565->43593 43566 7ff6b9cb5363 43569 7ff6b9cb4fc4 __crtCorExitProcess GetModuleHandleExW GetProcAddress 43566->43569 43567->43564 43570 7ff6b9cb536b ExitProcess 43569->43570 43575 7ff6b9c8df90 43571->43575 43574->43540 43576 7ff6b9c8e09d 43575->43576 43577 7ff6b9c8dfd7 _wctomb_s_l 43575->43577 43578 7ff6b9c8e0df 43576->43578 43579 7ff6b9c8e0d0 WSACleanup 43576->43579 43577->43576 43580 7ff6b9ca4ae0 282 API calls 43577->43580 43597 7ff6b9cb0fc4 283 API calls 2 library calls 43578->43597 43579->43578 43581 7ff6b9c8e025 43580->43581 43595 7ff6b9c915d0 283 API calls 2 library calls 43581->43595 43584 7ff6b9c8e11e 43598 7ff6b9cb0fc4 283 API calls 2 library calls 43584->43598 43586 7ff6b9c8e12b 43599 7ff6b9cb0fc4 283 API calls 2 library calls 43586->43599 43588 7ff6b9c8e138 43590 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 43588->43590 43589 7ff6b9c8e05a _wctomb_s_l 43589->43576 43589->43589 43596 7ff6b9c94160 283 API calls 2 library calls 43589->43596 43591 7ff6b9c8e17c DecodePointer DecodePointer 43590->43591 43591->43564 43595->43589 43596->43576 43597->43584 43598->43586 43599->43588 43601 7ff6b9cc259f 43600->43601 43602 7ff6b9cc2587 43600->43602 43604 7ff6b9cc2616 43601->43604 43608 7ff6b9cc25d1 43601->43608 43720 7ff6b9cb6658 283 API calls _getptd_noexit 43602->43720 43725 7ff6b9cb6658 283 API calls _getptd_noexit 43604->43725 43605 7ff6b9cc258c 43721 7ff6b9cb66c8 283 API calls _getptd_noexit 43605->43721 43659 7ff6b9cd5ea8 43608->43659 43609 7ff6b9cc261b 43726 7ff6b9cb66c8 283 API calls _getptd_noexit 43609->43726 43610 7ff6b9cc2594 43610->43490 43613 7ff6b9cc25d8 43615 7ff6b9cc25f5 43613->43615 43616 7ff6b9cc25e4 43613->43616 43614 7ff6b9cc2623 43727 7ff6b9cbd340 14 API calls _invalid_parameter_noinfo 43614->43727 43722 7ff6b9cb66c8 283 API calls _getptd_noexit 43615->43722 43667 7ff6b9cc2644 43616->43667 43620 7ff6b9cc25fa 43723 7ff6b9cb6658 283 API calls _getptd_noexit 43620->43723 43622 7ff6b9cc25f1 43724 7ff6b9cd6308 LeaveCriticalSection 43622->43724 43624->43490 43625->43490 43627 7ff6b9cd1406 43626->43627 43628 7ff6b9cd13f9 43626->43628 43631 7ff6b9cd13fe 43627->43631 43789 7ff6b9cb66c8 283 API calls _getptd_noexit 43627->43789 43788 7ff6b9cb66c8 283 API calls _getptd_noexit 43628->43788 43631->43492 43632 7ff6b9cd143d 43790 7ff6b9cbd340 14 API calls _invalid_parameter_noinfo 43632->43790 43634->43483 43636 7ff6b9cc234f 43635->43636 43637 7ff6b9cc2337 43635->43637 43639 7ff6b9cc23c9 43636->43639 43643 7ff6b9cc2381 43636->43643 43791 7ff6b9cb6658 283 API calls _getptd_noexit 43637->43791 43796 7ff6b9cb6658 283 API calls _getptd_noexit 43639->43796 43640 7ff6b9cc233c 43792 7ff6b9cb66c8 283 API calls _getptd_noexit 43640->43792 43645 7ff6b9cd5ea8 __lock_fhandle 283 API calls 43643->43645 43644 7ff6b9cc23ce 43797 7ff6b9cb66c8 283 API calls _getptd_noexit 43644->43797 43647 7ff6b9cc2388 43645->43647 43649 7ff6b9cc2394 43647->43649 43650 7ff6b9cc23a6 43647->43650 43648 7ff6b9cc23d6 43798 7ff6b9cbd340 14 API calls _invalid_parameter_noinfo 43648->43798 43653 7ff6b9cc23f8 _lseeki64_nolock 283 API calls 43649->43653 43793 7ff6b9cb66c8 283 API calls _getptd_noexit 43650->43793 43655 7ff6b9cc23a1 43653->43655 43654 7ff6b9cc23ab 43794 7ff6b9cb6658 283 API calls _getptd_noexit 43654->43794 43795 7ff6b9cd6308 LeaveCriticalSection 43655->43795 43658 7ff6b9cc2344 43658->43490 43660 7ff6b9cd5f12 EnterCriticalSection 43659->43660 43661 7ff6b9cd5ee0 43659->43661 43660->43613 43662 7ff6b9cb929c _lock 281 API calls 43661->43662 43663 7ff6b9cd5eea 43662->43663 43664 7ff6b9cd5ef2 InitializeCriticalSectionAndSpinCount 43663->43664 43665 7ff6b9cd5f08 43663->43665 43664->43665 43728 7ff6b9cb9484 LeaveCriticalSection 43665->43728 43669 7ff6b9cc2666 __crtCompareStringA_stat 43667->43669 43668 7ff6b9cc268e 43671 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 43668->43671 43669->43668 43670 7ff6b9cc269a 43669->43670 43673 7ff6b9cc26f6 43669->43673 43734 7ff6b9cb6658 283 API calls _getptd_noexit 43670->43734 43674 7ff6b9cc2d65 43671->43674 43676 7ff6b9cc270b 43673->43676 43737 7ff6b9cc23f8 43673->43737 43674->43622 43675 7ff6b9cc269f 43735 7ff6b9cb66c8 283 API calls _getptd_noexit 43675->43735 43679 7ff6b9cd13f0 _isatty 271 API calls 43676->43679 43681 7ff6b9cc2712 43679->43681 43680 7ff6b9cc26a6 43736 7ff6b9cbd340 14 API calls _invalid_parameter_noinfo 43680->43736 43683 7ff6b9cc29d6 43681->43683 43729 7ff6b9cc07b0 43681->43729 43684 7ff6b9cc2cb8 WriteFile 43683->43684 43685 7ff6b9cc29ed 43683->43685 43687 7ff6b9cc2cde GetLastError 43684->43687 43712 7ff6b9cc2ba1 43684->43712 43688 7ff6b9cc2ac7 43685->43688 43693 7ff6b9cc29ff 43685->43693 43698 7ff6b9cc29a3 43687->43698 43691 7ff6b9cc2ba6 43688->43691 43699 7ff6b9cc2ad1 43688->43699 43689 7ff6b9cc2d11 43689->43668 43750 7ff6b9cb66c8 283 API calls _getptd_noexit 43689->43750 43691->43689 43701 7ff6b9cc2bf6 WideCharToMultiByte 43691->43701 43692 7ff6b9cc276b 43692->43683 43694 7ff6b9cc2778 GetConsoleCP 43692->43694 43693->43689 43696 7ff6b9cc2a49 WriteFile 43693->43696 43693->43698 43694->43698 43714 7ff6b9cc2792 _chsize_nolock 43694->43714 43696->43687 43696->43693 43697 7ff6b9cc2d3d 43751 7ff6b9cb6658 283 API calls _getptd_noexit 43697->43751 43698->43668 43698->43689 43711 7ff6b9cc2d03 43698->43711 43747 7ff6b9cb66c8 283 API calls _getptd_noexit 43698->43747 43699->43689 43704 7ff6b9cc2b28 WriteFile 43699->43704 43701->43687 43715 7ff6b9cc2c45 43701->43715 43704->43687 43706 7ff6b9cc2b71 43704->43706 43705 7ff6b9cc2cf8 43748 7ff6b9cb6658 283 API calls _getptd_noexit 43705->43748 43706->43698 43706->43699 43706->43712 43708 7ff6b9cc2c47 WriteFile 43710 7ff6b9cc2c91 GetLastError 43708->43710 43708->43715 43710->43715 43749 7ff6b9cb6678 283 API calls 2 library calls 43711->43749 43712->43698 43713 7ff6b9cd6490 WriteConsoleW CreateFileW _putwch_nolock 43719 7ff6b9cc28b0 43713->43719 43714->43698 43716 7ff6b9cc2838 WideCharToMultiByte 43714->43716 43714->43719 43746 7ff6b9cc33a8 283 API calls _LocaleUpdate::_LocaleUpdate 43714->43746 43715->43691 43715->43698 43715->43708 43715->43712 43716->43698 43717 7ff6b9cc287b WriteFile 43716->43717 43717->43687 43717->43719 43718 7ff6b9cc28d4 WriteFile 43718->43687 43718->43719 43719->43687 43719->43698 43719->43713 43719->43714 43719->43718 43720->43605 43721->43610 43722->43620 43723->43622 43725->43609 43726->43614 43727->43610 43752 7ff6b9cc07d4 GetLastError 43729->43752 43731 7ff6b9cc07bb 43732 7ff6b9cc07cb GetConsoleMode 43731->43732 43733 7ff6b9cb5020 __updatetmbcinfo 283 API calls 43731->43733 43732->43683 43732->43692 43733->43732 43734->43675 43735->43680 43736->43668 43769 7ff6b9cd61e4 43737->43769 43740 7ff6b9cc242e SetFilePointerEx 43743 7ff6b9cc2446 GetLastError 43740->43743 43744 7ff6b9cc2422 43740->43744 43741 7ff6b9cc241d 43781 7ff6b9cb66c8 283 API calls _getptd_noexit 43741->43781 43782 7ff6b9cb6678 283 API calls 2 library calls 43743->43782 43744->43676 43746->43714 43747->43705 43748->43711 43749->43689 43750->43697 43751->43668 43766 7ff6b9cbc228 43752->43766 43754 7ff6b9cc07f1 43755 7ff6b9cc0840 SetLastError 43754->43755 43756 7ff6b9cbad98 _calloc_crt 280 API calls 43754->43756 43755->43731 43757 7ff6b9cc0806 43756->43757 43757->43755 43758 7ff6b9cbc244 _mtinit TlsSetValue 43757->43758 43759 7ff6b9cc081c 43758->43759 43760 7ff6b9cc0823 43759->43760 43761 7ff6b9cc0839 43759->43761 43762 7ff6b9cc0858 _initptd 280 API calls 43760->43762 43763 7ff6b9cb5a10 free 280 API calls 43761->43763 43764 7ff6b9cc082a GetCurrentThreadId 43762->43764 43765 7ff6b9cc083e 43763->43765 43764->43755 43765->43755 43767 7ff6b9cbc238 43766->43767 43768 7ff6b9cbc23b TlsGetValue 43766->43768 43767->43768 43770 7ff6b9cd6202 43769->43770 43771 7ff6b9cd61ed 43769->43771 43777 7ff6b9cc2417 43770->43777 43785 7ff6b9cb6658 283 API calls _getptd_noexit 43770->43785 43783 7ff6b9cb6658 283 API calls _getptd_noexit 43771->43783 43773 7ff6b9cd61f2 43784 7ff6b9cb66c8 283 API calls _getptd_noexit 43773->43784 43776 7ff6b9cd623c 43786 7ff6b9cb66c8 283 API calls _getptd_noexit 43776->43786 43777->43740 43777->43741 43779 7ff6b9cd6244 43787 7ff6b9cbd340 14 API calls _invalid_parameter_noinfo 43779->43787 43781->43744 43782->43744 43783->43773 43784->43777 43785->43776 43786->43779 43787->43777 43788->43631 43789->43632 43790->43631 43791->43640 43792->43658 43793->43654 43794->43655 43796->43644 43797->43648 43798->43658 43799->43502 43800->43500 43803 7ff6b9cb7c23 43801->43803 43804 7ff6b9cb7c3c 43803->43804 43806 7ff6b9cb7c42 Concurrency::details::platform::__GetLogicalProcessorInformationEx 43803->43806 43846 7ff6b9cbeb4c DecodePointer 43803->43846 43848 7ff6b9cb5c2c 43803->43848 43804->43465 43865 7ff6b9cb87f8 43806->43865 43808 7ff6b9cb7c80 std::_Facet_Register 43870 7ff6b9cc04e8 GetProcessHeap 43808->43870 43810 7ff6b9cb7ced 43811 7ff6b9cb7d13 43810->43811 43812 7ff6b9cb7cff 43810->43812 43813 7ff6b9cb7cfa 43810->43813 43871 7ff6b9cc091c 43811->43871 43958 7ff6b9cbe764 283 API calls 9 library calls 43812->43958 43957 7ff6b9cbe6f0 283 API calls 2 library calls 43813->43957 43818 7ff6b9cb7d09 43959 7ff6b9cb5008 GetModuleHandleExW GetProcAddress ExitProcess __crtCorExitProcess 43818->43959 43842 7ff6b9cb7d9d 43843 7ff6b9cb5020 __updatetmbcinfo 282 API calls 43842->43843 43844 7ff6b9cb7da8 43842->43844 43843->43844 43844->43465 43847 7ff6b9cbeb67 43846->43847 43847->43803 43849 7ff6b9cb5cc0 43848->43849 43856 7ff6b9cb5c44 43848->43856 43850 7ff6b9cbeb4c _callnewh DecodePointer 43849->43850 43853 7ff6b9cb5cc5 43850->43853 43851 7ff6b9cb5c7c HeapAlloc 43851->43856 43857 7ff6b9cb5cb5 43851->43857 43852 7ff6b9cb5c5c 43852->43851 43964 7ff6b9cbe6f0 283 API calls 2 library calls 43852->43964 43965 7ff6b9cbe764 283 API calls 9 library calls 43852->43965 43966 7ff6b9cb5008 GetModuleHandleExW GetProcAddress ExitProcess __crtCorExitProcess 43852->43966 43969 7ff6b9cb66c8 283 API calls _getptd_noexit 43853->43969 43856->43851 43856->43852 43858 7ff6b9cb5ca5 43856->43858 43861 7ff6b9cbeb4c _callnewh DecodePointer 43856->43861 43862 7ff6b9cb5caa 43856->43862 43857->43803 43967 7ff6b9cb66c8 283 API calls _getptd_noexit 43858->43967 43861->43856 43968 7ff6b9cb66c8 283 API calls _getptd_noexit 43862->43968 43866 7ff6b9cb8878 RtlPcToFileHeader 43865->43866 43867 7ff6b9cb8868 43865->43867 43868 7ff6b9cb88b8 RaiseException 43866->43868 43869 7ff6b9cb889d 43866->43869 43867->43866 43868->43808 43869->43868 43870->43810 43970 7ff6b9cb5124 EncodePointer 43871->43970 43873 7ff6b9cc0927 43975 7ff6b9cb9424 43873->43975 43876 7ff6b9cc098e 43980 7ff6b9cc099c TlsFree _mtterm 43876->43980 43953 7ff6b9cb50be 43954 7ff6b9cb50e1 _IsNonwritableInCurrentImage 43953->43954 44017 7ff6b9cf0300 43953->44017 44020 7ff6b9cf02d0 43953->44020 43954->43842 43957->43812 43958->43818 43964->43852 43965->43852 43967->43862 43968->43857 43969->43857 43971 7ff6b9cb513d _init_pointers 43970->43971 43981 7ff6b9cbeb2c EncodePointer 43971->43981 43973 7ff6b9cb5165 30 API calls 43973->43873 43976 7ff6b9cb943f 43975->43976 43977 7ff6b9cb9445 InitializeCriticalSectionAndSpinCount 43976->43977 43978 7ff6b9cb9470 43976->43978 43977->43976 43978->43876 43979 7ff6b9cbc1f0 TlsAlloc 43978->43979 43981->43973 44016 7ff6b9cb6c35 44016->43953 44039 7ff6b9c9d780 44017->44039 44147 7ff6b9c8de90 44020->44147 44025 7ff6b9cb6b41 DecodePointer DecodePointer 44026 7ff6b9cb6b6b 44025->44026 44028 7ff6b9cb6c06 _onexit 44025->44028 44027 7ff6b9cc2ec4 _recalloc 278 API calls 44026->44027 44026->44028 44029 7ff6b9cb6b87 44027->44029 44028->44016 44030 7ff6b9cb6be4 EncodePointer EncodePointer 44029->44030 44031 7ff6b9cb6bb4 44029->44031 44032 7ff6b9cb6ba3 44029->44032 44030->44028 44031->44028 44034 7ff6b9cb6bab 44031->44034 44033 7ff6b9cbae94 _realloc_crt 278 API calls 44032->44033 44033->44034 44034->44031 44035 7ff6b9cb6bcc EncodePointer 44034->44035 44036 7ff6b9cbae94 _realloc_crt 278 API calls 44034->44036 44035->44030 44037 7ff6b9cb6bc7 44036->44037 44037->44028 44037->44035 44068 7ff6b9c9d6a0 44039->44068 44042 7ff6b9ca49b0 283 API calls 44043 7ff6b9c9d7ee 44042->44043 44074 7ff6b9c84980 44043->44074 44046 7ff6b9c9da9b 44047 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 44046->44047 44048 7ff6b9c9db8b 44047->44048 44048->43953 44050 7ff6b9c9d929 44051 7ff6b9ca4ae0 283 API calls 44050->44051 44052 7ff6b9c9d95e 44051->44052 44053 7ff6b9ca49b0 283 API calls 44052->44053 44054 7ff6b9c9d986 44053->44054 44099 7ff6b9c83330 283 API calls $I10_OUTPUT 44054->44099 44056 7ff6b9c9d99a 44100 7ff6b9cabed0 283 API calls 44056->44100 44058 7ff6b9c9d9ae 44101 7ff6b9c81f70 283 API calls 3 library calls 44058->44101 44060 7ff6b9c9da38 44102 7ff6b9cb65a0 283 API calls strtoxl 44060->44102 44062 7ff6b9c9da51 44103 7ff6b9cb65a0 283 API calls strtoxl 44062->44103 44064 7ff6b9c9da67 44104 7ff6b9cb65a0 283 API calls strtoxl 44064->44104 44066 7ff6b9c9da7d 44066->44046 44067 7ff6b9ca49b0 283 API calls 44066->44067 44067->44046 44069 7ff6b9c9d6f0 _wctomb_s_l 44068->44069 44069->44069 44070 7ff6b9ca4ae0 283 API calls 44069->44070 44071 7ff6b9c9d759 44070->44071 44072 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 44071->44072 44073 7ff6b9c9d76c 44072->44073 44073->44042 44075 7ff6b9c84a3a 44074->44075 44090 7ff6b9c849eb std::ios_base::_Ios_base_dtor __ExceptionPtr::_CallCopyCtor 44074->44090 44105 7ff6b9ca31b0 44075->44105 44079 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 44081 7ff6b9c84c6a 44079->44081 44080 7ff6b9c84a64 44082 7ff6b9c81920 283 API calls 44080->44082 44081->44046 44098 7ff6b9ca13c0 283 API calls 44081->44098 44083 7ff6b9c84aa0 44082->44083 44086 7ff6b9c84b59 __ExceptionPtr::_CallCopyCtor Concurrency::details::SchedulerBase::PostAffinityMessage 44083->44086 44116 7ff6b9ca2280 44083->44116 44085 7ff6b9c84ab9 44122 7ff6b9ca2190 44085->44122 44146 7ff6b9ca3480 283 API calls _RunAllParam 44086->44146 44090->44079 44095 7ff6b9c84b34 44096 7ff6b9ca4ae0 283 API calls 44095->44096 44096->44086 44097 7ff6b9c81920 283 API calls 44097->44095 44098->44050 44099->44056 44100->44058 44101->44060 44102->44062 44103->44064 44104->44066 44106 7ff6b9ca5780 283 API calls 44105->44106 44107 7ff6b9ca3234 44106->44107 44108 7ff6b9ca8690 283 API calls 44107->44108 44109 7ff6b9c84a44 44108->44109 44110 7ff6b9ca5df0 44109->44110 44111 7ff6b9ca5e12 44110->44111 44115 7ff6b9ca5e4e 44110->44115 44112 7ff6b9cb0974 283 API calls 44111->44112 44113 7ff6b9ca5e22 44112->44113 44114 7ff6b9cacd50 283 API calls 44113->44114 44113->44115 44114->44115 44115->44080 44117 7ff6b9ca22b0 44116->44117 44118 7ff6b9ca5840 283 API calls 44117->44118 44119 7ff6b9ca22c1 44118->44119 44120 7ff6b9ca22f2 44119->44120 44121 7ff6b9ca3d00 283 API calls 44119->44121 44120->44085 44121->44120 44123 7ff6b9ca21c1 44122->44123 44124 7ff6b9c81920 283 API calls 44123->44124 44125 7ff6b9ca21cc 44124->44125 44126 7ff6b9ca5840 283 API calls 44125->44126 44127 7ff6b9ca21f3 44126->44127 44130 7ff6b9c84adb 44127->44130 44131 7ff6b9ca3d00 283 API calls 44127->44131 44128 7ff6b9ca2223 44129 7ff6b9c81920 283 API calls 44128->44129 44128->44130 44129->44130 44132 7ff6b9ca20a0 44130->44132 44131->44128 44134 7ff6b9ca20e8 44132->44134 44133 7ff6b9ca5840 283 API calls 44135 7ff6b9ca20f9 44133->44135 44134->44133 44136 7ff6b9ca2119 44135->44136 44139 7ff6b9ca2480 283 API calls 44135->44139 44137 7ff6b9c84aeb 44136->44137 44138 7ff6b9c81920 283 API calls 44136->44138 44140 7ff6b9ca5e90 44137->44140 44138->44137 44139->44136 44141 7ff6b9ca5eb2 44140->44141 44142 7ff6b9c84b09 44140->44142 44143 7ff6b9ca6010 _RunAllParam 283 API calls 44141->44143 44142->44095 44142->44097 44144 7ff6b9ca5eb7 44143->44144 44145 7ff6b9cb7b50 fclose 283 API calls 44144->44145 44145->44142 44146->44090 44162 7ff6b9cb0ff0 44147->44162 44149 7ff6b9c8debf 44150 7ff6b9c8deca 44149->44150 44173 7ff6b9cb0368 283 API calls std::_Throw_Cpp_error 44149->44173 44152 7ff6b9cb0ff0 _Mtx_init 283 API calls 44150->44152 44153 7ff6b9c8dedb 44152->44153 44154 7ff6b9c8dee6 44153->44154 44174 7ff6b9cb0368 283 API calls std::_Throw_Cpp_error 44153->44174 44156 7ff6b9cb0ff0 _Mtx_init 283 API calls 44154->44156 44158 7ff6b9c8def7 44156->44158 44157 7ff6b9c8df02 44165 7ff6b9c83730 44157->44165 44158->44157 44175 7ff6b9cb0368 283 API calls std::_Throw_Cpp_error 44158->44175 44161 7ff6b9c8df74 44176 7ff6b9cbb0b4 44162->44176 44164 7ff6b9cb1015 Concurrency::details::_NonReentrantPPLLock::_NonReentrantPPLLock 44164->44149 44166 7ff6b9c83760 44165->44166 44166->44166 44167 7ff6b9c837a3 44166->44167 44168 7ff6b9c83770 WSAStartup 44166->44168 44170 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 44167->44170 44169 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 44168->44169 44171 7ff6b9c8379b 44169->44171 44172 7ff6b9c837b5 44170->44172 44171->44161 44172->44161 44173->44150 44174->44154 44175->44157 44177 7ff6b9cc51bc _calloc_impl 283 API calls 44176->44177 44178 7ff6b9cbb0c9 44177->44178 44179 7ff6b9cbb0e6 44178->44179 44180 7ff6b9cb66c8 _errno 283 API calls 44178->44180 44179->44164 44181 7ff6b9cbb0dc 44180->44181 44181->44179 44182 7ff6b9cb66c8 _errno 283 API calls 44181->44182 44182->44179 44183->43419 44184->43421 44185->43420 44186->43320 44187->43331 44188->43338 44189->43335 44190->43345 44191->43346 44193->43377 44197->43394 44199 7ff6b9cc7424 44200 7ff6b9cc744f 44199->44200 44201 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44200->44201 44202 7ff6b9cc745a 44201->44202 44203 7ff6b9cc7479 Concurrency::details::InternalContextBase::Dispatch 44202->44203 44205 7ff6b9cdb518 44202->44205 44228 7ff6b9cbb250 InitializeCriticalSectionAndSpinCount 44205->44228 44207 7ff6b9cdb558 44229 7ff6b9cda6a0 44207->44229 44209 7ff6b9cdb59a 44210 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44209->44210 44211 7ff6b9cdb5ab 44210->44211 44212 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44211->44212 44213 7ff6b9cdb5bc 44212->44213 44214 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44213->44214 44215 7ff6b9cdb5cd 44214->44215 44216 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44215->44216 44217 7ff6b9cdb5de 44216->44217 44218 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44217->44218 44219 7ff6b9cdb5ef 44218->44219 44220 7ff6b9cdb61f 44219->44220 44221 7ff6b9cdb607 GetCurrentThread GetThreadPriority 44219->44221 44240 7ff6b9cc8ce0 44220->44240 44221->44220 44224 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44226 7ff6b9cdb726 Concurrency::details::HillClimbing::HillClimbing 44224->44226 44244 7ff6b9cc9004 44226->44244 44227 7ff6b9cdb752 44227->44203 44227->44227 44228->44207 44230 7ff6b9cda6ba 44229->44230 44231 7ff6b9cda6ac 44229->44231 44248 7ff6b9cc68b8 283 API calls std::exception::exception 44230->44248 44231->44209 44233 7ff6b9cda6d9 44234 7ff6b9cb87f8 _CxxThrowException 2 API calls 44233->44234 44235 7ff6b9cda6ea 44234->44235 44236 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44235->44236 44237 7ff6b9cda70a 44236->44237 44238 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44237->44238 44239 7ff6b9cda717 44238->44239 44239->44209 44241 7ff6b9cc8d4d 44240->44241 44242 7ff6b9cc8cf7 _SpinWait 44240->44242 44241->44224 44241->44226 44242->44241 44249 7ff6b9cc963c 44242->44249 44246 7ff6b9cc8f68 _SpinWait 44244->44246 44245 7ff6b9cc8fd5 44245->44227 44246->44245 44247 7ff6b9cc963c Concurrency::details::ResourceManager::InitializeSystemInformation 366 API calls 44246->44247 44247->44245 44248->44233 44250 7ff6b9cc9664 44249->44250 44251 7ff6b9cc9669 44249->44251 44265 7ff6b9ccad54 GetVersionExW 44250->44265 44253 7ff6b9cc9680 44251->44253 44281 7ff6b9cc6f3c GetCurrentProcess GetProcessAffinityMask 44251->44281 44255 7ff6b9cc9766 44253->44255 44256 7ff6b9cc9696 44253->44256 44257 7ff6b9cc9825 44255->44257 44258 7ff6b9cc976f 44255->44258 44302 7ff6b9cc901c 293 API calls 2 library calls 44256->44302 44261 7ff6b9cc9820 44257->44261 44262 7ff6b9cc6f3c Concurrency::details::ResourceManager::CaptureProcessAffinity 356 API calls 44257->44262 44303 7ff6b9cc901c 293 API calls 2 library calls 44258->44303 44261->44241 44262->44261 44263 7ff6b9cc96a0 Concurrency::details::ResourceManager::ApplyAffinityRestrictions 44263->44261 44299 7ff6b9cc70b4 44263->44299 44266 7ff6b9ccad88 44265->44266 44267 7ff6b9ccae29 std::bad_exception::bad_exception 44265->44267 44268 7ff6b9ccad91 44266->44268 44270 7ff6b9ccae44 std::bad_exception::bad_exception 44266->44270 44269 7ff6b9cb87f8 _CxxThrowException 2 API calls 44267->44269 44271 7ff6b9ccadb9 44268->44271 44304 7ff6b9cc5ef4 GetModuleHandleW GetProcAddress GetProcAddress 44268->44304 44269->44270 44274 7ff6b9cb87f8 _CxxThrowException 2 API calls 44270->44274 44273 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 44271->44273 44276 7ff6b9ccadd3 44273->44276 44277 7ff6b9ccae67 44274->44277 44275 7ff6b9ccae14 44316 7ff6b9cdcb44 GetModuleHandleW GetProcAddress 44275->44316 44276->44251 44279 7ff6b9ccae19 44279->44271 44418 7ff6b9cdd1f8 LoadLibraryExW 44279->44418 44282 7ff6b9cc6fb6 44281->44282 44283 7ff6b9cc6f87 GetLastError 44281->44283 44286 7ff6b9cc7040 44282->44286 44287 7ff6b9cc6fd4 GetCurrentThread 44282->44287 44298 7ff6b9cc7021 44282->44298 44284 7ff6b9cc6fa5 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44283->44284 44289 7ff6b9cb87f8 _CxxThrowException 2 API calls 44284->44289 44285 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 44288 7ff6b9cc70a3 44285->44288 44290 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44286->44290 44435 7ff6b9cc6a60 80 API calls Concurrency::details::platform::__GetThreadGroupAffinity 44287->44435 44288->44253 44289->44282 44292 7ff6b9cc704c 44290->44292 44295 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44292->44295 44292->44298 44293 7ff6b9cc6fe7 44294 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44293->44294 44296 7ff6b9cc6ff3 44294->44296 44295->44298 44297 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44296->44297 44297->44298 44298->44285 44300 7ff6b9cb5a10 free 283 API calls 44299->44300 44301 7ff6b9cc70c4 44300->44301 44301->44261 44302->44263 44303->44263 44305 7ff6b9cc5fd0 GetLastError 44304->44305 44308 7ff6b9cc5f3d Concurrency::details::Etw::GetEnableLevel 44304->44308 44306 7ff6b9cc5fee Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44305->44306 44307 7ff6b9cb87f8 _CxxThrowException 2 API calls 44306->44307 44309 7ff6b9cc5fff 44307->44309 44308->44305 44310 7ff6b9cc5f5d GetModuleHandleW GetProcAddress 44308->44310 44311 7ff6b9cc5fa0 GetLastError 44310->44311 44312 7ff6b9cc5f86 Concurrency::details::Etw::GetEnableLevel 44310->44312 44313 7ff6b9cc5fbe Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44311->44313 44312->44275 44314 7ff6b9cb87f8 _CxxThrowException 2 API calls 44313->44314 44315 7ff6b9cc5fcf 44314->44315 44315->44305 44317 7ff6b9cdcb82 Concurrency::details::Etw::GetEnableLevel 44316->44317 44318 7ff6b9cdcebd GetLastError 44316->44318 44320 7ff6b9cdcb8a GetModuleHandleW GetProcAddress 44317->44320 44319 7ff6b9cdcedb Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44318->44319 44323 7ff6b9cb87f8 _CxxThrowException 2 API calls 44319->44323 44321 7ff6b9cdcbb3 Concurrency::details::Etw::GetEnableLevel 44320->44321 44322 7ff6b9cdceed GetLastError 44320->44322 44326 7ff6b9cdcbbb GetModuleHandleW GetProcAddress 44321->44326 44325 7ff6b9cdcf0a Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44322->44325 44324 7ff6b9cdceec 44323->44324 44324->44322 44329 7ff6b9cb87f8 _CxxThrowException 2 API calls 44325->44329 44327 7ff6b9cdcbe4 Concurrency::details::Etw::GetEnableLevel 44326->44327 44328 7ff6b9cdcf1b GetLastError 44326->44328 44332 7ff6b9cdcbec GetModuleHandleW GetProcAddress 44327->44332 44330 7ff6b9cdcf38 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44328->44330 44331 7ff6b9cdcf1a 44329->44331 44333 7ff6b9cb87f8 _CxxThrowException 2 API calls 44330->44333 44331->44328 44334 7ff6b9cdcc15 Concurrency::details::Etw::GetEnableLevel 44332->44334 44335 7ff6b9cdcf49 GetLastError 44332->44335 44336 7ff6b9cdcf48 44333->44336 44338 7ff6b9cdcc1d GetModuleHandleW GetProcAddress 44334->44338 44337 7ff6b9cdcf69 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44335->44337 44336->44335 44339 7ff6b9cb87f8 _CxxThrowException 2 API calls 44337->44339 44340 7ff6b9cdcf7d GetLastError 44338->44340 44341 7ff6b9cdcc46 Concurrency::details::Etw::GetEnableLevel 44338->44341 44342 7ff6b9cdcf7c 44339->44342 44343 7ff6b9cdcf9a Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44340->44343 44344 7ff6b9cdcc4e GetModuleHandleW GetProcAddress 44341->44344 44342->44340 44347 7ff6b9cb87f8 _CxxThrowException 2 API calls 44343->44347 44345 7ff6b9cdcfab GetLastError 44344->44345 44346 7ff6b9cdcc77 Concurrency::details::Etw::GetEnableLevel 44344->44346 44348 7ff6b9cdcfcb Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44345->44348 44350 7ff6b9cdcc7f GetModuleHandleW GetProcAddress 44346->44350 44349 7ff6b9cdcfaa 44347->44349 44351 7ff6b9cb87f8 _CxxThrowException 2 API calls 44348->44351 44349->44345 44352 7ff6b9cdcfdf GetLastError 44350->44352 44353 7ff6b9cdcca8 Concurrency::details::Etw::GetEnableLevel 44350->44353 44354 7ff6b9cdcfde 44351->44354 44355 7ff6b9cdcffc Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44352->44355 44356 7ff6b9cdccb0 GetModuleHandleW GetProcAddress 44353->44356 44354->44352 44357 7ff6b9cb87f8 _CxxThrowException 2 API calls 44355->44357 44358 7ff6b9cdd00d GetLastError 44356->44358 44360 7ff6b9cdccd9 Concurrency::details::Etw::GetEnableLevel 44356->44360 44359 7ff6b9cdd00c 44357->44359 44361 7ff6b9cdd02d Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44358->44361 44359->44358 44362 7ff6b9cdcce1 GetModuleHandleW GetProcAddress 44360->44362 44365 7ff6b9cb87f8 _CxxThrowException 2 API calls 44361->44365 44363 7ff6b9cdd041 GetLastError 44362->44363 44364 7ff6b9cdcd0a Concurrency::details::Etw::GetEnableLevel 44362->44364 44367 7ff6b9cdd05f Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44363->44367 44368 7ff6b9cdcd12 GetModuleHandleW GetProcAddress 44364->44368 44366 7ff6b9cdd040 44365->44366 44366->44363 44369 7ff6b9cb87f8 _CxxThrowException 2 API calls 44367->44369 44370 7ff6b9cdd071 GetLastError 44368->44370 44371 7ff6b9cdcd3b Concurrency::details::Etw::GetEnableLevel 44368->44371 44372 7ff6b9cdd070 44369->44372 44373 7ff6b9cdd08f Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44370->44373 44374 7ff6b9cdcd43 GetModuleHandleW GetProcAddress 44371->44374 44372->44370 44377 7ff6b9cb87f8 _CxxThrowException 2 API calls 44373->44377 44375 7ff6b9cdd0a1 GetLastError 44374->44375 44376 7ff6b9cdcd6c Concurrency::details::Etw::GetEnableLevel 44374->44376 44379 7ff6b9cdd0be Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44375->44379 44380 7ff6b9cdcd74 GetModuleHandleW GetProcAddress 44376->44380 44378 7ff6b9cdd0a0 44377->44378 44378->44375 44383 7ff6b9cb87f8 _CxxThrowException 2 API calls 44379->44383 44381 7ff6b9cdd0cf GetLastError 44380->44381 44382 7ff6b9cdcd9d Concurrency::details::Etw::GetEnableLevel 44380->44382 44385 7ff6b9cdd0ec Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44381->44385 44386 7ff6b9cdcda5 GetModuleHandleW GetProcAddress 44382->44386 44384 7ff6b9cdd0ce 44383->44384 44384->44381 44387 7ff6b9cb87f8 _CxxThrowException 2 API calls 44385->44387 44388 7ff6b9cdcdce Concurrency::details::Etw::GetEnableLevel 44386->44388 44389 7ff6b9cdd0fd GetLastError 44386->44389 44390 7ff6b9cdd0fc 44387->44390 44392 7ff6b9cdcdd6 GetModuleHandleW GetProcAddress 44388->44392 44391 7ff6b9cdd11a Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44389->44391 44390->44389 44393 7ff6b9cb87f8 _CxxThrowException 2 API calls 44391->44393 44394 7ff6b9cdcdff Concurrency::details::Etw::GetEnableLevel 44392->44394 44395 7ff6b9cdd12b GetLastError 44392->44395 44396 7ff6b9cdd12a 44393->44396 44398 7ff6b9cdce07 GetModuleHandleW GetProcAddress 44394->44398 44397 7ff6b9cdd148 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44395->44397 44396->44395 44399 7ff6b9cb87f8 _CxxThrowException 2 API calls 44397->44399 44400 7ff6b9cdce30 Concurrency::details::Etw::GetEnableLevel 44398->44400 44401 7ff6b9cdd159 GetLastError 44398->44401 44402 7ff6b9cdd158 44399->44402 44404 7ff6b9cdce38 GetModuleHandleW GetProcAddress 44400->44404 44403 7ff6b9cdd179 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44401->44403 44402->44401 44407 7ff6b9cb87f8 _CxxThrowException 2 API calls 44403->44407 44405 7ff6b9cdce61 Concurrency::details::Etw::GetEnableLevel 44404->44405 44406 7ff6b9cdd18d GetLastError 44404->44406 44410 7ff6b9cdce69 GetModuleHandleW GetProcAddress 44405->44410 44409 7ff6b9cdd1ad Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44406->44409 44408 7ff6b9cdd18c 44407->44408 44408->44406 44413 7ff6b9cb87f8 _CxxThrowException 2 API calls 44409->44413 44411 7ff6b9cdce92 Concurrency::details::Etw::GetEnableLevel 44410->44411 44412 7ff6b9cdd1c1 GetLastError 44410->44412 44411->44279 44415 7ff6b9cdd1e1 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44412->44415 44414 7ff6b9cdd1c0 44413->44414 44414->44412 44416 7ff6b9cb87f8 _CxxThrowException 2 API calls 44415->44416 44417 7ff6b9cdd1f4 44416->44417 44419 7ff6b9cdd220 GetModuleHandleW GetProcAddress 44418->44419 44420 7ff6b9cdd29d GetLastError 44418->44420 44421 7ff6b9cdd2cd GetLastError 44419->44421 44422 7ff6b9cdd246 Concurrency::details::Etw::GetEnableLevel 44419->44422 44423 7ff6b9cdd2bb Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44420->44423 44424 7ff6b9cdd2eb Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44421->44424 44426 7ff6b9cdd24e GetModuleHandleW GetProcAddress 44422->44426 44425 7ff6b9cb87f8 _CxxThrowException 2 API calls 44423->44425 44428 7ff6b9cb87f8 _CxxThrowException 2 API calls 44424->44428 44427 7ff6b9cdd2cc 44425->44427 44429 7ff6b9cdd27b Concurrency::details::Etw::GetEnableLevel 44426->44429 44430 7ff6b9cdd2fd GetLastError 44426->44430 44427->44421 44431 7ff6b9cdd2fc 44428->44431 44429->44271 44432 7ff6b9cdd31b Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44430->44432 44431->44430 44433 7ff6b9cb87f8 _CxxThrowException 2 API calls 44432->44433 44434 7ff6b9cdd32c 44433->44434 44435->44293 44436 7ff6b9cb0e5c 44437 7ff6b9cb0e91 GetCurrentThreadId 44436->44437 44438 7ff6b9cb0ebf 44436->44438 44439 7ff6b9cb0e9f 44437->44439 44455 7ff6b9cb0eb4 44437->44455 44440 7ff6b9cb0ee1 44438->44440 44441 7ff6b9cb0ec4 GetCurrentThreadId 44438->44441 44442 7ff6b9cbb9f0 Concurrency::critical_section::lock 446 API calls 44439->44442 44445 7ff6b9cb0f42 GetCurrentThreadId 44440->44445 44456 7ff6b9cb0eef _Xtime_diff_to_millis2 44440->44456 44443 7ff6b9cb0ed6 44441->44443 44444 7ff6b9cb0edf 44441->44444 44446 7ff6b9cb0ea8 GetCurrentThreadId 44442->44446 44458 7ff6b9cbb9f0 44443->44458 44449 7ff6b9cb0f96 GetCurrentThreadId 44444->44449 44444->44455 44445->44444 44448 7ff6b9cb0f50 44445->44448 44446->44455 44465 7ff6b9cbba2c 444 API calls 2 library calls 44448->44465 44449->44455 44450 7ff6b9cb4a30 $I10_OUTPUT 9 API calls 44453 7ff6b9cb0fb1 44450->44453 44454 7ff6b9cb0f13 GetCurrentThreadId 44454->44444 44454->44456 44455->44450 44456->44444 44456->44454 44456->44455 44463 7ff6b9cb2d6c GetSystemTimeAsFileTime _Xtime_get_ticks 44456->44463 44464 7ff6b9cbbacc 446 API calls 4 library calls 44456->44464 44466 7ff6b9cbb0f8 44458->44466 44462 7ff6b9cbba16 Concurrency::critical_section::_Switch_to_active 44462->44444 44463->44456 44464->44456 44465->44444 44467 7ff6b9cbb14e 44466->44467 44468 7ff6b9cbb13d TlsGetValue 44466->44468 44483 7ff6b9ccc8dc 44467->44483 44468->44467 44469 7ff6b9cbb153 44468->44469 44471 7ff6b9cbb1b0 44469->44471 44488 7ff6b9cc8ff4 78 API calls 2 library calls 44469->44488 44482 7ff6b9cbb524 443 API calls 4 library calls 44471->44482 44473 7ff6b9cbb160 44474 7ff6b9cbb180 44473->44474 44478 7ff6b9cbb165 Concurrency::details::platform::__GetLogicalProcessorInformationEx 44473->44478 44489 7ff6b9cd04b0 3 API calls 3 library calls 44474->44489 44476 7ff6b9cbb185 CreateTimerQueueTimer 44476->44471 44477 7ff6b9cbb209 Concurrency::details::platform::__GetLogicalProcessorInformationEx 44476->44477 44479 7ff6b9cb87f8 _CxxThrowException 2 API calls 44477->44479 44478->44471 44480 7ff6b9cb87f8 _CxxThrowException 2 API calls 44478->44480 44481 7ff6b9cbb24e 44479->44481 44480->44477 44482->44462 44490 7ff6b9ccd348 44483->44490 44485 7ff6b9ccc8eb 44498 7ff6b9ccc274 TlsGetValue 44485->44498 44488->44473 44489->44476 44491 7ff6b9ccd370 _SpinWait Concurrency::details::SchedulerBase::SafeReference 44490->44491 44497 7ff6b9ccd3eb Concurrency::details::InternalContextBase::Dispatch 44491->44497 44512 7ff6b9cda5a8 44491->44512 44493 7ff6b9ccd3bb Concurrency::SchedulerPolicy::operator= 44515 7ff6b9ccc940 44493->44515 44497->44485 44499 7ff6b9ccc2bd 44498->44499 44500 7ff6b9ccc29d 44498->44500 44633 7ff6b9ccd41c InterlockedPopEntrySList 44499->44633 44501 7ff6b9ccc2a3 44500->44501 44502 7ff6b9ccc2f9 std::bad_exception::bad_exception 44500->44502 44503 7ff6b9ccc2b5 44501->44503 44641 7ff6b9ce05ac 301 API calls 4 library calls 44501->44641 44508 7ff6b9cb87f8 _CxxThrowException 2 API calls 44502->44508 44642 7ff6b9cd86c8 TlsSetValue 44503->44642 44510 7ff6b9ccc314 44508->44510 44544 7ff6b9cda73c 44512->44544 44514 7ff6b9cda5d0 44514->44493 44562 7ff6b9cda99c 44515->44562 44522 7ff6b9ccda9c 44593 7ff6b9cc741c 44522->44593 44524 7ff6b9ccdadb Concurrency::details::SchedulerBase::Initialize 44525 7ff6b9cc9004 Concurrency::details::SchedulerBase::Initialize 366 API calls 44524->44525 44526 7ff6b9ccdaf2 GetNumaHighestNodeNumber 44525->44526 44527 7ff6b9ccdb03 GetLastError 44526->44527 44536 7ff6b9ccdb30 Concurrency::details::QuickBitSet::Grow Concurrency::details::SchedulerBase::Initialize Concurrency::details::SchedulerBase::PostAffinityMessage _wctomb_s_l 44526->44536 44528 7ff6b9ccdb20 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44527->44528 44529 7ff6b9cb87f8 _CxxThrowException 2 API calls 44528->44529 44529->44536 44531 7ff6b9cb7c18 283 API calls std::_Facet_Register 44531->44536 44532 7ff6b9ccde83 Concurrency::details::QuickBitSet::Grow Concurrency::details::SchedulerBase::GetValidSchedulingRingIndex Concurrency::details::ReferenceCountedQuickBitSet::Grow 44606 7ff6b9cbc1a4 CreateSemaphoreW 44532->44606 44536->44531 44536->44532 44541 7ff6b9ccdfe4 283 API calls Concurrency::details::SchedulerBase::Initialize 44536->44541 44604 7ff6b9ce1260 286 API calls 2 library calls 44536->44604 44605 7ff6b9cded00 285 API calls 3 library calls 44536->44605 44541->44536 44545 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44544->44545 44550 7ff6b9cda76f Concurrency::SchedulerPolicy::_ValidPolicyValue 44545->44550 44546 7ff6b9cda87b 44555 7ff6b9cda6ec 44546->44555 44549 7ff6b9cda8a2 Concurrency::SchedulerPolicy::_ResolvePolicyValues 44549->44514 44550->44546 44551 7ff6b9cb87f8 RtlPcToFileHeader RaiseException _CxxThrowException 44550->44551 44560 7ff6b9cc68b8 283 API calls std::exception::exception 44550->44560 44561 7ff6b9cc6908 283 API calls std::exception::exception 44550->44561 44551->44550 44553 7ff6b9cda883 std::bad_exception::bad_exception 44553->44549 44554 7ff6b9cb87f8 _CxxThrowException 2 API calls 44553->44554 44554->44549 44556 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44555->44556 44557 7ff6b9cda70a 44556->44557 44558 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44557->44558 44559 7ff6b9cda717 44558->44559 44559->44553 44560->44550 44561->44550 44563 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44562->44563 44564 7ff6b9cda9af 44563->44564 44565 7ff6b9cda9b3 44564->44565 44566 7ff6b9cda9ca 44564->44566 44567 7ff6b9cda6a0 Concurrency::details::InternalContextBase::Dispatch 283 API calls 44565->44567 44588 7ff6b9cc6908 283 API calls std::exception::exception 44566->44588 44569 7ff6b9cda9c0 44567->44569 44571 7ff6b9ccc94e 44569->44571 44589 7ff6b9cc6908 283 API calls std::exception::exception 44569->44589 44570 7ff6b9cda9db 44572 7ff6b9cb87f8 _CxxThrowException 2 API calls 44570->44572 44577 7ff6b9ccc46c 44571->44577 44572->44569 44574 7ff6b9cda9fe 44575 7ff6b9cb87f8 _CxxThrowException 2 API calls 44574->44575 44576 7ff6b9cdaa0f 44575->44576 44578 7ff6b9ccc494 _SpinWait 44577->44578 44579 7ff6b9ccc4f1 44578->44579 44580 7ff6b9ccc4e0 44578->44580 44590 7ff6b9cddcb4 293 API calls 4 library calls 44578->44590 44583 7ff6b9ce3e7c 44579->44583 44580->44579 44591 7ff6b9cce39c 6 API calls 3 library calls 44580->44591 44584 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44583->44584 44586 7ff6b9ce3e98 44584->44586 44585 7ff6b9ccc95b 44585->44522 44586->44585 44592 7ff6b9ce3d88 298 API calls Concurrency::details::SchedulerBase::SchedulerBase 44586->44592 44588->44570 44589->44574 44590->44580 44591->44579 44592->44585 44595 7ff6b9cc749c _SpinWait 44593->44595 44594 7ff6b9cc74fb 44596 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44594->44596 44595->44594 44598 7ff6b9cc7520 Concurrency::details::Etw::GetEnableLevel 44595->44598 44597 7ff6b9cc7505 44596->44597 44602 7ff6b9cc7517 Concurrency::details::Etw::GetEnableLevel 44597->44602 44607 7ff6b9cc6a8c 44597->44607 44600 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44598->44600 44598->44602 44601 7ff6b9cc7545 44600->44601 44601->44602 44603 7ff6b9cc6a8c Concurrency::details::ResourceManager::ResourceManager 371 API calls 44601->44603 44602->44524 44603->44602 44604->44536 44605->44536 44623 7ff6b9cbb250 InitializeCriticalSectionAndSpinCount 44607->44623 44609 7ff6b9cc6ad0 44624 7ff6b9cdd368 44609->44624 44612 7ff6b9cc963c Concurrency::details::ResourceManager::InitializeSystemInformation 366 API calls 44613 7ff6b9cc6b14 44612->44613 44631 7ff6b9cc7678 283 API calls 3 library calls 44613->44631 44615 7ff6b9cc6b1c 44616 7ff6b9cc6b2e VirtualAlloc 44615->44616 44617 7ff6b9cc6b25 44615->44617 44620 7ff6b9cc6b51 Concurrency::details::platform::__GetLogicalProcessorInformationEx 44616->44620 44622 7ff6b9cc6b8f 44616->44622 44618 7ff6b9cc6b93 CreateEventW 44617->44618 44619 7ff6b9cc6bc5 44618->44619 44619->44602 44621 7ff6b9cb87f8 _CxxThrowException 2 API calls 44620->44621 44621->44622 44622->44618 44623->44609 44632 7ff6b9cbb250 InitializeCriticalSectionAndSpinCount 44624->44632 44626 7ff6b9cdd390 TlsAlloc 44627 7ff6b9cdd39f GetLastError 44626->44627 44630 7ff6b9cc6b0c 44626->44630 44628 7ff6b9cdd3bd Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44627->44628 44629 7ff6b9cb87f8 _CxxThrowException 2 API calls 44628->44629 44629->44630 44630->44612 44631->44615 44632->44626 44634 7ff6b9ccd47e 44633->44634 44635 7ff6b9ccd457 44633->44635 44657 7ff6b9ce3ae0 GetCurrentThreadId 44634->44657 44636 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44635->44636 44638 7ff6b9ccd461 44636->44638 44639 7ff6b9ccc2d8 44638->44639 44644 7ff6b9ce3758 44638->44644 44643 7ff6b9cd8d3c TlsSetValue 44639->44643 44678 7ff6b9cd7df8 44644->44678 44647 7ff6b9ce37b5 GetLastError 44648 7ff6b9ce37d3 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44647->44648 44650 7ff6b9cb87f8 _CxxThrowException 2 API calls 44648->44650 44649 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44652 7ff6b9ce37fc 44649->44652 44651 7ff6b9ce37e4 Concurrency::details::ExternalContextBase::ExternalContextBase 44650->44651 44651->44649 44682 7ff6b9ce1d00 44652->44682 44655 7ff6b9ce3ae0 Concurrency::details::ExternalContextBase::PrepareForUse 91 API calls 44656 7ff6b9ce383d 44655->44656 44656->44639 44658 7ff6b9ce3b14 GetCurrentProcess GetCurrentThread GetCurrentProcess DuplicateHandle 44657->44658 44659 7ff6b9ce3bb0 44657->44659 44660 7ff6b9ce3b5b 44658->44660 44661 7ff6b9ce3bc7 GetLastError 44658->44661 44659->44639 44687 7ff6b9cc8ff4 78 API calls 2 library calls 44660->44687 44663 7ff6b9ce3be5 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44661->44663 44665 7ff6b9cb87f8 _CxxThrowException 2 API calls 44663->44665 44664 7ff6b9ce3b60 44666 7ff6b9ce3b85 RegisterWaitForSingleObject 44664->44666 44667 7ff6b9ce3b65 44664->44667 44672 7ff6b9ce3b77 44665->44672 44666->44659 44669 7ff6b9ce3c27 GetLastError 44666->44669 44688 7ff6b9cc65e4 15 API calls 3 library calls 44667->44688 44671 7ff6b9ce3c45 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44669->44671 44670 7ff6b9ce3bf7 GetLastError 44673 7ff6b9ce3c15 Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error 44670->44673 44674 7ff6b9cb87f8 _CxxThrowException 2 API calls 44671->44674 44672->44659 44672->44670 44675 7ff6b9cb87f8 _CxxThrowException 2 API calls 44673->44675 44676 7ff6b9ce3c56 44674->44676 44677 7ff6b9ce3c26 44675->44677 44677->44669 44680 7ff6b9cd7e77 Concurrency::details::ContextBase::ContextBase Concurrency::details::_TaskCollection::_Initialize _wctomb_s_l 44678->44680 44679 7ff6b9cd7f35 CreateEventW 44679->44647 44679->44651 44680->44679 44686 7ff6b9cd929c EncodePointer _wctomb_s_l Concurrency::details::Etw::Trace 44680->44686 44685 7ff6b9ce1d2d _SpinWait _wctomb_s_l 44682->44685 44683 7ff6b9ce1e52 44683->44655 44684 7ff6b9cb7c18 std::_Facet_Register 283 API calls 44684->44685 44685->44683 44685->44684 44686->44679 44687->44664 44688->44672
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: memchr$Mtx_unlock
      • String ID: days$ seconds$'licString' is the license string of the product to be licensed$'privNum' is the private number of the product (can be set to - to ignore for certain actions)$'productName' is the name of the product to be validated or licensed (this is the filename of the license file without extension)$'version' is the optional version of the product to be licensed$('licString' can be set to - to unlicense a product)$('licString' can be set to -content to retrieve the current content of the license file as a string)$('licString' can be set to PID@REMOTE to request a floating license - replace PID with the product ID on the server)$) / $-auth_check_days$-auth_check_days [numDays] sets the online activation check interval in days$-check$-force_online$-force_online enables forced online activation$-license$-multi$-multi enables support for multi-licenses$-offline_support$-online$-online enables online checks$-timeout$-timeout [timeout] sets the online activation timeout in milliseconds$-unauth_check_days$-unauth_check_days [numDays] sets the online activation grace period in days$-url$-url [URL] sets the online check URL to use$-web$.43 ($2000$20241006$AESCRIPTSLICLIB 4.1.3$Forced online activation active$License checker mode call syntax:$Licenser mode call syntax:$Offline licensing support active$Online check active$Online check inactive$Setting online activation check interval to $Setting online activation grace period to $Setting online activation timeout to $Support for multi-licenses active$The following additional flags can be appended to the command line to enable specific features:$The tool can also be run in 'licenser' or 'license checker' mode$Using online check URL $aescriptsLicTool_Verbose$aescriptsLicTool_Verbose productName - [licString] [version] -check$aescriptsLicTool_Verbose productName - [licString] [version] -license$t$usage: aescriptsLicTool_Verbose productName privNum [licString] [version]$|||||||||$%$&;$6;
      • API String ID: 3101769438-276666048
      • Opcode ID: b1b383baf7a04ba0b06efc75c45f175071b192e2f2503bbc900848fffc0211fc
      • Instruction ID: 8f5a859461d02ba21ae9d1e4eb5bab45b8f9d4bd2e968077e99f74bce3d5f02e
      • Opcode Fuzzy Hash: b1b383baf7a04ba0b06efc75c45f175071b192e2f2503bbc900848fffc0211fc
      • Instruction Fuzzy Hash: E2A26F21A1869685EB25DF2DD8583F92771EF55788F845031DB0ECBAABEF6CE605C300

