Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
grade.exe

Overview

General Information

Sample name:grade.exe
Analysis ID:1430592
MD5:6e57c402199ce6e7bbf5ede13d4a838e
SHA1:69fb871bdb2d0fa0af25107215b5187e1f420ada
SHA256:e3eb252b1b009440c097ba7a40d8b2ccc4e233847dec9e1d6c08c5a4439dcc12
Infos:

Detection

Score:4
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Found potential string decryption / allocating functions
PE file contains sections with non-standard names
Program does not show much activity (idle)
Sample execution stops while process was sleeping (likely an evasion)

Classification

  • System is w10x64
  • grade.exe (PID: 2632 cmdline: "C:\Users\user\Desktop\grade.exe" MD5: 6E57C402199CE6E7BBF5EDE13D4A838E)
    • conhost.exe (PID: 3004 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: grade.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6841040D4 FindFirstFileExW,0_2_00007FF6841040D4
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF68410DD480_2_00007FF68410DD48
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F85880_2_00007FF6840F8588
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6841021BC0_2_00007FF6841021BC
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F69F00_2_00007FF6840F69F0
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840FAA040_2_00007FF6840FAA04
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF68410266C0_2_00007FF68410266C
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F96A40_2_00007FF6840F96A4
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840FCF100_2_00007FF6840FCF10
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF684108B640_2_00007FF684108B64
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F733C0_2_00007FF6840F733C
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF684107F580_2_00007FF684107F58
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F6BD80_2_00007FF6840F6BD8
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F68080_2_00007FF6840F6808
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F784C0_2_00007FF6840F784C
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF68410C08C0_2_00007FF68410C08C
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6841040D40_2_00007FF6841040D4
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF684102CEC0_2_00007FF684102CEC
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840FA50C0_2_00007FF6840FA50C
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840FF4FC0_2_00007FF6840FF4FC
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840FC9200_2_00007FF6840FC920
Source: C:\Users\user\Desktop\grade.exeCode function: String function: 00007FF6840F1D30 appears 36 times
Source: classification engineClassification label: clean4.winEXE@2/1@0/0
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3004:120:WilError_03
Source: grade.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\grade.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\grade.exe "C:\Users\user\Desktop\grade.exe"
Source: C:\Users\user\Desktop\grade.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\grade.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\grade.exeSection loaded: kernel.appcore.dllJump to behavior
Source: grade.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: grade.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: grade.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: grade.exeStatic PE information: section name: _RDATA
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6841040D4 FindFirstFileExW,0_2_00007FF6841040D4
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840FFD94 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6840FFD94
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF684106848 GetProcessHeap,0_2_00007FF684106848
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840FFD94 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6840FFD94
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F2708 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6840F2708
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F28B0 SetUnhandledExceptionFilter,0_2_00007FF6840F28B0
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F2104 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF6840F2104
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF68410DB90 cpuid 0_2_00007FF68410DB90
Source: C:\Users\user\Desktop\grade.exeCode function: 0_2_00007FF6840F25F0 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF6840F25F0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Process Injection
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
LSASS Memory2
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS12
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1430592 Sample: grade.exe Startdate: 23/04/2024 Architecture: WINDOWS Score: 4 5 grade.exe 1 2->5         started        process3 7 conhost.exe 5->7         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1430592
Start date and time:2024-04-23 23:02:10 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 1m 58s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:7
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:grade.exe
Detection:CLEAN
Classification:clean4.winEXE@2/1@0/0
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 98%
  • Number of executed functions: 14
  • Number of non-executed functions: 43
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Stop behavior analysis, all processes terminated
  • Exclude process from analysis (whitelisted): dllhost.exe, RuntimeBroker.exe, backgroundTaskHost.exe, svchost.exe
  • Excluded domains from analysis (whitelisted): client.wns.windows.com
  • Not all processes where analyzed, report is missing behavior information
  • VT rate limit hit for: grade.exe
No simulations
No context
No context
No context
No context
No context
Process:C:\Users\user\Desktop\grade.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):334
Entropy (8bit):3.5864209896797057
Encrypted:false
SSDEEP:3:fPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPt:Yv5ON2RCXdLANvB8xDCuKNEULiGC
MD5:602CC9A40803F3AF2C62D8E9CF509618
SHA1:F959B23F21DE0794D628AE327D9B2CC37438DECB
SHA-256:6A449525DF5AA861B4C511134AC8F1B3EF0AA6CBB014D0639F992D0A10F9BF40
SHA-512:AECA2007147EB148BCF18E97A27A9CDEF1730403210187A87560EF1A4791AA39D94C2C8D83FBF19D26B8C40D333CBE0D6C06A751725A0A3BB650E3F8BF3F105C
Malicious:false
Reputation:low
Preview:**************************************************************************..C:\Users\user\Desktop\grade.exe <File> [show]..File = file that has the pasted scores from Excel file...show = optional argument for showing the scores..Author: Rassul Saeedipour..**************************************************************************
File type:PE32+ executable (console) x86-64, for MS Windows
Entropy (8bit):6.306864194732709
TrID:
  • Win64 Executable Console (202006/5) 92.65%
  • Win64 Executable (generic) (12005/4) 5.51%
  • Generic Win/DOS Executable (2004/3) 0.92%
  • DOS Executable Generic (2002/1) 0.92%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:grade.exe
File size:180'224 bytes
MD5:6e57c402199ce6e7bbf5ede13d4a838e
SHA1:69fb871bdb2d0fa0af25107215b5187e1f420ada
SHA256:e3eb252b1b009440c097ba7a40d8b2ccc4e233847dec9e1d6c08c5a4439dcc12
SHA512:9c921a76c7ce2b15f5c7df716b88e823b3f211e918348a20063e44b7f577db1b8b695fc33f96d74da9508b37bd08dc0a9a643b36585c6f35fec7572b69a69cb0
SSDEEP:3072:fP7Eucpu+5JdvyOoyrjuPo2UsdZTAg9umO/Cyhdw7+dibC5:oHpu+5Pvyr0juPo2Bj8DmO/1Y
TLSH:8504AE5A77A114F4E1B78238CC510686E772B8120B219BAF03A41776DF3B3A15E3FB65
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......x.@.<..H<..H<..H..-I;..H..+I...H..*I0..H../I?..H<./He..Hs..H=..Hs.+I...Hs.*I,..Hs.-I5..H..*I=..H..,I=..HRich<..H...............
Icon Hash:00928e8e8686b000
Entrypoint:0x1400020f0
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x140000000
Subsystem:windows cui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x662566DE [Sun Apr 21 19:19:58 2024 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:8b2f0481982bd74a15596f64ec245694
Instruction
dec eax
sub esp, 28h
call 00007F144CF8FD1Ch
dec eax
add esp, 28h
jmp 00007F144CF8F697h
int3
int3
inc eax
push ebx
dec eax
sub esp, 20h
dec eax
mov ebx, ecx
xor ecx, ecx
call dword ptr [0001CF0Bh]
dec eax
mov ecx, ebx
call dword ptr [0001CEFAh]
call dword ptr [0001CF04h]
dec eax
mov ecx, eax
mov edx, C0000409h
dec eax
add esp, 20h
pop ebx
dec eax
jmp dword ptr [0001CEF8h]
dec eax
mov dword ptr [esp+08h], ecx
dec eax
sub esp, 38h
mov ecx, 00000017h
call dword ptr [0001CEECh]
test eax, eax
je 00007F144CF8F829h
mov ecx, 00000002h
int 29h
dec eax
lea ecx, dword ptr [00029132h]
call 00007F144CF8F9EEh
dec eax
mov eax, dword ptr [esp+38h]
dec eax
mov dword ptr [00029219h], eax
dec eax
lea eax, dword ptr [esp+38h]
dec eax
add eax, 08h
dec eax
mov dword ptr [000291A9h], eax
dec eax
mov eax, dword ptr [00029202h]
dec eax
mov dword ptr [00029073h], eax
dec eax
mov eax, dword ptr [esp+40h]
dec eax
mov dword ptr [00029177h], eax
mov dword ptr [0002904Dh], C0000409h
mov dword ptr [00029047h], 00000001h
mov dword ptr [00029051h], 00000001h
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x292b40x28.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x330000x16f8.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x360000x688.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x277f00x1c.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x276b00x140.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x1f0000x270.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x1da300x1dc000f13644fe3f402192676c0eb96b36c4cFalse0.5702304359243697zlib compressed data6.5157803645526515IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x1f0000xaade0xac00e2aeda0e5ff79caea959151fc713c4c6False0.45896166424418605data5.004565963167963IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x2a0000x85f00x120083e7198e6ed66391be71368899e6beefFalse0.2406684027777778data3.5429865666336964IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.pdata0x330000x16f80x18007898243f4d591b9490bded1a69fa861eFalse0.4713541666666667data5.087100398167949IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
_RDATA0x350000x15c0x2004abdc6ccba67d0d605f53aafbbb9f873False0.392578125data2.8103216483041695IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x360000x6880x80097fed5e2aaf751767837faf5acc79024False0.50244140625data4.968382633383432IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
DLLImport
KERNEL32.dllRtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleW, SetEndOfFile, RtlUnwindEx, GetLastError, SetLastError, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, GetProcAddress, LoadLibraryExW, EncodePointer, RaiseException, RtlPcToFileHeader, ExitProcess, GetModuleHandleExW, GetStdHandle, WriteFile, GetModuleFileNameW, GetCommandLineA, GetCommandLineW, HeapAlloc, HeapFree, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, CompareStringW, LCMapStringW, GetFileType, CloseHandle, FindClose, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, MultiByteToWideChar, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, SetStdHandle, GetStringTypeW, GetProcessHeap, FlushFileBuffers, GetConsoleOutputCP, GetConsoleMode, CreateFileW, GetFileSizeEx, SetFilePointerEx, HeapSize, HeapReAlloc, ReadFile, ReadConsoleW, WriteConsoleW
No network behavior found

Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:23:02:56
Start date:23/04/2024
Path:C:\Users\user\Desktop\grade.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\grade.exe"
Imagebase:0x7ff6840f0000
File size:180'224 bytes
MD5 hash:6E57C402199CE6E7BBF5EDE13D4A838E
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Target ID:1
Start time:23:02:56
Start date:23/04/2024
Path:C:\Windows\System32\conhost.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Imagebase:0x7ff66e660000
File size:862'208 bytes
MD5 hash:0D698AF330FD17BEE3BF90011D49251D
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Reset < >

    Execution Graph

    Execution Coverage:5.8%
    Dynamic/Decrypted Code Coverage:0%
    Signature Coverage:2.4%
    Total number of Nodes:1610
    Total number of Limit Nodes:14
    execution_graph 13101 7ff68410e75a 13104 7ff6840f3660 13101->13104 13105 7ff6840f368a 13104->13105 13106 7ff6840f3678 13104->13106 13118 7ff6840f3b5c 13105->13118 13106->13105 13108 7ff6840f3680 13106->13108 13109 7ff6840f3688 13108->13109 13111 7ff6840f3b5c ExFilterRethrow 85 API calls 13108->13111 13112 7ff6840f36af 13111->13112 13114 7ff6840f3b5c ExFilterRethrow 85 API calls 13112->13114 13113 7ff6840f3b5c ExFilterRethrow 85 API calls 13113->13109 13115 7ff6840f36bc 13114->13115 13116 7ff6840ffa08 76 API calls 13115->13116 13117 7ff6840f36c5 13116->13117 13124 7ff6840f3b78 13118->13124 13121 7ff6840f368f 13121->13109 13121->13113 13122 7ff6840ffbbc ExFilterRethrow 76 API calls 13123 7ff6840f3b74 13122->13123 13125 7ff6840f3b65 13124->13125 13126 7ff6840f3b97 GetLastError 13124->13126 13125->13121 13125->13122 13136 7ff6840f3f04 13126->13136 13137 7ff6840f3d24 __vcrt_InitializeCriticalSectionEx 5 API calls 13136->13137 13138 7ff6840f3f2b TlsGetValue 13137->13138 13140 7ff684101950 FlsAlloc 13141 7ff68410196f 13140->13141 13145 7ff68410196b 13140->13145 13142 7ff6841017c8 _get_daylight 11 API calls 13141->13142 13143 7ff684101974 13142->13143 13143->13145 13146 7ff68410198c 13143->13146 13147 7ff68410199b FlsFree 13146->13147 13148 7ff6841019a7 13146->13148 13147->13148 13148->13145 13668 7ff6841014d0 13669 7ff6841014d5 13668->13669 13670 7ff6841014ea 13668->13670 13674 7ff6841014f0 13669->13674 13675 7ff684101532 13674->13675 13676 7ff68410153a 13674->13676 13677 7ff684100238 __free_lconv_num 11 API calls 13675->13677 13678 7ff684100238 __free_lconv_num 11 API calls 13676->13678 13677->13676 13679 7ff684101547 13678->13679 13680 7ff684100238 __free_lconv_num 11 API calls 13679->13680 13681 7ff684101554 13680->13681 13682 7ff684100238 __free_lconv_num 11 API calls 13681->13682 13683 7ff684101561 13682->13683 13684 7ff684100238 __free_lconv_num 11 API calls 13683->13684 13685 7ff68410156e 13684->13685 13686 7ff684100238 __free_lconv_num 11 API calls 13685->13686 13687 7ff68410157b 13686->13687 13688 7ff684100238 __free_lconv_num 11 API calls 13687->13688 13689 7ff684101588 13688->13689 13690 7ff684100238 __free_lconv_num 11 API calls 13689->13690 13691 7ff684101595 13690->13691 13692 7ff684100238 __free_lconv_num 11 API calls 13691->13692 13693 7ff6841015a5 13692->13693 13694 7ff684100238 __free_lconv_num 11 API calls 13693->13694 13695 7ff6841015b5 13694->13695 13700 7ff6841013a0 13695->13700 13714 7ff684103884 EnterCriticalSection 13700->13714 13716 7ff6841055cc 13717 7ff6841055f0 13716->13717 13721 7ff684105600 13716->13721 13718 7ff6841001a0 _get_daylight 11 API calls 13717->13718 13719 7ff6841055f5 13718->13719 13720 7ff6841058e0 13723 7ff6841001a0 _get_daylight 11 API calls 13720->13723 13721->13720 13722 7ff684105622 13721->13722 13724 7ff684105643 13722->13724 13783 7ff684105924 13722->13783 13725 7ff6841058e5 13723->13725 13728 7ff6841056b5 