Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Clangen.exe

Overview

General Information

Sample name:Clangen.exe
Analysis ID:1430907
MD5:30712264600cb5dbac0cf9436afb8057
SHA1:87d07b89f5f94a705f4c8c3017887fe204c8582e
SHA256:4cca30c7f69113632bcbc829ffab14614599624752d021bc00d232bcea54c596
Tags:exe
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Extensive use of GetProcAddress (often used to hide API calls)
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains sections with non-standard names
Program does not show much activity (idle)
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • Clangen.exe (PID: 7108 cmdline: "C:\Users\user\Desktop\Clangen.exe" MD5: 30712264600CB5DBAC0CF9436AFB8057)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Clangen.exeVirustotal: Detection: 11%Perma Link
Source: Clangen.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F396714 _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,0_2_00007FF67F396714
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F387820 FindFirstFileExW,FindClose,0_2_00007FF67F387820
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F396714 _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,0_2_00007FF67F396714
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A09B4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF67F3A09B4
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A5D6C0_2_00007FF67F3A5D6C
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F39D0980_2_00007FF67F39D098
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3880A00_2_00007FF67F3880A0
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A509C0_2_00007FF67F3A509C
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3967140_2_00007FF67F396714
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3867800_2_00007FF67F386780
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F396F980_2_00007FF67F396F98
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F390FB40_2_00007FF67F390FB4
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F394F500_2_00007FF67F394F50
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3928000_2_00007FF67F392800
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A58200_2_00007FF67F3A5820
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F391E700_2_00007FF67F391E70
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3967140_2_00007FF67F396714
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F39D7180_2_00007FF67F39D718
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F390DB00_2_00007FF67F390DB0
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3965600_2_00007FF67F396560
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F39FA080_2_00007FF67F39FA08
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A4E200_2_00007FF67F3A4E20
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A2D300_2_00007FF67F3A2D30
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F381B900_2_00007FF67F381B90
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F398BA00_2_00007FF67F398BA0
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F390BA40_2_00007FF67F390BA4
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A8B680_2_00007FF67F3A8B68
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F392C040_2_00007FF67F392C04
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F39CC040_2_00007FF67F39CC04
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3913C40_2_00007FF67F3913C4
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3909A00_2_00007FF67F3909A0
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A09B40_2_00007FF67F3A09B4
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F39FA080_2_00007FF67F39FA08
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3911C00_2_00007FF67F3911C0
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A31CC0_2_00007FF67F3A31CC
Source: C:\Users\user\Desktop\Clangen.exeCode function: String function: 00007FF67F382770 appears 41 times
Source: classification engineClassification label: mal48.winEXE@1/0@0/0
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3874B0 GetLastError,FormatMessageW,WideCharToMultiByte,0_2_00007FF67F3874B0
Source: Clangen.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Clangen.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: Clangen.exeVirustotal: Detection: 11%
Source: C:\Users\user\Desktop\Clangen.exeFile read: C:\Users\user\Desktop\Clangen.exeJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\Clangen.exeSection loaded: wintypes.dllJump to behavior
Source: Clangen.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: Clangen.exeStatic file information: File size 5303823 > 1048576
Source: Clangen.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: Clangen.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: Clangen.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: Clangen.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Clangen.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: Clangen.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: Clangen.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Clangen.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Clangen.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: Clangen.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: Clangen.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: Clangen.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: Clangen.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: Clangen.exeStatic PE information: section name: _RDATA
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3D10CC push rbp; retn 0000h0_2_00007FF67F3D10CD
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3D10E4 push rcx; retn 0000h0_2_00007FF67F3D10ED
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3855D0 GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_00007FF67F3855D0
Source: C:\Users\user\Desktop\Clangen.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-17122
Source: C:\Users\user\Desktop\Clangen.exeAPI coverage: 7.1 %
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F396714 _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,0_2_00007FF67F396714
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F387820 FindFirstFileExW,FindClose,0_2_00007FF67F387820
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F396714 _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,0_2_00007FF67F396714
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A09B4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF67F3A09B4
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F38B69C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF67F38B69C
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A25A0 GetProcessHeap,0_2_00007FF67F3A25A0
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F38B880 SetUnhandledExceptionFilter,0_2_00007FF67F38B880
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F38B69C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF67F38B69C
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F38AE00 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF67F38AE00
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F399AE4 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF67F399AE4
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A89B0 cpuid 0_2_00007FF67F3A89B0
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F38B580 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF67F38B580
Source: C:\Users\user\Desktop\Clangen.exeCode function: 0_2_00007FF67F3A509C _get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,0_2_00007FF67F3A509C
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Native API
1
DLL Side-Loading
1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
OS Credential Dumping2
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
DLL Side-Loading
LSASS Memory2
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Obfuscated Files or Information
Security Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS13
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Clangen.exe8%ReversingLabsWin64.Trojan.Malgent
Clangen.exe11%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1430907
Start date and time:2024-04-24 10:57:08 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 2m 11s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:1
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:Clangen.exe
Detection:MAL
Classification:mal48.winEXE@1/0@0/0
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 98%
  • Number of executed functions: 20
  • Number of non-executed functions: 79
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Stop behavior analysis, all processes terminated
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
File type:PE32+ executable (GUI) x86-64, for MS Windows
Entropy (8bit):7.986906124417028
TrID:
  • Win64 Executable GUI (202006/5) 92.65%
  • Win64 Executable (generic) (12005/4) 5.51%
  • Generic Win/DOS Executable (2004/3) 0.92%
  • DOS Executable Generic (2002/1) 0.92%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:Clangen.exe
File size:5'303'823 bytes
MD5:30712264600cb5dbac0cf9436afb8057
SHA1:87d07b89f5f94a705f4c8c3017887fe204c8582e
SHA256:4cca30c7f69113632bcbc829ffab14614599624752d021bc00d232bcea54c596
SHA512:fcf890b818c5461b0cb244ac7436b98411617316de025cc5c8ed5857dc9c4e7477701ac09c47e4b3c77bb6b5a17e3a21d43ded982a21172648bc6b8bcfd6fd8c
SSDEEP:98304:UxnKSckpvmV+8flteWX8HIf0/IznJQoZ7c904Tp0wl:UxKSVOf8HJ/aWoGl0w
TLSH:943633AC935005B5ECEE923EC085D938E33271922B65D6CF07B4857B1F636D29C3BA61
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........6...W...W...W.../...W.../...W.../...W...+l..W...+...W...+...W...+...W.../...W...W..)W..e+...W..e+...W..Rich.W.................
Icon Hash:33c4cce8d8ece013
Entrypoint:0x14000b310
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x140000000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Time Stamp:0x66118D33 [Sat Apr 6 17:58:11 2024 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:5
OS Version Minor:2
File Version Major:5
File Version Minor:2
Subsystem Version Major:5
Subsystem Version Minor:2
Import Hash:0b5552dccd9d0a834cea55c0c8fc05be
Instruction
dec eax
sub esp, 28h
call 00007EFCB8F7E77Ch
dec eax
add esp, 28h
jmp 00007EFCB8F7E38Fh
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
dec eax
sub esp, 28h
call 00007EFCB8F7ECF4h
test eax, eax
je 00007EFCB8F7E533h
dec eax
mov eax, dword ptr [00000030h]
dec eax
mov ecx, dword ptr [eax+08h]
jmp 00007EFCB8F7E517h
dec eax
cmp ecx, eax
je 00007EFCB8F7E526h
xor eax, eax
dec eax
cmpxchg dword ptr [0004121Ch], ecx
jne 00007EFCB8F7E500h
xor al, al
dec eax
add esp, 28h
ret
mov al, 01h
jmp 00007EFCB8F7E509h
int3
int3
int3
inc eax
push ebx
dec eax
sub esp, 20h
movzx eax, byte ptr [00041207h]
test ecx, ecx
mov ebx, 00000001h
cmove eax, ebx
mov byte ptr [000411F7h], al
call 00007EFCB8F7EAF3h
call 00007EFCB8F7FC22h
test al, al
jne 00007EFCB8F7E516h
xor al, al
jmp 00007EFCB8F7E526h
call 00007EFCB8F8C201h
test al, al
jne 00007EFCB8F7E51Bh
xor ecx, ecx
call 00007EFCB8F7FC32h
jmp 00007EFCB8F7E4FCh
mov al, bl
dec eax
add esp, 20h
pop ebx
ret
int3
int3
int3
inc eax
push ebx
dec eax
sub esp, 20h
cmp byte ptr [000411BCh], 00000000h
mov ebx, ecx
jne 00007EFCB8F7E579h
cmp ecx, 01h
jnbe 00007EFCB8F7E57Ch
call 00007EFCB8F7EC5Ah
test eax, eax
je 00007EFCB8F7E53Ah
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x3bd0c0x78.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x520000x59f8.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x4e0000x20c4.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x580000x758.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x394800x1c.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x393400x140.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x2a0000x418.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x288000x28800443d51fb84559b563832949912f06b00False0.5583465952932098data6.488023200564254IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x2a0000x12b160x12c00e3c24e0b90ae51ee1c9200da80a54eb0False0.5154817708333334data5.824672921197667IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x3d0000x103f80xe00afabb66fdcd2825de5909f10c900fca7False0.13309151785714285DOS executable (block device driver \377\3)1.8096886543499544IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.pdata0x4e0000x20c40x22007b210ceebebc00c96d1c55c2b456bbb4False0.47794117647058826data5.274096406482418IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
_RDATA0x510000x15c0x200c059b775abce97446903f3597b027faeFalse0.384765625data2.808567494642619IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0x520000x59f80x5a0071001e43f8a7cd7ae6e0b529307b3a2fFalse0.9283420138888889data7.8770895859758925IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x580000x7580x80011aaafc72361ec8886a740c3e209ceb3False0.544921875data5.2576643703968475IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_ICON0x522080x307PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0141935483870967
RT_ICON0x525100x527PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.0083396512509477
RT_ICON0x52a380x748PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.0059012875536482
RT_ICON0x531800xba4PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.0036912751677853
RT_ICON0x53d240xebaPNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.0029177718832891
RT_ICON0x54be00x17ebPNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced1.0017965049812183
RT_ICON0x563cc0x1035PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.8949144372137865
RT_GROUP_ICON0x574040x68data0.7403846153846154
