Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
WinUI.exe

Overview

General Information

Sample name:WinUI.exe
Analysis ID:1427802
MD5:cbda0e120fd089cb6f31c81dcc3ad065
SHA1:4f3e30004357b7f570a1719ecd99df25fd9b41c4
SHA256:76b9211c8ccc28b01827089f4eda07f39a12f603b0e26726cdb0deec2c9a2893
Infos:

Detection

Score:4
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Detected potential crypto function
Found large amount of non-executed APIs
PE file contains sections with non-standard names
PE file contains strange resources
Program does not show much activity (idle)
Sample file is different than original file name gathered from version info

Classification

Analysis Advice

Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
  • System is w10x64
  • WinUI.exe (PID: 5956 cmdline: "C:\Users\user\Desktop\WinUI.exe" MD5: CBDA0E120FD089CB6F31C81DCC3AD065)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: WinUI.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb source: WinUI.exe
Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdbcccGCTL source: WinUI.exe
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5DFB00 FindFirstFileExW,FindNextFileW,FindClose,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,Concurrency::cancel_current_task,Concurrency::cancel_current_task,0_2_00007FF62E5DFB00
Source: WinUI.exeString found in binary or memory: https://aka.ms/dotnet-core-applaunch?
Source: WinUI.exeString found in binary or memory: https://aka.ms/dotnet-core-applaunch?You
Source: WinUI.exeString found in binary or memory: https://aka.ms/dotnet/app-launch-failed
Source: WinUI.exeString found in binary or memory: https://aka.ms/dotnet/app-launch-failed&gui=trueShowing
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5E1AF00_2_00007FF62E5E1AF0
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5D2BA00_2_00007FF62E5D2BA0
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5D67500_2_00007FF62E5D6750
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5D9C200_2_00007FF62E5D9C20
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5DEFF00_2_00007FF62E5DEFF0
Source: WinUI.exeStatic PE information: Resource name: RT_VERSION type: MacBinary, comment length 97, char. code 0x69, total length 1711304448, Wed Mar 28 22:22:24 2040 INVALID date, modified Tue Feb 7 01:41:58 2040, creator ' ' "4"
Source: WinUI.exeBinary or memory string: OriginalFilename vs WinUI.exe
Source: WinUI.exe, 00000000.00000000.1629017320.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameWinUI.dll: vs WinUI.exe
Source: WinUI.exeBinary or memory string: OriginalFilenameWinUI.dll: vs WinUI.exe
Source: classification engineClassification label: clean4.winEXE@1/0@0/0
Source: WinUI.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\WinUI.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: WinUI.exeString found in binary or memory: https://aka.ms/dotnet/app-launch-failed
Source: WinUI.exeString found in binary or memory: https://aka.ms/dotnet/app-launch-failed
Source: WinUI.exeString found in binary or memory: https://aka.ms/dotnet/app-launch-failed&gui=trueShowing error dialog for application: '%s' - error code: 0x%x - url: '%s' - dialog message: %sopenRedirecting errors to custom writer.invalid string position
Source: WinUI.exeString found in binary or memory: https://aka.ms/dotnet/app-launch-failed
Source: C:\Users\user\Desktop\WinUI.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\WinUI.exeSection loaded: kernel.appcore.dllJump to behavior
Source: WinUI.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: WinUI.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: WinUI.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: WinUI.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: WinUI.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: WinUI.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: WinUI.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: WinUI.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: WinUI.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb source: WinUI.exe
Source: Binary string: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdbcccGCTL source: WinUI.exe
Source: WinUI.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: WinUI.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: WinUI.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: WinUI.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: WinUI.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5DF400 LoadLibraryA,GetProcAddress,_invalid_parameter_noinfo_noreturn,0_2_00007FF62E5DF400
Source: WinUI.exeStatic PE information: section name: _RDATA
Source: C:\Users\user\Desktop\WinUI.exeAPI coverage: 8.0 %
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5DFB00 FindFirstFileExW,FindNextFileW,FindClose,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,Concurrency::cancel_current_task,Concurrency::cancel_current_task,0_2_00007FF62E5DFB00
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5E4120 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF62E5E4120
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5DF400 LoadLibraryA,GetProcAddress,_invalid_parameter_noinfo_noreturn,0_2_00007FF62E5DF400
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5E4120 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF62E5E4120
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5E3DD0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF62E5E3DD0
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5E42C8 SetUnhandledExceptionFilter,0_2_00007FF62E5E42C8
Source: C:\Users\user\Desktop\WinUI.exeCode function: 0_2_00007FF62E5E433C GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF62E5E433C
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
1
DLL Side-Loading
1
DLL Side-Loading
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts1
Native API
Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS2
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://aka.ms/dotnet/app-launch-failedWinUI.exefalse
    high
    https://aka.ms/dotnet-core-applaunch?YouWinUI.exefalse
      high
      https://aka.ms/dotnet/app-launch-failed&gui=trueShowingWinUI.exefalse
        high
        https://aka.ms/dotnet-core-applaunch?WinUI.exefalse
          high
          No contacted IP infos
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1427802
          Start date and time:2024-04-18 07:49:01 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 51s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:default.jbs
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:1
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Sample name:WinUI.exe
          Detection:CLEAN
          Classification:clean4.winEXE@1/0@0/0
          EGA Information:
          • Successful, ratio: 100%
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 7
          • Number of non-executed functions: 47
          Cookbook Comments:
          • Found application associated with file extension: .exe
          • Stop behavior analysis, all processes terminated
          • VT rate limit hit for: WinUI.exe
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          File type:PE32+ executable (GUI) x86-64, for MS Windows
          Entropy (8bit):6.044007074169727
          TrID:
          • Win64 Executable GUI (202006/5) 92.65%
          • Win64 Executable (generic) (12005/4) 5.51%
          • Generic Win/DOS Executable (2004/3) 0.92%
          • DOS Executable Generic (2002/1) 0.92%
          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
          File name:WinUI.exe
          File size:150'016 bytes
          MD5:cbda0e120fd089cb6f31c81dcc3ad065
          SHA1:4f3e30004357b7f570a1719ecd99df25fd9b41c4
          SHA256:76b9211c8ccc28b01827089f4eda07f39a12f603b0e26726cdb0deec2c9a2893
          SHA512:f392c1b801d50e58711c8f88fb1d4da1643c15318f0596914871440eab5364c0ed2b087bc04e74ddfe1d6bf6391edb616481c850ad360a0ca7ef1fe333f1f10e
          SSDEEP:3072:5czkitvo4BpYN/6mBPry8TXROLdW5m4mURu9OOG+0kD:5A4NCmBPry/N2KOOL
          TLSH:9BE32806B2AD01FCD1ABE33889A64A02F7767856473697CF0350867A1F777E0AE79311
          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........}.............../......./......./......a.....S../........"...I../....I../....Rich............................PE..d.....oe...
          Icon Hash:90cececece8e8eb0
          Entrypoint:0x140013c60
          Entrypoint Section:.text
          Digitally signed:false
          Imagebase:0x140000000
          Subsystem:windows gui
          Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
          DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
          Time Stamp:0x656F0000 [Tue Dec 5 10:48:32 2023 UTC]
          TLS Callbacks:
          CLR (.Net) Version:
          OS Version Major:6
          OS Version Minor:0
          File Version Major:6
          File Version Minor:0
          Subsystem Version Major:6
          Subsystem Version Minor:0
          Import Hash:6dbf27f4c70fe2c8ed3e0122ba75d641
          Instruction
          dec eax
          sub esp, 28h
          call 00007F562928D7A8h
          dec eax
          add esp, 28h
          jmp 00007F562928CF3Fh
          int3
          int3
          dec eax
          sub esp, 28h
          dec ebp
          mov eax, dword ptr [ecx+38h]
          dec eax
          mov ecx, edx
          dec ecx
          mov edx, ecx
          call 00007F562928D0E2h
          mov eax, 00000001h
          dec eax
          add esp, 28h
          ret
          int3
          int3
          int3
          inc eax
          push ebx
          inc ebp
          mov ebx, dword ptr [eax]
          dec eax
          mov ebx, edx
          inc ecx
          and ebx, FFFFFFF8h
          dec esp
          mov ecx, ecx
          inc ecx
          test byte ptr [eax], 00000004h
          dec esp
          mov edx, ecx
          je 00007F562928D0E5h
          inc ecx
          mov eax, dword ptr [eax+08h]
          dec ebp
          arpl word ptr [eax+04h], dx
          neg eax
          dec esp
          add edx, ecx
          dec eax
          arpl ax, cx
          dec esp
          and edx, ecx
          dec ecx
          arpl bx, ax
          dec edx
          mov edx, dword ptr [eax+edx]
          dec eax
          mov eax, dword ptr [ebx+10h]
          mov ecx, dword ptr [eax+08h]
          dec eax
          mov eax, dword ptr [ebx+08h]
          test byte ptr [ecx+eax+03h], 0000000Fh
          je 00007F562928D0DDh
          movzx eax, byte ptr [ecx+eax+03h]
          and eax, FFFFFFF0h
          dec esp
          add ecx, eax
          dec esp
          xor ecx, edx
          dec ecx
          mov ecx, ecx
          pop ebx
          jmp 00007F562928CAD6h
          int3
          dec eax
          mov eax, esp
          dec eax
          mov dword ptr [eax+08h], ebx
          dec eax
          mov dword ptr [eax+10h], ebp
          dec eax
          mov dword ptr [eax+18h], esi
          dec eax
          mov dword ptr [eax+20h], edi
          inc ecx
          push esi
          dec eax
          sub esp, 20h
          dec ecx
          mov ebx, dword ptr [ecx+38h]
          dec eax
          mov esi, edx
          dec ebp
          mov esi, eax
          dec eax
          mov ebp, ecx
          dec ecx
          mov edx, ecx
          dec eax
          mov ecx, esi
          dec ecx
          mov edi, ecx
          dec esp
          lea eax, dword ptr [ebx+04h]
          call 00007F562928D041h
          Programming Language:
          • [IMP] VS2008 SP1 build 30729
          NameVirtual AddressVirtual Size Is in Section
          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_IMPORT0x224740x104.rdata
          IMAGE_DIRECTORY_ENTRY_RESOURCE0x2a0000x680.rsrc
          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x260000x1440.pdata
          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
          IMAGE_DIRECTORY_ENTRY_BASERELOC0x290000x318.reloc
          IMAGE_DIRECTORY_ENTRY_DEBUG0x1efa00x54.rdata
          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
          IMAGE_DIRECTORY_ENTRY_TLS0x1f1800x28.rdata
          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x1f0000x138.rdata
          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_IAT0x1a0000x408.rdata
          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
          .text0x10000x1821c0x184000a11f732cbe48283e2e6549421819adcFalse0.49150289948453607data6.320245813356347IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          .rdata0x1a0000x93020x9400a8afb7c703fa303aca864d47fd45e9e8False0.36906144425675674data4.525335266420824IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
          .data0x240000x14f80xa006803f795472a57466539e7f6d412a3bbFalse0.183984375DOS executable (block device driver)2.4528649610883178IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
          .pdata0x260000x14400x16006a2868947463d3292323bc1a5bca8733False0.4440696022727273PEX Binary Archive4.722703557900984IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
          _RDATA0x280000xf40x2000a880db69ef3d95f9e9e17c8465b574fFalse0.30859375data2.4118532147102756IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
          .reloc0x290000x3180x400541be3271e778d705125ef64917f1dc4False0.55078125data4.693053408235668IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
          .rsrc0x2a0000x6800x800b5d58817a64de1e9271fd1b607cb03f5False0.373046875data3.990675555787608IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
          NameRVASizeTypeLanguageCountryZLIB Complexity
          RT_VERSION0x2a0800x300MacBinary, comment length 97, char. code 0x69, total length 1711304448, Wed Mar 28 22:22:24 2040 INVALID date, modified Tue Feb 7 01:41:58 2040, creator ' ' "4"0.4674479166666667
          RT_MANIFEST0x2a3800x2dfXML 1.0 document, ASCII text, with CRLF line terminators0.48299319727891155
          DLLImport
          KERNEL32.dllFindNextFileW, GetCurrentProcess, GetModuleHandleExW, GetModuleFileNameW, LeaveCriticalSection, InitializeCriticalSection, GetEnvironmentVariableW, FindClose, MultiByteToWideChar, GetLastError, GetFileAttributesExW, GetFullPathNameW, GetProcAddress, DeleteCriticalSection, WideCharToMultiByte, IsWow64Process, LoadLibraryExW, FreeLibrary, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, EnterCriticalSection, FindFirstFileExW, OutputDebugStringW, LoadLibraryA, GetModuleHandleW, InitializeCriticalSectionAndSpinCount, SetLastError, RaiseException, RtlPcToFileHeader, RtlUnwindEx, InitializeSListHead, GetSystemTimeAsFileTime, GetCurrentThreadId, GetCurrentProcessId, QueryPerformanceCounter, IsDebuggerPresent, IsProcessorFeaturePresent, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, LCMapStringEx, DecodePointer, EncodePointer, InitializeCriticalSectionEx, GetStringTypeW
          USER32.dllMessageBoxW
          SHELL32.dllShellExecuteW
          ADVAPI32.dllRegOpenKeyExW, RegGetValueW, DeregisterEventSource, RegisterEventSourceW, ReportEventW, RegCloseKey
          api-ms-win-crt-runtime-l1-1-0.dll_exit, __p___argc, _initterm_e, _initterm, _get_initial_wide_environment, _invalid_parameter_noinfo_noreturn, _initialize_wide_environment, _configure_wide_argv, _initialize_onexit_table, _set_app_type, __p___wargv, _seh_filter_exe, _register_onexit_function, _cexit, terminate, _errno, exit, abort, _crt_atexit, _c_exit, _register_thread_local_exe_atexit_callback
          api-ms-win-crt-stdio-l1-1-0.dllsetvbuf, fflush, _wfopen, __stdio_common_vswprintf, __stdio_common_vfwprintf, _set_fmode, __stdio_common_vsprintf_s, __acrt_iob_func, fputwc, fputws, __p__commode
          api-ms-win-crt-heap-l1-1-0.dll_set_new_mode, _callnewh, free, malloc, calloc
          api-ms-win-crt-string-l1-1-0.dllwcsnlen, strcpy_s, _wcsdup, strcspn, wcsncmp, toupper
          api-ms-win-crt-convert-l1-1-0.dll_wtoi, wcstoul
          api-ms-win-crt-locale-l1-1-0.dllsetlocale, ___lc_locale_name_func, localeconv, _unlock_locales, _lock_locales, ___mb_cur_max_func, _configthreadlocale, __pctype_func, ___lc_codepage_func
          api-ms-win-crt-math-l1-1-0.dllfrexp, __setusermatherr
          api-ms-win-crt-time-l1-1-0.dll_gmtime64_s, _time64, wcsftime
          No network behavior found

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:07:49:47
          Start date:18/04/2024
          Path:C:\Users\user\Desktop\WinUI.exe
          Wow64 process (32bit):false
          Commandline:"C:\Users\user\Desktop\WinUI.exe"
          Imagebase:0x7ff62e5d0000
          File size:150'016 bytes
          MD5 hash:CBDA0E120FD089CB6F31C81DCC3AD065
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          Reset < >

