Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
cylanceprotectsetupwithoptics.exe

Overview

General Information

Sample name:cylanceprotectsetupwithoptics.exe
Analysis ID:1426789
MD5:796375900c5f33db332ff8143f243083
SHA1:9baf9183df0a5ca02cd49dbe04d99578821b27f7
SHA256:bab72dfa7eed0ce4814580312ccba4fca4a136f4bb6f93a9f8f9648614d9ec68
Infos:

Detection

Score:10
Range:0 - 100
Whitelisted:false
Confidence:20%

Signatures

Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Found evaded block containing many API calls
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample may be VM or Sandbox-aware, try analysis on a native machine
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
  • System is w10x64
  • cylanceprotectsetupwithoptics.exe (PID: 3320 cmdline: "C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe" MD5: 796375900C5F33DB332FF8143F243083)
    • cylanceprotectsetupwithoptics.exe (PID: 1020 cmdline: "C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe" -burn.clean.room="C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe" -burn.filehandle.attached=512 -burn.filehandle.self=528 MD5: 796375900C5F33DB332FF8143F243083)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B19EB7 DecryptFileW,1_2_00B19EB7
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B3F961 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,1_2_00B3F961
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B19C99 DecryptFileW,DecryptFileW,1_2_00B19C99
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_00899EB7 DecryptFileW,2_2_00899EB7
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008BF961 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,2_2_008BF961
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_00899C99 DecryptFileW,DecryptFileW,2_2_00899C99
Source: cylanceprotectsetupwithoptics.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: cylanceprotectsetupwithoptics.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe.1.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb8 source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\mbahost.pdb source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmp, mbahost.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\WixStdBA.pdb source: mbapreq.dll.2.dr
Source: Binary string: e:\jenkins\sign2\workspace\UnifiedInstaller\REL\1070\exe\src\bundledinstaller\Cylance.Host.Installer.CustomBootstrapperWithOptics\obj\Release\Cylance.Host.Installer.CustomBootstrapperWithOptics.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3389746389.0000000006AE9000.00000002.00000001.01000000.0000000B.sdmp, Cylance.Host.Installer.CustomBootstrapperWithOptics.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\core\BootstrapperCore.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.2.dr
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B44315 FindFirstFileW,FindClose,1_2_00B44315
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B1993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,1_2_00B1993E
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B37A87 FindFirstFileExW,1_2_00B37A87
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B03BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,1_2_00B03BC3
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008C4315 FindFirstFileW,FindClose,2_2_008C4315
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_0089993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,2_2_0089993E
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008B7A87 FindFirstFileExW,2_2_008B7A87
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_00883BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,2_2_00883BC3
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E83BF6A FindFirstFileExA,2_2_6E83BF6A
Source: cylanceprotectsetupwithoptics.exeString found in binary or memory: http://appsyndication.org/2006/appsyn
Source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe.1.drString found in binary or memory: http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://defaultcontainer/Cylance.Host.Installer.CustomBootstrapperWithOptics;component/mainview.xamld
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://defaultcontainer/Cylance.Host.Installer.CustomBootstrapperWithOptics;component/resources/inst
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://foo/bar/mainview.baml
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://foo/bar/mainview.bamld
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://foo/mainview.xaml
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://foo/resources/installerBannerProtect.bmp
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: cylanceprotectsetupwithoptics.exeString found in binary or memory: http://wixtoolset.org/
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr, Microsoft.Deployment.WindowsInstaller.dll.2.drString found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v
Source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr, Microsoft.Deployment.WindowsInstaller.dll.2.drString found in binary or memory: http://wixtoolset.org/news/
Source: mbapreq.thm.2.drString found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010
Source: cylanceprotectsetupwithoptics.exeString found in binary or memory: http://wixtoolset.org/telemetry/v
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B2C0FA1_2_00B2C0FA
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B061841_2_00B06184
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B3022D1_2_00B3022D
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B3A3B01_2_00B3A3B0
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B306621_2_00B30662
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B0A7EF1_2_00B0A7EF
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B3A85E1_2_00B3A85E
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B169CC1_2_00B169CC
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B2F9191_2_00B2F919
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B30A971_2_00B30A97
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B32B211_2_00B32B21
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B32D501_2_00B32D50
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B3ED4C1_2_00B3ED4C
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B2FE151_2_00B2FE15
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008AC0FA2_2_008AC0FA
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008861842_2_00886184
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008B022D2_2_008B022D
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008BA3B02_2_008BA3B0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008B06622_2_008B0662
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_0088A7EF2_2_0088A7EF
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008BA85E2_2_008BA85E
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008969CC2_2_008969CC
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008AF9192_2_008AF919
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008B0A972_2_008B0A97
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008B2B212_2_008B2B21
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008BED4C2_2_008BED4C
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008B2D502_2_008B2D50
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008AFE152_2_008AFE15
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_066C96452_2_066C9645
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06ADE1CE2_2_06ADE1CE
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E83DCFE2_2_6E83DCFE
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E8370252_2_6E837025
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E83D8502_2_6E83D850
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E836DF62_2_6E836DF6
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E8429782_2_6E842978
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: String function: 00B431C7 appears 83 times
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: String function: 00B01F20 appears 54 times
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: String function: 00B4061A appears 34 times
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: String function: 00B4012F appears 678 times
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: String function: 00B037D3 appears 496 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: String function: 008C31C7 appears 83 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: String function: 00881F20 appears 54 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: String function: 008837D3 appears 496 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: String function: 008C061A appears 34 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: String function: 008C012F appears 678 times
Source: cylanceprotectsetupwithoptics.exeBinary or memory string: OriginalFilename vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exeBinary or memory string: OriginalFilename vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388997416.00000000066D4000.00000002.00000001.01000000.0000000A.sdmpBinary or memory string: OriginalFilenameBootstrapperCore.dll\ vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3389912943.0000000006AF0000.00000002.00000001.01000000.0000000B.sdmpBinary or memory string: OriginalFilenameCylance.Host.Installer.CustomBootstrapperWithOptics.dll vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Deployment.WindowsInstaller.dll\ vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpBinary or memory string: OriginalFilenamembahost.dll\ vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: classification engineClassification label: clean10.winEXE@3/35@0/0
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B3FD20 FormatMessageW,GetLastError,LocalFree,1_2_00B3FD20
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B044E9 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle,1_2_00B044E9
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008844E9 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle,2_2_008844E9
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B42F23 GetModuleHandleA,GetLastError,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CoCreateInstance,ExitProcess,1_2_00B42F23
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B26945 ChangeServiceConfigW,GetLastError,1_2_00B26945
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeMutant created: NULL
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCommand line argument: cabinet.dll1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCommand line argument: msi.dll1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCommand line argument: version.dll1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCommand line argument: wininet.dll1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCommand line argument: comres.dll1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCommand line argument: clbcatq.dll1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCommand line argument: msasn1.dll1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCommand line argument: crypt32.dll1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCommand line argument: feclient.dll1_2_00B01070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCommand line argument: cabinet.dll2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCommand line argument: msi.dll2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCommand line argument: version.dll2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCommand line argument: wininet.dll2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCommand line argument: comres.dll2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCommand line argument: clbcatq.dll2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCommand line argument: msasn1.dll2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCommand line argument: crypt32.dll2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCommand line argument: feclient.dll2_2_00881070
Source: cylanceprotectsetupwithoptics.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: cylanceprotectsetupwithoptics.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: cylanceprotectsetupwithoptics.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: cylanceprotectsetupwithoptics.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeFile read: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe "C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe"
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeProcess created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe "C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe" -burn.clean.room="C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe" -burn.filehandle.attached=512 -burn.filehandle.self=528
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeProcess created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe "C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe" -burn.clean.room="C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe" -burn.filehandle.attached=512 -burn.filehandle.self=528 Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: msi.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: msxml3.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: feclient.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: msxml3.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: feclient.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: msvcp140_clr0400.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: d3d9.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: winsta.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: msctfui.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeSection loaded: d3dcompiler_47.dllJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InProcServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
Source: cylanceprotectsetupwithoptics.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: cylanceprotectsetupwithoptics.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: cylanceprotectsetupwithoptics.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: cylanceprotectsetupwithoptics.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: cylanceprotectsetupwithoptics.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: cylanceprotectsetupwithoptics.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: cylanceprotectsetupwithoptics.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: cylanceprotectsetupwithoptics.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe.1.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb8 source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\mbahost.pdb source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmp, mbahost.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\WixStdBA.pdb source: mbapreq.dll.2.dr
Source: Binary string: e:\jenkins\sign2\workspace\UnifiedInstaller\REL\1070\exe\src\bundledinstaller\Cylance.Host.Installer.CustomBootstrapperWithOptics\obj\Release\Cylance.Host.Installer.CustomBootstrapperWithOptics.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3389746389.0000000006AE9000.00000002.00000001.01000000.0000000B.sdmp, Cylance.Host.Installer.CustomBootstrapperWithOptics.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\core\BootstrapperCore.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.2.dr
Source: cylanceprotectsetupwithoptics.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: cylanceprotectsetupwithoptics.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: cylanceprotectsetupwithoptics.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: cylanceprotectsetupwithoptics.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: cylanceprotectsetupwithoptics.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: cylanceprotectsetupwithoptics.exeStatic PE information: section name: .wixburn
Source: cylanceprotectsetupwithoptics.exe.1.drStatic PE information: section name: .wixburn
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B2E876 push ecx; ret 1_2_00B2E889
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008AE876 push ecx; ret 2_2_008AE889
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEADCD push ss; retf 2_2_06AEADCE
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB1AF push es; ret 2_2_06AEB1B0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB1BA push es; ret 2_2_06AEB1BC
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB1B4 push es; ret 2_2_06AEB1B6
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB1E9 push es; ret 2_2_06AEB1EC
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB1E3 push es; ret 2_2_06AEB1E6
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB1CC push es; ret 2_2_06AEB1DA
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB1C7 push es; ret 2_2_06AEB1C8
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB1C1 push es; ret 2_2_06AEB1C2
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB1DD push es; ret 2_2_06AEB1E0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_06AEB15A push es; ret 2_2_06AEB1AA
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E8344E6 push ecx; ret 2_2_6E8344F9
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_043E8420 push es; ret 2_2_043E8436
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_043E7522 push esp; retf 2_2_043E7531
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_043E87E0 push es; ret 2_2_043E87F0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_043E705A pushfd ; iretd 2_2_043E7089
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_043E704A pushad ; iretd 2_2_043E7059
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_043E3268 pushfd ; iretd 2_2_043E3341
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_043E3343 pushfd ; iretd 2_2_043E3341
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_043E7ECF push es; ret 2_2_043E7ED0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbapreq.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbahost.dllJump to dropped file
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Microsoft.Deployment.WindowsInstaller.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbapreq.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbahost.dllJump to dropped file
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeFile created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Microsoft.Deployment.WindowsInstaller.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeMemory allocated: 3420000 memory reserve | memory write watchJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeMemory allocated: 4440000 memory reserve | memory write watchJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeMemory allocated: 6440000 memory reserve | memory write watchJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeDropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeDropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbapreq.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeDropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbahost.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeDropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dllJump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeDropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Microsoft.Deployment.WindowsInstaller.dllJump to dropped file
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeEvaded block: after key decision
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeAPI coverage: 9.1 %
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B3FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 00B3FE5Dh1_2_00B3FDC2
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B3FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 00B3FE56h1_2_00B3FDC2
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008BFDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 008BFE5Dh2_2_008BFDC2
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008BFDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 008BFE56h2_2_008BFDC2
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B44315 FindFirstFileW,FindClose,1_2_00B44315
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B1993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,1_2_00B1993E
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B37A87 FindFirstFileExW,1_2_00B37A87
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B03BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,1_2_00B03BC3
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008C4315 FindFirstFileW,FindClose,2_2_008C4315
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_0089993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,2_2_0089993E
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008B7A87 FindFirstFileExW,2_2_008B7A87
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_00883BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,2_2_00883BC3
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E83BF6A FindFirstFileExA,2_2_6E83BF6A
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B4962D VirtualQuery,GetSystemInfo,1_2_00B4962D
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeAPI call chain: ExitProcess graph end node
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeAPI call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B2E625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00B2E625
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B34812 mov eax, dword ptr fs:[00000030h]1_2_00B34812
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008B4812 mov eax, dword ptr fs:[00000030h]2_2_008B4812
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E838EB1 mov eax, dword ptr fs:[00000030h]2_2_6E838EB1
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B038D4 GetProcessHeap,RtlAllocateHeap,1_2_00B038D4
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B2E188 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,1_2_00B2E188
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B2E625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00B2E625
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B2E773 SetUnhandledExceptionFilter,1_2_00B2E773
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B33BB0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00B33BB0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008AE188 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_008AE188
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008AE625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_008AE625
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008AE773 SetUnhandledExceptionFilter,2_2_008AE773
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_008B3BB0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_008B3BB0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E837E39 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_6E837E39
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E834321 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_6E834321
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeCode function: 2_2_6E8344FB SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_6E8344FB
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeMemory allocated: page read and write | page guardJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeProcess created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe "C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe" -burn.clean.room="C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe" -burn.filehandle.attached=512 -burn.filehandle.self=528 Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B415CB InitializeSecurityDescriptor,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,SetEntriesInAclA,SetSecurityDescriptorOwner,GetLastError,SetSecurityDescriptorGroup,GetLastError,SetSecurityDescriptorDacl,GetLastError,CoInitializeSecurity,LocalFree,1_2_00B415CB
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B4393B AllocateAndInitializeSid,CheckTokenMembership,1_2_00B4393B
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B2E9A7 cpuid 1_2_00B2E9A7
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dll VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dll VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemCore\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemCore.dll VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B14CE8 ConvertStringSecurityDescriptorToSecurityDescriptorW,GetLastError,CreateNamedPipeW,GetLastError,CreateNamedPipeW,GetLastError,CloseHandle,LocalFree,1_2_00B14CE8
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B4858F GetSystemTime,1_2_00B4858F
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B060BA GetUserNameW,GetLastError,1_2_00B060BA
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B48733 GetTimeZoneInformation,SystemTimeToTzSpecificLocalTime,1_2_00B48733
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exeCode function: 1_2_00B0508D GetModuleHandleW,CoInitializeEx,GetVersionExW,GetLastError,CoUninitialize,1_2_00B0508D
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts3
Command and Scripting Interpreter
1
Windows Service
1
Access Token Manipulation
1
Masquerading
OS Credential Dumping12
System Time Discovery
Remote Services1
Archive Collected Data
2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts1
Service Execution
1
DLL Side-Loading
1
Windows Service
11
Virtualization/Sandbox Evasion
LSASS Memory2
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain Accounts2
Native API
Logon Script (Windows)12
Process Injection
1
Disable or Modify Tools
Security Account Manager11
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
DLL Side-Loading
1
Access Token Manipulation
NTDS1
Account Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script12
Process Injection
LSA Secrets1
System Owner/User Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Deobfuscate/Decode Files or Information
Cached Domain Credentials1
File and Directory Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items2
Obfuscated Files or Information
DCSync25
System Information Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
DLL Side-Loading
Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
cylanceprotectsetupwithoptics.exe0%ReversingLabs
cylanceprotectsetupwithoptics.exe0%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dll0%ReversingLabs
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dll0%VirustotalBrowse
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dll0%ReversingLabs
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dll0%VirustotalBrowse
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Microsoft.Deployment.WindowsInstaller.dll0%ReversingLabs
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Microsoft.Deployment.WindowsInstaller.dll0%VirustotalBrowse
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbahost.dll0%ReversingLabs
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbahost.dll0%VirustotalBrowse
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbapreq.dll0%ReversingLabs
C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbapreq.dll1%VirustotalBrowse
C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe0%ReversingLabs
C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor0%URL Reputationsafe
http://appsyndication.org/2006/appsyn0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://wixtoolset.org/schemas/thmutil/2010mbapreq.thm.2.drfalse
    high
    http://foo/bar/mainview.bamlcylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpfalse
      low
      http://foo/bar/mainview.bamldcylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpfalse
        low
        http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/vcylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr, Microsoft.Deployment.WindowsInstaller.dll.2.drfalse
          high
          http://wixtoolset.org/cylanceprotectsetupwithoptics.exefalse
            high
            http://wixtoolset.org/telemetry/vcylanceprotectsetupwithoptics.exefalse
              high
              http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgorcylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe.1.drfalse
              • URL Reputation: safe
              unknown
              http://wixtoolset.org/news/cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr, Microsoft.Deployment.WindowsInstaller.dll.2.drfalse
                high
                http://foo/mainview.xamlcylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpfalse
                  low
                  http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namecylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    http://defaultcontainer/Cylance.Host.Installer.CustomBootstrapperWithOptics;component/resources/instcylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpfalse
                      low
                      http://foo/resources/installerBannerProtect.bmpcylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpfalse
                        low
                        http://appsyndication.org/2006/appsyncylanceprotectsetupwithoptics.exefalse
                        • URL Reputation: safe
                        unknown
                        http://defaultcontainer/Cylance.Host.Installer.CustomBootstrapperWithOptics;component/mainview.xamldcylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmpfalse
                          low
                          No contacted IP infos
                          Joe Sandbox version:40.0.0 Tourmaline
                          Analysis ID:1426789
                          Start date and time:2024-04-16 16:16:16 +02:00
                          Joe Sandbox product:CloudBasic
                          Overall analysis duration:0h 6m 31s
                          Hypervisor based Inspection enabled:false
                          Report type:full
                          Cookbook file name:default.jbs
                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                          Number of analysed new started processes analysed:12
                          Number of new started drivers analysed:0
                          Number of existing processes analysed:0
                          Number of existing drivers analysed:0
                          Number of injected processes analysed:0
                          Technologies:
                          • HCA enabled
                          • EGA enabled
                          • AMSI enabled
                          Analysis Mode:default
                          Analysis stop reason:Timeout
                          Sample name:cylanceprotectsetupwithoptics.exe
                          Detection:CLEAN
                          Classification:clean10.winEXE@3/35@0/0
                          EGA Information:
                          • Successful, ratio: 100%
                          HCA Information:
                          • Successful, ratio: 100%
                          • Number of executed functions: 136
                          • Number of non-executed functions: 255
                          Cookbook Comments:
                          • Found application associated with file extension: .exe
                          • Exclude process from analysis (whitelisted): dllhost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
                          • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                          • Report size exceeded maximum capacity and may have missing disassembly code.
                          No simulations
                          No context
                          No context
                          No context
                          No context
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbahost.dllInstantInvoice.exeGet hashmaliciousUnknownBrowse
                            InstantInvoice (1).exeGet hashmaliciousUnknownBrowse
                              C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Microsoft.Deployment.WindowsInstaller.dllavira_ru_vpnb0_189130201-1648227182__pvpnws.exeGet hashmaliciousUnknownBrowse
                                C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dllInstantInvoice.exeGet hashmaliciousUnknownBrowse
                                  InstantInvoice (1).exeGet hashmaliciousUnknownBrowse
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):4759
                                    Entropy (8bit):5.449828731919388
                                    Encrypted:false
                                    SSDEEP:96:NVrlXf90zqkyrC1EMjxOVctz7zhZ9Fto0:LlXfezqkBEMjxOVctz7zhHFX
                                    MD5:08DBCD484B726835209E5BE0DF4B242A
                                    SHA1:795770CCB41268C21A53468214166ECE755BFCAD
                                    SHA-256:A25B411A0A8ABE78F81415044305D731C5853739021CBB7CCE60447D8260A45F
                                    SHA-512:0D10A291B94F7B59C72B2D1ACAD7CBC64C1B85D158D165EE3B39C4CF13F01C00339EB6B0D508D6E972370CC4F03227D08ECC7F7C5F938375EE9E960904CAA68C
                                    Malicious:false
                                    Reputation:low
                                    Preview:[03FC:156C][2024-04-16T16:17:11]i001: Burn v3.10.4.4718, Windows v10.0 (Build 19045: Service Pack 0), path: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe..[03FC:156C][2024-04-16T16:17:11]i000: Initializing string variable 'PIDKEY' to value ''..[03FC:156C][2024-04-16T16:17:11]i000: Initializing numeric variable 'LAUNCHAPP' to value '1'..[03FC:156C][2024-04-16T16:17:11]i000: Initializing numeric variable 'SELFPROTECTIONLEVEL' to value '2'..[03FC:156C][2024-04-16T16:17:11]i000: Initializing numeric variable 'DATAPRIVACY' to value '0'..[03FC:156C][2024-04-16T16:17:11]i000: Initializing numeric variable 'UIMODE' to value '0'..[03FC:156C][2024-04-16T16:17:11]i000: Initializing numeric variable 'QUARANTINEDISPOSETYPE' to value '0'..[03FC:156C][2024-04-16T16:17:11]i000: Initializing string variable 'APPFOLDER' to value ''..[03FC:156C][2024-04-16T16:17:11]i000: Initializing string variable 'STATICURLS' to value ''..[03FC:156C][2024-04-16T16:17:11]i
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2025
                                    Entropy (8bit):6.231406644010833
                                    Encrypted:false
                                    SSDEEP:48:cxX7DTAT8tMBCus9T3FVWmHdniarRFeOrw8Nhv2VyfN3mKNWFP44SBWWW1GyfiPq:8L4T2RJhfHP8+VYuTmQUc2mE
                                    MD5:1D4B831F77EFEC96FFBC70BC4B59B8B5
                                    SHA1:1B3ED82655AEC8A52DAEC60F8674BC7E07F8CFEB
                                    SHA-256:1B93556F07C35AC0564D57E0743CCBA231950962C6506C8D4A74A31CD66FD04C
                                    SHA-512:C6CCB188281F161DEBF02DCDDE24B77D8D14943DEED8852E77E5AFB18F3F62683AB1AE06DCEB1E09D53804A76DF6400A360712D8E7E228B7F971054BB4FB2496
                                    Malicious:false
                                    Reputation:moderate, very likely benign file
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="zh-tw" Language="1028" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] ....</String>.. <String Id="Title">[WixBundleName] ...... Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">.......?</String>.. <String Id="HelpHeader">......</String>.. <String Id="HelpText">/passive | /quiet - ...... UI ............ UI ... ........... UI ........../norestart - ................UI ............./log log.txt - ............ %TEMP% ......</String>.. <Stri
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2458
                                    Entropy (8bit):5.36165936198009
                                    Encrypted:false
                                    SSDEEP:48:cxX7DTZT8u9cktosM6re4mSTcIIyfI7sh/DMNwIHWAoN3mepNRfKPnWZ0hqAQZfC:8LxTK23f33AwIViRrRynRuZfiMS
                                    MD5:CC8C6D04DC707B38E0F0C08BA16FE49B
                                    SHA1:95EA7F570677AEA52393D02FDB21CEBB218A7343
                                    SHA-256:DC445E2457ED31ABF536871F90FF7CC96800A40B6BC033F37D45E3156A3B4FA9
                                    SHA-512:A4B19EBC8BB0D88ABA7D3D5783E28F8B6E0960582A540059BC71076B1203BF43BCA15EA726272D15395C7B4E431046ADA1CBB9D55072BBC5DBE7729C4599F0E0
                                    Malicious:false
                                    Reputation:moderate, very likely benign file
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="cs-cz" Language="1029" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Instalace produktu [WixBundleName]</String>.. <String Id="Title">Pro instalaci produktu [WixBundleName] je vy.adov.no rozhran. Microsoft .NET Framework.</String>.. <String Id="ConfirmCancelMessage">Opravdu chcete akci zru.it?</String>.. <String Id="HelpHeader">N.pov.da k instalaci</String>.. <String Id="HelpText">/passive | /quiet - Zobraz. minim.ln. u.ivatelsk. rozhran. bez jak.chkoli.. v.zev, nebo nezobraz. ..dn. u.ivatelsk. rozhran. ani ..dn. v.zvy. Ve v.choz.m.. nastaven. se jak u.ivatelsk. rozhran., tak i v.echny v.zvy zobrazuj....../norestart - Potla.. jak.koli p
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2286
                                    Entropy (8bit):5.061915970731254
                                    Encrypted:false
                                    SSDEEP:48:cxX7DCrT81tbzjamsjFq7LhzqGgdRDJNbqoN3mpN+ELPnfyOwYxPyzraXnAF:8LaTOkaEOiGd/BwF
                                    MD5:7C6E4CE87870B3B5E71D3EF4555500F8
                                    SHA1:E831E8978A48BEAFA04AAD52A564B7EADED4311D
                                    SHA-256:CAC263E0E90A4087446A290055257B1C39F17E11F065598CB2286DF4332C7696
                                    SHA-512:2A02415A3E5F073F4530FD87C97B685D95B8C0E1B15EFD185CC5CB046FCF1D0DCE28DB9889AD52588B96FE01841A7A61F6B7D6D2F669EAB10A8926C46B8E93D1
                                    Malicious:false
                                    Reputation:moderate, very likely benign file
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="da-dk" Language="1030" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Installation af [WixBundleName]</String>.. <String Id="Title">Microsoft .NET Framework skal v.re installeret i forbindelse med Installationen af [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Er du sikker p., at du vil annullere?</String>.. <String Id="HelpHeader">Hj.lp til installation</String>.. <String Id="HelpText">/passive | /quiet - viser en minimal brugergr.nseflade uden prompter eller.. viser ingen brugergr.nseflade og ingen prompter... Brugergr.nsefladen og alle prompter vises som standard...../norestart - skjuler fors.g p. genstart. Der vises som standard en.. foresp.rgse
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2442
                                    Entropy (8bit):5.094465051245675
                                    Encrypted:false
                                    SSDEEP:48:cxX7DASTcCwit/soJy9hkVByUZN+29N3mfN65PS9CvZwZi7uuASD:8LxT8itGeVB97+gyC9BdaSD
                                    MD5:C8E7E0B4E63B3076047B7F49C76D56E1
                                    SHA1:4E44E656A0D552B2FFD65911CB45245364E5DBF3
                                    SHA-256:631D46CB048FB6CF0B9A1362F8E5A1854C46E9525A0260C7841A04B2316C8295
                                    SHA-512:FD7E8896F9414F0DB7A88F926F55EE24E0591DA676F330200BC6BB829EB32648D90D3094E0011BFE36C7BA8BE41DFD74B12D444AFEA0D2866801258DA4FA16E8
                                    Malicious:false
                                    Reputation:moderate, very likely benign file
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="de-de" Language="1031" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <UI Control="InstallButton" Width="180" />.. .. <String Id="Caption">[WixBundleName]-Setup</String>.. <String Id="Title">F.r das [WixBundleName]-Setup ist Microsoft .NET Framework erforderlich.</String>.. <String Id="ConfirmCancelMessage">Sind Sie sicher, dass Sie den Vorgang abbrechen m.chten?</String>.. <String Id="HelpHeader">Setup-Hilfe</String>.. <String Id="HelpText">/passive | /quiet - zeigt eine minimale Benutzeroberfl.che ohne.. Eingabeaufforderungen oder keine Benutzeroberfl.che und keine.. Eingabeaufforderungen an. Standardm..ig werden die Benutzeroberfl.che und.. alle Eingabeaufforderungen angezeigt...../no
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):3400
                                    Entropy (8bit):5.279888750092028
                                    Encrypted:false
                                    SSDEEP:48:cxX7D8jVT8dUk9Ug/usOo2pNSBIbESvR2drdESPzghC76DeN2hL0eLoN3mOLSNIx:8L45TCyop5riGzH7xgJit8IqSsBwqk
                                    MD5:074D5921AF07E6126049CB45814246ED
                                    SHA1:91D4BDDA8D2B703879CFE2C28550E0A46074FA57
                                    SHA-256:B8E90E20EDF110AAAAEA54FBC8533872831777BE5589E380CFDD17E1F93147B5
                                    SHA-512:28DAC36516BCC76BCC598C6E7ABDE359695F85AB7A830D6ADBC844EB240D9FA372CB5A5CE4DBE21E250408C6B246D371D3CDD656D2178FB0EC22DAC7D39CBD9F
                                    Malicious:false
                                    Reputation:moderate, very likely benign file
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="el-gr" Language="1032" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">........... ... [WixBundleName]</String>.. <String Id="Title">... ... ........... ... [WixBundleName] .......... .. Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">..... ....... ... ...... .. ..... .......;</String>.. <String Id="HelpHeader">....... ... ... ...........</String>.. <String Id="HelpText">/passive | /quiet - ......... ........ ........... ... ............. .......... ...... ..... ........ . ... ..
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2235
                                    Entropy (8bit):5.142592159444541
                                    Encrypted:false
                                    SSDEEP:48:cxX7DE+T8Z+bm5snwETMAoQEATN27uNBDReq4N3mJeNHNP64NsFKJJem4vyAs:8LZTDkZ7+2IBCht6J8neHs
                                    MD5:E338408F1101499EB22507A3451F7B06
                                    SHA1:83B42F9D7307265A108FC339D0460D36B66A8B94
                                    SHA-256:B7D9528F29761C82C3D926EFE5E0D5036A0E0D83EB4CCA7282846C86A9D6F9F3
                                    SHA-512:F7BE923DC2856E0941D0669E2DE5A5C307C98DC7EBA0A1B68728EB29C95B4625145C2AD3AC6F6B6D82F062887EA349E2187F1F91785DDE5A5083BC1150E56326
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="fi-fi" Language="1035" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] -asennus</String>.. <String Id="Title">Microsoft .NET Framework tarvitaan [WixBundleName] -asennusta varten</String>.. <String Id="ConfirmCancelMessage">Haluatko varmasti peruuttaa?</String>.. <String Id="HelpHeader">Asennusohjelman ohje</String>.. <String Id="HelpText">/passive | /quiet - n.ytt.. mahdollisimman v.h.n k.ytt.liittym.st.; ei.. kehotteita tai ei k.ytt.liittym.. ja kehotteita. Oletusarvoisesti.. k.ytt.liittym. ja kaikki kehotteet n.ytet..n...../norestart - est.. uudelleenk.ynnistysyritykset. Oletusarvoisesti.. k.ytt.liittym. kysyy ennen uudelleenk.yn
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2306
                                    Entropy (8bit):5.076293283609686
                                    Encrypted:false
                                    SSDEEP:48:cxX7DyBT81BbKBswAL1xV1wjRcDSNwDXoN3mSZfNhkLPkQpznsdMEodAY:8LwTK5KHsijmEXY
                                    MD5:AA32A059AADD42431F7837CB1BE7257F
                                    SHA1:4CD21661E341080FB8C2DEFD9F32F134561FC3BA
                                    SHA-256:88E7DDACD6B714D94D5322876BD50051479B7A0C686DC2E9EB06B3B7A0BC06C9
                                    SHA-512:78E201F369E65535E25722DFC0EFE99EDF641F7C14EFF1526DC1CC047FF11640079F1E3D25C9072CF25F4804195891BE006FC5ED313063AFCB91FB5700120B88
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="fr-fr" Language="1036" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Installation de [WixBundleName]</String>.. <String Id="Title">Microsoft .NET Framework requis pour l'installation de [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">.tes-vous s.r de vouloir annuler.?</String>.. <String Id="HelpHeader">Aide de l'installation</String>.. <String Id="HelpText">/passive | /quiet - affiche une interface minimale sans invites ou n'affiche.. aucune interface ni aucune invite. Par d.faut, l'interface et toutes les.. invites sont affich.es...../norestart - annule toute tentative de red.marrage. Par d.faut, l'interface.. affiche une invite avant de red.marrer..
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2392
                                    Entropy (8bit):5.293225307744296
                                    Encrypted:false
                                    SSDEEP:48:cxX7DwzT8cSwvs48mF7GD/g1v0wH7N3wwJxL99oN3m/ZNRUYPBZRT1XESW3o/ULG:8LQT2wpFGbgT3wMN2QRj/y/LKr
                                    MD5:17FB605A2F02DA203DF06F714D1CC6DE
                                    SHA1:3A71D13D4CCA06116B111625C90DD1C451EA9228
                                    SHA-256:55CF62D54EFB79801A9D94B24B3C9BA221C2465417A068950D40A67C52BA66EF
                                    SHA-512:D05008D37143A1CC031F4B6268490A5A10FBB686C86984D20DB94843BDC4624EF9651D158DCB5B660FC239C3C3E8D087EB5D23FFFB8C4681910CBC376148F0F0
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="hu-hu" Language="1038" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] telep.t.</String>.. <String Id="Title">A(z) [WixBundleName] telep.t.s.hez Microsoft .NET-keretrendszer sz.ks.ges</String>.. <String Id="ConfirmCancelMessage">Biztosan megszak.tja?</String>.. <String Id="HelpHeader">A telep.t. s.g.ja</String>.. <String Id="HelpText">/passive | /quiet - Minim.lis felhaszn.l.i fel.let megjelen.t.se k.rd.sek.. n.lk.l, illetve felhaszn.l.i fel.let .s k.rd.sek megjelen.t.se n.lk.li.. telep.t.s. Alapesetben a felhaszn.l.i fel.let .s minden k.rd.s megjelenik...../norestart - Az .jraind.t.si k.r.sek elrejt.se. Alapeset
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2304
                                    Entropy (8bit):4.985260685429469
                                    Encrypted:false
                                    SSDEEP:48:cxX7DQyT81ebRcesyB+lY25ukVpkXJM2DJNXhpXZoN3mMhNTM+POYO/n1YxXlcI5:8LFTzLtkfwWKXHZi37MIDp
                                    MD5:50261379B89457B1980FF19CFABE6A08
                                    SHA1:F80B1F416539D33206CE3C24BA3B14B799A84813
                                    SHA-256:A40C94EB33F8841C79E9F6958433AFFD517F97B4570F731666AF572E63178BB7
                                    SHA-512:BBD9794181EEC95D6BE7A1B7BA83FD61AF2B2DF61D9DA8DDA2788B61BEC53C30FCEFE5222EDF134166532B36D3AB6CE8996F2D670DC6907C1864AF881A21EA40
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="it-it" Language="1040" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Installazione di [WixBundleName]</String>.. <String Id="Title">Microsoft .NET Framework necessario per l'installazione di [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Annullare?</String>.. <String Id="HelpHeader">Guida dell'installazione</String>.. <String Id="HelpText">/passive | /quiet - visualizza l'interfaccia utente minima senza istruzioni.. oppure non visualizza n. l'interfaccia utente n. le istruzioni. Per.. impostazione predefinita vengono visualizzate interfaccia utente e.. istruzioni...../norestart - elimina eventuali tentativi di riavvio. Per impostazione.. predefinita l'int
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2545
                                    Entropy (8bit):5.923292576429967
                                    Encrypted:false
                                    SSDEEP:48:cxX7DpcYT86WyscLpTIFw6tnOUjsj/D3NIgHcQN3mKN/WPOhT0SXsDay+z8QZEcE:8L1TccOFw6tnOUjsjpICnlOO934apWz
                                    MD5:DB0F5BAB42403FD67C0A18E35E6880EC
                                    SHA1:C0A18C8C5BCD7B88C384B5304B56EEB85A0DA3DC
                                    SHA-256:CCDCDB111EFA152C5F9FF4930033698B843390A549699AE802098D87431F16FE
                                    SHA-512:589522BD4A26BF54CCF3564E392E41BBBA4E7B3FD1ED74E7F4F6AD6F2E65CDE11FFF32D0C5F3BCD09052FE5110FDC361D1926E220FD0BAD2D38CAC21BBE93211
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="ja-jp" Language="1041" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] ......</String>.. <String Id="Title">[WixBundleName] ........ Microsoft .NET Framework .....</String>.. <String Id="ConfirmCancelMessage">.......?</String>.. <String Id="HelpHeader">..........</String>.. <String Id="HelpText">/passive | /quiet - ... UI ....................UI.. .............. .....UI ....................../norestart - ........................
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2236
                                    Entropy (8bit):5.97627825234954
                                    Encrypted:false
                                    SSDEEP:48:cxX7D3sT8ZeusKOwOWGyKCstFmhENI2Y+kN3mp4iNmi6IPa0dDaoIunvZqIHU5UH:8LQTXvRFhIzl44wmgko04U5TY
                                    MD5:442F8463EF5CA42B99B2EFACA696BD01
                                    SHA1:67496DB91CBAA85AC0727B12FC2D35E990537DAC
                                    SHA-256:D22F6ADA97DBFFC1E7548E52163807F982B30B11A2A5109E71F42985102CCCBD
                                    SHA-512:A350EAF9E7AEAFAB1163D7C0B8D014AFE07EE98BAE3915CBDD3C26282E345A0838E853C89BAE8943474758DCBCFD0BB0724A0C75CBF969F321FAB4944E8704FD
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="ko-kr" Language="1042" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] ..</String>.. <String Id="Title">[WixBundleName] ... ... Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">........?</String>.. <String Id="HelpHeader">.. ...</String>.. <String Id="HelpText">/passive | /quiet - ... .. .. UI. ..... UI. .... .... .... ..... ..... UI . .. .... ........../norestart - .. ..... ... ...... ..... UI. .. .... .. .... ......../log log.txt - .
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2312
                                    Entropy (8bit):4.965432037520827
                                    Encrypted:false
                                    SSDEEP:48:cxX7DK1T8u7hbU7Asd7MqpSwzCcHGFN9OsNN3mvoNBC7hPFtO7+xw7t0Yza2Al:8LcTtpGLFSwJHmPnnKhEBtsl
                                    MD5:67F28BCDB3BA6774CD66AA198B06FF38
                                    SHA1:85D843B7248A5E1173FF9BD59CB73BB505F69B66
                                    SHA-256:226B778604236931B4AE45F6F272586C884A11517444A34BF45CD5CAE49BE62E
                                    SHA-512:7BC7D3E6E19ECF865B2CABFC46C75D516561D5A8A81A8ED55B4EDBA41A13A7110F474473740200AFB035B9597A2511D08C2A2E7A9ADE2C2AB4D3F168944B8328
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="nl-nl" Language="1043" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Installatie</String>.. <String Id="Title">Microsoft .NET Framework is vereist voor installatie [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Weet u zeker dat u de installatie wilt annuleren?</String>.. <String Id="HelpHeader">Help bij Setup</String>.. <String Id="HelpText">/passive | /quiet - geeft een minimale gebruikersinterface weer zonder prompts.. of geeft geen gebruikersinterface en geen prompts weer. Gebruikersinterface.. en alle prompts worden standaard weergegeven...../norestart - pogingen tot opnieuw opstarten onderdrukken... Gebruikersinterface vraagt standaard al
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2171
                                    Entropy (8bit):5.089922193759582
                                    Encrypted:false
                                    SSDEEP:48:cxX7DTeT8uUbnFdsLnFHv+Gpm1qL5DQNDDaoN3mpZfN15dPnfuOOg5wZ5uAq8fAS:8L+Tec1x8Siule4S
                                    MD5:5454F724C9CDAB8172678A1CC7057220
                                    SHA1:241A57018ACE1210881583A9CF646E7D2E51412F
                                    SHA-256:41545AC1247B61C3C3E2A7E4659D9FAD2BCCA8347C69F2EB7B9D0CF5FC31E113
                                    SHA-512:40E311EADA299996E32A7D35223CA678A03C869D63C023D59BC97A7B2049B0252AA9D0A7EC8558D5ACB73BD14C7BFA913097E65ABEE7455658DB7E35BBDA8AE1
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="nb-no" Language="1044" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Installasjonsprogram</String>.. <String Id="Title">Microsoft .NET Framework kreves for [WixBundleName]-installasjon</String>.. <String Id="ConfirmCancelMessage">Er du sikker p. at du vil avbryte?</String>.. <String Id="HelpHeader">Installasjonshjelp</String>.. <String Id="HelpText">/passive | /quiet - viser minimalt brukergrensesnitt uten ledetekster, eller.. ikke noe brukergrensesnitt og ingen ledetekster. Som standard vises.. brukergrensesnitt og alle ledetekster...../norestart - undertrykker alle fors.k p. omstart. Som standard sp.r.. brukergrensesnittet f.r omstart.../log log.txt
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2368
                                    Entropy (8bit):5.270514043715206
                                    Encrypted:false
                                    SSDEEP:48:cxX7Du4OT82gXusarwkfpYrKD8DTNkbNuoN3mjbsNniIPh8ynN1NYd4iYuffAL:8LKTsXgpYr2IyoiiOffpT3L
                                    MD5:96ACAAA5AEF7798E9048BAFF4C3FA8D3
                                    SHA1:E76629973F6C1CFC06F60BA64FE9F237B2DB9698
                                    SHA-256:F4AA983E39FB29C95E3306082F034B3A43E1D26489C997B8E6697B6A3B2F9F3C
                                    SHA-512:964F73E572BDCB1AD946C770E6A2FB4A1CE54AF4B5BB072F64256083BA27A223F4DAD4A95B9D2A646180806D1F977726147970B06AAC35EED75AEC6CA89ED337
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="pl-pl" Language="1045" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Instalator programu [WixBundleName]</String>.. <String Id="Title">Do zainstalowania programu [WixBundleName] jest wymagany program Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">Czy na pewno chcesz anulowa.?</String>.. <String Id="HelpHeader">Pomoc instalatora</String>.. <String Id="HelpText">/passive | /quiet - wy.wietla minimalny interfejs u.ytkownika bez monit.w.. lub nie wy.wietla interfejsu u.ytkownika ani monit.w. Domy.lnie jest.. wy.wietlany interfejs u.ytkownika i wszystkie monity...../norestart - pomija wszelkie pr.by ponownego uruchomienia. Domy.lnie.. interf
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2147
                                    Entropy (8bit):5.130635342194656
                                    Encrypted:false
                                    SSDEEP:48:cxX7DuoT85b0s/4TDoYDj4NF5j2hN3mMNYskPDXKIMaKcP9A5g:8L1TmBHjs59M8r6
                                    MD5:BD39ADB6B872163FD2D570028E9F3213
                                    SHA1:688B8A109688D3EA483548F29DE2E57A8A56C868
                                    SHA-256:ECB5C22E6C2423CAF07AEBE69F4FAF22450164EEE9587B64EF45A2D7F658CA15
                                    SHA-512:F2826BE203E767D09FF0D7677E1CF5B13113B773D529166DAE02A1F5DB2DC58E0856A34901DF70011EBABB6E964FAB7ACF38590E650BD629D4E4DC4CB36C8D45
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="pt-br" Language="1046" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Instala..o</String>.. <String Id="Title">Microsoft .NET Framework . necess.rio para instala..o do [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Tem certeza de que deseja cancelar?</String>.. <String Id="HelpHeader">Ajuda da Instala..o</String>.. <String Id="HelpText">/passive | /quiet - exibe UI m.nima sem avisos ou exibe sem UI e.. sem avisos. Por padr.o a UI e todos avisos s.o exibidos...../norestart - suprime qualquer tentativa de reinicializa..o. Por padr.o a UI.. ir. solicitar antes de reiniciar.../log log.txt - logs para um arquivo espec.fico. Por padr.
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2880
                                    Entropy (8bit):5.408094213063887
                                    Encrypted:false
                                    SSDEEP:48:cxX7DkTT8fjtEeusogrohY2Ar7DHNnjTh53oN3miRMNKrdPin+/uYcbSkuEIcOvG:8LYT8EeHMMJRNi1Ruwi3OwL
                                    MD5:DAF167AF4031EF47E562056A7D51AA73
                                    SHA1:0156B230CADD6169AC2820865E3C031ED79785EF
                                    SHA-256:C91C9E87AB4A6DB078F1991F4A2CDC726B58A40E47BCE49D39168A8F8F151C3B
                                    SHA-512:5E87EE3838E3595ADBD7EABA6E3E33CDFEA5E15ED716FBCCDBD55235B3E53E1E41EA5A907F425E96C35167543C7F75AC5214B5AEE177D299FC2464A68B22851E
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="ru-ru" Language="1049" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">......... [WixBundleName]</String>.. <String Id="Title">... ......... [WixBundleName] ......... Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">.. ............. ...... ........ ........?</String>.. <String Id="HelpHeader">....... .. .........</String>.. <String Id="HelpText">/passive | /quiet - ........... ............ .. ... ........ ... ...... ... .. .. . ............ .. ......... ............ .. . ... ......
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2334
                                    Entropy (8bit):5.397882326481071
                                    Encrypted:false
                                    SSDEEP:48:cxX7D+cT8muPusz2qs1u+Vh1TqDINHZJoN3m8fN0vPp3OAwa2ywSODAm:8L1TuPdKNzfifFmcatm
                                    MD5:016C278E515F87F589AD22C856B201F7
                                    SHA1:F20C7DB38B3161B143DEC4E578CE71D7F585F436
                                    SHA-256:4A7FDF4A9033FE05C31F565ED3AE5B8C67D324B7AEADB737CE95DBB416D46868
                                    SHA-512:310C85B27E1ECF4C6729E88051037150CFBA0234A0138666C26662B3D665FF38B74E95ABCADDEEF6CBEBB23E3357FAC487E6EE5EB8FE158C269D77672191B042
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="sk-sk" Language="1051" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] . in.tal.cia</String>.. <String Id="Title">Na in.tal.ciu aplik.cie [WixBundleName] sa vy.aduje s..as. Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">Naozaj chcete zru.i. oper.ciu?</String>.. <String Id="HelpHeader">Pomocn.k pre in.tal.ciu</String>.. <String Id="HelpText">/passive | /quiet . zobraz. minim.lne pou..vate.sk. rozhranie bez v.ziev alebo.. nezobraz. .iadne pou..vate.sk. rozhranie ani v.zvy. Predvolene sa.. zobrazuje pou..vate.sk. rozhranie aj v.etky v.zvy...../norestart . zru.. v.etky pokusy o re.tart. Pou..vate
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2132
                                    Entropy (8bit):5.1255014007111495
                                    Encrypted:false
                                    SSDEEP:48:cxX7DviT8NFLbu9sM2vECjf26axBZYXcqADCNKTbkoN3maT6NWOjEXPauOOKYnhf:8LmTAcRnQXFPK0iHMsfb2Ws3M
                                    MD5:D95E81164C57B6FD75E7C3022454192E
                                    SHA1:5D5ACBC56E7078AF4D04C45B78C0FF090C02EE6A
                                    SHA-256:6DD61CC6B87B53EAF28430068A2A459730FD4B2BCF876CCDF040212D04C4FE7D
                                    SHA-512:9E4BA81A145574818DD6A1F1D0EC38EA1629C7771919C35923F440E31EA9912E1630D94FCDB82B71104EBD61D0321DCDF935BA20D69988EE6E9B22259186AF0C
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="sv-se" Language="1053" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName]-installation</String>.. <String Id="Title">Microsoft .NET Framework kr.vs f.r installation av [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Vill du avbryta?</String>.. <String Id="HelpHeader">Installationshj.lp</String>.. <String Id="HelpText">/passive | /quiet - visar ett minimalt anv.ndargr.nssnitt utan prompter,.. alternativt inget anv.ndargr.nssnitt och inga prompter. Som standard visas.. anv.ndargr.nssnitt och samtliga prompter...../norestart - hejdar omstart. Som standard visar anv.ndargr.nssnittet en.. prompt f.re omstart.../log log.txt - skapar logg till
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2303
                                    Entropy (8bit):5.2754753523795275
                                    Encrypted:false
                                    SSDEEP:48:cxX7DNcYT8anOSMsHEqGpcBztpvrJlrs2ZmNI2+Yo6irN3m22NFcPc+4Trzrdgc7:8LZHTE7APaTI9sq6yEbgg
                                    MD5:01B200E06BA600A4EF00C00F7AAC5CE4
                                    SHA1:22234426C42637E069A46217019551E4434A4AB6
                                    SHA-256:06BFB6DFBC38105C699DEA226A029DF3EF673C33E4B8928DC4EC7FB8F761487D
                                    SHA-512:8BDCF7533A6BCFA231B42A7EF845A70C7535FBF607D62FF6404928D5941BA6AFBF139450A1A1B58C65FACF88DC0785AEC4ABEFBCC803466A58B1930F7C468CDD
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="tr-tr" Language="1055" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Kurulumu</String>.. <String Id="Title">[WixBundleName] kurulumu i.in Microsoft .NET Framework gerekir</String>.. <String Id="ConfirmCancelMessage">.ptal etmek istedi.inizden emin misiniz?</String>.. <String Id="HelpHeader">Kurulum Yard.m.</String>.. <String Id="HelpText">/passive | /quiet - komut istemi olmayan olabildi.ince k...k bir UI.. g.r.nt.ler veya komut istemi ve UI g.r.nt.lemez. Varsay.lan olarak UI.. ve t.m komut istemleri g.r.nt.lenir...../norestart - yeniden ba.latma denemelerini engeller. Varsay.lan.. olarak UI yeniden ba.latmadan .nce komut isteyecekt
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2200
                                    Entropy (8bit):5.1485120966265
                                    Encrypted:false
                                    SSDEEP:48:cxX7DZ0T8obZsw9g5gS56K97D7NCt2VoN3mQXNJPOhP58vqc1qwueo3RAL:8LyTLlS9h9hCtsihdxOh+NL
                                    MD5:5836F0C655BDD97093F68AAF69AB2BAB
                                    SHA1:B6842E816F9E0DCC559A5692E4D26101D10B4B16
                                    SHA-256:C015247D022BDC108B4FFCAE89CB55D1E313034D7E6EED18744C1BB55F108F8C
                                    SHA-512:640A79D6A756E591AD02DDCCC53BC43F855C5148B8CBB5CE6C1CAF5419CA02F7B2AFF89CCA4C056356814D3899EF79BF038B4E8B4B79EB85138A3CEDCCE93E5B
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="sl-si" Language="1060" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Namestitev</String>.. <String Id="Title">Microsoft .NET Framework, potreben za namestitev paketa [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Ali ste prepri.ani, da .elite preklicati?</String>.. <String Id="HelpHeader">Pomo. za namestitev</String>.. <String Id="HelpText">/passive | /quiet - prika.e minimalni uporabni.ki vmesnik brez pozivov ali ne prika.e.. uporabni.kega vmesnika in pozivov. Privzeto so prikazani uporabni.ki vmesnik in.. vsi pozivi...../norestart - skrije vse mo.nosti za vnovicni zagon. Privzeto uporabni.ki vmesnik.. prika.e poziv pred ponovnim zag
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):1980
                                    Entropy (8bit):6.189594519053644
                                    Encrypted:false
                                    SSDEEP:48:cxX7DjQT8tOBousi+zq+frUR2ropNV2rfN3msNUqPPT9T+DwZ9f5wDTAV:8L4TGUGw3V8N3RykV
                                    MD5:A34DCF7771198C779648B89156483E83
                                    SHA1:A6E0FA91CD50048511C7BEF1BE3A8D32B42B6D1F
                                    SHA-256:89C559C6765F8D643469E3C8F4AA93023F09369B0395EA647FAD5AF3C2893EB6
                                    SHA-512:0F1D7BC4FD64E18EEEC488CDCE01FB6BFA5CD3BFF614A8D03E388D39F569B8341E74302946877EB25BA1EB17AEC137499189605E251FAFB6B20051744CB463B1
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="zh-ch" Language="2052" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] ..</String>.. <String Id="Title">[WixBundleName] .... Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">.......?</String>.. <String Id="HelpHeader">......</String>.. <String Id="HelpText">/passive | /quiet - ..... UI .......... UI ... ........... UI ........../norestart - .............. UI ........../log log.txt - .............. %TEMP% ........</String>.. <String Id="HelpCloseButton"
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2211
                                    Entropy (8bit):5.1155097909395035
                                    Encrypted:false
                                    SSDEEP:48:cxX7DbT8QGls54nK3znI5zKDj4NLkdoN3mMNYsEPbpK2Aegeu9A5g:8LXTUasJnYdi59som6
                                    MD5:8A278E519EF81B2847490EFB070219BC
                                    SHA1:7365EDF6E4F9E66B6CEE47933B6C70FF0B9ECFF8
                                    SHA-256:E2BFDB2CF3BEAE2E988827C52C58006D7EEAD4ABA5312B5EAE1F6CCF3863C385
                                    SHA-512:88275C1136FFB15AB04D315E8601BE2DE77387F3E00F17E9807E415A9DFC4A73E2CD3B5710E4CA58006F91E18180D7CFAEEF4E8319C624E1B81397F9CB9ECA92
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="pt-pt" Language="2070" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Configura..o do [WixBundleName]</String>.. <String Id="Title">O Microsoft .NET Framework . necess.rio para a configura..o do [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Tem a certeza de que pretende cancelar?</String>.. <String Id="HelpHeader">Ajuda da Configura..o</String>.. <String Id="HelpText">/passive | /quiet - apresenta IU m.nima sem mensagens ou n.o apresenta IU nem.. mensagens. Por predefini..o, s.o apresentadas a IU e todas as mensagens...../norestart - suprimir qualquer tentativa de rein.cio. Por predefini..o, a IU.. avisar. antes de reiniciar.../log log.txt - r
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2400
                                    Entropy (8bit):4.992567587099768
                                    Encrypted:false
                                    SSDEEP:48:cxX7DLT8/OusS2V8j4Lq+7dKzCLdqaaD6NJaXFoN3mRNLo3PWKWnRcsB9A8:8LfTz+8EPqKqTJiFikUgk8
                                    MD5:1024AA88AE01BC7BA797193CC6023375
                                    SHA1:9252A309C1CB32573F4D58A595A78660FDF54B2F
                                    SHA-256:B884C4ABB8867553C1FFADD6721C2135EC5F9F1455C3F668D711CCEA65363D1A
                                    SHA-512:77E6DD332104C0461B7C5A08469161AF3F1DC51D3B55585D39DD9FC9E2088DA036BDF2278CFB96CA702FD26CE073C6C6F66611313270700B9E7A76600C1C8E38
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="es-es" Language="3082" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Instalaci.n de [WixBundleName]</String>.. <String Id="Title">La instalaci.n de [WixBundleName] requiere Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">.Est. seguro de que desea cancelar?</String>.. <String Id="HelpHeader">Ayuda del programa de instalaci.n</String>.. <String Id="HelpText">/passive | /quiet - muestra una interfaz de usuario m.nima y no realiza.. preguntas, o bien no muestra interfaz de usuario y no realiza preguntas... De manera predeterminada se muestra la interfaz de usuario completa y se.. realizan todas las preguntas necesarias...../norestart - suprime cu
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (558), with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):11204
                                    Entropy (8bit):3.7621410726526445
                                    Encrypted:false
                                    SSDEEP:192:XstJw/R9VcxuYKhJ2lOYwFKlOP/+IMAdsKM3gpl1z4rwB75:XfRCO2Oi1k5
                                    MD5:52E0225A599446003ABB5BEB5530D709
                                    SHA1:6C1A100CDD61B92CA90E2D13B27D34D2A3351762
                                    SHA-256:231F2A6BEB7F597EFF02CBFF46A192619CB62877D5DCF4A9D0062ED050023176
                                    SHA-512:F02A9C02051486307983C18F79170E5E1F7CAFE485FD35B489F383BDA56A1FF93690A78A41EF88470D05A1E437A9EB96B611A4C1B1C949F6DCE58C9DF086A51F
                                    Malicious:false
                                    Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.w.i.x./.2.0.1.0./.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a.".>..... . .<.W.i.x.B.u.n.d.l.e.P.r.o.p.e.r.t.i.e.s. .D.i.s.p.l.a.y.N.a.m.e.=.".C.y.l.a.n.c.e. .P.R.O.T.E.C.T. .w.i.t.h. .O.P.T.I.C.S.". .L.o.g.P.a.t.h.V.a.r.i.a.b.l.e.=.".W.i.x.B.u.n.d.l.e.L.o.g.". .C.o.m.p.r.e.s.s.e.d.=.".y.e.s.". .I.d.=.".{.f.3.6.7.5.3.d.d.-.6.9.d.c.-.4.8.b.8.-.a.0.e.e.-.b.5.f.e.6.b.7.d.d.a.1.0.}.". .U.p.g.r.a.d.e.C.o.d.e.=.".{.D.2.2.D.1.B.1.D.-.9.5.8.3.-.4.E.2.8.-.9.2.E.1.-.F.2.D.2.6.0.E.9.3.4.F.6.}.". .P.e.r.M.a.c.h.i.n.e.=.".y.e.s.". ./.>..... . .<.W.i.x.M.b.a.P.r.e.r.e.q.I.n.f.o.r.m.a.t.i.o.n. .P.a.c.k.a.g.e.I.d.=.".N.e.t.F.x.4.0.W.e.b.". .L.i.c.e.n.s.e.U.r.l.=.".N.e.t.f.x.L.i.c.e.n.s.e...r.t.f.". ./.>..... . .<.W.i.x.P.a.c.k.a.g.e.P.r.o.p.e.r.t.i.e.s. .P.a.c.k.a.g.e.=.".E.P...w.i.
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):837
                                    Entropy (8bit):4.998326031045003
                                    Encrypted:false
                                    SSDEEP:12:MMHd41Pd7lzc+TXYr+XFy9bWzc+TXYcXII3VymhsS+Qzop9g3XmGCGgXXujDjXRP:Jd67RtYrx9itYhmh9j3WDXiPdN3F
                                    MD5:7FEC4F8A43998BCABBB10BE207DDE83F
                                    SHA1:76F8442CFF5A13BF266C62469ECE7E2869248054
                                    SHA-256:6DB97AB6973D1E3E961FC89900668FC39FE9706F0CE8C42AADF903E6A4CF09C6
                                    SHA-512:F7EE31890F50D9C54C375AB1F8F6DFC6C565CE2803CE0B2DF3E1F2D259527DD2D6F00D5479E3C795483785144B87EB895140643690B557D4B9D904072B3579BC
                                    Malicious:false
                                    Preview:.<?xml version="1.0" encoding="utf-8" ?>..<configuration>.. <configSections>.. <sectionGroup name="wix.bootstrapper" type="Microsoft.Tools.WindowsInstallerXml.Bootstrapper.BootstrapperSectionGroup, BootstrapperCore">.. <section name="host" type="Microsoft.Tools.WindowsInstallerXml.Bootstrapper.HostSection, BootstrapperCore" />.. </sectionGroup>.. </configSections>.. <startup useLegacyV2RuntimeActivationPolicy="true">.. <supportedRuntime version="v4.0" />.. <supportedRuntime version="v2.0.50727"/>.. </startup>.. <wix.bootstrapper>.. <host assemblyName="Cylance.Host.Installer.CustomBootstrapperWithOptics">.. <supportedFramework version="v4\Full" />.. <supportedFramework version="v4\Client" />.. <supportedFramework version="v3.5" />.. </host>.. </wix.bootstrapper>..</configuration>..
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                    Category:dropped
                                    Size (bytes):81920
                                    Entropy (8bit):5.437314391025966
                                    Encrypted:false
                                    SSDEEP:1536:S2VnZ5kJsti1bhBjwYf+GiGKhq+cEFogn:S8Qsti1tpQTJq+cEFoi
                                    MD5:08E1610005BBBEC45BDF744BC93509BE
                                    SHA1:1FAC1E92074DC662DB14F1FCE43D0CA301BCA64C
                                    SHA-256:F8597F37A2687017ED2B33FB06770D47BF7BA672B3E813E611F41B7C79230425
                                    SHA-512:BE9A9D44D068477E8245918505BE041A79E068EBB7BC0DA43695FA9B1D5F26562798E9465C1910A033CE0240BE1A8EEB9E8D7BC24B237E9FF014EC24CF32271F
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    • Antivirus: Virustotal, Detection: 0%, Browse
                                    Joe Sandbox View:
                                    • Filename: InstantInvoice.exe, Detection: malicious, Browse
                                    • Filename: InstantInvoice (1).exe, Detection: malicious, Browse
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0...... ......F.... ...@....... ..............................*R....@..................................-..O....@.......................`.......,............................................... ............... ..H............text...L.... ...................... ..`.rsrc........@....... ..............@..@.reloc.......`.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                    Category:dropped
                                    Size (bytes):121344
                                    Entropy (8bit):2.514616654543185
                                    Encrypted:false
                                    SSDEEP:768:K6w7V5/0sIZnu6mQJLIoDoIaE/8iLv5Eaj+n:K6q5/acqaS8IhEag
                                    MD5:35DFC4020B5867733FFE5465174C1A51
                                    SHA1:EAE3DE772A66F4F2C0370FD2BEDA39EE403B9E0F
                                    SHA-256:6A99FEACD5CBC11BB8BEDF758F796D6DFDCD04DD1A4E377D5CD1241995A495AA
                                    SHA-512:2628AA456987415600CB6E71ACE54A0F3949CA547E60C2A6DCE9C1E393BE7DC06CEBD0C47E0D04074D10FE5F6A40311C5F77498C2858A6F9DD7AFAC4A8041E1B
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    • Antivirus: Virustotal, Detection: 0%, Browse
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...k..`...........!..................... ........... .......................@............@.................................h...S............................ ......0................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H..........hP...........?...]...........................................0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*n.{....,..{......s....o....*..(....*..{....*"..}....*...0...........(......}......o7...(.....{...........s....o.....(...........s....o.....(...........s....o.....(...........s....o.....(...........s ...o!....(...........s"...o#....(...........s$...o%....(...........s&...o'....(...........s(...o)...
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                    Category:dropped
                                    Size (bytes):176128
                                    Entropy (8bit):5.771237461184554
                                    Encrypted:false
                                    SSDEEP:3072:WnY3P0LI23gsAIvvIYttTRsgFGR69UgoXafH9ZCnfKlRUjW01KyM:XDittNER6joKfdU
                                    MD5:345299551A530B716BC4E406377B36A9
                                    SHA1:505BBEE0EB47F5DFCF7FD28A5525390D8D3A4010
                                    SHA-256:9AEBC76CB8C864593E0419162B2BF40B81BD52B3FF12EDAC1D032828DF83DCFA
                                    SHA-512:AC0DC22C0A7CB4A7F6E1D84C928C36ECE28094951DE94DEB3654EFE7D5399A664F1B9A7A95AA3211093A6759409E22BE64153ABB965718A5165F6D25566ECF92
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    • Antivirus: Virustotal, Detection: 0%, Browse
                                    Joe Sandbox View:
                                    • Filename: avira_ru_vpnb0_189130201-1648227182__pvpnws.exe, Detection: malicious, Browse
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0...... ......b.... ........... ...................................@.....................................O................................................................................... ............... ..H............text...hw... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                    Category:dropped
                                    Size (bytes):114688
                                    Entropy (8bit):6.503058663866751
                                    Encrypted:false
                                    SSDEEP:3072:4TyDh12xXnvuxsiHa11b2O+tPB2s0ruPS0BEEiC:4Toh12xXmuN11iC7cJfiC
                                    MD5:64FF2C64FE4FD30CCB8A9C8A0DB806AA
                                    SHA1:73607DACBAB36214943E22CB1FDF6BC5E466D0AE
                                    SHA-256:BBF38F1779A4ACCD152A01B19F296C646F23ABDC43FF3A92D6B17E0120F2271C
                                    SHA-512:860716A2E9C9DC7DDB9145566ED01688FC44A7DF02C95C502BE718785ABD96AECC5C6809D05BDBF0BE5A7C3481452F91EAB878FC4998C4BAD07C4BE08C8D3693
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    • Antivirus: Virustotal, Detection: 0%, Browse
                                    Joe Sandbox View:
                                    • Filename: InstantInvoice.exe, Detection: malicious, Browse
                                    • Filename: InstantInvoice (1).exe, Detection: malicious, Browse
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......k.../../../...U{.&...Uy.Y...Ux.7......>......?......9..&...>../......... ...........u..../.............Rich/..................PE..L......Z...........!.....(..........<>.......@............................... ............@......................... ...........x...............................x.......T...............................@............@...............................text...K&.......(.................. ..`.rdata...q...@...r...,..............@..@.data...D...........................@....gfids..............................@..@.rsrc...............................@..@.reloc..x...........................@..B................................................................................................................................................................................................................................................
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                    Category:dropped
                                    Size (bytes):178176
                                    Entropy (8bit):6.526838192155864
                                    Encrypted:false
                                    SSDEEP:3072:OxoiFK6b0k77I+QfaIl191rSJHvlalB+8BHkY6v53EfcUzN0m6I+WxBlnKzeZu:OxoQNb++gDrSJdr8BHkPh3wIgnK/
                                    MD5:0E2E0DDA2C6B9CABFA99394ACB97B025
                                    SHA1:1EC84920AF81C250B204356D24F435FCA4FA54DD
                                    SHA-256:8271912B7C7616EC04C2C19C608713E03651D91D404715376A1535E72D4BA2D7
                                    SHA-512:79F9CEEA83E93BEDBCB8013205FD55D7A7CB190023CDDEFA01DEE2233EFF9BB6757BFC59DB4422593E8D2B6B77FF3090E03653C5099D7E30C951507946A17A8A
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    • Antivirus: Virustotal, Detection: 1%, Browse
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........3..R...R...R..h.N..R..h.L.R..h.M..R.......R.......R.......R...*<..R...*,..R...R...S..K....R..K....R..N.@..R...R(..R..K....R..Rich.R..................PE..L......Z...........!................d.....................................................@.....................................................................,.......T...............................@...............X............................text............................... ..`.rdata.............................@..@.data...............................@....gfids..............................@..@.rsrc...............................@..@.reloc..,...........................@..B........................................................................................................................................................................................................................................
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:PNG image data, 63 x 63, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):797
                                    Entropy (8bit):7.648767094164769
                                    Encrypted:false
                                    SSDEEP:12:6v/7rW3M/jDYAlFTzdvhKZ7e/cbp4/82UNb6MjmlKPNXheD1H0oJodqSXaTbutak:lQD1lldv8Z7g04/82Y6+Pxi19mDoqt5
                                    MD5:A356956FD269567B8F4612A33802637B
                                    SHA1:75AE41181581FD6376CA9CA88147011E48BF9A30
                                    SHA-256:A401A225ADDAF89110B4B0F6E8CF94779E7C0640BCDD2D670FFCF05AAB0DAD03
                                    SHA-512:A0F7836AEFA1747F481C116F6B085F503B5C09B3A1DD97CD2189F7CE4E6E7EA98F1F66503CBA2E6A83E873248CC7507328710DFA670AA5763DF8AEDCC560285E
                                    Malicious:false
                                    Preview:.PNG........IHDR...?...?.....W_......sRGB.........gAMA......a.....pHYs..........+......IDAThC./W.0....P(...Db+q8$.........J...-..8.e]._..;........Y... .Y....z\........{W|..../q..<%.....C5...0....OrU....,..^........).....2.......i.Ge..T9T..}.7..J.......}..b...S.>.%y..Fc..j.X.....y."...e.U..M(ez....4\..C....u.......w..0..J.Wo."...mM.r.h..8..q..X..k!...j..xn...l...W`..r.+.R..J........c.T.}......cz..<43..@.c..rH...|..V.....K.mN.........k....,..4OL..5..M.tm%=.U.t-7.w....k.R.....c...-].5~..]2..5...GA..[..={.5..].=(.$}.\.9..5...MWu..[#.....F..j.F...d...,..MWu.7..3......$.......G.t.....=;N<_:[......0.,1.y.\.Z.|..%..>}...q.s....y.#p......!-.;.6!o.KO..E.6...........<..c..9_B....y....im...b...Xn.....)t9Q...........V.WMtP. .P..Z.&..KR.ac......IEND.B`.
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):3915
                                    Entropy (8bit):5.15881451198739
                                    Encrypted:false
                                    SSDEEP:48:cecHddpXBT2E/zPHWgtpmAPH8TSJmBP+NPHrM/O8YpQbFUuhJ3PK7usPH4Lr:wHdHxS4Z9UG4BmNjCOhpsB3PswP
                                    MD5:A20778EC90A094A62A6C3A6AB2A6DC7D
                                    SHA1:74C131B5FD80446FFDF2AFAD723762DD36621309
                                    SHA-256:F8C3A03F47F0B9B3C20F0522A2481DA28C77FECDBB302F8DD8FBED87758CBAEA
                                    SHA-512:47F34A9F416D223DCBF071E7292A05554AF3D27CDE67FC8C161C1BED564C6E7FC448C2F482E05F33149C782E09C681BD65730CA00CF9EC68B284128214B75529
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<Theme xmlns="http://wixtoolset.org/schemas/thmutil/2010">.. <Window Width="485" Height="300" HexStyle="100a0000" FontId="0">#(loc.Caption)</Window>.. <Font Id="0" Height="-12" Weight="500" Foreground="000000" Background="FFFFFF">Segoe UI</Font>.. <Font Id="1" Height="-24" Weight="500" Foreground="000000">Segoe UI</Font>.. <Font Id="2" Height="-22" Weight="500" Foreground="666666">Segoe UI</Font>.. <Font Id="3" Height="-12" Weight="500" Foreground="000000" Background="FFFFFF">Segoe UI</Font>.. <Font Id="4" Height="-12" Weight="500" Foreground="ff0000" Background="FFFFFF" Underline="yes">Segoe UI</Font>.... <Image X="11" Y="11" Width="64" Height="64" ImageFile="mbapreq.png" Visible="yes"/>.. <Text X="80" Y="11" Width="-11" Height="96" FontId="1" Visible="yes" DisablePrefix="yes">#(loc.Title)</Text>.... <Page Name="Help">.. <Text X="11" Y="112" Width="-11" Height="30" FontId="2" DisablePrefix="yes">#(loc.HelpHeader
                                    Process:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2363
                                    Entropy (8bit):5.082597499030882
                                    Encrypted:false
                                    SSDEEP:48:cxX7DxMT8dbCsK19Wqq8+JIDxN3Wm2WcN3miNlLPDHXsmkaYXfXQ2BmGA7b1h:8LuTY1xmmmTerNR0ATz
                                    MD5:035FB1B3661CA2FCE4DD6B7151CA34FD
                                    SHA1:D0BDAB5F415A7591276580C7C62D21003E7390A9
                                    SHA-256:97B20444592C26211BABE655D54AE98A9ADDA671382A3F7B90AE62665759FB30
                                    SHA-512:F07B6ED2EEBAF28DE8632F5E7785AC7D49437DE03A19F9F2B69B761590C07DACA2883A69479871CDD16A6041C7E1768C63471146FAC052B24AF207AE0983089B
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="en-us" Language="1033" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Setup</String>.. <String Id="Title">Microsoft .NET Framework required for [WixBundleName] setup</String>.. <String Id="ConfirmCancelMessage">Are you sure you want to cancel?</String>.. <String Id="HelpHeader">Setup Help</String>.. <String Id="HelpText">/passive | /quiet - displays minimal UI with no prompts or displays no UI and.. no prompts. By default UI and all prompts are displayed...../norestart - suppress any attempts to restart. By default UI will prompt before restart.../log log.txt - logs to a specific file. By default a log file is created in %TEMP%.</String>.. <String Id="HelpClos
                                    Process:C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe
                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                    Category:dropped
                                    Size (bytes):967938
                                    Entropy (8bit):7.135106227415395
                                    Encrypted:false
                                    SSDEEP:24576:tMysZgjS1hqgSC/iz+R+Rm2p1F4T3QyyBi:tRjvQo+R+Rlp1WeBi
                                    MD5:796375900C5F33DB332FF8143F243083
                                    SHA1:9BAF9183DF0A5CA02CD49DBE04D99578821B27F7
                                    SHA-256:BAB72DFA7EED0CE4814580312CCBA4FCA4A136F4BB6F93A9F8F9648614D9EC68
                                    SHA-512:BEA24F19BE89A69E8380B73B12CA877C9D87121A3B1C2B684CBB632457F6170B0A51FFE05C1D4CC770616D887DD39450D8ABE5ADCC96DF5F97FC6154CC2EEC1C
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    • Antivirus: Virustotal, Detection: 0%, Browse
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......c...'.u.'.u.'.u.......u.....[.u.....?.u...v.4.u...q.4.u...p...u.....".u....6.u.'.t.v.u...p.l.u....&.u.'..%.u...w.&.u.Rich'.u.........................PE..L......Z............................m.............@.......................................@.............................................p........................=.. t..T...................tt......@n..@...................$........................text.............................. ..`.rdata..............................@..@.data...@...........................@....wixburn8...........................@..@.tls................................@....gfids..............................@..@.rsrc...p...........................@..@.reloc...=.......>..................@..B........................................................................................................................................................
                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                    Entropy (8bit):7.135106227415395
                                    TrID:
                                    • Win32 Executable (generic) a (10002005/4) 99.96%
                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                    • DOS Executable Generic (2002/1) 0.02%
                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                    File name:cylanceprotectsetupwithoptics.exe
                                    File size:967'938 bytes
                                    MD5:796375900c5f33db332ff8143f243083
                                    SHA1:9baf9183df0a5ca02cd49dbe04d99578821b27f7
                                    SHA256:bab72dfa7eed0ce4814580312ccba4fca4a136f4bb6f93a9f8f9648614d9ec68
                                    SHA512:bea24f19be89a69e8380b73b12ca877c9d87121a3b1c2b684cbb632457f6170b0a51ffe05c1d4cc770616d887dd39450d8abe5adcc96df5f97fc6154cc2eec1c
                                    SSDEEP:24576:tMysZgjS1hqgSC/iz+R+Rm2p1F4T3QyyBi:tRjvQo+R+Rlp1WeBi
                                    TLSH:F3259F32782040E5D6B10B736D74A1242D6CBE143B34CD9EB6E8BB5C2BB58D766F3246
                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......c...'.u.'.u.'.u.......u.....[.u.....?.u...v.4.u...q.4.u...p...u.....".u.....6.u.'.t.v.u...p.l.u.....&.u.'...%.u...w.&.u.Rich'.u
                                    Icon Hash:0f0f092b27070e49
                                    Entrypoint:0x42e06d
                                    Entrypoint Section:.text
                                    Digitally signed:false
                                    Imagebase:0x400000
                                    Subsystem:windows gui
                                    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                    Time Stamp:0x5A10A818 [Sat Nov 18 21:37:28 2017 UTC]
                                    TLS Callbacks:
                                    CLR (.Net) Version:
                                    OS Version Major:5
                                    OS Version Minor:1
                                    File Version Major:5
                                    File Version Minor:1
                                    Subsystem Version Major:5
                                    Subsystem Version Minor:1
                                    Import Hash:1a5cdbf711fee14b077e599d13fddab2
                                    Instruction
                                    call 00007FA1508991E6h
                                    jmp 00007FA150898BD3h
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    mov eax, dword ptr [esp+08h]
                                    mov ecx, dword ptr [esp+10h]
                                    or ecx, eax
                                    mov ecx, dword ptr [esp+0Ch]
                                    jne 00007FA150898D4Bh
                                    mov eax, dword ptr [esp+04h]
                                    mul ecx
                                    retn 0010h
                                    push ebx
                                    mul ecx
                                    mov ebx, eax
                                    mov eax, dword ptr [esp+08h]
                                    mul dword ptr [esp+14h]
                                    add ebx, eax
                                    mov eax, dword ptr [esp+08h]
                                    mul ecx
                                    add edx, ebx
                                    pop ebx
                                    retn 0010h
                                    push ebp
                                    mov ebp, esp
                                    jmp 00007FA150898D61h
                                    push dword ptr [ebp+08h]
                                    call 00007FA15089F761h
                                    pop ecx
                                    test eax, eax
                                    jne 00007FA150898D54h
                                    cmp dword ptr [ebp+08h], FFFFFFFFh
                                    jne 00007FA150898D49h
                                    call 00007FA1508995ECh
                                    jmp 00007FA150898D47h
                                    call 00007FA1508995C8h
                                    push dword ptr [ebp+08h]
                                    call 00007FA15089F7D8h
                                    pop ecx
                                    test eax, eax
                                    je 00007FA150898D16h
                                    pop ebp
                                    ret
                                    push ebp
                                    mov ebp, esp
                                    push dword ptr [ebp+08h]
                                    call 00007FA1508995F5h
                                    pop ecx
                                    pop ebp
                                    ret
                                    push ebp
                                    mov ebp, esp
                                    test byte ptr [ebp+08h], 00000001h
                                    push esi
                                    mov esi, ecx
                                    mov dword ptr [esi], 00460BF0h
                                    je 00007FA150898D4Ch
                                    push 0000000Ch
                                    push esi
                                    call 00007FA150898D1Dh
                                    pop ecx
                                    pop ecx
                                    mov eax, esi
                                    pop esi
                                    pop ebp
                                    retn 0004h
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    push ebx
                                    push esi
                                    mov eax, dword ptr [esp+18h]
                                    or eax, eax
                                    jne 00007FA150898D5Ah
                                    mov ecx, dword ptr [esp+14h]
                                    mov eax, dword ptr [esp+10h]
                                    xor edx, edx
                                    Programming Language:
                                    • [ C ] VS2008 SP1 build 30729
                                    • [IMP] VS2008 SP1 build 30729
                                    • [C++] VS2015 UPD3.1 build 24215
                                    • [RES] VS2015 UPD3 build 24213
                                    • [LNK] VS2015 UPD3.1 build 24215
                                    NameVirtual AddressVirtual Size Is in Section
                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x684a40xb4.rdata
                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x6f0000x38370.rsrc
                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0xa80000x3d8c.reloc
                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x674200x54.rdata
                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_TLS0x674740x18.rdata
                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x66e400x40.rdata
                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_IAT0x4b0000x3d0.rdata
                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x680240x100.rdata
                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                    .text0x10000x497d70x498000af0aed976d9788b8826c9a3231c6fe9False0.5318943983843537data6.562809093346028IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                    .rdata0x4b0000x1eaf40x1ec00f3c726b1fd821276d2f89bade78a51f6False0.3135480182926829data5.113411732013242IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .data0x6a0000x17400xa00f209e7387aef138b4944b487b2f8cfdcFalse0.275firmware 2005 v9319 (revision 0) \261\031\277DN\346@\273 V2, 0 bytes or less, UNKNOWN2 0xffffffff, at 0 0 bytes , at 0 0 bytes , at 0x20a146003.165445916148103IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                    .wixburn0x6c0000x380x200729c00e001c45e48402e1fc7098d5fe2False0.109375data0.5922508836620997IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .tls0x6d0000x90x200bf619eac0cdf3f68d496ea9344137e8bFalse0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                    .gfids0x6e0000xe00x200d809509bc5ab771a9b57700ef6401fb3False0.3203125data2.006362017594661IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .rsrc0x6f0000x383700x384004b27133881a96961fe6aa3f464d60f42False0.38829861111111114data5.651171159709615IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .reloc0xa80000x3d8c0x3e0064550f907643aee4fbff379239bc128cFalse0.8015372983870968data6.776933972299988IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                    RT_BITMAP0x6f2800x1a864dataEnglishUnited States0.39087294282242924
                                    RT_ICON0x89ae40x468Device independent bitmap graphic, 16 x 32 x 32, image size 2048EnglishUnited States0.5930851063829787
                                    RT_ICON0x89f4c0x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 8192EnglishUnited States0.35295497185741087
                                    RT_ICON0x8aff40x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 18432EnglishUnited States0.2641078838174274
                                    RT_ICON0x8d59c0x10828Device independent bitmap graphic, 128 x 256 x 32, image size 131072EnglishUnited States0.17243877913166922
                                    RT_ICON0x9ddc40x653cPNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.991974070072542
                                    RT_MESSAGETABLE0xa43000x2808dataEnglishUnited States0.28844652615144417
                                    RT_GROUP_ICON0xa6b080x4cdataEnglishUnited States0.7631578947368421
                                    RT_VERSION0xa6b540x348dataEnglishUnited States0.44761904761904764
                                    RT_MANIFEST0xa6e9c0x4d2XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1174), with CRLF line terminatorsEnglishUnited States0.47568881685575365
                                    DLLImport
                                    ADVAPI32.dllRegCloseKey, RegOpenKeyExW, OpenProcessToken, AdjustTokenPrivileges, LookupPrivilegeValueW, InitiateSystemShutdownExW, GetUserNameW, RegQueryValueExW, RegDeleteValueW, ConvertStringSecurityDescriptorToSecurityDescriptorW, DecryptFileW, CreateWellKnownSid, InitializeAcl, SetEntriesInAclW, ChangeServiceConfigW, CloseServiceHandle, ControlService, OpenSCManagerW, OpenServiceW, QueryServiceStatus, SetNamedSecurityInfoW, CheckTokenMembership, AllocateAndInitializeSid, SetEntriesInAclA, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegSetValueExW, RegQueryInfoKeyW, RegEnumValueW, RegEnumKeyExW, RegDeleteKeyW, RegCreateKeyExW, GetTokenInformation, CryptDestroyHash, CryptHashData, CryptCreateHash, CryptGetHashParam, CryptReleaseContext, CryptAcquireContextW, QueryServiceConfigW
                                    USER32.dllGetMessageW, PostMessageW, IsWindow, WaitForInputIdle, PostQuitMessage, PeekMessageW, MsgWaitForMultipleObjects, PostThreadMessageW, GetMonitorInfoW, MonitorFromPoint, IsDialogMessageW, LoadCursorW, LoadBitmapW, SetWindowLongW, GetWindowLongW, GetCursorPos, MessageBoxW, CreateWindowExW, UnregisterClassW, RegisterClassW, DefWindowProcW, DispatchMessageW, TranslateMessage
                                    OLEAUT32.dllSysFreeString, SysAllocString, VariantInit, VariantClear
                                    GDI32.dllCreateCompatibleDC, DeleteObject, SelectObject, StretchBlt, GetObjectW, DeleteDC
                                    SHELL32.dllSHGetFolderPathW, CommandLineToArgvW, ShellExecuteExW
                                    ole32.dllCoUninitialize, CoInitializeEx, CoInitialize, StringFromGUID2, CoCreateInstance, CoTaskMemFree, CoInitializeSecurity, CLSIDFromProgID
                                    KERNEL32.dllGetCommandLineA, GetCPInfo, GetOEMCP, CloseHandle, CreateFileW, GetProcAddress, LocalFree, HeapSetInformation, GetLastError, GetModuleHandleW, FormatMessageW, lstrlenA, lstrlenW, MultiByteToWideChar, WideCharToMultiByte, LCMapStringW, Sleep, GetLocalTime, GetModuleFileNameW, ExpandEnvironmentStringsW, GetTempPathW, GetTempFileNameW, CreateDirectoryW, GetFullPathNameW, CompareStringW, GetCurrentProcessId, WriteFile, SetFilePointer, LoadLibraryW, GetSystemDirectoryW, CreateFileA, HeapAlloc, HeapReAlloc, HeapFree, HeapSize, GetProcessHeap, FindClose, GetCommandLineW, GetCurrentDirectoryW, RemoveDirectoryW, SetFileAttributesW, GetFileAttributesW, DeleteFileW, FindFirstFileW, FindNextFileW, MoveFileExW, GetCurrentProcess, GetCurrentThreadId, InitializeCriticalSection, DeleteCriticalSection, ReleaseMutex, GetEnvironmentStringsW, TlsGetValue, TlsSetValue, TlsFree, CreateProcessW, GetVersionExW, VerSetConditionMask, FreeLibrary, EnterCriticalSection, LeaveCriticalSection, GetSystemTime, GetNativeSystemInfo, GetModuleHandleExW, GetWindowsDirectoryW, GetSystemWow64DirectoryW, GetComputerNameW, VerifyVersionInfoW, GetVolumePathNameW, GetDateFormatW, GetSystemDefaultLangID, GetUserDefaultLangID, GetStringTypeW, ReadFile, SetFilePointerEx, DuplicateHandle, InterlockedExchange, InterlockedCompareExchange, CreateEventW, ProcessIdToSessionId, OpenProcess, GetProcessId, WaitForSingleObject, ConnectNamedPipe, SetNamedPipeHandleState, CreateNamedPipeW, CreateThread, GetExitCodeThread, SetEvent, WaitForMultipleObjects, InterlockedIncrement, InterlockedDecrement, ResetEvent, SetEndOfFile, SetFileTime, LocalFileTimeToFileTime, DosDateTimeToFileTime, CompareStringA, GetExitCodeProcess, SetThreadExecutionState, CopyFileExW, MapViewOfFile, UnmapViewOfFile, CreateMutexW, CreateFileMappingW, GetThreadLocale, IsValidCodePage, FreeEnvironmentStringsW, TlsAlloc, SetStdHandle, GetConsoleCP, GetConsoleMode, FlushFileBuffers, DecodePointer, WriteConsoleW, GetModuleHandleA, GlobalAlloc, GlobalFree, GetFileSizeEx, CopyFileW, VirtualAlloc, VirtualFree, SystemTimeToTzSpecificLocalTime, GetTimeZoneInformation, SystemTimeToFileTime, GetSystemInfo, VirtualProtect, VirtualQuery, SetCurrentDirectoryW, FindFirstFileExW, GetFileType, GetACP, ExitProcess, GetStdHandle, LoadLibraryExW, InitializeCriticalSectionAndSpinCount, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, RaiseException, RtlUnwind, SetLastError, LoadLibraryExA
                                    RPCRT4.dllUuidCreate
                                    Language of compilation systemCountry where language is spokenMap
                                    EnglishUnited States
                                    No network behavior found

                                    Click to jump to process

                                    Click to jump to process

                                    Click to dive into process behavior distribution

                                    Click to jump to process

                                    Target ID:1
                                    Start time:16:17:10
                                    Start date:16/04/2024
                                    Path:C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe
                                    Wow64 process (32bit):true
                                    Commandline:"C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe"
                                    Imagebase:0xb00000
                                    File size:967'938 bytes
                                    MD5 hash:796375900C5F33DB332FF8143F243083
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low
                                    Has exited:false

                                    Target ID:2
                                    Start time:16:17:11
                                    Start date:16/04/2024
                                    Path:C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                    Wow64 process (32bit):true
                                    Commandline:"C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe" -burn.clean.room="C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe" -burn.filehandle.attached=512 -burn.filehandle.self=528
                                    Imagebase:0x880000
                                    File size:967'938 bytes
                                    MD5 hash:796375900C5F33DB332FF8143F243083
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Antivirus matches:
                                    • Detection: 0%, ReversingLabs
                                    • Detection: 0%, Virustotal, Browse
                                    Reputation:low
                                    Has exited:false

