Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
createdump.exe

Overview

General Information

Sample name:createdump.exe
Analysis ID:1427814
MD5:688a16f9e8568486cf917be2edcddc09
SHA1:ce3ad3daf096e89487493b68d14d4e4d77aacfc6
SHA256:f5785f7d354173ef61b1264538433c34b02459227337ef6aff863787baf5fa6c
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Contains functionality to check if a debugger is running (IsDebuggerPresent)
Found large amount of non-executed APIs
PE file contains sections with non-standard names
Program does not show much activity (idle)
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • createdump.exe (PID: 7324 cmdline: "C:\Users\user\Desktop\createdump.exe" MD5: 688A16F9E8568486CF917BE2EDCDDC09)
    • conhost.exe (PID: 7332 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: createdump.exeStatic PE information: certificate valid
Source: createdump.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb source: createdump.exe
Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb;;;GCTL source: createdump.exe
Source: createdump.exeBinary or memory string: OriginalFilename vs createdump.exe
Source: createdump.exe, 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameFX_VER_INTERNALNAME_STR@ vs createdump.exe
Source: createdump.exeBinary or memory string: OriginalFilenameFX_VER_INTERNALNAME_STR@ vs createdump.exe
Source: classification engineClassification label: clean3.winEXE@2/1@0/0
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7332:120:WilError_03
Source: createdump.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\createdump.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\createdump.exe "C:\Users\user\Desktop\createdump.exe"
Source: C:\Users\user\Desktop\createdump.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\createdump.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\createdump.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Users\user\Desktop\createdump.exeSection loaded: dbgcore.dllJump to behavior
Source: C:\Users\user\Desktop\createdump.exeSection loaded: kernel.appcore.dllJump to behavior
Source: createdump.exeStatic PE information: certificate valid
Source: initial sampleStatic PE information: Valid certificate with Microsoft Issuer
Source: createdump.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: createdump.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: createdump.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: createdump.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: createdump.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: createdump.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: createdump.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: createdump.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: createdump.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb source: createdump.exe
Source: Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb;;;GCTL source: createdump.exe
Source: createdump.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: createdump.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: createdump.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: createdump.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: createdump.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: createdump.exeStatic PE information: section name: _RDATA
Source: C:\Users\user\Desktop\createdump.exeAPI coverage: 8.2 %
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\createdump.exeCode function: 0_2_00007FF68D622ECC IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF68D622ECC
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\createdump.exeCode function: 0_2_00007FF68D623074 SetUnhandledExceptionFilter,0_2_00007FF68D623074
Source: C:\Users\user\Desktop\createdump.exeCode function: 0_2_00007FF68D622ECC IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF68D622ECC
Source: C:\Users\user\Desktop\createdump.exeCode function: 0_2_00007FF68D622984 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF68D622984
Source: C:\Users\user\Desktop\createdump.exeCode function: 0_2_00007FF68D622DA0 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF68D622DA0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Process Injection
OS Credential Dumping1
System Time Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
DLL Side-Loading
LSASS Memory1
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager2
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1427814 Sample: createdump.exe Startdate: 18/04/2024 Architecture: WINDOWS Score: 3 5 createdump.exe 1 2->5         started        process3 7 conhost.exe 5->7         started       
SourceDetectionScannerLabelLink
createdump.exe0%ReversingLabs
createdump.exe0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1427814
Start date and time:2024-04-18 08:19:36 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 1m 47s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:2
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:createdump.exe
Detection:CLEAN
Classification:clean3.winEXE@2/1@0/0
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 3
  • Number of non-executed functions: 17
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Stop behavior analysis, all processes terminated
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
No context
Process:C:\Users\user\Desktop\createdump.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):638
Entropy (8bit):4.751962275036146
Encrypted:false
SSDEEP:12:ku/L92WF4gx9l+jsPczo/CdaD0gwiSrlEX6OPkRVdoaQLeU4wv:ku/h5F4Bs0oCdalwisCkRVKVeU4wv
MD5:15CA959638E74EEC47E0830B90D0696E
SHA1:E836936738DCB6C551B6B76054F834CFB8CC53E5
SHA-256:57F2C730C98D62D6C84B693294F6191FD2BEC7D7563AD9963A96AE87ABEBF9EE
SHA-512:101390C5D2FA93162804B589376CF1E4A1A3DD4BDF4B6FE26D807AFC3FF80DA26EE3BAEB731D297A482165DE7CA48508D6EAA69A5509168E9CEF20B4A88A49FD
Malicious:false
Reputation:low
Preview:[createdump] createdump [options] pid..-f, --name - dump path and file name. The default is '%TEMP%\dump.%p.dmp'. These specifiers are substituted with following values:.. %p PID of dumped process... %e The process executable filename... %h Hostname return by gethostname()... %t Time of dump, expressed as seconds since the Epoch, 1970-01-01 00:00:00 +0000 (UTC)...-n, --normal - create minidump...-h, --withheap - create minidump with heap (default)...-t, --triage - create triage minidump...-u, --full - create full core dump...-d, --diag - enable diagnostic messages...-v, --verbose - enable verbose diagnostic messages...
File type:PE32+ executable (console) x86-64, for MS Windows
Entropy (8bit):6.353826566596602
TrID:
  • Win64 Executable Console (202006/5) 92.65%
  • Win64 Executable (generic) (12005/4) 5.51%
  • Generic Win/DOS Executable (2004/3) 0.92%
  • DOS Executable Generic (2002/1) 0.92%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:createdump.exe
File size:57'576 bytes
MD5:688a16f9e8568486cf917be2edcddc09
SHA1:ce3ad3daf096e89487493b68d14d4e4d77aacfc6
SHA256:f5785f7d354173ef61b1264538433c34b02459227337ef6aff863787baf5fa6c
SHA512:1159cfc85e5133db0c05c2a0a8b2911ae1aba8d83b442f49402b7a0038366a31267d472440ba4e43d5f0dfc9bdccce7b8be7ea67618d1928085af09eb2e96f8b
SSDEEP:768:qQ6XULhGj8TzwsoeZwVAsuEIBh8v6Y3eQdDU/i1Q9zS:oCVbTGkiLx0iSzS
TLSH:41436D0A67B940E6E46B81B4C5E25A47FD79F512231192CF0FBDC2161F637C09E3AB29
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........l...............uU......x.......x.......x.......................x.......x9......x......Rich............PE..d...5joe.........."
Icon Hash:90cececece8e8eb0
Entrypoint:0x140002970
Entrypoint Section:.text
Digitally signed:true
Imagebase:0x140000000
Subsystem:windows cui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Time Stamp:0x656F6A35 [Tue Dec 5 18:21:41 2023 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:a59809c5c0d26ef15e2540ac3993c6e2
Signature Valid:true
Signature Issuer:CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Signature Validation Error:The operation completed successfully
Error Number:0
Not Before, Not After
  • 11/05/2023 20:03:32 08/05/2024 20:03:32
Subject Chain
  • CN=.NET, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Version:3
Thumbprint MD5:97762F82B14E28F4E97F0A97D81F280B
Thumbprint SHA-1:50A04FFE627F8E21FD61AF1B73E5D03B4ADB100D
Thumbprint SHA-256:C5C2879E3551DA2FA5B8B2576FB7567F2BBEF79DDA388C45D137B0EE62F8F62C
Serial:330000037CC9F6BCED0759AE0800000000037C
Instruction
dec eax
sub esp, 28h
call 00007F4B1D1A188Ch
dec eax
add esp, 28h
jmp 00007F4B1D1A12CFh
int3
int3
inc eax
push ebx
dec eax
sub esp, 20h