RT_MANIFEST0x5746c0x58cXML 1.0 document, ASCII text, with CRLF line terminators0.4450704225352113
DLLImport
USER32.dllCreateWindowExW, MessageBoxW, MessageBoxA, SystemParametersInfoW, DestroyIcon, SetWindowLongPtrW, GetWindowLongPtrW, GetClientRect, InvalidateRect, ReleaseDC, GetDC, DrawTextW, GetDialogBaseUnits, EndDialog, DialogBoxIndirectParamW, MoveWindow, SendMessageW
COMCTL32.dll
KERNEL32.dllGetStringTypeW, GetFileAttributesExW, HeapReAlloc, FlushFileBuffers, GetCurrentDirectoryW, IsValidCodePage, GetACP, GetModuleHandleW, MulDiv, GetLastError, SetDllDirectoryW, GetModuleFileNameW, GetProcAddress, GetCommandLineW, GetEnvironmentVariableW, GetOEMCP, ExpandEnvironmentStringsW, CreateDirectoryW, GetTempPathW, WaitForSingleObject, Sleep, GetExitCodeProcess, CreateProcessW, GetStartupInfoW, FreeLibrary, LoadLibraryExW, SetConsoleCtrlHandler, FindClose, FindFirstFileExW, CloseHandle, GetCurrentProcess, LocalFree, FormatMessageW, MultiByteToWideChar, WideCharToMultiByte, GetCPInfo, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetProcessHeap, GetTimeZoneInformation, HeapSize, WriteConsoleW, SetEnvironmentVariableW, RtlUnwindEx, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, SetEndOfFile, SetLastError, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, RaiseException, RtlPcToFileHeader, GetCommandLineA, CreateFileW, GetDriveTypeW, GetFileInformationByHandle, GetFileType, PeekNamedPipe, SystemTimeToTzSpecificLocalTime, FileTimeToSystemTime, GetFullPathNameW, RemoveDirectoryW, FindNextFileW, SetStdHandle, DeleteFileW, ReadFile, GetStdHandle, WriteFile, ExitProcess, GetModuleHandleExW, HeapFree, GetConsoleMode, ReadConsoleW, SetFilePointerEx, GetConsoleOutputCP, GetFileSizeEx, HeapAlloc, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, CompareStringW, LCMapStringW
ADVAPI32.dllOpenProcessToken, GetTokenInformation, ConvertStringSecurityDescriptorToSecurityDescriptorW, ConvertSidToStringSidW
GDI32.dllSelectObject, DeleteObject, CreateFontIndirectW
No network behavior found

Click to jump to process

Click to jump to process

Target ID:0
Start time:10:58:01
Start date:24/04/2024
Path:C:\Users\user\Desktop\Clangen.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\Clangen.exe"
Imagebase:0x7ff67f380000
File size:5'303'823 bytes
MD5 hash:30712264600CB5DBAC0CF9436AFB8057
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Reset < >

    Execution Graph

    Execution Coverage:6.5%
    Dynamic/Decrypted Code Coverage:0%
    Signature Coverage:12.9%
    Total number of Nodes:2000
    Total number of Limit Nodes:38
    execution_graph 18656 7ff67f3a96f9 18657 7ff67f3a9712 18656->18657 18658 7ff67f3a9708 18656->18658 18660 7ff67f39f7e8 LeaveCriticalSection 18658->18660 17756 7ff67f394290 17757 7ff67f39429b 17756->17757 17765 7ff67f39e354 17757->17765 17778 7ff67f39f788 EnterCriticalSection 17765->17778 17876 7ff67f3a6fa0 17879 7ff67f3a1730 17876->17879 17880 7ff67f3a173d 17879->17880 17884 7ff67f3a1782 17879->17884 17885 7ff67f39a6f4 17880->17885 17886 7ff67f39a720 FlsSetValue 17885->17886 17887 7ff67f39a705 FlsGetValue 17885->17887 17889 7ff67f39a712 17886->17889 17890 7ff67f39a72d 17886->17890 17888 7ff67f39a71a 17887->17888 17887->17889 17888->17886 17891 7ff67f39a718 17889->17891 17892 7ff67f39920c __CxxCallCatchBlock 45 API calls 17889->17892 17893 7ff67f39dd40 memcpy_s 11 API calls 17890->17893 17905 7ff67f3a1404 17891->17905 17894 7ff67f39a795 17892->17894 17895 7ff67f39a73c 17893->17895 17896 7ff67f39a75a FlsSetValue 17895->17896 17897 7ff67f39a74a FlsSetValue 17895->17897 17899 7ff67f39a766 FlsSetValue 17896->17899 17900 7ff67f39a778 17896->17900 17898 7ff67f39a753 17897->17898 17901 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17898->17901 17899->17898 17902 7ff67f39a3c4 memcpy_s 11 API calls 17900->17902 17901->17889 17903 7ff67f39a780 17902->17903 17904 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17903->17904 17904->17891 17928 7ff67f3a1674 17905->17928 17907 7ff67f3a1439 17943 7ff67f3a1104 17907->17943 17910 7ff67f39cacc _fread_nolock 12 API calls 17911 7ff67f3a1467 17910->17911 17912 7ff67f3a146f 17911->17912 17914 7ff67f3a147e 17911->17914 17913 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17912->17913 17924 7ff67f3a1456 17913->17924 17914->17914 17950 7ff67f3a17ac 17914->17950 17917 7ff67f3a157a 17918 7ff67f394444 memcpy_s 11 API calls 17917->17918 17920 7ff67f3a157f 17918->17920 17919 7ff67f3a15d5 17922 7ff67f3a163c 17919->17922 17961 7ff67f3a0f34 17919->17961 17923 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17920->17923 17921 7ff67f3a1594 17921->17919 17925 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17921->17925 17927 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17922->17927 17923->17924 17924->17884 17925->17919 17927->17924 17929 7ff67f3a1697 17928->17929 17931 7ff67f3a16a1 17929->17931 17976 7ff67f39f788 EnterCriticalSection 17929->17976 17933 7ff67f3a1713 17931->17933 17935 7ff67f39920c __CxxCallCatchBlock 45 API calls 17931->17935 17933->17907 17937 7ff67f3a172b 17935->17937 17938 7ff67f3a1782 17937->17938 17940 7ff67f39a6f4 50 API calls 17937->17940 17938->17907 17941 7ff67f3a176c 17940->17941 17942 7ff67f3a1404 65 API calls 17941->17942 17942->17938 17944 7ff67f394a1c 45 API calls 17943->17944 17945 7ff67f3a1118 17944->17945 17946 7ff67f3a1124 GetOEMCP 17945->17946 17947 7ff67f3a1136 17945->17947 17948 7ff67f3a114b 17946->17948 17947->17948 17949 7ff67f3a113b GetACP 17947->17949 17948->17910 17948->17924 17949->17948 17951 7ff67f3a1104 47 API calls 17950->17951 17953 7ff67f3a17d9 17951->17953 17952 7ff67f3a192f 17954 7ff67f38ad80 _wfindfirst32i64 8 API calls 17952->17954 17953->17952 17955 7ff67f3a1816 IsValidCodePage 17953->17955 17957 7ff67f3a1830 __scrt_get_show_window_mode 17953->17957 17956 7ff67f3a1571 17954->17956 17955->17952 17958 7ff67f3a1827 17955->17958 17956->17917 17956->17921 17977 7ff67f3a121c 17957->17977 17958->17957 17959 7ff67f3a1856 GetCPInfo 17958->17959 17959->17952 17959->17957 18048 7ff67f39f788 EnterCriticalSection 17961->18048 17978 7ff67f3a1259 GetCPInfo 17977->17978 17979 7ff67f3a134f 17977->17979 17978->17979 17984 7ff67f3a126c 17978->17984 17980 7ff67f38ad80 _wfindfirst32i64 8 API calls 17979->17980 17982 7ff67f3a13ee 17980->17982 17982->17952 17988 7ff67f3a1f60 17984->17988 17987 7ff67f3a6f04 54 API calls 17987->17979 17989 7ff67f394a1c 45 API calls 17988->17989 17990 7ff67f3a1fa2 17989->17990 17991 7ff67f39e7f0 _fread_nolock MultiByteToWideChar 17990->17991 17993 7ff67f3a1fd8 17991->17993 17992 7ff67f3a1fdf 17996 7ff67f38ad80 _wfindfirst32i64 8 API calls 17992->17996 17993->17992 17994 7ff67f3a2008 __scrt_get_show_window_mode 17993->17994 17995 7ff67f39cacc _fread_nolock 12 API calls 17993->17995 17997 7ff67f3a209c 17993->17997 17994->17997 18000 7ff67f39e7f0 _fread_nolock MultiByteToWideChar 17994->18000 17995->17994 17998 7ff67f3a12e3 17996->17998 17997->17992 17999 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17997->17999 18003 7ff67f3a6f04 17998->18003 17999->17992 18001 7ff67f3a207e 18000->18001 18001->17997 18002 7ff67f3a2082 GetStringTypeW 18001->18002 18002->17997 18004 7ff67f394a1c 45 API calls 18003->18004 18005 7ff67f3a6f29 18004->18005 18008 7ff67f3a6bd0 18005->18008 18009 7ff67f3a6c11 18008->18009 18010 7ff67f39e7f0 _fread_nolock MultiByteToWideChar 18009->18010 18013 7ff67f3a6c5b 18010->18013 18011 7ff67f3a6ed9 18012 7ff67f38ad80 _wfindfirst32i64 8 API calls 18011->18012 18014 7ff67f3a1316 18012->18014 18013->18011 18015 7ff67f39cacc _fread_nolock 12 API calls 18013->18015 18016 7ff67f3a6d91 18013->18016 18018 7ff67f3a6c93 18013->18018 18014->17987 18015->18018 18016->18011 18017 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18016->18017 18017->18011 18018->18016 18019 7ff67f39e7f0 _fread_nolock MultiByteToWideChar 18018->18019 18020 7ff67f3a6d06 18019->18020 18020->18016 18039 7ff67f39e18c 18020->18039 18023 7ff67f3a6d51 18023->18016 18026 7ff67f39e18c __crtLCMapStringW 6 API calls 18023->18026 18024 7ff67f3a6da2 18025 7ff67f39cacc _fread_nolock 12 API calls 18024->18025 18027 7ff67f3a6e74 18024->18027 18029 7ff67f3a6dc0 18024->18029 18025->18029 18026->18016 18027->18016 18028 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18027->18028 18028->18016 18029->18016 18030 7ff67f39e18c __crtLCMapStringW 6 API calls 18029->18030 18031 7ff67f3a6e40 18030->18031 18031->18027 18032 7ff67f3a6e60 18031->18032 18033 7ff67f3a6e76 18031->18033 18035 7ff67f39f0b8 WideCharToMultiByte 18032->18035 18034 7ff67f39f0b8 WideCharToMultiByte 18033->18034 18036 7ff67f3a6e6e 18034->18036 18035->18036 18036->18027 18037 7ff67f3a6e8e 18036->18037 18037->18016 18038 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18037->18038 18038->18016 18040 7ff67f39ddb8 __crtLCMapStringW 5 API calls 18039->18040 18041 7ff67f39e1ca 18040->18041 18042 7ff67f39e1d2 18041->18042 18045 7ff67f39e278 18041->18045 18042->18016 18042->18023 18042->18024 18044 7ff67f39e23b LCMapStringW 18044->18042 18046 7ff67f39ddb8 __crtLCMapStringW 5 API calls 18045->18046 18047 7ff67f39e2a6 __crtLCMapStringW 18046->18047 18047->18044 18069 7ff67f39a4a0 18070 7ff67f39a4ba 18069->18070 18071 7ff67f39a4a5 18069->18071 18075 7ff67f39a4c0 18071->18075 18076 7ff67f39a50a 18075->18076 18077 7ff67f39a502 18075->18077 18079 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18076->18079 18078 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18077->18078 18078->18076 18080 7ff67f39a517 18079->18080 18081 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18080->18081 18082 7ff67f39a524 18081->18082 18083 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18082->18083 18084 7ff67f39a531 18083->18084 18085 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18084->18085 18086 7ff67f39a53e 18085->18086 18087 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18086->18087 18088 7ff67f39a54b 18087->18088 18089 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18088->18089 18090 7ff67f39a558 18089->18090 18091 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18090->18091 18092 7ff67f39a565 18091->18092 18093 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18092->18093 18094 7ff67f39a575 18093->18094 18095 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18094->18095 18096 7ff67f39a585 18095->18096 18101 7ff67f39a364 18096->18101 18115 7ff67f39f788 EnterCriticalSection 18101->18115 14894 7ff67f38b19c 14915 7ff67f38b36c 14894->14915 14897 7ff67f38b2e8 15019 7ff67f38b69c IsProcessorFeaturePresent 14897->15019 14898 7ff67f38b1b8 __scrt_acquire_startup_lock 14900 7ff67f38b2f2 14898->14900 14905 7ff67f38b1d6 __scrt_release_startup_lock 14898->14905 14901 7ff67f38b69c 7 API calls 14900->14901 14903 7ff67f38b2fd __CxxCallCatchBlock 14901->14903 14902 7ff67f38b1fb 14904 7ff67f38b281 14921 7ff67f38b7e8 14904->14921 14905->14902 14905->14904 15008 7ff67f398984 14905->15008 14907 7ff67f38b286 14924 7ff67f381000 14907->14924 14912 7ff67f38b2a9 14912->14903 15015 7ff67f38b500 14912->15015 15026 7ff67f38b96c 14915->15026 14918 7ff67f38b1b0 14918->14897 14918->14898 14919 7ff67f38b39b __scrt_initialize_crt 14919->14918 15028 7ff67f38cac8 14919->15028 15055 7ff67f38c210 14921->15055 14925 7ff67f38100b 14924->14925 15057 7ff67f387600 14925->15057 14927 7ff67f38101d 15064 7ff67f394f14 14927->15064 14929 7ff67f38367b 15071 7ff67f381af0 14929->15071 14933 7ff67f38ad80 _wfindfirst32i64 8 API calls 14934 7ff67f3837ae 14933->14934 15013 7ff67f38b82c GetModuleHandleW 14934->15013 14935 7ff67f383699 14999 7ff67f38379a 14935->14999 15087 7ff67f383b20 14935->15087 14937 7ff67f3836cb 14937->14999 15090 7ff67f386990 14937->15090 14939 7ff67f3836e7 14940 7ff67f383733 14939->14940 14941 7ff67f386990 61 API calls 14939->14941 15105 7ff67f386f90 14940->15105 14947 7ff67f383708 __vcrt_freefls 14941->14947 14943 7ff67f383748 15109 7ff67f3819d0 14943->15109 14946 7ff67f38383d 14949 7ff67f383868 14946->14949 15211 7ff67f383280 14946->15211 14947->14940 14951 7ff67f386f90 58 API calls 14947->14951 14948 7ff67f3819d0 121 API calls 14950 7ff67f38377e 14948->14950 14960 7ff67f3838ab 14949->14960 15120 7ff67f387a30 14949->15120 14955 7ff67f383782 14950->14955 14956 7ff67f3837c0 14950->14956 14951->14940 14954 7ff67f383888 14957 7ff67f38388d 14954->14957 14958 7ff67f38389e SetDllDirectoryW 14954->14958 15175 7ff67f382770 14955->15175 14956->14946 15188 7ff67f383cb0 14956->15188 14961 7ff67f382770 59 API calls 14957->14961 14958->14960 15134 7ff67f385e40 14960->15134 14961->14999 14966 7ff67f383906 14974 7ff67f3839c6 14966->14974 14980 7ff67f383919 14966->14980 14967 7ff67f3837e2 14971 7ff67f382770 59 API calls 14967->14971 14970 7ff67f383810 14970->14946 14973 7ff67f383815 14970->14973 14971->14999 14972 7ff67f3838c8 14972->14966 15225 7ff67f385640 14972->15225 15207 7ff67f38f2ac 14973->15207 15329 7ff67f383110 14974->15329 14979 7ff67f3839d3 14979->14999 15339 7ff67f386f20 14979->15339 14989 7ff67f383965 14980->14989 15325 7ff67f381b30 14980->15325 14981 7ff67f3838dd 15245 7ff67f3855d0 14981->15245 14982 7ff67f3838fc 15319 7ff67f385890 14982->15319 14987 7ff67f3838e7 14987->14982 14990 7ff67f3838eb 14987->14990 14988 7ff67f3839fb 14991 7ff67f386990 61 API calls 14988->14991 14989->14999 15138 7ff67f3830b0 14989->15138 15313 7ff67f385c90 14990->15313 14994 7ff67f383a07 14991->14994 14997 7ff67f383a18 14994->14997 14994->14999 14995 7ff67f3839a1 14998 7ff67f385890 FreeLibrary 14995->14998 15346 7ff67f386fd0 14997->15346 14998->14999 14999->14933 15002 7ff67f385890 FreeLibrary 15004 7ff67f383a3c 15002->15004 15003 7ff67f383a57 15383 7ff67f381ab0 15003->15383 15004->15003 15369 7ff67f386c90 