                                    Reset < >

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 516 b0508d-b0513b call b2f670 * 2 GetModuleHandleW call b403f0 call b405a2 call b01209 527 b05151-b05162 call b041d2 516->527 528 b0513d 516->528 533 b05164-b05169 527->533 534 b0516b-b05187 call b05525 CoInitializeEx 527->534 530 b05142-b0514c call b4012f 528->530 537 b053cc-b053d3 530->537 533->530 543 b05190-b0519c call b3fbad 534->543 544 b05189-b0518e 534->544 539 b053e0-b053e2 537->539 540 b053d5-b053db call b454ef 537->540 541 b053e4-b053eb 539->541 542 b05407-b05425 call b0d723 call b1a6d0 call b1a91e 539->542 540->539 541->542 546 b053ed-b05402 call b4041b 541->546 566 b05453-b05466 call b04e9c 542->566 567 b05427-b0542f 542->567 553 b051b0-b051bf call b40cd1 543->553 554 b0519e 543->554 544->530 546->542 561 b051c1-b051c6 553->561 562 b051c8-b051d7 call b429b3 553->562 556 b051a3-b051ab call b4012f 554->556 556->537 561->556 572 b051e0-b051ef call b4343b 562->572 573 b051d9-b051de 562->573 575 b05468 call b43911 566->575 576 b0546d-b05474 566->576 567->566 570 b05431-b05434 567->570 570->566 574 b05436-b05451 call b1416a call b0550f 570->574 585 b051f1-b051f6 572->585 586 b051f8-b05217 GetVersionExW 572->586 573->556 574->566 575->576 580 b05476 call b42dd0 576->580 581 b0547b-b05482 576->581 580->581 587 b05484 call b41317 581->587 588 b05489-b05490 581->588 585->556 591 b05251-b05296 call b033d7 call b0550f 586->591 592 b05219-b0524c GetLastError call b037d3 586->592 587->588 594 b05492 call b3fcbc 588->594 595 b05497-b05499 588->595 614 b05298-b052a3 call b454ef 591->614 615 b052a9-b052b9 call b17337 591->615 592->556 594->595 596 b054a1-b054a8 595->596 597 b0549b CoUninitialize 595->597 602 b054e3-b054ec call b4000b 596->602 603 b054aa-b054ac 596->603 597->596 612 b054f3-b0550c call b406f5 call b2de36 602->612 613 b054ee call b044e9 602->613 606 b054b2-b054b8 603->606 607 b054ae-b054b0 603->607 610 b054ba-b054d3 call b13c30 call b0550f 606->610 607->610 610->602 631 b054d5-b054e2 call b0550f 610->631 613->612 614->615 627 b052c5-b052ce 615->627 628 b052bb 615->628 632 b052d4-b052d7 627->632 633 b05396-b053a3 call b04c33 627->633 628->627 631->602 636 b052dd-b052e0 632->636 637 b0536e-b0538a call b049df 632->637 639 b053a8-b053ac 633->639 641 b052e2-b052e5 636->641 642 b05346-b05362 call b047e9 636->642 644 b053b8-b053ca 637->644 651 b0538c 637->651 639->644 645 b053ae 639->645 647 b052e7-b052ea 641->647 648 b0531e-b0533a call b04982 641->648 642->644 656 b05364 642->656 644->537 645->644 649 b052fb-b0530e call b04b80 647->649 650 b052ec-b052f1 647->650 648->644 658 b0533c 648->658 649->644 659 b05314 649->659 650->649 651->633 656->637 658->642 659->648
                                      APIs
                                      • GetModuleHandleW.KERNEL32(00000000,?,?,?,?,?,?), ref: 00B0510F
                                        • Part of subcall function 00B403F0: InitializeCriticalSection.KERNEL32(00B6B60C,?,00B0511B,00000000,?,?,?,?,?,?), ref: 00B40407
                                        • Part of subcall function 00B01209: CommandLineToArgvW.SHELL32(00000000,00000000,00000000,00000000,00000000,00000000,ignored ,00000000,?,00000000,?,?,?,00B05137,00000000,?), ref: 00B01247
                                        • Part of subcall function 00B01209: GetLastError.KERNEL32(?,?,?,00B05137,00000000,?,?,00000003,00000000,00000000,?,?,?,?,?,?), ref: 00B01251
                                      • CoInitializeEx.OLE32(00000000,00000000,?,?,00000000,?,?,00000003,00000000,00000000,?,?,?,?,?,?), ref: 00B0517D
                                        • Part of subcall function 00B40CD1: GetProcAddress.KERNEL32(RegDeleteKeyExW,AdvApi32.dll), ref: 00B40CF2
                                      • GetVersionExW.KERNEL32(?,?,?,?,?,?,?), ref: 00B0520F
                                      • GetLastError.KERNEL32(?,?,?,?,?,?), ref: 00B05219
                                      • CoUninitialize.OLE32(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00B0549B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorInitializeLast$AddressArgvCommandCriticalHandleLineModuleProcSectionUninitializeVersion
                                      • String ID: 3.10.4.4718$Failed to get OS info.$Failed to initialize COM.$Failed to initialize Cryputil.$Failed to initialize Regutil.$Failed to initialize Wiutil.$Failed to initialize XML util.$Failed to initialize core.$Failed to initialize user state.$Failed to parse command line.$Failed to run RunOnce mode.$Failed to run embedded mode.$Failed to run per-machine mode.$Failed to run per-user mode.$Failed to run untrusted mode.$Invalid run mode.$Setup$_Failed$user.cpp$txt
                                      • API String ID: 3262001429-867073019
                                      • Opcode ID: 39fbb48a99db84d1be342e5c48dd2a50134f4acb29550056e14579e729db5a44
                                      • Instruction ID: f47f98fe21c7250496c1e7f1bcb2053a2ab88fec21b5a861875559c220a5b23b
                                      • Opcode Fuzzy Hash: 39fbb48a99db84d1be342e5c48dd2a50134f4acb29550056e14579e729db5a44
                                      • Instruction Fuzzy Hash: 28B19571D40629ABDB32AF649C46BEF7AE8EF04711F0400D5FA09B6691DB709F809F91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleHandleA.KERNEL32(kernel32.dll,00000000,00000000,00B434DF,00000000,?,00000000), ref: 00B42F3D
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00B2BDED,?,00B052FD,?,00000000,?), ref: 00B42F49
                                      • GetProcAddress.KERNEL32(00000000,IsWow64Process), ref: 00B42F89
                                      • GetProcAddress.KERNEL32(00000000,Wow64DisableWow64FsRedirection), ref: 00B42F95
                                      • GetProcAddress.KERNEL32(00000000,Wow64EnableWow64FsRedirection), ref: 00B42FA0
                                      • GetProcAddress.KERNEL32(00000000,Wow64RevertWow64FsRedirection), ref: 00B42FAA
                                      • CoCreateInstance.OLE32(00B6B6C8,00000000,00000001,00B4B808,?,?,?,?,?,?,?,?,?,?,?,00B2BDED), ref: 00B42FE5
                                      • ExitProcess.KERNEL32 ref: 00B43094
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressProc$CreateErrorExitHandleInstanceLastModuleProcess
                                      • String ID: IsWow64Process$Wow64DisableWow64FsRedirection$Wow64EnableWow64FsRedirection$Wow64RevertWow64FsRedirection$kernel32.dll$xmlutil.cpp
                                      • API String ID: 2124981135-499589564
                                      • Opcode ID: 28eb82d96987041554e40f1154109b9ec90feb66ed8a0efde48b5a35f0238c23
                                      • Instruction ID: 51b8dee510516b8db4253d812ddd9a7e9afdbafa91eaf59327b270054adc4ab8
                                      • Opcode Fuzzy Hash: 28eb82d96987041554e40f1154109b9ec90feb66ed8a0efde48b5a35f0238c23
                                      • Instruction Fuzzy Hash: A2419D31A01215ABDB249BA8C894FAEB7F4EF44B10F1541E9F901EB350DB75DF40AB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B033D7: GetModuleFileNameW.KERNEL32(?,?,00000104,?,00000104,?,?,?,?,00B010DD,?,00000000), ref: 00B033F8
                                      • CreateFileW.KERNELBASE(?,80000000,00000005,00000000,00000003,00000080,00000000,?,00000000), ref: 00B010F6
                                        • Part of subcall function 00B01174: HeapSetInformation.KERNEL32(00000000,00000001,00000000,00000000,?,?,?,?,?,00B0111A,cabinet.dll,00000009,?,?,00000000), ref: 00B01185
                                        • Part of subcall function 00B01174: GetModuleHandleW.KERNEL32(kernel32,?,?,?,?,00B0111A,cabinet.dll,00000009,?,?,00000000), ref: 00B01190
                                        • Part of subcall function 00B01174: GetProcAddress.KERNEL32(00000000,SetDefaultDllDirectories), ref: 00B0119E
                                        • Part of subcall function 00B01174: GetLastError.KERNEL32(?,?,?,?,00B0111A,cabinet.dll,00000009,?,?,00000000), ref: 00B011B9
                                        • Part of subcall function 00B01174: GetProcAddress.KERNEL32(00000000,SetDllDirectoryW), ref: 00B011C1
                                        • Part of subcall function 00B01174: GetLastError.KERNEL32(?,?,?,?,00B0111A,cabinet.dll,00000009,?,?,00000000), ref: 00B011D6
                                      • CloseHandle.KERNEL32(?,?,?,?,00B4B4C0,?,cabinet.dll,00000009,?,?,00000000), ref: 00B01131
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressErrorFileHandleLastModuleProc$CloseCreateHeapInformationName
                                      • String ID: cabinet.dll$clbcatq.dll$comres.dll$crypt32.dll$feclient.dll$msasn1.dll$msi.dll$version.dll$wininet.dll
                                      • API String ID: 3687706282-3151496603
                                      • Opcode ID: 49be9603d73cc67b176f5455531b03f7003a68638fc97bca43d1998c27a52c40
                                      • Instruction ID: 67968477122a73ef5a729cc374746a67169dda32eefa47a4ab05815d292643a1
                                      • Opcode Fuzzy Hash: 49be9603d73cc67b176f5455531b03f7003a68638fc97bca43d1998c27a52c40
                                      • Instruction Fuzzy Hash: AF217172900218ABDB149FA9DC45FEEBBF8FF05720F104599EA10B72D1DB709A04DBA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      • Failed to copy working folder., xrefs: 00B19F12
                                      • Failed to calculate working folder to ensure it exists., xrefs: 00B19ED4
                                      • Failed create working folder., xrefs: 00B19EEA
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CurrentDirectoryErrorLastProcessWindows
                                      • String ID: Failed create working folder.$Failed to calculate working folder to ensure it exists.$Failed to copy working folder.
                                      • API String ID: 3841436932-2072961686
                                      • Opcode ID: 7858fcfdb88fddd96d7381b6901012d380583c67286748a43d80fe8a10b8ceb6
                                      • Instruction ID: 02fe654337c50e4deb5a55af5659836b8d0aa909877290e10d609f89668dc414
                                      • Opcode Fuzzy Hash: 7858fcfdb88fddd96d7381b6901012d380583c67286748a43d80fe8a10b8ceb6
                                      • Instruction Fuzzy Hash: 6401B132D04668F78F22AB54DC16CEF7BE8EF91B21B5041E5F904B6221DB319F84A690
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                      • RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateProcess
                                      • String ID:
                                      • API String ID: 1357844191-0
                                      • Opcode ID: 9f28b94ebd396dba74ef296d16d5384112bc5267398071a909eae150869b54cd
                                      • Instruction ID: 8d7cfde95bd874be0a0eec5f72146795913b744c64691327285e1239d6524fd8
                                      • Opcode Fuzzy Hash: 9f28b94ebd396dba74ef296d16d5384112bc5267398071a909eae150869b54cd
                                      • Instruction Fuzzy Hash: 12C012361A0218AB8B006FF8EC0EC9A3BACBB296027008400BA05D3110CB3CE2148B60
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 0 b0f86e-b0f8a4 call b4388a 3 b0f8a6-b0f8b3 call b4012f 0->3 4 b0f8b8-b0f8d1 call b431c7 0->4 9 b0fda0-b0fda5 3->9 10 b0f8d3-b0f8d8 4->10 11 b0f8dd-b0f8f2 call b431c7 4->11 12 b0fda7-b0fda9 9->12 13 b0fdad-b0fdb2 9->13 14 b0fd97-b0fd9e call b4012f 10->14 20 b0f8f4-b0f8f9 11->20 21 b0f8fe-b0f90b call b0e936 11->21 12->13 18 b0fdb4-b0fdb6 13->18 19 b0fdba-b0fdbf 13->19 28 b0fd9f 14->28 18->19 23 b0fdc1-b0fdc3 19->23 24 b0fdc7-b0fdcb 19->24 20->14 31 b0f917-b0f92c call b431c7 21->31 32 b0f90d-b0f912 21->32 23->24 25 b0fdd5-b0fddc 24->25 26 b0fdcd-b0fdd0 call b454ef 24->26 26->25 28->9 35 b0f938-b0f94a call b44b5a 31->35 36 b0f92e-b0f933 31->36 32->14 39 b0f959-b0f96e call b431c7 35->39 40 b0f94c-b0f954 35->40 36->14 45 b0f970-b0f975 39->45 46 b0f97a-b0f98f call b431c7 39->46 41 b0fc23-b0fc2c call b4012f 40->41 41->28 45->14 50 b0f991-b0f996 46->50 51 b0f99b-b0f9ad call b433db 46->51 50->14 54 b0f9b9-b0f9cf call b4388a 51->54 55 b0f9af-b0f9b4 51->55 58 b0f9d5-b0f9d7 54->58 59 b0fc7e-b0fc98 call b0ebb2 54->59 55->14 61 b0f9e3-b0f9f8 call b433db 58->61 62 b0f9d9-b0f9de 58->62 66 b0fca4-b0fcbc call b4388a 59->66 67 b0fc9a-b0fc9f 59->67 68 b0fa04-b0fa19 call b431c7 61->68 69 b0f9fa-b0f9ff 61->69 62->14 74 b0fcc2-b0fcc4 66->74 75 b0fd86-b0fd87 call b0efe5 66->75 67->14 76 b0fa29-b0fa3e call b431c7 68->76 77 b0fa1b-b0fa1d 68->77 69->14 78 b0fcd0-b0fcee call b431c7 74->78 79 b0fcc6-b0fccb 74->79 81 b0fd8c-b0fd90 75->81 88 b0fa40-b0fa42 76->88 89 b0fa4e-b0fa63 call b431c7 76->89 77->76 82 b0fa1f-b0fa24 77->82 90 b0fcf0-b0fcf5 78->90 91 b0fcfa-b0fd12 call b431c7 78->91 79->14 81->28 85 b0fd92 81->85 82->14 85->14 88->89 92 b0fa44-b0fa49 88->92 97 b0fa73-b0fa88 call b431c7 89->97 98 b0fa65-b0fa67 89->98 90->14 99 b0fd14-b0fd16 91->99 100 b0fd1f-b0fd37 call b431c7 91->100 92->14 109 b0fa98-b0faad call b431c7 97->109 110 b0fa8a-b0fa8c 97->110 98->97 102 b0fa69-b0fa6e 98->102 99->100 101 b0fd18-b0fd1d 99->101 107 b0fd44-b0fd5c call b431c7 100->107 108 b0fd39-b0fd3b 100->108 101->14 102->14 117 b0fd65-b0fd7d call b431c7 107->117 118 b0fd5e-b0fd63 107->118 108->107 111 b0fd3d-b0fd42 108->111 119 b0fabd-b0fad2 call b431c7 109->119 120 b0faaf-b0fab1 109->120 110->109 112 b0fa8e-b0fa93 110->112 111->14 112->14 117->75 126 b0fd7f-b0fd84 117->126 118->14 127 b0fae2-b0faf7 call b431c7 119->127 128 b0fad4-b0fad6 119->128 120->119 122 b0fab3-b0fab8 120->122 122->14 126->14 132 b0fb07-b0fb1c call b431c7 127->132 133 b0faf9-b0fafb 127->133 128->127 129 b0fad8-b0fadd 128->129 129->14 137 b0fb2c-b0fb44 call b431c7 132->137 138 b0fb1e-b0fb20 132->138 133->132 134 b0fafd-b0fb02 133->134 134->14 142 b0fb54-b0fb6c call b431c7 137->142 143 b0fb46-b0fb48 137->143 138->137 139 b0fb22-b0fb27 138->139 139->14 147 b0fb7c-b0fb91 call b431c7 142->147 148 b0fb6e-b0fb70 142->148 143->142 145 b0fb4a-b0fb4f 143->145 145->14 152 b0fc31-b0fc33 147->152 153 b0fb97-b0fbb4 CompareStringW 147->153 148->147 149 b0fb72-b0fb77 148->149 149->14 154 b0fc35-b0fc3c 152->154 155 b0fc3e-b0fc40 152->155 156 b0fbb6-b0fbbc 153->156 157 b0fbbe-b0fbd3 CompareStringW 153->157 154->155 158 b0fc42-b0fc47 155->158 159 b0fc4c-b0fc64 call b433db 155->159 160 b0fbff-b0fc04 156->160 161 b0fbe1-b0fbf6 CompareStringW 157->161 162 b0fbd5-b0fbdf 157->162 158->14 159->59 169 b0fc66-b0fc68 159->169 160->155 164 b0fc06-b0fc1e call b037d3 161->164 165 b0fbf8 161->165 162->160 164->41 165->160 170 b0fc74 169->170 171 b0fc6a-b0fc6f 169->171 170->59 171->14
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID: AboutUrl$Arp$Classification$Comments$Contact$Department$DisableModify$DisableRemove$DisplayName$DisplayVersion$ExecutableName$Failed to get @AboutUrl.$Failed to get @Classification.$Failed to get @Comments.$Failed to get @Contact.$Failed to get @Department.$Failed to get @DisableModify.$Failed to get @DisableRemove.$Failed to get @DisplayName.$Failed to get @DisplayVersion.$Failed to get @ExecutableName.$Failed to get @HelpLink.$Failed to get @HelpTelephone.$Failed to get @Id.$Failed to get @Manufacturer.$Failed to get @Name.$Failed to get @ParentDisplayName.$Failed to get @PerMachine.$Failed to get @ProductFamily.$Failed to get @ProviderKey.$Failed to get @Publisher.$Failed to get @Register.$Failed to get @Tag.$Failed to get @UpdateUrl.$Failed to get @Version.$Failed to parse @Version: %ls$Failed to parse related bundles$Failed to parse software tag.$Failed to select ARP node.$Failed to select Update node.$Failed to select registration node.$Failed to set registration paths.$HelpLink$HelpTelephone$Invalid modify disabled type: %ls$Manufacturer$Name$ParentDisplayName$PerMachine$ProductFamily$ProviderKey$Publisher$Register$Registration$Tag$Update$UpdateUrl$Version$button$registration.cpp$yes
                                      • API String ID: 0-2956246334
                                      • Opcode ID: f8c7c1192e3f5fd59c0acc8cff32dbec45697e37cab99664dc12123f79e7595c
                                      • Instruction ID: 726cffc64c81860c11c2ad8d2d425a5575e138c091fd7edee4d8f7ff420c0477
                                      • Opcode Fuzzy Hash: f8c7c1192e3f5fd59c0acc8cff32dbec45697e37cab99664dc12123f79e7595c
                                      • Instruction Fuzzy Hash: 9DE19332F44667BACB31AAA4CC42FBD7EE4EB00B11F1546F5FD10B69E0DB619E449680
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 172 b0b389-b0b3fd call b2f670 * 2 177 b0b435-b0b450 SetFilePointerEx 172->177 178 b0b3ff-b0b42a GetLastError call b037d3 172->178 180 b0b452-b0b482 GetLastError call b037d3 177->180 181 b0b484-b0b49e ReadFile 177->181 186 b0b42f-b0b430 178->186 180->186 184 b0b4a0-b0b4d0 GetLastError call b037d3 181->184 185 b0b4d5-b0b4dc 181->185 184->186 189 b0b4e2-b0b4eb 185->189 190 b0bad3-b0bae7 call b037d3 185->190 192 b0baed-b0baf3 call b4012f 186->192 189->190 191 b0b4f1-b0b501 SetFilePointerEx 189->191 202 b0baec 190->202 195 b0b503-b0b52e GetLastError call b037d3 191->195 196 b0b538-b0b550 ReadFile 191->196 208 b0baf4-b0bb06 call b2de36 192->208 195->196 200 b0b552-b0b57d GetLastError call b037d3 196->200 201 b0b587-b0b58e 196->201 200->201 206 b0b594-b0b59e 201->206 207 b0bab8-b0bad1 call b037d3 201->207 202->192 206->207 212 b0b5a4-b0b5c7 SetFilePointerEx 206->212 207->202 215 b0b5c9-b0b5f4 GetLastError call b037d3 212->215 216 b0b5fe-b0b616 ReadFile 212->216 215->216 217 b0b618-b0b643 GetLastError call b037d3 216->217 218 b0b64d-b0b665 ReadFile 216->218 217->218 221 b0b667-b0b692 GetLastError call b037d3 218->221 222 b0b69c-b0b6b7 SetFilePointerEx 218->222 221->222 226 b0b6f1-b0b710 ReadFile 222->226 227 b0b6b9-b0b6e7 GetLastError call b037d3 222->227 228 b0b716-b0b718 226->228 229 b0ba79-b0baad GetLastError call b037d3 226->229 227->226 233 b0b719-b0b720 228->233 238 b0baae-b0bab6 call b4012f 229->238 236 b0ba54-b0ba71 call b037d3 233->236 237 b0b726-b0b732 233->237 252 b0ba76-b0ba77 236->252 239 b0b734-b0b73b 237->239 240 b0b73d-b0b746 237->240 238->208 239->240 243 b0b780-b0b787 239->243 244 b0ba17-b0ba2e call b037d3 240->244 245 b0b74c-b0b772 ReadFile 240->245 250 b0b7b0-b0b7c7 call b038d4 243->250 251 b0b789-b0b7ab call b037d3 243->251 256 b0ba33-b0ba39 call b4012f 244->256 245->229 249 b0b778-b0b77e 245->249 249->233 260 b0b7c9-b0b7e6 call b037d3 250->260 261 b0b7eb-b0b800 SetFilePointerEx 250->261 251->252 252->238 268 b0ba3f-b0ba40 256->268 260->192 263 b0b840-b0b865 ReadFile 261->263 264 b0b802-b0b830 GetLastError call b037d3 261->264 269 b0b867-b0b89a GetLastError call b037d3 263->269 270 b0b89c-b0b8a8 263->270 278 b0b835-b0b83b call b4012f 264->278 272 b0ba41-b0ba43 268->272 269->278 274 b0b8aa-b0b8c6 call b037d3 270->274 275 b0b8cb-b0b8cf 270->275 272->208 279 b0ba49-b0ba4f call b03999 272->279 274->256 276 b0b8d1-b0b905 call b037d3 call b4012f 275->276 277 b0b90a-b0b91d call b448cb 275->277 276->272 292 b0b929-b0b933 277->292 293 b0b91f-b0b924 277->293 278->268 279->208 295 b0b935-b0b93b 292->295 296 b0b93d-b0b945 292->296 293->278 297 b0b956-b0b9b6 call b038d4 295->297 298 b0b951-b0b954 296->298 299 b0b947-b0b94f 296->299 302 b0b9b8-b0b9d4 call b037d3 297->302 303 b0b9da-b0b9fb call b2f0f0 call b0b106 297->303 298->297 299->297 302->303 303->272 310 b0b9fd-b0ba0d call b037d3 303->310 310->244
                                      APIs
                                      • GetLastError.KERNEL32(?,?,?,00000000,7736C3F0,00000000), ref: 00B0B3FF
                                      • SetFilePointerEx.KERNELBASE(000000FF,00000000,00000000,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B44C
                                      • GetLastError.KERNEL32(?,?,?,00000000,7736C3F0,00000000), ref: 00B0B452
                                      • ReadFile.KERNELBASE(00000000,00B0435C,00000040,?,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B49A
                                      • GetLastError.KERNEL32(?,?,?,00000000,7736C3F0,00000000), ref: 00B0B4A0
                                      • SetFilePointerEx.KERNELBASE(00000000,00000000,?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B4FD
                                      • GetLastError.KERNEL32(?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B503
                                      • ReadFile.KERNELBASE(00000000,?,00000018,00000040,00000000,?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B54C
                                      • GetLastError.KERNEL32(?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B552
                                      • SetFilePointerEx.KERNELBASE(00000000,-00000098,00000000,00000000,00000000,?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B5C3
                                      • GetLastError.KERNEL32(?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B5C9
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$File$Pointer$Read
                                      • String ID: ($.wix$4$Failed to allocate buffer for section info.$Failed to allocate memory for container sizes.$Failed to find Burn section.$Failed to find valid DOS image header in buffer.$Failed to find valid NT image header in buffer.$Failed to get total size of bundle.$Failed to open handle to user process path.$Failed to read DOS header.$Failed to read NT header.$Failed to read complete image section header, index: %u$Failed to read complete section info.$Failed to read image section header, index: %u$Failed to read section info, data to short: %u$Failed to read section info, unsupported version: %08x$Failed to read section info.$Failed to read signature offset.$Failed to read signature size.$Failed to seek past optional headers.$Failed to seek to NT header.$Failed to seek to section info.$Failed to seek to start of file.$PE$PE Header from file didn't match PE Header in memory.$burn$section.cpp
                                      • API String ID: 2600052162-695169583
                                      • Opcode ID: 0c9b658b678db744873667f652fd8d6f3d56c5b799a2158ce8ed8085122c07f4
                                      • Instruction ID: a9945c07193c108401bdccf1f6f8b62bbdd57d5e0fffd147c86d48c034167679
                                      • Opcode Fuzzy Hash: 0c9b658b678db744873667f652fd8d6f3d56c5b799a2158ce8ed8085122c07f4
                                      • Instruction Fuzzy Hash: D9129575A40325ABEB209A25CC85FAB7AE8EB45710F0141E5BD09FB2D1DB71CE40DBA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 313 b0ccb6-b0cce2 call b43803 316 b0cce4 313->316 317 b0ccf6-b0cd07 313->317 318 b0cce9-b0ccf1 call b4012f 316->318 321 b0cd10-b0cd15 317->321 322 b0cd09-b0cd0e 317->322 324 b0d04b-b0d050 318->324 321->324 325 b0cd1b-b0cd22 call b038d4 321->325 322->318 326 b0d052-b0d054 324->326 327 b0d058-b0d05d 324->327 331 b0cd27-b0cd2e 325->331 326->327 329 b0d065-b0d069 327->329 330 b0d05f-b0d061 327->330 334 b0d073-b0d079 329->334 335 b0d06b-b0d06e call b454ef 329->335 330->329 332 b0cd30-b0cd4f call b037d3 call b4012f 331->332 333 b0cd54-b0cd61 331->333 345 b0d04a 332->345 338 b0d047 333->338 339 b0cd67-b0cd69 333->339 335->334 342 b0d049 338->342 341 b0cd6c-b0cd82 call b43760 339->341 348 b0d121 341->348 349 b0cd88-b0cd9a call b431c7 341->349 342->345 345->324 350 b0d126-b0d12e call b4012f 348->350 355 b0cda0-b0cdb5 call b431c7 349->355 356 b0d11a-b0d11f 349->356 350->342 359 b0d113-b0d118 355->359 360 b0cdbb-b0cdd0 call b431c7 355->360 356->350 359->350 363 b0cdd6-b0cdf1 CompareStringW 360->363 364 b0d10c-b0d111 360->364 365 b0cdf3-b0cdfa 363->365 366 b0cdfc-b0ce11 CompareStringW 363->366 364->350 367 b0ce3a-b0ce3e 365->367 368 b0ce13-b0ce16 366->368 369 b0ce18-b0ce2d CompareStringW 366->369 370 b0ce40-b0ce59 call b431c7 367->370 371 b0ce82-b0ce9b call b433db 367->371 368->367 372 b0d0f1-b0d0f9 369->372 373 b0ce33 369->373 380 b0ce61-b0ce63 370->380 381 b0ce5b-b0ce5f 370->381 382 b0cea5-b0cebe call b431c7 371->382 383 b0ce9d-b0ce9f 371->383 376 b0d0fe-b0d107 call b4012f 372->376 373->367 376->342 385 b0d086-b0d08b 380->385 386 b0ce69-b0ce7c call b0c0a9 380->386 381->371 381->380 392 b0cec0-b0cec4 382->392 393 b0cec6-b0cec8 382->393 383->382 387 b0d090-b0d095 383->387 385->350 386->371 396 b0d07c-b0d084 386->396 387->350 392->393 394 b0cece-b0cee7 call b431c7 392->394 393->394 395 b0d0ea-b0d0ef 393->395 399 b0cee9-b0ceed 394->399 400 b0ceef-b0cef1 394->400 395->350 396->376 399->400 401 b0cef7-b0cf10 call b431c7 399->401 400->401 402 b0d0e3-b0d0e8 400->402 405 b0cf32-b0cf4b call b431c7 401->405 406 b0cf12-b0cf14 401->406 402->350 412 b0cf4d-b0cf4f 405->412 413 b0cf6f-b0cf88 call b431c7 405->413 407 b0d0a4-b0d0a9 406->407 408 b0cf1a-b0cf2c call b02a22 406->408 407->350 408->405 418 b0d09a-b0d09f 408->418 415 b0d0b2-b0d0b7 412->415 416 b0cf55-b0cf69 call b0200b 412->416 422 b0cf8a-b0cf8c 413->422 423 b0cfac-b0cfc1 call b431c7 413->423 415->350 416->413 424 b0d0ab-b0d0b0 416->424 418->350 425 b0d0c0-b0d0c5 422->425 426 b0cf92-b0cfa6 call b0200b 422->426 431 b0cfc7-b0cfdb call b0200b 423->431 432 b0d0dc-b0d0e1 423->432 424->350 425->350 426->423 433 b0d0b9-b0d0be 426->433 436 b0cfe1-b0cffa call b431c7 431->436 437 b0d0d5-b0d0da 431->437 432->350 433->350 440 b0cffc-b0cffe 436->440 441 b0d01d-b0d022 436->441 437->350 442 b0d004-b0d017 call b0c780 440->442 443 b0d0ce-b0d0d3 440->443 444 b0d024-b0d02a 441->444 445 b0d02e-b0d041 441->445 442->441 449 b0d0c7-b0d0cc 442->449 443->350 444->445 445->338 445->341 449->350
                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • CompareStringW.KERNEL32(0000007F,00000000,00000000,000000FF,download,000000FF,00000000,Packaging,00000000,00000000,FilePath,00B05355,00000000,00B4CA64,00B0533D,00000000), ref: 00B0CDEC
                                      Strings
                                      • DownloadUrl, xrefs: 00B0CED2
                                      • FilePath, xrefs: 00B0CDA4
                                      • Failed to get @CertificateRootPublicKeyIdentifier., xrefs: 00B0D0B2
                                      • Failed to hex decode @CertificateRootThumbprint., xrefs: 00B0D0B9
                                      • Payload, xrefs: 00B0CCD1
                                      • Failed to get @CertificateRootThumbprint., xrefs: 00B0D0C0
                                      • external, xrefs: 00B0CE1A
                                      • SourcePath, xrefs: 00B0CEA9
                                      • Failed to hex decode the Payload/@Hash., xrefs: 00B0D0D5
                                      • Failed to get payload node count., xrefs: 00B0CD09
                                      • LayoutOnly, xrefs: 00B0CE86
                                      • download, xrefs: 00B0CDDE
                                      • Failed to allocate memory for payload structs., xrefs: 00B0CD42
                                      • Failed to get @DownloadUrl., xrefs: 00B0D0E3
                                      • Failed to find catalog., xrefs: 00B0D0C7
                                      • payload.cpp, xrefs: 00B0CD38
                                      • Failed to get @LayoutOnly., xrefs: 00B0D090
                                      • FileSize, xrefs: 00B0CEFB
                                      • embedded, xrefs: 00B0CDFE
                                      • Catalog, xrefs: 00B0CFE5
                                      • Failed to get @Container., xrefs: 00B0D086
                                      • Failed to get @Packaging., xrefs: 00B0D10C
                                      • Failed to hex decode @CertificateRootPublicKeyIdentifier., xrefs: 00B0D0AB
                                      • Packaging, xrefs: 00B0CDBF
                                      • Failed to parse @FileSize., xrefs: 00B0D09A
                                      • Failed to get next node., xrefs: 00B0D121
                                      • Failed to to find container: %ls, xrefs: 00B0D07F
                                      • Failed to get @FilePath., xrefs: 00B0D113
                                      • Container, xrefs: 00B0CE44
                                      • Failed to get @Hash., xrefs: 00B0D0DC
                                      • Failed to get @Id., xrefs: 00B0D11A
                                      • Failed to get @FileSize., xrefs: 00B0D0A4
                                      • Hash, xrefs: 00B0CFB0
                                      • CertificateRootThumbprint, xrefs: 00B0CF73
                                      • Invalid value for @Packaging: %ls, xrefs: 00B0D0F9
                                      • Failed to select payload nodes., xrefs: 00B0CCE4
                                      • Failed to get @SourcePath., xrefs: 00B0D0EA
                                      • CertificateRootPublicKeyIdentifier, xrefs: 00B0CF36
                                      • Failed to get @Catalog., xrefs: 00B0D0CE
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateCompareProcessString
                                      • String ID: Catalog$CertificateRootPublicKeyIdentifier$CertificateRootThumbprint$Container$DownloadUrl$Failed to allocate memory for payload structs.$Failed to find catalog.$Failed to get @Catalog.$Failed to get @CertificateRootPublicKeyIdentifier.$Failed to get @CertificateRootThumbprint.$Failed to get @Container.$Failed to get @DownloadUrl.$Failed to get @FilePath.$Failed to get @FileSize.$Failed to get @Hash.$Failed to get @Id.$Failed to get @LayoutOnly.$Failed to get @Packaging.$Failed to get @SourcePath.$Failed to get next node.$Failed to get payload node count.$Failed to hex decode @CertificateRootPublicKeyIdentifier.$Failed to hex decode @CertificateRootThumbprint.$Failed to hex decode the Payload/@Hash.$Failed to parse @FileSize.$Failed to select payload nodes.$Failed to to find container: %ls$FilePath$FileSize$Hash$Invalid value for @Packaging: %ls$LayoutOnly$Packaging$Payload$SourcePath$download$embedded$external$payload.cpp
                                      • API String ID: 1171520630-3127305756
                                      • Opcode ID: 05ebf84c4426e782fe9b90dffe3184d2d2956d28da602e7b35fc7388190b9a59
                                      • Instruction ID: 34b9c6be2925b94ba78f3326ab2531e89cac03e9c1db7fd648096d02ee5acf40
                                      • Opcode Fuzzy Hash: 05ebf84c4426e782fe9b90dffe3184d2d2956d28da602e7b35fc7388190b9a59
                                      • Instruction Fuzzy Hash: 26C1A072D4162ABACB219A90CC41EBEBEF4EB04B20F1442E5F905B71E0D775AF11E791
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 450 b20a77-b20a90 SetEvent 451 b20a92-b20ac5 GetLastError call b037d3 450->451 452 b20aca-b20ad6 WaitForSingleObject 450->452 460 b20e25-b20e26 call b4012f 451->460 454 b20b10-b20b1b ResetEvent 452->454 455 b20ad8-b20b0b GetLastError call b037d3 452->455 458 b20b55-b20b5b 454->458 459 b20b1d-b20b50 GetLastError call b037d3 454->459 455->460 463 b20b96-b20baf call b021bc 458->463 464 b20b5d-b20b60 458->464 459->460 470 b20e2b-b20e2c 460->470 476 b20bb1-b20bc5 call b4012f 463->476 477 b20bca-b20bd5 SetEvent 463->477 468 b20b62-b20b87 call b037d3 call b4012f 464->468 469 b20b8c-b20b91 464->469 468->470 471 b20e2d-b20e2f 469->471 470->471 475 b20e30-b20e40 471->475 476->471 480 b20c00-b20c0c WaitForSingleObject 477->480 481 b20bd7-b20bf6 GetLastError 477->481 484 b20c37-b20c42 ResetEvent 480->484 485 b20c0e-b20c2d GetLastError 480->485 481->480 486 b20c44-b20c63 GetLastError 484->486 487 b20c6d-b20c74 484->487 485->484 486->487 488 b20ce3-b20d05 CreateFileW 487->488 489 b20c76-b20c79 487->489 490 b20d42-b20d57 SetFilePointerEx 488->490 491 b20d07-b20d38 GetLastError call b037d3 488->491 492 b20ca0-b20ca7 call b038d4 489->492 493 b20c7b-b20c7e 489->493 497 b20d91-b20d9c SetEndOfFile 490->497 498 b20d59-b20d8c GetLastError call b037d3 490->498 491->490 505 b20cac-b20cb1 492->505 495 b20c80-b20c83 493->495 496 b20c99-b20c9b 493->496 495->469 501 b20c89-b20c8f 495->501 496->475 503 b20dd3-b20df0 SetFilePointerEx 497->503 504 b20d9e-b20dd1 GetLastError call b037d3 497->504 498->460 501->496 503->471 510 b20df2-b20e20 GetLastError call b037d3 503->510 504->460 508 b20cd2-b20cde 505->508 509 b20cb3-b20ccd call b037d3 505->509 508->471 509->460 510->460
                                      APIs
                                      • SetEvent.KERNEL32(?,?,?,?,00000000,00000000,?,00B20621,?,?), ref: 00B20A85
                                      • GetLastError.KERNEL32(?,?,?,00000000,00000000,?,00B20621,?,?), ref: 00B20A92
                                      • WaitForSingleObject.KERNEL32(?,?,?,?,?,00000000,00000000,?,00B20621,?,?), ref: 00B20ACE
                                      • GetLastError.KERNEL32(?,?,?,?,00000000,00000000,?,00B20621,?,?), ref: 00B20AD8
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$EventObjectSingleWait
                                      • String ID: Failed to allocate buffer for stream.$Failed to copy stream name: %ls$Failed to create file: %ls$Failed to reset begin operation event.$Failed to set end of file.$Failed to set file pointer to beginning of file.$Failed to set file pointer to end of file.$Failed to set operation complete event.$Failed to wait for begin operation event.$Invalid operation for this state.$cabextract.cpp
                                      • API String ID: 3600396749-2104912459
                                      • Opcode ID: a8fc7f9d6dbc9fef4383563e1c92f07e2f185b22181e862926a205acf3b34085
                                      • Instruction ID: e8aaf975985ea8ee71ccd84e4fde6668d474c33ea6327e3588794082b146507d
                                      • Opcode Fuzzy Hash: a8fc7f9d6dbc9fef4383563e1c92f07e2f185b22181e862926a205acf3b34085
                                      • Instruction Fuzzy Hash: 7A910F76A90731BBE7207A799D49F663AD4FF08751F0202A5BE09FB5A1E760CD0087D1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 660 b04c33-b04c7b call b2f670 call b033d7 665 b04c7d-b04c8a call b4012f 660->665 666 b04c8f-b04c99 call b196f2 660->666 673 b04e2b-b04e35 665->673 671 b04ca2-b04cb1 call b196f8 666->671 672 b04c9b-b04ca0 666->672 678 b04cb6-b04cba 671->678 674 b04cd7-b04cf2 call b01f20 672->674 676 b04e40-b04e44 673->676 677 b04e37-b04e3c CloseHandle 673->677 690 b04cf4-b04cf9 674->690 691 b04cfb-b04d0f call b16859 674->691 680 b04e46-b04e4b CloseHandle 676->680 681 b04e4f-b04e53 676->681 677->676 684 b04cd1-b04cd4 678->684 685 b04cbc 678->685 680->681 682 b04e55-b04e5a CloseHandle 681->682 683 b04e5e-b04e60 681->683 682->683 687 b04e62-b04e63 CloseHandle 683->687 688 b04e65-b04e79 call b02793 * 2 683->688 684->674 689 b04cc1-b04ccc call b4012f 685->689 687->688 706 b04e83-b04e87 688->706 707 b04e7b-b04e7e call b454ef 688->707 689->673 690->689 698 b04d11 691->698 699 b04d29-b04d3d call b16915 691->699 701 b04d16 698->701 709 b04d46-b04d61 call b01f62 699->709 710 b04d3f-b04d44 699->710 704 b04d1b-b04d24 call b4012f 701->704 717 b04e28 704->717 712 b04e91-b04e99 706->712 713 b04e89-b04e8c call b454ef 706->713 707->706 719 b04d63-b04d68 709->719 720 b04d6d-b04d86 call b01f62 709->720 710->701 713->712 717->673 719->689 723 b04d92-b04dbe CreateProcessW 720->723 724 b04d88-b04d8d 720->724 725 b04dc0-b04df6 GetLastError call b037d3 723->725 726 b04dfb-b04e1a call b40917 723->726 724->689 725->704 726->673 731 b04e1c-b04e23 call b4012f 726->731 731->717
                                      APIs
                                        • Part of subcall function 00B033D7: GetModuleFileNameW.KERNEL32(?,?,00000104,?,00000104,?,?,?,?,00B010DD,?,00000000), ref: 00B033F8
                                      • CloseHandle.KERNEL32(00000000,?,000000FF,?,?,?,?,?,00000000,?,?,?,?,?,?,00000000), ref: 00B04E3A
                                      • CloseHandle.KERNEL32(000000FF,?,000000FF,?,?,?,?,?,00000000,?,?,?,?,?,?,00000000), ref: 00B04E49
                                      • CloseHandle.KERNEL32(000000FF,?,000000FF,?,?,?,?,?,00000000,?,?,?,?,?,?,00000000), ref: 00B04E58
                                      • CloseHandle.KERNEL32(?,?,000000FF,?,?,?,?,?,00000000,?,?,?,?,?,?,00000000), ref: 00B04E63
                                      Strings
                                      • Failed to launch clean room process: %ls, xrefs: 00B04DF1
                                      • -%ls="%ls", xrefs: 00B04CE0
                                      • user.cpp, xrefs: 00B04DE4
                                      • Failed to append %ls, xrefs: 00B04D16
                                      • burn.clean.room, xrefs: 00B04CD8
                                      • Failed to allocate parameters for unelevated process., xrefs: 00B04CF4
                                      • %ls %ls, xrefs: 00B04D4F
                                      • burn.filehandle.self, xrefs: 00B04D3F
                                      • "%ls" %ls, xrefs: 00B04D74
                                      • Failed to get path for current process., xrefs: 00B04C7D
                                      • burn.filehandle.attached, xrefs: 00B04D11
                                      • Failed to cache to clean room., xrefs: 00B04CBC
                                      • D, xrefs: 00B04DA3
                                      • Failed to wait for clean room process: %ls, xrefs: 00B04E1D
                                      • Failed to allocate full command-line., xrefs: 00B04D88
                                      • Failed to append original command line., xrefs: 00B04D63
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseHandle$FileModuleName
                                      • String ID: "%ls" %ls$%ls %ls$-%ls="%ls"$D$Failed to allocate full command-line.$Failed to allocate parameters for unelevated process.$Failed to append %ls$Failed to append original command line.$Failed to cache to clean room.$Failed to get path for current process.$Failed to launch clean room process: %ls$Failed to wait for clean room process: %ls$burn.clean.room$burn.filehandle.attached$burn.filehandle.self$user.cpp
                                      • API String ID: 3884789274-2391192076
                                      • Opcode ID: 71646789c4d5d4012eedd500fc118b7a93f484085bb4096b57037433d3f7ef19
                                      • Instruction ID: 8b31fa2ee083d8c5ad6129f56493618e4c97b04c958a363a0eafaa371a8878b2
                                      • Opcode Fuzzy Hash: 71646789c4d5d4012eedd500fc118b7a93f484085bb4096b57037433d3f7ef19
                                      • Instruction Fuzzy Hash: 4D715471D01229BBDF219BA4CC81DEF7BF8EF04710F1042A5FB14B6291DB749A419BA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 838 b17337-b1737c call b2f670 call b07503 843 b17388-b17399 call b0c2a1 838->843 844 b1737e-b17383 838->844 850 b173a5-b173b6 call b0c108 843->850 851 b1739b-b173a0 843->851 845 b17602-b17609 call b4012f 844->845 852 b1760a-b1760f 845->852 857 b173c2-b173d7 call b0c362 850->857 858 b173b8-b173bd 850->858 851->845 855 b17611-b17612 call b454ef 852->855 856 b17617-b1761b 852->856 855->856 860 b17625-b1762a 856->860 861 b1761d-b17620 call b454ef 856->861 869 b173e3-b173f3 call b2bdc9 857->869 870 b173d9-b173de 857->870 858->845 864 b17632-b1763f call b0c055 860->864 865 b1762c-b1762d call b454ef 860->865 861->860 873 b17641-b17644 call b454ef 864->873 874 b17649-b1764d 864->874 865->864 882 b173f5-b173fa 869->882 883 b173ff-b17472 call b15a35 869->883 870->845 873->874 876 b17657-b1765b 874->876 877 b1764f-b17652 call b454ef 874->877 880 b17665-b1766d 876->880 881 b1765d-b17660 call b03999 876->881 877->876 881->880 882->845 887 b17474-b17479 883->887 888 b1747e-b174a6 call b0550f GetCurrentProcess call b4076c 883->888 887->845 892 b174ab-b174c2 call b08152 888->892 895 b174c4-b174d7 call b4012f 892->895 896 b174dc-b174e1 892->896 895->852 898 b174e3-b174f5 call b080f6 896->898 899 b1753d-b17542 896->899 910 b17501-b17511 call b03446 898->910 911 b174f7-b174fc 898->911 900 b17562-b1756b 899->900 901 b17544-b17556 call b080f6 899->901 905 b17577-b1758b call b1a307 900->905 906 b1756d-b17570 900->906 901->900 913 b17558-b1755d 901->913 917 b17594 905->917 918 b1758d-b17592 905->918 906->905 909 b17572-b17575 906->909 909->905 914 b1759a-b1759d 909->914 922 b17513-b17518 910->922 923 b1751d-b17531 call b080f6 910->923 911->845 913->845 919 b175a4-b175ba call b0d497 914->919 920 b1759f-b175a2 914->920 917->914 918->845 928 b175c3-b175db call b0cabe 919->928 929 b175bc-b175c1 919->929 920->852 920->919 922->845 923->899 930 b17533-b17538 923->930 933 b175e4-b175fb call b0c7df 928->933 934 b175dd-b175e2 928->934 929->845 930->845 933->852 937 b175fd 933->937 934->845 937->845
                                      Strings
                                      • Failed to set source process folder variable., xrefs: 00B17533
                                      • Failed to set original source variable., xrefs: 00B17558
                                      • WixBundleSourceProcessFolder, xrefs: 00B17522
                                      • Failed to load manifest., xrefs: 00B173F5
                                      • Failed to load catalog files., xrefs: 00B175FD
                                      • Failed to parse command line., xrefs: 00B17474
                                      • Failed to get source process folder from path., xrefs: 00B17513
                                      • Failed to overwrite the %ls built-in variable., xrefs: 00B174C9
                                      • Failed to get unique temporary folder for bootstrapper application., xrefs: 00B175BC
                                      • Failed to initialize internal cache functionality., xrefs: 00B1758D
                                      • WixBundleSourceProcessPath, xrefs: 00B174E6
                                      • Failed to open manifest stream., xrefs: 00B173B8
                                      • Failed to set source process path variable., xrefs: 00B174F7
                                      • Failed to open attached UX container., xrefs: 00B1739B
                                      • Failed to initialize variables., xrefs: 00B1737E
                                      • WixBundleElevated, xrefs: 00B174B3, 00B174C4
                                      • Failed to get manifest stream from container., xrefs: 00B173D9
                                      • Failed to extract bootstrapper application payloads., xrefs: 00B175DD
                                      • WixBundleOriginalSource, xrefs: 00B17547
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalInitializeSection
                                      • String ID: Failed to extract bootstrapper application payloads.$Failed to get manifest stream from container.$Failed to get source process folder from path.$Failed to get unique temporary folder for bootstrapper application.$Failed to initialize internal cache functionality.$Failed to initialize variables.$Failed to load catalog files.$Failed to load manifest.$Failed to open attached UX container.$Failed to open manifest stream.$Failed to overwrite the %ls built-in variable.$Failed to parse command line.$Failed to set original source variable.$Failed to set source process folder variable.$Failed to set source process path variable.$WixBundleElevated$WixBundleOriginalSource$WixBundleSourceProcessFolder$WixBundleSourceProcessPath
                                      • API String ID: 32694325-252221001
                                      • Opcode ID: c7d339778bfd0b0462deec5e5518b26bba206db8c64cd763c75929c82d77716a
                                      • Instruction ID: d5ce7e1c0da3f203e5873a7d8fe1b1bfde15f833b3453fba9f59e6aae3c3df10
                                      • Opcode Fuzzy Hash: c7d339778bfd0b0462deec5e5518b26bba206db8c64cd763c75929c82d77716a
                                      • Instruction Fuzzy Hash: 41916572988A19BBCB129AA4CC41FEEB7FCBF14700F4042E6F915E7151DB70EA849794
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      APIs
                                      • CreateFileW.KERNELBASE(00000000,40000000,00000005,00000000,00000002,08000080,00000000,?,00000000,00000000,00B04CB6,?,?,00000000,00B04CB6,00000000), ref: 00B18507
                                      • GetLastError.KERNEL32 ref: 00B18514
                                      • FindCloseChangeNotification.KERNELBASE(00000000,?,00000000,00B4B4F0,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00B186F6
                                      Strings
                                      • Failed to update signature offset., xrefs: 00B18615
                                      • Failed to copy user from: %ls to: %ls, xrefs: 00B1859C
                                      • Failed to seek to checksum in exe header., xrefs: 00B185F9
                                      • Failed to seek to beginning of user file: %ls, xrefs: 00B1856D
                                      • Failed to zero out original data offset., xrefs: 00B186E8
                                      • msi.dll, xrefs: 00B18608
                                      • cache.cpp, xrefs: 00B18538, 00B185EF, 00B18656, 00B186C5
                                      • Failed to seek to signature table in exe header., xrefs: 00B18660
                                      • cabinet.dll, xrefs: 00B1866F
                                      • Failed to seek to original data in exe burn section header., xrefs: 00B186CF
                                      • Failed to create user file at path: %ls, xrefs: 00B18545
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ChangeCloseCreateErrorFileFindLastNotification
                                      • String ID: Failed to copy user from: %ls to: %ls$Failed to create user file at path: %ls$Failed to seek to beginning of user file: %ls$Failed to seek to checksum in exe header.$Failed to seek to original data in exe burn section header.$Failed to seek to signature table in exe header.$Failed to update signature offset.$Failed to zero out original data offset.$cabinet.dll$cache.cpp$msi.dll
                                      • API String ID: 4091947256-1976062716
                                      • Opcode ID: fd05dce695fa678faee5d1b7bc361b65aaf22085f5afd41ef1f6e8c849f3900c
                                      • Instruction ID: 5f1b1755a099e8e05f6b60b0ea3fe2d8a92a2daf4b29fa847517a51687c171e6
                                      • Opcode Fuzzy Hash: fd05dce695fa678faee5d1b7bc361b65aaf22085f5afd41ef1f6e8c849f3900c
                                      • Instruction Fuzzy Hash: 1D51D772A41225BBEB116B689C49FBF36E8FB05B11F0101A5FE00F7291EF60CD1096E6
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 990 b180ae-b180f7 call b2f670 993 b18270-b1827d call b021a5 990->993 994 b180fd-b1810b GetCurrentProcess call b4076c 990->994 999 b1828c-b1829e call b2de36 993->999 1000 b1827f 993->1000 998 b18110-b1811d 994->998 1001 b18123-b18132 GetWindowsDirectoryW 998->1001 1002 b181ab-b181b9 998->1002 1003 b18284-b1828b call b4012f 1000->1003 1004 b18134-b18167 GetLastError call b037d3 1001->1004 1005 b1816c-b1817d call b0338f 1001->1005 1012 b181f3-b18205 UuidCreate 1002->1012 1013 b181bb-b181ee GetLastError call b037d3 1002->1013 1003->999 1004->1003 1020 b18189-b1819f call b036b4 1005->1020 1021 b1817f-b18184 1005->1021 1018 b18207-b1820c 1012->1018 1019 b1820e-b18223 StringFromGUID2 1012->1019 1013->1003 1018->1003 1023 b18241-b18262 call b01f20 1019->1023 1024 b18225-b1823f call b037d3 1019->1024 1020->1012 1029 b181a1-b181a6 1020->1029 1021->1003 1032 b18264-b18269 1023->1032 1033 b1826b 1023->1033 1024->1003 1029->1003 1032->1003 1033->993
                                      APIs
                                      • GetCurrentProcess.KERNEL32(00000000,00000000,00000000,00B05381), ref: 00B18104
                                        • Part of subcall function 00B4076C: OpenProcessToken.ADVAPI32(?,00000008,?,00B052B5,00000000,?,?,?,?,?,?,?,00B174AB,00000000), ref: 00B4078A
                                        • Part of subcall function 00B4076C: GetLastError.KERNEL32(?,?,?,?,?,?,?,00B174AB,00000000), ref: 00B40794
                                        • Part of subcall function 00B4076C: FindCloseChangeNotification.KERNELBASE(?,?,?,?,?,?,?,?,00B174AB,00000000), ref: 00B4081D
                                      • GetWindowsDirectoryW.KERNEL32(?,00000104,00000000), ref: 00B1812A
                                      • GetLastError.KERNEL32 ref: 00B18134
                                      • GetTempPathW.KERNEL32(00000104,?,00000000), ref: 00B181B1
                                      • GetLastError.KERNEL32 ref: 00B181BB
                                      Strings
                                      • Failed to append bundle id on to temp path for working folder., xrefs: 00B18264
                                      • Failed to convert working folder guid into string., xrefs: 00B1823A
                                      • Failed to copy working folder path., xrefs: 00B1827F
                                      • Temp\, xrefs: 00B18189
                                      • Failed to get temp path for working folder., xrefs: 00B181E9
                                      • %ls%ls\, xrefs: 00B1824C
                                      • Failed to create working folder guid., xrefs: 00B18207
                                      • Failed to get windows path for working folder., xrefs: 00B18162
                                      • cache.cpp, xrefs: 00B18158, 00B181DF, 00B18230
                                      • Failed to ensure windows path for working folder ended in backslash., xrefs: 00B1817F
                                      • Failed to concat Temp directory on windows path for working folder., xrefs: 00B181A1
                                      • 4#v, xrefs: 00B181B1
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$Process$ChangeCloseCurrentDirectoryFindNotificationOpenPathTempTokenWindows
                                      • String ID: 4#v$%ls%ls\$Failed to append bundle id on to temp path for working folder.$Failed to concat Temp directory on windows path for working folder.$Failed to convert working folder guid into string.$Failed to copy working folder path.$Failed to create working folder guid.$Failed to ensure windows path for working folder ended in backslash.$Failed to get temp path for working folder.$Failed to get windows path for working folder.$Temp\$cache.cpp
                                      • API String ID: 58964441-3587817078
                                      • Opcode ID: 88696d3a8c562d4dd3af2576a5c90baa92a7d1d62d5e7f70b9c78a345a545aa6
                                      • Instruction ID: 5e2170c0ec384d6e6baa303610ab3a4db96297f0d3497d65a00d2b42f2b1caeb
                                      • Opcode Fuzzy Hash: 88696d3a8c562d4dd3af2576a5c90baa92a7d1d62d5e7f70b9c78a345a545aa6
                                      • Instruction Fuzzy Hash: A141F672A4072477EB61A6A49C89FAA37E8BB04711F5001E5FE05F7190EE74CE488AE1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1034 b07503-b07dc0 InitializeCriticalSection 1035 b07dc3-b07de0 call b05530 1034->1035 1038 b07de2-b07de9 1035->1038 1039 b07ded-b07dfb call b4012f 1035->1039 1038->1035 1041 b07deb 1038->1041 1043 b07dfe-b07e10 call b2de36 1039->1043 1041->1043
                                      APIs
                                      • InitializeCriticalSection.KERNEL32(00B17378,00B052B5,00000000,00B0533D), ref: 00B07523
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalInitializeSection
                                      • String ID: #$$$'$0$Date$Failed to add built-in variable: %ls.$InstallerName$InstallerVersion$LogonUser$WixBundleAction$WixBundleActiveParent$WixBundleElevated$WixBundleExecutePackageAction$WixBundleExecutePackageCacheFolder$WixBundleForcedRestartPackage$WixBundleInstalled$WixBundleProviderKey$WixBundleSourceProcessFolder$WixBundleSourceProcessPath$WixBundleTag$WixBundleVersion
                                      • API String ID: 32694325-826827252
                                      • Opcode ID: ba6a8578919548e3f37ce42321b36cae3af07fdda099a2991f33317da85b4681
                                      • Instruction ID: e49530b2695093a656c1d9b4c8d7494c0e188daad37a1a471d755b2e32b1412d
                                      • Opcode Fuzzy Hash: ba6a8578919548e3f37ce42321b36cae3af07fdda099a2991f33317da85b4681
                                      • Instruction Fuzzy Hash: F9322DB1C262798BDBA5CF5989487DDBFF8BB49B04F5081DAE10CA6251D7B00B84DF84
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1046 b20e43-b20e6f CoInitializeEx 1047 b20e83-b20ece call b3f364 1046->1047 1048 b20e71-b20e7e call b4012f 1046->1048 1054 b20ed0-b20ef3 call b037d3 call b4012f 1047->1054 1055 b20ef8-b20f1a call b3f374 1047->1055 1053 b210df-b210f1 call b2de36 1048->1053 1075 b210d8-b210d9 CoUninitialize 1054->1075 1062 b20fd3-b20fde SetEvent 1055->1062 1063 b20f20-b20f28 1055->1063 1067 b20fe0-b21009 GetLastError call b037d3 1062->1067 1068 b2101b-b21029 WaitForSingleObject 1062->1068 1065 b210d0-b210d3 call b3f384 1063->1065 1066 b20f2e-b20f34 1063->1066 1065->1075 1066->1065 1073 b20f3a-b20f42 1066->1073 1089 b2100e-b21016 call b4012f 1067->1089 1071 b2105b-b21066 ResetEvent 1068->1071 1072 b2102b-b21059 GetLastError call b037d3 1068->1072 1079 b2109b-b210a1 1071->1079 1080 b21068-b21096 GetLastError call b037d3 1071->1080 1072->1089 1077 b20f44-b20f46 1073->1077 1078 b20fbb-b20fce call b4012f 1073->1078 1075->1053 1083 b20f58-b20f5b 1077->1083 1084 b20f48-b20f56 1077->1084 1078->1065 1087 b210a3-b210a6 1079->1087 1088 b210cb 1079->1088 1080->1089 1091 b20fb5 1083->1091 1092 b20f5d 1083->1092 1090 b20fb7-b20fb9 1084->1090 1095 b210c7-b210c9 1087->1095 1096 b210a8-b210c2 call b037d3 1087->1096 1088->1065 1089->1065 1090->1062 1090->1078 1091->1090 1098 b20f72-b20f77 1092->1098 1099 b20fa3-b20fa8 1092->1099 1100 b20f80-b20f85 1092->1100 1101 b20fb1-b20fb3 1092->1101 1102 b20f87-b20f8c 1092->1102 1103 b20f64-b20f69 1092->1103 1104 b20f95-b20f9a 1092->1104 1105 b20faa-b20faf 1092->1105 1106 b20f6b-b20f70 1092->1106 1107 b20f79-b20f7e 1092->1107 1108 b20f8e-b20f93 1092->1108 1109 b20f9c-b20fa1 1092->1109 1095->1065 1096->1089 1098->1078 1099->1078 1100->1078 1101->1078 1102->1078 1103->1078 1104->1078 1105->1078 1106->1078 1107->1078 1108->1078 1109->1078
                                      APIs
                                      • CoInitializeEx.OLE32(00000000,00000000), ref: 00B20E65
                                      • CoUninitialize.OLE32 ref: 00B210D9
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: InitializeUninitialize
                                      • String ID: <the>.cab$Failed to extract all files from container, erf: %d:%X:%d$Failed to initialize COM.$Failed to initialize cabinet.dll.$Failed to reset begin operation event.$Failed to set operation complete event.$Failed to wait for begin operation event.$Invalid operation for this state.$cabextract.cpp
                                      • API String ID: 3442037557-1168358783
                                      • Opcode ID: 498f2513c3e9025cf1f85d38df1fcd638947393b9bc3f768ecd21f56329a3187
                                      • Instruction ID: 6a0ca79bb4f5d34c9efcb30ebc751ed213892f24680744f26eb8ede8ff085460
                                      • Opcode Fuzzy Hash: 498f2513c3e9025cf1f85d38df1fcd638947393b9bc3f768ecd21f56329a3187
                                      • Instruction Fuzzy Hash: 70519E36EA0331E7D7303668AD85E6B79E4DB54720F2203E5FD0ABB2D1D6648D009BD2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1113 b041d2-b04229 InitializeCriticalSection * 2 call b14b0e * 2 1118 b0434d-b04357 call b0b389 1113->1118 1119 b0422f 1113->1119 1124 b0435c-b04360 1118->1124 1120 b04235-b04242 1119->1120 1122 b04340-b04347 1120->1122 1123 b04248-b04274 lstrlenW * 2 CompareStringW 1120->1123 1122->1118 1122->1120 1125 b042c6-b042f2 lstrlenW * 2 CompareStringW 1123->1125 1126 b04276-b04299 lstrlenW 1123->1126 1127 b04362-b0436e call b4012f 1124->1127 1128 b0436f-b04377 1124->1128 1125->1122 1129 b042f4-b04317 lstrlenW 1125->1129 1130 b04385-b0439a call b037d3 1126->1130 1131 b0429f-b042a4 1126->1131 1127->1128 1134 b043b1-b043cb call b037d3 1129->1134 1135 b0431d-b04322 1129->1135 1143 b0439f-b043a6 1130->1143 1131->1130 1136 b042aa-b042ba call b029dc 1131->1136 1134->1143 1135->1134 1139 b04328-b04338 call b029dc 1135->1139 1146 b042c0 1136->1146 1147 b0437a-b04383 1136->1147 1139->1147 1151 b0433a 1139->1151 1148 b043a7-b043af call b4012f 1143->1148 1146->1125 1147->1148 1148->1128 1151->1122
                                      APIs
                                      • InitializeCriticalSection.KERNEL32(00000000,?,00000000,00000000,?,?,00B0515E,?,?,00000000,?,?), ref: 00B041FE
                                      • InitializeCriticalSection.KERNEL32(000000D0,?,?,00B0515E,?,?,00000000,?,?), ref: 00B04207
                                      • lstrlenW.KERNEL32(burn.filehandle.attached,000004B8,000004A0,?,?,00B0515E,?,?,00000000,?,?), ref: 00B0424D
                                      • lstrlenW.KERNEL32(burn.filehandle.attached,burn.filehandle.attached,00000000,?,?,00B0515E,?,?,00000000,?,?), ref: 00B04257
                                      • CompareStringW.KERNEL32(0000007F,00000001,?,00000000,?,?,00B0515E,?,?,00000000,?,?), ref: 00B0426B
                                      • lstrlenW.KERNEL32(burn.filehandle.attached,?,?,00B0515E,?,?,00000000,?,?), ref: 00B0427B
                                      • lstrlenW.KERNEL32(burn.filehandle.self,?,?,00B0515E,?,?,00000000,?,?), ref: 00B042CB
                                      • lstrlenW.KERNEL32(burn.filehandle.self,burn.filehandle.self,00000000,?,?,00B0515E,?,?,00000000,?,?), ref: 00B042D5
                                      • CompareStringW.KERNEL32(0000007F,00000001,?,00000000,?,?,00B0515E,?,?,00000000,?,?), ref: 00B042E9
                                      • lstrlenW.KERNEL32(burn.filehandle.self,?,?,00B0515E,?,?,00000000,?,?), ref: 00B042F9
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: lstrlen$CompareCriticalInitializeSectionString
                                      • String ID: Failed to initialize user section.$Failed to parse file handle: '%ls'$Missing required parameter for switch: %ls$burn.filehandle.attached$burn.filehandle.self$user.cpp
                                      • API String ID: 3039292287-3209860532
                                      • Opcode ID: f435ca1852bb44ec2510f1e042f482973f2e1e730c50aba3a51d206b0a947f3f
                                      • Instruction ID: f9b49a0f35d595d5c83a908ba68a7a6a6e0f381f336fcd7ad74ba63f76ca9268
                                      • Opcode Fuzzy Hash: f435ca1852bb44ec2510f1e042f482973f2e1e730c50aba3a51d206b0a947f3f
                                      • Instruction Fuzzy Hash: D45188B1A40215BFC7249B69DC86F9A7BECFB05760F0041A5F714E72A0DB70EA50D794
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1153 b0c129-b0c15b 1154 b0c1c5-b0c1e1 GetCurrentProcess * 2 DuplicateHandle 1153->1154 1155 b0c15d-b0c17b CreateFileW 1153->1155 1156 b0c1e3-b0c219 GetLastError call b037d3 1154->1156 1157 b0c21b 1154->1157 1158 b0c181-b0c1b2 GetLastError call b037d3 1155->1158 1159 b0c21d-b0c223 1155->1159 1167 b0c1b7-b0c1c0 call b4012f 1156->1167 1157->1159 1158->1167 1161 b0c225-b0c22b 1159->1161 1162 b0c22d 1159->1162 1165 b0c22f-b0c23d SetFilePointerEx 1161->1165 1162->1165 1168 b0c274-b0c27a 1165->1168 1169 b0c23f-b0c272 GetLastError call b037d3 1165->1169 1171 b0c298-b0c29e 1167->1171 1168->1171 1172 b0c27c-b0c280 call b21484 1168->1172 1177 b0c290-b0c297 call b4012f 1169->1177 1178 b0c285-b0c289 1172->1178 1177->1171 1178->1171 1180 b0c28b 1178->1180 1180->1177
                                      APIs
                                      • CreateFileW.KERNEL32(00000000,80000000,00000001,00000000,00000003,08000080,00000000,?,00000000,00000000,?,00B0C319,00B052FD,?,?,00B0533D), ref: 00B0C170
                                      • GetLastError.KERNEL32(?,00B0C319,00B052FD,?,?,00B0533D,00B0533D,00000000,?,00000000), ref: 00B0C181
                                      • GetCurrentProcess.KERNEL32(?,00000000,00000000,00000002,?,00000000,00000000,?,00B0C319,00B052FD,?,?,00B0533D,00B0533D,00000000,?), ref: 00B0C1D0
                                      • GetCurrentProcess.KERNEL32(000000FF,00000000,?,00B0C319,00B052FD,?,?,00B0533D,00B0533D,00000000,?,00000000), ref: 00B0C1D6
                                      • DuplicateHandle.KERNELBASE(00000000,?,00B0C319,00B052FD,?,?,00B0533D,00B0533D,00000000,?,00000000), ref: 00B0C1D9
                                      • GetLastError.KERNEL32(?,00B0C319,00B052FD,?,?,00B0533D,00B0533D,00000000,?,00000000), ref: 00B0C1E3
                                      • SetFilePointerEx.KERNELBASE(?,00000000,00000000,00000000,00000000,?,00B0C319,00B052FD,?,?,00B0533D,00B0533D,00000000,?,00000000), ref: 00B0C235
                                      • GetLastError.KERNEL32(?,00B0C319,00B052FD,?,?,00B0533D,00B0533D,00000000,?,00000000), ref: 00B0C23F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CurrentFileProcess$CreateDuplicateHandlePointer
                                      • String ID: Failed to duplicate handle to container: %ls$Failed to move file pointer to container offset.$Failed to open container.$Failed to open file: %ls$container.cpp$crypt32.dll$feclient.dll
                                      • API String ID: 2619879409-373955632
                                      • Opcode ID: fe06b3549c411aca370d24a9018bddb5829989b3dedbb19bb3e074a70eb2adc2
                                      • Instruction ID: 1a46c7c496e7b54f9087b12a57172ff1c005e1f7da645d095e0c7ffdf8550d00
                                      • Opcode Fuzzy Hash: fe06b3549c411aca370d24a9018bddb5829989b3dedbb19bb3e074a70eb2adc2
                                      • Instruction Fuzzy Hash: 9041A176240301ABEB209F699C89E673FE9EB85750F1142A9FD18EB291DB31C901DB61
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1182 b429b3-b429d3 call b037ea 1185 b42af2-b42af6 1182->1185 1186 b429d9-b429e7 call b44932 1182->1186 1188 b42b00-b42b06 1185->1188 1189 b42af8-b42afb call b454ef 1185->1189 1190 b429ec-b42af1 GetProcAddress * 7 1186->1190 1189->1188 1190->1185
                                      APIs
                                        • Part of subcall function 00B037EA: GetSystemDirectoryW.KERNEL32(?,00000104), ref: 00B03829
                                        • Part of subcall function 00B037EA: GetLastError.KERNEL32 ref: 00B03833
                                        • Part of subcall function 00B44932: GetLastError.KERNEL32(?,00000000,00000000,00000000,00000000), ref: 00B4495A
                                      • GetProcAddress.KERNEL32(MsiDeterminePatchSequenceW,00000000), ref: 00B429FD
                                      • GetProcAddress.KERNEL32(MsiDetermineApplicablePatchesW), ref: 00B42A20
                                      • GetProcAddress.KERNEL32(MsiEnumProductsExW), ref: 00B42A43
                                      • GetProcAddress.KERNEL32(MsiGetPatchInfoExW), ref: 00B42A66
                                      • GetProcAddress.KERNEL32(MsiGetProductInfoExW), ref: 00B42A89
                                      • GetProcAddress.KERNEL32(MsiSetExternalUIRecord), ref: 00B42AAC
                                      • GetProcAddress.KERNEL32(MsiSourceListAddSourceExW), ref: 00B42ACF
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressProc$ErrorLast$DirectorySystem
                                      • String ID: Msi.dll$MsiDetermineApplicablePatchesW$MsiDeterminePatchSequenceW$MsiEnumProductsExW$MsiGetPatchInfoExW$MsiGetProductInfoExW$MsiSetExternalUIRecord$MsiSourceListAddSourceExW
                                      • API String ID: 2510051996-1735120554
                                      • Opcode ID: 90956991ab784e5f3df339dd1779989d06b4366dbb95574ced618012a46b48d5
                                      • Instruction ID: 92c878a3b2e8f84a0ec7d17d617d10d22a04ae6f4290b051994ae2bee99b8f84
                                      • Opcode Fuzzy Hash: 90956991ab784e5f3df339dd1779989d06b4366dbb95574ced618012a46b48d5
                                      • Instruction Fuzzy Hash: 7D31B3B0A42208AFDB18DF25EC52E29BBF5AB54700741456EE50AD32F0EFF999909F50
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,wininet.dll,?,00000000,00000000,00000000,?,?,00B0C285,?,00000000,?,00B0C319), ref: 00B214BB
                                      • GetLastError.KERNEL32(?,00B0C285,?,00000000,?,00B0C319,00B052FD,?,?,00B0533D,00B0533D,00000000,?,00000000), ref: 00B214C4
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateErrorEventLast
                                      • String ID: Failed to copy file name.$Failed to create begin operation event.$Failed to create extraction thread.$Failed to create operation complete event.$Failed to wait for operation complete.$cabextract.cpp$wininet.dll
                                      • API String ID: 545576003-938279966
                                      • Opcode ID: 1362e5756bbc2f7204d3e1bdc30c5119f4b572b62fe1971748b34ae298890c1c
                                      • Instruction ID: 1148927c9ac3a92feeaa0907f1be45a0eea04e58f47ad60f2379f268ae62eba7
                                      • Opcode Fuzzy Hash: 1362e5756bbc2f7204d3e1bdc30c5119f4b572b62fe1971748b34ae298890c1c
                                      • Instruction Fuzzy Hash: AE214BB2A40739BAF720267D6C85F672DECEF58790F0102E2BD09F7190EA50DD0085E2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcAddress.KERNELBASE(SystemFunction040,AdvApi32.dll), ref: 00B3FBD5
                                      • GetProcAddress.KERNEL32(SystemFunction041), ref: 00B3FBE7
                                      • GetProcAddress.KERNEL32(CryptProtectMemory,Crypt32.dll), ref: 00B3FC2A
                                      • GetLastError.KERNEL32(?,?,?,?,?,?), ref: 00B3FC3E
                                      • GetProcAddress.KERNEL32(CryptUnprotectMemory), ref: 00B3FC76
                                      • GetLastError.KERNEL32(?,?,?,?,?,?), ref: 00B3FC8A
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressProc$ErrorLast
                                      • String ID: AdvApi32.dll$Crypt32.dll$CryptProtectMemory$CryptUnprotectMemory$SystemFunction040$SystemFunction041$cryputil.cpp
                                      • API String ID: 4214558900-3191127217
                                      • Opcode ID: 491d02add2645bac5c494ff50d6653b6b009c5e19bfd8f61e9a8e9342d3225f9
                                      • Instruction ID: 2549b85ebeeed2b69e7b48545fd330f87bfe2f9f0c8d7e1d35d5582ed1a16916
                                      • Opcode Fuzzy Hash: 491d02add2645bac5c494ff50d6653b6b009c5e19bfd8f61e9a8e9342d3225f9
                                      • Instruction Fuzzy Hash: 63218A75E813279BD7215B269D24F627AE8FB21751F1101B5EC05E72F0EFA88C819ED0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringA.KERNELBASE(00000000,00000000,<the>.cab,?,?), ref: 00B20657
                                      • GetCurrentProcess.KERNEL32(?,00000000,00000000,00000000,?,?), ref: 00B2066F
                                      • GetCurrentProcess.KERNEL32(?,00000000,?,?), ref: 00B20674
                                      • DuplicateHandle.KERNELBASE(00000000,?,?), ref: 00B20677
                                      • GetLastError.KERNEL32(?,?), ref: 00B20681
                                      • CreateFileA.KERNEL32(?,80000000,00000001,00000000,00000003,08000080,00000000,?,?), ref: 00B206F0
                                      • GetLastError.KERNEL32(?,?), ref: 00B206FD
                                      Strings
                                      • Failed to duplicate handle to cab container., xrefs: 00B206AF
                                      • Failed to open cabinet file: %hs, xrefs: 00B2072E
                                      • <the>.cab, xrefs: 00B20650
                                      • cabextract.cpp, xrefs: 00B206A5, 00B20721
                                      • Failed to add virtual file pointer for cab container., xrefs: 00B206D6
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CurrentErrorLastProcess$CompareCreateDuplicateFileHandleString
                                      • String ID: <the>.cab$Failed to add virtual file pointer for cab container.$Failed to duplicate handle to cab container.$Failed to open cabinet file: %hs$cabextract.cpp
                                      • API String ID: 3030546534-3446344238
                                      • Opcode ID: 718841da380910a0fd3ad59b96d2d53e85a98c1afdd60b89452eee964a86d97f
                                      • Instruction ID: 0f21e6252a825d33bb471e587b2e5bd66324032fc749a7e4c0d49b7c389e0deb
                                      • Opcode Fuzzy Hash: 718841da380910a0fd3ad59b96d2d53e85a98c1afdd60b89452eee964a86d97f
                                      • Instruction Fuzzy Hash: FF31C375A11235BBEB216BA59C48F9B7EECEF05760F000295FE08B71A0D7609E108AE1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentProcess.KERNEL32(000000FF,00000000,00000001,00000002,?,00000000,?,?,00B04D0B,?,?), ref: 00B16879
                                      • GetCurrentProcess.KERNEL32(?,00000000,?,?,00B04D0B,?,?), ref: 00B1687F
                                      • DuplicateHandle.KERNELBASE(00000000,?,?,00B04D0B,?,?), ref: 00B16882
                                      • GetLastError.KERNEL32(?,?,00B04D0B,?,?), ref: 00B1688C
                                      • CloseHandle.KERNEL32(000000FF,?,00B04D0B,?,?), ref: 00B16905
                                      Strings
                                      • Failed to duplicate file handle for attached container., xrefs: 00B168BA
                                      • burn.filehandle.attached, xrefs: 00B168D2
                                      • %ls -%ls=%u, xrefs: 00B168D9
                                      • core.cpp, xrefs: 00B168B0
                                      • Failed to append the file handle to the command line., xrefs: 00B168ED
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CurrentHandleProcess$CloseDuplicateErrorLast
                                      • String ID: %ls -%ls=%u$Failed to append the file handle to the command line.$Failed to duplicate file handle for attached container.$burn.filehandle.attached$core.cpp
                                      • API String ID: 4224961946-4196573879
                                      • Opcode ID: a7d1559520145af0a9f02750273acc24174885902a7de99cf43f49994377111f
                                      • Instruction ID: 10262d07411a214a6d7b71d936248b107c1f9825c7c26030bf6703da6f15c91a
                                      • Opcode Fuzzy Hash: a7d1559520145af0a9f02750273acc24174885902a7de99cf43f49994377111f
                                      • Instruction Fuzzy Hash: F2118435A41715BBDB20ABB99D05E9A7BECEF05B71F1002A6FD10F72E0D7718E009690
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNELBASE(?,80000000,00000005,?,00000003,00000080,00000000,?,00000000,?,?,?), ref: 00B1694B
                                      • CloseHandle.KERNEL32(00000000), ref: 00B169BB
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateFileHandle
                                      • String ID: %ls -%ls=%u$Failed to append the file handle to the command line.$Failed to append the file handle to the obfuscated command line.$burn.filehandle.self
                                      • API String ID: 3498533004-3263533295
                                      • Opcode ID: e8314c3afa4e5433e928e1dc5d3befc980aacaa218e6a2d261b9c21245463fce
                                      • Instruction ID: 23bf48d675e02f98a4ff5bac792660cae985b267d73abb0aa2522f73e04fd20d
                                      • Opcode Fuzzy Hash: e8314c3afa4e5433e928e1dc5d3befc980aacaa218e6a2d261b9c21245463fce
                                      • Instruction Fuzzy Hash: D811E232600610BBCB205A6C9C45F9B7BECEB49B71F4103E0FE24AB2E1E77099548691
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • OpenProcessToken.ADVAPI32(?,00000008,?,00B052B5,00000000,?,?,?,?,?,?,?,00B174AB,00000000), ref: 00B4078A
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,00B174AB,00000000), ref: 00B40794
                                      • GetTokenInformation.KERNELBASE(?,00000014(TokenIntegrityLevel),?,00000004,?,?,?,?,?,?,?,?,00B174AB,00000000), ref: 00B407C6
                                      • FindCloseChangeNotification.KERNELBASE(?,?,?,?,?,?,?,?,00B174AB,00000000), ref: 00B4081D
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Token$ChangeCloseErrorFindInformationLastNotificationOpenProcess
                                      • String ID: procutil.cpp
                                      • API String ID: 2387526074-1178289305
                                      • Opcode ID: b53f70f736cefcde2ca58381ebe61e561e278c067b5fc47be86d018b0caeac30
                                      • Instruction ID: 42f7a3d81615a1bba97458130a19ae0db3d9e0618cb4ef2aa241685ecbaf68d9
                                      • Opcode Fuzzy Hash: b53f70f736cefcde2ca58381ebe61e561e278c067b5fc47be86d018b0caeac30
                                      • Instruction Fuzzy Hash: 5721C675D10228EBDB20AB999D44AAEBBE8EF44711F1140A6EE05E7250D7308F00EBD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CoInitialize.OLE32(00000000), ref: 00B4344A
                                      • InterlockedIncrement.KERNEL32(00B6B6D8), ref: 00B43467
                                      • CLSIDFromProgID.OLE32(Msxml2.DOMDocument,00B6B6C8,?,?,?,?,?,?), ref: 00B43482
                                      • CLSIDFromProgID.OLE32(MSXML.DOMDocument,00B6B6C8,?,?,?,?,?,?), ref: 00B4348E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FromProg$IncrementInitializeInterlocked
                                      • String ID: MSXML.DOMDocument$Msxml2.DOMDocument
                                      • API String ID: 2109125048-2356320334
                                      • Opcode ID: d2f85493e512a496640bedca2d22d1dadc2e0b23697a97440630daf32581d73f
                                      • Instruction ID: d50cbf085d9ef60fc6935e251f1120c8f538d03aa72fac4dd7c7985489b29f12
                                      • Opcode Fuzzy Hash: d2f85493e512a496640bedca2d22d1dadc2e0b23697a97440630daf32581d73f
                                      • Instruction Fuzzy Hash: C1F0A02174423556DB224BBAEC4DF5BAFF4EF81F64B140098E901D22A4DBA8CB8196A0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetLastError.KERNEL32(?,00000000,00000000,00000000,00000000), ref: 00B4495A
                                      • GlobalAlloc.KERNELBASE(00000000,00000000,?,00000000,00000000,00000000,00000000), ref: 00B44989
                                      • GetLastError.KERNEL32(?,00000000,00000000,00000000), ref: 00B449B3
                                      • GetLastError.KERNEL32(00000000,00B4B790,?,?,?,00000000,00000000,00000000), ref: 00B449F4
                                      • GlobalFree.KERNEL32(00000000), ref: 00B44A28
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$Global$AllocFree
                                      • String ID: fileutil.cpp
                                      • API String ID: 1145190524-2967768451
                                      • Opcode ID: 35412b7730069dd17c09e7848fdb6f53af8c561c16bb1a728ea3499bbcc86870
                                      • Instruction ID: bd4911406424760ef2c173f6d1d56ec7d90846a2eeb25c6dc12992b9d7b6d5f6
                                      • Opcode Fuzzy Hash: 35412b7730069dd17c09e7848fdb6f53af8c561c16bb1a728ea3499bbcc86870
                                      • Instruction Fuzzy Hash: D821D779A40329ABD7119BA58C45EABBBECEF85361F1141A6FD05E7210DB30CE10E6E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetFilePointerEx.KERNELBASE(?,?,?,?,?,?,?,?,?,?,?), ref: 00B2088A
                                      • GetLastError.KERNEL32(?,?,?), ref: 00B20894
                                      Strings
                                      • Invalid seek type., xrefs: 00B20820
                                      • Failed to move file pointer 0x%x bytes., xrefs: 00B208C5
                                      • cabextract.cpp, xrefs: 00B208B8
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastPointer
                                      • String ID: Failed to move file pointer 0x%x bytes.$Invalid seek type.$cabextract.cpp
                                      • API String ID: 2976181284-417918914
                                      • Opcode ID: cf66b86483a84865548c84c3d18d5466a9632c60328688847d0ccbed29305663
                                      • Instruction ID: 16a81ca03e21f13e990c2c396350f0b43b2facc88e6d8a13bc7afc9282e31d1e
                                      • Opcode Fuzzy Hash: cf66b86483a84865548c84c3d18d5466a9632c60328688847d0ccbed29305663
                                      • Instruction Fuzzy Hash: DC318471A10619FFDB04DF69DC84D5AB7F9FB08710B008259F919A7651D730ED118BD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateDirectoryW.KERNELBASE(00B0533D,00B053B5,00000000,00000000,?,00B19EE4,00000000,00000000,00B0533D,00000000,00B052B5,00000000,?,?,00B0D4AC,00B0533D), ref: 00B04021
                                      • GetLastError.KERNEL32(?,00B19EE4,00000000,00000000,00B0533D,00000000,00B052B5,00000000,?,?,00B0D4AC,00B0533D,00000000,00000000), ref: 00B0402F
                                      • CreateDirectoryW.KERNEL32(00B0533D,00B053B5,00B05381,?,00B19EE4,00000000,00000000,00B0533D,00000000,00B052B5,00000000,?,?,00B0D4AC,00B0533D,00000000), ref: 00B04097
                                      • GetLastError.KERNEL32(?,00B19EE4,00000000,00000000,00B0533D,00000000,00B052B5,00000000,?,?,00B0D4AC,00B0533D,00000000,00000000), ref: 00B040A1
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateDirectoryErrorLast
                                      • String ID: dirutil.cpp
                                      • API String ID: 1375471231-2193988115
                                      • Opcode ID: 5ca4b814d3c40388cf1a6f097958339acf84b9b1d80a9b743b7ddd59def6bb9a
                                      • Instruction ID: 9893d47dfeb9fd7f9763adcdcec8fb5f0d2323a63355b5498a55c2a86587fad1
                                      • Opcode Fuzzy Hash: 5ca4b814d3c40388cf1a6f097958339acf84b9b1d80a9b743b7ddd59def6bb9a
                                      • Instruction Fuzzy Hash: 7911E7B9600221A6EB311BA15C44B3BBED8EF51BA0F1041A5FF05FB1D0F7608D0192E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNELBASE(0000007F,00001000,?,000000FF,version.dll,000000FF,?,00000000,00000007,00B0648B,00B0648B,?,00B0554A,?,?,00000000), ref: 00B055F2
                                      • GetLastError.KERNEL32(?,00B0554A,?,?,00000000,?,00000000,00B0648B,?,00B07DDC,?,?,?,?,?), ref: 00B05621
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareErrorLastString
                                      • String ID: Failed to compare strings.$variable.cpp$version.dll
                                      • API String ID: 1733990998-4228644734
                                      • Opcode ID: 6be8f6d47d53f8228c94b6414b03e6ad6c801aad89290807465e14ed9d655baf
                                      • Instruction ID: 0ea36bcad5c47aaa64a1470c1a9c1babe41f3d59a547e1236757b6cd549bc2db
                                      • Opcode Fuzzy Hash: 6be8f6d47d53f8228c94b6414b03e6ad6c801aad89290807465e14ed9d655baf
                                      • Instruction Fuzzy Hash: AC21F932610614AFC7248FA8CC44A6ABBE4FF49760F650399F915FB6D0DA32DE019A90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B2114F: SetFilePointerEx.KERNELBASE(?,?,?,00000000,00000000,?,?,?,00000000,?,00B2077D,?,?,?), ref: 00B21177
                                        • Part of subcall function 00B2114F: GetLastError.KERNEL32(?,00B2077D,?,?,?), ref: 00B21181
                                      • ReadFile.KERNELBASE(?,?,?,?,00000000,?,?,?), ref: 00B2078B
                                      • GetLastError.KERNEL32 ref: 00B20795
                                      Strings
                                      • Failed to read during cabinet extraction., xrefs: 00B207C3
                                      • cabextract.cpp, xrefs: 00B207B9
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLast$PointerRead
                                      • String ID: Failed to read during cabinet extraction.$cabextract.cpp
                                      • API String ID: 2170121939-2426083571
                                      • Opcode ID: a18d69bbb9d0867b0d4c22a04f0f2e8d3b98119da0978286b0b9e8de538fe648
                                      • Instruction ID: c8281be78e408af4e86ca3a320d1a9793a603edf33403ad9ad6a1840b2b9ac37
                                      • Opcode Fuzzy Hash: a18d69bbb9d0867b0d4c22a04f0f2e8d3b98119da0978286b0b9e8de538fe648
                                      • Instruction Fuzzy Hash: 8901A572600224BBDB109FA8DC04E9A7BE9FF09760F010159FE09E7690D7319E109BD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetFilePointerEx.KERNELBASE(?,?,?,00000000,00000000,?,?,?,00000000,?,00B2077D,?,?,?), ref: 00B21177
                                      • GetLastError.KERNEL32(?,00B2077D,?,?,?), ref: 00B21181
                                      Strings
                                      • Failed to move to virtual file pointer., xrefs: 00B211AF
                                      • cabextract.cpp, xrefs: 00B211A5
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastPointer
                                      • String ID: Failed to move to virtual file pointer.$cabextract.cpp
                                      • API String ID: 2976181284-3005670968
                                      • Opcode ID: b977d5cec0106438b6dd096d3f3a4bcdbe8168b9935157b1d6434b7d1fcc95b6
                                      • Instruction ID: a33603fde005aa0e645d20ef85006fddd2f4a1c9187773f934fd3094e3630355
                                      • Opcode Fuzzy Hash: b977d5cec0106438b6dd096d3f3a4bcdbe8168b9935157b1d6434b7d1fcc95b6
                                      • Instruction Fuzzy Hash: E701F236600235BBD7211A6AAC04E87BFE9EF017A2B008269FE0CA6150DB31CD20C6D1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ReadFile.KERNELBASE(?,?,00000000,?,00000000), ref: 00B43E5E
                                      • GetLastError.KERNEL32 ref: 00B43EC1
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastRead
                                      • String ID: fileutil.cpp
                                      • API String ID: 1948546556-2967768451
                                      • Opcode ID: 80f05e91d6352386fa80b6fa22acce4389838d925b7ccb99220861bc66972cbc
                                      • Instruction ID: c6f886becb31f2e85aea917003a481fe72102838e4a4bd436ccb2a30a07a72d6
                                      • Opcode Fuzzy Hash: 80f05e91d6352386fa80b6fa22acce4389838d925b7ccb99220861bc66972cbc
                                      • Instruction Fuzzy Hash: 73415E71E412699BDF21CE14C8807EAB7F4FF48B51F0441E6A949E7240D7B59FC49BA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WriteFile.KERNELBASE(00000000,00000000,00000000,?,00000000,?,00000000,?,?,?,00B43E85,?,?,?), ref: 00B44D12
                                      • GetLastError.KERNEL32(?,?,00B43E85,?,?,?), ref: 00B44D1C
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastWrite
                                      • String ID: fileutil.cpp
                                      • API String ID: 442123175-2967768451
                                      • Opcode ID: 182c3d362bff87cbf41db402f9c0fb3ec8ad5d5345e10f77059cde98430b7296
                                      • Instruction ID: 83b45d4650b243d45e3dcf4374a646a4baaa543a62914c7aaec0db472546ed3d
                                      • Opcode Fuzzy Hash: 182c3d362bff87cbf41db402f9c0fb3ec8ad5d5345e10f77059cde98430b7296
                                      • Instruction Fuzzy Hash: E0F08172A01229BBD7109E9ACD45F9BBBEDFB44761F0041A6FD04D7140DB30EE1096E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetFilePointerEx.KERNELBASE(?,?,?,?,?,00000000,?,?,?,00B18564,00000000,00000000,00000000,00000000,00000000), ref: 00B447EB
                                      • GetLastError.KERNEL32(?,?,?,00B18564,00000000,00000000,00000000,00000000,00000000), ref: 00B447F5
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastPointer
                                      • String ID: fileutil.cpp
                                      • API String ID: 2976181284-2967768451
                                      • Opcode ID: 1a09f39ddabc4cb258f95b8ea163a89162be561de7f8c855c2ee15905bb40920
                                      • Instruction ID: fe4bae62bd95bc36991652ac08c557bf123d89c975ddad4e41c0fe61859a6941
                                      • Opcode Fuzzy Hash: 1a09f39ddabc4cb258f95b8ea163a89162be561de7f8c855c2ee15905bb40920
                                      • Instruction Fuzzy Hash: 4CF06D75A00219AB9B108F958C08EAB7BE8EB04751B014159BD0597260D731CD20D6E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetSystemDirectoryW.KERNEL32(?,00000104), ref: 00B03829
                                      • GetLastError.KERNEL32 ref: 00B03833
                                      • LoadLibraryW.KERNELBASE(?,?,00000104,?), ref: 00B0389B
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: DirectoryErrorLastLibraryLoadSystem
                                      • String ID:
                                      • API String ID: 1230559179-0
                                      • Opcode ID: 408e9a3d2437a74943ca01bea782a3e822eaf12697dc4b74e575bafe9e971b02
                                      • Instruction ID: d39b6d694fb21b9dca135602fd3e86d1b4a83e3c20357c7bef550f30d3cb8cd2
                                      • Opcode Fuzzy Hash: 408e9a3d2437a74943ca01bea782a3e822eaf12697dc4b74e575bafe9e971b02
                                      • Instruction Fuzzy Hash: 26219BB6D0132967EB209B649C4DF9A7BECEB05B10F1141E5BE04E7281EA74DE448790
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcessHeap.KERNEL32(00000000,00000000,00000000,?,00B03B34,00000000,?,00B01472,00000000,80004005,00000000,80004005,00000000,000001C7,?,00B013B7), ref: 00B039A3
                                      • RtlFreeHeap.NTDLL(00000000,?,00B03B34,00000000,?,00B01472,00000000,80004005,00000000,80004005,00000000,000001C7,?,00B013B7,000001C7,00000100), ref: 00B039AA
                                      • GetLastError.KERNEL32(?,00B03B34,00000000,?,00B01472,00000000,80004005,00000000,80004005,00000000,000001C7,?,00B013B7,000001C7,00000100,?), ref: 00B039B4
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$ErrorFreeLastProcess
                                      • String ID:
                                      • API String ID: 406640338-0
                                      • Opcode ID: c8df155764a72f98ac0483e80736281cf3c98741918892e5940048da90749a6e
                                      • Instruction ID: de803ca64ca36f84dfd12f49ecefcaafbd48ac2d82d4a9fca829c1c9ca01ffe1
                                      • Opcode Fuzzy Hash: c8df155764a72f98ac0483e80736281cf3c98741918892e5940048da90749a6e
                                      • Instruction Fuzzy Hash: 23D012366102346787202BFA5C0CE97BEDCFF065E27014121FE05D3110DB25C910C6E4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open
                                      • String ID: regutil.cpp
                                      • API String ID: 71445658-955085611
                                      • Opcode ID: 2746f2eab9bbb18f8b2979b552389f1a8d005e06dbbe20ebccaac4aefa3c0736
                                      • Instruction ID: b7f26b3e910a6f2ae88966e69ab0ff38c4c34f659b3ed38cd000f59b6ad5fce8
                                      • Opcode Fuzzy Hash: 2746f2eab9bbb18f8b2979b552389f1a8d005e06dbbe20ebccaac4aefa3c0736
                                      • Instruction Fuzzy Hash: 4FF0A772B421356BDF2859568C04FA77ED5DF446A0F118564FE49DA260D276CD20A2D0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcessHeap.KERNEL32(?,000001C7,?,?,00B0227D,?,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000), ref: 00B03A86
                                      • RtlReAllocateHeap.NTDLL(00000000,?,00B0227D,?,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B03A8D
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateProcess
                                      • String ID:
                                      • API String ID: 1357844191-0
                                      • Opcode ID: 907043cd2c6b3ee3f2e1d06aa0f35cacfb7d9c1e5cf320c8a20b32a181851a07
                                      • Instruction ID: 0fcd284ec65d963900e02f3d6edd5cd9e87a7ca3d3850db06732a03a2da81489
                                      • Opcode Fuzzy Hash: 907043cd2c6b3ee3f2e1d06aa0f35cacfb7d9c1e5cf320c8a20b32a181851a07
                                      • Instruction Fuzzy Hash: 37D0123216020DEBCF005FE8DC0DDAE3BACFB596127008405FA15D3110CB3DE5609B60
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • VariantInit.OLEAUT32(?), ref: 00B434CE
                                        • Part of subcall function 00B42F23: GetModuleHandleA.KERNEL32(kernel32.dll,00000000,00000000,00B434DF,00000000,?,00000000), ref: 00B42F3D
                                        • Part of subcall function 00B42F23: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00B2BDED,?,00B052FD,?,00000000,?), ref: 00B42F49
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorHandleInitLastModuleVariant
                                      • String ID:
                                      • API String ID: 52713655-0
                                      • Opcode ID: 6db936bab490a67e437e02039a6191be3df836ac0eedfe47010be2195afc54d2
                                      • Instruction ID: ff46cb1ca7ffc5afd692db8f6c847113150cf943dbb5ec1aa632f537d84c03fa
                                      • Opcode Fuzzy Hash: 6db936bab490a67e437e02039a6191be3df836ac0eedfe47010be2195afc54d2
                                      • Instruction Fuzzy Hash: DF311B76E006299BCB11DFA8D884ADEB7F8EF08710F05456AED15EB211D6719E048BA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegCloseKey.ADVAPI32(80070490,00000000,80070490,00B6AAA0,00000000,80070490,012FA040,?,00B1890E,WiX\Burn,PackageCache,00000000,00B6AAA0,00000000,00000000,80070490), ref: 00B45782
                                        • Part of subcall function 00B40F6E: RegQueryValueExW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000002,00000001,00000000,00000000,00000000,00000000,00000000), ref: 00B40FE4
                                        • Part of subcall function 00B40F6E: RegQueryValueExW.ADVAPI32(?,00000000,00000000,?,00000000,00000000,00000000,?), ref: 00B4101F
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: QueryValue$Close
                                      • String ID:
                                      • API String ID: 1979452859-0
                                      • Opcode ID: ac7fc6c1e528ebcb91bc5013e3f37c310e710cd7c299746779b7ddfd0ce4273b
                                      • Instruction ID: a564e7ade7263c6560cb3c7970c71f865796f5e447ff182bfc93a308ebcc1d15
                                      • Opcode Fuzzy Hash: ac7fc6c1e528ebcb91bc5013e3f37c310e710cd7c299746779b7ddfd0ce4273b
                                      • Instruction Fuzzy Hash: 5211C636800D29EBDF316FA4DC819AEB6E9EF04321B1542B9ED4167112C7315F50FAD0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RtlAllocateHeap.NTDLL(00000008,?,00000000,?,00B36113,00000001,00000364), ref: 00B35280
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AllocateHeap
                                      • String ID:
                                      • API String ID: 1279760036-0
                                      • Opcode ID: cf55d9b24f5b1b1ec860ffe0fef2d06d2ccc9a0495dd37f418b94c89845663c6
                                      • Instruction ID: a6178483a0241505646c10fccff851b42d578ddbe330be9479173f8f78b55966
                                      • Opcode Fuzzy Hash: cf55d9b24f5b1b1ec860ffe0fef2d06d2ccc9a0495dd37f418b94c89845663c6
                                      • Instruction Fuzzy Hash: 00F0BE39644A24AADB716A628C45A9B3BDCEF42B70F384191EC04EB181CB60EC008AE1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SHGetFolderPathW.SHELL32(00000000,00000000,00000000,00000000,00000000,00000000,00000104,00000000,?,00B189CA,0000001C,80070490,00000000,00000000,80070490), ref: 00B034E5
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FolderPath
                                      • String ID:
                                      • API String ID: 1514166925-0
                                      • Opcode ID: 115337363647cda8ff9c9be6e48a109a9b71f2b16fc817a40e8b501921c815f9
                                      • Instruction ID: 0bfc45743e0f7bb46bbfdd8dd40770b86c8d8cc378168ac7d7e4349e410e3018
                                      • Opcode Fuzzy Hash: 115337363647cda8ff9c9be6e48a109a9b71f2b16fc817a40e8b501921c815f9
                                      • Instruction Fuzzy Hash: 55E012762012257BEA022E66AC09DEF7FDCEF06B507008491BE44DB140EA61EA1086B4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 00B3F35B
                                        • Part of subcall function 00B49814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00B49891
                                        • Part of subcall function 00B49814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00B498A2
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: 17f09fdea27f729d17ccca7593173b77aca7f358c198149c66e7cb4ae65edf0e
                                      • Instruction ID: af1c9668e28cedd331fe8accef6f76c803bfbc3e8ecadfe053188cec127e0930
                                      • Opcode Fuzzy Hash: 17f09fdea27f729d17ccca7593173b77aca7f358c198149c66e7cb4ae65edf0e
                                      • Instruction Fuzzy Hash: DEB012A36585027C334853181C03C3702CCC1C1F20334C6FAF004C5080E8840D441033
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 00B3F35B
                                        • Part of subcall function 00B49814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00B49891
                                        • Part of subcall function 00B49814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00B498A2
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: ff70805a5ca3d75562d753616692410ef56bfe71f7c114b4be3a72a113633c52
                                      • Instruction ID: 05184fb8766b3b2061ab06b9e7aba139229e85d4d0204d55978b5917237b8b24
                                      • Opcode Fuzzy Hash: ff70805a5ca3d75562d753616692410ef56bfe71f7c114b4be3a72a113633c52
                                      • Instruction Fuzzy Hash: 1DB012A36584027D334457181D03C3702CCC1C1F20334C5FAB004C5080E8880D051433
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 00B3F35B
                                        • Part of subcall function 00B49814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00B49891
                                        • Part of subcall function 00B49814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00B498A2
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: 60dd62687221e2cf753ec0246ecd099e89718419193c123fa72c9d7ea90b223b
                                      • Instruction ID: c412b9ea773bac976f44c76d7d3294095cc52131cc82fc21e982f815c416a7f5
                                      • Opcode Fuzzy Hash: 60dd62687221e2cf753ec0246ecd099e89718419193c123fa72c9d7ea90b223b
                                      • Instruction Fuzzy Hash: 94B012A36584027C330413146C03C3703CCC1C1F24334C5FAB500D4080E8881E081033
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 00B494E7
                                        • Part of subcall function 00B49814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00B49891
                                        • Part of subcall function 00B49814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00B498A2
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: 9f10c44037179de98fe00e015fd977d95aad50647b833949f9d287953db3326d
                                      • Instruction ID: 17ad845378f74c484362877698fd3e95b9fcc3b719b1160a7b803abdc71a6170
                                      • Opcode Fuzzy Hash: 9f10c44037179de98fe00e015fd977d95aad50647b833949f9d287953db3326d
                                      • Instruction Fuzzy Hash: 94B012862A84027C326466185C07C3702CCC1C0F10330C7EBB500C21C0E8441D092032
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 00B494E7
                                        • Part of subcall function 00B49814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00B49891
                                        • Part of subcall function 00B49814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00B498A2
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: 1368fb1a8b689f54e0b8db8847e4681e62ac201a159a2ddd85d44980219378cc
                                      • Instruction ID: 5c4213afac86ffb58ba0897df9a8fca971dac0346f4a7ddcbbeb67575b4a89e2
                                      • Opcode Fuzzy Hash: 1368fb1a8b689f54e0b8db8847e4681e62ac201a159a2ddd85d44980219378cc
                                      • Instruction Fuzzy Hash: 07B012862A85017C372426185C83C3702CCD6C0F10330C7FBB100E10C0A8440D052033
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 00B494E7
                                        • Part of subcall function 00B49814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00B49891
                                        • Part of subcall function 00B49814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00B498A2
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: d6ba35880866dac7545a3240af412f0ad433da1c4dfb66d184581107c3d01e99
                                      • Instruction ID: 04cf45211dc3fd89d14617bdf5fd8a8038b608fcf18bf1260b350abc0d873bc7
                                      • Opcode Fuzzy Hash: d6ba35880866dac7545a3240af412f0ad433da1c4dfb66d184581107c3d01e99
                                      • Instruction Fuzzy Hash: 93B012862A86017C366466586E43C3702CCC5C0F1033087FBB100D21C0E8480D062432
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysFreeString.OLEAUT32(?), ref: 00B0B01A
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • CompareStringW.KERNEL32(0000007F,00000000,00B4CA64,000000FF,DirectorySearch,000000FF,00B4CA64,Condition,feclient.dll,00B4CA64,Variable,?,00B4CA64,00B4CA64,?,?), ref: 00B0A927
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,exists,000000FF,?,Type,?,?,Path,clbcatq.dll), ref: 00B0A97C
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,path,000000FF), ref: 00B0A998
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,FileSearch,000000FF), ref: 00B0A9BC
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,exists,000000FF,?,Type,?,?,Path,clbcatq.dll), ref: 00B0AA0F
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,version,000000FF), ref: 00B0AA29
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,RegistrySearch,000000FF), ref: 00B0AA51
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,HKCR,000000FF,?,Root,?), ref: 00B0AA8F
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,HKCU,000000FF), ref: 00B0AAAE
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,HKLM,000000FF), ref: 00B0AACD
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,exists,000000FF,?,Win64,msi.dll,?,Type,?,?,Value,version.dll,?), ref: 00B0AB8B
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,value,000000FF), ref: 00B0ABA5
                                        • Part of subcall function 00B431C7: VariantInit.OLEAUT32(?), ref: 00B431DD
                                        • Part of subcall function 00B431C7: SysAllocString.OLEAUT32(?), ref: 00B431F9
                                        • Part of subcall function 00B431C7: VariantClear.OLEAUT32(?), ref: 00B43280
                                        • Part of subcall function 00B431C7: SysFreeString.OLEAUT32(00000000), ref: 00B4328B
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,numeric,000000FF,?,VariableType,?,?,ExpandEnvironment,cabinet.dll), ref: 00B0AC04
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,string,000000FF), ref: 00B0AC26
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,version,000000FF), ref: 00B0AC46
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,directory,000000FF), ref: 00B0AD1E
                                      • SysFreeString.OLEAUT32(?), ref: 00B0AEFC
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$Compare$Free$HeapVariant$AllocAllocateClearInitProcess
                                      • String ID: ComponentId$Condition$DirectorySearch$DirectorySearch|FileSearch|RegistrySearch|MsiComponentSearch|MsiProductSearch|MsiFeatureSearch$ExpandEnvironment$Failed to allocate memory for search structs.$Failed to get @ComponentId.$Failed to get @Condition.$Failed to get @ExpandEnvironment.$Failed to get @FeatureId.$Failed to get @Id.$Failed to get @Path.$Failed to get @ProductCode or @UpgradeCode.$Failed to get @ProductCode.$Failed to get @Root.$Failed to get @Type.$Failed to get @UpgradeCode.$Failed to get @Variable.$Failed to get @VariableType.$Failed to get Key attribute.$Failed to get Value attribute.$Failed to get Win64 attribute.$Failed to get next node.$Failed to get search node count.$Failed to select search nodes.$FeatureId$FileSearch$HKCR$HKCU$HKLM$HKU$Invalid value for @Root: %ls$Invalid value for @Type: %ls$Invalid value for @VariableType: %ls$Key$MsiComponentSearch$MsiFeatureSearch$MsiProductSearch$Path$ProductCode$RegistrySearch$Root$Type$Unexpected element name: %ls$UpgradeCode$Value$Variable$VariableType$Win64$assignment$cabinet.dll$clbcatq.dll$comres.dll$directory$exists$feclient.dll$keyPath$language$msi.dll$numeric$path$search.cpp$state$string$value$version$version.dll$wininet.dll
                                      • API String ID: 2748437055-1695159631
                                      • Opcode ID: aef29d2e6dce9ba267f17df022251f382e23644e96e14206f68af1e87a7aba2e
                                      • Instruction ID: ea677495af98af7899aa32089203e556639acce33fe972e685b5f81e1a27e6fa
                                      • Opcode Fuzzy Hash: aef29d2e6dce9ba267f17df022251f382e23644e96e14206f68af1e87a7aba2e
                                      • Instruction Fuzzy Hash: 7E22C671949326BADB219A548C41EAEBEE5EF11B30F2047D0F531B62E1D7B0DF40E692
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetFileAttributesW.KERNEL32(?,?,?,?,00000001,00000000,?), ref: 00B03C3F
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03C52
                                      • SetFileAttributesW.KERNEL32(?,00000080,?,?,?,00000001,00000000,?), ref: 00B03C9D
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03CA7
                                      • GetTempPathW.KERNEL32(00000104,?,?,?,?,00000001,00000000,?), ref: 00B03CF5
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03CFF
                                      • FindFirstFileW.KERNEL32(?,?,?,*.*,?,?,?,?,00000001,00000000,?), ref: 00B03D52
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03D63
                                      • SetFileAttributesW.KERNEL32(?,00000080,?,?,?,?,?,?,00000001,00000000,?), ref: 00B03E3D
                                      • DeleteFileW.KERNEL32(?,?,?,?,?,?,?,00000001,00000000,?), ref: 00B03E51
                                      • GetTempFileNameW.KERNEL32(?,DEL,00000000,?,?,?,?,00000001,00000000,?), ref: 00B03E78
                                      • MoveFileExW.KERNEL32(?,?,00000001,?,?,?,00000001,00000000,?), ref: 00B03E9B
                                      • MoveFileExW.KERNEL32(?,00000000,00000004,?,?,?,00000001,00000000,?), ref: 00B03EB4
                                      • FindNextFileW.KERNEL32(000000FF,?,?,?,?,?,?,?,00000001,00000000,?), ref: 00B03EC4
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03ED9
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03F08
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03F2A
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03F4C
                                      • RemoveDirectoryW.KERNEL32(?,?,?,?,00000001,00000000,?), ref: 00B03F63
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03F6D
                                      • MoveFileExW.KERNEL32(?,00000000,00000004,?,?,?,00000001,00000000,?), ref: 00B03F93
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03FAE
                                      • FindClose.KERNEL32(000000FF,?,?,?,00000001,00000000,?), ref: 00B03FE4
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLast$AttributesFindMove$Temp$CloseDeleteDirectoryFirstNameNextPathRemove
                                      • String ID: 4#v$*.*$DEL$dirutil.cpp
                                      • API String ID: 1544372074-4118715877
                                      • Opcode ID: 96174a5f7e354bcad6787a6555fd80a872b460725e0fc385636382c1b4302aef
                                      • Instruction ID: 5370bb84d430b5c3452978739bf241b38ffa4b13c44b686707920043a36f7f70
                                      • Opcode Fuzzy Hash: 96174a5f7e354bcad6787a6555fd80a872b460725e0fc385636382c1b4302aef
                                      • Instruction Fuzzy Hash: A0B19975E01235AAEB315B758C48BA67AEDEF44B50F0142E5ED09F71D0DB368F90CAA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • InitializeSecurityDescriptor.ADVAPI32(?,00000001), ref: 00B4166B
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00B41675
                                      • CreateWellKnownSid.ADVAPI32(0000001A,00000000,?,?), ref: 00B416C2
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00B416C8
                                      • CreateWellKnownSid.ADVAPI32(00000017,00000000,?,?), ref: 00B41702
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00B41708
                                      • CreateWellKnownSid.ADVAPI32(00000018,00000000,?,?), ref: 00B41748
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00B4174E
                                      • CreateWellKnownSid.ADVAPI32(00000010,00000000,?,?), ref: 00B4178E
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00B41794
                                      • CreateWellKnownSid.ADVAPI32(00000016,00000000,?,?), ref: 00B417D4
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00B417DA
                                      • SetEntriesInAclA.ADVAPI32(00000005,?,00000000,?), ref: 00B418BD
                                      • LocalFree.KERNEL32(?), ref: 00B419DC
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CreateKnownWell$DescriptorEntriesFreeInitializeLocalSecurity
                                      • String ID: srputil.cpp
                                      • API String ID: 3627156773-4105181634
                                      • Opcode ID: 48e609eea84e29aff25c21902e28ca26be11ba7d2e6d59cd796f03458bbdfb2b
                                      • Instruction ID: d5097112b6fec23ac8f9c1a37d87347d8ec7da700fcb27d40dab1e53f87e9d65
                                      • Opcode Fuzzy Hash: 48e609eea84e29aff25c21902e28ca26be11ba7d2e6d59cd796f03458bbdfb2b
                                      • Instruction Fuzzy Hash: 01B16875D41329AAEB209F698D44FEB76FCFF08741F0141A6ED09F7150E7748E808AA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      • Failed to copy filename for pseudo bundle., xrefs: 00B2C1DF