dec eax
mov ebx, ecx
xor ecx, ecx
call dword ptr [00005743h]
dec eax
mov ecx, ebx
call dword ptr [00005742h]
call dword ptr [0000572Ch]
dec eax
mov ecx, eax
mov edx, C0000409h
dec eax
add esp, 20h
pop ebx
dec eax
jmp dword ptr [00005710h]
int3
int3
int3
int3
int3
int3
int3
int3
dec eax
mov dword ptr [esp+08h], ecx
dec eax
sub esp, 38h
mov ecx, 00000017h
call dword ptr [000056ECh]
test eax, eax
je 00007F4B1D1A1469h
mov ecx, 00000002h
int 29h
dec eax
lea ecx, dword ptr [0000981Ah]
call 00007F4B1D1A150Eh
dec eax
mov eax, dword ptr [esp+38h]
dec eax
mov dword ptr [00009901h], eax
dec eax
lea eax, dword ptr [esp+38h]
dec eax
add eax, 08h
dec eax
mov dword ptr [00009891h], eax
dec eax
mov eax, dword ptr [000098EAh]
dec eax
mov dword ptr [0000975Bh], eax
dec eax
mov eax, dword ptr [esp+40h]
dec eax
mov dword ptr [0000985Fh], eax
mov dword ptr [00009735h], C0000409h
mov dword ptr [0000972Fh], 00000001h
mov dword ptr [00000039h], 00000000h
Programming Language:
  • [IMP] VS2008 SP1 build 30729
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0xaca40xf0.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0xf0000x68c.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0xd0000x750.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0xb8000x28e8
IMAGE_DIRECTORY_ENTRY_BASERELOC0x100000x164.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x99840x54.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x99e00x138.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x80000x2c0.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x65c00x66002a90b47289c6e39476feb06a8f0e0479False0.5633425245098039data6.406845564004421IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x80000x36ce0x38006233dc4dbf7928b128dcd5b234c69c54False0.3701171875data4.398078476866589IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0xc0000x8d80x2002dd473d608761c084f9e65bd09cf2870False0.294921875data2.9727405049128794IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.pdata0xd0000x7500x800b9cdc1398dbaa98d5b4f9dfc2695c41aFalse0.458984375PEX Binary Archive4.091188184154214IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
_RDATA0xe0000xfc0x200ad51145aa785560b23186d128c549018False0.296875data1.9964173903557825IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0xf0000x68c0x8001bda74fde532a8d4da1201e8ddafd293False0.35546875data4.521186346065648IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x100000x1640x200c186ca82fafbc91f1037459acee31137False0.556640625data4.12571512797523IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_VERSION0xf0a00x490dataEnglishUnited States0.4203767123287671
RT_MANIFEST0xf5300x15aASCII text, with CRLF line terminatorsEnglishUnited States0.5491329479768786
DLLImport
KERNEL32.dllGetTempPathA, GetLastError, OpenProcess, CreateFileA, CloseHandle, K32GetModuleBaseNameA, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, EncodePointer, SetLastError, RaiseException, RtlPcToFileHeader, RtlUnwindEx, GetModuleHandleW, IsDebuggerPresent, InitializeSListHead, GetSystemTimeAsFileTime, GetCurrentThreadId, GetCurrentProcessId, QueryPerformanceCounter, IsProcessorFeaturePresent, TerminateProcess, GetCurrentProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, GetProcAddress, LoadLibraryExW, FreeLibrary
dbghelp.dllMiniDumpWriteDump
WS2_32.dllWSAGetLastError, gethostname, WSAStartup
api-ms-win-crt-stdio-l1-1-0.dll__stdio_common_vfprintf, _set_fmode, fflush, __p__commode, __acrt_iob_func
api-ms-win-crt-convert-l1-1-0.dllatoi
api-ms-win-crt-string-l1-1-0.dllwcsncmp, strcpy_s, strcat_s, strcmp
api-ms-win-crt-time-l1-1-0.dll_time64
api-ms-win-crt-runtime-l1-1-0.dll__p___argv, _initialize_onexit_table, _cexit, _c_exit, _exit, exit, _register_onexit_function, _initterm, _get_initial_narrow_environment, _initialize_narrow_environment, _configure_narrow_argv, _register_thread_local_exe_atexit_callback, _set_app_type, _seh_filter_exe, terminate, _invalid_parameter_noinfo_noreturn, abort, _crt_atexit, __p___argc, _initterm_e
api-ms-win-crt-heap-l1-1-0.dll_set_new_mode, malloc, free, _callnewh, calloc
api-ms-win-crt-math-l1-1-0.dll__setusermatherr
api-ms-win-crt-locale-l1-1-0.dll_configthreadlocale
Language of compilation systemCountry where language is spokenMap
EnglishUnited States
No network behavior found

Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:08:20:24
Start date:18/04/2024
Path:C:\Users\user\Desktop\createdump.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\createdump.exe"
Imagebase:0x7ff68d620000
File size:57'576 bytes
MD5 hash:688A16F9E8568486CF917BE2EDCDDC09
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Target ID:1
Start time:08:20:24
Start date:18/04/2024
Path:C:\Windows\System32\conhost.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Imagebase:0x7ff7699e0000
File size:862'208 bytes
MD5 hash:0D698AF330FD17BEE3BF90011D49251D
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Reset < >

    Execution Graph

    Execution Coverage:3.4%
    Dynamic/Decrypted Code Coverage:0%
    Signature Coverage:1.7%
    Total number of Nodes:700
    Total number of Limit Nodes:1
    execution_graph 2502 7ff68d6274a7 2505 7ff68d625cc0 2502->2505 2510 7ff68d625c38 2505->2510 2509 7ff68d625ce0 2511 7ff68d625c5a 2510->2511 2513 7ff68d625ca3 2510->2513 2512 7ff68d6243d0 _CreateFrameInfo 10 API calls 2511->2512 2511->2513 2512->2513 2513->2509 2514 7ff68d6243d0 2513->2514 2517 7ff68d6243ec 2514->2517 2516 7ff68d6243d9 2516->2509 2518 7ff68d62440b GetLastError 2517->2518 2519 7ff68d624404 2517->2519 2531 7ff68d626678 2518->2531 2519->2516 2532 7ff68d626498 __vcrt_InitializeCriticalSectionEx 5 API calls 2531->2532 2533 7ff68d62669f TlsGetValue 2532->2533 2535 7ff68d6259ad 2536 7ff68d6243d0 _CreateFrameInfo 10 API calls 2535->2536 2537 7ff68d6259ba 2536->2537 2538 7ff68d6243d0 _CreateFrameInfo 10 API calls 2537->2538 2540 7ff68d6259c3 __GSHandlerCheck_EH 2538->2540 2539 7ff68d625a0a RaiseException 2541 7ff68d625a29 2539->2541 2540->2539 2554 7ff68d623b54 2541->2554 2543 7ff68d6243d0 _CreateFrameInfo 10 API calls 2544 7ff68d625a6d 2543->2544 2546 7ff68d6243d0 _CreateFrameInfo 10 API calls 2544->2546 2548 7ff68d625a76 2546->2548 2550 7ff68d6243d0 _CreateFrameInfo 10 API calls 2548->2550 2549 7ff68d625a5a __GSHandlerCheck_EH 2549->2543 2551 7ff68d625a7f 2550->2551 2552 7ff68d6243d0 _CreateFrameInfo 10 API calls 2551->2552 2553 7ff68d625a8e 2552->2553 2555 7ff68d6243d0 _CreateFrameInfo 10 API calls 2554->2555 2556 7ff68d623b66 2555->2556 2557 7ff68d623ba1 abort 2556->2557 2558 7ff68d6243d0 _CreateFrameInfo 10 API calls 2556->2558 2560 7ff68d623b71 2558->2560 2559 7ff68d623b8d 2561 7ff68d6243d0 _CreateFrameInfo 10 API calls 2559->2561 2560->2557 2560->2559 2562 7ff68d623b92 2561->2562 2562->2549 2563 7ff68d624104 2562->2563 2564 7ff68d6243d0 _CreateFrameInfo 10 API calls 2563->2564 2565 7ff68d624112 2564->2565 2565->2549 2256 7ff68d6227ec 2279 7ff68d622b8c 2256->2279 2259 7ff68d62280d 2262 7ff68d62294d 2259->2262 2267 7ff68d62282b __scrt_release_startup_lock 2259->2267 2260 7ff68d622943 2319 7ff68d622ecc IsProcessorFeaturePresent 2260->2319 2263 7ff68d622ecc 7 API calls 2262->2263 2264 7ff68d622958 2263->2264 2266 7ff68d622960 _exit 2264->2266 2265 7ff68d622850 2267->2265 2268 7ff68d6228d6 _get_initial_narrow_environment __p___argv __p___argc 2267->2268 2271 7ff68d6228ce _register_thread_local_exe_atexit_callback 2267->2271 2285 7ff68d621060 2268->2285 2271->2268 2274 7ff68d622903 2275 7ff68d622908 _cexit 2274->2275 2276 7ff68d62290d 2274->2276 2275->2276 2315 7ff68d622d20 2276->2315 2326 7ff68d62316c 2279->2326 2282 7ff68d622805 2282->2259 2282->2260 2283 7ff68d622bbb __scrt_initialize_crt 2283->2282 2328 7ff68d62404c 2283->2328 2286 7ff68d621386 2285->2286 2307 7ff68d6210b4 2285->2307 2355 7ff68d621450 __acrt_iob_func 2286->2355 2288 7ff68d621399 2313 7ff68d623020 GetModuleHandleW 2288->2313 2289 7ff68d621289 2289->2286 2290 7ff68d62129f 2289->2290 2360 7ff68d622688 2290->2360 2292 7ff68d621125 strcmp 2292->2307 2293 7ff68d6212a9 2294 7ff68d6212b9 GetTempPathA 2293->2294 2295 7ff68d621325 2293->2295 2296 7ff68d6212e9 strcat_s 2294->2296 2297 7ff68d6212cb GetLastError 2294->2297 2369 7ff68d6223c0 2295->2369 2296->2295 2301 7ff68d621304 2296->2301 2300 7ff68d621450 6 API calls 2297->2300 2298 7ff68d621151 strcmp 2298->2307 2303 7ff68d6212df GetLastError 2300->2303 2304 7ff68d621450 6 API calls 2301->2304 2310 7ff68d621312 2303->2310 2304->2310 2305 7ff68d621344 __acrt_iob_func fflush __acrt_iob_func fflush 2305->2310 2306 7ff68d62117d strcmp 2306->2307 2307->2289 2307->2292 2307->2298 2307->2306 2311 7ff68d621226 