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 694 7ff6b9cc2644-7ff6b9cc268c call 7ff6b9cc5010 697 7ff6b9cc268e-7ff6b9cc2690 694->697 698 7ff6b9cc2695-7ff6b9cc2698 694->698 699 7ff6b9cc2d56-7ff6b9cc2d7f call 7ff6b9cb4a30 697->699 700 7ff6b9cc26b9-7ff6b9cc26eb 698->700 701 7ff6b9cc269a-7ff6b9cc26b4 call 7ff6b9cb6658 call 7ff6b9cb66c8 call 7ff6b9cbd340 698->701 704 7ff6b9cc26f6-7ff6b9cc26fc 700->704 705 7ff6b9cc26ed-7ff6b9cc26f4 700->705 701->699 708 7ff6b9cc26fe-7ff6b9cc2706 call 7ff6b9cc23f8 704->708 709 7ff6b9cc270b-7ff6b9cc2714 call 7ff6b9cd13f0 704->709 705->701 705->704 708->709 716 7ff6b9cc29d6-7ff6b9cc29e7 709->716 717 7ff6b9cc271a-7ff6b9cc272b 709->717 719 7ff6b9cc2cb8-7ff6b9cc2cd4 WriteFile 716->719 720 7ff6b9cc29ed-7ff6b9cc29f9 716->720 717->716 721 7ff6b9cc2731-7ff6b9cc2765 call 7ff6b9cc07b0 GetConsoleMode 717->721 723 7ff6b9cc2cde-7ff6b9cc2ce4 GetLastError 719->723 724 7ff6b9cc2cd6-7ff6b9cc2cdc 719->724 725 7ff6b9cc29ff-7ff6b9cc2a02 720->725 726 7ff6b9cc2ac7-7ff6b9cc2acb 720->726 721->716 734 7ff6b9cc276b-7ff6b9cc276d 721->734 730 7ff6b9cc2ce6-7ff6b9cc2ce8 723->730 724->730 727 7ff6b9cc2a08 725->727 728 7ff6b9cc2d16-7ff6b9cc2d2c 725->728 731 7ff6b9cc2ad1-7ff6b9cc2ad4 726->731 732 7ff6b9cc2ba6-7ff6b9cc2ba9 726->732 733 7ff6b9cc2a0b-7ff6b9cc2a16 727->733 735 7ff6b9cc2d2e-7ff6b9cc2d32 728->735 736 7ff6b9cc2d38-7ff6b9cc2d48 call 7ff6b9cb66c8 call 7ff6b9cb6658 728->736 738 7ff6b9cc2d50-7ff6b9cc2d54 730->738 739 7ff6b9cc2cea-7ff6b9cc2cec 730->739 731->728 740 7ff6b9cc2ada 731->740 732->728 737 7ff6b9cc2baf 732->737 741 7ff6b9cc2a18-7ff6b9cc2a21 733->741 742 7ff6b9cc276f-7ff6b9cc2772 734->742 743 7ff6b9cc2778-7ff6b9cc278c GetConsoleCP 734->743 735->697 735->736 736->738 744 7ff6b9cc2bb5-7ff6b9cc2bba 737->744 738->699 739->728 746 7ff6b9cc2cee-7ff6b9cc2cf1 739->746 747 7ff6b9cc2adf-7ff6b9cc2aea 740->747 748 7ff6b9cc2a23-7ff6b9cc2a2c 741->748 749 7ff6b9cc2a49-7ff6b9cc2a8c WriteFile 741->749 742->716 742->743 750 7ff6b9cc2792-7ff6b9cc2795 743->750 751 7ff6b9cc29cd-7ff6b9cc29d1 743->751 752 7ff6b9cc2bbc-7ff6b9cc2bc5 744->752 754 7ff6b9cc2cf3-7ff6b9cc2d03 call 7ff6b9cb66c8 call 7ff6b9cb6658 746->754 755 7ff6b9cc2d0a-7ff6b9cc2d11 call 7ff6b9cb6678 746->755 756 7ff6b9cc2aec-7ff6b9cc2af5 747->756 758 7ff6b9cc2a2e-7ff6b9cc2a35 748->758 759 7ff6b9cc2a38-7ff6b9cc2a47 748->759 749->723 762 7ff6b9cc2a92-7ff6b9cc2aa8 749->762 760 7ff6b9cc291f-7ff6b9cc2924 750->760 761 7ff6b9cc279b-7ff6b9cc27ba 750->761 751->739 763 7ff6b9cc2bc7-7ff6b9cc2bd4 752->763 764 7ff6b9cc2bf6-7ff6b9cc2c3f WideCharToMultiByte 752->764 754->755 755->728 767 7ff6b9cc2b28-7ff6b9cc2b6b WriteFile 756->767 768 7ff6b9cc2af7-7ff6b9cc2b04 756->768 758->759 759->741 759->749 778 7ff6b9cc2944 760->778 779 7ff6b9cc2926-7ff6b9cc2942 760->779 773 7ff6b9cc27dc-7ff6b9cc27e6 call 7ff6b9cc33a8 761->773 774 7ff6b9cc27bc-7ff6b9cc27da 761->774 762->730 775 7ff6b9cc2aae-7ff6b9cc2abc 762->775 776 7ff6b9cc2be2-7ff6b9cc2bf4 763->776 777 7ff6b9cc2bd6-7ff6b9cc2bde 763->777 764->723 781 7ff6b9cc2c45 764->781 767->723 771 7ff6b9cc2b71-7ff6b9cc2b87 767->771 769 7ff6b9cc2b14-7ff6b9cc2b26 768->769 770 7ff6b9cc2b06-7ff6b9cc2b10 768->770 769->756 769->767 770->769 771->730 783 7ff6b9cc2b8d-7ff6b9cc2b9b 771->783 800 7ff6b9cc27e8-7ff6b9cc27f5 773->800 801 7ff6b9cc281c-7ff6b9cc2822 773->801 784 7ff6b9cc2825-7ff6b9cc2832 call 7ff6b9cd6488 774->784 775->733 787 7ff6b9cc2ac2 775->787 776->752 776->764 777->776 788 7ff6b9cc2949-7ff6b9cc294e 778->788 779->788 786 7ff6b9cc2c47-7ff6b9cc2c81 WriteFile 781->786 783->747 794 7ff6b9cc2ba1 783->794 807 7ff6b9cc29c4-7ff6b9cc29c8 784->807 808 7ff6b9cc2838-7ff6b9cc2875 WideCharToMultiByte 784->808 790 7ff6b9cc2c91-7ff6b9cc2c99 GetLastError 786->790 791 7ff6b9cc2c83-7ff6b9cc2c8d 786->791 787->730 796 7ff6b9cc2950-7ff6b9cc295f call 7ff6b9cd6490 788->796 797 7ff6b9cc298f 788->797 803 7ff6b9cc2c9d-7ff6b9cc2c9f 790->803 791->786 802 7ff6b9cc2c8f 791->802 794->730 796->723 812 7ff6b9cc2965-7ff6b9cc296b 796->812 799 7ff6b9cc2994-7ff6b9cc299c 797->799 799->807 809 7ff6b9cc299e 799->809 810 7ff6b9cc29a3-7ff6b9cc29bb 800->810 811 7ff6b9cc27fb-7ff6b9cc2811 call 7ff6b9cd6488 800->811 801->784 802->803 803->730 806 7ff6b9cc2ca1-7ff6b9cc2cb0 803->806 806->744 814 7ff6b9cc2cb6 806->814 807->730 808->807 815 7ff6b9cc287b-7ff6b9cc28aa WriteFile 808->815 809->750 810->807 811->807 820 7ff6b9cc2817-7ff6b9cc281a 811->820 812->797 816 7ff6b9cc296d-7ff6b9cc2983 call 7ff6b9cd6490 812->816 814->730 815->723 817 7ff6b9cc28b0-7ff6b9cc28be 815->817 816->723 824 7ff6b9cc2989-7ff6b9cc298b 816->824 817->807 821 7ff6b9cc28c4-7ff6b9cc28ce 817->821 820->808 821->799 823 7ff6b9cc28d4-7ff6b9cc2906 WriteFile 821->823 823->723 825 7ff6b9cc290c-7ff6b9cc2911 823->825 824->797 825->807 826 7ff6b9cc2917-7ff6b9cc291d 825->826 826->799
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: __doserrno_errno_invalid_parameter_noinfo
      • String ID: U
      • API String ID: 3902385426-4171548499
      • Opcode ID: 310e5d689b6c9005fc2c29a6e7927e47ab9f9910382af6568becb401648d8fdb
      • Instruction ID: b6ed4202921600c81b83f927f3b694d82e71fce99fccd2af3bf52cebd0dd459e
      • Opcode Fuzzy Hash: 310e5d689b6c9005fc2c29a6e7927e47ab9f9910382af6568becb401648d8fdb
      • Instruction Fuzzy Hash: AC12D372A1864286EB208F2DD48837E6BB1FB85794F504136EB8DC3AA4DF3DE545CB50
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: __doserrno_errno_getptd_noexit$_invalid_parameter_noinfo
      • String ID:
      • API String ID: 388111225-0
      • Opcode ID: b1aebb7bc750ed6bd965db0952ebf2d304918c80961731e59570ffc347a6a6d3
      • Instruction ID: 1598fdf5fe9f011e66731fc2030e2ca9dad7663cd8b9d3346fc63e71ea8d488b
      • Opcode Fuzzy Hash: b1aebb7bc750ed6bd965db0952ebf2d304918c80961731e59570ffc347a6a6d3
      • Instruction Fuzzy Hash: 5B32D022A9C6C286FB219F2DC4882BC2BB0AF55798F548535CB1E87799DF3DED058710