13724->13728 13729 7ff684105669 13724->13729 13738 7ff6841056a9 13724->13738 13727 7ff684100238 __free_lconv_num 11 API calls 13725->13727 13727->13719 13731 7ff684105678 13728->13731 13732 7ff6841001c0 _get_daylight 11 API calls 13728->13732 13798 7ff6840ff044 13729->13798 13730 7ff684105762 13741 7ff68410577f 13730->13741 13743 7ff6841057d1 13730->13743 13737 7ff684100238 __free_lconv_num 11 API calls 13731->13737 13735 7ff6841056cb 13732->13735 13739 7ff684100238 __free_lconv_num 11 API calls 13735->13739 13737->13719 13738->13730 13738->13731 13804 7ff68410b404 13738->13804 13746 7ff6841056d9 13739->13746 13740 7ff684105673 13742 7ff6841001a0 _get_daylight 11 API calls 13740->13742 13744 7ff684100238 __free_lconv_num 11 API calls 13741->13744 13742->13731 13743->13731 13749 7ff6841067b0 79 API calls 13743->13749 13747 7ff684105788 13744->13747 13745 7ff684105691 13745->13738 13748 7ff684105924 76 API calls 13745->13748 13746->13731 13746->13738 13750 7ff6841001c0 _get_daylight 11 API calls 13746->13750 13756 7ff68410578d 13747->13756 13840 7ff6841067b0 13747->13840 13748->13738 13751 7ff68410580e 13749->13751 13752 7ff6841056fb 13750->13752 13753 7ff684100238 __free_lconv_num 11 API calls 13751->13753 13758 7ff684100238 __free_lconv_num 11 API calls 13752->13758 13759 7ff684105818 13753->13759 13755 7ff6841058d4 13761 7ff684100238 __free_lconv_num 11 API calls 13755->13761 13756->13755 13762 7ff6841001c0 _get_daylight 11 API calls 13756->13762 13757 7ff6841057b9 13760 7ff684100238 __free_lconv_num 11 API calls 13757->13760 13758->13738 13759->13731 13759->13756 13760->13756 13761->13719 13763 7ff68410585c 13762->13763 13764 7ff684105864 13763->13764 13765 7ff68410586d 13763->13765 13766 7ff684100238 __free_lconv_num 11 API calls 13764->13766 13767 7ff6840ffb5c __std_exception_copy 76 API calls 13765->13767 13768 7ff68410586b 13766->13768 13769 7ff68410587c 13767->13769 13773 7ff684100238 __free_lconv_num 11 API calls 13768->13773 13770 7ff684105884 13769->13770 13771 7ff68410590f 13769->13771 13849 7ff68410b51c 13770->13849 13772 7ff684100084 _vfwprintf_l 17 API calls 13771->13772 13775 7ff684105923 13772->13775 13773->13719 13777 7ff6841058cc 13779 7ff684100238 __free_lconv_num 11 API calls 13777->13779 13778 7ff6841058ab 13780 7ff6841001a0 _get_daylight 11 API calls 13778->13780 13779->13755 13781 7ff6841058b0 13780->13781 13782 7ff684100238 __free_lconv_num 11 API calls 13781->13782 13782->13768 13784 7ff684105941 13783->13784 13785 7ff684105959 13783->13785 13784->13724 13786 7ff6841001c0 _get_daylight 11 API calls 13785->13786 13787 7ff68410597d 13786->13787 13788 7ff6841059de 13787->13788 13792 7ff6841001c0 _get_daylight 11 API calls 13787->13792 13793 7ff684100238 __free_lconv_num 11 API calls 13787->13793 13794 7ff6840ffb5c __std_exception_copy 76 API calls 13787->13794 13795 7ff6841059ed 13787->13795 13797 7ff684105a02 13787->13797 13790 7ff684100238 __free_lconv_num 11 API calls 13788->13790 13789 7ff6840ffbbc ExFilterRethrow 76 API calls 13791 7ff684105a08 13789->13791 13790->13784 13792->13787 13793->13787 13794->13787 13796 7ff684100084 _vfwprintf_l 17 API calls 13795->13796 13796->13797 13797->13789 13799 7ff6840ff054 13798->13799 13800 7ff6840ff05d 13798->13800 13799->13800 13801 7ff6840fed64 98 API calls 13799->13801 13800->13740 13800->13745 13802 7ff6840ff066 13801->13802 13802->13800 13803 7ff6840fef2c 12 API calls 13802->13803 13803->13800 13805 7ff684107d94 13804->13805 13806 7ff68410b411 13804->13806 13807 7ff684107da1 13805->13807 13812 7ff684107dd7 13805->13812 13808 7ff6840fa0e0 _vfwprintf_l 76 API calls 13806->13808 13809 7ff6841001a0 _get_daylight 11 API calls 13807->13809 13825 7ff684107d48 13807->13825 13810 7ff68410b445 13808->13810 13813 7ff684107dab 13809->13813 13814 7ff68410b44a 13810->13814 13819 7ff68410b45b 13810->13819 13822 7ff68410b472 13810->13822 13811 7ff684107e01 13815 7ff6841001a0 _get_daylight 11 API calls 13811->13815 13812->13811 13817 7ff684107e26 13812->13817 13818 7ff684100064 _invalid_parameter_noinfo 76 API calls 13813->13818 13814->13738 13816 7ff684107e06 13815->13816 13820 7ff684100064 _invalid_parameter_noinfo 76 API calls 13816->13820 13828 7ff6840fa0e0 _vfwprintf_l 76 API calls 13817->13828 13831 7ff684107e11 13817->13831 13821 7ff684107db6 13818->13821 13823 7ff6841001a0 _get_daylight 11 API calls 13819->13823 13820->13831 13821->13738 13826 7ff68410b47c 13822->13826 13827 7ff68410b48e 13822->13827 13824 7ff68410b460 13823->13824 13829 7ff684100064 _invalid_parameter_noinfo 76 API calls 13824->13829 13825->13738 13830 7ff6841001a0 _get_daylight 11 API calls 13826->13830 13832 7ff68410b4b6 13827->13832 13833 7ff68410b49f 13827->13833 13828->13831 13829->13814 13834 7ff68410b481 13830->13834 13831->13738 13877 7ff68410d42c 13832->13877 13868 7ff684107de4 13833->13868 13837 7ff684100064 _invalid_parameter_noinfo 76 API calls 13834->13837 13837->13814 13839 7ff6841001a0 _get_daylight 11 API calls 13839->13814 13841 7ff6841067d2 13840->13841 13842 7ff6841067ef 13840->13842 13841->13842 13843 7ff6841067e0 13841->13843 13844 7ff6841067f9 13842->13844 13917 7ff68410b6bc 13842->13917 13845 7ff6841001a0 _get_daylight 11 API calls 13843->13845 13924 7ff68410b6f8 13844->13924 13848 7ff6841067e5 memcpy_s 13845->13848 13848->13757 13850 7ff6840fa0e0 _vfwprintf_l 76 API calls 13849->13850 13851 7ff68410b582 13850->13851 13852 7ff68410b590 13851->13852 13853 7ff68410048c 5 API calls 13851->13853 13854 7ff684103b88 14 API calls 13852->13854 13853->13852 13855 7ff68410b5ec 13854->13855 13856 7ff68410b67c 13855->13856 13857 7ff6840fa0e0 _vfwprintf_l 76 API calls 13855->13857 13859 7ff68410b68d 13856->13859 13860 7ff684100238 __free_lconv_num 11 API calls 13856->13860 13858 7ff68410b5ff 13857->13858 13863 7ff68410048c 5 API calls 13858->13863 13865 7ff68410b608 13858->13865 13861 7ff6841058a7 13859->13861 13862 7ff684100238 __free_lconv_num 11 API calls 13859->13862 13860->13859 13861->13777 13861->13778 13862->13861 13863->13865 13864 7ff684103b88 14 API calls 13866 7ff68410b663 13864->13866 13865->13864 13866->13856 13867 7ff68410b66b SetEnvironmentVariableW 13866->13867 13867->13856 13869 7ff684107e01 13868->13869 13870 7ff684107e18 13868->13870 13871 7ff6841001a0 _get_daylight 11 API calls 13869->13871 13870->13869 13873 7ff684107e26 13870->13873 13872 7ff684107e06 13871->13872 13874 7ff684100064 _invalid_parameter_noinfo 76 API calls 13872->13874 13875 7ff6840fa0e0 _vfwprintf_l 76 API calls 13873->13875 13876 7ff684107e11 13873->13876 13874->13876 13875->13876 13876->13814 13878 7ff6840fa0e0 _vfwprintf_l 76 API calls 13877->13878 13879 7ff68410d451 13878->13879 13882 7ff68410d0ac 13879->13882 13885 7ff68410d0fa 13882->13885 13883 7ff6840f1e70 _log10_special 8 API calls 13884 7ff68410b4dd 13883->13884 13884->13814 13884->13839 13886 7ff68410d181 13885->13886 13888 7ff68410d16c GetCPInfo 13885->13888 13890 7ff68410d185 13885->13890 13887 7ff6841053b0 _vfwprintf_l MultiByteToWideChar 13886->13887 13886->13890 13889 7ff68410d21b 13887->13889 13888->13886 13888->13890 13889->13890 13891 7ff684101d5c _vfwprintf_l 12 API calls 13889->13891 13892 7ff68410d252 _vfwprintf_l 13889->13892 13890->13883 13891->13892 13892->13890 13893 7ff6841053b0 _vfwprintf_l MultiByteToWideChar 13892->13893 13894 7ff68410d2b8 13893->13894 13895 7ff68410d2e1 13894->13895 13896 7ff6841053b0 _vfwprintf_l MultiByteToWideChar 13894->13896 13895->13890 13897 7ff684100238 __free_lconv_num 11 API calls 13895->13897 13898 7ff68410d2da 13896->13898 13897->13890 13898->13895 13899 7ff684101d5c _vfwprintf_l 12 API calls 13898->13899 13900 7ff68410d32f _vfwprintf_l 13898->13900 13899->13900 13900->13895 13901 7ff6841053b0 _vfwprintf_l MultiByteToWideChar 13900->13901 13902 7ff68410d3a2 13901->13902 13903 7ff68410d3a8 13902->13903 13904 7ff68410d3c5 13902->13904 13903->13895 13907 7ff684100238 __free_lconv_num 11 API calls 13903->13907 13911 7ff6841004d0 13904->13911 13907->13895 13908 7ff68410d404 13908->13890 13910 7ff684100238 __free_lconv_num 11 API calls 13908->13910 13909 7ff684100238 __free_lconv_num 11 API calls 13909->13908 13910->13890 13912 7ff684100274 5 API calls 13911->13912 13913 7ff68410050e 13912->13913 13914 7ff684100516 13913->13914 13915 7ff684100738 5 API calls 13913->13915 13914->13908 13914->13909 13916 7ff68410057f CompareStringW 13915->13916 13916->13914 13918 7ff68410b6de HeapSize 13917->13918 13919 7ff68410b6c5 13917->13919 13920 7ff6841001a0 _get_daylight 11 API calls 13919->13920 13921 7ff68410b6ca 13920->13921 13922 7ff684100064 _invalid_parameter_noinfo 76 API calls 13921->13922 13923 7ff68410b6d5 13922->13923 13923->13844 13925 7ff68410b717 13924->13925 13926 7ff68410b70d 13924->13926 13928 7ff68410b71c 13925->13928 13934 7ff68410b723 _get_daylight 13925->13934 13927 7ff684101d5c _vfwprintf_l 12 API calls 13926->13927 13932 7ff68410b715 13927->13932 13929 7ff684100238 __free_lconv_num 11 API calls 13928->13929 13929->13932 13930 7ff68410b756 HeapReAlloc 13930->13932 13930->13934 13931 7ff68410b729 13933 7ff6841001a0 _get_daylight 11 API calls 13931->13933 13932->13848 13933->13932 13934->13930 13934->13931 13935 7ff684106954 _get_daylight 2 API calls 13934->13935 13935->13934 13936 7ff6840f55c8 13937 7ff6840f3b5c ExFilterRethrow 85 API calls 13936->13937 13938 7ff6840f55fd 13937->13938 13939 7ff6840f3b5c ExFilterRethrow 85 API calls 13938->13939 13940 7ff6840f560b __except_validate_context_record 13939->13940 13941 7ff6840f3b5c ExFilterRethrow 85 API calls 13940->13941 13942 7ff6840f564f 13941->13942 13943 7ff6840f3b5c ExFilterRethrow 85 API calls 13942->13943 13944 7ff6840f5658 13943->13944 13945 7ff6840f3b5c ExFilterRethrow 85 API calls 13944->13945 13946 7ff6840f5661 13945->13946 13959 7ff6840f445c 13946->13959 13949 7ff6840f3b5c ExFilterRethrow 85 API calls 13950 7ff6840f5691 __CxxCallCatchBlock 13949->13950 13966 7ff6840f4498 13950->13966 13952 7ff6840f576b __CxxCallCatchBlock 13953 7ff6840f3b5c ExFilterRethrow 85 API calls 13952->13953 13954 7ff6840f577e 13953->13954 13956 7ff6840f3b5c ExFilterRethrow 85 API calls 13954->13956 13958 7ff6840f5787 13956->13958 13960 7ff6840f3b5c ExFilterRethrow 85 API calls 13959->13960 13961 7ff6840f446d 13960->13961 13962 7ff6840f4478 13961->13962 13963 7ff6840f3b5c ExFilterRethrow 85 API calls 13961->13963 13964 7ff6840f3b5c ExFilterRethrow 85 API calls 13962->13964 13963->13962 13965 7ff6840f4489 13964->13965 13965->13949 13965->13950 13967 7ff6840f3b5c ExFilterRethrow 85 API calls 13966->13967 13968 7ff6840f44aa 13967->13968 13969 7ff6840f44e5 13968->13969 13970 7ff6840f3b5c ExFilterRethrow 85 API calls 13968->13970 13971 7ff6840ffbbc ExFilterRethrow 76 API calls 13969->13971 13972 7ff6840f44b5 13970->13972 13973 7ff6840f44ea 13971->13973 13972->13969 13974 7ff6840f44d1 13972->13974 13975 7ff6840f3b5c ExFilterRethrow 85 API calls 13974->13975 13976 7ff6840f44d6 13975->13976 13976->13952 13977 7ff6840f360c 13976->13977 13978 7ff6840f3b5c ExFilterRethrow 85 API calls 13977->13978 13979 7ff6840f361a 13978->13979 13979->13952 13149 7ff684106848 GetProcessHeap 13980 7ff6840ff8c8 13983 7ff6840ff080 13980->13983 13990 7ff6840ff00c 13983->13990 13988 7ff6840feee8 11 API calls 13989 7ff6840ff0b3 13988->13989 13991 7ff6840ff021 13990->13991 13992 7ff6840ff01c 13990->13992 13994 7ff6840ff028 13991->13994 13993 7ff6840feee8 11 API calls 13992->13993 13993->13991 13995 7ff6840ff03d 13994->13995 13996 7ff6840ff038 13994->13996 13995->13988 13997 7ff6840feee8 11 API calls 13996->13997 13997->13995 13998 7ff6840f56c2 13999 7ff6840f3b5c ExFilterRethrow 85 API calls 13998->13999 14001 7ff6840f56cf __CxxCallCatchBlock 13999->14001 14000 7ff6840f5713 RaiseException 14002 7ff6840f573a 14000->14002 14001->14000 14003 7ff6840f4498 __CxxCallCatchBlock 85 API calls 14002->14003 14006 7ff6840f5742 14003->14006 14004 7ff6840f3b5c ExFilterRethrow 85 API calls 14005 7ff6840f577e 14004->14005 14007 7ff6840f3b5c ExFilterRethrow 85 API calls 14005->14007 14008 7ff6840f360c __CxxCallCatchBlock 85 API calls 14006->14008 14010 7ff6840f576b __CxxCallCatchBlock 14006->14010 14009 7ff6840f5787 14007->14009 14008->14010 14010->14004 14011 7ff6840f28c0 14012 7ff6840f28f4 14011->14012 14013 7ff6840f28d8 14011->14013 14013->14012 14020 7ff6840f36c8 14013->14020 14018 7ff6840ffa08 76 API calls 14019 7ff6840f291a 14018->14019 14021 7ff6840f3b5c ExFilterRethrow 85 API calls 14020->14021 14022 7ff6840f2906 14021->14022 14023 7ff6840f36dc 14022->14023 14024 7ff6840f3b5c ExFilterRethrow 85 API calls 14023->14024 14025 7ff6840f2912 14024->14025 14025->14018 14026 7ff68410b3ec 14027 7ff684104fec 95 API calls 14026->14027 14028 7ff68410b3f5 14027->14028 13150 7ff68410e96d 13151 7ff68410e9b8 13150->13151 13152 7ff68410e97c 13150->13152 13154 7ff684105c9c LeaveCriticalSection 13152->13154 13155 7ff6840f553c 13158 7ff6840f5d18 13155->13158 13157 7ff6840f5565 13159 7ff6840f5d39 13158->13159 13160 7ff6840f5d6e __std_exception_copy 13158->13160 13159->13160 13161 7ff6840ffb5c __std_exception_copy 76 API calls 13159->13161 13160->13157 13161->13160 13162 7ff68410383c 13164 7ff684103844 13162->13164 13165 7ff684103875 13164->13165 13166 7ff684103871 13164->13166 13168 7ff6841005dc 13164->13168 13173 7ff6841038a0 13165->13173 13169 7ff684100274 5 API calls 13168->13169 13170 7ff684100612 13169->13170 13171 7ff684100631 InitializeCriticalSectionAndSpinCount 13170->13171 13172 7ff684100617 13170->13172 13171->13172 13172->13164 13174 7ff6841038cb 13173->13174 13175 7ff6841038cf 13174->13175 13176 7ff6841038ae DeleteCriticalSection 13174->13176 13175->13166 13176->13174 14029 7ff6841007bc 14030 7ff6841007f5 14029->14030 14031 7ff6841007c6 14029->14031 14031->14030 14032 7ff6841007db FreeLibrary 14031->14032 14032->14031 13177 7ff68410e770 13178 7ff6840f3b5c ExFilterRethrow 85 API calls 13177->13178 13179 7ff68410e77e 13178->13179 13180 7ff68410e789 13179->13180 13181 7ff6840f3b5c ExFilterRethrow 85 API calls 13179->13181 13181->13180 13182 7ff6840f6238 13183 7ff6840f625e 13182->13183 13184 7ff6840f6262 13183->13184 13187 7ff6840f6290 13183->13187 13185 7ff6841001a0 _get_daylight 11 API calls 13184->13185 13186 7ff6840f6267 13185->13186 13188 7ff684100064 _invalid_parameter_noinfo 76 API calls 13186->13188 13189 7ff6840f6272 13187->13189 13197 7ff6840f6000 EnterCriticalSection 13187->13197 13188->13189 11575 7ff6840f1f74 11598 7ff6840f23dc 11575->11598 11578 7ff6840f1f95 __scrt_acquire_startup_lock 11581 7ff6840f20d5 11578->11581 11582 7ff6840f1fb3 11578->11582 11579 7ff6840f20cb 11707 7ff6840f2708 IsProcessorFeaturePresent 11579->11707 11583 7ff6840f2708 7 API calls 11581->11583 11588 7ff6840f1fd4 __scrt_release_startup_lock 11582->11588 11606 7ff6840ff160 11582->11606 11586 7ff6840f20e0 ExFilterRethrow 11583->11586 11585 7ff6840f1fd8 11587 7ff6840f205e 11610 7ff6840ff0c4 11587->11610 11588->11585 11588->11587 11696 7ff6840fdd6c 11588->11696 11591 7ff6840f2063 11616 7ff6840f1620 11591->11616 11593 7ff6840f2080 11701 7ff6840f285c GetModuleHandleW 11593->11701 11595 7ff6840f2087 11595->11586 11703 7ff6840f2570 11595->11703 11714 