15004->15369 15007 7ff67f383a5f 15007->14999 15009 7ff67f39899b 15008->15009 15010 7ff67f3989bc 15008->15010 15009->14904 15011 7ff67f3990d8 45 API calls 15010->15011 15012 7ff67f3989c1 15011->15012 15014 7ff67f38b83d 15013->15014 15014->14912 15017 7ff67f38b511 15015->15017 15016 7ff67f38b2c0 15016->14902 15017->15016 15018 7ff67f38cac8 __scrt_initialize_crt 7 API calls 15017->15018 15018->15016 15020 7ff67f38b6c2 _wfindfirst32i64 __scrt_get_show_window_mode 15019->15020 15021 7ff67f38b6e1 RtlCaptureContext RtlLookupFunctionEntry 15020->15021 15022 7ff67f38b746 __scrt_get_show_window_mode 15021->15022 15023 7ff67f38b70a RtlVirtualUnwind 15021->15023 15024 7ff67f38b778 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 15022->15024 15023->15022 15025 7ff67f38b7ca _wfindfirst32i64 15024->15025 15025->14900 15027 7ff67f38b38e __scrt_dllmain_crt_thread_attach 15026->15027 15027->14918 15027->14919 15029 7ff67f38cad0 15028->15029 15030 7ff67f38cada 15028->15030 15034 7ff67f38ce44 15029->15034 15030->14918 15035 7ff67f38cad5 15034->15035 15036 7ff67f38ce53 15034->15036 15038 7ff67f38ceb0 15035->15038 15042 7ff67f38d080 15036->15042 15039 7ff67f38cedb 15038->15039 15040 7ff67f38cebe DeleteCriticalSection 15039->15040 15041 7ff67f38cedf 15039->15041 15040->15039 15041->15030 15046 7ff67f38cee8 15042->15046 15047 7ff67f38d002 TlsFree 15046->15047 15052 7ff67f38cf2c __vcrt_FlsAlloc 15046->15052 15048 7ff67f38cf5a LoadLibraryExW 15049 7ff67f38cfd1 15048->15049 15050 7ff67f38cf7b GetLastError 15048->15050 15051 7ff67f38cff1 GetProcAddress 15049->15051 15053 7ff67f38cfe8 FreeLibrary 15049->15053 15050->15052 15051->15047 15052->15047 15052->15048 15052->15051 15054 7ff67f38cf9d LoadLibraryExW 15052->15054 15053->15051 15054->15049 15054->15052 15056 7ff67f38b7ff GetStartupInfoW 15055->15056 15056->14907 15059 7ff67f38761f 15057->15059 15058 7ff67f387670 WideCharToMultiByte 15058->15059 15062 7ff67f387718 15058->15062 15059->15058 15061 7ff67f3876c6 WideCharToMultiByte 15059->15061 15059->15062 15063 7ff67f387627 __vcrt_freefls 15059->15063 15061->15059 15061->15062 15387 7ff67f382620 15062->15387 15063->14927 15065 7ff67f39ec40 15064->15065 15066 7ff67f39ec93 15065->15066 15068 7ff67f39ece6 15065->15068 15067 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15066->15067 15070 7ff67f39ecbc 15067->15070 15753 7ff67f39eb18 15068->15753 15070->14929 15072 7ff67f381b05 15071->15072 15073 7ff67f381b20 15072->15073 15761 7ff67f3824d0 15072->15761 15073->14999 15075 7ff67f383ba0 15073->15075 15076 7ff67f38adb0 15075->15076 15077 7ff67f383bac GetModuleFileNameW 15076->15077 15078 7ff67f383bdb 15077->15078 15079 7ff67f383bf2 15077->15079 15080 7ff67f382620 57 API calls 15078->15080 15801 7ff67f387b40 15079->15801 15082 7ff67f383bee 15080->15082 15085 7ff67f38ad80 _wfindfirst32i64 8 API calls 15082->15085 15084 7ff67f382770 59 API calls 15084->15082 15086 7ff67f383c2f 15085->15086 15086->14935 15088 7ff67f381b30 49 API calls 15087->15088 15089 7ff67f383b3d 15088->15089 15089->14937 15091 7ff67f38699a 15090->15091 15092 7ff67f387a30 57 API calls 15091->15092 15093 7ff67f3869bc GetEnvironmentVariableW 15092->15093 15094 7ff67f386a26 15093->15094 15095 7ff67f3869d4 ExpandEnvironmentStringsW 15093->15095 15096 7ff67f38ad80 _wfindfirst32i64 8 API calls 15094->15096 15097 7ff67f387b40 59 API calls 15095->15097 15098 7ff67f386a38 15096->15098 15099 7ff67f3869fc 15097->15099 15098->14939 15099->15094 15100 7ff67f386a06 15099->15100 15812 7ff67f39910c 15100->15812 15103 7ff67f38ad80 _wfindfirst32i64 8 API calls 15104 7ff67f386a1e 15103->15104 15104->14939 15106 7ff67f387a30 57 API calls 15105->15106 15107 7ff67f386fa7 SetEnvironmentVariableW 15106->15107 15108 7ff67f386fbf __vcrt_freefls 15107->15108 15108->14943 15110 7ff67f381b30 49 API calls 15109->15110 15111 7ff67f381a00 15110->15111 15112 7ff67f381b30 49 API calls 15111->15112 15118 7ff67f381a7a 15111->15118 15113 7ff67f381a22 15112->15113 15114 7ff67f383b20 49 API calls 15113->15114 15113->15118 15115 7ff67f381a3b 15114->15115 15819 7ff67f3817b0 15115->15819 15118->14946 15118->14948 15119 7ff67f38f2ac 74 API calls 15119->15118 15121 7ff67f387ad7 MultiByteToWideChar 15120->15121 15122 7ff67f387a51 MultiByteToWideChar 15120->15122 15123 7ff67f387afa 15121->15123 15124 7ff67f387b1f 15121->15124 15125 7ff67f387a9c 15122->15125 15126 7ff67f387a77 15122->15126 15127 7ff67f382620 55 API calls 15123->15127 15124->14954 15125->15121 15131 7ff67f387ab2 15125->15131 15128 7ff67f382620 55 API calls 15126->15128 15129 7ff67f387b0d 15127->15129 15130 7ff67f387a8a 15128->15130 15129->14954 15130->14954 15132 7ff67f382620 55 API calls 15131->15132 15133 7ff67f387ac5 15132->15133 15133->14954 15135 7ff67f385e55 15134->15135 15136 7ff67f3838b0 15135->15136 15137 7ff67f3824d0 59 API calls 15135->15137 15136->14966 15215 7ff67f385ae0 15136->15215 15137->15136 15892 7ff67f384960 15138->15892 15141 7ff67f3830fd 15141->14995 15143 7ff67f3830d4 15143->15141 15948 7ff67f3846e0 15143->15948 15145 7ff67f3830e0 15145->15141 15958 7ff67f384840 15145->15958 15147 7ff67f3830ec 15147->15141 15148 7ff67f38333c 15147->15148 15149 7ff67f383327 15147->15149 15152 7ff67f38335c 15148->15152 15163 7ff67f383372 __vcrt_freefls 15148->15163 15150 7ff67f382770 59 API calls 15149->15150 15151 7ff67f383333 __vcrt_freefls 15150->15151 15153 7ff67f38ad80 _wfindfirst32i64 8 API calls 15151->15153 15154 7ff67f382770 59 API calls 15152->15154 15155 7ff67f3834ca 15153->15155 15154->15151 15155->14995 15158 7ff67f381b30 49 API calls 15158->15163 15159 7ff67f38360b 15160 7ff67f382770 59 API calls 15159->15160 15160->15151 15161 7ff67f3835e5 15162 7ff67f382770 59 API calls 15161->15162 15162->15151 15163->15151 15163->15158 15163->15159 15163->15161 15164 7ff67f3834d6 15163->15164 15963 7ff67f3812b0 15163->15963 15989 7ff67f381780 15163->15989 15165 7ff67f383542 15164->15165 15166 7ff67f39910c 37 API calls 15164->15166 15993 7ff67f3816d0 15165->15993 15166->15165 15169 7ff67f383569 15171 7ff67f39910c 37 API calls 15169->15171 15170 7ff67f383577 15997 7ff67f382ea0 15170->15997 15173 7ff67f383575 15171->15173 16001 7ff67f3823b0 15173->16001 15176 7ff67f382790 15175->15176 15177 7ff67f393be4 49 API calls 15176->15177 15178 7ff67f3827dd __scrt_get_show_window_mode 15177->15178 15179 7ff67f387a30 57 API calls 15178->15179 15180 7ff67f38280a 15179->15180 15181 7ff67f382849 MessageBoxA 15180->15181 15182 7ff67f38280f 15180->15182 15184 7ff67f382863 15181->15184 15183 7ff67f387a30 57 API calls 15182->15183 15185 7ff67f382829 MessageBoxW 15183->15185 15186 7ff67f38ad80 _wfindfirst32i64 8 API calls 15184->15186 15185->15184 15187 7ff67f382873 15186->15187 15187->14999 15189 7ff67f383cbc 15188->15189 15190 7ff67f387a30 57 API calls 15189->15190 15191 7ff67f383ce7 15190->15191 15192 7ff67f387a30 57 API calls 15191->15192 15193 7ff67f383cfa 15192->15193 16528 7ff67f3954c8 15193->16528 15196 7ff67f38ad80 _wfindfirst32i64 8 API calls 15197 7ff67f3837da 15196->15197 15197->14967 15198 7ff67f387200 15197->15198 15199 7ff67f387224 15198->15199 15200 7ff67f38f934 73 API calls 15199->15200 15203 7ff67f3872fb __vcrt_freefls 15199->15203 15201 7ff67f38723e 15200->15201 15201->15203 16945 7ff67f397938 15201->16945 15203->14970 15204 7ff67f38f934 73 API calls 15206 7ff67f387253 15204->15206 15205 7ff67f38f5fc _fread_nolock 53 API calls 15205->15206 15206->15203 15206->15204 15206->15205 15208 7ff67f38f2dc 15207->15208 16960 7ff67f38f088 15208->16960 15210 7ff67f38f2f5 15210->14967 15212 7ff67f383297 15211->15212 15213 7ff67f3832c0 15211->15213 15212->15213 15214 7ff67f381780 59 API calls 15212->15214 15213->14949 15214->15212 15216 7ff67f385b04 15215->15216 15220 7ff67f385b31 15215->15220 15217 7ff67f385b2c 15216->15217 15218 7ff67f381780 59 API calls 15216->15218 15216->15220 15224 7ff67f385b27 memcpy_s __vcrt_freefls 15216->15224 15219 7ff67f3812b0 122 API calls 15217->15219 15218->15216 15219->15220 15221 7ff67f383d30 49 API calls 15220->15221 15220->15224 15222 7ff67f385b97 15221->15222 15223 7ff67f382770 59 API calls 15222->15223 15222->15224 15223->15224 15224->14972 15238 7ff67f38565a memcpy_s 15225->15238 15227 7ff67f38577f 15229 7ff67f383d30 49 API calls 15227->15229 15228 7ff67f38579b 15230 7ff67f382770 59 API calls 15228->15230 15231 7ff67f3857f8 15229->15231 15235 7ff67f385791 __vcrt_freefls 15230->15235 15234 7ff67f383d30 49 API calls 15231->15234 15232 7ff67f383d30 49 API calls 15232->15238 15233 7ff67f385760 15233->15227 15236 7ff67f383d30 49 API calls 15233->15236 15237 7ff67f385828 15234->15237 15239 7ff67f38ad80 _wfindfirst32i64 8 API calls 15235->15239 15236->15227 15241 7ff67f383d30 49 API calls 15237->15241 15238->15227 15238->15228 15238->15232 15238->15233 15238->15238 15243 7ff67f385781 15238->15243 16971 7ff67f381650 15238->16971 16976 7ff67f381440 15238->16976 15240 7ff67f3838d9 15239->15240 15240->14981 15240->14982 15241->15235 15244 7ff67f382770 59 API calls 15243->15244 15244->15235 15246 7ff67f3871b0 58 API calls 15245->15246 15247 7ff67f3855e2 15246->15247 15248 7ff67f3871b0 58 API calls 15247->15248 15249 7ff67f3855f5 15248->15249 15250 7ff67f38561a 15249->15250 15251 7ff67f38560d GetProcAddress 15249->15251 15252 7ff67f382770 59 API calls 15250->15252 15255 7ff67f385f9c GetProcAddress 15251->15255 15256 7ff67f385f79 15251->15256 15254 7ff67f385626 15252->15254 15254->14987 15255->15256 15257 7ff67f385fc1 GetProcAddress 15255->15257 15258 7ff67f382620 57 API calls 15256->15258 15257->15256 15259 7ff67f385fe6 GetProcAddress 15257->15259 15260 7ff67f385f8c 15258->15260 15259->15256 15261 7ff67f38600e GetProcAddress 15259->15261 15260->14987 15261->15256 15262 7ff67f386036 GetProcAddress 15261->15262 15262->15256 15263 7ff67f38605e GetProcAddress 15262->15263 15264 7ff67f38607a 15263->15264 15265 7ff67f386086 GetProcAddress 15263->15265 15264->15265 15266 7ff67f3860a2 15265->15266 15267 7ff67f3860ae GetProcAddress 15265->15267 15266->15267 15268 7ff67f3860ca 15267->15268 15269 7ff67f3860d6 GetProcAddress 15267->15269 15268->15269 15270 7ff67f3860f2 15269->15270 15271 7ff67f3860fe GetProcAddress 15269->15271 15270->15271 15272 7ff67f38611a 15271->15272 15273 7ff67f386126 GetProcAddress 15271->15273 15272->15273 15274 7ff67f386142 15273->15274 15275 7ff67f38614e GetProcAddress 15273->15275 15274->15275 15276 7ff67f38616a 15275->15276 15277 7ff67f386176 GetProcAddress 15275->15277 15276->15277 15278 7ff67f386192 15277->15278 15279 7ff67f38619e GetProcAddress 15277->15279 15278->15279 15280 7ff67f3861ba 15279->15280 15281 7ff67f3861c6 GetProcAddress 15279->15281 15280->15281 15282 7ff67f3861e2 15281->15282 15283 7ff67f3861ee GetProcAddress 15281->15283 15282->15283 15284 7ff67f38620a 15283->15284 15285 7ff67f386216 GetProcAddress 15283->15285 15284->15285 15286 7ff67f386232 15285->15286 15287 7ff67f38623e GetProcAddress 15285->15287 15286->15287 15288 7ff67f38625a 15287->15288 15289 7ff67f386266 GetProcAddress 15287->15289 15288->15289 15290 7ff67f386282 15289->15290 15291 7ff67f38628e GetProcAddress 15289->15291 15290->15291 15292 7ff67f3862aa 15291->15292 15293 7ff67f3862b6 GetProcAddress 15291->15293 15292->15293 15294 7ff67f3862d2 15293->15294 15295 7ff67f3862de GetProcAddress 15293->15295 15294->15295 15296 7ff67f3862fa 15295->15296 15297 7ff67f386306 GetProcAddress 15295->15297 15296->15297 15298 7ff67f386322 15297->15298 15299 7ff67f38632e GetProcAddress 15297->15299 15298->15299 15300 7ff67f38634a 15299->15300 15301 7ff67f386356 GetProcAddress 15299->15301 15300->15301 15302 7ff67f386372 15301->15302 15303 7ff67f38637e GetProcAddress 15301->15303 15302->15303 15304 7ff67f38639a 15303->15304 15305 7ff67f3863a6 GetProcAddress 15303->15305 15304->15305 15306 7ff67f3863c2 15305->15306 15307 7ff67f3863ce GetProcAddress 15305->15307 15306->15307 15308 7ff67f3863ea 15307->15308 15309 7ff67f3863f6 GetProcAddress 15307->15309 15308->15309 15310 7ff67f386412 15309->15310 15311 7ff67f38641e GetProcAddress 15309->15311 15310->15311 15312 7ff67f38643a 15311->15312 15312->14987 15314 7ff67f385cb4 15313->15314 15315 7ff67f382770 59 API calls 15314->15315 15318 7ff67f3838fa 15314->15318 15316 7ff67f385d0e 15315->15316 15317 7ff67f385890 FreeLibrary 15316->15317 15317->15318 15318->14966 15320 7ff67f3858a2 15319->15320 15321 7ff67f3858bd 15319->15321 15320->15321 15322 7ff67f385980 15320->15322 17385 7ff67f387190 FreeLibrary 15320->17385 15321->14966 15322->15321 17386 7ff67f387190 FreeLibrary 15322->17386 15326 7ff67f381b55 15325->15326 15327 7ff67f393be4 49 API calls 15326->15327 15328 7ff67f381b78 15327->15328 15328->14989 15330 7ff67f3831c4 15329->15330 15337 7ff67f383183 15329->15337 15331 7ff67f383203 15330->15331 15332 7ff67f381ab0 74 API calls 15330->15332 15333 7ff67f38ad80 _wfindfirst32i64 8 API calls 15331->15333 15332->15330 15334 7ff67f383215 15333->15334 15334->14979 15335 7ff67f381780 59 API calls 15335->15337 15337->15330 15337->15335 15338 7ff67f381440 161 API calls 15337->15338 17387 7ff67f382990 15337->17387 15338->15337 15340 7ff67f387a30 57 API calls 15339->15340 15341 7ff67f386f3f 15340->15341 15342 7ff67f387a30 57 API calls 15341->15342 15343 7ff67f386f4f 15342->15343 15344 7ff67f3966b4 38 API calls 15343->15344 15345 7ff67f386f5d __vcrt_freefls 15344->15345 15345->14988 15347 7ff67f386fe0 15346->15347 15348 7ff67f387a30 57 API calls 15347->15348 15349 7ff67f387011 SetConsoleCtrlHandler GetStartupInfoW 15348->15349 15350 7ff67f387072 15349->15350 15351 7ff67f399184 _fread_nolock 37 API calls 15350->15351 15352 7ff67f38707a 15351->15352 15353 7ff67f396ef8 _fread_nolock 37 API calls 15352->15353 15354 7ff67f387081 15353->15354 15355 