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 827 7ff6b9cb7c18-7ff6b9cb7c21 828 7ff6b9cb7c32-7ff6b9cb7c3a call 7ff6b9cb5c2c 827->828 831 7ff6b9cb7c23-7ff6b9cb7c2d call 7ff6b9cbeb4c 828->831 832 7ff6b9cb7c3c-7ff6b9cb7c41 828->832 831->828 835 7ff6b9cb7c42-7ff6b9cb7ca6 call 7ff6b9cb4d3c call 7ff6b9cb87f8 call 7ff6b9cc3e74 831->835 842 7ff6b9cb7ca8-7ff6b9cb7caa 835->842 843 7ff6b9cb7cac-7ff6b9cb7cc3 835->843 844 7ff6b9cb7ce4-7ff6b9cb7cef call 7ff6b9cc04e8 842->844 843->842 843->844 847 7ff6b9cb7cf1-7ff6b9cb7cf8 844->847 848 7ff6b9cb7d13-7ff6b9cb7d1a call 7ff6b9cc091c 844->848 849 7ff6b9cb7cff-7ff6b9cb7d0e call 7ff6b9cbe764 call 7ff6b9cb5008 847->849 850 7ff6b9cb7cfa call 7ff6b9cbe6f0 847->850 856 7ff6b9cb7d3e-7ff6b9cb7d4b call 7ff6b9cbe680 call 7ff6b9cbd730 848->856 857 7ff6b9cb7d1c-7ff6b9cb7d23 848->857 849->848 850->849 869 7ff6b9cb7d57-7ff6b9cb7d77 GetCommandLineA call 7ff6b9cc3f68 call 7ff6b9cc3a84 856->869 870 7ff6b9cb7d4d-7ff6b9cb7d52 call 7ff6b9cb7e04 856->870 860 7ff6b9cb7d25 call 7ff6b9cbe6f0 857->860 861 7ff6b9cb7d2a-7ff6b9cb7d39 call 7ff6b9cbe764 call 7ff6b9cb5008 857->861 860->861 861->856 876 7ff6b9cb7d83-7ff6b9cb7d8a call 7ff6b9cc3d40 869->876 877 7ff6b9cb7d79-7ff6b9cb7d7e call 7ff6b9cb5020 869->877 870->869 881 7ff6b9cb7d96-7ff6b9cb7d9f call 7ff6b9cb5068 876->881 882 7ff6b9cb7d8c-7ff6b9cb7d91 call 7ff6b9cb5020 876->882 877->876 886 7ff6b9cb7da1-7ff6b9cb7da3 call 7ff6b9cb5020 881->886 887 7ff6b9cb7da8-7ff6b9cb7dd0 call 7ff6b9c9df40 881->887 882->881 886->887 891 7ff6b9cb7dd2-7ff6b9cb7dd4 call 7ff6b9cb5390 887->891 892 7ff6b9cb7dd9-7ff6b9cb7e03 call 7ff6b9cb5058 887->892 891->892
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _callnewh_errno$AllocHeapmalloc
      • String ID: bad allocation
      • API String ID: 3727741168-2104205924
      • Opcode ID: 7dfc25d6364a89fa24b2a1d03c71c712614c6b3cfffbc134d47ee1c094b8417a
      • Instruction ID: 5fa3066823c3cb6cf975381c4f8a8e988f1e8951903c1f3b450f3ae7b33f0066
      • Opcode Fuzzy Hash: 7dfc25d6364a89fa24b2a1d03c71c712614c6b3cfffbc134d47ee1c094b8417a
      • Instruction Fuzzy Hash: A6312F21E0CB5B45FE50AF69A8591B973B4AF42784F600538EB4DC6AA6EF3CF5058740