                                      • Failed to copy repair arguments for related bundle package, xrefs: 00B2C398
                                      • Failed to copy version for pseudo bundle., xrefs: 00B2C4D0
                                      • Failed to copy key for pseudo bundle., xrefs: 00B2C30A
                                      • Failed to allocate memory for pseudo bundle payload hash., xrefs: 00B2C275
                                      • Failed to copy local source path for pseudo bundle., xrefs: 00B2C203
                                      • Failed to allocate space for burn package payload inside of related bundle struct, xrefs: 00B2C14D
                                      • Failed to append relation type to install arguments for related bundle package, xrefs: 00B2C371
                                      • Failed to copy download source for pseudo bundle., xrefs: 00B2C231
                                      • -%ls, xrefs: 00B2C114
                                      • pseudobundle.cpp, xrefs: 00B2C141, 00B2C17A, 00B2C269, 00B2C475
                                      • Failed to copy display name for pseudo bundle., xrefs: 00B2C4F2
                                      • Failed to copy uninstall arguments for related bundle package, xrefs: 00B2C3EB
                                      • Failed to copy key for pseudo bundle payload., xrefs: 00B2C1BB
                                      • Failed to copy install arguments for related bundle package, xrefs: 00B2C34C
                                      • Failed to append relation type to repair arguments for related bundle package, xrefs: 00B2C3B9
                                      • Failed to append relation type to uninstall arguments for related bundle package, xrefs: 00B2C40C
                                      • Failed to allocate memory for dependency providers., xrefs: 00B2C481
                                      • Failed to allocate space for burn payload inside of related bundle struct, xrefs: 00B2C186
                                      • Failed to copy cache id for pseudo bundle., xrefs: 00B2C327
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateProcess
                                      • String ID: -%ls$Failed to allocate memory for dependency providers.$Failed to allocate memory for pseudo bundle payload hash.$Failed to allocate space for burn package payload inside of related bundle struct$Failed to allocate space for burn payload inside of related bundle struct$Failed to append relation type to install arguments for related bundle package$Failed to append relation type to repair arguments for related bundle package$Failed to append relation type to uninstall arguments for related bundle package$Failed to copy cache id for pseudo bundle.$Failed to copy display name for pseudo bundle.$Failed to copy download source for pseudo bundle.$Failed to copy filename for pseudo bundle.$Failed to copy install arguments for related bundle package$Failed to copy key for pseudo bundle payload.$Failed to copy key for pseudo bundle.$Failed to copy local source path for pseudo bundle.$Failed to copy repair arguments for related bundle package$Failed to copy uninstall arguments for related bundle package$Failed to copy version for pseudo bundle.$pseudobundle.cpp
                                      • API String ID: 1357844191-2832335422
                                      • Opcode ID: 0aeb5fe6341e775db17cc2f6adbd92ed6914ab5b8fdae68b4fa5ee9128bc5e9e
                                      • Instruction ID: 7adb8648b140cfb2a7aba1e787da2738e06b0a91cb02872e0d689769fbb66223
                                      • Opcode Fuzzy Hash: 0aeb5fe6341e775db17cc2f6adbd92ed6914ab5b8fdae68b4fa5ee9128bc5e9e
                                      • Instruction Fuzzy Hash: AAC19271A00666BBEB15DE64D895E6EBBE8EF08710B0041E5FD19EB351DB70EC109B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B0D39D: EnterCriticalSection.KERNEL32(000000D0,?,000000B8,00000000,?,00B16E4B,000000B8,00000000,?,00000000,7694B390), ref: 00B0D3AC
                                        • Part of subcall function 00B0D39D: InterlockedCompareExchange.KERNEL32(000000E8,00000001,00000000), ref: 00B0D3BB
                                        • Part of subcall function 00B0D39D: LeaveCriticalSection.KERNEL32(000000D0,?,00B16E4B,000000B8,00000000,?,00000000,7694B390), ref: 00B0D3D0
                                      • ReleaseMutex.KERNEL32(00000000,?,00000000,?,00000000,00000001,00000000), ref: 00B16D9A
                                      • CloseHandle.KERNEL32(00000000), ref: 00B16DA3
                                      • CloseHandle.KERNEL32(00B04740,?,00000000,?,00000000,00000001,00000000), ref: 00B16DC0
                                      Strings
                                      • user cannot start apply because it is busy with another action., xrefs: 00B16A2F
                                      • Failed to create cache thread., xrefs: 00B16C80
                                      • Failed to elevate., xrefs: 00B16BA5
                                      • UX aborted apply begin., xrefs: 00B16AA6
                                      • Failed to set initial apply variables., xrefs: 00B16B18
                                      • Another per-user setup is already executing., xrefs: 00B16AF1
                                      • Failed while caching, aborting execution., xrefs: 00B16CA8
                                      • Failed to register bundle., xrefs: 00B16C00
                                      • crypt32.dll, xrefs: 00B16CD2
                                      • core.cpp, xrefs: 00B16A9C, 00B16C76
                                      • Failed to cache user to working directory., xrefs: 00B16B7F
                                      • Another per-machine setup is already executing., xrefs: 00B16BD9
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCriticalHandleSection$CompareEnterExchangeInterlockedLeaveMutexRelease
                                      • String ID: Another per-machine setup is already executing.$Another per-user setup is already executing.$user cannot start apply because it is busy with another action.$Failed to cache user to working directory.$Failed to create cache thread.$Failed to elevate.$Failed to register bundle.$Failed to set initial apply variables.$Failed while caching, aborting execution.$UX aborted apply begin.$core.cpp$crypt32.dll
                                      • API String ID: 322611130-4292671789
                                      • Opcode ID: 89c2ebe31db295bf8e40c750356a330304473417f2bb9ba6503cf4c6a76468b9
                                      • Instruction ID: 602bc9607facda84c686a2a0a0628a6e77283c774dfa65e13cf0a6a683502945
                                      • Opcode Fuzzy Hash: 89c2ebe31db295bf8e40c750356a330304473417f2bb9ba6503cf4c6a76468b9
                                      • Instruction Fuzzy Hash: 30C1B171A01616BBDF199BA4D885FEFB7F8FF04305F4042BAF615A6150DB30A984CB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentProcess.KERNEL32(00000020,?,00000001,00000000,?,?,?,?,?,?,?), ref: 00B04512
                                      • OpenProcessToken.ADVAPI32(00000000,?,?,?,?,?,?,?,00000000,?,?,?,?,?,?), ref: 00B04519
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,00000000,?,?,?,?,?,?), ref: 00B04523
                                      • LookupPrivilegeValueW.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 00B04573
                                      • GetLastError.KERNEL32 ref: 00B0457D
                                      • CloseHandle.KERNEL32(?), ref: 00B04677
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastProcess$CloseCurrentHandleLookupOpenPrivilegeTokenValue
                                      • String ID: Failed to adjust token to add shutdown privileges.$Failed to get process token.$Failed to get shutdown privilege LUID.$Failed to schedule restart.$SeShutdownPrivilege$user.cpp
                                      • API String ID: 4232854991-1583736410
                                      • Opcode ID: e37dada12bcd439b80bdc4e8086cde582945538460c7d4307b5a0ad6b0cb4028
                                      • Instruction ID: 991981af789665cf738f4d1430b1ddb32ed12c3cf72e335cafb8b6e27219cc34
                                      • Opcode Fuzzy Hash: e37dada12bcd439b80bdc4e8086cde582945538460c7d4307b5a0ad6b0cb4028
                                      • Instruction Fuzzy Hash: 1741C8B5A40325BBEB205AB99C49F7B7AECEB01751F0101A5BF05F72D0EB658E0096E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(D:(A;;GA;;;SY)(A;;GA;;;BA)(A;;GRGW0x00100000;;;WD),00000001,?,00000000), ref: 00B14D16
                                      • GetLastError.KERNEL32(?,00000000,?,?,00B0442A,?), ref: 00B14D1F
                                      • CreateNamedPipeW.KERNEL32(000000FF,00080003,00000000,00000001,00010000,00010000,00000001,?,?,00000000,?,?,00B0442A,?), ref: 00B14DC0
                                      • GetLastError.KERNEL32(?,00B0442A,?), ref: 00B14DCD
                                      • CloseHandle.KERNEL32(00000000,pipe.cpp,00000132,00000000,?,?,?,?,?,?,?,00B0442A,?), ref: 00B14E93
                                      • LocalFree.KERNEL32(00000000,?,00B0442A,?), ref: 00B14EC1
                                      Strings
                                      • Failed to allocate full name of cache pipe: %ls, xrefs: 00B14E2A
                                      • pipe.cpp, xrefs: 00B14D43, 00B14DF1, 00B14E77
                                      • \\.\pipe\%ls.Cache, xrefs: 00B14E14
                                      • Failed to create the security descriptor for the connection event and pipe., xrefs: 00B14D4D
                                      • Failed to create pipe: %ls, xrefs: 00B14DFE, 00B14E84
                                      • D:(A;;GA;;;SY)(A;;GA;;;BA)(A;;GRGW0x00100000;;;WD), xrefs: 00B14D11
                                      • \\.\pipe\%ls, xrefs: 00B14D77
                                      • Failed to allocate full name of pipe: %ls, xrefs: 00B14D8D
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: DescriptorErrorLastSecurity$CloseConvertCreateFreeHandleLocalNamedPipeString
                                      • String ID: D:(A;;GA;;;SY)(A;;GA;;;BA)(A;;GRGW0x00100000;;;WD)$Failed to allocate full name of cache pipe: %ls$Failed to allocate full name of pipe: %ls$Failed to create pipe: %ls$Failed to create the security descriptor for the connection event and pipe.$\\.\pipe\%ls$\\.\pipe\%ls.Cache$pipe.cpp
                                      • API String ID: 3065245045-3253666091
                                      • Opcode ID: 4b3eb2d7b2c6ea81e607030f48f7463973757c005e76d5203c91e518fb74829c
                                      • Instruction ID: 50f2fa317e626d0e981b384ce0b5df0c287b421750f0d5c3ed84723ceee64823
                                      • Opcode Fuzzy Hash: 4b3eb2d7b2c6ea81e607030f48f7463973757c005e76d5203c91e518fb74829c
                                      • Instruction Fuzzy Hash: CD51A376E40315BBEB119BA4DC46BEEBAF8EF04711F1041A5FE00B62E0D7758F849A91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000003,F0000040,00000003,00000000,00000000,00B19CFF,00000003,000007D0,00000003,?,000007D0,00000000,000007D0), ref: 00B3F9C6
                                      • GetLastError.KERNEL32 ref: 00B3F9D0
                                      • CryptCreateHash.ADVAPI32(?,?,00000000,00000000,?), ref: 00B3FA0D
                                      • GetLastError.KERNEL32 ref: 00B3FA17
                                      • CryptDestroyHash.ADVAPI32(00000000), ref: 00B3FAC9
                                      • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 00B3FAE0
                                      • GetLastError.KERNEL32 ref: 00B3FAFB
                                      • CryptGetHashParam.ADVAPI32(?,00000002,?,?,00000000), ref: 00B3FB33
                                      • GetLastError.KERNEL32 ref: 00B3FB3D
                                      • SetFilePointerEx.KERNEL32(00000000,00000000,00000000,00008004,00000001), ref: 00B3FB76
                                      • GetLastError.KERNEL32 ref: 00B3FB84
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CryptErrorLast$Hash$Context$AcquireCreateDestroyFileParamPointerRelease
                                      • String ID: cryputil.cpp
                                      • API String ID: 1716956426-2185294990
                                      • Opcode ID: 066868335564155f33dad821788eef7828a25816b0994d6afe0f289b1463f5f5
                                      • Instruction ID: d9d47c1aaa500afe1351ef37214f350f88773c59047f12bfa77fa01e73866f04
                                      • Opcode Fuzzy Hash: 066868335564155f33dad821788eef7828a25816b0994d6afe0f289b1463f5f5
                                      • Instruction Fuzzy Hash: 64518636E00265ABEB319A658C44BE776F8FB08741F1141A5BE4DF7190E7748E80DAA4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      • Failed to transfer working path to unverified path for payload: %ls., xrefs: 00B19D9F
                                      • Failed to find payload: %ls in working path: %ls and unverified path: %ls, xrefs: 00B19DC6
                                      • Failed to concat complete cached path., xrefs: 00B19CEF
                                      • Failed to get cached path for package with cache id: %ls, xrefs: 00B19CC3
                                      • copying, xrefs: 00B19E27
                                      • moving, xrefs: 00B19E2C, 00B19E34
                                      • Failed to reset permissions on unverified cached payload: %ls, xrefs: 00B19DEC
                                      • Failed to move verified file to complete payload path: %ls, xrefs: 00B19E68
                                      • Failed to create unverified path., xrefs: 00B19D69
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID: Failed to concat complete cached path.$Failed to create unverified path.$Failed to find payload: %ls in working path: %ls and unverified path: %ls$Failed to get cached path for package with cache id: %ls$Failed to move verified file to complete payload path: %ls$Failed to reset permissions on unverified cached payload: %ls$Failed to transfer working path to unverified path for payload: %ls.$copying$moving
                                      • API String ID: 0-1289240508
                                      • Opcode ID: 88350fd6f400e5845ea53f04556e9b73a987eccc6c22bda4624700d3bf8db904
                                      • Instruction ID: a1cc00741c59e62dd2ee31a71c31efe0facb65f09168b85779908cfe631ffec2
                                      • Opcode Fuzzy Hash: 88350fd6f400e5845ea53f04556e9b73a987eccc6c22bda4624700d3bf8db904
                                      • Instruction Fuzzy Hash: C7517F32940159BBDF226B90DC52FDE7BF6AF04700F6041E5FA00761A1E7729FA4AB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetVersionExW.KERNEL32(0000011C), ref: 00B061D2
                                      • GetLastError.KERNEL32 ref: 00B061DC
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastVersion
                                      • String ID: Failed to get OS info.$Failed to set variant value.$variable.cpp
                                      • API String ID: 305913169-1971907631
                                      • Opcode ID: e6447190ac035b80c013323033135fc90999e7b1d03eda67ca206ecd584e2b85
                                      • Instruction ID: cd43123fdb89793bc6da7cec756a5b5bf181c2ab60c76d89ba9123325e364772
                                      • Opcode Fuzzy Hash: e6447190ac035b80c013323033135fc90999e7b1d03eda67ca206ecd584e2b85
                                      • Instruction Fuzzy Hash: 60417771E05228ABDB209B69DC85FEB7FF8EB89710F1001DAF505E7190D6709E91CB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00B6B60C,00000000,?,?,?,?,00B21014,8007139F,Invalid operation for this state.,cabextract.cpp,000001C7,8007139F), ref: 00B3FDF0
                                      • GetCurrentProcessId.KERNEL32(00000000,?,00B21014,8007139F,Invalid operation for this state.,cabextract.cpp,000001C7,8007139F), ref: 00B3FE00
                                      • GetCurrentThreadId.KERNEL32 ref: 00B3FE09
                                      • GetLocalTime.KERNEL32(8007139F,?,00B21014,8007139F,Invalid operation for this state.,cabextract.cpp,000001C7,8007139F), ref: 00B3FE1F
                                      • LeaveCriticalSection.KERNEL32(00B6B60C,?,00000000,00000000,0000FDE9), ref: 00B3FF12
                                      Strings
                                      • %ls[%04X:%04X][%04hu-%02hu-%02huT%02hu:%02hu:%02hu]%hs%03d:%ls %ls%ls, xrefs: 00B3FEB9
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalCurrentSection$EnterLeaveLocalProcessThreadTime
                                      • String ID: %ls[%04X:%04X][%04hu-%02hu-%02huT%02hu:%02hu:%02hu]%hs%03d:%ls %ls%ls
                                      • API String ID: 296830338-59366893
                                      • Opcode ID: d792b9cf5f272156fd3b21c80af879d32d99c988a833cffad5e67763ca00c156
                                      • Instruction ID: 4f81a940c676a45ee3e211124a2b9879b7fbfc17492fd2d9f917b496ae0b344a
                                      • Opcode Fuzzy Hash: d792b9cf5f272156fd3b21c80af879d32d99c988a833cffad5e67763ca00c156
                                      • Instruction Fuzzy Hash: 90414572D0111AABDF209BA4DC45ABEB7F9FB09711F104065FA05E72A1D738DD80DB61
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • FindFirstFileW.KERNEL32(?,?,?,?,*.*,?,?,?,00000000,.unverified,?), ref: 00B199ED
                                      • lstrlenW.KERNEL32(?), ref: 00B19A14
                                      • FindNextFileW.KERNEL32(00000000,00000010), ref: 00B19A74
                                      • FindClose.KERNEL32(00000000), ref: 00B19A7F
                                        • Part of subcall function 00B03BC3: GetFileAttributesW.KERNEL32(?,?,?,?,00000001,00000000,?), ref: 00B03C3F
                                        • Part of subcall function 00B03BC3: GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B03C52
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FileFind$AttributesCloseErrorFirstLastNextlstrlen
                                      • String ID: *.*$.unverified
                                      • API String ID: 457978746-2528915496
                                      • Opcode ID: 75608bdd0cd28c189ba7b8ddc0fb9ca9896894b2b2f65e2a264ac635c984ff93
                                      • Instruction ID: 69dec8e1d47452b56acca2e991e94042f3fb8f16b51d560d43de8a8dff5344d7
                                      • Opcode Fuzzy Hash: 75608bdd0cd28c189ba7b8ddc0fb9ca9896894b2b2f65e2a264ac635c984ff93
                                      • Instruction Fuzzy Hash: E041513191056CAEDF20AB64DC59BEA77F8EF44702F9041E5E908A60A0EB759FC8DF14
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetTimeZoneInformation.KERNEL32(?,00000001,00000000), ref: 00B48788
                                      • SystemTimeToTzSpecificLocalTime.KERNEL32(?,?,?), ref: 00B4879A
                                      Strings
                                      • feclient.dll, xrefs: 00B48762
                                      • %04hu-%02hu-%02huT%02hu:%02hu:%02hu%c%02u:%02u, xrefs: 00B487E3
                                      • %04hu-%02hu-%02huT%02hu:%02hu:%02huZ, xrefs: 00B48771
                                      • crypt32.dll, xrefs: 00B48758
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Time$InformationLocalSpecificSystemZone
                                      • String ID: %04hu-%02hu-%02huT%02hu:%02hu:%02hu%c%02u:%02u$%04hu-%02hu-%02huT%02hu:%02hu:%02huZ$crypt32.dll$feclient.dll
                                      • API String ID: 1772835396-1985132828
                                      • Opcode ID: b320d7eb7ee75637c152484085780db10852a10f0355056140a4ce1b326237ef
                                      • Instruction ID: 52fbf78c55287e03855ae2d0786bf9b7bc414a08e3fb9c62e0316affd769d321
                                      • Opcode Fuzzy Hash: b320d7eb7ee75637c152484085780db10852a10f0355056140a4ce1b326237ef
                                      • Instruction Fuzzy Hash: 89210EA6900118BED724DF999C05FBBB3FCEB48B11F10455AFA45E6080E778AE80D770
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: __floor_pentium4
                                      • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                      • API String ID: 4168288129-2761157908
                                      • Opcode ID: 06315b8f004dab91d6c515c8e22c291cbecba5e611ca36116dc8a58986ed525d
                                      • Instruction ID: 042ba2b7493fb3f2ca94fc3873b9a193098a400814949b96e451760800a5a19f
                                      • Opcode Fuzzy Hash: 06315b8f004dab91d6c515c8e22c291cbecba5e611ca36116dc8a58986ed525d
                                      • Instruction Fuzzy Hash: CFC23C72E046288FDB25CE28DD80BEAB7F9EB44305F2541EAD54DE7244E774AE818F41
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastNameUser
                                      • String ID: Failed to get the user name.$Failed to set variant value.$variable.cpp
                                      • API String ID: 2054405381-1522884404
                                      • Opcode ID: abdb28b422cbfecfad71994533ed00533081495d389b6e092fe9efef955e3eef
                                      • Instruction ID: dec57f8edb68abc98edc2b029ec1c9d3ddbb8dc8092484d2452cdf78aa7214e1
                                      • Opcode Fuzzy Hash: abdb28b422cbfecfad71994533ed00533081495d389b6e092fe9efef955e3eef
                                      • Instruction Fuzzy Hash: 4D019671A0133967DB20AB65AC49EAB7BE8EB00710F0041D6F915F7281EE749E5496D1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • FormatMessageW.KERNEL32(00000900,?,00000000,00000000,00000000,00000000,?,00000000,?,?,00B403EC,?,00000000,?,?,00000001), ref: 00B3FD3F
                                      • GetLastError.KERNEL32(?,00B403EC,?,00000000,?,?,00000001,?,00B05523,?,?,00000000,?,?,00B0528D,00000002), ref: 00B3FD4B
                                      • LocalFree.KERNEL32(00000000,?,00000000,00000000,?,?,00B403EC,?,00000000,?,?,00000001,?,00B05523,?,?), ref: 00B3FDB3
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFormatFreeLastLocalMessage
                                      • String ID: logutil.cpp
                                      • API String ID: 1365068426-3545173039
                                      • Opcode ID: 21732d37a6849e0d757d979ca65e080416e9885678aab6368239132f372e89f8
                                      • Instruction ID: 0af6e913bc87f09dab1be8184bfc1259ce5efe4a694e0d3e4f77e5df6e47d3d3
                                      • Opcode Fuzzy Hash: 21732d37a6849e0d757d979ca65e080416e9885678aab6368239132f372e89f8
                                      • Instruction Fuzzy Hash: 5E119D35A0021ABADF21AF908D09EBF7BA8EF54711F1140B9FE0196160D7308E20D6A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ChangeServiceConfigW.ADVAPI32(00000000,000000FF,00000003,000000FF,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00B268EF,00000000,00000003), ref: 00B2695C
                                      • GetLastError.KERNEL32(?,00B268EF,00000000,00000003,00000000,?,?,?,?,?,?,?,?,?,00B26CE1,?), ref: 00B26966
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ChangeConfigErrorLastService
                                      • String ID: Failed to set service start type.$msuuser.cpp
                                      • API String ID: 1456623077-1628545019
                                      • Opcode ID: f7a1f3a3c096704166ce3be95143f645519778258defb17e2d0dc619f3f11238
                                      • Instruction ID: 2c3d4ade7ceedbd905af05c3e02a7851c9b10fb8a913c71e83285bef5490f0e0
                                      • Opcode Fuzzy Hash: f7a1f3a3c096704166ce3be95143f645519778258defb17e2d0dc619f3f11238
                                      • Instruction Fuzzy Hash: 3FF0E53370433036AB2026A96C09F877EC8EF027B1B110365FE28F62E0DE218D0092E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • IsDebuggerPresent.KERNEL32(?,?,?,?,?,?), ref: 00B33CA8
                                      • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,?), ref: 00B33CB2
                                      • UnhandledExceptionFilter.KERNEL32(80003CDD,?,?,?,?,?,?), ref: 00B33CBF
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                      • String ID:
                                      • API String ID: 3906539128-0
                                      • Opcode ID: 38a6435cc0671a294b4dc4761bc4731456b1dfade7f957c8f25b02291a33390e
                                      • Instruction ID: 9833a83ed2af9c2b0a27b5eb08eb32b0c4d4e7a2f0b583c8a22cdebbf0a980f4
                                      • Opcode Fuzzy Hash: 38a6435cc0671a294b4dc4761bc4731456b1dfade7f957c8f25b02291a33390e
                                      • Instruction Fuzzy Hash: 0431D574901228ABCB21DF64D888B9DBBF8FF08710F5041EAE41CA7261EB709F858F44
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentProcess.KERNEL32(00000000,?,00B347E8,00000000,00B67CF8,0000000C,00B3493F,00000000,00000002,00000000), ref: 00B34833
                                      • TerminateProcess.KERNEL32(00000000,?,00B347E8,00000000,00B67CF8,0000000C,00B3493F,00000000,00000002,00000000), ref: 00B3483A
                                      • ExitProcess.KERNEL32 ref: 00B3484C
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Process$CurrentExitTerminate
                                      • String ID:
                                      • API String ID: 1703294689-0
                                      • Opcode ID: 2f0a27673cb08fea550d873926633269f571cdaff0a796467962a70bfc336370
                                      • Instruction ID: 96422863152e953a790830ab1280ada19df8b02bb1c175023bc1f033eaeecd07
                                      • Opcode Fuzzy Hash: 2f0a27673cb08fea550d873926633269f571cdaff0a796467962a70bfc336370
                                      • Instruction Fuzzy Hash: 0FE0B635400688ABCF116F65DD09E5A3FA9FB42341F2504A4FA059B232CF75EE42DA94
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID: /
                                      • API String ID: 0-2043925204
                                      • Opcode ID: 598e5ecb53422e2969b2789af39eb15c610fd1ccca4a4cf89fd96dba953538dc
                                      • Instruction ID: 42e11c1d32980720ffadeb34d40f81dc1b2941d767b25c1a76bff6761df85ea1
                                      • Opcode Fuzzy Hash: 598e5ecb53422e2969b2789af39eb15c610fd1ccca4a4cf89fd96dba953538dc
                                      • Instruction Fuzzy Hash: 954128B65402196BCB309FB9DC89DBBB7F8EB84710F6042E8F905D7180EA309E81CB50
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: eb5ef6380223df80c09fbffff4406c54564286920eb9de1bd108dda9bf4439f2
                                      • Instruction ID: b39ed54a6dbfa85446f2426c81f949354fb300d7716f6c639faed83fc9274355
                                      • Opcode Fuzzy Hash: eb5ef6380223df80c09fbffff4406c54564286920eb9de1bd108dda9bf4439f2
                                      • Instruction Fuzzy Hash: 24021B71E002199BDF14CFA9C8906ADBBF1EF48314F3581AAD959E7384D731AE45CB81
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B43AC9: RegCloseKey.ADVAPI32(00000000,80000002,SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System,00020019,00000000,?,?,?,?,?,00B4396A,?), ref: 00B43B3A
                                      • AllocateAndInitializeSid.ADVAPI32(?,00000002,00000020,00000220,00000000,00000000,00000000,00000000,00000000,00000000,?,?), ref: 00B4398E
                                      • CheckTokenMembership.ADVAPI32(00000000,?,?), ref: 00B4399F
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AllocateCheckCloseInitializeMembershipToken
                                      • String ID:
                                      • API String ID: 2114926846-0
                                      • Opcode ID: e10a65368b6b79df91eeaaee476d3d06c1bd569dd05bb2d26bd58c9425c0f830
                                      • Instruction ID: 5d2895fe7f45e65e29928fcd5de2b33eff707a5ff2b4e25ca9d3534ccfbed09a
                                      • Opcode Fuzzy Hash: e10a65368b6b79df91eeaaee476d3d06c1bd569dd05bb2d26bd58c9425c0f830
                                      • Instruction Fuzzy Hash: BC113C7190021AABDF10EFA5DC85ABFB7F8FF08700F54086DA546A6181D7709B44DB51
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • FindFirstFileW.KERNEL32(00B28FFA,?,000002C0,00000000,00000000), ref: 00B44350
                                      • FindClose.KERNEL32(00000000), ref: 00B4435C
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Find$CloseFileFirst
                                      • String ID:
                                      • API String ID: 2295610775-0
                                      • Opcode ID: 3903e90c6f6655100d0653655c1a9cdfa584f06bb822a5eda2e6e3ec8cd987fa
                                      • Instruction ID: 79e1e552ae48c3521594dd3db753a75b2c27488e63204b72381b07e93a87c310
                                      • Opcode Fuzzy Hash: 3903e90c6f6655100d0653655c1a9cdfa584f06bb822a5eda2e6e3ec8cd987fa
                                      • Instruction Fuzzy Hash: D201D671600118ABDB10EF699D89EAAB3BCEBC6711F0001A5E948D3240DB349E598B54
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID: 0$comres.dll
                                      • API String ID: 0-3030269839
                                      • Opcode ID: f7a880ec5967ec64a90054ca813bf1243ddeae79b496adee3d9f08ad155e7dd2
                                      • Instruction ID: ea20bd3648a9d14632be4c739a0a4e5579321bbe5559f4ddadead4cea2c23151
                                      • Opcode Fuzzy Hash: f7a880ec5967ec64a90054ca813bf1243ddeae79b496adee3d9f08ad155e7dd2
                                      • Instruction Fuzzy Hash: C551987060474467DF384F2C8996BBFB3C4EF12740F7805D9D882DB282E611EE458352
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,00000008,?,?,00B3ED47,?,?,00000008,?,?,00B3E9E7,00000000), ref: 00B3EF79
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ExceptionRaise
                                      • String ID:
                                      • API String ID: 3997070919-0
                                      • Opcode ID: 378f935601291c1d21e6d369ad33a4e580221ebebbd3586ab3a6d60a158d487e
                                      • Instruction ID: cac5c13aecfb547d7b966a9f18edf7ba985f8c83928c081c28b214f07bbbd599
                                      • Opcode Fuzzy Hash: 378f935601291c1d21e6d369ad33a4e580221ebebbd3586ab3a6d60a158d487e
                                      • Instruction Fuzzy Hash: 41B13C32510609DFD719CF28C48AB657BE0FF45364F258699E8A9CF2E1C375E991CB40
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetSystemTime.KERNEL32(?,00000000,?,?,?), ref: 00B485A7
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: SystemTime
                                      • String ID:
                                      • API String ID: 2656138-0
                                      • Opcode ID: 71487b88e08b19918d6aca39e9ccc7d86d6fddcf2eeb9587a978fd191ab1abe1
                                      • Instruction ID: 5f50552c89ebb5fe2103828b30583aec0e2545ed796de1a0179b7254774f0bfd
                                      • Opcode Fuzzy Hash: 71487b88e08b19918d6aca39e9ccc7d86d6fddcf2eeb9587a978fd191ab1abe1
                                      • Instruction Fuzzy Hash: B4E01A7190111DAB8F00EFA8D911CBEB7BCEF09210B51409AE905AB100DA30AF199BA2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetUnhandledExceptionFilter.KERNEL32(Function_0002E77F,00B2DEF8), ref: 00B2E778
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ExceptionFilterUnhandled
                                      • String ID:
                                      • API String ID: 3192549508-0
                                      • Opcode ID: ef6ca424f18c5f037d7af85cb2cf184bb77d61dfeffbeb53a59113097a4b329e
                                      • Instruction ID: 0622407b0bf44db9800fefbe59bbfafde6cab8a1d273b7165835a05553372fe7
                                      • Opcode Fuzzy Hash: ef6ca424f18c5f037d7af85cb2cf184bb77d61dfeffbeb53a59113097a4b329e
                                      • Instruction Fuzzy Hash:
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: bf6ffcbe3773841c348058a39a16573d3b2338b254e5945c46ce03dce2746f28
                                      • Instruction ID: 8b8ab902aba37cbc36cfbd5c280ac6ce3ea2a7e080d0e754bc06c7cf07e8380e
                                      • Opcode Fuzzy Hash: bf6ffcbe3773841c348058a39a16573d3b2338b254e5945c46ce03dce2746f28
                                      • Instruction Fuzzy Hash: E8C1D5322151A30DDF6D567D987413FBAE0AEA27B172A57DDD4B3CB0C5EE20C524D620
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: a635e2a33a60bcf8d734eac2a911e111534612f0cd64c6a362f1e57f4f360174
                                      • Instruction ID: 511296841cbd1e7a33730b5486fce5ed29d4a902127328eccf50082addd6fd59
                                      • Opcode Fuzzy Hash: a635e2a33a60bcf8d734eac2a911e111534612f0cd64c6a362f1e57f4f360174
                                      • Instruction Fuzzy Hash: 86C1D3322191A30DDB6D5679D83413FFAE1EEA27B172A17EDD4B2CB0C4EE20D524D620
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 693fc2a06020ee0ee57da02a4a933cd5ad315ff3ac21a4b032580d2a5e4f36f6
                                      • Instruction ID: 25fbccd156806a52a46a8f664f625c58fae1f2b291daadbe8d72cbec78ccdea6
                                      • Opcode Fuzzy Hash: 693fc2a06020ee0ee57da02a4a933cd5ad315ff3ac21a4b032580d2a5e4f36f6
                                      • Instruction Fuzzy Hash: 3FC1C5322251A30EDF6D5679987413FBAF19EA17B172A17EDD4B3CB1C4EE20C524D610
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: b18fb967447e529c76739499a87999de3f08bdf72590393fa5476362680146d7
                                      • Instruction ID: 28c5d7bfdbec4aba4d43e88fbed3704f963e2cff5035c9cf3ae05f9522362d3d
                                      • Opcode Fuzzy Hash: b18fb967447e529c76739499a87999de3f08bdf72590393fa5476362680146d7
                                      • Instruction Fuzzy Hash: 96C1C4322150A30DDF6D5679A83413FBAF1AEA27B172A57EDD4B2CB0D4EE20C524D610
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: c43f081d1057f414b1f20572c43bc80dab02b6f516bdfbf9698bc08cc4bcc24b
                                      • Instruction ID: 1dd982f43f409835c3eaac8d772717017f3f3cf262ec78e90b67c681ffc536a9
                                      • Opcode Fuzzy Hash: c43f081d1057f414b1f20572c43bc80dab02b6f516bdfbf9698bc08cc4bcc24b
                                      • Instruction Fuzzy Hash: 4D616B716007296ADA385B2888A7BBF33D4EF51700F3409EAE943DF291DA15ED868355
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegCloseKey.ADVAPI32(00000000,00000000,00000001,00000000,00000101,?,?,00020006,00000000,?,?,?), ref: 00B10409
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Close
                                      • String ID: /uninstall$"%ls" %ls$"%ls" /modify$"%ls" /uninstall /quiet$%hs$%hu.%hu.%hu.%hu$%s,0$/modify$3.10.4.4718$BundleAddonCode$BundleCachePath$BundleDetectCode$BundlePatchCode$BundleProviderKey$BundleTag$BundleUpgradeCode$BundleVersion$Comments$Contact$DisplayIcon$DisplayName$DisplayVersion$userVersion$EstimatedSize$Failed to cache bundle from path: %ls$Failed to create registration key.$Failed to register the bundle dependency key.$Failed to update resume mode.$Failed to write %ls value.$Failed to write software tags.$Failed to write update registration.$HelpLink$HelpTelephone$ModifyPath$NoElevateOnModify$NoModify$NoRemove$ParentDisplayName$ParentKeyName$Publisher$QuietUninstallString$SystemComponent$URLInfoAbout$URLUpdateInfo$UninstallString
                                      • API String ID: 3535843008-3978993339
                                      • Opcode ID: e70c96234d9da217a9120dfe68308bf566c4c5b144ed52ebf4e374aa6df74863
                                      • Instruction ID: fd2099f1ee78ffa17ed6b45da6f92f0da0afab9e438561c6ca29b249013b08e4
                                      • Opcode Fuzzy Hash: e70c96234d9da217a9120dfe68308bf566c4c5b144ed52ebf4e374aa6df74863
                                      • Instruction Fuzzy Hash: 9DF1D631E60A26FBCF227A54DC42BED7AE0EB08711F5045E0FD10B6261D7B19EE4A6C4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00B0533D,?,00000000,80070490,?,?,?,?,?,?,?,?,00B2BF87,?,00B0533D,?), ref: 00B0837E
                                      • LeaveCriticalSection.KERNEL32(00B0533D,?,?,?,?,?,?,?,?,00B2BF87,?,00B0533D,?,00B0533D,00B0533D,Chain), ref: 00B086DB
                                      Strings
                                      • Failed to set variant value., xrefs: 00B08666
                                      • Failed to set value of variable: %ls, xrefs: 00B0867E
                                      • Failed to select variable nodes., xrefs: 00B0839B
                                      • string, xrefs: 00B084CE
                                      • Attempt to set built-in variable value: %ls, xrefs: 00B0869F
                                      • Type, xrefs: 00B0847A
                                      • Initializing numeric variable '%ls' to value '%ls', xrefs: 00B084B9
                                      • Failed to find variable value '%ls'., xrefs: 00B086A9
                                      • Persisted, xrefs: 00B08421
                                      • Failed to get @Persisted., xrefs: 00B086B8
                                      • Initializing string variable '%ls' to value '%ls', xrefs: 00B084F1
                                      • Initializing version variable '%ls' to value '%ls', xrefs: 00B0852A
                                      • Failed to set variant encryption, xrefs: 00B08674
                                      • Failed to get @Value., xrefs: 00B0866D
                                      • Hidden, xrefs: 00B08406
                                      • numeric, xrefs: 00B08493
                                      • Failed to change variant type., xrefs: 00B086B1
                                      • Failed to get @Type., xrefs: 00B0865F
                                      • Failed to get next node., xrefs: 00B086CD
                                      • Variable, xrefs: 00B08388
                                      • Failed to get @Id., xrefs: 00B086C6
                                      • Value, xrefs: 00B0843C
                                      • Failed to get variable node count., xrefs: 00B083B8
                                      • Failed to insert variable '%ls'., xrefs: 00B0859D
                                      • Failed to get @Hidden., xrefs: 00B086BF
                                      • Initializing hidden variable '%ls', xrefs: 00B08548
                                      • Invalid value for @Type: %ls, xrefs: 00B0864F
                                      • version, xrefs: 00B08503
                                      • variable.cpp, xrefs: 00B08690
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: Attempt to set built-in variable value: %ls$Failed to change variant type.$Failed to find variable value '%ls'.$Failed to get @Hidden.$Failed to get @Id.$Failed to get @Persisted.$Failed to get @Type.$Failed to get @Value.$Failed to get next node.$Failed to get variable node count.$Failed to insert variable '%ls'.$Failed to select variable nodes.$Failed to set value of variable: %ls$Failed to set variant encryption$Failed to set variant value.$Hidden$Initializing hidden variable '%ls'$Initializing numeric variable '%ls' to value '%ls'$Initializing string variable '%ls' to value '%ls'$Initializing version variable '%ls' to value '%ls'$Invalid value for @Type: %ls$Persisted$Type$Value$Variable$numeric$string$variable.cpp$version
                                      • API String ID: 3168844106-1614826165
                                      • Opcode ID: 39e8460c67ea9485c4b4ce8a7da9ef2d8b868ec8ada1f759df7bb7132732623b
                                      • Instruction ID: 1c2a94c03bfba10a788988e82c5bb8a9421be10fe319abc37d5c21b704339b81
                                      • Opcode Fuzzy Hash: 39e8460c67ea9485c4b4ce8a7da9ef2d8b868ec8ada1f759df7bb7132732623b
                                      • Instruction Fuzzy Hash: F5B1CD72D01229BBCF11AB94CC45EAEBFF5EF44B10F1142E5F954B62A1CB719B40AB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentProcess.KERNEL32(?,?,00000000,?,?,?,?,?,?,?,?,00B1BBCA,00000007,?,?,?), ref: 00B26AD9
                                        • Part of subcall function 00B409BB: GetModuleHandleW.KERNEL32(kernel32,IsWow64Process,?,?,?,00B05D8F,00000000), ref: 00B409CF
                                        • Part of subcall function 00B409BB: GetProcAddress.KERNEL32(00000000), ref: 00B409D6
                                        • Part of subcall function 00B409BB: GetLastError.KERNEL32(?,?,?,00B05D8F,00000000), ref: 00B409ED
                                      • CloseHandle.KERNEL32(00000000,?,000001F4,?,?,?,?,?,?,?,?,?,?,wusa.exe,?,00000025), ref: 00B26EC9
                                      • CloseHandle.KERNEL32(00000000,?,000001F4,?,?,?,?,?,?,?,?,?,?,wusa.exe,?,00000025), ref: 00B26EDD
                                      Strings
                                      • Failed to wait for executable to complete: %ls, xrefs: 00B26E58
                                      • Failed to determine WOW64 status., xrefs: 00B26AEB
                                      • Failed to format MSU install command., xrefs: 00B26C15
                                      • Failed to find System32 directory., xrefs: 00B26B4E
                                      • Failed to get cached path for package: %ls, xrefs: 00B26BB5
                                      • 2, xrefs: 00B26D6C
                                      • Failed to get process exit code., xrefs: 00B26DE5
                                      • Failed to find Windows directory., xrefs: 00B26B18
                                      • Failed to append log path to MSU command-line., xrefs: 00B26C8D
                                      • SysNative\, xrefs: 00B26B23
                                      • Bootstrapper application aborted during MSU progress., xrefs: 00B26E0D
                                      • Failed to append log switch to MSU command-line., xrefs: 00B26C6F
                                      • Failed to build MSU path., xrefs: 00B26BEE
                                      • Failed to get action arguments for MSU package., xrefs: 00B26B8F
                                      • /log:, xrefs: 00B26C5B
                                      • wusa.exe, xrefs: 00B26B59
                                      • Failed to format MSU uninstall command., xrefs: 00B26C42
                                      • D, xrefs: 00B26CF4
                                      • Failed to allocate WUSA.exe path., xrefs: 00B26B6C
                                      • Failed to CreateProcess on path: %ls, xrefs: 00B26D53
                                      • Failed to ensure WU service was enabled to install MSU package., xrefs: 00B26CE7
                                      • WixBundleExecutePackageCacheFolder, xrefs: 00B26BC4, 00B26EF5
                                      • "%ls" "%ls" /quiet /norestart, xrefs: 00B26C01
                                      • Failed to append SysNative directory., xrefs: 00B26B36
                                      • msuuser.cpp, xrefs: 00B26D46, 00B26DDB, 00B26E03
                                      • "%ls" /uninstall /kb:%ls /quiet /norestart, xrefs: 00B26C2E
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Handle$Close$AddressCurrentErrorLastModuleProcProcess
                                      • String ID: /log:$"%ls" "%ls" /quiet /norestart$"%ls" /uninstall /kb:%ls /quiet /norestart$2$Bootstrapper application aborted during MSU progress.$D$Failed to CreateProcess on path: %ls$Failed to allocate WUSA.exe path.$Failed to append SysNative directory.$Failed to append log path to MSU command-line.$Failed to append log switch to MSU command-line.$Failed to build MSU path.$Failed to determine WOW64 status.$Failed to ensure WU service was enabled to install MSU package.$Failed to find System32 directory.$Failed to find Windows directory.$Failed to format MSU install command.$Failed to format MSU uninstall command.$Failed to get action arguments for MSU package.$Failed to get cached path for package: %ls$Failed to get process exit code.$Failed to wait for executable to complete: %ls$SysNative\$WixBundleExecutePackageCacheFolder$msuuser.cpp$wusa.exe
                                      • API String ID: 1400713077-4261965642
                                      • Opcode ID: e0ae1c21d2de00848f08da07580a4aa62e007f1b35c3ed6b25022335ce9dbb54
                                      • Instruction ID: 6a820189529962650cf483f7ca0eaaed655c730d858048912235a04f787ad296
                                      • Opcode Fuzzy Hash: e0ae1c21d2de00848f08da07580a4aa62e007f1b35c3ed6b25022335ce9dbb54
                                      • Instruction Fuzzy Hash: 7DD19474A00329BBDF11AFA4EC86FAE7BF8EF04700F1041E5F609A21A1D7B19E449B51
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,generator,000000FF,?,?,?), ref: 00B47407
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B475D0
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B4766D
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$FreeHeap$AllocateCompareProcess
                                      • String ID: ($@$atomutil.cpp$author$category$entry$generator$icon$link$logo$subtitle$title$updated
                                      • API String ID: 1555028553-2592408802
                                      • Opcode ID: 296bbaa119c8ed41e76acc5a1ae5bf62ff422e4bef6dea235c12324b33f1b614
                                      • Instruction ID: b2789fa6bb79626977016b03fb7277ab5ae07dca9fb51e14f09f547ce65b1da9
                                      • Opcode Fuzzy Hash: 296bbaa119c8ed41e76acc5a1ae5bf62ff422e4bef6dea235c12324b33f1b614
                                      • Instruction Fuzzy Hash: A8B18271988616BBCB119B58CC81F6E7BF5EB15720F214394F921A62D1DB70EF00EB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,00B63C78,000000FF,?,?,?), ref: 00B4707E
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,summary,000000FF), ref: 00B470A3
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,title,000000FF), ref: 00B470C3
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,published,000000FF), ref: 00B470DF
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,updated,000000FF), ref: 00B47107
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,author,000000FF), ref: 00B47123
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,category,000000FF), ref: 00B4715C
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,content,000000FF), ref: 00B47195
                                        • Part of subcall function 00B46BF6: SysFreeString.OLEAUT32(00000000), ref: 00B46D2F
                                        • Part of subcall function 00B46BF6: SysFreeString.OLEAUT32(00000000), ref: 00B46D71
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B47219
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B472C9
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$Compare$Free
                                      • String ID: ($atomutil.cpp$author$cabinet.dll$category$clbcatq.dll$content$feclient.dll$link$msi.dll$published$summary$title$updated$version.dll
                                      • API String ID: 318886736-4294603148
                                      • Opcode ID: e795d3a54daf5e0e71c541180b89a38ca5f57657375ac77ae886ebc5b326b4bd
                                      • Instruction ID: fd7401297c2e45539e64b3749b1c4172943924d412b791edca992d3e65f654e1
                                      • Opcode Fuzzy Hash: e795d3a54daf5e0e71c541180b89a38ca5f57657375ac77ae886ebc5b326b4bd
                                      • Instruction Fuzzy Hash: 08A17031988216BBDB219B94CC41FAD77F4EB06720F2047D5F521A62D1DBB0EB50EB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenW.KERNEL32(?,?,00000000,?,00B4B4F0,?,00000000,?,00B0442A,?,00B4B4F0), ref: 00B15304
                                      • GetCurrentProcessId.KERNEL32(?,00B0442A,?,00B4B4F0), ref: 00B1530F
                                      • SetNamedPipeHandleState.KERNEL32(?,000000FF,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B15346
                                      • ConnectNamedPipe.KERNEL32(?,00000000,?,00B0442A,?,00B4B4F0), ref: 00B1535B
                                      • GetLastError.KERNEL32(?,00B0442A,?,00B4B4F0), ref: 00B15365
                                      • Sleep.KERNEL32(00000064,?,00B0442A,?,00B4B4F0), ref: 00B15396
                                      • SetNamedPipeHandleState.KERNEL32(?,00000000,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B153B9
                                      • WriteFile.KERNEL32(?,crypt32.dll,00000004,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B153D4
                                      • WriteFile.KERNEL32(?,00B0442A,00B4B4F0,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B153EF
                                      • WriteFile.KERNEL32(?,?,00000004,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B1540A
                                      • ReadFile.KERNEL32(?,00000000,00000004,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B15425
                                      • GetLastError.KERNEL32(?,00B0442A,?,00B4B4F0), ref: 00B1547D
                                      • GetLastError.KERNEL32(?,00B0442A,?,00B4B4F0), ref: 00B154B1
                                      • GetLastError.KERNEL32(?,00B0442A,?,00B4B4F0), ref: 00B154E5
                                      • GetLastError.KERNEL32(?,00B0442A,?,00B4B4F0), ref: 00B1557B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$File$NamedPipeWrite$HandleState$ConnectCurrentProcessReadSleeplstrlen
                                      • String ID: Failed to read ACK from pipe.$Failed to reset pipe to blocking.$Failed to set pipe to non-blocking.$Failed to wait for child to connect to pipe.$Failed to write our process id to pipe.$Failed to write secret length to pipe.$Failed to write secret to pipe.$crypt32.dll$pipe.cpp
                                      • API String ID: 2944378912-2047837012
                                      • Opcode ID: c6427e9353c73e3f79600b3cc64e6c6051648dbf0f37eb766387ae728ffa9c0d
                                      • Instruction ID: 2118b2cb8c28b39fa1cfb7cdebf7d0799aa4b88cfdaa5764fb8b2ccf734e4864
                                      • Opcode Fuzzy Hash: c6427e9353c73e3f79600b3cc64e6c6051648dbf0f37eb766387ae728ffa9c0d
                                      • Instruction Fuzzy Hash: B66107B6E40325AAE7209AB98C85FEAB6EDEF04B41F1141A5FE01F7190D774CE4086E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B0A356
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B0A37C
                                      • RegCloseKey.ADVAPI32(00000000,?,00000000,?,?,?,?,?), ref: 00B0A666
                                      Strings
                                      • Registry value not found. Key = '%ls', Value = '%ls', xrefs: 00B0A418
                                      • Unsupported registry key value type. Type = '%u', xrefs: 00B0A506
                                      • Failed to allocate memory registry value., xrefs: 00B0A487
                                      • Failed to set variable., xrefs: 00B0A629
                                      • Failed to clear variable., xrefs: 00B0A3D4
                                      • Failed to format value string., xrefs: 00B0A387
                                      • Failed to format key string., xrefs: 00B0A361
                                      • Failed to open registry key., xrefs: 00B0A3E9
                                      • Registry key not found. Key = '%ls', xrefs: 00B0A3B0
                                      • Failed to get expand environment string., xrefs: 00B0A5DB
                                      • Failed to query registry key value., xrefs: 00B0A4D8
                                      • search.cpp, xrefs: 00B0A44A, 00B0A47D, 00B0A4CE, 00B0A5D1
                                      • Failed to change value type., xrefs: 00B0A60D
                                      • Failed to query registry key value size., xrefs: 00B0A454
                                      • RegistrySearchValue failed: ID '%ls', HRESULT 0x%x, xrefs: 00B0A63E
                                      • Failed to allocate string buffer., xrefs: 00B0A565
                                      • Failed to read registry value., xrefs: 00B0A5F4
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open@16$Close
                                      • String ID: Failed to allocate memory registry value.$Failed to allocate string buffer.$Failed to change value type.$Failed to clear variable.$Failed to format key string.$Failed to format value string.$Failed to get expand environment string.$Failed to open registry key.$Failed to query registry key value size.$Failed to query registry key value.$Failed to read registry value.$Failed to set variable.$Registry key not found. Key = '%ls'$Registry value not found. Key = '%ls', Value = '%ls'$RegistrySearchValue failed: ID '%ls', HRESULT 0x%x$Unsupported registry key value type. Type = '%u'$search.cpp
                                      • API String ID: 2348241696-3124384294
                                      • Opcode ID: 385c72b66fd1c634206b5959c71fb58b8d554494a51185512a52aa917f28735b
                                      • Instruction ID: 3b70fd762c7f2ac3c163743f4842198bce58d69dcd645ed05b1b8f90e3aaeda8
                                      • Opcode Fuzzy Hash: 385c72b66fd1c634206b5959c71fb58b8d554494a51185512a52aa917f28735b
                                      • Instruction Fuzzy Hash: C3A1C372D40729BBDF11AAA4CC45EAE7EF9FB04710F1485E1F904B61D0DA72DE00A792
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • UuidCreate.RPCRT4(?), ref: 00B2D2A7
                                      • StringFromGUID2.OLE32(?,?,00000027), ref: 00B2D2D0
                                      • CreateProcessW.KERNEL32(?,?,00000000,00000000,00000000,08000000,00000000,00000000,?,?,?,?,?,?), ref: 00B2D3BC
                                      • GetLastError.KERNEL32(?,?,?,?), ref: 00B2D3C6
                                      • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,00000064,?,?,?,?), ref: 00B2D45B
                                      • GetExitCodeProcess.KERNEL32(?,?), ref: 00B2D485
                                      • GetLastError.KERNEL32(?,?,?,?), ref: 00B2D493
                                      • GetLastError.KERNEL32(?,?,?,?), ref: 00B2D4CB
                                        • Part of subcall function 00B2D12C: WaitForSingleObject.KERNEL32(?,000000FF,762330B0,00000000,?,?,?,?,00B2D439,?), ref: 00B2D145
                                        • Part of subcall function 00B2D12C: ReleaseMutex.KERNEL32(?,?,?,?,00B2D439,?), ref: 00B2D161
                                        • Part of subcall function 00B2D12C: WaitForSingleObject.KERNEL32(?,000000FF), ref: 00B2D1A4
                                        • Part of subcall function 00B2D12C: ReleaseMutex.KERNEL32(?), ref: 00B2D1BB
                                        • Part of subcall function 00B2D12C: SetEvent.KERNEL32(?), ref: 00B2D1C4
                                      • CloseHandle.KERNEL32(00000000,?,?,?,?,?,?,?,?), ref: 00B2D580
                                      • CloseHandle.KERNEL32(00000000,?,?,?,?,?,?,?,?), ref: 00B2D598
                                      Strings
                                      • Failed to wait for netfx chainer process to complete, xrefs: 00B2D4F9
                                      • Failed to convert netfx chainer guid into string., xrefs: 00B2D2EF
                                      • D, xrefs: 00B2D3A1
                                      • %ls /pipe %ls, xrefs: 00B2D373
                                      • NetFxEvent.%ls, xrefs: 00B2D31F
                                      • Failed to allocate section name., xrefs: 00B2D311
                                      • Failed to allocate event name., xrefs: 00B2D333
                                      • Failed to CreateProcess on path: %ls, xrefs: 00B2D3F5
                                      • Failed to create netfx chainer., xrefs: 00B2D352
                                      • Failed to create netfx chainer guid., xrefs: 00B2D2B4
                                      • Failed to get netfx return code., xrefs: 00B2D4C1
                                      • NetFxSection.%ls, xrefs: 00B2D2FD
                                      • Failed to allocate netfx chainer arguments., xrefs: 00B2D387
                                      • NetFxChainer.cpp, xrefs: 00B2D2E5, 00B2D3EA, 00B2D4B7, 00B2D4EF
                                      • Failed to process netfx chainer message., xrefs: 00B2D43F
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastWait$CloseCreateHandleMutexObjectProcessReleaseSingle$CodeEventExitFromMultipleObjectsStringUuid
                                      • String ID: %ls /pipe %ls$D$Failed to CreateProcess on path: %ls$Failed to allocate event name.$Failed to allocate netfx chainer arguments.$Failed to allocate section name.$Failed to convert netfx chainer guid into string.$Failed to create netfx chainer guid.$Failed to create netfx chainer.$Failed to get netfx return code.$Failed to process netfx chainer message.$Failed to wait for netfx chainer process to complete$NetFxChainer.cpp$NetFxEvent.%ls$NetFxSection.%ls
                                      • API String ID: 2531618940-1825855094
                                      • Opcode ID: fc017f93f3e24b9f6f29b6545b4bae5313f62363494265e974ebaff4c6f6247e
                                      • Instruction ID: 8dad3ffd5d711f511e8c06ab1c3c886760f71fa74b0297b8aa07b6b467cf6a82
                                      • Opcode Fuzzy Hash: fc017f93f3e24b9f6f29b6545b4bae5313f62363494265e974ebaff4c6f6247e
                                      • Instruction Fuzzy Hash: AFA17F71E40328ABEB20ABA5DC45BAEB7F8AF04710F1041A9F90DF7251D7759E448F92
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(000002C0,00000100,00000100,00000000,00000000,?,00B099BB,000002C0,?,00000000,00000000,000002C0,00000100,000002C0,00000100), ref: 00B056A2
                                      • lstrlenW.KERNEL32(00000000,?,00B099BB,000002C0,?,00000000,00000000,000002C0,00000100,000002C0,00000100), ref: 00B056AC
                                      • _wcschr.LIBVCRUNTIME ref: 00B058B4
                                      • LeaveCriticalSection.KERNEL32(000002C0,00000000,00000000,00000000,00000000,00000000,00000001,?,00B099BB,000002C0,?,00000000,00000000,000002C0,00000100,000002C0), ref: 00B05B56
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave_wcschrlstrlen
                                      • String ID: *****$Failed to allocate buffer for format string.$Failed to allocate record.$Failed to allocate string.$Failed to allocate variable array.$Failed to append placeholder.$Failed to append string.$Failed to copy string.$Failed to determine variable visibility: '%ls'.$Failed to format placeholder string.$Failed to format record.$Failed to get formatted length.$Failed to get variable name.$Failed to reallocate variable array.$Failed to set record format string.$Failed to set record string.$Failed to set variable value.$[%d]$variable.cpp
                                      • API String ID: 1026845265-2050445661
                                      • Opcode ID: 3c6f9a781c0300689877506d91f5d9ef541ce32d417715123c675d8dace90285
                                      • Instruction ID: 3af68c77b18930ed1b2a08ebde96125cef9e306209ad23dab98073f9eba09a60
                                      • Opcode Fuzzy Hash: 3c6f9a781c0300689877506d91f5d9ef541ce32d417715123c675d8dace90285
                                      • Instruction Fuzzy Hash: 47F1A271E00719EBDF219FA48881EAF7FE8EB04B50F1181A9BD05A7690D7349E019FA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • CreateEventW.KERNEL32(00000000,00000000,00000000,?,00000000,00000018,00000001,?,00000000,?,?,00B2D34C,?,?,?), ref: 00B2CC6A
                                      • GetLastError.KERNEL32(?,?,00B2D34C,?,?,?), ref: 00B2CC77
                                      • ReleaseMutex.KERNEL32(?), ref: 00B2CEDF
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateCreateErrorEventLastMutexProcessRelease
                                      • String ID: %ls_mutex$%ls_send$Failed to MapViewOfFile for %ls.$Failed to allocate memory for NetFxChainer struct.$Failed to create event: %ls$Failed to create mutex: %ls$Failed to memory map cabinet file: %ls$NetFxChainer.cpp$failed to allocate memory for event name$failed to allocate memory for mutex name$failed to copy event name to shared memory structure.
                                      • API String ID: 3944734951-2991465304
                                      • Opcode ID: c5efe28ea4da65cd13f52d5086c8cf9c24def21d3de1deedde83a38e897c9294
                                      • Instruction ID: e9212c9d79ee9718d1c3f760245f54f8033aea3da42eb1f3e8a786d0b15a06cd
                                      • Opcode Fuzzy Hash: c5efe28ea4da65cd13f52d5086c8cf9c24def21d3de1deedde83a38e897c9294
                                      • Instruction Fuzzy Hash: 3B711276A40721BBD721AB699C49F9B7EE8FF09350F0241A5FD08A72A0D774DE00C6E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B431C7: VariantInit.OLEAUT32(?), ref: 00B431DD
                                        • Part of subcall function 00B431C7: SysAllocString.OLEAUT32(?), ref: 00B431F9
                                        • Part of subcall function 00B431C7: VariantClear.OLEAUT32(?), ref: 00B43280
                                        • Part of subcall function 00B431C7: SysFreeString.OLEAUT32(00000000), ref: 00B4328B
                                      • CompareStringW.KERNEL32(0000007F,00000000,000000FF,000000FF,Detect,000000FF,?,00B4CA64,?,?,Action,?,?,?,00000000,00B0533D), ref: 00B0EA07
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,Upgrade,000000FF), ref: 00B0EA51
                                      Strings
                                      • Addon, xrefs: 00B0EA8E
                                      • comres.dll, xrefs: 00B0EA1A
                                      • RelatedBundle, xrefs: 00B0E944
                                      • Upgrade, xrefs: 00B0EA44
                                      • Detect, xrefs: 00B0E9F8
                                      • Action, xrefs: 00B0E9C4
                                      • Failed to resize Addon code array in registration, xrefs: 00B0EB30
                                      • Failed to get @Id., xrefs: 00B0EB56
                                      • cabinet.dll, xrefs: 00B0EAAE
                                      • Failed to get RelatedBundle element count., xrefs: 00B0E98B
                                      • Failed to get RelatedBundle nodes, xrefs: 00B0E966
                                      • Failed to resize Upgrade code array in registration, xrefs: 00B0EB29
                                      • Failed to get next RelatedBundle element., xrefs: 00B0EB64
                                      • version.dll, xrefs: 00B0EA64
                                      • Failed to get @Action., xrefs: 00B0EB5D
                                      • Patch, xrefs: 00B0EAD1
                                      • Failed to resize Detect code array in registration, xrefs: 00B0EB22
                                      • Invalid value for @Action: %ls, xrefs: 00B0EB46
                                      • Failed to resize Patch code array in registration, xrefs: 00B0EB37
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$CompareVariant$AllocClearFreeInit
                                      • String ID: Action$Addon$Detect$Failed to get @Action.$Failed to get @Id.$Failed to get RelatedBundle element count.$Failed to get RelatedBundle nodes$Failed to get next RelatedBundle element.$Failed to resize Addon code array in registration$Failed to resize Detect code array in registration$Failed to resize Patch code array in registration$Failed to resize Upgrade code array in registration$Invalid value for @Action: %ls$Patch$RelatedBundle$Upgrade$cabinet.dll$comres.dll$version.dll
                                      • API String ID: 702752599-259800149
                                      • Opcode ID: 023ba895072c926d58307e274f1bed795aceb57f2f6741fe98887629afd77135
                                      • Instruction ID: 452d9020ddc3a0c07064feade239b9fa93112c19fc8b17563aae7e0f3a312e89
                                      • Opcode Fuzzy Hash: 023ba895072c926d58307e274f1bed795aceb57f2f6741fe98887629afd77135
                                      • Instruction Fuzzy Hash: C9718D71A45626BFCB109A54C881FAABBF4FF04721F204AD4F922A76D1D730EE51DB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetStringTypeW.KERNEL32(00000001,5600B4DB,00000001,?,00B09801,?,00000000,00000000), ref: 00B08E8D
                                      Strings
                                      • Failed to set symbol value., xrefs: 00B08F35
                                      • NOT, xrefs: 00B091A7
                                      • Failed to parse condition "%ls". Constant too big, at position %d., xrefs: 00B0924D
                                      • Failed to parse condition "%ls". Invalid version format, at position %d., xrefs: 00B0910C
                                      • condition.cpp, xrefs: 00B08F5C, 00B09027, 00B0909C, 00B090F9, 00B0923A, 00B0927A, 00B092B5
                                      • -, xrefs: 00B08FF1
                                      • Failed to parse condition "%ls". Unterminated literal at position %d., xrefs: 00B08F6F
                                      • Failed to parse condition "%ls". Unexpected character at position %d., xrefs: 00B0903A
                                      • AND, xrefs: 00B09187
                                      • @, xrefs: 00B08E93
                                      • Failed to parse condition "%ls". Identifier cannot start at a digit, at position %d., xrefs: 00B0928D
                                      • Failed to parse condition "%ls". Unexpected '~' operator at position %d., xrefs: 00B092C8
                                      • Failed to parse condition "%ls". Version can have a maximum of 4 parts, at position %d., xrefs: 00B090AF
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: StringType
                                      • String ID: -$@$AND$Failed to parse condition "%ls". Constant too big, at position %d.$Failed to parse condition "%ls". Identifier cannot start at a digit, at position %d.$Failed to parse condition "%ls". Invalid version format, at position %d.$Failed to parse condition "%ls". Unexpected '~' operator at position %d.$Failed to parse condition "%ls". Unexpected character at position %d.$Failed to parse condition "%ls". Unterminated literal at position %d.$Failed to parse condition "%ls". Version can have a maximum of 4 parts, at position %d.$Failed to set symbol value.$NOT$condition.cpp
                                      • API String ID: 4177115715-3640792234
                                      • Opcode ID: 7cab581422e35e035a7fd93d3ef42f7cdfe4468b92d5ae68f5016881149f10b2
                                      • Instruction ID: fa55220f830485d7d273b4f1c47feaa834cfc935680a61c47966631e955e4a66
                                      • Opcode Fuzzy Hash: 7cab581422e35e035a7fd93d3ef42f7cdfe4468b92d5ae68f5016881149f10b2
                                      • Instruction Fuzzy Hash: 8AE1FDB1640205EBDB218F64C889BBA7FE9FB05710F2480D5F9459E2D6CBB5CA81DB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentProcessId.KERNEL32(?,8000FFFF,feclient.dll,?,00B149FE,00B4B4D8,?,feclient.dll,00000000,?,?), ref: 00B144FE
                                      • ReadFile.KERNEL32(feclient.dll,feclient.dll,00000004,?,00000000,?,00B149FE,00B4B4D8,?,feclient.dll,00000000,?,?), ref: 00B1451F
                                      • GetLastError.KERNEL32(?,00B149FE,00B4B4D8,?,feclient.dll,00000000,?,?), ref: 00B14525
                                      • WriteFile.KERNEL32(feclient.dll,?,00000004,00B149FE,00000000,?,00B149FE,00B4B4D8,?,feclient.dll,00000000,?,?), ref: 00B1468E
                                      • GetLastError.KERNEL32(?,00B149FE,00B4B4D8,?,feclient.dll,00000000,?,?), ref: 00B14698
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLast$CurrentProcessReadWrite
                                      • String ID: Failed to allocate buffer for verification secret.$Failed to inform parent process that child is running.$Failed to read size of verification secret from parent pipe.$Failed to read verification process id from parent pipe.$Failed to read verification secret from parent pipe.$Verification process id from parent does not match.$Verification secret from parent does not match.$Verification secret from parent is too big.$feclient.dll$msasn1.dll$pipe.cpp
                                      • API String ID: 3008747291-452622383
                                      • Opcode ID: 12507a62198af1c2c34508e673046a9b2febfc64198d86760cf36a283a445137
                                      • Instruction ID: bfee78f9d2a24312acbf5d19d422db738bb64c7ce39c2ee2319ec59dbe4edc5a
                                      • Opcode Fuzzy Hash: 12507a62198af1c2c34508e673046a9b2febfc64198d86760cf36a283a445137
                                      • Instruction Fuzzy Hash: 5751F176A40315BBE7219AA58C85FAFB6FCEB05B11F1101E5FE01F72A0D7348E4496E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: StringVariant$AllocClearFreeInit
                                      • String ID: DetectCondition$Failed to get @DetectCondition.$Failed to get @InstallArguments.$Failed to get @Protocol.$Failed to get @RepairArguments.$Failed to get @Repairable.$Failed to get @UninstallArguments.$Failed to parse command lines.$Failed to parse exit codes.$InstallArguments$Invalid protocol type: %ls$Protocol$RepairArguments$Repairable$UninstallArguments$burn$netfx4$none
                                      • API String ID: 760788290-1911311241
                                      • Opcode ID: 56e6168309ebef0b880fa0fb54e9465514a839d5523bafa89c61ae2c9169131b
                                      • Instruction ID: 20d58a5e7eb8488056c7d625a2fb2dc8e29e2c8190fb07b959afbf13aee8518a
                                      • Opcode Fuzzy Hash: 56e6168309ebef0b880fa0fb54e9465514a839d5523bafa89c61ae2c9169131b
                                      • Instruction Fuzzy Hash: 57410F32A8877576CF266764AC42F6A75EC9B10B31F3443E1FD18F62F1C7A4AE049291
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • CompareStringW.KERNEL32(0000007F,00000000,00000000,000000FF,success,000000FF,?,Type,00000000,?,?,00000000,?,00000001,?), ref: 00B21A77
                                      • CompareStringW.KERNEL32(0000007F,00000000,00000000,000000FF,error,000000FF), ref: 00B21A95
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareHeapString$AllocateProcess
                                      • String ID: Code$ExitCode$Failed to allocate memory for exit code structs.$Failed to get @Code.$Failed to get @Type.$Failed to get exit code node count.$Failed to get next node.$Failed to parse @Code value: %ls$Failed to select exit code nodes.$Invalid exit code type: %ls$Type$error$exeuser.cpp$forceReboot$scheduleReboot$success
                                      • API String ID: 2664528157-1714101571
                                      • Opcode ID: e6274e741e981d3dbbb09bb1164895b382722ba2721846736bb61f376cf3a432
                                      • Instruction ID: 41b47164ed32c9c3f820280db8bcc25f725f485b7fc5242f75c325bd81668950
                                      • Opcode Fuzzy Hash: e6274e741e981d3dbbb09bb1164895b382722ba2721846736bb61f376cf3a432
                                      • Instruction Fuzzy Hash: 8261F435A01229BBCB109B58DC45EAEBBF4EF14B20F204AD5F828BB2D1D7709E41D790
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B439CD: GetVersionExW.KERNEL32(?,?,00000000,?), ref: 00B43A1A
                                      • RegCloseKey.ADVAPI32(00000000,?,00020006,00020006,00000000,?,?,00000002,00000000,?,00000000,00000001,00000002), ref: 00B0F2CB
                                        • Part of subcall function 00B41344: RegSetValueExW.ADVAPI32(?,?,00000000,00000004,?,00000004,SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce,?,00B0F11A,00000005,Resume,?,?,?,00000002,00000000), ref: 00B41359
                                      Strings
                                      • Failed to format resume command line for RunOnce., xrefs: 00B0F186
                                      • BundleResumeCommandLine, xrefs: 00B0F1D5, 00B0F267
                                      • Failed to delete run key value., xrefs: 00B0F25A
                                      • Failed to write run key value., xrefs: 00B0F1C8
                                      • Failed to create run key., xrefs: 00B0F1AA
                                      • burn.runonce, xrefs: 00B0F167
                                      • Failed to delete resume command line value., xrefs: 00B0F2A7
                                      • SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, xrefs: 00B0F0AE
                                      • Resume, xrefs: 00B0F10F
                                      • Failed to write Resume value., xrefs: 00B0F120
                                      • "%ls" /%ls, xrefs: 00B0F172
                                      • Failed to write resume command line value., xrefs: 00B0F1EA
                                      • Failed to write Installed value., xrefs: 00B0F143
                                      • Installed, xrefs: 00B0F132
                                      • registration.cpp, xrefs: 00B0F250, 00B0F29D
                                      • SOFTWARE\Microsoft\Windows\CurrentVersion\Run, xrefs: 00B0F0FA
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseValueVersion
                                      • String ID: "%ls" /%ls$BundleResumeCommandLine$Failed to create run key.$Failed to delete resume command line value.$Failed to delete run key value.$Failed to format resume command line for RunOnce.$Failed to write Installed value.$Failed to write Resume value.$Failed to write resume command line value.$Failed to write run key value.$Installed$Resume$SOFTWARE\Microsoft\Windows\CurrentVersion\Run$SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce$burn.runonce$registration.cpp
                                      • API String ID: 2348918689-3140388177
                                      • Opcode ID: b4d97c4e25679025bbd4507bb98e632955f940d7e6154d9c98213cb48042a802
                                      • Instruction ID: e38195785618e7cb3ecbc76cddc78000983fd201cf93f80e301b8e864c295325
                                      • Opcode Fuzzy Hash: b4d97c4e25679025bbd4507bb98e632955f940d7e6154d9c98213cb48042a802
                                      • Instruction Fuzzy Hash: 8C51AD36A40726BBDF21AAA8CC42BBE7AE4EF04741F0045F5FD00B65A1D771DE549AC1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,http://appsyndication.org/2006/appsyn,000000FF,00000000,00000000,00000000,000002C0), ref: 00B48019
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,application,000000FF), ref: 00B48034
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,upgrade,000000FF), ref: 00B480D7
                                      • CompareStringW.KERNEL32(0000007F,00000000,00700079,000000FF,version,000000FF,00000018,00B4B508,00000000), ref: 00B48116
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,exclusive,000000FF), ref: 00B48169
                                      • CompareStringW.KERNEL32(0000007F,00000000,00B4B508,000000FF,true,000000FF), ref: 00B48187
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,version,000000FF), ref: 00B481BF
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,enclosure,000000FF), ref: 00B48303
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareString
                                      • String ID: application$apuputil.cpp$enclosure$exclusive$http://appsyndication.org/2006/appsyn$true$type$upgrade$version
                                      • API String ID: 1825529933-3037633208
                                      • Opcode ID: b05a85c8492fa63d4748f37c41cf92df17297e81cafd594fe1025967a6c80f70
                                      • Instruction ID: 3ecb683792b0a899f5d13891b0e576eefda52a997c3ea8e59e3eb42212b42c8c
                                      • Opcode Fuzzy Hash: b05a85c8492fa63d4748f37c41cf92df17297e81cafd594fe1025967a6c80f70
                                      • Instruction Fuzzy Hash: AFB19C31954206ABDB219F54CC81F5E77F6EB44720F248699FA28AB2D1DB70EA40DB00
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,rel,000000FF,?,?,?,00000000), ref: 00B47703
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,href,000000FF), ref: 00B47727
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,length,000000FF), ref: 00B47746
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,title,000000FF), ref: 00B4777D
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,type,000000FF), ref: 00B47798
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B477C3
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B47842
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B4788E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$Compare$Free
                                      • String ID: comres.dll$feclient.dll$href$length$msasn1.dll$msi.dll$rel$title$type$version.dll
                                      • API String ID: 318886736-3944986760
                                      • Opcode ID: 7a6c07ff8c2a156f5c6128cc8f031650e6cc6e934f9bcd073e54a88a1018ed89
                                      • Instruction ID: 938eb2afd442f11dfe396767feb7ac37d6d9ffd9cb02583bbb771d4d284d83be
                                      • Opcode Fuzzy Hash: 7a6c07ff8c2a156f5c6128cc8f031650e6cc6e934f9bcd073e54a88a1018ed89
                                      • Instruction Fuzzy Hash: FE714F35944119BBCF15DBA4CC84EAEBBF8EF04720F2542E4E925A71A1DB319F44EB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B1E05E: LoadBitmapW.USER32(?,00000001), ref: 00B1E094
                                        • Part of subcall function 00B1E05E: GetLastError.KERNEL32 ref: 00B1E0A0
                                      • LoadCursorW.USER32(00000000,00007F00), ref: 00B1E1D8
                                      • RegisterClassW.USER32(?), ref: 00B1E1EC
                                      • GetLastError.KERNEL32 ref: 00B1E1F7
                                      • UnregisterClassW.USER32(WixBurnSplashScreen,?), ref: 00B1E2FC
                                      • DeleteObject.GDI32(00000000), ref: 00B1E30B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ClassErrorLastLoad$BitmapCursorDeleteObjectRegisterUnregister
                                      • String ID: Failed to create window.$Failed to load splash screen.$Failed to register window.$Unexpected return value from message pump.$WixBurnSplashScreen$splashscreen.cpp
                                      • API String ID: 164797020-2188509422
                                      • Opcode ID: 6da1cdd36f5d99b37f02b0ade85148a9d992558e6bfaa2715c061b29529bf835
                                      • Instruction ID: c86258e1a2266ce4d39a6a756185601ca500d214d93d43b0c315db14599142ee
                                      • Opcode Fuzzy Hash: 6da1cdd36f5d99b37f02b0ade85148a9d992558e6bfaa2715c061b29529bf835
                                      • Instruction Fuzzy Hash: 4A418B76A00619FEEB119BA5DC49EEABBF9FF08700F100165FE15E7160DB70DE448AA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WaitForMultipleObjects.KERNEL32(00000001,?,00000000,000000FF,00000001,00000000,00000000,?,00B2BA53,00000001), ref: 00B29C18
                                      • GetLastError.KERNEL32(?,00B2BA53,00000001), ref: 00B29D88
                                      • GetExitCodeThread.KERNEL32(00000001,00000000,?,00B2BA53,00000001), ref: 00B29DC8
                                      • GetLastError.KERNEL32(?,00B2BA53,00000001), ref: 00B29DD2
                                      Strings
                                      • Failed to load compatible package on per-machine package., xrefs: 00B29D2E
                                      • apply.cpp, xrefs: 00B29DAC, 00B29DF6
                                      • Failed to get cache thread exit code., xrefs: 00B29E03
                                      • Failed to execute dependency action., xrefs: 00B29D08
                                      • Failed to execute MSU package., xrefs: 00B29CCD
                                      • Failed to wait for cache check-point., xrefs: 00B29DB9
                                      • Failed to execute compatible package action., xrefs: 00B29D45
                                      • Failed to execute EXE package., xrefs: 00B29C4F
                                      • Cache thread exited unexpectedly., xrefs: 00B29E14
                                      • Failed to execute package provider registration action., xrefs: 00B29CE9
                                      • Invalid execute action., xrefs: 00B29E23
                                      • Failed to execute MSI package., xrefs: 00B29C78
                                      • Failed to execute MSP package., xrefs: 00B29C9D
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CodeExitMultipleObjectsThreadWait
                                      • String ID: Cache thread exited unexpectedly.$Failed to execute EXE package.$Failed to execute MSI package.$Failed to execute MSP package.$Failed to execute MSU package.$Failed to execute compatible package action.$Failed to execute dependency action.$Failed to execute package provider registration action.$Failed to get cache thread exit code.$Failed to load compatible package on per-machine package.$Failed to wait for cache check-point.$Invalid execute action.$apply.cpp
                                      • API String ID: 3703294532-2662572847
                                      • Opcode ID: 01b8293687ec53755e6e94f67b643f342e081b13fb45c2b206869c9b725d824d
                                      • Instruction ID: 118a6cfdc6fa7c148b46b66f4b9132e76f245e6c6c8f58b51ceb56bd37f32e0d
                                      • Opcode Fuzzy Hash: 01b8293687ec53755e6e94f67b643f342e081b13fb45c2b206869c9b725d824d
                                      • Instruction Fuzzy Hash: 3F716B71A01229EBDB14DF64E941EBEBBF8EB08710F1141E9BD0DF7290D6709E059B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentProcessId.KERNEL32(76228FB0,00000002,00000000), ref: 00B2CA40
                                        • Part of subcall function 00B14B96: UuidCreate.RPCRT4(?), ref: 00B14BC9
                                      • CreateProcessW.KERNEL32(?,?,00000000,00000000,00000001,08000000,00000000,00000000,?,00B221A5,?,?,00000000,?,?,?), ref: 00B2CB1E
                                      • GetLastError.KERNEL32(?,?,00000000,?,?,?,?), ref: 00B2CB28
                                      • GetProcessId.KERNEL32(00B221A5,?,?,00000000,?,?,?,?), ref: 00B2CB60
                                        • Part of subcall function 00B152E3: lstrlenW.KERNEL32(?,?,00000000,?,00B4B4F0,?,00000000,?,00B0442A,?,00B4B4F0), ref: 00B15304
                                        • Part of subcall function 00B152E3: GetCurrentProcessId.KERNEL32(?,00B0442A,?,00B4B4F0), ref: 00B1530F
                                        • Part of subcall function 00B152E3: SetNamedPipeHandleState.KERNEL32(?,000000FF,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B15346
                                        • Part of subcall function 00B152E3: ConnectNamedPipe.KERNEL32(?,00000000,?,00B0442A,?,00B4B4F0), ref: 00B1535B
                                        • Part of subcall function 00B152E3: GetLastError.KERNEL32(?,00B0442A,?,00B4B4F0), ref: 00B15365
                                        • Part of subcall function 00B152E3: Sleep.KERNEL32(00000064,?,00B0442A,?,00B4B4F0), ref: 00B15396
                                        • Part of subcall function 00B152E3: SetNamedPipeHandleState.KERNEL32(?,00000000,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B153B9
                                        • Part of subcall function 00B152E3: WriteFile.KERNEL32(?,crypt32.dll,00000004,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B153D4
                                        • Part of subcall function 00B152E3: WriteFile.KERNEL32(?,00B0442A,00B4B4F0,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B153EF
                                        • Part of subcall function 00B152E3: WriteFile.KERNEL32(?,?,00000004,00000000,00000000,?,00B0442A,?,00B4B4F0), ref: 00B1540A
                                        • Part of subcall function 00B40917: WaitForSingleObject.KERNEL32(000000FF,?,00000000,?,?,00B04E16,?,000000FF,?,?,?,?,?,00000000,?,?), ref: 00B40927
                                        • Part of subcall function 00B40917: GetLastError.KERNEL32(?,?,00B04E16,?,000000FF,?,?,?,?,?,00000000,?,?,?,?,?), ref: 00B40935
                                      • CloseHandle.KERNEL32(00000000,?,000000FF,00000000,?,00B2C992,?,?,?,?,?,00000000,?,?,?,?), ref: 00B2CBE4
                                      • CloseHandle.KERNEL32(00000000,?,000000FF,00000000,?,00B2C992,?,?,?,?,?,00000000,?,?,?,?), ref: 00B2CBF3
                                      • CloseHandle.KERNEL32(00000000,?,?,000000FF,00000000,?,00B2C992,?,?,?,?,?,00000000,?,?,?), ref: 00B2CC0A
                                      Strings
                                      • Failed to create embedded pipe name and client token., xrefs: 00B2CAA3
                                      • Failed to create embedded process at path: %ls, xrefs: 00B2CB56
                                      • embedded.cpp, xrefs: 00B2CB49
                                      • Failed to allocate embedded command., xrefs: 00B2CAF7
                                      • %ls -%ls %ls %ls %u, xrefs: 00B2CAE3
                                      • burn.embedded, xrefs: 00B2CADB
                                      • Failed to wait for embedded process to connect to pipe., xrefs: 00B2CB82
                                      • Failed to process messages from embedded message., xrefs: 00B2CBA7
                                      • Failed to create embedded pipe., xrefs: 00B2CACA
                                      • Failed to wait for embedded executable: %ls, xrefs: 00B2CBC7
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Handle$Process$CloseErrorFileLastNamedPipeWrite$CreateCurrentState$ConnectObjectSingleSleepUuidWaitlstrlen
                                      • String ID: %ls -%ls %ls %ls %u$Failed to allocate embedded command.$Failed to create embedded pipe name and client token.$Failed to create embedded pipe.$Failed to create embedded process at path: %ls$Failed to process messages from embedded message.$Failed to wait for embedded executable: %ls$Failed to wait for embedded process to connect to pipe.$burn.embedded$embedded.cpp
                                      • API String ID: 875070380-3803182736
                                      • Opcode ID: 385faa006568a6d3f0831b8e662e71ab44718e2d420d216589dd2cf7180da505
                                      • Instruction ID: 12c272128a28ac13b04dd4993dbfa0084ae20a82201f1e7a69041978b65f39df
                                      • Opcode Fuzzy Hash: 385faa006568a6d3f0831b8e662e71ab44718e2d420d216589dd2cf7180da505
                                      • Instruction Fuzzy Hash: 6F515C72D4022DBBDF11AAA4DC46FDEBEF8EB04710F1041A1FA04B6190D7749A419B91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,msi.dll,000000FF,http://appsyndication.org/2006/appsyn,000000FF,00000000,00000000,00000000,?,00B48320,00000001,?), ref: 00B47E56
                                      • CompareStringW.KERNEL32(0000007F,00000000,digest,000000FF,002E0069,000000FF,?,00B48320,00000001,?), ref: 00B47E71
                                      • CompareStringW.KERNEL32(0000007F,00000000,name,000000FF,002E0069,000000FF,?,00B48320,00000001,?), ref: 00B47E8C
                                      • CompareStringW.KERNEL32(0000007F,00000000,algorithm,000000FF,?,000000FF,?,00B48320,00000001,?), ref: 00B47EF8
                                      • CompareStringW.KERNEL32(0000007F,00000001,md5,000000FF,?,000000FF,?,00B48320,00000001,?), ref: 00B47F1C
                                      • CompareStringW.KERNEL32(0000007F,00000001,sha1,000000FF,?,000000FF,?,00B48320,00000001,?), ref: 00B47F40
                                      • CompareStringW.KERNEL32(0000007F,00000001,sha256,000000FF,?,000000FF,?,00B48320,00000001,?), ref: 00B47F60
                                      • lstrlenW.KERNEL32(006C0064,?,00B48320,00000001,?), ref: 00B47F7B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareString$lstrlen
                                      • String ID: algorithm$apuputil.cpp$digest$http://appsyndication.org/2006/appsyn$md5$msi.dll$name$sha1$sha256
                                      • API String ID: 1657112622-2492263259
                                      • Opcode ID: d84fc9274593194ac4d56825b55e3000c1778c5c0cff8dd0f7f3710350ddc420
                                      • Instruction ID: cbd8bc8f6a321d4a7dcafbd2a12df1d2a39446e96f724de2b9b7e6fa229f79e5
                                      • Opcode Fuzzy Hash: d84fc9274593194ac4d56825b55e3000c1778c5c0cff8dd0f7f3710350ddc420
                                      • Instruction Fuzzy Hash: 135160316CC212BBDB204E54CC86F267BA5EB15730F204394FA34BA6E5CB65EE90D790
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B09FA3
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open@16
                                      • String ID: AssignmentType$Failed to change value type.$Failed to copy upgrade code.$Failed to enumerate related products for upgrade code.$Failed to format GUID string.$Failed to get product info.$Failed to set variable.$Language$MsiProductSearch failed: ID '%ls', HRESULT 0x%x$Product or related product not found: %ls$State$Trying per-machine extended info for property '%ls' for product: %ls$Trying per-user extended info for property '%ls' for product: %ls$Unsupported product search type: %u$VersionString
                                      • API String ID: 3613110473-2134270738
                                      • Opcode ID: c826859852fcf2d34aa31fad6ed558a4b8a8bef8e5cbd28c4cbcfbb903be2669
                                      • Instruction ID: ee7bd6d37d075c239953ae0f672b8dd3ab0d3f8f5a1e5fec36d72efa4fe7bf51
                                      • Opcode Fuzzy Hash: c826859852fcf2d34aa31fad6ed558a4b8a8bef8e5cbd28c4cbcfbb903be2669
                                      • Instruction Fuzzy Hash: A061C132D4021DBBCB11AEA8C985DEE7FE9EB45710F1045E5F510BA2D2D632DF40A792
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenW.KERNEL32(?,?,00B29751,75C08550,?,?,00000000,?,?,?,00000001,00000000,?), ref: 00B2DC28
                                      Strings
                                      • Failed to add file to BITS job., xrefs: 00B2DCF5
                                      • Failed while waiting for BITS download., xrefs: 00B2DDD9
                                      • Invalid BITS user URL: %ls, xrefs: 00B2DC4A
                                      • Failed to set credentials for BITS job., xrefs: 00B2DCD6
                                      • Failed to complete BITS job., xrefs: 00B2DDD2
                                      • Falied to start BITS job., xrefs: 00B2DDE0
                                      • Failed to create BITS job callback., xrefs: 00B2DD3B
                                      • Failed to copy download URL., xrefs: 00B2DC6F
                                      • Failed to create BITS job., xrefs: 00B2DCB7
                                      • bitsuser.cpp, xrefs: 00B2DC3E, 00B2DD31
                                      • Failed to initialize BITS job callback., xrefs: 00B2DD49
                                      • Failed to download BITS job., xrefs: 00B2DDBF
                                      • Failed to set callback interface for BITS job., xrefs: 00B2DD60
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: lstrlen
                                      • String ID: Failed to add file to BITS job.$Failed to complete BITS job.$Failed to copy download URL.$Failed to create BITS job callback.$Failed to create BITS job.$Failed to download BITS job.$Failed to initialize BITS job callback.$Failed to set callback interface for BITS job.$Failed to set credentials for BITS job.$Failed while waiting for BITS download.$Falied to start BITS job.$Invalid BITS user URL: %ls$bitsuser.cpp
                                      • API String ID: 1659193697-2382896028
                                      • Opcode ID: dd8e2550df1d27f90e9d77c1b17649d049496a88c1b3ebe49ea9077efb985a53
                                      • Instruction ID: 5311aaf5737806c4bf7404e1de4bfc2f83f56f821ddac076891b788b804a2672
                                      • Opcode Fuzzy Hash: dd8e2550df1d27f90e9d77c1b17649d049496a88c1b3ebe49ea9077efb985a53
                                      • Instruction Fuzzy Hash: B761A131A10635EBCB11AF94E885E6E7BF4EF08B90B2141E9FC08AB261D774DD00DB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysFreeString.OLEAUT32(?), ref: 00B0ED40
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • SysFreeString.OLEAUT32(?), ref: 00B0ECF8
                                      Strings
                                      • Path, xrefs: 00B0ECA6
                                      • Failed to get @Filename., xrefs: 00B0ED9D
                                      • Failed to get next node., xrefs: 00B0EDA7
                                      • Failed to get @Path., xrefs: 00B0ED89
                                      • Failed to convert SoftwareTag text to UTF-8, xrefs: 00B0ED75
                                      • Failed to select software tag nodes., xrefs: 00B0EBE2
                                      • Regid, xrefs: 00B0EC8E
                                      • Failed to allocate memory for software tag structs., xrefs: 00B0EC3F
                                      • SoftwareTag, xrefs: 00B0EBC1
                                      • Filename, xrefs: 00B0EC73
                                      • registration.cpp, xrefs: 00B0EC35
                                      • Failed to get SoftwareTag text., xrefs: 00B0ED7F
                                      • Failed to get @Regid., xrefs: 00B0ED93
                                      • Failed to get software tag count., xrefs: 00B0EC07
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FreeHeapString$AllocateProcess
                                      • String ID: Failed to allocate memory for software tag structs.$Failed to convert SoftwareTag text to UTF-8$Failed to get @Filename.$Failed to get @Path.$Failed to get @Regid.$Failed to get SoftwareTag text.$Failed to get next node.$Failed to get software tag count.$Failed to select software tag nodes.$Filename$Path$Regid$SoftwareTag$registration.cpp
                                      • API String ID: 336948655-1068704183
                                      • Opcode ID: aff4e6c32822427a61c567d56910c83ed91eed46ba590cccee2e8f31b121c674
                                      • Instruction ID: fe68d87431f6b68098c9c809b95165e90f9277133439e5661daecdee85f6a366
                                      • Opcode Fuzzy Hash: aff4e6c32822427a61c567d56910c83ed91eed46ba590cccee2e8f31b121c674
                                      • Instruction Fuzzy Hash: 52518575A01319BBDB119F58C895FAEBFE4EF04B11F1449E9B826AB290DB70DE009790
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNEL32(00000000,C0000000,00000000,00000000,00000003,00000000,00000000,00000000,?,?), ref: 00B1498D
                                      • GetLastError.KERNEL32 ref: 00B1499B
                                      • Sleep.KERNEL32(00000064), ref: 00B149BF
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateErrorFileLastSleep
                                      • String ID: Failed to allocate name of parent cache pipe.$Failed to allocate name of parent pipe.$Failed to open companion process with PID: %u$Failed to open parent pipe: %ls$Failed to verify parent pipe: %ls$\\.\pipe\%ls$\\.\pipe\%ls.Cache$feclient.dll$pipe.cpp
                                      • API String ID: 408151869-3212458075
                                      • Opcode ID: ca9d8fa490b1a9609aceeb79fec7a56c9392b516ebacfa1fb5329f28b5551c23
                                      • Instruction ID: 2926e607dbc5bf15635ded381c2ccccd001bf8bc2849a5002a2b6dd3205f9939
                                      • Opcode Fuzzy Hash: ca9d8fa490b1a9609aceeb79fec7a56c9392b516ebacfa1fb5329f28b5551c23
                                      • Instruction Fuzzy Hash: 23410736D80721BBEB215BA49C46F9B7AE8EF00B61F1142A1FE04F7290D7749E9096D4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegCloseKey.ADVAPI32(00000000,00000000,00B10348,InstallerVersion,InstallerVersion,00000000,00B10348,InstallerName,InstallerName,00000000,00B10348,Date,InstalledDate,00000000,00B10348,LogonUser), ref: 00B0F5BE
                                        • Part of subcall function 00B41392: RegSetValueExW.ADVAPI32(00020006,00020006,00000000,00000001,?,00000000,?,000000FF,00000000,00000000,?,?,00B0F1C2,00000000,?,00020006), ref: 00B413C5
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseValue
                                      • String ID: Date$Failed to create the key for update registration.$Failed to get the formatted key path for update registration.$Failed to write %ls value.$InstalledBy$InstalledDate$InstallerName$InstallerVersion$LogonUser$PackageName$PackageVersion$Publisher$PublishingGroup$ReleaseType$ThisVersionInstalled
                                      • API String ID: 3132538880-2703781546
                                      • Opcode ID: 8c00651054c1789c5d59426e7572e0544e8dc5197ad9240a8a850864ae4808ab
                                      • Instruction ID: 8e234c5d162646b1c187bcc9143c14decc235c5a1f9b1b12ca3aa606b7f5efd0
                                      • Opcode Fuzzy Hash: 8c00651054c1789c5d59426e7572e0544e8dc5197ad9240a8a850864ae4808ab
                                      • Instruction Fuzzy Hash: E8418032B42626BBCF326A54DC02F7E7EE5AB11B21F1441F1BD00B66E1D7609F14A680
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • TlsSetValue.KERNEL32(?,?), ref: 00B1E5AE
                                      • RegisterClassW.USER32(?), ref: 00B1E5DA
                                      • GetLastError.KERNEL32 ref: 00B1E5E5
                                      • CreateWindowExW.USER32(00000080,00B59CC4,00000000,90000000,80000000,00000008,00000000,00000000,00000000,00000000,?,?), ref: 00B1E64C
                                      • GetLastError.KERNEL32 ref: 00B1E656
                                      • UnregisterClassW.USER32(WixBurnMessageWindow,?), ref: 00B1E6F4
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ClassErrorLast$CreateRegisterUnregisterValueWindow
                                      • String ID: Failed to create window.$Failed to register window.$Unexpected return value from message pump.$WixBurnMessageWindow$uithread.cpp
                                      • API String ID: 213125376-288575659
                                      • Opcode ID: aba91e1c982ce21418c28e070e2fbcca956117be2496830702c662340afba9ba
                                      • Instruction ID: cadebbdb69e550e6d99f88162e4eea03fc6327caf8b7e4897d1157d0b88d2bf3
                                      • Opcode Fuzzy Hash: aba91e1c982ce21418c28e070e2fbcca956117be2496830702c662340afba9ba
                                      • Instruction Fuzzy Hash: 2A418D76A00214EBDB209BA59C44EDABEE8FF19750F5041A6FE19E7190DB30DA40CBA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      • Failed to copy key for passthrough pseudo bundle payload., xrefs: 00B2C768
                                      • Failed to copy uninstall arguments for passthrough bundle package, xrefs: 00B2C84F
                                      • Failed to copy filename for passthrough pseudo bundle., xrefs: 00B2C761
                                      • Failed to copy key for passthrough pseudo bundle., xrefs: 00B2C72B
                                      • Failed to copy local source path for passthrough pseudo bundle., xrefs: 00B2C75A
                                      • Failed to recreate command-line arguments., xrefs: 00B2C7E6
                                      • Failed to allocate memory for pseudo bundle payload hash., xrefs: 00B2C750
                                      • Failed to copy install arguments for passthrough bundle package, xrefs: 00B2C805
                                      • Failed to copy download source for passthrough pseudo bundle., xrefs: 00B2C732
                                      • Failed to allocate space for burn package payload inside of passthrough bundle., xrefs: 00B2C557
                                      • pseudobundle.cpp, xrefs: 00B2C54B, 00B2C744, 00B2C77E
                                      • Failed to copy cache id for passthrough pseudo bundle., xrefs: 00B2C7A8
                                      • Failed to allocate space for burn payload inside of related bundle struct, xrefs: 00B2C78A
                                      • Failed to copy related arguments for passthrough bundle package, xrefs: 00B2C825
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateProcess
                                      • String ID: Failed to allocate memory for pseudo bundle payload hash.$Failed to allocate space for burn package payload inside of passthrough bundle.$Failed to allocate space for burn payload inside of related bundle struct$Failed to copy cache id for passthrough pseudo bundle.$Failed to copy download source for passthrough pseudo bundle.$Failed to copy filename for passthrough pseudo bundle.$Failed to copy install arguments for passthrough bundle package$Failed to copy key for passthrough pseudo bundle payload.$Failed to copy key for passthrough pseudo bundle.$Failed to copy local source path for passthrough pseudo bundle.$Failed to copy related arguments for passthrough bundle package$Failed to copy uninstall arguments for passthrough bundle package$Failed to recreate command-line arguments.$pseudobundle.cpp
                                      • API String ID: 1357844191-115096447
                                      • Opcode ID: be9b836bca8d340f7e1a02aabb45ef97dd57c08fd6d249a9435398a6f5be7a56
                                      • Instruction ID: e29b4c26a47565cf0c018871e992ad1039eaa411a997fc32746de9975c5a76bd
                                      • Opcode Fuzzy Hash: be9b836bca8d340f7e1a02aabb45ef97dd57c08fd6d249a9435398a6f5be7a56
                                      • Instruction Fuzzy Hash: 60B11675A00626AFDB11DF68D881F5ABBE5BF08B10F1181E9ED18AB361C731EC51DB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B0BB82
                                      • CreateProcessW.KERNEL32(?,?,00000000,00000000,00000000,00000200,00000000,?,00000044,?,?,?,?,?), ref: 00B0BC8F
                                      • GetLastError.KERNEL32(?,?,?,?), ref: 00B0BC99
                                      • WaitForInputIdle.USER32(?,?), ref: 00B0BCED
                                      • CloseHandle.KERNEL32(?,?,?), ref: 00B0BD38
                                      • CloseHandle.KERNEL32(?,?,?), ref: 00B0BD45
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseHandle$CreateErrorIdleInputLastOpen@16ProcessWait
                                      • String ID: "%ls"$"%ls" %s$D$Failed to CreateProcess on path: %ls$Failed to create executable command.$Failed to create obfuscated executable command.$Failed to format argument string.$Failed to format obfuscated argument string.$approvedexe.cpp
                                      • API String ID: 155678114-2737401750
                                      • Opcode ID: 0e40ce68e9a762c115a88d2d95f091265b32f252f692703aa7cd9d65855511bf
                                      • Instruction ID: cce7aaf55b07ef7402eef8ef334924538fe75de08e0096c554f5038fca961b79
                                      • Opcode Fuzzy Hash: 0e40ce68e9a762c115a88d2d95f091265b32f252f692703aa7cd9d65855511bf
                                      • Instruction Fuzzy Hash: 39514F72D0061ABBDF119F95CD41DAEBBF9FF04700F1045A5FA04B61A1DB319E50AB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • OpenSCManagerW.ADVAPI32(00000000,00000000,000F003F,?,?,00000000,?,?,?,?,?,?,?,?,00B26CE1,?), ref: 00B267C8
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00B26CE1,?,?,?), ref: 00B267D5
                                      • OpenServiceW.ADVAPI32(00000000,wuauserv,00000027,?,?,?,?,?,?,?,?,00B26CE1,?,?,?), ref: 00B2681D
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00B26CE1,?,?,?), ref: 00B26829
                                      • QueryServiceStatus.ADVAPI32(00000000,?,?,?,?,?,?,?,?,?,00B26CE1,?,?,?), ref: 00B26863
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00B26CE1,?,?,?), ref: 00B2686D
                                      • CloseServiceHandle.ADVAPI32(00000000), ref: 00B26924
                                      • CloseServiceHandle.ADVAPI32(?), ref: 00B2692E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Service$ErrorLast$CloseHandleOpen$ManagerQueryStatus
                                      • String ID: Failed to mark WU service to start on demand.$Failed to open WU service.$Failed to open service control manager.$Failed to query status of WU service.$Failed to read configuration for WU service.$msuuser.cpp$wuauserv
                                      • API String ID: 971853308-301359130
                                      • Opcode ID: 8f601d5056789b24b0bc481d346c239eab9dc7d6295a98ed2dcd00a7a2507c68
                                      • Instruction ID: 4cebfc842a23eeb40cac36324f461e8d7f96b7a366bec8ddfa9682834574f313
                                      • Opcode Fuzzy Hash: 8f601d5056789b24b0bc481d346c239eab9dc7d6295a98ed2dcd00a7a2507c68
                                      • Instruction Fuzzy Hash: C341C671F00334ABEB209BB99C85BAE77E8EB48711F0141A6FD09FB250DB30DD4486A0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleHandleW.KERNEL32(00000000,00000000,00000000,?,00B0B9F7,00000008,?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B10E
                                      • GetLastError.KERNEL32(?,00B0B9F7,00000008,?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B0B11A
                                      • _memcmp.LIBVCRUNTIME ref: 00B0B1C2
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorHandleLastModule_memcmp