7ff67f399184 _fread_nolock 37 API calls 15354->15355 15356 7ff67f3870a0 15355->15356 15357 7ff67f396ef8 _fread_nolock 37 API calls 15356->15357 15358 7ff67f3870a7 15357->15358 15359 7ff67f399184 _fread_nolock 37 API calls 15358->15359 15360 7ff67f3870c7 15359->15360 15361 7ff67f396ef8 _fread_nolock 37 API calls 15360->15361 15362 7ff67f3870ce GetCommandLineW CreateProcessW 15361->15362 15363 7ff67f38712a WaitForSingleObject GetExitCodeProcess 15362->15363 15364 7ff67f387150 15362->15364 15365 7ff67f387163 15363->15365 15366 7ff67f382620 57 API calls 15364->15366 15367 7ff67f38ad80 _wfindfirst32i64 8 API calls 15365->15367 15366->15365 15368 7ff67f383a30 15367->15368 15368->15002 15370 7ff67f386ca0 15369->15370 15371 7ff67f387a30 57 API calls 15370->15371 15372 7ff67f386ccb 15371->15372 15373 7ff67f386eee 15372->15373 17663 7ff67f387330 15372->17663 17686 7ff67f3966ec RemoveDirectoryW 15373->17686 15377 7ff67f38ad80 _wfindfirst32i64 8 API calls 15378 7ff67f386f0b 15377->15378 15378->15003 15384 7ff67f381ab5 __vcrt_freefls 15383->15384 15386 7ff67f381ad8 __vcrt_freefls 15383->15386 15385 7ff67f38f2ac 74 API calls 15384->15385 15384->15386 15385->15386 15386->15007 15406 7ff67f38adb0 15387->15406 15390 7ff67f382669 15408 7ff67f393be4 15390->15408 15395 7ff67f381b30 49 API calls 15396 7ff67f3826c8 __scrt_get_show_window_mode 15395->15396 15397 7ff67f387a30 54 API calls 15396->15397 15398 7ff67f3826f5 15397->15398 15399 7ff67f3826fa 15398->15399 15400 7ff67f382734 MessageBoxA 15398->15400 15401 7ff67f387a30 54 API calls 15399->15401 15402 7ff67f38274e 15400->15402 15403 7ff67f382714 MessageBoxW 15401->15403 15404 7ff67f38ad80 _wfindfirst32i64 8 API calls 15402->15404 15403->15402 15405 7ff67f38275e 15404->15405 15405->15063 15407 7ff67f38263c GetLastError 15406->15407 15407->15390 15410 7ff67f393c3e 15408->15410 15409 7ff67f393c63 15411 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15409->15411 15410->15409 15412 7ff67f393c9f 15410->15412 15425 7ff67f393c8d 15411->15425 15438 7ff67f391e70 15412->15438 15415 7ff67f393d7c 15417 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 15415->15417 15416 7ff67f38ad80 _wfindfirst32i64 8 API calls 15418 7ff67f382699 15416->15418 15417->15425 15426 7ff67f3874b0 15418->15426 15419 7ff67f393da0 15419->15415 15421 7ff67f393daa 15419->15421 15420 7ff67f393d51 15422 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 15420->15422 15424 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 15421->15424 15422->15425 15423 7ff67f393d48 15423->15415 15423->15420 15424->15425 15425->15416 15427 7ff67f3874bc 15426->15427 15428 7ff67f3874dd FormatMessageW 15427->15428 15429 7ff67f3874d7 GetLastError 15427->15429 15430 7ff67f38752c WideCharToMultiByte 15428->15430 15431 7ff67f387510 15428->15431 15429->15428 15432 7ff67f387566 15430->15432 15433 7ff67f387523 15430->15433 15434 7ff67f382620 54 API calls 15431->15434 15435 7ff67f382620 54 API calls 15432->15435 15436 7ff67f38ad80 _wfindfirst32i64 8 API calls 15433->15436 15434->15433 15435->15433 15437 7ff67f3826a0 15436->15437 15437->15395 15439 7ff67f391eae 15438->15439 15440 7ff67f391e9e 15438->15440 15441 7ff67f391eb7 15439->15441 15446 7ff67f391ee5 15439->15446 15442 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15440->15442 15443 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15441->15443 15444 7ff67f391edd 15442->15444 15443->15444 15444->15415 15444->15419 15444->15420 15444->15423 15446->15440 15446->15444 15448 7ff67f392194 15446->15448 15452 7ff67f392800 15446->15452 15478 7ff67f3924c8 15446->15478 15508 7ff67f391d50 15446->15508 15511 7ff67f393a20 15446->15511 15449 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15448->15449 15449->15440 15453 7ff67f392842 15452->15453 15454 7ff67f3928b5 15452->15454 15455 7ff67f3928df 15453->15455 15456 7ff67f392848 15453->15456 15457 7ff67f39290f 15454->15457 15458 7ff67f3928ba 15454->15458 15535 7ff67f390db0 15455->15535 15464 7ff67f39284d 15456->15464 15467 7ff67f39291e 15456->15467 15457->15455 15457->15467 15476 7ff67f392878 15457->15476 15459 7ff67f3928ef 15458->15459 15460 7ff67f3928bc 15458->15460 15542 7ff67f3909a0 15459->15542 15462 7ff67f39285d 15460->15462 15466 7ff67f3928cb 15460->15466 15477 7ff67f39294d 15462->15477 15517 7ff67f393164 15462->15517 15464->15462 15468 7ff67f392890 15464->15468 15464->15476 15466->15455 15470 7ff67f3928d0 15466->15470 15467->15477 15549 7ff67f3911c0 15467->15549 15468->15477 15527 7ff67f393620 15468->15527 15470->15477 15531 7ff67f3937b8 15470->15531 15472 7ff67f38ad80 _wfindfirst32i64 8 API calls 15474 7ff67f392be3 15472->15474 15474->15446 15476->15477 15556 7ff67f39da00 15476->15556 15477->15472 15479 7ff67f3924d3 15478->15479 15480 7ff67f3924e9 15478->15480 15481 7ff67f392842 15479->15481 15482 7ff67f3928b5 15479->15482 15484 7ff67f392527 15479->15484 15483 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15480->15483 15480->15484 15485 7ff67f3928df 15481->15485 15486 7ff67f392848 15481->15486 15487 7ff67f39290f 15482->15487 15488 7ff67f3928ba 15482->15488 15483->15484 15484->15446 15491 7ff67f390db0 38 API calls 15485->15491 15495 7ff67f39284d 15486->15495 15498 7ff67f39291e 15486->15498 15487->15485 15487->15498 15506 7ff67f392878 15487->15506 15489 7ff67f3928ef 15488->15489 15490 7ff67f3928bc 15488->15490 15493 7ff67f3909a0 38 API calls 15489->15493 15492 7ff67f39285d 15490->15492 15496 7ff67f3928cb 15490->15496 15491->15506 15494 7ff67f393164 47 API calls 15492->15494 15505 7ff67f39294d 15492->15505 15493->15506 15494->15506 15495->15492 15497 7ff67f392890 15495->15497 15495->15506 15496->15485 15500 7ff67f3928d0 15496->15500 15501 7ff67f393620 47 API calls 15497->15501 15497->15505 15499 7ff67f3911c0 38 API calls 15498->15499 15498->15505 15499->15506 15503 7ff67f3937b8 37 API calls 15500->15503 15500->15505 15501->15506 15502 7ff67f38ad80 _wfindfirst32i64 8 API calls 15504 7ff67f392be3 15502->15504 15503->15506 15504->15446 15505->15502 15506->15505 15507 7ff67f39da00 47 API calls 15506->15507 15507->15506 15712 7ff67f38ff74 15508->15712 15512 7ff67f393a37 15511->15512 15729 7ff67f39cb60 15512->15729 15518 7ff67f393186 15517->15518 15566 7ff67f38fde0 15518->15566 15523 7ff67f393a20 45 API calls 15524 7ff67f3932c3 15523->15524 15524->15524 15525 7ff67f393a20 45 API calls 15524->15525 15526 7ff67f39334c 15524->15526 15525->15526 15526->15476 15528 7ff67f393638 15527->15528 15530 7ff67f3936a0 15527->15530 15529 7ff67f39da00 47 API calls 15528->15529 15528->15530 15529->15530 15530->15476 15534 7ff67f3937d9 15531->15534 15532 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15533 7ff67f39380a 15532->15533 15533->15476 15534->15532 15534->15533 15536 7ff67f390de3 15535->15536 15537 7ff67f390e12 15536->15537 15539 7ff67f390ecf 15536->15539 15538 7ff67f38fde0 12 API calls 15537->15538 15541 7ff67f390e4f 15537->15541 15538->15541 15540 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15539->15540 15540->15541 15541->15476 15543 7ff67f3909d3 15542->15543 15544 7ff67f390a02 15543->15544 15546 7ff67f390abf 15543->15546 15545 7ff67f38fde0 12 API calls 15544->15545 15548 7ff67f390a3f 15544->15548 15545->15548 15547 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15546->15547 15547->15548 15548->15476 15550 7ff67f3911f3 15549->15550 15551 7ff67f391222 15550->15551 15553 7ff67f3912df 15550->15553 15552 7ff67f38fde0 12 API calls 15551->15552 15555 7ff67f39125f 15551->15555 15552->15555 15554 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15553->15554 15554->15555 15555->15476 15557 7ff67f39da28 15556->15557 15558 7ff67f39da6d 15557->15558 15559 7ff67f393a20 45 API calls 15557->15559 15561 7ff67f39da2d __scrt_get_show_window_mode 15557->15561 15565 7ff67f39da56 __scrt_get_show_window_mode 15557->15565 15558->15561 15558->15565 15709 7ff67f39f0b8 15558->15709 15559->15558 15560 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15560->15561 15561->15476 15565->15560 15565->15561 15567 7ff67f38fe06 15566->15567 15568 7ff67f38fe17 15566->15568 15574 7ff67f39d718 15567->15574 15568->15567 15596 7ff67f39cacc 15568->15596 15571 7ff67f38fe58 15573 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 15571->15573 15572 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 15572->15571 15573->15567 15575 7ff67f39d735 15574->15575 15576 7ff67f39d768 15574->15576 15577 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15575->15577 15576->15575 15578 7ff67f39d79a 15576->15578 15587 7ff67f3932a1 15577->15587 15582 7ff67f39d8ad 15578->15582 15591 7ff67f39d7e2 15578->15591 15579 7ff67f39d99f 15636 7ff67f39cc04 15579->15636 15581 7ff67f39d965 15629 7ff67f39cf9c 15581->15629 15582->15579 15582->15581 15583 7ff67f39d934 15582->15583 15585 7ff67f39d8f7 15582->15585 15588 7ff67f39d8ed 15582->15588 15622 7ff67f39d27c 15583->15622 15612 7ff67f39d4ac 15585->15612 15587->15523 15587->15524 15588->15581 15590 7ff67f39d8f2 15588->15590 15590->15583 15590->15585 15591->15587 15603 7ff67f3991ac 15591->15603 15594 7ff67f399dd0 _wfindfirst32i64 17 API calls 15595 7ff67f39d9fc 15594->15595 15597 7ff67f39cb17 15596->15597 15601 7ff67f39cadb memcpy_s 15596->15601 15599 7ff67f394444 memcpy_s 11 API calls 15597->15599 15598 7ff67f39cafe HeapAlloc 15600 7ff67f38fe44 15598->15600 15598->15601 15599->15600 15600->15571 15600->15572 15601->15597 15601->15598 15602 7ff67f3a26b0 memcpy_s 2 API calls 15601->15602 15602->15601 15604 7ff67f3991c3 15603->15604 15605 7ff67f3991b9 15603->15605 15606 7ff67f394444 memcpy_s 11 API calls 15604->15606 15605->15604 15607 7ff67f3991de 15605->15607 15611 7ff67f3991ca 15606->15611 15609 7ff67f3991d6 15607->15609 15610 7ff67f394444 memcpy_s 11 API calls 15607->15610 15608 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 15608->15609 15609->15587 15609->15594 15610->15611 15611->15608 15645 7ff67f3a31cc 15612->15645 15616 7ff67f39d554 15617 7ff67f39d558 15616->15617 15618 7ff67f39d5a9 15616->15618 15620 7ff67f39d574 15616->15620 15617->15587 15698 7ff67f39d098 15618->15698 15694 7ff67f39d354 15620->15694 15623 7ff67f3a31cc 38 API calls 15622->15623 15624 7ff67f39d2c6 15623->15624 15625 7ff67f3a2c14 37 API calls 15624->15625 15626 7ff67f39d316 15625->15626 15627 7ff67f39d31a 15626->15627 15628 7ff67f39d354 45 API calls 15626->15628 15627->15587 15628->15627 15630 7ff67f3a31cc 38 API calls 15629->15630 15631 7ff67f39cfe7 15630->15631 15632 7ff67f3a2c14 37 API calls 15631->15632 15633 7ff67f39d03f 15632->15633 15634 7ff67f39d043 15633->15634 15635 7ff67f39d098 45 API calls 15633->15635 15634->15587 15635->15634 15637 7ff67f39cc49 15636->15637 15638 7ff67f39cc7c 15636->15638 15639 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15637->15639 15640 7ff67f39cc94 15638->15640 15642 7ff67f39cd15 15638->15642 15644 7ff67f39cc75 __scrt_get_show_window_mode 15639->15644 15641 7ff67f39cf9c 46 API calls 15640->15641 15641->15644 15643 7ff67f393a20 45 API calls 15642->15643 15642->15644 15643->15644 15644->15587 15646 7ff67f3a321f fegetenv 15645->15646 15647 7ff67f3a712c 37 API calls 15646->15647 15652 7ff67f3a3272 15647->15652 15648 7ff67f3a329f 15651 7ff67f3991ac __std_exception_copy 37 API calls 15648->15651 15649 7ff67f3a3362 15650 7ff67f3a712c 37 API calls 15649->15650 15653 7ff67f3a338c 15650->15653 15654 7ff67f3a331d 15651->15654 15652->15649 15655 7ff67f3a328d 15652->15655 15656 7ff67f3a333c 15652->15656 15657 7ff67f3a712c 37 API calls 15653->15657 15658 7ff67f3a4444 15654->15658 15664 7ff67f3a3325 15654->15664 15655->15648 15655->15649 15659 7ff67f3991ac __std_exception_copy 37 API calls 15656->15659 15660 7ff67f3a339d 15657->15660 15662 7ff67f399dd0 _wfindfirst32i64 17 API calls 15658->15662 15659->15654 15661 7ff67f3a7320 20 API calls 15660->15661 15670 7ff67f3a3406 __scrt_get_show_window_mode 15661->15670 15663 7ff67f3a4459 15662->15663 15665 7ff67f38ad80 _wfindfirst32i64 8 API calls 15664->15665 15666 7ff67f39d4f9 15665->15666 15690 7ff67f3a2c14 15666->15690 15667 7ff67f3a37af __scrt_get_show_window_mode 15668 7ff67f3a3447 memcpy_s 15684 7ff67f3a3d8b memcpy_s __scrt_get_show_window_mode 15668->15684 15685 7ff67f3a38a3 memcpy_s __scrt_get_show_window_mode 15668->15685 15669 7ff67f3a2d30 37 API calls 15675 7ff67f3a4207 15669->15675 15670->15667 15670->15668 15674 7ff67f394444 memcpy_s 11 API calls 15670->15674 15671 7ff67f3a3aef 15671->15669 15672 7ff67f3a445c memcpy_s 37 API calls 15672->15671 15673 7ff67f3a3a9b 15673->15671 15673->15672 15676 7ff67f3a3880 15674->15676 15678 7ff67f3a445c memcpy_s 37 API calls 15675->15678 15683 7ff67f3a4262 15675->15683 15677 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 15676->15677 15677->15668 15678->15683 15679 7ff67f3a43e8 15680 7ff67f3a712c 37 API calls 15679->15680 15680->15664 15681 7ff67f394444 11 API calls memcpy_s 15681->15684 15682 7ff67f394444 11 API calls memcpy_s 15682->15685 15683->15679 15686 7ff67f3a2d30 37 API calls 15683->15686 15689 7ff67f3a445c memcpy_s 37 API calls 15683->15689 15684->15671 15684->15673 15684->15681 15687 7ff67f399db0 37 API calls _invalid_parameter_noinfo 15684->15687 15685->15673 15685->15682 15688 7ff67f399db0 37 API calls _invalid_parameter_noinfo 15685->15688 15686->15683 15687->15684 15688->15685 15689->15683 15691 7ff67f3a2c33 15690->15691 15692 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15691->15692 15693 7ff67f3a2c5e memcpy_s 15691->15693 15692->15693 15693->15616 15695 7ff67f39d380 memcpy_s 15694->15695 15696 7ff67f393a20 45 API calls 15695->15696 15697 7ff67f39d43a memcpy_s __scrt_get_show_window_mode 15695->15697 15696->15697 15697->15617 15699 7ff67f39d0d3 15698->15699 15703 7ff67f39d120 memcpy_s 15698->15703 15700 