7ff6840f2994 11598->11714 11601 7ff6840f240b 11716 7ff6840ff9bc 11601->11716 11602 7ff6840f1f8d 11602->11578 11602->11579 11607 7ff6840ff173 11606->11607 11608 7ff6840ff19a 11607->11608 12212 7ff6840f1e90 11607->12212 11608->11588 11611 7ff6840ff0d4 11610->11611 11615 7ff6840ff0e9 11610->11615 11611->11615 12342 7ff6840fed64 11611->12342 11615->11591 11617 7ff6840f1684 11616->11617 11618 7ff6840f16e1 11616->11618 12419 7ff6840f1d30 11617->12419 11619 7ff6840f1713 11618->11619 12423 7ff6840ffa70 11618->12423 12438 7ff6840f6464 11619->12438 11624 7ff6840f1d30 82 API calls 11626 7ff6840f16b1 11624->11626 11627 7ff6840f1d30 82 API calls 11626->11627 11629 7ff6840f16bd 11627->11629 11628 7ff6840f1d30 82 API calls 11636 7ff6840f176b _vfwprintf_l 11628->11636 11630 7ff6840f1d30 82 API calls 11629->11630 11632 7ff6840f16c9 11630->11632 11631 7ff6840f17c4 11634 7ff6840f1d30 82 API calls 11631->11634 11633 7ff6840f1d30 82 API calls 11632->11633 11635 7ff6840f16d5 11633->11635 11637 7ff6840f17da 11634->11637 11638 7ff6840f1d30 82 API calls 11635->11638 11636->11631 12457 7ff6840f13f0 11636->12457 11640 7ff6840f1d30 82 API calls 11637->11640 11638->11618 11641 7ff6840f17e6 11640->11641 11642 7ff6840f1d30 82 API calls 11641->11642 11648 7ff6840f17f2 11642->11648 11643 7ff6840f1858 11644 7ff6840f1d30 82 API calls 11643->11644 11645 7ff6840f186e 11644->11645 11646 7ff6840f1d30 82 API calls 11645->11646 11649 7ff6840f187a 11646->11649 11648->11643 11650 7ff6840f1d30 82 API calls 11648->11650 12477 7ff6840f1310 11648->12477 12483 7ff6840f1d90 11649->12483 11650->11648 11653 7ff6840f19aa 12487 7ff6840f1000 11653->12487 11654 7ff6840f1d30 82 API calls 11656 7ff6840f18a4 11654->11656 11658 7ff6840f1d30 82 API calls 11656->11658 11657 7ff6840f19b7 11659 7ff6840f1d30 82 API calls 11657->11659 11669 7ff6840f18b0 11658->11669 11660 7ff6840f19c3 11659->11660 11662 7ff6840f1a12 11660->11662 11667 7ff6840f1d30 82 API calls 11660->11667 11661 7ff6840f18e6 11666 7ff6840f1d30 82 API calls 11661->11666 11670 7ff6840f1b95 11662->11670 11677 7ff6840f1a36 11662->11677 11663 7ff6840f1d30 82 API calls 11665 7ff6840f18f2 11663->11665 11664 7ff6840f1d30 82 API calls 11664->11669 11665->11653 11665->11663 11666->11665 11668 7ff6840f19e2 11667->11668 11671 7ff6840f1d30 82 API calls 11668->11671 11669->11661 11669->11664 11672 7ff6840f1bd1 11670->11672 11674 7ff6840f1d30 82 API calls 11670->11674 11673 7ff6840f19ee 11671->11673 11678 7ff6840f1d30 82 API calls 11672->11678 11675 7ff6840f1d30 82 API calls 11673->11675 11674->11672 11681 7ff6840f19fa 11675->11681 11676 7ff6840f1b2f 11679 7ff6840f1b3e 11676->11679 11680 7ff6840f1b7a 11676->11680 11677->11676 11682 7ff6840f1d30 82 API calls 11677->11682 11683 7ff6840f1c48 11678->11683 11684 7ff6840f1b64 11679->11684 11689 7ff6840f1d30 82 API calls 11679->11689 11680->11684 11691 7ff6840f1d30 82 API calls 11680->11691 11685 7ff6840f1d30 82 API calls 11681->11685 11686 7ff6840f1abd 11682->11686 11688 7ff6840f1d30 82 API calls 11683->11688 11684->11593 11690 7ff6840f1a06 11685->11690 11687 7ff6840f1d30 82 API calls 11686->11687 11687->11676 11692 7ff6840f1c54 11688->11692 11689->11684 11693 7ff6840f1d30 82 API calls 11690->11693 11691->11684 11694 7ff6840f1e70 _log10_special 8 API calls 11692->11694 11693->11662 11695 7ff6840f1c66 11694->11695 11695->11593 11697 7ff6840fdda4 11696->11697 11698 7ff6840fdd83 11696->11698 13053 7ff6840ffa08 11697->13053 11698->11587 11702 7ff6840f286d 11701->11702 11702->11595 11704 7ff6840f2581 11703->11704 11705 7ff6840f209e 11704->11705 11706 7ff6840f3554 __scrt_initialize_crt 7 API calls 11704->11706 11705->11585 11706->11705 11708 7ff6840f272e ExFilterRethrow memcpy_s 11707->11708 11709 7ff6840f274d RtlCaptureContext RtlLookupFunctionEntry 11708->11709 11710 7ff6840f27b2 memcpy_s 11709->11710 11711 7ff6840f2776 RtlVirtualUnwind 11709->11711 11712 7ff6840f27e4 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 11710->11712 11711->11710 11713 7ff6840f2836 ExFilterRethrow 11712->11713 11713->11581 11715 7ff6840f23fe __scrt_dllmain_crt_thread_attach 11714->11715 11715->11601 11715->11602 11717 7ff684106870 11716->11717 11718 7ff6840f2410 11717->11718 11728 7ff684104f34 11717->11728 11743 7ff684104fec 11717->11743 11749 7ff684100e30 11717->11749 11718->11602 11722 7ff6840f3554 11718->11722 11723 7ff6840f355c 11722->11723 11724 7ff6840f3566 11722->11724 12191 7ff6840f3c80 11723->12191 11724->11602 11729 7ff684104f57 11728->11729 11730 7ff684104f61 11729->11730 11769 7ff684103884 EnterCriticalSection 11729->11769 11732 7ff684104fd3 11730->11732 11760 7ff6840ffbbc 11730->11760 11732->11717 11736 7ff684104feb 11739 7ff684101724 81 API calls 11736->11739 11742 7ff68410503e 11736->11742 11740 7ff684105028 11739->11740 11741 7ff684104cc4 95 API calls 11740->11741 11741->11742 11742->11717 11744 7ff684104ff9 11743->11744 11748 7ff68410503e 11743->11748 11987 7ff684101724 11744->11987 11748->11717 12190 7ff684103884 EnterCriticalSection 11749->12190 11751 7ff684100e40 11752 7ff684105b0c 82 API calls 11751->11752 11753 7ff684100e49 11752->11753 11754 7ff684100e57 11753->11754 11755 7ff684100c38 84 API calls 11753->11755 11756 7ff6841038d8 Concurrency::details::SchedulerProxy::DeleteThis LeaveCriticalSection 11754->11756 11757 7ff684100e52 11755->11757 11758 7ff684100e63 11756->11758 11759 7ff684100d28 GetStdHandle GetFileType 11757->11759 11758->11717 11759->11754 11770 7ff684106a0c 11760->11770 11804 7ff6841069c4 11770->11804 11809 7ff684103884 EnterCriticalSection 11804->11809 11988 7ff684101735 FlsGetValue 11987->11988 11989 7ff684101750 FlsSetValue 11987->11989 11990 7ff684101742 11988->11990 11991 7ff68410174a 11988->11991 11989->11990 11992 7ff68410175d 11989->11992 11993 7ff684101748 11990->11993 11994 7ff6840ffbbc ExFilterRethrow 76 API calls 11990->11994 11991->11989 11995 7ff6841001c0 _get_daylight 11 API calls 11992->11995 12007 7ff684104cc4 11993->12007 11996 7ff6841017c5 11994->11996 11997 7ff68410176c 11995->11997 11998 7ff68410178a FlsSetValue 11997->11998 11999 7ff68410177a FlsSetValue 11997->11999 12001 7ff6841017a8 11998->12001 12002 7ff684101796 FlsSetValue 11998->12002 12000 7ff684101783 11999->12000 12004 7ff684100238 __free_lconv_num 11 API calls 12000->12004 12003 7ff684101400 _get_daylight 11 API calls 12001->12003 12002->12000 12005 7ff6841017b0 12003->12005 12004->11990 12006 7ff684100238 __free_lconv_num 11 API calls 12005->12006 12006->11993 12008 7ff684104f34 95 API calls 12007->12008 12009 7ff684104cf9 12008->12009 12030 7ff6841049c4 12009->12030 12012 7ff684104d16 12012->11748 12015 7ff684104d2f 12016 7ff684100238 __free_lconv_num 11 API calls 12015->12016 12016->12012 12017 7ff684104d3e 12017->12017 12045 7ff684105068 12017->12045 12020 7ff684104e3a 12021 7ff6841001a0 _get_daylight 11 API calls 12020->12021 12023 7ff684104e3f 12021->12023 12022 7ff684104e95 12025 7ff684104efc 12022->12025 12056 7ff6841047f4 12022->12056 12026 7ff684100238 __free_lconv_num 11 API calls 12023->12026 12024 7ff684104e54 12024->12022 12027 7ff684100238 __free_lconv_num 11 API calls 12024->12027 12029 7ff684100238 __free_lconv_num 11 API calls 12025->12029 12026->12012 12027->12022 12029->12012 12071 7ff6840fa0e0 12030->12071 12033 7ff6841049e4 GetOEMCP 12035 7ff684104a0b 12033->12035 12034 7ff6841049f6 12034->12035 12036 7ff6841049fb GetACP 12034->12036 12035->12012 12037 7ff684101d5c 12035->12037 12036->12035 12038 7ff684101da7 12037->12038 12044 7ff684101d6b _get_daylight 12037->12044 12039 7ff6841001a0 _get_daylight 11 API calls 12038->12039 12042 7ff684101dac 12039->12042 12040 7ff684101d8e HeapAlloc 12041 7ff684101da5 12040->12041 12040->12044 12041->12042 12042->12015 12042->12017 12043 7ff684106954 _get_daylight 2 API calls 12043->12044 12044->12038 12044->12040 12044->12043 12046 7ff6841049c4 78 API calls 12045->12046 12047 7ff684105095 12046->12047 12049 7ff6841050d2 IsValidCodePage 12047->12049 12053 7ff684105115 memcpy_s 12047->12053 12048 7ff6840f1e70 _log10_special 8 API calls 12050 7ff684104e31 12048->12050 12051 7ff6841050e3 12049->12051 12049->12053 12050->12020 12050->12024 12052 7ff68410511a GetCPInfo 12051->12052 12055 7ff6841050ec memcpy_s 12051->12055 12052->12053 12052->12055 12053->12048 12103 7ff684104adc 12055->12103 12189 7ff684103884 EnterCriticalSection 12056->12189 12072 7ff6840fa104 12071->12072 12073 7ff6840fa0ff 12071->12073 12072->12073 12074 7ff684101650 ExFilterRethrow 76 API calls 12072->12074 12073->12033 12073->12034 12075 7ff6840fa11f 12074->12075 12079 7ff6841020e4 12075->12079 12080 7ff6841020f9 12079->12080 12082 7ff6840fa142 12079->12082 12080->12082 12087 7ff6841066d8 12080->12087 12083 7ff684102150 12082->12083 12084 7ff684102165 12083->12084 12085 7ff684102178 12083->12085 12084->12085 12100 7ff68410504c 12084->12100 12085->12073 12088 7ff684101650 ExFilterRethrow 76 API calls 12087->12088 12089 7ff6841066e7 12088->12089 12090 7ff684106732 12089->12090 12099 7ff684103884 EnterCriticalSection 12089->12099 12090->12082 12101 7ff684101650 ExFilterRethrow 76 API calls 12100->12101 12102 7ff684105055 12101->12102 12104 7ff684104b19 GetCPInfo 12103->12104 12105 7ff684104c0f 12103->12105 12104->12105 12111 7ff684104b2c 12104->12111 12106 7ff6840f1e70 _log10_special 8 API calls 12105->12106 12108 7ff684104cae 12106->12108 12108->12053 12114 7ff684106208 12111->12114 12113 7ff68410b354 84 API calls 12113->12105 12115 7ff6840fa0e0 _vfwprintf_l 76 API calls 12114->12115 12116 7ff68410624a 12115->12116 12134 7ff6841053b0 12116->12134 12118 7ff684106287 12122 7ff6840f1e70 _log10_special 8 API calls 12118->12122 12119 7ff684106280 12119->12118 12120 7ff68410634e 12119->12120 12121 7ff684101d5c _vfwprintf_l 12 API calls 12119->12121 12125 7ff6841062b0 memcpy_s _vfwprintf_l 12119->12125 12120->12118 12124 7ff684100238 __free_lconv_num 11 API calls 12120->12124 12121->12125 12123 7ff684104ba3 12122->12123 12129 7ff68410b354 12123->12129 12124->12118 12125->12120 12126 7ff6841053b0 _vfwprintf_l MultiByteToWideChar 12125->12126 12127 7ff684106329 12126->12127 12127->12120 12128 7ff684106334 GetStringTypeW 12127->12128 12128->12120 12130 7ff6840fa0e0 _vfwprintf_l 76 API calls 12129->12130 12131 7ff68410b379 12130->12131 12137 7ff68410b034 12131->12137 12135 7ff6841053b8 MultiByteToWideChar 12134->12135 12138 7ff68410b076 12137->12138 12139 7ff6841053b0 _vfwprintf_l MultiByteToWideChar 12138->12139 12142 7ff68410b0c0 12139->12142 12140 7ff68410b32b 12141 7ff6840f1e70 _log10_special 8 API calls 12140->12141 12143 7ff684104bd6 12141->12143 12142->12140 12144 7ff684101d5c _vfwprintf_l 12 API calls 12142->12144 12145 7ff68410b1f8 12142->12145 12147 7ff68410b0f6 _vfwprintf_l 12142->12147 12143->12113 12144->12147 12145->12140 12146 7ff684100238 __free_lconv_num 11 API calls 12145->12146 12146->12140 12147->12145 12148 7ff6841053b0 _vfwprintf_l MultiByteToWideChar 12147->12148 12149 7ff68410b166 12148->12149 12149->12145 12165 7ff68410064c 12149->12165 12152 7ff68410b207 12152->12145 12155 7ff684101d5c _vfwprintf_l 12 API calls 12152->12155 12156 7ff68410b225 _vfwprintf_l 12152->12156 12153 7ff68410b1b5 12153->12145 12154 7ff68410064c 7 API calls 12153->12154 12154->12145 12155->12156 12156->12145 12157 7ff68410064c 7 API calls 12156->12157 12158 7ff68410b2a2 12157->12158 12159 7ff68410b2d7 12158->12159 12173 7ff68410540c 12158->12173 12159->12145 12160 7ff684100238 __free_lconv_num 11 API calls 12159->12160 12160->12145 12176 7ff684100274 12165->12176 12168 7ff684100692 LCMapStringEx 12170 7ff684100723 12168->12170 12169 7ff6841006f1 12186 7ff684100738 12169->12186 12170->12145 12170->12152 12170->12153 12172 7ff6841006fb LCMapStringW 12172->12170 12174 7ff68410542f WideCharToMultiByte 12173->12174 12177 7ff6841002d5 12176->12177 12184 7ff6841002d0 __vcrt_InitializeCriticalSectionEx 12176->12184 12177->12168 12177->12169 12178 7ff684100304 LoadLibraryW 12179 7ff6841003d9 12178->12179 12180 7ff684100329 GetLastError 12178->12180 12181 7ff6841003f9 GetProcAddress 12179->12181 12183 7ff6841003f0 FreeLibrary 12179->12183 12180->12184 12181->12177 12182 7ff68410040a 12181->12182 12182->12177 12183->12181 12184->12177 12184->12178 12184->12181 12185 7ff684100363 LoadLibraryExW 12184->12185 12185->12179 12185->12184 12187 7ff684100274 LoadLibraryW GetLastError LoadLibraryExW FreeLibrary GetProcAddress 12186->12187 12188 7ff684100766 12187->12188 12188->12172 12192 7ff6840f3c8f 12191->12192 12194 7ff6840f3561 12191->12194 12199 7ff6840f3ebc 12192->12199 12195 7ff6840f3cec 12194->12195 12196 7ff6840f3d17 12195->12196 12197 7ff6840f3cfa DeleteCriticalSection 12196->12197 12198 7ff6840f3d1b 12196->12198 12197->12196 12198->11724 12203 7ff6840f3d24 12199->12203 12204 7ff6840f3d68 __vcrt_InitializeCriticalSectionEx 12203->12204 12210 7ff6840f3e3e TlsFree 12203->12210 12205 7ff6840f3d96 LoadLibraryExW 12204->12205 12206 7ff6840f3e2d GetProcAddress 12204->12206 12204->12210 12211 7ff6840f3dd9 LoadLibraryExW 12204->12211 12207 7ff6840f3e0d 12205->12207 12208 7ff6840f3db7 GetLastError 12205->12208 12206->12210 12207->12206 12209 7ff6840f3e24 FreeLibrary 12207->12209 12208->12204 12209->12206 12211->12204 12211->12207 12213 7ff6840f1ea0 12212->12213 12229 7ff6840ff1d8 12213->12229 12215 7ff6840f1eac 12235 7ff6840f2428 12215->12235 12217 7ff6840f2708 7 API calls 12219 7ff6840f1f45 12217->12219 12218 7ff6840f1ec4 _RTC_Initialize 12227 7ff6840f1f19 12218->12227 12240 7ff6840f25d8 12218->12240 12219->11607 12221 7ff6840f1ed9 12243 7ff6840febdc 12221->12243 12225 7ff6840f1eee 12226 7ff6840ff3dc 76 API calls 12225->12226 12226->12227 12227->12217 12228 7ff6840f1f35 12227->12228 12228->11607 12230 7ff6840ff1e9 12229->12230 12231 7ff6840ff1f1 12230->12231 12232 7ff6841001a0 _get_daylight 11 API calls 12230->12232 12231->12215 12233 7ff6840ff200 12232->12233 12234 7ff684100064 _invalid_parameter_noinfo 76 API calls 12233->12234 12234->12231 12236 7ff6840f2439 12235->12236 12239 7ff6840f243e __scrt_acquire_startup_lock 12235->12239 12237 7ff6840f2708 7 API calls 12236->12237 12236->12239 12238 7ff6840f24b2 12237->12238 12239->12218 12277 7ff6840f259c 12240->12277 12242 7ff6840f25e1 12242->12221 12244 7ff6840f1ee5 12243->12244 12245 7ff6840febfc 12243->12245 12244->12227 12276 7ff6840f26b0 InitializeSListHead 12244->12276 12246 7ff6840fec04 12245->12246 12247 7ff6840fec1a 12245->12247 12248 7ff6841001a0 _get_daylight 11 API calls 12246->12248 12249 7ff684104fec 95 API calls 12247->12249 12250 7ff6840fec09 12248->12250 12251 7ff6840fec1f 12249->12251 12252 7ff684100064 _invalid_parameter_noinfo 76 API calls 12250->12252 12292 7ff6841046d0 GetModuleFileNameW 12251->12292 12252->12244 12259 7ff6840fec91 12261 7ff6841001a0 _get_daylight 11 API calls 12259->12261 12260 7ff6840feca9 12262 7ff6840fe9bc 76 API calls 12260->12262 12263 7ff6840fec96 12261->12263 12268 7ff6840fecc5 12262->12268 12264 7ff684100238 __free_lconv_num 11 API calls 12263->12264 12266 7ff6840feca4 12264->12266 12265 7ff6840feccb 12267 7ff684100238 __free_lconv_num 11 API calls 12265->12267 12266->12244 12267->12244 12268->12265 12269 7ff6840fed10 12268->12269 12270 