            Execution Graph

            Execution Coverage:5.2%
            Dynamic/Decrypted Code Coverage:0%
            Signature Coverage:20.4%
            Total number of Nodes:1367
            Total number of Limit Nodes:9
            execution_graph 8558 7ff62e5dafa0 8559 7ff62e5db013 8558->8559 8560 7ff62e5db00a 8558->8560 8559->8560 8561 7ff62e5db052 frexp 8559->8561 8563 7ff62e5db094 8560->8563 8572 7ff62e5dd230 8560->8572 8561->8560 8587 7ff62e5d89c0 8563->8587 8565 7ff62e5db1c0 8590 7ff62e5dc430 8565->8590 8567 7ff62e5db1ff 8568 7ff62e5db239 8567->8568 8570 7ff62e5db232 _invalid_parameter_noinfo_noreturn 8567->8570 8569 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8568->8569 8571 7ff62e5db24d 8569->8571 8570->8568 8573 7ff62e5dd3ac 8572->8573 8575 7ff62e5dd25e 8572->8575 8574 7ff62e5d14b0 3 API calls 8573->8574 8578 7ff62e5dd3b1 8574->8578 8576 7ff62e5dd2b1 8575->8576 8577 7ff62e5dd2e6 8575->8577 8580 7ff62e5dd2be 8575->8580 8576->8578 8576->8580 8584 7ff62e5e3718 std::_Facet_Register 4 API calls 8577->8584 8585 7ff62e5dd2cf _Yarn 8577->8585 8581 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 8578->8581 8579 7ff62e5e3718 std::_Facet_Register 4 API calls 8579->8585 8580->8579 8582 7ff62e5dd3b7 8581->8582 8583 7ff62e5dd365 _invalid_parameter_noinfo_noreturn 8586 7ff62e5dd358 _Yarn 8583->8586 8584->8585 8585->8583 8585->8586 8586->8563 8612 7ff62e5d64d0 8587->8612 8589 7ff62e5d89e5 __stdio_common_vsprintf_s 8589->8565 8592 7ff62e5dc47d strcspn localeconv strcspn 8590->8592 8593 7ff62e5dc522 8592->8593 8594 7ff62e5d5b20 22 API calls 8593->8594 8595 7ff62e5dc52c 8594->8595 8613 7ff62e5dba20 8595->8613 8597 7ff62e5dc582 8627 7ff62e5dcf30 8597->8627 8599 7ff62e5dc5d3 _Yarn 8600 7ff62e5dcbda 8599->8600 8609 7ff62e5dc72b 8599->8609 8641 7ff62e5dd040 8599->8641 8601 7ff62e5d57b0 3 API calls 8600->8601 8603 7ff62e5dcbdf free free free 8601->8603 8604 7ff62e5dcc26 8603->8604 8604->8567 8605 7ff62e5dcb54 8606 7ff62e5dcbab 8605->8606 8610 7ff62e5dcba4 _invalid_parameter_noinfo_noreturn 8605->8610 8608 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8606->8608 8607 7ff62e5dcb4d _invalid_parameter_noinfo_noreturn 8607->8605 8611 7ff62e5dcbbf 8608->8611 8609->8605 8609->8607 8610->8606 8611->8567 8612->8589 8614 7ff62e5dba4b 8613->8614 8619 7ff62e5dba7c 8613->8619 8614->8597 8615 7ff62e5dbbb2 8616 7ff62e5d14b0 3 API calls 8615->8616 8618 7ff62e5dbbb7 8616->8618 8617 7ff62e5dbaa3 8617->8618 8622 7ff62e5e3718 std::_Facet_Register 4 API calls 8617->8622 8620 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 8618->8620 8619->8615 8619->8617 8619->8618 8621 7ff62e5dbb20 8619->8621 8625 7ff62e5dbbbd 8620->8625 8624 7ff62e5e3718 std::_Facet_Register 4 API calls 8621->8624 8626 7ff62e5dbb09 8621->8626 8622->8626 8623 7ff62e5dbbab _invalid_parameter_noinfo_noreturn 8623->8615 8624->8626 8625->8597 8626->8614 8626->8623 8628 7ff62e5dcf4b std::_Lockit::_Lockit 8627->8628 8632 7ff62e5dcf9a 8628->8632 8633 7ff62e5e2a18 std::_Lockit::~_Lockit _unlock_locales 8628->8633 8629 7ff62e5dcfdf 8630 7ff62e5e2a18 std::_Lockit::~_Lockit _unlock_locales 8629->8630 8631 7ff62e5dd02a 8630->8631 8631->8599 8632->8629 8656 7ff62e5dd3c0 8632->8656 8633->8632 8636 7ff62e5dd03a 8638 7ff62e5d1a70 Concurrency::cancel_current_task 3 API calls 8636->8638 8637 7ff62e5dcff7 8639 7ff62e5e2e8c std::_Facet_Register 4 API calls 8637->8639 8640 7ff62e5dd03f 8638->8640 8639->8629 8642 7ff62e5dd21b 8641->8642 8646 7ff62e5dd06e 8641->8646 8643 7ff62e5d14b0 3 API calls 8642->8643 8645 7ff62e5dd220 8643->8645 8644 7ff62e5dd096 8644->8645 8647 7ff62e5dd0f7 8644->8647 8650 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 8645->8650 8646->8644 8646->8645 8648 7ff62e5dd116 8646->8648 8649 7ff62e5e3718 std::_Facet_Register 4 API calls 8647->8649 8653 7ff62e5e3718 std::_Facet_Register 4 API calls 8648->8653 8654 7ff62e5dd0ff _Yarn 8648->8654 8649->8654 8651 7ff62e5dd226 8650->8651 8652 7ff62e5dd1b6 _invalid_parameter_noinfo_noreturn 8655 7ff62e5dd1a9 _Yarn 8652->8655 8653->8654 8654->8652 8654->8655 8655->8599 8657 7ff62e5dd3f0 8656->8657 8658 7ff62e5dcff1 8656->8658 8657->8658 8659 7ff62e5e3718 std::_Facet_Register 4 API calls 8657->8659 8658->8636 8658->8637 8660 7ff62e5dd402 std::_Lockit::_Lockit 8659->8660 8661 7ff62e5dd46f 8660->8661 8662 7ff62e5dd546 8660->8662 8664 7ff62e5e3040 std::_Locinfo::_Locinfo_ctor 3 API calls 8661->8664 8663 7ff62e5e2d08 3 API calls 8662->8663 8666 7ff62e5dd552 8663->8666 8665 7ff62e5dd47b 8664->8665 8684 7ff62e5dd6e0 localeconv 8665->8684 8668 7ff62e5dd4a0 8716 7ff62e5e30ac 8668->8716 8671 7ff62e5dd4bc 8673 7ff62e5dd4cf 8671->8673 8674 7ff62e5dd4c9 free 8671->8674 8672 7ff62e5dd4b6 free 8672->8671 8675 7ff62e5dd4e2 8673->8675 8676 7ff62e5dd4dc free 8673->8676 8674->8673 8677 7ff62e5dd4f5 8675->8677 8678 7ff62e5dd4ef free 8675->8678 8676->8675 8679 7ff62e5dd502 free 8677->8679 8680 7ff62e5dd508 8677->8680 8678->8677 8679->8680 8681 7ff62e5dd515 free 8680->8681 8682 7ff62e5dd51b 8680->8682 8681->8682 8683 7ff62e5e2a18 std::_Lockit::~_Lockit _unlock_locales 8682->8683 8683->8658 8719 7ff62e5e3460 ___lc_codepage_func 8684->8719 8687 7ff62e5e3460 3 API calls 8688 7ff62e5dd775 calloc 8687->8688 8690 7ff62e5dd9e1 8688->8690 8695 7ff62e5dd7a8 _Yarn 8688->8695 8691 7ff62e5e2c7c Concurrency::cancel_current_task 2 API calls 8690->8691 8692 7ff62e5dd9e7 8691->8692 8694 7ff62e5e2c7c Concurrency::cancel_current_task 2 API calls 8692->8694 8696 7ff62e5dd9ed 8694->8696 8697 7ff62e5dd80d calloc 8695->8697 8724 7ff62e5e27c0 8695->8724 8698 7ff62e5dda22 8696->8698 8699 7ff62e5dd9fe free free free 8696->8699 8697->8692 8702 7ff62e5dd82a 8697->8702 8698->8668 8699->8698 8700 7ff62e5e27c0 2 API calls 8700->8702 8701 7ff62e5e27c0 2 API calls 8703 7ff62e5dd871 8701->8703 8702->8700 8702->8703 8703->8701 8704 7ff62e5dd8bd calloc 8703->8704 8705 7ff62e5dd8da 8704->8705 8706 7ff62e5dd9dc 8704->8706 8707 7ff62e5dd921 8705->8707 8710 7ff62e5e27c0 2 API calls 8705->8710 8708 7ff62e5e2c7c Concurrency::cancel_current_task 2 API calls 8706->8708 8709 7ff62e5dd98c 8707->8709 8711 7ff62e5e27c0 2 API calls 8707->8711 8708->8690 8713 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8709->8713 8710->8705 8712 7ff62e5dd959 8711->8712 8714 7ff62e5e27c0 2 API calls 8712->8714 8715 7ff62e5dd9bb 8713->8715 8714->8709 8715->8668 8717 7ff62e5dd4ad 8716->8717 8718 7ff62e5e30b9 setlocale 8716->8718 8717->8671 8717->8672 8718->8717 8720 7ff62e5e8127 8719->8720 8721 7ff62e5e348c ___lc_locale_name_func 8720->8721 8722 7ff62e5dd72b 8721->8722 8723 7ff62e5e34aa __pctype_func 8721->8723 8722->8687 8723->8722 8725 7ff62e5e27e6 8724->8725 8729 7ff62e5e27df 8724->8729 8726 7ff62e5e2906 MultiByteToWideChar 8725->8726 8727 7ff62e5e2815 8725->8727 8728 7ff62e5e28a8 8725->8728 8725->8729 8726->8729 8727->8726 8727->8729 8728->8729 8730 7ff62e5e28dd MultiByteToWideChar 8728->8730 8729->8695 8730->8729 7186 7ff62e5e3adc 7209 7ff62e5e3790 7186->7209 7189 7ff62e5e3c33 7191 7ff62e5e4120 7 API calls 7189->7191 7190 7ff62e5e3afd __scrt_acquire_startup_lock 7192 7ff62e5e3c3d 7190->7192 7197 7ff62e5e3b1b __scrt_release_startup_lock 7190->7197 7191->7192 7193 7ff62e5e4120 7 API calls 7192->7193 7194 7ff62e5e3c48 7193->7194 7196 7ff62e5e3c50 _exit 7194->7196 7195 7ff62e5e3b40 7197->7195 7198 7ff62e5e3bc6 _get_initial_wide_environment __p___wargv __p___argc 7197->7198 7201 7ff62e5e3bbe _register_thread_local_exe_atexit_callback 7197->7201 7215 7ff62e5e2690 7198->7215 7201->7198 7204 7ff62e5e3bf3 7205 7ff62e5e3bfd 7204->7205 7206 7ff62e5e3bf8 _cexit 7204->7206 7232 7ff62e5e3924 7205->7232 7206->7205 7236 7ff62e5e3f60 7209->7236 7212 7ff62e5e37bb 7212->7189 7212->7190 7213 7ff62e5e37bf __scrt_initialize_crt 7213->7212 7238 7ff62e5e5990 7213->7238 7266 7ff62e5d64e0 GetEnvironmentVariableW 7215->7266 7222 7ff62e5e26f8 7223 7ff62e5d6b20 4 API calls 7222->7223 7226 7ff62e5e2704 7223->7226 7225 7ff62e5d6b20 4 API calls 7228 7ff62e5e26d9 7225->7228 7291 7ff62e5d6a90 7226->7291 7228->7222 7228->7225 7229 7ff62e5e2793 7230 7ff62e5e4274 GetModuleHandleW 7229->7230 7231 7ff62e5e3bef 7230->7231 7231->7194 7231->7204 7234 7ff62e5e3935 __scrt_initialize_crt 7232->7234 7233 7ff62e5e3945 7233->7195 7234->7233 7235 7ff62e5e5990 __scrt_initialize_crt 8 API calls 7234->7235 7235->7233 7237 7ff62e5e37b2 __scrt_dllmain_crt_thread_attach 7236->7237 7237->7212 7237->7213 7239 7ff62e5e59a2 7238->7239 7240 7ff62e5e5998 7238->7240 7239->7212 7244 7ff62e5e5d74 7240->7244 7245 7ff62e5e5d83 7244->7245 7246 7ff62e5e599d 7244->7246 7252 7ff62e5e7ea4 7245->7252 7248 7ff62e5e7c58 7246->7248 7249 7ff62e5e7c83 7248->7249 7250 7ff62e5e7c87 7249->7250 7251 7ff62e5e7c66 DeleteCriticalSection 7249->7251 7250->7239 7251->7249 7256 7ff62e5e7d0c 7252->7256 7257 7ff62e5e7d50 7256->7257 7258 7ff62e5e7e26 TlsFree 7256->7258 7257->7258 7259 7ff62e5e7d7e LoadLibraryExW 7257->7259 7260 7ff62e5e7e15 GetProcAddress 7257->7260 7261 7ff62e5e7df5 7259->7261 7262 7ff62e5e7d9f GetLastError 7259->7262 7260->7258 7261->7260 7264 7ff62e5e7e0c FreeLibrary 7261->7264 7262->7257 7263 7ff62e5e7daa wcsncmp 7262->7263 7263->7257 7265 7ff62e5e7dc1 LoadLibraryExW 7263->7265 7264->7260 7265->7257 7265->7261 7267 7ff62e5d6543 GetLastError 7266->7267 7268 7ff62e5d657b 7266->7268 7270 7ff62e5d6554 7267->7270 7289 7ff62e5d6576 7267->7289 7271 7ff62e5d6596 GetEnvironmentVariableW 7268->7271 7269 7ff62e5d671e 7443 7ff62e5e36f0 7269->7443 7452 7ff62e5d6e10 7270->7452 7271->7267 7274 7ff62e5d65b0 7271->7274 7457 7ff62e5d51b0 7274->7457 7275 7ff62e5d6717 _invalid_parameter_noinfo_noreturn 7275->7269 7278 7ff62e5d65cb 7279 7ff62e5d65d3 _wtoi 7278->7279 7280 7ff62e5d65f2 7279->7280 7279->7289 7474 7ff62e5d6750 7280->7474 7283 7ff62e5d65ff _time64 _gmtime64_s wcsftime 7284 7ff62e5d6660 7283->7284 7284->7284 7285 7ff62e5d51b0 5 API calls 7284->7285 7286 7ff62e5d667b 7285->7286 7287 7ff62e5d6b20 4 API calls 7286->7287 7288 7ff62e5d6698 7287->7288 7288->7289 7290 7ff62e5d66d1 _invalid_parameter_noinfo_noreturn 7288->7290 7289->7269 7289->7275 7290->7289 7292 7ff62e5d6ab1 EnterCriticalSection 7291->7292 7293 7ff62e5d6b17 7291->7293 7587 7ff62e5d64d0 7292->7587 7296 7ff62e5e1af0 7293->7296 7295 7ff62e5d6ad9 __stdio_common_vfwprintf fputwc LeaveCriticalSection 7295->7293 7588 7ff62e5ddd10 7296->7588 7299 7ff62e5e25f1 7301 7ff62e5d6bb0 17 API calls 7299->7301 7317 7ff62e5e25d6 7301->7317 7303 7ff62e5e1b70 7628 7ff62e5e17e0 7303->7628 7304 7ff62e5e2651 7306 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7304->7306 7309 7ff62e5e2667 7 API calls 7306->7309 7308 7ff62e5e264a _invalid_parameter_noinfo_noreturn 7308->7304 7397 7ff62e5d3c40 7309->7397 7310 7ff62e5e1bc0 7311 7ff62e5d6bb0 17 API calls 7310->7311 7351 7ff62e5e1bcc 7311->7351 7312 7ff62e5e252c 7313 7ff62e5e2580 7312->7313 7316 7ff62e5e2579 _invalid_parameter_noinfo_noreturn 7312->7316 7313->7317 7319 7ff62e5e25cf _invalid_parameter_noinfo_noreturn 7313->7319 7315 7ff62e5e2525 _invalid_parameter_noinfo_noreturn 7315->7312 7316->7313 7317->7304 7317->7308 7318 7ff62e5e1d42 7670 7ff62e5d71b0 7318->7670 7319->7317 7320 7ff62e5e1bd6 7320->7318 7322 7ff62e5e1d30 _invalid_parameter_noinfo_noreturn 7320->7322 7653 7ff62e5d7500 7320->7653 7322->7320 7324 7ff62e5d6b20 4 API calls 7329 7ff62e5e1d7b 7324->7329 7325 7ff62e5df680 35 API calls 7325->7329 7326 7ff62e5e1e53 7328 7ff62e5d6bb0 17 API calls 7326->7328 7327 7ff62e5d7500 17 API calls 7327->7329 7328->7351 7329->7325 7329->7326 7329->7327 7330 7ff62e5e1e7a 7329->7330 7332 7ff62e5e1e38 _invalid_parameter_noinfo_noreturn 7329->7332 7685 7ff62e5e1120 7330->7685 7332->7329 7333 7ff62e5e1ed7 7337 7ff62e5e1edb 7333->7337 7758 7ff62e5ddf10 7333->7758 7336 7ff62e5e1f4c 7338 7ff62e5e2170 GetProcAddress 7336->7338 7339 7ff62e5e1f60 GetProcAddress 7336->7339 7337->7336 7347 7ff62e5e23f9 7337->7347 7342 7ff62e5e2240 7338->7342 7343 7ff62e5e2189 7338->7343 7344 7ff62e5e1f75 7339->7344 7355 7ff62e5e1fb1 7339->7355 7340 7ff62e5d6bb0 17 API calls 7341 7ff62e5e1f1d 7340->7341 7345 7ff62e5d6bb0 17 API calls 7341->7345 7364 7ff62e5d6b20 4 API calls 7342->7364 7346 7ff62e5d6b20 4 API calls 7343->7346 7348 7ff62e5d6b20 4 API calls 7344->7348 7352 7ff62e5e1f29 7345->7352 7350 7ff62e5e219c 7346->7350 7349 7ff62e5e24d1 _invalid_parameter_noinfo_noreturn 7347->7349 7347->7351 7353 7ff62e5e1f88 7348->7353 7349->7351 7356 7ff62e5e21c6 7350->7356 7357 7ff62e5e21a6 7350->7357 7351->7312 7351->7315 7354 7ff62e5d6bb0 17 API calls 7352->7354 7358 7ff62e5d6bb0 17 API calls 7353->7358 7354->7337 7362 7ff62e5d6b20 4 API calls 7355->7362 7360 7ff62e5d6b20 4 API calls 7356->7360 7359 7ff62e5d6bb0 17 API calls 7357->7359 7361 7ff62e5e1fa2 7358->7361 7373 7ff62e5e1fa7 7359->7373 7363 7ff62e5e21dc 7360->7363 7781 7ff62e5e1a30 7361->7781 7366 7ff62e5e201a 7362->7366 7794 7ff62e5d6ea0 7 API calls 7363->7794 7368 7ff62e5e22a2 7364->7368 7369 7ff62e5d6b20 4 API calls 7366->7369 7371 7ff62e5d6b20 4 API calls 7368->7371 7372 7ff62e5e2036 7369->7372 7375 7ff62e5e22be 7371->7375 7376 7ff62e5d6b20 4 API calls 7372->7376 7373->7347 7378 7ff62e5d6b20 4 API calls 7375->7378 7380 7ff62e5e2050 7376->7380 7379 7ff62e5e22d8 7378->7379 7382 7ff62e5d6b20 4 API calls 7379->7382 7383 7ff62e5d6b20 4 API calls 7380->7383 7385 7ff62e5e22f5 GetProcAddress 7382->7385 7386 7ff62e5e206d 7383->7386 7387 7ff62e5e230e 7385->7387 7388 7ff62e5e2321 7 API calls 7385->7388 7389 7ff62e5d6b20 4 API calls 7386->7389 7390 7ff62e5d6b20 4 API calls 7387->7390 7395 7ff62e5e2396 7388->7395 7391 7ff62e5e207c GetProcAddress 7389->7391 7390->7388 7392 7ff62e5e2095 7391->7392 7393 7ff62e5e20a8 7 API calls 7391->7393 7394 7ff62e5d6b20 4 API calls 7392->7394 7393->7373 7394->7393 7395->7373 7396 7ff62e5e1a30 41 API calls 7395->7396 7396->7373 7398 7ff62e5d3c83 7397->7398 7399 7ff62e5d4057 7397->7399 7401 7ff62e5ddd10 16 API calls 7398->7401 7400 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7399->7400 7402 7ff62e5d4063 7400->7402 7405 7ff62e5d3cbb 7401->7405 7402->7229 7406 7ff62e5d3d3e 7405->7406 7412 7ff62e5d3f60 7405->7412 7419 7ff62e5d3e03 7405->7419 7426 7ff62e5d3ccc _Yarn 7405->7426 7413 7ff62e5d4084 7406->7413 7416 7ff62e5d3dd0 7406->7416 7417 7ff62e5d3da1 7406->7417 7406->7426 7407 7ff62e5d3fbf 7411 7ff62e5d3ffe 7407->7411 7421 7ff62e5d3ff7 _invalid_parameter_noinfo_noreturn 7407->7421 7408 7ff62e5d3fa9 8184 7ff62e5d2ba0 GetEnvironmentVariableW 7408->8184 7409 7ff62e5d4089 7414 7ff62e5d57b0 3 API calls 7409->7414 7411->7399 7422 7ff62e5d4052 7411->7422 7428 7ff62e5d404b _invalid_parameter_noinfo_noreturn 7411->7428 8157 7ff62e5d2480 RegisterEventSourceW 7412->8157 7418 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7413->7418 7420 7ff62e5d408f 7414->7420 7415 7ff62e5d3f59 _invalid_parameter_noinfo_noreturn 7415->7412 7425 7ff62e5d3dd5 7416->7425 7416->7426 7417->7413 7423 7ff62e5d3dae 7417->7423 7418->7409 7419->7409 7419->7413 7419->7420 7424 7ff62e5d3e7e 7419->7424 7419->7426 7431 7ff62e5d3ee5 7419->7431 7427 7ff62e5d14b0 3 API calls 7420->7427 7421->7411 7422->7399 7429 7ff62e5e3718 std::_Facet_Register 4 API calls 7423->7429 7424->7413 7432 7ff62e5d3ec6 7424->7432 7430 7ff62e5e3718 std::_Facet_Register 4 API calls 7425->7430 7426->7412 7426->7415 7437 7ff62e5d4095 7427->7437 7428->7422 7433 7ff62e5d3db6 7429->7433 7430->7433 7431->7426 7434 7ff62e5d3eea 7431->7434 7435 7ff62e5e3718 std::_Facet_Register 4 API calls 7432->7435 7433->7415 7433->7426 7436 7ff62e5e3718 std::_Facet_Register 4 API calls 7434->7436 7435->7433 7436->7433 7437->7229 7438 7ff62e5d6b20 7439 7ff62e5d6b41 EnterCriticalSection 7438->7439 7440 7ff62e5d6ba7 7438->7440 8553 7ff62e5d64d0 7439->8553 7440->7228 7442 7ff62e5d6b69 __stdio_common_vfwprintf fputwc LeaveCriticalSection 7442->7440 7444 7ff62e5e36f9 7443->7444 7445 7ff62e5d672f 7444->7445 7446 7ff62e5e3e10 IsProcessorFeaturePresent 7444->7446 7445->7226 7445->7438 7447 7ff62e5e3e28 7446->7447 7508 7ff62e5e3ee4 RtlCaptureContext 7447->7508 7453 7ff62e5d6e31 EnterCriticalSection 7452->7453 7454 7ff62e5d6e97 7452->7454 7513 7ff62e5d64d0 7453->7513 7454->7289 7456 7ff62e5d6e59 __stdio_common_vfwprintf fputwc LeaveCriticalSection 7456->7454 7461 7ff62e5d51e0 _Yarn 7457->7461 7462 7ff62e5d5229 7457->7462 7458 7ff62e5d533b 7523 7ff62e5d14b0 7458->7523 7459 7ff62e5d524b 7463 7ff62e5d5340 7459->7463 7464 7ff62e5d52a9 7459->7464 7461->7278 7462->7458 7462->7459 7462->7463 7466 7ff62e5d52c4 7462->7466 7528 7ff62e5d1410 7463->7528 7514 7ff62e5e3718 7464->7514 7469 7ff62e5d52c9 7466->7469 7473 7ff62e5d52d3 _Yarn 7466->7473 7471 7ff62e5e3718 std::_Facet_Register 4 API calls 7469->7471 7470 7ff62e5d5334 _invalid_parameter_noinfo_noreturn 7470->7458 7472 7ff62e5d52b1 7471->7472 7472->7470 7472->7473 7473->7470 7475 7ff62e5d67a9 EnterCriticalSection __acrt_iob_func GetEnvironmentVariableW 7474->7475 7482 7ff62e5d67a2 7474->7482 7476 7ff62e5d6842 7475->7476 7477 7ff62e5d680a GetLastError 7475->7477 