strcmp 2307->2311 2310->2288 2311->2307 2312 7ff68d621239 atoi 2311->2312 2312->2307 2314 7ff68d6228ff 2313->2314 2314->2264 2314->2274 2317 7ff68d622d31 __scrt_initialize_crt 2315->2317 2316 7ff68d622916 2316->2265 2317->2316 2318 7ff68d62404c __scrt_initialize_crt 7 API calls 2317->2318 2318->2316 2320 7ff68d622ef2 2319->2320 2321 7ff68d622f11 RtlCaptureContext RtlLookupFunctionEntry 2320->2321 2322 7ff68d622f76 2321->2322 2323 7ff68d622f3a RtlVirtualUnwind 2321->2323 2324 7ff68d622fa8 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 2322->2324 2323->2322 2325 7ff68d622ffa 2324->2325 2325->2262 2327 7ff68d622bae __scrt_dllmain_crt_thread_attach 2326->2327 2327->2282 2327->2283 2329 7ff68d62405e 2328->2329 2330 7ff68d624054 2328->2330 2329->2282 2334 7ff68d6244f4 2330->2334 2335 7ff68d624059 2334->2335 2336 7ff68d624503 2334->2336 2338 7ff68d626460 2335->2338 2342 7ff68d626630 2336->2342 2339 7ff68d62648b 2338->2339 2340 7ff68d62648f 2339->2340 2341 7ff68d62646e DeleteCriticalSection 2339->2341 2340->2329 2341->2339 2346 7ff68d626498 2342->2346 2347 7ff68d6265b2 TlsFree 2346->2347 2348 7ff68d6264dc 2346->2348 2348->2347 2349 7ff68d62650a LoadLibraryExW 2348->2349 2350 7ff68d6265a1 GetProcAddress 2348->2350 2354 7ff68d62654d LoadLibraryExW 2348->2354 2351 7ff68d62652b GetLastError 2349->2351 2352 7ff68d626581 2349->2352 2350->2347 2351->2348 2352->2350 2353 7ff68d626598 FreeLibrary 2352->2353 2353->2350 2354->2348 2354->2352 2405 7ff68d621010 2355->2405 2357 7ff68d62148a __acrt_iob_func 2408 7ff68d621000 2357->2408 2359 7ff68d6214a2 __stdio_common_vfprintf __acrt_iob_func fflush 2359->2288 2363 7ff68d622690 2360->2363 2361 7ff68d6226aa malloc 2362 7ff68d6226b4 2361->2362 2361->2363 2362->2293 2363->2361 2364 7ff68d6226ba 2363->2364 2365 7ff68d6226c5 2364->2365 2410 7ff68d622b30 2364->2410 2414 7ff68d621720 2365->2414 2368 7ff68d6226cb 2368->2293 2370 7ff68d622688 5 API calls 2369->2370 2371 7ff68d6223f5 OpenProcess 2370->2371 2372 7ff68d622458 K32GetModuleBaseNameA 2371->2372 2373 7ff68d62243b GetLastError 2371->2373 2375 7ff68d622470 GetLastError 2372->2375 2376 7ff68d622492 2372->2376 2374 7ff68d621450 6 API calls 2373->2374 2379 7ff68d622453 2374->2379 2377 7ff68d621450 6 API calls 2375->2377 2431 7ff68d621800 2376->2431 2380 7ff68d622484 CloseHandle 2377->2380 2384 7ff68d6225fa 2379->2384 2386 7ff68d6225f3 _invalid_parameter_noinfo_noreturn 2379->2386 2380->2379 2382 7ff68d6224ae 2385 7ff68d6213c0 6 API calls 2382->2385 2383 7ff68d6225b3 CloseHandle 2383->2379 2442 7ff68d622660 2384->2442 2387 7ff68d6224cf CreateFileA 2385->2387 2386->2384 2389 7ff68d62250f GetLastError 2387->2389 2390 7ff68d622543 2387->2390 2391 7ff68d621450 6 API calls 2389->2391 2392 7ff68d622550 MiniDumpWriteDump 2390->2392 2396 7ff68d62258a CloseHandle CloseHandle 2390->2396 2394 7ff68d622538 CloseHandle 2391->2394 2395 7ff68d622576 GetLastError 2392->2395 2392->2396 2394->2379 2395->2390 2397 7ff68d62258c 2395->2397 2396->2379 2399 7ff68d621450 6 API calls 2397->2399 2399->2396 2400 7ff68d6213c0 __acrt_iob_func 2401 7ff68d621010 fprintf __stdio_common_vfprintf 2400->2401 2402 7ff68d6213fa __acrt_iob_func 2401->2402 2501 7ff68d621000 2402->2501 2404 7ff68d621412 __stdio_common_vfprintf __acrt_iob_func fflush 2404->2305 2409 7ff68d621000 2405->2409 2407 7ff68d621036 __stdio_common_vfprintf 2407->2357 2408->2359 2409->2407 2411 7ff68d622b3e std::bad_alloc::bad_alloc 2410->2411 2420 7ff68d623f84 2411->2420 2413 7ff68d622b4f 2415 7ff68d62172e Concurrency::cancel_current_task 2414->2415 2416 7ff68d623f84 Concurrency::cancel_current_task 2 API calls 2415->2416 2417 7ff68d62173f 2416->2417 2425 7ff68d623cc0 2417->2425 2421 7ff68d623fc0 RtlPcToFileHeader 2420->2421 2422 7ff68d623fa3 2420->2422 2423 7ff68d623fe7 RaiseException 2421->2423 2424 7ff68d623fd8 2421->2424 2422->2421 2423->2413 2424->2423 2426 7ff68d62176d 2425->2426 2427 7ff68d623ce1 2425->2427 2426->2368 2427->2426 2428 7ff68d623cf6 malloc 2427->2428 2429 7ff68d623d07 2428->2429 2430 7ff68d623d23 free 2428->2430 2429->2430 2430->2426 2432 7ff68d621850 2431->2432 2433 7ff68d621863 WSAStartup 2431->2433 2434 7ff68d621450 6 API calls 2432->2434 2436 7ff68d62187f 2433->2436 2441 7ff68d62185c 2433->2441 2434->2441 2435 7ff68d622660 __GSHandlerCheck_EH 8 API calls 2437 7ff68d621d87 2435->2437 2438 7ff68d621dd0 2436->2438 2436->2441 2451 7ff68d6220c0 2436->2451 2437->2382 2437->2383 2440 7ff68d621450 6 API calls 2438->2440 2440->2441 2441->2435 2443 7ff68d622669 2442->2443 2444 7ff68d621334 2443->2444 2445 7ff68d6229c0 IsProcessorFeaturePresent 2443->2445 2444->2305 2444->2400 2446 7ff68d6229d8 2445->2446 2496 7ff68d622a94 RtlCaptureContext 2446->2496 2452 7ff68d6220e9 2451->2452 2453 7ff68d622218 2451->2453 2455 7ff68d622144 2452->2455 2458 7ff68d622137 2452->2458 2459 7ff68d62216c 2452->2459 2475 7ff68d6217e0 2453->2475 2466 7ff68d622690 2455->2466 2456 7ff68d62221d 2461 7ff68d621720 Concurrency::cancel_current_task 4 API calls 2456->2461 2458->2455 2458->2456 2460 7ff68d622155 BuildCatchObjectHelperInternal 2459->2460 2463 7ff68d622690 5 API calls 2459->2463 2462 7ff68d6221e0 _invalid_parameter_noinfo_noreturn 2460->2462 2465 7ff68d6221d3 BuildCatchObjectHelperInternal 2460->2465 2464 7ff68d622223 2461->2464 2462->2465 2463->2460 2465->2436 2467 7ff68d6226aa malloc 2466->2467 2468 7ff68d62269b 2467->2468 2469 7ff68d6226b4 2467->2469 2468->2467 2470 7ff68d6226ba 2468->2470 2469->2460 2472 7ff68d622b30 Concurrency::cancel_current_task 2 API calls 2470->2472 2474 7ff68d6226c5 2470->2474 2471 7ff68d621720 Concurrency::cancel_current_task 4 API calls 2473 7ff68d6226cb 2471->2473 2472->2474 2473->2460 2474->2471 2488 7ff68d6234d4 2475->2488 2493 7ff68d6233f8 2488->2493 2491 7ff68d623f84 Concurrency::cancel_current_task 2 API calls 2492 7ff68d6234f6 2491->2492 2494 7ff68d623cc0 __std_exception_copy 2 API calls 2493->2494 2495 7ff68d62342c 2494->2495 2495->2491 2497 7ff68d622aae RtlLookupFunctionEntry 2496->2497 2498 7ff68d6229eb 2497->2498 2499 7ff68d622ac4 RtlVirtualUnwind 2497->2499 2500 7ff68d622984 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 2498->2500 2499->2497 2499->2498 2501->2404 2961 7ff68d62756f 2962 7ff68d6243d0 _CreateFrameInfo 10 API calls 2961->2962 2963 7ff68d62757d 2962->2963 2964 7ff68d627588 2963->2964 2965 7ff68d6243d0 _CreateFrameInfo 10 API calls 2963->2965 2965->2964 2566 7ff68d627130 2567 7ff68d627168 __GSHandlerCheckCommon 2566->2567 2568 7ff68d627194 2567->2568 2570 7ff68d623c00 2567->2570 2571 7ff68d6243d0 _CreateFrameInfo 10 API calls 2570->2571 2572 7ff68d623c42 2571->2572 2573 7ff68d6243d0 _CreateFrameInfo 10 API calls 2572->2573 2574 7ff68d623c4f 2573->2574 2575 7ff68d6243d0 _CreateFrameInfo 10 API calls 2574->2575 2576 7ff68d623c58 __GSHandlerCheck_EH 2575->2576 2579 7ff68d625414 2576->2579 2580 7ff68d625443 __except_validate_context_record 2579->2580 2581 7ff68d6243d0 _CreateFrameInfo 10 API calls 2580->2581 2582 7ff68d625448 2581->2582 2583 7ff68d623ca9 2582->2583 2586 7ff68d6255b2 __GSHandlerCheck_EH 2582->2586 2589 7ff68d625498 2582->2589 2583->2568 2584 7ff68d6255f7 2584->2583 2626 7ff68d6249a4 2584->2626 2585 7ff68d62559f 2619 7ff68d623678 2585->2619 2586->2583 2586->2584 2623 7ff68d623bbc 2586->2623 2589->2583 2589->2585 2593 7ff68d6254f3 __GSHandlerCheck_EH 2589->2593 2590 7ff68d6256a2 abort 2592 7ff68d625543 2595 7ff68d625cf0 2592->2595 2593->2590 2593->2592 2679 7ff68d623ba8 2595->2679 2597 7ff68d625d40 __GSHandlerCheck_EH 2598 7ff68d625d5b 2597->2598 2599 7ff68d625d72 2597->2599 2600 7ff68d6243d0 _CreateFrameInfo 10 API calls 2598->2600 2601 7ff68d6243d0 _CreateFrameInfo 10 API calls 2599->2601 2602 7ff68d625d60 2600->2602 2603 7ff68d625d77 2601->2603 2604 7ff68d625d6a 2602->2604 2605 7ff68d625fd0 abort 2602->2605 2603->2604 2607 7ff68d6243d0 _CreateFrameInfo 10 API calls 2603->2607 2606 7ff68d6243d0 _CreateFrameInfo 10 API calls 2604->2606 2617 7ff68d625d96 __GSHandlerCheck_EH 2606->2617 2608 7ff68d625d82 2607->2608 2609 7ff68d6243d0 _CreateFrameInfo 10 API calls 2608->2609 2609->2604 2610 7ff68d625f92 2611 7ff68d6243d0 _CreateFrameInfo 10 API calls 2610->2611 2612 7ff68d625f97 2611->2612 2613 7ff68d625fa2 2612->2613 2614 7ff68d6243d0 _CreateFrameInfo 10 API calls 2612->2614 2615 7ff68d622660 __GSHandlerCheck_EH 8 API calls 2613->2615 2614->2613 2616 7ff68d625fb5 2615->2616 2616->2583 2617->2610 2682 7ff68d623bd0 2617->2682 2620 7ff68d62368a 2619->2620 2621 7ff68d625cf0 __GSHandlerCheck_EH 19 API calls 2620->2621 2622 7ff68d6236a5 2621->2622 2622->2583 2624 7ff68d6243d0 _CreateFrameInfo 10 API calls 2623->2624 2625 7ff68d623bc5 