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 897 7ff6b9cb7cc5-7ff6b9cb7cce 898 7ff6b9cb7cd0-7ff6b9cb7cd9 897->898 899 7ff6b9cb7ca8-7ff6b9cb7caa 897->899 900 7ff6b9cb7ce4-7ff6b9cb7cef call 7ff6b9cc04e8 898->900 901 7ff6b9cb7cdb-7ff6b9cb7ce1 898->901 899->900 904 7ff6b9cb7cf1-7ff6b9cb7cf8 900->904 905 7ff6b9cb7d13-7ff6b9cb7d1a call 7ff6b9cc091c 900->905 901->900 906 7ff6b9cb7cff 904->906 907 7ff6b9cb7cfa call 7ff6b9cbe6f0 904->907 913 7ff6b9cb7d3e call 7ff6b9cbe680 905->913 914 7ff6b9cb7d1c-7ff6b9cb7d23 905->914 910 7ff6b9cb7d04 call 7ff6b9cbe764 906->910 907->906 912 7ff6b9cb7d09 910->912 916 7ff6b9cb7d0e call 7ff6b9cb5008 912->916 920 7ff6b9cb7d43-7ff6b9cb7d44 call 7ff6b9cbd730 913->920 917 7ff6b9cb7d25 call 7ff6b9cbe6f0 914->917 918 7ff6b9cb7d2a 914->918 916->905 917->918 919 7ff6b9cb7d2f call 7ff6b9cbe764 918->919 922 7ff6b9cb7d34 919->922 925 7ff6b9cb7d49-7ff6b9cb7d4b 920->925 924 7ff6b9cb7d39 call 7ff6b9cb5008 922->924 924->913 926 7ff6b9cb7d57-7ff6b9cb7d77 GetCommandLineA call 7ff6b9cc3f68 call 7ff6b9cc3a84 925->926 927 7ff6b9cb7d4d-7ff6b9cb7d52 call 7ff6b9cb7e04 925->927 933 7ff6b9cb7d83-7ff6b9cb7d8a call 7ff6b9cc3d40 926->933 934 7ff6b9cb7d79-7ff6b9cb7d7e call 7ff6b9cb5020 926->934 927->926 938 7ff6b9cb7d96-7ff6b9cb7d98 call 7ff6b9cb5068 933->938 939 7ff6b9cb7d8c-7ff6b9cb7d91 call 7ff6b9cb5020 933->939 934->933 942 7ff6b9cb7d9d-7ff6b9cb7d9f 938->942 939->938 943 7ff6b9cb7da1-7ff6b9cb7da3 call 7ff6b9cb5020 942->943 944 7ff6b9cb7da8-7ff6b9cb7dc3 call 7ff6b9c9df40 942->944 943->944 947 7ff6b9cb7dc8-7ff6b9cb7dd0 944->947 948 7ff6b9cb7dd2-7ff6b9cb7dd4 call 7ff6b9cb5390 947->948 949 7ff6b9cb7dd9-7ff6b9cb7e03 call 7ff6b9cb5058 947->949 948->949
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _set_error_mode$CommandEnvironmentInitializeLineStrings__crt__setargv_cinit_heap_init_ioinit_mtinit_setenvpfast_error_exit
      • String ID:
      • API String ID: 3166661917-0
      • Opcode ID: b0981de98021ddb0104c549e5ebe9159d348e26bf22f0a2f6efc72fa0723fe93
      • Instruction ID: 96372eac869c0d6519e3ce9faada33103ff76615845e9e61c84b6440eb82aa91
      • Opcode Fuzzy Hash: b0981de98021ddb0104c549e5ebe9159d348e26bf22f0a2f6efc72fa0723fe93
      • Instruction Fuzzy Hash: B3315C21E0C65B46FB907F7DA55E2B935B1AF82744F640439EB0DC66E3EF2CB8408291

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: __doserrno_errno_getptd_noexit$_invalid_parameter_noinfo
      • String ID:
      • API String ID: 388111225-0
      • Opcode ID: 45f8a82ceec06cf673c7f0369de7f0b233dfce2b3635af425e81092c052b3ba0
      • Instruction ID: a44bbf6b5f79ccd638ed5745f74a55306849712e7123bcb73d9808ded6430ea6
      • Opcode Fuzzy Hash: 45f8a82ceec06cf673c7f0369de7f0b233dfce2b3635af425e81092c052b3ba0
      • Instruction Fuzzy Hash: 82310532B8869A46E7126F6DD84917D3670AF817A0F854539EB2D877D6CF7CE8018710

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd_noexit$__doserrno__lock_fhandle_errno_lseek_nolock_unlock_fhandle
      • String ID:
      • API String ID: 1078912150-0
      • Opcode ID: 72afa058709bb828e96d3415c19377e2bbb9911eed6dfa1a6824f421d2ce3fe8
      • Instruction ID: 6ddb6b450f90d93c2afabe58f9aa2e37e9ef64a0f53f39d82f43e94b2afffb8d
      • Opcode Fuzzy Hash: 72afa058709bb828e96d3415c19377e2bbb9911eed6dfa1a6824f421d2ce3fe8
      • Instruction Fuzzy Hash: B521D022F0865645E7116F2DD94937CA9706F807A0F568638EB1D873E2CF7CA8418310

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd_noexit$__doserrno__lock_fhandle_errno_lseeki64_nolock_unlock_fhandle
      • String ID:
      • API String ID: 2644381645-0
      • Opcode ID: dd8faada70b3f1f2db14f4a0876ca9cda89bb6854984bafce4abb2666d957345
      • Instruction ID: bdf2fe7087bfd47b6e0d3ca150055838855e54b90150a3e8a2bd5732429a68a1
      • Opcode Fuzzy Hash: dd8faada70b3f1f2db14f4a0876ca9cda89bb6854984bafce4abb2666d957345
      • Instruction Fuzzy Hash: 8421D022B0869985EA116F1EE94937D69706F84BB0F490738EB3D873D2CF3CE8408720

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd_noexit$__doserrno__lock_fhandle_errno_unlock_fhandle
      • String ID:
      • API String ID: 2464146582-0
      • Opcode ID: 5fcd879006f93b5fe29c795d0880f50e6eebd262978a8f42948adc3209e56eb7
      • Instruction ID: 2f2cc29a256b185e9b159dd30109959c366cae7b7dfa8046a040c324176340a3
      • Opcode Fuzzy Hash: 5fcd879006f93b5fe29c795d0880f50e6eebd262978a8f42948adc3209e56eb7
      • Instruction Fuzzy Hash: 8321CF22A0899646E7116F2DD94937D69706F81BA0F454538EB2D877E2CF7CE8418760

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd_noexit$__doserrno__lock_fhandle_close_nolock_errno_unlock_fhandle
      • String ID:
      • API String ID: 2140805544-0
      • Opcode ID: f87f21952b45cb965ec34267ab40e2fd4b9299d68018c2f6f6fc69f248886a23
      • Instruction ID: df391b199be703fbf7ea850c8554a3083ba737c98b1ddaba962476a867514f94
      • Opcode Fuzzy Hash: f87f21952b45cb965ec34267ab40e2fd4b9299d68018c2f6f6fc69f248886a23
      • Instruction Fuzzy Hash: A111EE72A0C68A46F7156F2DEAAD27C2A70AF81761F590638DB1DC72D3DF7CA8408750

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1114 7ff6b9ca3a00-7ff6b9ca3a42 1115 7ff6b9ca3a70-7ff6b9ca3a78 1114->1115 1116 7ff6b9ca3a44-7ff6b9ca3a52 1114->1116 1118 7ff6b9ca3a83-7ff6b9ca3a91 1115->1118 1119 7ff6b9ca3a7a-7ff6b9ca3a7e 1115->1119 1116->1115 1117 7ff6b9ca3a54-7ff6b9ca3a6b 1116->1117 1120 7ff6b9ca3cca-7ff6b9ca3cf2 call 7ff6b9cb4a30 1117->1120 1121 7ff6b9ca3a93-7ff6b9ca3aab 1118->1121 1122 7ff6b9ca3aad-7ff6b9ca3ab2 1118->1122 1119->1120 1121->1122 1123 7ff6b9ca3ab4-7ff6b9ca3abb call 7ff6b9cb6738 1122->1123 1124 7ff6b9ca3ad6-7ff6b9ca3af5 call 7ff6b9cb6738 1122->1124 1129 7ff6b9ca3ac0-7ff6b9ca3ac3 1123->1129 1133 7ff6b9ca3af9-7ff6b9ca3aff 1124->1133 1131 7ff6b9ca3ac5-7ff6b9ca3ac8 1129->1131 1132 7ff6b9ca3acd-7ff6b9ca3ad1 1129->1132 1134 7ff6b9ca3cc8 1131->1134 1132->1134 1135 7ff6b9ca3b05-7ff6b9ca3b13 1133->1135 1136 7ff6b9ca3cb8-7ff6b9ca3cbd 1133->1136 1134->1120 1137 7ff6b9ca3b19-7ff6b9ca3b21 1135->1137 1138 7ff6b9ca3cab-7ff6b9ca3cb7 call 7ff6b9cb0700 1135->1138 1136->1134 1139 7ff6b9ca3cbf-7ff6b9ca3cc3 call 7ff6b9cb72d8 1136->1139 1140 7ff6b9ca3c9e-7ff6b9ca3caa call 7ff6b9cb0700 1137->1140 1141 7ff6b9ca3b27-7ff6b9ca3b2e 1137->1141 1138->1136 1139->1134 1140->1138 1145 7ff6b9ca3b41-7ff6b9ca3b44 1141->1145 1146 7ff6b9ca3b30-7ff6b9ca3b3f call 7ff6b9ca8510 1141->1146 1150 7ff6b9ca3b66-7ff6b9ca3b91 1145->1150 1151 7ff6b9ca3b46-7ff6b9ca3b57 1145->1151 1153 7ff6b9ca3b59-7ff6b9ca3b64 1146->1153 1154 7ff6b9ca3b95-7ff6b9ca3be5 1150->1154 1151->1153 1153->1150 1153->1154 1154->1136 1156 7ff6b9ca3beb-7ff6b9ca3bee 1154->1156 1157 7ff6b9ca3bf0-7ff6b9ca3bf3 1156->1157 1158 7ff6b9ca3c02-7ff6b9ca3c0e 1156->1158 1157->1136 1161 7ff6b9ca3bf9-7ff6b9ca3bfe 1157->1161 1159 7ff6b9ca3c10-7ff6b9ca3c27 call 7ff6b9ca10e0 1158->1159 1160 7ff6b9ca3c62-7ff6b9ca3c7a 1158->1160 1167 7ff6b9ca3c2c-7ff6b9ca3c38 call 7ff6b9cb6738 1159->1167 1163 7ff6b9ca3c5c-7ff6b9ca3c60 1160->1163 1164 7ff6b9ca3c7c 1160->1164 1165 7ff6b9ca3c00 1161->1165 1166 7ff6b9ca3c3d-7ff6b9ca3c57 call 7ff6b9cb74b0 1161->1166 1163->1136 1169 7ff6b9ca3c80-7ff6b9ca3c96 call 7ff6b9cb61b0 1164->1169 1165->1167 1166->1163 1167->1133 1169->1163 1174 7ff6b9ca3c98-7ff6b9ca3c9c 1169->1174 1174->1169
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: fgetc
      • String ID: string too long
      • API String ID: 2807381905-2556327735
      • Opcode ID: 1a938cfd65599276fb3aadb580e9b2d1027a9da448c82545d8171305ed1fd370
      • Instruction ID: 58f08a271ad2132f495dd7a451774aac217621644b8c937649c5e558cafd0987
      • Opcode Fuzzy Hash: 1a938cfd65599276fb3aadb580e9b2d1027a9da448c82545d8171305ed1fd370
      • Instruction Fuzzy Hash: 1B912732705A41DAEB148F69C4A42AC73B4FB44B68F450732EB2D93BD9DF39D9648310

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Mtx_destroy$CleanupIos_base_dtorstd::ios_base::_
      • String ID: 1.0.0
      • API String ID: 4003963943-322658870
      • Opcode ID: e2633af78b420bc41f454823a79be59aadfea9a2133544200fed54a12148376b
      • Instruction ID: 67430e67c5fca83d610ce5d3caf2eeaa5649916a8a33fa67d7cfb0866cdccad7
      • Opcode Fuzzy Hash: e2633af78b420bc41f454823a79be59aadfea9a2133544200fed54a12148376b
      • Instruction Fuzzy Hash: 3E513822A1DAA681F710DF1AE8883797772FB86394F901234DB5D836E6CF3DE4448704

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1214 7ff6b9ca35e0-7ff6b9ca361d 1215 7ff6b9ca361f-7ff6b9ca3621 1214->1215 1216 7ff6b9ca3626-7ff6b9ca3630 1214->1216 1219 7ff6b9ca38b3-7ff6b9ca38da call 7ff6b9cb4a30 1215->1219 1217 7ff6b9ca3661-7ff6b9ca3669 1216->1217 1218 7ff6b9ca3632-7ff6b9ca3640 1216->1218 1222 7ff6b9ca3674-7ff6b9ca3682 1217->1222 1223 7ff6b9ca366b-7ff6b9ca366f 1217->1223 1218->1217 1220 7ff6b9ca3642-7ff6b9ca365c 1218->1220 1220->1219 1225 7ff6b9ca369e-7ff6b9ca36a3 1222->1225 1226 7ff6b9ca3684-7ff6b9ca369c 1222->1226 1223->1219 1227 7ff6b9ca36a5-7ff6b9ca36b0 call 7ff6b9cb4a50 1225->1227 1228 7ff6b9ca36c4-7ff6b9ca36f6 1225->1228 1226->1225 1231 7ff6b9ca36b5-7ff6b9ca36bf 1227->1231 1230 7ff6b9ca36f9-7ff6b9ca36fd 1228->1230 1232 7ff6b9ca3701-7ff6b9ca3752 1230->1232 1233 7ff6b9ca38b1 1231->1233 1235 7ff6b9ca389e 1232->1235 1236 7ff6b9ca3758-7ff6b9ca375b 1232->1236 1233->1219 1239 7ff6b9ca38a2-7ff6b9ca38a6 1235->1239 1237 7ff6b9ca3761-7ff6b9ca377c 1236->1237 1238 7ff6b9ca3882-7ff6b9ca3885 1236->1238 1240 7ff6b9ca377e-7ff6b9ca37a5 call 7ff6b9cb76c8 1237->1240 1241 7ff6b9ca37ab-7ff6b9ca37ba 1237->1241 1238->1235 1242 7ff6b9ca3887-7ff6b9ca389a call 7ff6b9cb4a50 1238->1242 1239->1233 1243 7ff6b9ca38a8-7ff6b9ca38ac call 7ff6b9cb72d8 1239->1243 1240->1239 1240->1241 1245 7ff6b9ca37c0-7ff6b9ca37c7 1241->1245 1246 7ff6b9ca387d-7ff6b9ca3880 1241->1246 1242->1235 1243->1233 1245->1232 1250 7ff6b9ca37cd-7ff6b9ca37d1 1245->1250 1246->1239 1250->1239 1252 7ff6b9ca37d7-7ff6b9ca37e1 1250->1252 1253 7ff6b9ca3870-7ff6b9ca387c call 7ff6b9cb0700 1252->1253 1254 7ff6b9ca37e7-7ff6b9ca37ef 1252->1254 1253->1246 1256 7ff6b9ca37f1-7ff6b9ca37f4 1254->1256 1257 7ff6b9ca3863-7ff6b9ca386f call 7ff6b9cb0700 1254->1257 1260 7ff6b9ca380f-7ff6b9ca3812 1256->1260 1261 7ff6b9ca37f6-7ff6b9ca3830 call 7ff6b9ca8510 1256->1261 1257->1253 1264 7ff6b9ca3814-7ff6b9ca3828 1260->1264 1265 7ff6b9ca3836-7ff6b9ca385e 1260->1265 1261->1232 1261->1265 1264->1230 1265->1230
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID:
      • String ID: string too long
      • API String ID: 0-2556327735
      • Opcode ID: 70e423f66ee6790fe538ff7c039c66202f1dfd9db47b5ea2ea59a5846aeafa6a
      • Instruction ID: a36a90799534d835ff8d32262dd04c7aa880c6518506c8b95b142b0594ee78c1
      • Opcode Fuzzy Hash: 70e423f66ee6790fe538ff7c039c66202f1dfd9db47b5ea2ea59a5846aeafa6a
      • Instruction Fuzzy Hash: 82916D72B18A819AEB148F69D4642EC37B1F7047A8F904636EB2D97BD8DF38D564C340