7ff6840fecf7 12268->12270 12273 7ff684100238 __free_lconv_num 11 API calls 12269->12273 12271 7ff684100238 __free_lconv_num 11 API calls 12270->12271 12272 7ff6840fed00 12271->12272 12274 7ff684100238 __free_lconv_num 11 API calls 12272->12274 12273->12265 12275 7ff6840fed0c 12274->12275 12275->12244 12278 7ff6840f25b6 12277->12278 12280 7ff6840f25af 12277->12280 12281 7ff6840ff848 12278->12281 12280->12242 12284 7ff6840ff484 12281->12284 12291 7ff684103884 EnterCriticalSection 12284->12291 12293 7ff684104715 GetLastError 12292->12293 12294 7ff684104729 12292->12294 12316 7ff684100114 12293->12316 12296 7ff6840fa0e0 _vfwprintf_l 76 API calls 12294->12296 12298 7ff684104757 12296->12298 12297 7ff684104722 12299 7ff6840f1e70 _log10_special 8 API calls 12297->12299 12303 7ff684104768 12298->12303 12321 7ff68410048c 12298->12321 12302 7ff6840fec36 12299->12302 12304 7ff6840fe9bc 12302->12304 12324 7ff6841045b4 12303->12324 12306 7ff6840fe9fa 12304->12306 12308 7ff6840fea60 12306->12308 12338 7ff68410539c 12306->12338 12307 7ff6840feb4f 12310 7ff6840feb7c 12307->12310 12308->12307 12309 7ff68410539c 76 API calls 12308->12309 12309->12308 12311 7ff6840feb94 12310->12311 12312 7ff6840febcc 12310->12312 12311->12312 12313 7ff6841001c0 _get_daylight 11 API calls 12311->12313 12312->12259 12312->12260 12314 7ff6840febc2 12313->12314 12315 7ff684100238 __free_lconv_num 11 API calls 12314->12315 12315->12312 12317 7ff6841017c8 _get_daylight 11 API calls 12316->12317 12318 7ff684100121 __free_lconv_num 12317->12318 12319 7ff6841017c8 _get_daylight 11 API calls 12318->12319 12320 7ff684100143 12319->12320 12320->12297 12322 7ff684100274 5 API calls 12321->12322 12323 7ff6841004ac 12322->12323 12323->12303 12325 7ff6841045f3 12324->12325 12328 7ff6841045d8 12324->12328 12326 7ff6841045f8 12325->12326 12327 7ff68410540c _vfwprintf_l WideCharToMultiByte 12325->12327 12326->12328 12331 7ff6841001a0 _get_daylight 11 API calls 12326->12331 12329 7ff68410464f 12327->12329 12328->12297 12329->12326 12330 7ff684104656 GetLastError 12329->12330 12333 7ff684104681 12329->12333 12332 7ff684100114 _vfwprintf_l 11 API calls 12330->12332 12331->12328 12334 7ff684104663 12332->12334 12335 7ff68410540c _vfwprintf_l WideCharToMultiByte 12333->12335 12336 7ff6841001a0 _get_daylight 11 API calls 12334->12336 12337 7ff6841046a8 12335->12337 12336->12328 12337->12328 12337->12330 12339 7ff684105328 12338->12339 12340 7ff6840fa0e0 _vfwprintf_l 76 API calls 12339->12340 12341 7ff68410534c 12340->12341 12341->12306 12343 7ff6840fed7d 12342->12343 12356 7ff6840fed79 12342->12356 12344 7ff684104fec 95 API calls 12343->12344 12345 7ff6840fed82 12344->12345 12365 7ff6841054bc GetEnvironmentStringsW 12345->12365 12348 7ff6840fed8f 12350 7ff684100238 __free_lconv_num 11 API calls 12348->12350 12349 7ff6840fed9b 12385 7ff6840fedd8 12349->12385 12350->12356 12353 7ff684100238 __free_lconv_num 11 API calls 12354 7ff6840fedc2 12353->12354 12355 7ff684100238 __free_lconv_num 11 API calls 12354->12355 12355->12356 12356->11615 12357 7ff6840fef2c 12356->12357 12358 7ff6840fef55 12357->12358 12363 7ff6840fef6e 12357->12363 12358->11615 12359 7ff6841001c0 _get_daylight 11 API calls 12359->12363 12360 7ff6840feffe 12362 7ff684100238 __free_lconv_num 11 API calls 12360->12362 12361 7ff68410540c WideCharToMultiByte _vfwprintf_l 12361->12363 12362->12358 12363->12358 12363->12359 12363->12360 12363->12361 12364 7ff684100238 __free_lconv_num 11 API calls 12363->12364 12364->12363 12366 7ff6840fed87 12365->12366 12367 7ff6841054ec 12365->12367 12366->12348 12366->12349 12368 7ff68410540c _vfwprintf_l WideCharToMultiByte 12367->12368 12369 7ff68410553d 12368->12369 12370 7ff684105544 FreeEnvironmentStringsW 12369->12370 12371 7ff684101d5c _vfwprintf_l 12 API calls 12369->12371 12370->12366 12372 7ff684105557 12371->12372 12373 7ff68410555f 12372->12373 12374 7ff684105568 12372->12374 12375 7ff684100238 __free_lconv_num 11 API calls 12373->12375 12376 7ff68410540c _vfwprintf_l WideCharToMultiByte 12374->12376 12377 7ff684105566 12375->12377 12378 7ff68410558b 12376->12378 12377->12370 12379 7ff68410558f 12378->12379 12380 7ff684105599 12378->12380 12381 7ff684100238 __free_lconv_num 11 API calls 12379->12381 12382 7ff684100238 __free_lconv_num 11 API calls 12380->12382 12383 7ff684105597 FreeEnvironmentStringsW 12381->12383 12382->12383 12383->12366 12386 7ff6840fedfd 12385->12386 12387 7ff6841001c0 _get_daylight 11 API calls 12386->12387 12399 7ff6840fee33 12387->12399 12388 7ff6840fee3b 12389 7ff684100238 __free_lconv_num 11 API calls 12388->12389 12391 7ff6840feda3 12389->12391 12390 7ff6840feeae 12392 7ff684100238 __free_lconv_num 11 API calls 12390->12392 12391->12353 12392->12391 12393 7ff6841001c0 _get_daylight 11 API calls 12393->12399 12394 7ff6840fee9d 12413 7ff6840feee8 12394->12413 12398 7ff6840feed3 12401 7ff684100084 _vfwprintf_l 17 API calls 12398->12401 12399->12388 12399->12390 12399->12393 12399->12394 12399->12398 12402 7ff684100238 __free_lconv_num 11 API calls 12399->12402 12404 7ff6840ffb5c 12399->12404 12400 7ff684100238 __free_lconv_num 11 API calls 12400->12388 12403 7ff6840feee6 12401->12403 12402->12399 12405 7ff6840ffb73 12404->12405 12406 7ff6840ffb69 12404->12406 12407 7ff6841001a0 _get_daylight 11 API calls 12405->12407 12406->12405 12408 7ff6840ffb8e 12406->12408 12412 7ff6840ffb7a 12407->12412 12410 7ff6840ffb86 12408->12410 12411 7ff6841001a0 _get_daylight 11 API calls 12408->12411 12409 7ff684100064 _invalid_parameter_noinfo 76 API calls 12409->12410 12410->12399 12411->12412 12412->12409 12414 7ff6840feeed 12413->12414 12418 7ff6840feea5 12413->12418 12415 7ff6840fef16 12414->12415 12416 7ff684100238 __free_lconv_num 11 API calls 12414->12416 12417 7ff684100238 __free_lconv_num 11 API calls 12415->12417 12416->12414 12417->12418 12418->12400 12420 7ff6840f1d5c _vfwprintf_l 12419->12420 12498 7ff6840f1c90 12420->12498 12424 7ff6840ffa7d 12423->12424 12425 7ff6840ffaaa 12423->12425 12426 7ff6841001a0 _get_daylight 11 API calls 12424->12426 12430 7ff6840ffa34 12424->12430 12427 7ff6840ffacd 12425->12427 12428 7ff6840ffae9 12425->12428 12429 7ff6840ffa87 12426->12429 12431 7ff6841001a0 _get_daylight 11 API calls 12427->12431 12433 7ff6840fa0e0 _vfwprintf_l 76 API calls 12428->12433 12434 7ff684100064 _invalid_parameter_noinfo 76 API calls 12429->12434 12430->11619 12432 7ff6840ffad2 12431->12432 12435 7ff684100064 _invalid_parameter_noinfo 76 API calls 12432->12435 12437 7ff6840ffadd 12433->12437 12436 7ff6840ffa92 12434->12436 12435->12437 12436->11619 12437->11619 12439 7ff6840f63a8 12438->12439 12440 7ff6840f63c5 12439->12440 12442 7ff6840f63f1 12439->12442 12441 7ff6841001a0 _get_daylight 11 API calls 12440->12441 12443 7ff6840f63ca 12441->12443 12444 7ff6840f6403 12442->12444 12445 7ff6840f63f6 12442->12445 12446 7ff684100064 _invalid_parameter_noinfo 76 API calls 12443->12446 12521 7ff684101178 12444->12521 12447 7ff6841001a0 _get_daylight 11 API calls 12445->12447 12456 7ff6840f173d 12446->12456 12447->12456 12456->11628 12456->11636 12939 7ff6840fe658 12457->12939 12461 7ff6840fe658 80 API calls 12462 7ff6840f1441 12461->12462 12462->12461 12463 7ff6840fe374 78 API calls 12462->12463 12464 7ff6840f14cc 12462->12464 12463->12462 12465 7ff6840f1d30 82 API calls 12464->12465 12475 7ff6840f1431 12464->12475 12466 7ff6840f158d 12465->12466 12467 7ff6840f1d30 82 API calls 12466->12467 12468 7ff6840f1599 12467->12468 12469 7ff6840f1d30 82 API calls 12468->12469 12470 7ff6840f15a5 12469->12470 12471 7ff6840f1d30 82 API calls 12470->12471 12472 7ff6840f15b1 12471->12472 12473 7ff6840f1d90 88 API calls 12472->12473 12474 7ff6840f15c2 12473->12474 12474->12475 12476 7ff6840f1d30 82 API calls 12474->12476 12475->11636 12476->12475 12478 7ff6840f1321 memcpy_s 12477->12478 12480 7ff6840f1328 12477->12480 12478->11648 12479 7ff6840f1380 12479->12478 12482 7ff6840fe690 _vfwprintf_l 78 API calls 12479->12482 12480->12479 13023 7ff6840fe690 12480->13023 12482->12479 12484 7ff6840f1db9 _vfwprintf_l 12483->12484 13032 7ff6840f1ce0 12484->13032 12488 7ff6840f1053 12487->12488 12489 7ff6840fe658 80 API calls 12488->12489 12490 7ff6840f1062 12489->12490 12491 7ff6840f11ee 12490->12491 12494 7ff6840f1097 12490->12494 12496 7ff6840fe658 80 API calls 12490->12496 12492 7ff6840f1e70 _log10_special 8 API calls 12491->12492 12493 7ff6840f11fb 12492->12493 12493->11657 12495 7ff6840fe374 78 API calls 12494->12495 12497 7ff6840f10a1 12495->12497 12496->12490 12497->11657 12499 7ff6840f1cad _vfwprintf_l 12498->12499 12502 7ff6840f82a4 12499->12502 12503 7ff6840f82ce 12502->12503 12504 7ff6840f8306 12503->12504 12506 7ff6840f8339 12503->12506 12505 7ff6840fff94 _vfwprintf_l 76 API calls 12504->12505 12508 7ff6840f832f 12505->12508 12513 7ff6840f6470 12506->12513 12509 7ff6840f83a3 12508->12509 12510 7ff6840f6138 _vfwprintf_l 76 API calls 12508->12510 12511 7ff6840f1690 12509->12511 12512 7ff6840f6138 _vfwprintf_l 76 API calls 12509->12512 12510->12509 12511->11624 12512->12511 12520 7ff6840f6000 EnterCriticalSection 12513->12520 12515 7ff6840f648d 12516 7ff6840f7124 _vfwprintf_l 82 API calls 12515->12516 12517 7ff6840f6496 12516->12517 12518 7ff6840f600c _vfwprintf_l LeaveCriticalSection 12517->12518 12519 7ff6840f64a0 12518->12519 12519->12508 12534 7ff684103884 EnterCriticalSection 12521->12534 12940 7ff684101650 ExFilterRethrow 76 API calls 12939->12940 12942 7ff6840fe66d 12940->12942 12941 7ff684103a55 12956 7ff6840f220c 12941->12956 12942->12941 12945 7ff68410396e 12942->12945 12946 7ff6840f1e70 _log10_special 8 API calls 12945->12946 12947 7ff6840f1424 12946->12947 12947->12462 12947->12475 12948 7ff6840fe374 12947->12948 12949 7ff6840fe3a4 12948->12949 12969 7ff6840fddb8 12949->12969 12952 7ff6840fe3f8 12953 7ff6840fe40d 12952->12953 12955 7ff6840f6138 _vfwprintf_l 76 API calls 12952->12955 12953->12462 12954 7ff6840f6138 _vfwprintf_l 76 API calls 12954->12952 12955->12953 12959 7ff6840f2220 IsProcessorFeaturePresent 12956->12959 12960 7ff6840f2237 12959->12960 12965 7ff6840f22bc RtlCaptureContext RtlLookupFunctionEntry 12960->12965 12966 7ff6840f224b 12965->12966 12967 7ff6840f22ec RtlVirtualUnwind 12965->12967 12968 7ff6840f2104 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 12966->12968 12967->12966 12970 7ff6840fddfb 12969->12970 12971 7ff6840fdde9 12969->12971 12973 7ff6840fde45 12970->12973 12975 7ff6840fde08 12970->12975 12972 7ff6841001a0 _get_daylight 11 API calls 12971->12972 12974 7ff6840fddee 12972->12974 12976 7ff6840fde60 12973->12976 12990 7ff6840f8160 12973->12990 12978 7ff684100064 _invalid_parameter_noinfo 76 API calls 12974->12978 12979 7ff6840fff94 _vfwprintf_l 76 API calls 12975->12979 12983 7ff6840fde82 12976->12983 12997 7ff6840fd998 12976->12997 12981 7ff6840fddf9 12978->12981 12979->12981 12981->12952 12981->12954 12982 7ff6840fdf20 12982->12981 12985 7ff6841001a0 _get_daylight 11 API calls 12982->12985 12983->12982 12984 7ff6841001a0 _get_daylight 11 API calls 12983->12984 12986 7ff6840fdf15 12984->12986 12987 7ff6840fdfcd 12985->12987 12988 7ff684100064 _invalid_parameter_noinfo 76 API calls 12986->12988 12989 7ff684100064 _invalid_parameter_noinfo 76 API calls 12987->12989 12988->12982 12989->12981 12991 7ff6840f6138 _vfwprintf_l 76 API calls 12990->12991 12992 7ff6840f8177 12991->12992 13003 7ff684102118 12992->13003 12998 7ff6840fd9d2 12997->12998 12999 7ff6840fd9bb 12997->12999 13002 7ff6840fd9c0 12998->13002 13016 7ff68410354c 12998->13016 13011 7ff68410351c 12999->13011 13002->12976 13004 7ff684102131 13003->13004 13006 7ff6840f819f 13003->13006 13005 7ff6841066d8 _vfwprintf_l 76 API calls 13004->13005 13004->13006 13005->13006 13007 7ff684102184 13006->13007 13008 7ff68410219d 13007->13008 13010 7ff6840f81af 13007->13010 13009 7ff68410504c _vfwprintf_l 76 API calls 13008->13009 13008->13010 13009->13010 13010->12976 13012 7ff684101650 ExFilterRethrow 76 API calls 13011->13012 13013 7ff684103525 13012->13013 13014 7ff6841020e4 _vfwprintf_l 76 API calls 13013->13014 13015 7ff68410353e 13014->13015 13015->13002 13017 7ff6840fa0e0 _vfwprintf_l 76 API calls 13016->13017 13018 7ff684103585 13017->13018 13020 7ff684106208 _vfwprintf_l 78 API calls 13018->13020 13022 7ff684103591 13018->13022 13019 7ff6840f1e70 _log10_special 8 API calls 13021 7ff68410363b 13019->13021 13020->13022 13021->13002 13022->13019 13024 7ff6840fe6ca 13023->13024 13025 7ff6840fe6a9 13023->13025 13026 7ff684101650 ExFilterRethrow 76 API calls 13024->13026 13025->12480 13027 7ff6840fe6cf 13026->13027 13028 7ff6841020e4 _vfwprintf_l 76 API calls 13027->13028 13029 7ff6840fe6e8 13028->13029 13029->13025 13030 7ff68410354c _vfwprintf_l 78 API calls 13029->13030 13031 7ff6840fe71e 13030->13031 13031->12480 13033 7ff6840f1cfd _vfwprintf_l 13032->13033 13036 7ff6840fd90c 13033->13036 13037 7ff6840fd932 13036->13037 13038 7ff6840fd947 13036->13038 13039 7ff6841001a0 _get_daylight 11 API calls 13037->13039 13038->13037 13040 7ff6840fd94c 13038->13040 13041 7ff6840fd937 13039->13041 13045 7ff6840f83c8 13040->13045 13043 7ff684100064 _invalid_parameter_noinfo 76 API calls 13041->13043 13044 7ff6840f188e 13043->13044 13044->11654 13044->11665 13052 7ff6840f6000 EnterCriticalSection 13045->13052 13054 7ff684101650 ExFilterRethrow 76 API calls 13053->13054 13055 7ff6840ffa11 13054->13055 13056 7ff6840ffbbc ExFilterRethrow 76 API calls 13055->13056 13057 7ff6840fdda9 13056->13057 13198 7ff6840f5e70 13199 7ff6840f5e9a 13198->13199 13200 7ff6841001c0 _get_daylight 11 API calls 13199->13200 13201 7ff6840f5eb9 13200->13201 13202 7ff684100238 __free_lconv_num 11 API calls 13201->13202 13203 7ff6840f5ec7 13202->13203 13204 7ff6841001c0 _get_daylight 11 API calls 13203->13204 13208 7ff6840f5ef1 13203->13208 13205 7ff6840f5ee3 13204->13205 13207 7ff684100238 __free_lconv_num 11 API calls 13205->13207 13206 7ff6841005dc 6 API calls 13206->13208 13207->13208 13208->13206 13209 7ff6840f5efa 13208->13209 14033 7ff6840f36f0 14034 7ff6840ffa08 76 API calls 14033->14034 14035 7ff6840f36f9 14034->14035 14036 7ff6840f20f0 14039 7ff6840f25f0 14036->14039 14040 7ff6840f2613 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 14039->14040 14041 7ff6840f20f9 14039->14041 14040->14041 13210 7ff684100e6c 13211 7ff684100e78 13210->13211 13213 7ff684100e9f 13211->13213 13214 7ff684105abc 13211->13214 13215 7ff684105ac1 13214->13215 13216 7ff684105afc 13214->13216 13217 7ff684105af4 13215->13217 13218 7ff684105ae2 DeleteCriticalSection 13215->13218 13216->13211 13219 7ff684100238 __free_lconv_num 11 API calls 13217->13219 13218->13217 13218->13218 13219->13216 13220 7ff68410e540 13223 7ff6840fe7a0 13220->13223 13224 7ff6841017c8 _get_daylight 11 API calls 13223->13224 13225 7ff6840fe7be 13224->13225 14042 7ff68410e2c0 14043 7ff68410e2f8 __GSHandlerCheckCommon 14042->14043 14044 7ff68410e324 14043->14044 14046 7ff6840f4544 14043->14046 14047 7ff6840f3b5c ExFilterRethrow 85 API calls 14046->14047 14048 7ff6840f456e 14047->14048 14049 7ff6840f3b5c ExFilterRethrow 85 API calls 14048->14049 14050 7ff6840f457b 14049->14050 14051 7ff6840f3b5c