                                      • String ID: .wix$.wixburn$Bundle guid didn't match the guid in the PE Header in memory.$Failed to find Burn section.$Failed to find valid DOS image header in buffer.$Failed to find valid NT image header in buffer.$Failed to get module handle to process.$Failed to read section info, data to short: %u$Failed to read section info, unsupported version: %08x$burn$section.cpp
                                      • API String ID: 3888311042-926796631
                                      • Opcode ID: 22bc02aae0b3283fa70662bae8ee7fa6ae1b0a82b79bc3b57e7c445d1b0dbfbe
                                      • Instruction ID: feae81f706cedbfb15e218cf7f92f1a7509f49a5105ef5061254f064852d3295
                                      • Opcode Fuzzy Hash: 22bc02aae0b3283fa70662bae8ee7fa6ae1b0a82b79bc3b57e7c445d1b0dbfbe
                                      • Instruction Fuzzy Hash: F2412476381310B7D7206A51DC82E2B2EE5FB80B21F2540F9F9026F6D1DB74CE01A3A6
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetTempPathW.KERNEL32(00000104,?,?,00000000,crypt32.dll), ref: 00B13A51
                                      • GetLastError.KERNEL32(?,00000000,crypt32.dll), ref: 00B13A5B
                                      • GetCurrentProcessId.KERNEL32(?,?,?,00000104,?,?,00000000,crypt32.dll), ref: 00B13AC4
                                      • ProcessIdToSessionId.KERNEL32(00000000,?,00000000,crypt32.dll), ref: 00B13ACB
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Process$CurrentErrorLastPathSessionTemp
                                      • String ID: 4#v$%u\$Failed to copy temp folder.$Failed to format session id as a string.$Failed to get length of session id string.$Failed to get length of temp folder.$Failed to get temp folder.$crypt32.dll$logging.cpp
                                      • API String ID: 1726527325-4287186919
                                      • Opcode ID: 0b59a7b71beadd927f09a4071473c2cf54102d80283551af7dee5b8c388f66d7
                                      • Instruction ID: 6f1ea8ca9448da3bba76fdaad899b5487d899985368bd717697b92404cbb92a7
                                      • Opcode Fuzzy Hash: 0b59a7b71beadd927f09a4071473c2cf54102d80283551af7dee5b8c388f66d7
                                      • Instruction Fuzzy Hash: 8E41937698023DABDB209A649C49FDA77F8EB14B10F1001D5FD08B7291EA709F848B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      • UX aborted plan related bundle., xrefs: 00B13127
                                      • Failed to create string array from ancestors., xrefs: 00B12E1A
                                      • feclient.dll, xrefs: 00B130BB
                                      • Failed to copy ancestors and self to related bundle ancestors., xrefs: 00B12EF6
                                      • Unexpected relation type encountered during plan: %d, xrefs: 00B130FE
                                      • crypt32.dll, xrefs: 00B12E0E
                                      • Failed to lookup the bundle ID in the ancestors dictionary., xrefs: 00B130F0
                                      • Failed to create dictionary from ancestors array., xrefs: 00B12E46
                                      • %ls;%ls, xrefs: 00B12EDE
                                      • plan.cpp, xrefs: 00B1311D
                                      • Failed to copy self to related bundle ancestors., xrefs: 00B1312E
                                      • Failed to add the package provider key "%ls" to the planned list., xrefs: 00B13107
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID: %ls;%ls$Failed to add the package provider key "%ls" to the planned list.$Failed to copy ancestors and self to related bundle ancestors.$Failed to copy self to related bundle ancestors.$Failed to create dictionary from ancestors array.$Failed to create string array from ancestors.$Failed to lookup the bundle ID in the ancestors dictionary.$UX aborted plan related bundle.$Unexpected relation type encountered during plan: %d$crypt32.dll$feclient.dll$plan.cpp
                                      • API String ID: 0-794096528
                                      • Opcode ID: 2d2159650f0e33f842d91a425590a6b0848cf8353025f1f9d1d8cf88c6ecc5d6
                                      • Instruction ID: 0617613f293711bcf2af05f0e8183c8a937844fc9fac88d4b910d2ce92cb25ed
                                      • Opcode Fuzzy Hash: 2d2159650f0e33f842d91a425590a6b0848cf8353025f1f9d1d8cf88c6ecc5d6
                                      • Instruction Fuzzy Hash: 27B1AF31900616EFDB15DF64C885BEABBF5FF09710F9045E5E804AB251E7319AE1CB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B0A1A8
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B0A204
                                      • RegQueryValueExW.ADVAPI32(000002C0,00000000,00000000,000002C0,00000000,00000000,000002C0,?,00000000,00000000,?,00000000,00000101,000002C0,000002C0,?), ref: 00B0A226
                                      • RegCloseKey.ADVAPI32(00000000,00000000,00000000,000002C0,00000100,00000000,000002C0), ref: 00B0A300
                                      Strings
                                      • Registry key not found. Key = '%ls', xrefs: 00B0A291
                                      • Registry value not found. Key = '%ls', Value = '%ls', xrefs: 00B0A275
                                      • Failed to query registry key value., xrefs: 00B0A265
                                      • Failed to set variable., xrefs: 00B0A2B8
                                      • search.cpp, xrefs: 00B0A25B
                                      • Failed to format value string., xrefs: 00B0A20F
                                      • Failed to format key string., xrefs: 00B0A1B3
                                      • Failed to open registry key. Key = '%ls', xrefs: 00B0A2C2
                                      • RegistrySearchExists failed: ID '%ls', HRESULT 0x%x, xrefs: 00B0A2D8
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open@16$CloseQueryValue
                                      • String ID: Failed to format key string.$Failed to format value string.$Failed to open registry key. Key = '%ls'$Failed to query registry key value.$Failed to set variable.$Registry key not found. Key = '%ls'$Registry value not found. Key = '%ls', Value = '%ls'$RegistrySearchExists failed: ID '%ls', HRESULT 0x%x$search.cpp
                                      • API String ID: 2702208347-46557908
                                      • Opcode ID: 929a6725fef3c1b2764843e120d998003bb2013dae9c7fb36184c43c6d2465b1
                                      • Instruction ID: 7b8cfd1edce5785ca2457eaf7135df533fa54e1b0e7999e588b0f12541a0da73
                                      • Opcode Fuzzy Hash: 929a6725fef3c1b2764843e120d998003bb2013dae9c7fb36184c43c6d2465b1
                                      • Instruction Fuzzy Hash: A041B372E40314BBDF116A94CC46FAEBFE9EB04700F1045E5FD04BA2E1D6728E10A692
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleHandleExW.KERNEL32(00000000,ntdll,?), ref: 00B06835
                                      • GetLastError.KERNEL32 ref: 00B0683F
                                      • GetProcAddress.KERNEL32(?,RtlGetVersion), ref: 00B06882
                                      • GetLastError.KERNEL32 ref: 00B0688C
                                      • FreeLibrary.KERNEL32(00000000,00000000,?), ref: 00B0699D
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$AddressFreeHandleLibraryModuleProc
                                      • String ID: Failed to get OS info.$Failed to locate NTDLL.$Failed to locate RtlGetVersion.$Failed to set variant value.$RtlGetVersion$ntdll$variable.cpp
                                      • API String ID: 3057421322-109962352
                                      • Opcode ID: b74ac695cfac3e1ae676ab2d7bf57bfc8cea9076702c46ab6196e4bad2bfac64
                                      • Instruction ID: cbf58611150a60240090351712675c307e86bf91dc77e4c1c67548e931d7f802
                                      • Opcode Fuzzy Hash: b74ac695cfac3e1ae676ab2d7bf57bfc8cea9076702c46ab6196e4bad2bfac64
                                      • Instruction Fuzzy Hash: 20419275A01238ABDB319B659C45BEABBF4FB08750F0001D9F948F61D0DB748FA4DA91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • TlsAlloc.KERNEL32(?,00000001,00000001,00000000,00000000,?,?,?,00B0535E,?,?,?,?), ref: 00B0481A
                                      • GetLastError.KERNEL32(?,?,?,00B0535E,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00B0482B
                                      • ReleaseMutex.KERNEL32(?,?,00000000,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,?), ref: 00B04968
                                      • CloseHandle.KERNEL32(?,?,?,?,00B0535E,?,?,?,?,?,?,?,?,?,?,?), ref: 00B04971
                                      Strings
                                      • Failed to allocate thread local storage for logging., xrefs: 00B04859
                                      • Failed to connect to unelevated process., xrefs: 00B04810
                                      • Failed to set elevated pipe into thread local storage for logging., xrefs: 00B048A2
                                      • comres.dll, xrefs: 00B048D7
                                      • user.cpp, xrefs: 00B0484F, 00B04898
                                      • Failed to create the message window., xrefs: 00B048C6
                                      • Failed to pump messages from parent process., xrefs: 00B0493C
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AllocCloseErrorHandleLastMutexRelease
                                      • String ID: Failed to allocate thread local storage for logging.$Failed to connect to unelevated process.$Failed to create the message window.$Failed to pump messages from parent process.$Failed to set elevated pipe into thread local storage for logging.$comres.dll$user.cpp
                                      • API String ID: 687263955-1790235126
                                      • Opcode ID: 6334ae02d0131ba4f35ed1ad046c7b5965dbc451a4c844c2fe91877cb48676d0
                                      • Instruction ID: bb90aa0eea859ad2f414ccef6f14fa3f45107457617d03107e7deabbc6bea84e
                                      • Opcode Fuzzy Hash: 6334ae02d0131ba4f35ed1ad046c7b5965dbc451a4c844c2fe91877cb48676d0
                                      • Instruction Fuzzy Hash: 014185B2A40615BEDB119BB4CC85EEBBAECFF45710F0006A6FB05E3190DB709A5096E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00000000,00000000,00000000,?,000000B9,00000002,?,00000000,00000000), ref: 00B07E99
                                      • LeaveCriticalSection.KERNEL32(?,?,?), ref: 00B080C1
                                      Strings
                                      • Failed to write variable count., xrefs: 00B07EB4
                                      • Failed to get numeric., xrefs: 00B08093
                                      • Failed to write variable name., xrefs: 00B080A8
                                      • feclient.dll, xrefs: 00B07F74, 00B07FCA, 00B0800B
                                      • Failed to write variable value as number., xrefs: 00B0806B
                                      • Failed to get version., xrefs: 00B08072
                                      • Failed to write variable value as string., xrefs: 00B08085
                                      • Failed to get string., xrefs: 00B0808C
                                      • Failed to write variable value type., xrefs: 00B080A1
                                      • Failed to write literal flag., xrefs: 00B0809A
                                      • Unsupported variable type., xrefs: 00B0807E
                                      • Failed to write included flag., xrefs: 00B080AF
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: Failed to get numeric.$Failed to get string.$Failed to get version.$Failed to write included flag.$Failed to write literal flag.$Failed to write variable count.$Failed to write variable name.$Failed to write variable value as number.$Failed to write variable value as string.$Failed to write variable value type.$Unsupported variable type.$feclient.dll
                                      • API String ID: 3168844106-2118673349
                                      • Opcode ID: 4dc5e9812c22ca7b9cdddafbd4df357eeecf587dc483998a535b688a69c1ce63
                                      • Instruction ID: 637e12a4cce66e63f52253cf415380a3eb526120f351a5ebd66343ef6d52be0a
                                      • Opcode Fuzzy Hash: 4dc5e9812c22ca7b9cdddafbd4df357eeecf587dc483998a535b688a69c1ce63
                                      • Instruction Fuzzy Hash: B8619232D0161AEBCF229E64C851AAEBFE9FB04750F1081D1F940672A1DF31DF589B91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNEL32(?,80000000,00000005,00000000,00000003,08000000,00000000,?,00000000,?,00B1A63D,?,00000000,?,?,00B2B049), ref: 00B195C7
                                      • GetLastError.KERNEL32(?,00B1A63D,?,00000000,?,?,00B2B049,?,00000000,?,00000000,?,?,00B2B049,?), ref: 00B195D7
                                      • CloseHandle.KERNEL32(?,00B2B049,00000001,00000003,000007D0,?,?,00B2B049,?), ref: 00B196E4
                                      Strings
                                      • %ls payload from working path '%ls' to path '%ls', xrefs: 00B1968F
                                      • Failed to verify payload signature: %ls, xrefs: 00B19632
                                      • Copying, xrefs: 00B19679
                                      • Moving, xrefs: 00B19686, 00B1968E
                                      • Failed to verify payload hash: %ls, xrefs: 00B1966F
                                      • Failed to move %ls to %ls, xrefs: 00B196BC
                                      • Failed to open payload in working path: %ls, xrefs: 00B19606
                                      • cache.cpp, xrefs: 00B195FB
                                      • Failed to copy %ls to %ls, xrefs: 00B196D2
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateErrorFileHandleLast
                                      • String ID: %ls payload from working path '%ls' to path '%ls'$Copying$Failed to copy %ls to %ls$Failed to move %ls to %ls$Failed to open payload in working path: %ls$Failed to verify payload hash: %ls$Failed to verify payload signature: %ls$Moving$cache.cpp
                                      • API String ID: 2528220319-1604654059
                                      • Opcode ID: 7298276e7ec0fc85d73b9b5d582a935b58faff405dbc4751f00fb20344a45507
                                      • Instruction ID: 3a62009ad0352c7b25d6044973762e1f9780dd73749d247237427e5edf764b96
                                      • Opcode Fuzzy Hash: 7298276e7ec0fc85d73b9b5d582a935b58faff405dbc4751f00fb20344a45507
                                      • Instruction Fuzzy Hash: CC315871A806647BEB212A259C56FAB3ADCDF42F51F4101E9FD04BB290DA609E4095F1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B13955: RegCloseKey.ADVAPI32(00000000,SOFTWARE\Policies\Microsoft\Windows\Installer,00020019,00000001,feclient.dll,?,?,?,00B13E61,feclient.dll,?,00000000,?,?,?,00B04A0C), ref: 00B139F1
                                      • Sleep.KERNEL32(000007D0,00000001,feclient.dll,?,00000000,?,?,?,00B04A0C,?,?,00B4B478,?,00000001,00000000,00000000), ref: 00B13EF8
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseSleep
                                      • String ID: Failed to copy full log path to prefix.$Failed to copy log extension to extension.$Failed to copy log path to prefix.$Failed to get current directory.$Failed to get non-session specific TEMP folder.$Failed to open log: %ls$Setup$clbcatq.dll$crypt32.dll$feclient.dll$log$msasn1.dll
                                      • API String ID: 2834455192-2673269691
                                      • Opcode ID: 51fe74feab666970475540d3e9805f7f2f5684d27d123a875bc2d1ea7546b688
                                      • Instruction ID: 613dafd6b17e12600127c8c8f5baf67814c39d15a418b8d0fa1bbfd0db3aadde
                                      • Opcode Fuzzy Hash: 51fe74feab666970475540d3e9805f7f2f5684d27d123a875bc2d1ea7546b688
                                      • Instruction Fuzzy Hash: A961E471A00215BBDF219F64CC46BAA7BE8EF04B40B4441E9F905DB251F771EED097A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00000001,?,00000000,00B0533D,00000000,00000001), ref: 00B06C6E
                                        • Part of subcall function 00B055B6: CompareStringW.KERNELBASE(0000007F,00001000,?,000000FF,version.dll,000000FF,?,00000000,00000007,00B0648B,00B0648B,?,00B0554A,?,?,00000000), ref: 00B055F2
                                        • Part of subcall function 00B055B6: GetLastError.KERNEL32(?,00B0554A,?,?,00000000,?,00000000,00B0648B,?,00B07DDC,?,?,?,?,?), ref: 00B05621
                                      • LeaveCriticalSection.KERNEL32(00000001,?,00000001), ref: 00B06E02
                                      Strings
                                      • Failed to find variable value '%ls'., xrefs: 00B06C89
                                      • Setting version variable '%ls' to value '%hu.%hu.%hu.%hu', xrefs: 00B06D79
                                      • Unsetting variable '%ls', xrefs: 00B06DBE
                                      • Failed to insert variable '%ls'., xrefs: 00B06CB3
                                      • Setting hidden variable '%ls', xrefs: 00B06D2C
                                      • Failed to set value of variable: %ls, xrefs: 00B06DEA
                                      • Attempt to set built-in variable value: %ls, xrefs: 00B06CFC
                                      • Setting variable failed: ID '%ls', HRESULT 0x%x, xrefs: 00B06E14
                                      • Setting numeric variable '%ls' to value %lld, xrefs: 00B06DA3
                                      • Setting string variable '%ls' to value '%ls', xrefs: 00B06D96
                                      • variable.cpp, xrefs: 00B06CF1
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$CompareEnterErrorLastLeaveString
                                      • String ID: Attempt to set built-in variable value: %ls$Failed to find variable value '%ls'.$Failed to insert variable '%ls'.$Failed to set value of variable: %ls$Setting hidden variable '%ls'$Setting numeric variable '%ls' to value %lld$Setting string variable '%ls' to value '%ls'$Setting variable failed: ID '%ls', HRESULT 0x%x$Setting version variable '%ls' to value '%hu.%hu.%hu.%hu'$Unsetting variable '%ls'$variable.cpp
                                      • API String ID: 2716280545-445000439
                                      • Opcode ID: dac3176571ac12c7868018fd24862b608f873c8b2e8f5361cf6ba00690c7223a
                                      • Instruction ID: 5c529342bf8798b8e747b1603fbaf05407d3361c36a393c5cc5ec731c9ca3d63
                                      • Opcode Fuzzy Hash: dac3176571ac12c7868018fd24862b608f873c8b2e8f5361cf6ba00690c7223a
                                      • Instruction Fuzzy Hash: 8A51F771B00215A7DB309E14CD8AF6B3FE9EB95B10F1102E9F8455A2C2D274DE70DAE1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(00000000,00000001,006C0064,000000FF,002C002B,000000FF,?,00000000,?,wininet.dll,?,crypt32.dll,?,?,?,00000000), ref: 00B12ACD
                                      Strings
                                      • Failed to add registration action for dependent related bundle., xrefs: 00B12DD5
                                      • Failed to add self-dependent to ignore dependents., xrefs: 00B12B51
                                      • wininet.dll, xrefs: 00B12D1E
                                      • Failed to add registration action for self dependent., xrefs: 00B12D9E
                                      • Failed to add dependent bundle provider key to ignore dependents., xrefs: 00B12C37
                                      • Failed to check for remaining dependents during planning., xrefs: 00B12C73
                                      • crypt32.dll, xrefs: 00B12B18, 00B12C16, 00B12D0B, 00B12D80
                                      • Failed to create the string dictionary., xrefs: 00B12B06
                                      • Failed to add dependents ignored from command-line., xrefs: 00B12B82
                                      • Failed to allocate registration action., xrefs: 00B12B36
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareString
                                      • String ID: Failed to add dependent bundle provider key to ignore dependents.$Failed to add dependents ignored from command-line.$Failed to add registration action for dependent related bundle.$Failed to add registration action for self dependent.$Failed to add self-dependent to ignore dependents.$Failed to allocate registration action.$Failed to check for remaining dependents during planning.$Failed to create the string dictionary.$crypt32.dll$wininet.dll
                                      • API String ID: 1825529933-1705955799
                                      • Opcode ID: 11e7f0ce5df117706e5aa5966e82dfc4fd09cd0db5bbd3948d54c3c778d29dea
                                      • Instruction ID: fc2057031aad37a8f266c258c1f408176795095bc158aaac42b5ce8ff9471065
                                      • Opcode Fuzzy Hash: 11e7f0ce5df117706e5aa5966e82dfc4fd09cd0db5bbd3948d54c3c778d29dea
                                      • Instruction Fuzzy Hash: 85B17A70A00626EFDF259F64D881BEE7BE5FF44310F5081A9F904AA261D770DAA0DBD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • IsWindow.USER32(?), ref: 00B04B5E
                                      • PostMessageW.USER32(?,00000010,00000000,00000000), ref: 00B04B6F
                                      Strings
                                      • Failed while running , xrefs: 00B04B24
                                      • Failed to set layout directory variable to value provided from command-line., xrefs: 00B04B00
                                      • Failed to create the message window., xrefs: 00B04A92
                                      • WixBundleLayoutDirectory, xrefs: 00B04AEF
                                      • Failed to check global conditions, xrefs: 00B04A43
                                      • Failed to open log., xrefs: 00B04A12
                                      • Failed to set action variables., xrefs: 00B04ABE
                                      • Failed to query registration., xrefs: 00B04AA8
                                      • Failed to set registration variables., xrefs: 00B04AD8
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: MessagePostWindow
                                      • String ID: Failed to check global conditions$Failed to create the message window.$Failed to open log.$Failed to query registration.$Failed to set action variables.$Failed to set layout directory variable to value provided from command-line.$Failed to set registration variables.$Failed while running $WixBundleLayoutDirectory
                                      • API String ID: 3618638489-3051724725
                                      • Opcode ID: fcdd05458930b30bd1874d04235a3c00c88fdb3ef0e49502b11281ec49997ec4
                                      • Instruction ID: 354be46a1193aa0e5eedd348c60e662c6e5e712434f564f7f04ea804cf40ae0c
                                      • Opcode Fuzzy Hash: fcdd05458930b30bd1874d04235a3c00c88fdb3ef0e49502b11281ec49997ec4
                                      • Instruction Fuzzy Hash: 9A41C8B1B4061ABBDB265A64CC85FB7BEECFF00750F0042E5BA04A65D1DB60EE5097D0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • EnterCriticalSection.KERNEL32(?,00000014,00000001), ref: 00B1EE1B
                                      • LeaveCriticalSection.KERNEL32(?), ref: 00B1EF48
                                      Strings
                                      • user is active, cannot change user state., xrefs: 00B1EE36
                                      • userForApplication.cpp, xrefs: 00B1EF29
                                      • Failed to copy the id., xrefs: 00B1EEAD
                                      • UX requested unknown approved exe with id: %ls, xrefs: 00B1EE7B
                                      • Failed to post launch approved exe message., xrefs: 00B1EF33
                                      • Failed to copy the arguments., xrefs: 00B1EEDA
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalHeapSection$AllocateEnterLeaveProcess
                                      • String ID: user is active, cannot change user state.$userForApplication.cpp$Failed to copy the arguments.$Failed to copy the id.$Failed to post launch approved exe message.$UX requested unknown approved exe with id: %ls
                                      • API String ID: 1367039788-528931743
                                      • Opcode ID: 19ba6c8fa75dd8c3937d5ab8cd3d839654edd4b2071ddfe379d57c833ece89d5
                                      • Instruction ID: 1143472389537760d449fff4639daaa52c527238b125fc65b3bd4a1626ce5c4e
                                      • Opcode Fuzzy Hash: 19ba6c8fa75dd8c3937d5ab8cd3d839654edd4b2071ddfe379d57c833ece89d5
                                      • Instruction Fuzzy Hash: 6D31C336A50225ABEB119F24DC45EAB7BE8EF04B20B0581E5FE14EB291DB30DD40D7A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNEL32(?,80000000,00000005,00000000,00000003,08000000,00000000,?,00000000,?,00B1A5CE,?,00000000,?,?,00B2B041), ref: 00B194B1
                                      • GetLastError.KERNEL32(?,00B1A5CE,?,00000000,?,?,00B2B041,?,00000000,?,00000000,?,?,00B2B041,?), ref: 00B194BF
                                      • CloseHandle.KERNEL32(?,00B2B041,00000001,00000003,000007D0,?,?,00B2B041,?), ref: 00B1959E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateErrorFileHandleLast
                                      • String ID: %ls container from working path '%ls' to path '%ls'$Copying$Failed to copy %ls to %ls$Failed to move %ls to %ls$Failed to open container in working path: %ls$Failed to verify container hash: %ls$Moving$cache.cpp
                                      • API String ID: 2528220319-1187406825
                                      • Opcode ID: 950180ef70cc139fd9881f4b51cff58ed47f0e61b391647d0f7c048ac092d7fc
                                      • Instruction ID: 38b6349ff879e3d33a66835304f81e557d80a32c1373c5414029ba63622c7fcd
                                      • Opcode Fuzzy Hash: 950180ef70cc139fd9881f4b51cff58ed47f0e61b391647d0f7c048ac092d7fc
                                      • Instruction Fuzzy Hash: 66215A72B807643BEB2229245C46FAB36DDDF61F11F4001D8FE05BB2D0DAA19E4091E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00000000,?,00000000,?,00000000,?,?,?,00000000,?,?,?,?,?,?,00000000), ref: 00B06E89
                                      • LeaveCriticalSection.KERNEL32(?), ref: 00B07095
                                      Strings
                                      • Failed to read variable value as string., xrefs: 00B07062
                                      • Failed to read variable value type., xrefs: 00B07077
                                      • Failed to read variable included flag., xrefs: 00B07085
                                      • Failed to set variable., xrefs: 00B07069
                                      • Failed to read variable value as number., xrefs: 00B0704F
                                      • Failed to read variable literal flag., xrefs: 00B07070
                                      • Failed to read variable count., xrefs: 00B06EA9
                                      • Unsupported variable type., xrefs: 00B0705B
                                      • Failed to read variable name., xrefs: 00B0707E
                                      • Failed to set variable value., xrefs: 00B07048
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: Failed to read variable count.$Failed to read variable included flag.$Failed to read variable literal flag.$Failed to read variable name.$Failed to read variable value as number.$Failed to read variable value as string.$Failed to read variable value type.$Failed to set variable value.$Failed to set variable.$Unsupported variable type.
                                      • API String ID: 3168844106-528957463
                                      • Opcode ID: 5f959b340cf2cc634c96a834a9aebd576393c3db2c37ff8a1445ec3bbdb2329f
                                      • Instruction ID: 78fc2203f51d2d073e4ef6e9f21331af3d833c4da1b1936499f6e1c2a7918478
                                      • Opcode Fuzzy Hash: 5f959b340cf2cc634c96a834a9aebd576393c3db2c37ff8a1445ec3bbdb2329f
                                      • Instruction Fuzzy Hash: CB716271D4521AABDF11DE94DC45EAEBFF9EB04710F1082E2F910A6190EA31EE159B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNEL32(00000000,80000000,00000005,00000000,00000003,08000080,00000000,?,?,00000000,?,00000000,?,?,?), ref: 00B44425
                                      • GetLastError.KERNEL32 ref: 00B4443B
                                      • GetFileSizeEx.KERNEL32(00000000,?), ref: 00B44486
                                      • GetLastError.KERNEL32 ref: 00B44490
                                      • CloseHandle.KERNEL32(?), ref: 00B44650
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLast$CloseCreateHandleSize
                                      • String ID: fileutil.cpp
                                      • API String ID: 3555958901-2967768451
                                      • Opcode ID: 2fe078cb0d56b54fcc42be486d5282ce4b3888107477680a9987b3f8c560a089
                                      • Instruction ID: 8d9bdb5060c5600fa01f6c7497624c12a797872d5a6f8eeaa52bcd941b13baa1
                                      • Opcode Fuzzy Hash: 2fe078cb0d56b54fcc42be486d5282ce4b3888107477680a9987b3f8c560a089
                                      • Instruction Fuzzy Hash: A971F771A00215EBEF219E698C84F7B76E8EF40760F1141A9FD15EB290DB74CF20A794
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetTempPathW.KERNEL32(00000104,?,00000001,00000000,00000000), ref: 00B02E7A
                                      • GetLastError.KERNEL32 ref: 00B02E84
                                      • GetLocalTime.KERNEL32(?,?,?,?,?,?), ref: 00B02F1F
                                      • CreateFileW.KERNEL32(?,40000000,00000001,00000000,00000001,00000080,00000000), ref: 00B02FAD
                                      • GetLastError.KERNEL32 ref: 00B02FBA
                                      • Sleep.KERNEL32(00000064), ref: 00B02FCC
                                      • CloseHandle.KERNEL32(?), ref: 00B0302C
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CloseCreateFileHandleLocalPathSleepTempTime
                                      • String ID: 4#v$%ls_%04u%02u%02u%02u%02u%02u%ls%ls%ls$pathutil.cpp
                                      • API String ID: 3480017824-1777530710
                                      • Opcode ID: 14a4acd6c4d6c15f1c7cabc08bb61664f3480cb6adf46f65cd5859ebfe725d3d
                                      • Instruction ID: 8af5a7a483ac8b4094ecbb828dd9e0d3f776689053d89185ca08639eae00fa6e
                                      • Opcode Fuzzy Hash: 14a4acd6c4d6c15f1c7cabc08bb61664f3480cb6adf46f65cd5859ebfe725d3d
                                      • Instruction Fuzzy Hash: E7715376941229ABDB309BA4DC4CBAAB6FDEB08750F0001D5FA05E71D0E774DE849F60
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • UuidCreate.RPCRT4(?), ref: 00B14BC9
                                      • StringFromGUID2.OLE32(?,?,00000027), ref: 00B14BF8
                                      • UuidCreate.RPCRT4(?), ref: 00B14C43
                                      • StringFromGUID2.OLE32(?,?,00000027), ref: 00B14C6F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateFromStringUuid
                                      • String ID: BurnPipe.%s$Failed to allocate pipe name.$Failed to allocate pipe secret.$Failed to convert pipe guid into string.$Failed to create pipe guid.$pipe.cpp
                                      • API String ID: 4041566446-2510341293
                                      • Opcode ID: fcfb1c9b882652c950220ace45032f89e2900238472c11a289db790ea6a542e9
                                      • Instruction ID: 935fd3eb93db1c4a498fa7d028a5812276f3d2044a1c7baaf20497cf68a8a890
                                      • Opcode Fuzzy Hash: fcfb1c9b882652c950220ace45032f89e2900238472c11a289db790ea6a542e9
                                      • Instruction Fuzzy Hash: 9941BF72D05308ABDB10DBE4C945FDEBBF8EB44711F6041A6E905FB250DB749A88CB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetSystemTime.KERNEL32(?), ref: 00B05F3F
                                      • GetDateFormatW.KERNEL32(00000400,00000001,?,00000000,00000000,00000000), ref: 00B05F53
                                      • GetLastError.KERNEL32 ref: 00B05F65
                                      • GetDateFormatW.KERNEL32(00000400,00000001,?,00000000,?,00000000,?,00000000), ref: 00B05FB8
                                      • GetLastError.KERNEL32 ref: 00B05FC2
                                      Strings
                                      • Failed to set variant value., xrefs: 00B05FFF
                                      • Failed to get the Date., xrefs: 00B05FE6
                                      • Failed to get the required buffer length for the Date., xrefs: 00B05F89
                                      • variable.cpp, xrefs: 00B05F7F, 00B05FDC
                                      • Failed to allocate the buffer for the Date., xrefs: 00B05FA0
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: DateErrorFormatLast$SystemTime
                                      • String ID: Failed to allocate the buffer for the Date.$Failed to get the Date.$Failed to get the required buffer length for the Date.$Failed to set variant value.$variable.cpp
                                      • API String ID: 2700948981-3682088697
                                      • Opcode ID: f3d4a72cd1ca75de91b12060381972306b323bb289db793fb9b21fe543756ae9
                                      • Instruction ID: 3ff5c663b89e31022a68367deb90ef73cd81f0e554e364de29559baca8275b7e
                                      • Opcode Fuzzy Hash: f3d4a72cd1ca75de91b12060381972306b323bb289db793fb9b21fe543756ae9
                                      • Instruction Fuzzy Hash: 4331B975A406157BDB21AAA5DC85EAF7FE8EB04710F004065FB05F71D0EA70DE4096A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,00000000,?,?,00B05386,?,?), ref: 00B1E84A
                                      • GetLastError.KERNEL32(?,00B05386,?,?), ref: 00B1E857
                                      • CreateThread.KERNEL32(00000000,00000000,00B1E563,?,00000000,00000000), ref: 00B1E8B0
                                      • GetLastError.KERNEL32(?,00B05386,?,?), ref: 00B1E8BD
                                      • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF,?,00B05386,?,?), ref: 00B1E8F8
                                      • CloseHandle.KERNEL32(00000000,?,00B05386,?,?), ref: 00B1E917
                                      • CloseHandle.KERNEL32(?,?,00B05386,?,?), ref: 00B1E924
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateErrorHandleLast$EventMultipleObjectsThreadWait
                                      • String ID: Failed to create initialization event.$Failed to create the UI thread.$uithread.cpp
                                      • API String ID: 2351989216-3599963359
                                      • Opcode ID: 0ccd90ae65d066aa2953445891eec512af8aa1da3c79dbf88aab7a310516e633
                                      • Instruction ID: 581f2fc05425b22f826b21a21bbd2769dfa15910127443350d2f29a9cf1b286d
                                      • Opcode Fuzzy Hash: 0ccd90ae65d066aa2953445891eec512af8aa1da3c79dbf88aab7a310516e633
                                      • Instruction Fuzzy Hash: F2315475E00219BBEB109FA99D84AAFBAECFF08351F5141A6FD15F3250D6709E0086A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,00000000,00000000,?,?,00B05386,?,?), ref: 00B1E415
                                      • GetLastError.KERNEL32(?,?,00B05386,?,?), ref: 00B1E422
                                      • CreateThread.KERNEL32(00000000,00000000,00B1E177,00000000,00000000,00000000), ref: 00B1E481
                                      • GetLastError.KERNEL32(?,?,00B05386,?,?), ref: 00B1E48E
                                      • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF,?,?,00B05386,?,?), ref: 00B1E4C9
                                      • CloseHandle.KERNEL32(?,?,?,00B05386,?,?), ref: 00B1E4DD
                                      • CloseHandle.KERNEL32(?,?,?,00B05386,?,?), ref: 00B1E4EA
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateErrorHandleLast$EventMultipleObjectsThreadWait
                                      • String ID: Failed to create UI thread.$Failed to create modal event.$splashscreen.cpp
                                      • API String ID: 2351989216-1977201954
                                      • Opcode ID: c5ded4af1eee1305a219593912df4388ac7baf753f3fe1f3c07cfd020bdef518
                                      • Instruction ID: 7bab665a22548f26a91b30fbcc0ed32b2e53e411961f6716b16e64aa7b470e7c
                                      • Opcode Fuzzy Hash: c5ded4af1eee1305a219593912df4388ac7baf753f3fe1f3c07cfd020bdef518
                                      • Instruction Fuzzy Hash: 10318F75D00219BBEB109FA99C45EAFBBF8EF45711F1081AAFE14F3250D7748A40CAA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF,?,76232F60,?,?,00B052FD,00B052B5,00000000,00B0533D), ref: 00B21249
                                      • GetLastError.KERNEL32 ref: 00B2125C
                                      • GetExitCodeThread.KERNEL32(00B4B478,?), ref: 00B2129E
                                      • GetLastError.KERNEL32 ref: 00B212AC
                                      • ResetEvent.KERNEL32(00B4B450), ref: 00B212E7
                                      • GetLastError.KERNEL32 ref: 00B212F1
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CodeEventExitMultipleObjectsResetThreadWait
                                      • String ID: Failed to get extraction thread exit code.$Failed to reset operation complete event.$Failed to wait for operation complete event.$cabextract.cpp
                                      • API String ID: 2979751695-3400260300
                                      • Opcode ID: 19d8e6339a275a5ac5538ce22d9bbab21ddcefb910fd23d65164256e2bfacf0b
                                      • Instruction ID: 33e67069a7d20e656448ff442d404e1b2d64587c35531909e21dbc4492a904e3
                                      • Opcode Fuzzy Hash: 19d8e6339a275a5ac5538ce22d9bbab21ddcefb910fd23d65164256e2bfacf0b
                                      • Instruction Fuzzy Hash: 4A21D175600304BFEB149B399D45ABE7AF8EB04701F0041AEB94AE61E0E770CE009A55
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetEvent.KERNEL32(685479F6,00B0533D,00000000,?,00B0C06D,00B0533D,00B052B5,00000000,?,00B1763B,?,00B05565,00B05371,00B05371,00000000,?), ref: 00B2135E
                                      • GetLastError.KERNEL32(?,00B0C06D,00B0533D,00B052B5,00000000,?,00B1763B,?,00B05565,00B05371,00B05371,00000000,?,00B05381,FFF9E89D,00B05381), ref: 00B21368
                                      • WaitForSingleObject.KERNEL32(85F08BFF,000000FF,?,00B0C06D,00B0533D,00B052B5,00000000,?,00B1763B,?,00B05565,00B05371,00B05371,00000000,?,00B05381), ref: 00B213A2
                                      • GetLastError.KERNEL32(?,00B0C06D,00B0533D,00B052B5,00000000,?,00B1763B,?,00B05565,00B05371,00B05371,00000000,?,00B05381,FFF9E89D,00B05381), ref: 00B213AC
                                      • CloseHandle.KERNEL32(85F08BFF,00B05381,00B0533D,00000000,?,00B0C06D,00B0533D,00B052B5,00000000,?,00B1763B,?,00B05565,00B05371,00B05371,00000000), ref: 00B213F7
                                      • CloseHandle.KERNEL32(685479F6,00B05381,00B0533D,00000000,?,00B0C06D,00B0533D,00B052B5,00000000,?,00B1763B,?,00B05565,00B05371,00B05371,00000000), ref: 00B21406
                                      • CloseHandle.KERNEL32(00B4BA60,00B05381,00B0533D,00000000,?,00B0C06D,00B0533D,00B052B5,00000000,?,00B1763B,?,00B05565,00B05371,00B05371,00000000), ref: 00B21415
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseHandle$ErrorLast$EventObjectSingleWait
                                      • String ID: Failed to set begin operation event.$Failed to wait for thread to terminate.$cabextract.cpp
                                      • API String ID: 1206859064-226982402
                                      • Opcode ID: f538a6ec50b13a5a432438719ae0dd6bab246691b5c69cb740f5b57cdcac7e2e
                                      • Instruction ID: 8f4fcabde4696d7827f1ed49534a7ab1bf6ccf4a804e3f4923046f1b0717e3fb
                                      • Opcode Fuzzy Hash: f538a6ec50b13a5a432438719ae0dd6bab246691b5c69cb740f5b57cdcac7e2e
                                      • Instruction Fuzzy Hash: 1D212736200710EBE330AB2ADC49B6776F6FF84712F010A6DE64E929E0DB75D845DE25
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • LoadLibraryW.KERNEL32(?,00000000,?,00B046F8,00000000,00000000,wininet.dll,?,00000000,00000000,?,?,00B05386,?,?), ref: 00B0D5CD
                                      • GetLastError.KERNEL32(?,00B046F8,00000000,00000000,wininet.dll,?,00000000,00000000,?,?,00B05386,?,?), ref: 00B0D5DA
                                      • GetProcAddress.KERNEL32(00000000,BootstrapperApplicationCreate), ref: 00B0D612
                                      • GetLastError.KERNEL32(?,00B046F8,00000000,00000000,wininet.dll,?,00000000,00000000,?,?,00B05386,?,?), ref: 00B0D61E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$AddressLibraryLoadProc
                                      • String ID: BootstrapperApplicationCreate$Failed to create UX.$Failed to get BootstrapperApplicationCreate entry-point$Failed to load UX DLL.$userexperience.cpp$wininet.dll
                                      • API String ID: 1866314245-1140179540
                                      • Opcode ID: d7453325317d880ce3df1b2d824ec7f95443158a9835726c903cb730ff09f362
                                      • Instruction ID: b674875173d7b29a7b4c0d05b7b15c396b52133ee32b42fa0f0b9e08ad770e74
                                      • Opcode Fuzzy Hash: d7453325317d880ce3df1b2d824ec7f95443158a9835726c903cb730ff09f362
                                      • Instruction Fuzzy Hash: 2811E936A41722ABEB215AA99C05F673AD8EF05751F01417AFD09F72E0EB21CD0096D5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetLastError.KERNEL32(000007D0,000007D0,00000000,00000000,?,00000000,00000000,00000003,00000000,00000000), ref: 00B19297
                                      • GetLastError.KERNEL32(000007D0,000007D0,00000000,00000000,000007D0,00000001), ref: 00B192BB
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast
                                      • String ID: $$0$Could not close verify handle.$Could not verify file %ls.$Failed to allocate memory$Failed to allocate string.$Failed to encode file hash.$Failed to get file hash.$cache.cpp
                                      • API String ID: 1452528299-4263581490
                                      • Opcode ID: 1b3f36105b90dbcb356bccf5cb987561578ea427acaf06f91694448d9821b970
                                      • Instruction ID: 39785ea5f8e52dbecfbf09f65e695a868641c308e0fb7724e93d24bbf3bc707c
                                      • Opcode Fuzzy Hash: 1b3f36105b90dbcb356bccf5cb987561578ea427acaf06f91694448d9821b970
                                      • Instruction Fuzzy Hash: D6718271D00229AAEB21DBA8DC41BEEB7F8EF08710F5141A6ED04F7291E7749D458BA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetWindowLongW.USER32(?,000000EB), ref: 00B1E326
                                      • DefWindowProcW.USER32(?,00000082,?,?), ref: 00B1E364
                                      • SetWindowLongW.USER32(?,000000EB,00000000), ref: 00B1E371
                                      • SetWindowLongW.USER32(?,000000EB,?), ref: 00B1E380
                                      • DefWindowProcW.USER32(?,?,?,?), ref: 00B1E38E
                                      • CreateCompatibleDC.GDI32(?), ref: 00B1E39A
                                      • SelectObject.GDI32(00000000,00000000), ref: 00B1E3AB
                                      • StretchBlt.GDI32(?,00000000,00000000,?,?,00000000,00000000,00000000,?,?,00CC0020), ref: 00B1E3CD
                                      • SelectObject.GDI32(00000000,00000000), ref: 00B1E3D5
                                      • DeleteDC.GDI32(00000000), ref: 00B1E3D8
                                      • PostQuitMessage.USER32(00000000), ref: 00B1E3E6
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Window$Long$ObjectProcSelect$CompatibleCreateDeleteMessagePostQuitStretch
                                      • String ID:
                                      • API String ID: 409979828-0
                                      • Opcode ID: 6b98bb797020303ee36b4be99ee61869c668972f45d14fc8ab9ac5b8986c1a40
                                      • Instruction ID: 12205a69a0bd35782ebcee0cf55025e16a01d69a2cb384592455314f1d54a439
                                      • Opcode Fuzzy Hash: 6b98bb797020303ee36b4be99ee61869c668972f45d14fc8ab9ac5b8986c1a40
                                      • Instruction Fuzzy Hash: B121AE36104108BFCB165FA9AC4CEBB3FE9FB4A321B554558FB2697160DB30C910DB64
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      • WixBundleLastUsedSource, xrefs: 00B19F9D
                                      • Failed to combine layout source with source., xrefs: 00B1A0A0
                                      • Failed to copy source path., xrefs: 00B1A113
                                      • Failed to get bundle layout directory property., xrefs: 00B1A083
                                      • Failed to get current process directory., xrefs: 00B19FEF
                                      • Failed to combine last source with source., xrefs: 00B1A00C
                                      • WixBundleLayoutDirectory, xrefs: 00B1A068
                                      • WixBundleOriginalSource, xrefs: 00B19FB3
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Find$CloseFileFirstlstrlen
                                      • String ID: Failed to combine last source with source.$Failed to combine layout source with source.$Failed to copy source path.$Failed to get bundle layout directory property.$Failed to get current process directory.$WixBundleLastUsedSource$WixBundleLayoutDirectory$WixBundleOriginalSource
                                      • API String ID: 2767606509-3003062821
                                      • Opcode ID: 05cb420a5d70facb9d4ef5b505c4779fb8e98408e5f7dd4406a3b4db63cb442e
                                      • Instruction ID: 13eb2ad7272f6c0d42d5133cc7c70dab98db84f7b961f88eefb1d8f2a3f3b36b
                                      • Opcode Fuzzy Hash: 05cb420a5d70facb9d4ef5b505c4779fb8e98408e5f7dd4406a3b4db63cb442e
                                      • Instruction Fuzzy Hash: 72718F71D01219ABDF119FA4D845AFEBBF5EF09710F9041A9F900F7290D735AD809B62
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ExpandEnvironmentStringsW.KERNEL32(00000000,00000000,00000000,00000000,00000040,00000000,00000000), ref: 00B030C7
                                      • GetLastError.KERNEL32 ref: 00B030D1
                                      • ExpandEnvironmentStringsW.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 00B03129
                                      • GetLastError.KERNEL32 ref: 00B03133
                                      • GetFullPathNameW.KERNEL32(00000000,00000040,00000000,00000000,00000000,00000040,00000000,00000000), ref: 00B031EC
                                      • GetLastError.KERNEL32 ref: 00B031F6
                                      • GetFullPathNameW.KERNEL32(00000000,00000007,00000000,00000000,00000000,00000007), ref: 00B0324D
                                      • GetLastError.KERNEL32 ref: 00B03257
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$EnvironmentExpandFullNamePathStrings
                                      • String ID: pathutil.cpp
                                      • API String ID: 1547313835-741606033
                                      • Opcode ID: dc59d4c2ad74162d9c5b7567147ea885cb9dfc8aa75bb66f4c519444b891403b
                                      • Instruction ID: 2860d9454dc4c1486b3fdf9986b2305d20ca3ff71bf752c0255e648497e96b9b
                                      • Opcode Fuzzy Hash: dc59d4c2ad74162d9c5b7567147ea885cb9dfc8aa75bb66f4c519444b891403b
                                      • Instruction Fuzzy Hash: BF617236E00229BBDF219AA98C49BAE7EECEF48B51F1141A5ED05F7190E735CF409790
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,label,000000FF,?,?,?,7622DFD0,?,00B47172,?,?), ref: 00B46C4C
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B46CB7
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B46D2F
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B46D71
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$Free$Compare
                                      • String ID: label$scheme$term
                                      • API String ID: 1324494773-4117840027
                                      • Opcode ID: 44f927b11590795adb968bd74e696e70a8c0e15b0a3af9800031363ea55d2519
                                      • Instruction ID: adef7ef41c0dee4118da0cf714fccf0a079c5de1610ca5d72e5b9ffb76a7f1fe
                                      • Opcode Fuzzy Hash: 44f927b11590795adb968bd74e696e70a8c0e15b0a3af9800031363ea55d2519
                                      • Instruction Fuzzy Hash: 80513975E00219BBCF15CBA4C884FAEBBF8EF05721F2442A5E511AB1A1DB319F40EB51
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,FFFEB88D,000000FF,?,000000FF,00B05381,?,00B052B5,00000000,00B05381,FFF9E89D,00B05381,00B053B5,00B0533D,?), ref: 00B0CB15
                                      Strings
                                      • Failed to get next stream., xrefs: 00B0CBFC
                                      • Failed to get directory portion of local file path, xrefs: 00B0CBEE
                                      • Payload was not found in container: %ls, xrefs: 00B0CC22
                                      • Failed to extract file., xrefs: 00B0CBE0
                                      • Failed to concat file paths., xrefs: 00B0CBF5
                                      • Failed to ensure directory exists, xrefs: 00B0CBE7
                                      • Failed to find embedded payload: %ls, xrefs: 00B0CB41
                                      • payload.cpp, xrefs: 00B0CC16
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareString
                                      • String ID: Failed to concat file paths.$Failed to ensure directory exists$Failed to extract file.$Failed to find embedded payload: %ls$Failed to get directory portion of local file path$Failed to get next stream.$Payload was not found in container: %ls$payload.cpp
                                      • API String ID: 1825529933-1711239286
                                      • Opcode ID: e626283c5904bd20ce8207577e6a2759a5055b0a249fa05d71a6ec0766304f31
                                      • Instruction ID: 720523126a47e445dd471825054d51f225abae66098bacf4df9a6de63e7d1f51
                                      • Opcode Fuzzy Hash: e626283c5904bd20ce8207577e6a2759a5055b0a249fa05d71a6ec0766304f31
                                      • Instruction Fuzzy Hash: F1419D31D00219EBDF259F84C9829AEBFE5EF40710F1082E9E915AB2E1D7709E41EB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • PeekMessageW.USER32(00000000,00000000,00000400,00000400,00000000), ref: 00B046B5
                                      • GetCurrentThreadId.KERNEL32 ref: 00B046BB
                                        • Part of subcall function 00B1FC51: new.LIBCMT ref: 00B1FC58
                                      • GetMessageW.USER32(00000000,00000000,00000000,00000000), ref: 00B04749
                                      Strings
                                      • Failed to start bootstrapper application., xrefs: 00B04717
                                      • Unexpected return value from message pump., xrefs: 00B0479F
                                      • wininet.dll, xrefs: 00B046E8
                                      • user.cpp, xrefs: 00B04795
                                      • Failed to load UX., xrefs: 00B046FE
                                      • Failed to create user for UX., xrefs: 00B046D5
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Message$CurrentPeekThread
                                      • String ID: Failed to create user for UX.$Failed to load UX.$Failed to start bootstrapper application.$Unexpected return value from message pump.$user.cpp$wininet.dll
                                      • API String ID: 673430819-2573580774
                                      • Opcode ID: 8ef397da9c5625fd1e27bd9529ffb37f5d18bb91b6691120338369485cd285cb
                                      • Instruction ID: 89e4dd121f8f293265a62603ef6ff4447b091cfdace88802ab53a40dc6539e4e
                                      • Opcode Fuzzy Hash: 8ef397da9c5625fd1e27bd9529ffb37f5d18bb91b6691120338369485cd285cb
                                      • Instruction Fuzzy Hash: 734193B1600115BFDB159BA4CC85EBA7BECEF05714F1041A9FA05E72D0EB30EE4497A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • LocalFree.KERNEL32(00000000,?,00000001,80000005,?,00000000,00000000,00000000,00000003,000007D0), ref: 00B18E01
                                      Strings
                                      • Failed to create ACL to secure cache path: %ls, xrefs: 00B18DB7
                                      • Failed to secure cache path: %ls, xrefs: 00B18DE4
                                      • Failed to allocate access for Administrators group to path: %ls, xrefs: 00B18D08
                                      • cache.cpp, xrefs: 00B18DAC
                                      • Failed to allocate access for Users group to path: %ls, xrefs: 00B18D6B
                                      • Failed to allocate access for Everyone group to path: %ls, xrefs: 00B18D4A
                                      • Failed to allocate access for SYSTEM group to path: %ls, xrefs: 00B18D29
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FreeLocal
                                      • String ID: Failed to allocate access for Administrators group to path: %ls$Failed to allocate access for Everyone group to path: %ls$Failed to allocate access for SYSTEM group to path: %ls$Failed to allocate access for Users group to path: %ls$Failed to create ACL to secure cache path: %ls$Failed to secure cache path: %ls$cache.cpp
                                      • API String ID: 2826327444-4113288589
                                      • Opcode ID: f2c6a52efbd7469c7aa765d4b162cefac41e4a8a4651deaab9bbd80788090281
                                      • Instruction ID: f1ae8083b77302b60f8e9f4b01645f5f610fb8088942818ce506e9d31f0a4842
                                      • Opcode Fuzzy Hash: f2c6a52efbd7469c7aa765d4b162cefac41e4a8a4651deaab9bbd80788090281
                                      • Instruction Fuzzy Hash: D241D772B41329B6DB219654AC45FEB7AE8FF11B10F8040F9BD04BA1D1DE609E88C7A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetFileAttributesW.KERNEL32(00000000,00000000,00000000,00000000,?,?,?,00000000,00000000,00000000,?,?,00B2ADE5,?,00000001,00000000), ref: 00B29AE1
                                      • GetLastError.KERNEL32(?,?,?,00000000,00000000,00000000,?,?,00B2ADE5,?,00000001,00000000,00000000,00000000,00000001,00000000), ref: 00B29AEB
                                      • CopyFileExW.KERNEL32(00000000,00000000,00B2993C,00000000,00000020,00000000,00000000,00000000,?,?,?,00000000,00000000,00000000), ref: 00B29B39
                                      • GetLastError.KERNEL32(?,?,?,00000000,00000000,00000000,?,?,00B2ADE5,?,00000001,00000000,00000000,00000000,00000001,00000000), ref: 00B29B68
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLast$AttributesCopy
                                      • String ID: BA aborted copy of payload from: '%ls' to: %ls.$Failed attempt to copy payload from: '%ls' to: %ls.$Failed to clear readonly bit on payload destination path: %ls$apply.cpp$copy
                                      • API String ID: 1969131206-836986073
                                      • Opcode ID: 3ffd8ad6e5cd87290138d2fe42b482e292b9d3f238cfc1c0b48fa20a42e9d86c
                                      • Instruction ID: 711055bbc19b277c876888e13301bd61fdcef8f11723a7ad15b8ca905ec6a83a
                                      • Opcode Fuzzy Hash: 3ffd8ad6e5cd87290138d2fe42b482e292b9d3f238cfc1c0b48fa20a42e9d86c
                                      • Instruction Fuzzy Hash: 9A31E171B40325BBEB149A65AC85F7BB7ECEF02751F1041A9BC0DE7191D720CE0096A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • LoadBitmapW.USER32(?,00000001), ref: 00B1E094
                                      • GetLastError.KERNEL32 ref: 00B1E0A0
                                      • GetObjectW.GDI32(00000000,00000018,?), ref: 00B1E0E7
                                      • GetCursorPos.USER32(?), ref: 00B1E108
                                      • MonitorFromPoint.USER32(?,?,00000002), ref: 00B1E11A
                                      • GetMonitorInfoW.USER32(00000000,?), ref: 00B1E130
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Monitor$BitmapCursorErrorFromInfoLastLoadObjectPoint
                                      • String ID: ($Failed to load splash screen bitmap.$splashscreen.cpp
                                      • API String ID: 2342928100-598475503
                                      • Opcode ID: 3b2562c98dca6ec19bc8107536094f128aa50e8cba54833d36ce516a5ab43aec
                                      • Instruction ID: a38335ca908805630d714645a6210c4e394dcd4cd7e5d07239ed0de3acd7d896
                                      • Opcode Fuzzy Hash: 3b2562c98dca6ec19bc8107536094f128aa50e8cba54833d36ce516a5ab43aec
                                      • Instruction Fuzzy Hash: CD315075A00205AFDB10DFB9D989A9EBBF5FB08701F408169FD14EB280DB70D904CB61
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetSystemWow64DirectoryW.KERNEL32(?,00000104), ref: 00B064F7
                                      • GetLastError.KERNEL32 ref: 00B06505
                                      • GetSystemDirectoryW.KERNEL32(?,00000104), ref: 00B06546
                                      • GetLastError.KERNEL32 ref: 00B06550
                                      Strings
                                      • Failed to set system folder variant value., xrefs: 00B065BE
                                      • Failed to get 32-bit system folder., xrefs: 00B0653F
                                      • Failed to get 64-bit system folder., xrefs: 00B0657E
                                      • Failed to backslash terminate system folder., xrefs: 00B065A2
                                      • variable.cpp, xrefs: 00B06535, 00B06574
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: DirectoryErrorLastSystem$Wow64
                                      • String ID: Failed to backslash terminate system folder.$Failed to get 32-bit system folder.$Failed to get 64-bit system folder.$Failed to set system folder variant value.$variable.cpp
                                      • API String ID: 2634638900-1590374846
                                      • Opcode ID: 717a83cc706766adc799e651c5d4206784dfa5907a6af9c8c6bbaa820dd47e5c
                                      • Instruction ID: 414253126f5d45069da2e0866d8bb045c6ae92420b7abcec5846c8032aed14c7
                                      • Opcode Fuzzy Hash: 717a83cc706766adc799e651c5d4206784dfa5907a6af9c8c6bbaa820dd47e5c
                                      • Instruction Fuzzy Hash: 5221E9B2A413396AEB2067659C49B6A3BE8DF10750F1141E9FD08F71C0EA64CE4486E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentProcessId.KERNEL32(?,00000000,?,?,00B4B4F0), ref: 00B14EDB
                                      • GetProcessId.KERNEL32(000000FF,?,?,open,00000000,00000000,?,000000FF,?,?), ref: 00B14F79
                                      • CloseHandle.KERNEL32(00000000), ref: 00B14F92
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Process$CloseCurrentHandle
                                      • String ID: -q -%ls %ls %ls %u$Failed to allocate parameters for elevated process.$Failed to launch elevated child process: %ls$burn.elevated$open$runas
                                      • API String ID: 2815245435-1352204306
                                      • Opcode ID: b0d0135db87ed03a1f21405f3d97cf62a23846b7a126c1f82fbbf560db30e2f9
                                      • Instruction ID: 0ff9f492557aee8581b30806f36218f62de763f23ad0468b005e1aa1468e34c3
                                      • Opcode Fuzzy Hash: b0d0135db87ed03a1f21405f3d97cf62a23846b7a126c1f82fbbf560db30e2f9
                                      • Instruction Fuzzy Hash: 8D214875D00219BFCF01AF94D8819AEBBF8EF08355B5081EAF908A2350D7719F95AB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleHandleW.KERNEL32(msi,DllGetVersion), ref: 00B06746
                                      • GetProcAddress.KERNEL32(00000000), ref: 00B0674D
                                      • GetLastError.KERNEL32 ref: 00B06757
                                      Strings
                                      • Failed to find DllGetVersion entry point in msi.dll., xrefs: 00B06785
                                      • msi, xrefs: 00B0673D
                                      • Failed to set variant value., xrefs: 00B067C3
                                      • DllGetVersion, xrefs: 00B06738
                                      • variable.cpp, xrefs: 00B0677B
                                      • Failed to get msi.dll version info., xrefs: 00B0679F
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressErrorHandleLastModuleProc
                                      • String ID: DllGetVersion$Failed to find DllGetVersion entry point in msi.dll.$Failed to get msi.dll version info.$Failed to set variant value.$msi$variable.cpp
                                      • API String ID: 4275029093-842451892
                                      • Opcode ID: fbfc6ef943e3391cd20cb7480069565294fb4a74b9238172cbc5c9f89a5378de
                                      • Instruction ID: fbd0bab3afd15bddee542d36d512197ecc14908a5b4a39149aa4756a21457f40
                                      • Opcode Fuzzy Hash: fbfc6ef943e3391cd20cb7480069565294fb4a74b9238172cbc5c9f89a5378de
                                      • Instruction Fuzzy Hash: 5E11D671B40624BAEB20AB78DC41A7F7BE8EB04B51F000599FE05F7291EA649E0492E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • HeapSetInformation.KERNEL32(00000000,00000001,00000000,00000000,?,?,?,?,?,00B0111A,cabinet.dll,00000009,?,?,00000000), ref: 00B01185
                                      • GetModuleHandleW.KERNEL32(kernel32,?,?,?,?,00B0111A,cabinet.dll,00000009,?,?,00000000), ref: 00B01190
                                      • GetProcAddress.KERNEL32(00000000,SetDefaultDllDirectories), ref: 00B0119E
                                      • GetLastError.KERNEL32(?,?,?,?,00B0111A,cabinet.dll,00000009,?,?,00000000), ref: 00B011B9
                                      • GetProcAddress.KERNEL32(00000000,SetDllDirectoryW), ref: 00B011C1
                                      • GetLastError.KERNEL32(?,?,?,?,00B0111A,cabinet.dll,00000009,?,?,00000000), ref: 00B011D6
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressErrorLastProc$HandleHeapInformationModule
                                      • String ID: SetDefaultDllDirectories$SetDllDirectoryW$kernel32
                                      • API String ID: 3104334766-1824683568
                                      • Opcode ID: f7cd4831793e1940c8aa97b43f3bf60123ed5d9d0c91b0dedd5cbab26bfc8189
                                      • Instruction ID: 06e89c72b581cbedca8f3d9593faead18d416cfbd180af643e30db1a22c007a7
                                      • Opcode Fuzzy Hash: f7cd4831793e1940c8aa97b43f3bf60123ed5d9d0c91b0dedd5cbab26bfc8189
                                      • Instruction Fuzzy Hash: 7B019E75600215BAC7246BAA9C09D6FBFACFB41792B008095FB15A2290DB70DB008AB1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(?), ref: 00B1F3FB
                                      • LeaveCriticalSection.KERNEL32(?), ref: 00B1F576
                                      Strings
                                      • UX denied while trying to set download URL on embedded payload: %ls, xrefs: 00B1F466
                                      • UX did not provide container or payload id., xrefs: 00B1F565
                                      • UX requested unknown container with id: %ls, xrefs: 00B1F4A0
                                      • user is active, cannot change user state., xrefs: 00B1F415
                                      • Failed to set download user., xrefs: 00B1F4FE
                                      • UX requested unknown payload with id: %ls, xrefs: 00B1F450
                                      • Failed to set download password., xrefs: 00B1F524
                                      • Failed to set download URL., xrefs: 00B1F4D5
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: user is active, cannot change user state.$Failed to set download URL.$Failed to set download password.$Failed to set download user.$UX denied while trying to set download URL on embedded payload: %ls$UX did not provide container or payload id.$UX requested unknown container with id: %ls$UX requested unknown payload with id: %ls
                                      • API String ID: 3168844106-2615595102
                                      • Opcode ID: dddaaaf504f1a6f06d0e72a1ff9a236a26089ccb4cd190a27588e7f300cfaa84
                                      • Instruction ID: 67949806c48083ec11dbc749bd1b72db393fe1c935364ac18c805904d70f8a47
                                      • Opcode Fuzzy Hash: dddaaaf504f1a6f06d0e72a1ff9a236a26089ccb4cd190a27588e7f300cfaa84
                                      • Instruction Fuzzy Hash: 4B41F331A10613ABDB219F64C845ABA77E9EF10721F5482F5F905BB280EB30DE80C791
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNEL32(000000FF,C0000000,00000004,00000000,00000004,00000080,00000000,00000000,00000000,00000000,00000078,00000000,000000FF,?,00000000,00000000), ref: 00B45955
                                      • GetLastError.KERNEL32 ref: 00B45963
                                      • VirtualAlloc.KERNEL32(00000000,00010000,00003000,00000004), ref: 00B459A4
                                      • GetLastError.KERNEL32 ref: 00B459B1
                                      • VirtualFree.KERNEL32(?,00000000,00008000), ref: 00B45B26
                                      • CloseHandle.KERNEL32(?), ref: 00B45B35
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastVirtual$AllocCloseCreateFileFreeHandle
                                      • String ID: GET$dlutil.cpp
                                      • API String ID: 2028584396-3303425918
                                      • Opcode ID: 21e67b0367eaf6b01986ef42a3baffe6ba6d70c44ba5a9b5bd3f1f2e52289fa1
                                      • Instruction ID: 8277e7e75d66449054eba8f7b50f00d74adfa6af97ebe209620543e4332f7069
                                      • Opcode Fuzzy Hash: 21e67b0367eaf6b01986ef42a3baffe6ba6d70c44ba5a9b5bd3f1f2e52289fa1
                                      • Instruction Fuzzy Hash: F1615D76A00A19ABDF21DFA4CC84BAE7BF9FF08750F114255FE05B7291D7709A40AB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B10E7E: CompareStringW.KERNEL32(00000000,00000000,feclient.dll,000000FF,00000000,000000FF,00000000,00000000,?,?,00B10ACD,?,00000000,?,00000000,00000000), ref: 00B10EAD
                                      • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,00000000,?,00000000,?,00000000,00000001,?,?,00000000,?,00000000), ref: 00B10C51
                                      • GetLastError.KERNEL32 ref: 00B10C5E
                                      Strings
                                      • Failed to append cache action., xrefs: 00B10BA8
                                      • Failed to append package start action., xrefs: 00B10AF3
                                      • Failed to append payload cache action., xrefs: 00B10C08
                                      • Failed to append rollback cache action., xrefs: 00B10B2D
                                      • plan.cpp, xrefs: 00B10C82
                                      • Failed to create syncpoint event., xrefs: 00B10C8C
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareCreateErrorEventLastString
                                      • String ID: Failed to append cache action.$Failed to append package start action.$Failed to append payload cache action.$Failed to append rollback cache action.$Failed to create syncpoint event.$plan.cpp
                                      • API String ID: 801187047-2489563283
                                      • Opcode ID: c58e4ea00104a87226a6f3677b874fb128b9f53195b3fbb957cd65fdaefb928f
                                      • Instruction ID: f32f6df344524dca94d2737261438d683826fe2c48afec99615848a898468413
                                      • Opcode Fuzzy Hash: c58e4ea00104a87226a6f3677b874fb128b9f53195b3fbb957cd65fdaefb928f
                                      • Instruction Fuzzy Hash: DA617175910604EFDB05EF68C880AAABBF9FF84314F6184D9E9159B311DB70EE81DB50
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B09DDA
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B09DFF
                                      Strings
                                      • MsiComponentSearch failed: ID '%ls', HRESULT 0x%x, xrefs: 00B09EF3
                                      • Failed to set variable., xrefs: 00B09EE3
                                      • Failed to format product code string., xrefs: 00B09E0A
                                      • Failed to get component path: %d, xrefs: 00B09E63
                                      • Failed to format component id string., xrefs: 00B09DE5
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open@16
                                      • String ID: Failed to format component id string.$Failed to format product code string.$Failed to get component path: %d$Failed to set variable.$MsiComponentSearch failed: ID '%ls', HRESULT 0x%x
                                      • API String ID: 3613110473-1671347822
                                      • Opcode ID: ed5b57d2b50bf5479488d063e35d83a79ca28a96098385a629682960f6f5f3a8
                                      • Instruction ID: aaa7eff67fa963d1001b0cd4f7f2ef20bec6bf0849ae981ef5abcb7d57bf9f6f
                                      • Opcode Fuzzy Hash: ed5b57d2b50bf5479488d063e35d83a79ca28a96098385a629682960f6f5f3a8
                                      • Instruction Fuzzy Hash: 7D41F972900215BACF21EA68CC86B7EBEE9EF04310F244AD6F115E51E3DB309E54E752
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,7622DFD0,000000FF,name,000000FF,7622DFD0,?,7622DFD0,?,7622DFD0), ref: 00B46B2B
                                      • CompareStringW.KERNEL32(0000007F,00000000,000000FF,000000FF,email,000000FF), ref: 00B46B48
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B46B86
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B46BCD
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$CompareFree
                                      • String ID: email$name$uri
                                      • API String ID: 3589242889-1168628755
                                      • Opcode ID: a0a6d346da5777922c3166ce0e6cd02dfd3078db01be57041e4620d8c0471239
                                      • Instruction ID: 63adc8e62ef54506f6dbc64df9a0d0ca405b7e26bb68effaffa30d2c9abe5055
                                      • Opcode Fuzzy Hash: a0a6d346da5777922c3166ce0e6cd02dfd3078db01be57041e4620d8c0471239
                                      • Instruction Fuzzy Hash: 33415E35904218BBCB11DBA4CC45FAE77F4EB05720F2042E5E911E7290CB309F44EB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ReadFile.KERNEL32(00000000,?,00000008,00B04740,00000000,?,00000000,00000000,?,00000000,00B04740,?,?,00000000,?,00000000), ref: 00B14765
                                      • GetLastError.KERNEL32 ref: 00B14772
                                      • ReadFile.KERNEL32(?,00000000,?,?,00000000,?,00000000), ref: 00B1481B
                                      • GetLastError.KERNEL32 ref: 00B14825
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastRead
                                      • String ID: Failed to allocate data for message.$Failed to read data for message.$Failed to read message from pipe.$pipe.cpp
                                      • API String ID: 1948546556-3912962418
                                      • Opcode ID: 3618d910ba77dbd69141c0cc32d07d6acedfa85488f8387f6ecd4a754a9477bc
                                      • Instruction ID: 0d6f5f52cd442a1ee463e14edaa031227b3e80068192587202d43381909d66a0
                                      • Opcode Fuzzy Hash: 3618d910ba77dbd69141c0cc32d07d6acedfa85488f8387f6ecd4a754a9477bc
                                      • Instruction Fuzzy Hash: 06310575A40325BBDB109F65DC45BAAB7E8FB01B52F1081A9F900E61D0DB70DE8487D1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B0F315
                                        • Part of subcall function 00B04013: CreateDirectoryW.KERNELBASE(00B0533D,00B053B5,00000000,00000000,?,00B19EE4,00000000,00000000,00B0533D,00000000,00B052B5,00000000,?,?,00B0D4AC,00B0533D), ref: 00B04021
                                        • Part of subcall function 00B04013: GetLastError.KERNEL32(?,00B19EE4,00000000,00000000,00B0533D,00000000,00B052B5,00000000,?,?,00B0D4AC,00B0533D,00000000,00000000), ref: 00B0402F
                                      • lstrlenA.KERNEL32(00B4B4F0,00000000,00000094,00000000,00000094,?,?,00B10328,swidtag,00000094,?,00B4B508,00B10328,00000000,?,00000000), ref: 00B0F368
                                        • Part of subcall function 00B44C67: CreateFileW.KERNEL32(00B4B4F0,40000000,00000001,00000000,00000002,00000080,00000000,00B10328,00000000,?,00B0F37F,?,00000080,00B4B4F0,00000000), ref: 00B44C7F
                                        • Part of subcall function 00B44C67: GetLastError.KERNEL32(?,00B0F37F,?,00000080,00B4B4F0,00000000,?,00B10328,?,00000094,?,?,?,?,?,00000000), ref: 00B44C8C
                                      Strings
                                      • Failed to format tag folder path., xrefs: 00B0F3CE
                                      • Failed to allocate regid folder path., xrefs: 00B0F3C7
                                      • Failed to write tag xml to file: %ls, xrefs: 00B0F3A6
                                      • swidtag, xrefs: 00B0F328
                                      • Failed to create regid folder: %ls, xrefs: 00B0F3B0
                                      • Failed to allocate regid file path., xrefs: 00B0F3C0
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateErrorLast$DirectoryFileOpen@16lstrlen
                                      • String ID: Failed to allocate regid file path.$Failed to allocate regid folder path.$Failed to create regid folder: %ls$Failed to format tag folder path.$Failed to write tag xml to file: %ls$swidtag
                                      • API String ID: 904508749-1201533908
                                      • Opcode ID: de4d0dcb79d0c6b6c805c7a8875a540b6a44c6253a614c4732106a03441011d4
                                      • Instruction ID: 1c4869016c27f1ee5efc685e6b44c662d3ebf1123b82d97306a194540f06c057
                                      • Opcode Fuzzy Hash: de4d0dcb79d0c6b6c805c7a8875a540b6a44c6253a614c4732106a03441011d4
                                      • Instruction Fuzzy Hash: DC316131E00616BBCB219A94DC41BADBFF5EF04720F1081F6F910BA6A1D7719E50AB94
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WaitForSingleObject.KERNEL32(?,0002BF20,?,F0000003,00000000,00000000,?,00000000,00000000,00000000,00B05386,00000000,00000000,?,00000000), ref: 00B15292
                                      • GetLastError.KERNEL32(?,?,?,00B04B5B,?,?,00000000,?,?,?,?,?,?,00B4B490,?,?), ref: 00B1529D
                                      Strings
                                      • pipe.cpp, xrefs: 00B152C1
                                      • Failed to post terminate message to child process cache thread., xrefs: 00B15261
                                      • Failed to post terminate message to child process., xrefs: 00B1527D
                                      • Failed to write restart to message buffer., xrefs: 00B15235
                                      • Failed to write exit code to message buffer., xrefs: 00B1520D
                                      • Failed to wait for child process exit., xrefs: 00B152CB
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastObjectSingleWait
                                      • String ID: Failed to post terminate message to child process cache thread.$Failed to post terminate message to child process.$Failed to wait for child process exit.$Failed to write exit code to message buffer.$Failed to write restart to message buffer.$pipe.cpp
                                      • API String ID: 1211598281-2161881128
                                      • Opcode ID: 1e29d2610067d02c62b80b9a3d57c97b7220e3153b2a04656503c7f6549b0387
                                      • Instruction ID: eb391dbc187fcd72322053c2561879834ee7eef027ec4d60a64c6d195a2e0fe7
                                      • Opcode Fuzzy Hash: 1e29d2610067d02c62b80b9a3d57c97b7220e3153b2a04656503c7f6549b0387
                                      • Instruction Fuzzy Hash: EF210673940B25FBDB2256949C41FDE7BE8EF00721F6143D5F900B2290DB709E9496E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNEL32(00000000,80000000,00000005,00000000,00000003,08000000,00000000,00000000,00000101,?,00B19CFF,00000003,000007D0,00000003,?,000007D0), ref: 00B18EAC
                                      • GetLastError.KERNEL32(?,00B19CFF,00000003,000007D0,00000003,?,000007D0,00000000,000007D0,00000000,00000003,00000000,00000003,000007D0,00000000,-00000004), ref: 00B18EB9
                                      • CloseHandle.KERNEL32(00000000,?,00B19CFF,00000003,000007D0,00000003,?,000007D0,00000000,000007D0,00000000,00000003,00000000,00000003,000007D0,00000000), ref: 00B18F80
                                      Strings
                                      • Failed to verify catalog signature of payload: %ls, xrefs: 00B18F47
                                      • Failed to verify signature of payload: %ls, xrefs: 00B18F28
                                      • cache.cpp, xrefs: 00B18EEF
                                      • Failed to open payload at path: %ls, xrefs: 00B18EFC
                                      • Failed to verify hash of payload: %ls, xrefs: 00B18F6B
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateErrorFileHandleLast
                                      • String ID: Failed to open payload at path: %ls$Failed to verify catalog signature of payload: %ls$Failed to verify hash of payload: %ls$Failed to verify signature of payload: %ls$cache.cpp
                                      • API String ID: 2528220319-2757871984
                                      • Opcode ID: 3b60909594ebf8779dc0d5758d8f5fd86fd20614ad78d33e0bdaee6d1c78ae33
                                      • Instruction ID: 67fd74e2f42f34e2dbb99a2f3b6c919a6b77890a50973ad984052108920cc0b2
                                      • Opcode Fuzzy Hash: 3b60909594ebf8779dc0d5758d8f5fd86fd20614ad78d33e0bdaee6d1c78ae33
                                      • Instruction Fuzzy Hash: 75214735640220BADB222A64AC49FDE3BDAFF01771F5042A0FD00762A0DB359DE2DAD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetWindowsDirectoryW.KERNEL32(?,00000104), ref: 00B06A03
                                      • GetLastError.KERNEL32 ref: 00B06A0D
                                      • GetVolumePathNameW.KERNEL32(?,?,00000104), ref: 00B06A51
                                      • GetLastError.KERNEL32 ref: 00B06A5B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$DirectoryNamePathVolumeWindows
                                      • String ID: Failed to get volume path name.$Failed to get windows directory.$Failed to set variant value.$variable.cpp
                                      • API String ID: 124030351-4026719079
                                      • Opcode ID: aa22d15d552ef73c4a2d5aac3ad8ebb569d935e04203908337064d0c60a43330
                                      • Instruction ID: 45020677081fc2c8952baf324d7f87a2e2bc1f5a5ca0bb11813eb8bad9f68e89
                                      • Opcode Fuzzy Hash: aa22d15d552ef73c4a2d5aac3ad8ebb569d935e04203908337064d0c60a43330
                                      • Instruction Fuzzy Hash: 9C21F976F013286BEB20A6649C45FAB77ECDB40B10F0141E6BE09F7181EA349E4086A5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B09B5A
                                      • GetFileAttributesW.KERNEL32(00000000,000002C0,?,00000000,00000000,000002C0,00000100,000002C0,00000100), ref: 00B09B72
                                      • GetLastError.KERNEL32 ref: 00B09B81
                                      Strings
                                      • Failed to format variable string., xrefs: 00B09B65
                                      • Failed to set variable., xrefs: 00B09C07
                                      • Failed get to file attributes. '%ls', xrefs: 00B09BC0
                                      • search.cpp, xrefs: 00B09BB3
                                      • File search: %ls, did not find path: %ls, xrefs: 00B09BD5
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AttributesErrorFileLastOpen@16
                                      • String ID: Failed get to file attributes. '%ls'$Failed to format variable string.$Failed to set variable.$File search: %ls, did not find path: %ls$search.cpp
                                      • API String ID: 1811509786-2053429945
                                      • Opcode ID: 37492a49708b5cc09b0bf882e5d723a4445c17eab3a96cb03f89cebc7517e5e2
                                      • Instruction ID: d186c20c6c15196c9f7d9493485b0394b22e50dcb01ec482b97b4d824148883d
                                      • Opcode Fuzzy Hash: 37492a49708b5cc09b0bf882e5d723a4445c17eab3a96cb03f89cebc7517e5e2
                                      • Instruction Fuzzy Hash: 76212732E40214BBDB116AA49D46A6EBFE9EF05320F1043D5F910B21E1EB709E50E6D1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • TlsSetValue.KERNEL32(?,?), ref: 00B1AB53
                                      • GetLastError.KERNEL32 ref: 00B1AB5D
                                      • CoInitializeEx.OLE32(00000000,00000000), ref: 00B1AB9C
                                      • CoUninitialize.OLE32(?,00B1C4F4,?,?), ref: 00B1ABD9
                                      Strings
                                      • Failed to set elevated cache pipe into thread local storage for logging., xrefs: 00B1AB8B
                                      • elevation.cpp, xrefs: 00B1AB81
                                      • Failed to initialize COM., xrefs: 00B1ABA8
                                      • Failed to pump messages in child process., xrefs: 00B1ABC7
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorInitializeLastUninitializeValue
                                      • String ID: Failed to initialize COM.$Failed to pump messages in child process.$Failed to set elevated cache pipe into thread local storage for logging.$elevation.cpp
                                      • API String ID: 876858697-113251691
                                      • Opcode ID: f7b01574041eb9dcfae58f75597eae8080f65405e1a753742ff730b6f41d192e
                                      • Instruction ID: 43ef4ed2b78508396b94fb5c4c86f47f48fb42e3d183ecd9e10c0da040bd2ef8
                                      • Opcode Fuzzy Hash: f7b01574041eb9dcfae58f75597eae8080f65405e1a753742ff730b6f41d192e
                                      • Instruction Fuzzy Hash: DA115972A5A230BB9B111B699C05DDBBFE8EF05B21B0041D6FD04F3250EF70AE40A6D6
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      • RegCloseKey.ADVAPI32(00000000,?,00000000,CommonFilesDir,?,80000002,SOFTWARE\Microsoft\Windows\CurrentVersion,00020119,00000000), ref: 00B05C77
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseOpen
                                      • String ID: +$CommonFilesDir$Failed to ensure path was backslash terminated.$Failed to open Windows folder key.$Failed to read folder path for '%ls'.$ProgramFilesDir$SOFTWARE\Microsoft\Windows\CurrentVersion
                                      • API String ID: 47109696-3209209246
                                      • Opcode ID: 29a24868676f90bd207d6391afaf1600f3937270b0d0bd84a452c3dc5ee41978
                                      • Instruction ID: aceedf70c61cc2504aa094647b0daa1b4cfe54f5f6d91b523251be391e33adb3
                                      • Opcode Fuzzy Hash: 29a24868676f90bd207d6391afaf1600f3937270b0d0bd84a452c3dc5ee41978
                                      • Instruction Fuzzy Hash: 8F01B932A44628B7DB326A549D06E9F7EE8DB40750F1041E9F900B6251D6719F10B6D1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetFileAttributesW.KERNEL32(?,00000000,?,00000000,?,?,?,00000001,00000000,?), ref: 00B2A0F1
                                      • GetLastError.KERNEL32(?,?,?,00000001,00000000,?), ref: 00B2A0FB
                                      Strings
                                      • download, xrefs: 00B2A0BB
                                      • :, xrefs: 00B2A174
                                      • apply.cpp, xrefs: 00B2A11F
                                      • Failed attempt to download URL: '%ls' to: '%ls', xrefs: 00B2A1D8
                                      • Failed to clear readonly bit on payload destination path: %ls, xrefs: 00B2A12A
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AttributesErrorFileLast
                                      • String ID: :$Failed attempt to download URL: '%ls' to: '%ls'$Failed to clear readonly bit on payload destination path: %ls$apply.cpp$download
                                      • API String ID: 1799206407-1905830404
                                      • Opcode ID: 10bedf908bf810cdb22efb19fa4e1e063c1b8bb70fb8f6e1cb9cded1a17bb511
                                      • Instruction ID: a26142c6714e7ca4030564199f05d2c260f944d157ee6a1d147980218f947612
                                      • Opcode Fuzzy Hash: 10bedf908bf810cdb22efb19fa4e1e063c1b8bb70fb8f6e1cb9cded1a17bb511
                                      • Instruction Fuzzy Hash: D4517E71A00229AFDB11DFA8D880BABB7F5FF05711F148099E909AB251E771DE50CB92
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,7622DFD0,000000FF,type,000000FF,?,7622DFD0,7622DFD0,7622DFD0), ref: 00B46DFE
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B46E49
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B46EC5
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B46F11
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$Free$Compare
                                      • String ID: type$url
                                      • API String ID: 1324494773-1247773906
                                      • Opcode ID: 39aa7f39cc8a62d0d3b16fc5151e0ea3d9ebc211088bbbb55170a3a3053db599
                                      • Instruction ID: 9e531ab41002fd9d29458ec7b0b7eeb4e9c03fa5d2c9c675cc5339f4366c3594
                                      • Opcode Fuzzy Hash: 39aa7f39cc8a62d0d3b16fc5151e0ea3d9ebc211088bbbb55170a3a3053db599
                                      • Instruction Fuzzy Hash: 06514675901219EBCF15CBA4C844EAEBBF8EF05721F1442E9E911EB2A0DB319F44EB51
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,http://appsyndication.org/2006/appsyn,000000FF,00000010,00000001,00000000,00000000,00000000,?,?,00B28E1F,000002C0,00000100), ref: 00B483AD
                                      • CompareStringW.KERNEL32(0000007F,00000000,?,000000FF,application,000000FF,?,?,00B28E1F,000002C0,00000100,000002C0,000002C0,00000100,000002C0,00000410), ref: 00B483C8
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareHeapString$AllocateProcess
                                      • String ID: application$apuputil.cpp$http://appsyndication.org/2006/appsyn$type
                                      • API String ID: 2664528157-4206478990
                                      • Opcode ID: 2c386bb51dff22c2cf20a2199dde2156baaf151e33f80229b3b9d421fc03c6b3
                                      • Instruction ID: 007a7431543cbb23a1260a7872db1541996423b55a7f8360798d00ef21f738d7
                                      • Opcode Fuzzy Hash: 2c386bb51dff22c2cf20a2199dde2156baaf151e33f80229b3b9d421fc03c6b3
                                      • Instruction Fuzzy Hash: 8351A171A44301ABEB219F54CC81F2E77E5EB14760F208294F965AB2D1DF74EA40EB10
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetLastError.KERNEL32 ref: 00B463B7
                                      • DeleteFileW.KERNEL32(00000000,00000000,00000000,?,?,00000078,000000FF,00000000,?,?,?,00000078,000000FF,?,?,00000078), ref: 00B464AE
                                      • CloseHandle.KERNEL32(000000FF,00000000,00000000,?,?,00000078,000000FF,00000000,?,?,?,00000078,000000FF,?,?,00000078), ref: 00B464BD
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseDeleteErrorFileHandleLast
                                      • String ID: Burn$DownloadTimeout$WiX\Burn$dlutil.cpp
                                      • API String ID: 3522763407-1704223933
                                      • Opcode ID: fae1fbb147df8a224d69d73b5090c3dbc9a65df229ac21b5f25df1102462cc3c
                                      • Instruction ID: 145d4f34b662e00dd1fbe95c0eb3edde4ba1cfa5bb3012f32f2cb25966c693b3
                                      • Opcode Fuzzy Hash: fae1fbb147df8a224d69d73b5090c3dbc9a65df229ac21b5f25df1102462cc3c
                                      • Instruction Fuzzy Hash: 96514E76D00619BBDF129FA4CC45EEEBBF9EF09710F014195FA04E6290E7358A50EBA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _memcmp.LIBVCRUNTIME ref: 00B1910E
                                        • Part of subcall function 00B45587: GetLastError.KERNEL32(?,?,00B19133,?,00000003,00000000,?), ref: 00B455A6
                                      • _memcmp.LIBVCRUNTIME ref: 00B19148
                                      • GetLastError.KERNEL32 ref: 00B191C2
                                      Strings
                                      • Failed to find expected public key in certificate chain., xrefs: 00B19183
                                      • Failed to get certificate public key identifier., xrefs: 00B191F0
                                      • Failed to read certificate thumbprint., xrefs: 00B191B6
                                      • cache.cpp, xrefs: 00B191E6
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast_memcmp
                                      • String ID: Failed to find expected public key in certificate chain.$Failed to get certificate public key identifier.$Failed to read certificate thumbprint.$cache.cpp
                                      • API String ID: 3428363238-3408201827
                                      • Opcode ID: 6b21da3956a0505356399ace5ee7fba6c4b6944f61dd6fa7bcdf34d2f70789ba
                                      • Instruction ID: 8535f756cc70a7245622882887fdb00d4f59f7be5f4733c81394c9ca7a3290a9
                                      • Opcode Fuzzy Hash: 6b21da3956a0505356399ace5ee7fba6c4b6944f61dd6fa7bcdf34d2f70789ba
                                      • Instruction Fuzzy Hash: 81416E71E00216BFDB10DAA9D895AEAB7F9EB08710F4040A9F905F7251DB74ED94CBA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegCloseKey.ADVAPI32(00000000,00000001,00000000,00000001,00000000,?,?,00020006,00000000,?,?,00000000,?), ref: 00B1054A
                                      • RegCloseKey.ADVAPI32(00000000,00000001,00000000,00000001,00000000,?,?,00020006,00000000,?,?,00000000,?), ref: 00B10559
                                        • Part of subcall function 00B40AD5: RegCreateKeyExW.ADVAPI32(00000001,00000000,00000000,00000000,00000000,00000001,00000000,?,00000000,00000001,?,?,00B10491,?,00000000,00020006), ref: 00B40AFA
                                      Strings
                                      • Failed to write volatile reboot required registry key., xrefs: 00B10495
                                      • Failed to delete registration key: %ls, xrefs: 00B104F8
                                      • Failed to update resume mode., xrefs: 00B1052E
                                      • Failed to open registration key., xrefs: 00B10591
                                      • %ls.RebootRequired, xrefs: 00B10467
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Close$Create
                                      • String ID: %ls.RebootRequired$Failed to delete registration key: %ls$Failed to open registration key.$Failed to update resume mode.$Failed to write volatile reboot required registry key.
                                      • API String ID: 359002179-2517785395
                                      • Opcode ID: 6e8cb57c9e7c7112e9de5094eefe213b7703b510928270c45edcc0d3337fb893
                                      • Instruction ID: b70935cae1fd6eeb01d34d3ef8ec6fa67e364dbf64f7e6ce35892c3ed6908b83
                                      • Opcode Fuzzy Hash: 6e8cb57c9e7c7112e9de5094eefe213b7703b510928270c45edcc0d3337fb893
                                      • Instruction Fuzzy Hash: E0418E31910218BADF22BEA4DC42EEE7BFAEF50310F5044E9FA4562161D7B19AD0EA51
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegCloseKey.ADVAPI32(?,?,?,00000001,?,?,?,00000001,00000000,?,00000000,?,?,?,00000000,?), ref: 00B0F7CD
                                      • RegCloseKey.ADVAPI32(00000000,?,?,00000001,?,?,?,00000001,00000000,?,00000000,?,?,?,00000000,?), ref: 00B0F7DA
                                      Strings
                                      • Resume, xrefs: 00B0F741
                                      • Failed to open registration key., xrefs: 00B0F736
                                      • %ls.RebootRequired, xrefs: 00B0F6BA
                                      • Failed to read Resume value., xrefs: 00B0F763
                                      • Failed to format pending restart registry key to read., xrefs: 00B0F6D1
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Close
                                      • String ID: %ls.RebootRequired$Failed to format pending restart registry key to read.$Failed to open registration key.$Failed to read Resume value.$Resume
                                      • API String ID: 3535843008-3890505273
                                      • Opcode ID: 80d935048c768f3806a6ddcf00a9bedd7ba572af92a94bd8d670189fbd21da35
                                      • Instruction ID: fd0d22d46c91acb0f25dd3b4c203ccfcc2c8ec4f0cd71fb8578b855a6001ad06
                                      • Opcode Fuzzy Hash: 80d935048c768f3806a6ddcf00a9bedd7ba572af92a94bd8d670189fbd21da35
                                      • Instruction Fuzzy Hash: E1415436A0011AEFCB21AF98C881ABDBFF5FB05350F1581F6E914A7690C3719E50DB52
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID: Failed to determine length of relative path.$Failed to determine length of source path.$Failed to set last source.$Failed to trim source folder.$WixBundleLastUsedSource
                                      • API String ID: 0-660234312
                                      • Opcode ID: ce690dfd26abe5b4cfc8c7bdb971799e0e2efcc2f802ba50cf49d87bcff79f87
                                      • Instruction ID: 720802358cc918412b7579dbc5390d49b7b80bd47412a8ee611d64e1d3e7ca1a
                                      • Opcode Fuzzy Hash: ce690dfd26abe5b4cfc8c7bdb971799e0e2efcc2f802ba50cf49d87bcff79f87
                                      • Instruction Fuzzy Hash: 0231C732901219BBDF219A54CC45EEEBBF9EF00720F5042E5F920B71D1EA30AEC19751
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CoCreateInstance.OLE32(00B60A84,00000000,00000017,00B60A94,?,?,00000000,00000000,?,?,?,?,?,00B2DCAE,00000000,00000000), ref: 00B2D6AF
                                      Strings
                                      • Failed to set BITS job to foreground., xrefs: 00B2D730
                                      • Failed to create BITS job., xrefs: 00B2D6E9
                                      • Failed to create IBackgroundCopyManager., xrefs: 00B2D6BB
                                      • WixBurn, xrefs: 00B2D6DA
                                      • Failed to set notification flags for BITS job., xrefs: 00B2D701
                                      • Failed to set progress timeout., xrefs: 00B2D719
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateInstance
                                      • String ID: Failed to create BITS job.$Failed to create IBackgroundCopyManager.$Failed to set BITS job to foreground.$Failed to set notification flags for BITS job.$Failed to set progress timeout.$WixBurn
                                      • API String ID: 542301482-468763447
                                      • Opcode ID: 357792fc860b7430d38aebe9d5eadbfebe4f49491d38151d7edd8acbff7692d3
                                      • Instruction ID: 2046681419a9169a51254c8e969995d1c18ae401878c0a967ea5f92fccf7659a
                                      • Opcode Fuzzy Hash: 357792fc860b7430d38aebe9d5eadbfebe4f49491d38151d7edd8acbff7692d3
                                      • Instruction Fuzzy Hash: B7318531B50226AFDB15DFA9D855E7FB7F4EF48710B104199F909EB3A0CA74AC018B91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNEL32(00000000,C0000000,00000004,00000000,00000004,00000080,00000000,00000000,?,?,?,?,?,WiX\Burn,DownloadTimeout,00000078), ref: 00B45CB2
                                      • GetLastError.KERNEL32 ref: 00B45CBF
                                      • ReadFile.KERNEL32(00000000,00000008,00000008,?,00000000), ref: 00B45D06
                                      • CloseHandle.KERNEL32(00000000,dlutil.cpp,000000C8,00000000), ref: 00B45D6E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: File$CloseCreateErrorHandleLastRead
                                      • String ID: %ls.R$dlutil.cpp
                                      • API String ID: 2136311172-657863730
                                      • Opcode ID: 00c414dc78931fdebe9ad48e136c2ea8d58ab884db16f85872116242d5214dae
                                      • Instruction ID: 784e815dcf29caab2ca4a46ac4f512d9f2aa9011198b1d5604460a3861a5b65b
                                      • Opcode Fuzzy Hash: 00c414dc78931fdebe9ad48e136c2ea8d58ab884db16f85872116242d5214dae
                                      • Instruction Fuzzy Hash: D731E972A00A14ABEB308B68CC49F6A77E8EF05721F1142A5FE15EB2D1D7708E0097A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B0CC57: CompareStringW.KERNEL32(0000007F,00000000,00000000,000000FF,00B0E336,000000FF,00000000,00000000,00B0E336,?,?,00B0DADD,?,?,?,?), ref: 00B0CC82
                                      • CreateFileW.KERNEL32(E900B4BA,80000000,00000005,00000000,00000003,08000000,00000000,00B052BD,00B4B450,00000000,00B053B5,04680A79,?,00B052B5,00000000,00B05381), ref: 00B0C84F
                                      • GetLastError.KERNEL32(?,?,?,00B175F7,00B05565,00B05371,00B05371,00000000,?,00B05381,FFF9E89D,00B05381,00B053B5,00B0533D,?,00B0533D), ref: 00B0C894
                                      Strings
                                      • Failed to verify catalog signature: %ls, xrefs: 00B0C88D
                                      • Failed to find payload for catalog file., xrefs: 00B0C8D9
                                      • Failed to open catalog in working path: %ls, xrefs: 00B0C8C2
                                      • Failed to get catalog local file path, xrefs: 00B0C8D2
                                      • catalog.cpp, xrefs: 00B0C8B5
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareCreateErrorFileLastString
                                      • String ID: Failed to find payload for catalog file.$Failed to get catalog local file path$Failed to open catalog in working path: %ls$Failed to verify catalog signature: %ls$catalog.cpp
                                      • API String ID: 1774366664-48089280
                                      • Opcode ID: 8450105b180cdb3c586728cc813fd56ef5afe53e866e1a3023237b2295faadc8
                                      • Instruction ID: 735b1620eabb78211f7b77f2488e8411519f9aad459b446059615c196d60c373
                                      • Opcode Fuzzy Hash: 8450105b180cdb3c586728cc813fd56ef5afe53e866e1a3023237b2295faadc8
                                      • Instruction Fuzzy Hash: B131AF71A40715BBDB119B64CC41F6ABFE4EB04750F2182A9F909EB290E770EE50AB94
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WaitForSingleObject.KERNEL32(?,000000FF,762330B0,00000000,?,?,?,?,00B2D439,?), ref: 00B2D145
                                      • ReleaseMutex.KERNEL32(?,?,?,?,00B2D439,?), ref: 00B2D161
                                      • WaitForSingleObject.KERNEL32(?,000000FF), ref: 00B2D1A4
                                      • ReleaseMutex.KERNEL32(?), ref: 00B2D1BB
                                      • SetEvent.KERNEL32(?), ref: 00B2D1C4
                                      Strings
                                      • Failed to get message from netfx chainer., xrefs: 00B2D1E5
                                      • Failed to send files in use message from netfx chainer., xrefs: 00B2D20A
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: MutexObjectReleaseSingleWait$Event
                                      • String ID: Failed to get message from netfx chainer.$Failed to send files in use message from netfx chainer.
                                      • API String ID: 2608678126-3424578679
                                      • Opcode ID: 00c9b72e22575891e75dda772ec26c553186c16251b36b880a356a6f90044d2b
                                      • Instruction ID: 977d61ad9fe07505b28d96f7d5b7d5a9e5a625a3ae093eac63a2676e6a95e61c
                                      • Opcode Fuzzy Hash: 00c9b72e22575891e75dda772ec26c553186c16251b36b880a356a6f90044d2b
                                      • Instruction Fuzzy Hash: 7931E931900619AFCB129FA4DC08EAFBFF5FF45321F1086A5F515A72A1CB75DA109B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateProcessW.KERNEL32(00000001,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00000000,?,?,?,?,00000000,00000000), ref: 00B4089A
                                      • GetLastError.KERNEL32(?,?,?,?,00000000,00000000,00000000), ref: 00B408A4
                                      • CloseHandle.KERNEL32(?,?,?,?,?,00000000,00000000,00000000), ref: 00B408ED
                                      • CloseHandle.KERNEL32(00000000,?,?,?,?,00000000,00000000,00000000), ref: 00B408FA
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseHandle$CreateErrorLastProcess
                                      • String ID: "%ls" %ls$D$procutil.cpp
                                      • API String ID: 161867955-2732225242
                                      • Opcode ID: 653a1bbc2f67f22cfca2e35ae559e67ca2ff5ee79372e16d1ceb6e484d3e19f0
                                      • Instruction ID: 0a8b48545b7ee208fe49466c9d2833c38c3c0bb312d484006cfd3704df800601
                                      • Opcode Fuzzy Hash: 653a1bbc2f67f22cfca2e35ae559e67ca2ff5ee79372e16d1ceb6e484d3e19f0
                                      • Instruction Fuzzy Hash: 97211C75D0021AAFDB11EFE8CE409AEBBF9EF04355F104166EA05B6261D7709F40ABA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B09A86
                                      • GetFileAttributesW.KERNEL32(00000000,000002C0,?,00000000,00000000,000002C0,00000100,00000000,?,00B0A7A9,00000100,000002C0,000002C0,00000100), ref: 00B09AA6
                                      • GetLastError.KERNEL32(?,00B0A7A9,00000100,000002C0,000002C0,00000100), ref: 00B09AB1
                                      Strings
                                      • Failed to format variable string., xrefs: 00B09A91
                                      • Directory search: %ls, did not find path: %ls, reason: 0x%x, xrefs: 00B09B1C
                                      • Failed while searching directory search: %ls, for path: %ls, xrefs: 00B09B06
                                      • Failed to set directory search path variable., xrefs: 00B09AE1
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AttributesErrorFileLastOpen@16
                                      • String ID: Directory search: %ls, did not find path: %ls, reason: 0x%x$Failed to format variable string.$Failed to set directory search path variable.$Failed while searching directory search: %ls, for path: %ls
                                      • API String ID: 1811509786-2966038646
                                      • Opcode ID: 32e0ba8cfcbe5fa3b2c3819063eb585c14552b847c906871780e0ec7fe8f7919
                                      • Instruction ID: ab426d5786cfb8610b6e40786c16313971edb416c68a5825173aa648622b8bd2
                                      • Opcode Fuzzy Hash: 32e0ba8cfcbe5fa3b2c3819063eb585c14552b847c906871780e0ec7fe8f7919
                                      • Instruction Fuzzy Hash: 2D11C032A40124BBCB126A989D06F9EBEE5EF14330F2142E5FD15761E2DB369E10B6D1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B09C52
                                      • GetFileAttributesW.KERNEL32(00000000,000002C0,?,00000000,00000000,000002C0,00000100,000002C0,?,00B0A781,00000100,000002C0,000002C0,?,000002C0,00000100), ref: 00B09C72
                                      • GetLastError.KERNEL32(?,00B0A781,00000100,000002C0,000002C0,?,000002C0,00000100,000002C0,000002C0,00000100), ref: 00B09C7D
                                      Strings
                                      • Failed to format variable string., xrefs: 00B09C5D
                                      • Failed to set variable to file search path., xrefs: 00B09CD4
                                      • Failed while searching file search: %ls, for path: %ls, xrefs: 00B09CAA
                                      • File search: %ls, did not find path: %ls, xrefs: 00B09CE0
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AttributesErrorFileLastOpen@16
                                      • String ID: Failed to format variable string.$Failed to set variable to file search path.$Failed while searching file search: %ls, for path: %ls$File search: %ls, did not find path: %ls
                                      • API String ID: 1811509786-3425311760
                                      • Opcode ID: 09e82280038d446ab6e89c950bb67fcecff88e9e26fc7579ce4120960f10c6e9