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15699->15700 15701 7ff67f39d0ff 15700->15701 15701->15617 15702 7ff67f39d18b 15704 7ff67f3991ac __std_exception_copy 37 API calls 15702->15704 15703->15702 15705 7ff67f393a20 45 API calls 15703->15705 15708 7ff67f39d1cd memcpy_s 15704->15708 15705->15702 15706 7ff67f399dd0 _wfindfirst32i64 17 API calls 15707 7ff67f39d278 15706->15707 15708->15706 15711 7ff67f39f0dc WideCharToMultiByte 15709->15711 15713 7ff67f38ffa1 15712->15713 15714 7ff67f38ffb3 15712->15714 15715 7ff67f394444 memcpy_s 11 API calls 15713->15715 15716 7ff67f38fffd 15714->15716 15718 7ff67f38ffc0 15714->15718 15717 7ff67f38ffa6 15715->15717 15721 7ff67f3900a6 15716->15721 15723 7ff67f394444 memcpy_s 11 API calls 15716->15723 15719 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 15717->15719 15720 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15718->15720 15725 7ff67f38ffb1 15719->15725 15720->15725 15722 7ff67f394444 memcpy_s 11 API calls 15721->15722 15721->15725 15724 7ff67f390150 15722->15724 15726 7ff67f39009b 15723->15726 15728 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 15724->15728 15725->15446 15727 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 15726->15727 15727->15721 15728->15725 15730 7ff67f393a5f 15729->15730 15731 7ff67f39cb79 15729->15731 15733 7ff67f39cbcc 15730->15733 15731->15730 15737 7ff67f3a2424 15731->15737 15734 7ff67f39cbe5 15733->15734 15735 7ff67f393a6f 15733->15735 15734->15735 15750 7ff67f3a1790 15734->15750 15735->15446 15738 7ff67f39a620 __CxxCallCatchBlock 45 API calls 15737->15738 15739 7ff67f3a2433 15738->15739 15740 7ff67f3a247e 15739->15740 15749 7ff67f39f788 EnterCriticalSection 15739->15749 15740->15730 15751 7ff67f39a620 __CxxCallCatchBlock 45 API calls 15750->15751 15752 7ff67f3a1799 15751->15752 15760 7ff67f3942ec EnterCriticalSection 15753->15760 15762 7ff67f3824ec 15761->15762 15763 7ff67f393be4 49 API calls 15762->15763 15764 7ff67f38253f 15763->15764 15765 7ff67f394444 memcpy_s 11 API calls 15764->15765 15766 7ff67f382544 15765->15766 15780 7ff67f394464 15766->15780 15769 7ff67f381b30 49 API calls 15770 7ff67f382573 __scrt_get_show_window_mode 15769->15770 15771 7ff67f387a30 57 API calls 15770->15771 15772 7ff67f3825a0 15771->15772 15773 7ff67f3825a5 15772->15773 15774 7ff67f3825df MessageBoxA 15772->15774 15776 7ff67f387a30 57 API calls 15773->15776 15775 7ff67f3825f9 15774->15775 15778 7ff67f38ad80 _wfindfirst32i64 8 API calls 15775->15778 15777 7ff67f3825bf MessageBoxW 15776->15777 15777->15775 15779 7ff67f382609 15778->15779 15779->15073 15781 7ff67f39a798 memcpy_s 11 API calls 15780->15781 15782 7ff67f39447b 15781->15782 15783 7ff67f38254b 15782->15783 15784 7ff67f39dd40 memcpy_s 11 API calls 15782->15784 15787 7ff67f3944bb 15782->15787 15783->15769 15785 7ff67f3944b0 15784->15785 15786 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 15785->15786 15786->15787 15787->15783 15792 7ff67f39e418 15787->15792 15790 7ff67f399dd0 _wfindfirst32i64 17 API calls 15791 7ff67f394500 15790->15791 15796 7ff67f39e435 15792->15796 15793 7ff67f39e43a 15794 7ff67f3944e1 15793->15794 15795 7ff67f394444 memcpy_s 11 API calls 15793->15795 15794->15783 15794->15790 15797 7ff67f39e444 15795->15797 15796->15793 15796->15794 15799 7ff67f39e484 15796->15799 15798 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 15797->15798 15798->15794 15799->15794 15800 7ff67f394444 memcpy_s 11 API calls 15799->15800 15800->15797 15802 7ff67f387b64 WideCharToMultiByte 15801->15802 15803 7ff67f387bd2 WideCharToMultiByte 15801->15803 15805 7ff67f387b8e 15802->15805 15809 7ff67f387ba5 15802->15809 15804 7ff67f387bff 15803->15804 15807 7ff67f383c05 15803->15807 15806 7ff67f382620 57 API calls 15804->15806 15808 7ff67f382620 57 API calls 15805->15808 15806->15807 15807->15082 15807->15084 15808->15807 15809->15803 15810 7ff67f387bbb 15809->15810 15811 7ff67f382620 57 API calls 15810->15811 15811->15807 15813 7ff67f386a0e 15812->15813 15814 7ff67f399123 15812->15814 15813->15103 15814->15813 15815 7ff67f3991ac __std_exception_copy 37 API calls 15814->15815 15816 7ff67f399150 15815->15816 15816->15813 15817 7ff67f399dd0 _wfindfirst32i64 17 API calls 15816->15817 15818 7ff67f399180 15817->15818 15820 7ff67f3817d4 15819->15820 15821 7ff67f3817e4 15819->15821 15822 7ff67f383cb0 116 API calls 15820->15822 15823 7ff67f387200 83 API calls 15821->15823 15849 7ff67f381842 15821->15849 15822->15821 15824 7ff67f381815 15823->15824 15824->15849 15853 7ff67f38f934 15824->15853 15826 7ff67f38ad80 _wfindfirst32i64 8 API calls 15830 7ff67f3819c0 15826->15830 15827 7ff67f38182b 15828 7ff67f38184c 15827->15828 15829 7ff67f38182f 15827->15829 15857 7ff67f38f5fc 15828->15857 15831 7ff67f3824d0 59 API calls 15829->15831 15830->15118 15830->15119 15831->15849 15834 7ff67f38f934 73 API calls 15836 7ff67f3818d1 15834->15836 15835 7ff67f3824d0 59 API calls 15835->15849 15837 7ff67f3818e3 15836->15837 15838 7ff67f3818fe 15836->15838 15839 7ff67f3824d0 59 API calls 15837->15839 15840 7ff67f38f5fc _fread_nolock 53 API calls 15838->15840 15839->15849 15841 7ff67f381913 15840->15841 15842 7ff67f381867 15841->15842 15843 7ff67f381925 15841->15843 15842->15835 15860 7ff67f38f370 15843->15860 15846 7ff67f38193d 15847 7ff67f382770 59 API calls 15846->15847 15847->15849 15848 7ff67f381993 15848->15849 15850 7ff67f38f2ac 74 API calls 15848->15850 15849->15826 15850->15849 15851 7ff67f381950 15851->15848 15852 7ff67f382770 59 API calls 15851->15852 15852->15848 15854 7ff67f38f964 15853->15854 15866 7ff67f38f6c4 15854->15866 15856 7ff67f38f97d 15856->15827 15878 7ff67f38f61c 15857->15878 15861 7ff67f38f379 15860->15861 15862 7ff67f381939 15860->15862 15863 7ff67f394444 memcpy_s 11 API calls 15861->15863 15862->15846 15862->15851 15864 7ff67f38f37e 15863->15864 15865 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 15864->15865 15865->15862 15867 7ff67f38f72e 15866->15867 15868 7ff67f38f6ee 15866->15868 15867->15868 15870 7ff67f38f73a 15867->15870 15869 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 15868->15869 15871 7ff67f38f715 15869->15871 15877 7ff67f3942ec EnterCriticalSection 15870->15877 15871->15856 15879 7ff67f38f646 15878->15879 15890 7ff67f381861 15878->15890 15880 7ff67f38f692 15879->15880 15881 7ff67f38f655 __scrt_get_show_window_mode 15879->15881 15879->15890 15891 7ff67f3942ec EnterCriticalSection 15880->15891 15883 7ff67f394444 memcpy_s 11 API calls 15881->15883 15885 7ff67f38f66a 15883->15885 15887 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 15885->15887 15887->15890 15890->15834 15890->15842 15893 7ff67f384970 15892->15893 15894 7ff67f381b30 49 API calls 15893->15894 15895 7ff67f3849a2 15894->15895 15896 7ff67f3849cb 15895->15896 15897 7ff67f3849ab 15895->15897 15899 7ff67f384a22 15896->15899 15901 7ff67f383d30 49 API calls 15896->15901 15898 7ff67f382770 59 API calls 15897->15898 15919 7ff67f3849c1 15898->15919 16011 7ff67f383d30 15899->16011 15906 7ff67f3849ec 15901->15906 15902 7ff67f38ad80 _wfindfirst32i64 8 API calls 15907 7ff67f3830be 15902->15907 15903 7ff67f384a59 16014 7ff67f3871b0 15903->16014 15904 7ff67f384a3b 15904->15903 15908 7ff67f382770 59 API calls 15904->15908 15905 7ff67f384a0a 16018 7ff67f383c40 15905->16018 15906->15905 15910 7ff67f382770 59 API calls 15906->15910 15907->15141 15920 7ff67f384ce0 15907->15920 15908->15903 15910->15905 15913 7ff67f384a66 15914 7ff67f384a8d 15913->15914 15915 7ff67f384a6b 15913->15915 16024 7ff67f383df0 GetProcAddress 15914->16024 15917 7ff67f382620 57 API calls 15915->15917 15916 7ff67f3871b0 58 API calls 15916->15899 15917->15919 15919->15902 15921 7ff67f386990 61 API calls 15920->15921 15923 7ff67f384cf5 15921->15923 15922 7ff67f384d10 15924 7ff67f387a30 57 API calls 15922->15924 15923->15922 16131 7ff67f382880 15923->16131 15926 7ff67f384d54 15924->15926 15927 7ff67f384d59 15926->15927 15928 7ff67f384d70 15926->15928 15929 7ff67f382770 59 API calls 15927->15929 15931 7ff67f387a30 57 API calls 15928->15931 15930 7ff67f384d65 15929->15930 15930->15143 15932 7ff67f384da5 15931->15932 15934 7ff67f381b30 49 API calls 15932->15934 15946 7ff67f384daa __vcrt_freefls 15932->15946 15933 7ff67f382770 59 API calls 15935 7ff67f384f51 15933->15935 15936 7ff67f384e27 15934->15936 15935->15143 15937 7ff67f384e53 15936->15937 15938 7ff67f384e2e 15936->15938 15940 7ff67f387a30 57 API calls 15937->15940 15939 7ff67f382770 59 API calls 15938->15939 15941 7ff67f384e43 15939->15941 15942 7ff67f384e6c 15940->15942 15941->15143 15942->15946 16144 7ff67f384ac0 15942->16144 15946->15933 15947 7ff67f384f3a 15946->15947 15947->15143 15949 7ff67f3846f7 15948->15949 15949->15949 15950 7ff67f384720 15949->15950 15957 7ff67f384737 __vcrt_freefls 15949->15957 15951 7ff67f382770 59 API calls 15950->15951 15952 7ff67f38472c 15951->15952 15952->15145 15953 7ff67f38481b 15953->15145 15954 7ff67f3812b0 122 API calls 15954->15957 15955 7ff67f381780 59 API calls 15955->15957 15956 7ff67f382770 59 API calls 15956->15957 15957->15953 15957->15954 15957->15955 15957->15956 15959 7ff67f384947 15958->15959 15960 7ff67f38485b 15958->15960 15959->15147 15960->15959 15960->15960 15961 7ff67f381780 59 API calls 15960->15961 15962 7ff67f382770 59 API calls 15960->15962 15961->15960 15962->15960 15964 7ff67f3812f8 15963->15964 15965 7ff67f3812c6 15963->15965 15966 7ff67f38f934 73 API calls 15964->15966 15967 7ff67f383cb0 116 API calls 15965->15967 15968 7ff67f38130a 15966->15968 15969 7ff67f3812d6 15967->15969 15970 7ff67f38132f 15968->15970 15971 7ff67f38130e 15968->15971 15969->15964 15972 7ff67f3812de 15969->15972 15977 7ff67f381364 15970->15977 15978 7ff67f381344 15970->15978 15973 7ff67f3824d0 59 API calls 15971->15973 15974 7ff67f382770 59 API calls 15972->15974 15976 7ff67f381325 15973->15976 15975 7ff67f3812ee 15974->15975 15975->15163 15976->15163 15980 7ff67f381395 15977->15980 15981 7ff67f38137e 15977->15981 15979 7ff67f3824d0 59 API calls 15978->15979 15982 7ff67f38135f __vcrt_freefls 15979->15982 15980->15982 15984 7ff67f38f5fc _fread_nolock 53 API calls 15980->15984 15987 7ff67f3813de 15980->15987 16265 7ff67f381050 15981->16265 15985 7ff67f38f2ac 74 API calls 15982->15985 15986 7ff67f381421 15982->15986 15984->15980 15985->15986 15986->15163 15988 7ff67f3824d0 59 API calls 15987->15988 15988->15982 15990 7ff67f3817a1 15989->15990 15991 7ff67f381795 15989->15991 15990->15163 15992 7ff67f382770 59 API calls 15991->15992 15992->15990 15995 7ff67f3816f5 15993->15995 15994 7ff67f381738 15994->15169 15994->15170 15995->15994 15996 7ff67f382770 59 API calls 15995->15996 15996->15994 15998 7ff67f382ed4 15997->15998 15999 7ff67f38303f 15998->15999 16000 7ff67f39910c 37 API calls 15998->16000 15999->15173 16000->15999 16002 7ff67f3823e9 16001->16002 16003 7ff67f3823dc 16001->16003 16005 7ff67f3823fe 16002->16005 16006 7ff67f387a30 57 API calls 16002->16006 16004 7ff67f387a30 57 API calls 16003->16004 16004->16002 16007 7ff67f382413 16005->16007 16008 7ff67f387a30 57 API calls 16005->16008 16006->16005 16302 7ff67f382240 16007->16302 16008->16007 16012 7ff67f381b30 49 API calls 16011->16012 16013 7ff67f383d60 16012->16013 16013->15904 16015 7ff67f387a30 57 API calls 16014->16015 16016 7ff67f3871c7 LoadLibraryW 16015->16016 16017 7ff67f3871e4 __vcrt_freefls 16016->16017 16017->15913 16019 7ff67f383c4a 16018->16019 16020 7ff67f387a30 57 API calls 16019->16020 16021 7ff67f383c72 16020->16021 16022 7ff67f38ad80 _wfindfirst32i64 8 API calls 16021->16022 16023 7ff67f383c9a 16022->16023 16023->15899 16023->15916 16025 7ff67f383e3b GetProcAddress 16024->16025 16026 7ff67f383e18 16024->16026 16025->16026 16027 7ff67f383e60 GetProcAddress 16025->16027 16028 7ff67f382620 57 API calls 16026->16028 16027->16026 16029 7ff67f383e85 GetProcAddress 16027->16029 16030 7ff67f383e2b 16028->16030 16029->16026 16031 7ff67f383ead GetProcAddress 16029->16031 16030->15919 16031->16026 16032 7ff67f383ed5 GetProcAddress 16031->16032 16032->16026 16033 7ff67f383efd GetProcAddress 16032->16033 16034 7ff67f383f19 16033->16034 16035 7ff67f383f25 GetProcAddress 16033->16035 16034->16035 16036 7ff67f383f4d GetProcAddress 16035->16036 16037 7ff67f383f41 16035->16037 16038 7ff67f383f69 16036->16038 16037->16036 16039 7ff67f383f7d GetProcAddress 16038->16039 16040 7ff67f383fa5 GetProcAddress 16038->16040 16039->16040 16043 7ff67f383f99 16039->16043 16041 7ff67f383fcd GetProcAddress 16040->16041 16042 7ff67f383fc1 16040->16042 16044 7ff67f383fe9 16041->16044 16045 7ff67f383ff5 GetProcAddress 16041->16045 16042->16041 16043->16040 16044->16045 16046 7ff67f38401d GetProcAddress 16045->16046 16047 7ff67f384011 16045->16047 16048 7ff67f384039 16046->16048 16049 7ff67f384045 GetProcAddress 16046->16049 16047->16046 16048->16049 16050 7ff67f38406d GetProcAddress 16049->16050 16051 7ff67f384061 16049->16051 16052 7ff67f384089 16050->16052 16053 7ff67f384095 GetProcAddress 16050->16053 16051->16050 16052->16053 16054 7ff67f3840bd GetProcAddress 16053->16054 16055 7ff67f3840b1 16053->16055 16056 7ff67f3840d9 16054->16056 16057 7ff67f3840e5 GetProcAddress 16054->16057 16055->16054 16056->16057 16058 7ff67f38410d GetProcAddress 16057->16058 16059 7ff67f384101 16057->16059 16060 7ff67f384129 16058->16060 16061 7ff67f384135 GetProcAddress 16058->16061 16059->16058 16060->16061 16062 7ff67f38415d GetProcAddress 16061->16062 16063 7ff67f384151 16061->16063 16064 7ff67f384179 16062->16064 16065 7ff67f384185 GetProcAddress 16062->16065 16063->16062 16064->16065 16066 7ff67f3841ad GetProcAddress 16065->16066 16067 7ff67f3841a1 16065->16067 16068 7ff67f3841c9 16066->16068 16069 7ff67f3841d5 GetProcAddress 16066->16069 