ExFilterRethrow 85 API calls 14050->14051 14052 7ff6840f4584 14051->14052 14052->14044 14053 7ff68410e7c3 14054 7ff68410e7d3 _vfwprintf_l 14053->14054 14057 7ff6840f600c LeaveCriticalSection 14054->14057 13226 7ff68410e348 13236 7ff6840f3334 13226->13236 13228 7ff68410e370 13230 7ff6840f3b5c ExFilterRethrow 85 API calls 13231 7ff68410e380 13230->13231 13232 7ff6840f3b5c ExFilterRethrow 85 API calls 13231->13232 13233 7ff68410e389 13232->13233 13234 7ff6840ffa08 76 API calls 13233->13234 13235 7ff68410e392 13234->13235 13237 7ff6840f3364 __CxxCallCatchBlock _IsNonwritableInCurrentImage __except_validate_context_record 13236->13237 13238 7ff6840f3455 13237->13238 13239 7ff6840f3420 RtlUnwindEx 13237->13239 13238->13228 13238->13230 13239->13237 13240 7ff6840ff960 13241 7ff684100238 __free_lconv_num 11 API calls 13240->13241 13242 7ff6840ff970 13241->13242 13243 7ff684100238 __free_lconv_num 11 API calls 13242->13243 13244 7ff6840ff984 13243->13244 13245 7ff684100238 __free_lconv_num 11 API calls 13244->13245 13246 7ff6840ff998 13245->13246 13247 7ff684100238 __free_lconv_num 11 API calls 13246->13247 13248 7ff6840ff9ac 13247->13248 13249 7ff6840f5958 13260 7ff6840f588b __CxxCallCatchBlock __FrameHandler3::GetHandlerSearchState 13249->13260 13250 7ff6840f597f 13251 7ff6840f3b5c ExFilterRethrow 85 API calls 13250->13251 13252 7ff6840f5984 13251->13252 13255 7ff6840f3b5c ExFilterRethrow 85 API calls 13252->13255 13257 7ff6840f598f 13252->13257 13253 7ff6840f59ba 13254 7ff6840ffbbc ExFilterRethrow 76 API calls 13253->13254 13254->13257 13255->13257 13256 7ff6840f599c __FrameHandler3::GetHandlerSearchState 13257->13256 13258 7ff6840ffbbc ExFilterRethrow 76 API calls 13257->13258 13259 7ff6840f59c5 13258->13259 13260->13250 13260->13253 13261 7ff6840f44ec 85 API calls Is_bad_exception_allowed 13260->13261 13263 7ff6840f4514 13260->13263 13261->13260 13264 7ff6840f3b5c ExFilterRethrow 85 API calls 13263->13264 13265 7ff6840f4522 13264->13265 13265->13260 13266 7ff6840f1f58 13273 7ff6840f28b0 SetUnhandledExceptionFilter 13266->13273 14061 7ff68410e6d4 14062 7ff6840f4498 __CxxCallCatchBlock 85 API calls 14061->14062 14066 7ff68410e6e7 14062->14066 14063 7ff68410e726 __CxxCallCatchBlock 14064 7ff6840f3b5c ExFilterRethrow 85 API calls 14063->14064 14065 7ff68410e73a 14064->14065 14067 7ff6840f3b5c ExFilterRethrow 85 API calls 14065->14067 14066->14063 14069 7ff6840f360c __CxxCallCatchBlock 85 API calls 14066->14069 14068 7ff68410e74a 14067->14068 14069->14063 13058 7ff6840fdb95 13059 7ff6840ffa08 76 API calls 13058->13059 13060 7ff6840fdb9a 13059->13060 13061 7ff6840fdbc1 GetModuleHandleW 13060->13061 13062 7ff6840fdc0b 13060->13062 13061->13062 13068 7ff6840fdbce 13061->13068 13070 7ff6840fda98 13062->13070 13065 7ff6840fdc4e 13068->13062 13084 7ff6840fdcc8 GetModuleHandleExW 13068->13084 13090 7ff684103884 EnterCriticalSection 13070->13090 13072 7ff6840fdab4 13073 7ff6840fdad0 11 API calls 13072->13073 13074 7ff6840fdabd 13073->13074 13075 7ff6841038d8 Concurrency::details::SchedulerProxy::DeleteThis LeaveCriticalSection 13074->13075 13076 7ff6840fdac5 13075->13076 13076->13065 13077 7ff6840fdc64 13076->13077 13091 7ff6840fdc98 13077->13091 13080 7ff6840fdc75 GetCurrentProcess TerminateProcess 13081 7ff6840fdc86 13080->13081 13082 7ff6840fdcc8 3 API calls 13081->13082 13083 7ff6840fdc8d ExitProcess 13082->13083 13085 7ff6840fdd25 13084->13085 13086 7ff6840fdcfc GetProcAddress 13084->13086 13087 7ff6840fdd31 13085->13087 13088 7ff6840fdd2a FreeLibrary 13085->13088 13089 7ff6840fdd0e 13086->13089 13087->13062 13088->13087 13089->13085 13094 7ff6841038f4 13091->13094 13095 7ff684103912 13094->13095 13097 7ff6840fdc71 13094->13097 13098 7ff684100434 13095->13098 13097->13080 13097->13081 13099 7ff684100274 5 API calls 13098->13099 13100 7ff68410045c 13099->13100 13100->13097 13277 7ff68410af98 13278 7ff68410afa0 13277->13278 13279 7ff68410afb5 13278->13279 13281 7ff68410afce 13278->13281 13280 7ff6841001a0 _get_daylight 11 API calls 13279->13280 13282 7ff68410afba 13280->13282 13284 7ff6840fa0e0 _vfwprintf_l 76 API calls 13281->13284 13285 7ff68410afc5 13281->13285 13283 7ff684100064 _invalid_parameter_noinfo 76 API calls 13282->13283 13283->13285 13284->13285 14070 7ff6840f1210 14071 7ff6840f1251 14070->14071 14072 7ff6840fe658 80 API calls 14071->14072 14078 7ff6840f1260 14072->14078 14073 7ff6840f12f4 14074 7ff6840f1e70 _log10_special 8 API calls 14073->14074 14075 7ff6840f1301 14074->14075 14076 7ff6840fe658 80 API calls 14076->14078 14077 7ff6840fe374 78 API calls 14077->14078 14078->14073 14078->14076 14078->14077 14079 7ff6840f1d30 82 API calls 14078->14079 14079->14078 13286 7ff684103e90 13287 7ff684103eb5 13286->13287 13288 7ff684103ecc 13286->13288 13289 7ff6841001a0 _get_daylight 11 API calls 13287->13289 13292 7ff684103f84 13288->13292 13300 7ff684103f19 13288->13300 13302 7ff684103f5c 13288->13302 13318 7ff6841040d4 13288->13318 13290 7ff684103eba 13289->13290 13291 7ff684100064 _invalid_parameter_noinfo 76 API calls 13290->13291 13294 7ff684103ec5 13291->13294 13293 7ff6840feb7c 11 API calls 13292->13293 13295 7ff684103fdc 13293->13295 13296 7ff684103fe4 13295->13296 13305 7ff684104016 13295->13305 13299 7ff684100238 __free_lconv_num 11 API calls 13296->13299 13298 7ff684104075 13303 7ff684100238 __free_lconv_num 11 API calls 13298->13303 13301 7ff684103feb 13299->13301 13304 7ff684103f3c 13300->13304 13307 7ff684100238 __free_lconv_num 11 API calls 13300->13307 13301->13304 13308 7ff684100238 __free_lconv_num 11 API calls 13301->13308 13302->13304 13309 7ff684100238 __free_lconv_num 11 API calls 13302->13309 13306 7ff684104080 13303->13306 13311 7ff684100238 __free_lconv_num 11 API calls 13304->13311 13305->13298 13305->13305 13315 7ff6841040bb 13305->13315 13340 7ff68410aa40 13305->13340 13310 7ff684104099 13306->13310 13313 7ff684100238 __free_lconv_num 11 API calls 13306->13313 13307->13300 13308->13301 13309->13302 13314 7ff684100238 __free_lconv_num 11 API calls 13310->13314 13311->13294 13313->13306 13314->13294 13316 7ff684100084 _vfwprintf_l 17 API calls 13315->13316 13317 7ff6841040d0 13316->13317 13319 7ff684104102 13318->13319 13319->13319 13320 7ff6841001c0 _get_daylight 11 API calls 13319->13320 13321 7ff68410414d 13320->13321 13322 7ff68410aa40 76 API calls 13321->13322 13323 7ff684104183 13322->13323 13324 7ff684100084 _vfwprintf_l 17 API calls 13323->13324 13325 7ff68410425a 13324->13325 13326 7ff6840fa0e0 _vfwprintf_l 76 API calls 13325->13326 13327 7ff68410433e 13326->13327 13328 7ff68410048c 5 API calls 13327->13328 13329 7ff684104369 13328->13329 13330 7ff684103b88 14 API calls 13329->13330 13331 7ff6841043ae FindFirstFileExW 13330->13331 13332 7ff684104405 13331->13332 13333 7ff6840fa0e0 _vfwprintf_l 76 API calls 13332->13333 13334 7ff684104435 13333->13334 13335 7ff68410048c 5 API calls 13334->13335 13336 7ff68410445e 13335->13336 13349 7ff684103d04 13336->13349 13339 7ff6841040d4 84 API calls 13344 7ff68410aa5d 13340->13344 13341 7ff68410aa62 13342 7ff68410aa78 13341->13342 13343 7ff6841001a0 _get_daylight 11 API calls 13341->13343 13342->13305 13345 7ff68410aa6c 13343->13345 13344->13341 13344->13342 13347 7ff68410aaac 13344->13347 13346 7ff684100064 _invalid_parameter_noinfo 76 API calls 13345->13346 13346->13342 13347->13342 13348 7ff6841001a0 _get_daylight 11 API calls 13347->13348 13348->13345 13350 7ff684103d52 13349->13350 13351 7ff684103d2e 13349->13351 13352 7ff684103dac 13350->13352 13356 7ff684103d58 13350->13356 13353 7ff684103d3d 13351->13353 13355 7ff684100238 __free_lconv_num 11 API calls 13351->13355 13354 7ff68410540c _vfwprintf_l WideCharToMultiByte 13352->13354 13353->13339 13364 7ff684103dd0 13354->13364 13355->13353 13356->13353 13357 7ff684103d6d 13356->13357 13359 7ff684100238 __free_lconv_num 11 API calls 13356->13359 13360 7ff684101d5c _vfwprintf_l 12 API calls 13357->13360 13358 7ff684103dd7 GetLastError 13361 7ff684100114 _vfwprintf_l 11 API calls 13358->13361 13359->13357 13360->13353 13363 7ff684103de4 13361->13363 13362 7ff684103e14 13362->13353 13366 7ff68410540c _vfwprintf_l WideCharToMultiByte 13362->13366 13367 7ff6841001a0 _get_daylight 11 API calls 13363->13367 13364->13358 13364->13362 13365 7ff684103e08 13364->13365 13368 7ff684100238 __free_lconv_num 11 API calls 13364->13368 13369 7ff684101d5c _vfwprintf_l 12 API calls 13365->13369 13370 7ff684103e60 13366->13370 13367->13353 13368->13365 13369->13362 13370->13353 13370->13358 13371 7ff68410e6af 13374 7ff6840f57b4 13371->13374 13375 7ff6840f57d3 13374->13375 13377 7ff6840f5824 13374->13377 13376 7ff6840f3b5c ExFilterRethrow 85 API calls 13375->13376 13375->13377 13376->13377 13378 7ff6840f107d 13382 7ff6840f1067 13378->13382 13379 7ff6840f1097 13380 7ff6840fe374 78 API calls 13379->13380 13384 7ff6840f10a1 13380->13384 13381 7ff6840fe658 80 API calls 13381->13382 13382->13379 13382->13381 13383 7ff6840f11ee 13382->13383 13385 7ff6840f1e70 _log10_special 8 API calls 13383->13385 13386 7ff6840f11fb 13385->13386 14080 7ff68410a630 14081 7ff68410a65d 14080->14081 14082 7ff6841001a0 _get_daylight 11 API calls 14081->14082 14086 7ff68410a672 14081->14086 14083 7ff68410a667 14082->14083 14084 7ff684100064 _invalid_parameter_noinfo 76 API calls 14083->14084 14084->14086 14085 7ff6840f1e70 _log10_special 8 API calls 14087 7ff68410aa30 14085->14087 14086->14085 14088 7ff68410ab30 14089 7ff68410ab4f 14088->14089 14090 7ff68410abc8 14089->14090 14093 7ff68410ab5f 14089->14093 14091 7ff6840f220c 8 API calls 14090->14091 14092 7ff68410abcd 14091->14092 14094 7ff6840f1e70 _log10_special 8 API calls 14093->14094 14095 7ff68410abbe 14094->14095 14096 7ff6840ff2f8 GetCommandLineA GetCommandLineW 14097 7ff68410e935 14098 7ff68410e94e 14097->14098 14099 7ff68410e944 14097->14099 14101 7ff6841038d8 LeaveCriticalSection 14099->14101 13387 7ff68410e576 13388 7ff68410e58e 13387->13388 13394 7ff68410e5f9 13387->13394 13389 7ff6840f3b5c ExFilterRethrow 85 API calls 13388->13389 13388->13394 13390 7ff68410e5db 13389->13390 13391 7ff6840f3b5c ExFilterRethrow 85 API calls 13390->13391 13392 7ff68410e5f0 13391->13392 13393 7ff6840ffa08 76 API calls 13392->13393 13393->13394 14102 7ff68410c8fb 14103 7ff68410c93b 14102->14103 14104 7ff68410cba0 14102->14104 14103->14104 14106 7ff68410c96f 14103->14106 14107 7ff68410cb82 14103->14107 14105 7ff68410cb96 14104->14105 14109 7ff68410dc00 _log10_special 20 API calls 14104->14109 14110 7ff68410dc00 14107->14110 14109->14105 14113 7ff68410dc20 14110->14113 14114 7ff68410dc3a 14113->14114 14115 7ff68410dc1b 14114->14115 14117 7ff68410da44 14114->14117 14115->14105 14118 7ff68410da84 _log10_special 14117->14118 14119 7ff68410daf0 _log10_special 14118->14119 14128 7ff68410dd20 14118->14128 14121 7ff68410db2d 14119->14121 14122 7ff68410dafd 14119->14122 14135 7ff68410e058 14121->14135 14131 7ff68410d920 14122->14131 14125 7ff68410db2b _log10_special 14126 7ff6840f1e70 _log10_special 8 API calls 14125->14126 14127 7ff68410db55 14126->14127 14127->14115 14141 7ff68410dd48 14128->14141 14132 7ff68410d964 _log10_special 14131->14132 14133 7ff68410d979 14132->14133 14134 7ff68410e058 _set_errno_from_matherr 11 API calls 14132->14134 14133->14125 14134->14133 14136 7ff68410e076 14135->14136 14137 7ff68410e061 14135->14137 14139 7ff6841001a0 _get_daylight 11 API calls 14136->14139 14138 7ff68410e06e 14137->14138 14140 7ff6841001a0 _get_daylight 11 API calls 14137->14140 14138->14125 14139->14138 14140->14138 14142 7ff68410dd87 _raise_exc _clrfp 14141->14142 14143 7ff68410df9c RaiseException 14142->14143 14144 7ff68410dd42 14143->14144 14144->14119 14145 7ff6840f352c 14152 7ff6840f3ca4 14145->14152 14150 7ff6840f3539 14153 7ff6840f3cac 14152->14153 14155 7ff6840f3cdd 14153->14155 14156 7ff6840f3535 14153->14156 14165 7ff6840f3fa0 14153->14165 14157 7ff6840f3cec __vcrt_uninitialize_locks DeleteCriticalSection 14155->14157 14156->14150 14158 7ff6840f3c38 14156->14158 14157->14156 14170 7ff6840f3e74 14158->14170 14166 7ff6840f3d24 __vcrt_InitializeCriticalSectionEx 5 API calls 14165->14166 14167 7ff6840f3fd6 14166->14167 14168 7ff6840f3fe0 14167->14168 14169 7ff6840f3feb InitializeCriticalSectionAndSpinCount 14167->14169 14168->14153 14169->14168 14171 7ff6840f3d24 __vcrt_InitializeCriticalSectionEx 5 API calls 14170->14171 14172 7ff6840f3e99 TlsAlloc 14171->14172 13395 7ff6840ff3ac 13398 7ff6840ff330 13395->13398 13405 7ff684103884 EnterCriticalSection 13398->13405 13406 7ff6840f5fa4 13407 7ff6840f5faf 13406->13407 13415 7ff684100800 13407->13415 13427 7ff684103884 EnterCriticalSection 13415->13427 13428 7ff6840f20a2 13429 7ff6840f285c GetModuleHandleW 13428->13429 13430 7ff6840f20a9 ExFilterRethrow 13429->13430 13431 7ff6840f52a0 13432 7ff6840f52cd __except_validate_context_record 13431->13432 13433 7ff6840f3b5c ExFilterRethrow 85 API calls 13432->13433 13434 7ff6840f52d2 13433->13434 13436 7ff6840f532c 13434->13436 13439 7ff6840f53ba 13434->13439 13453 7ff6840f5380 13434->13453 13435 7ff6840f5428 13435->13453 13493 7ff6840f4a6c 13435->13493 13437 7ff6840f53a7 13436->13437 13442 7ff6840f5385 13436->13442 13443 7ff6840f534e 13436->13443 13436->13453 13478 7ff6840f40e8 13437->13478 13445 7ff6840f53d9 13439->13445 13487 7ff6840f44ec 13439->13487 13442->13437 13444 7ff6840f535d 13442->13444 13454 7ff6840f4670 13443->13454 13447 7ff6840f54d1 13444->13447 13451 7ff6840f536f 13444->13451 13445->13435 13445->13453 13490 7ff6840f4500 13445->13490 13449 7ff6840ffbbc ExFilterRethrow 76 API calls 13447->13449 13450 7ff6840f54d6 13449->13450 13459 7ff6840f583c 13451->13459 13455 7ff6840f467e 13454->13455 13456 7ff6840ffbbc ExFilterRethrow 76 API calls 13455->13456 13458 7ff6840f468f 13455->13458 13457 7ff6840f46d5 13456->13457 13458->13444 13460 7ff6840f44ec Is_bad_exception_allowed 85 API calls 13459->13460 13461 7ff6840f586b 13460->13461 13555 7ff6840f45cc 13461->13555 13464 7ff6840f3b5c ExFilterRethrow 85 API calls 13476 7ff6840f5888 __CxxCallCatchBlock __FrameHandler3::GetHandlerSearchState 13464->13476 13465 7ff6840f597f 13466 7ff6840f3b5c ExFilterRethrow 85 API calls 13465->13466 13467 7ff6840f5984 13466->13467 13470 7ff6840f3b5c ExFilterRethrow 85 API calls 13467->13470 13472 7ff6840f598f 13467->13472 13468 7ff6840f59ba 13469 7ff6840ffbbc ExFilterRethrow 76 API calls 13468->13469 13469->13472 13470->13472 13471 7ff6840f599c __FrameHandler3::GetHandlerSearchState 13471->13453 13472->13471 13474 7ff6840ffbbc ExFilterRethrow 76 API calls 13472->13474 13473 7ff6840f44ec 85 API calls Is_bad_exception_allowed 13473->13476 13475 7ff6840f59c5 13474->13475 13476->13465 13476->13468 13476->13473 13477 7ff6840f4514 __FrameHandler3::FrameUnwindToEmptyState 85 API calls 13476->13477 13477->13476 13559 7ff6840f414c 13478->13559 13485 7ff6840f583c __FrameHandler3::FrameUnwindToEmptyState 85 API calls 13486 7ff6840f413c 13485->13486 13486->13453 13488 7ff6840f3b5c ExFilterRethrow 85 API calls 13487->13488 13489 7ff6840f44f5 13488->13489 13489->13445 13491 7ff6840f3b5c ExFilterRethrow 85 API calls 13490->13491 13492 7ff6840f4509 13491->13492 13492->13435 13573 