2624->2625 2625->2584 2627 7ff68d624a01 __GSHandlerCheck_EH 2626->2627 2628 7ff68d624a09 2627->2628 2629 7ff68d624a20 2627->2629 2630 7ff68d6243d0 _CreateFrameInfo 10 API calls 2628->2630 2631 7ff68d6243d0 _CreateFrameInfo 10 API calls 2629->2631 2639 7ff68d624a0e 2630->2639 2632 7ff68d624a25 2631->2632 2634 7ff68d6243d0 _CreateFrameInfo 10 API calls 2632->2634 2632->2639 2633 7ff68d624e99 abort 2635 7ff68d624a30 2634->2635 2636 7ff68d6243d0 _CreateFrameInfo 10 API calls 2635->2636 2636->2639 2637 7ff68d624def 2637->2633 2641 7ff68d624ded 2637->2641 2721 7ff68d624ea0 2637->2721 2638 7ff68d624b54 __GSHandlerCheck_EH 2638->2637 2673 7ff68d624b90 __GSHandlerCheck_EH 2638->2673 2639->2633 2639->2638 2640 7ff68d6243d0 _CreateFrameInfo 10 API calls 2639->2640 2642 7ff68d624ac0 2640->2642 2643 7ff68d6243d0 _CreateFrameInfo 10 API calls 2641->2643 2645 7ff68d624e37 2642->2645 2648 7ff68d6243d0 _CreateFrameInfo 10 API calls 2642->2648 2647 7ff68d624e30 2643->2647 2644 7ff68d624dd4 __GSHandlerCheck_EH 2644->2641 2653 7ff68d624e81 2644->2653 2649 7ff68d622660 __GSHandlerCheck_EH 8 API calls 2645->2649 2647->2633 2647->2645 2650 7ff68d624ad0 2648->2650 2651 7ff68d624e43 2649->2651 2652 7ff68d6243d0 _CreateFrameInfo 10 API calls 2650->2652 2651->2583 2654 7ff68d624ad9 2652->2654 2655 7ff68d6243d0 _CreateFrameInfo 10 API calls 2653->2655 2685 7ff68d623be8 2654->2685 2657 7ff68d624e86 2655->2657 2659 7ff68d6243d0 _CreateFrameInfo 10 API calls 2657->2659 2660 7ff68d624e8f terminate 2659->2660 2660->2633 2661 7ff68d6243d0 _CreateFrameInfo 10 API calls 2662 7ff68d624b16 2661->2662 2662->2638 2664 7ff68d6243d0 _CreateFrameInfo 10 API calls 2662->2664 2663 7ff68d623bbc 10 API calls BuildCatchObjectHelperInternal 2663->2673 2665 7ff68d624b22 2664->2665 2666 7ff68d6243d0 _CreateFrameInfo 10 API calls 2665->2666 2667 7ff68d624b2b 2666->2667 2688 7ff68d625fd8 2667->2688 2671 7ff68d624b3f 2695 7ff68d6260c8 2671->2695 2673->2644 2673->2663 2699 7ff68d6252d0 2673->2699 2713 7ff68d6248d0 2673->2713 2674 7ff68d624e7b terminate 2674->2653 2676 7ff68d624b47 std::bad_alloc::bad_alloc __GSHandlerCheck_EH 2676->2674 2677 7ff68d623f84 Concurrency::cancel_current_task 2 API calls 2676->2677 2678 7ff68d624e7a 2677->2678 2678->2674 2680 7ff68d6243d0 _CreateFrameInfo 10 API calls 2679->2680 2681 7ff68d623bb1 2680->2681 2681->2597 2683 7ff68d6243d0 _CreateFrameInfo 10 API calls 2682->2683 2684 7ff68d623bde 2683->2684 2684->2617 2686 7ff68d6243d0 _CreateFrameInfo 10 API calls 2685->2686 2687 7ff68d623bf6 2686->2687 2687->2633 2687->2661 2689 7ff68d6260bf abort 2688->2689 2694 7ff68d626003 2688->2694 2690 7ff68d624b3b 2690->2638 2690->2671 2691 7ff68d623bbc 10 API calls BuildCatchObjectHelperInternal 2691->2694 2692 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2692->2694 2694->2690 2694->2691 2694->2692 2737 7ff68d625190 2694->2737 2696 7ff68d626135 2695->2696 2698 7ff68d6260e5 Is_bad_exception_allowed 2695->2698 2696->2676 2697 7ff68d623ba8 10 API calls BuildCatchObjectHelperInternal 2697->2698 2698->2696 2698->2697 2700 7ff68d6252fd 2699->2700 2701 7ff68d62538d 2699->2701 2702 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2700->2702 2701->2673 2703 7ff68d625306 2702->2703 2703->2701 2704 7ff68d62531f 2703->2704 2705 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2703->2705 2704->2701 2706 7ff68d62534c 2704->2706 2707 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2704->2707 2705->2704 2708 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2706->2708 2707->2706 2709 7ff68d625360 2708->2709 2709->2701 2710 7ff68d625379 2709->2710 2711 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2709->2711 2712 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2710->2712 2711->2710 2712->2701 2714 7ff68d62490d __GSHandlerCheck_EH 2713->2714 2715 7ff68d624933 2714->2715 2751 7ff68d62480c 2714->2751 2717 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2715->2717 2718 7ff68d624945 2717->2718 2760 7ff68d623838 RtlUnwindEx 2718->2760 2722 7ff68d625169 2721->2722 2723 7ff68d624ef4 2721->2723 2725 7ff68d622660 __GSHandlerCheck_EH 8 API calls 2722->2725 2724 7ff68d6243d0 _CreateFrameInfo 10 API calls 2723->2724 2727 7ff68d624ef9 2724->2727 2726 7ff68d625175 2725->2726 2726->2641 2728 7ff68d624f60 __GSHandlerCheck_EH 2727->2728 2729 7ff68d624f0e EncodePointer 2727->2729 2728->2722 2731 7ff68d625189 abort 2728->2731 2735 7ff68d624f82 __GSHandlerCheck_EH 2728->2735 2730 7ff68d6243d0 _CreateFrameInfo 10 API calls 2729->2730 2732 7ff68d624f1e 2730->2732 2732->2728 2784 7ff68d6234f8 2732->2784 2734 7ff68d6248d0 __GSHandlerCheck_EH 21 API calls 2734->2735 2735->2722 2735->2734 2736 7ff68d623ba8 10 API calls BuildCatchObjectHelperInternal 2735->2736 2736->2735 2738 7ff68d62524c 2737->2738 2739 7ff68d6251bd 2737->2739 2738->2694 2740 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2739->2740 2741 7ff68d6251c6 2740->2741 2741->2738 2742 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2741->2742 2743 7ff68d6251df 2741->2743 2742->2743 2743->2738 2744 7ff68d62520b 2743->2744 2745 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2743->2745 2746 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2744->2746 2745->2744 2747 7ff68d62521f 2746->2747 2747->2738 2748 7ff68d625238 2747->2748 2749 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2747->2749 2750 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2748->2750 2749->2748 2750->2738 2752 7ff68d62482f 2751->2752 2763 7ff68d624608 2752->2763 2754 7ff68d624840 2755 7ff68d624845 __AdjustPointer 2754->2755 2756 7ff68d624881 __AdjustPointer 2754->2756 2758 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2755->2758 2759 7ff68d624864 BuildCatchObjectHelperInternal 2755->2759 2757 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2756->2757 2756->2759 2757->2759 2758->2759 2759->2715 2761 7ff68d622660 __GSHandlerCheck_EH 8 API calls 2760->2761 2762 7ff68d62394e 2761->2762 2762->2673 2764 7ff68d624635 2763->2764 2766 7ff68d62463e 2763->2766 2765 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2764->2765 2765->2766 2767 7ff68d623ba8 BuildCatchObjectHelperInternal 10 API calls 2766->2767 2768 7ff68d62465d 2766->2768 2769 7ff68d6246c2 __AdjustPointer BuildCatchObjectHelperInternal 2766->2769 2767->2768 2768->2769 2770 7ff68d6246aa 2768->2770 2771 7ff68d6246ca 2768->2771 2769->2754 2770->2769 2774 7ff68d6247e9 abort abort 2770->2774 2771->2769 2772 7ff68d62474a 2771->2772 2773 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2771->2773 2772->2769 2777 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2772->2777 2773->2772 2775 7ff68d62480c 2774->2775 2776 7ff68d624608 BuildCatchObjectHelperInternal 10 API calls 2775->2776 2778 7ff68d624840 2776->2778 2777->2769 2779 7ff68d624845 __AdjustPointer 2778->2779 2780 7ff68d624881 __AdjustPointer 2778->2780 2782 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2779->2782 2783 7ff68d624864 BuildCatchObjectHelperInternal 2779->2783 2781 7ff68d623bbc BuildCatchObjectHelperInternal 10 API calls 2780->2781 2780->2783 2781->2783 2782->2783 2783->2754 2785 7ff68d6243d0 _CreateFrameInfo 10 API calls 2784->2785 2786 7ff68d623524 2785->2786 2786->2728 2787 7ff68d6243b0 2788 7ff68d6243b9 2787->2788 2789 7ff68d6243ca 2787->2789 2788->2789 2790 7ff68d6243c5 free 2788->2790 2790->2789 2791 7ff68d621630 2794 7ff68d623d50 2791->2794 2795 7ff68d62164c 2794->2795 2796 7ff68d623d5f free 2794->2796 2796->2795 2966 7ff68d622970 2969 7ff68d622da0 2966->2969 2970 7ff68d622979 2969->2970 2971 7ff68d622dc3 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 2969->2971 2971->2970 2979 7ff68d627372 2980 7ff68d6243d0 _CreateFrameInfo 10 API calls 2979->2980 2981 7ff68d627389 2980->2981 2982 7ff68d6243d0 _CreateFrameInfo 10 API calls 2981->2982 2983 7ff68d6273a4 2982->2983 2984 7ff68d6243d0 _CreateFrameInfo 10 API calls 2983->2984 2985 7ff68d6273ad 2984->2985 2986 7ff68d625414 __GSHandlerCheck_EH 31 API calls 2985->2986 2987 7ff68d6273f3 2986->2987 2988 7ff68d6243d0 _CreateFrameInfo 10 API calls 2987->2988 2989 7ff68d6273f8 2988->2989 2990 7ff68d625f75 2998 7ff68d625e35 __GSHandlerCheck_EH 2990->2998 2991 7ff68d625f92 2992 7ff68d6243d0 _CreateFrameInfo 10 API calls 2991->2992 2993 7ff68d625f97 2992->2993 2994 7ff68d625fa2 2993->2994 2995 7ff68d6243d0 _CreateFrameInfo 10 API calls 2993->2995 2996 7ff68d622660 __GSHandlerCheck_EH 8 API calls 2994->2996 2995->2994 2997 7ff68d625fb5 2996->2997 2998->2991 2999 7ff68d623bd0 __GSHandlerCheck_EH 10 API calls 2998->2999 2999->2998 3000 7ff68d6274d6 3001 7ff68d623b54 11 API calls 3000->3001 3005 