16067->16066 16068->16069 16070 7ff67f3841fd GetProcAddress 16069->16070 16071 7ff67f3841f1 16069->16071 16072 7ff67f384219 16070->16072 16073 7ff67f384225 GetProcAddress 16070->16073 16071->16070 16072->16073 16074 7ff67f38424d GetProcAddress 16073->16074 16075 7ff67f384241 16073->16075 16076 7ff67f384269 16074->16076 16077 7ff67f384275 GetProcAddress 16074->16077 16075->16074 16076->16077 16132 7ff67f3828a0 16131->16132 16133 7ff67f393be4 49 API calls 16132->16133 16134 7ff67f3828ed __scrt_get_show_window_mode 16133->16134 16135 7ff67f387a30 57 API calls 16134->16135 16136 7ff67f38291a 16135->16136 16137 7ff67f382959 MessageBoxA 16136->16137 16138 7ff67f38291f 16136->16138 16140 7ff67f382973 16137->16140 16139 7ff67f387a30 57 API calls 16138->16139 16141 7ff67f382939 MessageBoxW 16139->16141 16142 7ff67f38ad80 _wfindfirst32i64 8 API calls 16140->16142 16141->16140 16143 7ff67f382983 16142->16143 16143->15922 16151 7ff67f384ada 16144->16151 16145 7ff67f384c91 16146 7ff67f38ad80 _wfindfirst32i64 8 API calls 16145->16146 16148 7ff67f384cb0 16146->16148 16147 7ff67f381780 59 API calls 16147->16151 16171 7ff67f387c30 16148->16171 16150 7ff67f384bf3 16150->16145 16182 7ff67f399184 16150->16182 16151->16145 16151->16147 16151->16150 16153 7ff67f384cc9 16151->16153 16178 7ff67f3956d0 16151->16178 16156 7ff67f382770 59 API calls 16153->16156 16156->16145 16157 7ff67f384c16 16158 7ff67f399184 _fread_nolock 37 API calls 16157->16158 16159 7ff67f384c28 16158->16159 16160 7ff67f3957dc 39 API calls 16159->16160 16161 7ff67f384c34 16160->16161 16207 7ff67f395d64 16161->16207 16163 7ff67f384c46 16164 7ff67f395d64 73 API calls 16163->16164 16165 7ff67f384c58 16164->16165 16166 7ff67f394f14 71 API calls 16165->16166 16167 7ff67f384c69 16166->16167 16172 7ff67f387c4f 16171->16172 16173 7ff67f387c57 __vcrt_freefls 16172->16173 16174 7ff67f387ca0 MultiByteToWideChar 16172->16174 16175 7ff67f387d2d 16172->16175 16176 7ff67f387ce8 MultiByteToWideChar 16172->16176 16173->15946 16174->16172 16174->16175 16177 7ff67f382620 57 API calls 16175->16177 16176->16172 16176->16175 16177->16173 16179 7ff67f395700 16178->16179 16213 7ff67f3954d4 16179->16213 16181 7ff67f395719 16181->16151 16183 7ff67f39918d 16182->16183 16187 7ff67f384c0a 16182->16187 16184 7ff67f394444 memcpy_s 11 API calls 16183->16184 16185 7ff67f399192 16184->16185 16186 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 16185->16186 16186->16187 16188 7ff67f3957dc 16187->16188 16194 7ff67f395805 16188->16194 16189 7ff67f39585f 16191 7ff67f395864 16189->16191 16197 7ff67f395871 16189->16197 16190 7ff67f395832 16192 7ff67f394444 memcpy_s 11 API calls 16190->16192 16193 7ff67f394444 memcpy_s 11 API calls 16191->16193 16195 7ff67f395837 16192->16195 16196 7ff67f395842 16193->16196 16194->16189 16194->16190 16199 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 16195->16199 16196->16157 16198 7ff67f39588a 16197->16198 16201 7ff67f3958bb 16197->16201 16200 7ff67f394444 memcpy_s 11 API calls 16198->16200 16199->16196 16200->16195 16245 7ff67f396bec EnterCriticalSection 16201->16245 16208 7ff67f395d72 16207->16208 16209 7ff67f395d79 16207->16209 16246 7ff67f395b9c 16208->16246 16211 7ff67f395d77 16209->16211 16249 7ff67f395b5c 16209->16249 16211->16163 16214 7ff67f395507 16213->16214 16215 7ff67f395549 16214->16215 16216 7ff67f39551c 16214->16216 16225 7ff67f39550c 16214->16225 16218 7ff67f395557 16215->16218 16221 7ff67f393a20 45 API calls 16215->16221 16217 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 16216->16217 16217->16225 16219 7ff67f39558f 16218->16219 16220 7ff67f39556b 16218->16220 16223 7ff67f39559f 16219->16223 16224 7ff67f395671 16219->16224 16232 7ff67f39f57c 16220->16232 16221->16218 16223->16225 16238 7ff67f39e7f0 16223->16238 16224->16225 16227 7ff67f39e7f0 _fread_nolock MultiByteToWideChar 16224->16227 16225->16181 16225->16225 16227->16225 16233 7ff67f39f694 16232->16233 16235 7ff67f39f5ad 16232->16235 16234 7ff67f39f669 16233->16234 16236 7ff67f3a6190 8 API calls 16233->16236 16234->16225 16235->16234 16241 7ff67f3a6190 16235->16241 16236->16233 16239 7ff67f39e7f9 MultiByteToWideChar 16238->16239 16244 7ff67f3a61f4 16241->16244 16242 7ff67f38ad80 _wfindfirst32i64 8 API calls 16243 7ff67f3a635a 16242->16243 16243->16235 16244->16242 16256 7ff67f395a78 16246->16256 16264 7ff67f3942ec EnterCriticalSection 16249->16264 16263 7ff67f39f788 EnterCriticalSection 16256->16263 16266 7ff67f3810a6 16265->16266 16267 7ff67f3810ad 16266->16267 16268 7ff67f3810d3 16266->16268 16269 7ff67f382770 59 API calls 16267->16269 16271 7ff67f3810ed 16268->16271 16272 7ff67f381109 16268->16272 16270 7ff67f3810c0 16269->16270 16270->15982 16273 7ff67f3824d0 59 API calls 16271->16273 16274 7ff67f38111b 16272->16274 16281 7ff67f381137 memcpy_s 16272->16281 16277 7ff67f381104 __vcrt_freefls 16273->16277 16275 7ff67f3824d0 59 API calls 16274->16275 16275->16277 16276 7ff67f38f5fc _fread_nolock 53 API calls 16276->16281 16277->15982 16278 7ff67f3811fe 16279 7ff67f382770 59 API calls 16278->16279 16279->16277 16281->16276 16281->16277 16281->16278 16282 7ff67f38f370 37 API calls 16281->16282 16283 7ff67f38fd3c 16281->16283 16282->16281 16284 7ff67f38fd6c 16283->16284 16287 7ff67f38fa8c 16284->16287 16286 7ff67f38fd8a 16286->16281 16288 7ff67f38faac 16287->16288 16289 7ff67f38fad9 16287->16289 16288->16289 16290 7ff67f38fae1 16288->16290 16291 7ff67f38fab6 16288->16291 16289->16286 16294 7ff67f38f9cc 16290->16294 16292 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 16291->16292 16292->16289 16303 7ff67f38adb0 16302->16303 16304 7ff67f382259 GetModuleHandleW 16303->16304 16305 7ff67f382295 __scrt_get_show_window_mode 16304->16305 16321 7ff67f382470 16305->16321 16322 7ff67f382495 16321->16322 16529 7ff67f3953fc 16528->16529 16530 7ff67f395422 16529->16530 16533 7ff67f395455 16529->16533 16531 7ff67f394444 memcpy_s 11 API calls 16530->16531 16532 7ff67f395427 16531->16532 16536 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 16532->16536 16534 7ff67f395468 16533->16534 16535 7ff67f39545b 16533->16535 16547 7ff67f39a0f8 16534->16547 16537 7ff67f394444 memcpy_s 11 API calls 16535->16537 16546 7ff67f383d09 16536->16546 16537->16546 16546->15196 16560 7ff67f39f788 EnterCriticalSection 16547->16560 16946 7ff67f397968 16945->16946 16949 7ff67f397444 16946->16949 16948 7ff67f397981 16948->15206 16950 7ff67f39748e 16949->16950 16951 7ff67f39745f 16949->16951 16959 7ff67f3942ec EnterCriticalSection 16950->16959 16952 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 16951->16952 16954 7ff67f39747f 16952->16954 16954->16948 16961 7ff67f38f0d1 16960->16961 16962 7ff67f38f0a3 16960->16962 16964 7ff67f38f0c3 16961->16964 16970 7ff67f3942ec EnterCriticalSection 16961->16970 16963 7ff67f399ce4 _invalid_parameter_noinfo 37 API calls 16962->16963 16963->16964 16964->15210 16972 7ff67f3816aa 16971->16972 16973 7ff67f381666 16971->16973 16972->15238 16973->16972 16974 7ff67f382770 59 API calls 16973->16974 16975 7ff67f3816be 16974->16975 16975->15238 17010 7ff67f386720 16976->17010 16978 7ff67f381454 16979 7ff67f381459 16978->16979 17019 7ff67f386a40 16978->17019 16979->15238 16982 7ff67f3814a7 16985 7ff67f3814e0 16982->16985 16988 7ff67f383cb0 116 API calls 16982->16988 16983 7ff67f381487 16984 7ff67f3824d0 59 API calls 16983->16984 16987 7ff67f38149d 16984->16987 16986 7ff67f38f934 73 API calls 16985->16986 16990 7ff67f3814f2 16986->16990 16987->15238 16989 7ff67f3814bf 16988->16989 16989->16985 16991 7ff67f3814c7 16989->16991 16992 7ff67f381516 16990->16992 16993 7ff67f3814f6 16990->16993 16994 7ff67f382770 59 API calls 16991->16994 16996 7ff67f38151c 16992->16996 16997 7ff67f381534 16992->16997 16995 7ff67f3824d0 59 API calls 16993->16995 17004 7ff67f3814d6 __vcrt_freefls 16994->17004 16995->17004 16998 7ff67f381050 98 API calls 16996->16998 16999 7ff67f381556 16997->16999 17009 7ff67f381575 16997->17009 16998->17004 17001 7ff67f3824d0 59 API calls 16999->17001 17000 7ff67f381624 17003 7ff67f38f2ac 74 API calls 17000->17003 17001->17004 17002 7ff67f38f2ac 74 API calls 17002->17000 17003->16987 17004->17000 17004->17002 17005 7ff67f38f5fc _fread_nolock 53 API calls 17005->17009 17006 7ff67f3815d5 17008 7ff67f3824d0 59 API calls 17006->17008 17007 7ff67f38fd3c 76 API calls 17007->17009 17008->17004 17009->17004 17009->17005 17009->17006 17009->17007 17011 7ff67f386768 17010->17011 17012 7ff67f386732 17010->17012 17011->16978 17013 7ff67f3816d0 59 API calls 17012->17013 17014 7ff67f38673e 17013->17014 17044 7ff67f386780 17014->17044 17017 7ff67f382770 59 API calls 17018 7ff67f38675d 17017->17018 17018->16978 17020 7ff67f386a50 17019->17020 17021 7ff67f381b30 49 API calls 17020->17021 17022 7ff67f386a81 17021->17022 17023 7ff67f381b30 49 API calls 17022->17023 17037 7ff67f386c4b 17022->17037 17026 7ff67f386aa8 17023->17026 17024 7ff67f38ad80 _wfindfirst32i64 8 API calls 17025 7ff67f38147f 17024->17025 17025->16982 17025->16983 17026->17037 17363 7ff67f3950e8 17026->17363 17028 7ff67f386bb9 17029 7ff67f387a30 57 API calls 17028->17029 17031 7ff67f386bd1 17029->17031 17030 7ff67f386add 17030->17028 17030->17030 17030->17037 17041 7ff67f3950e8 49 API calls 17030->17041 17042 7ff67f387a30 57 API calls 17030->17042 17043 7ff67f3878a0 58 API calls 17030->17043 17032 7ff67f386c7a 17031->17032 17036 7ff67f386990 61 API calls 17031->17036 17040 7ff67f386c02 __vcrt_freefls 17031->17040 17033 7ff67f383cb0 116 API calls 17032->17033 17033->17037 17034 7ff67f386c3f 17038 7ff67f382880 59 API calls 17034->17038 17035 7ff67f386c6e 17039 7ff67f382880 59 API calls 17035->17039 17036->17040 17037->17024 17038->17037 17039->17032 17040->17034 17040->17035 17041->17030 17042->17030 17043->17030 17045 7ff67f386798 17044->17045 17046 7ff67f38680b 17045->17046 17048 7ff67f386990 61 API calls 17045->17048 17047 7ff67f386810 GetTempPathW 17046->17047 17049 7ff67f386825 17047->17049 17050 7ff67f3867c4 17048->17050 17052 7ff67f382470 48 API calls 17049->17052 17082 7ff67f386480 17050->17082 17062 7ff67f38683e __vcrt_freefls 17052->17062 17053 7ff67f3867cf 17081 7ff67f386804 __vcrt_freefls 17053->17081 17106 7ff67f3966b4 17053->17106 17055 7ff67f3867ea __vcrt_freefls 17055->17047 17060 7ff67f3867f8 17055->17060 17056 7ff67f38ad80 _wfindfirst32i64 8 API calls 17058 7ff67f38674d 17056->17058 17058->17011 17058->17017 17063 7ff67f382770 59 API calls 17060->17063 17061 7ff67f3868e6 17064 7ff67f387b40 59 API calls 17061->17064 17062->17061 17065 7ff67f386871 17062->17065 17116 7ff67f39736c 17062->17116 17119 7ff67f3878a0 17062->17119 17063->17081 17067 7ff67f3868f7 __vcrt_freefls 17064->17067 17066 7ff67f387a30 57 API calls 17065->17066 17065->17081 17068 7ff67f386887 17066->17068 17069 7ff67f387a30 57 API calls 17067->17069 17067->17081 17070 7ff67f38688c 17068->17070 17071 7ff67f3868c9 SetEnvironmentVariableW 17068->17071 17072 7ff67f386915 17069->17072 17073 7ff67f387a30 57 API calls 17070->17073 17071->17081 17074 7ff67f38694d SetEnvironmentVariableW 17072->17074 17075 7ff67f38691a 17072->17075 17076 7ff67f38689c 17073->17076 17074->17081 17077 7ff67f387a30 57 API calls 17075->17077 17079 7ff67f3966b4 38 API calls 17076->17079 17078 7ff67f38692a 17077->17078 17080 7ff67f3966b4 38 API calls 17078->17080 17079->17081 17080->17081 17081->17056 17083 7ff67f38648c 17082->17083 17084 7ff67f387a30 57 API calls 17083->17084 17085 7ff67f3864ae 17084->17085 17086 7ff67f3864c9 ExpandEnvironmentStringsW 17085->17086 17087 7ff67f3864b6 17085->17087 17088 7ff67f3864ef __vcrt_freefls 17086->17088 17089 7ff67f382770 59 API calls 17087->17089 17090 7ff67f386506 17088->17090 17091 7ff67f3864f3 17088->17091 17095 7ff67f3864c2 17089->17095 17096 7ff67f386514 17090->17096 17097 7ff67f386520 17090->17097 17093 7ff67f382770 59 API calls 17091->17093 17092 7ff67f38ad80 _wfindfirst32i64 8 API calls 17094 7ff67f3865e8 17092->17094 17093->17095 17094->17053 17095->17092 17098 7ff67f395f44 37 API calls 17096->17098 17136 7ff67f395348 17097->17136 17100 7ff67f38651e 17098->17100 17101 7ff67f38653a 17100->17101 17104 7ff67f38654d __scrt_get_show_window_mode 17100->17104 17102 7ff67f382770 59 API calls 17101->17102 17102->17095 17103 7ff67f3865c2 CreateDirectoryW 17103->17095 17104->17103 17105 7ff67f38659c CreateDirectoryW 17104->17105 17105->17104 17107 7ff67f3966c1 17106->17107 17108 7ff67f3966d4 17106->17108 17109 7ff67f394444 memcpy_s 11 API calls 17107->17109 17228 7ff67f396338 17108->17228 17111 7ff67f3966c6 17109->17111 17113 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 17111->17113 17115 7ff67f3966d2 17113->17115 17115->17055 17236 7ff67f396f98 17116->17236 17120 7ff67f38adb0 17119->17120 17121 7ff67f3878b0 GetCurrentProcess OpenProcessToken 17120->17121 17122 7ff67f3878fb GetTokenInformation 17121->17122 17123 7ff67f387971 __vcrt_freefls 17121->17123 17124 7ff67f38791d GetLastError 17122->17124 17125 7ff67f387928 17122->17125 17126 7ff67f38798a 17123->17126 17127 7ff67f387984 CloseHandle 17123->17127 17124->17123 17124->17125 17125->17123 17129 7ff67f38793e GetTokenInformation 17125->17129 17359 7ff67f3875a0 17126->17359 17127->17126 17129->17123 17130 7ff67f387964 ConvertSidToStringSidW 17129->17130 17130->17123 17132 7ff67f3879e6 CreateDirectoryW 17133 7ff67f3879fe 17132->17133 17134 7ff67f38ad80 _wfindfirst32i64 8 API calls 17133->17134 17135 7ff67f387a13 17134->17135 17135->17062 17137 7ff67f3953d2 17136->17137 17138 7ff67f395364 17136->17138 17173 7ff67f39f090 17137->17173 17138->17137 17139 7ff67f395369 17138->17139 17141 7ff67f39539e 17139->17141 17142 7ff67f395381 17139->17142 17156 7ff67f39518c GetFullPathNameW 17141->17156 17148 