7ff6840f59c8 13493->13573 13495 7ff6840ffbbc ExFilterRethrow 76 API calls 13496 7ff6840f4f40 13495->13496 13497 7ff6840f4e8b 13534 7ff6840f4f3a 13497->13534 13543 7ff6840f4e89 13497->13543 13636 7ff6840f4f44 13497->13636 13498 7ff6840f4bb3 13498->13497 13499 7ff6840f4beb 13498->13499 13502 7ff6840f4dbc 13499->13502 13601 7ff6840f4218 13499->13601 13501 7ff6840f3b5c ExFilterRethrow 85 API calls 13505 7ff6840f4ecd 13501->13505 13511 7ff6840f44ec Is_bad_exception_allowed 85 API calls 13502->13511 13513 7ff6840f4dd9 13502->13513 13502->13543 13503 7ff6840f3b5c ExFilterRethrow 85 API calls 13507 7ff6840f4b1a 13503->13507 13508 7ff6840f4ed4 13505->13508 13505->13534 13507->13508 13512 7ff6840f3b5c ExFilterRethrow 85 API calls 13507->13512 13509 7ff6840f1e70 _log10_special 8 API calls 13508->13509 13510 7ff6840f4ee0 13509->13510 13510->13453 13511->13513 13515 7ff6840f4b2a 13512->13515 13516 7ff6840f4dfb 13513->13516 13513->13543 13628 7ff6840f40bc 13513->13628 13517 7ff6840f3b5c ExFilterRethrow 85 API calls 13515->13517 13518 7ff6840f4e11 13516->13518 13519 7ff6840f4f1d 13516->13519 13516->13543 13520 7ff6840f4b33 13517->13520 13521 7ff6840f4e1c 13518->13521 13524 7ff6840f44ec Is_bad_exception_allowed 85 API calls 13518->13524 13522 7ff6840f3b5c ExFilterRethrow 85 API calls 13519->13522 13585 7ff6840f452c 13520->13585 13527 7ff6840f5a60 85 API calls 13521->13527 13525 7ff6840f4f23 13522->13525 13524->13521 13528 7ff6840f3b5c ExFilterRethrow 85 API calls 13525->13528 13530 7ff6840f4e33 13527->13530 13529 7ff6840f4f2c 13528->13529 13532 7ff6840ffa08 76 API calls 13529->13532 13535 7ff6840f414c __FrameHandler3::GetHandlerSearchState 77 API calls 13530->13535 13530->13543 13531 7ff6840f3b5c ExFilterRethrow 85 API calls 13533 7ff6840f4b75 13531->13533 13532->13534 13533->13498 13538 7ff6840f3b5c ExFilterRethrow 85 API calls 13533->13538 13534->13495 13537 7ff6840f4e4d 13535->13537 13536 7ff6840f4500 85 API calls 13539 7ff6840f4c1a 13536->13539 13633 7ff6840f4358 RtlUnwindEx 13537->13633 13541 7ff6840f4b81 13538->13541 13539->13502 13539->13536 13607 7ff6840f5160 13539->13607 13621 7ff6840f4998 13539->13621 13544 7ff6840f3b5c ExFilterRethrow 85 API calls 13541->13544 13543->13501 13545 7ff6840f4b8a 13544->13545 13588 7ff6840f5a60 13545->13588 13549 7ff6840f4b9e 13597 7ff6840f5b50 13549->13597 13551 7ff6840f4f17 13552 7ff6840ffa08 76 API calls 13551->13552 13552->13519 13553 7ff6840f4ba6 __CxxCallCatchBlock std::bad_alloc::bad_alloc 13553->13551 13654 7ff6840f5dd0 13553->13654 13556 7ff6840f45e3 13555->13556 13557 7ff6840f45ee 13555->13557 13558 7ff6840f4670 __GetCurrentState 76 API calls 13556->13558 13557->13464 13558->13557 13560 7ff6840f4668 __FrameHandler3::GetHandlerSearchState 76 API calls 13559->13560 13561 7ff6840f417a 13560->13561 13562 7ff6840f41a6 RtlLookupFunctionEntry 13561->13562 13563 7ff6840f4107 13561->13563 13562->13561 13564 7ff6840f4668 13563->13564 13565 7ff6840f4670 13564->13565 13566 7ff6840ffbbc ExFilterRethrow 76 API calls 13565->13566 13568 7ff6840f4115 13565->13568 13567 7ff6840f46d5 13566->13567 13569 7ff6840f4058 13568->13569 13570 7ff6840f4076 13569->13570 13571 7ff6840f40a3 13570->13571 13572 7ff6840f3b5c ExFilterRethrow 85 API calls 13570->13572 13571->13485 13572->13570 13574 7ff6840f4668 __FrameHandler3::GetHandlerSearchState 76 API calls 13573->13574 13575 7ff6840f59ed 13574->13575 13576 7ff6840f414c __FrameHandler3::GetHandlerSearchState 77 API calls 13575->13576 13577 7ff6840f5a02 13576->13577 13659 7ff6840f45f4 13577->13659 13580 7ff6840f5a14 __FrameHandler3::GetHandlerSearchState 13662 7ff6840f462c 13580->13662 13581 7ff6840f5a37 13582 7ff6840f45f4 __GetUnwindTryBlock 77 API calls 13581->13582 13584 7ff6840f4ace 13582->13584 13584->13498 13584->13503 13584->13534 13586 7ff6840f3b5c ExFilterRethrow 85 API calls 13585->13586 13587 7ff6840f453a 13586->13587 13587->13531 13587->13534 13589 7ff6840f5b47 13588->13589 13594 7ff6840f5a8b 13588->13594 13591 7ff6840ffbbc ExFilterRethrow 76 API calls 13589->13591 13590 7ff6840f4b9a 13590->13498 13590->13549 13593 7ff6840f5b4c 13591->13593 13592 7ff6840f4500 85 API calls 13592->13594 13594->13590 13594->13592 13595 7ff6840f44ec Is_bad_exception_allowed 85 API calls 13594->13595 13596 7ff6840f5160 85 API calls 13594->13596 13595->13594 13596->13594 13598 7ff6840f5b6d Is_bad_exception_allowed 13597->13598 13600 7ff6840f5bbd 13597->13600 13599 7ff6840f44ec 85 API calls Is_bad_exception_allowed 13598->13599 13598->13600 13599->13598 13600->13553 13602 7ff6840f4668 __FrameHandler3::GetHandlerSearchState 76 API calls 13601->13602 13603 7ff6840f4257 13602->13603 13604 7ff6840ffbbc ExFilterRethrow 76 API calls 13603->13604 13606 7ff6840f4265 13603->13606 13605 7ff6840f4355 13604->13605 13606->13539 13608 7ff6840f521c 13607->13608 13609 7ff6840f518d 13607->13609 13608->13539 13610 7ff6840f44ec Is_bad_exception_allowed 85 API calls 13609->13610 13611 7ff6840f5196 13610->13611 13611->13608 13612 7ff6840f44ec Is_bad_exception_allowed 85 API calls 13611->13612 13613 7ff6840f51af 13611->13613 13612->13613 13613->13608 13614 7ff6840f51db 13613->13614 13615 7ff6840f44ec Is_bad_exception_allowed 85 API calls 13613->13615 13616 7ff6840f4500 85 API calls 13614->13616 13615->13614 13617 7ff6840f51ef 13616->13617 13617->13608 13618 7ff6840f5208 13617->13618 13619 7ff6840f44ec Is_bad_exception_allowed 85 API calls 13617->13619 13620 7ff6840f4500 85 API calls 13618->13620 13619->13618 13620->13608 13622 7ff6840f414c __FrameHandler3::GetHandlerSearchState 77 API calls 13621->13622 13623 7ff6840f49d5 13622->13623 13624 7ff6840f44ec Is_bad_exception_allowed 85 API calls 13623->13624 13625 7ff6840f4a0d 13624->13625 13626 7ff6840f4358 9 API calls 13625->13626 13627 7ff6840f4a51 13626->13627 13627->13539 13629 7ff6840f4668 __FrameHandler3::GetHandlerSearchState 76 API calls 13628->13629 13630 7ff6840f40d0 13629->13630 13631 7ff6840f4058 __FrameHandler3::FrameUnwindToEmptyState 85 API calls 13630->13631 13632 7ff6840f40da 13631->13632 13632->13516 13634 7ff6840f1e70 _log10_special 8 API calls 13633->13634 13635 7ff6840f4452 13634->13635 13635->13543 13637 7ff6840f4f7a 13636->13637 13638 7ff6840f4fe8 13636->13638 13639 7ff6840f3b5c ExFilterRethrow 85 API calls 13637->13639 13638->13543 13640 7ff6840f4f7f 13639->13640 13641 7ff6840f4fe4 13640->13641 13642 7ff6840f4f8e EncodePointer 13640->13642 13641->13638 13644 7ff6840f501d 13641->13644 13645 7ff6840f5157 13641->13645 13643 7ff6840f3b5c ExFilterRethrow 85 API calls 13642->13643 13649 7ff6840f4f9e 13643->13649 13646 7ff6840f4218 76 API calls 13644->13646 13647 7ff6840ffbbc ExFilterRethrow 76 API calls 13645->13647 13653 7ff6840f503a 13646->13653 13648 7ff6840f515c 13647->13648 13649->13641 13665 7ff6840f4004 13649->13665 13651 7ff6840f44ec 85 API calls Is_bad_exception_allowed 13651->13653 13652 7ff6840f4998 87 API calls 13652->13653 13653->13638 13653->13651 13653->13652 13655 7ff6840f5def 13654->13655 13656 7ff6840f5e0c RtlPcToFileHeader 13654->13656 13655->13656 13657 7ff6840f5e33 RaiseException 13656->13657 13658 7ff6840f5e24 13656->13658 13657->13551 13658->13657 13660 7ff6840f414c __FrameHandler3::GetHandlerSearchState 77 API calls 13659->13660 13661 7ff6840f4607 13660->13661 13661->13580 13661->13581 13663 7ff6840f414c __FrameHandler3::GetHandlerSearchState 77 API calls 13662->13663 13664 7ff6840f4646 13663->13664 13664->13584 13666 7ff6840f3b5c ExFilterRethrow 85 API calls 13665->13666 13667 7ff6840f4030 13666->13667 13667->13641 14174 7ff6840ff920 14175 7ff6840ff939 14174->14175 14176 7ff6840ff951 14174->14176 14175->14176 14177 7ff684100238 __free_lconv_num 11 API calls 14175->14177 14177->14176 14178 7ff68410e60c 14179 7ff6840f3b5c ExFilterRethrow 85 API calls 14178->14179 14180 7ff68410e624 14179->14180 14181 7ff6840f3b5c ExFilterRethrow 85 API calls 14180->14181 14182 7ff68410e63f 14181->14182 14183 7ff6840f3b5c ExFilterRethrow 85 API calls 14182->14183 14184 7ff68410e653 14183->14184 14185 7ff6840f3b5c ExFilterRethrow 85 API calls 14184->14185 14186 7ff68410e695 14185->14186 14187 7ff68410d50c 14188 7ff68410d51d CloseHandle 14187->14188 14189 7ff68410d523 14187->14189 14188->14189 14190 7ff6840f1a1c 14191 7ff6840f1a26 14190->14191 14192 7ff6840f1b95 14191->14192 14196 7ff6840f1a36 14191->14196 14193 7ff6840f1bd1 14192->14193 14194 7ff6840f1d30 82 API calls 14192->14194 14197 7ff6840f1d30 82 API calls 14193->14197 14194->14193 14195 7ff6840f1b2f 14198 7ff6840f1b3e 14195->14198 14199 7ff6840f1b7a 14195->14199 14196->14195 14200 7ff6840f1d30 82 API calls 14196->14200 14201 7ff6840f1c48 14197->14201 14202 7ff6840f1b64 14198->14202 14206 7ff6840f1d30 82 API calls 14198->14206 14199->14202 14207 7ff6840f1d30 82 API calls 14199->14207 14203 7ff6840f1abd 14200->14203 14205 7ff6840f1d30 82 API calls 14201->14205 14204 7ff6840f1d30 82 API calls 14203->14204 14204->14195 14208 7ff6840f1c54 14205->14208 14206->14202 14207->14202 14209 7ff6840f1e70 _log10_special 8 API calls 14208->14209 14210 7ff6840f1c66 14209->14210

    Control-flow Graph

    APIs
    • FreeLibrary.KERNEL32(?,?,?,00007FF684100612,?,?,-00000018,00007FF6841012A2,?,?,?,00007FF68410119A,?,?,?,00007FF6840F640D), ref: 00007FF6841003F3
    • GetProcAddress.KERNEL32(?,?,?,00007FF684100612,?,?,-00000018,00007FF6841012A2,?,?,?,00007FF68410119A,?,?,?,00007FF6840F640D), ref: 00007FF6841003FF
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: AddressFreeLibraryProc
    • String ID: api-ms-$ext-ms-
    • API String ID: 3013587201-537541572
    • Opcode ID: 1b45266ec9771067a26fa83aa274804e7b5c9a1966a113be077a1b509eb141a4
    • Instruction ID: 9932475338bc456166b4fc30b17d88b341707393bcf4915575d67f4e697d062a
    • Opcode Fuzzy Hash: 1b45266ec9771067a26fa83aa274804e7b5c9a1966a113be077a1b509eb141a4
    • Instruction Fuzzy Hash: 5F41C521B19A02C6EA129B16A9942B66B92BF44BD0F44513EDE4DCB788FF7CE455C340
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 165 7ff684107880-7ff6841078a5 166 7ff684107b7d 165->166 167 7ff6841078ab-7ff6841078ae 165->167 168 7ff684107b7f-7ff684107b8f 166->168 169 7ff6841078b0-7ff6841078e2 call 7ff6840fff94 167->169 170 7ff6841078e7-7ff684107912 167->170 169->168 172 7ff684107914-7ff68410791b 170->172 173 7ff68410791d-7ff684107923 170->173 172->169 172->173 175 7ff684107925-7ff68410792e call 7ff68410ba80 173->175 176 7ff684107933-7ff68410794c call 7ff68410a268 173->176 175->176 180 7ff684107952-7ff68410795b 176->180 181 7ff684107a69-7ff684107a72 176->181 180->181 184 7ff684107961-7ff684107965 180->184 182 7ff684107ac5-7ff684107aea WriteFile 181->182 183 7ff684107a74-7ff684107a79 181->183 189 7ff684107af5 182->189 190 7ff684107aec-7ff684107af2 GetLastError 182->190 185 7ff684107ab1-7ff684107abe call 7ff684107330 183->185 186 7ff684107a7b-7ff684107a7e 183->186 187 7ff68410797a-7ff684107985 184->187 188 7ff684107967-7ff684107973 call 7ff6840f8160 184->188 203 7ff684107ac3 185->203 191 7ff684107a80-7ff684107a83 186->191 192 7ff684107a9d-7ff684107aaf call 7ff684107550 186->192 195 7ff684107987-7ff684107990 187->195 196 7ff684107996-7ff6841079ab GetConsoleMode 187->196 188->187 197 7ff684107af8 189->197 190->189 199 7ff684107b0d-7ff684107b17 191->199 200 7ff684107a89-7ff684107a9b call 7ff684107434 191->200 211 7ff684107a52-7ff684107a59 192->211 195->181 195->196 204 7ff6841079b1-7ff6841079b4 196->204 205 7ff684107a5e-7ff684107a62 196->205 198 7ff684107afd 197->198 206 7ff684107b02-7ff684107b06 198->206 207 7ff684107b19-7ff684107b1e 199->207 208 7ff684107b76-7ff684107b7b 199->208 200->211 203->211 212 7ff684107a3b-7ff684107a4d call 7ff684106ea4 204->212 213 7ff6841079ba-7ff6841079c1 204->213 205->181 206->199 214 7ff684107b20-7ff684107b23 207->214 215 7ff684107b4c-7ff684107b56 207->215 208->168 211->198 212->211 213->206 218 7ff6841079c7-7ff6841079d5 213->218 219 7ff684107b25-7ff684107b34 214->219 220 7ff684107b3c-7ff684107b47 call 7ff68410015c 214->220 221 7ff684107b5e-7ff684107b6d 215->221 222 7ff684107b58-7ff684107b5c 215->222 218->197 223 7ff6841079db 218->223 219->220 220->215 221->208 222->166 222->221 224 7ff6841079de-7ff6841079f5 call 7ff68410ba88 223->224 229 7ff684107a2d-7ff684107a36 GetLastError 224->229 230 7ff6841079f7-7ff684107a01 224->230 229->197 231 7ff684107a03-7ff684107a15 call 7ff68410ba88 230->231 232 7ff684107a1e-7ff684107a25 230->232 231->229 236 7ff684107a17-7ff684107a1c 231->236 232->197 234 7ff684107a2b 232->234 234->224 236->232
    APIs
    • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FF684107820), ref: 00007FF6841079A3
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FF684107820), ref: 00007FF684107A2D
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: ConsoleErrorLastMode
    • String ID:
    • API String ID: 953036326-0
    • Opcode ID: fded8a97fe0603a0778edaa5c764133d28f504cb692cfb8a3452c74e1a05afda
    • Instruction ID: 95ba53d30f34fed13e802aee4b03828b51e8adb71e62cd13860fbafd9490d384
    • Opcode Fuzzy Hash: fded8a97fe0603a0778edaa5c764133d28f504cb692cfb8a3452c74e1a05afda
    • Instruction Fuzzy Hash: 0591D062F18652C9FB608B6594C06BD2FA0BF24B98F48413EDE9E97A94DF38D461C710
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: String
    • String ID: LCMapStringEx
    • API String ID: 2568140703-3893581201
    • Opcode ID: a0f868da1af82e01342fbd000abb89ab9a795cfa19fee68ce67e2fc1342dc39a
    • Instruction ID: 04d014cc3de2b772441a47c1c827432b186e688f2a88d47e10e8bb2089d797aa
    • Opcode Fuzzy Hash: a0f868da1af82e01342fbd000abb89ab9a795cfa19fee68ce67e2fc1342dc39a
    • Instruction Fuzzy Hash: DF21ED35608B81C6D760CB16B4802AABBA5FB89BD0F54413AEACD93B19DF3CD555CB40
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
    • String ID:
    • API String ID: 3058843127-0
    • Opcode ID: c9c3cd7c29927abd31f3b49e105a0995f79a26efa26f274cf051917e7df3851f
    • Instruction ID: 9edec613c048f47268bf2d2fe4bc7860eaf26fa7affbf90fc430767056f1b3b6
    • Opcode Fuzzy Hash: c9c3cd7c29927abd31f3b49e105a0995f79a26efa26f274cf051917e7df3851f
    • Instruction Fuzzy Hash: DD311E22A0A506C1FA14AB24A5D23BB2691BF45784F44403DEA4EC73E7DEAEE845C649
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: Process$CurrentExitTerminate
    • String ID:
    • API String ID: 1703294689-0
    • Opcode ID: 7fe735ed36e22e01c0081141643d85a710bef08a62bd7fb68d17b4913d89c3da
    • Instruction ID: 1079869c840a7cf7457a28e555a4b0037a5cde417e842900047c082655910d61
    • Opcode Fuzzy Hash: 7fe735ed36e22e01c0081141643d85a710bef08a62bd7fb68d17b4913d89c3da
    • Instruction Fuzzy Hash: 18D09E14F3A607C2EA542B7068D617A16527F48751F00583CC98F863D7DDFCA45DC244
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: Info
    • String ID:
    • API String ID: 1807457897-3916222277
    • Opcode ID: be44ce34aa222255b5420ec981f22736bef20295e4214e3c23c2c2b709479160
    • Instruction ID: d36fe362e077f96fcb49b99fadf2948c6a608fc03a235f92e9a1c3c32cbd08bc
    • Opcode Fuzzy Hash: be44ce34aa222255b5420ec981f22736bef20295e4214e3c23c2c2b709479160
    • Instruction Fuzzy Hash: 11518A32A18685CAE7218F24E1C43BE7BA0FB48744F54423AE6CD87A85CF7CE565CB40