7ff68d6274e9 3001->3005 3002 7ff68d62751a __GSHandlerCheck_EH 3003 7ff68d6243d0 _CreateFrameInfo 10 API calls 3002->3003 3004 7ff68d62752e 3003->3004 3006 7ff68d6243d0 _CreateFrameInfo 10 API calls 3004->3006 3005->3002 3007 7ff68d624104 10 API calls 3005->3007 3008 7ff68d62753b 3006->3008 3007->3002 3009 7ff68d6243d0 _CreateFrameInfo 10 API calls 3008->3009 3010 7ff68d627548 3009->3010 3011 7ff68d627559 3014 7ff68d624158 3011->3014 3015 7ff68d624170 3014->3015 3016 7ff68d624182 3014->3016 3015->3016 3017 7ff68d624178 3015->3017 3018 7ff68d6243d0 _CreateFrameInfo 10 API calls 3016->3018 3019 7ff68d624180 3017->3019 3021 7ff68d6243d0 _CreateFrameInfo 10 API calls 3017->3021 3020 7ff68d624187 3018->3020 3020->3019 3022 7ff68d6243d0 _CreateFrameInfo 10 API calls 3020->3022 3023 7ff68d6241a7 3021->3023 3022->3019 3024 7ff68d6243d0 _CreateFrameInfo 10 API calls 3023->3024 3025 7ff68d6241b4 terminate 3024->3025 2797 7ff68d621b18 _time64 2798 7ff68d621b34 2797->2798 2798->2798 2799 7ff68d621bf1 2798->2799 2813 7ff68d621ee0 2798->2813 2802 7ff68d621c34 BuildCatchObjectHelperInternal 2799->2802 2827 7ff68d622230 2799->2827 2803 7ff68d6218a0 2802->2803 2804 7ff68d621da2 _invalid_parameter_noinfo_noreturn 2802->2804 2808 7ff68d621dd0 2803->2808 2809 7ff68d621d76 2803->2809 2810 7ff68d6220c0 21 API calls 2803->2810 2805 7ff68d621da9 WSAGetLastError 2804->2805 2806 7ff68d621450 6 API calls 2805->2806 2806->2809 2807 7ff68d622660 __GSHandlerCheck_EH 8 API calls 2811 7ff68d621d87 2807->2811 2812 7ff68d621450 6 API calls 2808->2812 2809->2807 2810->2803 2812->2809 2814 7ff68d621f04 BuildCatchObjectHelperInternal 2813->2814 2818 7ff68d621f25 2813->2818 2814->2799 2815 7ff68d622031 2816 7ff68d6217e0 21 API calls 2815->2816 2819 7ff68d622036 2816->2819 2817 7ff68d621f74 2817->2819 2821 7ff68d622690 5 API calls 2817->2821 2818->2815 2818->2817 2820 7ff68d621fa9 2818->2820 2822 7ff68d621720 Concurrency::cancel_current_task 4 API calls 2819->2822 2824 7ff68d622690 5 API calls 2820->2824 2826 7ff68d621f92 BuildCatchObjectHelperInternal 2820->2826 2821->2826 2825 7ff68d62203c 2822->2825 2823 7ff68d62202a _invalid_parameter_noinfo_noreturn 2823->2815 2824->2826 2826->2814 2826->2823 2828 7ff68d6223ab 2827->2828 2829 7ff68d62225e 2827->2829 2831 7ff68d6217e0 21 API calls 2828->2831 2830 7ff68d6222be 2829->2830 2833 7ff68d6222e6 2829->2833 2834 7ff68d6222b1 2829->2834 2835 7ff68d622690 5 API calls 2830->2835 2832 7ff68d6223b0 2831->2832 2836 7ff68d621720 Concurrency::cancel_current_task 4 API calls 2832->2836 2838 7ff68d622690 5 API calls 2833->2838 2840 7ff68d6222cf BuildCatchObjectHelperInternal 2833->2840 2834->2830 2834->2832 2835->2840 2839 7ff68d6223b6 2836->2839 2837 7ff68d622364 _invalid_parameter_noinfo_noreturn 2841 7ff68d622357 BuildCatchObjectHelperInternal 2837->2841 2838->2840 2840->2837 2840->2841 2841->2802 2842 7ff68d62191a 2843 7ff68d62194d 2842->2843 2845 7ff68d6218a0 2842->2845 2844 7ff68d6220c0 21 API calls 2843->2844 2844->2845 2847 7ff68d621dd0 2845->2847 2848 7ff68d6220c0 21 API calls 2845->2848 2851 7ff68d621d76 2845->2851 2846 7ff68d622660 __GSHandlerCheck_EH 8 API calls 2849 7ff68d621d87 2846->2849 2850 7ff68d621450 6 API calls 2847->2850 2848->2845 2850->2851 2851->2846 2852 7ff68d62291a 2853 7ff68d623020 __scrt_is_managed_app GetModuleHandleW 2852->2853 2854 7ff68d622921 2853->2854 2855 7ff68d622960 _exit 2854->2855 2856 7ff68d622925 2854->2856 3026 7ff68d62195f 3027 7ff68d62196d 3026->3027 3028 7ff68d621a23 3027->3028 3029 7ff68d621ee0 22 API calls 3027->3029 3030 7ff68d622230 22 API calls 3028->3030 3031 7ff68d621a67 BuildCatchObjectHelperInternal 3028->3031 3029->3028 3030->3031 3032 7ff68d621da2 _invalid_parameter_noinfo_noreturn 3031->3032 3033 7ff68d6218a0 3031->3033 3034 7ff68d621da9 WSAGetLastError 3032->3034 3037 7ff68d621dd0 3033->3037 3038 7ff68d6220c0 21 API calls 3033->3038 3041 7ff68d621d76 3033->3041 3035 7ff68d621450 6 API calls 3034->3035 3035->3041 3036 7ff68d622660 __GSHandlerCheck_EH 8 API calls 3039 7ff68d621d87 3036->3039 3040 7ff68d621450 6 API calls 3037->3040 3038->3033 3040->3041 3041->3036 3042 7ff68d625860 3043 7ff68d6243d0 _CreateFrameInfo 10 API calls 3042->3043 3044 7ff68d6258ad 3043->3044 3045 7ff68d6243d0 _CreateFrameInfo 10 API calls 3044->3045 3046 7ff68d6258bb __except_validate_context_record 3045->3046 3047 7ff68d6243d0 _CreateFrameInfo 10 API calls 3046->3047 3048 7ff68d625914 3047->3048 3049 7ff68d6243d0 _CreateFrameInfo 10 API calls 3048->3049 3050 7ff68d62591d 3049->3050 3051 7ff68d6243d0 _CreateFrameInfo 10 API calls 3050->3051 3052 7ff68d625926 3051->3052 3071 7ff68d623b18 3052->3071 3055 7ff68d6243d0 _CreateFrameInfo 10 API calls 3056 7ff68d625959 3055->3056 3057 7ff68d625aa9 abort 3056->3057 3058 7ff68d625991 3056->3058 3059 7ff68d623b54 11 API calls 3058->3059 3063 7ff68d625a31 3059->3063 3060 7ff68d625a5a __GSHandlerCheck_EH 3061 7ff68d6243d0 _CreateFrameInfo 10 API calls 3060->3061 3062 7ff68d625a6d 3061->3062 3064 7ff68d6243d0 _CreateFrameInfo 10 API calls 3062->3064 3063->3060 3065 7ff68d624104 10 API calls 3063->3065 3066 7ff68d625a76 3064->3066 3065->3060 3067 7ff68d6243d0 _CreateFrameInfo 10 API calls 3066->3067 3068 7ff68d625a7f 3067->3068 3069 7ff68d6243d0 _CreateFrameInfo 10 API calls 3068->3069 3070 7ff68d625a8e 3069->3070 3072 7ff68d6243d0 _CreateFrameInfo 10 API calls 3071->3072 3073 7ff68d623b29 3072->3073 3074 7ff68d623b34 3073->3074 3075 7ff68d6243d0 _CreateFrameInfo 10 API calls 3073->3075 3076 7ff68d6243d0 _CreateFrameInfo 10 API calls 3074->3076 3075->3074 3077 7ff68d623b45 3076->3077 3077->3055 3077->3056 3078 7ff68d627260 3079 7ff68d627280 3078->3079 3080 7ff68d627273 3078->3080 3081 7ff68d621e80 _invalid_parameter_noinfo_noreturn 3080->3081 3081->3079 3082 7ff68d621ce0 3083 7ff68d622688 5 API calls 3082->3083 3084 7ff68d621cea gethostname 3083->3084 3085 7ff68d621da9 WSAGetLastError 3084->3085 3086 7ff68d621d08 3084->3086 3087 7ff68d621450 6 API calls 3085->3087 3096 7ff68d622040 3086->3096 3089 7ff68d621d76 3087->3089 3090 7ff68d622660 __GSHandlerCheck_EH 8 API calls 3089->3090 3091 7ff68d621d87 3090->3091 3092 7ff68d6218a0 3092->3089 3093 7ff68d621dd0 3092->3093 3094 7ff68d6220c0 21 API calls 3092->3094 3095 7ff68d621450 6 API calls 3093->3095 3094->3092 3095->3089 3097 7ff68d622063 BuildCatchObjectHelperInternal 3096->3097 3098 7ff68d6220a2 3096->3098 3097->3092 3099 7ff68d622230 22 API calls 3098->3099 3100 7ff68d6220b5 3099->3100 3100->3092 2860 7ff68d624024 2867 7ff68d62642c 2860->2867 2866 7ff68d624031 2879 7ff68d626714 2867->2879 2870 7ff68d62402d 2870->2866 2872 7ff68d6244ac 2870->2872 2871 7ff68d626460 __vcrt_uninitialize_locks DeleteCriticalSection 2871->2870 2884 7ff68d6265e8 2872->2884 2880 7ff68d626498 __vcrt_InitializeCriticalSectionEx 5 API calls 2879->2880 2881 7ff68d62674a 2880->2881 2882 7ff68d62675f InitializeCriticalSectionAndSpinCount 2881->2882 2883 7ff68d626444 2881->2883 2882->2883 2883->2870 2883->2871 2885 7ff68d626498 __vcrt_InitializeCriticalSectionEx 5 API calls 2884->2885 2886 7ff68d62660d TlsAlloc 2885->2886 3104 7ff68d6248c7 abort 2888 7ff68d627411 2889 7ff68d627495 2888->2889 2890 7ff68d627429 2888->2890 2890->2889 2891 7ff68d6243d0 _CreateFrameInfo 10 API calls 2890->2891 2892 7ff68d627476 2891->2892 2893 7ff68d6243d0 _CreateFrameInfo 10 API calls 2892->2893 2894 7ff68d62748b terminate 2893->2894 2894->2889 2911 7ff68d627090 2912 7ff68d6270d2 __GSHandlerCheckCommon 2911->2912 2913 7ff68d6270fa 2912->2913 2915 7ff68d623d78 2912->2915 2916 7ff68d623da8 _IsNonwritableInCurrentImage __C_specific_handler __except_validate_context_record 2915->2916 2917 7ff68d623e99 2916->2917 2918 7ff68d623e64 RtlUnwindEx 2916->2918 2917->2913 2918->2916 2898 7ff68d623090 2899 7ff68d6230a8 2898->2899 2900 7ff68d6230c4 2898->2900 2899->2900 2905 7ff68d6241c0 2899->2905 2904 7ff68d6230e2 2906 7ff68d6243d0 _CreateFrameInfo 10 API calls 2905->2906 2907 7ff68d6230d6 2906->2907 2908 7ff68d6241d4 2907->2908 2909 7ff68d6243d0 _CreateFrameInfo 10 API calls 2908->2909 2910 7ff68d6241dd 2909->2910 2910->2904 2919 7ff68d627290 2920 7ff68d6272b0 2919->2920 2921 7ff68d6272a3 2919->2921 2923 7ff68d621e80 2921->2923 2924 7ff68d621e93 2923->2924 2925 7ff68d621eb7 2923->2925 2924->2925 2926 7ff68d621ed8 _invalid_parameter_noinfo_noreturn 2924->2926 2925->2920 2927 7ff68d621510 2928 7ff68d623cc0 __std_exception_copy 2 API calls 2927->2928 2929 7ff68d621539 2928->2929 3105 7ff68d621550 3106 7ff68d623d50 __std_exception_destroy free 3105->3106 3107 7ff68d621567 3106->3107 3108 7ff68d6227d0 3112 7ff68d623074 SetUnhandledExceptionFilter 3108->3112 3113 7ff68d621d39 3114 7ff68d621d40 3113->3114 3114->3114 3115 7ff68d622040 22 API calls 3114->3115 3117 7ff68d6218a0 3114->3117 3115->3117 3116 7ff68d621d76 3118 7ff68d622660 __GSHandlerCheck_EH 8 API calls 3116->3118 3117->3116 3119 7ff68d621dd0 3117->3119 3120 7ff68d6220c0 21 API calls 3117->3120 3121 7ff68d621d87 3118->3121 3122 7ff68d621450 6 API calls 3119->3122 3120->3117 3122->3116 3123 7ff68d62733c _seh_filter_exe 2939 7ff68d622700 2940 7ff68d622710 2939->2940 2952 7ff68d622bd8 2940->2952 2942 7ff68d622ecc 7 API calls 2943 7ff68d6227b5 2942->2943 2944 7ff68d622734 _RTC_Initialize 2949 7ff68d622797 2944->2949 2960 7ff68d622e64 InitializeSListHead 2944->2960 2949->2942 2951 7ff68d6227a5 2949->2951 2953 7ff68d622be9 2952->2953 2954 7ff68d622c1b 2952->2954 2955 7ff68d622c58 2953->2955 2958 7ff68d622bee __scrt_release_startup_lock 2953->2958 2954->2944 2956 7ff68d622ecc 7 API calls 2955->2956 2957 7ff68d622c62 2956->2957 2958->2954 2959 7ff68d622c0b _initialize_onexit_table 2958->2959 2959->2954