                                      • Instruction ID: b059d54133b32394ac6abda3e49d9a2ce497c6f8f465aac76458c0e579a8f48e
                                      • Opcode Fuzzy Hash: 09e82280038d446ab6e89c950bb67fcecff88e9e26fc7579ce4120960f10c6e9
                                      • Instruction Fuzzy Hash: E211D532D40124BBEF2226949E46A9DBEE5EF10720F2142D5FD10B61E2DB319E10B7D5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WaitForSingleObject.KERNEL32(00000001,000493E0,00000000,?,?,00B1D134,00000000,?,?,00B1C59C,00000001,?,?,?,?,?), ref: 00B1CD06
                                      • GetLastError.KERNEL32(?,?,00B1D134,00000000,?,?,00B1C59C,00000001,?,?,?,?,?,00000000,00000000,?), ref: 00B1CD10
                                      • GetExitCodeThread.KERNEL32(00000001,?,?,?,00B1D134,00000000,?,?,00B1C59C,00000001,?,?,?,?,?,00000000), ref: 00B1CD4C
                                      • GetLastError.KERNEL32(?,?,00B1D134,00000000,?,?,00B1C59C,00000001,?,?,?,?,?,00000000,00000000,?), ref: 00B1CD56
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CodeExitObjectSingleThreadWait
                                      • String ID: Failed to get cache thread exit code.$Failed to wait for cache thread to terminate.$elevation.cpp
                                      • API String ID: 3686190907-1954264426
                                      • Opcode ID: 3cdd3e4cafb7c87cf080f13197438a6a1d3240584eaa03b114a8619b6a5a6e29
                                      • Instruction ID: 1eb2527ada69411cb0f8ae904d3783120330eced5c83fd5fb312b407d584bacd
                                      • Opcode Fuzzy Hash: 3cdd3e4cafb7c87cf080f13197438a6a1d3240584eaa03b114a8619b6a5a6e29
                                      • Instruction Fuzzy Hash: 4D01F976B807347AAB206A79AC06F9B7DD8EF05792F4101A5FE05E7190EA508E0095E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WaitForSingleObject.KERNEL32(00000001,000000FF,00000000,?,00B16CFB,00B04740,?,00000000,?,00000000,00000001), ref: 00B167BD
                                      • GetLastError.KERNEL32(?,00B16CFB,00B04740,?,00000000,?,00000000,00000001), ref: 00B167C7
                                      • GetExitCodeThread.KERNEL32(00000001,00000000,?,00B16CFB,00B04740,?,00000000,?,00000000,00000001), ref: 00B16806
                                      • GetLastError.KERNEL32(?,00B16CFB,00B04740,?,00000000,?,00000000,00000001), ref: 00B16810
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CodeExitObjectSingleThreadWait
                                      • String ID: Failed to get cache thread exit code.$Failed to wait for cache thread to terminate.$core.cpp
                                      • API String ID: 3686190907-2546940223
                                      • Opcode ID: 326a6eb24d86760d284fd56a1d60c77f6eb6b8985f681d30c10dc2b5e6988332
                                      • Instruction ID: bb28285695853e2b6076e7f8bbd255a5ed7ea642fe51daeac496b70493b7381f
                                      • Opcode Fuzzy Hash: 326a6eb24d86760d284fd56a1d60c77f6eb6b8985f681d30c10dc2b5e6988332
                                      • Instruction Fuzzy Hash: 6B015E70240304BBEB189B65DD16BBE76E5EB00711F5041AEBD06D61E0EB75DE40A519
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(?), ref: 00B1F59B
                                      • LeaveCriticalSection.KERNEL32(?), ref: 00B1F6A8
                                      Strings
                                      • UX requested unknown container with id: %ls, xrefs: 00B1F667
                                      • Failed to set source path for payload., xrefs: 00B1F637
                                      • user is active, cannot change user state., xrefs: 00B1F5B5
                                      • UX denied while trying to set source on embedded payload: %ls, xrefs: 00B1F61D
                                      • UX requested unknown payload with id: %ls, xrefs: 00B1F607
                                      • Failed to set source path for container., xrefs: 00B1F68D
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: user is active, cannot change user state.$Failed to set source path for container.$Failed to set source path for payload.$UX denied while trying to set source on embedded payload: %ls$UX requested unknown container with id: %ls$UX requested unknown payload with id: %ls
                                      • API String ID: 3168844106-4121889706
                                      • Opcode ID: a37fcdf22abf738ad1547386ad7475028a627f99ec4994648fe3c859e99bb888
                                      • Instruction ID: 64fd135e8889a801796853aab99d7e42839e57ee622290072db0223b77d8d51f
                                      • Opcode Fuzzy Hash: a37fcdf22abf738ad1547386ad7475028a627f99ec4994648fe3c859e99bb888
                                      • Instruction Fuzzy Hash: 11311472A10612AB8B219B58CC45EAA77ECEF54721B4481EAFC04F72A0DB74ED80C791
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenW.KERNEL32(00000000), ref: 00B070E7
                                      Strings
                                      • Failed to append characters., xrefs: 00B07173
                                      • []{}, xrefs: 00B07111
                                      • Failed to allocate buffer for escaped string., xrefs: 00B070FE
                                      • [\%c], xrefs: 00B07146
                                      • Failed to append escape sequence., xrefs: 00B0717A
                                      • Failed to copy string., xrefs: 00B0719B
                                      • Failed to format escape sequence., xrefs: 00B07181
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: lstrlen
                                      • String ID: Failed to allocate buffer for escaped string.$Failed to append characters.$Failed to append escape sequence.$Failed to copy string.$Failed to format escape sequence.$[\%c]$[]{}
                                      • API String ID: 1659193697-3250950999
                                      • Opcode ID: 92f8947b7a063ce33610fe491332151bc67952b8e57b92c2cee34c583f418af3
                                      • Instruction ID: 635a8c20c8bc2b47e6fddfe6aa6f65a50b1c6d0157ad0e7605537d39ecaba2b1
                                      • Opcode Fuzzy Hash: 92f8947b7a063ce33610fe491332151bc67952b8e57b92c2cee34c583f418af3
                                      • Instruction Fuzzy Hash: E521B632D89225BBDB215694DC46BAEFEE9DF00B10F2041D6F900B61D1EF74BF44A294
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(00000000,00000000,00B4B4F0,000000FF,feclient.dll,000000FF,00000000,00000000,?,?,?,00B2659B,?,00000001,?,00B4B490), ref: 00B25A19
                                      Strings
                                      • Failed to copy target product code., xrefs: 00B25B4C
                                      • Failed to insert execute action., xrefs: 00B25A6E
                                      • Failed grow array of ordered patches., xrefs: 00B25AB2
                                      • feclient.dll, xrefs: 00B25A0F, 00B25B39
                                      • Failed to plan action for target product., xrefs: 00B25AC4
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareString
                                      • String ID: Failed grow array of ordered patches.$Failed to copy target product code.$Failed to insert execute action.$Failed to plan action for target product.$feclient.dll
                                      • API String ID: 1825529933-3477540455
                                      • Opcode ID: 8fd0c107ca5459cbc1643d8d7422a4198ec4711d73e7223cef0608146db10220
                                      • Instruction ID: 2bec04581efc1a183ebfaaa66334a05954357b0f1111a6d18365a9af1a0a2531
                                      • Opcode Fuzzy Hash: 8fd0c107ca5459cbc1643d8d7422a4198ec4711d73e7223cef0608146db10220
                                      • Instruction Fuzzy Hash: E78135B560076A9FCB24CF58D881AAA77E4FF08324F1586A9EC199B352D730EC51CF90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(00000000,00000001,?,000000FF,?,000000FF,00000000,00000100,00000000,?,?,?,00B16F20,000000B8,0000001C,00000100), ref: 00B29068
                                      • CompareStringW.KERNEL32(00000000,00000001,?,000000FF,00B4B4A8,000000FF,?,?,?,00B16F20,000000B8,0000001C,00000100,00000100,00000100,000000B0), ref: 00B29101
                                      Strings
                                      • comres.dll, xrefs: 00B29187
                                      • detect.cpp, xrefs: 00B29163
                                      • BA aborted detect forward compatible bundle., xrefs: 00B2916D
                                      • Failed to initialize update bundle., xrefs: 00B291A9
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareString
                                      • String ID: BA aborted detect forward compatible bundle.$Failed to initialize update bundle.$comres.dll$detect.cpp
                                      • API String ID: 1825529933-439563586
                                      • Opcode ID: 4882c76525340f345373f20fe3e2b3f1911300cd01422c7870f3dd72ed99a570
                                      • Instruction ID: c549b2c33efc772657ce0d7b6326c375402b10bebe5804d0ce1af9dce0497a93
                                      • Opcode Fuzzy Hash: 4882c76525340f345373f20fe3e2b3f1911300cd01422c7870f3dd72ed99a570
                                      • Instruction Fuzzy Hash: 0651D071600226BFDB199F64DC85E6AB7EAFF05311F1042A8F92DEA190D731DC60DB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetConsoleCP.KERNEL32(?,00000000,?,?,?,?,?,?,?,00B3D132,?,00000000,?,00000000,00000000), ref: 00B3C9FF
                                      • __fassign.LIBCMT ref: 00B3CA7A
                                      • __fassign.LIBCMT ref: 00B3CA95
                                      • WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000001,?,00000005,00000000,00000000), ref: 00B3CABB
                                      • WriteFile.KERNEL32(?,?,00000000,00B3D132,00000000,?,?,?,?,?,?,?,?,?,00B3D132,?), ref: 00B3CADA
                                      • WriteFile.KERNEL32(?,?,00000001,00B3D132,00000000,?,?,?,?,?,?,?,?,?,00B3D132,?), ref: 00B3CB13
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FileWrite__fassign$ByteCharConsoleMultiWide
                                      • String ID:
                                      • API String ID: 1324828854-0
                                      • Opcode ID: 492f794f16a344179a9802f2ccd842fef507abe20ab485040bf1ef91b42a8758
                                      • Instruction ID: e531756c8dc2693e07c312b590392758150e53ce4cff5f5079531d38c8dafd71
                                      • Opcode Fuzzy Hash: 492f794f16a344179a9802f2ccd842fef507abe20ab485040bf1ef91b42a8758
                                      • Instruction Fuzzy Hash: 80517F7590024DAFDB10CFA8D885AEEBBF4FF09300F24415AE555F7291E7709941CBA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetLastError.KERNEL32(?,000000FF,00AAC56B,?,00B052B5,00000000,00B0533D), ref: 00B1AA90
                                      • GetLastError.KERNEL32(00000000,00000000,00000000,00000000,?,000000FF,00AAC56B,?,00B052B5,00000000,00B0533D), ref: 00B1AAD4
                                      Strings
                                      • Failed to get signer chain from authenticode certificate., xrefs: 00B1AB02
                                      • Failed to get provider state from authenticode certificate., xrefs: 00B1AABE
                                      • Failed to verify expected payload against actual certificate chain., xrefs: 00B1AB1A
                                      • Failed authenticode verification of payload: %ls, xrefs: 00B1AA71
                                      • cache.cpp, xrefs: 00B1AA66, 00B1AAB4, 00B1AAF8
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast
                                      • String ID: Failed authenticode verification of payload: %ls$Failed to get provider state from authenticode certificate.$Failed to get signer chain from authenticode certificate.$Failed to verify expected payload against actual certificate chain.$cache.cpp
                                      • API String ID: 1452528299-2590768268
                                      • Opcode ID: 3b4ee32d62029714fea016f7ca0747304a25d5bc78670105ab03062278dfa9f5
                                      • Instruction ID: 0e45a84353fb9dd9ad25975622cef4880591efcc1082fab22fcf3999ae4a1ace
                                      • Opcode Fuzzy Hash: 3b4ee32d62029714fea016f7ca0747304a25d5bc78670105ab03062278dfa9f5
                                      • Instruction Fuzzy Hash: 5C41A671E01229ABEB109BA9DD45BEFBBF8EF08310F50016AFD04F7291E7709D4586A5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleFileNameW.KERNEL32(00000000,?,00000104,00000001,00000000,00000000), ref: 00B40234
                                      • GetComputerNameW.KERNEL32(?,?), ref: 00B4028C
                                      Strings
                                      • Executable: %ls v%d.%d.%d.%d, xrefs: 00B402E8
                                      • --- logging level: %hs ---, xrefs: 00B4034C
                                      • Computer : %ls, xrefs: 00B402FA
                                      • === Logging started: %ls ===, xrefs: 00B402B7
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Name$ComputerFileModule
                                      • String ID: --- logging level: %hs ---$=== Logging started: %ls ===$Computer : %ls$Executable: %ls v%d.%d.%d.%d
                                      • API String ID: 2577110986-3153207428
                                      • Opcode ID: 5bf2dd4a2e9aa7949200755ccc22bf6d2c22fedc99bc6429ea0e3eb743c2f346
                                      • Instruction ID: c45a44234d4e87372de6bd1e7025029a08ce0b2bf23a06334faffc0d437a795d
                                      • Opcode Fuzzy Hash: 5bf2dd4a2e9aa7949200755ccc22bf6d2c22fedc99bc6429ea0e3eb743c2f346
                                      • Instruction Fuzzy Hash: 794151F29101289BCF21AF64DC85ABA77FCEB59300F0041E9EA09A7141DA74AF859F65
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenW.KERNEL32(?,00000000,00000000,BundleUpgradeCode,?,00020006,00000000,?,?,?,00000001), ref: 00B41479
                                      • lstrlenW.KERNEL32(?,00000000,00000000,?,00000000,00000001,00000000,00000000,BundleUpgradeCode,?,00020006,00000000,?,?,?,00000001), ref: 00B414F1
                                      • lstrlenW.KERNEL32(?,?,?,?,00000001), ref: 00B414FD
                                      • RegSetValueExW.ADVAPI32(00020006,?,00000000,00000007,00000000,?,00000000,?,?,00000000,00000001,00000000,00000000,BundleUpgradeCode,?,00020006), ref: 00B4153D
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: lstrlen$Value
                                      • String ID: BundleUpgradeCode$regutil.cpp
                                      • API String ID: 198323757-1648651458
                                      • Opcode ID: 9540962cd45094f92d71edc39e66fc2cfe9bc6cb4e884292df43b613e9ee2e69
                                      • Instruction ID: 2b137414e36eae3e0dced96ae24cf992e9226a4b24c2b52af5d9d9cc96840814
                                      • Opcode Fuzzy Hash: 9540962cd45094f92d71edc39e66fc2cfe9bc6cb4e884292df43b613e9ee2e69
                                      • Instruction Fuzzy Hash: 1A41B432E00226AFCF21DFACD850AAE7BF9EF44710F1145A9FD05A7250DA70DE519BA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CloseHandle.KERNEL32(00000000,?,?,00000001,00B4B4F0,?,00000001,000000FF,?,?,7694B390,00000000,00000001,00000000,?,00B172F3), ref: 00B1D32F
                                      Strings
                                      • Failed to create pipe and cache pipe., xrefs: 00B1D28C
                                      • UX aborted elevation requirement., xrefs: 00B1D244
                                      • Failed to create pipe name and client token., xrefs: 00B1D270
                                      • Failed to elevate., xrefs: 00B1D311
                                      • Failed to connect to elevated child process., xrefs: 00B1D318
                                      • elevation.cpp, xrefs: 00B1D23A
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseHandle
                                      • String ID: Failed to connect to elevated child process.$Failed to create pipe and cache pipe.$Failed to create pipe name and client token.$Failed to elevate.$UX aborted elevation requirement.$elevation.cpp
                                      • API String ID: 2962429428-3003415917
                                      • Opcode ID: e5b1bfc9e623da68450b682f94252f83837f390eb07bf0ebd701e8bbe8a43664
                                      • Instruction ID: 035afcb5efa6ce9ae0b8dab5a297e6f390ac40c098647e2f3ab56ddfd907dcdf
                                      • Opcode Fuzzy Hash: e5b1bfc9e623da68450b682f94252f83837f390eb07bf0ebd701e8bbe8a43664
                                      • Instruction Fuzzy Hash: 4A315B32A44621BAEB25A260EC46FEF77CCDF00720F5001D5F915B71C1DB61EE8082E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00B6B60C,00000000,?,?,?,00B05407,00000000,Setup,_Failed,txt,00000000,00000000,00000000,?,?,?), ref: 00B4042B
                                      • CreateFileW.KERNEL32(40000000,00000001,00000000,00000002,00000080,00000000,?,00000000,?,?,?,00B6B604,?,00B05407,00000000,Setup), ref: 00B404CC
                                      • GetLastError.KERNEL32(?,00B05407,00000000,Setup,_Failed,txt,00000000,00000000,00000000,?,?,?), ref: 00B404DC
                                      • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002,?,00B05407,00000000,Setup,_Failed,txt,00000000,00000000,00000000,?,?,?), ref: 00B40515
                                        • Part of subcall function 00B02DE0: GetLocalTime.KERNEL32(?,?,?,?,?,?), ref: 00B02F1F
                                      • LeaveCriticalSection.KERNEL32(00B6B60C,?,?,00B6B604,?,00B05407,00000000,Setup,_Failed,txt,00000000,00000000,00000000,?,?,?), ref: 00B4056E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalFileSection$CreateEnterErrorLastLeaveLocalPointerTime
                                      • String ID: logutil.cpp
                                      • API String ID: 4111229724-3545173039
                                      • Opcode ID: 79b44a3f0b02c6c26ce51cd81d0940e621de412f346d15a875cccb15701b5662
                                      • Instruction ID: 3c8b906f73433897cd58745aa827d589b0f36a7b9bf478d89a13d7e486987401
                                      • Opcode Fuzzy Hash: 79b44a3f0b02c6c26ce51cd81d0940e621de412f346d15a875cccb15701b5662
                                      • Instruction Fuzzy Hash: EF317371911215AFDF21BF65DD85E6A7AF8EB10B50F0041A5FB04E71A0DB74CF40ABA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateThread.KERNEL32(00000000,00000000,00B1AB3C,?,00000000,00000000), ref: 00B1D0B8
                                      • GetLastError.KERNEL32(?,?,?,?,00000000,00000000,?,?,?,?,?,?,?,?,?,?), ref: 00B1D0C4
                                      • CloseHandle.KERNEL32(00000000,00000000,?,?,00B1C59C,00000001,?,?,?,?,?,00000000,00000000,?,?,?), ref: 00B1D145
                                      Strings
                                      • Failed to create elevated cache thread., xrefs: 00B1D0F2
                                      • elevation.cpp, xrefs: 00B1D0E8
                                      • Failed to pump messages in child process., xrefs: 00B1D11C
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateErrorHandleLastThread
                                      • String ID: Failed to create elevated cache thread.$Failed to pump messages in child process.$elevation.cpp
                                      • API String ID: 747004058-4134175193
                                      • Opcode ID: 2a20d8603f1d687cde58da9018aaba163ca3fa73435c96b0dabb288760571b70
                                      • Instruction ID: fb46e7cebb5db1333370b4b21b470b6d9ae95790234039f0ee87ceada7975972
                                      • Opcode Fuzzy Hash: 2a20d8603f1d687cde58da9018aaba163ca3fa73435c96b0dabb288760571b70
                                      • Instruction Fuzzy Hash: 8241E6B5E01219AF8B00DFA9D8819EEBBF8FF08310F50416AF908F3350D7749A408B94
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B237B7
                                      Strings
                                      • Failed to format property value., xrefs: 00B23840
                                      • Failed to append property string part., xrefs: 00B2382B
                                      • %s%="%s", xrefs: 00B237EA
                                      • Failed to format property string part., xrefs: 00B23832
                                      • Failed to escape string., xrefs: 00B23839
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open@16
                                      • String ID: %s%="%s"$Failed to append property string part.$Failed to escape string.$Failed to format property string part.$Failed to format property value.
                                      • API String ID: 3613110473-515423128
                                      • Opcode ID: 9fc497fb47525ad8fdae620b130ddd1856a95b3a33b488b75faea71ca70d0959
                                      • Instruction ID: 42413330a16cd30f1bdda2de0af6398e516de18a0bba6ed7564a710e3286205f
                                      • Opcode Fuzzy Hash: 9fc497fb47525ad8fdae620b130ddd1856a95b3a33b488b75faea71ca70d0959
                                      • Instruction Fuzzy Hash: 5331A2B2901225AFDF159F94EC42EAEBBE9EF00F00F1041EAF9056A291D7749F149B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00000000,00000000,00000000,?,?,?,00B0583F,000002C0,000002C0,00000000,00000100,00000001,00000000,000002C0,00000002), ref: 00B07215
                                      • LeaveCriticalSection.KERNEL32(00000000,00000000,00000002,00000000,?,?,?,00B0583F,000002C0,000002C0,00000000,00000100,00000001,00000000,000002C0,00000002), ref: 00B072F4
                                      Strings
                                      • Failed to get unformatted string., xrefs: 00B07285
                                      • Failed to get value as string for variable: %ls, xrefs: 00B072E3
                                      • Failed to format value '%ls' of variable: %ls, xrefs: 00B072BE
                                      • *****, xrefs: 00B072B0, 00B072BD
                                      • Failed to get variable: %ls, xrefs: 00B07256
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: *****$Failed to format value '%ls' of variable: %ls$Failed to get unformatted string.$Failed to get value as string for variable: %ls$Failed to get variable: %ls
                                      • API String ID: 3168844106-2873099529
                                      • Opcode ID: 6b767bc1c0bea021e0ed17def98aca49ed237654f820ba46995a2b6cf5016623
                                      • Instruction ID: 591de81dd4cf4107dbe3877e637b1f2bb5ea843b1ac91aeb46b389642b966b6a
                                      • Opcode Fuzzy Hash: 6b767bc1c0bea021e0ed17def98aca49ed237654f820ba46995a2b6cf5016623
                                      • Instruction Fuzzy Hash: 9731BF32D8462AFBCF219A50CC05B9EBFE4EF12720F1081A5F90476590DB31BA61ABC4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • InitializeAcl.ADVAPI32(?,00000008,00000002,0000001A,00000000,?,00000000,00000000,?,?,00000000,00000000,?,?,-00000004,00000000), ref: 00B18C30
                                      • GetLastError.KERNEL32(?,?,?,00000001), ref: 00B18C3A
                                      • SetFileAttributesW.KERNEL32(?,00000080,?,00000001,20000004,00000000,00000000,?,00000000,00000003,000007D0,?,00000000,00000000,?,?), ref: 00B18C9A
                                      Strings
                                      • Failed to initialize ACL., xrefs: 00B18C68
                                      • cache.cpp, xrefs: 00B18C5E
                                      • Failed to allocate administrator SID., xrefs: 00B18C16
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AttributesErrorFileInitializeLast
                                      • String ID: Failed to allocate administrator SID.$Failed to initialize ACL.$cache.cpp
                                      • API String ID: 669721577-1117388985
                                      • Opcode ID: ee3240c696cf117ade623e0d41b5fea66db464768aa72713cd3e6abcc31b1f44
                                      • Instruction ID: 0d90fcac22955ccbfb61480b0fb4d34e5912f879a57302f6369aba87366b7bd8
                                      • Opcode Fuzzy Hash: ee3240c696cf117ade623e0d41b5fea66db464768aa72713cd3e6abcc31b1f44
                                      • Instruction Fuzzy Hash: 1621D872A41314BBEB209A999C85F9BB7E9FB04751F5140A9FE04F7280EA709E4096E4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentDirectoryW.KERNEL32(00000000,00000000,?,00000000,crypt32.dll,?,?,00B13ED4,00000001,feclient.dll,?,00000000,?,?,?,00B04A0C), ref: 00B04148
                                      • GetLastError.KERNEL32(?,?,00B13ED4,00000001,feclient.dll,?,00000000,?,?,?,00B04A0C,?,?,00B4B478,?,00000001), ref: 00B04154
                                      • GetCurrentDirectoryW.KERNEL32(00000000,?,?,00000000,?,?,00B13ED4,00000001,feclient.dll,?,00000000,?,?,?,00B04A0C,?), ref: 00B0418F
                                      • GetLastError.KERNEL32(?,?,00B13ED4,00000001,feclient.dll,?,00000000,?,?,?,00B04A0C,?,?,00B4B478,?,00000001), ref: 00B04199
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CurrentDirectoryErrorLast
                                      • String ID: crypt32.dll$dirutil.cpp
                                      • API String ID: 152501406-1104880720
                                      • Opcode ID: 5fc26d01568c73eb5beb380976b88b282db30e66e2b5523f9b1b43ab90f26203
                                      • Instruction ID: 2a3f79dd4d339d0d61266804aeeeb9ebe1c0d65d9b78e7d6619514c94c3c2d6d
                                      • Opcode Fuzzy Hash: 5fc26d01568c73eb5beb380976b88b282db30e66e2b5523f9b1b43ab90f26203
                                      • Instruction Fuzzy Hash: BB11B076E00726ABE7219A694C84B6BBEECEF15791B110175FF04F7290E760CD4086E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B099B6
                                      • GetFileAttributesW.KERNEL32(00000000,000002C0,?,00000000,00000000,000002C0,00000100,000002C0,00000100), ref: 00B099CE
                                      • GetLastError.KERNEL32 ref: 00B099D9
                                      Strings
                                      • Failed to format variable string., xrefs: 00B099C1
                                      • Failed to set variable., xrefs: 00B09A4E
                                      • Failed while searching directory search: %ls, for path: %ls, xrefs: 00B09A16
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AttributesErrorFileLastOpen@16
                                      • String ID: Failed to format variable string.$Failed to set variable.$Failed while searching directory search: %ls, for path: %ls
                                      • API String ID: 1811509786-402580132
                                      • Opcode ID: 6667ed9ff57d02a06f16027cce4dfa275bca72c3da4ff4a2213e5190d43133a3
                                      • Instruction ID: 1c623eb3ba6340d691f7f894f9af6e19b644a4c8632c9b41fd39eef8502b2d43
                                      • Opcode Fuzzy Hash: 6667ed9ff57d02a06f16027cce4dfa275bca72c3da4ff4a2213e5190d43133a3
                                      • Instruction Fuzzy Hash: D421F932E50224B7DB11AAA4DC41AADBBE5EF54320F208399F910B21D1D7709E50AAD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Strings
                                      • Failed to write during cabinet extraction., xrefs: 00B20997
                                      • Unexpected call to CabWrite()., xrefs: 00B20923
                                      • cabextract.cpp, xrefs: 00B2098D
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastWrite_memcpy_s
                                      • String ID: Failed to write during cabinet extraction.$Unexpected call to CabWrite().$cabextract.cpp
                                      • API String ID: 1970631241-3111339858
                                      • Opcode ID: 34e909c7f8fac3d7a7511dfe52118838ad0252bfa86f24358b780cd415e36c86
                                      • Instruction ID: 256d84c0a7a75b4e1b3b3d10e64ed9114f6bc0a0f37f41b9799482b7835bac29
                                      • Opcode Fuzzy Hash: 34e909c7f8fac3d7a7511dfe52118838ad0252bfa86f24358b780cd415e36c86
                                      • Instruction Fuzzy Hash: C4219D76610204AFEB00EF6DED84EAA77E9FF89710F110199FE09D7256E631DA009B51
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • DosDateTimeToFileTime.KERNEL32(?,?,?), ref: 00B20A25
                                      • LocalFileTimeToFileTime.KERNEL32(?,?), ref: 00B20A37
                                      • SetFileTime.KERNEL32(?,?,?,?), ref: 00B20A4A
                                      • CloseHandle.KERNEL32(000000FF,?,?,?,?,?,?,?,?,?,?,?,?,00B20616,?,?), ref: 00B20A59
                                      Strings
                                      • Invalid operation for this state., xrefs: 00B209FE
                                      • cabextract.cpp, xrefs: 00B209F4
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Time$File$CloseDateHandleLocal
                                      • String ID: Invalid operation for this state.$cabextract.cpp
                                      • API String ID: 609741386-1751360545
                                      • Opcode ID: 5077c18fd457cadcb3e7f748c173f6b09f125a6c60dd70634afae97b5f2e520d
                                      • Instruction ID: 9e9f5e0fac212ee2bf92f53bec924aa1b34492cde8e9e5aac531e25c92cc96b0
                                      • Opcode Fuzzy Hash: 5077c18fd457cadcb3e7f748c173f6b09f125a6c60dd70634afae97b5f2e520d
                                      • Instruction Fuzzy Hash: 7B21C672820229AB8B10AF68DC489AA7BFCFE09710B504296F925E75D1D770DA11CB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • _memcpy_s.LIBCMT ref: 00B1449E
                                      • _memcpy_s.LIBCMT ref: 00B144B1
                                      • _memcpy_s.LIBCMT ref: 00B144CC
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: _memcpy_s$Heap$AllocateProcess
                                      • String ID: Failed to allocate memory for message.$feclient.dll$pipe.cpp
                                      • API String ID: 886498622-766083570
                                      • Opcode ID: 2b3232d55ed0af65e586343bc92884d11b34f44921826a7da7a9f0d7c1fa42fb
                                      • Instruction ID: ece36272566470b6a0b94be99a5674ffcee3ddc2a3a721e3a10b6a613178c842
                                      • Opcode Fuzzy Hash: 2b3232d55ed0af65e586343bc92884d11b34f44921826a7da7a9f0d7c1fa42fb
                                      • Instruction Fuzzy Hash: 0F1194B250031DABDB019E54DC86EDBB7ECEF19710B0044AAFA0497251EB74DA54C7E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetTempPathW.KERNEL32(00000104,?), ref: 00B0667D
                                      • GetLastError.KERNEL32 ref: 00B06687
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastPathTemp
                                      • String ID: 4#v$Failed to get temp path.$Failed to set variant value.$variable.cpp
                                      • API String ID: 1238063741-2550301277
                                      • Opcode ID: 1cac74bd243b83283f4f1236ac0f652611ec45e258166f876276cb98d7fa3741
                                      • Instruction ID: 9558207e4f9b20ee490cd8ca407fdc508790393c166743d3b0d2c36fe71ce6bc
                                      • Opcode Fuzzy Hash: 1cac74bd243b83283f4f1236ac0f652611ec45e258166f876276cb98d7fa3741
                                      • Instruction Fuzzy Hash: 6A01D6B2E41338A7EB20EB64AC46FAA77D8EB04B10F0101E5FD08F71C1EA659E0496D5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID: AcquireSRWLockExclusive$KERNEL32.DLL$ReleaseSRWLockExclusive
                                      • API String ID: 0-1718035505
                                      • Opcode ID: 43c33e43a28c78ae25972784f6ff08917640bb368895671209761866854a72f5
                                      • Instruction ID: 0a983f86e87873bbd4a022840613fcf19d2bede12e227359cbbdeda713220fac
                                      • Opcode Fuzzy Hash: 43c33e43a28c78ae25972784f6ff08917640bb368895671209761866854a72f5
                                      • Instruction Fuzzy Hash: 0F01C8B57413215B4F329E755C849A727DCEAA271233041FAE521C3290DB55CF95F7E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleHandleW.KERNEL32(kernel32,IsWow64Process,?,?,?,00B05D8F,00000000), ref: 00B409CF
                                      • GetProcAddress.KERNEL32(00000000), ref: 00B409D6
                                      • GetLastError.KERNEL32(?,?,?,00B05D8F,00000000), ref: 00B409ED
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressErrorHandleLastModuleProc
                                      • String ID: IsWow64Process$kernel32$procutil.cpp
                                      • API String ID: 4275029093-1586155540
                                      • Opcode ID: abc148ec332828c8ed0d36198e70502cc409cd1328ae7fdce464c8456a1b377d
                                      • Instruction ID: bd757686f9a931581100e6e2cae5350586e2f8c76d75ea50462b9fcc9d7d5f28
                                      • Opcode Fuzzy Hash: abc148ec332828c8ed0d36198e70502cc409cd1328ae7fdce464c8456a1b377d
                                      • Instruction Fuzzy Hash: FDF0A475A10328BBD720ABA59C09D6B7BD8EF05751B004155BE05E7350EB74CF00D7E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • MultiByteToWideChar.KERNEL32(00000001,00000000,?,?,00000000,00000000,?,00B33382,00B33382,?,?,?,00B3A2AA,00000001,00000001,E3E85006), ref: 00B3A0B3
                                      • MultiByteToWideChar.KERNEL32(00000001,00000001,?,?,00000000,?,?,?,?,00B3A2AA,00000001,00000001,E3E85006,?,?,?), ref: 00B3A139
                                      • WideCharToMultiByte.KERNEL32(00000001,00000000,00000000,00000000,?,E3E85006,00000000,00000000,?,00000400,00000000,?,00000000,00000000,00000000,00000000), ref: 00B3A233
                                      • __freea.LIBCMT ref: 00B3A240
                                        • Part of subcall function 00B35154: HeapAlloc.KERNEL32(00000000,?,?,?,00B31E90,?,0000015D,?,?,?,?,00B332E9,000000FF,00000000,?,?), ref: 00B35186
                                      • __freea.LIBCMT ref: 00B3A249
                                      • __freea.LIBCMT ref: 00B3A26E
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ByteCharMultiWide__freea$AllocHeap
                                      • String ID:
                                      • API String ID: 3147120248-0
                                      • Opcode ID: 270d7961d253d2795f874949bb973586f97d5932f43b01c0f723defd453f69a4
                                      • Instruction ID: 5b30d7927b62c57a31f96083aea796e44bbbf7312ceab7ae3ddafda0de491ea1
                                      • Opcode Fuzzy Hash: 270d7961d253d2795f874949bb973586f97d5932f43b01c0f723defd453f69a4
                                      • Instruction Fuzzy Hash: BE512172600206AFDB259F64CC82EBB77EAEB45750F3442A8FD44EB180EB75DC40C662
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(?), ref: 00B1F6D0
                                      • LeaveCriticalSection.KERNEL32(?,?), ref: 00B1F81D
                                      Strings
                                      • Failed to set update bundle., xrefs: 00B1F7F3
                                      • Failed to default local update source, xrefs: 00B1F742
                                      • update\%ls, xrefs: 00B1F72E
                                      • Failed to recreate command-line for update bundle., xrefs: 00B1F79C
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: Failed to default local update source$Failed to recreate command-line for update bundle.$Failed to set update bundle.$update\%ls
                                      • API String ID: 3168844106-1266646976
                                      • Opcode ID: fe49abf8013bd805be47f6b8d1f8d36a1bbab288908ddbafef7a399773277825
                                      • Instruction ID: d095ccf305d165c92d73ce008ae83d5810a0fd403712dcab8b87405786742c0c
                                      • Opcode Fuzzy Hash: fe49abf8013bd805be47f6b8d1f8d36a1bbab288908ddbafef7a399773277825
                                      • Instruction Fuzzy Hash: 9A41453194020AEFDF228F94C845EFABBE5EB04310F4182F9F905A61A1D771ADA0DB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • Sleep.KERNEL32(000007D0,00000000,00000000), ref: 00B18B0F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Sleep
                                      • String ID: Failed to calculate cache path.$Failed to get %hs package cache root directory.$Failed to get old %hs package cache root directory.$per-machine$per-user
                                      • API String ID: 3472027048-398165853
                                      • Opcode ID: 7df4784207b86e2a2e259652e7b671c9701046a5b125190a7881d99b272e6b96
                                      • Instruction ID: 14ee3e02c8b9e99820a2312e7551b718fa4c664ba60d6dae7a1e8ec5d34d5b97
                                      • Opcode Fuzzy Hash: 7df4784207b86e2a2e259652e7b671c9701046a5b125190a7881d99b272e6b96
                                      • Instruction Fuzzy Hash: 283128B2A04214BBEB21A6548C46FFFB7EDEF00711F9440E9FD05F7141DA758E8052A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • DefWindowProcW.USER32(?,00000082,?,?), ref: 00B1E734
                                      • SetWindowLongW.USER32(?,000000EB,00000000), ref: 00B1E743
                                      • SetWindowLongW.USER32(?,000000EB,?), ref: 00B1E757
                                      • DefWindowProcW.USER32(?,?,?,?), ref: 00B1E767
                                      • GetWindowLongW.USER32(?,000000EB), ref: 00B1E781
                                      • PostQuitMessage.USER32(00000000), ref: 00B1E7DE
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Window$Long$Proc$MessagePostQuit
                                      • String ID:
                                      • API String ID: 3812958022-0
                                      • Opcode ID: 5fa9d9487d7174c8ad1337c020c92433e900dd14fa2c8a245a1742e8b0417eef
                                      • Instruction ID: ffe42df516c709e4efcea6872806e0c6f40f9c17ca90d35178e3be839716cea4
                                      • Opcode Fuzzy Hash: 5fa9d9487d7174c8ad1337c020c92433e900dd14fa2c8a245a1742e8b0417eef
                                      • Instruction Fuzzy Hash: E621B036104218BFEF115FA4DC48EAA3BE9FF45750F944564FE16AA1A0C730DE50DB61
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Strings
                                      • Failed to save state., xrefs: 00B1C661
                                      • elevation.cpp, xrefs: 00B1C788
                                      • Unexpected elevated message sent to child process, msg: %u, xrefs: 00B1C794
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseHandleMutexRelease
                                      • String ID: Failed to save state.$Unexpected elevated message sent to child process, msg: %u$elevation.cpp
                                      • API String ID: 4207627910-1576875097
                                      • Opcode ID: dd45a9d195000133ce194ede35b91dd6aecff888a3e5edc9d9e81fa1970fe067
                                      • Instruction ID: 24a04d3c6f206bcf390b607f843b60e7484e360132f6308ca6a60b3bcbb78bf1
                                      • Opcode Fuzzy Hash: dd45a9d195000133ce194ede35b91dd6aecff888a3e5edc9d9e81fa1970fe067
                                      • Instruction Fuzzy Hash: 7D61E53A140604EFCB225F94C985C95BFF2FF093107618598FA695A672CB32ED60EF41
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegQueryValueExW.ADVAPI32(00000000,000002C0,00000000,000002C0,00000000,00000000,000002C0,BundleUpgradeCode,00000410,000002C0,00000000,00000000,00000000,00000100,00000000), ref: 00B410ED
                                      • RegQueryValueExW.ADVAPI32(?,00000000,00000000,?,?,?,?,?,?,00B16EF3,00000100,000000B0,00000088,00000410,000002C0), ref: 00B41126
                                      • lstrlenW.KERNEL32(?,?,?,00000000,?,-00000001,00000004,00000000), ref: 00B4121A
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: QueryValue$lstrlen
                                      • String ID: BundleUpgradeCode$regutil.cpp
                                      • API String ID: 3790715954-1648651458
                                      • Opcode ID: 312b15bd588ec5554cddac263b9c0b1f8cef46aa79ff3c68e0c3024699e272a5
                                      • Instruction ID: afaddabc57c344f088459da521aaa79084d90504ca9b93c4de3e5ee70386ae43
                                      • Opcode Fuzzy Hash: 312b15bd588ec5554cddac263b9c0b1f8cef46aa79ff3c68e0c3024699e272a5
                                      • Instruction Fuzzy Hash: B741A531E0021EAFDB258FA9C884EAEB7F9EF44710F1145A9ED05EB250D670DE419B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B447D3: SetFilePointerEx.KERNELBASE(?,?,?,?,?,00000000,?,?,?,00B18564,00000000,00000000,00000000,00000000,00000000), ref: 00B447EB
                                        • Part of subcall function 00B447D3: GetLastError.KERNEL32(?,?,?,00B18564,00000000,00000000,00000000,00000000,00000000), ref: 00B447F5
                                      • WriteFile.KERNEL32(?,?,00000000,?,00000000,?,00B45AC5,?,?,?,?,?,?,?,00010000,?), ref: 00B46263
                                      • WriteFile.KERNEL32(000000FF,00000008,00000008,?,00000000,000000FF,00000000,00000000,00000000,00000000,?,00B45AC5,?,?,?,?), ref: 00B462B5
                                      • GetLastError.KERNEL32(?,00B45AC5,?,?,?,?,?,?,?,00010000,?,00000001,?,GET,?,?), ref: 00B462FB
                                      • GetLastError.KERNEL32(?,00B45AC5,?,?,?,?,?,?,?,00010000,?,00000001,?,GET,?,?), ref: 00B46321
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLast$Write$Pointer
                                      • String ID: dlutil.cpp
                                      • API String ID: 133221148-2067379296
                                      • Opcode ID: 1b8b50db7d356ff286fad7c08ae88a9f76e562d0b3939be3ae2821bf64d46a40
                                      • Instruction ID: c56e7c97f988a577a28e58d308466c4bf7df883c65255efce4bb717b75038b1d
                                      • Opcode Fuzzy Hash: 1b8b50db7d356ff286fad7c08ae88a9f76e562d0b3939be3ae2821bf64d46a40
                                      • Instruction Fuzzy Hash: A3418D72A00229BFEF218EA8CD44BAA7BE8FF05351F144165FD04E6090D775DE60EBA5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WideCharToMultiByte.KERNEL32(00000000,00000000,00B3FEE7,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00B3FEE7,?,00000000,00000000), ref: 00B0247C
                                      • GetLastError.KERNEL32(?,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00B3FEE7,?,00000000,00000000,0000FDE9), ref: 00B02488
                                        • Part of subcall function 00B03B51: GetProcessHeap.KERNEL32(00000000,000001C7,?,00B021DC,000001C7,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B03B59
                                        • Part of subcall function 00B03B51: HeapSize.KERNEL32(00000000,?,00B021DC,000001C7,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B03B60
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$ByteCharErrorLastMultiProcessSizeWide
                                      • String ID: strutil.cpp
                                      • API String ID: 3662877508-3612885251
                                      • Opcode ID: b003d8ebe600e0bd2d49a467c25fe118f5b8d69eac2ba8d6ceb09f70f9af34b6
                                      • Instruction ID: 7a9f56eb557ee07dd65d7167a33cf6b19d7791bfa3ce98be7eafbb186ab9f434
                                      • Opcode Fuzzy Hash: b003d8ebe600e0bd2d49a467c25fe118f5b8d69eac2ba8d6ceb09f70f9af34b6
                                      • Instruction Fuzzy Hash: 2331E431200309AFEB109F798CC8A7A7ADDEF54768B1042A9FE11DB2E0EB71CC448764
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      • Failed to extract payload: %ls from container: %ls, xrefs: 00B2ABE3
                                      • Failed to open container: %ls., xrefs: 00B2AB2A
                                      • Failed to extract all payloads from container: %ls, xrefs: 00B2AB9C
                                      • Failed to skip the extraction of payload: %ls from container: %ls, xrefs: 00B2ABEF
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateErrorFileLast
                                      • String ID: Failed to extract all payloads from container: %ls$Failed to extract payload: %ls from container: %ls$Failed to open container: %ls.$Failed to skip the extraction of payload: %ls from container: %ls
                                      • API String ID: 1214770103-3891707333
                                      • Opcode ID: 9d2305c55fb7fac87ab57ab6b5cb125eb7101276c286d2066821f444d1812dae
                                      • Instruction ID: 0102aebf780e55479df0cb009b7e36f660d9a273973bf52017b012089bc6982b
                                      • Opcode Fuzzy Hash: 9d2305c55fb7fac87ab57ab6b5cb125eb7101276c286d2066821f444d1812dae
                                      • Instruction Fuzzy Hash: E131E632C00129BBCF11AAD4DC86E8E7BE9EF04711F1042E5FE25B6191D730DA54DB92
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • MoveFileExW.KERNEL32(00000003,00000001,00000000,00000000,00000101,?,00B44203,00000003,00000001,00000001,000007D0,00000003,00000000,?,00B19E5F,00000000), ref: 00B440ED
                                      • GetLastError.KERNEL32(00000001,?,00B44203,00000003,00000001,00000001,000007D0,00000003,00000000,?,00B19E5F,00000000,000007D0,00000001,00000001,00000003), ref: 00B440FC
                                      • MoveFileExW.KERNEL32(00000003,00000001,000007D0,00000001,00000000,?,00B44203,00000003,00000001,00000001,000007D0,00000003,00000000,?,00B19E5F,00000000), ref: 00B4417F
                                      • GetLastError.KERNEL32(?,00B44203,00000003,00000001,00000001,000007D0,00000003,00000000,?,00B19E5F,00000000,000007D0,00000001,00000001,00000003,000007D0), ref: 00B44189
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastMove
                                      • String ID: fileutil.cpp
                                      • API String ID: 55378915-2967768451
                                      • Opcode ID: b4d0282e8d7f12ea542fa7b10c3ef894ae528f1fc629613e4ba4df0b77f064d2
                                      • Instruction ID: 8c3789ecc8249c86cbd8c11d59a1b270a15b435a8d590e87ebd8860a56fad0e9
                                      • Opcode Fuzzy Hash: b4d0282e8d7f12ea542fa7b10c3ef894ae528f1fc629613e4ba4df0b77f064d2
                                      • Instruction Fuzzy Hash: B4210636600735A7EB211E659C41B7F7AD4EB657A1F024166FD05B7150DB308EA1A2E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B44315: FindFirstFileW.KERNEL32(00B28FFA,?,000002C0,00000000,00000000), ref: 00B44350
                                        • Part of subcall function 00B44315: FindClose.KERNEL32(00000000), ref: 00B4435C
                                      • RegCloseKey.ADVAPI32(?,00000000,?,00000000,?,00000000,?,00000000,?,wininet.dll), ref: 00B44305
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                        • Part of subcall function 00B410C5: RegQueryValueExW.ADVAPI32(00000000,000002C0,00000000,000002C0,00000000,00000000,000002C0,BundleUpgradeCode,00000410,000002C0,00000000,00000000,00000000,00000100,00000000), ref: 00B410ED
                                        • Part of subcall function 00B410C5: RegQueryValueExW.ADVAPI32(?,00000000,00000000,?,?,?,?,?,?,00B16EF3,00000100,000000B0,00000088,00000410,000002C0), ref: 00B41126
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseFindQueryValue$FileFirstOpen
                                      • String ID: PendingFileRenameOperations$SYSTEM\CurrentControlSet\Control\Session Manager$\$crypt32.dll
                                      • API String ID: 3397690329-3978359083
                                      • Opcode ID: 0982f2c04544f9aebc7f21906ab518133c221f74f55083e084c0b9e4b78b78ec
                                      • Instruction ID: 5f45874c887d2334bd0170ec9dc028beb64d6347718915bf464f9314fdc1a321
                                      • Opcode Fuzzy Hash: 0982f2c04544f9aebc7f21906ab518133c221f74f55083e084c0b9e4b78b78ec
                                      • Instruction Fuzzy Hash: 2A31E235A10209BBDF20AFD1CD41BAEBBF9EF00750F2481EAF900A6151D7B18B60EB54
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,00000001,000000FF,?,000000FF,00000001,PackageVersion,00000001,?,00B104CB,00000001,00000001,00000001,00B104CB,00000000), ref: 00B0EF70
                                      • RegCloseKey.ADVAPI32(00000000,00000001,PackageVersion,00000001,?,00B104CB,00000001,00000001,00000001,00B104CB,00000000,00000001,00000002,00B104CB,00000001), ref: 00B0EF87
                                      Strings
                                      • Failed to format key for update registration., xrefs: 00B0EF26
                                      • Failed to remove update registration key: %ls, xrefs: 00B0EFB4
                                      • PackageVersion, xrefs: 00B0EF51
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCompareString
                                      • String ID: Failed to format key for update registration.$Failed to remove update registration key: %ls$PackageVersion
                                      • API String ID: 446873843-3222553582
                                      • Opcode ID: 571f482dd5445fce6b8ebf339c34552637416bc71e9691157249fe07cbd08d04
                                      • Instruction ID: 4a544cd02a40b860ea2146934cbbf381098551347abafc118462a22373725365
                                      • Opcode Fuzzy Hash: 571f482dd5445fce6b8ebf339c34552637416bc71e9691157249fe07cbd08d04
                                      • Instruction Fuzzy Hash: 4521D532901619BBDB21ABA4CD45E9FBFF8EF00751F1045E9FA20B6190DB30DE409690
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B0EE4A
                                        • Part of subcall function 00B44038: SetFileAttributesW.KERNEL32(00B28FFA,00000080,00000000,00B28FFA,000000FF,00000000,?,?,00B28FFA), ref: 00B44067
                                        • Part of subcall function 00B44038: GetLastError.KERNEL32(?,?,00B28FFA), ref: 00B44071
                                        • Part of subcall function 00B03B6A: RemoveDirectoryW.KERNEL32(00000001,00000000,00000000,00000000,?,?,00B0EE95,00000001,00000000,00000095,00000001,00B104DA,00000095,00000000,swidtag,00000001), ref: 00B03B87
                                      Strings
                                      • Failed to format tag folder path., xrefs: 00B0EEB7
                                      • Failed to allocate regid folder path., xrefs: 00B0EEB0
                                      • swidtag, xrefs: 00B0EE59
                                      • Failed to allocate regid file path., xrefs: 00B0EEA9
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AttributesDirectoryErrorFileLastOpen@16Remove
                                      • String ID: Failed to allocate regid file path.$Failed to allocate regid folder path.$Failed to format tag folder path.$swidtag
                                      • API String ID: 1428973842-4170906717
                                      • Opcode ID: 4b6ce877148f532af42de8e60f7f995ca0542a46c20c0db0a2cdaf41b1daf06b
                                      • Instruction ID: 18195bb7ed45c08f1ba3f92a4a840ecda6fa32b33ce9dc49a48ede612f5f71cf
                                      • Opcode Fuzzy Hash: 4b6ce877148f532af42de8e60f7f995ca0542a46c20c0db0a2cdaf41b1daf06b
                                      • Instruction Fuzzy Hash: 93214B32D00618BBCB15EB99C841A9EBFF5EF44710F14C5E6F924AA2A1D7319E90AB50
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      • CompareStringW.KERNEL32(00000000,00000001,00000000,000000FF,?,000000FF,00000000,00000000,00000000,-80000001,SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall,00020019,00000000,00000100,00000100,000001B4), ref: 00B28BF7
                                      • RegCloseKey.ADVAPI32(00000000,-80000001,SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall,00020019,00000000,00000100,00000100,000001B4,?,?,?,00B0F66B,00000001,00000100,000001B4,00000000), ref: 00B28C45
                                      Strings
                                      • Failed to open uninstall registry key., xrefs: 00B28BBA
                                      • SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall, xrefs: 00B28B94
                                      • Failed to enumerate uninstall key for related bundles., xrefs: 00B28C56
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCompareOpenString
                                      • String ID: Failed to enumerate uninstall key for related bundles.$Failed to open uninstall registry key.$SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
                                      • API String ID: 2817536665-2531018330
                                      • Opcode ID: bca7333fd854ecb4a00f9525f7fb598acee5a959dff8290d472b4e5babcf6317
                                      • Instruction ID: 2db3f039a21bffc0a09615f17756d2bc95b1214d5b4a864e2abaea9d0139c8bd
                                      • Opcode Fuzzy Hash: bca7333fd854ecb4a00f9525f7fb598acee5a959dff8290d472b4e5babcf6317
                                      • Instruction Fuzzy Hash: 6921B736912128FFDF156BA4DC45FAEBAF9EB00321F2446E4F9147A0A0CB754F90E690
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CopyFileW.KERNEL32(00000000,00B04CB6,00000000,?,?,00000000,?,00B44012,00000000,00B04CB6,00000000,00000000,?,00B183E2,?,?), ref: 00B43F1E
                                      • GetLastError.KERNEL32(?,00B44012,00000000,00B04CB6,00000000,00000000,?,00B183E2,?,?,00000001,00000003,000007D0,?,?,?), ref: 00B43F2C
                                      • CopyFileW.KERNEL32(00000000,00B04CB6,00000000,00B04CB6,00000000,?,00B44012,00000000,00B04CB6,00000000,00000000,?,00B183E2,?,?,00000001), ref: 00B43F92
                                      • GetLastError.KERNEL32(?,00B44012,00000000,00B04CB6,00000000,00000000,?,00B183E2,?,?,00000001,00000003,000007D0,?,?,?), ref: 00B43F9C
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CopyErrorFileLast
                                      • String ID: fileutil.cpp
                                      • API String ID: 374144340-2967768451
                                      • Opcode ID: 1a2c7941f1aec1f1d24161fc2a3ca48cfafe92f5274dc5cc3e0c34fbf39f8b37
                                      • Instruction ID: 962b45e2317c8398b4bd99646043ab52a1a8d4a799dde1d9a9e09047edb46d20
                                      • Opcode Fuzzy Hash: 1a2c7941f1aec1f1d24161fc2a3ca48cfafe92f5274dc5cc3e0c34fbf39f8b37
                                      • Instruction Fuzzy Hash: 5D210B36E04632AAEB201F654C44B7B76F8EF50F60F1940A6FD05D7150DB20CF05A2E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • VariantInit.OLEAUT32(?), ref: 00B431DD
                                      • SysAllocString.OLEAUT32(?), ref: 00B431F9
                                      • VariantClear.OLEAUT32(?), ref: 00B43280
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B4328B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: StringVariant$AllocClearFreeInit
                                      • String ID: xmlutil.cpp
                                      • API String ID: 760788290-1270936966
                                      • Opcode ID: e10fc66e123c6ee61d796048c01f22f98de16220731cd61018afb6ed064cdef4
                                      • Instruction ID: cc522e728cb11dbf691911711f3198c532a830403c47035497fa8254d4484de8
                                      • Opcode Fuzzy Hash: e10fc66e123c6ee61d796048c01f22f98de16220731cd61018afb6ed064cdef4
                                      • Instruction Fuzzy Hash: 41219135901219EFCB14DFA8C848EAEBBF9EF44B10F194198F905AB220CB71DF409B91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • WaitForSingleObject.KERNEL32(?,000000FF), ref: 00B2D0DC
                                      • ReleaseMutex.KERNEL32(?), ref: 00B2D10A
                                      • SetEvent.KERNEL32(?), ref: 00B2D113
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateEventMutexObjectProcessReleaseSingleWait
                                      • String ID: Failed to allocate buffer.$NetFxChainer.cpp
                                      • API String ID: 944053411-3611226795
                                      • Opcode ID: aadd1718aa0777865dfc20338367cf97a61c2d108ca85acfb9d08b655c52f415
                                      • Instruction ID: 57476e1bbdfacd7cc36e6f3537d0f4a7beced3ff6d356f3968e1a5d4cbd88e66
                                      • Opcode Fuzzy Hash: aadd1718aa0777865dfc20338367cf97a61c2d108ca85acfb9d08b655c52f415
                                      • Instruction Fuzzy Hash: EE21A3B4600319BFDB109F68D849E9ABBF5FF08314F1086A9FA24A7361C775E950CB51
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • QueryServiceConfigW.ADVAPI32(00000000,00000000,00000000,?,00000001,00000000,?,?,00B268CE,00000000,?), ref: 00B457D5
                                      • GetLastError.KERNEL32(?,?,00B268CE,00000000,?,?,?,?,?,?,?,?,?,00B26CE1,?,?), ref: 00B457E3
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • QueryServiceConfigW.ADVAPI32(00000000,00000000,?,?,?,00000001,?,?,00B268CE,00000000,?), ref: 00B4581D
                                      • GetLastError.KERNEL32(?,?,00B268CE,00000000,?,?,?,?,?,?,?,?,?,00B26CE1,?,?), ref: 00B45827
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ConfigErrorHeapLastQueryService$AllocateProcess
                                      • String ID: svcutil.cpp
                                      • API String ID: 355237494-1746323212
                                      • Opcode ID: d193984a8211a917499a9970b2a05443f64feb4f0c2214227da07deece87e098
                                      • Instruction ID: 46ad5372eb44a65d5ed91379182522570bcac9105f41f12924261deccf2499e9
                                      • Opcode Fuzzy Hash: d193984a8211a917499a9970b2a05443f64feb4f0c2214227da07deece87e098
                                      • Instruction Fuzzy Hash: C521C636A40A24BBEB305A664D04FAB7BECDF55B90F110195FD05E7151DE61CF00E6E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: _memcpy_s
                                      • String ID: Failed to find variable.$Failed to parse condition '%ls' at position: %u$Failed to read next symbol.$condition.cpp
                                      • API String ID: 2001391462-1605196437
                                      • Opcode ID: 1753bc5010771aa92b223e5da3ce5aa99baa1372e24a3e29c819625cb215297b
                                      • Instruction ID: 4851028c3130e207af1d4765d42c37f7a08260ad701f1d24865c6e0831cd512b
                                      • Opcode Fuzzy Hash: 1753bc5010771aa92b223e5da3ce5aa99baa1372e24a3e29c819625cb215297b
                                      • Instruction Fuzzy Hash: B4110A336902207BDB153D68DC86E9B7ED4DB45710F0440E5FA04AE2E3CBA2DE10A2E2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 00B09D25
                                      Strings
                                      • Failed get file version., xrefs: 00B09D65
                                      • Failed to set variable., xrefs: 00B09D84
                                      • Failed to format path string., xrefs: 00B09D30
                                      • File search: %ls, did not find path: %ls, xrefs: 00B09D90
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open@16
                                      • String ID: Failed get file version.$Failed to format path string.$Failed to set variable.$File search: %ls, did not find path: %ls
                                      • API String ID: 3613110473-2458530209
                                      • Opcode ID: 21f0ea9d9a530bbb19a15097369d0780e6e5ced5e8fa7e6925749508df741c53
                                      • Instruction ID: f7c3a7ffa9c4f3ca577144f50d0fefa1c19934eaa699bf2bc02ef9aef78dcd63
                                      • Opcode Fuzzy Hash: 21f0ea9d9a530bbb19a15097369d0780e6e5ced5e8fa7e6925749508df741c53
                                      • Instruction Fuzzy Hash: 46118432D80129BECF126E94DC819AEFFA9EF04360F1042F6F90476162D6319F10A7D1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WriteFile.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,?,00000000,00000000,00000000,?,00000000,00000000,00000000,?,00B151A4), ref: 00B148CC
                                      Strings
                                      • pipe.cpp, xrefs: 00B14904
                                      • Failed to allocate message to write., xrefs: 00B148AB
                                      • Failed to write message type to pipe., xrefs: 00B1490E
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FileWrite
                                      • String ID: Failed to allocate message to write.$Failed to write message type to pipe.$pipe.cpp
                                      • API String ID: 3934441357-1996674626
                                      • Opcode ID: 9f0186cfdc6bef1e4311a290d433e2902e40f9638257128d044e1908a891d9a1
                                      • Instruction ID: dd37fe60f4a95f98d8199da4215e48a20d4f30f9a866173f88b764ed1697736b
                                      • Opcode Fuzzy Hash: 9f0186cfdc6bef1e4311a290d433e2902e40f9638257128d044e1908a891d9a1
                                      • Instruction Fuzzy Hash: 11119A72A00218BEEB219F95DD09FDF7BE9EB40791F1101A6FD00B2250DB709E90D6A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • CreateWellKnownSid.ADVAPI32(00000000,00000000,00000000,00000000,00000044,00000001,00000000,00000000,?,?,00B18C10,0000001A,00000000,?,00000000,00000000), ref: 00B1804C
                                      • GetLastError.KERNEL32(?,?,00B18C10,0000001A,00000000,?,00000000,00000000,?,?,00000000,00000000,?,?,-00000004,00000000), ref: 00B18056
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateCreateErrorKnownLastProcessWell
                                      • String ID: Failed to allocate memory for well known SID.$Failed to create well known SID.$cache.cpp
                                      • API String ID: 2186923214-2110050797
                                      • Opcode ID: d71912e8873230725e81c0420bc9c20d47870350381bcc411f09353907b80d67
                                      • Instruction ID: 8c75cfbe423a3e8c7af42ddbb24f1c4074d6f10b028387adb92f3d8414c2bea0
                                      • Opcode Fuzzy Hash: d71912e8873230725e81c0420bc9c20d47870350381bcc411f09353907b80d67
                                      • Instruction Fuzzy Hash: D1018836A403287AE72066295C0EF9B6BDCDF40B21F1100DAFE04AB190EEB08E4192E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • MsgWaitForMultipleObjects.USER32(00000001,?,00000000,000003E8,000004FF), ref: 00B2DB95
                                      • PeekMessageW.USER32(?,00000000,00000000,00000000,00000000), ref: 00B2DBBF
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00B2DD8F,00000000,?,?,?,00000001,00000000), ref: 00B2DBC7
                                      Strings
                                      • Failed while waiting for download., xrefs: 00B2DBF5
                                      • bitsuser.cpp, xrefs: 00B2DBEB
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastMessageMultipleObjectsPeekWait
                                      • String ID: Failed while waiting for download.$bitsuser.cpp
                                      • API String ID: 435350009-228655868
                                      • Opcode ID: 8b5fa8f0662403e607562f14c81e4b73d99be8a108629e2c051cd1c022f06da4
                                      • Instruction ID: 8c18215f1f2ca29d0e1913bd3bb4b4483179ea8924aeceaa58e4f94ef27a85ff
                                      • Opcode Fuzzy Hash: 8b5fa8f0662403e607562f14c81e4b73d99be8a108629e2c051cd1c022f06da4
                                      • Instruction Fuzzy Hash: F3110C33B413357BE7205AB9AC49EEB7AECEB05720F010165FE08E71D4D9649E0085E4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ShellExecuteExW.SHELL32(?), ref: 00B43B98
                                      • GetLastError.KERNEL32(?,?,00000000), ref: 00B43BA2
                                      • CloseHandle.KERNEL32(?,?,?,00000000), ref: 00B43BD5
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseErrorExecuteHandleLastShell
                                      • String ID: <$shelutil.cpp
                                      • API String ID: 3023784893-3991740012
                                      • Opcode ID: 89267940102e770df26c74b2d0f44e1019f90548a800f0ce3f7f297b6cdbc2a0
                                      • Instruction ID: d3742916774236e6c2fc6da351858b32aa9e1a4d44f214fd62cbbb2985a3d61a
                                      • Opcode Fuzzy Hash: 89267940102e770df26c74b2d0f44e1019f90548a800f0ce3f7f297b6cdbc2a0
                                      • Instruction Fuzzy Hash: 6211D6B5E01219ABDB10DFA9D845A9EBBF8EB08750F10416AFD09E7350E7349A00DBA4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetComputerNameW.KERNEL32(?,00000010), ref: 00B05E39
                                      • GetLastError.KERNEL32 ref: 00B05E43
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ComputerErrorLastName
                                      • String ID: Failed to get computer name.$Failed to set variant value.$variable.cpp
                                      • API String ID: 3560734967-484636765
                                      • Opcode ID: e728a9d9360c1f083e9e03c5ab1a2cacf40d3ac190ec46a5e46204655a2cefc8
                                      • Instruction ID: 4bea8a587680e538676b5b02223dabfbccdcbb22ac8b4460988f851d26fd9e7b
                                      • Opcode Fuzzy Hash: e728a9d9360c1f083e9e03c5ab1a2cacf40d3ac190ec46a5e46204655a2cefc8
                                      • Instruction Fuzzy Hash: FA01A932A416286BDB10EAA4AC45AEF77E8EB08710F014196FD05F7180DA749F0486E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B0997F
                                      Strings
                                      • Failed to copy condition string from BSTR, xrefs: 00B09969
                                      • Failed to get Condition inner text., xrefs: 00B0994F
                                      • Condition, xrefs: 00B0991A
                                      • Failed to select condition node., xrefs: 00B09936
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FreeString
                                      • String ID: Condition$Failed to copy condition string from BSTR$Failed to get Condition inner text.$Failed to select condition node.
                                      • API String ID: 3341692771-3600577998
                                      • Opcode ID: f687752a15ff4eec71433389b72e3d8a034264a22e626365a8650d7d5cb93a8a
                                      • Instruction ID: c954113fc8b5aa1910ddb98643dd883a5ef30c69aeeeeabd32bd851eaf33c364
                                      • Opcode Fuzzy Hash: f687752a15ff4eec71433389b72e3d8a034264a22e626365a8650d7d5cb93a8a
                                      • Instruction Fuzzy Hash: A9117C32950228BBDB169B94CD45BAEBFE8EF00720F1081D8F800B61A2DB719F00A781
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentProcess.KERNEL32(?), ref: 00B05D83
                                        • Part of subcall function 00B409BB: GetModuleHandleW.KERNEL32(kernel32,IsWow64Process,?,?,?,00B05D8F,00000000), ref: 00B409CF
                                        • Part of subcall function 00B409BB: GetProcAddress.KERNEL32(00000000), ref: 00B409D6
                                        • Part of subcall function 00B409BB: GetLastError.KERNEL32(?,?,?,00B05D8F,00000000), ref: 00B409ED
                                        • Part of subcall function 00B43BF7: SHGetFolderPathW.SHELL32(00000000,?,00000000,00000000,?), ref: 00B43C24
                                      Strings
                                      • Failed to set variant value., xrefs: 00B05DE7
                                      • Failed to get shell folder., xrefs: 00B05DB7
                                      • Failed to get 64-bit folder., xrefs: 00B05DCD
                                      • variable.cpp, xrefs: 00B05DAD
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressCurrentErrorFolderHandleLastModulePathProcProcess
                                      • String ID: Failed to get 64-bit folder.$Failed to get shell folder.$Failed to set variant value.$variable.cpp
                                      • API String ID: 2084161155-3906113122
                                      • Opcode ID: b17d9cea8a0e3013731d4f2936f5e9590502e5955f2426541e52965fc7134813
                                      • Instruction ID: 19fe6053c91b7732de12c1faeb13c2c9769eac3fd35c0735a196b942726a5b5d
                                      • Opcode Fuzzy Hash: b17d9cea8a0e3013731d4f2936f5e9590502e5955f2426541e52965fc7134813
                                      • Instruction Fuzzy Hash: 9601A531951628B7DF21B694DC0AF9F7EE8EB00710F1042E6F900B6591DBB49F40ABE1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WaitForSingleObject.KERNEL32(000000FF,?,00000000,?,?,00B04E16,?,000000FF,?,?,?,?,?,00000000,?,?), ref: 00B40927
                                      • GetLastError.KERNEL32(?,?,00B04E16,?,000000FF,?,?,?,?,?,00000000,?,?,?,?,?), ref: 00B40935
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastObjectSingleWait
                                      • String ID: procutil.cpp
                                      • API String ID: 1211598281-1178289305
                                      • Opcode ID: 743ddbb57c63acc3d4da906126e82f86addf823befa9b70306d29974c970bda0
                                      • Instruction ID: da9aa60c82d613d5174f4f1f85b515995db3545e88ceb29f7780f4f8c806131b
                                      • Opcode Fuzzy Hash: 743ddbb57c63acc3d4da906126e82f86addf823befa9b70306d29974c970bda0
                                      • Instruction Fuzzy Hash: BC11A536E10325EBEB20AFA98C48BAB7BE4EF05360F114255FE15E7251D7748E00E6E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B44315: FindFirstFileW.KERNEL32(00B28FFA,?,000002C0,00000000,00000000), ref: 00B44350
                                        • Part of subcall function 00B44315: FindClose.KERNEL32(00000000), ref: 00B4435C
                                      • SetFileAttributesW.KERNEL32(00B28FFA,00000080,00000000,00B28FFA,000000FF,00000000,?,?,00B28FFA), ref: 00B44067
                                      • GetLastError.KERNEL32(?,?,00B28FFA), ref: 00B44071
                                      • DeleteFileW.KERNEL32(00B28FFA,00000000,00B28FFA,000000FF,00000000,?,?,00B28FFA), ref: 00B44090
                                      • GetLastError.KERNEL32(?,?,00B28FFA), ref: 00B4409A
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: File$ErrorFindLast$AttributesCloseDeleteFirst
                                      • String ID: fileutil.cpp
                                      • API String ID: 3967264933-2967768451
                                      • Opcode ID: 17656657a599d1e41bc6da6bf697ea2b216f0f4e6d1fbc82c86de5ea850cbdbe
                                      • Instruction ID: e26e360fef1bbccee58d9efcef5f37856ef224d371a80587aab4945f2152108b
                                      • Opcode Fuzzy Hash: 17656657a599d1e41bc6da6bf697ea2b216f0f4e6d1fbc82c86de5ea850cbdbe
                                      • Instruction Fuzzy Hash: B1019231A01725A7DB315AB98D08F5B7ED8EF01761F004365FE05E7290DB61CF20A5E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(?), ref: 00B2D7E1
                                      • LeaveCriticalSection.KERNEL32(?), ref: 00B2D826
                                      • SetEvent.KERNEL32(?,?,?,?), ref: 00B2D83A
                                      Strings
                                      • Failure while sending progress during BITS job modification., xrefs: 00B2D815
                                      • Failed to get state during job modification., xrefs: 00B2D7FA
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterEventLeave
                                      • String ID: Failed to get state during job modification.$Failure while sending progress during BITS job modification.
                                      • API String ID: 3094578987-1258544340
                                      • Opcode ID: fe7138a0432f83c366af8803d14996449d5b46634144835d626f05149ae7ba90
                                      • Instruction ID: cc71553fc7a0e5cb390e6484a5508cb2b7480d74db5178e2c857ca8fb7494697
                                      • Opcode Fuzzy Hash: fe7138a0432f83c366af8803d14996449d5b46634144835d626f05149ae7ba90
                                      • Instruction Fuzzy Hash: 00019232515625ABCB019B55E849EAAB7ECFF08731B108299F908EB610DB74EE048BD5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00000008,?,00000000,00000000,00000000,?,00B2DBB5), ref: 00B2DA59
                                      • LeaveCriticalSection.KERNEL32(00000008,?,00B2DBB5), ref: 00B2DA9E
                                      • SetEvent.KERNEL32(?,?,00B2DBB5), ref: 00B2DAB2
                                      Strings
                                      • Failed to get BITS job state., xrefs: 00B2DA72
                                      • Failure while sending progress., xrefs: 00B2DA8D
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterEventLeave
                                      • String ID: Failed to get BITS job state.$Failure while sending progress.
                                      • API String ID: 3094578987-2876445054
                                      • Opcode ID: 4c98a54c1526fe0b8698c78b599dc54ca384db01bf4856c954f1795ca21832c0
                                      • Instruction ID: 009e4cbee5bee7cb7a34fa142a5bfcd0bcedbe41d372db1e78c9917c0b02d51d
                                      • Opcode Fuzzy Hash: 4c98a54c1526fe0b8698c78b599dc54ca384db01bf4856c954f1795ca21832c0
                                      • Instruction Fuzzy Hash: 70012872504625BBCB01DB55E849DAEB7E8FF19721B004296FA0DE3210DB34ED00C7D4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • InitializeCriticalSection.KERNEL32(00000008,00000000,00000000,?,00B2DD19,?,?,?,?,?,00000001,00000000,?), ref: 00B2D5C9
                                      • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,00B2DD19,?,?,?,?,?,00000001,00000000,?), ref: 00B2D5D4
                                      • GetLastError.KERNEL32(?,00B2DD19,?,?,?,?,?,00000001,00000000,?), ref: 00B2D5E1
                                      Strings
                                      • Failed to create BITS job complete event., xrefs: 00B2D60F
                                      • bitsuser.cpp, xrefs: 00B2D605
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateCriticalErrorEventInitializeLastSection
                                      • String ID: Failed to create BITS job complete event.$bitsuser.cpp
                                      • API String ID: 3069647169-3441864216
                                      • Opcode ID: b6493e62d3a1ceb2e2b4aa6a6285e07dce9a25c70cb1e2576373da459664145f
                                      • Instruction ID: b3dbeb875cbb1a473f96e2ec0fa192ee4632c964403b75dfb33dd36d937408ba
                                      • Opcode Fuzzy Hash: b6493e62d3a1ceb2e2b4aa6a6285e07dce9a25c70cb1e2576373da459664145f
                                      • Instruction Fuzzy Hash: E7015E76611726BBD710AF6AD805A87BED8FF49760B004126F908D7640EBB4D910CBE4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(000000D0,?,000000B8,00000000,?,00B16E4B,000000B8,00000000,?,00000000,7694B390), ref: 00B0D3AC
                                      • InterlockedCompareExchange.KERNEL32(000000E8,00000001,00000000), ref: 00B0D3BB
                                      • LeaveCriticalSection.KERNEL32(000000D0,?,00B16E4B,000000B8,00000000,?,00000000,7694B390), ref: 00B0D3D0
                                      Strings
                                      • userexperience.cpp, xrefs: 00B0D3E9
                                      • user active cannot be changed because it was already in that state., xrefs: 00B0D3F3
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$CompareEnterExchangeInterlockedLeave
                                      • String ID: user active cannot be changed because it was already in that state.$userexperience.cpp
                                      • API String ID: 3376869089-1544469594
                                      • Opcode ID: bf6db165314fbbe5523269ef727eafb634d7dc40c013256d207f36244239bb09
                                      • Instruction ID: da03559410279aac21412484a428847d636c2d395fe5ce9eca69446ac4dfb460
                                      • Opcode Fuzzy Hash: bf6db165314fbbe5523269ef727eafb634d7dc40c013256d207f36244239bb09
                                      • Instruction Fuzzy Hash: 28F0AF763103086BD7106EAAAC84E9B7BEDFB86B65700446ABA05D3290DA70EE058725
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcAddress.KERNEL32(SRSetRestorePointW,srclient.dll), ref: 00B41B53
                                      • GetLastError.KERNEL32(?,00B048D4,00000001,?,?,00B0444C,?,?,?,?,00B0535E,?,?,?,?), ref: 00B41B62
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressErrorLastProc
                                      • String ID: SRSetRestorePointW$srclient.dll$srputil.cpp
                                      • API String ID: 199729137-398595594
                                      • Opcode ID: 8f4a879bcfc83987bebead0e897c71140e24cf9f32deb9743fe16acf0166d8ad
                                      • Instruction ID: 48a226556dc6753bb59df4f74b945306b2f9b3f947d9aad143016ed274cdedf7
                                      • Opcode Fuzzy Hash: 8f4a879bcfc83987bebead0e897c71140e24cf9f32deb9743fe16acf0166d8ad
                                      • Instruction Fuzzy Hash: 86F0D676F4163197D722167D9C05B6669E4DB00791F0145B1ED01E72A0EE68CDC0A6E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,?,00B34848,00000000,?,00B347E8,00000000,00B67CF8,0000000C,00B3493F,00000000,00000002), ref: 00B348B7
                                      • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00B348CA
                                      • FreeLibrary.KERNEL32(00000000,?,?,?,00B34848,00000000,?,00B347E8,00000000,00B67CF8,0000000C,00B3493F,00000000,00000002), ref: 00B348ED
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressFreeHandleLibraryModuleProc
                                      • String ID: CorExitProcess$mscoree.dll
                                      • API String ID: 4061214504-1276376045
                                      • Opcode ID: 6155c809246b193c7bc04b3c2afb499d9706e0f10784c87f7dbf6d6ec4cca545
                                      • Instruction ID: 52ffbf57faf9a69f6e5030d660f7777f796689238f425beee4b0906e4b6479fc
                                      • Opcode Fuzzy Hash: 6155c809246b193c7bc04b3c2afb499d9706e0f10784c87f7dbf6d6ec4cca545
                                      • Instruction Fuzzy Hash: E1F04474610218BBCB119FA5EC19BADBFF8FF04711F1001A5F905A21A0DF749E40DB50
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      • RegCloseKey.ADVAPI32(00000001,00000001,?,00000000,00000001,?,00000000,00000001,00000000,00020019,00000001,00000000,00000000,00020019,00000000,00000001), ref: 00B49457
                                      • RegCloseKey.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000001,?,00000000,00000001,?,00000000,00000001,00000000,00020019), ref: 00B49492
                                      • RegCloseKey.ADVAPI32(00000001,00000001,00020019,00000000,00000000,00000000,00000000), ref: 00B494AE
                                      • RegCloseKey.ADVAPI32(00000000,00000001,00020019,00000000,00000000,00000000,00000000), ref: 00B494BB
                                      • RegCloseKey.ADVAPI32(00000000,00000001,00020019,00000000,00000000,00000000,00000000), ref: 00B494C8
                                        • Part of subcall function 00B40B49: RegCloseKey.ADVAPI32(00000000), ref: 00B40CA0
                                        • Part of subcall function 00B40E9B: RegQueryInfoKeyW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00B49444,00000001), ref: 00B40EB3
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Close$InfoOpenQuery
                                      • String ID:
                                      • API String ID: 796878624-0
                                      • Opcode ID: aeb8eb4954c1b52362b5f69ee4019fc80ee500563446439b2409bab729cdcdd6
                                      • Instruction ID: 085d8b2d92a4190ce1e56ff79f0c2ba1180c5be0fb065b5c9935bc6108c73fdd
                                      • Opcode Fuzzy Hash: aeb8eb4954c1b52362b5f69ee4019fc80ee500563446439b2409bab729cdcdd6
                                      • Instruction Fuzzy Hash: 0841F176C0112DFFDF21AF96DD819AEFBB5EF04764F1141A9EA0076221C7314F51AA90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenW.KERNEL32(?,?,00000000,00000000,?,?,00B08A9E,00B095E7,?,00B095E7,?,?,00B095E7,?,?), ref: 00B088FE
                                      • lstrlenW.KERNEL32(?,?,00000000,00000000,?,?,00B08A9E,00B095E7,?,00B095E7,?,?,00B095E7,?,?), ref: 00B08906
                                      • CompareStringW.KERNEL32(0000007F,?,?,?,?,00000000,?,00000000,00000000,?,?,00B08A9E,00B095E7,?,00B095E7,?), ref: 00B08955
                                      • CompareStringW.KERNEL32(0000007F,?,?,00000000,?,00000000,?,00000000,00000000,?,?,00B08A9E,00B095E7,?,00B095E7,?), ref: 00B089B7
                                      • CompareStringW.KERNEL32(0000007F,?,?,00000000,?,00000000,?,00000000,00000000,?,?,00B08A9E,00B095E7,?,00B095E7,?), ref: 00B089E4
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareString$lstrlen
                                      • String ID:
                                      • API String ID: 1657112622-0
                                      • Opcode ID: d222d12be5df0b0f6202bda5a215b71c86e59767379e91b229a0aa2db737ca7f
                                      • Instruction ID: 70e32f077214edd2f44879ec943a0d1f6444d549006d823dc0762dae00badaf9
                                      • Opcode Fuzzy Hash: d222d12be5df0b0f6202bda5a215b71c86e59767379e91b229a0aa2db737ca7f
                                      • Instruction Fuzzy Hash: 5E316472600109FFCF159F58CC84ABE3FA6EB49390F154095F99997250CA31CA90DB92
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • MultiByteToWideChar.KERNEL32(8007139F,00000000,?,?,00000000,00000000,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B02202
                                      • GetLastError.KERNEL32(?,00000000,00000000,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B0220E
                                        • Part of subcall function 00B03B51: GetProcessHeap.KERNEL32(00000000,000001C7,?,00B021DC,000001C7,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B03B59
                                        • Part of subcall function 00B03B51: HeapSize.KERNEL32(00000000,?,00B021DC,000001C7,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B03B60
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$ByteCharErrorLastMultiProcessSizeWide
                                      • String ID: strutil.cpp
                                      • API String ID: 3662877508-3612885251
                                      • Opcode ID: 3d5079d1fa1733730c215827c7f09c65a4f8e6de830596cb907f6c1b4422e076
                                      • Instruction ID: 72527fb33b4d185a29ecb36a61d1b7aeba8acc9b8de7f913203ae563d0f845dd
                                      • Opcode Fuzzy Hash: 3d5079d1fa1733730c215827c7f09c65a4f8e6de830596cb907f6c1b4422e076
                                      • Instruction Fuzzy Hash: A331DA32700216ABEB109BA9CC8CA677FD9EF45764B1142A5FD15DB2E0EA30CD04D7A0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00B052B5,WixBundleOriginalSource,?,?,00B1A41D,00B053B5,WixBundleOriginalSource,00B0533D,00B6AA90,?,00000000,00B0533D,?,00B17587,?,?), ref: 00B0739A
                                      • LeaveCriticalSection.KERNEL32(00B052B5,00B052B5,00000000,00000000,?,?,00B1A41D,00B053B5,WixBundleOriginalSource,00B0533D,00B6AA90,?,00000000,00B0533D,?,00B17587), ref: 00B07401
                                      Strings
                                      • Failed to get value as string for variable: %ls, xrefs: 00B073F0
                                      • Failed to get value of variable: %ls, xrefs: 00B073D4
                                      • WixBundleOriginalSource, xrefs: 00B07396
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: Failed to get value as string for variable: %ls$Failed to get value of variable: %ls$WixBundleOriginalSource
                                      • API String ID: 3168844106-30613933
                                      • Opcode ID: c20b99ed59bffe75e95d0a4bcc6d3e969f3ff16f659510f638310e9a7de41893
                                      • Instruction ID: 5cea663c33d070534a771db13c398ed51b30fffefed1e88b18cb04dd896a124c
                                      • Opcode Fuzzy Hash: c20b99ed59bffe75e95d0a4bcc6d3e969f3ff16f659510f638310e9a7de41893
                                      • Instruction Fuzzy Hash: E501B132D95128FBDF115F54DC05E9EBFA4EB10760F1080A4FD04AA260DB35AE21BBD4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CloseHandle.KERNEL32(?,00000000,?,00000000,?,00B2CEEB,00000000), ref: 00B2CF10
                                      • CloseHandle.KERNEL32(00000000,00000000,?,00000000,?,00B2CEEB,00000000), ref: 00B2CF1C
                                      • CloseHandle.KERNEL32(00B4B508,00000000,?,00000000,?,00B2CEEB,00000000), ref: 00B2CF29
                                      • CloseHandle.KERNEL32(00000000,00000000,?,00000000,?,00B2CEEB,00000000), ref: 00B2CF36
                                      • UnmapViewOfFile.KERNEL32(00B4B4D8,00000000,?,00B2CEEB,00000000), ref: 00B2CF45
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseHandle$FileUnmapView
                                      • String ID:
                                      • API String ID: 260491571-0
                                      • Opcode ID: 82f9818810199be8b4958ead150831222f5da462387e02cd6790ae09391dbe6c
                                      • Instruction ID: ef69845370b12130100b0d3b6dc4fc183dbeb05144df24c9a75c57f202ed1dab
                                      • Opcode Fuzzy Hash: 82f9818810199be8b4958ead150831222f5da462387e02cd6790ae09391dbe6c
                                      • Instruction Fuzzy Hash: D901F676404B29DFCB306F6AED9081AFBEAFF50711315C87EE29A52921C771A844DF90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B47B2C
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B47B37
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B47B42
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FreeString$Heap$AllocateProcess
                                      • String ID: atomutil.cpp
                                      • API String ID: 2724874077-4059165915
                                      • Opcode ID: 584413a39830da4271c7eb701386fda4f94f3e5a12243333e845846c88e5b8cb
                                      • Instruction ID: 18fe8119b1667460e575439be5fc1153f81aab2b3965cc3508ead6f58e3b38a4
                                      • Opcode Fuzzy Hash: 584413a39830da4271c7eb701386fda4f94f3e5a12243333e845846c88e5b8cb
                                      • Instruction Fuzzy Hash: 90516C71A4422AAFDB21DB64C894FAEB7F8EF44754F1545E4E905AB250DF30DE00EBA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SystemTimeToFileTime.KERNEL32(?,00000000,00000000,clbcatq.dll,00000000,clbcatq.dll,00000000,00000000,00000000), ref: 00B486D8
                                      • GetLastError.KERNEL32 ref: 00B486E2
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Time$ErrorFileLastSystem
                                      • String ID: clbcatq.dll$timeutil.cpp
                                      • API String ID: 2781989572-961924111
                                      • Opcode ID: 4efce39ee56135c06b019ea077f65e0add412bb0145091e8c6c81a9b4de26eed
                                      • Instruction ID: 44cba2fbb258c35fd4acb1102c44fd532bf8654d444654d1a6bcbf3fa9db3682
                                      • Opcode Fuzzy Hash: 4efce39ee56135c06b019ea077f65e0add412bb0145091e8c6c81a9b4de26eed
                                      • Instruction Fuzzy Hash: 31410571E4021576EB60AFB88C85BBF77E9EF80700F124199BA01A7290DE31CF00A7A5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • VariantInit.OLEAUT32(000002C0), ref: 00B435BE
                                      • SysAllocString.OLEAUT32(?), ref: 00B435CE
                                      • VariantClear.OLEAUT32(?), ref: 00B436AF
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Variant$AllocClearInitString
                                      • String ID: xmlutil.cpp
                                      • API String ID: 2213243845-1270936966
                                      • Opcode ID: 603973a60a70e474e75995a89c7793bf3ce4c5a9dcb9b192c1eabcd9c1dde781
                                      • Instruction ID: 08bc3507bb9063b9dc37b66d4398b8c600480ec7e094b1b2dca1efd355e8f99e
                                      • Opcode Fuzzy Hash: 603973a60a70e474e75995a89c7793bf3ce4c5a9dcb9b192c1eabcd9c1dde781
                                      • Instruction Fuzzy Hash: 9D415675900626ABCB119FA5C888EAFBBF8EF45710B0645E5FD05EB311D734DE009BA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegEnumKeyExW.ADVAPI32(00000000,000002C0,00000410,00000002,00000000,00000000,00000000,00000000,00000410,00000002,00000100,00000000,00000000,?,?,00B28BD8), ref: 00B40D77
                                      • RegQueryInfoKeyW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000002,00000000,00000000,00000000,00000000,00000000,00000000,?,?,00B28BD8,00000000), ref: 00B40D99
                                      • RegEnumKeyExW.ADVAPI32(00000000,000002C0,00000410,00000002,00000000,00000000,00000000,00000000,00000410,00000003,?,?,00B28BD8,00000000,00000000,00000000), ref: 00B40DF1
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Enum$InfoQuery
                                      • String ID: regutil.cpp
                                      • API String ID: 73471667-955085611
                                      • Opcode ID: 79c54a99e0c783c49cc5e8314c672f9621bf39f5736be8bf67a094795ce74aab
                                      • Instruction ID: e56d5622633ebcdc4d5b05428dd4e481c71c8c13121aa1cd11c4e8b73ff3fbdc
                                      • Opcode Fuzzy Hash: 79c54a99e0c783c49cc5e8314c672f9621bf39f5736be8bf67a094795ce74aab
                                      • Instruction Fuzzy Hash: F63183B6D01129FFEB219AD9CD84EABBBECEF04750F1144A5BE04E7150D7719E10A6A0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B479AA
                                      • SysFreeString.OLEAUT32(?), ref: 00B479B5
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B479C0
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FreeString$Heap$AllocateProcess
                                      • String ID: atomutil.cpp
                                      • API String ID: 2724874077-4059165915
                                      • Opcode ID: d07051f69ef8d79e42108e9e25bd0d948a3c2532f91d47a7af8d8a9255e0b12c
                                      • Instruction ID: bd9528c8a4e286d24f7fc9ac744de11029c2cf9e45f1386a54fafe6920f80686
                                      • Opcode Fuzzy Hash: d07051f69ef8d79e42108e9e25bd0d948a3c2532f91d47a7af8d8a9255e0b12c
                                      • Instruction Fuzzy Hash: D8315472D45629BBDF129B64CC45AAEBBF8EF44710F0541E1E900AB250DB71DE04EB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      • RegCloseKey.ADVAPI32(00000000,00000000,00000088,00000000,000002C0,00000410,00020019,00000000,000002C0,00000000,?,?,?,00B28C14,00000000,00000000), ref: 00B2898C
                                      Strings
                                      • Failed to ensure there is space for related bundles., xrefs: 00B2893F
                                      • Failed to open uninstall key for potential related bundle: %ls, xrefs: 00B288FB
                                      • Failed to initialize package from related bundle id: %ls, xrefs: 00B28972
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseOpen
                                      • String ID: Failed to ensure there is space for related bundles.$Failed to initialize package from related bundle id: %ls$Failed to open uninstall key for potential related bundle: %ls
                                      • API String ID: 47109696-1717420724
                                      • Opcode ID: 89ade0de0651c4ac4743f9dd4f821c4e6590319001c0ec5a5ad968702c9707e0
                                      • Instruction ID: 2001b2a284344fd568a4716b80b91ef9f05855aa939076ac699c8b4ef84a5f00
                                      • Opcode Fuzzy Hash: 89ade0de0651c4ac4743f9dd4f821c4e6590319001c0ec5a5ad968702c9707e0
                                      • Instruction Fuzzy Hash: DE21A43294122AFBDF129E80EC05BBEBBE8EB00711F1451D5F914A6150DB359E60EB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcessHeap.KERNEL32(00000010,00000000,80004005,00000000,00000000,00000100,?,00B01472,00000000,80004005,00000000,80004005,00000000,000001C7,?,00B013B7), ref: 00B03AB2
                                      • HeapReAlloc.KERNEL32(00000000,?,00B01472,00000000,80004005,00000000,80004005,00000000,000001C7,?,00B013B7,000001C7,00000100,?,80004005,00000000), ref: 00B03AB9
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                        • Part of subcall function 00B03B51: GetProcessHeap.KERNEL32(00000000,000001C7,?,00B021DC,000001C7,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B03B59
                                        • Part of subcall function 00B03B51: HeapSize.KERNEL32(00000000,?,00B021DC,000001C7,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B03B60
                                      • _memcpy_s.LIBCMT ref: 00B03B04
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$Process$AllocAllocateSize_memcpy_s
                                      • String ID: memutil.cpp
                                      • API String ID: 3406509257-2429405624
                                      • Opcode ID: f238b17d4eca1aa3ffc381c0d1ec6c3916307bc72a55d324b39218245b66adb6
                                      • Instruction ID: ee0a870a91254ac7d7dfcc468c66f3f20114dd3306d4299b307cd387e752daba
                                      • Opcode Fuzzy Hash: f238b17d4eca1aa3ffc381c0d1ec6c3916307bc72a55d324b39218245b66adb6
                                      • Instruction Fuzzy Hash: 8611B131601628AFDB221A289C9DEAE3FDDEF45F68B044295FA155B1D1CB71CF5093A0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetLastError.KERNEL32 ref: 00B4884C
                                      • SystemTimeToFileTime.KERNEL32(?,00000000), ref: 00B48874
                                      • GetLastError.KERNEL32 ref: 00B4887E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastTime$FileSystem
                                      • String ID: inetutil.cpp
                                      • API String ID: 1528435940-2900720265
                                      • Opcode ID: deccfa507bec087c297e23272902d28a84881270eb6b19e5a8295974a8d3bcb1
                                      • Instruction ID: 6d73739397cb61cb88afe6103a8ec332f996e360e6ee8e2ee2ceb98ca0182f36
                                      • Opcode Fuzzy Hash: deccfa507bec087c297e23272902d28a84881270eb6b19e5a8295974a8d3bcb1
                                      • Instruction Fuzzy Hash: 2F116676A01229BBE720DBB98D44FABB7ECEF44750F110166EE05F7150EA748E0497E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      • RegCloseKey.ADVAPI32(00000000,SOFTWARE\Policies\Microsoft\Windows\Installer,00020019,00000001,feclient.dll,?,?,?,00B13E61,feclient.dll,?,00000000,?,?,?,00B04A0C), ref: 00B139F1
                                        • Part of subcall function 00B40F6E: RegQueryValueExW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000002,00000001,00000000,00000000,00000000,00000000,00000000), ref: 00B40FE4
                                        • Part of subcall function 00B40F6E: RegQueryValueExW.ADVAPI32(?,00000000,00000000,?,00000000,00000000,00000000,?), ref: 00B4101F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: QueryValue$CloseOpen
                                      • String ID: Logging$SOFTWARE\Policies\Microsoft\Windows\Installer$feclient.dll
                                      • API String ID: 1586453840-3596319545
                                      • Opcode ID: 6a65193bba65dc2539b3ac526fac8f6e2260c79a492372afcb7c0c92edf31990
                                      • Instruction ID: 2496dc4ff29152a98b1cf4cd8d58101d972e26dabb799b47c9cc28312bf2222e
                                      • Opcode Fuzzy Hash: 6a65193bba65dc2539b3ac526fac8f6e2260c79a492372afcb7c0c92edf31990
                                      • Instruction Fuzzy Hash: 68119632A40208BBDB219A95DD42AEEB7F8EB00F91F8440F6E5069B150F6B15FC1E750
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenA.KERNEL32(?,00000000,00000000,00000000,?,?,00B3FF0B,?,?,00000000,00000000,0000FDE9), ref: 00B4066A
                                      • WriteFile.KERNEL32(FFFFFFFF,00000000,00000000,00000000,00000000,?,?,00B3FF0B,?,?,00000000,00000000,0000FDE9), ref: 00B406A6
                                      • GetLastError.KERNEL32(?,?,00B3FF0B,?,?,00000000,00000000,0000FDE9), ref: 00B406B0
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastWritelstrlen
                                      • String ID: logutil.cpp
                                      • API String ID: 606256338-3545173039
                                      • Opcode ID: 91df30a84192c01a6aeca940bb1a4dcf3204d225ff466d117d5e3d28e88af729
                                      • Instruction ID: 9cfa782208b158d471b73499c0eacf0a676a83093aff7e20697c2f93280a54c1
                                      • Opcode Fuzzy Hash: 91df30a84192c01a6aeca940bb1a4dcf3204d225ff466d117d5e3d28e88af729
                                      • Instruction Fuzzy Hash: F1110632A112247BD710AA798C44DAFBAECEBD1761B024255FE06E7140DB74EE1096E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CommandLineToArgvW.SHELL32(00000000,00000000,00000000,00000000,00000000,00000000,ignored ,00000000,?,00000000,?,?,?,00B05137,00000000,?), ref: 00B01247
                                      • GetLastError.KERNEL32(?,?,?,00B05137,00000000,?,?,00000003,00000000,00000000,?,?,?,?,?,?), ref: 00B01251
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ArgvCommandErrorLastLine
                                      • String ID: apputil.cpp$ignored
                                      • API String ID: 3459693003-568828354
                                      • Opcode ID: 0ce4f39f5b361b874ffe730120659e82f007cb9994a99bd217e46b15b6670093
                                      • Instruction ID: 6b03f298fb659288ca4746b2252fd18656c1a00fd3c2e944e013f984efbcf8a5
                                      • Opcode Fuzzy Hash: 0ce4f39f5b361b874ffe730120659e82f007cb9994a99bd217e46b15b6670093
                                      • Instruction Fuzzy Hash: 59116A76A01228BBDB25DBADC905DAEBFF8EB44750B014199FD04E7250E730DE009AA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WaitForSingleObject.KERNEL32(?,000000FF,00000002,00000000,?,?,00B2D1DC,00000000,00000000,00000000,?), ref: 00B2CF66
                                      • ReleaseMutex.KERNEL32(?,?,00B2D1DC,00000000,00000000,00000000,?), ref: 00B2CFED
                                        • Part of subcall function 00B038D4: GetProcessHeap.KERNEL32(?,000001C7,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038E5
                                        • Part of subcall function 00B038D4: RtlAllocateHeap.NTDLL(00000000,?,00B02284,000001C7,00000001,80004005,8007139F,?,?,00B4015F,8007139F,?,00000000,00000000,8007139F), ref: 00B038EC
                                      Strings
                                      • Failed to allocate memory for message data, xrefs: 00B2CFB5
                                      • NetFxChainer.cpp, xrefs: 00B2CFAB
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateMutexObjectProcessReleaseSingleWait
                                      • String ID: Failed to allocate memory for message data$NetFxChainer.cpp
                                      • API String ID: 2993511968-1624333943
                                      • Opcode ID: f16193c3d9f9c0c8f4d6a71a062d1cb9ec76bbccc803938f8d806d6450564715
                                      • Instruction ID: c79b49fa5dbb3fd4fe687a1f6d5753870561e380a61f939fb559e6351e7eb277
                                      • Opcode Fuzzy Hash: f16193c3d9f9c0c8f4d6a71a062d1cb9ec76bbccc803938f8d806d6450564715
                                      • Instruction Fuzzy Hash: 2C1182B5300215AFC715DF24E895E6ABBF5FF09720F1042A9F9189B3A1C771AC10CBA4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • FormatMessageW.KERNEL32(000011FF,00B05386,?,00000000,00000000,00000000,?,80070656,?,?,?,00B1E50B,00000000,00B05386,00000000,80070656), ref: 00B01FAA
                                      • GetLastError.KERNEL32(?,?,?,00B1E50B,00000000,00B05386,00000000,80070656,?,?,00B13F6B,00B05386,?,80070656,00000001,crypt32.dll), ref: 00B01FB7
                                      • LocalFree.KERNEL32(00000000,?,00000000,00000000,?,?,?,00B1E50B,00000000,00B05386,00000000,80070656,?,?,00B13F6B,00B05386), ref: 00B01FFE
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFormatFreeLastLocalMessage
                                      • String ID: strutil.cpp
                                      • API String ID: 1365068426-3612885251
                                      • Opcode ID: 41e5303c724e525bccbb33d0a40caed7f8bcb0ab2a48c1d699de6d5e5a462e2b
                                      • Instruction ID: 27ee395d7c21f4cd47ce50f5302b43d8ec2634141599032cd8340c09c11d9cc0
                                      • Opcode Fuzzy Hash: 41e5303c724e525bccbb33d0a40caed7f8bcb0ab2a48c1d699de6d5e5a462e2b
                                      • Instruction Fuzzy Hash: 17115276900229FBEB159F94CC09EEE7AE9EF04741F004199BE01A3250EB718E10D7E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Strings
                                      • Failed to allocate new BootstrapperuserForApplication object., xrefs: 00B1FC8E
                                      • userForApplication.cpp, xrefs: 00B1FC84
                                      • Failed to QI for IBootstrapperuser from BootstrapperuserForApplication object., xrefs: 00B1FCB0
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID: userForApplication.cpp$Failed to QI for IBootstrapperuser from BootstrapperuserForApplication object.$Failed to allocate new BootstrapperuserForApplication object.
                                      • API String ID: 0-1509993410
                                      • Opcode ID: f06434b4e6ccc558148d0b59db15701babc4d3d1cb20c02261b8d9f6d1b3cba1
                                      • Instruction ID: 9eb6abb0bde57567d40eb1880cf5f83fa6624ea0fbf721bdee3c71b5551b5d43
                                      • Opcode Fuzzy Hash: f06434b4e6ccc558148d0b59db15701babc4d3d1cb20c02261b8d9f6d1b3cba1
                                      • Instruction Fuzzy Hash: ACF026322402167B87012714EC06EAE37E8CF84BA171000FAFD04BA2A0EA208A81E5A2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNEL32(00B4B4F0,40000000,00000001,00000000,00000002,00000080,00000000,00B10328,00000000,?,00B0F37F,?,00000080,00B4B4F0,00000000), ref: 00B44C7F
                                      • GetLastError.KERNEL32(?,00B0F37F,?,00000080,00B4B4F0,00000000,?,00B10328,?,00000094,?,?,?,?,?,00000000), ref: 00B44C8C
                                      • CloseHandle.KERNEL32(00000000,00000000,?,00B0F37F,?,00B0F37F,?,00000080,00B4B4F0,00000000,?,00B10328,?,00000094), ref: 00B44CE0
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateErrorFileHandleLast
                                      • String ID: fileutil.cpp
                                      • API String ID: 2528220319-2967768451
                                      • Opcode ID: 551ce5e385d7b39f3bcfdc8b868b5f4833430e133596b8be10dff39628409e74
                                      • Instruction ID: 479499b0086ac61487ed21ce86f42b6ca1f0dcdd08a693e1d4f987472a9f5ba5
                                      • Opcode Fuzzy Hash: 551ce5e385d7b39f3bcfdc8b868b5f4833430e133596b8be10dff39628409e74
                                      • Instruction Fuzzy Hash: 6C01DF767022247BEB315E699C85F5B3AD8EB81BB0F154210FE24EB1E1C731CD21A2A0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateFileW.KERNEL32(00000000,00000080,00000001,00000000,00000003,00000080,00000000,000002C0,00000000,?,00B28A30,00000000,00000088,000002C0,BundleCachePath,00000000), ref: 00B44874
                                      • GetLastError.KERNEL32(?,00B28A30,00000000,00000088,000002C0,BundleCachePath,00000000,000002C0,BundleVersion,000000B8,000002C0,userVersion,000002C0,000000B0), ref: 00B44881
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateErrorFileLast
                                      • String ID: fileutil.cpp
                                      • API String ID: 1214770103-2967768451
                                      • Opcode ID: df6b595b48f9ec824247d73594511e301d2866b0ab6bf9aaca19aff2611815a8
                                      • Instruction ID: a8f070fcf6bf045a6c3dd93d9553cc3cc2fc542dc38db63a04963a6297e7e7d1
                                      • Opcode Fuzzy Hash: df6b595b48f9ec824247d73594511e301d2866b0ab6bf9aaca19aff2611815a8
                                      • Instruction Fuzzy Hash: D401F936740220B6F73126A8AC09F7B27DCEB41B62F014261FE05EB1D0CB658E1062E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ControlService.ADVAPI32(00B268BA,00000001,?,00000001,00000000,?,?,?,?,?,?,00B268BA,00000000), ref: 00B269D0
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,00B268BA,00000000), ref: 00B269DA
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ControlErrorLastService
                                      • String ID: Failed to stop wusa service.$msuuser.cpp
                                      • API String ID: 4114567744-2259829683
                                      • Opcode ID: ccee82c0aaf46a9ed2b3da3ae5d404d0e40a61f81741be8a317eb49a7045b6a2
                                      • Instruction ID: 993df33f6b61bab67ff7aacb4da6f67d79567308f47c2e19d96d6028aa281339