7481 7ff62e5d6856 GetEnvironmentVariableW 7476->7481 7479 7ff62e5d68d2 GetEnvironmentVariableW 7477->7479 7480 7ff62e5d681b 7477->7480 7478 7ff62e5d6a5b 7483 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7478->7483 7484 7ff62e5d692a GetLastError 7479->7484 7485 7ff62e5d68fc 7479->7485 7486 7ff62e5d6e10 4 API calls 7480->7486 7481->7477 7490 7ff62e5d6870 7481->7490 7482->7478 7491 7ff62e5d6a54 _invalid_parameter_noinfo_noreturn 7482->7491 7487 7ff62e5d65f7 7483->7487 7488 7ff62e5d6937 7484->7488 7489 7ff62e5d6959 7484->7489 7492 7ff62e5d6910 GetEnvironmentVariableW 7485->7492 7506 7ff62e5d683d 7486->7506 7487->7283 7487->7289 7497 7ff62e5d6e10 4 API calls 7488->7497 7493 7ff62e5d69e2 LeaveCriticalSection 7489->7493 7494 7ff62e5d69dd 7489->7494 7498 7ff62e5d69d6 _invalid_parameter_noinfo_noreturn 7489->7498 7500 7ff62e5d51b0 5 API calls 7490->7500 7491->7478 7492->7484 7495 7ff62e5d6960 7492->7495 7493->7482 7496 7ff62e5d6a01 7493->7496 7494->7493 7495->7495 7502 7ff62e5d51b0 5 API calls 7495->7502 7555 7ff62e5d6bb0 EnterCriticalSection 7496->7555 7497->7489 7498->7494 7501 7ff62e5d688a 7500->7501 7504 7ff62e5d6892 _wfopen 7501->7504 7503 7ff62e5d6979 7502->7503 7507 7ff62e5d6981 _wtoi 7503->7507 7505 7ff62e5d68b5 setvbuf 7504->7505 7504->7506 7505->7479 7506->7479 7507->7489 7509 7ff62e5e3efe RtlLookupFunctionEntry 7508->7509 7510 7ff62e5e3f14 RtlVirtualUnwind 7509->7510 7511 7ff62e5e3e3b 7509->7511 7510->7509 7510->7511 7512 7ff62e5e3dd0 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 7511->7512 7513->7456 7515 7ff62e5e3732 malloc 7514->7515 7516 7ff62e5e373c 7515->7516 7517 7ff62e5e3723 7515->7517 7516->7472 7517->7515 7519 7ff62e5e3742 7517->7519 7518 7ff62e5e374d 7521 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7518->7521 7519->7518 7534 7ff62e5e2c7c 7519->7534 7522 7ff62e5e3753 7521->7522 7543 7ff62e5e2cc0 7523->7543 7529 7ff62e5d141e Concurrency::cancel_current_task 7528->7529 7530 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 7529->7530 7531 7ff62e5d142f 7530->7531 7532 7ff62e5e4df4 Concurrency::cancel_current_task free 7531->7532 7533 7ff62e5d1459 7532->7533 7535 7ff62e5e2c8a std::bad_alloc::bad_alloc 7534->7535 7538 7ff62e5e4edc 7535->7538 7537 7ff62e5e2c9b 7539 7ff62e5e4efb 7538->7539 7540 7ff62e5e4f18 RtlPcToFileHeader 7538->7540 7539->7540 7541 7ff62e5e4f3f RaiseException 7540->7541 7542 7ff62e5e4f30 7540->7542 7541->7537 7542->7541 7548 7ff62e5e2b2c 7543->7548 7546 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 7547 7ff62e5e2ce2 7546->7547 7551 7ff62e5e4df4 7548->7551 7552 7ff62e5e2b60 7551->7552 7553 7ff62e5e4e15 7551->7553 7552->7546 7553->7552 7554 7ff62e5e4e57 free 7553->7554 7554->7552 7583 7ff62e5d64d0 7555->7583 7557 7ff62e5d6bf6 __stdio_common_vswprintf 7558 7ff62e5d6c44 7557->7558 7571 7ff62e5d6c9f 7557->7571 7560 7ff62e5d6dfc 7558->7560 7563 7ff62e5d6c64 7558->7563 7564 7ff62e5d6c8d 7558->7564 7559 7ff62e5d6cc8 __stdio_common_vswprintf 7561 7ff62e5d6d3b 7559->7561 7562 7ff62e5d6d0b __acrt_iob_func fputws __acrt_iob_func fputwc 7559->7562 7584 7ff62e5d6f70 7560->7584 7566 7ff62e5d6d44 OutputDebugStringW 7561->7566 7562->7566 7567 7ff62e5d6c71 7563->7567 7568 7ff62e5d6df7 7563->7568 7570 7ff62e5d6c92 7564->7570 7564->7571 7574 7ff62e5d6d56 __acrt_iob_func 7566->7574 7582 7ff62e5d6d9e 7566->7582 7573 7ff62e5e3718 std::_Facet_Register 4 API calls 7567->7573 7572 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7568->7572 7575 7ff62e5e3718 std::_Facet_Register 4 API calls 7570->7575 7571->7559 7572->7560 7576 7ff62e5d6c76 7573->7576 7577 7ff62e5d6d73 __stdio_common_vfwprintf fputwc 7574->7577 7578 7ff62e5d6d6d 7574->7578 7575->7576 7576->7571 7580 7ff62e5d6dce _invalid_parameter_noinfo_noreturn 7576->7580 7577->7582 7578->7577 7578->7582 7579 7ff62e5d6dde LeaveCriticalSection 7579->7482 7581 7ff62e5d6dd5 7580->7581 7581->7579 7582->7579 7582->7580 7582->7581 7583->7557 7585 7ff62e5e2cc0 3 API calls 7584->7585 7586 7ff62e5d6f80 7585->7586 7587->7295 7589 7ff62e5ddd60 7588->7589 7590 7ff62e5dddd2 GetModuleFileNameW 7589->7590 7795 7ff62e5e0480 7589->7795 7590->7589 7593 7ff62e5dde01 7590->7593 7592 7ff62e5ddee5 7596 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7592->7596 7594 7ff62e5e0480 5 API calls 7593->7594 7595 7ff62e5dde05 7593->7595 7597 7ff62e5dde12 7593->7597 7594->7597 7595->7592 7599 7ff62e5ddede _invalid_parameter_noinfo_noreturn 7595->7599 7600 7ff62e5ddefa 7596->7600 7597->7595 7598 7ff62e5d51b0 5 API calls 7597->7598 7598->7595 7599->7592 7600->7299 7601 7ff62e5df680 7600->7601 7605 7ff62e5df6c0 7601->7605 7621 7ff62e5df6ff 7601->7621 7602 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7603 7ff62e5df757 7602->7603 7603->7299 7603->7303 7604 7ff62e5df6ee GetFileAttributesExW 7607 7ff62e5df703 GetFullPathNameW 7604->7607 7604->7621 7605->7604 7605->7607 7608 7ff62e5df76f 7607->7608 7609 7ff62e5df728 7607->7609 7610 7ff62e5df7c3 7608->7610 7611 7ff62e5df794 7608->7611 7613 7ff62e5d6bb0 17 API calls 7609->7613 7609->7621 7612 7ff62e5df7cf GetFullPathNameW 7610->7612 7614 7ff62e5e0480 5 API calls 7610->7614 7616 7ff62e5d51b0 5 API calls 7611->7616 7617 7ff62e5df840 7612->7617 7626 7ff62e5df7b9 _Yarn 7612->7626 7613->7621 7614->7612 7616->7626 7620 7ff62e5d6bb0 17 API calls 7617->7620 7617->7626 7618 7ff62e5dfaa0 GetFileAttributesExW 7618->7626 7620->7626 7621->7602 7622 7ff62e5df8a6 _invalid_parameter_noinfo_noreturn 7622->7626 7623 7ff62e5d51b0 5 API calls 7623->7626 7626->7618 7626->7621 7626->7622 7626->7623 7627 7ff62e5dfa78 _invalid_parameter_noinfo_noreturn 7626->7627 7810 7ff62e5e01d0 7626->7810 7815 7ff62e5e0140 7626->7815 7821 7ff62e5d5350 7626->7821 7627->7626 7629 7ff62e5e1820 7628->7629 7629->7629 7630 7ff62e5e183d MultiByteToWideChar 7629->7630 7631 7ff62e5e19ec 7630->7631 7632 7ff62e5e1869 7630->7632 7634 7ff62e5d6bb0 17 API calls 7631->7634 7633 7ff62e5e0140 5 API calls 7632->7633 7636 7ff62e5e1874 MultiByteToWideChar 7633->7636 7635 7ff62e5e19df 7634->7635 7638 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7635->7638 7636->7631 7639 7ff62e5e18a8 7636->7639 7640 7ff62e5e1a07 7638->7640 7847 7ff62e5d53c0 7639->7847 7640->7310 7640->7320 7642 7ff62e5e1992 7643 7ff62e5d6b20 4 API calls 7642->7643 7652 7ff62e5e198e 7643->7652 7644 7ff62e5e18d9 7644->7642 7645 7ff62e5e1a21 7644->7645 7647 7ff62e5e1938 7644->7647 7861 7ff62e5d57b0 7645->7861 7647->7642 7650 7ff62e5e1975 7647->7650 7649 7ff62e5e19d8 _invalid_parameter_noinfo_noreturn 7649->7635 7651 7ff62e5d6bb0 17 API calls 7650->7651 7651->7652 7652->7635 7652->7649 7872 7ff62e5d83e0 7653->7872 7655 7ff62e5d76f0 7657 7ff62e5d777a 7655->7657 7901 7ff62e5d8880 7655->7901 7656 7ff62e5d7535 7656->7655 7660 7ff62e5d75e9 7656->7660 7659 7ff62e5d14b0 3 API calls 7657->7659 7661 7ff62e5d777f 7659->7661 7662 7ff62e5d51b0 5 API calls 7660->7662 7664 7ff62e5d7642 7662->7664 7663 7ff62e5d76c7 7665 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7663->7665 7669 7ff62e5d7650 7664->7669 7886 7ff62e5d62f0 7664->7886 7667 7ff62e5d76db 7665->7667 7666 7ff62e5d7773 _invalid_parameter_noinfo_noreturn 7666->7657 7667->7320 7669->7663 7669->7666 7671 7ff62e5d71f2 7670->7671 7671->7671 7672 7ff62e5d51b0 5 API calls 7671->7672 7673 7ff62e5d720e 7672->7673 7674 7ff62e5d7272 7673->7674 7676 7ff62e5d726b _invalid_parameter_noinfo_noreturn 7673->7676 7675 7ff62e5d727c 7674->7675 7679 7ff62e5d729a 7674->7679 7681 7ff62e5d51b0 5 API calls 7675->7681 7676->7674 7677 7ff62e5d72c0 7913 7ff62e5d4c70 7677->7913 7679->7677 7683 7ff62e5d62f0 5 API calls 7679->7683 7680 7ff62e5d7298 7682 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7680->7682 7681->7680 7684 7ff62e5d730b 7682->7684 7683->7677 7684->7324 7684->7329 7686 7ff62e5e1168 7685->7686 7693 7ff62e5e11b2 7685->7693 7687 7ff62e5d51b0 5 API calls 7686->7687 7688 7ff62e5e1196 7687->7688 7935 7ff62e5d6fc0 7688->7935 7689 7ff62e5e1205 7690 7ff62e5e126f 7689->7690 7691 7ff62e5e120f 7689->7691 7959 7ff62e5d7e70 7690->7959 7695 7ff62e5d6b20 4 API calls 7691->7695 7693->7689 7696 7ff62e5e11fe _invalid_parameter_noinfo_noreturn 7693->7696 7698 7ff62e5e1228 7695->7698 7696->7689 7701 7ff62e5e1246 7698->7701 7708 7ff62e5d51b0 5 API calls 7698->7708 7699 7ff62e5e12d4 7984 7ff62e5deff0 7699->7984 7700 7ff62e5e12ab 7703 7ff62e5d6b20 4 API calls 7700->7703 7705 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7701->7705 7706 7ff62e5e12d2 7703->7706 7709 7ff62e5e1254 7705->7709 7712 7ff62e5d83e0 5 API calls 7706->7712 7707 7ff62e5e1303 7711 7ff62e5d6b20 4 API calls 7707->7711 7708->7701 7709->7333 7714 7ff62e5e131f 7711->7714 7715 7ff62e5e1351 7712->7715 7714->7706 7717 7ff62e5d51b0 5 API calls 7714->7717 7718 7ff62e5d71b0 16 API calls 7715->7718 7716 7ff62e5e12f0 7719 7ff62e5d6bb0 17 API calls 7716->7719 7717->7706 7720 7ff62e5e1362 7718->7720 7743 7ff62e5e12fc 7719->7743 7721 7ff62e5d71b0 16 API calls 7720->7721 7723 7ff62e5e1372 7721->7723 7722 7ff62e5e173f 7724 7ff62e5e1794 7722->7724 7730 7ff62e5e178d _invalid_parameter_noinfo_noreturn 7722->7730 7723->7724 7728 7ff62e5e13eb 7723->7728 7729 7ff62e5e141a 7723->7729 7736 7ff62e5e1399 _Yarn 7723->7736 7726 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7724->7726 7725 7ff62e5e1738 _invalid_parameter_noinfo_noreturn 7725->7722 7731 7ff62e5e17a6 7726->7731 7727 7ff62e5df680 35 API calls 7732 7ff62e5e1457 7727->7732 7728->7724 7735 7ff62e5e3718 std::_Facet_Register 4 API calls 7728->7735 7733 7ff62e5e3718 std::_Facet_Register 4 API calls 7729->7733 7729->7736 7730->7724 7731->7333 7734 7ff62e5e149a 7732->7734 7737 7ff62e5e1493 _invalid_parameter_noinfo_noreturn 7732->7737 7733->7736 7738 7ff62e5deff0 33 API calls 7734->7738 7740 7ff62e5e14ca 7734->7740 7756 7ff62e5e1674 7734->7756 7735->7736 7736->7727 7736->7737 7737->7734 7739 7ff62e5e14b9 7738->7739 7739->7740 7741 7ff62e5de160 65 API calls 7739->7741 7742 7ff62e5d6a90 4 API calls 7740->7742 7741->7740 7745 7ff62e5e152a 7742->7745 7743->7722 7743->7725 7744 7ff62e5e16e4 _invalid_parameter_noinfo_noreturn 7744->7743 7746 7ff62e5ddd10 16 API calls 7745->7746 7747 7ff62e5e154f 7746->7747 8062 7ff62e5d80a0 7747->8062 7750 7ff62e5d6bb0 17 API calls 7751 7ff62e5e1598 7750->7751 7752 7ff62e5e15d7 7751->7752 7754 7ff62e5e15d0 _invalid_parameter_noinfo_noreturn 7751->7754 7753 7ff62e5e161d 7752->7753 7755 7ff62e5e1616 _invalid_parameter_noinfo_noreturn 7752->7755 7753->7756 7757 7ff62e5e166d _invalid_parameter_noinfo_noreturn 7753->7757 7754->7752 7755->7753 7756->7743 7756->7744 7757->7756 7759 7ff62e5d83e0 5 API calls 7758->7759 7762 7ff62e5ddf3a 7759->7762 7760 7ff62e5df680 35 API calls 7761 7ff62e5ddfba 7760->7761 7763 7ff62e5ddfe8 GetLastError 7761->7763 7764 7ff62e5ddfc6 LoadLibraryExW 7761->7764 7762->7760 7762->7764 7766 7ff62e5ddff2 7763->7766 7764->7763 7765 7ff62e5de01e GetModuleHandleExW 7764->7765 7768 7ff62e5de03f 7765->7768 7769 7ff62e5de067 7765->7769 7767 7ff62e5d6bb0 17 API calls 7766->7767 7779 7ff62e5de017 7767->7779 7770 7ff62e5d6bb0 17 API calls 7768->7770 7771 7ff62e5ddd10 16 API calls 7769->7771 7769->7779 7770->7779 7772 7ff62e5de096 7771->7772 7775 7ff62e5d6b20 4 API calls 7772->7775 7773 7ff62e5de134 7774 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7773->7774 7776 7ff62e5de148 7774->7776 7777 7ff62e5de0b0 7775->7777 7776->7337 7776->7340 7777->7779 7780 7ff62e5de0e8 _invalid_parameter_noinfo_noreturn 7777->7780 7778 7ff62e5de12d _invalid_parameter_noinfo_noreturn 7778->7773 7779->7773 7779->7778 7780->7779 7782 7ff62e5d80a0 27 API calls 7781->7782 7783 7ff62e5e1a4d 7782->7783 7784 7ff62e5d6bb0 17 API calls 7783->7784 7785 7ff62e5e1a5a 7784->7785 7786 7ff62e5d6bb0 17 API calls 7785->7786 7787 7ff62e5e1a66 7786->7787 7788 7ff62e5d6bb0 17 API calls 7787->7788 7789 7ff62e5e1a8a 7788->7789 7790 7ff62e5e1acb 7789->7790 7793 7ff62e5e1ac4 _invalid_parameter_noinfo_noreturn 7789->7793 7791 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7790->7791 7792 7ff62e5e1add 7791->7792 7792->7373 7793->7790 7796 7ff62e5e0625 7795->7796 7800 7ff62e5e04ae 7795->7800 7798 7ff62e5d14b0 3 API calls 7796->7798 7797 7ff62e5e04d9 7799 7ff62e5e062a 7797->7799 7801 7ff62e5e0537 7797->7801 7798->7799 7803 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7799->7803 7800->7797 7800->7799 7802 7ff62e5e0556 7800->7802 7804 7ff62e5e3718 std::_Facet_Register 4 API calls 7801->7804 7806 7ff62e5e3718 std::_Facet_Register 4 API calls 7802->7806 7809 7ff62e5e053f _Yarn 7802->7809 7805 7ff62e5e0630 7803->7805 7804->7809 7806->7809 7807 7ff62e5e05d8 _invalid_parameter_noinfo_noreturn 7808 7ff62e5e05cb _Yarn 7807->7808 7808->7590 7809->7807 7809->7808 7811 7ff62e5e01e7 7810->7811 7814 7ff62e5e0205 _Yarn 7811->7814 7832 7ff62e5e02e0 7811->7832 7813 7ff62e5e02d0 7813->7626 7814->7626 7816 7ff62e5e0155 7815->7816 7817 7ff62e5e0170 7815->7817 7816->7626 7818 7ff62e5e0182 7817->7818 7819 7ff62e5e0480 5 API calls 7817->7819 7818->7626 7820 7ff62e5e01c4 7819->7820 7820->7626 7822 7ff62e5d5363 7821->7822 7823 7ff62e5d53b6 7821->7823 7822->7823 7826 7ff62e5d5379 7822->7826 7827 7ff62e5d53a1 7822->7827 7824 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7823->7824 7825 7ff62e5d53bb 7824->7825 7828 7ff62e5e3718 std::_Facet_Register 4 API calls 7826->7828 7827->7626 7829 7ff62e5d5381 7828->7829 7830 7ff62e5d539a _invalid_parameter_noinfo_noreturn 7829->7830 7831 7ff62e5d5389 7829->7831 7830->7827 7831->7626 7833 7ff62e5e0469 7832->7833 7837 7ff62e5e0309 7832->7837 7835 7ff62e5d14b0 3 API calls 7833->7835 7834 7ff62e5e032c 7836 7ff62e5e046e 7834->7836 7838 7ff62e5e038d 7834->7838 7835->7836 7839 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7836->7839 7837->7834 7837->7836 7840 7ff62e5e03ac 7837->7840 7841 7ff62e5e3718 std::_Facet_Register 4 API calls 7838->7841 7842 7ff62e5e0474 7839->7842 7844 7ff62e5e3718 std::_Facet_Register 4 API calls 7840->7844 7845 7ff62e5e0395 _Yarn 7840->7845 7841->7845 7843 7ff62e5e0431 _invalid_parameter_noinfo_noreturn 7846 7ff62e5e0424 _Yarn 7843->7846 7844->7845 7845->7843 7845->7846 7846->7813 7850 7ff62e5d5405 7847->7850 7860 7ff62e5d53e4 _Yarn 7847->7860 7848 7ff62e5d5511 7849 7ff62e5d14b0 3 API calls 7848->7849 7851 7ff62e5d5516 7849->7851 7850->7848 7852 7ff62e5d5454 7850->7852 7853 7ff62e5d5489 7850->7853 7855 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7851->7855 7852->7851 7854 7ff62e5e3718 std::_Facet_Register 4 API calls 7852->7854 7857 7ff62e5e3718 std::_Facet_Register 4 API calls 7853->7857 7859 7ff62e5d5472 _Yarn 7853->7859 7854->7859 7858 7ff62e5d551c 7855->7858 7856 7ff62e5d550a _invalid_parameter_noinfo_noreturn 7856->7848 7857->7859 7859->7856 7859->7860 7860->7644 7864 7ff62e5e2ce4 7861->7864 7869 7ff62e5e2bec 7864->7869 7867 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 7868 7ff62e5e2d06 7867->7868 7870 7ff62e5e4df4 Concurrency::cancel_current_task free 7869->7870 7871 7ff62e5e2c20 7870->7871 7871->7867 7875 7ff62e5d840d 7872->7875 7873 7ff62e5d84d0 7874 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7873->7874 7877 7ff62e5d84d5 7874->7877 7875->7873 7876 7ff62e5d8490 7875->7876 7878 7ff62e5d846b 7875->7878 7880 7ff62e5d841b _Yarn 7875->7880 7879 7ff62e5d8495 7876->7879 7876->7880 7881 7ff62e5e3718 std::_Facet_Register 4 API calls 7878->7881 7882 7ff62e5e3718 std::_Facet_Register 4 API calls 7879->7882 7880->7656 7883 7ff62e5d8473 7881->7883 7882->7880 7884 7ff62e5d847b 7883->7884 7885 7ff62e5d8489 _invalid_parameter_noinfo_noreturn 7883->7885 7884->7880 7885->7876 7887 7ff62e5d6479 7886->7887 7889 7ff62e5d6320 7886->7889 7888 7ff62e5d14b0 3 API calls 7887->7888 7891 7ff62e5d647e 7888->7891 7890 7ff62e5d634b 7889->7890 7889->7891 7894 7ff62e5d63c8 7889->7894 7890->7891 7892 7ff62e5d63a9 7890->7892 7893 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7891->7893 7895 7ff62e5e3718 std::_Facet_Register 4 API calls 7892->7895 7896 7ff62e5d6484 7893->7896 7898 7ff62e5e3718 std::_Facet_Register 4 API calls 7894->7898 7899 7ff62e5d63b1 _Yarn 7894->7899 7895->7899 7897 7ff62e5d643a _invalid_parameter_noinfo_noreturn 7900 7ff62e5d642d _Yarn 7897->7900 7898->7899 7899->7897 7899->7900 7900->7669 7902 7ff62e5d88d2 7901->7902 7907 7ff62e5d8939 _Yarn 7901->7907 7903 7ff62e5d89b4 7902->7903 7904 7ff62e5d894e 7902->7904 7905 7ff62e5d892c 7902->7905 7906 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7903->7906 7904->7907 7911 7ff62e5e3718 std::_Facet_Register 4 API calls 7904->7911 7908 7ff62e5e3718 std::_Facet_Register 4 API calls 7905->7908 7909 7ff62e5d89b9 7906->7909 7907->7669 7910 7ff62e5d8934 7908->7910 7910->7907 7912 7ff62e5d8947 _invalid_parameter_noinfo_noreturn 7910->7912 7911->7907 7912->7904 7914 7ff62e5d4c83 7913->7914 7915 7ff62e5d4ca1 _Yarn 7914->7915 7918 7ff62e5d57d0 7914->7918 7915->7680 7917 7ff62e5d4cf5 7917->7680 7919 7ff62e5d597b 7918->7919 7923 7ff62e5d57fe 7918->7923 7921 7ff62e5d14b0 3 API calls 7919->7921 7920 7ff62e5d5829 7922 