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 0 7ff68d621060-7ff68d6210ae 1 7ff68d621386-7ff68d621394 call 7ff68d621450 0->1 2 7ff68d6210b4-7ff68d6210c6 0->2 5 7ff68d621399 1->5 4 7ff68d6210d0-7ff68d6210d6 2->4 6 7ff68d6210dc-7ff68d6210df 4->6 7 7ff68d62127f-7ff68d621283 4->7 10 7ff68d62139e-7ff68d6213b7 5->10 8 7ff68d6210ed 6->8 9 7ff68d6210e1-7ff68d6210e5 6->9 7->4 11 7ff68d621289-7ff68d621299 7->11 13 7ff68d6210f0-7ff68d6210fc 8->13 9->8 12 7ff68d6210e7-7ff68d6210eb 9->12 11->1 14 7ff68d62129f-7ff68d6212b7 call 7ff68d622688 11->14 12->8 15 7ff68d621104-7ff68d62110b 12->15 16 7ff68d6210fe-7ff68d621102 13->16 17 7ff68d621110-7ff68d621113 13->17 26 7ff68d6212b9-7ff68d6212c9 GetTempPathA 14->26 27 7ff68d62132a-7ff68d621336 call 7ff68d6223c0 14->27 19 7ff68d62127b 15->19 16->13 16->15 20 7ff68d621125-7ff68d621136 strcmp 17->20 21 7ff68d621115-7ff68d621119 17->21 19->7 24 7ff68d621267-7ff68d62126e 20->24 25 7ff68d62113c-7ff68d62113f 20->25 21->20 23 7ff68d62111b-7ff68d62111f 21->23 23->20 23->24 30 7ff68d621276 24->30 31 7ff68d621151-7ff68d621162 strcmp 25->31 32 7ff68d621141-7ff68d621145 25->32 28 7ff68d6212e9-7ff68d621302 strcat_s 26->28 29 7ff68d6212cb-7ff68d6212e7 GetLastError call 7ff68d621450 GetLastError 26->29 43 7ff68d621346 27->43 44 7ff68d621338-7ff68d621344 call 7ff68d6213c0 27->44 35 7ff68d621325 28->35 36 7ff68d621304-7ff68d621312 call 7ff68d621450 28->36 51 7ff68d621313-7ff68d621323 call 7ff68d622680 29->51 30->19 39 7ff68d621258-7ff68d621265 31->39 40 7ff68d621168-7ff68d62116b 31->40 32->31 37 7ff68d621147-7ff68d62114b 32->37 35->27 36->51 37->31 37->39 39->19 45 7ff68d62117d-7ff68d62118e strcmp 40->45 46 7ff68d62116d-7ff68d621171 40->46 48 7ff68d62134b-7ff68d621384 __acrt_iob_func fflush __acrt_iob_func fflush call 7ff68d622680 43->48 44->48 49 7ff68d621247-7ff68d621256 45->49 50 7ff68d621194-7ff68d621197 45->50 46->45 47 7ff68d621173-7ff68d621177 46->47 47->45 47->49 48->10 49->30 56 7ff68d621199-7ff68d62119d 50->56 57 7ff68d6211a5-7ff68d6211af 50->57 51->10 56->57 60 7ff68d62119f-7ff68d6211a3 56->60 61 7ff68d6211b0-7ff68d6211bb 57->61 60->57 63 7ff68d6211c3-7ff68d6211d2 60->63 64 7ff68d6211d7-7ff68d6211da 61->64 65 7ff68d6211bd-7ff68d6211c1 61->65 63->30 66 7ff68d6211ec-7ff68d6211f6 64->66 67 7ff68d6211dc-7ff68d6211e0 64->67 65->61 65->63 69 7ff68d621200-7ff68d62120b 66->69 67->66 68 7ff68d6211e2-7ff68d6211e6 67->68 68->19 68->66 70 7ff68d62120d-7ff68d621211 69->70 71 7ff68d621215-7ff68d621218 69->71 70->69 74 7ff68d621213 70->74 72 7ff68d621226-7ff68d621237 strcmp 71->72 73 7ff68d62121a-7ff68d62121e 71->73 72->19 76 7ff68d621239-7ff68d621245 atoi 72->76 73->72 75 7ff68d621220-7ff68d621224 73->75 74->19 75->19 75->72 76->19
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: strcmp$ErrorLast__acrt_iob_funcfflush$PathTempatoistrcat_s
    • String ID: -$-$-$-$-$-$-$--diag$--full$--name$--normal$--triage$--verbose$--withheap$Dump successfully written$GetTempPath failed (0x%08x)$createdump [options] pid-f, --name - dump path and file name. The default is '%TEMP%\dump.%p.dmp'. These specifiers are substituted with following values: %p PID of dumped process. %e The process executable filename. %h Hostname return by gethostn$dump.%p.dmp$full dump$minidump$minidump with heap$strcat_s failed (%d)$triage minidump$v
    • API String ID: 2647627392-2367407095
    • Opcode ID: 3e8843d71ddd811f5735ae345386871f6517bdd5673e2455e3aa9b185965a2cd
    • Instruction ID: 422f4f4dd16e3cc89b1fbc0356baa7bf626563202deaa246fa9b8f526d289b1d
    • Opcode Fuzzy Hash: 3e8843d71ddd811f5735ae345386871f6517bdd5673e2455e3aa9b185965a2cd
    • Instruction Fuzzy Hash: 56A19062D4C68AD1FB618F20A4042B927A4BF4E75CF08413AD94EC6695FE3CE4CCE320
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: __p___argc__p___argv__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_is_managed_app__scrt_release_startup_lock_cexit_exit_get_initial_narrow_environment_register_thread_local_exe_atexit_callback
    • String ID:
    • API String ID: 2308368977-0
    • Opcode ID: 5a9b20bb9eaae0def914decdfc47a4fcc48693c8541f2657ef11ecffac799aa6
    • Instruction ID: a9148991be512e24a98630447b737cbfc8de061dc7c5b296a1bbda13da08b513
    • Opcode Fuzzy Hash: 5a9b20bb9eaae0def914decdfc47a4fcc48693c8541f2657ef11ecffac799aa6
    • Instruction Fuzzy Hash: 2B310B21E8824BC1EA14AB2194513BD2251BF5D78CF44503DD56DCB2A7EE2DE9CCE270
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: __acrt_iob_func$__stdio_common_vfprintf$fflushfprintf
    • String ID: [createdump]
    • API String ID: 3735572767-2657508301
    • Opcode ID: f7b41b5d75985a22341ebafe60962d777547180dfe076665e84a48d8af4ee52e
    • Instruction ID: 7397e6e9dd91c9c0343afb538b17830f9be40da9a899d905dfa91f6971399d46
    • Opcode Fuzzy Hash: f7b41b5d75985a22341ebafe60962d777547180dfe076665e84a48d8af4ee52e
    • Instruction Fuzzy Hash: 80014B21E09B96C2E600DB50F80556AA364FF88BE9F004539EA8D83769EF3CD499D750
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
    • String ID:
    • API String ID: 3140674995-0
    • Opcode ID: 92083fc3b2590fb7f42fdf2bff26a09e0be32edceb9cda99800bf26d983c5eac
    • Instruction ID: 7165d58efd951d6b242a3f5ed6d1a2ab6eb099de05c32bbcfb76e13224425637
    • Opcode Fuzzy Hash: 92083fc3b2590fb7f42fdf2bff26a09e0be32edceb9cda99800bf26d983c5eac
    • Instruction Fuzzy Hash: 89316F72A09A85C6EB608F60E8403EE7361FF58758F40403DDA4E87A98EF38D58CD724
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 8c8a5ce5a61a9accbe9d72245b7862f6c7c599a8b634bc8698eb0ff17e984138
    • Instruction ID: 2faf0e5035b4d32ee41e73e66e5f0fcda88ba9c0d81f6dea78699e30f76c8b59
    • Opcode Fuzzy Hash: 8c8a5ce5a61a9accbe9d72245b7862f6c7c599a8b634bc8698eb0ff17e984138
    • Instruction Fuzzy Hash: 75A00121D0C80AD0E6448B10A8545252320FF58B18F404439D00D810A0EF3CA488E224
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • OpenProcess.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF68D62242D
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF68D62243B
      • Part of subcall function 00007FF68D621450: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D621475
      • Part of subcall function 00007FF68D621450: fprintf.MSPDB140-MSVCRT ref: 00007FF68D621485
      • Part of subcall function 00007FF68D621450: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D621494
      • Part of subcall function 00007FF68D621450: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D6214B3
      • Part of subcall function 00007FF68D621450: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D6214BE
      • Part of subcall function 00007FF68D621450: fflush.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D6214C7
    • K32GetModuleBaseNameA.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF68D622466
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF68D622470
    • CloseHandle.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF68D622487
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FF68D6225F3
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: __acrt_iob_func$ErrorLast$BaseCloseHandleModuleNameOpenProcess__stdio_common_vfprintf_invalid_parameter_noinfo_noreturnfflushfprintf
    • String ID: Get process name FAILED %d$Invalid dump path '%s' error %d$Invalid process id '%d' error %d$Write dump FAILED 0x%08x$Writing %s to file %s
    • API String ID: 3971781330-1292085346
    • Opcode ID: 8ec448eeb6e8f02312a1538d84a3c8dfc991fc7cafdc13e8cd0ded943aea62a7
    • Instruction ID: fabf372df4b2ab5dfefb49ef5e333ec670e3d0bc4e7c7a921a938e3369e941e7
    • Opcode Fuzzy Hash: 8ec448eeb6e8f02312a1538d84a3c8dfc991fc7cafdc13e8cd0ded943aea62a7