7ff67f395118 GetFullPathNameW 17142->17148 17143 7ff67f395396 __vcrt_freefls 17143->17100 17149 7ff67f39513e GetLastError 17148->17149 17151 7ff67f395154 17148->17151 17150 7ff67f3943b8 _fread_nolock 11 API calls 17149->17150 17152 7ff67f39514b 17150->17152 17154 7ff67f394444 memcpy_s 11 API calls 17151->17154 17155 7ff67f395150 17151->17155 17153 7ff67f394444 memcpy_s 11 API calls 17152->17153 17153->17155 17154->17155 17155->17143 17157 7ff67f3951bf GetLastError 17156->17157 17161 7ff67f3951d5 __vcrt_freefls 17156->17161 17158 7ff67f3943b8 _fread_nolock 11 API calls 17157->17158 17159 7ff67f3951cc 17158->17159 17160 7ff67f394444 memcpy_s 11 API calls 17159->17160 17163 7ff67f3951d1 17160->17163 17162 7ff67f39522f GetFullPathNameW 17161->17162 17161->17163 17162->17157 17162->17163 17164 7ff67f395264 17163->17164 17165 7ff67f3952d8 memcpy_s 17164->17165 17166 7ff67f39528d __scrt_get_show_window_mode 17164->17166 17165->17143 17166->17165 17167 7ff67f3952c1 17166->17167 17170 7ff67f3952fa 17166->17170 17168 7ff67f394444 memcpy_s 11 API calls 17167->17168 17169 7ff67f3952c6 17168->17169 17171 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 17169->17171 17170->17165 17172 7ff67f394444 memcpy_s 11 API calls 17170->17172 17171->17165 17172->17169 17176 7ff67f39eea0 17173->17176 17177 7ff67f39eee2 17176->17177 17178 7ff67f39eecb 17176->17178 17180 7ff67f39ef07 17177->17180 17181 7ff67f39eee6 17177->17181 17179 7ff67f394444 memcpy_s 11 API calls 17178->17179 17185 7ff67f39eed0 17179->17185 17214 7ff67f39e508 17180->17214 17202 7ff67f39f00c 17181->17202 17184 7ff67f39ef0c 17191 7ff67f39efb1 17184->17191 17197 7ff67f39ef33 17184->17197 17188 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 17185->17188 17187 7ff67f39eeef 17189 7ff67f394424 _fread_nolock 11 API calls 17187->17189 17201 7ff67f39eedb __vcrt_freefls 17188->17201 17190 7ff67f39eef4 17189->17190 17193 7ff67f394444 memcpy_s 11 API calls 17190->17193 17191->17178 17194 7ff67f39efb9 17191->17194 17192 7ff67f38ad80 _wfindfirst32i64 8 API calls 17195 7ff67f39f001 17192->17195 17193->17185 17196 7ff67f395118 13 API calls 17194->17196 17195->17143 17196->17201 17198 7ff67f39518c 14 API calls 17197->17198 17199 7ff67f39ef77 17198->17199 17200 7ff67f395264 37 API calls 17199->17200 17199->17201 17200->17201 17201->17192 17203 7ff67f39f056 17202->17203 17204 7ff67f39f026 17202->17204 17205 7ff67f39f061 GetDriveTypeW 17203->17205 17206 7ff67f39f041 17203->17206 17207 7ff67f394424 _fread_nolock 11 API calls 17204->17207 17205->17206 17209 7ff67f38ad80 _wfindfirst32i64 8 API calls 17206->17209 17208 7ff67f39f02b 17207->17208 17210 7ff67f394444 memcpy_s 11 API calls 17208->17210 17211 7ff67f39eeeb 17209->17211 17212 7ff67f39f036 17210->17212 17211->17184 17211->17187 17213 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 17212->17213 17213->17206 17215 7ff67f38c210 __scrt_get_show_window_mode 17214->17215 17216 7ff67f39e53e GetCurrentDirectoryW 17215->17216 17217 7ff67f39e57c 17216->17217 17220 7ff67f39e555 17216->17220 17218 7ff67f39dd40 memcpy_s 11 API calls 17217->17218 17221 7ff67f39e58b 17218->17221 17219 7ff67f38ad80 _wfindfirst32i64 8 API calls 17222 7ff67f39e5e9 17219->17222 17220->17219 17223 7ff67f39e595 GetCurrentDirectoryW 17221->17223 17224 7ff67f39e5a4 17221->17224 17222->17184 17223->17224 17225 7ff67f39e5a9 17223->17225 17226 7ff67f394444 memcpy_s 11 API calls 17224->17226 17227 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17225->17227 17226->17225 17227->17220 17235 7ff67f39f788 EnterCriticalSection 17228->17235 17277 7ff67f3a0698 17236->17277 17336 7ff67f3a0410 17277->17336 17357 7ff67f39f788 EnterCriticalSection 17336->17357 17360 7ff67f3875c5 17359->17360 17361 7ff67f393e38 48 API calls 17360->17361 17362 7ff67f3875e8 LocalFree ConvertStringSecurityDescriptorToSecurityDescriptorW 17361->17362 17362->17132 17362->17133 17364 7ff67f39a620 __CxxCallCatchBlock 45 API calls 17363->17364 17366 7ff67f3950fd 17364->17366 17365 7ff67f39ee97 17372 7ff67f38af14 17365->17372 17366->17365 17369 7ff67f39edb6 17366->17369 17370 7ff67f38ad80 _wfindfirst32i64 8 API calls 17369->17370 17371 7ff67f39ee8f 17370->17371 17371->17030 17375 7ff67f38af28 IsProcessorFeaturePresent 17372->17375 17376 7ff67f38af3f 17375->17376 17381 7ff67f38afc4 RtlCaptureContext RtlLookupFunctionEntry 17376->17381 17382 7ff67f38aff4 RtlVirtualUnwind 17381->17382 17383 7ff67f38af53 17381->17383 17382->17383 17384 7ff67f38ae00 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 17383->17384 17385->15322 17386->15321 17388 7ff67f3829a6 17387->17388 17389 7ff67f381b30 49 API calls 17388->17389 17391 7ff67f3829db 17389->17391 17390 7ff67f382de1 17391->17390 17392 7ff67f383b20 49 API calls 17391->17392 17393 7ff67f382a4f 17392->17393 17442 7ff67f382e00 17393->17442 17396 7ff67f382aca 17398 7ff67f382e00 75 API calls 17396->17398 17397 7ff67f382a91 17399 7ff67f386720 98 API calls 17397->17399 17400 7ff67f382b1c 17398->17400 17401 7ff67f382a99 17399->17401 17402 7ff67f382b86 17400->17402 17403 7ff67f382b20 17400->17403 17404 7ff67f382aba 17401->17404 17450 7ff67f386600 17401->17450 17405 7ff67f382e00 75 API calls 17402->17405 17406 7ff67f386720 98 API calls 17403->17406 17407 7ff67f382770 59 API calls 17404->17407 17411 7ff67f382ac3 17404->17411 17409 7ff67f382bb2 17405->17409 17410 7ff67f382b28 17406->17410 17407->17411 17412 7ff67f382c12 17409->17412 17413 7ff67f382e00 75 API calls 17409->17413 17410->17404 17414 7ff67f386600 138 API calls 17410->17414 17416 7ff67f38ad80 _wfindfirst32i64 8 API calls 17411->17416 17412->17390 17415 7ff67f386720 98 API calls 17412->17415 17417 7ff67f382be2 17413->17417 17418 7ff67f382b45 17414->17418 17423 7ff67f382c22 17415->17423 17419 7ff67f382b7b 17416->17419 17417->17412 17421 7ff67f382e00 75 API calls 17417->17421 17418->17404 17420 7ff67f382dc6 17418->17420 17419->15337 17425 7ff67f382770 59 API calls 17420->17425 17421->17412 17422 7ff67f381af0 59 API calls 17424 7ff67f382c7f 17422->17424 17423->17390 17423->17422 17428 7ff67f382d3f 17423->17428 17424->17390 17426 7ff67f381b30 49 API calls 17424->17426 17441 7ff67f382d3a 17425->17441 17429 7ff67f382ca7 17426->17429 17427 7ff67f381ab0 74 API calls 17427->17390 17431 7ff67f382dab 17428->17431 17436 7ff67f381780 59 API calls 17428->17436 17429->17420 17430 7ff67f381b30 49 API calls 17429->17430 17432 7ff67f382cd4 17430->17432 17431->17420 17433 7ff67f381440 161 API calls 17431->17433 17432->17420 17434 7ff67f381b30 49 API calls 17432->17434 17433->17431 17435 7ff67f382d01 17434->17435 17435->17420 17437 7ff67f3817b0 121 API calls 17435->17437 17436->17428 17438 7ff67f382d23 17437->17438 17438->17428 17439 7ff67f382d27 17438->17439 17440 7ff67f382770 59 API calls 17439->17440 17440->17441 17441->17427 17443 7ff67f382e34 17442->17443 17444 7ff67f393be4 49 API calls 17443->17444 17445 7ff67f382e5a 17444->17445 17446 7ff67f382e6b 17445->17446 17474 7ff67f394e08 17445->17474 17448 7ff67f38ad80 _wfindfirst32i64 8 API calls 17446->17448 17449 7ff67f382a8d 17448->17449 17449->17396 17449->17397 17451 7ff67f38660e 17450->17451 17452 7ff67f383cb0 116 API calls 17451->17452 17453 7ff67f386635 17452->17453 17454 7ff67f386a40 136 API calls 17453->17454 17455 7ff67f386643 17454->17455 17456 7ff67f3866f3 17455->17456 17457 7ff67f38665d 17455->17457 17459 7ff67f38f2ac 74 API calls 17456->17459 17467 7ff67f3866ef 17456->17467 17637 7ff67f38f344 17457->17637 17459->17467 17460 7ff67f386662 17464 7ff67f38f5fc _fread_nolock 53 API calls 17460->17464 17468 7ff67f38fd3c 76 API calls 17460->17468 17469 7ff67f386699 17460->17469 17470 7ff67f38f344 37 API calls 17460->17470 17471 7ff67f38f370 37 API calls 17460->17471 17473 7ff67f3866d0 17460->17473 17461 7ff67f38ad80 _wfindfirst32i64 8 API calls 17462 7ff67f386715 17461->17462 17462->17404 17463 7ff67f38f2ac 74 API calls 17465 7ff67f3866e7 17463->17465 17464->17460 17466 7ff67f38f2ac 74 API calls 17465->17466 17466->17467 17467->17461 17468->17460 17643 7ff67f397388 17469->17643 17470->17460 17471->17460 17473->17463 17475 7ff67f394e31 17474->17475 17476 7ff67f394e25 17474->17476 17478 7ff67f394a1c 45 API calls 17475->17478 17491 7ff67f394680 17476->17491 17480 7ff67f394e59 17478->17480 17479 7ff67f394e2a 17479->17446 17482 7ff67f394e69 17480->17482 17515 7ff67f39dfcc 17480->17515 17518 7ff67f394504 17482->17518 17485 7ff67f394ed9 17486 7ff67f394680 69 API calls 17485->17486 17488 7ff67f394ee5 17486->17488 17487 7ff67f394ec5 17487->17479 17489 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17487->17489 17488->17479 17490 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17488->17490 17489->17479 17490->17479 17492 7ff67f3946b7 17491->17492 17493 7ff67f39469a 17491->17493 17492->17493 17495 7ff67f3946ca CreateFileW 17492->17495 17494 7ff67f394424 _fread_nolock 11 API calls 17493->17494 17496 7ff67f39469f 17494->17496 17497 7ff67f3946fe 17495->17497 17498 7ff67f394734 17495->17498 17499 7ff67f394444 memcpy_s 11 API calls 17496->17499 17540 7ff67f3947d4 GetFileType 17497->17540 17566 7ff67f394cf8 17498->17566 17502 7ff67f3946a7 17499->17502 17507 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 17502->17507 17505 7ff67f394768 17587 7ff67f394ab8 17505->17587 17506 7ff67f39473d 17510 7ff67f3943b8 _fread_nolock 11 API calls 17506->17510 17514 7ff67f3946b2 17507->17514 17508 7ff67f394713 CloseHandle 17508->17514 17509 7ff67f394729 CloseHandle 17509->17514 17510->17514 17514->17479 17628 7ff67f39ddb8 17515->17628 17519 7ff67f39452e 17518->17519 17520 7ff67f394552 17518->17520 17524 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17519->17524 17527 7ff67f39453d 17519->17527 17521 7ff67f394557 17520->17521 17522 7ff67f3945ac 17520->17522 17525 7ff67f39456c 17521->17525 17521->17527 17528 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17521->17528 17523 7ff67f39e7f0 _fread_nolock MultiByteToWideChar 17522->17523 17526 7ff67f3945c8 17523->17526 17524->17527 17529 7ff67f39cacc _fread_nolock 12 API calls 17525->17529 17530 7ff67f3945cf GetLastError 17526->17530 17533 7ff67f3945fd 17526->17533 17536 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17526->17536 17539 7ff67f39460a 17526->17539 17527->17485 17527->17487 17528->17525 17529->17527 17531 7ff67f3943b8 _fread_nolock 11 API calls 17530->17531 17532 7ff67f3945dc 17531->17532 17535 7ff67f394444 memcpy_s 11 API calls 17532->17535 17537 7ff67f39cacc _fread_nolock 12 API calls 17533->17537 17534 7ff67f39e7f0 _fread_nolock MultiByteToWideChar 17538 7ff67f39464e 17534->17538 17535->17527 17536->17533 17537->17539 17538->17527 17538->17530 17539->17527 17539->17534 17541 7ff67f3948df 17540->17541 17542 7ff67f394822 17540->17542 17543 7ff67f3948e7 17541->17543 17544 7ff67f394909 17541->17544 17545 7ff67f39484e GetFileInformationByHandle 17542->17545 17546 7ff67f394bf4 21 API calls 17542->17546 17547 7ff67f3948fa GetLastError 17543->17547 17548 7ff67f3948eb 17543->17548 17550 7ff67f39492c PeekNamedPipe 17544->17550 17565 7ff67f3948ca 17544->17565 17545->17547 17549 7ff67f394877 17545->17549 17551 7ff67f39483c 17546->17551 17554 7ff67f3943b8 _fread_nolock 11 API calls 17547->17554 17552 7ff67f394444 memcpy_s 11 API calls 17548->17552 17553 7ff67f394ab8 51 API calls 17549->17553 17550->17565 17551->17545 17551->17565 17552->17565 17556 7ff67f394882 17553->17556 17554->17565 17555 7ff67f38ad80 _wfindfirst32i64 8 API calls 17557 7ff67f39470c 17555->17557 17604 7ff67f39497c 17556->17604 17557->17508 17557->17509 17560 7ff67f39497c 10 API calls 17561 7ff67f3948a1 17560->17561 17562 7ff67f39497c 10 API calls 17561->17562 17563 7ff67f3948b2 17562->17563 17564 7ff67f394444 memcpy_s 11 API calls 17563->17564 17563->17565 17564->17565 17565->17555 17567 7ff67f394d2e 17566->17567 17568 7ff67f394dc6 __vcrt_freefls 17567->17568 17569 7ff67f394444 memcpy_s 11 API calls 17567->17569 17570 7ff67f38ad80 _wfindfirst32i64 8 API calls 17568->17570 17571 7ff67f394d40 17569->17571 17572 7ff67f394739 17570->17572 17573 7ff67f394444 memcpy_s 11 API calls 17571->17573 17572->17505 17572->17506 17574 7ff67f394d48 17573->17574 17575 7ff67f395348 45 API calls 17574->17575 17576 7ff67f394d5d 17575->17576 17577 7ff67f394d6f 17576->17577 17578 7ff67f394d65 17576->17578 17579 7ff67f394444 memcpy_s 11 API calls 17577->17579 17580 7ff67f394444 memcpy_s 11 API calls 17578->17580 17581 7ff67f394d74 17579->17581 17584 7ff67f394d6a 17580->17584 17581->17568 17582 7ff67f394444 memcpy_s 11 API calls 17581->17582 17583 7ff67f394d7e 17582->17583 17585 7ff67f395348 45 API calls 17583->17585 17584->17568 17586 7ff67f394db8 GetDriveTypeW 17584->17586 17585->17584 17586->17568 17588 7ff67f394ae0 17587->17588 17596 7ff67f394775 17588->17596 17611 7ff67f39e674 17588->17611 17590 7ff67f394b74 17591 7ff67f39e674 51 API calls 17590->17591 17590->17596 17592 7ff67f394b87 17591->17592 17593 7ff67f39e674 51 API calls 17592->17593 17592->17596 17594 7ff67f394b9a 17593->17594 17595 7ff67f39e674 51 API calls 17594->17595 17594->17596 17595->17596 17597 7ff67f394bf4 17596->17597 17598 7ff67f394c0e 17597->17598 17599 7ff67f394c45 17598->17599 17600 7ff67f394c1e 17598->17600 17601 7ff67f39e508 21 API calls 17599->17601 17602 7ff67f3943b8 _fread_nolock 11 API calls 17600->17602 17603 7ff67f394c2e 17600->17603 17601->17603 17602->17603 17603->17514 17605 7ff67f3949a5 FileTimeToSystemTime 17604->17605 17606 7ff67f394998 17604->17606 17607 7ff67f3949b9 SystemTimeToTzSpecificLocalTime 17605->17607 17608 7ff67f3949a0 17605->17608 17606->17605 17606->17608 17607->17608 17609 7ff67f38ad80 _wfindfirst32i64 8 API calls 17608->17609 17610 7ff67f394891 17609->17610 17610->17560 17612 7ff67f39e6a5 