7ff62e5d5980 7920->7922 7924 7ff62e5d5887 7920->7924 7921->7922 7927 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7922->7927 7923->7920 7923->7922 7926 7ff62e5d58a6 7923->7926 7925 7ff62e5e3718 std::_Facet_Register 4 API calls 7924->7925 7932 7ff62e5d588f 7925->7932 7928 7ff62e5d58ab 7926->7928 7933 7ff62e5d58b5 _Yarn 7926->7933 7929 7ff62e5d5986 7927->7929 7931 7ff62e5e3718 std::_Facet_Register 4 API calls 7928->7931 7930 7ff62e5d5933 _invalid_parameter_noinfo_noreturn 7934 7ff62e5d5926 _Yarn 7930->7934 7931->7932 7932->7930 7932->7933 7933->7930 7933->7934 7934->7917 7936 7ff62e5d83e0 5 API calls 7935->7936 7937 7ff62e5d6fee 7936->7937 7938 7ff62e5d71b0 16 API calls 7937->7938 7939 7ff62e5d7005 7938->7939 7940 7ff62e5d71aa 7939->7940 7941 7ff62e5d70a5 7939->7941 7942 7ff62e5d707a 7939->7942 7952 7ff62e5d702b _Yarn 7939->7952 7943 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 7940->7943 7948 7ff62e5e3718 std::_Facet_Register 4 API calls 7941->7948 7941->7952 7942->7940 7945 7ff62e5d7087 7942->7945 7946 7ff62e5d71af 7943->7946 7944 7ff62e5df680 35 API calls 7950 7ff62e5d70d9 7944->7950 7947 7ff62e5e3718 std::_Facet_Register 4 API calls 7945->7947 7947->7952 7948->7952 7949 7ff62e5d714b 7954 7ff62e5d718b 7949->7954 7958 7ff62e5d7184 _invalid_parameter_noinfo_noreturn 7949->7958 7951 7ff62e5d7113 _invalid_parameter_noinfo_noreturn 7950->7951 7953 7ff62e5d711a 7950->7953 7951->7953 7952->7944 7952->7951 7953->7949 7957 7ff62e5d51b0 5 API calls 7953->7957 7955 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7954->7955 7956 7ff62e5d719f 7955->7956 7956->7693 7957->7949 7958->7954 7960 7ff62e5d51b0 5 API calls 7959->7960 7961 7ff62e5d7ead 7960->7961 7962 7ff62e5d51b0 5 API calls 7961->7962 7963 7ff62e5d7edc 7962->7963 7964 7ff62e5d7f36 7963->7964 7965 7ff62e5d7f20 toupper 7963->7965 7966 7ff62e5d57d0 5 API calls 7964->7966 7968 7ff62e5d7f65 _Yarn 7964->7968 7965->7964 7965->7965 7966->7968 7967 7ff62e5d7fde 8081 7ff62e5d7ac0 7967->8081 7968->7967 7970 7ff62e5d7fd7 _invalid_parameter_noinfo_noreturn 7968->7970 7970->7967 7972 7ff62e5d8078 7976 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 7972->7976 7973 7ff62e5d7ffc GetCurrentProcess IsWow64Process 7974 7ff62e5d804a 7973->7974 7975 7ff62e5d8019 7973->7975 7974->7972 7977 7ff62e5d51b0 5 API calls 7974->7977 7975->7974 7979 7ff62e5d51b0 5 API calls 7975->7979 7978 7ff62e5d8089 7976->7978 7980 7ff62e5d8063 7977->7980 7978->7699 7978->7700 7981 7ff62e5d8035 7979->7981 7982 7ff62e5d7ac0 47 API calls 7980->7982 7983 7ff62e5d7ac0 47 API calls 7981->7983 7982->7972 7983->7974 7985 7ff62e5df030 7984->7985 7986 7ff62e5df0b2 7985->7986 7987 7ff62e5df05e GetEnvironmentVariableW 7985->7987 7990 7ff62e5df0d8 RegOpenKeyExW 7986->7990 7988 7ff62e5df083 GetLastError 7987->7988 7989 7ff62e5df121 7987->7989 7988->7986 7991 7ff62e5df090 7988->7991 7994 7ff62e5df135 GetEnvironmentVariableW 7989->7994 7992 7ff62e5df19e RegGetValueW 7990->7992 7993 7ff62e5df10e 7990->7993 7995 7ff62e5d6e10 4 API calls 7991->7995 7996 7ff62e5df1d3 7992->7996 7997 7ff62e5df315 7992->7997 7998 7ff62e5d6a90 4 API calls 7993->7998 7994->7988 7999 7ff62e5df153 7994->7999 7995->7986 7996->7997 8000 7ff62e5df1de 7996->8000 8001 7ff62e5d6a90 4 API calls 7997->8001 8013 7ff62e5df11c 7998->8013 7999->7999 8004 7ff62e5d51b0 5 API calls 7999->8004 8002 7ff62e5df214 8000->8002 8006 7ff62e5df202 8000->8006 8007 7ff62e5df22b 8000->8007 8003 7ff62e5df323 RegCloseKey 8001->8003 8005 7ff62e5df266 RegGetValueW 8002->8005 8027 7ff62e5df304 _invalid_parameter_noinfo_noreturn 8002->8027 8003->8013 8008 7ff62e5df16c 8004->8008 8009 7ff62e5df293 8005->8009 8010 7ff62e5df2b0 8005->8010 8011 7ff62e5df20f 8006->8011 8012 7ff62e5df3f1 8006->8012 8007->8002 8017 7ff62e5e3718 std::_Facet_Register 4 API calls 8007->8017 8023 7ff62e5df197 8008->8023 8024 7ff62e5d51b0 5 API calls 8008->8024 8014 7ff62e5d6a90 4 API calls 8009->8014 8010->8010 8021 7ff62e5d51b0 5 API calls 8010->8021 8015 7ff62e5e3718 std::_Facet_Register 4 API calls 8011->8015 8016 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 8012->8016 8022 7ff62e5df366 _invalid_parameter_noinfo_noreturn 8013->8022 8013->8023 8019 7ff62e5df2a1 RegCloseKey 8014->8019 8015->8002 8020 7ff62e5df3f6 8016->8020 8017->8002 8018 7ff62e5df3c1 8025 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8018->8025 8026 7ff62e5df2d4 8019->8026 8028 7ff62e5df2c8 RegCloseKey 8021->8028 8022->8023 8023->8018 8029 7ff62e5df3ba _invalid_parameter_noinfo_noreturn 8023->8029 8024->8023 8030 7ff62e5df3d5 8025->8030 8026->8013 8026->8027 8027->8013 8028->8026 8029->8018 8030->7707 8031 7ff62e5de160 8030->8031 8032 7ff62e5de1f8 GetCurrentProcess IsWow64Process 8031->8032 8033 7ff62e5de1a8 GetEnvironmentVariableW 8031->8033 8036 7ff62e5de215 8032->8036 8034 7ff62e5de241 8033->8034 8035 7ff62e5de1c9 GetLastError 8033->8035 8039 7ff62e5de25c GetEnvironmentVariableW 8034->8039 8035->8032 8037 7ff62e5de1d6 8035->8037 8038 7ff62e5d7ac0 47 API calls 8036->8038 8041 7ff62e5d6e10 4 API calls 8037->8041 8042 7ff62e5de232 8038->8042 8039->8035 8040 7ff62e5de27a 8039->8040 8044 7ff62e5d51b0 5 API calls 8040->8044 8041->8032 8043 7ff62e5d71b0 16 API calls 8042->8043 8050 7ff62e5de23a 8042->8050 8045 7ff62e5de2e2 LoadLibraryExW 8043->8045 8056 7ff62e5de29a 8044->8056 8048 7ff62e5de312 GetProcAddress 8045->8048 8049 7ff62e5de2fc GetLastError 8045->8049 8046 7ff62e5de3bd 8047 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8046->8047 8052 7ff62e5de3d2 8047->8052 8048->8050 8051 7ff62e5de32a GetCurrentProcess 8048->8051 8053 7ff62e5d6b20 4 API calls 8049->8053 8050->8046 8054 7ff62e5de3b6 _invalid_parameter_noinfo_noreturn 8050->8054 8055 7ff62e5de346 8051->8055 8052->7707 8052->7716 8053->8050 8054->8046 8057 7ff62e5de360 8055->8057 8058 7ff62e5de34a GetLastError 8055->8058 8056->8050 8059 7ff62e5d51b0 5 API calls 8056->8059 8057->8050 8061 7ff62e5d71b0 16 API calls 8057->8061 8060 7ff62e5d6b20 4 API calls 8058->8060 8059->8050 8060->8050 8061->8050 8063 7ff62e5d51b0 5 API calls 8062->8063 8064 7ff62e5d80fa 8063->8064 8065 7ff62e5d57d0 5 API calls 8064->8065 8066 7ff62e5d8116 _Yarn 8064->8066 8065->8066 8067 7ff62e5d57d0 5 API calls 8066->8067 8068 7ff62e5d8178 _Yarn 8066->8068 8067->8068 8069 7ff62e5d57d0 5 API calls 8068->8069 8070 7ff62e5d81da _Yarn 8068->8070 8069->8070 8103 7ff62e5d7780 GetEnvironmentVariableW 8070->8103 8073 7ff62e5d57d0 5 API calls 8074 7ff62e5d8247 _Yarn 8073->8074 8075 7ff62e5d57d0 5 API calls 8074->8075 8077 7ff62e5d82c4 _Yarn 8074->8077 8075->8077 8076 7ff62e5d833c 8078 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8076->8078 8077->8076 8079 7ff62e5d8335 _invalid_parameter_noinfo_noreturn 8077->8079 8080 7ff62e5d8354 8078->8080 8079->8076 8080->7750 8082 7ff62e5d7afa GetEnvironmentVariableW 8081->8082 8083 7ff62e5d7af7 8081->8083 8084 7ff62e5d7b5e 8082->8084 8085 7ff62e5d7b2a GetLastError 8082->8085 8083->8082 8087 7ff62e5d7b79 GetEnvironmentVariableW 8084->8087 8086 7ff62e5d7b3b 8085->8086 8091 7ff62e5d7b59 8085->8091 8088 7ff62e5d6e10 4 API calls 8086->8088 8087->8085 8089 7ff62e5d7b8f 8087->8089 8088->8091 8095 7ff62e5d51b0 5 API calls 8089->8095 8090 7ff62e5d7c50 8092 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8090->8092 8091->8090 8093 7ff62e5d7c49 _invalid_parameter_noinfo_noreturn 8091->8093 8094 7ff62e5d7c65 8092->8094 8093->8090 8094->7972 8094->7973 8096 7ff62e5d7baa 8095->8096 8097 7ff62e5df680 35 API calls 8096->8097 8098 7ff62e5d7bbe 8097->8098 8099 7ff62e5d7bc2 8098->8099 8100 7ff62e5d7bee 8098->8100 8099->8091 8102 7ff62e5d51b0 5 API calls 8099->8102 8101 7ff62e5d6a90 4 API calls 8100->8101 8101->8091 8102->8091 8104 7ff62e5d77e4 8103->8104 8105 7ff62e5d781d GetLastError 8103->8105 8108 7ff62e5d77ff GetEnvironmentVariableW 8104->8108 8106 7ff62e5d782a 8105->8106 8107 7ff62e5d784c 8105->8107 8111 7ff62e5d6e10 4 API calls 8106->8111 8126 7ff62e5df400 8107->8126 8108->8105 8110 7ff62e5d7a60 8108->8110 8110->8110 8112 7ff62e5d51b0 5 API calls 8110->8112 8111->8107 8115 7ff62e5d7a09 _Yarn 8112->8115 8113 7ff62e5d790b 8117 7ff62e5d7981 8113->8117 8119 7ff62e5d51b0 5 API calls 8113->8119 8114 7ff62e5d7855 8114->8113 8116 7ff62e5d7904 _invalid_parameter_noinfo_noreturn 8114->8116 8122 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8115->8122 8116->8113 8117->8115 8118 7ff62e5d79b7 8117->8118 8121 7ff62e5d57d0 5 API calls 8117->8121 8118->8115 8123 7ff62e5d57d0 5 API calls 8118->8123 8120 7ff62e5d7943 8119->8120 8120->8117 8125 7ff62e5d797a _invalid_parameter_noinfo_noreturn 8120->8125 8121->8118 8124 7ff62e5d7a9f 8122->8124 8123->8115 8124->8073 8124->8074 8125->8117 8150 7ff62e5e5700 8126->8150 8128 7ff62e5df464 LoadLibraryA 8129 7ff62e5df482 GetProcAddress 8128->8129 8130 7ff62e5df4e6 8128->8130 8129->8130 8133 7ff62e5df49b 8129->8133 8131 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8130->8131 8132 7ff62e5df65a 8131->8132 8132->8114 8133->8130 8134 7ff62e5df50d 8133->8134 8135 7ff62e5df4cd 8133->8135 8134->8130 8141 7ff62e5d4c70 5 API calls 8134->8141 8136 7ff62e5df4d5 8135->8136 8137 7ff62e5df4fc 8135->8137 8138 7ff62e5df4eb 8136->8138 8139 7ff62e5df4da 8136->8139 8140 7ff62e5d4c70 5 API calls 8137->8140 8143 7ff62e5d4c70 5 API calls 8138->8143 8142 7ff62e5d4c70 5 API calls 8139->8142 8140->8130 8144 7ff62e5df525 8141->8144 8142->8130 8143->8130 8145 7ff62e5df5ec 8144->8145 8146 7ff62e5d51b0 5 API calls 8144->8146 8152 7ff62e5d4d00 8145->8152 8146->8145 8148 7ff62e5df601 8148->8130 8149 7ff62e5df63b _invalid_parameter_noinfo_noreturn 8148->8149 8149->8130 8151 7ff62e5e56e0 8150->8151 8151->8128 8151->8151 8153 7ff62e5d4d13 8152->8153 8154 7ff62e5d57d0 5 API calls 8153->8154 8156 7ff62e5d4d2d _Yarn 8153->8156 8155 7ff62e5d4d81 8154->8155 8155->8148 8156->8148 8158 7ff62e5d57d0 5 API calls 8157->8158 8159 7ff62e5d24f5 8158->8159 8160 7ff62e5d57d0 5 API calls 8159->8160 8161 7ff62e5d2509 _Yarn 8159->8161 8160->8161 8162 7ff62e5d4c70 5 API calls 8161->8162 8163 7ff62e5d2566 8162->8163 8164 7ff62e5d57d0 5 API calls 8163->8164 8165 7ff62e5d2584 8163->8165 8164->8165 8166 7ff62e5d57d0 5 API calls 8165->8166 8167 7ff62e5d25cb _Yarn 8165->8167 8166->8167 8168 7ff62e5d4c70 5 API calls 8167->8168 8169 7ff62e5d262a 8168->8169 8170 7ff62e5d57d0 5 API calls 8169->8170 8171 7ff62e5d263d 8169->8171 8170->8171 8172 7ff62e5d57d0 5 API calls 8171->8172 8173 7ff62e5d2684 _Yarn 8171->8173 8172->8173 8174 7ff62e5d270c _Yarn 8173->8174 8175 7ff62e5d57d0 5 API calls 8173->8175 8176 7ff62e5d57d0 5 API calls 8174->8176 8177 7ff62e5d275f 8174->8177 8175->8174 8178 7ff62e5d2792 ReportEventW DeregisterEventSource 8176->8178 8177->8178 8179 7ff62e5d281f 8178->8179 8180 7ff62e5d27eb 8178->8180 8181 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8179->8181 8180->8179 8182 7ff62e5d2818 _invalid_parameter_noinfo_noreturn 8180->8182 8183 7ff62e5d2830 GetModuleHandleW 8181->8183 8182->8179 8183->7407 8183->7408 8185 7ff62e5d2c14 GetLastError 8184->8185 8186 7ff62e5d2c49 8184->8186 8187 7ff62e5d2c25 8185->8187 8188 7ff62e5d2c47 8185->8188 8190 7ff62e5d2c5d GetEnvironmentVariableW 8186->8190 8193 7ff62e5d6e10 4 API calls 8187->8193 8189 7ff62e5d2e92 8188->8189 8271 7ff62e5d2a70 8188->8271 8192 7ff62e5d3477 8189->8192 8195 7ff62e5d51b0 5 API calls 8189->8195 8190->8185 8194 7ff62e5d2c77 8190->8194 8198 7ff62e5d49c0 41 API calls 8192->8198 8238 7ff62e5d37d7 8192->8238 8193->8188 8200 7ff62e5d51b0 5 API calls 8194->8200 8196 7ff62e5d2ec5 8195->8196 8201 7ff62e5d49c0 41 API calls 8196->8201 8211 7ff62e5d3469 _invalid_parameter_noinfo_noreturn 8196->8211 8197 7ff62e5d3a4a 8209 7ff62e5d3a9c _invalid_parameter_noinfo_noreturn 8197->8209 8216 7ff62e5d3aa3 8197->8216 8264 7ff62e5d34a2 _Yarn 8198->8264 8199 7ff62e5d2dc9 8278 7ff62e5d49c0 8199->8278 8203 7ff62e5d2c9a 8200->8203 8263 7ff62e5d2f3f _Yarn 8201->8263 8202 7ff62e5d2d0f 8202->8199 8206 7ff62e5d2dc2 _invalid_parameter_noinfo_noreturn 8202->8206 8215 7ff62e5d2ca2 _wtoi 8203->8215 8205 7ff62e5d3a43 _invalid_parameter_noinfo_noreturn 8205->8197 8206->8199 8207 7ff62e5d2dec 8289 7ff62e5d5c50 8207->8289 8208 7ff62e5d5c50 19 API calls 8208->8264 8209->8216 8210 7ff62e5d3afc 8212 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8210->8212 8214 7ff62e5d3470 _invalid_parameter_noinfo_noreturn 8211->8214 8217 7ff62e5d3b10 8212->8217 8214->8192 8215->8188 8215->8216 8216->8210 8220 7ff62e5d3af5 _invalid_parameter_noinfo_noreturn 8216->8220 8217->7407 8218 7ff62e5d5c50 19 API calls 8218->8263 8219 7ff62e5d378a 8221 7ff62e5d37e1 8219->8221 8222 7ff62e5d3796 8219->8222 8220->8210 8227 7ff62e5d3b40 _invalid_parameter_noinfo_noreturn 8221->8227 8226 7ff62e5d3b40 _invalid_parameter_noinfo_noreturn 8222->8226 8223 7ff62e5d2e3d 8320 7ff62e5d3b40 8223->8320 8224 7ff62e5d34ca wcsncmp 8224->8264 8225 7ff62e5d3415 8230 7ff62e5d3b40 _invalid_parameter_noinfo_noreturn 8225->8230 8231 7ff62e5d379b 8226->8231 8227->8231 8229 7ff62e5d2ffc wcsncmp 8229->8263 8234 7ff62e5d341f 8230->8234 8236 7ff62e5d3825 8231->8236 8231->8238 8242 7ff62e5d381e _invalid_parameter_noinfo_noreturn 8231->8242 8233 7ff62e5d2e47 8233->8236 8245 7ff62e5d2e8b _invalid_parameter_noinfo_noreturn 8233->8245 8234->8211 8234->8236 8235 7ff62e5d303a wcsncmp 8235->8263 8246 7ff62e5d57d0 5 API calls 8236->8246 8247 7ff62e5d383e _Yarn 8236->8247 8237 7ff62e5d2a70 6 API calls 8237->8264 8238->8197 8238->8205 8239 7ff62e5d2dfb 8239->8223 8243 7ff62e5d5c50 19 API calls 8239->8243 8300 7ff62e5d2850 8239->8300 8240 7ff62e5d3182 wcsncmp 8240->8263 8241 7ff62e5d2850 19 API calls 8241->8263 8242->8236 8243->8239 8244 7ff62e5d57d0 _invalid_parameter_noinfo_noreturn malloc free RtlPcToFileHeader RaiseException 8244->8263 8245->8189 8246->8247 8251 7ff62e5d4c70 5 API calls 8247->8251 8248 7ff62e5d3b2b 8249 7ff62e5d57b0 3 API calls 8248->8249 8254 7ff62e5d3b30 8249->8254 8250 7ff62e5d80a0 27 API calls 8250->8264 8255 7ff62e5d38af 8251->8255 8252 7ff62e5d3b36 8257 7ff62e5d14b0 3 API calls 8252->8257 8253 7ff62e5d377c _invalid_parameter_noinfo_noreturn 8256 7ff62e5d3783 _invalid_parameter_noinfo_noreturn 8253->8256 8259 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 8254->8259 8258 7ff62e5d57d0 5 API calls 8255->8258 8261 7ff62e5d38c3 _Yarn 8255->8261 8256->8219 8260 7ff62e5d3b3c 8257->8260 8258->8261 8259->8252 8265 7ff62e5d57d0 5 API calls 8261->8265 8266 7ff62e5d392c _Yarn 8261->8266 8262 7ff62e5e3718 malloc free RtlPcToFileHeader RaiseException std::_Facet_Register 8262->8263 8263->8214 8263->8218 8263->8225 8263->8229 8263->8235 8263->8240 8263->8241 8263->8244 8263->8248 8263->8252 8263->8254 8263->8262 8264->8208 8264->8219 8264->8224 8264->8237 8264->8250 8264->8253 8264->8256 8268 7ff62e5d57d0 _invalid_parameter_noinfo_noreturn malloc free RtlPcToFileHeader RaiseException 8264->8268 8265->8266 8267 7ff62e5d6a90 4 API calls 8266->8267 8269 7ff62e5d39b4 MessageBoxW 8267->8269 8268->8264 8269->8238 8270 7ff62e5d39d8 ShellExecuteW 8269->8270 8270->8238 8272 7ff62e5d51b0 5 API calls 8271->8272 8273 7ff62e5d2ab4 8272->8273 8274 7ff62e5d57d0 5 API calls 8273->8274 8275 7ff62e5d2ad0 _Yarn 8273->8275 8274->8275 8276 7ff62e5d57d0 5 API calls 8275->8276 8277 7ff62e5d2b31 _Yarn 8275->8277 8276->8277 8277->8202 8323 7ff62e5d5630 8278->8323 8283 7ff62e5d4ae2 8287 7ff62e5d5350 5 API calls 8283->8287 8288 7ff62e5d4af3 _Yarn 8283->8288 8284 7ff62e5d4b60 8285 7ff62e5e2c7c Concurrency::cancel_current_task 2 API calls 8284->8285 8286 7ff62e5d4b65 8285->8286 8286->8207 8287->8288 8288->8207 8290 7ff62e5d5ca2 8289->8290 8505 7ff62e5d5fb0 8290->8505 8292 7ff62e5d5cb8 8294 7ff62e5d5d23 8292->8294 8298 7ff62e5d62f0 5 API calls 8292->8298 8293 7ff62e5d5ecc 8293->8239 8294->8293 8295 7ff62e5d2220 18 API calls 8294->8295 8296 7ff62e5d5f37 8295->8296 8297 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 8296->8297 8299 7ff62e5d5f48 8297->8299 8298->8292 8299->8239 8301 7ff62e5d28d3 wcsncmp 8300->8301 8303 7ff62e5d2919 8300->8303 8301->8303 8305 7ff62e5d28f1 8301->8305 8304 7ff62e5d2988 wcsncmp 8303->8304 8318 7ff62e5d2912 8303->8318 8306 7ff62e5d29a3 8304->8306 8304->8318 8312 7ff62e5d51b0 5 API calls 8305->8312 8305->8318 8308 7ff62e5d2a5e 8306->8308 8309 7ff62e5d29c9 8306->8309 8307 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8310 7ff62e5d2a49 8307->8310 8311 7ff62e5d57b0 3 API calls 8308->8311 8313 7ff62e5d51b0 5 API calls 8309->8313 8310->8239 8314 7ff62e5d2a63 8311->8314 8312->8318 8315 7ff62e5d29e1 8313->8315 8540 7ff62e5d4d90 8315->8540 8317 7ff62e5d29ee 8317->8318 8319 7ff62e5d2a27 _invalid_parameter_noinfo_noreturn 8317->8319 8318->8307 8319->8318 8321 7ff62e5d45f0 _invalid_parameter_noinfo_noreturn 8320->8321 8322 7ff62e5d3b8c 8321->8322 8322->8233 8324 7ff62e5e3718 std::_Facet_Register 4 API calls 8323->8324 8325 7ff62e5d56b0 8324->8325 8340 7ff62e5e2ecc 8325->8340 8329 7ff62e5d4a38 8335 7ff62e5d55a0 8329->8335 8330 7ff62e5d56ee 8330->8329 8366 