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1268 7ff6b9cb0974 1270 7ff6b9cb08ae-7ff6b9cb08b1 1268->1270 1271 7ff6b9cb08ab 1268->1271 1272 7ff6b9cb08b3 1270->1272 1273 7ff6b9cb08b6-7ff6b9cb08c8 1270->1273 1271->1270 1272->1273 1274 7ff6b9cb08cb-7ff6b9cb08cd 1273->1274 1275 7ff6b9cb08e0-7ff6b9cb08ec 1274->1275 1276 7ff6b9cb08cf-7ff6b9cb08de 1274->1276 1277 7ff6b9cb08ee-7ff6b9cb08f0 1275->1277 1278 7ff6b9cb08f2-7ff6b9cb08f5 1275->1278 1276->1274 1276->1275 1279 7ff6b9cb0956-7ff6b9cb0970 1277->1279 1280 7ff6b9cb08f7-7ff6b9cb08fa 1278->1280 1281 7ff6b9cb091d-7ff6b9cb0936 call 7ff6b9cb6c44 1278->1281 1280->1281 1283 7ff6b9cb08fc-7ff6b9cb0911 call 7ff6b9cb6c44 1280->1283 1281->1277 1286 7ff6b9cb0938-7ff6b9cb093a 1281->1286 1283->1281 1290 7ff6b9cb0913 1283->1290 1288 7ff6b9cb0953 1286->1288 1289 7ff6b9cb093c-7ff6b9cb0945 call 7ff6b9cba908 1286->1289 1288->1279 1293 7ff6b9cb094a-7ff6b9cb094c 1289->1293 1292 7ff6b9cb0916-7ff6b9cb091b call 7ff6b9cb7b50 1290->1292 1292->1277 1293->1288 1295 7ff6b9cb094e-7ff6b9cb0951 1293->1295 1295->1292
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _fsopen$fclosefseek
      • String ID:
      • API String ID: 410343947-0
      • Opcode ID: 264fa5cf69113298d8e32d3fe2f0c6501ea07c7103afaa3aed354072517c642a
      • Instruction ID: 06f8222b34e077698df6b0685b1121a423b60624b3d50e3166a02814d3c7ca36
      • Opcode Fuzzy Hash: 264fa5cf69113298d8e32d3fe2f0c6501ea07c7103afaa3aed354072517c642a
      • Instruction Fuzzy Hash: A921B421F1960A85FAA8CE0ED49977932B1EF46B84F188134CF4DC7B99DF2EE9418740

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Resource$Concurrency::details::ManagerManager::$SpinWait
      • String ID:
      • API String ID: 2068395708-0
      • Opcode ID: b6795b7f52903b4d6eb5cbc4091ac2d6def441bb89f3e22c6d367937602bf315
      • Instruction ID: bb465e6799f3e04d8047ffc27ebd7eb03af234562de1ad490581a3357ab74344
      • Opcode Fuzzy Hash: b6795b7f52903b4d6eb5cbc4091ac2d6def441bb89f3e22c6d367937602bf315
      • Instruction Fuzzy Hash: 93213921B09A4385EB91DF6AE4582796AB4DF49750F284138DB4ECB3E1EF3CF4448B90

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Mtx_init$calloc
      • String ID:
      • API String ID: 2545118020-0
      • Opcode ID: f828f983e790094a28bbb2a708ea9e09a06a1c05030c6f23811644e6675f23a9
      • Instruction ID: 450e60b68164f596bee30ecf224069f24b7b5a35b54512e0f7755f96487971ef
      • Opcode Fuzzy Hash: f828f983e790094a28bbb2a708ea9e09a06a1c05030c6f23811644e6675f23a9
      • Instruction Fuzzy Hash: C921A522F0DA7285F750DF6AA89937436B6AF1B304F440638C74DC72A6EF7CA0449329