                                      • Opcode Fuzzy Hash: ccee82c0aaf46a9ed2b3da3ae5d404d0e40a61f81741be8a317eb49a7045b6a2
                                      • Instruction Fuzzy Hash: C601DB72B402286BEB20AB75AC05FAB77E8EB49711F014169FD04FB180DA349D0586E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • PostThreadMessageW.USER32(?,00009002,00000000,?), ref: 00B1EA9A
                                      • GetLastError.KERNEL32 ref: 00B1EAA4
                                      Strings
                                      • Failed to post elevate message., xrefs: 00B1EAD2
                                      • userForApplication.cpp, xrefs: 00B1EAC8
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastMessagePostThread
                                      • String ID: userForApplication.cpp$Failed to post elevate message.
                                      • API String ID: 2609174426-4098423239
                                      • Opcode ID: 442088546cf4ed56d88b369e5efca33a745c5f0aab6c0e40e88f1ba358879ea4
                                      • Instruction ID: 622b10d5895e32fd69eb670550bc09458e5128ab1c57733947a924c0100bf14b
                                      • Opcode Fuzzy Hash: 442088546cf4ed56d88b369e5efca33a745c5f0aab6c0e40e88f1ba358879ea4
                                      • Instruction Fuzzy Hash: 62F0F636710330ABD3206A589C09E9337D8FF04761F1142A9BF28FB1E0DB25CC4186D5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcAddress.KERNEL32(?,BootstrapperApplicationDestroy), ref: 00B0D7F6
                                      • FreeLibrary.KERNEL32(?,?,00B047D1,00000000,?,?,00B05386,?,?), ref: 00B0D805
                                      • GetLastError.KERNEL32(?,00B047D1,00000000,?,?,00B05386,?,?), ref: 00B0D80F
                                      Strings
                                      • BootstrapperApplicationDestroy, xrefs: 00B0D7EE
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressErrorFreeLastLibraryProc
                                      • String ID: BootstrapperApplicationDestroy
                                      • API String ID: 1144718084-3186005537
                                      • Opcode ID: 7d4cf9d0e6a36864e8a89142405608064757ccf00518025ddb2e36bacc550dc3
                                      • Instruction ID: 53b564bd637326e5c9adefd93e3433ded08b87e8313236138c73f9bf7427fc8d
                                      • Opcode Fuzzy Hash: 7d4cf9d0e6a36864e8a89142405608064757ccf00518025ddb2e36bacc550dc3
                                      • Instruction Fuzzy Hash: 65F049362007009FD7209FA6DC08A67BBE9FF81762B01C56EE566C35A0DB35E800CB60
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • PostThreadMessageW.USER32(?,00009001,00000000,?), ref: 00B1F09B
                                      • GetLastError.KERNEL32 ref: 00B1F0A5
                                      Strings
                                      • userForApplication.cpp, xrefs: 00B1F0C9
                                      • Failed to post plan message., xrefs: 00B1F0D3
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastMessagePostThread
                                      • String ID: userForApplication.cpp$Failed to post plan message.
                                      • API String ID: 2609174426-2952114608
                                      • Opcode ID: ce64a01e05bdb2f6bce4bcb3f380d47b553fd9f221bf973f7e7a36fea77c45bf
                                      • Instruction ID: 8120fbf856b8fc3a415f0ea1233cf444f173c4a8e2f3962a0c5921174f507e09
                                      • Opcode Fuzzy Hash: ce64a01e05bdb2f6bce4bcb3f380d47b553fd9f221bf973f7e7a36fea77c45bf
                                      • Instruction Fuzzy Hash: B9F0A0367403307AE7206AAA9C09F977BD8EF08BA1F014065FE0CEB1A1DA25CD40D6E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • PostThreadMessageW.USER32(?,00009005,?,00000000), ref: 00B1F1A9
                                      • GetLastError.KERNEL32 ref: 00B1F1B3
                                      Strings
                                      • Failed to post shutdown message., xrefs: 00B1F1E1
                                      • userForApplication.cpp, xrefs: 00B1F1D7
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastMessagePostThread
                                      • String ID: userForApplication.cpp$Failed to post shutdown message.
                                      • API String ID: 2609174426-188808143
                                      • Opcode ID: 02ba0cae3672bb0a21edf7381f4b3f6a600d684426e0ed12d7198aed6b85bcee
                                      • Instruction ID: f826464192c5c1920a7e973711412ae178673cc8f1a805c51420c262f29e7210
                                      • Opcode Fuzzy Hash: 02ba0cae3672bb0a21edf7381f4b3f6a600d684426e0ed12d7198aed6b85bcee
                                      • Instruction Fuzzy Hash: 68F0A7367413307AE7206AAA9C09F977AD8EF04B61F014065BE08F71A1DA11CE00D6E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetEvent.KERNEL32(00B4B468,00000000,?,00B2145A,?,00000000,?,00B0C121,?,00B052FD,?,00B173B2,?,?,00B052FD,?), ref: 00B20524
                                      • GetLastError.KERNEL32(?,00B2145A,?,00000000,?,00B0C121,?,00B052FD,?,00B173B2,?,?,00B052FD,?,00B0533D,00000001), ref: 00B2052E
                                      Strings
                                      • Failed to set begin operation event., xrefs: 00B2055C
                                      • cabextract.cpp, xrefs: 00B20552
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorEventLast
                                      • String ID: Failed to set begin operation event.$cabextract.cpp
                                      • API String ID: 3848097054-4159625223
                                      • Opcode ID: d3eefa84bdf13f81de0e338d1e8f19eadabf880c4e24eabd5f1d0eb05c1b31b8
                                      • Instruction ID: 6b41cccb793ac8f51cc8d5a78a181edcea80796d989595d0aeb82f422928147c
                                      • Opcode Fuzzy Hash: d3eefa84bdf13f81de0e338d1e8f19eadabf880c4e24eabd5f1d0eb05c1b31b8
                                      • Instruction Fuzzy Hash: F6F0EC33A517306BA71076797C45F977AD8DF09761B0101A5FE09F7150EA149D0056E6
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • PostThreadMessageW.USER32(?,00009003,00000000,?), ref: 00B1E98D
                                      • GetLastError.KERNEL32 ref: 00B1E997
                                      Strings
                                      • Failed to post apply message., xrefs: 00B1E9C5
                                      • userForApplication.cpp, xrefs: 00B1E9BB
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastMessagePostThread
                                      • String ID: userForApplication.cpp$Failed to post apply message.
                                      • API String ID: 2609174426-1304321051
                                      • Opcode ID: 7d1979d2b53569de69f308659c788934f4a3b18acf15e9d863b3d61b447b8cf9
                                      • Instruction ID: cd3a2da6f9e42e505005fc35bbd2b8e9058aa1bb80d0fbea50e1c5efdd871a05
                                      • Opcode Fuzzy Hash: 7d1979d2b53569de69f308659c788934f4a3b18acf15e9d863b3d61b447b8cf9
                                      • Instruction Fuzzy Hash: 0BF0A7367403306AE7202A699C09F877BD8EF04BA1F010065BE08FB1A1D621CD0096E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • PostThreadMessageW.USER32(?,00009000,00000000,?), ref: 00B1EA1E
                                      • GetLastError.KERNEL32 ref: 00B1EA28
                                      Strings
                                      • userForApplication.cpp, xrefs: 00B1EA4C
                                      • Failed to post detect message., xrefs: 00B1EA56
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastMessagePostThread
                                      • String ID: userForApplication.cpp$Failed to post detect message.
                                      • API String ID: 2609174426-598219917
                                      • Opcode ID: f9d7d1fcff493a2b15377eeedb0d163c54f73366c02f8fdf36ad4f998b6bfd2f
                                      • Instruction ID: 7da3f322c1e3df95a2bdc32ee1d0e0cef686bff858565fc937a8dbd23a79a5f6
                                      • Opcode Fuzzy Hash: f9d7d1fcff493a2b15377eeedb0d163c54f73366c02f8fdf36ad4f998b6bfd2f
                                      • Instruction Fuzzy Hash: BFF0A7367413306BE7206A699C09F877AD8EF05BA1F014165FE08E71A0DA21DE00D6E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: __alldvrm$_strrchr
                                      • String ID:
                                      • API String ID: 1036877536-0
                                      • Opcode ID: f3a74c95afe91129e83f4a200ae329e72b68e1b987d16e4549aa364eb4fd1ab8
                                      • Instruction ID: 69452a175d08582a0d542674331c5005bc04d7cae8b63762c92bfbdf768db765
                                      • Opcode Fuzzy Hash: f3a74c95afe91129e83f4a200ae329e72b68e1b987d16e4549aa364eb4fd1ab8
                                      • Instruction Fuzzy Hash: D6A12476A00386AFDB25CF28C8927AEBBE4EF55350F3881EDE5859B281D6349D41CB50
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: lstrlen
                                      • String ID: dlutil.cpp
                                      • API String ID: 1659193697-2067379296
                                      • Opcode ID: 314bdad6e3b06231c44d7d76db9746fe1b65b811e0ba33e72eb29de938f1b6b2
                                      • Instruction ID: 16cb7a8938392dfb8dad8b3e69d5e5457bbf17d6d1841d147a9e1fbcfbcd3718
                                      • Opcode Fuzzy Hash: 314bdad6e3b06231c44d7d76db9746fe1b65b811e0ba33e72eb29de938f1b6b2
                                      • Instruction Fuzzy Hash: 9851B432A01A15ABDF219FA4CC84EAFB7F9EF48740B154065FE01A7251DB71DF41ABA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • MultiByteToWideChar.KERNEL32(?,00000000,E3E85006,00B3234D,00000000,00000000,00B33382,?,00B33382,?,00000001,00B3234D,E3E85006,00000001,00B33382,00B33382), ref: 00B390F7
                                      • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 00B39180
                                      • GetStringTypeW.KERNEL32(?,00000000,00000000,?), ref: 00B39192
                                      • __freea.LIBCMT ref: 00B3919B
                                        • Part of subcall function 00B35154: HeapAlloc.KERNEL32(00000000,?,?,?,00B31E90,?,0000015D,?,?,?,?,00B332E9,000000FF,00000000,?,?), ref: 00B35186
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ByteCharMultiWide$AllocHeapStringType__freea
                                      • String ID:
                                      • API String ID: 573072132-0
                                      • Opcode ID: 61962214cee7df48caf6a64bf2667aaa99f7e76929ca805ac0389fbc929a8a71
                                      • Instruction ID: 0d471fd7fdc428d9030c36039c32898833583688ebccba462b3a8909a89b2d47
                                      • Opcode Fuzzy Hash: 61962214cee7df48caf6a64bf2667aaa99f7e76929ca805ac0389fbc929a8a71
                                      • Instruction Fuzzy Hash: AA31D072A0061AABDF248F65CC89EAF7BE5EB01710F2441A8FC04E7250EB75CD54CBA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CloseHandle.KERNEL32(?,?,?,00000000,?,00B0545F,?,?,?,?,?,?), ref: 00B04EF6
                                      • DeleteCriticalSection.KERNEL32(?,?,?,00000000,?,00B0545F,?,?,?,?,?,?), ref: 00B04F0A
                                      • TlsFree.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00B0545F,?,?), ref: 00B04FF9
                                      • DeleteCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00B0545F,?,?), ref: 00B05000
                                        • Part of subcall function 00B01160: LocalFree.KERNEL32(?,?,00B04EB3,?,00000000,?,00B0545F,?,?,?,?,?,?), ref: 00B0116A
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalDeleteFreeSection$CloseHandleLocal
                                      • String ID:
                                      • API String ID: 3671900028-0
                                      • Opcode ID: 09ee1ddf9b298b919e176da4ba4db5f5eacb18a58a745461438ba560841bd2a0
                                      • Instruction ID: 25f94ae183366259d253ef3ed69f0be65e9fe14f5ed20b213e264dbbe1b13447
                                      • Opcode Fuzzy Hash: 09ee1ddf9b298b919e176da4ba4db5f5eacb18a58a745461438ba560841bd2a0
                                      • Instruction Fuzzy Hash: D241A7B1500B05ABCA20EBB5C889F9B77ECAF04341F4408A9B65AD7192DB34F6849624
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysAllocString.OLEAUT32(?), ref: 00B4312C
                                      • VariantInit.OLEAUT32(?), ref: 00B43138
                                      • VariantClear.OLEAUT32(?), ref: 00B431AC
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B431B7
                                        • Part of subcall function 00B4336E: SysAllocString.OLEAUT32(?), ref: 00B43383
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$AllocVariant$ClearFreeInit
                                      • String ID:
                                      • API String ID: 347726874-0
                                      • Opcode ID: e6bcd624d0fce1056404f0a30c512521c30869b6f3f34de268f0e3c2643deb39
                                      • Instruction ID: c1751acf3636417e2755104f13fa5f175042fb66cf23b76c26c4edbc440abf3e
                                      • Opcode Fuzzy Hash: e6bcd624d0fce1056404f0a30c512521c30869b6f3f34de268f0e3c2643deb39
                                      • Instruction Fuzzy Hash: CA213C35901219AFCB28DFA5C888EAEBBF8FF45B11F184198E901A7210DB31DF05DB94
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B0F7F7: RegCloseKey.ADVAPI32(00000000,?,?,00000001,00000000,00000000,?,?,00B04B9F,?,?,00000001), ref: 00B0F847
                                      • CloseHandle.KERNEL32(?,?,?,?,?,?,00000000,?,?,00000001,00000000,?,?,?), ref: 00B04C06
                                        • Part of subcall function 00B4082D: CreateProcessW.KERNEL32(00000001,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00000000,?,?,?,?,00000000,00000000), ref: 00B4089A
                                        • Part of subcall function 00B4082D: GetLastError.KERNEL32(?,?,?,?,00000000,00000000,00000000), ref: 00B408A4
                                        • Part of subcall function 00B4082D: CloseHandle.KERNEL32(?,?,?,?,?,00000000,00000000,00000000), ref: 00B408ED
                                        • Part of subcall function 00B4082D: CloseHandle.KERNEL32(00000000,?,?,?,?,00000000,00000000,00000000), ref: 00B408FA
                                      Strings
                                      • Failed to re-launch bundle process after RunOnce: %ls, xrefs: 00B04BF0
                                      • Failed to get current process path., xrefs: 00B04BC4
                                      • Unable to get resume command line from the registry, xrefs: 00B04BA5
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Close$Handle$CreateErrorLastProcess
                                      • String ID: Failed to get current process path.$Failed to re-launch bundle process after RunOnce: %ls$Unable to get resume command line from the registry
                                      • API String ID: 1572399834-642631345
                                      • Opcode ID: a84aa5b41443f753928a2660c5abc8a2487ac67d97b30beb816c2c074bbf7a7b
                                      • Instruction ID: 5efff8686deb9a66bf4e063338073e5ed4b9c57fb278b5932ff6b407c42c4679
                                      • Opcode Fuzzy Hash: a84aa5b41443f753928a2660c5abc8a2487ac67d97b30beb816c2c074bbf7a7b
                                      • Instruction Fuzzy Hash: DC116DB6D01518FBCF22AA98D901CAEFFF8EF50710B1041E6FA04B6261D7718B40AB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • LoadLibraryExW.KERNEL32(00000000,00000000,00000800,00B388D5,00000000,00000000,?,00B386D8,00B388D5,00000000,00000000,00000000,?,00B388D5,00000006,FlsSetValue), ref: 00B38763
                                      • GetLastError.KERNEL32(?,00B386D8,00B388D5,00000000,00000000,00000000,?,00B388D5,00000006,FlsSetValue,00B62208,00B62210,00000000,00000364,?,00B36130), ref: 00B3876F
                                      • LoadLibraryExW.KERNEL32(00000000,00000000,00000000,?,00B386D8,00B388D5,00000000,00000000,00000000,?,00B388D5,00000006,FlsSetValue,00B62208,00B62210,00000000), ref: 00B3877D
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: LibraryLoad$ErrorLast
                                      • String ID:
                                      • API String ID: 3177248105-0
                                      • Opcode ID: ef87c3f01310b994f9e68ed469a6f6c2a87c7a968cf9e6d33da0b7f80168f171
                                      • Instruction ID: 0ae5966ef6c89a2131a0316c1a9dc71e7253509cb630e2c3c19abd65e048a3f9
                                      • Opcode Fuzzy Hash: ef87c3f01310b994f9e68ed469a6f6c2a87c7a968cf9e6d33da0b7f80168f171
                                      • Instruction Fuzzy Hash: 9901D43A211326EBC7214A79AC84E563BD9FB05BA1B340660FA16E3240DF24DC01C6E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetLastError.KERNEL32(?,00000000,00B319F5,00000000,80004004,?,00B31CF9,00000000,80004004,00000000,00000000), ref: 00B36062
                                      • SetLastError.KERNEL32(00000000,80004004,00000000,00000000), ref: 00B360CA
                                      • SetLastError.KERNEL32(00000000,80004004,00000000,00000000), ref: 00B360D6
                                      • _abort.LIBCMT ref: 00B360DC
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$_abort
                                      • String ID:
                                      • API String ID: 88804580-0
                                      • Opcode ID: c52276c971a64ad811380065e95034fd65c0e5b0928ee47a7c15dba6d675f9c8
                                      • Instruction ID: cf6697eb301480c94d9a30f9e2b1d919a176e98bce6cd9f7fa2ee061a43d464c
                                      • Opcode Fuzzy Hash: c52276c971a64ad811380065e95034fd65c0e5b0928ee47a7c15dba6d675f9c8
                                      • Instruction Fuzzy Hash: 79F0DC36100A0076C63A3A786C8BF2B37EADBC2731F348298F919A31A1FE249D014162
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(?), ref: 00B07318
                                      • LeaveCriticalSection.KERNEL32(?,?,?,00000000), ref: 00B0737F
                                      Strings
                                      • Failed to get value as numeric for variable: %ls, xrefs: 00B0736E
                                      • Failed to get value of variable: %ls, xrefs: 00B07352
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: Failed to get value as numeric for variable: %ls$Failed to get value of variable: %ls
                                      • API String ID: 3168844106-4270472870
                                      • Opcode ID: 8917c65d59053fa545c5c844bd53d5b5222fa2328c27ddfc64467b9f5f4a7dc5
                                      • Instruction ID: cc26b0761b5f47561f3a4171217265e833804b97b5e28dc064831cfcf67282f6
                                      • Opcode Fuzzy Hash: 8917c65d59053fa545c5c844bd53d5b5222fa2328c27ddfc64467b9f5f4a7dc5
                                      • Instruction Fuzzy Hash: 60019232D94128FBDF215E54DC05A9E7FA9EB04720F1081A4FD04A6160CB35AE11BBD4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(?), ref: 00B0748D
                                      • LeaveCriticalSection.KERNEL32(?,?,?,00000000), ref: 00B074F4
                                      Strings
                                      • Failed to get value of variable: %ls, xrefs: 00B074C7
                                      • Failed to get value as version for variable: %ls, xrefs: 00B074E3
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: Failed to get value as version for variable: %ls$Failed to get value of variable: %ls
                                      • API String ID: 3168844106-1851729331
                                      • Opcode ID: 40bd263753729d75b13b796db4893770ee76926a9ec56abe4130856dfbcabcd5
                                      • Instruction ID: cdfc2c3beca5dc2852616ccb15fe176df21582e590f18d564ceb05e2772f2b5a
                                      • Opcode Fuzzy Hash: 40bd263753729d75b13b796db4893770ee76926a9ec56abe4130856dfbcabcd5
                                      • Instruction Fuzzy Hash: 0A015E32D95128FBCF215A44DC05A9EBFA8EB10761F1081A5FD04BA360CB35AE10A7E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00000000,00000000,00000006,?,00B09752,00000000,?,00000000,00000000,00000000,?,00B09590,00000000,?,00000000,00000000), ref: 00B0741C
                                      • LeaveCriticalSection.KERNEL32(00000000,00000000,00000000,00000000,?,00B09752,00000000,?,00000000,00000000,00000000,?,00B09590,00000000,?,00000000), ref: 00B07472
                                      Strings
                                      • Failed to copy value of variable: %ls, xrefs: 00B07461
                                      • Failed to get value of variable: %ls, xrefs: 00B07442
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave
                                      • String ID: Failed to copy value of variable: %ls$Failed to get value of variable: %ls
                                      • API String ID: 3168844106-2936390398
                                      • Opcode ID: 3797c434ab6d416c7f13f22758c7ee627b68e52b85cde8e24834f875147c1157
                                      • Instruction ID: c73965ccb66477969259c8ca69c19e9a628c2556b92e6e66c2782bb1de1deea2
                                      • Opcode Fuzzy Hash: 3797c434ab6d416c7f13f22758c7ee627b68e52b85cde8e24834f875147c1157
                                      • Instruction Fuzzy Hash: EAF08136D85128BBCF11AF54DC05D9E7FA4EB04760F0081A4FD04A6360DB31AB20ABD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___vcrt_initialize_pure_virtual_call_handler.LIBVCRUNTIME ref: 00B31246
                                      • ___vcrt_initialize_winapi_thunks.LIBVCRUNTIME ref: 00B3124B
                                      • ___vcrt_initialize_locks.LIBVCRUNTIME ref: 00B31250
                                        • Part of subcall function 00B31548: ___vcrt_InitializeCriticalSectionEx.LIBVCRUNTIME ref: 00B31559
                                      • ___vcrt_uninitialize_locks.LIBVCRUNTIME ref: 00B31265
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalInitializeSection___vcrt____vcrt_initialize_locks___vcrt_initialize_pure_virtual_call_handler___vcrt_initialize_winapi_thunks___vcrt_uninitialize_locks
                                      • String ID:
                                      • API String ID: 1761009282-0
                                      • Opcode ID: 294756368ebb91e0d837f8d85631f380e5f2af2aa371e18ba28d844398db2aca
                                      • Instruction ID: ee6039aa0006d3c89ddaac2e61f5e0cd49a35c4589fc26c117c8b6396b43e9a6
                                      • Opcode Fuzzy Hash: 294756368ebb91e0d837f8d85631f380e5f2af2aa371e18ba28d844398db2aca
                                      • Instruction Fuzzy Hash: F1C04808104201A41E203BFE2A832EE73CC8CF2786FB12CC5F866A7603AD0A181F2533
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      • RegCloseKey.ADVAPI32(00000000,80000002,SYSTEM\CurrentControlSet\Control\Session Manager,00000003,?,00000000,00000000,00000101), ref: 00B447C2
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseOpen
                                      • String ID: PendingFileRenameOperations$SYSTEM\CurrentControlSet\Control\Session Manager
                                      • API String ID: 47109696-3023217399
                                      • Opcode ID: 117f3002bc734980b95709c182f0e9c4356327927f21c38a48c3a85046d54418
                                      • Instruction ID: 8f3607185fbf73218446ed09577797a6e676a9cc4d43a58fae8da480e0f3a131
                                      • Opcode Fuzzy Hash: 117f3002bc734980b95709c182f0e9c4356327927f21c38a48c3a85046d54418
                                      • Instruction Fuzzy Hash: EF416375E00119EBCF21DF94C981AAEBBF9EF46710F1140E9E510AB211DB719F62EB50
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegCloseKey.ADVAPI32(00000000), ref: 00B40CA0
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseOpen
                                      • String ID: regutil.cpp
                                      • API String ID: 47109696-955085611
                                      • Opcode ID: 5d9c9adfa6b8eab053a48c0b6d0762c1e88480ff8dee3f6555a9739ca54a8867
                                      • Instruction ID: 0f05e7574ec59fa7973791539b0d4421ef5935f74d11d25559d5217fd0cf257f
                                      • Opcode Fuzzy Hash: 5d9c9adfa6b8eab053a48c0b6d0762c1e88480ff8dee3f6555a9739ca54a8867
                                      • Instruction Fuzzy Hash: 1E41E332D51229FBDF216AA4CD84BADBBF5EB04311F1182A9EE01AB161D7358F50F784
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegQueryValueExW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000002,00000001,00000000,00000000,00000000,00000000,00000000), ref: 00B40FE4
                                      • RegQueryValueExW.ADVAPI32(?,00000000,00000000,?,00000000,00000000,00000000,?), ref: 00B4101F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: QueryValue
                                      • String ID: regutil.cpp
                                      • API String ID: 3660427363-955085611
                                      • Opcode ID: c8efed52d9bb363e584b5c4e971b9db251b957c5746863e67c117cc7f1bc97fc
                                      • Instruction ID: da7d05b0f92b5d3355b1bfd90810ee6e554b288777e7ee35837dbf6f882e4130
                                      • Opcode Fuzzy Hash: c8efed52d9bb363e584b5c4e971b9db251b957c5746863e67c117cc7f1bc97fc
                                      • Instruction Fuzzy Hash: 1E41AF31D0112AEFDF209F98C884AAEBBF9EF54750F1085A9E914E7250D7718F81EB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WideCharToMultiByte.KERNEL32(00B4B508,00000000,00000006,00000001,comres.dll,?,00000000,?,00000000,?,?,00000000,00000006,?,comres.dll,?), ref: 00B366A3
                                      • GetLastError.KERNEL32 ref: 00B366BF
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ByteCharErrorLastMultiWide
                                      • String ID: comres.dll
                                      • API String ID: 203985260-246242247
                                      • Opcode ID: 83fd945a8d39ab72bb4119428830d741b34053b348a63c489865f732425be433
                                      • Instruction ID: 0b8a9b9139ee9e14632348d65a563890849634504ffd2b04eb81db5fb583ddad
                                      • Opcode Fuzzy Hash: 83fd945a8d39ab72bb4119428830d741b34053b348a63c489865f732425be433
                                      • Instruction Fuzzy Hash: 5631B331600215FBCB21AF55D887AEB7BE8DF52B90F3581E5F9145B291DB708D00C7A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B48CFB: lstrlenW.KERNEL32(00000100,?,?,00B49098,000002C0,00000100,00000100,00000100,?,?,?,00B27B40,?,?,000001BC,00000000), ref: 00B48D1B
                                      • RegCloseKey.ADVAPI32(00000000,?,?,00000000,?,00000000,?,?,?,00000000,wininet.dll,?,00B4B4F0,wininet.dll,?), ref: 00B48F07
                                      • RegCloseKey.ADVAPI32(?,?,?,00000000,?,00000000,?,?,?,00000000,wininet.dll,?,00B4B4F0,wininet.dll,?), ref: 00B48F14
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                        • Part of subcall function 00B40D1C: RegEnumKeyExW.ADVAPI32(00000000,000002C0,00000410,00000002,00000000,00000000,00000000,00000000,00000410,00000002,00000100,00000000,00000000,?,?,00B28BD8), ref: 00B40D77
                                        • Part of subcall function 00B40D1C: RegQueryInfoKeyW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000002,00000000,00000000,00000000,00000000,00000000,00000000,?,?,00B28BD8,00000000), ref: 00B40D99
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Close$EnumInfoOpenQuerylstrlen
                                      • String ID: wininet.dll
                                      • API String ID: 2680864210-3354682871
                                      • Opcode ID: e4b595191462e99403d5bcd0c6be852b9464f4ddb4aeec5ec0f958aaa6fe5ed9
                                      • Instruction ID: fc34f0f2e52bea0873a9600c09ee03efd1707da545bbfd5708c7bf52297f277c
                                      • Opcode Fuzzy Hash: e4b595191462e99403d5bcd0c6be852b9464f4ddb4aeec5ec0f958aaa6fe5ed9
                                      • Instruction Fuzzy Hash: 3C311D36C0152ABFCF21AF94D8408AEBAFAEF44350B1541A9EA0077121DB314F54AB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B48CFB: lstrlenW.KERNEL32(00000100,?,?,00B49098,000002C0,00000100,00000100,00000100,?,?,?,00B27B40,?,?,000001BC,00000000), ref: 00B48D1B
                                      • RegCloseKey.ADVAPI32(00000000,00000000,?,00000000,00000000,00000000), ref: 00B49305
                                      • RegCloseKey.ADVAPI32(00000001,00000000,?,00000000,00000000,00000000), ref: 00B4931F
                                        • Part of subcall function 00B40AD5: RegCreateKeyExW.ADVAPI32(00000001,00000000,00000000,00000000,00000000,00000001,00000000,?,00000000,00000001,?,?,00B10491,?,00000000,00020006), ref: 00B40AFA
                                        • Part of subcall function 00B41392: RegSetValueExW.ADVAPI32(00020006,00020006,00000000,00000001,?,00000000,?,000000FF,00000000,00000000,?,?,00B0F1C2,00000000,?,00020006), ref: 00B413C5
                                        • Part of subcall function 00B41392: RegDeleteValueW.ADVAPI32(00020006,00020006,00000000,?,?,00B0F1C2,00000000,?,00020006,?,00020006,00020006,00000000,?,?,?), ref: 00B413F5
                                        • Part of subcall function 00B41344: RegSetValueExW.ADVAPI32(?,?,00000000,00000004,?,00000004,SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce,?,00B0F11A,00000005,Resume,?,?,?,00000002,00000000), ref: 00B41359
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Value$Close$CreateDeletelstrlen
                                      • String ID: %ls\%ls
                                      • API String ID: 3924016894-2125769799
                                      • Opcode ID: 0afb94f7ce950a175997fc557751a38eba743fbfe40e73e810c548051987de19
                                      • Instruction ID: 4c30cd4f32735ced004ce6c330dc26e5157c2012caa3f018679402069687d66a
                                      • Opcode Fuzzy Hash: 0afb94f7ce950a175997fc557751a38eba743fbfe40e73e810c548051987de19
                                      • Instruction Fuzzy Hash: 3831D972C0152EBBCF12AF94DC818AFBBB9EF44750B1141AAEA0076121DB758F50BB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: _memcpy_s
                                      • String ID: crypt32.dll$wininet.dll
                                      • API String ID: 2001391462-82500532
                                      • Opcode ID: 20d9f25f4ff598d2956f110480d47adb0513f97da9c1314b068fe09bcabe11f2
                                      • Instruction ID: 1b2e418f24ac22d62d7001f293192307652115bc8367572a2783f81c92006ba4
                                      • Opcode Fuzzy Hash: 20d9f25f4ff598d2956f110480d47adb0513f97da9c1314b068fe09bcabe11f2
                                      • Instruction Fuzzy Hash: 19115171700219AFCF08DF19DDD999FBFADEF95650B14816AFC094B351D231EA108AE0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegSetValueExW.ADVAPI32(00020006,00020006,00000000,00000001,?,00000000,?,000000FF,00000000,00000000,?,?,00B0F1C2,00000000,?,00020006), ref: 00B413C5
                                      • RegDeleteValueW.ADVAPI32(00020006,00020006,00000000,?,?,00B0F1C2,00000000,?,00020006,?,00020006,00020006,00000000,?,?,?), ref: 00B413F5
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Value$Delete
                                      • String ID: regutil.cpp
                                      • API String ID: 1738766685-955085611
                                      • Opcode ID: cbe16f737400c1536efe0e4a082a32e55fabb2318c2063f821f692be32390f88
                                      • Instruction ID: 29e367148ea8b8f33728b77d7c27fb27a82fb596d9767dee6dedc5dfc9b6afc4
                                      • Opcode Fuzzy Hash: cbe16f737400c1536efe0e4a082a32e55fabb2318c2063f821f692be32390f88
                                      • Instruction Fuzzy Hash: FF11CA32E11239BBEF215E698D04FAA76E9EF05790F014575FD00E61A0D771CE50A6D0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(00000000,00000000,00000000,000000FF,?,000000FF,IGNOREDEPENDENCIES,00000000,?,?,00B2744B,00000000,IGNOREDEPENDENCIES,00000000,?,00B4B508), ref: 00B0DCF6
                                      Strings
                                      • Failed to copy the property value., xrefs: 00B0DD2A
                                      • IGNOREDEPENDENCIES, xrefs: 00B0DCAD
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareString
                                      • String ID: Failed to copy the property value.$IGNOREDEPENDENCIES
                                      • API String ID: 1825529933-1412343224
                                      • Opcode ID: 3c0608f0b0371462bca61d165bb915fe51b3bf051aa6796390f8eec4d60aa142
                                      • Instruction ID: dfff239d5153c66cbdec4424dd32c1fb651b79a7da5cc3b069dcb11b281a0af6
                                      • Opcode Fuzzy Hash: 3c0608f0b0371462bca61d165bb915fe51b3bf051aa6796390f8eec4d60aa142
                                      • Instruction Fuzzy Hash: 5811A336204215AFEB204F84CC84F697BE5FF15320F2542FAFA19AB2E1C7B09850DA90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • Sleep.KERNEL32(20000004,00000000,00000000,00000000,00000000,00000000,?,?,00B18C90,?,00000001,20000004,00000000,00000000,?,00000000), ref: 00B45527
                                      • SetNamedSecurityInfoW.ADVAPI32(00000000,?,000007D0,00000003,00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,?,?,00B18C90,?), ref: 00B45542
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: InfoNamedSecuritySleep
                                      • String ID: aclutil.cpp
                                      • API String ID: 2352087905-2159165307
                                      • Opcode ID: 7fcb6b7477e2c8383e80fbd712f2a6edcc4dd55fb7b245452eb0c8279d3ce81d
                                      • Instruction ID: 79a4c477ccac5effa6ae2be2c34a9b57ceefbfa10fd1ed5ad85e21905bca750a
                                      • Opcode Fuzzy Hash: 7fcb6b7477e2c8383e80fbd712f2a6edcc4dd55fb7b245452eb0c8279d3ce81d
                                      • Instruction Fuzzy Hash: 0F018237800928BBDF229E99DC05EDE7EBAEF44760F014195FE0467120D6318F60A7A0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CoInitializeEx.OLE32(00000000,00000000), ref: 00B155D9
                                      • CoUninitialize.OLE32(?,00000000,?,?,?,?,?,?,?), ref: 00B15633
                                      Strings
                                      • Failed to initialize COM on cache thread., xrefs: 00B155E5
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: InitializeUninitialize
                                      • String ID: Failed to initialize COM on cache thread.
                                      • API String ID: 3442037557-3629645316
                                      • Opcode ID: cf8abed47b8640e2eb5ede912f3080861df1ce112564f7a1fbc73fe66cfffe6b
                                      • Instruction ID: 3edbb3b8a27e83ca7547117019e60e8a38eda6cedb8aff073b1ebbdc8eef56bd
                                      • Opcode Fuzzy Hash: cf8abed47b8640e2eb5ede912f3080861df1ce112564f7a1fbc73fe66cfffe6b
                                      • Instruction Fuzzy Hash: 7A015B72600619BFCB059FA5DC80DD6FBECFF48354B4081A6FA08D7121DB31AE549B94
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • LCMapStringW.KERNEL32(0000007F,00000000,00000000,00B16EF3,00000000,00B16EF3,00000000,00000000,00B16EF3,00000000,00000000,00000000,?,00B02326,00000000,00000000), ref: 00B015A3
                                      • GetLastError.KERNEL32(?,00B02326,00000000,00000000,00B16EF3,00000200,?,00B4516B,00000000,00B16EF3,00000000,00B16EF3,00000000,00000000,00000000), ref: 00B015AD
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastString
                                      • String ID: strutil.cpp
                                      • API String ID: 3728238275-3612885251
                                      • Opcode ID: 2473f8e821c959f14e859763f56b3a35a5770293eea6f9b9d1f80febbb60dfc0
                                      • Instruction ID: 7234fa64c1dd8d104e951114a783b3ed0a1ec5672f61f1e74108aa997bc3d81b
                                      • Opcode Fuzzy Hash: 2473f8e821c959f14e859763f56b3a35a5770293eea6f9b9d1f80febbb60dfc0
                                      • Instruction Fuzzy Hash: F701D83360062577DB219E9A8C44E577EEDEF96760B020555FE15EF190DB20DC10C7E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysAllocString.OLEAUT32(00000000), ref: 00B438D0
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B43903
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$AllocFree
                                      • String ID: xmlutil.cpp
                                      • API String ID: 344208780-1270936966
                                      • Opcode ID: 724b9e5065f7f264644d61531e41bbf59a075a351a476b9ba80ca362f8952194
                                      • Instruction ID: 6e15450991606a80fd86806a01af12081c64bc6ddeacdd54174c701a9f6dab9e
                                      • Opcode Fuzzy Hash: 724b9e5065f7f264644d61531e41bbf59a075a351a476b9ba80ca362f8952194
                                      • Instruction Fuzzy Hash: 1901A275A40219BBDB205A588C09F7B77E8EF45B60F1800A5FE05A7290C7B8CF0067A2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysAllocString.OLEAUT32(00000000), ref: 00B43849
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B4387C
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$AllocFree
                                      • String ID: xmlutil.cpp
                                      • API String ID: 344208780-1270936966
                                      • Opcode ID: 49be46ba234bb0deeb3b3cbe5bbecc39f188a37ecab1541d591765a81478886b
                                      • Instruction ID: 265d3cdf3d1b6957df567d110e9baabda06694bd23c28b4c94e6d75757bbab1f
                                      • Opcode Fuzzy Hash: 49be46ba234bb0deeb3b3cbe5bbecc39f188a37ecab1541d591765a81478886b
                                      • Instruction Fuzzy Hash: 5901A275640219ABDB211A598C09F7B77E8EF55B60F1440B9FE05E7240C778CF01A7A2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      • RegCloseKey.ADVAPI32(00000000,80000002,SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System,00020019,00000000,?,?,?,?,?,00B4396A,?), ref: 00B43B3A
                                      Strings
                                      • EnableLUA, xrefs: 00B43B0C
                                      • SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System, xrefs: 00B43AE4
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseOpen
                                      • String ID: EnableLUA$SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
                                      • API String ID: 47109696-3551287084
                                      • Opcode ID: 7b1cbf3190b2a55132810e3d6e393c444a5554282235c5647cb67ae4fef1a387
                                      • Instruction ID: b9e684a09744e7f55890b64e46e9281d9bc910bdfa082e013a3f253d00fddc79
                                      • Opcode Fuzzy Hash: 7b1cbf3190b2a55132810e3d6e393c444a5554282235c5647cb67ae4fef1a387
                                      • Instruction Fuzzy Hash: 54017C32C50238FBDB10AAA4D84ABEEFBECEB14B21F2441A5E901A3111D3745F50E6D4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenW.KERNEL32(burn.clean.room,?,?,?,?,00B01104,?,?,00000000), ref: 00B0503A
                                      • CompareStringW.KERNEL32(0000007F,00000001,?,0000000F,burn.clean.room,0000000F,?,?,?,?,00B01104,?,?,00000000), ref: 00B0506A
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareStringlstrlen
                                      • String ID: burn.clean.room
                                      • API String ID: 1433953587-3055529264
                                      • Opcode ID: e76465d0d30f6dbcbac8065aed5775a635baa0221019f8429b8199fb3c0cd931
                                      • Instruction ID: 532f889b1370130f43c626f0cc62204f62c2f45e487d7c4f751ca712149a8fb5
                                      • Opcode Fuzzy Hash: e76465d0d30f6dbcbac8065aed5775a635baa0221019f8429b8199fb3c0cd931
                                      • Instruction Fuzzy Hash: 3301D6776006256EC7344B989C84D7BBBECFB047547104116F645D3A90E7B4AC40CFE1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysFreeString.OLEAUT32(?), ref: 00B467B3
                                        • Part of subcall function 00B485CB: SystemTimeToFileTime.KERNEL32(?,00000000,00000000,clbcatq.dll,00000000,clbcatq.dll,00000000,00000000,00000000), ref: 00B486D8
                                        • Part of subcall function 00B485CB: GetLastError.KERNEL32 ref: 00B486E2
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Time$ErrorFileFreeLastStringSystem
                                      • String ID: atomutil.cpp$clbcatq.dll
                                      • API String ID: 211557998-3749116663
                                      • Opcode ID: 2e4f321645070392d86329aed20b7542a3df3ef5fbdba840c588d2fb618ee087
                                      • Instruction ID: e28546b88b8f1f1fd6a9283dc1b1eb0d71bf5b073badfbe2a98d564798b42fb2
                                      • Opcode Fuzzy Hash: 2e4f321645070392d86329aed20b7542a3df3ef5fbdba840c588d2fb618ee087
                                      • Instruction Fuzzy Hash: E101A271901116FBDB209F859981C5EFBF8EB16764B5442FAFD04A7110D7319F10E792
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetCurrentProcess.KERNEL32(?), ref: 00B0642A
                                        • Part of subcall function 00B409BB: GetModuleHandleW.KERNEL32(kernel32,IsWow64Process,?,?,?,00B05D8F,00000000), ref: 00B409CF
                                        • Part of subcall function 00B409BB: GetProcAddress.KERNEL32(00000000), ref: 00B409D6
                                        • Part of subcall function 00B409BB: GetLastError.KERNEL32(?,?,?,00B05D8F,00000000), ref: 00B409ED
                                        • Part of subcall function 00B05BF0: RegCloseKey.ADVAPI32(00000000,?,00000000,CommonFilesDir,?,80000002,SOFTWARE\Microsoft\Windows\CurrentVersion,00020119,00000000), ref: 00B05C77
                                      Strings
                                      • Failed to set variant value., xrefs: 00B06467
                                      • Failed to get 64-bit folder., xrefs: 00B0644D
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressCloseCurrentErrorHandleLastModuleProcProcess
                                      • String ID: Failed to get 64-bit folder.$Failed to set variant value.
                                      • API String ID: 3109562764-2681622189
                                      • Opcode ID: be188d26d36562b2ee41fd4dccfce3bd8f45b55d2ff8646e6ef5a81cd113be03
                                      • Instruction ID: 401f8262b4c4f1615b542de23bef63fdc463040b25c24dd82fff41a012ad5412
                                      • Opcode Fuzzy Hash: be188d26d36562b2ee41fd4dccfce3bd8f45b55d2ff8646e6ef5a81cd113be03
                                      • Instruction Fuzzy Hash: C3016232911228BBCF21AB94DC05AAE7FF8EB00721F1081D5F940B6292D6719F50E7D0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleFileNameW.KERNEL32(?,?,00000104,?,00000104,?,?,?,?,00B010DD,?,00000000), ref: 00B033F8
                                      • GetLastError.KERNEL32(?,?,?,00B010DD,?,00000000), ref: 00B0340F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastModuleName
                                      • String ID: pathutil.cpp
                                      • API String ID: 2776309574-741606033
                                      • Opcode ID: 049f1cf5a67740a57c0153c7384dce8a6f81c3bea4a0bbbc18634f490a38e6c9
                                      • Instruction ID: d3dbb54cc407e9766fc6f47adb644626f38c912dbeabbe904ab6adafa982b92f
                                      • Opcode Fuzzy Hash: 049f1cf5a67740a57c0153c7384dce8a6f81c3bea4a0bbbc18634f490a38e6c9
                                      • Instruction Fuzzy Hash: FCF06873B4023067D721566A5C8CE5BBEDDEB45B60B124165BE05EB290D671CD0182E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00B40E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,00B45699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 00B40E52
                                      • RegCloseKey.ADVAPI32(00000000,00000001,00000000,00000001,00000000,?,?,00020006,00000000,00000001,00000000,?,?,00B2BB7C,00000101,?), ref: 00B105EF
                                      Strings
                                      • Failed to update resume mode., xrefs: 00B105D9
                                      • Failed to open registration key., xrefs: 00B105BF
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseOpen
                                      • String ID: Failed to open registration key.$Failed to update resume mode.
                                      • API String ID: 47109696-3366686031
                                      • Opcode ID: a616fc83885ae4f21755b79945667bae5ad38f17ebdbae51185debc35487d010
                                      • Instruction ID: 0d5d0383998bf2ed3ad2ee4792b77abe701e1f7d1e1e113de9d0f9adbfaf5023
                                      • Opcode Fuzzy Hash: a616fc83885ae4f21755b79945667bae5ad38f17ebdbae51185debc35487d010
                                      • Instruction Fuzzy Hash: 0CF0CD32951129B7CB216E54DC41FDEB7E9EB10751F1000D5FA00B6150DBB1AF50A7D0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetFileSizeEx.KERNEL32(00000000,00000000,00000000,762334C0,?,?,?,00B0B919,?,?,?,00000000,00000000), ref: 00B448E3
                                      • GetLastError.KERNEL32(?,?,?,00B0B919,?,?,?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 00B448ED
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastSize
                                      • String ID: fileutil.cpp
                                      • API String ID: 464720113-2967768451
                                      • Opcode ID: d7d418bbd29537e64819318d49044da8b6be5dd8ffb6ed0009bcdb90c08db194
                                      • Instruction ID: 6dfe71717d3a3ded6cfc5cd1753133b0e59dd7840568fbc9f445c14f64c54f66
                                      • Opcode Fuzzy Hash: d7d418bbd29537e64819318d49044da8b6be5dd8ffb6ed0009bcdb90c08db194
                                      • Instruction Fuzzy Hash: D1F0A475A00225AFA7109F598804A6BFBECFF05751B01425AFC04D3300D770AE10D7E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CLSIDFromProgID.OLE32(Microsoft.Update.AutoUpdate,00B0535E,?,00000000,00B0535E,?,?,?), ref: 00B43C7F
                                      • CoCreateInstance.OLE32(00000000,00000000,00000001,00B66F3C,?), ref: 00B43C97
                                      Strings
                                      • Microsoft.Update.AutoUpdate, xrefs: 00B43C7A
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateFromInstanceProg
                                      • String ID: Microsoft.Update.AutoUpdate
                                      • API String ID: 2151042543-675569418
                                      • Opcode ID: 265d6c0472cf4e67f0a3081e4b0cefe5ec35d244119744c1a19bbc3a2abe40de
                                      • Instruction ID: 85d8d51ed3cd215c90ddcd0683bddcce1fb6b568ba9ceac514380c6d529df413
                                      • Opcode Fuzzy Hash: 265d6c0472cf4e67f0a3081e4b0cefe5ec35d244119744c1a19bbc3a2abe40de
                                      • Instruction Fuzzy Hash: ADF05475600218BBDB00DFA9ED45DFFB7F8EB09710F410065EA01F7151DA70AF0486A2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysAllocString.OLEAUT32(?), ref: 00B430D4
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B43104
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$AllocFree
                                      • String ID: xmlutil.cpp
                                      • API String ID: 344208780-1270936966
                                      • Opcode ID: 79e47f10666d4932d3906dcb0dece2610246b963187c421767ea4c1f93938845
                                      • Instruction ID: 9e4361ba5d989bcbdada20b76dff8d574363013aa5b8389161422f863efa445e
                                      • Opcode Fuzzy Hash: 79e47f10666d4932d3906dcb0dece2610246b963187c421767ea4c1f93938845
                                      • Instruction Fuzzy Hash: 71F0B435201258E7CB219F049C0AF6B7BF5EB45F60F2840A9FD0567210C7758F10AAA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysAllocString.OLEAUT32(?), ref: 00B43383
                                      • SysFreeString.OLEAUT32(00000000), ref: 00B433B3
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$AllocFree
                                      • String ID: xmlutil.cpp
                                      • API String ID: 344208780-1270936966
                                      • Opcode ID: f623d6ebc30f891d58e1b7d3f6cf5b18417fb90ca8048d206dab26ce6c90b929
                                      • Instruction ID: bc8ab5f68ff6080312628c3a71b4d41f14cc5cc6a9c393738096d713fb8de481
                                      • Opcode Fuzzy Hash: f623d6ebc30f891d58e1b7d3f6cf5b18417fb90ca8048d206dab26ce6c90b929
                                      • Instruction Fuzzy Hash: D1F0B439200118A7C7211E099C08E6B3BE8EB85B60B180059FD059B210CB78CF00AAE9
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegSetValueExW.ADVAPI32(?,?,00000000,00000004,?,00000004,SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce,?,00B0F11A,00000005,Resume,?,?,?,00000002,00000000), ref: 00B41359
                                      Strings
                                      • SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, xrefs: 00B41347
                                      • regutil.cpp, xrefs: 00B41381
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Value
                                      • String ID: SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce$regutil.cpp
                                      • API String ID: 3702945584-2416625845
                                      • Opcode ID: 3784bcbb08287fd2f5be18aabd9a6d663e4d6811a8ef83968d6924166735290a
                                      • Instruction ID: fa21bed1aefd42cc859f16d315379fac25f5994303a61e6404989e6bcd4b1298
                                      • Opcode Fuzzy Hash: 3784bcbb08287fd2f5be18aabd9a6d663e4d6811a8ef83968d6924166735290a
                                      • Instruction Fuzzy Hash: D8E06D72B412357AEB205AAA8C09F977EDCDB04AE0F014021BE08EA1A0D6618D0082E4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcAddress.KERNEL32(RegDeleteKeyExW,AdvApi32.dll), ref: 00B40CF2
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000001.00000002.3385058826.0000000000B01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00B00000, based on PE: true
                                      • Associated: 00000001.00000002.3385015318.0000000000B00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385244840.0000000000B4B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385308246.0000000000B6A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000001.00000002.3385356660.0000000000B6E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_1_2_b00000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressProc
                                      • String ID: AdvApi32.dll$RegDeleteKeyExW
                                      • API String ID: 190572456-850864035
                                      • Opcode ID: 36a6f67bfc073513835ff4a1a94b485c75b263d1d1656cd196ba66965c9409b1
                                      • Instruction ID: db239d773e7bbce7bac5733e0a73dbb974f6a9a463d42bd426eed82869c2f5ba
                                      • Opcode Fuzzy Hash: 36a6f67bfc073513835ff4a1a94b485c75b263d1d1656cd196ba66965c9409b1
                                      • Instruction Fuzzy Hash: 74E046B1605A209BCB089F24FC0AE05BAF0AB15B0530081B8E802D33F1DFF858808B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 008833D7: GetModuleFileNameW.KERNEL32(?,?,00000104,?,00000104,?,?,?,?,008810DD,?,00000000), ref: 008833F8
                                      • CreateFileW.KERNELBASE(?,80000000,00000005,00000000,00000003,00000080,00000000,?,00000000), ref: 008810F6
                                        • Part of subcall function 00881174: HeapSetInformation.KERNEL32(00000000,00000001,00000000,00000000,?,?,?,?,?,0088111A,cabinet.dll,00000009,?,?,00000000), ref: 00881185
                                        • Part of subcall function 00881174: GetModuleHandleW.KERNEL32(kernel32,?,?,?,?,0088111A,cabinet.dll,00000009,?,?,00000000), ref: 00881190
                                        • Part of subcall function 00881174: GetProcAddress.KERNEL32(00000000,SetDefaultDllDirectories), ref: 0088119E
                                        • Part of subcall function 00881174: GetLastError.KERNEL32(?,?,?,?,0088111A,cabinet.dll,00000009,?,?,00000000), ref: 008811B9
                                        • Part of subcall function 00881174: GetProcAddress.KERNEL32(00000000,SetDllDirectoryW), ref: 008811C1
                                        • Part of subcall function 00881174: GetLastError.KERNEL32(?,?,?,?,0088111A,cabinet.dll,00000009,?,?,00000000), ref: 008811D6
                                      • CloseHandle.KERNEL32(?,?,?,?,008CB4C0,?,cabinet.dll,00000009,?,?,00000000), ref: 00881131
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressErrorFileHandleLastModuleProc$CloseCreateHeapInformationName
                                      • String ID: cabinet.dll$clbcatq.dll$comres.dll$crypt32.dll$feclient.dll$msasn1.dll$msi.dll$version.dll$wininet.dll
                                      • API String ID: 3687706282-3151496603
                                      • Opcode ID: 82529ceadc83cb82647a5a456e6e2f5a95e07a8033b0945b2d39cb0f160fe9ec
                                      • Instruction ID: 1e3c7c9de18e9c77700b6b52cd0bed1c09ebc8699bc28e392916c9b3681ef298
                                      • Opcode Fuzzy Hash: 82529ceadc83cb82647a5a456e6e2f5a95e07a8033b0945b2d39cb0f160fe9ec
                                      • Instruction Fuzzy Hash: D3216071900608AADB10AFA9DC4AFEEBBBCFF05715F104119EA10F7291DB709909CBA5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(008EB60C,00000000,?,?,?,?,008A1014,8007139F,Invalid operation for this state.,cabextract.cpp,000001C7,8007139F), ref: 008BFDF0
                                      • GetCurrentProcessId.KERNEL32(00000000,?,008A1014,8007139F,Invalid operation for this state.,cabextract.cpp,000001C7,8007139F), ref: 008BFE00
                                      • GetCurrentThreadId.KERNEL32 ref: 008BFE09
                                      • GetLocalTime.KERNEL32(8007139F,?,008A1014,8007139F,Invalid operation for this state.,cabextract.cpp,000001C7,8007139F), ref: 008BFE1F
                                      • LeaveCriticalSection.KERNEL32(008EB60C,?,00000000,00000000,0000FDE9), ref: 008BFF12
                                      Strings
                                      • %ls[%04X:%04X][%04hu-%02hu-%02huT%02hu:%02hu:%02hu]%hs%03d:%ls %ls%ls, xrefs: 008BFEB9
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalCurrentSection$EnterLeaveLocalProcessThreadTime
                                      • String ID: %ls[%04X:%04X][%04hu-%02hu-%02huT%02hu:%02hu:%02hu]%hs%03d:%ls %ls%ls
                                      • API String ID: 296830338-59366893
                                      • Opcode ID: 3638bd6d52830024f3a956a1849f1532f974a90a508f485cfbf422b4b98531bd
                                      • Instruction ID: 850e1b72e34086d7acb3b55f736d5f1f7d4ec4c7ee7d93ad4534c59e731cb25b
                                      • Opcode Fuzzy Hash: 3638bd6d52830024f3a956a1849f1532f974a90a508f485cfbf422b4b98531bd
                                      • Instruction Fuzzy Hash: BC415C72D00219ABDB209BE5DC45AFEB7F9FB19751F144026FA01E6261EB349D40CBA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      • Failed create working folder., xrefs: 00899EEA
                                      • Failed to copy working folder., xrefs: 00899F12
                                      • Failed to calculate working folder to ensure it exists., xrefs: 00899ED4
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CurrentDirectoryErrorLastProcessWindows
                                      • String ID: Failed create working folder.$Failed to calculate working folder to ensure it exists.$Failed to copy working folder.
                                      • API String ID: 3841436932-2072961686
                                      • Opcode ID: 39ce863e147c7f2126f7876facbce1f7d6a31e6be1f58f7f9c582d1efb6e42cd
                                      • Instruction ID: 6fe4b6d3eb0751ca57c0bfcad31169bee0f15d65627d668616b72c44776e7220
                                      • Opcode Fuzzy Hash: 39ce863e147c7f2126f7876facbce1f7d6a31e6be1f58f7f9c582d1efb6e42cd
                                      • Instruction Fuzzy Hash: C4017532D04529F68F327A5DDC06C6FBB79FF80720B14425AF844E6211EB719E50A691
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SysFreeString.OLEAUT32(00000000), ref: 0088DF4A
                                      • SysFreeString.OLEAUT32(00000000), ref: 0088E62A
                                        • Part of subcall function 008838D4: GetProcessHeap.KERNEL32(?,000001C7,?,00882284,000001C7,00000001,80004005,8007139F,?,?,008C015F,8007139F,?,00000000,00000000,8007139F), ref: 008838E5
                                        • Part of subcall function 008838D4: RtlAllocateHeap.NTDLL(00000000,?,00882284,000001C7,00000001,80004005,8007139F,?,?,008C015F,8007139F,?,00000000,00000000,8007139F), ref: 008838EC
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FreeHeapString$AllocateProcess
                                      • String ID: Cache$CacheId$Chain/ExePackage|Chain/MsiPackage|Chain/MspPackage|Chain/MsuPackage$ExePackage$Failed to allocate memory for MSP patch sequence information.$Failed to allocate memory for package structs.$Failed to allocate memory for patch sequence information to package lookup.$Failed to allocate memory for rollback boundary structs.$Failed to find backward transaction boundary: %ls$Failed to find forward transaction boundary: %ls$Failed to get @Cache.$Failed to get @CacheId.$Failed to get @Id.$Failed to get @InstallCondition.$Failed to get @InstallSize.$Failed to get @LogPathVariable.$Failed to get @PerMachine.$Failed to get @Permanent.$Failed to get @RollbackBoundaryBackward.$Failed to get @RollbackBoundaryForward.$Failed to get @RollbackLogPathVariable.$Failed to get @Size.$Failed to get @Vital.$Failed to get next node.$Failed to get package node count.$Failed to get rollback bundary node count.$Failed to parse EXE package.$Failed to parse MSI package.$Failed to parse MSP package.$Failed to parse MSU package.$Failed to parse dependency providers.$Failed to parse payload references.$Failed to parse target product codes.$Failed to select package nodes.$Failed to select rollback boundary nodes.$InstallCondition$InstallSize$Invalid cache type: %ls$LogPathVariable$MsiPackage$MspPackage$MsuPackage$PerMachine$Permanent$RollbackBoundary$RollbackBoundaryBackward$RollbackBoundaryForward$RollbackLogPathVariable$Size$Vital$always$cabinet.dll$clbcatq.dll$comres.dll$crypt32.dll$feclient.dll$msi.dll$package.cpp$wininet.dll$yes
                                      • API String ID: 336948655-2612374807
                                      • Opcode ID: 340dab3467c6addf977c3190ca8bdaf57caee45c83acd7ca85ff0fe42ef04798
                                      • Instruction ID: 2c88d7d2cc8cc4983d861edb49137255cf5f9ab7b1bffac787ae6d057c52532b
                                      • Opcode Fuzzy Hash: 340dab3467c6addf977c3190ca8bdaf57caee45c83acd7ca85ff0fe42ef04798
                                      • Instruction Fuzzy Hash: 5032907190062AABDB21AA54CC41FAEBBB5FB04728F104265F925FB391D774EE00DF91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 220 88f86e-88f8a4 call 8c388a 223 88f8b8-88f8d1 call 8c31c7 220->223 224 88f8a6-88f8b3 call 8c012f 220->224 230 88f8dd-88f8f2 call 8c31c7 223->230 231 88f8d3-88f8d8 223->231 229 88fda0-88fda5 224->229 234 88fdad-88fdb2 229->234 235 88fda7-88fda9 229->235 242 88f8fe-88f90b call 88e936 230->242 243 88f8f4-88f8f9 230->243 232 88fd97-88fd9e call 8c012f 231->232 248 88fd9f 232->248 236 88fdba-88fdbf 234->236 237 88fdb4-88fdb6 234->237 235->234 240 88fdc1-88fdc3 236->240 241 88fdc7-88fdcb 236->241 237->236 240->241 245 88fdcd-88fdd0 call 8c54ef 241->245 246 88fdd5-88fddc 241->246 251 88f90d-88f912 242->251 252 88f917-88f92c call 8c31c7 242->252 243->232 245->246 248->229 251->232 255 88f938-88f94a call 8c4b5a 252->255 256 88f92e-88f933 252->256 259 88f959-88f96e call 8c31c7 255->259 260 88f94c-88f954 255->260 256->232 265 88f97a-88f98f call 8c31c7 259->265 266 88f970-88f975 259->266 261 88fc23-88fc2c call 8c012f 260->261 261->248 270 88f99b-88f9ad call 8c33db 265->270 271 88f991-88f996 265->271 266->232 274 88f9b9-88f9cf call 8c388a 270->274 275 88f9af-88f9b4 270->275 271->232 278 88fc7e-88fc98 call 88ebb2 274->278 279 88f9d5-88f9d7 274->279 275->232 286 88fc9a-88fc9f 278->286 287 88fca4-88fcbc call 8c388a 278->287 280 88f9d9-88f9de 279->280 281 88f9e3-88f9f8 call 8c33db 279->281 280->232 288 88f9fa-88f9ff 281->288 289 88fa04-88fa19 call 8c31c7 281->289 286->232 294 88fcc2-88fcc4 287->294 295 88fd86-88fd87 call 88efe5 287->295 288->232 297 88fa29-88fa3e call 8c31c7 289->297 298 88fa1b-88fa1d 289->298 299 88fcd0-88fcee call 8c31c7 294->299 300 88fcc6-88fccb 294->300 303 88fd8c-88fd90 295->303 308 88fa4e-88fa63 call 8c31c7 297->308 309 88fa40-88fa42 297->309 298->297 304 88fa1f-88fa24 298->304 310 88fcfa-88fd12 call 8c31c7 299->310 311 88fcf0-88fcf5 299->311 300->232 303->248 307 88fd92 303->307 304->232 307->232 319 88fa73-88fa88 call 8c31c7 308->319 320 88fa65-88fa67 308->320 309->308 312 88fa44-88fa49 309->312 317 88fd1f-88fd37 call 8c31c7 310->317 318 88fd14-88fd16 310->318 311->232 312->232 327 88fd39-88fd3b 317->327 328 88fd44-88fd5c call 8c31c7 317->328 318->317 321 88fd18-88fd1d 318->321 329 88fa98-88faad call 8c31c7 319->329 330 88fa8a-88fa8c 319->330 320->319 322 88fa69-88fa6e 320->322 321->232 322->232 327->328 332 88fd3d-88fd42 327->332 337 88fd5e-88fd63 328->337 338 88fd65-88fd7d call 8c31c7 328->338 339 88fabd-88fad2 call 8c31c7 329->339 340 88faaf-88fab1 329->340 330->329 333 88fa8e-88fa93 330->333 332->232 333->232 337->232 338->295 346 88fd7f-88fd84 338->346 347 88fae2-88faf7 call 8c31c7 339->347 348 88fad4-88fad6 339->348 340->339 342 88fab3-88fab8 340->342 342->232 346->232 352 88faf9-88fafb 347->352 353 88fb07-88fb1c call 8c31c7 347->353 348->347 349 88fad8-88fadd 348->349 349->232 352->353 354 88fafd-88fb02 352->354 357 88fb2c-88fb44 call 8c31c7 353->357 358 88fb1e-88fb20 353->358 354->232 362 88fb54-88fb6c call 8c31c7 357->362 363 88fb46-88fb48 357->363 358->357 359 88fb22-88fb27 358->359 359->232 367 88fb7c-88fb91 call 8c31c7 362->367 368 88fb6e-88fb70 362->368 363->362 364 88fb4a-88fb4f 363->364 364->232 372 88fc31-88fc33 367->372 373 88fb97-88fbb4 CompareStringW 367->373 368->367 369 88fb72-88fb77 368->369 369->232 376 88fc3e-88fc40 372->376 377 88fc35-88fc3c 372->377 374 88fbbe-88fbd3 CompareStringW 373->374 375 88fbb6-88fbbc 373->375 381 88fbe1-88fbf6 CompareStringW 374->381 382 88fbd5-88fbdf 374->382 380 88fbff-88fc04 375->380 378 88fc4c-88fc64 call 8c33db 376->378 379 88fc42-88fc47 376->379 377->376 378->278 388 88fc66-88fc68 378->388 379->232 380->376 384 88fbf8 381->384 385 88fc06-88fc1e call 8837d3 381->385 382->380 384->380 385->261 390 88fc6a-88fc6f 388->390 391 88fc74 388->391 390->232 391->278
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID: AboutUrl$Arp$Classification$Comments$Contact$Department$DisableModify$DisableRemove$DisplayName$DisplayVersion$ExecutableName$Failed to get @AboutUrl.$Failed to get @Classification.$Failed to get @Comments.$Failed to get @Contact.$Failed to get @Department.$Failed to get @DisableModify.$Failed to get @DisableRemove.$Failed to get @DisplayName.$Failed to get @DisplayVersion.$Failed to get @ExecutableName.$Failed to get @HelpLink.$Failed to get @HelpTelephone.$Failed to get @Id.$Failed to get @Manufacturer.$Failed to get @Name.$Failed to get @ParentDisplayName.$Failed to get @PerMachine.$Failed to get @ProductFamily.$Failed to get @ProviderKey.$Failed to get @Publisher.$Failed to get @Register.$Failed to get @Tag.$Failed to get @UpdateUrl.$Failed to get @Version.$Failed to parse @Version: %ls$Failed to parse related bundles$Failed to parse software tag.$Failed to select ARP node.$Failed to select Update node.$Failed to select registration node.$Failed to set registration paths.$HelpLink$HelpTelephone$Invalid modify disabled type: %ls$Manufacturer$Name$ParentDisplayName$PerMachine$ProductFamily$ProviderKey$Publisher$Register$Registration$Tag$Update$UpdateUrl$Version$button$registration.cpp$yes
                                      • API String ID: 0-2956246334
                                      • Opcode ID: bb8351a2a06be1adad661913b619a6cb9fa3a4235b67404fa906ef4ebfa9ca82
                                      • Instruction ID: c74df544d67b959a91f26930233934a86e5f3e3d74d08a3c3daf72195bd8718d
                                      • Opcode Fuzzy Hash: bb8351a2a06be1adad661913b619a6cb9fa3a4235b67404fa906ef4ebfa9ca82
                                      • Instruction Fuzzy Hash: ECE1B132A4067ABACF11B6A4CC42EADBBA4FF00724F154376FB20F6352D7659E419781
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 392 88b389-88b3fd call 8af670 * 2 397 88b3ff-88b42a GetLastError call 8837d3 392->397 398 88b435-88b450 SetFilePointerEx 392->398 409 88b42f-88b430 397->409 400 88b452-88b482 GetLastError call 8837d3 398->400 401 88b484-88b49e ReadFile 398->401 400->409 402 88b4a0-88b4d0 GetLastError call 8837d3 401->402 403 88b4d5-88b4dc 401->403 402->409 407 88b4e2-88b4eb 403->407 408 88bad3-88bae7 call 8837d3 403->408 407->408 412 88b4f1-88b501 SetFilePointerEx 407->412 419 88baec 408->419 413 88baed-88baf3 call 8c012f 409->413 417 88b538-88b550 ReadFile 412->417 418 88b503-88b52e GetLastError call 8837d3 412->418 426 88baf4-88bb06 call 8ade36 413->426 422 88b552-88b57d GetLastError call 8837d3 417->422 423 88b587-88b58e 417->423 418->417 419->413 422->423 424 88bab8-88bad1 call 8837d3 423->424 425 88b594-88b59e 423->425 424->419 425->424 429 88b5a4-88b5c7 SetFilePointerEx 425->429 433 88b5c9-88b5f4 GetLastError call 8837d3 429->433 434 88b5fe-88b616 ReadFile 429->434 433->434 438 88b618-88b643 GetLastError call 8837d3 434->438 439 88b64d-88b665 ReadFile 434->439 438->439 442 88b69c-88b6b7 SetFilePointerEx 439->442 443 88b667-88b692 GetLastError call 8837d3 439->443 444 88b6b9-88b6e7 GetLastError call 8837d3 442->444 445 88b6f1-88b710 ReadFile 442->445 443->442 444->445 449 88ba79-88baad GetLastError call 8837d3 445->449 450 88b716-88b718 445->450 459 88baae-88bab6 call 8c012f 449->459 454 88b719-88b720 450->454 456 88ba54-88ba71 call 8837d3 454->456 457 88b726-88b732 454->457 467 88ba76-88ba77 456->467 460 88b73d-88b746 457->460 461 88b734-88b73b 457->461 459->426 465 88b74c-88b772 ReadFile 460->465 466 88ba17-88ba2e call 8837d3 460->466 461->460 464 88b780-88b787 461->464 471 88b789-88b7ab call 8837d3 464->471 472 88b7b0-88b7c7 call 8838d4 464->472 465->449 470 88b778-88b77e 465->470 478 88ba33-88ba39 call 8c012f 466->478 467->459 470->454 471->467 479 88b7c9-88b7e6 call 8837d3 472->479 480 88b7eb-88b800 SetFilePointerEx 472->480 490 88ba3f-88ba40 478->490 479->413 483 88b840-88b865 ReadFile 480->483 484 88b802-88b830 GetLastError call 8837d3 480->484 486 88b89c-88b8a8 483->486 487 88b867-88b89a GetLastError call 8837d3 483->487 500 88b835-88b83b call 8c012f 484->500 492 88b8aa-88b8c6 call 8837d3 486->492 493 88b8cb-88b8cf 486->493 487->500 495 88ba41-88ba43 490->495 492->478 498 88b90a-88b91d call 8c48cb 493->498 499 88b8d1-88b905 call 8837d3 call 8c012f 493->499 495->426 501 88ba49-88ba4f call 883999 495->501 511 88b929-88b933 498->511 512 88b91f-88b924 498->512 499->495 500->490 501->426 514 88b93d-88b945 511->514 515 88b935-88b93b 511->515 512->500 518 88b951-88b954 514->518 519 88b947-88b94f 514->519 517 88b956-88b9b6 call 8838d4 515->517 522 88b9b8-88b9d4 call 8837d3 517->522 523 88b9da-88b9fb call 8af0f0 call 88b106 517->523 518->517 519->517 522->523 523->495 530 88b9fd-88ba0d call 8837d3 523->530 530->466
                                      APIs
                                      • GetLastError.KERNEL32(?,?,?,00000000,7736C3F0,00000000), ref: 0088B3FF
                                      • SetFilePointerEx.KERNELBASE(000000FF,00000000,00000000,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 0088B44C
                                      • GetLastError.KERNEL32(?,?,?,00000000,7736C3F0,00000000), ref: 0088B452
                                      • ReadFile.KERNELBASE(00000000,0088435C,00000040,?,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 0088B49A
                                      • GetLastError.KERNEL32(?,?,?,00000000,7736C3F0,00000000), ref: 0088B4A0
                                      • SetFilePointerEx.KERNELBASE(00000000,00000000,?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 0088B4FD
                                      • GetLastError.KERNEL32(?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 0088B503
                                      • ReadFile.KERNELBASE(00000000,?,00000018,00000040,00000000,?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 0088B54C
                                      • GetLastError.KERNEL32(?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 0088B552
                                      • SetFilePointerEx.KERNELBASE(00000000,-00000098,00000000,00000000,00000000,?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 0088B5C3
                                      • GetLastError.KERNEL32(?,00000000,00000000,?,?,?,00000000,7736C3F0,00000000), ref: 0088B5C9
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$File$Pointer$Read
                                      • String ID: ($.wix$4$Failed to allocate buffer for section info.$Failed to allocate memory for container sizes.$Failed to find Burn section.$Failed to find valid DOS image header in buffer.$Failed to find valid NT image header in buffer.$Failed to get total size of bundle.$Failed to open handle to user process path.$Failed to read DOS header.$Failed to read NT header.$Failed to read complete image section header, index: %u$Failed to read complete section info.$Failed to read image section header, index: %u$Failed to read section info, data to short: %u$Failed to read section info, unsupported version: %08x$Failed to read section info.$Failed to read signature offset.$Failed to read signature size.$Failed to seek past optional headers.$Failed to seek to NT header.$Failed to seek to section info.$Failed to seek to start of file.$PE$PE Header from file didn't match PE Header in memory.$burn$section.cpp
                                      • API String ID: 2600052162-695169583
                                      • Opcode ID: acc1b9527e12b9116d4c3edc48a3f304ada11a78ca536cb120daf93c39f01abf
                                      • Instruction ID: 3493521010ace671d0f0459969230e65ac41658ae505ca9af2bab6bb9e4a4a74
                                      • Opcode Fuzzy Hash: acc1b9527e12b9116d4c3edc48a3f304ada11a78ca536cb120daf93c39f01abf
                                      • Instruction Fuzzy Hash: 4A12C971A40725ABEB20AA29CC46FA776B9FF44B50F014169FD09F7281DB74CE40CBA5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 533 8a0a77-8a0a90 SetEvent 534 8a0aca-8a0ad6 WaitForSingleObject 533->534 535 8a0a92-8a0ac5 GetLastError call 8837d3 533->535 537 8a0ad8-8a0b0b GetLastError call 8837d3 534->537 538 8a0b10-8a0b1b ResetEvent 534->538 543 8a0e25-8a0e26 call 8c012f 535->543 537->543 541 8a0b1d-8a0b50 GetLastError call 8837d3 538->541 542 8a0b55-8a0b5b 538->542 541->543 546 8a0b5d-8a0b60 542->546 547 8a0b96-8a0baf call 8821bc 542->547 553 8a0e2b-8a0e2c 543->553 551 8a0b8c-8a0b91 546->551 552 8a0b62-8a0b87 call 8837d3 call 8c012f 546->552 558 8a0bca-8a0bd5 SetEvent 547->558 559 8a0bb1-8a0bc5 call 8c012f 547->559 554 8a0e2d-8a0e2f 551->554 552->553 553->554 557 8a0e30-8a0e40 554->557 562 8a0c00-8a0c0c WaitForSingleObject 558->562 563 8a0bd7-8a0bf6 GetLastError 558->563 559->554 567 8a0c0e-8a0c2d GetLastError 562->567 568 8a0c37-8a0c42 ResetEvent 562->568 563->562 567->568 569 8a0c6d-8a0c74 568->569 570 8a0c44-8a0c63 GetLastError 568->570 571 8a0ce3-8a0d05 CreateFileW 569->571 572 8a0c76-8a0c79 569->572 570->569 573 8a0d42-8a0d57 SetFilePointerEx 571->573 574 8a0d07-8a0d38 GetLastError call 8837d3 571->574 575 8a0c7b-8a0c7e 572->575 576 8a0ca0-8a0ca7 call 8838d4 572->576 580 8a0d59-8a0d8c GetLastError call 8837d3 573->580 581 8a0d91-8a0d9c SetEndOfFile 573->581 574->573 578 8a0c99-8a0c9b 575->578 579 8a0c80-8a0c83 575->579 588 8a0cac-8a0cb1 576->588 578->557 579->551 584 8a0c89-8a0c8f 579->584 580->543 586 8a0d9e-8a0dd1 GetLastError call 8837d3 581->586 587 8a0dd3-8a0df0 SetFilePointerEx 581->587 584->578 586->543 587->554 593 8a0df2-8a0e20 GetLastError call 8837d3 587->593 591 8a0cd2-8a0cde 588->591 592 8a0cb3-8a0ccd call 8837d3 588->592 591->554 592->543 593->543
                                      APIs
                                      • SetEvent.KERNEL32(?,?,?,?,00000000,00000000,?,008A0621,?,?), ref: 008A0A85
                                      • GetLastError.KERNEL32(?,?,?,00000000,00000000,?,008A0621,?,?), ref: 008A0A92
                                      • WaitForSingleObject.KERNEL32(?,?,?,?,?,00000000,00000000,?,008A0621,?,?), ref: 008A0ACE
                                      • GetLastError.KERNEL32(?,?,?,?,00000000,00000000,?,008A0621,?,?), ref: 008A0AD8
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$EventObjectSingleWait
                                      • String ID: Failed to allocate buffer for stream.$Failed to copy stream name: %ls$Failed to create file: %ls$Failed to reset begin operation event.$Failed to set end of file.$Failed to set file pointer to beginning of file.$Failed to set file pointer to end of file.$Failed to set operation complete event.$Failed to wait for begin operation event.$Invalid operation for this state.$cabextract.cpp
                                      • API String ID: 3600396749-2104912459
                                      • Opcode ID: 92058c21c8bdb454635fad337e357ee62233791d0609b8f6d88bfa9940777f72
                                      • Instruction ID: 47b2e55b923906c81e997ffce12e32bec21b2053aaf9b30184192ef485cd08aa
                                      • Opcode Fuzzy Hash: 92058c21c8bdb454635fad337e357ee62233791d0609b8f6d88bfa9940777f72
                                      • Instruction Fuzzy Hash: 79911672B80B21BBF7206A798D4AF6736E4FF05760F110325FD05EAAA0E765DC109AD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 599 88508d-88513b call 8af670 * 2 GetModuleHandleW call 8c03f0 call 8c05a2 call 881209 610 88513d 599->610 611 885151-885162 call 8841d2 599->611 613 885142-88514c call 8c012f 610->613 617 88516b-885187 call 885525 CoInitializeEx 611->617 618 885164-885169 611->618 619 8853cc-8853d3 613->619 627 885189-88518e 617->627 628 885190-88519c call 8bfbad 617->628 618->613 622 8853e0-8853e2 619->622 623 8853d5-8853db call 8c54ef 619->623 625 8853e4-8853eb 622->625 626 885407-885425 call 88d723 call 89a6d0 call 89a91e 622->626 623->622 625->626 629 8853ed-885402 call 8c041b 625->629 649 885453-885466 call 884e9c 626->649 650 885427-88542f 626->650 627->613 636 88519e 628->636 637 8851b0-8851bf call 8c0cd1 628->637 629->626 640 8851a3-8851ab call 8c012f 636->640 644 8851c8-8851d7 call 8c29b3 637->644 645 8851c1-8851c6 637->645 640->619 655 8851d9-8851de 644->655 656 8851e0-8851ef call 8c343b 644->656 645->640 658 885468 call 8c3911 649->658 659 88546d-885474 649->659 650->649 653 885431-885434 650->653 653->649 657 885436-885451 call 89416a call 88550f 653->657 655->640 669 8851f8-885217 GetVersionExW 656->669 670 8851f1-8851f6 656->670 657->649 658->659 664 88547b-885482 659->664 665 885476 call 8c2dd0 659->665 671 885489-885490 664->671 672 885484 call 8c1317 664->672 665->664 674 885219-88524c GetLastError call 8837d3 669->674 675 885251-885296 call 8833d7 call 88550f 669->675 670->640 677 885492 call 8bfcbc 671->677 678 885497-885499 671->678 672->671 674->640 697 885298-8852a3 call 8c54ef 675->697 698 8852a9-8852b9 call 897337 675->698 677->678 681 88549b CoUninitialize 678->681 682 8854a1-8854a8 678->682 681->682 685 8854aa-8854ac 682->685 686 8854e3-8854ec call 8c000b 682->686 690 8854ae-8854b0 685->690 691 8854b2-8854b8 685->691 695 8854ee call 8844e9 686->695 696 8854f3-88550c call 8c06f5 call 8ade36 686->696 694 8854ba-8854d3 call 893c30 call 88550f 690->694 691->694 694->686 714 8854d5-8854e2 call 88550f 694->714 695->696 697->698 710 8852bb 698->710 711 8852c5-8852ce 698->711 710->711 715 8852d4-8852d7 711->715 716 885396-8853ac call 884c33 711->716 714->686 719 8852dd-8852e0 715->719 720 88536e-885381 call 8849df 715->720 729 8853b8-8853ca 716->729 730 8853ae 716->730 721 8852e2-8852e5 719->721 722 885346-885362 call 8847e9 719->722 728 885386-88538a 720->728 726 88531e-88533a call 884982 721->726 727 8852e7-8852ea 721->727 722->729 737 885364 722->737 726->729 741 88533c 726->741 733 8852fb-88530e call 884b80 727->733 734 8852ec-8852f1 727->734 728->729 735 88538c 728->735 729->619 730->729 733->729 742 885314 733->742 734->733 735->716 737->720 741->722 742->726
                                      APIs
                                      • GetModuleHandleW.KERNEL32(00000000,?,?,?,?,?,?), ref: 0088510F
                                        • Part of subcall function 008C03F0: InitializeCriticalSection.KERNEL32(008EB60C,?,0088511B,00000000,?,?,?,?,?,?), ref: 008C0407
                                        • Part of subcall function 00881209: CommandLineToArgvW.SHELL32(00000000,00000000,00000000,00000000,00000000,00000000,ignored ,00000000,?,00000000,?,?,?,00885137,00000000,?), ref: 00881247
                                        • Part of subcall function 00881209: GetLastError.KERNEL32(?,?,?,00885137,00000000,?,?,00000003,00000000,00000000,?,?,?,?,?,?), ref: 00881251
                                      • CoInitializeEx.OLE32(00000000,00000000,?,?,00000000,?,?,00000003,00000000,00000000,?,?,?,?,?,?), ref: 0088517D
                                        • Part of subcall function 008C0CD1: GetProcAddress.KERNEL32(RegDeleteKeyExW,AdvApi32.dll), ref: 008C0CF2
                                      • GetVersionExW.KERNEL32(?,?,?,?,?,?,?), ref: 0088520F
                                      • GetLastError.KERNEL32(?,?,?,?,?,?), ref: 00885219
                                      • CoUninitialize.OLE32(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 0088549B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorInitializeLast$AddressArgvCommandCriticalHandleLineModuleProcSectionUninitializeVersion
                                      • String ID: 3.10.4.4718$Failed to get OS info.$Failed to initialize COM.$Failed to initialize Cryputil.$Failed to initialize Regutil.$Failed to initialize Wiutil.$Failed to initialize XML util.$Failed to initialize core.$Failed to initialize user state.$Failed to parse command line.$Failed to run RunOnce mode.$Failed to run embedded mode.$Failed to run per-machine mode.$Failed to run per-user mode.$Failed to run untrusted mode.$Invalid run mode.$Setup$_Failed$user.cpp$txt
                                      • API String ID: 3262001429-867073019
                                      • Opcode ID: b8d585905b608ddcfb15168f545a0780e3390744b3a0147faba3cd1f852fc2b6
                                      • Instruction ID: 97d2059add920e32e376a52e07fc00a6a5706c946c07f2144d0cab1d2bde80cb
                                      • Opcode Fuzzy Hash: b8d585905b608ddcfb15168f545a0780e3390744b3a0147faba3cd1f852fc2b6
                                      • Instruction Fuzzy Hash: 20B1A472D41A299BDB32BA68CC46FAD76B8FF04711F040199F909E6341DB74DE848F92
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 743 88a311-88a35f call 8871cf 746 88a36b-88a36e 743->746 747 88a361-88a366 743->747 749 88a370-88a385 call 8871cf 746->749 750 88a391-88a3ab call 8c0e3f 746->750 748 88a62e-88a638 call 8c012f 747->748 757 88a63a-88a64a call 8c061a 748->757 758 88a64d-88a661 call 882793 * 2 748->758 749->750 759 88a387-88a38c 749->759 760 88a3ad-88a3bc call 8c061a 750->760 761 88a3e5-88a3e7 750->761 757->758 784 88a670-88a672 758->784 785 88a663-88a66c RegCloseKey 758->785 759->748 776 88a3bf-88a3d2 call 888137 760->776 762 88a3e9-88a3ee 761->762 763 88a3f3-88a410 RegQueryValueExW 761->763 762->748 767 88a428-88a42a 763->767 768 88a412-88a426 call 8c061a 763->768 773 88a42c-88a459 call 8837d3 767->773 774 88a45e-88a470 call 8838d4 767->774 768->776 773->748 787 88a499-88a4ae RegQueryValueExW 774->787 788 88a472-88a494 call 8837d3 call 8c012f 774->788 789 88a3de-88a3e0 776->789 790 88a3d4-88a3d9 776->790 791 88a67a-88a68b call 8a0499 784->791 792 88a674-88a675 call 883999 784->792 785->784 796 88a4b0-88a4dd call 8837d3 787->796 797 88a4e2-88a4e8 787->797 788->757 789->758 790->748 792->791 796->748 801 88a4ee-88a4f1 797->801 802 88a5e2-88a5e9 call 8a02f4 797->802 806 88a549-88a54d 801->806 807 88a4f3-88a4f7 801->807 809 88a5ee 802->809 806->802 810 88a553-88a563 call 881ede 806->810 811 88a4f9-88a4fc 807->811 812 88a53c-88a540 807->812 815 88a5f0-88a5f2 809->815 827 88a56f-88a589 ExpandEnvironmentStringsW 810->827 828 88a565-88a56a 810->828 817 88a519-88a51d 811->817 818 88a4fe-88a514 call 8c012f 811->818 813 88a51f-88a524 812->813 814 88a542-88a547 812->814 813->757 820 88a52e-88a537 call 8a02b0 814->820 821 88a5fb-88a60b call 89feb7 815->821 822 88a5f4-88a5f9 815->822 817->813 819 88a529-88a52c 817->819 818->757 819->820 820->809 833 88a60d-88a612 821->833 834 88a614-88a61e call 888137 821->834 822->748 827->815 832 88a58b-88a599 call 881ede 827->832 828->748 832->828 839 88a59b-88a5ab ExpandEnvironmentStringsW 832->839 833->748 838 88a623-88a627 834->838 838->758 840 88a629 838->840 839->815 841 88a5ad-88a5e0 GetLastError call 8837d3 839->841 840->748 841->748
                                      APIs
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 0088A356
                                      • _MREFOpen@16.MSPDB140-MSVCRT ref: 0088A37C
                                      • RegCloseKey.KERNELBASE(00000000,?,00000000,?,?,?,?,?), ref: 0088A666
                                      Strings
                                      • Failed to allocate string buffer., xrefs: 0088A565
                                      • Failed to allocate memory registry value., xrefs: 0088A487
                                      • Failed to set variable., xrefs: 0088A629
                                      • Failed to open registry key., xrefs: 0088A3E9
                                      • search.cpp, xrefs: 0088A44A, 0088A47D, 0088A4CE, 0088A5D1
                                      • Failed to format value string., xrefs: 0088A387
                                      • Failed to change value type., xrefs: 0088A60D
                                      • Registry key not found. Key = '%ls', xrefs: 0088A3B0
                                      • Failed to get expand environment string., xrefs: 0088A5DB
                                      • Failed to format key string., xrefs: 0088A361
                                      • Registry value not found. Key = '%ls', Value = '%ls', xrefs: 0088A418
                                      • Failed to clear variable., xrefs: 0088A3D4
                                      • Unsupported registry key value type. Type = '%u', xrefs: 0088A506
                                      • Failed to query registry key value., xrefs: 0088A4D8
                                      • Failed to query registry key value size., xrefs: 0088A454
                                      • Failed to read registry value., xrefs: 0088A5F4
                                      • RegistrySearchValue failed: ID '%ls', HRESULT 0x%x, xrefs: 0088A63E
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open@16$Close
                                      • String ID: Failed to allocate memory registry value.$Failed to allocate string buffer.$Failed to change value type.$Failed to clear variable.$Failed to format key string.$Failed to format value string.$Failed to get expand environment string.$Failed to open registry key.$Failed to query registry key value size.$Failed to query registry key value.$Failed to read registry value.$Failed to set variable.$Registry key not found. Key = '%ls'$Registry value not found. Key = '%ls', Value = '%ls'$RegistrySearchValue failed: ID '%ls', HRESULT 0x%x$Unsupported registry key value type. Type = '%u'$search.cpp
                                      • API String ID: 2348241696-3124384294
                                      • Opcode ID: 1789c3baaf7883246c334a53c33216cde4152a5738a317e3e888952e762b4b58
                                      • Instruction ID: 04f17c3b9b0e228cf9cec7d8a610738fab59cc1072f7234e0e9543f16e8fcb01
                                      • Opcode Fuzzy Hash: 1789c3baaf7883246c334a53c33216cde4152a5738a317e3e888952e762b4b58
                                      • Instruction Fuzzy Hash: CDA1D572D40629BBEF15BAA8CC05FAE7AB9FF14710F144126F904F6290E775CE109B92
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 844 88567d-8856c4 EnterCriticalSection lstrlenW call 881ede 847 8856ca-8856d7 call 8c012f 844->847 848 8858b1-8858bf call 8af7ca 844->848 855 885b53-885b61 LeaveCriticalSection 847->855 853 8856dc-8856ee call 8af7ca 848->853 854 8858c5-8858e2 call 88823e 848->854 853->854 872 8856f4-885700 853->872 867 885728 854->867 868 8858e8-8858eb call 8bf3d0 854->868 858 885b9c-885ba1 855->858 859 885b63-885b69 855->859 861 885ba9-885bad 858->861 862 885ba3-885ba4 call 8bf3c0 858->862 864 885b6b 859->864 865 885b96-885b97 call 883999 859->865 870 885bcd-885be0 call 882793 * 3 861->870 871 885baf-885bb3 861->871 862->861 873 885b6d-885b71 864->873 865->858 874 88572d 867->874 890 8858f0-8858f7 868->890 884 885be5-885bed 870->884 877 885bbd-885bc1 871->877 878 885bb5-885bb8 call 8c54ef 871->878 879 88573a-88573c 872->879 880 885702-885722 call 88823e 872->880 881 885b83-885b86 call 882793 873->881 882 885b73-885b77 873->882 885 88572e-885735 call 8c012f 874->885 883 885bc3-885bcb call 8c54ef 877->883 877->884 878->877 888 88573e-88575f call 88823e 879->888 889 885764-885785 call 888281 879->889 880->867 906 8858ab-8858ae 880->906 894 885b8b-885b8e 881->894 893 885b79-885b81 call 8c54ef 882->893 882->894 883->884 915 885b50 885->915 888->867 917 885761 888->917 919 885998-88599d 889->919 920 88578b-88579d 889->920 902 8858fd-88591c call 8837d3 890->902 903 8859a2-8859b0 call 8bf3e0 890->903 893->894 894->873 899 885b90-885b93 894->899 899->865 923 88593d-88593e 902->923 921 8859b2-8859e2 call 8837d3 903->921 922 8859e7-8859ee 903->922 906->848 915->855 917->889 919->874 924 88579f-8857a7 call 883a72 920->924 925 8857b4-8857c0 call 8838d4 920->925 921->874 929 8859f0-8859f3 922->929 930 885a21-885a3c call 8bf3f0 922->930 923->885 937 8857ad-8857b2 924->937 938 88591e-885938 call 8837d3 924->938 939 8857c6-8857ca 925->939 940 885977-885996 call 8837d3 925->940 934 8859f6-885a01 929->934 943 885aac-885ab0 930->943 944 885a3e-885a40 930->944 941 885a1a-885a1d 934->941 942 885a03-885a12 call 8bf3e0 934->942 937->939 938->923 945 8857cc-8857d3 939->945 946 8857f2-8857f6 939->946 940->923 941->934 949 885a1f 941->949 966 885a14-885a17 942->966 967 885a77-885aa7 call 8837d3 942->967 954 885b44-885b49 943->954 955 885ab6-885acf call 88821f 943->955 944->943 952 885a42-885a72 call 8837d3 944->952 945->946 953 8857d5-8857f0 call 888281 945->953 957 8857f8-88580e call 887e13 946->957 958 885814-88581b 946->958 949->930 952->874 979 885862-885864 953->979 954->915 963 885b4b-885b4e 954->963 980 885adb-885aed call 8bf3f0 955->980 981 885ad1-885ad6 955->981 957->958 982 885943-885954 call 8c012f 957->982 960 88581d-88582e call 8821a5 958->960 961 885830-88584a call 887203 958->961 983 88585a-88585c 960->983 985 88584c-885855 call 8822f9 961->985 986 88585f 961->986 963->915 966->941 967->874 987 88586a-885888 call 888260 979->987 988 88596d 979->988 994 885aef-885b1f call 8837d3 980->994 995 885b24-885b38 call 888281 980->995 981->874 982->915 983->986 985->983 986->979 999 88588e-8858a5 call 88823e 987->999 1000 885963 987->1000 988->940 994->874 995->954 1005 885b3a-885b3f 995->1005 999->906 1006 885959 999->1006 1000->988 1005->874 1006->1000
                                      APIs
                                      • EnterCriticalSection.KERNEL32(000002C0,00000100,00000100,00000000,00000000,?,008899BB,000002C0,?,00000000,00000000,000002C0,00000100,000002C0,00000100), ref: 008856A2
                                      • lstrlenW.KERNEL32(00000000,?,008899BB,000002C0,?,00000000,00000000,000002C0,00000100,000002C0,00000100), ref: 008856AC
                                      • _wcschr.LIBVCRUNTIME ref: 008858B4
                                      • LeaveCriticalSection.KERNEL32(000002C0,00000000,00000000,00000000,00000000,00000000,00000001,?,008899BB,000002C0,?,00000000,00000000,000002C0,00000100,000002C0), ref: 00885B56
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$EnterLeave_wcschrlstrlen
                                      • String ID: *****$Failed to allocate buffer for format string.$Failed to allocate record.$Failed to allocate string.$Failed to allocate variable array.$Failed to append placeholder.$Failed to append string.$Failed to copy string.$Failed to determine variable visibility: '%ls'.$Failed to format placeholder string.$Failed to format record.$Failed to get formatted length.$Failed to get variable name.$Failed to reallocate variable array.$Failed to set record format string.$Failed to set record string.$Failed to set variable value.$[%d]$variable.cpp
                                      • API String ID: 1026845265-2050445661
                                      • Opcode ID: f043b3bfd7c111bc63b2f5e7d0ed0b71257a540e83c54269a15ce3c8f86e9482
                                      • Instruction ID: 5a857859a01e8706b61c1c2cb4f01ab73d2146ec74701953a4599c596576edd1
                                      • Opcode Fuzzy Hash: f043b3bfd7c111bc63b2f5e7d0ed0b71257a540e83c54269a15ce3c8f86e9482
                                      • Instruction Fuzzy Hash: CBF16071900729EADB21BEA88C41EAF7BB9FB44750F15812AFD15E7240E774DE018BA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1112 897337-89737c call 8af670 call 887503 1117 897388-897399 call 88c2a1 1112->1117 1118 89737e-897383 1112->1118 1123 89739b-8973a0 1117->1123 1124 8973a5-8973b6 call 88c108 1117->1124 1119 897602-897609 call 8c012f 1118->1119 1127 89760a-89760f 1119->1127 1123->1119 1133 8973b8-8973bd 1124->1133 1134 8973c2-8973d7 call 88c362 1124->1134 1129 897611-897612 call 8c54ef 1127->1129 1130 897617-89761b 1127->1130 1129->1130 1131 89761d-897620 call 8c54ef 1130->1131 1132 897625-89762a 1130->1132 1131->1132 1137 89762c-89762d call 8c54ef 1132->1137 1138 897632-89763f call 88c055 1132->1138 1133->1119 1144 8973d9-8973de 1134->1144 1145 8973e3-8973f3 call 8abdc9 1134->1145 1137->1138 1147 897649-89764d 1138->1147 1148 897641-897644 call 8c54ef 1138->1148 1144->1119 1153 8973ff-897472 call 895a35 1145->1153 1154 8973f5-8973fa 1145->1154 1151 89764f-897652 call 8c54ef 1147->1151 1152 897657-89765b 1147->1152 1148->1147 1151->1152 1156 89765d-897660 call 883999 1152->1156 1157 897665-89766d 1152->1157 1161 89747e-8974c2 call 88550f GetCurrentProcess call 8c076c call 888152 1153->1161 1162 897474-897479 1153->1162 1154->1119 1156->1157 1169 8974dc-8974e1 1161->1169 1170 8974c4-8974d7 call 8c012f 1161->1170 1162->1119 1172 89753d-897542 1169->1172 1173 8974e3-8974f5 call 8880f6 1169->1173 1170->1127 1174 897562-89756b 1172->1174 1175 897544-897556 call 8880f6 1172->1175 1184 897501-897511 call 883446 1173->1184 1185 8974f7-8974fc 1173->1185 1179 89756d-897570 1174->1179 1180 897577-89758b call 89a307 1174->1180 1175->1174 1187 897558-89755d 1175->1187 1179->1180 1183 897572-897575 1179->1183 1192 89758d-897592 1180->1192 1193 897594 1180->1193 1183->1180 1188 89759a-89759d 1183->1188 1196 89751d-897531 call 8880f6 1184->1196 1197 897513-897518 1184->1197 1185->1119 1187->1119 1194 89759f-8975a2 1188->1194 1195 8975a4-8975ba call 88d497 1188->1195 1192->1119 1193->1188 1194->1127 1194->1195 1201 8975bc-8975c1 1195->1201 1202 8975c3-8975d2 call 88cabe 1195->1202 1196->1172 1205 897533-897538 1196->1205 1197->1119 1201->1119 1206 8975d7-8975db 1202->1206 1205->1119 1207 8975dd-8975e2 1206->1207 1208 8975e4-8975fb call 88c7df 1206->1208 1207->1119 1208->1127 1211 8975fd 1208->1211 1211->1119
                                      Strings
                                      • Failed to get source process folder from path., xrefs: 00897513
                                      • Failed to open manifest stream., xrefs: 008973B8
                                      • Failed to get manifest stream from container., xrefs: 008973D9
                                      • Failed to set source process path variable., xrefs: 008974F7
                                      • Failed to overwrite the %ls built-in variable., xrefs: 008974C9
                                      • Failed to get unique temporary folder for bootstrapper application., xrefs: 008975BC
                                      • Failed to initialize variables., xrefs: 0089737E
                                      • Failed to set source process folder variable., xrefs: 00897533
                                      • WixBundleSourceProcessFolder, xrefs: 00897522
                                      • WixBundleSourceProcessPath, xrefs: 008974E6
                                      • Failed to parse command line., xrefs: 00897474
                                      • WixBundleOriginalSource, xrefs: 00897547
                                      • Failed to load catalog files., xrefs: 008975FD
                                      • Failed to load manifest., xrefs: 008973F5
                                      • Failed to set original source variable., xrefs: 00897558
                                      • WixBundleElevated, xrefs: 008974B3, 008974C4
                                      • Failed to initialize internal cache functionality., xrefs: 0089758D
                                      • Failed to open attached UX container., xrefs: 0089739B
                                      • Failed to extract bootstrapper application payloads., xrefs: 008975DD
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalInitializeSection
                                      • String ID: Failed to extract bootstrapper application payloads.$Failed to get manifest stream from container.$Failed to get source process folder from path.$Failed to get unique temporary folder for bootstrapper application.$Failed to initialize internal cache functionality.$Failed to initialize variables.$Failed to load catalog files.$Failed to load manifest.$Failed to open attached UX container.$Failed to open manifest stream.$Failed to overwrite the %ls built-in variable.$Failed to parse command line.$Failed to set original source variable.$Failed to set source process folder variable.$Failed to set source process path variable.$WixBundleElevated$WixBundleOriginalSource$WixBundleSourceProcessFolder$WixBundleSourceProcessPath
                                      • API String ID: 32694325-252221001
                                      • Opcode ID: cf649fc8f19f2af07af7b3f5fab014851d70d90b350074fbc9f18e059488ab32
                                      • Instruction ID: 1e7e0376988e3e48efc404d86cb0a21264d928c4fc1cbb0aff76754228b7cde1
                                      • Opcode Fuzzy Hash: cf649fc8f19f2af07af7b3f5fab014851d70d90b350074fbc9f18e059488ab32
                                      • Instruction Fuzzy Hash: D8917372A54A1ABBCF13AAA8CC41EEEB77CFF14700F090226F515E6241D774EA448B95
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1212 8980ae-8980f7 call 8af670 1215 8980fd-89810b GetCurrentProcess call 8c076c 1212->1215 1216 898270-89827d call 8821a5 1212->1216 1219 898110-89811d 1215->1219 1223 89828c-89829e call 8ade36 1216->1223 1224 89827f 1216->1224 1221 8981ab-8981b9 1219->1221 1222 898123-898132 GetWindowsDirectoryW 1219->1222 1234 8981bb-8981ee GetLastError call 8837d3 1221->1234 1235 8981f3-898205 UuidCreate 1221->1235 1225 89816c-89817d call 88338f 1222->1225 1226 898134-898167 GetLastError call 8837d3 1222->1226 1227 898284-89828b call 8c012f 1224->1227 1242 898189-89819f call 8836b4 1225->1242 1243 89817f-898184 1225->1243 1226->1227 1227->1223 1234->1227 1240 89820e-898223 StringFromGUID2 1235->1240 1241 898207-89820c 1235->1241 1246 898241-898262 call 881f20 1240->1246 1247 898225-89823f call 8837d3 1240->1247 1241->1227 1242->1235 1252 8981a1-8981a6 1242->1252 1243->1227 1254 89826b 1246->1254 1255 898264-898269 1246->1255 1247->1227 1252->1227 1254->1216 1255->1227
                                      APIs
                                      • GetCurrentProcess.KERNEL32(00000000,00000000,00000000,00885381), ref: 00898104
                                        • Part of subcall function 008C076C: OpenProcessToken.ADVAPI32(?,00000008,?,008852B5,00000000,?,?,?,?,?,?,?,008974AB,00000000), ref: 008C078A
                                        • Part of subcall function 008C076C: GetLastError.KERNEL32(?,?,?,?,?,?,?,008974AB,00000000), ref: 008C0794
                                        • Part of subcall function 008C076C: FindCloseChangeNotification.KERNELBASE(?,?,?,?,?,?,?,?,008974AB,00000000), ref: 008C081D
                                      • GetWindowsDirectoryW.KERNEL32(?,00000104,00000000), ref: 0089812A
                                      • GetLastError.KERNEL32 ref: 00898134
                                      • GetTempPathW.KERNEL32(00000104,?,00000000), ref: 008981B1
                                      • GetLastError.KERNEL32 ref: 008981BB
                                      Strings
                                      • Temp\, xrefs: 00898189
                                      • Failed to copy working folder path., xrefs: 0089827F
                                      • Failed to convert working folder guid into string., xrefs: 0089823A
                                      • Failed to append bundle id on to temp path for working folder., xrefs: 00898264
                                      • Failed to get temp path for working folder., xrefs: 008981E9
                                      • cache.cpp, xrefs: 00898158, 008981DF, 00898230
                                      • Failed to concat Temp directory on windows path for working folder., xrefs: 008981A1
                                      • Failed to create working folder guid., xrefs: 00898207
                                      • Failed to ensure windows path for working folder ended in backslash., xrefs: 0089817F
                                      • %ls%ls\, xrefs: 0089824C
                                      • 4#v, xrefs: 008981B1
                                      • Failed to get windows path for working folder., xrefs: 00898162
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$Process$ChangeCloseCurrentDirectoryFindNotificationOpenPathTempTokenWindows
                                      • String ID: 4#v$%ls%ls\$Failed to append bundle id on to temp path for working folder.$Failed to concat Temp directory on windows path for working folder.$Failed to convert working folder guid into string.$Failed to copy working folder path.$Failed to create working folder guid.$Failed to ensure windows path for working folder ended in backslash.$Failed to get temp path for working folder.$Failed to get windows path for working folder.$Temp\$cache.cpp
                                      • API String ID: 58964441-3587817078
                                      • Opcode ID: d8d3ee3aaa96d211b3b6a301c469a01048a7fd96903bf88b952e05b9ecbbac40
                                      • Instruction ID: 4a974cacec287a5ccb00ae83927c8e8a80b93a2a2ef241487372e26cf7d3ee8f
                                      • Opcode Fuzzy Hash: d8d3ee3aaa96d211b3b6a301c469a01048a7fd96903bf88b952e05b9ecbbac40
                                      • Instruction Fuzzy Hash: E041D972A40B29EBEF20B7F49C4AF9773A8FB05710F040266F905E7240EA799D444691
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1256 887503-887dc0 InitializeCriticalSection 1257 887dc3-887de0 call 885530 1256->1257 1260 887ded-887dfb call 8c012f 1257->1260 1261 887de2-887de9 1257->1261 1264 887dfe-887e10 call 8ade36 1260->1264 1261->1257 1262 887deb 1261->1262 1262->1264
                                      APIs
                                      • InitializeCriticalSection.KERNEL32(00897378,008852B5,00000000,0088533D), ref: 00887523
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalInitializeSection
                                      • String ID: #$$$'$0$Date$Failed to add built-in variable: %ls.$InstallerName$InstallerVersion$LogonUser$WixBundleAction$WixBundleActiveParent$WixBundleElevated$WixBundleExecutePackageAction$WixBundleExecutePackageCacheFolder$WixBundleForcedRestartPackage$WixBundleInstalled$WixBundleProviderKey$WixBundleSourceProcessFolder$WixBundleSourceProcessPath$WixBundleTag$WixBundleVersion
                                      • API String ID: 32694325-826827252
                                      • Opcode ID: 9d3a01a4a79fbff454ffb9b616e8e1968bfad3d9c4c7f2be303d2d70be12b553
                                      • Instruction ID: 4fd023f93e135a865c374e3616afae8e4df91935fd0c5bb9aa228d5a53b6212c
                                      • Opcode Fuzzy Hash: 9d3a01a4a79fbff454ffb9b616e8e1968bfad3d9c4c7f2be303d2d70be12b553
                                      • Instruction Fuzzy Hash: 42321DB0C256798BDB65CF5989487CDBAB8FB49B04F5081DFE20CA6211D7B04B89CF84
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1268 89e177-89e1ae call 89e05e 1271 89e1b0-89e1b6 call 8c012f 1268->1271 1272 89e1c2-89e1f5 LoadCursorW RegisterClassW 1268->1272 1276 89e1bb-89e1bd 1271->1276 1274 89e22f-89e25e CreateWindowExW 1272->1274 1275 89e1f7-89e22a GetLastError call 8837d3 1272->1275 1278 89e260-89e293 GetLastError call 8837d3 1274->1278 1279 89e295-89e2a2 SetEvent 1274->1279 1288 89e2eb-89e2f2 call 8c012f 1275->1288 1281 89e2f4-89e306 UnregisterClassW 1276->1281 1278->1288 1280 89e2cc-89e2dd GetMessageW 1279->1280 1284 89e2df 1280->1284 1285 89e2a4-89e2a7 1280->1285 1286 89e308-89e30b DeleteObject 1281->1286 1287 89e311-89e318 1281->1287 1292 89e2f3 1284->1292 1290 89e2a9-89e2b6 IsDialogMessageW 1285->1290 1291 89e2e1-89e2e6 1285->1291 1286->1287 1288->1292 1290->1280 1294 89e2b8-89e2c6 TranslateMessage DispatchMessageW 1290->1294 1291->1288 1292->1281 1294->1280
                                      APIs
                                        • Part of subcall function 0089E05E: LoadBitmapW.USER32(?,00000001), ref: 0089E094
                                        • Part of subcall function 0089E05E: GetLastError.KERNEL32 ref: 0089E0A0
                                      • LoadCursorW.USER32(00000000,00007F00), ref: 0089E1D8
                                      • RegisterClassW.USER32(?), ref: 0089E1EC
                                      • GetLastError.KERNEL32(?,?,?), ref: 0089E1F7
                                      • UnregisterClassW.USER32(WixBurnSplashScreen,?), ref: 0089E2FC
                                      • DeleteObject.GDI32(00000000), ref: 0089E30B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ClassErrorLastLoad$BitmapCursorDeleteObjectRegisterUnregister
                                      • String ID: Failed to create window.$Failed to load splash screen.$Failed to register window.$Unexpected return value from message pump.$WixBurnSplashScreen$splashscreen.cpp
                                      • API String ID: 164797020-2188509422
                                      • Opcode ID: 119b1b8822a9c21b083e47b988ca15cf006cd470f5687756f5ac60d3c7606816
                                      • Instruction ID: 5d7c83bd7a9a05c0905a1c3a7c81167630b568694da4c9b93c7be5e47974b0f5
                                      • Opcode Fuzzy Hash: 119b1b8822a9c21b083e47b988ca15cf006cd470f5687756f5ac60d3c7606816
                                      • Instruction Fuzzy Hash: C5419072A00A29FFEF11ABE8DD45EAABBBDFF04310F100126F915E6250D7749D008B91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1296 8a0e43-8a0e6f CoInitializeEx 1297 8a0e83-8a0ece call 8bf364 1296->1297 1298 8a0e71-8a0e7e call 8c012f 1296->1298 1303 8a0ef8-8a0f1a call 8bf374 1297->1303 1304 8a0ed0-8a0ef3 call 8837d3 call 8c012f 1297->1304 1305 8a10df-8a10f1 call 8ade36 1298->1305 1313 8a0fd3-8a0fde SetEvent 1303->1313 1314 8a0f20-8a0f28 1303->1314 1321 8a10d8-8a10d9 CoUninitialize 1304->1321 1315 8a101b-8a1029 WaitForSingleObject 1313->1315 1316 8a0fe0-8a1009 GetLastError call 8837d3 1313->1316 1318 8a0f2e-8a0f34 1314->1318 1319 8a10d0-8a10d3 call 8bf384 1314->1319 1323 8a105b-8a1066 ResetEvent 1315->1323 1324 8a102b-8a1059 GetLastError call 8837d3 1315->1324 1334 8a100e-8a1016 call 8c012f 1316->1334 1318->1319 1325 8a0f3a-8a0f42 1318->1325 1319->1321 1321->1305 1330 8a109b-8a10a1 1323->1330 1331 8a1068-8a1096 GetLastError call 8837d3 1323->1331 1324->1334 1328 8a0fbb-8a0fce call 8c012f 1325->1328 1329 8a0f44-8a0f46 1325->1329 1328->1319 1336 8a0f58-8a0f5b 1329->1336 1337 8a0f48-8a0f56 1329->1337 1332 8a10cb 1330->1332 1333 8a10a3-8a10a6 1330->1333 1331->1334 1332->1319 1341 8a10a8-8a10c2 call 8837d3 1333->1341 1342 8a10c7-8a10c9 1333->1342 1334->1319 1345 8a0f5d 1336->1345 1346 8a0fb5 1336->1346 1344 8a0fb7-8a0fb9 1337->1344 1341->1334 1342->1319 1344->1313 1344->1328 1348 8a0faa-8a0faf 1345->1348 1349 8a0f6b-8a0f70 1345->1349 1350 8a0f79-8a0f7e 1345->1350 1351 8a0f8e-8a0f93 1345->1351 1352 8a0f9c-8a0fa1 1345->1352 1353 8a0f72-8a0f77 1345->1353 1354 8a0fa3-8a0fa8 1345->1354 1355 8a0f80-8a0f85 1345->1355 1356 8a0fb1-8a0fb3 1345->1356 1357 8a0f87-8a0f8c 1345->1357 1358 8a0f64-8a0f69 1345->1358 1359 8a0f95-8a0f9a 1345->1359 1346->1344 1348->1328 1349->1328 1350->1328 1351->1328 1352->1328 1353->1328 1354->1328 1355->1328 1356->1328 1357->1328 1358->1328 1359->1328
                                      APIs
                                      • CoInitializeEx.OLE32(00000000,00000000), ref: 008A0E65
                                      • CoUninitialize.OLE32 ref: 008A10D9
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: InitializeUninitialize