7ff62e5d2220 8330->8366 8333 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 8334 7ff62e5d57aa 8333->8334 8336 7ff62e5e3718 std::_Facet_Register 4 API calls 8335->8336 8337 7ff62e5d55c1 8336->8337 8338 7ff62e5e2ecc 9 API calls 8337->8338 8339 7ff62e5d4ab0 8338->8339 8339->8283 8339->8284 8341 7ff62e5e2eee std::_Lockit::_Lockit 8340->8341 8351 7ff62e5e2f59 _Yarn 8341->8351 8376 7ff62e5e30c8 8341->8376 8346 7ff62e5d56ba 8352 7ff62e5d5b20 8346->8352 8348 7ff62e5e2f32 malloc 8348->8351 8349 7ff62e5e2f2d free 8349->8348 8385 7ff62e5e2a18 8351->8385 8353 7ff62e5d5b3b std::_Lockit::_Lockit 8352->8353 8356 7ff62e5d5b8a 8353->8356 8357 7ff62e5e2a18 std::_Lockit::~_Lockit _unlock_locales 8353->8357 8354 7ff62e5d5bcf 8355 7ff62e5e2a18 std::_Lockit::~_Lockit _unlock_locales 8354->8355 8358 7ff62e5d5c1a 8355->8358 8356->8354 8396 7ff62e5d1c10 8356->8396 8357->8356 8358->8330 8361 7ff62e5d5c2a 8431 7ff62e5d1a70 8361->8431 8362 7ff62e5d5be7 8428 7ff62e5e2e8c 8362->8428 8367 7ff62e5d2266 8366->8367 8367->8367 8368 7ff62e5d53c0 5 API calls 8367->8368 8369 7ff62e5d2279 8368->8369 8457 7ff62e5d15b0 8369->8457 8371 7ff62e5d2292 8372 7ff62e5d22ce 8371->8372 8374 7ff62e5d22c7 _invalid_parameter_noinfo_noreturn 8371->8374 8373 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8372->8373 8375 7ff62e5d22ed 8373->8375 8374->8372 8375->8333 8377 7ff62e5e3718 std::_Facet_Register 4 API calls 8376->8377 8378 7ff62e5e30da 8377->8378 8379 7ff62e5e2f06 8378->8379 8389 7ff62e5e2d2c 8378->8389 8381 7ff62e5e30f8 8379->8381 8382 7ff62e5e310a 8381->8382 8383 7ff62e5e2f11 8381->8383 8393 7ff62e5e3614 8382->8393 8383->8348 8383->8349 8383->8351 8386 7ff62e5e2a23 _unlock_locales 8385->8386 8387 7ff62e5e2a2c 8385->8387 8387->8346 8390 7ff62e5e2d73 8389->8390 8390->8390 8391 7ff62e5e2d7b malloc 8390->8391 8392 7ff62e5e2d90 _Yarn 8391->8392 8392->8379 8394 7ff62e5e3622 EncodePointer 8393->8394 8395 7ff62e5e3649 8393->8395 8394->8383 8397 7ff62e5d1d9f 8396->8397 8398 7ff62e5d1c39 8396->8398 8397->8361 8397->8362 8398->8397 8399 7ff62e5e3718 std::_Facet_Register 4 API calls 8398->8399 8400 7ff62e5d1c4d std::_Lockit::_Lockit 8399->8400 8401 7ff62e5d1dbd 8400->8401 8402 7ff62e5d1cbd 8400->8402 8443 7ff62e5e2d08 8401->8443 8437 7ff62e5e3040 8402->8437 8429 7ff62e5e3718 std::_Facet_Register 4 API calls 8428->8429 8430 7ff62e5e2e9f 8429->8430 8430->8354 8432 7ff62e5d1a7e Concurrency::cancel_current_task 8431->8432 8433 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 8432->8433 8434 7ff62e5d1a8f 8433->8434 8435 7ff62e5e4df4 Concurrency::cancel_current_task free 8434->8435 8436 7ff62e5d1ab9 8435->8436 8436->8330 8438 7ff62e5e3059 8437->8438 8448 7ff62e5e2db4 8438->8448 8440 7ff62e5e3073 8441 7ff62e5e3085 8440->8441 8442 7ff62e5e3078 setlocale 8440->8442 8442->8441 8454 7ff62e5e2c34 8443->8454 8446 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 8447 7ff62e5e2d2a 8446->8447 8449 7ff62e5e2dd1 8448->8449 8450 7ff62e5e2e08 _Yarn 8448->8450 8451 7ff62e5e2ddb 8449->8451 8452 7ff62e5e2dd6 free 8449->8452 8450->8440 8451->8450 8453 7ff62e5e2df4 malloc 8451->8453 8452->8451 8453->8450 8455 7ff62e5e4df4 Concurrency::cancel_current_task free 8454->8455 8456 7ff62e5e2c68 8455->8456 8456->8446 8458 7ff62e5d15fc 8457->8458 8459 7ff62e5d1667 8458->8459 8460 7ff62e5d1638 8458->8460 8464 7ff62e5d1605 _Yarn 8458->8464 8459->8464 8467 7ff62e5e3718 std::_Facet_Register 4 API calls 8459->8467 8462 7ff62e5d1645 8460->8462 8463 7ff62e5d1846 8460->8463 8461 7ff62e5d16b3 8497 7ff62e5d5520 8461->8497 8465 7ff62e5e3718 std::_Facet_Register 4 API calls 8462->8465 8466 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 8463->8466 8464->8461 8472 7ff62e5d1806 _invalid_parameter_noinfo_noreturn 8464->8472 8482 7ff62e5d5990 8464->8482 8465->8464 8468 7ff62e5d184b 8466->8468 8467->8464 8502 7ff62e5e4e84 8468->8502 8474 7ff62e5d180d 8472->8474 8473 7ff62e5d1872 8473->8371 8480 7ff62e5e36f0 __GSHandlerCheck_EH 8 API calls 8474->8480 8475 7ff62e5d172b 8476 7ff62e5d1765 8475->8476 8478 7ff62e5d175e _invalid_parameter_noinfo_noreturn 8475->8478 8477 7ff62e5e4df4 Concurrency::cancel_current_task free 8476->8477 8479 7ff62e5d17ca 8477->8479 8478->8476 8479->8472 8479->8474 8481 7ff62e5d1834 8480->8481 8481->8371 8483 7ff62e5d5b0b 8482->8483 8485 7ff62e5d59be 8482->8485 8484 7ff62e5d14b0 3 API calls 8483->8484 8488 7ff62e5d5b10 8484->8488 8486 7ff62e5d5a11 8485->8486 8487 7ff62e5d5a46 8485->8487 8490 7ff62e5d5a1e 8485->8490 8486->8488 8486->8490 8494 7ff62e5e3718 std::_Facet_Register 4 API calls 8487->8494 8495 7ff62e5d5a2f _Yarn 8487->8495 8491 7ff62e5d1410 Concurrency::cancel_current_task 3 API calls 8488->8491 8489 7ff62e5e3718 std::_Facet_Register 4 API calls 8489->8495 8490->8489 8492 7ff62e5d5b16 8491->8492 8493 7ff62e5d5ac4 _invalid_parameter_noinfo_noreturn 8496 7ff62e5d5ab7 _Yarn 8493->8496 8494->8495 8495->8493 8495->8496 8496->8461 8498 7ff62e5d5582 8497->8498 8500 7ff62e5d5543 _Yarn 8497->8500 8499 7ff62e5d5990 5 API calls 8498->8499 8501 7ff62e5d5595 8499->8501 8500->8475 8501->8475 8503 7ff62e5e4e93 free 8502->8503 8504 7ff62e5e4e9b 8502->8504 8503->8504 8504->8473 8506 7ff62e5d5ff1 8505->8506 8510 7ff62e5d5fcc 8505->8510 8507 7ff62e5d6002 8506->8507 8515 7ff62e5d6070 8506->8515 8507->8292 8508 7ff62e5d5feb 8508->8292 8510->8508 8511 7ff62e5d2220 18 API calls 8510->8511 8512 7ff62e5d604f 8511->8512 8513 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 8512->8513 8514 7ff62e5d6060 8513->8514 8516 7ff62e5d608e 8515->8516 8517 7ff62e5d60e6 8515->8517 8529 7ff62e5d61c0 8516->8529 8517->8507 8520 7ff62e5d60d3 8520->8517 8533 7ff62e5d6240 8520->8533 8522 7ff62e5d611c 8523 7ff62e5d2220 18 API calls 8522->8523 8524 7ff62e5d6154 8523->8524 8525 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 8524->8525 8526 7ff62e5d6165 8525->8526 8527 7ff62e5d618a 8526->8527 8528 7ff62e5d6240 18 API calls 8526->8528 8527->8507 8528->8527 8531 7ff62e5d61e9 8529->8531 8530 7ff62e5d609b 8530->8520 8530->8522 8531->8530 8532 7ff62e5d6070 18 API calls 8531->8532 8532->8530 8534 7ff62e5d6290 8533->8534 8535 7ff62e5d6257 8533->8535 8534->8517 8535->8534 8536 7ff62e5d2220 18 API calls 8535->8536 8537 7ff62e5d62ce 8536->8537 8538 7ff62e5e4edc Concurrency::cancel_current_task 2 API calls 8537->8538 8539 7ff62e5d62df 8538->8539 8541 7ff62e5d4da5 8540->8541 8542 7ff62e5d4dd8 8540->8542 8541->8542 8543 7ff62e5d4e1c _invalid_parameter_noinfo_noreturn 8541->8543 8542->8317 8544 7ff62e5d4e43 8543->8544 8545 7ff62e5d4e67 8543->8545 8544->8545 8546 7ff62e5d4e88 _invalid_parameter_noinfo_noreturn 8544->8546 8545->8317 8549 7ff62e5d45f0 8546->8549 8548 7ff62e5d4ea4 8548->8317 8550 7ff62e5d4609 8549->8550 8552 7ff62e5d4666 8549->8552 8551 7ff62e5d46fa _invalid_parameter_noinfo_noreturn 8550->8551 8550->8552 8552->8548 8553->7442 7157 7ff62e5e39f0 7158 7ff62e5e3a00 7157->7158 7170 7ff62e5e37dc 7158->7170 7161 7ff62e5e3aa5 7162 7ff62e5e3a24 _RTC_Initialize 7168 7ff62e5e3a87 7162->7168 7178 7ff62e5e43f0 InitializeSListHead 7162->7178 7164 7ff62e5e3a4e 7165 7ff62e5e3a72 _configthreadlocale 7164->7165 7166 7ff62e5e3a7e __scrt_initialize_crt 7165->7166 7167 7ff62e5e3a82 _initialize_wide_environment 7166->7167 7166->7168 7167->7168 7169 7ff62e5e3a95 7168->7169 7179 7ff62e5e4120 IsProcessorFeaturePresent 7168->7179 7171 7ff62e5e37ed 7170->7171 7175 7ff62e5e381f 7170->7175 7172 7ff62e5e385c 7171->7172 7176 7ff62e5e37f2 __scrt_release_startup_lock 7171->7176 7173 7ff62e5e4120 7 API calls 7172->7173 7174 7ff62e5e3866 7173->7174 7175->7162 7176->7175 7177 7ff62e5e380f _initialize_onexit_table 7176->7177 7177->7175 7180 7ff62e5e4146 7179->7180 7181 7ff62e5e4165 RtlCaptureContext RtlLookupFunctionEntry 7180->7181 7182 7ff62e5e418e RtlVirtualUnwind 7181->7182 7183 7ff62e5e41ca 7181->7183 7182->7183 7184 7ff62e5e41fc IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 7183->7184 7185 7ff62e5e424e 7184->7185 7185->7161
            APIs
              • Part of subcall function 00007FF62E5DDD10: GetModuleFileNameW.KERNEL32 ref: 00007FF62E5DDDE7
              • Part of subcall function 00007FF62E5DDD10: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5DDEDE
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E264A
              • Part of subcall function 00007FF62E5DF680: GetFileAttributesExW.KERNEL32 ref: 00007FF62E5DF6F5
              • Part of subcall function 00007FF62E5E17E0: MultiByteToWideChar.KERNEL32 ref: 00007FF62E5E1858
              • Part of subcall function 00007FF62E5E17E0: MultiByteToWideChar.KERNEL32 ref: 00007FF62E5E189A
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E2525
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E2579
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E25CF
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E1D30
              • Part of subcall function 00007FF62E5D6BB0: EnterCriticalSection.KERNEL32(?,?,0000000100000004,00000000,00000000,00000000,00000000,00000007,FFFFFFFF,00007FF62E5D6A1B), ref: 00007FF62E5D6BE2
              • Part of subcall function 00007FF62E5D6BB0: __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6C1B
              • Part of subcall function 00007FF62E5D6BB0: __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6CEB
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D0E
              • Part of subcall function 00007FF62E5D6BB0: fputws.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D1A
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D25
              • Part of subcall function 00007FF62E5D6BB0: fputwc.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D33
              • Part of subcall function 00007FF62E5D6BB0: OutputDebugStringW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D47
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D5B
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$__acrt_iob_func$ByteCharFileMultiWide__stdio_common_vswprintf$AttributesCriticalDebugEnterModuleNameOutputSectionStringfputwcfputws
            • String ID: %s$ - Installing .NET prerequisites might help resolve this problem.$A fatal error was encountered. This executable was not bound to load a managed DLL.$App path: [%s]$Bundle Header Offset: [%lx]$Detected Single-File app bundle$Dotnet path: [%s]$Failed to resolve full path of the current executable [%s]$Host path: [%s]$Invoking fx resolver [%s] hostfxr_main_bundle_startupinfo$Invoking fx resolver [%s] hostfxr_main_startupinfo$Invoking fx resolver [%s] v1$Probed for and did not resolve library symbol %S$The application to execute does not exist: '%s'.$The library %s was found, but loading it from %s failed$The required library %s does not contain the expected entry point.$The required library %s does not support relative app dll paths.$The required library %s does not support single-file apps.$hostfxr.dll$hostfxr_main$hostfxr_main_bundle_startupinfo$hostfxr_main_startupinfo$hostfxr_set_error_writer$https://go.microsoft.com/fwlink/?linkid=798306
            • API String ID: 3488066100-2178251435
            • Opcode ID: 3fe97d1f1a519df4fcab6a169498e731899a9131dcdc252ef1cb52c927d3cfa7
            • Instruction ID: 3701549960bdf4177f2cde302a91a5babb038493e482bf142260f2222e78b544
            • Opcode Fuzzy Hash: 3fe97d1f1a519df4fcab6a169498e731899a9131dcdc252ef1cb52c927d3cfa7
            • Instruction Fuzzy Hash: 3A729566A28F4285FF00CB24EC643AD2361FB64398F584139FA5DA7A99DF7DE485C301
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            APIs
            • EnterCriticalSection.KERNEL32(?,?,0000000100000004,00000000,00000000,00000000,00000000,00000007,FFFFFFFF,00007FF62E5D6A1B), ref: 00007FF62E5D6BE2
            • __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6C1B
            • __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6CEB
            • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D0E
            • fputws.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D1A
            • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D25
            • fputwc.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D33
            • OutputDebugStringW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D47
            • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D5B
            • __stdio_common_vfwprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D89
            • fputwc.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D97
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6DCE
            • LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6DE1
            • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D6DF7
              • Part of subcall function 00007FF62E5E3718: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FF62E5D1C4D), ref: 00007FF62E5E3732
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: __acrt_iob_func$CriticalSection__stdio_common_vswprintffputwc$Concurrency::cancel_current_taskDebugEnterLeaveOutputString__stdio_common_vfwprintf_invalid_parameter_noinfo_noreturnfputwsmalloc
            • String ID:
            • API String ID: 742152493-0
            • Opcode ID: 58c2e7b25a33e6ffedc99cb14a7720a5e971c58ca368530c9475b07ccaba4ca5
            • Instruction ID: a2257aebb4a7ebd762293866b879f07695a3df86df9e311cbd6b86708e4353f2
            • Opcode Fuzzy Hash: 58c2e7b25a33e6ffedc99cb14a7720a5e971c58ca368530c9475b07ccaba4ca5
            • Instruction Fuzzy Hash: 10518325A28B4181EE109B21FC6437963A1EF99BA4F044239FE6EA37D5DF7DE4458301
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: CriticalSection$fflush$EnterLeave__acrt_iob_func$EnvironmentErrorLastVariable__stdio_common_vfwprintf_invalid_parameter_noinfo_noreturnfputwc
            • String ID: --- Invoked %s [version: %s, commit hash: %s] main = {$6.0.26$Redirecting errors to custom writer.$apphost$dc45e96840243b203b13e61952230e225d2aac52
            • API String ID: 3223879508-1783827699
            • Opcode ID: 350a5edf093ae0ad086516d0697309f0a4ec986958250bd9a3aa45c930d59259
            • Instruction ID: 48d90b2f4f56a97945ae902002013fe91e6143145c8ae22bd9dc8df5786f2339
            • Opcode Fuzzy Hash: 350a5edf093ae0ad086516d0697309f0a4ec986958250bd9a3aa45c930d59259
            • Instruction Fuzzy Hash: 40312124A38F4281EE109B60EC741B92361BF68B45F48103DF94EE32A6DE7EE549C342
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 282 7ff62e5d2480-7ff62e5d2507 RegisterEventSourceW call 7ff62e5d57d0 285 7ff62e5d253d-7ff62e5d2556 call 7ff62e5d57d0 282->285 286 7ff62e5d2509-7ff62e5d253b call 7ff62e5e4fb0 282->286 290 7ff62e5d255b-7ff62e5d2582 call 7ff62e5d4c70 285->290 286->290 293 7ff62e5d2584-7ff62e5d2590 290->293 294 7ff62e5d25a0-7ff62e5d25b2 call 7ff62e5d57d0 290->294 295 7ff62e5d2592 293->295 296 7ff62e5d2595-7ff62e5d259e 293->296 298 7ff62e5d25b7-7ff62e5d25c9 294->298 295->296 296->298 299 7ff62e5d2601-7ff62e5d261a call 7ff62e5d57d0 298->299 300 7ff62e5d25cb-7ff62e5d25ff call 7ff62e5e4fb0 298->300 304 7ff62e5d261f-7ff62e5d263b call 7ff62e5d4c70 299->304 300->304 307 7ff62e5d263d-7ff62e5d2649 304->307 308 7ff62e5d2659-7ff62e5d266b call 7ff62e5d57d0 304->308 309 7ff62e5d264e-7ff62e5d2657 307->309 310 7ff62e5d264b 307->310 312 7ff62e5d2670-7ff62e5d2682 308->312 309->312 310->309 313 7ff62e5d2684-7ff62e5d26b8 call 7ff62e5e4fb0 312->313 314 7ff62e5d26ba-7ff62e5d26d8 call 7ff62e5d57d0 312->314 319 7ff62e5d26db-7ff62e5d270a 313->319 314->319 320 7ff62e5d273c-7ff62e5d2749 call 7ff62e5d57d0 319->320 321 7ff62e5d270c-7ff62e5d271b 319->321 328 7ff62e5d274c-7ff62e5d275d 320->328 322 7ff62e5d2720-7ff62e5d273a call 7ff62e5e4fb0 321->322 323 7ff62e5d271d 321->323 322->328 323->322 329 7ff62e5d275f-7ff62e5d276b 328->329 330 7ff62e5d277b-7ff62e5d278d call 7ff62e5d57d0 328->330 332 7ff62e5d2770-7ff62e5d2779 329->332 333 7ff62e5d276d 329->333 334 7ff62e5d2792-7ff62e5d27e9 ReportEventW DeregisterEventSource 330->334 332->334 333->332 335 7ff62e5d2824-7ff62e5d284a call 7ff62e5e36f0 334->335 336 7ff62e5d27eb-7ff62e5d2801 334->336 337 7ff62e5d2803-7ff62e5d2816 336->337 338 7ff62e5d281f call 7ff62e5e3710 336->338 337->338 340 7ff62e5d2818-7ff62e5d281e _invalid_parameter_noinfo_noreturn 337->340 338->335 340->338
            APIs
            • RegisterEventSourceW.ADVAPI32 ref: 00007FF62E5D24B7
              • Part of subcall function 00007FF62E5D57D0: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(00000000,?,?,?,00007FF62E5D23DC), ref: 00007FF62E5D5933
              • Part of subcall function 00007FF62E5D57D0: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D5981
            • ReportEventW.ADVAPI32 ref: 00007FF62E5D27D1
            • DeregisterEventSource.ADVAPI32 ref: 00007FF62E5D27DA
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D2818
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: Event$Source_invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_taskDeregisterRegisterReport
            • String ID: ($.NET Runtime$Application: $Description: A .NET application failed.$Message: $Path:
            • API String ID: 1590356926-970997692
            • Opcode ID: e69c02a80248be455c259719f3e539824fe67ed41d84da92768ef9c93390835b
            • Instruction ID: 5dc1490d72f567429b4ed30c1a17114f8d6bb817dabdf8a9e4554debbfe502f4
            • Opcode Fuzzy Hash: e69c02a80248be455c259719f3e539824fe67ed41d84da92768ef9c93390835b
            • Instruction Fuzzy Hash: 51B1CD6AB24B4584EF14CF61E8602AD2371FB68B98F44113AEE4DA7B68EF3DD144C341
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: __p___argc__p___wargv__scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_is_managed_app__scrt_release_startup_lock_cexit_exit_get_initial_wide_environment_register_thread_local_exe_atexit_callback
            • String ID:
            • API String ID: 3940706900-0
            • Opcode ID: 9baad04e32da97dfe58c31f91464f54df98b2aa5717a7082cef238bb28c49e17
            • Instruction ID: e127105166967266f43d9e2efbf9ba27956ccdaab50e621b3eb13c9455f28ba6
            • Opcode Fuzzy Hash: 9baad04e32da97dfe58c31f91464f54df98b2aa5717a7082cef238bb28c49e17
            • Instruction Fuzzy Hash: 58310A21A2CE4241EE14AB25AC363B92291AF65784F4C553CFA4EE72D7DE3EE4058242
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 394 7ff62e5d3c40-7ff62e5d3c7d 395 7ff62e5d3c83-7ff62e5d3cbd call 7ff62e5ddd10 394->395 396 7ff62e5d4057-7ff62e5d4083 call 7ff62e5e36f0 394->396 401 7ff62e5d3cc3-7ff62e5d3cca 395->401 402 7ff62e5d3f75-7ff62e5d3f91 call 7ff62e5d2480 395->402 404 7ff62e5d3cee-7ff62e5d3d19 401->404 405 7ff62e5d3ccc-7ff62e5d3ce9 401->405 406 7ff62e5d3f96-7ff62e5d3fa7 GetModuleHandleW 402->406 408 7ff62e5d3d2f-7ff62e5d3d38 404->408 409 7ff62e5d3d1b 404->409 407 7ff62e5d3f1e-7ff62e5d3f2a 405->407 412 7ff62e5d3fc0-7ff62e5d3fc8 406->412 413 7ff62e5d3fa9-7ff62e5d3fbf call 7ff62e5d2ba0 406->413 414 7ff62e5d3f65-7ff62e5d3f71 407->414 415 7ff62e5d3f2c-7ff62e5d3f42 407->415 410 7ff62e5d3e03-7ff62e5d3e15 408->410 411 7ff62e5d3d3e-7ff62e5d3d50 408->411 416 7ff62e5d3d20-7ff62e5d3d23 409->416 419 7ff62e5d408a-7ff62e5d408f call 7ff62e5d57b0 410->419 420 7ff62e5d3e1b-7ff62e5d3e3b 410->420 417 7ff62e5d3d52-7ff62e5d3d61 411->417 418 7ff62e5d3d66-7ff62e5d3d8f 411->418 422 7ff62e5d4003-7ff62e5d401c 412->422 423 7ff62e5d3fca-7ff62e5d3fe0 412->423 413->412 414->402 424 7ff62e5d3f44-7ff62e5d3f57 415->424 425 7ff62e5d3f60 call 7ff62e5e3710 415->425 416->411 426 7ff62e5d3d25-7ff62e5d3d2d 416->426 417->407 427 7ff62e5d4084-7ff62e5d4089 call 7ff62e5d1410 418->427 428 7ff62e5d3d95-7ff62e5d3d9f 418->428 443 7ff62e5d4090-7ff62e5d40c4 call 7ff62e5d14b0 419->443 429 7ff62e5d3e5f-7ff62e5d3e6c 420->429 430 7ff62e5d3e3d-7ff62e5d3e5a call 7ff62e5e4fb0 420->430 422->396 436 7ff62e5d401e-7ff62e5d4034 422->436 432 7ff62e5d3fe2-7ff62e5d3ff5 423->432 433 7ff62e5d3ffe call 7ff62e5e3710 423->433 424->425 435 7ff62e5d3f59-7ff62e5d3f5f _invalid_parameter_noinfo_noreturn 424->435 425->414 426->408 426->416 427->419 438 7ff62e5d3dd0-7ff62e5d3dd3 428->438 439 7ff62e5d3da1-7ff62e5d3da8 428->439 442 7ff62e5d3e72-7ff62e5d3e7c 429->442 429->443 460 7ff62e5d3f1a 430->460 432->433 444 7ff62e5d3ff7-7ff62e5d3ffd _invalid_parameter_noinfo_noreturn 432->444 433->422 435->425 447 7ff62e5d4052 call 7ff62e5e3710 436->447 448 7ff62e5d4036-7ff62e5d4049 436->448 455 7ff62e5d3dd5-7ff62e5d3dda call 7ff62e5e3718 438->455 456 7ff62e5d3ddc 438->456 439->427 450 7ff62e5d3dae-7ff62e5d3dbc call 7ff62e5e3718 439->450 453 7ff62e5d3e7e-7ff62e5d3e85 442->453 454 7ff62e5d3e87-7ff62e5d3ea7 442->454 470 7ff62e5d40ca-7ff62e5d40d4 443->470 471 7ff62e5d40c6-7ff62e5d40c8 443->471 444->433 447->396 448->447 458 7ff62e5d404b-7ff62e5d4051 _invalid_parameter_noinfo_noreturn 448->458 450->435 478 7ff62e5d3dc2-7ff62e5d3dce 450->478 461 7ff62e5d3eb9-7ff62e5d3ec0 453->461 454->427 462 7ff62e5d3ead-7ff62e5d3eb7 454->462 465 7ff62e5d3ddf-7ff62e5d3dfe call 7ff62e5e4fb0 455->465 456->465 458->447 460->407 461->427 468 7ff62e5d3ec6-7ff62e5d3ed1 call 7ff62e5e3718 461->468 462->461 467 7ff62e5d3ee5-7ff62e5d3ee8 462->467 465->460 476 7ff62e5d3ef4 467->476 477 7ff62e5d3eea-7ff62e5d3ef2 call 7ff62e5e3718 467->477 468->435 491 7ff62e5d3ed7-7ff62e5d3ee3 468->491 473 7ff62e5d40e0-7ff62e5d40f7 470->473 474 7ff62e5d40d6-7ff62e5d40da 470->474 471->473 482 7ff62e5d417d 473->482 483 7ff62e5d40fd-7ff62e5d4100 473->483 474->473 480 7ff62e5d40dc 474->480 484 7ff62e5d3ef7-7ff62e5d3f16 call 7ff62e5e4fb0 476->484 477->484 478->465 480->473 486 7ff62e5d4184-7ff62e5d41a1 482->486 488 7ff62e5d4102-7ff62e5d4106 483->488 489 7ff62e5d4118-7ff62e5d4125 483->489 484->460 492 7ff62e5d410d-7ff62e5d4111 488->492 493 7ff62e5d4108-7ff62e5d410b 488->493 495 7ff62e5d413b-7ff62e5d413f 489->495 496 7ff62e5d4127-7ff62e5d412a 489->496 491->484 492->489 497 7ff62e5d4113-7ff62e5d4116 492->497 493->482 493->492 499 7ff62e5d4173-7ff62e5d417b 495->499 500 7ff62e5d4141-7ff62e5d4144 495->500 496->495 498 7ff62e5d412c-7ff62e5d4139 496->498 497->482 497->489 498->495 499->486 500->499 501 7ff62e5d4146-7ff62e5d4170 500->501 501->499
            APIs
              • Part of subcall function 00007FF62E5DDD10: GetModuleFileNameW.KERNEL32 ref: 00007FF62E5DDDE7
              • Part of subcall function 00007FF62E5DDD10: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5DDEDE
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D3F59
            • GetModuleHandleW.KERNEL32 ref: 00007FF62E5D3F98
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D3FF7
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D404B
            • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D4084
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$Module$Concurrency::cancel_current_taskFileHandleName
            • String ID:
            • API String ID: 1091411171-0
            • Opcode ID: e55fe4e6014d1dff07f6d5449918019ceea8d0041f3cd64099c86efab912ce9a
            • Instruction ID: e6f322f3cfbe3212a3c67084d33ae6ddad073a7b7c43e858ba247dc1ae6cff00
            • Opcode Fuzzy Hash: e55fe4e6014d1dff07f6d5449918019ceea8d0041f3cd64099c86efab912ce9a
            • Instruction Fuzzy Hash: 75F1EF26B24B4685EF14CF64E8243AC23A5EB247A8F444639EE6D63BD8DF3ED444C301
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: Initialize_configthreadlocale_initialize_onexit_table_initialize_wide_environment
            • String ID:
            • API String ID: 2955177221-0
            • Opcode ID: 179c0bb19fa0e0eb09f19558a3c2f6784e9049ed7313d69cca476d26072ad358
            • Instruction ID: 4b2f8e96e26469a9137e16e01ffd6277a58e8f574c129976464ba93a410a0759
            • Opcode Fuzzy Hash: 179c0bb19fa0e0eb09f19558a3c2f6784e9049ed7313d69cca476d26072ad358
            • Instruction Fuzzy Hash: 45115814E28A8346FE1876B16CB62BD11824FB9350F4C143CF54DF62C3AE3EA8864263
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$wcsncmp$EnvironmentVariable$Concurrency::cancel_current_taskErrorExecuteLastMessageShell_wtoi
            • String ID: https://aka.ms/dotnet/app-launch-failed$&apphost_version=$&gui=true$($6.0.26$Bundle header version compatibility check failed.$DOTNET_DISABLE_GUI_ERRORS$Failed to read environment variable [%s], HRESULT: 0x%X$Showing error dialog for application: '%s' - error code: 0x%x - url: '%s' - dialog message: %s$Would you like to download it now?Learn about $You must install or update .NET to run this application.$framework resolution:$open$runtime installation:
            • API String ID: 2183938501-3084740795
            • Opcode ID: a3fe6fedfa3e2b978aed788e891d11d6aee9162becca560793c00ac4bcd4ca28
            • Instruction ID: 4de81d8e2298dcaba7b503d56cdb7e3b0c4e7e1ea1c82a364e85871746188e7d
            • Opcode Fuzzy Hash: a3fe6fedfa3e2b978aed788e891d11d6aee9162becca560793c00ac4bcd4ca28
            • Instruction Fuzzy Hash: D2929E66A24B8285EF20CF24DC643EC2361FB64798F40523AFA5D97AD9DF79E185C301
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 815 7ff62e5deff0-7ff62e5df02e 816 7ff62e5df033-7ff62e5df05c 815->816 817 7ff62e5df030 815->817 818 7ff62e5df0b2-7ff62e5df108 call 7ff62e5de3f0 RegOpenKeyExW 816->818 819 7ff62e5df05e-7ff62e5df07d GetEnvironmentVariableW 816->819 817->816 826 7ff62e5df19e-7ff62e5df1cd RegGetValueW 818->826 827 7ff62e5df10e-7ff62e5df11c call 7ff62e5d6a90 818->827 821 7ff62e5df083-7ff62e5df08e GetLastError 819->821 822 7ff62e5df121-7ff62e5df14d call 7ff62e5e39dc GetEnvironmentVariableW 819->822 821->818 825 7ff62e5df090-7ff62e5df092 821->825 822->821 835 7ff62e5df153-7ff62e5df15b 822->835 829 7ff62e5df094-7ff62e5df097 825->829 830 7ff62e5df09c-7ff62e5df0ad call 7ff62e5d6e10 825->830 832 7ff62e5df1d3-7ff62e5df1d8 826->832 833 7ff62e5df315-7ff62e5df327 call 7ff62e5d6a90 RegCloseKey 826->833 843 7ff62e5df32d 827->843 829->830 830->818 832->833 836 7ff62e5df1de-7ff62e5df1f3 832->836 833->843 835->835 839 7ff62e5df15d-7ff62e5df17b call 7ff62e5d51b0 call 7ff62e5e3710 835->839 840 7ff62e5df262 836->840 841 7ff62e5df1f5-7ff62e5df200 836->841 871 7ff62e5df17d-7ff62e5df192 call 7ff62e5d51b0 839->871 872 7ff62e5df197-7ff62e5df199 839->872 845 7ff62e5df266-7ff62e5df291 RegGetValueW 840->845 846 7ff62e5df202-7ff62e5df209 841->846 847 7ff62e5df22b-7ff62e5df22e 841->847 848 7ff62e5df32f-7ff62e5df337 843->848 850 7ff62e5df293-7ff62e5df2ad call 7ff62e5d6a90 RegCloseKey 845->850 851 7ff62e5df2b0-7ff62e5df2b8 845->851 852 7ff62e5df20f-7ff62e5df217 call 7ff62e5e3718 846->852 853 7ff62e5df3f1-7ff62e5df3f7 call 7ff62e5d1410 846->853 856 7ff62e5df230-7ff62e5df23b call 7ff62e5e3718 847->856 857 7ff62e5df23d 847->857 854 7ff62e5df372-7ff62e5df37e 848->854 855 7ff62e5df339-7ff62e5df34f 848->855 886 7ff62e5df2d4-7ff62e5df2d7 850->886 851->851 863 7ff62e5df2ba-7ff62e5df2d2 call 7ff62e5d51b0 RegCloseKey 851->863 887 7ff62e5df304-7ff62e5df30a _invalid_parameter_noinfo_noreturn 852->887 888 7ff62e5df21d-7ff62e5df229 852->888 867 7ff62e5df383-7ff62e5df38b 854->867 864 7ff62e5df351-7ff62e5df364 855->864 865 7ff62e5df36d call 7ff62e5e3710 855->865 859 7ff62e5df240-7ff62e5df260 call 7ff62e5e5700 856->859 857->859 859->845 863->886 864->865 878 7ff62e5df366-7ff62e5df36c _invalid_parameter_noinfo_noreturn 864->878 865->854 869 7ff62e5df38d-7ff62e5df3a3 867->869 870 7ff62e5df3c6-7ff62e5df3f0 call 7ff62e5e36f0 867->870 881 7ff62e5df3a5-7ff62e5df3b8 869->881 882 7ff62e5df3c1 call 7ff62e5e3710 869->882 871->872 872->867 878->865 881->882 891 7ff62e5df3ba-7ff62e5df3c0 _invalid_parameter_noinfo_noreturn 881->891 882->870 886->848 894 7ff62e5df2d9-7ff62e5df2ed 886->894 890 7ff62e5df30b-7ff62e5df313 call 7ff62e5e3710 887->890 888->859 890->848 891->882 894->890 896 7ff62e5df2ef-7ff62e5df302 894->896 896->887 896->890
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$CloseEnvironmentValueVariable$Concurrency::cancel_current_taskErrorLastOpenmalloc
            • String ID: Can't get the size of the SDK location registry value or it's empty, result: 0x%X$Can't get the value of the SDK location registry value, result: 0x%X$Can't open the SDK installed location registry key, result: 0x%X$Failed to read environment variable [%s], HRESULT: 0x%X$HKCU\$HKEY_CURRENT_USER\$HKLM\$InstallLocation$SOFTWARE\dotnet$\Setup\InstalledVersions\$_DOTNET_TEST_GLOBALLY_REGISTERED_PATH$_DOTNET_TEST_REGISTRY_PATH$x64
            • API String ID: 1906321200-3907257641
            • Opcode ID: a7b7202842ca20de65efdfe0564e3f21e84a96a5e03aa9aee9432afd4b7e57a8
            • Instruction ID: 32956823ac6d5de4133695ae18bcd6638b1ae14aea4706a4dd96d76301bf0eaa
            • Opcode Fuzzy Hash: a7b7202842ca20de65efdfe0564e3f21e84a96a5e03aa9aee9432afd4b7e57a8
            • Instruction Fuzzy Hash: DCB1C426F28A0285EF10CB62EC602BD23A1EB54798F444239EE5DA7BD9DF3ED145C341
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1102 7ff62e5d6750-7ff62e5d67a0 1103 7ff62e5d67a2-7ff62e5d67a4 1102->1103 1104 7ff62e5d67a9-7ff62e5d6808 EnterCriticalSection __acrt_iob_func GetEnvironmentVariableW 1102->1104 1105 7ff62e5d6a21-7ff62e5d6a25 1103->1105 1106 7ff62e5d6842-7ff62e5d686e call 7ff62e5e39dc GetEnvironmentVariableW 1104->1106 1107 7ff62e5d680a-7ff62e5d6815 GetLastError 1104->1107 1109 7ff62e5d6a60-7ff62e5d6a8c call 7ff62e5e36f0 1105->1109 1110 7ff62e5d6a27-7ff62e5d6a3d 1105->1110 1106->1107 1126 7ff62e5d6870 1106->1126 1111 7ff62e5d68d2-7ff62e5d68fa GetEnvironmentVariableW 1107->1111 1112 7ff62e5d681b-7ff62e5d681d 1107->1112 1114 7ff62e5d6a3f-7ff62e5d6a52 1110->1114 1115 7ff62e5d6a5b call 7ff62e5e3710 1110->1115 1119 7ff62e5d692a-7ff62e5d6935 GetLastError 1111->1119 1120 7ff62e5d68fc-7ff62e5d6928 call 7ff62e5e39dc GetEnvironmentVariableW 1111->1120 1116 7ff62e5d681f-7ff62e5d6822 1112->1116 1117 7ff62e5d6827-7ff62e5d683d call 7ff62e5d6e10 1112->1117 1114->1115 1127 7ff62e5d6a54-7ff62e5d6a5a _invalid_parameter_noinfo_noreturn 1114->1127 1115->1109 1116->1117 1117->1111 1124 7ff62e5d6937-7ff62e5d6939 1119->1124 1125 7ff62e5d6998-7ff62e5d69a7 1119->1125 1120->1119 1138 7ff62e5d6960-7ff62e5d6968 1120->1138 1131 7ff62e5d6943-7ff62e5d6959 call 7ff62e5d6e10 1124->1131 1132 7ff62e5d693b-7ff62e5d693e 1124->1132 1134 7ff62e5d69e2-7ff62e5d69ff LeaveCriticalSection 1125->1134 1135 7ff62e5d69a9-7ff62e5d69bf 1125->1135 1133 7ff62e5d6873-7ff62e5d687c 1126->1133 1127->1115 1131->1125 1132->1131 1133->1133 1142 7ff62e5d687e-7ff62e5d68b3 call 7ff62e5d51b0 call 7ff62e5e3710 _wfopen 1133->1142 1139 7ff62e5d6a01-7ff62e5d6a16 call 7ff62e5d6bb0 1134->1139 1140 7ff62e5d6a1b-7ff62e5d6a1d 1134->1140 1136 7ff62e5d69c1-7ff62e5d69d4 1135->1136 1137 7ff62e5d69dd call 7ff62e5e3710 1135->1137 1136->1137 1143 7ff62e5d69d6-7ff62e5d69dc _invalid_parameter_noinfo_noreturn 1136->1143 1137->1134 1138->1138 1148 7ff62e5d696a-7ff62e5d6995 call 7ff62e5d51b0 call 7ff62e5e3710 _wtoi 1138->1148 1139->1140 1140->1105 1155 7ff62e5d68b5-7ff62e5d68cd setvbuf 1142->1155 1156 7ff62e5d68cf 1142->1156 1143->1137 1148->1125 1155->1111 1156->1111
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: EnvironmentVariable$CriticalErrorLastSection_invalid_parameter_noinfo_noreturn$EnterLeave__acrt_iob_func
            • String ID: COREHOST_TRACEFILE$COREHOST_TRACE_VERBOSITY$Failed to read environment variable [%s], HRESULT: 0x%X$Unable to open COREHOST_TRACEFILE=%s for writing
            • API String ID: 3064537429-1641920025
            • Opcode ID: 88771679a748c143c17eb09de76398be2fb1bdf63250da61755db2bf8c3aaaac
            • Instruction ID: ee92d452e201e3ee8055f5bec34b6527fe36f8109a9cd4b689f7816053ce5dc6
            • Opcode Fuzzy Hash: 88771679a748c143c17eb09de76398be2fb1bdf63250da61755db2bf8c3aaaac
            • Instruction Fuzzy Hash: 2B918D25F24A0284FF00CB65EC642BD23A1BB65798F581139ED5EE36A5DF7EE4458302
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$_errnomallocwcstoul
            • String ID: ,$.$invalid stoul argument$stoul argument out of range
            • API String ID: 1031985940-164841169
            • Opcode ID: 7ef8e38316318c0ff259c727d84d1475dcce39112a0cffbc2f186418e9e429bb
            • Instruction ID: 9653d80019e22637dc2bd30fee833b4c636b22a808eaaba79e6181e548534938
            • Opcode Fuzzy Hash: 7ef8e38316318c0ff259c727d84d1475dcce39112a0cffbc2f186418e9e429bb
            • Instruction Fuzzy Hash: 8F62E736B28B4281EE109B14D96437E6361EB557E4F504239FA6DA3BE9DF7EE080C301
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: AddressLibraryLoadProc
            • String ID: RtlGetVersion$ntdll.dll$win$win7$win8$win81
            • API String ID: 2574300362-238241336
            • Opcode ID: 1c347d411ba30a8b4a3fe03b3f85ecdf011b61d078eaca487c314b95127a5920
            • Instruction ID: 6ac84d6bce7894f591c7424ce7c182ff8ac1155ee2b64a09c0e3be9c9da88b35
            • Opcode Fuzzy Hash: 1c347d411ba30a8b4a3fe03b3f85ecdf011b61d078eaca487c314b95127a5920
            • Instruction Fuzzy Hash: 0151D675A2CB8286EE10DF25E8603AA7361FBA4790F844139F64D93B94DF7EE400C742
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$Find$Concurrency::cancel_current_taskFile$CloseFirstNextmalloc
            • String ID:
            • API String ID: 2417148112-0
            • Opcode ID: 4de97b4dcda384b496e58fa6990f5ce76aeaeb5985e9e0e4492b687040ff640b
            • Instruction ID: b8ffd63439f4d85cf1204edfd96209b664ab7ec5511de14f6441926581ac3d87
            • Opcode Fuzzy Hash: 4de97b4dcda384b496e58fa6990f5ce76aeaeb5985e9e0e4492b687040ff640b
            • Instruction Fuzzy Hash: 85F10922B28A8280EE108B25EC643B96391EF657E4F544239FE5DA36E4DF7DD581C311
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
            • String ID:
            • API String ID: 3140674995-0
            • Opcode ID: 98f326408a43c49323143dc62a80fd424c8c6b2329f9185471fd778eda5b9060
            • Instruction ID: 8c72534989c6e855d8136a032e88f5f17b8f4c8bbb130bb74778a2b8b00560af
            • Opcode Fuzzy Hash: 98f326408a43c49323143dc62a80fd424c8c6b2329f9185471fd778eda5b9060
            • Instruction Fuzzy Hash: D9315A72618E818AEF648F60E8603ED2361FBA8744F48443AEA4E97A95DF39C548C701
            Uniqueness