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 348 7ff684105068-7ff68410509b call 7ff6841049c4 351 7ff6841052f5-7ff6841052f8 call 7ff684104a44 348->351 352 7ff6841050a1-7ff6841050ae 348->352 355 7ff6841052fd 351->355 354 7ff6841050b1-7ff6841050b3 352->354 356 7ff6841050b9-7ff6841050c4 354->356 357 7ff684105207-7ff684105235 call 7ff6840f3730 354->357 358 7ff6841052ff-7ff684105324 call 7ff6840f1e70 355->358 356->354 359 7ff6841050c6-7ff6841050cc 356->359 367 7ff684105238-7ff68410523e 357->367 362 7ff6841050d2-7ff6841050dd IsValidCodePage 359->362 363 7ff6841051ff-7ff684105202 359->363 362->363 366 7ff6841050e3-7ff6841050ea 362->366 363->358 368 7ff6841050ec-7ff6841050fa 366->368 369 7ff68410511a-7ff684105129 GetCPInfo 366->369 370 7ff684105240-7ff684105243 367->370 371 7ff68410527e-7ff684105288 367->371 376 7ff6841050fe-7ff684105110 call 7ff684104adc 368->376 373 7ff6841051f3-7ff6841051f9 369->373 374 7ff68410512f-7ff68410514f call 7ff6840f3730 369->374 370->371 372 7ff684105245-7ff684105250 370->372 371->367 375 7ff68410528a-7ff684105296 371->375 377 7ff684105252 372->377 378 7ff684105276-7ff68410527c 372->378 373->351 373->363 390 7ff684105155-7ff68410515e 374->390 391 7ff6841051e9 374->391 380 7ff6841052c1 375->380 381 7ff684105298-7ff68410529b 375->381 383 7ff684105115 376->383 384 7ff684105256-7ff68410525d 377->384 378->370 378->371 388 7ff6841052c8-7ff6841052db 380->388 386 7ff68410529d-7ff6841052a0 381->386 387 7ff6841052b8-7ff6841052bf 381->387 383->355 384->378 389 7ff68410525f-7ff684105274 384->389 392 7ff6841052a2-7ff6841052a4 386->392 393 7ff6841052af-7ff6841052b6 386->393 387->388 394 7ff6841052df-7ff6841052ee 388->394 389->378 389->384 396 7ff684105160-7ff684105163 390->396 397 7ff68410518c-7ff684105190 390->397 398 7ff6841051eb-7ff6841051ee 391->398 392->388 399 7ff6841052a6-7ff6841052ad 392->399 393->388 394->394 395 7ff6841052f0 394->395 395->351 396->397 400 7ff684105165-7ff68410516e 396->400 401 7ff684105195-7ff68410519e 397->401 398->376 399->388 402 7ff684105184-7ff68410518a 400->402 403 7ff684105170-7ff684105175 400->403 401->401 404 7ff6841051a0-7ff6841051a9 401->404 402->396 402->397 405 7ff684105178-7ff684105182 403->405 406 7ff6841051ab-7ff6841051ae 404->406 407 7ff6841051d9 404->407 405->402 405->405 409 7ff6841051d0-7ff6841051d7 406->409 410 7ff6841051b0-7ff6841051b3 406->410 408 7ff6841051e0-7ff6841051e7 407->408 408->398 409->408 411 7ff6841051b5-7ff6841051b7 410->411 412 7ff6841051c7-7ff6841051ce 410->412 413 7ff6841051be-7ff6841051c5 411->413 414 7ff6841051b9-7ff6841051bc 411->414 412->408 413->408 414->408
    APIs
      • Part of subcall function 00007FF6841049C4: GetOEMCP.KERNEL32(?,?,?,?,?,?,FFFFFFFD,00007FF684104D00), ref: 00007FF6841049EE
    • IsValidCodePage.KERNEL32(?,?,?,00000001,?,00000000,?,00007FF684104E31), ref: 00007FF6841050D5
    • GetCPInfo.KERNEL32(?,?,?,00000001,?,00000000,?,00007FF684104E31), ref: 00007FF684105121
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: CodeInfoPageValid
    • String ID:
    • API String ID: 546120528-0
    • Opcode ID: 222cad02fe40f821455c5b7c30d6ac466e308c81209dcc864a0cb870c9b5141a
    • Instruction ID: a6e6590baf1aca347c118405141c03652c7c7e81906dab30a07fb5e6249f3dd4
    • Opcode Fuzzy Hash: 222cad02fe40f821455c5b7c30d6ac466e308c81209dcc864a0cb870c9b5141a
    • Instruction Fuzzy Hash: 5981AB62A0C682C6EB65DF25A4C4179BFA1FF54784F48413ACACE87691DF7DE961C300
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 415 7ff684107330-7ff684107396 call 7ff68410e270 418 7ff684107398 415->418 419 7ff684107407-7ff684107431 call 7ff6840f1e70 415->419 421 7ff68410739d-7ff6841073a0 418->421 423 7ff6841073a2-7ff6841073a9 421->423 424 7ff6841073c6-7ff6841073eb WriteFile 421->424 427 7ff6841073b4-7ff6841073c4 423->427 428 7ff6841073ab-7ff6841073b1 423->428 425 7ff6841073ff-7ff684107405 GetLastError 424->425 426 7ff6841073ed-7ff6841073f6 424->426 425->419 426->419 429 7ff6841073f8-7ff6841073fb 426->429 427->421 427->424 428->427 429->418 430 7ff6841073fd 429->430 430->419
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: ErrorFileLastWrite
    • String ID:
    • API String ID: 442123175-0
    • Opcode ID: e6fceaaa9a21d7b1dd1ed8f0828f5f9ea05f014dd0ef3d942d3edebe8990df0f
    • Instruction ID: ac05f2df19c6d07d21ed9cc2d0e05529afa81c58dd49808862e37894c5caaef2
    • Opcode Fuzzy Hash: e6fceaaa9a21d7b1dd1ed8f0828f5f9ea05f014dd0ef3d942d3edebe8990df0f
    • Instruction Fuzzy Hash: 2B31A032618B81C6EB119F25E5806A97BA1FB68780F44403AEE9DC7B55DF3CE566C700
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: FileHandleType
    • String ID:
    • API String ID: 3000768030-0
    • Opcode ID: 076147a36b533debe34a27ae2876a668ec541cd228bda0177b061b0d40d28c08
    • Instruction ID: ddf316d9745b25173bbaec5979d322616c1341decf6fed5e15d7f50fc473ee65
    • Opcode Fuzzy Hash: 076147a36b533debe34a27ae2876a668ec541cd228bda0177b061b0d40d28c08
    • Instruction Fuzzy Hash: C3316F21A18A45C1E7608B14A5D01796E50FF45BB0B68133DEBAE973E0DF38E4B1D340
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: Initialize_invalid_parameter_noinfo_set_fmode
    • String ID:
    • API String ID: 3548387204-0
    • Opcode ID: 1c31e816b9a52671ce369ecbaddc29c951034789c1a9fdf0d0ceaef68d2603f4
    • Instruction ID: 990e4c185a4e0d2f438bd09e0d74d3675d28e8e9b8b778258952bf4b8739bd47
    • Opcode Fuzzy Hash: 1c31e816b9a52671ce369ecbaddc29c951034789c1a9fdf0d0ceaef68d2603f4
    • Instruction Fuzzy Hash: E6119950E1B103C6FA5877B064D22BB21907F94301F80043DE94DCA2C3DEEEB886C66A
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: HandleModule$AddressFreeLibraryProc
    • String ID:
    • API String ID: 3947729631-0
    • Opcode ID: e33298493a98b7c0429772620a1a846320d835de74cc284387c33f1468ac47d2
    • Instruction ID: 8996844442393caa46e1f586a5120b021e5820e94115dd66b48f00310fcf9262
    • Opcode Fuzzy Hash: e33298493a98b7c0429772620a1a846320d835de74cc284387c33f1468ac47d2
    • Instruction Fuzzy Hash: 2C219131A15B0AC9EB24CF64D4842AD33A0FF04318F140639D71F86AC5EFB8D445CB88
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 2063547b987781361bee4cf75965ca167c44c7983fca8f1dbf4df2d13f5a11f1
    • Instruction ID: 17f0ddd3c15fcf9882ad4071f1bc0f79426c8587e49adf248e468e592dd00496
    • Opcode Fuzzy Hash: 2063547b987781361bee4cf75965ca167c44c7983fca8f1dbf4df2d13f5a11f1
    • Instruction Fuzzy Hash: 41113A36A19642C2F710DB15A4C0679ABA6FF88744F59013DE6DD97692EF3CF860CB08
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • RtlAllocateHeap.NTDLL(?,?,00000000,00007FF6841016B2,?,?,?,00007FF6840FE66D), ref: 00007FF684100215
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: AllocateHeap
    • String ID:
    • API String ID: 1279760036-0
    • Opcode ID: f97ada7fbd599237d7393624cd2b913583b52e28a79355954de62731691aa7c8
    • Instruction ID: ac7b904e03126b8d7a044ffbcd0d699e169f49ce1fa98df0ad241e2ae52ef948
    • Opcode Fuzzy Hash: f97ada7fbd599237d7393624cd2b913583b52e28a79355954de62731691aa7c8
    • Instruction Fuzzy Hash: 89F04900B09202D1FE649BA1B9812B51E813F99F50F48103CCC8EC62C2EE2CE4A4C210
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 557 7ff6840f1d30-7ff6840f1d86 call 7ff6840f5f90 call 7ff6840f1c90
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _vfwprintf_l
    • String ID:
    • API String ID: 1692953108-0
    • Opcode ID: d0233d1e94c66d8e2dc1ca1f0d243942dc3f88bf7c96fcdfee8c9905d5fb31a4
    • Instruction ID: 5ccda45d7a6c0ecfd6ca65de581f0baf5b6fce68196ad85e82795389511d318d
    • Opcode Fuzzy Hash: d0233d1e94c66d8e2dc1ca1f0d243942dc3f88bf7c96fcdfee8c9905d5fb31a4
    • Instruction Fuzzy Hash: 3FE07F72608B8086D720DB14B48175BBBA4FB89398F900629FACC46B69DB7DC2608B44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: memcpy_s$_invalid_parameter_noinfo
    • String ID: $
    • API String ID: 2880407647-227171996
    • Opcode ID: c4ea54f63cbd4d0a9d0e14dd216b8cb128caa816c86cfe7d1c5e37177d0bf1b8
    • Instruction ID: 4b90b3900a53e1591336959c6920cd8e1d2c1183ad4f094d1869f018bf74c451
    • Opcode Fuzzy Hash: c4ea54f63cbd4d0a9d0e14dd216b8cb128caa816c86cfe7d1c5e37177d0bf1b8
    • Instruction Fuzzy Hash: E603B672A192C2CBE7758F259580BFA37A1FF94788F405139DA0AD7B85DF78A900CB44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
    • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
    • API String ID: 808467561-2761157908
    • Opcode ID: 436955ccb22b48bca490a8ded85e916626e7fb7816552579be5e77d8f9f167a8
    • Instruction ID: 34d1caa799a69d0984f9f5ece1b617d72b7a855d4d10fb77dcfc76f4240bac3b
    • Opcode Fuzzy Hash: 436955ccb22b48bca490a8ded85e916626e7fb7816552579be5e77d8f9f167a8
    • Instruction Fuzzy Hash: 4CB2C372A28282CBE7658F24D5907FD3BA1FF54788F545139DA4A97A88DF38E910CB40
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 6123995c456b7f1e5ba3b79e84b9cafaf6407a6b655f64262677e11a7ce3823e
    • Instruction ID: 2d4078d1c57a6be426147068338cb28a6b7d74393b9797ff5877eaaeb5d0c46c
    • Opcode Fuzzy Hash: 6123995c456b7f1e5ba3b79e84b9cafaf6407a6b655f64262677e11a7ce3823e
    • Instruction Fuzzy Hash: 00C1CD22A1C686D6E7699B51D4803BD2FA0FF84B80F444139EACE87795EF7CE464CB00
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
    • String ID:
    • API String ID: 3140674995-0
    • Opcode ID: 2d7525312a6657bcb5882ece53918f1a3704b53c53e7da8fb53b7088444a062e
    • Instruction ID: 25aaf7ef779afa7c75dfb6ca7fd6db74216dbfd8d10b31899e9243b6b50d2eb0
    • Opcode Fuzzy Hash: 2d7525312a6657bcb5882ece53918f1a3704b53c53e7da8fb53b7088444a062e
    • Instruction Fuzzy Hash: B0314C72619B81C6EB609F60E8807FA7365FB84744F44443EDB8E87A98DF78D548C714
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
    • String ID:
    • API String ID: 1239891234-0
    • Opcode ID: 3829ae74bf71e0cb5bb2bd97b787ef049aff150a491613f828c3d96994fd02d7
    • Instruction ID: 5f13f4ae4c5b82a0138b8508d6b85e67420db393f618a1b7086471bb1a609b37
    • Opcode Fuzzy Hash: 3829ae74bf71e0cb5bb2bd97b787ef049aff150a491613f828c3d96994fd02d7
    • Instruction Fuzzy Hash: AB316C36618F81C6EB60CF25E8806AE77A1FF88754F50013AEA9D83B99DF78D155CB00
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: memcpy_s
    • String ID:
    • API String ID: 1502251526-3916222277
    • Opcode ID: 109874d94e0b872f05b0a9e5404d8707ef423afa9b6a00e41ed3d4d154f4db59
    • Instruction ID: 7b9f5cdd6ef3b88d6158333baea4156b2a6739cb433e0dd0ddca17f91c9189eb
    • Opcode Fuzzy Hash: 109874d94e0b872f05b0a9e5404d8707ef423afa9b6a00e41ed3d4d154f4db59
    • Instruction Fuzzy Hash: A6C1C376A1E686C7D724CF19E089A6EB791FB84784F448139DB4A83B84DF7CE805CB44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: ExceptionRaise_clrfp
    • String ID:
    • API String ID: 15204871-0
    • Opcode ID: 271c0d8bf9f0ad158ff07bec116ba512e9fe6929010cab1ea0d58cf796623e8d
    • Instruction ID: f9ccb9fb0d954516c38714cfd1387988a95d7fd014293d122afddc53324abd0f
    • Opcode Fuzzy Hash: 271c0d8bf9f0ad158ff07bec116ba512e9fe6929010cab1ea0d58cf796623e8d
    • Instruction Fuzzy Hash: 06B13E73600B85CBEB15CF2AC88636C7BA1FB44B48F158925DA9D87BA8CF39D461C700
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID: e+000$gfff
    • API String ID: 0-3030954782
    • Opcode ID: 11b650a1c3784239d1fd6df14463c68ee2151c5aaa2633adc566f6a88fb18b6f
    • Instruction ID: 1bbad08835d644a0dbe8429e94c168df951ac186ec9a7c8432f94db37db4f396
    • Opcode Fuzzy Hash: 11b650a1c3784239d1fd6df14463c68ee2151c5aaa2633adc566f6a88fb18b6f
    • Instruction Fuzzy Hash: CE516766B182C586E7648F359880779AB91FB54B94F48C23ACBAC87BC5DF7DD844C700
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: d86fe434e41b6001a3fc2d0168113d91e5b4a952e5df6f911117f81f3967bd82
    • Instruction ID: eef0877f0ed11a4582206b1d24be3b481f4d283275fb13cb902a205627e98c12
    • Opcode Fuzzy Hash: d86fe434e41b6001a3fc2d0168113d91e5b4a952e5df6f911117f81f3967bd82
    • Instruction Fuzzy Hash: 3E52B42390AA86C5EB149F25C4C0BFE27A1FF01B58F18493ACA5D876D9CFB8E455D344
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 67e3503ca5095182f53e3daadbbeff50917cd4321a83b4807d19b934a95a1e1c
    • Instruction ID: 4be3a99651192178edfc186cc464acc1726c451bab80a7f50f4a16f0edaf4951
    • Opcode Fuzzy Hash: 67e3503ca5095182f53e3daadbbeff50917cd4321a83b4807d19b934a95a1e1c
    • Instruction Fuzzy Hash: 42D19322A0AB46C1EB648F69C4C167E2390FF40B68F55463ACA6D837D4DFBCE851C348
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _get_daylight_invalid_parameter_noinfo
    • String ID:
    • API String ID: 474895018-0
    • Opcode ID: 7a43723d5f6ca39190d8b0e4f55405bdbfbdb2756f5dd8115f47f7f33ea78160
    • Instruction ID: 8652348d41b654c3e45bf994dbe3c16743aae4305a6a7532e948ba181db33916
    • Opcode Fuzzy Hash: 7a43723d5f6ca39190d8b0e4f55405bdbfbdb2756f5dd8115f47f7f33ea78160
    • Instruction Fuzzy Hash: 8C61AF22F0C692CAFB649A2888807796AC1BF50760F14423DDAEDC76C5EF7DE861C710
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: f3b25047ba5f04c7ac284e11e0ac21224c0795f2a74150ae96a2b12978caba41
    • Instruction ID: b270939b3713c08a642240a22544309c04aa8550e4ff241f88074df68d73e4e7
    • Opcode Fuzzy Hash: f3b25047ba5f04c7ac284e11e0ac21224c0795f2a74150ae96a2b12978caba41
    • Instruction Fuzzy Hash: 63519322B08791C5EB209B72A8C06BA7FA5FF44798F144139EE9CA7A99DF38D411C704
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID: gfffffff
    • API String ID: 0-1523873471
    • Opcode ID: 18aff8fdb43de5301eef239b1603367e97498316aa83c693dfebc2d028e1c4d3
    • Instruction ID: 711eb83a1560e09e596b74e8dfafe1f827661c46f9e28331f2b608241644796f
    • Opcode Fuzzy Hash: 18aff8fdb43de5301eef239b1603367e97498316aa83c693dfebc2d028e1c4d3
    • Instruction Fuzzy Hash: 42A15662B087C686EB65CB25E4907BABB91BF54784F04813ADE8DC7785DE3CE815C701
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID: 0-3916222277
    • Opcode ID: 2d1138b85b1147b0ebf82975de327dd650abc04239b98de7aa4e62eb5bbd56cf
    • Instruction ID: a3fd4472207d7e0b2b46daf0e0d962dcbfa6da018e27022064b5ca47c6589505
    • Opcode Fuzzy Hash: 2d1138b85b1147b0ebf82975de327dd650abc04239b98de7aa4e62eb5bbd56cf
    • Instruction Fuzzy Hash: D2B16C7290AA56C5E7699F39C09027E3BA0FF05B48F185139DA4E873D6CFB9E440C74A
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: HeapProcess
    • String ID:
    • API String ID: 54951025-0
    • Opcode ID: 651349cded3eaa1f17c842fd3c57fcd57cf5434b821f59af53352c5bfef3b5c4
    • Instruction ID: e31a4be13fe7f69eecc53be324bf965f3775d0d5ad97e23d026b5d8cd4c47580
    • Opcode Fuzzy Hash: 651349cded3eaa1f17c842fd3c57fcd57cf5434b821f59af53352c5bfef3b5c4
    • Instruction Fuzzy Hash: E9B09225E27B02C2EA082B116CC222427A67F58B10F98003CD08C80320EE2C20F5D705
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 4ec307ed3338de62cbed40ba19046713bccc19a95b8c304709c898d113fd60b5
    • Instruction ID: 312f87057f009258ae1cc99f4fdbbb7a69c557229cd550ab9b5e794787e1a267
    • Opcode Fuzzy Hash: 4ec307ed3338de62cbed40ba19046713bccc19a95b8c304709c898d113fd60b5
    • Instruction Fuzzy Hash: 8DE1C32291DA42C5EB688B2984C037B27A1FF45B58F14423DCE4D877D6DFB9E942C34A
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: c248f55d2cad8b17c625ec7d073b18cae2a6338ba573e08bfcc3e7637e2ac2bb
    • Instruction ID: 3faef9babab33d4c38e6297fa20b51c23265edac5970552eafc25aa03638ed73
    • Opcode Fuzzy Hash: c248f55d2cad8b17c625ec7d073b18cae2a6338ba573e08bfcc3e7637e2ac2bb