    • Instruction Fuzzy Hash: 71618431E08A45C1E6109B15E85067A7761FF8D7A8F504138EEAD83AA9EF3CE4C9E750
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 177 7ff68d6249a4-7ff68d624a07 call 7ff68d624518 180 7ff68d624a09-7ff68d624a12 call 7ff68d6243d0 177->180 181 7ff68d624a20-7ff68d624a29 call 7ff68d6243d0 177->181 188 7ff68d624e99-7ff68d624e9f abort 180->188 189 7ff68d624a18-7ff68d624a1e 180->189 186 7ff68d624a2b-7ff68d624a38 call 7ff68d6243d0 * 2 181->186 187 7ff68d624a3f-7ff68d624a42 181->187 186->187 187->188 191 7ff68d624a48-7ff68d624a54 187->191 189->187 193 7ff68d624a56-7ff68d624a7d 191->193 194 7ff68d624a7f 191->194 196 7ff68d624a81-7ff68d624a83 193->196 194->196 196->188 198 7ff68d624a89-7ff68d624a8f 196->198 199 7ff68d624b59-7ff68d624b6f call 7ff68d625724 198->199 200 7ff68d624a95-7ff68d624a99 198->200 205 7ff68d624def-7ff68d624df3 199->205 206 7ff68d624b75-7ff68d624b79 199->206 200->199 202 7ff68d624a9f-7ff68d624aaa 200->202 202->199 204 7ff68d624ab0-7ff68d624ab5 202->204 204->199 207 7ff68d624abb-7ff68d624ac5 call 7ff68d6243d0 204->207 209 7ff68d624e2b-7ff68d624e35 call 7ff68d6243d0 205->209 210 7ff68d624df5-7ff68d624dfc 205->210 206->205 211 7ff68d624b7f-7ff68d624b8a 206->211 218 7ff68d624e37-7ff68d624e56 call 7ff68d622660 207->218 219 7ff68d624acb-7ff68d624af1 call 7ff68d6243d0 * 2 call 7ff68d623be8 207->219 209->188 209->218 210->188 214 7ff68d624e02-7ff68d624e26 call 7ff68d624ea0 210->214 211->205 212 7ff68d624b90-7ff68d624b94 211->212 216 7ff68d624b9a-7ff68d624bd1 call 7ff68d6236d0 212->216 217 7ff68d624dd4-7ff68d624dd8 212->217 214->209 216->217 231 7ff68d624bd7-7ff68d624be2 216->231 217->209 225 7ff68d624dda-7ff68d624de7 call 7ff68d623670 217->225 246 7ff68d624b11-7ff68d624b1b call 7ff68d6243d0 219->246 247 7ff68d624af3-7ff68d624af7 219->247 233 7ff68d624ded 225->233 234 7ff68d624e81-7ff68d624e98 call 7ff68d6243d0 * 2 terminate 225->234 235 7ff68d624be6-7ff68d624bf6 231->235 233->209 234->188 238 7ff68d624bfc-7ff68d624c02 235->238 239 7ff68d624d2f-7ff68d624dce 235->239 238->239 242 7ff68d624c08-7ff68d624c31 call 7ff68d6256a8 238->242 239->217 239->235 242->239 252 7ff68d624c37-7ff68d624c7e call 7ff68d623bbc * 2 242->252 246->199 256 7ff68d624b1d-7ff68d624b3d call 7ff68d6243d0 * 2 call 7ff68d625fd8 246->256 247->246 250 7ff68d624af9-7ff68d624b04 247->250 250->246 253 7ff68d624b06-7ff68d624b0b 250->253 264 7ff68d624cba-7ff68d624cd0 call 7ff68d625ab0 252->264 265 7ff68d624c80-7ff68d624ca5 call 7ff68d623bbc call 7ff68d6252d0 252->265 253->188 253->246 273 7ff68d624b3f-7ff68d624b49 call 7ff68d6260c8 256->273 274 7ff68d624b54 256->274 275 7ff68d624d2b 264->275 276 7ff68d624cd2 264->276 279 7ff68d624cd7-7ff68d624d26 call 7ff68d6248d0 265->279 280 7ff68d624ca7-7ff68d624cb3 265->280 283 7ff68d624e7b-7ff68d624e80 terminate 273->283 284 7ff68d624b4f-7ff68d624e7a call 7ff68d624090 call 7ff68d625838 call 7ff68d623f84 273->284 274->199 275->239 276->252 279->275 280->265 282 7ff68d624cb5 280->282 282->264 283->234 284->283
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: terminate$Is_bad_exception_allowedabortstd::bad_alloc::bad_alloc
    • String ID: csm$csm$csm
    • API String ID: 695522112-393685449
    • Opcode ID: b33eca4017884e99d2f222704934a1d2e619e74398d1b95ed41b8d3f9756be10
    • Instruction ID: ce098630ab923f46a2e9381368767b83fe84b55effeeb3655adbce58bf4dfa51
    • Opcode Fuzzy Hash: b33eca4017884e99d2f222704934a1d2e619e74398d1b95ed41b8d3f9756be10
    • Instruction Fuzzy Hash: 1FE17072E0868ACAE7209F25D4803AD77A0FF6875CF144139DA8D87696EF38E5C9D710
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: __acrt_iob_func$__stdio_common_vfprintf$fflushfprintf
    • String ID: [createdump]
    • API String ID: 3735572767-2657508301
    • Opcode ID: 5b675bc39e039bc525fd467c26ca74d7b5bd1981a0b88a155956b168aee24ed4
    • Instruction ID: 38609c689cffe1994c0bee94e5606065d006499437cb01a7ef6065eee9a19223
    • Opcode Fuzzy Hash: 5b675bc39e039bc525fd467c26ca74d7b5bd1981a0b88a155956b168aee24ed4
    • Instruction Fuzzy Hash: 61012C31E09B86C2E7009B50F8145AAA360FF88BE9F004539DA8D43765EF7CD4D9D750
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • WSAStartup.WS2_32 ref: 00007FF68D62186C
      • Part of subcall function 00007FF68D621450: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D621475
      • Part of subcall function 00007FF68D621450: fprintf.MSPDB140-MSVCRT ref: 00007FF68D621485
      • Part of subcall function 00007FF68D621450: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D621494
      • Part of subcall function 00007FF68D621450: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D6214B3
      • Part of subcall function 00007FF68D621450: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D6214BE
      • Part of subcall function 00007FF68D621450: fflush.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D6214C7
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: __acrt_iob_func$Startup__stdio_common_vfprintffflushfprintf
    • String ID: %%%%%%%%$%%%%%%%%$--name$Invalid dump name format char '%c'$Pipe syntax in dump name not supported
    • API String ID: 3378602911-3973674938
    • Opcode ID: 6d691e12a95190b73438bc01f861d361a60469c0dc3d28550e2b0afd423a51ff
    • Instruction ID: 14b05bb425bf380ff5a69c1325e10cdf7ff32224b4d78e46172d2a244a9c9af9
    • Opcode Fuzzy Hash: 6d691e12a95190b73438bc01f861d361a60469c0dc3d28550e2b0afd423a51ff
    • Instruction Fuzzy Hash: 8F31E062E0CA89D6E7598F1598947F92762BF4D788F44043ADE4D472D1EE3CE18DE320
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • LoadLibraryExW.KERNEL32(00000000,?,00000000,00007FF68D62669F,?,?,?,00007FF68D62441E,?,?,?,00007FF68D6243D9), ref: 00007FF68D62651D
    • GetLastError.KERNEL32(?,00000000,00007FF68D62669F,?,?,?,00007FF68D62441E,?,?,?,00007FF68D6243D9,?,?,?,?,00007FF68D623524), ref: 00007FF68D62652B
    • LoadLibraryExW.KERNEL32(?,00000000,00007FF68D62669F,?,?,?,00007FF68D62441E,?,?,?,00007FF68D6243D9,?,?,?,?,00007FF68D623524), ref: 00007FF68D626555
    • FreeLibrary.KERNEL32(?,00000000,00007FF68D62669F,?,?,?,00007FF68D62441E,?,?,?,00007FF68D6243D9,?,?,?,?,00007FF68D623524), ref: 00007FF68D62659B
    • GetProcAddress.KERNEL32(?,00000000,00007FF68D62669F,?,?,?,00007FF68D62441E,?,?,?,00007FF68D6243D9,?,?,?,?,00007FF68D623524), ref: 00007FF68D6265A7
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: Library$Load$AddressErrorFreeLastProc
    • String ID: api-ms-
    • API String ID: 2559590344-2084034818
    • Opcode ID: 91eaabdab86b5d7484fb536d38c8d26551698fbc6984510a5f5d6d43d06b7795
    • Instruction ID: 6148c598ad12b669283e6dc271fb410faba13aa0d1a720ebbe694c8df34b43f7
    • Opcode Fuzzy Hash: 91eaabdab86b5d7484fb536d38c8d26551698fbc6984510a5f5d6d43d06b7795
    • Instruction Fuzzy Hash: E231B021E1A60AC1FE219B4298009792394FF4CBA9F194638DD1D9A398FF3CE4C8D320
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 360 7ff68d621b18-7ff68d621b32 _time64 361 7ff68d621b80-7ff68d621ba8 360->361 362 7ff68d621b34-7ff68d621b37 360->362 361->361 364 7ff68d621baa-7ff68d621bd8 361->364 363 7ff68d621b40-7ff68d621b68 362->363 363->363 367 7ff68d621b6a-7ff68d621b71 363->367 365 7ff68d621bfa-7ff68d621c32 364->365 366 7ff68d621bda-7ff68d621bf5 call 7ff68d621ee0 364->366 369 7ff68d621c64-7ff68d621c78 call 7ff68d622230 365->369 370 7ff68d621c34-7ff68d621c43 365->370 366->365 367->364 378 7ff68d621c7d-7ff68d621c88 369->378 372 7ff68d621c48-7ff68d621c62 call 7ff68d6268c0 370->372 373 7ff68d621c45 370->373 372->378 373->372 379 7ff68d621cbb-7ff68d621cde 378->379 380 7ff68d621c8a-7ff68d621c98 378->380 381 7ff68d621d55-7ff68d621d70 379->381 382 7ff68d621c9a-7ff68d621cad 380->382 383 7ff68d621cb3-7ff68d621cb6 call 7ff68d622680 380->383 387 7ff68d621d76 381->387 388 7ff68d6218a0-7ff68d6218a3 381->388 382->383 386 7ff68d621da2-7ff68d621dce _invalid_parameter_noinfo_noreturn WSAGetLastError call 7ff68d621450 call 7ff68d622680 382->386 383->379 392 7ff68d621d78-7ff68d621da1 call 7ff68d622660 386->392 387->392 390 7ff68d6218f3-7ff68d6218fe 388->390 391 7ff68d6218a5-7ff68d6218b7 388->391 397 7ff68d621dd0-7ff68d621dde call 7ff68d621450 390->397 398 7ff68d621904-7ff68d621915 390->398 394 7ff68d6218b9-7ff68d6218c8 391->394 395 7ff68d6218e2-7ff68d6218ee call 7ff68d6220c0 391->395 400 7ff68d6218ca 394->400 401 7ff68d6218cd-7ff68d6218dd 394->401 395->381 397->392 398->381 400->401 401->381
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: _time64
    • String ID: %%%%%%%%$Could not get the host name for dump name: %d
    • API String ID: 1670930206-4114407318
    • Opcode ID: 30f253d6cb86930f70187238c9af70fef4a32202514a54efb800f102df6d23dc