                                      • String ID: <the>.cab$Failed to extract all files from container, erf: %d:%X:%d$Failed to initialize COM.$Failed to initialize cabinet.dll.$Failed to reset begin operation event.$Failed to set operation complete event.$Failed to wait for begin operation event.$Invalid operation for this state.$cabextract.cpp
                                      • API String ID: 3442037557-1168358783
                                      • Opcode ID: e91c1163e4db4ae9788e50ec142012fce9b548b0906caf00c734818914749de5
                                      • Instruction ID: ee5b5911d7b05a051a336ec9c04fc5e3ef3437f44dccb557f4f1ba81fce7bedb
                                      • Opcode Fuzzy Hash: e91c1163e4db4ae9788e50ec142012fce9b548b0906caf00c734818914749de5
                                      • Instruction Fuzzy Hash: 64512E36A40B65EFF72056648C45E6B7664FB43720F260326FC12FBBC0DA698C409ED6
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: lstrlen
                                      • String ID: Failed to convert version: %ls to DWORD64 for ProductCode: %ls$Failed to copy the installed ProductCode to the package.$Failed to enum related products.$Failed to get product information for ProductCode: %ls$Failed to get version for product in machine context: %ls$Failed to get version for product in user unmanaged context: %ls$Failed to query feature state.$Invalid state value.$Language$UX aborted detect compatible MSI package.$UX aborted detect related MSI package.$UX aborted detect.$VersionString$msasn1.dll$msiuser.cpp
                                      • API String ID: 1659193697-2574767977
                                      • Opcode ID: ef9051994cef0343d96cf972f2bea27336a313753c8e68615445fba95d8b0a02
                                      • Instruction ID: 3475e5341fa4fabcda1066b562129fe1cd31b643cbf82091e5c746dae195c165
                                      • Opcode Fuzzy Hash: ef9051994cef0343d96cf972f2bea27336a313753c8e68615445fba95d8b0a02
                                      • Instruction Fuzzy Hash: CB228D71A00619EFEB249EA4CC81FADB7B9FF06314F10422AF515EBA51D730AE51CB51
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1569 8841d2-884229 InitializeCriticalSection * 2 call 894b0e * 2 1574 88434d-884357 call 88b389 1569->1574 1575 88422f 1569->1575 1578 88435c-884360 1574->1578 1576 884235-884242 1575->1576 1579 884248-884274 lstrlenW * 2 CompareStringW 1576->1579 1580 884340-884347 1576->1580 1583 88436f-884377 1578->1583 1584 884362-88436e call 8c012f 1578->1584 1581 8842c6-8842f2 lstrlenW * 2 CompareStringW 1579->1581 1582 884276-884299 lstrlenW 1579->1582 1580->1574 1580->1576 1581->1580 1588 8842f4-884317 lstrlenW 1581->1588 1585 88429f-8842a4 1582->1585 1586 884385-88439a call 8837d3 1582->1586 1584->1583 1585->1586 1589 8842aa-8842ba call 8829dc 1585->1589 1599 88439f-8843a6 1586->1599 1592 88431d-884322 1588->1592 1593 8843b1-8843cb call 8837d3 1588->1593 1602 88437a-884383 1589->1602 1603 8842c0 1589->1603 1592->1593 1596 884328-884338 call 8829dc 1592->1596 1593->1599 1596->1602 1607 88433a 1596->1607 1604 8843a7-8843af call 8c012f 1599->1604 1602->1604 1603->1581 1604->1583 1607->1580
                                      APIs
                                      • InitializeCriticalSection.KERNEL32(00000000,?,00000000,00000000,?,?,0088515E,?,?,00000000,?,?), ref: 008841FE
                                      • InitializeCriticalSection.KERNEL32(000000D0,?,?,0088515E,?,?,00000000,?,?), ref: 00884207
                                      • lstrlenW.KERNEL32(burn.filehandle.attached,000004B8,000004A0,?,?,0088515E,?,?,00000000,?,?), ref: 0088424D
                                      • lstrlenW.KERNEL32(burn.filehandle.attached,burn.filehandle.attached,00000000,?,?,0088515E,?,?,00000000,?,?), ref: 00884257
                                      • CompareStringW.KERNEL32(0000007F,00000001,?,00000000,?,?,0088515E,?,?,00000000,?,?), ref: 0088426B
                                      • lstrlenW.KERNEL32(burn.filehandle.attached,?,?,0088515E,?,?,00000000,?,?), ref: 0088427B
                                      • lstrlenW.KERNEL32(burn.filehandle.self,?,?,0088515E,?,?,00000000,?,?), ref: 008842CB
                                      • lstrlenW.KERNEL32(burn.filehandle.self,burn.filehandle.self,00000000,?,?,0088515E,?,?,00000000,?,?), ref: 008842D5
                                      • CompareStringW.KERNEL32(0000007F,00000001,?,00000000,?,?,0088515E,?,?,00000000,?,?), ref: 008842E9
                                      • lstrlenW.KERNEL32(burn.filehandle.self,?,?,0088515E,?,?,00000000,?,?), ref: 008842F9
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: lstrlen$CompareCriticalInitializeSectionString
                                      • String ID: Failed to initialize user section.$Failed to parse file handle: '%ls'$Missing required parameter for switch: %ls$burn.filehandle.attached$burn.filehandle.self$user.cpp
                                      • API String ID: 3039292287-3209860532
                                      • Opcode ID: 18292afdebf64c38ad1124bde38b166df43786712ccdb6735ea0bf1e4630db10
                                      • Instruction ID: c9d20b91dc987d97408f64c82038a8486077cfb5fe4183e32d7376b43f73b4b1
                                      • Opcode Fuzzy Hash: 18292afdebf64c38ad1124bde38b166df43786712ccdb6735ea0bf1e4630db10
                                      • Instruction Fuzzy Hash: A5519672A40616BFC724AB69DC46F9AB77CFB04760F04012AF624D7390D774E950C7A5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1609 89e563-89e5a0 1610 89e5c2-89e5e3 RegisterClassW 1609->1610 1611 89e5a2-89e5b6 TlsSetValue 1609->1611 1613 89e61d-89e654 CreateWindowExW 1610->1613 1614 89e5e5-89e618 GetLastError call 8837d3 1610->1614 1611->1610 1612 89e5b8-89e5bd 1611->1612 1617 89e6ec-89e702 UnregisterClassW 1612->1617 1615 89e68b-89e69f SetEvent 1613->1615 1616 89e656-89e689 GetLastError call 8837d3 1613->1616 1622 89e6e4-89e6eb call 8c012f 1614->1622 1620 89e6cb-89e6d6 KiUserCallbackDispatcher 1615->1620 1616->1622 1624 89e6d8 1620->1624 1625 89e6a1-89e6a4 1620->1625 1622->1617 1624->1617 1626 89e6da-89e6df 1625->1626 1627 89e6a6-89e6b5 IsDialogMessageW 1625->1627 1626->1622 1627->1620 1629 89e6b7-89e6c5 TranslateMessage DispatchMessageW 1627->1629 1629->1620
                                      APIs
                                      • TlsSetValue.KERNEL32(?,?), ref: 0089E5AE
                                      • RegisterClassW.USER32(?), ref: 0089E5DA
                                      • GetLastError.KERNEL32 ref: 0089E5E5
                                      • CreateWindowExW.USER32(00000080,008D9CC4,00000000,90000000,80000000,00000008,00000000,00000000,00000000,00000000,?,?), ref: 0089E64C
                                      • GetLastError.KERNEL32 ref: 0089E656
                                      • UnregisterClassW.USER32(WixBurnMessageWindow,?), ref: 0089E6F4
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ClassErrorLast$CreateRegisterUnregisterValueWindow
                                      • String ID: Failed to create window.$Failed to register window.$Unexpected return value from message pump.$WixBurnMessageWindow$uithread.cpp
                                      • API String ID: 213125376-288575659
                                      • Opcode ID: 05a979661c2dbc6847c4a9d3f6ec9164652d9dbd1caab115699d9b38546e5170
                                      • Instruction ID: 07d417278b26b52e010ee6bfbd2c83fded1234d14e28ea3555b9659a9faa64fd
                                      • Opcode Fuzzy Hash: 05a979661c2dbc6847c4a9d3f6ec9164652d9dbd1caab115699d9b38546e5170
                                      • Instruction Fuzzy Hash: 90418E72A00614ABDF21EFA4DC45EDABFF8FF18750F158126F909EA290D7319950CBA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1631 88c129-88c15b 1632 88c15d-88c17b CreateFileW 1631->1632 1633 88c1c5-88c1e1 GetCurrentProcess * 2 DuplicateHandle 1631->1633 1636 88c21d-88c223 1632->1636 1637 88c181-88c1b2 GetLastError call 8837d3 1632->1637 1634 88c21b 1633->1634 1635 88c1e3-88c219 GetLastError call 8837d3 1633->1635 1634->1636 1645 88c1b7-88c1c0 call 8c012f 1635->1645 1639 88c22d 1636->1639 1640 88c225-88c22b 1636->1640 1637->1645 1643 88c22f-88c23d SetFilePointerEx 1639->1643 1640->1643 1646 88c23f-88c272 GetLastError call 8837d3 1643->1646 1647 88c274-88c27a 1643->1647 1649 88c298-88c29e 1645->1649 1655 88c290-88c297 call 8c012f 1646->1655 1647->1649 1650 88c27c-88c280 call 8a1484 1647->1650 1656 88c285-88c289 1650->1656 1655->1649 1656->1649 1658 88c28b 1656->1658 1658->1655
                                      APIs
                                      • CreateFileW.KERNEL32(00000000,80000000,00000001,00000000,00000003,08000080,00000000,?,00000000,00000000,?,0088C319,008852FD,?,?,0088533D), ref: 0088C170
                                      • GetLastError.KERNEL32(?,0088C319,008852FD,?,?,0088533D,0088533D,00000000,?,00000000), ref: 0088C181
                                      • GetCurrentProcess.KERNEL32(?,00000000,00000000,00000002,?,00000000,00000000,?,0088C319,008852FD,?,?,0088533D,0088533D,00000000,?), ref: 0088C1D0
                                      • GetCurrentProcess.KERNEL32(000000FF,00000000,?,0088C319,008852FD,?,?,0088533D,0088533D,00000000,?,00000000), ref: 0088C1D6
                                      • DuplicateHandle.KERNELBASE(00000000,?,0088C319,008852FD,?,?,0088533D,0088533D,00000000,?,00000000), ref: 0088C1D9
                                      • GetLastError.KERNEL32(?,0088C319,008852FD,?,?,0088533D,0088533D,00000000,?,00000000), ref: 0088C1E3
                                      • SetFilePointerEx.KERNELBASE(?,00000000,00000000,00000000,00000000,?,0088C319,008852FD,?,?,0088533D,0088533D,00000000,?,00000000), ref: 0088C235
                                      • GetLastError.KERNEL32(?,0088C319,008852FD,?,?,0088533D,0088533D,00000000,?,00000000), ref: 0088C23F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CurrentFileProcess$CreateDuplicateHandlePointer
                                      • String ID: Failed to duplicate handle to container: %ls$Failed to move file pointer to container offset.$Failed to open container.$Failed to open file: %ls$container.cpp$crypt32.dll$feclient.dll
                                      • API String ID: 2619879409-373955632
                                      • Opcode ID: 5fb7228fdf27e02523b1f36bbf1e3a52b54ee7f629d4dc744437f3e272751ec6
                                      • Instruction ID: de6186917020dce19e07a829f837cc1993d903169d96204a72d2f02256e1b2f2
                                      • Opcode Fuzzy Hash: 5fb7228fdf27e02523b1f36bbf1e3a52b54ee7f629d4dc744437f3e272751ec6
                                      • Instruction Fuzzy Hash: FD41A172240301ABEB10AF699C49F577BFAFB85760F114129F918DB296DB31C801CB75
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 008837EA: GetSystemDirectoryW.KERNEL32(?,00000104), ref: 00883829
                                        • Part of subcall function 008837EA: GetLastError.KERNEL32 ref: 00883833
                                        • Part of subcall function 008C4932: GetLastError.KERNEL32(?,00000000,00000000,00000000,00000000), ref: 008C495A
                                      • GetProcAddress.KERNEL32(MsiDeterminePatchSequenceW,00000000), ref: 008C29FD
                                      • GetProcAddress.KERNEL32(MsiDetermineApplicablePatchesW), ref: 008C2A20
                                      • GetProcAddress.KERNEL32(MsiEnumProductsExW), ref: 008C2A43
                                      • GetProcAddress.KERNEL32(MsiGetPatchInfoExW), ref: 008C2A66
                                      • GetProcAddress.KERNEL32(MsiGetProductInfoExW), ref: 008C2A89
                                      • GetProcAddress.KERNEL32(MsiSetExternalUIRecord), ref: 008C2AAC
                                      • GetProcAddress.KERNEL32(MsiSourceListAddSourceExW), ref: 008C2ACF
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressProc$ErrorLast$DirectorySystem
                                      • String ID: Msi.dll$MsiDetermineApplicablePatchesW$MsiDeterminePatchSequenceW$MsiEnumProductsExW$MsiGetPatchInfoExW$MsiGetProductInfoExW$MsiSetExternalUIRecord$MsiSourceListAddSourceExW
                                      • API String ID: 2510051996-1735120554
                                      • Opcode ID: c8672177ab6e5192f52333a7415507254366da73d55d2e16d397e2b2964e7642
                                      • Instruction ID: 451ae267e97053a36f4b7508a99231981b15969284c402fc94ca20f899bc86f4
                                      • Opcode Fuzzy Hash: c8672177ab6e5192f52333a7415507254366da73d55d2e16d397e2b2964e7642
                                      • Instruction Fuzzy Hash: CD3106B0641299AFDF59DF2AEC92A2B3BB5FB65704740442EE005DA2B0E7B5D810DF04
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetErrorMode.KERNELBASE(00000000,00000000,00000000,?,00000000,?,BootstrapperCore.config,00000000,?,?), ref: 6E83166F
                                      • SetErrorMode.KERNELBASE(00000000,?,00000000,?,BootstrapperCore.config,00000000,?,?), ref: 6E831686
                                      • GetProcAddress.KERNEL32(?,CLRCreateInstance), ref: 6E8316AE
                                      • SHCreateStreamOnFileEx.SHLWAPI(?,00000020,00000000,00000000,00000000,?,?,00000000,?,BootstrapperCore.config,00000000,?,?), ref: 6E8316FD
                                      • CompareStringW.KERNEL32(00000000,00000000,v4.0.30319,000000FF,?,?,?,00000000,?,BootstrapperCore.config,00000000,?,?), ref: 6E8317A4
                                      • GetProcAddress.KERNEL32(?,CorBindToCurrentRuntime), ref: 6E831813
                                      • GetLastError.KERNEL32(?,00000000,?,BootstrapperCore.config,00000000,?,?), ref: 6E831819
                                      • FreeLibrary.KERNEL32(?,?,00000000,?,BootstrapperCore.config,00000000), ref: 6E8318C5
                                      • SetErrorMode.KERNELBASE(00000000,?,00000000,?,BootstrapperCore.config,00000000), ref: 6E8318CE
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3393212218.000000006E831000.00000020.00000001.01000000.00000007.sdmp, Offset: 6E830000, based on PE: true
                                      • Associated: 00000002.00000002.3393155013.000000006E830000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393294909.000000006E84C000.00000004.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_6e830000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Error$Mode$AddressProc$CompareCreateFileFreeLastLibraryStreamString
                                      • String ID: CLRCreateInstance$CorBindToCurrentRuntime$host.cpp$mscoree.dll$v4.0.30319
                                      • API String ID: 3217175720-388369516
                                      • Opcode ID: e7d4db5dbd615041d28cd5c38e5107af3947ec8c73bc762d7ed22a655d592131
                                      • Instruction ID: 15d8e4a336e114d766f2e08dffba11ee417e4585221777ef8b8c22eaa8e907cf
                                      • Opcode Fuzzy Hash: e7d4db5dbd615041d28cd5c38e5107af3947ec8c73bc762d7ed22a655d592131
                                      • Instruction Fuzzy Hash: 12716F31D01529EBDB119BE9CC44E9EBBB8EF85B54F214A59E814BB350C7309905CBE4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleHandleA.KERNEL32(kernel32.dll,00000000,00000000,00000000,00000000,00000000,?,?,?,6E8310B0,?,?,00000000,00000000,6E8314A6,00000000), ref: 6E832EEB
                                      • GetLastError.KERNEL32(?,?,?,6E8310B0,?,?,00000000,00000000,6E8314A6,00000000,?,BootstrapperCore.config,00000000,?,?), ref: 6E832EF7
                                      • GetProcAddress.KERNEL32(00000000,IsWow64Process), ref: 6E832F37
                                      • GetProcAddress.KERNEL32(00000000,Wow64DisableWow64FsRedirection), ref: 6E832F43
                                      • GetProcAddress.KERNEL32(00000000,Wow64EnableWow64FsRedirection), ref: 6E832F4E
                                      • GetProcAddress.KERNEL32(00000000,Wow64RevertWow64FsRedirection), ref: 6E832F58
                                      • CoCreateInstance.OLE32(6E84C7D4,00000000,00000001,6E844220,?,?,?,?,6E8310B0,?,?,00000000,00000000,6E8314A6,00000000,?), ref: 6E832F93
                                      • ExitProcess.KERNEL32 ref: 6E833042
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3393212218.000000006E831000.00000020.00000001.01000000.00000007.sdmp, Offset: 6E830000, based on PE: true
                                      • Associated: 00000002.00000002.3393155013.000000006E830000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393294909.000000006E84C000.00000004.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_6e830000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressProc$CreateErrorExitHandleInstanceLastModuleProcess
                                      • String ID: IsWow64Process$Wow64DisableWow64FsRedirection$Wow64EnableWow64FsRedirection$Wow64RevertWow64FsRedirection$kernel32.dll$xmlutil.cpp
                                      • API String ID: 2124981135-499589564
                                      • Opcode ID: ca4f64cb137efa6871f69cdb2d0e5e5b393997d0e2a955abfc568068731d5048
                                      • Instruction ID: 583d08fe45211824d64dc6eb7f97f3c6011699f7d7be9db83613f33f66229cf0
                                      • Opcode Fuzzy Hash: ca4f64cb137efa6871f69cdb2d0e5e5b393997d0e2a955abfc568068731d5048
                                      • Instruction Fuzzy Hash: D241D135A4062AEBEB20DEE8C894B5E77B4EF45751F210968E911EB380D775CD01CBD0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleHandleA.KERNEL32(kernel32.dll,00000000,00000000,008C34DF,00000000,?,00000000), ref: 008C2F3D
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,008ABDED,?,008852FD,?,00000000,?), ref: 008C2F49
                                      • GetProcAddress.KERNEL32(00000000,IsWow64Process), ref: 008C2F89
                                      • GetProcAddress.KERNEL32(00000000,Wow64DisableWow64FsRedirection), ref: 008C2F95
                                      • GetProcAddress.KERNEL32(00000000,Wow64EnableWow64FsRedirection), ref: 008C2FA0
                                      • GetProcAddress.KERNEL32(00000000,Wow64RevertWow64FsRedirection), ref: 008C2FAA
                                      • CoCreateInstance.OLE32(008EB6C8,00000000,00000001,008CB808,?,?,?,?,?,?,?,?,?,?,?,008ABDED), ref: 008C2FE5
                                      • ExitProcess.KERNEL32 ref: 008C3094
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressProc$CreateErrorExitHandleInstanceLastModuleProcess
                                      • String ID: IsWow64Process$Wow64DisableWow64FsRedirection$Wow64EnableWow64FsRedirection$Wow64RevertWow64FsRedirection$kernel32.dll$xmlutil.cpp
                                      • API String ID: 2124981135-499589564
                                      • Opcode ID: 86c3fb2787fb4fe6d0346d32dc2db9a4bd1c80a668e75be1df6849f5e5d0dd16
                                      • Instruction ID: 37d8073132b1d1065e93734b1c88922d4dd6acbe2ebb0b31217ce564d9be9d1b
                                      • Opcode Fuzzy Hash: 86c3fb2787fb4fe6d0346d32dc2db9a4bd1c80a668e75be1df6849f5e5d0dd16
                                      • Instruction Fuzzy Hash: F041DC32A00B59ABDB20DFA98845FAEB7F4FF45751F11806DE901EB290DB71DE018B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,wininet.dll,?,00000000,00000000,00000000,?,?,0088C285,?,00000000,?,0088C319), ref: 008A14BB
                                      • GetLastError.KERNEL32(?,0088C285,?,00000000,?,0088C319,008852FD,?,?,0088533D,0088533D,00000000,?,00000000), ref: 008A14C4
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateErrorEventLast
                                      • String ID: Failed to copy file name.$Failed to create begin operation event.$Failed to create extraction thread.$Failed to create operation complete event.$Failed to wait for operation complete.$cabextract.cpp$wininet.dll
                                      • API String ID: 545576003-938279966
                                      • Opcode ID: d76fda14fbe30743d67341ff9f52c23910b22fcffa660d6514b2d01aa24b3020
                                      • Instruction ID: cf1e3facd509c88d513d61a4c43bc57cfa68b10e1173b7d2f304ab0c32bef00e
                                      • Opcode Fuzzy Hash: d76fda14fbe30743d67341ff9f52c23910b22fcffa660d6514b2d01aa24b3020
                                      • Instruction Fuzzy Hash: 2D21F7B2E40B357AFB2066795C45F6766ECFB457A0F110222BC15E7B80EB64DC0086E6
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcAddress.KERNELBASE(SystemFunction040,AdvApi32.dll), ref: 008BFBD5
                                      • GetProcAddress.KERNEL32(SystemFunction041), ref: 008BFBE7
                                      • GetProcAddress.KERNEL32(CryptProtectMemory,Crypt32.dll), ref: 008BFC2A
                                      • GetLastError.KERNEL32(?,?,?,?,?,?), ref: 008BFC3E
                                      • GetProcAddress.KERNEL32(CryptUnprotectMemory), ref: 008BFC76
                                      • GetLastError.KERNEL32(?,?,?,?,?,?), ref: 008BFC8A
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AddressProc$ErrorLast
                                      • String ID: AdvApi32.dll$Crypt32.dll$CryptProtectMemory$CryptUnprotectMemory$SystemFunction040$SystemFunction041$cryputil.cpp
                                      • API String ID: 4214558900-3191127217
                                      • Opcode ID: f898ee680be614eb01e8db464b73ea176d3ac6fa1915bd1b6c3a0bbc96a7df35
                                      • Instruction ID: 80c62bc0f2f3d40f676c383ea5e9a266af6efab1d5737e65ac9fa1372173d8c3
                                      • Opcode Fuzzy Hash: f898ee680be614eb01e8db464b73ea176d3ac6fa1915bd1b6c3a0bbc96a7df35
                                      • Instruction Fuzzy Hash: 3D21A431A447BA9BD7226B279D55B537AD0FB11790F010235ED10EB372E7749C408A90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringA.KERNELBASE(00000000,00000000,<the>.cab,?,?), ref: 008A0657
                                      • GetCurrentProcess.KERNEL32(?,00000000,00000000,00000000,?,?), ref: 008A066F
                                      • GetCurrentProcess.KERNEL32(?,00000000,?,?), ref: 008A0674
                                      • DuplicateHandle.KERNELBASE(00000000,?,?), ref: 008A0677
                                      • GetLastError.KERNEL32(?,?), ref: 008A0681
                                      • CreateFileA.KERNEL32(?,80000000,00000001,00000000,00000003,08000080,00000000,?,?), ref: 008A06F0
                                      • GetLastError.KERNEL32(?,?), ref: 008A06FD
                                      Strings
                                      • <the>.cab, xrefs: 008A0650
                                      • Failed to duplicate handle to cab container., xrefs: 008A06AF
                                      • Failed to open cabinet file: %hs, xrefs: 008A072E
                                      • Failed to add virtual file pointer for cab container., xrefs: 008A06D6
                                      • cabextract.cpp, xrefs: 008A06A5, 008A0721
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CurrentErrorLastProcess$CompareCreateDuplicateFileHandleString
                                      • String ID: <the>.cab$Failed to add virtual file pointer for cab container.$Failed to duplicate handle to cab container.$Failed to open cabinet file: %hs$cabextract.cpp
                                      • API String ID: 3030546534-3446344238
                                      • Opcode ID: 28422550773a793c2b80cb0e80ce68e2cabc6bcab692bfbd5a52a3f0ac06f70b
                                      • Instruction ID: e82c87e9cb29bea917e348dd479483466a0de0db4a17ff9ec3abc989c62a40e6
                                      • Opcode Fuzzy Hash: 28422550773a793c2b80cb0e80ce68e2cabc6bcab692bfbd5a52a3f0ac06f70b
                                      • Instruction Fuzzy Hash: 92310472A41B35BBEB206B698C49F9B7BACFF05760F110226FD08E7650D7319D108AE5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00893955: RegCloseKey.ADVAPI32(00000000,SOFTWARE\Policies\Microsoft\Windows\Installer,00020019,00000001,feclient.dll,?,?,?,00893E61,feclient.dll,?,00000000,?,?,?,00884A0C), ref: 008939F1
                                      • Sleep.KERNEL32(000007D0,00000001,feclient.dll,?,00000000,?,?,?,00884A0C,?,?,008CB478,?,00000001,00000000,00000000), ref: 00893EF8
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseSleep
                                      • String ID: Failed to copy full log path to prefix.$Failed to copy log extension to extension.$Failed to copy log path to prefix.$Failed to get current directory.$Failed to get non-session specific TEMP folder.$Failed to open log: %ls$Setup$clbcatq.dll$crypt32.dll$feclient.dll$log$msasn1.dll
                                      • API String ID: 2834455192-2673269691
                                      • Opcode ID: cbddcc17c07ff4c841eabde99fb012d792cca963de52bbec356f7144b9649c50
                                      • Instruction ID: d092acf4f2a365e1c167dd86bb193b405f139e7af920271b045acf3717000784
                                      • Opcode Fuzzy Hash: cbddcc17c07ff4c841eabde99fb012d792cca963de52bbec356f7144b9649c50
                                      • Instruction Fuzzy Hash: B7619071A00616BBDF25FB68CC46F6A7BB8FF14340B184269F805DB641EB71EE508792
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(00000001,?,00000000,0088533D,00000000,00000001), ref: 00886C6E
                                        • Part of subcall function 008855B6: CompareStringW.KERNEL32(0000007F,00001000,?,000000FF,version.dll,000000FF,?,00000000,00000007,0088648B,0088648B,?,0088554A,?,?,00000000), ref: 008855F2
                                        • Part of subcall function 008855B6: GetLastError.KERNEL32(?,0088554A,?,?,00000000,?,00000000,0088648B,?,00887DDC,?,?,?,?,?), ref: 00885621
                                      • LeaveCriticalSection.KERNEL32(00000001,?,00000001), ref: 00886E02
                                      Strings
                                      • Setting string variable '%ls' to value '%ls', xrefs: 00886D96
                                      • Failed to insert variable '%ls'., xrefs: 00886CB3
                                      • Setting hidden variable '%ls', xrefs: 00886D2C
                                      • variable.cpp, xrefs: 00886CF1
                                      • Failed to find variable value '%ls'., xrefs: 00886C89
                                      • Setting version variable '%ls' to value '%hu.%hu.%hu.%hu', xrefs: 00886D79
                                      • Attempt to set built-in variable value: %ls, xrefs: 00886CFC
                                      • Unsetting variable '%ls', xrefs: 00886DBE
                                      • Failed to set value of variable: %ls, xrefs: 00886DEA
                                      • Setting variable failed: ID '%ls', HRESULT 0x%x, xrefs: 00886E14
                                      • Setting numeric variable '%ls' to value %lld, xrefs: 00886DA3
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalSection$CompareEnterErrorLastLeaveString
                                      • String ID: Attempt to set built-in variable value: %ls$Failed to find variable value '%ls'.$Failed to insert variable '%ls'.$Failed to set value of variable: %ls$Setting hidden variable '%ls'$Setting numeric variable '%ls' to value %lld$Setting string variable '%ls' to value '%ls'$Setting variable failed: ID '%ls', HRESULT 0x%x$Setting version variable '%ls' to value '%hu.%hu.%hu.%hu'$Unsetting variable '%ls'$variable.cpp
                                      • API String ID: 2716280545-445000439
                                      • Opcode ID: e6eec6519d58caa26fb3cfc9da6496994d83ec78eab7a90b1d6ae108e28a08b3
                                      • Instruction ID: 63498c31e22b8fb3b6796c14590b3a0834499591494e4d7d961bdb18576a22ff
                                      • Opcode Fuzzy Hash: e6eec6519d58caa26fb3cfc9da6496994d83ec78eab7a90b1d6ae108e28a08b3
                                      • Instruction Fuzzy Hash: 5751D271A00219A7CB30BE18CD4AF6B7A79FB95704F14011DF858DA382E676DD61CBE2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • IsWindow.USER32(?), ref: 00884B5E
                                      • PostMessageW.USER32(?,00000010,00000000,00000000), ref: 00884B6F
                                      Strings
                                      • Failed to set registration variables., xrefs: 00884AD8
                                      • Failed to check global conditions, xrefs: 00884A43
                                      • Failed to set layout directory variable to value provided from command-line., xrefs: 00884B00
                                      • Failed to create the message window., xrefs: 00884A92
                                      • Failed to query registration., xrefs: 00884AA8
                                      • Failed while running , xrefs: 00884B24
                                      • WixBundleLayoutDirectory, xrefs: 00884AEF
                                      • Failed to open log., xrefs: 00884A12
                                      • Failed to set action variables., xrefs: 00884ABE
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: MessagePostWindow
                                      • String ID: Failed to check global conditions$Failed to create the message window.$Failed to open log.$Failed to query registration.$Failed to set action variables.$Failed to set layout directory variable to value provided from command-line.$Failed to set registration variables.$Failed while running $WixBundleLayoutDirectory
                                      • API String ID: 3618638489-3051724725
                                      • Opcode ID: 80a8083549953ab0a5447a06d446163c7974aed7c198cffac364a762be101d94
                                      • Instruction ID: 75c52228cf3e8e70d77b146a671c0b7302f05c0b13ca3329ea0093603fa6e5fe
                                      • Opcode Fuzzy Hash: 80a8083549953ab0a5447a06d446163c7974aed7c198cffac364a762be101d94
                                      • Instruction Fuzzy Hash: 3B410B32640A2BBBDB16BAA4CC46FBBB66CFF00764F041225B415E6550D770ED1097D1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetTempPathW.KERNEL32(00000104,?,00000001,00000000,00000000), ref: 00882E7A
                                      • GetLastError.KERNEL32 ref: 00882E84
                                      • GetLocalTime.KERNEL32(?,?,?,?,?,?), ref: 00882F1F
                                      • CreateFileW.KERNELBASE(?,40000000,00000001,00000000,00000001,00000080,00000000), ref: 00882FAD
                                      • GetLastError.KERNEL32 ref: 00882FBA
                                      • Sleep.KERNEL32(00000064), ref: 00882FCC
                                      • CloseHandle.KERNEL32(?), ref: 0088302C
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CloseCreateFileHandleLocalPathSleepTempTime
                                      • String ID: 4#v$%ls_%04u%02u%02u%02u%02u%02u%ls%ls%ls$pathutil.cpp
                                      • API String ID: 3480017824-1777530710
                                      • Opcode ID: 30a91687b8f743492ac0a5d550bf8cbd720f1d2b1e99692d0a8a3f0eaae22f2f
                                      • Instruction ID: e7e180ec414ecf999a365b1089ac93ae53f486e1e3a75918f18652dec9732b2a
                                      • Opcode Fuzzy Hash: 30a91687b8f743492ac0a5d550bf8cbd720f1d2b1e99692d0a8a3f0eaae22f2f
                                      • Instruction Fuzzy Hash: F9715472D41629ABDB31ABA8DC49BAAB3F8FB08711F000195FA05E7191D774DE80CB61
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • VariantInit.OLEAUT32(?), ref: 6E83123F
                                      • SysAllocString.OLEAUT32(BootstrapperCore, Version=3.0.0.0, Culture=neutral, PublicKeyToken=ce35f76fcda82bad), ref: 6E831250
                                      • SysAllocString.OLEAUT32(Microsoft.Tools.WindowsInstallerXml.Bootstrapper.BootstrapperApplicationFactory), ref: 6E83126F
                                      • VariantClear.OLEAUT32(?), ref: 6E8312FC
                                      • SysFreeString.OLEAUT32(00000000), ref: 6E831318
                                      • SysFreeString.OLEAUT32(00000000), ref: 6E831323
                                      Strings
                                      • BootstrapperCore, Version=3.0.0.0, Culture=neutral, PublicKeyToken=ce35f76fcda82bad, xrefs: 6E83124B
                                      • host.cpp, xrefs: 6E8312EE
                                      • Microsoft.Tools.WindowsInstallerXml.Bootstrapper.BootstrapperApplicationFactory, xrefs: 6E83126A
                                      • p=Dv, xrefs: 6E83123F
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3393212218.000000006E831000.00000020.00000001.01000000.00000007.sdmp, Offset: 6E830000, based on PE: true
                                      • Associated: 00000002.00000002.3393155013.000000006E830000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393294909.000000006E84C000.00000004.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_6e830000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$AllocFreeVariant$ClearInit
                                      • String ID: BootstrapperCore, Version=3.0.0.0, Culture=neutral, PublicKeyToken=ce35f76fcda82bad$Microsoft.Tools.WindowsInstallerXml.Bootstrapper.BootstrapperApplicationFactory$host.cpp$p=Dv
                                      • API String ID: 2225245433-740776165
                                      • Opcode ID: 958867df8e597533c4e930dabeb598632043a92a326eb9d2892ee99c156b5fbb
                                      • Instruction ID: 41ced0cc42d5ba9a7e781d9cc8f3c423d7748e4b4e0635edd3083a063492da21
                                      • Opcode Fuzzy Hash: 958867df8e597533c4e930dabeb598632043a92a326eb9d2892ee99c156b5fbb
                                      • Instruction Fuzzy Hash: F831B571A4122DEFDB21DAE9C948E9B77B8DF85B11B210569F909EB340DA70CD05C7E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,00000000,?,?,00885386,?,?), ref: 0089E84A
                                      • GetLastError.KERNEL32(?,00885386,?,?), ref: 0089E857
                                      • CreateThread.KERNELBASE(00000000,00000000,Function_0001E563,?,00000000,00000000), ref: 0089E8B0
                                      • GetLastError.KERNEL32(?,00885386,?,?), ref: 0089E8BD
                                      • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF,?,00885386,?,?), ref: 0089E8F8
                                      • CloseHandle.KERNEL32(00000000,?,00885386,?,?), ref: 0089E917
                                      • FindCloseChangeNotification.KERNELBASE(?,?,00885386,?,?), ref: 0089E924
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateErrorLast$ChangeEventFindHandleMultipleNotificationObjectsThreadWait
                                      • String ID: Failed to create initialization event.$Failed to create the UI thread.$uithread.cpp
                                      • API String ID: 1372344712-3599963359
                                      • Opcode ID: 7dc024ce0a14081007ddbce3ce15dfc9f60a7100f5dde76cb0d4a82d553125b0
                                      • Instruction ID: ff785ef45e6918bef7389f1e9873628265b2dfc63081ddb11f36e4b66cbfff92
                                      • Opcode Fuzzy Hash: 7dc024ce0a14081007ddbce3ce15dfc9f60a7100f5dde76cb0d4a82d553125b0
                                      • Instruction Fuzzy Hash: 97313275E40619BBEB10EFA99D85AAFBAFCFF08750F114126F915F3251D6309E008AA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,00000000,00000000,?,?,00885386,?,?), ref: 0089E415
                                      • GetLastError.KERNEL32(?,?,00885386,?,?), ref: 0089E422
                                      • CreateThread.KERNELBASE(00000000,00000000,Function_0001E177,00000000,00000000,00000000), ref: 0089E481
                                      • GetLastError.KERNEL32(?,?,00885386,?,?), ref: 0089E48E
                                      • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF,?,?,00885386,?,?), ref: 0089E4C9
                                      • FindCloseChangeNotification.KERNELBASE(?,?,?,00885386,?,?), ref: 0089E4DD
                                      • CloseHandle.KERNEL32(?,?,?,00885386,?,?), ref: 0089E4EA
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCreateErrorLast$ChangeEventFindHandleMultipleNotificationObjectsThreadWait
                                      • String ID: Failed to create UI thread.$Failed to create modal event.$splashscreen.cpp
                                      • API String ID: 1372344712-1977201954
                                      • Opcode ID: 427e04daf5e0f85b58c233de86012885c0c945e176961199008695ff3c028cbf
                                      • Instruction ID: 3c088a957d1af6ea47add9beb93c186596ed4506f7dd861a46ad4dbf765f6c56
                                      • Opcode Fuzzy Hash: 427e04daf5e0f85b58c233de86012885c0c945e176961199008695ff3c028cbf
                                      • Instruction Fuzzy Hash: 89316175D00719BBEB11ABA9DC45EAFBBF8FB44710F11412BFD15E2250D7744A008BA5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF,?,76232F60,?,?,008852FD,008852B5,00000000,0088533D), ref: 008A1249
                                      • GetLastError.KERNEL32 ref: 008A125C
                                      • GetExitCodeThread.KERNELBASE(008CB478,?), ref: 008A129E
                                      • GetLastError.KERNEL32 ref: 008A12AC
                                      • ResetEvent.KERNEL32(008CB450), ref: 008A12E7
                                      • GetLastError.KERNEL32 ref: 008A12F1
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CodeEventExitMultipleObjectsResetThreadWait
                                      • String ID: Failed to get extraction thread exit code.$Failed to reset operation complete event.$Failed to wait for operation complete event.$cabextract.cpp
                                      • API String ID: 2979751695-3400260300
                                      • Opcode ID: d7ddd978146474120aeaa66e02485f970173421fabeda64365eeb2529d6e3ee5
                                      • Instruction ID: 720c28aa38488f7daad9208edec8348b99c2bb99e8f8ff035d04e27a82de55bf
                                      • Opcode Fuzzy Hash: d7ddd978146474120aeaa66e02485f970173421fabeda64365eeb2529d6e3ee5
                                      • Instruction Fuzzy Hash: 5F21B1B1600704AFFF18AB798D4AABE77F8FB05710F10412EA896D66A0E734CA009B15
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • LoadLibraryW.KERNELBASE(?,00000000,?,008846F8,00000000,00000000,wininet.dll,?,00000000,00000000,?,?,00885386,?,?), ref: 0088D5CD
                                      • GetLastError.KERNEL32(?,008846F8,00000000,00000000,wininet.dll,?,00000000,00000000,?,?,00885386,?,?), ref: 0088D5DA
                                      • GetProcAddress.KERNEL32(00000000,BootstrapperApplicationCreate), ref: 0088D612
                                      • GetLastError.KERNEL32(?,008846F8,00000000,00000000,wininet.dll,?,00000000,00000000,?,?,00885386,?,?), ref: 0088D61E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$AddressLibraryLoadProc
                                      • String ID: BootstrapperApplicationCreate$Failed to create UX.$Failed to get BootstrapperApplicationCreate entry-point$Failed to load UX DLL.$userexperience.cpp$wininet.dll
                                      • API String ID: 1866314245-1140179540
                                      • Opcode ID: cd5a06d013bbf4a10f798d03a2fb1c60c5207cc3135e5815d1a1a533c78d4dd4
                                      • Instruction ID: f59cb83cf8532c22e821d8ac3372d2f16aef3f50b32eccf4f0f5ce65cf5db8a7
                                      • Opcode Fuzzy Hash: cd5a06d013bbf4a10f798d03a2fb1c60c5207cc3135e5815d1a1a533c78d4dd4
                                      • Instruction Fuzzy Hash: E911E332A50B25ABEB20AA689C05F5737E5FF04761F01402EFE1AE3290EE34DC008BD5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ExpandEnvironmentStringsW.KERNEL32(00000000,00000000,00000000,00000000,00000040,00000000,00000000), ref: 008830C7
                                      • GetLastError.KERNEL32 ref: 008830D1
                                      • ExpandEnvironmentStringsW.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 00883129
                                      • GetLastError.KERNEL32 ref: 00883133
                                      • GetFullPathNameW.KERNEL32(00000000,00000040,00000000,00000000,00000000,00000040,00000000,00000000), ref: 008831EC
                                      • GetLastError.KERNEL32 ref: 008831F6
                                      • GetFullPathNameW.KERNEL32(00000000,00000007,00000000,00000000,00000000,00000007), ref: 0088324D
                                      • GetLastError.KERNEL32 ref: 00883257
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$EnvironmentExpandFullNamePathStrings
                                      • String ID: pathutil.cpp
                                      • API String ID: 1547313835-741606033
                                      • Opcode ID: cc0a477e3d12416ded8d9466f790f0ec0113f6b5b6d8b65d55b617b36062dad6
                                      • Instruction ID: e87c1a50fb2e84bfc1a99956d04d03623fc409c7bfc7620bab872833cf0e25d4
                                      • Opcode Fuzzy Hash: cc0a477e3d12416ded8d9466f790f0ec0113f6b5b6d8b65d55b617b36062dad6
                                      • Instruction Fuzzy Hash: 78619072E00629BBEF21AAA98C49BAE7AF8FF44B51F114165FD05E7150E734DF408B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CompareStringW.KERNEL32(0000007F,00000000,FFFEB88D,000000FF,?,000000FF,00885381,?,008852B5,00000000,00885381,FFF9E89D,00885381,008853B5,0088533D,?), ref: 0088CB15
                                      Strings
                                      • Failed to ensure directory exists, xrefs: 0088CBE7
                                      • Failed to get next stream., xrefs: 0088CBFC
                                      • Failed to concat file paths., xrefs: 0088CBF5
                                      • Failed to extract file., xrefs: 0088CBE0
                                      • payload.cpp, xrefs: 0088CC16
                                      • Failed to find embedded payload: %ls, xrefs: 0088CB41
                                      • Payload was not found in container: %ls, xrefs: 0088CC22
                                      • Failed to get directory portion of local file path, xrefs: 0088CBEE
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareString
                                      • String ID: Failed to concat file paths.$Failed to ensure directory exists$Failed to extract file.$Failed to find embedded payload: %ls$Failed to get directory portion of local file path$Failed to get next stream.$Payload was not found in container: %ls$payload.cpp
                                      • API String ID: 1825529933-1711239286
                                      • Opcode ID: 3d05bcef6a79bed457b7e9ad6767804a2c196aeeaa14095aa654836097ad41f3
                                      • Instruction ID: e6d12c7530786494d72be80e31efb8fb936f68d3f85ad0f3036341521ff42e43
                                      • Opcode Fuzzy Hash: 3d05bcef6a79bed457b7e9ad6767804a2c196aeeaa14095aa654836097ad41f3
                                      • Instruction Fuzzy Hash: 3B41D331900629EBCF15EF98C882E6EBB76FF00720F104169E915EB25AC370DD40DBA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • PeekMessageW.USER32(00000000,00000000,00000400,00000400,00000000), ref: 008846B5
                                      • GetCurrentThreadId.KERNEL32 ref: 008846BB
                                        • Part of subcall function 0089FC51: new.LIBCMT ref: 0089FC58
                                      • GetMessageW.USER32(00000000,00000000,00000000,00000000), ref: 00884749
                                      Strings
                                      • wininet.dll, xrefs: 008846E8
                                      • Unexpected return value from message pump., xrefs: 0088479F
                                      • Failed to load UX., xrefs: 008846FE
                                      • Failed to start bootstrapper application., xrefs: 00884717
                                      • user.cpp, xrefs: 00884795
                                      • Failed to create user for UX., xrefs: 008846D5
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Message$CurrentPeekThread
                                      • String ID: Failed to create user for UX.$Failed to load UX.$Failed to start bootstrapper application.$Unexpected return value from message pump.$user.cpp$wininet.dll
                                      • API String ID: 673430819-2573580774
                                      • Opcode ID: 5edefcf8886a12e087faaac4669cd3ef1eb7158af56037f002c784412548f47d
                                      • Instruction ID: 9b2da5c884bd90fbf3249e0b741a4cd5b3cad5f43c3c8a233bfbc6002dcc2bcf
                                      • Opcode Fuzzy Hash: 5edefcf8886a12e087faaac4669cd3ef1eb7158af56037f002c784412548f47d
                                      • Instruction Fuzzy Hash: 0941917260061ABFEB14BAA4CC85EBAB7BCFF05314F100129F915E7240EB35ED0587A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • LoadBitmapW.USER32(?,00000001), ref: 0089E094
                                      • GetLastError.KERNEL32 ref: 0089E0A0
                                      • GetObjectW.GDI32(00000000,00000018,?), ref: 0089E0E7
                                      • GetCursorPos.USER32(?), ref: 0089E108
                                      • MonitorFromPoint.USER32(?,?,00000002), ref: 0089E11A
                                      • GetMonitorInfoW.USER32(00000000,?), ref: 0089E130
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Monitor$BitmapCursorErrorFromInfoLastLoadObjectPoint
                                      • String ID: ($Failed to load splash screen bitmap.$splashscreen.cpp
                                      • API String ID: 2342928100-598475503
                                      • Opcode ID: d76f27028e883ed7ea34a30fe8f794f7c4e266037805cb627f8d9aefe201f6ae
                                      • Instruction ID: 23dbee8d2b10d839fe28d66b9bb65a18f4a899e9296b24736db01202e59ae277
                                      • Opcode Fuzzy Hash: d76f27028e883ed7ea34a30fe8f794f7c4e266037805cb627f8d9aefe201f6ae
                                      • Instruction Fuzzy Hash: E0311E71A006199FDB10DFB8D986A9EBBF5FF08711F148129F905EB244EB70E905CBA1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 6E832117: GetModuleFileNameW.KERNEL32(?,?,00000104,?,00000104,00000000,?,?,?,6E831459,?), ref: 6E832138
                                      • SysAllocString.OLEAUT32(?), ref: 6E83153B
                                      • SysAllocString.OLEAUT32(00000000), ref: 6E83157D
                                      • SysFreeString.OLEAUT32(00000000), ref: 6E8315F5
                                      • SysFreeString.OLEAUT32(?), ref: 6E8315FE
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3393212218.000000006E831000.00000020.00000001.01000000.00000007.sdmp, Offset: 6E830000, based on PE: true
                                      • Associated: 00000002.00000002.3393155013.000000006E830000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393294909.000000006E84C000.00000004.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_6e830000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: String$AllocFree$FileModuleName
                                      • String ID: BootstrapperCore.config$MBA$host.cpp
                                      • API String ID: 1371041548-1101837331
                                      • Opcode ID: 95a9cc3d57883cd70f2ff9c1dacd084fb313784c5026441dcc5d80cfd1d557a4
                                      • Instruction ID: 00b6da6ad88ec5e09eda123a9444d0933e99a7316f37a63aaf1fd609c16ae5b3
                                      • Opcode Fuzzy Hash: 95a9cc3d57883cd70f2ff9c1dacd084fb313784c5026441dcc5d80cfd1d557a4
                                      • Instruction Fuzzy Hash: E9517D31D0162AEFDB22DBD8C954FAE7BB9EF45B15F210A54E901AB250DB308D05CBD0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegCloseKey.ADVAPI32(?,?,?,00000001,?,?,?,00000001,00000000,?,00000000,?,?,?,00000000,?), ref: 0088F7CD
                                      • RegCloseKey.ADVAPI32(00000000,?,?,00000001,?,?,?,00000001,00000000,?,00000000,?,?,?,00000000,?), ref: 0088F7DA
                                      Strings
                                      • %ls.RebootRequired, xrefs: 0088F6BA
                                      • Failed to open registration key., xrefs: 0088F736
                                      • Resume, xrefs: 0088F741
                                      • Failed to format pending restart registry key to read., xrefs: 0088F6D1
                                      • Failed to read Resume value., xrefs: 0088F763
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Close
                                      • String ID: %ls.RebootRequired$Failed to format pending restart registry key to read.$Failed to open registration key.$Failed to read Resume value.$Resume
                                      • API String ID: 3535843008-3890505273
                                      • Opcode ID: ccc3b6ac078fd1235b9da84b2f6abd47d959275b3add662acc9b71f8237744ac
                                      • Instruction ID: 462e2772b2dff9a9a70a0f289280510ade1ae8f9068b39377321c4a4d888434a
                                      • Opcode Fuzzy Hash: ccc3b6ac078fd1235b9da84b2f6abd47d959275b3add662acc9b71f8237744ac
                                      • Instruction Fuzzy Hash: 5E418136900159EFEB11BF98C881AADBBB5FF01314F258176EA14EB312D3759E40DB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 6E8331F5: CoInitialize.OLE32(00000000), ref: 6E833204
                                        • Part of subcall function 6E8331F5: InterlockedIncrement.KERNEL32(6E84C7E4), ref: 6E833221
                                        • Part of subcall function 6E8331F5: CLSIDFromProgID.OLE32(Msxml2.DOMDocument,6E84C7D4,?,?), ref: 6E83323C
                                        • Part of subcall function 6E8331F5: CLSIDFromProgID.OLE32(MSXML.DOMDocument,6E84C7D4,?,?), ref: 6E833248
                                      • RegCloseKey.ADVAPI32(?,00000000,00000000,6E8314A6,00000000,?,BootstrapperCore.config,00000000,?,?), ref: 6E8311D4
                                        • Part of subcall function 6E8334FF: VariantInit.OLEAUT32(?), ref: 6E83350B
                                        • Part of subcall function 6E8334FF: SysAllocString.OLEAUT32(?), ref: 6E83351B
                                        • Part of subcall function 6E8334FF: VariantClear.OLEAUT32(?), ref: 6E833558
                                      Strings
                                      • version, xrefs: 6E8310FB
                                      • Install, xrefs: 6E83114E
                                      • SOFTWARE\Microsoft\NET Framework Setup\NDP\%ls, xrefs: 6E831118
                                      • /configuration/wix.bootstrapper/host/supportedFramework, xrefs: 6E8310BE
                                      • host.cpp, xrefs: 6E831199
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3393212218.000000006E831000.00000020.00000001.01000000.00000007.sdmp, Offset: 6E830000, based on PE: true
                                      • Associated: 00000002.00000002.3393155013.000000006E830000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393294909.000000006E84C000.00000004.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_6e830000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FromProgVariant$AllocClearCloseIncrementInitInitializeInterlockedString
                                      • String ID: /configuration/wix.bootstrapper/host/supportedFramework$Install$SOFTWARE\Microsoft\NET Framework Setup\NDP\%ls$host.cpp$version
                                      • API String ID: 126564746-712564890
                                      • Opcode ID: 9ee9b2a06bae1b92b5b0d1c33f73dd16798bf4898be1be6332eff38e8328b34b
                                      • Instruction ID: d6bb136975149fe92b1c09a8a99a4eca2ee17364c166db05c676eec74241c19a
                                      • Opcode Fuzzy Hash: 9ee9b2a06bae1b92b5b0d1c33f73dd16798bf4898be1be6332eff38e8328b34b
                                      • Instruction Fuzzy Hash: 6A514B75D0162AEFCF11DFD9C814AEEBBB8AF45B05B214969E810B7261D7318E04CBD0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • EnterCriticalSection.KERNEL32(008EB60C,00000000,?,?,?,00885407,00000000,Setup,_Failed,txt,00000000,00000000,00000000,?,?,?), ref: 008C042B
                                      • CreateFileW.KERNEL32(40000000,00000001,00000000,00000002,00000080,00000000,?,00000000,?,?,?,008EB604,?,00885407,00000000,Setup), ref: 008C04CC
                                      • GetLastError.KERNEL32(?,00885407,00000000,Setup,_Failed,txt,00000000,00000000,00000000,?,?,?), ref: 008C04DC
                                      • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002,?,00885407,00000000,Setup,_Failed,txt,00000000,00000000,00000000,?,?,?), ref: 008C0515
                                        • Part of subcall function 00882DE0: GetLocalTime.KERNEL32(?,?,?,?,?,?), ref: 00882F1F
                                      • LeaveCriticalSection.KERNEL32(008EB60C,?,?,008EB604,?,00885407,00000000,Setup,_Failed,txt,00000000,00000000,00000000,?,?,?), ref: 008C056E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CriticalFileSection$CreateEnterErrorLastLeaveLocalPointerTime
                                      • String ID: logutil.cpp
                                      • API String ID: 4111229724-3545173039
                                      • Opcode ID: 0add7cb6f7d2d933f331ac16bb8b1f763e9d94848508733403ab441fab1c4410
                                      • Instruction ID: 2002e1aff7248bafd08d7a77441a2416fae8bdd0141cb5a06dc7a00647436100
                                      • Opcode Fuzzy Hash: 0add7cb6f7d2d933f331ac16bb8b1f763e9d94848508733403ab441fab1c4410
                                      • Instruction Fuzzy Hash: B9316FB1E01659EFDB21AF659C82F6B3A78FB11B95F000129FA00EA260D770DD409F91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      Strings
                                      • Unexpected call to CabWrite()., xrefs: 008A0923
                                      • Failed to write during cabinet extraction., xrefs: 008A0997
                                      • cabextract.cpp, xrefs: 008A098D
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastWrite_memcpy_s
                                      • String ID: Failed to write during cabinet extraction.$Unexpected call to CabWrite().$cabextract.cpp
                                      • API String ID: 1970631241-3111339858
                                      • Opcode ID: 5814547d046b1e241da212c96e884a9fe72cb1ac09f7b54eddc0923fc725b526
                                      • Instruction ID: e9d36dd9530d1ea08f890847c43a1c0df90300b9d3e4a7208c675349f9f09aaa
                                      • Opcode Fuzzy Hash: 5814547d046b1e241da212c96e884a9fe72cb1ac09f7b54eddc0923fc725b526
                                      • Instruction Fuzzy Hash: 1221CD72200204AFEB04DF6CDD84EAA7BF9FF89720F15015AFE18C7256E631DA008B51
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • OpenProcessToken.ADVAPI32(?,00000008,?,008852B5,00000000,?,?,?,?,?,?,?,008974AB,00000000), ref: 008C078A
                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,008974AB,00000000), ref: 008C0794
                                      • GetTokenInformation.KERNELBASE(?,00000014(TokenIntegrityLevel),?,00000004,?,?,?,?,?,?,?,?,008974AB,00000000), ref: 008C07C6
                                      • FindCloseChangeNotification.KERNELBASE(?,?,?,?,?,?,?,?,008974AB,00000000), ref: 008C081D
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Token$ChangeCloseErrorFindInformationLastNotificationOpenProcess
                                      • String ID: procutil.cpp
                                      • API String ID: 2387526074-1178289305
                                      • Opcode ID: 2c749775e7f6def29c2f0b3a67c6502a01012d3d20492d30177a4a511c38efb5
                                      • Instruction ID: 835dbd07ed08ef8ae136a83d23df4da082c9b57dc2b59897ad77b6293b90450d
                                      • Opcode Fuzzy Hash: 2c749775e7f6def29c2f0b3a67c6502a01012d3d20492d30177a4a511c38efb5
                                      • Instruction Fuzzy Hash: 61219271D00628EBDB109B999C45F9EBBF8FF54751F11806AAD15E7190D7308E00DAD0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • DosDateTimeToFileTime.KERNEL32(?,?,?), ref: 008A0A25
                                      • LocalFileTimeToFileTime.KERNEL32(?,?), ref: 008A0A37
                                      • SetFileTime.KERNELBASE(?,?,?,?), ref: 008A0A4A
                                      • FindCloseChangeNotification.KERNELBASE(000000FF,?,?,?,?,?,?,?,?,?,?,?,?,008A0616,?,?), ref: 008A0A59
                                      Strings
                                      • Invalid operation for this state., xrefs: 008A09FE
                                      • cabextract.cpp, xrefs: 008A09F4
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Time$File$ChangeCloseDateFindLocalNotification
                                      • String ID: Invalid operation for this state.$cabextract.cpp
                                      • API String ID: 1330928052-1751360545
                                      • Opcode ID: a088efa70b3c6aed1b72b2f38193d9f8b0923a93c833ccd49463893ac63d481d
                                      • Instruction ID: daa97ca8f4831ee1dc0bdd3d5325a29d5d2769ecc647fd5dc5939744c25eee52
                                      • Opcode Fuzzy Hash: a088efa70b3c6aed1b72b2f38193d9f8b0923a93c833ccd49463893ac63d481d
                                      • Instruction Fuzzy Hash: 9921C07290062AABD7109FA8DC488AABBBCFF05720B14421AF865D69D0D774EA11CF90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CoInitialize.OLE32(00000000), ref: 008C344A
                                      • InterlockedIncrement.KERNEL32(008EB6D8), ref: 008C3467
                                      • CLSIDFromProgID.OLE32(Msxml2.DOMDocument,008EB6C8,?,?,?,?,?,?), ref: 008C3482
                                      • CLSIDFromProgID.OLE32(MSXML.DOMDocument,008EB6C8,?,?,?,?,?,?), ref: 008C348E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FromProg$IncrementInitializeInterlocked
                                      • String ID: MSXML.DOMDocument$Msxml2.DOMDocument
                                      • API String ID: 2109125048-2356320334
                                      • Opcode ID: 3ddc55e8e36336447191f76d9ef6b530884402084faf623303da155db3abbfac
                                      • Instruction ID: dbbbb39b6de8a2b424804da99bde2f2410b9a9845c11035f7081ddf946f2ab8f
                                      • Opcode Fuzzy Hash: 3ddc55e8e36336447191f76d9ef6b530884402084faf623303da155db3abbfac
                                      • Instruction Fuzzy Hash: D6F0EC207447F657CB164BA6AC0DF171E78FBB1F95F00401CEC00E12A4D374CA428AB4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetLastError.KERNEL32(?,00000000,00000000,00000000,00000000), ref: 008C495A
                                      • GlobalAlloc.KERNEL32(00000000,00000000,?,00000000,00000000,00000000,00000000), ref: 008C4989
                                      • GetLastError.KERNEL32(?,00000000,00000000,00000000), ref: 008C49B3
                                      • GetLastError.KERNEL32(00000000,008CB790,?,?,?,00000000,00000000,00000000), ref: 008C49F4
                                      • GlobalFree.KERNEL32(00000000), ref: 008C4A28
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$Global$AllocFree
                                      • String ID: fileutil.cpp
                                      • API String ID: 1145190524-2967768451
                                      • Opcode ID: 97dc40449c5a7be5c8fdd233e07f78c644f25a432010ebb9758e78819b5dbfe7
                                      • Instruction ID: 861ccb73e7e070f57e20e729c8fdd84803204fba36a401aec69658810e6c6f90
                                      • Opcode Fuzzy Hash: 97dc40449c5a7be5c8fdd233e07f78c644f25a432010ebb9758e78819b5dbfe7
                                      • Instruction Fuzzy Hash: ED21C335A40739ABD711ABA98C55FABBBB8FF84364F01426AFD05E7211E730CD4096A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • DefWindowProcW.USER32(?,00000082,?,?), ref: 0089E734
                                      • SetWindowLongW.USER32(?,000000EB,00000000), ref: 0089E743
                                      • SetWindowLongW.USER32(?,000000EB,?), ref: 0089E757
                                      • DefWindowProcW.USER32(?,?,?,?), ref: 0089E767
                                      • GetWindowLongW.USER32(?,000000EB), ref: 0089E781
                                      • PostQuitMessage.USER32(00000000), ref: 0089E7DE
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Window$Long$Proc$MessagePostQuit
                                      • String ID:
                                      • API String ID: 3812958022-0
                                      • Opcode ID: 4d85e36c4a6debd3fde86062941ac6057d885d496825ca5ed281adc6394f7388
                                      • Instruction ID: 10f3da0f27aa439775a077558f464dce39c11c1f8cdfb4f98e68e3ecfdadabc6
                                      • Opcode Fuzzy Hash: 4d85e36c4a6debd3fde86062941ac6057d885d496825ca5ed281adc6394f7388
                                      • Instruction Fuzzy Hash: 51216D32104118BFDF11AFA8DD49E6A3FA9FF45354F184524F906EA2A0C731DD10DB62
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegQueryValueExW.KERNELBASE(00000000,000002C0,00000000,000002C0,00000000,00000000,000002C0,BundleUpgradeCode,00000410,000002C0,00000000,00000000,00000000,00000100,00000000), ref: 008C10ED
                                      • RegQueryValueExW.KERNELBASE(?,00000000,00000000,?,?,?,?,?,?,00896EF3,00000100,000000B0,00000088,00000410,000002C0), ref: 008C1126
                                      • lstrlenW.KERNEL32(?,?,?,00000000,?,-00000001,00000004,00000000), ref: 008C121A
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: QueryValue$lstrlen
                                      • String ID: BundleUpgradeCode$regutil.cpp
                                      • API String ID: 3790715954-1648651458
                                      • Opcode ID: 0ccd8199d4439f02cb8bd39297aefbcaa835c2b3fed7d315e5fc5984802b6a72
                                      • Instruction ID: ec1e2bdedad0d621ee0a68ccca1b6165d254168707ae3d8b3699c134e116ac13
                                      • Opcode Fuzzy Hash: 0ccd8199d4439f02cb8bd39297aefbcaa835c2b3fed7d315e5fc5984802b6a72
                                      • Instruction Fuzzy Hash: 5C41BE35A0021AEBDF25DF98C8C8FAEB7B9FB46710F55416EE905EB211D630DD018B90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • VariantInit.OLEAUT32(?), ref: 6E833281
                                      • SysAllocString.OLEAUT32(00000000), ref: 6E833291
                                      • VariantClear.OLEAUT32(?), ref: 6E833372
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3393212218.000000006E831000.00000020.00000001.01000000.00000007.sdmp, Offset: 6E830000, based on PE: true
                                      • Associated: 00000002.00000002.3393155013.000000006E830000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393294909.000000006E84C000.00000004.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_6e830000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Variant$AllocClearInitString
                                      • String ID: p=Dv$xmlutil.cpp
                                      • API String ID: 2213243845-2046842063
                                      • Opcode ID: af4574788e544e37b1feab4ab07aae0ce04189e93689f86bf2c7a78b44f09558
                                      • Instruction ID: eca30ab27018befa16e47b75d3d1fcde3a98d11001b1ef8a446071e352401bf6
                                      • Opcode Fuzzy Hash: af4574788e544e37b1feab4ab07aae0ce04189e93689f86bf2c7a78b44f09558
                                      • Instruction Fuzzy Hash: 3441827190162AAFCB119FE9C888E9EBBB8FF45B10F1145A4EC15EB261DA34DD00CBD0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetFilePointerEx.KERNELBASE(?,?,?,?,?,?,?,?,?,?,?), ref: 008A088A
                                      • GetLastError.KERNEL32(?,?,?), ref: 008A0894
                                      Strings
                                      • Failed to move file pointer 0x%x bytes., xrefs: 008A08C5
                                      • cabextract.cpp, xrefs: 008A08B8
                                      • Invalid seek type., xrefs: 008A0820
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastPointer
                                      • String ID: Failed to move file pointer 0x%x bytes.$Invalid seek type.$cabextract.cpp
                                      • API String ID: 2976181284-417918914
                                      • Opcode ID: 2581be67a0284f4845a6d38d459ce34600da4c66803ecef5516aed9a53946b75
                                      • Instruction ID: 6e89f2ed83a82dfac298be2122dd93c38c0eae59042d180c899a11434df7630e
                                      • Opcode Fuzzy Hash: 2581be67a0284f4845a6d38d459ce34600da4c66803ecef5516aed9a53946b75
                                      • Instruction Fuzzy Hash: 9A319031A00619EFEB04DF68CC85DAAB7B9FB05724F14822AF915D7A50D734E9108FD5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 008C0E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,008C5699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 008C0E52
                                      • CompareStringW.KERNEL32(00000000,00000001,00000000,000000FF,?,000000FF,00000000,00000000,00000000,-80000001,SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall,00020019,00000000,00000100,00000100,000001B4), ref: 008A8BF7
                                      • RegCloseKey.ADVAPI32(00000000,-80000001,SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall,00020019,00000000,00000100,00000100,000001B4,?,?,?,0088F66B,00000001,00000100,000001B4,00000000), ref: 008A8C45
                                      Strings
                                      • Failed to open uninstall registry key., xrefs: 008A8BBA
                                      • SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall, xrefs: 008A8B94
                                      • Failed to enumerate uninstall key for related bundles., xrefs: 008A8C56
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseCompareOpenString
                                      • String ID: Failed to enumerate uninstall key for related bundles.$Failed to open uninstall registry key.$SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
                                      • API String ID: 2817536665-2531018330
                                      • Opcode ID: 1e51a40056632ccff4cc9b9f4b35d8e7c0ed76e3d1442cebb4c64ce19dcb3acf
                                      • Instruction ID: 6116de87f25ae1507ac02bd61af691ab8bdbe77ff598029b6826d2ccf74f090c
                                      • Opcode Fuzzy Hash: 1e51a40056632ccff4cc9b9f4b35d8e7c0ed76e3d1442cebb4c64ce19dcb3acf
                                      • Instruction Fuzzy Hash: CD21B432900128FFEB11AA94CC45FAEBB79FB01371F244669F510F6190DB754E909AB0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • CreateDirectoryW.KERNELBASE(0088533D,008853B5,00000000,00000000,?,00899EE4,00000000,00000000,0088533D,00000000,008852B5,00000000,?,?,0088D4AC,0088533D), ref: 00884021
                                      • GetLastError.KERNEL32(?,00899EE4,00000000,00000000,0088533D,00000000,008852B5,00000000,?,?,0088D4AC,0088533D,00000000,00000000), ref: 0088402F
                                      • CreateDirectoryW.KERNEL32(0088533D,008853B5,00885381,?,00899EE4,00000000,00000000,0088533D,00000000,008852B5,00000000,?,?,0088D4AC,0088533D,00000000), ref: 00884097
                                      • GetLastError.KERNEL32(?,00899EE4,00000000,00000000,0088533D,00000000,008852B5,00000000,?,?,0088D4AC,0088533D,00000000,00000000), ref: 008840A1
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CreateDirectoryErrorLast
                                      • String ID: dirutil.cpp
                                      • API String ID: 1375471231-2193988115
                                      • Opcode ID: 5db49f069c68118ec4e4b6514bb8ce5c009ae0f5e07bf3f428966767f9214e05
                                      • Instruction ID: 2c2dd1aa24506bcc23cb954a3928aa853c36547713dce5455478cbd6cc98fe75
                                      • Opcode Fuzzy Hash: 5db49f069c68118ec4e4b6514bb8ce5c009ae0f5e07bf3f428966767f9214e05
                                      • Instruction Fuzzy Hash: 91110537600B27AAEB703AA54C45B3BB668FF40B60F105226FF05EB051D7218C0193E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegEnumKeyExW.KERNELBASE(00000000,000002C0,00000410,00000002,00000000,00000000,00000000,00000000,00000410,00000002,00000100,00000000,00000000,?,?,008A8BD8), ref: 008C0D77
                                      • RegQueryInfoKeyW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000002,00000000,00000000,00000000,00000000,00000000,00000000,?,?,008A8BD8,00000000), ref: 008C0D99
                                      • RegEnumKeyExW.KERNELBASE(00000000,000002C0,00000410,00000002,00000000,00000000,00000000,00000000,00000410,00000003,?,?,008A8BD8,00000000,00000000,00000000), ref: 008C0DF1
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Enum$InfoQuery
                                      • String ID: regutil.cpp
                                      • API String ID: 73471667-955085611
                                      • Opcode ID: 7e483d23891a076a7d76ef3ef0e855e8b0e413187e0db1a919dea1ca2de1bce6
                                      • Instruction ID: 6dcb629d25015e9180fc40e9a5ba6a04ff1b5231ce17d4c3d8a61d18366e4d05
                                      • Opcode Fuzzy Hash: 7e483d23891a076a7d76ef3ef0e855e8b0e413187e0db1a919dea1ca2de1bce6
                                      • Instruction Fuzzy Hash: BB31A3B6901129FFEB219A998D84FABB7BCFF04794F114569BD04EB150D730DE109AA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 008C0E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,008C5699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 008C0E52
                                      • RegCloseKey.KERNELBASE(00000000,00000000,00000088,00000000,000002C0,00000410,00020019,00000000,000002C0,00000000,?,?,?,008A8C14,00000000,00000000), ref: 008A898C
                                      Strings
                                      • Failed to ensure there is space for related bundles., xrefs: 008A893F
                                      • Failed to open uninstall key for potential related bundle: %ls, xrefs: 008A88FB
                                      • Failed to initialize package from related bundle id: %ls, xrefs: 008A8972
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseOpen
                                      • String ID: Failed to ensure there is space for related bundles.$Failed to initialize package from related bundle id: %ls$Failed to open uninstall key for potential related bundle: %ls
                                      • API String ID: 47109696-1717420724
                                      • Opcode ID: 3af64ea5fb69865dba63adbfd33633c425c8e009ec4ccd9872c205a89db9a291
                                      • Instruction ID: 9c42011a910687d24a70db855072938f036aa573f232e4e802c696b228e00f0f
                                      • Opcode Fuzzy Hash: 3af64ea5fb69865dba63adbfd33633c425c8e009ec4ccd9872c205a89db9a291
                                      • Instruction Fuzzy Hash: 2721623294061AFBEB129A84CC06FBFBF78FB05710F184155F910E6550DB759D20ABA2
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 008C0E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,008C5699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 008C0E52
                                      • RegCloseKey.ADVAPI32(00000000,SOFTWARE\Policies\Microsoft\Windows\Installer,00020019,00000001,feclient.dll,?,?,?,00893E61,feclient.dll,?,00000000,?,?,?,00884A0C), ref: 008939F1
                                        • Part of subcall function 008C0F6E: RegQueryValueExW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000002,00000001,00000000,00000000,00000000,00000000,00000000), ref: 008C0FE4
                                        • Part of subcall function 008C0F6E: RegQueryValueExW.ADVAPI32(?,00000000,00000000,?,00000000,00000000,00000000,?), ref: 008C101F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: QueryValue$CloseOpen
                                      • String ID: Logging$SOFTWARE\Policies\Microsoft\Windows\Installer$feclient.dll
                                      • API String ID: 1586453840-3596319545
                                      • Opcode ID: 4fd81ca922c59d1338a44dcd1538828cefb362a6bc73c7fe16e39d246bf697cf
                                      • Instruction ID: 1773fe7c6e5217b72d2cb1ab8c35fff11d61399787f089e35d84b11c3acc4307
                                      • Opcode Fuzzy Hash: 4fd81ca922c59d1338a44dcd1538828cefb362a6bc73c7fe16e39d246bf697cf
                                      • Instruction Fuzzy Hash: 5F11D072A40208BBDF21AA94DC42FAEBFB8FB02B41F484066F505EB180D6B19F80D710
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenA.KERNEL32(?,00000000,00000000,00000000,?,?,008BFF0B,?,?,00000000,00000000,0000FDE9), ref: 008C066A
                                      • WriteFile.KERNELBASE(00000204,00000000,00000000,00000000,00000000,?,?,008BFF0B,?,?,00000000,00000000,0000FDE9), ref: 008C06A6
                                      • GetLastError.KERNEL32(?,?,008BFF0B,?,?,00000000,00000000,0000FDE9), ref: 008C06B0
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastWritelstrlen
                                      • String ID: logutil.cpp
                                      • API String ID: 606256338-3545173039
                                      • Opcode ID: 77a298bc4a5471cb17ccbdf3c6a10349755106ae4a36490070d31f9acb9c2337
                                      • Instruction ID: 539fd213e3d19c0497f24605de824d39adebc3f7b4a1aa728aa51f7db255d86e
                                      • Opcode Fuzzy Hash: 77a298bc4a5471cb17ccbdf3c6a10349755106ae4a36490070d31f9acb9c2337
                                      • Instruction Fuzzy Hash: 8911C672A01725ABD720DF6A8C44EAFB67CFBA5BA1F000219FD15D7240E670ED108AE0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • FormatMessageW.KERNEL32(00000900,?,00000000,00000000,00000000,00000000,?,00000000,?,?,008C03EC,?,00000000,?,?,00000001), ref: 008BFD3F
                                      • GetLastError.KERNEL32(?,008C03EC,?,00000000,?,?,00000001,?,00885523,?,?,00000000,?,?,0088528D,00000002), ref: 008BFD4B
                                      • LocalFree.KERNEL32(00000000,?,00000000,00000000,?,?,008C03EC,?,00000000,?,?,00000001,?,00885523,?,?), ref: 008BFDB3
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFormatFreeLastLocalMessage
                                      • String ID: logutil.cpp
                                      • API String ID: 1365068426-3545173039
                                      • Opcode ID: f1e3dc63bbfecb364ab68bf5cded02a7fc1e342c6e9343597ff2f252f4f1fafe
                                      • Instruction ID: 24ca2d40a402d21275ace103207ff929c8ca3d42c1e76f2002efba980bdae6f5
                                      • Opcode Fuzzy Hash: f1e3dc63bbfecb364ab68bf5cded02a7fc1e342c6e9343597ff2f252f4f1fafe
                                      • Instruction Fuzzy Hash: 9211BC32600619AADB21AF94CC06EEF7B68FF54710F018029FE01D6261E7308A20D7A1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 008A114F: SetFilePointerEx.KERNELBASE(?,?,?,00000000,00000000,?,?,?,00000000,?,008A077D,?,?,?), ref: 008A1177
                                        • Part of subcall function 008A114F: GetLastError.KERNEL32(?,008A077D,?,?,?), ref: 008A1181
                                      • ReadFile.KERNELBASE(?,?,?,?,00000000,?,?,?), ref: 008A078B
                                      • GetLastError.KERNEL32 ref: 008A0795
                                      Strings
                                      • Failed to read during cabinet extraction., xrefs: 008A07C3
                                      • cabextract.cpp, xrefs: 008A07B9
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLast$PointerRead
                                      • String ID: Failed to read during cabinet extraction.$cabextract.cpp
                                      • API String ID: 2170121939-2426083571
                                      • Opcode ID: cefdba500c1163bb6c5a592b4a1413d5889d81d5a5634951a39b1511d3edd825
                                      • Instruction ID: e71a6db6fa039861da0471f052bef3e97b4a0ee751e15592785e081650fa72cb
                                      • Opcode Fuzzy Hash: cefdba500c1163bb6c5a592b4a1413d5889d81d5a5634951a39b1511d3edd825
                                      • Instruction Fuzzy Hash: 2C01C872600664FBDB109FA8DC05E9A7BB9FF05760F01011AFD09D7650D731DA118BD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetFilePointerEx.KERNELBASE(?,?,?,00000000,00000000,?,?,?,00000000,?,008A077D,?,?,?), ref: 008A1177
                                      • GetLastError.KERNEL32(?,008A077D,?,?,?), ref: 008A1181
                                      Strings
                                      • Failed to move to virtual file pointer., xrefs: 008A11AF
                                      • cabextract.cpp, xrefs: 008A11A5
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorFileLastPointer
                                      • String ID: Failed to move to virtual file pointer.$cabextract.cpp
                                      • API String ID: 2976181284-3005670968
                                      • Opcode ID: bb6a3967aa74a9deda0128953af9421fa094498a31b4bacd99e0f45a9d676a93
                                      • Instruction ID: 3934829c6b831e38cbf68675c3cd90952ef61a97ced742a951700976ccc45710
                                      • Opcode Fuzzy Hash: bb6a3967aa74a9deda0128953af9421fa094498a31b4bacd99e0f45a9d676a93
                                      • Instruction Fuzzy Hash: F801F232600635BBEB212A6A9C08E87BFA9FF017B0F10822AFE18D6610D735CC10C6D4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SetEvent.KERNEL32(008CB468,00000000,?,008A145A,?,00000000,?,0088C121,?,008852FD,?,008973B2,?,?,008852FD,?), ref: 008A0524
                                      • GetLastError.KERNEL32(?,008A145A,?,00000000,?,0088C121,?,008852FD,?,008973B2,?,?,008852FD,?,0088533D,00000001), ref: 008A052E
                                      Strings
                                      • Failed to set begin operation event., xrefs: 008A055C
                                      • cabextract.cpp, xrefs: 008A0552
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorEventLast
                                      • String ID: Failed to set begin operation event.$cabextract.cpp
                                      • API String ID: 3848097054-4159625223
                                      • Opcode ID: ba12d51e199268e75115760132573bee93c3d3871f06d98b8cc5d329e8f5d57c
                                      • Instruction ID: 8612fbc12a5efa45da275e952d95da79606dd864e7840a0938b6e70839776c79
                                      • Opcode Fuzzy Hash: ba12d51e199268e75115760132573bee93c3d3871f06d98b8cc5d329e8f5d57c
                                      • Instruction Fuzzy Hash: AAF0A733E00B3066B71066A96C06F9776D8FF057A1F010136FD05F7650E6249D0056E6
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • PostThreadMessageW.USER32(?,00009000,00000000,?), ref: 0089EA1E
                                      • GetLastError.KERNEL32 ref: 0089EA28
                                      Strings
                                      • userForApplication.cpp, xrefs: 0089EA4C
                                      • Failed to post detect message., xrefs: 0089EA56
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLastMessagePostThread
                                      • String ID: userForApplication.cpp$Failed to post detect message.
                                      • API String ID: 2609174426-598219917
                                      • Opcode ID: b44156a50f3e58b067dc29d008d00338b472b7f4832316bcbe72b82fea3cbd29
                                      • Instruction ID: bd4bcc2c63b605494f8e7fd805b66c21b2b92b4e3e851a63973d0457f5c91f4b
                                      • Opcode Fuzzy Hash: b44156a50f3e58b067dc29d008d00338b472b7f4832316bcbe72b82fea3cbd29
                                      • Instruction Fuzzy Hash: D2F037327417346BE7207A699C05F87BBD5FF04BA1F014126FD18E6291D625DD00C6E5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenW.KERNEL32(burn.clean.room,?,?,?,?,00881104,?,?,00000000), ref: 0088503A
                                      • CompareStringW.KERNELBASE(0000007F,00000001,?,0000000F,burn.clean.room,0000000F,?,?,?,?,00881104,?,?,00000000), ref: 0088506A
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CompareStringlstrlen
                                      • String ID: burn.clean.room
                                      • API String ID: 1433953587-3055529264
                                      • Opcode ID: d44a9fd1193010ad29cc11530c06de972b8a487b64b8944bf083c1333a6516bd
                                      • Instruction ID: 064993d6491db09b1c57c0c9a35953f787ebd3f721a19c298c394057b47ec035
                                      • Opcode Fuzzy Hash: d44a9fd1193010ad29cc11530c06de972b8a487b64b8944bf083c1333a6516bd
                                      • Instruction Fuzzy Hash: 14016D72600A25AEC7349B99AC85D73BBACFB18BA57104126F949C6610D371AC40C7E1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetSystemDirectoryW.KERNEL32(?,00000104), ref: 6E831E0C
                                      • GetLastError.KERNEL32 ref: 6E831E16
                                      • LoadLibraryW.KERNELBASE(?,?,00000104,?), ref: 6E831E7E
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3393212218.000000006E831000.00000020.00000001.01000000.00000007.sdmp, Offset: 6E830000, based on PE: true
                                      • Associated: 00000002.00000002.3393155013.000000006E830000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393294909.000000006E84C000.00000004.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_6e830000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: DirectoryErrorLastLibraryLoadSystem
                                      • String ID:
                                      • API String ID: 1230559179-0
                                      • Opcode ID: 7796558ac548a32036bc46f6c8a2a685ff118c6c6c08a85adaf348ef8d9474fa
                                      • Instruction ID: 8a2562de426478475c0207fe50b2b9a9a30a3c1de4cdb350156ed8630efc7359
                                      • Opcode Fuzzy Hash: 7796558ac548a32036bc46f6c8a2a685ff118c6c6c08a85adaf348ef8d9474fa
                                      • Instruction Fuzzy Hash: 6921D672D01B3A97DB109BE59C44F9B73ACDF44B10F210962AD18F7240EA71DD58C6E0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetSystemDirectoryW.KERNEL32(?,00000104), ref: 00883829
                                      • GetLastError.KERNEL32 ref: 00883833
                                      • LoadLibraryW.KERNELBASE(?,?,00000104,?), ref: 0088389B
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: DirectoryErrorLastLibraryLoadSystem
                                      • String ID:
                                      • API String ID: 1230559179-0
                                      • Opcode ID: 25d2be3b195cde9988f4f0f924a3e340c58379387a1929b306b6d8b327f56867
                                      • Instruction ID: ba82296f8694a40aa0b86b02f9b408100e187d0bc500708c32aa6235ec07d3b0
                                      • Opcode Fuzzy Hash: 25d2be3b195cde9988f4f0f924a3e340c58379387a1929b306b6d8b327f56867
                                      • Instruction Fuzzy Hash: FC2198B6D0172E77EB20EB689C49F9A776CFB04B10F150175BD15E7241E670DE4487A0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcessHeap.KERNEL32(00000000,00000000,00000000,?,00883B34,00000000,?,00881472,00000000,80004005,00000000,80004005,00000000,000001C7,?,008813B7), ref: 008839A3
                                      • RtlFreeHeap.NTDLL(00000000,?,00883B34,00000000,?,00881472,00000000,80004005,00000000,80004005,00000000,000001C7,?,008813B7,000001C7,00000100), ref: 008839AA
                                      • GetLastError.KERNEL32(?,00883B34,00000000,?,00881472,00000000,80004005,00000000,80004005,00000000,000001C7,?,008813B7,000001C7,00000100,?), ref: 008839B4
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$ErrorFreeLastProcess
                                      • String ID:
                                      • API String ID: 406640338-0
                                      • Opcode ID: 89f6efbd841df1f6b833a583b97a04ecb13d90959264599016543bdede4ec289
                                      • Instruction ID: fa2d986e8d947f04c2eac8055bc1e886680de1353dc82bba686bb852d56f2c2a
                                      • Opcode Fuzzy Hash: 89f6efbd841df1f6b833a583b97a04ecb13d90959264599016543bdede4ec289
                                      • Instruction Fuzzy Hash: 55D01232600A346787102BFA9C0DA97BEACFF055A2F014022FD05D2110D735881096E4
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetModuleFileNameW.KERNEL32(00000000,C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe,00000104), ref: 008B40E7
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FileModuleName
                                      • String ID: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe
                                      • API String ID: 514040917-2636094901
                                      • Opcode ID: 3d7101c4ddb99622d51be6aec56a27ac844fc80ad9f7bfa655e9ec0e1a5832ce
                                      • Instruction ID: 9d8e7c6d857d450646dd2583f2698701e065aa1405816b67c447c6ebc931538f
                                      • Opcode Fuzzy Hash: 3d7101c4ddb99622d51be6aec56a27ac844fc80ad9f7bfa655e9ec0e1a5832ce
                                      • Instruction Fuzzy Hash: 83314971E00658ABCB21DF9D9C869EBBBFCFB99350B144066E904DB312D7708E848B91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegQueryValueExW.KERNELBASE(00000004,00000000,00000000,?,80000002,00020019,00000000,?,?,?,6E83115B,?,Install,?,80000002,00000000), ref: 6E8322E6
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3393212218.000000006E831000.00000020.00000001.01000000.00000007.sdmp, Offset: 6E830000, based on PE: true
                                      • Associated: 00000002.00000002.3393155013.000000006E830000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393294909.000000006E84C000.00000004.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_6e830000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: QueryValue
                                      • String ID: regutil.cpp
                                      • API String ID: 3660427363-955085611
                                      • Opcode ID: e4bf498ff0a580bf824406fc17905768b89d95d5bea92153e0e7b75849ff2f72
                                      • Instruction ID: d97c292ac2b47bcdcc5f8e47a270144c6bed67e1c40434b274e5432552e99857
                                      • Opcode Fuzzy Hash: e4bf498ff0a580bf824406fc17905768b89d95d5bea92153e0e7b75849ff2f72
                                      • Instruction Fuzzy Hash: 7201DB71A01239FFEF148AD58C04AAFBE9CDB01660F20856DFD05EB260E2758E10C6D0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 008C0E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,008C5699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 008C0E52
                                      • RegCloseKey.ADVAPI32(00000000,?,?,00000001,00000000,00000000,?,?,?,00897B4D,?,?,?), ref: 0088F644
                                        • Part of subcall function 008C0EEC: RegQueryValueExW.ADVAPI32(00000004,?,00000000,00000000,?,00000000,00000000,?,?,?,0088F619,00000000,Installed,00000000,?,?), ref: 008C0F10
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseOpenQueryValue
                                      • String ID: Installed
                                      • API String ID: 3677997916-3662710971
                                      • Opcode ID: 0c9e46bebfdca39ae4ff4c74022c4af43029970a99340ecae1f7ddbfcac0e7f7
                                      • Instruction ID: 58478f978e256eae5643b1b46f149e7d512c1ddaff967b2879c2f504132b9eb0
                                      • Opcode Fuzzy Hash: 0c9e46bebfdca39ae4ff4c74022c4af43029970a99340ecae1f7ddbfcac0e7f7
                                      • Instruction Fuzzy Hash: AF018F32810128FBCB11EB94C846BDEBBB8FB04311F1142A9F900E7121D3759E50DB90
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegOpenKeyExW.KERNELBASE(00020019,00000000,00000000,80000002,6E831146,00000000,?,6E831146,80000002,00000000,00020019,?,?,?,?,version), ref: 6E832279
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3393212218.000000006E831000.00000020.00000001.01000000.00000007.sdmp, Offset: 6E830000, based on PE: true
                                      • Associated: 00000002.00000002.3393155013.000000006E830000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393294909.000000006E84C000.00000004.00000001.01000000.00000007.sdmpDownload File
                                      • Associated: 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_6e830000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open
                                      • String ID: regutil.cpp
                                      • API String ID: 71445658-955085611
                                      • Opcode ID: cb08509c878f21b2934feaea71315de417dcce404784c3f8d8a33e6752dcc158
                                      • Instruction ID: 6e2b6ba70b0d24dfd0d62f5f75a95ed31101593401aed567616cebe35e2a3c58
                                      • Opcode Fuzzy Hash: cb08509c878f21b2934feaea71315de417dcce404784c3f8d8a33e6752dcc158
                                      • Instruction Fuzzy Hash: 42F0A732702635AFEF2559DA5C04BA77EC5EF456B0F118924FD49DB250D226CC1192D0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,008C5699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 008C0E52
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Open
                                      • String ID: regutil.cpp
                                      • API String ID: 71445658-955085611
                                      • Opcode ID: 5a38f83051bfd2b141d94e79985d437b683a1db2b78a6070d69a288043f0100b
                                      • Instruction ID: fd10d91be9853282e9817be678c95dc51516f167f53b8b9d419f5cf4fb380baa
                                      • Opcode Fuzzy Hash: 5a38f83051bfd2b141d94e79985d437b683a1db2b78a6070d69a288043f0100b
                                      • Instruction Fuzzy Hash: 7DF08272741129ABEF2459964C00FA77995FB556E0F118528BD49DA261E235CC1096D0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcessHeap.KERNEL32(?,000001C7,?,?,0088227D,?,000001C7,00000001,80004005,8007139F,?,?,008C015F,8007139F,?,00000000), ref: 00883A86
                                      • RtlReAllocateHeap.NTDLL(00000000,?,0088227D,?,000001C7,00000001,80004005,8007139F,?,?,008C015F,8007139F,?,00000000,00000000,8007139F), ref: 00883A8D
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateProcess
                                      • String ID:
                                      • API String ID: 1357844191-0
                                      • Opcode ID: 56a239c92e45053ef4a7bfe986b539611b05102d24fbd8b35f85eeb8db8ae2eb
                                      • Instruction ID: a3fa59c52114d1429cc3d38894ac2af029935d3587a6ab5ae203bdc7023878d7
                                      • Opcode Fuzzy Hash: 56a239c92e45053ef4a7bfe986b539611b05102d24fbd8b35f85eeb8db8ae2eb
                                      • Instruction Fuzzy Hash: 7FD0C932150609EB8F005FE8DC0ADAE3BACFB58612B048416B915C2110C739E4649A60
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetProcessHeap.KERNEL32(?,000001C7,?,00882284,000001C7,00000001,80004005,8007139F,?,?,008C015F,8007139F,?,00000000,00000000,8007139F), ref: 008838E5
                                      • RtlAllocateHeap.NTDLL(00000000,?,00882284,000001C7,00000001,80004005,8007139F,?,?,008C015F,8007139F,?,00000000,00000000,8007139F), ref: 008838EC
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$AllocateProcess
                                      • String ID:
                                      • API String ID: 1357844191-0
                                      • Opcode ID: 99fa3f2488662618ef87659607ebbd482b02046db6749e8ca8dbff9c33ac594d
                                      • Instruction ID: c1f3b5cbfd482f854e6355b735a4fafed820bd003c82a9266a3f7459302a2a06
                                      • Opcode Fuzzy Hash: 99fa3f2488662618ef87659607ebbd482b02046db6749e8ca8dbff9c33ac594d
                                      • Instruction Fuzzy Hash: D8C012321A0608AB8B006FF9EC0EC9A3BACBB28612B048412B905C3110CB3CE0189B60
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • VariantInit.OLEAUT32(?), ref: 008C34CE
                                        • Part of subcall function 008C2F23: GetModuleHandleA.KERNEL32(kernel32.dll,00000000,00000000,008C34DF,00000000,?,00000000), ref: 008C2F3D
                                        • Part of subcall function 008C2F23: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,008ABDED,?,008852FD,?,00000000,?), ref: 008C2F49
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorHandleInitLastModuleVariant
                                      • String ID:
                                      • API String ID: 52713655-0
                                      • Opcode ID: 8f4443820c5edd00162919be080627e0986e3818d2a267c9d987f2d9faa8303a
                                      • Instruction ID: 5c88632e44ff4e2956f4bbeeb2e00ddc078dfeb5058ed8842456b61836dd582f
                                      • Opcode Fuzzy Hash: 8f4443820c5edd00162919be080627e0986e3818d2a267c9d987f2d9faa8303a
                                      • Instruction Fuzzy Hash: 81311A76E006299BCB11DFA8C884ADEB7F8FF09710F01456AED15EB311D670EE058BA0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 008C8CFB: lstrlenW.KERNEL32(00000100,?,?,008C9098,000002C0,00000100,00000100,00000100,?,?,?,008A7B40,?,?,000001BC,00000000), ref: 008C8D1B
                                      • RegCloseKey.ADVAPI32(000002C0,000002C0,00000100,00000100,00000100,?,?,?,008A7B40,?,?,000001BC,00000000,00000000,00000000,00000100), ref: 008C9136
                                        • Part of subcall function 008C0E3F: RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000001,00000000,?,008C5699,80000002,00000000,00020019,00000000,SOFTWARE\Policies\,00000000,00000000,00000000), ref: 008C0E52
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: CloseOpenlstrlen
                                      • String ID:
                                      • API String ID: 514153755-0
                                      • Opcode ID: 7e20c4a4ae3748e794f7acb2a7ada66d533122b74c333e5316a8b92dc59a4782
                                      • Instruction ID: aa9f7d9026db4dd7cd0488240bd7778b774fe3b4e1411eedb1903660f7c3ee80
                                      • Opcode Fuzzy Hash: 7e20c4a4ae3748e794f7acb2a7ada66d533122b74c333e5316a8b92dc59a4782
                                      • Instruction Fuzzy Hash: 3D218872C0052AFBCF21AE68CC4AD9EBAB5FB44750B1542AAFD41E7111E632CE509BD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RegCloseKey.ADVAPI32(80070490,00000000,80070490,008EAAA0,00000000,80070490,0111AB60,?,0089890E,WiX\Burn,PackageCache,00000000,008EAAA0,00000000,00000000,80070490), ref: 008C5782
                                        • Part of subcall function 008C0F6E: RegQueryValueExW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000002,00000001,00000000,00000000,00000000,00000000,00000000), ref: 008C0FE4
                                        • Part of subcall function 008C0F6E: RegQueryValueExW.ADVAPI32(?,00000000,00000000,?,00000000,00000000,00000000,?), ref: 008C101F
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: QueryValue$Close
                                      • String ID:
                                      • API String ID: 1979452859-0
                                      • Opcode ID: 381bb1703600501af47ab0ce4e9c277ccd9eb6d4090b6c9cf92bd4f77ee1f530
                                      • Instruction ID: 2bc6a3e0a969cda3f6929467ac1b838acab64df2425dffaefb5315540497a1fd
                                      • Opcode Fuzzy Hash: 381bb1703600501af47ab0ce4e9c277ccd9eb6d4090b6c9cf92bd4f77ee1f530
                                      • Instruction Fuzzy Hash: AD11A37680152AEBCF226EA89D81FAEB679FB04760B15423DED01E7110C335ADE0DAD1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                        • Part of subcall function 00883083: ExpandEnvironmentStringsW.KERNEL32(00000000,00000000,00000000,00000000,00000040,00000000,00000000), ref: 008830C7
                                        • Part of subcall function 00883083: GetLastError.KERNEL32 ref: 008830D1
                                        • Part of subcall function 00883083: ExpandEnvironmentStringsW.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 00883129
                                        • Part of subcall function 00883083: GetLastError.KERNEL32 ref: 00883133
                                        • Part of subcall function 00883083: GetFullPathNameW.KERNEL32(00000000,00000040,00000000,00000000,00000000,00000040,00000000,00000000), ref: 008831EC
                                        • Part of subcall function 00883083: GetLastError.KERNEL32 ref: 008831F6
                                      • CompareStringW.KERNEL32(00000000,00000001,00000000,000000FF,00000000,000000FF,00000000,00000000,00000003,00000000,00000000,00000003,00000000), ref: 00882D49
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: ErrorLast$EnvironmentExpandStrings$CompareFullNamePathString
                                      • String ID:
                                      • API String ID: 1340564764-0
                                      • Opcode ID: ecaed9708371053d098e09f721881e3b379f040b18cfc29b27ffeb356cf0dcec
                                      • Instruction ID: dcfb1685d0cccde4bbd7eef909b2d1a58255b39ccc74451bf4e46ebb8fc4ec30
                                      • Opcode Fuzzy Hash: ecaed9708371053d098e09f721881e3b379f040b18cfc29b27ffeb356cf0dcec
                                      • Instruction Fuzzy Hash: 66015E31801619BBDF22AB98CC06FCDBB79FB04725F100295B610A61E0D7B19B90DB91
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • RtlAllocateHeap.NTDLL(00000008,?,00000000,?,008B6113,00000001,00000364), ref: 008B5280
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AllocateHeap
                                      • String ID:
                                      • API String ID: 1279760036-0
                                      • Opcode ID: f543cd6a314065d3363dd23054fef28aab579e12081e3f78fb2d72d6343e0cb5
                                      • Instruction ID: 06c7712fcb58f879e744d5b4e344e37162d8577ac925763d0ad330df8f196fd4
                                      • Opcode Fuzzy Hash: f543cd6a314065d3363dd23054fef28aab579e12081e3f78fb2d72d6343e0cb5
                                      • Instruction Fuzzy Hash: CDF0B435646924AADB616A669C46BDB3B49FF41B70B184111EC04EB3C2CB60DC008AE1
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • SHGetFolderPathW.SHELL32(00000000,00000000,00000000,00000000,00000000,00000000,00000104,00000000,?,008989CA,0000001C,80070490,00000000,00000000,80070490), ref: 008834E5
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: FolderPath
                                      • String ID:
                                      • API String ID: 1514166925-0
                                      • Opcode ID: 131392c118f9a43cc01479fa5c92bbd44d873e608929594913300c1b5ca49db1
                                      • Instruction ID: b2173c12cac2574b664953bd975a1618eb72f9888fcedad5dfc4701f8c3df028
                                      • Opcode Fuzzy Hash: 131392c118f9a43cc01479fa5c92bbd44d873e608929594913300c1b5ca49db1
                                      • Instruction Fuzzy Hash: E8E05B723012257BEB023E765C0ADEB7B9CFF15760B408055FE44D6101EB71E91187B5
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • GetFileAttributesW.KERNELBASE(00000000,00000000,?,0089A229,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000001,00000000,00000000,00000000,80070490), ref: 008840EB
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AttributesFile
                                      • String ID:
                                      • API String ID: 3188754299-0
                                      • Opcode ID: f322bd89988b6ca553a6baca49560a808459502e6d489cd655e433cbd882eae4
                                      • Instruction ID: d580500dff334b7d7256a6ae324a2a9244d757010a5d46195c6fe4c8df85c4ff
                                      • Opcode Fuzzy Hash: f322bd89988b6ca553a6baca49560a808459502e6d489cd655e433cbd882eae4
                                      • Instruction Fuzzy Hash: 80D02E33202128174B28EEAA8C089AABB29FF227B07018216EC14CB1A1C3308C52C3C0
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 008BF35B
                                        • Part of subcall function 008C9814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 008C9891
                                        • Part of subcall function 008C9814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 008C98A2
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: 4308008408de5e4176224d9f52918356c7cc5c30ece4efe2db3877e858a31a06
                                      • Instruction ID: 3b4dccf3e1e3f5a7704ba37b0ccc7077461748a051025e13cdae7340b2aa7c69
                                      • Opcode Fuzzy Hash: 4308008408de5e4176224d9f52918356c7cc5c30ece4efe2db3877e858a31a06
                                      • Instruction Fuzzy Hash: 27B09292268841AC220822566D06C3A0658E2C2F28324C03AB651C1242E89469080032
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 008BF35B
                                        • Part of subcall function 008C9814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 008C9891
                                        • Part of subcall function 008C9814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 008C98A2
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: 66fdd557cdc21b8405f7e12dc985140de9c20c4f3a5fd3c79fc9a381e49c6b31
                                      • Instruction ID: 14714058927a1b03befb1fa6ca02d90e5c1d514a1119e5c4be1d2a3bc55e46e6
                                      • Opcode Fuzzy Hash: 66fdd557cdc21b8405f7e12dc985140de9c20c4f3a5fd3c79fc9a381e49c6b31
                                      • Instruction Fuzzy Hash: BAB01291278841ED3248635A1E07D3A029DF2C7F34334C03EF255C2343F8946C090033
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 008BF35B
                                        • Part of subcall function 008C9814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 008C9891
                                        • Part of subcall function 008C9814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 008C98A2
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: 219c06e63f0bbb9268b097419ee704e42a5d52e3288728bac5244912701b08f7
                                      • Instruction ID: f1cf58c7974a2e699a12bd030595f99bd45ab81a0182f3fa7f3e56e685c3a37a
                                      • Opcode Fuzzy Hash: 219c06e63f0bbb9268b097419ee704e42a5d52e3288728bac5244912701b08f7
                                      • Instruction Fuzzy Hash: B2B01291278941EC3248635A1D06D3A029CF2C7F34334C13EF255C2343F8A46C480033
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 008C94E7
                                        • Part of subcall function 008C9814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 008C9891
                                        • Part of subcall function 008C9814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 008C98A2
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: e26043c1bce68f53d53f7301b1a20beab0485a9f19ccf0e5458cea8a9c509c35
                                      • Instruction ID: f0487853819cc5442f19f772cf8d11b9bd01d9d949b1d5b354ffce71d73c2c09
                                      • Opcode Fuzzy Hash: e26043c1bce68f53d53f7301b1a20beab0485a9f19ccf0e5458cea8a9c509c35
                                      • Instruction Fuzzy Hash: E3B01286278945FC320C325A5D4AD3A012CF5C2F20331C1FEF261D2081F8609C090033
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 008C94E7
                                        • Part of subcall function 008C9814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 008C9891
                                        • Part of subcall function 008C9814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 008C98A2
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: 2ba273559de826a14a31a681ad7897e97df72d5b2c3c89425e501d4d4e804401
                                      • Instruction ID: 9d8d5f600b0fc614cb0b4b1843fa2b5e3a628a3c3cf66069415c182f545465a8
                                      • Opcode Fuzzy Hash: 2ba273559de826a14a31a681ad7897e97df72d5b2c3c89425e501d4d4e804401
                                      • Instruction Fuzzy Hash: E3B09286268842AC2248625A590AE3A052CF182F20320C1AEF655C2181E8609C090032
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • ___delayLoadHelper2@8.DELAYIMP ref: 008C94E7
                                        • Part of subcall function 008C9814: DloadReleaseSectionWriteAccess.DELAYIMP ref: 008C9891
                                        • Part of subcall function 008C9814: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 008C98A2
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                      • String ID:
                                      • API String ID: 1269201914-0
                                      • Opcode ID: 1809ddf361c768878b24efc66f746cd469c7dac3f6206689e86f54f6b86a0f2d
                                      • Instruction ID: 46c7e451d602a4f9e20a3607512b9859ddac05736e48ebb4e66d85ee5e932672
                                      • Opcode Fuzzy Hash: 1809ddf361c768878b24efc66f746cd469c7dac3f6206689e86f54f6b86a0f2d
                                      • Instruction Fuzzy Hash: 7AB01286278A41BC324C729A6F0BE3A012CF5C2F2033081FEF265C3181F8649C0A0033
                                      Uniqueness