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1348 7ff6b9ca3d00-7ff6b9ca3d2c 1349 7ff6b9ca3d3e-7ff6b9ca3d46 1348->1349 1350 7ff6b9ca3d2e-7ff6b9ca3d32 1348->1350 1351 7ff6b9ca3dbf-7ff6b9ca3dcb 1349->1351 1352 7ff6b9ca3d48-7ff6b9ca3d4f call 7ff6b9ca6010 1349->1352 1350->1349 1353 7ff6b9ca3d34-7ff6b9ca3d39 1350->1353 1354 7ff6b9ca3dcf-7ff6b9ca3de7 1351->1354 1352->1351 1358 7ff6b9ca3d51-7ff6b9ca3d54 1352->1358 1353->1349 1356 7ff6b9ca3d3b 1353->1356 1356->1349 1359 7ff6b9ca3d56-7ff6b9ca3d59 1358->1359 1360 7ff6b9ca3d5b-7ff6b9ca3d68 call 7ff6b9cb625c 1358->1360 1359->1360 1361 7ff6b9ca3d71-7ff6b9ca3d7d call 7ff6b9cb6210 1359->1361 1363 7ff6b9ca3d6d-7ff6b9ca3d6f 1360->1363 1365 7ff6b9ca3d82-7ff6b9ca3d84 1361->1365 1363->1351 1363->1361 1365->1351 1366 7ff6b9ca3d86-7ff6b9ca3d8d 1365->1366 1367 7ff6b9ca3d8f-7ff6b9ca3da7 1366->1367 1368 7ff6b9ca3da9-7ff6b9ca3dbd 1366->1368 1367->1368 1368->1354
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _fseeki64fgetpos
      • String ID:
      • API String ID: 3401907645-0
      • Opcode ID: 2d07afbde344102b07baddbf295aeba4b69dc366d2f8b588f6cf9893c080d52c
      • Instruction ID: 2dd3310c387dc60e83e02ddceecdf8a5a81baf3f1e49d7d5b390ab4881bc9e05
      • Opcode Fuzzy Hash: 2d07afbde344102b07baddbf295aeba4b69dc366d2f8b588f6cf9893c080d52c
      • Instruction Fuzzy Hash: 95210632A18B45C6EB55AF2AE55836973B4FB48B84F144032DF4CC7769DF38E8A68300
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Ios_base_dtorstd::ios_base::_
      • String ID:
      • API String ID: 323602529-0
      • Opcode ID: 9b44925c02c2e88953423d10a3ad63bf04538ca92b4ab34bcf1bfa73036b6fc8
      • Instruction ID: 7bb0f1caed98d05d6426d3e959614a4e33b53b0f46dfea44835c3def9557a2bb
      • Opcode Fuzzy Hash: 9b44925c02c2e88953423d10a3ad63bf04538ca92b4ab34bcf1bfa73036b6fc8
      • Instruction Fuzzy Hash: 8B915D32604B8185EB24DF69E8883BD37B5F741798F504035EB5D87A99DF39D585C340
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Xbad_allocstd::_
      • String ID:
      • API String ID: 3176948561-0
      • Opcode ID: b25b15a0a6981202789ae43a53349b1dbe77c2363a8764ac63b19ae5d2016aa1
      • Instruction ID: d6f1d9cc3909fd2f59b87d91e23ffdb1d7e455bb7b070c5cd4fd6709bc493d86
      • Opcode Fuzzy Hash: b25b15a0a6981202789ae43a53349b1dbe77c2363a8764ac63b19ae5d2016aa1
      • Instruction Fuzzy Hash: 5A219E71A09B4642FA249F6D994817866B0AB11BF4F508730DF3D57ADDDF3CD8428344
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: fclose
      • String ID:
      • API String ID: 3125558077-0
      • Opcode ID: 5a875a415c49c9c20a898516846b72c16f7ad0147206709a1b9ba25a693ae870
      • Instruction ID: ba61d7fd9643b6c499ef13b463d03698a3803ee4e73590b99e6b574f2a8a7edd
      • Opcode Fuzzy Hash: 5a875a415c49c9c20a898516846b72c16f7ad0147206709a1b9ba25a693ae870
      • Instruction Fuzzy Hash: 9621DF32605B8085DB018F39E59039D73B8FB98F88F548126CB8D87768DF39C896C790
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Startup
      • String ID:
      • API String ID: 724789610-0
      • Opcode ID: d796a6bf9521cb0195dfca69093e4acaf78ed48d890644789f0a43a6fc02fca1
      • Instruction ID: d6497eaf9b9e0663de67ce1f30d5c70413984cce01e90cdb6a6006e318d42a4d
      • Opcode Fuzzy Hash: d796a6bf9521cb0195dfca69093e4acaf78ed48d890644789f0a43a6fc02fca1
      • Instruction Fuzzy Hash: DD011D39F1DA6686FB94DF19A5A53B533B1FB9A344F801135CA0DC7341EE2CD4018A40
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Mtx_unlock
      • String ID:
      • API String ID: 1418687624-0
      • Opcode ID: d06215beca06562395e28bd098bf8e419738607fef14e18969a7b4fe457cafd1
      • Instruction ID: c5446e08682a441c975cac0df73ff608b00d79addc643eeba7956acfcd3f0051
      • Opcode Fuzzy Hash: d06215beca06562395e28bd098bf8e419738607fef14e18969a7b4fe457cafd1
      • Instruction Fuzzy Hash: F3F01512F0C64682FB55AF6EA5DA0BD21B26F8D354F845535E70DD7287EF2CE8858310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _callnewh_errno$AllocHeapmalloc
      • String ID:
      • API String ID: 3727741168-0
      • Opcode ID: 6e648e51d8c46801f16917810c9e2fad3662a4875bcee400e5c3c3c9bf6f3398
      • Instruction ID: f86c0dff3502862a705e0cc4d5349178e96122a1fdd97febc4a9c110f24f9617
      • Opcode Fuzzy Hash: 6e648e51d8c46801f16917810c9e2fad3662a4875bcee400e5c3c3c9bf6f3398
      • Instruction Fuzzy Hash: 9AB01281E0630751FC051A15500513430710F44341C0C0834CF0E407C35F1C68914010
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Time_time64$FileSystemrand
      • String ID: (e: $ (permanent activation!)$ and initializing lastActivationTimestamp$ bytes received$ days$ days (currently $ days ago, grace period of $ days ago, so starting new grace period of $ days is over, so successfuly online check is immediately necessary$ days) - activation step #$ days, enforcing activation$ days, so no further online check is necessary at the moment$#OFF$&device_id=$&lic=$&mode=$&p=$': $), so invalidating local license$, 'error_code' = $, 'license_status' = $, lastActivationTry: $//ipa$1.0.0$1.0.0|||||$20241006$BTA$ESB$FLT$FSU$Invalid response from server for deactivation$Invalidating local license$Next required successful online activation check in $Online check disabled - return$Online check end$Online check return code of web request: $Online check send data for '$Online check start: lastActivation: $Product has been successfully activated before and is still in allowed period of $Product has been successfully activated before, but more than $Product has been successfully activated more than 4 times - skipping online check in future$Product has been successfully activated within the last $Product has not been activated, but online check already done today$Product has not been activated, doing online check$Product is over the initial grace period of $Product needs activation, as it it over the activation interval of $Product requires an immediate successful online activation!$Received a valid response from the server, 'status' = 'error', 'code' = $Received a valid response from the server, 'status' = 'ok', 'code' = $SUB$Server did not respond or came back with an invalid response$Server did not respond or came back with an invalid response, but activation is enforced, so invalidating local license$Server response: $Server says deactivation successful$Server says license is expired (L$Server says license is invalid (E$Server says license is invalid (L$Server says license is over activation limit (L$Server says license is valid$Server says missing device ID (E$Server says payload is invalid (E$Server says record not found (E$Server says subscription is invalid (L$Server sent device_id $TLC$Trigger for $Updating local license (lastActivationTryTimestamp and lastActivationTimestamp) with $Updating local license (lastActivationTryTimestamp only) with $Updating local license (lastActivationTryTimestamp) with $Using online check URL: $WARNING: Server response is not encrypted - tolerated for now, but should be changed to an ecrypted text!$WARNING: no local device ID found to send to server for deactivation!$_status:$activate$activation of this product$aescripts$aescripts-license-fw/$c$code:$com/api/$deactivate$doOnlineCheck start, mode $doOnlineCheck: invalid license (trial license), skipping online check$doOnlineCheck: invalid license, skipping online check$doOnlineCheck: license type not suited for online check (FLT/FSU/BTA/#OFF), skipping online check$doOnlineCheck: product is permanently activated - skipping online check$error:$error_code:$id:$license$p$ps:$result:$sending device ID $t$v1/$|a:$|a:1$|d:$|o:
      • API String ID: 2872900303-3171066617
      • Opcode ID: cde1f9f71d052a22059f2b192bdd61bd95ecc560b8be3e69d30f7cb304b23565
      • Instruction ID: 209d80211ac1a9d1942d681fe06a8e7cf9eb26295beda45eb7c68b2e262012bf
      • Opcode Fuzzy Hash: cde1f9f71d052a22059f2b192bdd61bd95ecc560b8be3e69d30f7cb304b23565
      • Instruction Fuzzy Hash: 37339231A0CAC691EA60EF18E8993FA6771EB81394F805235D74DC7AEADF2CD549C740
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: AddressConcurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionHandleLastModuleProcThrow
      • String ID: CreateRemoteThreadEx$CreateUmsCompletionList$CreateUmsThreadContext$DeleteProcThreadAttributeList$DeleteUmsCompletionList$DeleteUmsThreadContext$DequeueUmsCompletionListItems$EnterUmsSchedulingMode$ExecuteUmsThread$GetCurrentUmsThread$GetNextUmsListItem$GetUmsCompletionListEvent$InitializeProcThreadAttributeList$QueryUmsThreadInformation$SetUmsThreadInformation$UmsThreadYield$UpdateProcThreadAttribute$kernel32.dll
      • API String ID: 1942842289-2643937717
      • Opcode ID: 2beddd28d9a71738a41f93e85f78c5167e4941fd89a7b66c7690ebcdfcd8415d
      • Instruction ID: fe73f574a94d9899fdf8bd99d800450c867530e9db2b164022deddfa8c521738
      • Opcode Fuzzy Hash: 2beddd28d9a71738a41f93e85f78c5167e4941fd89a7b66c7690ebcdfcd8415d
      • Instruction Fuzzy Hash: 99022921E09A5785FF04EF6AA91C2B822F1BF89788F849535D60DC7295EF3DE109C394
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: AttributesFile
      • String ID: (limited license period from $ to $-$-content$1.0.0$DATA*$ESB$FILE*$FLT$FSU$SUB$WARNING: invalid machine ID - there was a problem reading your network adapter data!$_RENDER_ONLY$a_next: $a_succ: $a_try: $content$first name: '$invalid$last name: '$license end: '$license start: '$license type: '$loading license directly (*$local license deactivated$number of user licenses: $product ID: '$product version: '$remote license lease dropped$result: $serial: '$status: $status: floating licenses can only be used with the floating license server$t$valid$writing new license to file$ $-$:$D$J$S$l$
      • API String ID: 3188754299-916615497
      • Opcode ID: 23220f13062f759fb2fd56c97aef39f2f3706d3a5e1f4664fef1b26a48c8f5ea
      • Instruction ID: 6a86566d32edfda3387f2f49af7eed8e232f2230f7cdbb70d1afce663995eb9f
      • Opcode Fuzzy Hash: 23220f13062f759fb2fd56c97aef39f2f3706d3a5e1f4664fef1b26a48c8f5ea
      • Instruction Fuzzy Hash: 96923361A5998694EB61EF28DC593F92370EF55388F805432D70EDB6AEEF2CD608C344
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Internet$Http$CloseHandleOption$InfoOpenQueryRequest$ConnectErrorFileLastReadSend
      • String ID: Content-Type$Content-Type: application/x-www-form-urlencoded$GET$Mozilla/5.0 (Compatible)$POST$http://$https://$t
      • API String ID: 1486255883-1336110008
      • Opcode ID: ba58e2f75b416f112594b53a6ae6878838e6ba7699d92f3cd6147f220f0cb922
      • Instruction ID: 78aa6e60e642319ff34d727dcc44a3819b472010d845ae8bbed50e030d7812c1
      • Opcode Fuzzy Hash: ba58e2f75b416f112594b53a6ae6878838e6ba7699d92f3cd6147f220f0cb922
      • Instruction Fuzzy Hash: FA82F63261CAC681EB319F29E4987EAA3B1FB85744F804135D78D87A9ADF7DD548CB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _errnowrite_multi_charwrite_string$Locale_invalid_parameter_noinfowrite_char$UpdateUpdate::___updatetlocinfo__updatetmbcinfo_fileno_getptd_getptd_noexit_isleadbyte_lfree
      • String ID: $@
      • API String ID: 3318157856-1077428164
      • Opcode ID: 88c9b5e4abb27927cb064ca53120f5ed29995979e43e2f8379dfcc59aa9e6c90
      • Instruction ID: d63625c10d67fbf16f2a1046c03dfcd5ff4f6ab7fb29b6bc9549d2f07c0b802f
      • Opcode Fuzzy Hash: 88c9b5e4abb27927cb064ca53120f5ed29995979e43e2f8379dfcc59aa9e6c90
      • Instruction Fuzzy Hash: C752D062ACC68686FB6C8E5D954C37E6AB1BF81784F14A135DB4E867D4DF3CE9408B00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _errnowrite_multi_charwrite_string$Locale_invalid_parameter_noinfowrite_char$UpdateUpdate::___updatetlocinfo__updatetmbcinfo_fileno_getptd_getptd_noexit_isleadbyte_lfree
      • String ID: $%li.%li.%li.%li
      • API String ID: 3318157856-2495504251
      • Opcode ID: 53a93e026cdb33f0ba4079394c99ec866ed19bb3243859ba2758b9384a7bb7d4
      • Instruction ID: a90092102fb5a956d69a41f2162fa80b44496f7ab700b529e1b652468a8ded9a
      • Opcode Fuzzy Hash: 53a93e026cdb33f0ba4079394c99ec866ed19bb3243859ba2758b9384a7bb7d4
      • Instruction Fuzzy Hash: 47529962A0C69A86FB648F5D94482BE7FB0BF45B84F641035DB4E87695DF3CE8408B81
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: File$Time_time64$rand$AttributesIos_base_dtorSystemstd::ios_base::_$CloseCreateFolderHandlePathSleepXbad_allocstd::_
      • String ID: gfff$string too long
      • API String ID: 438800184-2250279893
      • Opcode ID: f48570b9438044147d6169b71e2f6c8697e3a89a47b065e7cdbbb993b120ddd2
      • Instruction ID: 1da321cd4495f9aa3bab1f3b3c265f34c5cffe647424b5ce7e30cbbc92aff34f
      • Opcode Fuzzy Hash: f48570b9438044147d6169b71e2f6c8697e3a89a47b065e7cdbbb993b120ddd2
      • Instruction Fuzzy Hash: 34526E32615AC299EB749F38C8983FD2371EB45758F804236DB5D8AAEADF78D645C300
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _errno$_time64
      • String ID: bytes to file $0$@REMOTE$FAIL ($FLT$FSU$new license data: $new license data: trial license$writing $l$(b$Ub
      • API String ID: 318442946-2718888663
      • Opcode ID: 739bf9cde98539b27dd7aab6cdb8468f82ea2c960eaeb0d63c31873315eaf0dc
      • Instruction ID: b4f24548d90bfb7e96b763601c664bc031be4d46f88b3b0656106d1f542fe9fb
      • Opcode Fuzzy Hash: 739bf9cde98539b27dd7aab6cdb8468f82ea2c960eaeb0d63c31873315eaf0dc
      • Instruction Fuzzy Hash: E4426E62A1DAC691EB31DF18E4593EEA771FB81788F805131D78D87AAADF2CD544CB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Time_time64$FileSystem_getptdrand
      • String ID: 1.0.0$@REMOTE$FLT$FLT$FSU$_RENDER_ONLY$gfff$gfff
      • API String ID: 2056829080-791714639
      • Opcode ID: fb20300fa841780d844b4cdcaf53c710758ea8605ded05741403712cfa48ef4a
      • Instruction ID: 5d0bfa8a0352dffe65717783544ea6468be5bdce2e0e9605c4772674aa520f0c
      • Opcode Fuzzy Hash: fb20300fa841780d844b4cdcaf53c710758ea8605ded05741403712cfa48ef4a
      • Instruction Fuzzy Hash: 17B22A2251CAC681EB719F28E4587EAB771EB81384F504135DB8D86AEBDF7CD489CB01
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID:
      • String ID: *****$000000000000$@REMOTE$DATA*$LICS*$TLC$_RENDER_ONLY$acde48001122$license data: $no matching machine ID found!$trial license found (no valid license data)$|a:$|d:$|o:
      • API String ID: 0-3095003553
      • Opcode ID: de3f80668324199a0d3f2da254c2847f7feaa850a721e293a55ce2a3d2de6680
      • Instruction ID: 658c30bb272d43e6fcd31add3e348e0e969feff248ce1771eae07439033ca5cd
      • Opcode Fuzzy Hash: de3f80668324199a0d3f2da254c2847f7feaa850a721e293a55ce2a3d2de6680
      • Instruction Fuzzy Hash: 1C03602261D6C695EB319F28E4983FAA771FB95788F805132D78D87A9BDF2CD504CB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: remove$FolderPath_errno_invalid_parameter_noinfo_wgetenv
      • String ID: 27100$</string>$<key>$LicensingBackupServer_Address$LicensingBackupServer_Port$LicensingServer_Address$LicensingServer_Port$aescriptsLicensingServer
      • API String ID: 2317211808-1479187049
      • Opcode ID: 411b386f009fd4ea07bcd56b4c65bfa66c3fa2465820cf6a174a641641dffbc7
      • Instruction ID: 800fffda549bd81e70535f6ceff215f541e79aa31bb1e6d7d6c96e002eefe7f6
      • Opcode Fuzzy Hash: 411b386f009fd4ea07bcd56b4c65bfa66c3fa2465820cf6a174a641641dffbc7
      • Instruction Fuzzy Hash: 18726E22608B8689FB11DF69D4983ED3B71FB81388F504035EB4D9BA9ADF39D589C740
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: free$AdaptersInfomalloc$sprintf
      • String ID: %li.%li.%li.%li
      • API String ID: 3176089250-1731176481
      • Opcode ID: d10cdf357ab2bc3959a5a3fc129a597d6f23535822cbe3174e1f630efbb2aa6d
      • Instruction ID: bfe084ac9eada76ae6833f677a45fa62efd62138f05828340735258b5d687b1a
      • Opcode Fuzzy Hash: d10cdf357ab2bc3959a5a3fc129a597d6f23535822cbe3174e1f630efbb2aa6d
      • Instruction Fuzzy Hash: E6125A32A18A9589EB14CF68E8883BD3BB1FB45798F540235EB5E97AD9DF38D444C340
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: FormatMessagefreeaddrinfogetaddrinfogethostnameinet_ntop
      • String ID: .local$.localdomain$getaddrinfo error
      • API String ID: 1835220482-1587782278
      • Opcode ID: 0d3869f166b1bdac87fcd9c7cadc5d42e38a32cd38cc797aa963cfdd30f5da21
      • Instruction ID: 9e654c14f36304d95d7216a0c2991abe28938f3402f44d85aea910713ff71f24
      • Opcode Fuzzy Hash: 0d3869f166b1bdac87fcd9c7cadc5d42e38a32cd38cc797aa963cfdd30f5da21
      • Instruction Fuzzy Hash: 01025932A18A928AEB00DF79E8883AD37B1FB41798F501235EB5D97AD9DF78D544C340
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _time64
      • String ID: 1.0.0$@REMOTE$FLT$TLC$_RENDER_ONLY$K
      • API String ID: 1670930206-2998733053
      • Opcode ID: 6a2d34c6ceb55a6fa653833b9ca4c061a6abb3f4207e8aff040eca89f61d54ab
      • Instruction ID: e5c1d197cd039864183148f0a40c01d159a27eb06e4a3f185ce86aca2530813a
      • Opcode Fuzzy Hash: 6a2d34c6ceb55a6fa653833b9ca4c061a6abb3f4207e8aff040eca89f61d54ab
      • Instruction Fuzzy Hash: 26F13A22A18A9189FB11DF78D4483ED3BB1EB4535CF504136EB4D96ADADF78D285C340
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: closesocket$Mtx_unlockNameUserrandrecv
      • String ID: DRPL$REQL
      • API String ID: 2035232360-3605393878
      • Opcode ID: 721fc08aca532f495d05d118156107921167988e477034a3580ef18a1549f98c
      • Instruction ID: 82f4d57df18d8238510062879d6f4ff631d4b4f152eb9de55d62716bd0e18155
      • Opcode Fuzzy Hash: 721fc08aca532f495d05d118156107921167988e477034a3580ef18a1549f98c
      • Instruction Fuzzy Hash: F6A27E22A08A8289FB10DF78D8583ED3771EB41398F805535EB5D97AEADF78D685C340
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _time64$Mtx_unlock
      • String ID: 1.0.0$t~
      • API String ID: 1903240241-4207783639
      • Opcode ID: c360343a8360908138749ddabf9604666f8e131e62fd64f0da7eb135858dfb96
      • Instruction ID: ed9e9a84bff81b17901b84e75084ca847e75d19956b7cd0b474447009aa4e15b
      • Opcode Fuzzy Hash: c360343a8360908138749ddabf9604666f8e131e62fd64f0da7eb135858dfb96
      • Instruction Fuzzy Hash: B2324A3250CBC185E7719B28E4483EAB6B4EB953A4F504235D7DD86AEADF7CD588CB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _time64$Mtx_unlock
      • String ID: 1.0.0$@REMOTE$content
      • API String ID: 1903240241-4152950612
      • Opcode ID: 40e5f10e47ca47a6761a1aedc3e36bdca0f7d5396d43875c1889cb17a7612ab4
      • Instruction ID: 00377d78c896fe412818f56d61110297dc240543be74642726b20254af675c66
      • Opcode Fuzzy Hash: 40e5f10e47ca47a6761a1aedc3e36bdca0f7d5396d43875c1889cb17a7612ab4
      • Instruction Fuzzy Hash: 11324B3250CBC285E7729B28E4483EAB6B4FB953A4F504235D7AD96ADADF7CD144CB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _wcstoi64sprintf
      • String ID: 2%i
      • API String ID: 3955018481-70509047
      • Opcode ID: 5e23b37e2fdf3e6468c6f338f5f408d1b77b1317337c8013a83a54b6ab350443
      • Instruction ID: 14292722234301997401a3e7afeaad307f75a15096a09dfa2d80fa57dcbe741b
      • Opcode Fuzzy Hash: 5e23b37e2fdf3e6468c6f338f5f408d1b77b1317337c8013a83a54b6ab350443
      • Instruction Fuzzy Hash: 7FE20D22A5958699EB20EF68C8993FD2370FB91398F805531D74ED7AEEDF28D604C344
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: sprintf
      • String ID: 1%i$3194837251290356$7654321234567898
      • API String ID: 590974362-2870800511
      • Opcode ID: 3398522d3731beca5f597bdad1c4eb6b5ef9381435dd5f48417ed061d0fb1c3a
      • Instruction ID: cba43a29488b9770e9b40fc106f38e44fbb68d73c9367dc1ac54d3b293aa5be0
      • Opcode Fuzzy Hash: 3398522d3731beca5f597bdad1c4eb6b5ef9381435dd5f48417ed061d0fb1c3a
      • Instruction Fuzzy Hash: EAC23D22609A8599EB24EF78D8983ED3770FB41348F805535DB4D9BAEADF38D648C350
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Ios_base_dtor_time64std::ios_base::_$FolderPath
      • String ID:
      • API String ID: 1954716527-0
      • Opcode ID: af25f6fde421100cb7257152a915afc76279274dcf84ef90c747a9d93e43852d
      • Instruction ID: 0cb6634923efd137da43e91e6367350b69a0185b3fece599e93900d98586fd9e
      • Opcode Fuzzy Hash: af25f6fde421100cb7257152a915afc76279274dcf84ef90c747a9d93e43852d
      • Instruction Fuzzy Hash: F1F12922508AC689EB74DF38C8987ED3771EB41358F904135DB5D8AAEADF78D689C340
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: AttributesCreateDirectoryFileFolderPath
      • String ID:
      • API String ID: 1991693529-0
      • Opcode ID: 82fd2451d5227bc0dcd1215ad816a73d7755197062dc978f56ad1395053a3863
      • Instruction ID: 658adb8997841a0b201ff026e8bfac5226d4f74790fc548f1c4ec5230fb92855
      • Opcode Fuzzy Hash: 82fd2451d5227bc0dcd1215ad816a73d7755197062dc978f56ad1395053a3863
      • Instruction Fuzzy Hash: 16919022A18A9185FB149F7CE4883AD3771FB417A4F501231EB6E97ADADFB8D485C700
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID:
      • String ID: - Unknown$DATA*$FILE*
      • API String ID: 0-115703852
      • Opcode ID: e223762f1597084f296bc8fb5f4f44bad34682083b4c48ff3c19dc1f3b42985c
      • Instruction ID: cd7ffd7e1949517707e987835d734487821eeff0a47e4c44b42862682fba4553
      • Opcode Fuzzy Hash: e223762f1597084f296bc8fb5f4f44bad34682083b4c48ff3c19dc1f3b42985c
      • Instruction Fuzzy Hash: A3E12C32A196C699EB31EF38C8593ED2371EB55788F805432D74D8BA9EDF68DA45C300