    • Instruction ID: ec2bd4c815a85976125a9caeb3ccaaab96c031d3276af1caea963c181881c411
    • Opcode Fuzzy Hash: 30f253d6cb86930f70187238c9af70fef4a32202514a54efb800f102df6d23dc
    • Instruction Fuzzy Hash: 0751E562E18B89C6EB00CB28D4403AA6761FF497D8F400139DA5D57BE9EF3CD089E350
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: EncodePointerabort
    • String ID: MOC$RCC
    • API String ID: 1188231555-2084237596
    • Opcode ID: 97abe66515cb1414aeefc8003222462485e27fa84eefc4111ad6d0138f6fd2ea
    • Instruction ID: af416642cca3e6fb705644aadb2ee8dc315cecee70e6b2cc252e18604db7f150
    • Opcode Fuzzy Hash: 97abe66515cb1414aeefc8003222462485e27fa84eefc4111ad6d0138f6fd2ea
    • Instruction Fuzzy Hash: EE919273E08B8ACAE710CB65D8802AD77A0FB4878CF144129EA8D97755EF38D199DB50
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 459 7ff68d625414-7ff68d625461 call 7ff68d6263f4 call 7ff68d6243d0 464 7ff68d62548e-7ff68d625492 459->464 465 7ff68d625463-7ff68d625469 459->465 467 7ff68d625498-7ff68d62549b 464->467 468 7ff68d6255b2-7ff68d6255c7 call 7ff68d625724 464->468 465->464 466 7ff68d62546b-7ff68d62546e 465->466 469 7ff68d625480-7ff68d625483 466->469 470 7ff68d625470-7ff68d625474 466->470 471 7ff68d6254a1-7ff68d6254d1 467->471 472 7ff68d625680 467->472 479 7ff68d6255c9-7ff68d6255cc 468->479 480 7ff68d6255d2-7ff68d6255d8 468->480 469->464 476 7ff68d625485-7ff68d625488 469->476 475 7ff68d625476-7ff68d62547e 470->475 470->476 471->472 477 7ff68d6254d7-7ff68d6254de 471->477 478 7ff68d625685-7ff68d6256a1 472->478 475->464 475->469 476->464 476->472 477->472 481 7ff68d6254e4-7ff68d6254e8 477->481 479->472 479->480 482 7ff68d625647-7ff68d62567b call 7ff68d6249a4 480->482 483 7ff68d6255da-7ff68d6255de 480->483 484 7ff68d62559f-7ff68d6255ad call 7ff68d623678 481->484 485 7ff68d6254ee-7ff68d6254f1 481->485 482->472 483->482 486 7ff68d6255e0-7ff68d6255e7 483->486 484->472 489 7ff68d625556-7ff68d625559 485->489 490 7ff68d6254f3-7ff68d625508 call 7ff68d624520 485->490 486->482 491 7ff68d6255e9-7ff68d6255f0 486->491 489->484 492 7ff68d62555b-7ff68d625563 489->492 497 7ff68d6256a2-7ff68d6256a7 abort 490->497 499 7ff68d62550e-7ff68d625511 490->499 491->482 495 7ff68d6255f2-7ff68d625605 call 7ff68d623bbc 491->495 496 7ff68d625569-7ff68d625593 492->496 492->497 495->482 508 7ff68d625607-7ff68d625645 495->508 496->497 501 7ff68d625599-7ff68d62559d 496->501 502 7ff68d62553a-7ff68d62553d 499->502 503 7ff68d625513-7ff68d625538 499->503 505 7ff68d625546-7ff68d625551 call 7ff68d625cf0 501->505 502->497 506 7ff68d625543 502->506 503->502 505->472 506->505 508->478
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: __except_validate_context_recordabort
    • String ID: csm$csm
    • API String ID: 746414643-3733052814
    • Opcode ID: 1056e810e0031d83590426beccc43492b2f2866ca19cabfb7471893f0b3bcd0b
    • Instruction ID: 013f6a070965ee3ae48e4d9b72580730a518e214a6d2def018c3ab4e472bdd99
    • Opcode Fuzzy Hash: 1056e810e0031d83590426beccc43492b2f2866ca19cabfb7471893f0b3bcd0b
    • Instruction Fuzzy Hash: D871D032A08686CAD7308F21945467A7BA1FF08BDDF048139DE8C87A95EF3CD498D751
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID:
    • String ID: %%%%%%%%$Could not get the host name for dump name: %d
    • API String ID: 0-4114407318
    • Opcode ID: 3a1402493b52144332fc7ef885a246e0bef5bb5eddb931c8bdeb75c83dbb8659
    • Instruction ID: e307dc13598711c8a0546449a52ff3d063777d029ea708295f01cdededfdf8a0
    • Opcode Fuzzy Hash: 3a1402493b52144332fc7ef885a246e0bef5bb5eddb931c8bdeb75c83dbb8659
    • Instruction Fuzzy Hash: A551D422E18B8986E700CB29E4407AA6761FF997D4F400139EA9D47B99DF3DD089E750
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: CreateFrameInfo__except_validate_context_record
    • String ID: csm
    • API String ID: 2558813199-1018135373
    • Opcode ID: 08459d2de849ea082ca6f7467207d0873ef5a0572d3180cf677e49d91fe67cef
    • Instruction ID: 8aa57cb3bff687bd6a8a2b1763fdf00071dfeeb8e51c89b1566c1b71f65b33d3
    • Opcode Fuzzy Hash: 08459d2de849ea082ca6f7467207d0873ef5a0572d3180cf677e49d91fe67cef
    • Instruction Fuzzy Hash: 00516132A1874AC6D6209B16E44126E77B4FF9CBA8F140138DB8D87B55EF7CE4A4DB10
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • std::_Xinvalid_argument.LIBCPMT ref: 00007FF68D6217EB
    • WSAStartup.WS2_32 ref: 00007FF68D62186C
      • Part of subcall function 00007FF68D621450: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D621475
      • Part of subcall function 00007FF68D621450: fprintf.MSPDB140-MSVCRT ref: 00007FF68D621485
      • Part of subcall function 00007FF68D621450: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D621494
      • Part of subcall function 00007FF68D621450: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D6214B3
      • Part of subcall function 00007FF68D621450: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D6214BE
      • Part of subcall function 00007FF68D621450: fflush.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF68D6214C7
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: __acrt_iob_func$StartupXinvalid_argument__stdio_common_vfprintffflushfprintfstd::_
    • String ID: --name$Pipe syntax in dump name not supported$string too long
    • API String ID: 1412700758-3183687674
    • Opcode ID: 937e6b2c28cea08e1eee527b5bf6a7363096d6cc0634c1c423fcc3cad23f2144
    • Instruction ID: 78c70193783c419802effd1067ad34c71884f38ff8fb602f316635776ef7f19b
    • Opcode Fuzzy Hash: 937e6b2c28cea08e1eee527b5bf6a7363096d6cc0634c1c423fcc3cad23f2144
    • Instruction Fuzzy Hash: 5301B122E18989E5F7619F12EC817BA6350BF8C79CF44003AEE4D46651EE3CD4CAD710
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: ErrorLastgethostname
    • String ID: %%%%%%%%$Could not get the host name for dump name: %d
    • API String ID: 3782448640-4114407318
    • Opcode ID: 320cb389b9e396755b8a5578c83a0b73153155c3fa84c5d330cc0819ada1fb95
    • Instruction ID: 9f1a312d07b75c6920cec35188a5e7b0a86fb3250f87ed8fccbe8dc6b442efcc
    • Opcode Fuzzy Hash: 320cb389b9e396755b8a5578c83a0b73153155c3fa84c5d330cc0819ada1fb95
    • Instruction Fuzzy Hash: 1811C411E4C14AC6E6489B21A8507BB2340BF8E7B8F001639D96F976D6ED3CD0CEE360
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: terminate
    • String ID: MOC$RCC$csm
    • API String ID: 1821763600-2671469338
    • Opcode ID: 2eecf08628838b8288b91de4d166118c23004d29b6453832f1ed38693e8fa958
    • Instruction ID: a0965e0427bfb7cc4d3cd0f5746e9d617dc842fb680e5591354944c52c6567a3
    • Opcode Fuzzy Hash: 2eecf08628838b8288b91de4d166118c23004d29b6453832f1ed38693e8fa958
    • Instruction Fuzzy Hash: 1EF08136D0824EC1E3285B51A14607C3264FF6CB4CF185039D7088A252EF7CF5E8EA12
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(-3333333333333333,?,00000000,00007FF68D6218EE), ref: 00007FF68D6221E0
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF68D62221E
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
    • String ID: Invalid process id '%d' error %d
    • API String ID: 73155330-4244389950
    • Opcode ID: bba2875ca5ab07f9a8534c7e54732a79a80581b419c8ee845a73c6edf0a3127c
    • Instruction ID: 910ed1e5ce139f779244dcbea4cb1007f005fd3bccc5b8508c4cf447f8116bef
    • Opcode Fuzzy Hash: bba2875ca5ab07f9a8534c7e54732a79a80581b419c8ee845a73c6edf0a3127c
    • Instruction Fuzzy Hash: 6E310522F49789C5EA148F1195482A963A1BF0DBD8F040639DF6D47BD5EE7CE0D8E320
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF68D62173F), ref: 00007FF68D623FC8
    • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF68D62173F), ref: 00007FF68D62400E
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1649947094.00007FF68D621000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF68D620000, based on PE: true
    • Associated: 00000000.00000002.1649935794.00007FF68D620000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649962124.00007FF68D628000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649976357.00007FF68D62C000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1649988427.00007FF68D62D000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff68d620000_createdump.jbxd
    Similarity
    • API ID: ExceptionFileHeaderRaise
    • String ID: csm
    • API String ID: 2573137834-1018135373
    • Opcode ID: 7531413fd5ba05c8efc2732aab9693bebd0b5d96e62eb0afc70bc4d0601aafd3
    • Instruction ID: d86a01e53bd59eb5990ff582b3a0d4627fbcf8c71cfb66f45492edd3daa7c711
    • Opcode Fuzzy Hash: 7531413fd5ba05c8efc2732aab9693bebd0b5d96e62eb0afc70bc4d0601aafd3
    • Instruction Fuzzy Hash: 73113D32A18B46C2EB108B15F44026977A0FF88B98F184238EF8D47B58EF3DD599C700
    Uniqueness

    Uniqueness Score: -1.00%