            Uniqueness Score: -1.00%

            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 4c15ffedba99abd84fb0b0588364e65f2de8faf221ed5ba893e7e25a6afcfbef
            • Instruction ID: 35daf539607f74af101b5744eda4509307c87ca9aa65e8144f3c183bdeb61f69
            • Opcode Fuzzy Hash: 4c15ffedba99abd84fb0b0588364e65f2de8faf221ed5ba893e7e25a6afcfbef
            • Instruction Fuzzy Hash: 01A00126928C12D0EE4A8B20AC600242220AB65340B885439F00DA50A19F3EA8818206
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 898 7ff62e5e1120-7ff62e5e1166 899 7ff62e5e11bc 898->899 900 7ff62e5e1168-7ff62e5e11b4 call 7ff62e5d51b0 call 7ff62e5d6fc0 898->900 902 7ff62e5e11bf-7ff62e5e11c3 899->902 900->899 917 7ff62e5e11b6-7ff62e5e11ba 900->917 904 7ff62e5e11c5-7ff62e5e11ce 902->904 905 7ff62e5e120a-7ff62e5e120d 902->905 904->905 909 7ff62e5e11d0-7ff62e5e11e7 904->909 906 7ff62e5e126f-7ff62e5e129e 905->906 907 7ff62e5e120f-7ff62e5e1214 905->907 915 7ff62e5e12a2 call 7ff62e5d7e70 906->915 910 7ff62e5e1216 907->910 911 7ff62e5e1219-7ff62e5e122b call 7ff62e5d6b20 907->911 913 7ff62e5e1205 call 7ff62e5e3710 909->913 914 7ff62e5e11e9-7ff62e5e11fc 909->914 910->911 926 7ff62e5e122d-7ff62e5e1232 911->926 927 7ff62e5e1246-7ff62e5e126e call 7ff62e5e36f0 911->927 913->905 914->913 918 7ff62e5e11fe-7ff62e5e1204 _invalid_parameter_noinfo_noreturn 914->918 920 7ff62e5e12a7-7ff62e5e12a9 915->920 917->902 918->913 922 7ff62e5e12d4 920->922 923 7ff62e5e12ab-7ff62e5e12b3 920->923 928 7ff62e5e12d9 call 7ff62e5deff0 922->928 924 7ff62e5e12b5 923->924 925 7ff62e5e12b8-7ff62e5e12d2 call 7ff62e5d6b20 923->925 924->925 939 7ff62e5e1345-7ff62e5e1397 call 7ff62e5d83e0 call 7ff62e5d71b0 * 2 925->939 930 7ff62e5e1234 926->930 931 7ff62e5e1237-7ff62e5e1241 call 7ff62e5d51b0 926->931 932 7ff62e5e12de-7ff62e5e12e0 928->932 930->931 931->927 935 7ff62e5e1303-7ff62e5e1327 call 7ff62e5d6b20 932->935 936 7ff62e5e12e2 932->936 935->939 945 7ff62e5e1329-7ff62e5e1340 call 7ff62e5d51b0 935->945 940 7ff62e5e12e7 call 7ff62e5de160 936->940 960 7ff62e5e13b0-7ff62e5e13d9 939->960 961 7ff62e5e1399-7ff62e5e13ab 939->961 943 7ff62e5e12ec-7ff62e5e12ee 940->943 943->935 947 7ff62e5e12f0-7ff62e5e12fe call 7ff62e5d6bb0 943->947 945->939 954 7ff62e5e1701-7ff62e5e1709 947->954 955 7ff62e5e1744-7ff62e5e175d 954->955 956 7ff62e5e170b-7ff62e5e1721 954->956 962 7ff62e5e175f-7ff62e5e1776 955->962 963 7ff62e5e1799 955->963 958 7ff62e5e1723-7ff62e5e1736 956->958 959 7ff62e5e173f call 7ff62e5e3710 956->959 958->959 964 7ff62e5e1738-7ff62e5e173e _invalid_parameter_noinfo_noreturn 958->964 959->955 967 7ff62e5e13df-7ff62e5e13e9 960->967 968 7ff62e5e17a1-7ff62e5e17bd call 7ff62e5d1410 960->968 966 7ff62e5e1446-7ff62e5e1463 call 7ff62e5df680 961->966 969 7ff62e5e1794 call 7ff62e5e3710 962->969 970 7ff62e5e1778-7ff62e5e178b 962->970 963->968 964->959 986 7ff62e5e1465-7ff62e5e147c 966->986 987 7ff62e5e149f-7ff62e5e14a2 966->987 973 7ff62e5e13eb-7ff62e5e13f2 967->973 974 7ff62e5e141a-7ff62e5e141d 967->974 983 7ff62e5e17d3-7ff62e5e17d8 968->983 984 7ff62e5e17bf-7ff62e5e17c5 968->984 969->963 970->969 975 7ff62e5e178d-7ff62e5e1793 _invalid_parameter_noinfo_noreturn 970->975 973->968 981 7ff62e5e13f8 973->981 977 7ff62e5e141f 974->977 978 7ff62e5e1426 974->978 975->969 982 7ff62e5e141f call 7ff62e5e3718 977->982 985 7ff62e5e1429-7ff62e5e1441 call 7ff62e5e4fb0 978->985 988 7ff62e5e13fb call 7ff62e5e3718 981->988 991 7ff62e5e1424 982->991 984->983 992 7ff62e5e17c7-7ff62e5e17cf 984->992 985->966 994 7ff62e5e147e-7ff62e5e1491 986->994 995 7ff62e5e149a call 7ff62e5e3710 986->995 989 7ff62e5e167d-7ff62e5e16aa call 7ff62e5e0820 987->989 990 7ff62e5e14a8-7ff62e5e14ad 987->990 996 7ff62e5e1400-7ff62e5e1406 988->996 1010 7ff62e5e16ad-7ff62e5e16b5 989->1010 1000 7ff62e5e14af 990->1000 1001 7ff62e5e14ca-7ff62e5e1505 call 7ff62e5dec50 990->1001 991->985 992->983 994->995 998 7ff62e5e1493-7ff62e5e1499 _invalid_parameter_noinfo_noreturn 994->998 995->987 996->998 999 7ff62e5e140c-7ff62e5e1418 996->999 998->995 999->985 1004 7ff62e5e14b4 call 7ff62e5deff0 1000->1004 1012 7ff62e5e150a-7ff62e5e155e call 7ff62e5d6a90 call 7ff62e5ddd10 call 7ff62e5d80a0 1001->1012 1013 7ff62e5e1507 1001->1013 1008 7ff62e5e14b9-7ff62e5e14be 1004->1008 1008->1001 1011 7ff62e5e14c0 1008->1011 1014 7ff62e5e16f0-7ff62e5e16fc 1010->1014 1015 7ff62e5e16b7-7ff62e5e16cd 1010->1015 1016 7ff62e5e14c5 call 7ff62e5de160 1011->1016 1027 7ff62e5e1563-7ff62e5e15a1 call 7ff62e5d6bb0 1012->1027 1028 7ff62e5e1560 1012->1028 1013->1012 1014->954 1018 7ff62e5e16cf-7ff62e5e16e2 1015->1018 1019 7ff62e5e16eb call 7ff62e5e3710 1015->1019 1016->1001 1018->1019 1020 7ff62e5e16e4-7ff62e5e16ea _invalid_parameter_noinfo_noreturn 1018->1020 1019->1014 1020->1019 1031 7ff62e5e15a3-7ff62e5e15b9 1027->1031 1032 7ff62e5e15dd-7ff62e5e15e6 1027->1032 1028->1027 1033 7ff62e5e15bb-7ff62e5e15ce 1031->1033 1034 7ff62e5e15d7-7ff62e5e15dc call 7ff62e5e3710 1031->1034 1035 7ff62e5e1622-7ff62e5e163e 1032->1035 1036 7ff62e5e15e8-7ff62e5e15ff 1032->1036 1033->1034 1039 7ff62e5e15d0-7ff62e5e15d6 _invalid_parameter_noinfo_noreturn 1033->1039 1034->1032 1037 7ff62e5e1640-7ff62e5e1656 1035->1037 1038 7ff62e5e1679-7ff62e5e167b 1035->1038 1041 7ff62e5e1601-7ff62e5e1614 1036->1041 1042 7ff62e5e161d call 7ff62e5e3710 1036->1042 1045 7ff62e5e1674 call 7ff62e5e3710 1037->1045 1046 7ff62e5e1658-7ff62e5e166b 1037->1046 1038->1010 1039->1034 1041->1042 1043 7ff62e5e1616-7ff62e5e161c _invalid_parameter_noinfo_noreturn 1041->1043 1042->1035 1043->1042 1045->1038 1046->1045 1048 7ff62e5e166d-7ff62e5e1673 _invalid_parameter_noinfo_noreturn 1046->1048 1048->1045
            APIs
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E11FE
              • Part of subcall function 00007FF62E5D6FC0: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D7113
              • Part of subcall function 00007FF62E5D6FC0: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D7184
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E1493
              • Part of subcall function 00007FF62E5DEFF0: GetEnvironmentVariableW.KERNEL32 ref: 00007FF62E5DF073
              • Part of subcall function 00007FF62E5DEFF0: GetLastError.KERNEL32 ref: 00007FF62E5DF083
              • Part of subcall function 00007FF62E5DEFF0: RegOpenKeyExW.ADVAPI32 ref: 00007FF62E5DF100
              • Part of subcall function 00007FF62E5DEFF0: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5DF366
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E15D0
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E1616
              • Part of subcall function 00007FF62E5DE160: GetEnvironmentVariableW.KERNEL32 ref: 00007FF62E5DE1BD
              • Part of subcall function 00007FF62E5DE160: GetLastError.KERNEL32 ref: 00007FF62E5DE1C9
              • Part of subcall function 00007FF62E5DE160: GetCurrentProcess.KERNEL32 ref: 00007FF62E5DE1FD
              • Part of subcall function 00007FF62E5DE160: IsWow64Process.KERNEL32 ref: 00007FF62E5DE20B
              • Part of subcall function 00007FF62E5DE160: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5DE3B6
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E166D
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E16E4
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E1738
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E178D
              • Part of subcall function 00007FF62E5D6BB0: EnterCriticalSection.KERNEL32(?,?,0000000100000004,00000000,00000000,00000000,00000000,00000007,FFFFFFFF,00007FF62E5D6A1B), ref: 00007FF62E5D6BE2
              • Part of subcall function 00007FF62E5D6BB0: __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6C1B
              • Part of subcall function 00007FF62E5D6BB0: __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6CEB
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D0E
              • Part of subcall function 00007FF62E5D6BB0: fputws.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D1A
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D25
              • Part of subcall function 00007FF62E5D6BB0: fputwc.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D33
              • Part of subcall function 00007FF62E5D6BB0: OutputDebugStringW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D47
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D5B
            • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5E17A1
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$__acrt_iob_func$EnvironmentErrorLastProcessVariable__stdio_common_vswprintf$Concurrency::cancel_current_taskCriticalCurrentDebugEnterOpenOutputSectionStringWow64fputwcfputws
            • String ID: 6.0.26$A fatal error occurred, the default install location cannot be obtained.$A fatal error occurred, the folder [%s] does not contain any version-numbered child folders$A fatal error occurred, the required library %s could not be found in [%s]$Considering fxr version=[%s]...$Detected latest fxr version=[%s]...$Reading fx resolver directory=[%s]$Resolved fxr [%s]...$The required library %s could not be found. Searched with root path [%s], environment variable [%s], default install location [%s]$Using environment variable %s=[%s] as runtime location.$Using global installation location [%s] as runtime location.$You must install .NET to run this application.App: %sArchitecture: %sApp host version: %s.NET location: Not foundLearn abou$fxr$host$hostfxr.dll$x64
            • API String ID: 2036119248-3898005199
            • Opcode ID: fd15f0103e346f8351e56e5115226750c286214b22c1d53048c53747ed92fd86
            • Instruction ID: c1cc981fd867785bbceb62b26ddb4f3fe2bb01ecf00f7c7af280e99134d3ba07
            • Opcode Fuzzy Hash: fd15f0103e346f8351e56e5115226750c286214b22c1d53048c53747ed92fd86
            • Instruction Fuzzy Hash: 1812D662F28F4280EF04DB64E9643AD2361EB543A8F440239FA5DA7AE9DF7DD485C311
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1050 7ff62e5de160-7ff62e5de1a6 1051 7ff62e5de1f8-7ff62e5de213 GetCurrentProcess IsWow64Process 1050->1051 1052 7ff62e5de1a8-7ff62e5de1c7 GetEnvironmentVariableW 1050->1052 1055 7ff62e5de223 1051->1055 1056 7ff62e5de215-7ff62e5de221 1051->1056 1053 7ff62e5de241-7ff62e5de274 call 7ff62e5e39dc GetEnvironmentVariableW 1052->1053 1054 7ff62e5de1c9-7ff62e5de1d4 GetLastError 1052->1054 1053->1054 1064 7ff62e5de27a 1053->1064 1054->1051 1057 7ff62e5de1d6-7ff62e5de1d8 1054->1057 1058 7ff62e5de22a-7ff62e5de234 call 7ff62e5d7ac0 1055->1058 1056->1055 1056->1058 1060 7ff62e5de1e2-7ff62e5de1f3 call 7ff62e5d6e10 1057->1060 1061 7ff62e5de1da-7ff62e5de1dd 1057->1061 1068 7ff62e5de2d3-7ff62e5de2fa call 7ff62e5d71b0 LoadLibraryExW 1058->1068 1069 7ff62e5de23a-7ff62e5de23c 1058->1069 1060->1051 1061->1060 1067 7ff62e5de280-7ff62e5de288 1064->1067 1067->1067 1070 7ff62e5de28a-7ff62e5de2aa call 7ff62e5d51b0 call 7ff62e5e3710 1067->1070 1079 7ff62e5de312-7ff62e5de328 GetProcAddress 1068->1079 1080 7ff62e5de2fc-7ff62e5de310 GetLastError call 7ff62e5d6b20 1068->1080 1072 7ff62e5de37d-7ff62e5de386 1069->1072 1084 7ff62e5de37b 1070->1084 1093 7ff62e5de2b0-7ff62e5de2ce call 7ff62e5d51b0 1070->1093 1075 7ff62e5de3c2-7ff62e5de3e6 call 7ff62e5e36f0 1072->1075 1076 7ff62e5de388-7ff62e5de39f 1072->1076 1081 7ff62e5de3a1-7ff62e5de3b4 1076->1081 1082 7ff62e5de3bd call 7ff62e5e3710 1076->1082 1079->1084 1085 7ff62e5de32a-7ff62e5de348 GetCurrentProcess 1079->1085 1080->1084 1081->1082 1089 7ff62e5de3b6-7ff62e5de3bc _invalid_parameter_noinfo_noreturn 1081->1089 1082->1075 1084->1072 1094 7ff62e5de360-7ff62e5de36a 1085->1094 1095 7ff62e5de34a-7ff62e5de35e GetLastError call 7ff62e5d6b20 1085->1095 1089->1082 1093->1084 1094->1084 1098 7ff62e5de36c-7ff62e5de376 call 7ff62e5d71b0 1094->1098 1095->1084 1098->1084
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: ErrorLastProcess$CurrentEnvironmentVariable_invalid_parameter_noinfo_noreturn$AddressLibraryLoadProcWow64
            • String ID: Call to IsWow64Process2 failed: %u$Could not load 'kernel32.dll': %u$Failed to read environment variable [%s], HRESULT: 0x%X$IsWow64Process2$ProgramFiles$ProgramFiles(x86)$_DOTNET_TEST_DEFAULT_INSTALL_PATH$dotnet$kernel32.dll$x64
            • API String ID: 2279001996-1892901996
            • Opcode ID: 185217d042381de5a9c557a0287e59a933322b4926c4a7fff026822e0fdb4640
            • Instruction ID: 4fccde6f7778936e3eff67417d5c475f4661577ac129064051567f389e4a9f70
            • Opcode Fuzzy Hash: 185217d042381de5a9c557a0287e59a933322b4926c4a7fff026822e0fdb4640
            • Instruction Fuzzy Hash: 8E61A025F2CA0281FE109B21EC642B933A1FFA5790F480139F95DE2695DF3EE945C342
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: EnvironmentVariable_invalid_parameter_noinfo_noreturn$ErrorLast_gmtime64_s_time64_wtoiwcsftime
            • String ID: %c GMT$COREHOST_TRACE$Failed to read environment variable [%s], HRESULT: 0x%X$Tracing enabled @ %s
            • API String ID: 29591814-1875902258
            • Opcode ID: b9b73a2a91235428ad1dbece82736edbb4fd0da49cd5566e20efd095bbedb76e
            • Instruction ID: 80a14d836f2b7509f8a9fc874c77c7b442f4e44f1172a86c7e1c743d5ce03338
            • Opcode Fuzzy Hash: b9b73a2a91235428ad1dbece82736edbb4fd0da49cd5566e20efd095bbedb76e
            • Instruction Fuzzy Hash: 6161F872A28B4681EF108B24EC6036D23A1FBA4794F540239F65DE36E4DF7EE485C701
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1479 7ff62e5d1c10-7ff62e5d1c33 1480 7ff62e5d1da0-7ff62e5d1dbc 1479->1480 1481 7ff62e5d1c39-7ff62e5d1c3d 1479->1481 1481->1480 1482 7ff62e5d1c43 1481->1482 1483 7ff62e5d1c48 call 7ff62e5e3718 1482->1483 1484 7ff62e5d1c4d-7ff62e5d1c5b 1483->1484 1485 7ff62e5d1c6c 1484->1485 1486 7ff62e5d1c5d-7ff62e5d1c64 1484->1486 1487 7ff62e5d1c73-7ff62e5d1cb7 call 7ff62e5e29a0 1485->1487 1486->1487 1488 7ff62e5d1c66-7ff62e5d1c6a 1486->1488 1491 7ff62e5d1dbd-7ff62e5d1df1 call 7ff62e5e2d08 call 7ff62e5e32cc 1487->1491 1492 7ff62e5d1cbd-7ff62e5d1d2b call 7ff62e5e3040 call 7ff62e5e33a0 call 7ff62e5e3460 call 7ff62e5e30ac 1487->1492 1488->1487 1505 7ff62e5d1d33-7ff62e5d1d3e 1492->1505 1506 7ff62e5d1d2d free 1492->1506 1507 7ff62e5d1d40 free 1505->1507 1508 7ff62e5d1d46-7ff62e5d1d51 1505->1508 1506->1505 1507->1508 1509 7ff62e5d1d53 free 1508->1509 1510 7ff62e5d1d59-7ff62e5d1d64 1508->1510 1509->1510 1511 7ff62e5d1d6c-7ff62e5d1d77 1510->1511 1512 7ff62e5d1d66 free 1510->1512 1513 7ff62e5d1d7f-7ff62e5d1d8a 1511->1513 1514 7ff62e5d1d79 free 1511->1514 1512->1511 1515 7ff62e5d1d92-7ff62e5d1d9f call 7ff62e5e2a18 1513->1515 1516 7ff62e5d1d8c free 1513->1516 1514->1513 1515->1480 1516->1515
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: free$std::_$Lockit$GetctypeGetwctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_malloc
            • String ID: bad locale name
            • API String ID: 3869375685-1405518554
            • Opcode ID: ee6288f85be6d1be3f4980db941b8ce6f7c73a40d33900b2f2e388a4fe95c86c
            • Instruction ID: bfa39c916eb6b095ea58b6abfb1c0c5fa448c763b4f5567152d2bc470ef4041c
            • Opcode Fuzzy Hash: ee6288f85be6d1be3f4980db941b8ce6f7c73a40d33900b2f2e388a4fe95c86c
            • Instruction Fuzzy Hash: 8B517B26F19B418AEF15DBB0D9602AC33B4AF68744B080139EE4DB3A65CF39A466C351
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1519 7ff62e5dd6e0-7ff62e5dd766 localeconv call 7ff62e5e3460 1522 7ff62e5dd76c-7ff62e5dd77c call 7ff62e5e3460 1519->1522 1523 7ff62e5dd768 1519->1523 1526 7ff62e5dd780-7ff62e5dd788 1522->1526 1523->1522 1526->1526 1527 7ff62e5dd78a-7ff62e5dd7a2 calloc 1526->1527 1528 7ff62e5dd9e2-7ff62e5dd9e7 call 7ff62e5e2c7c 1527->1528 1529 7ff62e5dd7a8-7ff62e5dd7ab 1527->1529 1536 7ff62e5dd9e8-7ff62e5dd9fc call 7ff62e5e2c7c 1528->1536 1531 7ff62e5dd7bb-7ff62e5dd7d8 1529->1531 1532 7ff62e5dd7ad-7ff62e5dd7b6 call 7ff62e5e4fb0 1529->1532 1535 7ff62e5dd7e0-7ff62e5dd7fe call 7ff62e5e27c0 1531->1535 1532->1531 1541 7ff62e5dd800-7ff62e5dd80b 1535->1541 1542 7ff62e5dd80d-7ff62e5dd824 calloc 1535->1542 1544 7ff62e5dda22-7ff62e5dda27 1536->1544 1545 7ff62e5dd9fe-7ff62e5dda1b free * 3 1536->1545 1541->1535 1541->1542 1542->1536 1543 7ff62e5dd82a-7ff62e5dd836 1542->1543 1546 7ff62e5dd873-7ff62e5dd88d 1543->1546 1547 7ff62e5dd838 1543->1547 1545->1544 1549 7ff62e5dd890-7ff62e5dd8ae call 7ff62e5e27c0 1546->1549 1548 7ff62e5dd840-7ff62e5dd860 call 7ff62e5e27c0 1547->1548 1554 7ff62e5dd862-7ff62e5dd86f 1548->1554 1555 7ff62e5dd871 1548->1555 1556 7ff62e5dd8b0-7ff62e5dd8bb 1549->1556 1557 7ff62e5dd8bd-7ff62e5dd8d4 calloc 1549->1557 1554->1548 1554->1555 1555->1546 1556->1549 1556->1557 1558 7ff62e5dd8da-7ff62e5dd8e6 1557->1558 1559 7ff62e5dd9dc-7ff62e5dd9e1 call 7ff62e5e2c7c 1557->1559 1560 7ff62e5dd921-7ff62e5dd92d 1558->1560 1561 7ff62e5dd8e8 1558->1561 1559->1528 1565 7ff62e5dd92f-7ff62e5dd995 call 7ff62e5e27c0 * 2 1560->1565 1566 7ff62e5dd997-7ff62e5dd9aa 1560->1566 1563 7ff62e5dd8f0-7ff62e5dd910 call 7ff62e5e27c0 1561->1563 1563->1560 1573 7ff62e5dd912-7ff62e5dd91f 1563->1573 1569 7ff62e5dd9af-7ff62e5dd9db call 7ff62e5e36f0 1565->1569 1566->1569 1573->1560 1573->1563
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: Concurrency::cancel_current_taskcalloc$free$___lc_codepage_func___lc_locale_name_func__pctype_funclocaleconv
            • String ID: false$true
            • API String ID: 2692559698-2658103896
            • Opcode ID: 3917893eaca84c61b31c9444f81e8c2d23554261cef87bda6cd7c48a81861222
            • Instruction ID: cc1bf5f2c6069d27e23cd4e4bf66b1c3c1f6701b07b02423a4b5624e8d815046
            • Opcode Fuzzy Hash: 3917893eaca84c61b31c9444f81e8c2d23554261cef87bda6cd7c48a81861222
            • Instruction Fuzzy Hash: 8DA1C126B29B4685EB10CF70D8102AD33B5FB59B98F050239EE4CA7B59EF3AD516C341
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1577 7ff62e5da900-7ff62e5da940 1578 7ff62e5da952-7ff62e5da95b 1577->1578 1579 7ff62e5da942-7ff62e5da94f 1577->1579 1580 7ff62e5da961-7ff62e5da969 1578->1580 1581 7ff62e5da95d-7ff62e5da95f 1578->1581 1579->1578 1583 7ff62e5da96b-7ff62e5da96e 1580->1583 1584 7ff62e5da986 1580->1584 1582 7ff62e5da988-7ff62e5da98e 1581->1582 1587 7ff62e5da994-7ff62e5da9da call 7ff62e5e29a0 1582->1587 1588 7ff62e5dab57 1582->1588 1583->1584 1586 7ff62e5da970-7ff62e5da984 call 7ff62e5d6070 1583->1586 1584->1582 1586->1582 1605 7ff62e5daa1f-7ff62e5daa23 1587->1605 1606 7ff62e5da9dc-7ff62e5da9f2 call 7ff62e5e29a0 1587->1606 1590 7ff62e5dab5c-7ff62e5dab7d 1588->1590 1592 7ff62e5dab7f-7ff62e5dab86 call 7ff62e5e31a4 1590->1592 1593 7ff62e5dabcc-7ff62e5dabcf 1590->1593 1603 7ff62e5dab91-7ff62e5daba0 1592->1603 1604 7ff62e5dab88-7ff62e5dab90 call 7ff62e5d6240 1592->1604 1597 7ff62e5dabd1-7ff62e5dabd8 1593->1597 1598 7ff62e5dabda-7ff62e5dabeb 1593->1598 1601 7ff62e5dabef-7ff62e5dacbc call 7ff62e5d1590 call 7ff62e5d2220 call 7ff62e5e4edc call 7ff62e5d89c0 call 7ff62e5dbd00 call 7ff62e5e36f0 1597->1601 1598->1601 1611 7ff62e5daba2-7ff62e5dabaf 1603->1611 1612 7ff62e5dabb0-7ff62e5dabc5 1603->1612 1604->1603 1608 7ff62e5daa25-7ff62e5daa30 1605->1608 1609 7ff62e5daa34 1605->1609 1625 7ff62e5da9f4-7ff62e5daa04 1606->1625 1626 7ff62e5daa0b-7ff62e5daa18 call 7ff62e5e2a18 1606->1626 1615 7ff62e5daa32 1608->1615 1616 7ff62e5daaa5-7ff62e5daac6 call 7ff62e5e2a18 1608->1616 1617 7ff62e5daa37-7ff62e5daa3c 1609->1617 1611->1612 1615->1617 1643 7ff62e5daadc-7ff62e5dab43 1616->1643 1644 7ff62e5daac8-7ff62e5daad3 1616->1644 1622 7ff62e5daa3e-7ff62e5daa47 call 7ff62e5e2ec4 1617->1622 1623 7ff62e5daa51-7ff62e5daa54 1617->1623 1631 7ff62e5daa56-7ff62e5daa59 1622->1631 1640 7ff62e5daa49-7ff62e5daa4d 1622->1640 1623->1616 1623->1631 1625->1626 1626->1605 1635 7ff62e5daa60-7ff62e5daa73 call 7ff62e5dd560 1631->1635 1636 7ff62e5daa5b-7ff62e5daa5e 1631->1636 1645 7ff62e5dabc6-7ff62e5dabcb call 7ff62e5d1a70 1635->1645 1646 7ff62e5daa79-7ff62e5daa9e call 7ff62e5e2e8c 1635->1646 1636->1616 1640->1623 1643->1588 1643->1590 1644->1643 1645->1593 1646->1616
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
            • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
            • API String ID: 459529453-1866435925
            • Opcode ID: 1ed02d35e11ea6a30be12da75785a1c50de9abd0665852f5b43d4e1d766091c8
            • Instruction ID: 2b4c22c078feb77225a6667fda423890e548ab9e6f30f1b8bf5197d826615809
            • Opcode Fuzzy Hash: 1ed02d35e11ea6a30be12da75785a1c50de9abd0665852f5b43d4e1d766091c8
            • Instruction Fuzzy Hash: D8B17126618B8581EF10CB15E9643BAA360FFA4B94F04413AFE4DA37A5DF3ED445C742
            Uniqueness