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Xbad_allocrecvstd::_
      • String ID: string too long
      • API String ID: 3140412268-2556327735
      • Opcode ID: c19a0434db2db8eb3a2300d5e2e1edb1f711a82605da510c40de306e8249432c
      • Instruction ID: 877f105c9b993a4525f20c5af507d786ff8b4bb6ec466353692c44ba47e0fc45
      • Opcode Fuzzy Hash: c19a0434db2db8eb3a2300d5e2e1edb1f711a82605da510c40de306e8249432c
      • Instruction Fuzzy Hash: 1141E122A09B4282EB199F2DD59C2796671FB44BA4F401631CF6D83BE5DF3CE101C740
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ExceptionFilterUnhandled
      • String ID: csm
      • API String ID: 3192549508-1018135373
      • Opcode ID: 2447300f6ec3465ead16d629e4ce46c99b562a325acde4c5e5da852cf9bc7048
      • Instruction ID: 4b3465b6ad8cf63118b94969facd80c6faebd62595c23a85861237490894cc5a
      • Opcode Fuzzy Hash: 2447300f6ec3465ead16d629e4ce46c99b562a325acde4c5e5da852cf9bc7048
      • Instruction Fuzzy Hash: DEE06D22F18106C7DA59AE2EA48D07C2BB1EB94704FA00432C30ED3291DF6CE992CB81
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: memchr
      • String ID: 1.0.0$string too long
      • API String ID: 3297308162-3307889991
      • Opcode ID: 33dfac10b30f5bac4d1ad7bc2cfdde2bb7764896482db54e0ee1ae35160bfca3
      • Instruction ID: 4627f51f962a9c1e3ccac1f1139c1e232236755f59494b54e9aaf6867ec2b4e4
      • Opcode Fuzzy Hash: 33dfac10b30f5bac4d1ad7bc2cfdde2bb7764896482db54e0ee1ae35160bfca3
      • Instruction Fuzzy Hash: AE42AD22A18BA189FB11CF69E4883AD77B1FB41788F500532EB5E97ADADF79D144C700
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID:
      • String ID: DRPL$REQL
      • API String ID: 0-3605393878
      • Opcode ID: c9a52c2b3fbd5138a98fb996f46619709b60f3b5713481f66d8d2fef14153de3
      • Instruction ID: 72815465725f81165655f035aa38da05db399416e4c1e8ba923ec28f11aa3820
      • Opcode Fuzzy Hash: c9a52c2b3fbd5138a98fb996f46619709b60f3b5713481f66d8d2fef14153de3
      • Instruction Fuzzy Hash: 3BE11622A18BD199E7619F78E8843ED37B5F70534CF404235DB8D5BA9ADF789288D340
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: NameUser
      • String ID:
      • API String ID: 2645101109-0
      • Opcode ID: 0f98686a4b8fcfee3e556cf16876fa0a5e50784ec64797073e31495439e65b8c
      • Instruction ID: 5a5274f33bf00b76743bd752efe153938f73334bd1876736e876d26a0e2e7416
      • Opcode Fuzzy Hash: 0f98686a4b8fcfee3e556cf16876fa0a5e50784ec64797073e31495439e65b8c
      • Instruction Fuzzy Hash: 1851AF22A18A9286FB10DF78E8883ED3770EB417A8F501235DB5E97AE9CF78D145C740
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID:
      • String ID: 27100
      • API String ID: 0-2886292763
      • Opcode ID: 6e4a6d859505b2f3c07ea4f32d8960a1d868a64456b9a277e269e8e1eb1d1e88
      • Instruction ID: f3ff52a083cf9469ac30082a0022eaf47aa53c18757498aad9394a4db63773fc
      • Opcode Fuzzy Hash: 6e4a6d859505b2f3c07ea4f32d8960a1d868a64456b9a277e269e8e1eb1d1e88
      • Instruction Fuzzy Hash: 32D1DF22B1965285FB10AF69E0597BD23B1EB017A8F409630DF2E97ADADF7CE145C340
      APIs
      • EnumSystemLocalesW.KERNEL32(?,?,?,?,00007FF6B9CD42C7,?,?,00000140,00007FF6B9CD4997), ref: 00007FF6B9CBCFCD
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: EnumLocalesSystem
      • String ID:
      • API String ID: 2099609381-0
      • Opcode ID: 987e55d109183da88758b5caddb6c4ece99c384733c83da0ac54fc19a894a36d
      • Instruction ID: fa0136591b418df34eceec446ca635de6fbeea4d8abf383784c6dce80e70b8fb
      • Opcode Fuzzy Hash: 987e55d109183da88758b5caddb6c4ece99c384733c83da0ac54fc19a894a36d
      • Instruction Fuzzy Hash: AAE0B662E59A2686EB458F9EE8853202270AB5A305F405271C70DC6775CF6CA1958300
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 56002f7d27eb1eb39365d711a26b4f71e54e163b4668d0f80b23bc306ea981a8
      • Instruction ID: ad015363bf0b841af4e8986c8b9c825def1f6356c8c2d65412f4ed30bc2ba53c
      • Opcode Fuzzy Hash: 56002f7d27eb1eb39365d711a26b4f71e54e163b4668d0f80b23bc306ea981a8
      • Instruction Fuzzy Hash: 511292B7F3816057C35DCB29EC52F9A3692B7A4308749D428E706D2F08E63DFA159B44
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Ios_base_dtorstd::ios_base::_
      • String ID:
      • API String ID: 323602529-0
      • Opcode ID: 61394798c055cc122092d47e7fc80b814d525bccadcad0948e68e49d4e1d6167
      • Instruction ID: 7577d76494d14a86cbcf46b814fb5e99bfddad6089d0151621f0a1bba257d4ab
      • Opcode Fuzzy Hash: 61394798c055cc122092d47e7fc80b814d525bccadcad0948e68e49d4e1d6167
      • Instruction Fuzzy Hash: F5A1DE22A28A9186E7189F78E8493ED67B1F784348F500539EF4D9BFEADF79D4408740
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: CriticalExceptionResourceSectionThrowWaitstd::exception::exception$Concurrency::details::EnterEventLeaveManagerManager::~ObjectSingleSpin
      • String ID: pScheduler$version
      • API String ID: 699445218-3154422776
      • Opcode ID: 37124c8201fcf94d47151efbafb6cda6ec09a0aeebdb7ffeb8d655e1df7dfb0a
      • Instruction ID: fd6b613ed1636a91489b8f1a42e33036ea9711b51e8032b3abb96c66f1b57f5e
      • Opcode Fuzzy Hash: 37124c8201fcf94d47151efbafb6cda6ec09a0aeebdb7ffeb8d655e1df7dfb0a
      • Instruction Fuzzy Hash: 7441BC32A08E5682EB10DF19E4981A833B4FF45394F504232E75DC3AA4DF3CE559CB80
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID:
      • String ID: bytes to file $content$new license data: trial license$writing $(b$Ub
      • API String ID: 0-3042556935
      • Opcode ID: 9448679977c9af379fb54e091d718d9741fec6894d6337a3ccf21176fde89b46
      • Instruction ID: 13afb4317b42d9cf6dc621827df587352469713db19c3f5c672acf2a0c417e77
      • Opcode Fuzzy Hash: 9448679977c9af379fb54e091d718d9741fec6894d6337a3ccf21176fde89b46
      • Instruction Fuzzy Hash: AC123A6260CAC695EA319F28E4593EAB775FB81784F804135E78D87AABDF2CD544CB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Exception$Throw$std::exception::exception$FileHeaderRaise
      • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
      • API String ID: 4097400096-1866435925
      • Opcode ID: 20b84a5826d7b11eb14a7e140e936dd628b3824314bec0e49429d5af5ecbd604
      • Instruction ID: 4f29a169ecd71cde22443a641f4eac52727b7aa5f99f75505fea70325c438875
      • Opcode Fuzzy Hash: 20b84a5826d7b11eb14a7e140e936dd628b3824314bec0e49429d5af5ecbd604
      • Instruction Fuzzy Hash: 77513A32A09B05D9EB14DF68D8A43EC33B4EB0474CF805935EB0D96AA9DF79D219C340
      APIs
      • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FF6B9CC9043,?,?,?,?,00007FF6B9CC9779), ref: 00007FF6B9CC6083
      • malloc.LIBCMT ref: 00007FF6B9CC6090
        • Part of subcall function 00007FF6B9CB5C2C: _FF_MSGBANNER.LIBCMT ref: 00007FF6B9CB5C5C
        • Part of subcall function 00007FF6B9CB5C2C: _NMSG_WRITE.LIBCMT ref: 00007FF6B9CB5C66
        • Part of subcall function 00007FF6B9CB5C2C: HeapAlloc.KERNEL32(?,?,00000000,00007FF6B9CBAE48,?,?,?,00007FF6B9CB93C0,?,?,?,00007FF6B9CB92BF), ref: 00007FF6B9CB5C81
        • Part of subcall function 00007FF6B9CB5C2C: _callnewh.LIBCMT ref: 00007FF6B9CB5C9A
        • Part of subcall function 00007FF6B9CB5C2C: _errno.LIBCMT ref: 00007FF6B9CB5CA5
        • Part of subcall function 00007FF6B9CB5C2C: _errno.LIBCMT ref: 00007FF6B9CB5CB0
        • Part of subcall function 00007FF6B9CBC2B0: SetLastError.KERNEL32(?,?,?,?,00007FF6B9CC6083,?,?,?,?,?,?,00000000,00007FF6B9CC9043), ref: 00007FF6B9CBC2D0
      • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FF6B9CC9043,?,?,?,?,00007FF6B9CC9779), ref: 00007FF6B9CC60BA
      • Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error.LIBCMT ref: 00007FF6B9CC60D3
      • _CxxThrowException.LIBCMT ref: 00007FF6B9CC60E4
      • _CxxThrowException.LIBCMT ref: 00007FF6B9CC6123
      • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FF6B9CC9043,?,?,?,?,00007FF6B9CC9779), ref: 00007FF6B9CC6129
      • Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error.LIBCMT ref: 00007FF6B9CC6142
      • _CxxThrowException.LIBCMT ref: 00007FF6B9CC6153
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ErrorLast$ExceptionThrow$Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error_errno$AllocHeap_callnewhmalloc
      • String ID: bad allocation
      • API String ID: 1961218317-2104205924
      • Opcode ID: 0225e01ed3cd48f97f23321390d0bb6128aebccebbd389f9e5f25c7c7613fbfe
      • Instruction ID: 02131feb22920c5fedb2095a749e79c35d02305bb7981978c98c722963e31065
      • Opcode Fuzzy Hash: 0225e01ed3cd48f97f23321390d0bb6128aebccebbd389f9e5f25c7c7613fbfe
      • Instruction Fuzzy Hash: 36219222A0CA4B81EE14EF69E5591B963B1FF84388F808531E78DC769AEF3DE505C744
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Cpp_errorThrow_std::_$Mtx_unlockclosesocketsetsockoptsocket$Concurrency::critical_section::unlockfreeaddrinfogetaddrinfoinet_ntop
      • String ID:
      • API String ID: 3148495818-0
      • Opcode ID: f604289629911277989480bb5d5973037388575b7524291c876a2ebb8b5018d2
      • Instruction ID: 0f58184395843bda640957c81586ac9373a7f43aff1748efce0d9a30eee0fe41
      • Opcode Fuzzy Hash: f604289629911277989480bb5d5973037388575b7524291c876a2ebb8b5018d2
      • Instruction Fuzzy Hash: 08813B32A08A4286EB20DF29E44836D77B1FB89B68F544235DB9E876D6DF3CE444C750
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ExceptionThrowstd::exception::exception$AffinitizeConcurrency::details::FreeObjectProcessorRoot::SignalVirtualWait
      • String ID: pContext$switchState
      • API String ID: 2521916644-2660820399
      • Opcode ID: a3473efad4469623265d71763c12b7fb0313d89ce7e337f260fd642833b2ecea
      • Instruction ID: 5eb32be8c990acb49c8dd0d8cd975a8346e01a1d1fad27588e56bf2d1afb1b01
      • Opcode Fuzzy Hash: a3473efad4469623265d71763c12b7fb0313d89ce7e337f260fd642833b2ecea
      • Instruction Fuzzy Hash: 16418E72A09F4A82EE20DF1AE14926973B0FB45B88F504131DB4E97B98DF3CE146C744
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ExceptionThrow$std::bad_exception::bad_exception$Concurrency::details::CurrentExecutionProxy::ResourceSchedulerThreadValuestd::exception::exception
      • String ID: pScheduler
      • API String ID: 2546527957-923244539
      • Opcode ID: 0a92d1236b80b8fdbef8a58dc719a057624d1992e7403410bef65b88da2779f8
      • Instruction ID: 4fccf0f6b29f25a81ba213927b4dbe2ce394ac1829ff5a8667ebcf7b6ac157cd
      • Opcode Fuzzy Hash: 0a92d1236b80b8fdbef8a58dc719a057624d1992e7403410bef65b88da2779f8
      • Instruction Fuzzy Hash: 90112E62A48A4792EE20EF09E4590A96374FF88788F904531E78D87675EF7CD605C740
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _errno$BuffersErrorFileFlushLast__doserrno__lock_fhandle_getptd_noexit_unlock_fhandle
      • String ID:
      • API String ID: 2927645455-0
      • Opcode ID: a89aaae0539ade81d037064eb86fb358608727817e567aabedb7f0df4bab6221
      • Instruction ID: 8a58605ec89d448a5e99d82572862cde998905d4794df0d7c6d9152157b6eaee
      • Opcode Fuzzy Hash: a89aaae0539ade81d037064eb86fb358608727817e567aabedb7f0df4bab6221
      • Instruction Fuzzy Hash: 8321A121F08A5645EA116F6DA99827E6A70AF81760F590138DB1EC73E2CF7CF8458354
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: remove$FolderPath
      • String ID: .lic$.plist$aescripts\
      • API String ID: 2070512967-1236034080
      • Opcode ID: 50eeefc3062eecd178c5cc6e2785b66720f537c8fa5d53ec275a4f874a5f38b1
      • Instruction ID: 473e998a4636295993aad01902c28d1ee00e3ad0bef5366a17f36a87d6f145e5
      • Opcode Fuzzy Hash: 50eeefc3062eecd178c5cc6e2785b66720f537c8fa5d53ec275a4f874a5f38b1
      • Instruction Fuzzy Hash: 6081522261CAC581EB10DF19E4593AAB771FB827A4F901231E7AD83AEACF7DD544C700
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ExceptionThrow$std::bad_exception::bad_exception$std::exception::exception
      • String ID: pContext
      • API String ID: 3610078031-2046700901
      • Opcode ID: 1a10e65e9c3be4f5ef1747115894c9c672c718e4b042ef2fd29cfcd7c0986a62
      • Instruction ID: 278ef574d40c3e01e8e8941937126669cf24e2357f0f800c0030365072e25f40
      • Opcode Fuzzy Hash: 1a10e65e9c3be4f5ef1747115894c9c672c718e4b042ef2fd29cfcd7c0986a62
      • Instruction Fuzzy Hash: 9711BF62A18A4B81EE10EF08E4691B96370FF84788F904431EB5EC76A5EF3CE149C744
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: free$Sleep_malloc_crtmalloc
      • String ID:
      • API String ID: 2523592665-0
      • Opcode ID: d538ba41b055fb1f9364d438104dd17988e7f216bec028accaf4dd629781d306
      • Instruction ID: b9e597990c7bf58fda6296d93ec7acae59e2ecde95371497f10066e2c7c3e501
      • Opcode Fuzzy Hash: d538ba41b055fb1f9364d438104dd17988e7f216bec028accaf4dd629781d306
      • Instruction Fuzzy Hash: 28619F22B09B4293EB119F1BE98526A77B0FB84B98F448135DF4D93B51DF3CE5668380
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: CriticalSection$_lock$CountEnterInitializeLeaveSpin__lock_fhandle_calloc_crt_mtinitlocknum
      • String ID:
      • API String ID: 854778215-0
      • Opcode ID: 08545cbb6868adf57ace4d267df997acc697e57f35bf43482b42d38d8ee1e828
      • Instruction ID: 4a52e5b8aa8afd304836f7d0c813601f9494fc7b2abf7f5b3fd2478e6699664f
      • Opcode Fuzzy Hash: 08545cbb6868adf57ace4d267df997acc697e57f35bf43482b42d38d8ee1e828
      • Instruction Fuzzy Hash: EF51BB22A98B8582EB208F28D948239B7B5FF84B98F554535DB4D877E9CF3CE841C705
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Thread$Concurrency::details::Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorCreateErrorExceptionLastLibraryLoadThrow$PriorityReference
      • String ID:
      • API String ID: 2237552173-0
      • Opcode ID: 0cb42799f0be884d7e1ea55998eca801c8cc529737faef5f85796a878d6bb837
      • Instruction ID: dd1abe19acc753f77c0dfb3945933b7325ee24b41eec754c654ab1248ca5b11f
      • Opcode Fuzzy Hash: 0cb42799f0be884d7e1ea55998eca801c8cc529737faef5f85796a878d6bb837
      • Instruction Fuzzy Hash: C911A121A18A4782FB00EF29E9183BA22B1FF88744F544531E74DC6699EF3CE509C794
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _errno_invalid_parameter_noinfo$_getptd_noexit
      • String ID:
      • API String ID: 1573762532-0
      • Opcode ID: d285b2bbadf80e2166a45276edc87aa0736bfca5b4ec6619b3545f8714ce3ff0
      • Instruction ID: a790603ec90553fe8889a48aad481c043719416a7a97377929072486078f52cb
      • Opcode Fuzzy Hash: d285b2bbadf80e2166a45276edc87aa0736bfca5b4ec6619b3545f8714ce3ff0
      • Instruction Fuzzy Hash: 2A4117B2E8829382FA645F1995581B972F0EF40795FA44135DBAD977E5DF3CE940C300
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Locale_errno_invalid_parameter_noinfo$UpdateUpdate::__getptd_noexit
      • String ID:
      • API String ID: 781512312-0
      • Opcode ID: 0899df62475010d5ee482fa7f7096b6a796be90366d2c6e758e3543dec0c843c
      • Instruction ID: bc9408115807a89090158c4782a9ea024de095a106906226d89cf559cf054089
      • Opcode Fuzzy Hash: 0899df62475010d5ee482fa7f7096b6a796be90366d2c6e758e3543dec0c843c
      • Instruction Fuzzy Hash: 1D413772E9C2A281EB686F1991491BD33F0EF44BA5F848135E78887BC5DF2CE9418700
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: std::_$LockitLockit::_$ExceptionFacet_RegisterThrow_lockstd::bad_exception::bad_exception
      • String ID: bad cast
      • API String ID: 1776536810-3145022300
      • Opcode ID: cf94a65d29a58edc82353b24941c8619b48cca9a216b557fe6a530e4c3d837b9
      • Instruction ID: f3354af05a838e7847b37ab9f770ef1a3f96917c42f3bc02ae35cb2dcc9b04bb
      • Opcode Fuzzy Hash: cf94a65d29a58edc82353b24941c8619b48cca9a216b557fe6a530e4c3d837b9
      • Instruction Fuzzy Hash: F0317E22A0CA1681EA10DF1EF4480B973B1EB95BA4F444232DB5D836FADF3CE442C704
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: std::_$LockitLockit::_$ExceptionFacet_RegisterThrow_lockstd::bad_exception::bad_exception
      • String ID: bad cast
      • API String ID: 1776536810-3145022300
      • Opcode ID: 0cb3c862abbe387d89923255385b267e96230e7d8c8512852b1ed9874cb265e9
      • Instruction ID: baa0e2b3b17c1e4b0b2532defc70fc2c76a1348da1e52eb94c59802df2ce560a
      • Opcode Fuzzy Hash: 0cb3c862abbe387d89923255385b267e96230e7d8c8512852b1ed9874cb265e9
      • Instruction Fuzzy Hash: 2C316F22A48A1681EA11DF1EE4481B97371FB95BA4F444335DB6D836FADF3CE942C704
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: std::_$LockitLockit::_$ExceptionFacet_RegisterThrow_lockstd::bad_exception::bad_exception
      • String ID: bad cast
      • API String ID: 1776536810-3145022300
      • Opcode ID: 8a5555141b173215c6208a9c8aeb2d79524cb6a645284a8cc6ebc8768d1bb076
      • Instruction ID: 917cee3fe0f1c8927271131e0a512b2347fcb4c143c8c1f62428263f68597167
      • Opcode Fuzzy Hash: 8a5555141b173215c6208a9c8aeb2d79524cb6a645284a8cc6ebc8768d1bb076
      • Instruction Fuzzy Hash: B731A022A0DB1681EA10DF2EE4480B96770EF95BA4F580231DB5D836FADF3CE542C700
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: std::_$LockitLockit::_$ExceptionFacet_RegisterThrow_lockstd::bad_exception::bad_exception
      • String ID: bad cast
      • API String ID: 1776536810-3145022300
      • Opcode ID: b620016426c3c4f85725f080e70a896ebae7bd1f02c87cd46daec41abacdc0d6
      • Instruction ID: 55b7d68590d9bf95264da6bec2db1419b1fc267d9c306d141af627546c9d043b
      • Opcode Fuzzy Hash: b620016426c3c4f85725f080e70a896ebae7bd1f02c87cd46daec41abacdc0d6
      • Instruction Fuzzy Hash: 05315C22A48A5281FA51DF1EE8481B967B1FB95BA4F544232DB5DC36FADF3CE442C700
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: std::_$LockitLockit::_$ExceptionFacet_RegisterThrow_lockstd::bad_exception::bad_exception
      • String ID: bad cast
      • API String ID: 1776536810-3145022300
      • Opcode ID: aa154f2c991e8ed59acf2e90d9ba5e8cd8cb48189b39342ab2e944e951774971
      • Instruction ID: c4440049e6a1761a754115075aac891503b0d819aba473f6b7e540d4b8f89fbd
      • Opcode Fuzzy Hash: aa154f2c991e8ed59acf2e90d9ba5e8cd8cb48189b39342ab2e944e951774971
      • Instruction Fuzzy Hash: BF317A22A08A5282FA50DF2EE4881B96371FF95BA4F544232DB5D836EDDF3CE442C700
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Locale$UpdateUpdate::___updatetlocinfo__updatetmbcinfo_errno_getptd_invalid_parameter_noinfo
      • String ID:
      • API String ID: 3191669884-0
      • Opcode ID: 0feb9feecc3329452ea8ec885c6d8bb3b47baf9b3ae0000ffeb1a2f89b7271b5
      • Instruction ID: 7b7e893edf3cba011cc9e441b01950cbcdbbd58040c06ec7006b3bf298113de4
      • Opcode Fuzzy Hash: 0feb9feecc3329452ea8ec885c6d8bb3b47baf9b3ae0000ffeb1a2f89b7271b5
      • Instruction Fuzzy Hash: DA317F72A0C7458AE7219F19E58866DBAB4FB58BE0F544131EB5D83BD5CF38E8418780
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ExceptionThrow$Concurrency::details::CoreDecrementEventProxy::SchedulerSubscriptionstd::bad_exception::bad_exceptionstd::exception::exception
      • String ID: pScheduler
      • API String ID: 627769529-923244539
      • Opcode ID: 4a65618706d70c55c2da5df99ba9c83219bbdc0a02742f42fd5244051ed5d83f
      • Instruction ID: 923f1e5fe1cc27ae58c540b94a50bed271e0f02369cdb0bd19624ee79b5fcad0
      • Opcode Fuzzy Hash: 4a65618706d70c55c2da5df99ba9c83219bbdc0a02742f42fd5244051ed5d83f
      • Instruction Fuzzy Hash: 48016172A18A0B81EE14DF18E0591A87371FF84B88F901531EB4D8B6A5DF3CE14AC744
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd
      • String ID: MOC$RCC$csm
      • API String ID: 3186804695-2671469338
      • Opcode ID: 9cd19f3f06bc7988da1e9b1409e20964e5baf2f5a54db59486cd1313f4ff8454
      • Instruction ID: 595dd3beadca6964345b2c177c8c2b09bd839b042ccd39813f60dfba2f9b8431
      • Opcode Fuzzy Hash: 9cd19f3f06bc7988da1e9b1409e20964e5baf2f5a54db59486cd1313f4ff8454
      • Instruction Fuzzy Hash: 06F0A235D0814AC5EA556F5D805D3B835F0EF58715F569471C34C86392CF7CA8848A96
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Concurrency::details::$Manager::ResourceVersion$CompletionCreateExceptionInformationListRetrieveSpinSystemThrowWaitstd::bad_exception::bad_exception
      • String ID:
      • API String ID: 1876357193-0
      • Opcode ID: 04b2fa28b64b16b95eb29dc48d225d5f6a05fa65057bac5eed109b2516558bb8
      • Instruction ID: 46c71cc537c8eaf87ad404e093569b962cc45525ec588bab7755ccda6cb969f7
      • Opcode Fuzzy Hash: 04b2fa28b64b16b95eb29dc48d225d5f6a05fa65057bac5eed109b2516558bb8
      • Instruction Fuzzy Hash: F6318076A0C29353FB685F2DD40827A6BB1FF80780F584539E74ED6696CF2CE8518784
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ioctlsocket$ErrorLastconnectselect
      • String ID:
      • API String ID: 3923486878-0
      • Opcode ID: 03cf7c826b59199f0458c21940543876197c5f873f210f816771850b6b73a7d2
      • Instruction ID: 573dfd5f6c5ce4959dc9eb72a0d8e89eb4b30ec0ed705d15e37b6bea4fa55d64
      • Opcode Fuzzy Hash: 03cf7c826b59199f0458c21940543876197c5f873f210f816771850b6b73a7d2
      • Instruction Fuzzy Hash: 7B21D722A18A8147E3548F29B84C769B771EBC9799F445231EA4EC2AE4DF3CD509CB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Getcvt$___lc_codepage_func___lc_locale_name_func___mb_cur_max_func__updatetlocinfo_getptdlocaleconv
      • String ID: false$true
      • API String ID: 379465546-2658103896
      • Opcode ID: 73d06d7626cf9a4e34ff0ac674d40b771966c80e8ed58987b3a410164db86684
      • Instruction ID: 69343a70aa2830c18adc6673fd803431e60c1ef7c97db45d89a9857bbebab278