                                      Uniqueness Score: -1.00%

                                      APIs
                                      • lstrlenW.KERNEL32(00000000,00000000,00000000,?,?,008821B8,?,00000000,?,00000000,?,008838BD,00000000,?,00000104), ref: 008814E4
                                        • Part of subcall function 00883B51: GetProcessHeap.KERNEL32(00000000,000001C7,?,008821DC,000001C7,80004005,8007139F,?,?,008C015F,8007139F,?,00000000,00000000,8007139F), ref: 00883B59
                                        • Part of subcall function 00883B51: HeapSize.KERNEL32(00000000,?,008821DC,000001C7,80004005,8007139F,?,?,008C015F,8007139F,?,00000000,00000000,8007139F), ref: 00883B60
                                      Memory Dump Source
                                      • Source File: 00000002.00000002.3385055896.0000000000881000.00000020.00000001.01000000.00000005.sdmp, Offset: 00880000, based on PE: true
                                      • Associated: 00000002.00000002.3384991097.0000000000880000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385242382.00000000008CB000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385304209.00000000008EA000.00000004.00000001.01000000.00000005.sdmpDownload File
                                      • Associated: 00000002.00000002.3385358424.00000000008EE000.00000002.00000001.01000000.00000005.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_2_2_880000_cylanceprotectsetupwithoptics.jbxd
                                      Similarity
                                      • API ID: Heap$ProcessSizelstrlen
                                      • String ID:
                                      • API String ID: 3492610842-0
                                      • Opcode ID: 7611b5d87ca44e805343878a37ddd43768482ef186beb1e28945122761165ceb
                                      • Instruction ID: 839df66061f70ca73d70923afb15532944c5d426bb778c9c2854ae6d0638907c
                                      • Opcode Fuzzy Hash: 7611b5d87ca44e805343878a37ddd43768482ef186beb1e28945122761165ceb
                                      • Instruction Fuzzy Hash: 7901F537200219AFCF217E54CC48E9A779EFF41764F214225FA25DB161DB31ED528794
                                      Uniqueness

                                      Uniqueness Score: -1.00%