            Uniqueness Score: -1.00%

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1657 7ff62e5dd3c0-7ff62e5dd3ea 1658 7ff62e5dd3f0-7ff62e5dd3f3 1657->1658 1659 7ff62e5dd529-7ff62e5dd545 1657->1659 1658->1659 1660 7ff62e5dd3f9 1658->1660 1661 7ff62e5dd3fd call 7ff62e5e3718 1660->1661 1662 7ff62e5dd402-7ff62e5dd410 1661->1662 1663 7ff62e5dd412-7ff62e5dd419 1662->1663 1664 7ff62e5dd421 1662->1664 1665 7ff62e5dd41b-7ff62e5dd41f 1663->1665 1666 7ff62e5dd428-7ff62e5dd469 call 7ff62e5e29a0 1663->1666 1664->1666 1665->1666 1669 7ff62e5dd46f-7ff62e5dd498 call 7ff62e5e3040 1666->1669 1670 7ff62e5dd546-7ff62e5dd552 call 7ff62e5e2d08 1666->1670 1675 7ff62e5dd49b call 7ff62e5dd6e0 1669->1675 1676 7ff62e5dd4a0-7ff62e5dd4b4 call 7ff62e5e30ac 1675->1676 1679 7ff62e5dd4bc-7ff62e5dd4c7 1676->1679 1680 7ff62e5dd4b6 free 1676->1680 1681 7ff62e5dd4cf-7ff62e5dd4da 1679->1681 1682 7ff62e5dd4c9 free 1679->1682 1680->1679 1683 7ff62e5dd4e2-7ff62e5dd4ed 1681->1683 1684 7ff62e5dd4dc free 1681->1684 1682->1681 1685 7ff62e5dd4f5-7ff62e5dd500 1683->1685 1686 7ff62e5dd4ef free 1683->1686 1684->1683 1687 7ff62e5dd502 free 1685->1687 1688 7ff62e5dd508-7ff62e5dd513 1685->1688 1686->1685 1687->1688 1689 7ff62e5dd515 free 1688->1689 1690 7ff62e5dd51b-7ff62e5dd528 call 7ff62e5e2a18 1688->1690 1689->1690 1690->1659
            APIs
              • Part of subcall function 00007FF62E5E3718: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FF62E5D1C4D), ref: 00007FF62E5E3732
            • std::_Lockit::_Lockit.LIBCPMT ref: 00007FF62E5DD42E
            • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 00007FF62E5DD476
            • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF62E5DD4B6
            • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF62E5DD4C9
            • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF62E5DD4DC
            • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF62E5DD4EF
            • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF62E5DD502
            • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF62E5DD515
            • std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF62E5DD523
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: free$std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_malloc
            • String ID: bad locale name
            • API String ID: 2125654041-1405518554
            • Opcode ID: 27aaee594dc21d4a569ffc6f82f316202a40387fcd697ca08dce96372995476d
            • Instruction ID: 42f06a0e3721d01dba2a7fdc0d629bcc7b8ecf08614b4eb7acb023c63efef5c0
            • Opcode Fuzzy Hash: 27aaee594dc21d4a569ffc6f82f316202a40387fcd697ca08dce96372995476d
            • Instruction Fuzzy Hash: 88416A36A5AB418AEF11CF70D8A02AC33A4EF65708F080538EE0DB2A59CF3AD515D356
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: free$std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_malloc
            • String ID: bad locale name
            • API String ID: 2125654041-1405518554
            • Opcode ID: ec59430a67cc044530dfa984ce1c8ec2e9156a052a1223e2b090c3e470db73a3
            • Instruction ID: ef5298fa670d8501b9ef3cae34853b09486df4bfd9bb5337c8e4ef63345c3070
            • Opcode Fuzzy Hash: ec59430a67cc044530dfa984ce1c8ec2e9156a052a1223e2b090c3e470db73a3
            • Instruction Fuzzy Hash: 38414926A5AB4189EF10DF70D8A02AC33A4EF65748F080538EE4DB2A65CF3AD525D356
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: EnvironmentVariable_invalid_parameter_noinfo_noreturn$ErrorLast
            • String ID: DOTNET_RUNTIME_ID$Failed to read environment variable [%s], HRESULT: 0x%X$win10$x64
            • API String ID: 1055180287-4222452407
            • Opcode ID: b4dd305fcbae1f409cc1e5e7405e1e890a99bb3a8150e5303c1d22e027a86964
            • Instruction ID: 53076acaed28c0445855f0999fdf3dea6960d6879cb3e55598b35de3e81c745f
            • Opcode Fuzzy Hash: b4dd305fcbae1f409cc1e5e7405e1e890a99bb3a8150e5303c1d22e027a86964
            • Instruction Fuzzy Hash: A091BF66F24B4184FF00CB75E8603AD2371AB647A8F545239FE5DA3A99DF39E181C301
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • MultiByteToWideChar.KERNEL32 ref: 00007FF62E5E1858
            • MultiByteToWideChar.KERNEL32 ref: 00007FF62E5E189A
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E19D8
              • Part of subcall function 00007FF62E5D6BB0: EnterCriticalSection.KERNEL32(?,?,0000000100000004,00000000,00000000,00000000,00000000,00000007,FFFFFFFF,00007FF62E5D6A1B), ref: 00007FF62E5D6BE2
              • Part of subcall function 00007FF62E5D6BB0: __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6C1B
              • Part of subcall function 00007FF62E5D6BB0: __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6CEB
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D0E
              • Part of subcall function 00007FF62E5D6BB0: fputws.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D1A
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D25
              • Part of subcall function 00007FF62E5D6BB0: fputwc.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D33
              • Part of subcall function 00007FF62E5D6BB0: OutputDebugStringW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D47
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D5B
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: __acrt_iob_func$ByteCharMultiWide__stdio_common_vswprintf$CriticalDebugEnterOutputSectionString_invalid_parameter_noinfo_noreturnfputwcfputws
            • String ID: 74e592c2fa383d4a3960714caef0c4f2$The managed DLL bound to this executable could not be retrieved from the executable image.$The managed DLL bound to this executable is: '%s'$This executable is not bound to a managed DLL to execute. The binding value is: '%s'$WinUI.dll$c3ab8ff13720e8ad9047dd39466b3c89
            • API String ID: 1778511166-3694144917
            • Opcode ID: 7ed54c74e417ad20565162e4993666ac240e9b321e91315c463d338e00064cdd
            • Instruction ID: 009cfc7ce1df788711108565361ecc865b11aed92f0ba4830e59aead12f2f979
            • Opcode Fuzzy Hash: 7ed54c74e417ad20565162e4993666ac240e9b321e91315c463d338e00064cdd
            • Instruction Fuzzy Hash: A151D221B28E8185EF149F25ED602B96391FF64BD0F485539FA9DA3B99CF3ED4418302
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$ErrorHandleLastLibraryLoadModule
            • String ID: Failed to load the dll from [%s], HRESULT: 0x%X$Failed to pin library [%s] in [%s]$Loaded library from %s$pal::load_library
            • API String ID: 2518456378-4234151505
            • Opcode ID: 44a55972f72e8af0b1df553a19f44d7be126c3ce0afd211a4839dd5edd71754d
            • Instruction ID: d3634af3a7b67c3aab738247dcf4b261d1938ebedec293d98b754040ab514771
            • Opcode Fuzzy Hash: 44a55972f72e8af0b1df553a19f44d7be126c3ce0afd211a4839dd5edd71754d
            • Instruction Fuzzy Hash: FC51A366F24A4288FF00DBA5DC642FC27B1AF65798F944139EE0DA2699DF3DD485C302
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: terminate$Is_bad_exception_allowedabortstd::bad_alloc::bad_alloc
            • String ID: csm$csm$csm
            • API String ID: 695522112-393685449
            • Opcode ID: 837d083d201cbc3135c20fa32617bf00e06923f4267a5697540ee33bd5b85c85
            • Instruction ID: 1130d3499c0a44706092c9c73ccb50fce955c224c3290e36fd3f8ee2c3dce7d5
            • Opcode Fuzzy Hash: 837d083d201cbc3135c20fa32617bf00e06923f4267a5697540ee33bd5b85c85
            • Instruction Fuzzy Hash: D1E1C872928B818AEF109F25D8602AD37E1FB64788F190139EB4DA7796CF79E441C701
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: Process$CurrentWow64_invalid_parameter_noinfo_noreturntoupper
            • String ID: DOTNET_ROOT$DOTNET_ROOT(x86)$DOTNET_ROOT_$x64
            • API String ID: 1386953757-2049366658
            • Opcode ID: 0ff3c2f889b2d1f5aacf6e1c9933f2f9b731244532a6ff88bf6ad3c6d4344934
            • Instruction ID: b4c6b86a487b4ff14dc5a69acfc200a52333d8a2b76b7870d06203e58bfb4eb4
            • Opcode Fuzzy Hash: 0ff3c2f889b2d1f5aacf6e1c9933f2f9b731244532a6ff88bf6ad3c6d4344934
            • Instruction Fuzzy Hash: E251F766728A8281EE108B11EC642BE7361FB94BD4F445039FA4EA7BA4CF7DE191C701
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: AttributesFileFullNamePath_invalid_parameter_noinfo_noreturn
            • String ID: Error resolving full path [%s]
            • API String ID: 2208424437-1390578158
            • Opcode ID: 20d65c18bfe167a0d608a7a4ad3ffa716a6aa52231606fd0e64a7edd228aea07
            • Instruction ID: 816589c9bc4aff786b8e1f06e6d5e2c647797ad6c83103560a96e7b80db695ba
            • Opcode Fuzzy Hash: 20d65c18bfe167a0d608a7a4ad3ffa716a6aa52231606fd0e64a7edd228aea07
            • Instruction Fuzzy Hash: BEC10726B38A8281EE10CB16EC642BD6361FFA1B94F541139FA4DA7A98DF3ED444C351
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • LoadLibraryExW.KERNEL32(?,?,?,00007FF62E5E7FBE,?,?,?,00007FF62E5E7C3C,?,?,?,?,00007FF62E5E5971), ref: 00007FF62E5E7D91
            • GetLastError.KERNEL32(?,?,?,00007FF62E5E7FBE,?,?,?,00007FF62E5E7C3C,?,?,?,?,00007FF62E5E5971), ref: 00007FF62E5E7D9F
            • wcsncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FF62E5E7FBE,?,?,?,00007FF62E5E7C3C,?,?,?,?,00007FF62E5E5971), ref: 00007FF62E5E7DB8
            • LoadLibraryExW.KERNEL32(?,?,?,00007FF62E5E7FBE,?,?,?,00007FF62E5E7C3C,?,?,?,?,00007FF62E5E5971), ref: 00007FF62E5E7DC9
            • FreeLibrary.KERNEL32(?,?,?,00007FF62E5E7FBE,?,?,?,00007FF62E5E7C3C,?,?,?,?,00007FF62E5E5971), ref: 00007FF62E5E7E0F
            • GetProcAddress.KERNEL32(?,?,?,00007FF62E5E7FBE,?,?,?,00007FF62E5E7C3C,?,?,?,?,00007FF62E5E5971), ref: 00007FF62E5E7E1B
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: Library$Load$AddressErrorFreeLastProcwcsncmp
            • String ID: api-ms-
            • API String ID: 916704608-2084034818
            • Opcode ID: edc5afeb0e9154ea8fd17a2d4ffbc2fcd00ce1b2753e376130add8ac6e37622c
            • Instruction ID: 2eca50d72c3d8d2399545be44f9d64c446930dde7116a12a1d7b6c3a9b64db56
            • Opcode Fuzzy Hash: edc5afeb0e9154ea8fd17a2d4ffbc2fcd00ce1b2753e376130add8ac6e37622c
            • Instruction Fuzzy Hash: B231C521A3AE4291EE21DB229C206756395FF24B64F5D053CFE1DAB391DF3DE4848342
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D8335
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn
            • String ID: &arch=$&rid=$https://aka.ms/dotnet-core-applaunch?$missing_runtime=true$x64
            • API String ID: 3668304517-1194784717
            • Opcode ID: 9a00aeff54e0026a918295eec5e5a41f703b08e553a679b81d35de23c14eb78b
            • Instruction ID: f9247e48be08c63ef76a2473b432ca98038b0fcd835a6c8cb03c4f0813b4977e
            • Opcode Fuzzy Hash: 9a00aeff54e0026a918295eec5e5a41f703b08e553a679b81d35de23c14eb78b
            • Instruction Fuzzy Hash: A681CD6AA28B4181EF04CF25E92436D2322FB55FC4F94113AEA5DA3798DF3EE115C342
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • GetEnvironmentVariableW.KERNEL32 ref: 00007FF62E5D7B1D
            • GetLastError.KERNEL32 ref: 00007FF62E5D7B2A
            • GetEnvironmentVariableW.KERNEL32 ref: 00007FF62E5D7B85
              • Part of subcall function 00007FF62E5D6A90: EnterCriticalSection.KERNEL32 ref: 00007FF62E5D6AC2
              • Part of subcall function 00007FF62E5D6A90: __stdio_common_vfwprintf.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF62E5D6AEC
              • Part of subcall function 00007FF62E5D6A90: fputwc.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF62E5D6AFA
              • Part of subcall function 00007FF62E5D6A90: LeaveCriticalSection.KERNEL32 ref: 00007FF62E5D6B07
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D7C49
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: CriticalEnvironmentSectionVariable$EnterErrorLastLeave__stdio_common_vfwprintf_invalid_parameter_noinfo_noreturnfputwc
            • String ID: Did not find [%s] directory [%s]$Failed to read environment variable [%s], HRESULT: 0x%X
            • API String ID: 2627214341-4112875940
            • Opcode ID: 4d719651c97b153f0903a8f940c09f2524a1f95568e493827c104dbccfed473d
            • Instruction ID: 519d485235856ade0bdb68e2581dc904351365a6734ac683611eb4fbf56b746a
            • Opcode Fuzzy Hash: 4d719651c97b153f0903a8f940c09f2524a1f95568e493827c104dbccfed473d
            • Instruction Fuzzy Hash: 2C41F626628A8185EF109B25EC6427A6361FBA97D0F440239FE9ED37E5DF3ED440C701
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D8CFF
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D8D67
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D8DA6
            • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D8DE9
            • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D8DEF
              • Part of subcall function 00007FF62E5E3718: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FF62E5D1C4D), ref: 00007FF62E5E3732
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$malloc
            • String ID:
            • API String ID: 2122263803-0
            • Opcode ID: a5c4a0fc3434579eda36cf7026211656f4616b042b1062987e4aaccf45fcf020
            • Instruction ID: 20f738f8f1a4c73b9312d10fde4415e04000dab5e91bbf3fd05c955f9ac216c8
            • Opcode Fuzzy Hash: a5c4a0fc3434579eda36cf7026211656f4616b042b1062987e4aaccf45fcf020
            • Instruction Fuzzy Hash: 5181EE66A29B4185EE10DB15E82476933A5FB24BA0F590739EABD53BD4DF3EE080C301
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D9016
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D907E
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D90BD
            • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D9100
            • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D9106
              • Part of subcall function 00007FF62E5E3718: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FF62E5D1C4D), ref: 00007FF62E5E3732
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$malloc
            • String ID:
            • API String ID: 2122263803-0
            • Opcode ID: 2fcf3f1e5a61e990528957049766d6061e05b4cb5307b079f334507ac4678a3d
            • Instruction ID: 19ab0f8d1b20b73f46fb1ac6b2808a4b73aaeb652d8b6e3e48a79d14a8785458
            • Opcode Fuzzy Hash: 2fcf3f1e5a61e990528957049766d6061e05b4cb5307b079f334507ac4678a3d
            • Instruction Fuzzy Hash: 3581A376A28B4281EE109B25E81426973A5FB55BB0F500739FABD63BD9DF7ED480C301
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
            • String ID:
            • API String ID: 2081738530-0
            • Opcode ID: 850ea38bf2c17fbf03df8ec111c7b3874e4e60588dc40c4f730379ad143cf9f9
            • Instruction ID: f8166ceb42556fb3d48905160ab0f15601b6d1e456fd2be0e8bf85bb8a8030c5
            • Opcode Fuzzy Hash: 850ea38bf2c17fbf03df8ec111c7b3874e4e60588dc40c4f730379ad143cf9f9
            • Instruction Fuzzy Hash: 9231D325A2DA42C1FE149B25EC201786360FFA4B94F480139FA4EA37E5CF3EE8418302
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
            • String ID:
            • API String ID: 2081738530-0
            • Opcode ID: ab8ab814ba3511984cf5ed3c351e9091b53e5478ee9693207cdca9b44a573017
            • Instruction ID: dfe94140d610fcd0dadcc9c5b8344e2e84a822b629053222bd37fe312b53dc9e
            • Opcode Fuzzy Hash: ab8ab814ba3511984cf5ed3c351e9091b53e5478ee9693207cdca9b44a573017
            • Instruction Fuzzy Hash: 9C31B825A28B4281EF159B15EC201F96760FFA5B94F584139FA4DA37D9DF3EE841C302
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: fflush$__acrt_iob_func$CriticalEnterSection
            • String ID:
            • API String ID: 3544201161-0
            • Opcode ID: 2731d0a9e04ccc719c57056ea5c75d87e175fb7864308c06b590a7371e3cb08a
            • Instruction ID: 585886ea9f224e195fed548841af3186ee159e3137402bcbaec4bf0b6d82752a
            • Opcode Fuzzy Hash: 2731d0a9e04ccc719c57056ea5c75d87e175fb7864308c06b590a7371e3cb08a
            • Instruction Fuzzy Hash: 75E05024D29F42C1EF149B65FC791342321AF69B56F48003DF94EA2662DE3E648D9712
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: abort$CallEncodePointerTranslator
            • String ID: MOC$RCC
            • API String ID: 2889003569-2084237596
            • Opcode ID: 20d7d184b0056a24742401391fcd3fff5d75678a03bc000d322554d621dbccaf
            • Instruction ID: b19329a5b2310ba8630c483236399bdd7310ff46b94f90b62bbd78474d8c3803
            • Opcode Fuzzy Hash: 20d7d184b0056a24742401391fcd3fff5d75678a03bc000d322554d621dbccaf
            • Instruction Fuzzy Hash: FF91B073A18B818AEB108B65E8502AD7BE0FB18788F18413AEF8DA7755DF39D195C701
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: Lockitstd::_$Lockit::_Lockit::~_Setgloballocalefreemallocstd::locale::_
            • String ID:
            • API String ID: 2400387105-0
            • Opcode ID: 592eadc93bcfca70ad94dbef6ec65dcf479535f9c9af674e3813221da5b35de5
            • Instruction ID: 77cb9be380a9a69ccd3cf4ba4e55ff234638cb06b3c61ab105d69b4a063488ce
            • Opcode Fuzzy Hash: 592eadc93bcfca70ad94dbef6ec65dcf479535f9c9af674e3813221da5b35de5
            • Instruction Fuzzy Hash: 7C217E25A28F4684EF189B22DC6127827A0EF69F84F5D4039EA4DA3769CF3DE481C301
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: free$setlocale
            • String ID:
            • API String ID: 294139027-0
            • Opcode ID: 2200f7a366044af2d41774760eacd117e585667a85d04f6b9eb66cfca57ad71f
            • Instruction ID: bd7b8d5eb899a1c13725e26f07d84467858bcecfa79f5152ad0726d1a15c2e6f
            • Opcode Fuzzy Hash: 2200f7a366044af2d41774760eacd117e585667a85d04f6b9eb66cfca57ad71f
            • Instruction Fuzzy Hash: 3411F179A16B4184FF548F61EDA013C63A4EF78F54B180139EA4EA3665DE3ED890C292
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: __except_validate_context_recordabort
            • String ID: csm$csm
            • API String ID: 746414643-3733052814
            • Opcode ID: 8d2ec9922b7b23e57f2c68368143aadfdf182c5b97ee631e391647a8024cbedb
            • Instruction ID: 899d21cb89189c73f38640aec83fb657d8c8cadcf911e2c974981369d59aeb4c
            • Opcode Fuzzy Hash: 8d2ec9922b7b23e57f2c68368143aadfdf182c5b97ee631e391647a8024cbedb
            • Instruction Fuzzy Hash: BB71D172918A8186DF648F21D9606797BE1FB14BC4F488139FB8CA7A8ACF7DD451C702
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
              • Part of subcall function 00007FF62E5E5C00: abort.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,00007FF62E5E4C0A), ref: 00007FF62E5E5C13
            • __except_validate_context_record.LIBVCRUNTIME ref: 00007FF62E5E718A
            • _CreateFrameInfo.LIBVCRUNTIME ref: 00007FF62E5E71B6
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: CreateFrameInfo__except_validate_context_recordabort
            • String ID: csm
            • API String ID: 2466640111-1018135373
            • Opcode ID: 6256cfcd7fe2c0f316825f703e49b5cf51986b157c45fc6cb264a57f17627ef3
            • Instruction ID: 87909c500ed3b5f69002d885fb4b984bfb672ec48121363deef4270c8fd9cd70
            • Opcode Fuzzy Hash: 6256cfcd7fe2c0f316825f703e49b5cf51986b157c45fc6cb264a57f17627ef3
            • Instruction Fuzzy Hash: 5B517233628B4286DA20EF16E85126E77A4F798B90F581139FB8DA7B55CF3DD450CB02
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _errnowcstoul
            • String ID: invalid stoul argument$stoul argument out of range
            • API String ID: 4037081904-1365241121
            • Opcode ID: 4c3c19e3ebd639f358a1cd85e994aaa7d926f5baf9736b011a4fe081f52624fe
            • Instruction ID: a2025feeb41ca4193376952ad425a5689592758dd249355049976eca99614a20
            • Opcode Fuzzy Hash: 4c3c19e3ebd639f358a1cd85e994aaa7d926f5baf9736b011a4fe081f52624fe
            • Instruction Fuzzy Hash: 26110625A28A0181EF548B31E8902A82360EF69764F4C0535F72D97AD5CF3ED881C702
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
              • Part of subcall function 00007FF62E5D6BB0: EnterCriticalSection.KERNEL32(?,?,0000000100000004,00000000,00000000,00000000,00000000,00000007,FFFFFFFF,00007FF62E5D6A1B), ref: 00007FF62E5D6BE2
              • Part of subcall function 00007FF62E5D6BB0: __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6C1B
              • Part of subcall function 00007FF62E5D6BB0: __stdio_common_vswprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6CEB
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D0E
              • Part of subcall function 00007FF62E5D6BB0: fputws.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D1A
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D25
              • Part of subcall function 00007FF62E5D6BB0: fputwc.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D33
              • Part of subcall function 00007FF62E5D6BB0: OutputDebugStringW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D47
              • Part of subcall function 00007FF62E5D6BB0: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D5B
              • Part of subcall function 00007FF62E5D6BB0: __stdio_common_vfwprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D89
              • Part of subcall function 00007FF62E5D6BB0: fputwc.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6D97
              • Part of subcall function 00007FF62E5D6BB0: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6DCE
              • Part of subcall function 00007FF62E5D6BB0: LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF62E5D6DE1
              • Part of subcall function 00007FF62E5D6BB0: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D6DF7
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E1AC4
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: __acrt_iob_func$CriticalSection__stdio_common_vswprintf_invalid_parameter_noinfo_noreturnfputwc$Concurrency::cancel_current_taskDebugEnterLeaveOutputString__stdio_common_vfwprintffputws
            • String ID: - %s&apphost_version=%s$ _ To run this application, you need to install a newer version of .NET Core.$6.0.26
            • API String ID: 2481621342-2173233827
            • Opcode ID: eef8a8882754751be4453aa21360eea06e2765eb80e56675baead4a7a8354280
            • Instruction ID: 789a5f24a892634170aad7dbef7ba03fd94f566674f34da92ca99dd384426416
            • Opcode Fuzzy Hash: eef8a8882754751be4453aa21360eea06e2765eb80e56675baead4a7a8354280
            • Instruction Fuzzy Hash: 8711E961A38E8281FD10EB24EC7517D2361FFA5394F844239F59DA26E9DF3EE5008701
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: terminate
            • String ID: MOC$RCC$csm
            • API String ID: 1821763600-2671469338
            • Opcode ID: 27b3dcaf4902910b04bd84fc37f66beb2ee0c18d4cc4257ad07ad9c558b915ec
            • Instruction ID: ee10e7618e8a25b9c424c5768864e61cbb97c391934bff58d0728302c9917e57
            • Opcode Fuzzy Hash: 27b3dcaf4902910b04bd84fc37f66beb2ee0c18d4cc4257ad07ad9c558b915ec
            • Instruction Fuzzy Hash: A9F0AF36928A4681EB645F519A6217C3764EF5C744F4D5079F70CA7292CF3DE490CA03
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D175E
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D1806
            • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D1846
            • __std_exception_destroy.LIBVCRUNTIME ref: 00007FF62E5D186D
              • Part of subcall function 00007FF62E5E3718: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FF62E5D1C4D), ref: 00007FF62E5E3732
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task__std_exception_destroymalloc
            • String ID:
            • API String ID: 2647511316-0
            • Opcode ID: 683cb786968fecde9701aba5b8263c40390043bffc0bf2035cb7af8afbb4040c
            • Instruction ID: d8346df7aac9e0252c7a897528de455ad4ff63801361196a9985fd4ca05082a9
            • Opcode Fuzzy Hash: 683cb786968fecde9701aba5b8263c40390043bffc0bf2035cb7af8afbb4040c
            • Instruction Fuzzy Hash: E181B322F24B4589FF10CBA4D9143EC3372AB687A8F544639EE5C63B96EF399095C341
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E8FC6
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E9036
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E90A6
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5E9116
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn
            • String ID:
            • API String ID: 3668304517-0
            • Opcode ID: 0d662af9008669fd0ec613a5e6eb2e43aa9fb312ac22bff1e5e07aebafdb1987
            • Instruction ID: b54accc9c175e8020b4dea0b01d7632fe68beaca62416d412d5024b3dd9ada4b
            • Opcode Fuzzy Hash: 0d662af9008669fd0ec613a5e6eb2e43aa9fb312ac22bff1e5e07aebafdb1987
            • Instruction Fuzzy Hash: BE417670E39A8680EE18D725ECA83382362BF51B85F84043DE50DEB565EF7FA5848302
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,00007FF62E5D784C), ref: 00007FF62E5D6E42
            • __stdio_common_vfwprintf.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,00007FF62E5D784C), ref: 00007FF62E5D6E6C
            • fputwc.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,?,?,?,00007FF62E5D784C), ref: 00007FF62E5D6E7A
            • LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,00007FF62E5D784C), ref: 00007FF62E5D6E87
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: CriticalSection$EnterLeave__stdio_common_vfwprintffputwc
            • String ID:
            • API String ID: 4070124032-0
            • Opcode ID: d7db584e16a6be461f25d04910dd0c79693fc68d95b54cb3a6b668042161430c
            • Instruction ID: 0ac5f7d3b0913c9a0d0baf4f3ef8d17a1f0faa247fb6d288703e37b3b9aef92b
            • Opcode Fuzzy Hash: d7db584e16a6be461f25d04910dd0c79693fc68d95b54cb3a6b668042161430c
            • Instruction Fuzzy Hash: 5F011E31A18B82C2DF109B10FC6406AB7A5FBA9785F444139FA8D93B29CF3DD459C701
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: CriticalSection$EnterLeave__stdio_common_vfwprintffputwc
            • String ID:
            • API String ID: 4070124032-0
            • Opcode ID: 80726567e331f5c969f38b0ee50634b30822c4dc1fd06a43ae5c44f76b935747
            • Instruction ID: a7ade3594d3f78bbd47da25fae9e90fc02c0762d7559e4d3e6beb5d0e1b62dc6
            • Opcode Fuzzy Hash: 80726567e331f5c969f38b0ee50634b30822c4dc1fd06a43ae5c44f76b935747
            • Instruction Fuzzy Hash: 96010C35A18B8282DE109B10FC6406AB7A1FBA9785F444139FA8D93A29CF3DD455C701
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: CriticalSection$EnterLeave__stdio_common_vfwprintffputwc
            • String ID:
            • API String ID: 4070124032-0
            • Opcode ID: c380a47fe0081dcf7cf49a38ed320f8d2506f5651096cae879bc4988e8b5fbd8
            • Instruction ID: 5814ef3e4364c17d0e4e87bce1fc9e85bb13c7db2448cf98ffe1e1c2f2e10d1d
            • Opcode Fuzzy Hash: c380a47fe0081dcf7cf49a38ed320f8d2506f5651096cae879bc4988e8b5fbd8
            • Instruction Fuzzy Hash: 84010C35A18B8282DF109B10FC6406AB7A1FBA9789F544139FA8D93A29CF7DD455C701
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,\\?\,?,?,00007FF62E5D5595), ref: 00007FF62E5D5AC4
            • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF62E5D5B11
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
            • String ID: \\?\
            • API String ID: 73155330-4282027825
            • Opcode ID: de7a16d0764b1f9efac0cebd142e35439489550fc91339ec0e6b383edbfcbe21
            • Instruction ID: 4bbbc8166497ab1c5194a22a9f9e4c76f2997f17f4fc3da0fe17c8f72aaa88aa
            • Opcode Fuzzy Hash: de7a16d0764b1f9efac0cebd142e35439489550fc91339ec0e6b383edbfcbe21
            • Instruction Fuzzy Hash: 83414666729B82C5EE109B12E8542ADA356FB18BD1F880639FF6D9B7C5CE7DE0408301
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF62E5D8AD2
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn
            • String ID: invalid stoul argument$stoul argument out of range
            • API String ID: 3668304517-1365241121
            • Opcode ID: 330c5a34b0a8f9ab6b1a2709ea9f8d80fb9a75f6c2688c4bbcf4dc4e51440ad9
            • Instruction ID: 74076488d3fe23e37b0b005ff3fd679778360e1340467d6e6143b76e55e164f7
            • Opcode Fuzzy Hash: 330c5a34b0a8f9ab6b1a2709ea9f8d80fb9a75f6c2688c4bbcf4dc4e51440ad9
            • Instruction Fuzzy Hash: 601160B2724A8581EF048B29E45836D6326FB54FD8F54503ADA4C57659EF7ED880C304
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF62E5E2CE2), ref: 00007FF62E5E4F20
            • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF62E5E2CE2), ref: 00007FF62E5E4F66
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: ExceptionFileHeaderRaise
            • String ID: csm
            • API String ID: 2573137834-1018135373
            • Opcode ID: 6a4b09854641f9778161c1b8d0185bf144bae762e0ab30c7f7dec4ec9b494210
            • Instruction ID: 93b9c9de95504fc622bd97417dca1a7d8e6e86a05aeaf0647a4959e320b54162
            • Opcode Fuzzy Hash: 6a4b09854641f9778161c1b8d0185bf144bae762e0ab30c7f7dec4ec9b494210
            • Instruction Fuzzy Hash: 6C116A32A28B8182EF248F25E85026977A0FB98B84F5C4238EE8C57B65DF3DC4518B00
            Uniqueness

            Uniqueness Score: -1.00%

            APIs
            • GetLastError.KERNEL32(?,?,?,00007FF62E5E5C09,?,?,?,?,00007FF62E5E4C0A), ref: 00007FF62E5E5C3B
            • SetLastError.KERNEL32(?,?,?,00007FF62E5E5C09,?,?,?,?,00007FF62E5E4C0A), ref: 00007FF62E5E5CC2
            Memory Dump Source
            • Source File: 00000000.00000002.1629949001.00007FF62E5D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF62E5D0000, based on PE: true
            • Associated: 00000000.00000002.1629932546.00007FF62E5D0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629970983.00007FF62E5EA000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1629991501.00007FF62E5F4000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.1630012306.00007FF62E5F6000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff62e5d0000_WinUI.jbxd
            Similarity
            • API ID: ErrorLast
            • String ID:
            • API String ID: 1452528299-0
            • Opcode ID: 5e6e74bf33f2ba030fc1ee03060395f846af5e39ad28ff1cab3f2eb74033dd11
            • Instruction ID: 9b793d0a3d67f9b59abb221b40528b58afa6cb1185c564dca070bd950947c4b1
            • Opcode Fuzzy Hash: 5e6e74bf33f2ba030fc1ee03060395f846af5e39ad28ff1cab3f2eb74033dd11
            • Instruction Fuzzy Hash: 0B117230E39A4281FE549B31AC711392251AF647A0F0C4A3CFA2EA73D5DE3EF8418746
            Uniqueness

            Uniqueness Score: -1.00%