      • Opcode Fuzzy Hash: 73d06d7626cf9a4e34ff0ac674d40b771966c80e8ed58987b3a410164db86684
      • Instruction Fuzzy Hash: 0331C222A09B8582DB228F25E44826A77B1FB55BE0B084275DBAD473D9DF3CE155C350
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd$ExceptionRaise_getptd_noexit
      • String ID: csm
      • API String ID: 1742125525-1018135373
      • Opcode ID: 07e646bd3f459ca950e7042a5cd6759f866d2739a47ac95533c609a32ddd3d48
      • Instruction ID: cfc473971d072ff4201cfdefe84a2f56439aa5fe249c17fdfb8a0082107217fa
      • Opcode Fuzzy Hash: 07e646bd3f459ca950e7042a5cd6759f866d2739a47ac95533c609a32ddd3d48
      • Instruction Fuzzy Hash: A221293660864686E630DF19E04426E77B0FB85BA5F014232DF9E43796CF3DE485CB45
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ByteCharLocaleMultiWide$UpdateUpdate::__errno_isleadbyte_l
      • String ID:
      • API String ID: 2998201375-0
      • Opcode ID: 5297c7b9408e9efefd71701747c1766c4c13969b4c72a5129c678fb0fd4e6d0e
      • Instruction ID: d1746f2d99a84d19bd642a091ec5d317343e9194720e914de7785ff25b12f592
      • Opcode Fuzzy Hash: 5297c7b9408e9efefd71701747c1766c4c13969b4c72a5129c678fb0fd4e6d0e
      • Instruction Fuzzy Hash: 38418E32A8878286EB60CF19A244279BAB1FF44B94F188135EB8D97B95DF3CD851C700
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Work$Concurrency::details::List$ArrayQueueQueue::$AcquireBase::Concurrency::details::_CriticalDetachedEntryGroupInterlockedLock::_ReentrantReinitializeScheduleSegment
      • String ID:
      • API String ID: 935885060-0
      • Opcode ID: 9421269130d03d1d2ad055145f5cb457a119ac990fcf1a517f77fa8765db3d48
      • Instruction ID: ddfd9ca24aeffaf8fcf3f325ece76f064baf820dbcee0956fb011fe8dcf0f99e
      • Opcode Fuzzy Hash: 9421269130d03d1d2ad055145f5cb457a119ac990fcf1a517f77fa8765db3d48
      • Instruction Fuzzy Hash: 49115E21A59B4182EF54DF1CE42433822B0FF85B94F544238DB5D877D9EF39E0008304
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: free$ErrorFreeHeapLast_errnosetlocale
      • String ID:
      • API String ID: 3944588114-0
      • Opcode ID: a129dca775d2206b801279d9bcf3f6d9b083367e658b8ec053318e3da434a495
      • Instruction ID: 477164f09c04fb8527da2784a28d66f652158d0f57c8bdd67d17293ba8a21b78
      • Opcode Fuzzy Hash: a129dca775d2206b801279d9bcf3f6d9b083367e658b8ec053318e3da434a495
      • Instruction Fuzzy Hash: 8A016121A0664184EF5DDF6990D627973F4EF94F84B185435D70EA7A86CF28DD90C380
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd_noexit$__doserrno_errno
      • String ID:
      • API String ID: 2964073243-0
      • Opcode ID: 0927e6ef729c9e596bf91f2aacf5c84096a56864d4d06e221d04a04a90b24eca
      • Instruction ID: 5a127fc5d31d8f403eeb9f31c2ef3bf4d3c8c0e8d1f4c49c02e727a16a4c117c
      • Opcode Fuzzy Hash: 0927e6ef729c9e596bf91f2aacf5c84096a56864d4d06e221d04a04a90b24eca
      • Instruction Fuzzy Hash: 2901ADB2E8AA5A44EE181F1CCA8937C35705F92B35F904338C72D823E2CF3C64008210
      APIs
      • Concurrency::details::_CriticalNonReentrantLock::_Acquire.LIBCMT ref: 00007FF6B9CCC61C
        • Part of subcall function 00007FF6B9CC66D0: _SpinWait.LIBCMT ref: 00007FF6B9CC66FF
      • Concurrency::details::SchedulerBase::UpdatePendingVersion.LIBCMT ref: 00007FF6B9CCC624
        • Part of subcall function 00007FF6B9CCFE00: Concurrency::details::SchedulerBase::ComputeSafePointCommitVersion.LIBCMT ref: 00007FF6B9CCFE09
      • Concurrency::details::SchedulerBase::CommitToVersion.LIBCMT ref: 00007FF6B9CCC630
      • Concurrency::details::_CriticalNonReentrantLock::_Acquire.LIBCMT ref: 00007FF6B9CCC638
      • Concurrency::details::SchedulerBase::UpdateCommitVersion.LIBCMT ref: 00007FF6B9CCC642
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Base::Concurrency::details::SchedulerVersion$Commit$AcquireConcurrency::details::_CriticalLock::_ReentrantUpdate$ComputePendingPointSafeSpinWait
      • String ID:
      • API String ID: 4127798528-0
      • Opcode ID: b752e140cde508a889828605ea4a5ff6bff43a6522ddf288ae4795b530531b87
      • Instruction ID: 524a5425df8fe1ef01a717886d3786316b77a939af39b5df086e6c35e2f505f3
      • Opcode Fuzzy Hash: b752e140cde508a889828605ea4a5ff6bff43a6522ddf288ae4795b530531b87
      • Instruction Fuzzy Hash: 48F09A21E4825241E914AF2AA3490B95A309F98BC0F142031FB4A8BB47CF2CD44283C0
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd$_inconsistency$DecodePointer_getptd_noexit
      • String ID:
      • API String ID: 3566995948-0
      • Opcode ID: db5a918070a374afb43049a900a9a587905e0fb94cbe37e2d6d5f365a64d4e94
      • Instruction ID: 8146bd09db297b7318cfe0f061656ed77c44ae43197367cf0aa1a6ec23a60dc8
      • Opcode Fuzzy Hash: db5a918070a374afb43049a900a9a587905e0fb94cbe37e2d6d5f365a64d4e94
      • Instruction Fuzzy Hash: F6F01262A0968680EA95AF6DD04D1BD7A74BF4CB80F1C4131E74D87387DF2CE49087D8
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _errnoremove$FolderPath_getptd_noexit
      • String ID: bytes to file $writing
      • API String ID: 1059067161-3905530474
      • Opcode ID: a258a0d2fb234b067224a0abd3bd05381ec48211be329789dcb5eb39b8ade8e1
      • Instruction ID: a9700fe59b0bdaec251f17135f7ed5dae0aaf4a71527f3e11c0e4e4000e8ddf4
      • Opcode Fuzzy Hash: a258a0d2fb234b067224a0abd3bd05381ec48211be329789dcb5eb39b8ade8e1
      • Instruction Fuzzy Hash: DA614B62A4D6C651EA21EF28E4593EE6371EB91784F805431D78EC36AFDF2CE508C704
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ExceptionThrowXbad_allocstd::_
      • String ID: gfffffff$gfffffff$vector<T> too long
      • API String ID: 944563697-3862842194
      • Opcode ID: f90385889ea05b3f7392f4bf7350b9480659d1bf8b8a68eb028385fe443dc1ed
      • Instruction ID: 4c32b03fbd76e41d341e83f6a731a34169a6b972e213b2c5d45e0f7d4f3a3c0b
      • Opcode Fuzzy Hash: f90385889ea05b3f7392f4bf7350b9480659d1bf8b8a68eb028385fe443dc1ed
      • Instruction Fuzzy Hash: 623193A2F09B6E42ED04CF5FB959064A372AB457C0B508536CF0DCB799EF3CE1418206
      APIs
      • _getptd_noexit.LIBCMT ref: 00007FF6B9CB5CF0
        • Part of subcall function 00007FF6B9CC07D4: GetLastError.KERNEL32(?,?,?,00007FF6B9CB66D1,?,?,?,?,00007FF6B9CB5A35,?,?,?,00007FF6B9CB4EA0), ref: 00007FF6B9CC07DE
        • Part of subcall function 00007FF6B9CC07D4: _calloc_crt.LIBCMT ref: 00007FF6B9CC0801
        • Part of subcall function 00007FF6B9CC07D4: _initptd.LIBCMT ref: 00007FF6B9CC0825
        • Part of subcall function 00007FF6B9CC07D4: GetCurrentThreadId.KERNEL32 ref: 00007FF6B9CC082A
        • Part of subcall function 00007FF6B9CC07D4: SetLastError.KERNEL32(?,?,?,00007FF6B9CB66D1,?,?,?,?,00007FF6B9CB5A35,?,?,?,00007FF6B9CB4EA0), ref: 00007FF6B9CC0842
      • _calloc_crt.LIBCMT ref: 00007FF6B9CB5D20
      • _invoke_watson.LIBCMT ref: 00007FF6B9CB5D78
        • Part of subcall function 00007FF6B9CBD360: _call_reportfault.LIBCMT ref: 00007FF6B9CBD388
      Strings
      • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 00007FF6B9CB5CFD
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ErrorLast_calloc_crt$CurrentThread_call_reportfault_getptd_noexit_initptd_invoke_watson
      • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
      • API String ID: 835963739-798102604
      • Opcode ID: e458e596050656dde5d0d4c743bcf5eb15964c97def0755c343391bd7b1bd0b9
      • Instruction ID: aef561e946007c76fed70822c1c9774d050996b6441ed513259fa34f64cb6915
      • Opcode Fuzzy Hash: e458e596050656dde5d0d4c743bcf5eb15964c97def0755c343391bd7b1bd0b9
      • Instruction Fuzzy Hash: BA11AD22A1878A42FBA4AF28D15D3BD32B1AF85B44F595534DB0D8B786EF3DF8418340
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Locale$UpdateUpdate::___updatetlocinfo__updatetmbcinfo_errno_getptd_getptd_noexit_invalid_parameter_noinfostrchr
      • String ID:
      • API String ID: 4151157258-0
      • Opcode ID: 36c0bb8c8628e5e199e1d459f3f3e4ff65f57ebdba7ca7f1b266bdbb24a60703
      • Instruction ID: 0f25d7b2cc6021c27046713b0a511e382b5c0b0894a06193fa63ddb0db85cb02
      • Opcode Fuzzy Hash: 36c0bb8c8628e5e199e1d459f3f3e4ff65f57ebdba7ca7f1b266bdbb24a60703
      • Instruction Fuzzy Hash: FE21C362A2DAE641EB615F1A905A17DB6F1EB80BD4F184131EB9F87AC5CF2CF8418710
      APIs
        • Part of subcall function 00007FF6B9CCCA80: TlsGetValue.KERNEL32(?,?,?,?,00007FF6B9CCC21A), ref: 00007FF6B9CCCA8A
      • Concurrency::details::SchedulerBase::AttachExternalContext.LIBCMT ref: 00007FF6B9CCC224
        • Part of subcall function 00007FF6B9CCC274: TlsGetValue.KERNEL32(?,?,?,?,?,?,00000000,00007FF6B9CCC8F8,?,?,?,00007FF6B9CBB153), ref: 00007FF6B9CCC28F
        • Part of subcall function 00007FF6B9CCC274: Concurrency::details::InternalContextBase::LeaveScheduler.LIBCMT ref: 00007FF6B9CCC2B0
        • Part of subcall function 00007FF6B9CCC274: Concurrency::details::SchedulerBase::GetExternalContext.LIBCMT ref: 00007FF6B9CCC2D3
      • Concurrency::details::SchedulerBase::ThrowSchedulerEvent.LIBCMT ref: 00007FF6B9CCC24B
        • Part of subcall function 00007FF6B9CCFC84: Concurrency::details::Etw::Trace.LIBCMT ref: 00007FF6B9CCFCF5
      • std::bad_exception::bad_exception.LIBCMT ref: 00007FF6B9CCC25B
      • _CxxThrowException.LIBCMT ref: 00007FF6B9CCC26C
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Concurrency::details::Scheduler$Base::$Context$ExternalThrowValue$AttachEtw::EventExceptionInternalLeaveTracestd::bad_exception::bad_exception
      • String ID:
      • API String ID: 3337661974-0
      • Opcode ID: a8ffa42869d0cca481dc8e7d30508a6de5a9f9c283b2c504f4a04659c1eefe2b
      • Instruction ID: e135c3e55d394cca8c17d6af1ee012c9ff3c8fab36407518a023dcde2cff8f5c
      • Opcode Fuzzy Hash: a8ffa42869d0cca481dc8e7d30508a6de5a9f9c283b2c504f4a04659c1eefe2b
      • Instruction Fuzzy Hash: 92F09A62A4865742ED20AFADD8591B51B30AF8A348F080830DB5ECB7A3CE3DB5468784
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ExceptionThrowstd::bad_exception::bad_exception
      • String ID:
      • API String ID: 1480402491-0
      • Opcode ID: 52b6f9ac578ef59788abf9f234be2f52d284893acd74629aa72149f022c5e788
      • Instruction ID: aa048b468adb241a4ad4e8b04b023f5e41a6952b30ca25404085d51435f7c452
      • Opcode Fuzzy Hash: 52b6f9ac578ef59788abf9f234be2f52d284893acd74629aa72149f022c5e788
      • Instruction Fuzzy Hash: C9F06262A4891B81EE10AF2AD5561B92371FF45384F814531E78DC66EADF2DD506C340
      APIs
      • SetThreadPriority.KERNEL32(?,?,?,?,?,?,?,?,00007FF6B9CDD610), ref: 00007FF6B9CE934B
      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00007FF6B9CDD610), ref: 00007FF6B9CE935A
      • Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error.LIBCMT ref: 00007FF6B9CE9373
      • _CxxThrowException.LIBCMT ref: 00007FF6B9CE9384
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionLastPriorityThreadThrow
      • String ID:
      • API String ID: 152467346-0
      • Opcode ID: bd81974e09e3a9616df76e0388476f62eaa7e0dc68a4e20fee498b5bbef2bd85
      • Instruction ID: 73c16d310719c13bb5d7ef1a3ef03bcbef0ca12e3b67fd6015c6f5ed02ec0048
      • Opcode Fuzzy Hash: bd81974e09e3a9616df76e0388476f62eaa7e0dc68a4e20fee498b5bbef2bd85
      • Instruction Fuzzy Hash: B6E06565A18A4786EB14AF2AD80927523B1FF88748F908931D34DC65A4EF3DE50ACB40
      APIs
      • UnregisterWaitEx.KERNEL32 ref: 00007FF6B9CCC9C8
      • Concurrency::details::platform::__DeleteTimerQueueTimer.LIBCMT ref: 00007FF6B9CCC9DB
        • Part of subcall function 00007FF6B9CC6000: DeleteTimerQueueTimer.KERNEL32 ref: 00007FF6B9CC6030
      • CloseHandle.KERNEL32 ref: 00007FF6B9CCC9E7
      • Concurrency::details::SchedulerBase::Finalize.LIBCMT ref: 00007FF6B9CCC9F9
        • Part of subcall function 00007FF6B9CCCAA4: CloseHandle.KERNEL32(?,?,?,?,?,?,00000000,00007FF6B9CCF973,?,?,00000000,00007FF6B9CCC335), ref: 00007FF6B9CCCACA
        • Part of subcall function 00007FF6B9CCCAA4: InterlockedFlushSList.KERNEL32(?,?,?,?,?,?,00000000,00007FF6B9CCF973,?,?,00000000,00007FF6B9CCC335), ref: 00007FF6B9CCCB10
        • Part of subcall function 00007FF6B9CCCAA4: InterlockedFlushSList.KERNEL32(?,?,?,?,?,?,00000000,00007FF6B9CCF973,?,?,00000000,00007FF6B9CCC335), ref: 00007FF6B9CCCB53
        • Part of subcall function 00007FF6B9CCCAA4: Concurrency::details::SchedulerBase::ThrowSchedulerEvent.LIBCMT ref: 00007FF6B9CCCBB0
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Timer$Scheduler$Base::CloseConcurrency::details::DeleteFlushHandleInterlockedListQueue$Concurrency::details::platform::__EventFinalizeThrowUnregisterWait
      • String ID:
      • API String ID: 1020705008-0
      • Opcode ID: 5d5854dba2f339c7cf30f9e02c3e4fad926736d1f37232c3274770b9356adc06
      • Instruction ID: be3dc2ed82a4a6e859e2a4e648e0f2723b7f0ae4d76c0c4d54a6475a5be0b1e4
      • Opcode Fuzzy Hash: 5d5854dba2f339c7cf30f9e02c3e4fad926736d1f37232c3274770b9356adc06
      • Instruction Fuzzy Hash: 5BE09262A0948281FB005F7A984D3BD2230EF44BB4F486331CE3E891EACF1980854354
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Xbad_allocstd::_$ExceptionThrowmalloc
      • String ID: vector<T> too long
      • API String ID: 1779041212-3788999226
      • Opcode ID: ab913dcbeb243f7378f64ac265282a4f72605455fcb9a8e55051d2279df21308
      • Instruction ID: 209e3bed6dee21e815ecfa2f9f08c626394ee77cbf35e69a5f3575da46cd146a
      • Opcode Fuzzy Hash: ab913dcbeb243f7378f64ac265282a4f72605455fcb9a8e55051d2279df21308
      • Instruction Fuzzy Hash: 6351E272B05B8583EA14DF2AA449169A2B5FB44BE0F148631DFAC57BD9EF3CE441C304
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: swprintf
      • String ID: %$+
      • API String ID: 233258989-2626897407
      • Opcode ID: 6fa85a4a5f98d9b2edd65c8fc52f8eaba122c580845481ee6f06e08475fe2951
      • Instruction ID: af454b4035acc25f66e2aa36f41bf4e7d694679ca0e2dae952390733b359a2a2
      • Opcode Fuzzy Hash: 6fa85a4a5f98d9b2edd65c8fc52f8eaba122c580845481ee6f06e08475fe2951
      • Instruction Fuzzy Hash: 65514722E0CB8185FB228F39E5993BA6771FF553C4F145231DB8E93A99DF2CE4418600
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: swprintf
      • String ID: %$+
      • API String ID: 233258989-2626897407
      • Opcode ID: ba670cdc73b5d295f30c137456232ec9728c73304c93483a7b7d5d2b88c9bbc0
      • Instruction ID: 35f4e95ce86498c773e81ef98b0d6eb8bce07f6966465cf1c2eeb0c31c974b47
      • Opcode Fuzzy Hash: ba670cdc73b5d295f30c137456232ec9728c73304c93483a7b7d5d2b88c9bbc0
      • Instruction Fuzzy Hash: DC512922A0CB8189FB628F28E9593BA6771EF553C4F449231EB4D93B99DF3CE445C600
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: swprintf
      • String ID: %$+
      • API String ID: 233258989-2626897407
      • Opcode ID: 4f884a797e3be12bfada8cb5e3661bfcc9e2ec278513ca55729cd4a6a98e770f
      • Instruction ID: eb1802ae7efe87562ae7e0e4b21c6b1bc72b74669cb21381c97ef51e97ce99bd
      • Opcode Fuzzy Hash: 4f884a797e3be12bfada8cb5e3661bfcc9e2ec278513ca55729cd4a6a98e770f
      • Instruction Fuzzy Hash: 7021F15260CBC485E7258B19E4893EAB771EB95B84F449035DB8C03BCADF2CD509CB41
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: swprintf
      • String ID: %$+
      • API String ID: 233258989-2626897407
      • Opcode ID: bd2448649ee57e4d5998f2208d3a164235575cf06586aa510bff15654f418069
      • Instruction ID: 34292149d80875db9c7ec5ace2a5a12b92b2ffb5fc2fbd816cd47c6f06270b5f
      • Opcode Fuzzy Hash: bd2448649ee57e4d5998f2208d3a164235575cf06586aa510bff15654f418069
      • Instruction Fuzzy Hash: 1C21024260C7C484F7258B19E4893FAB7B1EB95B84F448035DB8D43B8ADF2CDA09C741
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: swprintf
      • String ID: %$+
      • API String ID: 233258989-2626897407
      • Opcode ID: c2ab8cbe4c38ac8b2161e06a6ed5e29d440f316e3521188a2708fde680d69b84
      • Instruction ID: 8599cffb3720c00f5590d980a7c0ff56582fca5dc103637ba1de71c23adc4823
      • Opcode Fuzzy Hash: c2ab8cbe4c38ac8b2161e06a6ed5e29d440f316e3521188a2708fde680d69b84
      • Instruction Fuzzy Hash: 9921FC5260C7C085E7218B2AE4493FAB770EBAA780F485035EBCC43B89DF2CD049CB51
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: swprintf
      • String ID: %$+
      • API String ID: 233258989-2626897407
      • Opcode ID: 38663dba18d0d25d2075d16b7d25364ae185f2c545367c52f6517a1dd6074f36
      • Instruction ID: 46d12fd57a497a2891b917dd6073f3edb10555d73a05608185187a388a945fc4
      • Opcode Fuzzy Hash: 38663dba18d0d25d2075d16b7d25364ae185f2c545367c52f6517a1dd6074f36
      • Instruction Fuzzy Hash: 7021FE52A0C7C086E7218B18E4453EAB774EBA9798F445035EB8D43B89DF2CD045CB51
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd
      • String ID: csm$csm
      • API String ID: 3186804695-3733052814
      • Opcode ID: 761bbdb581a1da8e2284ec1f21cb742ae57594a5225517d28d8f09f6c435668e
      • Instruction ID: c9a07d0bfe9dfbb363495fe8714e724bca0a867c660f099c8c93bc712035efba
      • Opcode Fuzzy Hash: 761bbdb581a1da8e2284ec1f21cb742ae57594a5225517d28d8f09f6c435668e
      • Instruction Fuzzy Hash: 4031EA77514B05CAEB608F6AC0852B83B75F758B9DF4A1225E70E4BB54CF39E890C784
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Exception$FileHeaderRaiseSleepThrow_malloc_crtmalloc
      • String ID: bad allocation
      • API String ID: 340456944-2104205924
      • Opcode ID: 35f1bc3740df1caf6d7d07bf89e0cc798afd3c848886c57562113992f615682e
      • Instruction ID: 2d528af39ce5451a0fb6b4c71a3e2fb0fb0cd6617ebc74d3b8a0e7ab9a2ef596
      • Opcode Fuzzy Hash: 35f1bc3740df1caf6d7d07bf89e0cc798afd3c848886c57562113992f615682e
      • Instruction Fuzzy Hash: 53216F32614F8292EB10CF19E88426973B4FB89BA4F588235DB9D477A4DF3CE565C740
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _handle_error
      • String ID: !$sqrt
      • API String ID: 1757819995-799759792
      • Opcode ID: 062c47d617d1b06cc8f9885f04ed537725f66ac90b938101cb89aa41ff868c8d
      • Instruction ID: 859271c4fee0be3bb325f93b42bdd80da73e2dd8f73fa2bfdaf523edb8ad7bc9
      • Opcode Fuzzy Hash: 062c47d617d1b06cc8f9885f04ed537725f66ac90b938101cb89aa41ff868c8d
      • Instruction Fuzzy Hash: 4721C272D58BC983D711CF69A04436A7671FFD67A4F200325EB6816ACACF2DD0808B00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _getptd$_inconsistency
      • String ID: csm
      • API String ID: 1773999731-1018135373
      • Opcode ID: cc382658ad257d6a53cdc3de2009e2b9ead7a3f4f7326b46ffc43048dfa9dc90
      • Instruction ID: e24ca323792de54888e4aafeb778acf1d6ffc46a6338817d5063adb9b5b2876a
      • Opcode Fuzzy Hash: cc382658ad257d6a53cdc3de2009e2b9ead7a3f4f7326b46ffc43048dfa9dc90
      • Instruction Fuzzy Hash: D90144229046828ADBA4DF36C8592BD2374EB55799F041432FB0D87745DF28E880C780
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ExceptionThrowstd::exception::exception
      • String ID: pContext
      • API String ID: 4279132481-2046700901
      • Opcode ID: 9a9254acd0818dea865ed3536d1d2b2c234e7448caf268871d4950f6f5e143a4
      • Instruction ID: da5457f4719814dba526633689b2a7c703127e7b73ab919f6d1cedb9b81ea1f1
      • Opcode Fuzzy Hash: 9a9254acd0818dea865ed3536d1d2b2c234e7448caf268871d4950f6f5e143a4
      • Instruction Fuzzy Hash: 70F06966A08B4A91DE14DF19E198169A371FB88BC8B448031DB9D87B68EF7CD158CB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: _handle_error
      • String ID: !$sqrt
      • API String ID: 1757819995-799759792
      • Opcode ID: 9ee81001ab96a3020d92c62d35741d9657c359ef35bf3942f53d73308bbadfc5
      • Instruction ID: e0750bb44a57d1d776bd54178da378746dc0e5706435c25ad70bbba9b9951810
      • Opcode Fuzzy Hash: 9ee81001ab96a3020d92c62d35741d9657c359ef35bf3942f53d73308bbadfc5
      • Instruction Fuzzy Hash: B8F0D172E58B8982D700CF54E4453777632EFEB794F204326EA5C4AB89DF2DE0808B00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: ExceptionThrowstd::exception::exception
      • String ID: pThreadProxy
      • API String ID: 4279132481-3651400591
      • Opcode ID: 3b6d5a5437ee8c8c730aa7db00305f52f2161aba5272be33be333d17a79e59f8
      • Instruction ID: bb1c61e422e47e0fd15caabdf0d42a66843004425d364e7a34e2e0d887d386e9
      • Opcode Fuzzy Hash: 3b6d5a5437ee8c8c730aa7db00305f52f2161aba5272be33be333d17a79e59f8
      • Instruction Fuzzy Hash: 59E03076A08B4B91DD24DF48E05919963B4FB45388F904531D39C87B64DF7CE20ACB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1698382434.00007FF6B9C81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B9C80000, based on PE: true
      • Associated: 00000000.00000002.1698297531.00007FF6B9C80000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698422664.00007FF6B9CF1000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698445077.00007FF6B9D13000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1698499589.00007FF6B9D1A000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff6b9c80000_wnGDKyXdAo.jbxd
      Similarity
      • API ID: Exceptionstd::bad_exception::bad_exception$FileHeaderRaiseThrow
      • String ID: Access violation - no RTTI data!
      • API String ID: 2866377151-2158758863
      • Opcode ID: 23997e88545030d1aea56eb2b441ca10bd2c9bedac894ae6f7fbeb74f77f7ac1
      • Instruction ID: 21b9712b15115d7511ccee370a7fdd4db27c6cfa6999928000da8dd3df6480cc
      • Opcode Fuzzy Hash: 23997e88545030d1aea56eb2b441ca10bd2c9bedac894ae6f7fbeb74f77f7ac1
      • Instruction Fuzzy Hash: 1EE04F27618A8A91DB41CF09F4447A96330F785398F815172EF1C83659DF3DD98BC704