    • Instruction Fuzzy Hash: 57912526F1E742CAFA254B299490BBB1690BF54798F14113DDE6EC77C0DDACE806DE08
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: c824fa0418409c4725c657295481fbfb6f8639a2c7d056fc24cb1a81b41b061d
    • Instruction ID: c7accae141223e2c47ebcd182377104c5d2202f80d0bcb20df73c8a244f278a2
    • Opcode Fuzzy Hash: c824fa0418409c4725c657295481fbfb6f8639a2c7d056fc24cb1a81b41b061d
    • Instruction Fuzzy Hash: 7381A172A1878186E7B4CB1994C037A6A91FF957D4F144239EADE87BD9DE3CE850CB00
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: a69405bfc8cd9c375f2a4e114867b51ad06e270a6236c55bdc22601cf5ab1185
    • Instruction ID: b72d4355662be189b7c9c0ac4e2375618c7dbfabf814c03a8bc6a2b80eff3c3c
    • Opcode Fuzzy Hash: a69405bfc8cd9c375f2a4e114867b51ad06e270a6236c55bdc22601cf5ab1185
    • Instruction Fuzzy Hash: 33517F72E19611C2E7288F24C19423E27A0FF55B58F14A539CE0A977D8CFA9EC92C784
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: f92c94bea4fd842bcff211724540bb77934ffb56ad01a6d4a1b7be360d8aa954
    • Instruction ID: 1ef546fad439da26818bd8f51e7ca3c6bec1a8e0c569bf99854601c05531d7ab
    • Opcode Fuzzy Hash: f92c94bea4fd842bcff211724540bb77934ffb56ad01a6d4a1b7be360d8aa954
    • Instruction Fuzzy Hash: 9751BD72E1A611C2E7288F29C19423E27A0FF51B58F152539CE8D977D9DFA8EC42C784
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 5fd14c38c18eb089541994a7d65b6649a4b38e485915baa4b0484587c38aa7d3
    • Instruction ID: 9825e0b931e730845669badc6168fee7b87fdad51a7bfdc6aa3d66c5fe725454
    • Opcode Fuzzy Hash: 5fd14c38c18eb089541994a7d65b6649a4b38e485915baa4b0484587c38aa7d3
    • Instruction Fuzzy Hash: F7516D72E0A651C2E7288F24C19433E27A0FF55B58F54563DCE49977D8CEA9E843C788
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: ErrorFreeHeapLast
    • String ID:
    • API String ID: 485612231-0
    • Opcode ID: f729f789081dc07bd32549d33617cd65f88c3248c5a935dac76d2a90e7153fc0
    • Instruction ID: a3abe95e4479cd97a202f282bed5ab9eddc03f0f8456a90b1ed791ffb7500094
    • Opcode Fuzzy Hash: f729f789081dc07bd32549d33617cd65f88c3248c5a935dac76d2a90e7153fc0
    • Instruction Fuzzy Hash: 3441C022714A5482EB44CF2AD99517A6BA1FB48FD4B49A03BEE4D87B68DE7CD141C304
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 08fd610c0f802dcc60ae470b222653b9c8bf6f5f7747dfd2f832f3d00d0f077f
    • Instruction ID: 24ed681f80113d67e91a6f1d62f03e1e6593299695631a2c1f624334a740a90e
    • Opcode Fuzzy Hash: 08fd610c0f802dcc60ae470b222653b9c8bf6f5f7747dfd2f832f3d00d0f077f
    • Instruction Fuzzy Hash: 85318332E0E107C5F6A9572995D677B9552BFC2340F248138C90F82DCACCEEB94AF50A
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: a258ecf9a2b6934d6e764c08442464d22293535620421c18e8a5b944892d5be1
    • Instruction ID: dd83456f24745e46605d7bdb3df02b133099c037bb8e789654534b096e2831fe
    • Opcode Fuzzy Hash: a258ecf9a2b6934d6e764c08442464d22293535620421c18e8a5b944892d5be1
    • Instruction Fuzzy Hash: 14F044B1A28265CAEBA48F2CA4826397BD0FB18780B50903DD5D9C3A04DA3C9160CF08
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: ab9c0cbe540811d7c1fb439fc6e484141576a5598b5394a209a91fa519ee9198
    • Instruction ID: 829e26353b2e8486604106063d009b60c223a3bee5414417713a22c85ca77e4e
    • Opcode Fuzzy Hash: ab9c0cbe540811d7c1fb439fc6e484141576a5598b5394a209a91fa519ee9198
    • Instruction Fuzzy Hash: 9FA0012595A902D0E6849B00A8911312B61BF54340B800039D58D810A4DFADA411D225
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type_get_daylight
    • String ID:
    • API String ID: 1330151763-0
    • Opcode ID: 9ae5f5a8c053c1d1dd2a1c4c89bf1029f78995226051dbf79116b70eafdc1474
    • Instruction ID: f8d42c0372ac5d8589051dd68f36b3a6b4ed99c15432b0e631b6b8f9006fc9f8
    • Opcode Fuzzy Hash: 9ae5f5a8c053c1d1dd2a1c4c89bf1029f78995226051dbf79116b70eafdc1474
    • Instruction Fuzzy Hash: 5BC1B136B28A45C5EB10DF65D4912BC3BA1FB89BA8B011239DEAE977D4DF38D461C340
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
    • String ID: csm$csm$csm
    • API String ID: 849930591-393685449
    • Opcode ID: 8e916d687b5e9b43eaa8676eb2ad1c7a6c27f5e0ded3e359381a3c2ab64b8ed1
    • Instruction ID: 33fc53dce5eb38c52fe3184145b6e63262189a146bd2ac098b25effcbc69b9d2
    • Opcode Fuzzy Hash: 8e916d687b5e9b43eaa8676eb2ad1c7a6c27f5e0ded3e359381a3c2ab64b8ed1
    • Instruction Fuzzy Hash: 45E1A372A19741C6EB609F65D4802AE77A0FF55798F040139EE8DABB9ACF78E080C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • LoadLibraryExW.KERNEL32(?,?,?,00007FF6840F3FD6,?,?,?,00007FF6840F3CC8,?,?,00000001,00007FF6840F3535), ref: 00007FF6840F3DA9
    • GetLastError.KERNEL32(?,?,?,00007FF6840F3FD6,?,?,?,00007FF6840F3CC8,?,?,00000001,00007FF6840F3535), ref: 00007FF6840F3DB7
    • LoadLibraryExW.KERNEL32(?,?,?,00007FF6840F3FD6,?,?,?,00007FF6840F3CC8,?,?,00000001,00007FF6840F3535), ref: 00007FF6840F3DE1
    • FreeLibrary.KERNEL32(?,?,?,00007FF6840F3FD6,?,?,?,00007FF6840F3CC8,?,?,00000001,00007FF6840F3535), ref: 00007FF6840F3E27
    • GetProcAddress.KERNEL32(?,?,?,00007FF6840F3FD6,?,?,?,00007FF6840F3CC8,?,?,00000001,00007FF6840F3535), ref: 00007FF6840F3E33
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: Library$Load$AddressErrorFreeLastProc
    • String ID: api-ms-
    • API String ID: 2559590344-2084034818
    • Opcode ID: d120cbac430a7cde9ed7bf2b035a8bd7cb7630aaa922411965ab72717436f98d
    • Instruction ID: 20d1e05f80a397165563344312c61c9ebd6eaefbe33807113ce7f218e3012510
    • Opcode Fuzzy Hash: d120cbac430a7cde9ed7bf2b035a8bd7cb7630aaa922411965ab72717436f98d
    • Instruction Fuzzy Hash: 8431BE21A1BA42C1EE15DB02A88067A3798BF48BA4F59453ADE5D8A7C4EFBCE044C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: Value$ErrorLast
    • String ID:
    • API String ID: 2506987500-0
    • Opcode ID: 15949b0561ea137d50506fdd8ec79dd97d734055b8a45d049a0396541e859930
    • Instruction ID: 4731f361cbb88cc20bd0fbe82229cf12c49396e8c68625f025283e5ad54dbe24
    • Opcode Fuzzy Hash: 15949b0561ea137d50506fdd8ec79dd97d734055b8a45d049a0396541e859930
    • Instruction Fuzzy Hash: 70218E20E0D242C2FA656761A9D11399E827F44BF0F08073DE9BEC66C6EE6DF861C700
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
    • String ID: CONOUT$
    • API String ID: 3230265001-3130406586
    • Opcode ID: e1f350374d3b5acb8ca91a9a2d00138dee3832237cd9a78898d335e84adadcc7
    • Instruction ID: 25a61b38e909db8e12ab6c7e37132f27f3619e175910f513288163ef3e0fb3d9
    • Opcode Fuzzy Hash: e1f350374d3b5acb8ca91a9a2d00138dee3832237cd9a78898d335e84adadcc7
    • Instruction Fuzzy Hash: 58115E21B28A45C6E7509B52F885339ABA5FF98BE4F044238EA9DC7794DF7CD414C740
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetLastError.KERNEL32(?,?,?,00007FF6841001A9,?,?,?,?,00007FF684100227,?,?,00000000,00007FF6841016B2,?,?,?), ref: 00007FF6841017D7
    • FlsSetValue.KERNEL32(?,?,?,00007FF6841001A9,?,?,?,?,00007FF684100227,?,?,00000000,00007FF6841016B2,?,?,?), ref: 00007FF68410180D
    • FlsSetValue.KERNEL32(?,?,?,00007FF6841001A9,?,?,?,?,00007FF684100227,?,?,00000000,00007FF6841016B2,?,?,?), ref: 00007FF68410183A
    • FlsSetValue.KERNEL32(?,?,?,00007FF6841001A9,?,?,?,?,00007FF684100227,?,?,00000000,00007FF6841016B2,?,?,?), ref: 00007FF68410184B
    • FlsSetValue.KERNEL32(?,?,?,00007FF6841001A9,?,?,?,?,00007FF684100227,?,?,00000000,00007FF6841016B2,?,?,?), ref: 00007FF68410185C
    • SetLastError.KERNEL32(?,?,?,00007FF6841001A9,?,?,?,?,00007FF684100227,?,?,00000000,00007FF6841016B2,?,?,?), ref: 00007FF684101877
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: Value$ErrorLast
    • String ID:
    • API String ID: 2506987500-0
    • Opcode ID: d600949866d499faba61cc66606a69b418155eeddc8e0a7874b57269f556758f
    • Instruction ID: aa5cbf788600325f6bdb10da63974e3fa4e67ceb3313f236f794e0adab87b432
    • Opcode Fuzzy Hash: d600949866d499faba61cc66606a69b418155eeddc8e0a7874b57269f556758f
    • Instruction Fuzzy Hash: DA118E20E4C242C2FA65673165C1139AE82BF44BF0F14473EE8AEC76D6EE2CE562C700
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
    • String ID: csm$f
    • API String ID: 2395640692-629598281
    • Opcode ID: 5674842d865fa054f7754243fd4700562c79f163664243a12ae4c759dea48c34
    • Instruction ID: d3c15e3eec9f54a2015e48cbd906ed29e6425551af362a024d4dd61839cf9787
    • Opcode Fuzzy Hash: 5674842d865fa054f7754243fd4700562c79f163664243a12ae4c759dea48c34
    • Instruction Fuzzy Hash: 58519032A1A602C6DB15CB15E484A2A3795FF44BA8F50853ADE5E877C8DFB8F841C708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: AddressFreeHandleLibraryModuleProc
    • String ID: CorExitProcess$mscoree.dll
    • API String ID: 4061214504-1276376045
    • Opcode ID: b4d5c3b408ad346616be52e1836f78b68c73631f55f6072fc6aabb82c80843de
    • Instruction ID: 453e985d824c34297c28c1254a48206bb338f59a441712830b9f9355896d428f
    • Opcode Fuzzy Hash: b4d5c3b408ad346616be52e1836f78b68c73631f55f6072fc6aabb82c80843de
    • Instruction Fuzzy Hash: 48F09661B1960AC1EB108F24E4C577AA760BF487A1F54523DCAAE851F8DF7CD049C340
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _set_statfp
    • String ID:
    • API String ID: 1156100317-0
    • Opcode ID: f7d7966ef37214f077654dcdb013ff297ba3e4a7513d63f7aababb699d8a5442
    • Instruction ID: 5663aefcac09fae45e0e939e38797000adaa8d7d863d5ea0ffcafbce3f37c3fa
    • Opcode Fuzzy Hash: f7d7966ef37214f077654dcdb013ff297ba3e4a7513d63f7aababb699d8a5442
    • Instruction Fuzzy Hash: 27119E66E9CB03C1F7641129E8D237919807F953B0F49463CEBFE962DACE2CA861C201
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • FlsGetValue.KERNEL32(?,?,?,00007FF6840FFD23,?,?,00000000,00007FF6840FFFBE,?,?,?,?,00000000,00007FF6840FFF4A), ref: 00007FF6841018AF
    • FlsSetValue.KERNEL32(?,?,?,00007FF6840FFD23,?,?,00000000,00007FF6840FFFBE,?,?,?,?,00000000,00007FF6840FFF4A), ref: 00007FF6841018CE
    • FlsSetValue.KERNEL32(?,?,?,00007FF6840FFD23,?,?,00000000,00007FF6840FFFBE,?,?,?,?,00000000,00007FF6840FFF4A), ref: 00007FF6841018F6
    • FlsSetValue.KERNEL32(?,?,?,00007FF6840FFD23,?,?,00000000,00007FF6840FFFBE,?,?,?,?,00000000,00007FF6840FFF4A), ref: 00007FF684101907
    • FlsSetValue.KERNEL32(?,?,?,00007FF6840FFD23,?,?,00000000,00007FF6840FFFBE,?,?,?,?,00000000,00007FF6840FFF4A), ref: 00007FF684101918
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: Value
    • String ID:
    • API String ID: 3702945584-0
    • Opcode ID: b9d0f39cf87e550e7373e0bcab485d5e02ce5d5aaf4965d8be53be057f4360ae
    • Instruction ID: 0d7a08c3410a2c57fdc9f8b1fdaa67ce3187c508bbdcc7ecca26d02d408bd285
    • Opcode Fuzzy Hash: b9d0f39cf87e550e7373e0bcab485d5e02ce5d5aaf4965d8be53be057f4360ae
    • Instruction Fuzzy Hash: 37116D20E0D642C1FA696325A5C1179AE817F447B0F04533DE8AE866DAEE3CE462C700
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: Value
    • String ID:
    • API String ID: 3702945584-0
    • Opcode ID: a549a77e1e528f092dfa9b4d36fdf3ba9a090c7c2449dc1340dcf4919b041a0d
    • Instruction ID: d95fbaf5b2936ee87659cb8e07528a19ec07528e2b0b42b94a8db30dc59b6107
    • Opcode Fuzzy Hash: a549a77e1e528f092dfa9b4d36fdf3ba9a090c7c2449dc1340dcf4919b041a0d
    • Instruction Fuzzy Hash: D6112A14E49247C2FA69633158D15795E827F45BB0E041B3DE9BECA2C2EE3DF462D740
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: UTF-16LEUNICODE$UTF-8$ccs
    • API String ID: 3215553584-1196891531
    • Opcode ID: 3de14f5d5c9a4aabf8cf3c2becf0dd26e9540cc5455f39d4de4dde48d87fb953
    • Instruction ID: 069f79c1488583982ab4f38813e2411aebd666207407068eee097e52b02d3e90
    • Opcode Fuzzy Hash: 3de14f5d5c9a4aabf8cf3c2becf0dd26e9540cc5455f39d4de4dde48d87fb953
    • Instruction Fuzzy Hash: 6D81B132E0C242C5F7A54A2886D4278AFA1BF11748F59903DCA8EC7695EF2FE861D305
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: CallEncodePointerTranslator
    • String ID: MOC$RCC
    • API String ID: 3544855599-2084237596
    • Opcode ID: c77e720224de488b4c413800bc05c3d3e6fba984749f43d5e87a3be5d7cbd9fb
    • Instruction ID: 89c5ee3a9a2a6160ddfe349d11c6d145cabd1f4091a1c1a23b2c162d69d01f7e
    • Opcode Fuzzy Hash: c77e720224de488b4c413800bc05c3d3e6fba984749f43d5e87a3be5d7cbd9fb
    • Instruction Fuzzy Hash: 4B614A36A09A45CAE720CF65D4803AE77A0FB84B88F144239EF8D57B99DFB8E055C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
    • String ID: csm$csm
    • API String ID: 3896166516-3733052814
    • Opcode ID: d6ab328318f37516ec412dab3fcf5e3b622bb538729ab8e4a9228887a9b4d15e
    • Instruction ID: 73a1f0a084e9042ea1e893a0ce01face96b2a28b4e1ba6987b7e9ead7e5f48b6
    • Opcode Fuzzy Hash: d6ab328318f37516ec412dab3fcf5e3b622bb538729ab8e4a9228887a9b4d15e
    • Instruction Fuzzy Hash: 05519F3290A252C6EB648F15948426AB7A0FF94B89F544139DACC87BD6CFBCF451CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: FileWrite$ConsoleErrorLastOutput
    • String ID:
    • API String ID: 2718003287-0
    • Opcode ID: 3935df83813671c5302a5d3511c6a77fec9548675e737d46d0d1eb1d1baf9780
    • Instruction ID: 2b24f52aadf6db983477e21e322f8bbf32392153eea5237aac9180fcd1c8b683
    • Opcode Fuzzy Hash: 3935df83813671c5302a5d3511c6a77fec9548675e737d46d0d1eb1d1baf9780
    • Instruction Fuzzy Hash: 0CD10222B08A85C9E711CF79D5802BC3BB1FB55798B10423ADE9D97B99DF38D526C340
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo$_get_daylight
    • String ID:
    • API String ID: 72036449-0
    • Opcode ID: 84fa70e16dec7406d439eee739c354eb90958fd93df13ea6f15e958565aa6c79
    • Instruction ID: 9687cd04a770cfdeb6e49bdb64029720cc990aecd9c016366f43ac00d1c077d4
    • Opcode Fuzzy Hash: 84fa70e16dec7406d439eee739c354eb90958fd93df13ea6f15e958565aa6c79
    • Instruction Fuzzy Hash: 2B51C136D0CA02C2F7694A28998137E6ED0BF85B14F19503DDACDCA2DADE3CE860D741
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: ErrorFileLastWrite
    • String ID: U
    • API String ID: 442123175-4171548499
    • Opcode ID: ec5d196d87fa6afedfc1b7cbf2143a831a76c7b6d5d102da5dfce111a9055b17
    • Instruction ID: 227fb4eaccd2511157720ffa0e214e3dbef4ad76942c37c640974de2fae02003
    • Opcode Fuzzy Hash: ec5d196d87fa6afedfc1b7cbf2143a831a76c7b6d5d102da5dfce111a9055b17
    • Instruction Fuzzy Hash: B241B162B18A41C2EB509F25E4847B96BA1FB98794F404135EE8EC7B84EF7CD451C740
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2078013824.00007FF6840F1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6840F0000, based on PE: true
    • Associated: 00000000.00000002.2077998888.00007FF6840F0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078034648.00007FF68410F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078050634.00007FF68411A000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2078064756.00007FF684123000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6840f0000_grade.jbxd
    Similarity
    • API ID: ExceptionFileHeaderRaise
    • String ID: csm
    • API String ID: 2573137834-1018135373
    • Opcode ID: 60492db50927d80b48fe4c7c35c2f26e12b515590f004ef549d900166b0380f4
    • Instruction ID: be336a911e9ae028df3ac082b2917423d30c36be125a5978007de6ade2a307f8
    • Opcode Fuzzy Hash: 60492db50927d80b48fe4c7c35c2f26e12b515590f004ef549d900166b0380f4
    • Instruction Fuzzy Hash: CE114F32A19B4182EB548F15E48026ABBA4FF88B94F584238EECC47799DFBCD551C700
    Uniqueness

    Uniqueness Score: -1.00%