17611->17612 17613 7ff67f39e681 17611->17613 17615 7ff67f39e6df 17612->17615 17618 7ff67f39e6fe 17612->17618 17613->17612 17614 7ff67f39e686 17613->17614 17616 7ff67f394444 memcpy_s 11 API calls 17614->17616 17617 7ff67f394444 memcpy_s 11 API calls 17615->17617 17619 7ff67f39e68b 17616->17619 17620 7ff67f39e6e4 17617->17620 17621 7ff67f394a1c 45 API calls 17618->17621 17622 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 17619->17622 17623 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 17620->17623 17626 7ff67f39e70b 17621->17626 17624 7ff67f39e696 17622->17624 17625 7ff67f39e6ef 17623->17625 17624->17590 17625->17590 17626->17625 17627 7ff67f3a4640 51 API calls 17626->17627 17627->17626 17634 7ff67f39de15 17628->17634 17635 7ff67f39de10 __vcrt_FlsAlloc 17628->17635 17629 7ff67f39de45 LoadLibraryExW 17631 7ff67f39df1a 17629->17631 17632 7ff67f39de6a GetLastError 17629->17632 17630 7ff67f39df3a GetProcAddress 17630->17634 17631->17630 17633 7ff67f39df31 FreeLibrary 17631->17633 17632->17635 17633->17630 17634->17482 17635->17629 17635->17630 17635->17634 17636 7ff67f39dea4 LoadLibraryExW 17635->17636 17636->17631 17636->17635 17638 7ff67f38f34d 17637->17638 17642 7ff67f38f35d 17637->17642 17639 7ff67f394444 memcpy_s 11 API calls 17638->17639 17640 7ff67f38f352 17639->17640 17641 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 17640->17641 17641->17642 17642->17460 17644 7ff67f397390 17643->17644 17645 7ff67f3973ac 17644->17645 17646 7ff67f3973cd 17644->17646 17648 7ff67f394444 memcpy_s 11 API calls 17645->17648 17662 7ff67f3942ec EnterCriticalSection 17646->17662 17650 7ff67f3973b1 17648->17650 17652 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 17650->17652 17653 7ff67f3973bb 17652->17653 17653->17473 17664 7ff67f38733c 17663->17664 17667 7ff67f387471 17664->17667 17668 7ff67f38743f 17664->17668 17680 7ff67f387465 17664->17680 17665 7ff67f38ad80 _wfindfirst32i64 8 API calls 17666 7ff67f38749d 17665->17666 17695 7ff67f396f70 DeleteFileW 17667->17695 17690 7ff67f387820 FindFirstFileExW 17668->17690 17680->17665 17687 7ff67f3966fa GetLastError 17686->17687 17689 7ff67f386efb 17686->17689 17688 7ff67f3943b8 _fread_nolock 11 API calls 17687->17688 17688->17689 17689->15377 17691 7ff67f38785d FindClose 17690->17691 17692 7ff67f387870 17690->17692 17691->17692 18137 7ff67f38b0b0 18138 7ff67f38b0c0 18137->18138 18154 7ff67f39579c 18138->18154 18140 7ff67f38b0cc 18160 7ff67f38b3b8 18140->18160 18142 7ff67f38b69c 7 API calls 18145 7ff67f38b165 18142->18145 18143 7ff67f38b0e4 _RTC_Initialize 18152 7ff67f38b139 18143->18152 18165 7ff67f38b568 18143->18165 18146 7ff67f38b0f9 18168 7ff67f397e6c 18146->18168 18152->18142 18153 7ff67f38b155 18152->18153 18155 7ff67f3957ad 18154->18155 18156 7ff67f3957b5 18155->18156 18157 7ff67f394444 memcpy_s 11 API calls 18155->18157 18156->18140 18158 7ff67f3957c4 18157->18158 18159 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 18158->18159 18159->18156 18161 7ff67f38b3c9 18160->18161 18164 7ff67f38b3ce __scrt_acquire_startup_lock 18160->18164 18162 7ff67f38b69c 7 API calls 18161->18162 18161->18164 18163 7ff67f38b442 18162->18163 18164->18143 18193 7ff67f38b52c 18165->18193 18167 7ff67f38b571 18167->18146 18169 7ff67f397e8c 18168->18169 18182 7ff67f38b105 18168->18182 18170 7ff67f397e94 18169->18170 18171 7ff67f397eaa GetModuleFileNameW 18169->18171 18172 7ff67f394444 memcpy_s 11 API calls 18170->18172 18175 7ff67f397ed5 18171->18175 18173 7ff67f397e99 18172->18173 18174 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 18173->18174 18174->18182 18208 7ff67f397e0c 18175->18208 18178 7ff67f397f1d 18179 7ff67f394444 memcpy_s 11 API calls 18178->18179 18180 7ff67f397f22 18179->18180 18181 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18180->18181 18181->18182 18182->18152 18192 7ff67f38b63c InitializeSListHead 18182->18192 18183 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18183->18182 18184 7ff67f397f35 18185 7ff67f397f83 18184->18185 18186 7ff67f397f9c 18184->18186 18190 7ff67f397f57 18184->18190 18187 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18185->18187 18188 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18186->18188 18189 7ff67f397f8c 18187->18189 18188->18190 18191 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18189->18191 18190->18183 18191->18182 18194 7ff67f38b546 18193->18194 18196 7ff67f38b53f 18193->18196 18197 7ff67f398eec 18194->18197 18196->18167 18200 7ff67f398b28 18197->18200 18207 7ff67f39f788 EnterCriticalSection 18200->18207 18209 7ff67f397e5c 18208->18209 18210 7ff67f397e24 18208->18210 18209->18178 18209->18184 18210->18209 18211 7ff67f39dd40 memcpy_s 11 API calls 18210->18211 18212 7ff67f397e52 18211->18212 18213 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18212->18213 18213->18209 14684 7ff67f3987b9 14696 7ff67f3990d8 14684->14696 14701 7ff67f39a620 GetLastError 14696->14701 14702 7ff67f39a661 FlsSetValue 14701->14702 14703 7ff67f39a644 FlsGetValue 14701->14703 14705 7ff67f39a673 14702->14705 14720 7ff67f39a651 SetLastError 14702->14720 14704 7ff67f39a65b 14703->14704 14703->14720 14704->14702 14732 7ff67f39dd40 14705->14732 14708 7ff67f3990e1 14723 7ff67f39920c 14708->14723 14709 7ff67f39a6ed 14711 7ff67f39920c __CxxCallCatchBlock 38 API calls 14709->14711 14717 7ff67f39a6f2 14711->14717 14712 7ff67f39a6a0 FlsSetValue 14715 7ff67f39a6be 14712->14715 14716 7ff67f39a6ac FlsSetValue 14712->14716 14713 7ff67f39a690 FlsSetValue 14714 7ff67f39a699 14713->14714 14739 7ff67f399e18 14714->14739 14745 7ff67f39a3c4 14715->14745 14716->14714 14720->14708 14720->14709 14793 7ff67f3a2770 14723->14793 14738 7ff67f39dd51 memcpy_s 14732->14738 14733 7ff67f39dda2 14753 7ff67f394444 14733->14753 14734 7ff67f39dd86 RtlAllocateHeap 14736 7ff67f39a682 14734->14736 14734->14738 14736->14712 14736->14713 14738->14733 14738->14734 14750 7ff67f3a26b0 14738->14750 14740 7ff67f399e4c 14739->14740 14741 7ff67f399e1d HeapFree 14739->14741 14740->14720 14741->14740 14742 7ff67f399e38 GetLastError 14741->14742 14743 7ff67f399e45 Concurrency::details::SchedulerProxy::DeleteThis 14742->14743 14744 7ff67f394444 memcpy_s 9 API calls 14743->14744 14744->14740 14779 7ff67f39a29c 14745->14779 14756 7ff67f3a26f0 14750->14756 14762 7ff67f39a798 GetLastError 14753->14762 14755 7ff67f39444d 14755->14736 14761 7ff67f39f788 EnterCriticalSection 14756->14761 14763 7ff67f39a7d9 FlsSetValue 14762->14763 14767 7ff67f39a7bc 14762->14767 14764 7ff67f39a7eb 14763->14764 14768 7ff67f39a7c9 14763->14768 14766 7ff67f39dd40 memcpy_s 5 API calls 14764->14766 14765 7ff67f39a845 SetLastError 14765->14755 14769 7ff67f39a7fa 14766->14769 14767->14763 14767->14768 14768->14765 14770 7ff67f39a818 FlsSetValue 14769->14770 14771 7ff67f39a808 FlsSetValue 14769->14771 14773 7ff67f39a824 FlsSetValue 14770->14773 14774 7ff67f39a836 14770->14774 14772 7ff67f39a811 14771->14772 14775 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 5 API calls 14772->14775 14773->14772 14776 7ff67f39a3c4 memcpy_s 5 API calls 14774->14776 14775->14768 14777 7ff67f39a83e 14776->14777 14778 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 5 API calls 14777->14778 14778->14765 14791 7ff67f39f788 EnterCriticalSection 14779->14791 14827 7ff67f3a2728 14793->14827 14832 7ff67f39f788 EnterCriticalSection 14827->14832 17699 7ff67f38fd3c 17700 7ff67f38fd6c 17699->17700 17701 7ff67f38fa8c 76 API calls 17700->17701 17702 7ff67f38fd8a 17701->17702 18320 7ff67f398a50 18323 7ff67f3989d0 18320->18323 18330 7ff67f39f788 EnterCriticalSection 18323->18330 19284 7ff67f39e8dc 19285 7ff67f39eace 19284->19285 19287 7ff67f39e91e _isindst 19284->19287 19286 7ff67f394444 memcpy_s 11 API calls 19285->19286 19304 7ff67f39eabe 19286->19304 19287->19285 19290 7ff67f39e99e _isindst 19287->19290 19288 7ff67f38ad80 _wfindfirst32i64 8 API calls 19289 7ff67f39eae9 19288->19289 19305 7ff67f3a53b4 19290->19305 19295 7ff67f39eafa 19297 7ff67f399dd0 _wfindfirst32i64 17 API calls 19295->19297 19299 7ff67f39eb0e 19297->19299 19302 7ff67f39e9fb 19302->19304 19329 7ff67f3a53f8 19302->19329 19304->19288 19306 7ff67f3a53c3 19305->19306 19310 7ff67f39e9bc 19305->19310 19336 7ff67f39f788 EnterCriticalSection 19306->19336 19311 7ff67f3a47b8 19310->19311 19312 7ff67f3a47c1 19311->19312 19313 7ff67f39e9d1 19311->19313 19314 7ff67f394444 memcpy_s 11 API calls 19312->19314 19313->19295 19317 7ff67f3a47e8 19313->19317 19315 7ff67f3a47c6 19314->19315 19316 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 19315->19316 19316->19313 19318 7ff67f3a47f1 19317->19318 19322 7ff67f39e9e2 19317->19322 19319 7ff67f394444 memcpy_s 11 API calls 19318->19319 19320 7ff67f3a47f6 19319->19320 19321 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 19320->19321 19321->19322 19322->19295 19323 7ff67f3a4818 19322->19323 19324 7ff67f3a4821 19323->19324 19328 7ff67f39e9f3 19323->19328 19325 7ff67f394444 memcpy_s 11 API calls 19324->19325 19326 7ff67f3a4826 19325->19326 19327 7ff67f399db0 _invalid_parameter_noinfo 37 API calls 19326->19327 19327->19328 19328->19295 19328->19302 19337 7ff67f39f788 EnterCriticalSection 19329->19337 19342 7ff67f3a07f0 19353 7ff67f3a6764 19342->19353 19354 7ff67f3a6771 19353->19354 19355 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19354->19355 19356 7ff67f3a678d 19354->19356 19355->19354 19357 7ff67f399e18 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19356->19357 19358 7ff67f3a07f9 19356->19358 19357->19356 19359 7ff67f39f788 EnterCriticalSection 19358->19359 19360 7ff67f39b9f0 19371 7ff67f39f788 EnterCriticalSection 19360->19371

    Control-flow Graph

    APIs
    • GetLastError.KERNEL32(00000000,00007FF67F3826A0), ref: 00007FF67F3874D7
    • FormatMessageW.KERNELBASE(00000000,00007FF67F3826A0), ref: 00007FF67F387506
    • WideCharToMultiByte.KERNEL32 ref: 00007FF67F38755C
      • Part of subcall function 00007FF67F382620: GetLastError.KERNEL32(00000000,00000000,00000000,00007FF67F387744,?,?,?,?,?,?,?,?,?,?,?,00007FF67F38101D), ref: 00007FF67F382654
      • Part of subcall function 00007FF67F382620: MessageBoxW.USER32 ref: 00007FF67F38272C
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ErrorLastMessage$ByteCharFormatMultiWide
    • String ID: Failed to encode wchar_t as UTF-8.$FormatMessageW$No error messages generated.$PyInstaller: FormatMessageW failed.$PyInstaller: pyi_win32_utils_to_utf8 failed.$WideCharToMultiByte
    • API String ID: 2920928814-2573406579
    • Opcode ID: 684abde574661316fac8865b91606f208a8d8888a5608514f8e9f6b0269201cd
    • Instruction ID: 3361eae6260f05b744997fdfd60c8d65b2e6aa9781bb2f183f6d608ae1f00e9e
    • Opcode Fuzzy Hash: 684abde574661316fac8865b91606f208a8d8888a5608514f8e9f6b0269201cd
    • Instruction Fuzzy Hash: 50215033A3CA4282EB60DB21E850A7663A6FF483A5F840135E54DCA7A4EF7CE145C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 154 7ff67f3a5d6c-7ff67f3a5ddf call 7ff67f3a5aa0 157 7ff67f3a5de1-7ff67f3a5dea call 7ff67f394424 154->157 158 7ff67f3a5df9-7ff67f3a5e03 call 7ff67f396cfc 154->158 163 7ff67f3a5ded-7ff67f3a5df4 call 7ff67f394444 157->163 164 7ff67f3a5e1e-7ff67f3a5e87 CreateFileW 158->164 165 7ff67f3a5e05-7ff67f3a5e1c call 7ff67f394424 call 7ff67f394444 158->165 178 7ff67f3a613a-7ff67f3a615a 163->178 168 7ff67f3a5f04-7ff67f3a5f0f GetFileType 164->168 169 7ff67f3a5e89-7ff67f3a5e8f 164->169 165->163 171 7ff67f3a5f11-7ff67f3a5f4c GetLastError call 7ff67f3943b8 CloseHandle 168->171 172 7ff67f3a5f62-7ff67f3a5f69 168->172 174 7ff67f3a5ed1-7ff67f3a5eff GetLastError call 7ff67f3943b8 169->174 175 7ff67f3a5e91-7ff67f3a5e95 169->175 171->163 189 7ff67f3a5f52-7ff67f3a5f5d call 7ff67f394444 171->189 181 7ff67f3a5f71-7ff67f3a5f74 172->181 182 7ff67f3a5f6b-7ff67f3a5f6f 172->182 174->163 175->174 176 7ff67f3a5e97-7ff67f3a5ecf CreateFileW 175->176 176->168 176->174 186 7ff67f3a5f7a-7ff67f3a5fcf call 7ff67f396c14 181->186 187 7ff67f3a5f76 181->187 182->186 192 7ff67f3a5fee-7ff67f3a601f call 7ff67f3a5820 186->192 193 7ff67f3a5fd1-7ff67f3a5fdd call 7ff67f3a5ca8 186->193 187->186 189->163 200 7ff67f3a6021-7ff67f3a6023 192->200 201 7ff67f3a6025-7ff67f3a6067 192->201 193->192 199 7ff67f3a5fdf 193->199 202 7ff67f3a5fe1-7ff67f3a5fe9 call 7ff67f399f90 199->202 200->202 203 7ff67f3a6089-7ff67f3a6094 201->203 204 7ff67f3a6069-7ff67f3a606d 201->204 202->178 205 7ff67f3a6138 203->205 206 7ff67f3a609a-7ff67f3a609e 203->206 204->203 208 7ff67f3a606f-7ff67f3a6084 204->208 205->178 206->205 209 7ff67f3a60a4-7ff67f3a60e9 CloseHandle CreateFileW 206->209 208->203 211 7ff67f3a611e-7ff67f3a6133 209->211 212 7ff67f3a60eb-7ff67f3a6119 GetLastError call 7ff67f3943b8 call 7ff67f396e3c 209->212 211->205 212->211
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
    • String ID:
    • API String ID: 1617910340-0
    • Opcode ID: f9714f3a8e10acd42ca2d2c5b2c2c8a966f4ca54d5d677232d284773bb45134f
    • Instruction ID: 6388f40977ffef298b60018f7a03875b02f0f23f4e55f3aa3737da1d09616b6e
    • Opcode Fuzzy Hash: f9714f3a8e10acd42ca2d2c5b2c2c8a966f4ca54d5d677232d284773bb45134f
    • Instruction Fuzzy Hash: ECC1B537B28A4285EF50CF65C490AAC37A1FB49BA8B015235EE2E9B795DF38D055C3C0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _fread_nolock$Message_invalid_parameter_noinfo
    • String ID: Cannot read Table of Contents.$Could not allocate buffer for TOC!$Could not read full TOC!$Error on file.$Failed to read cookie!$Failed to seek to cookie position!$MEI$fread$fseek$malloc
    • API String ID: 2153230061-4158440160
    • Opcode ID: 3c065522737470c5bc3f7426856c5649201b393ecdf4055a802535b9189bd7de
    • Instruction ID: 894f987a763506432a7601afb4a2959512945c2b24fd44583a732d15a053c153
    • Opcode Fuzzy Hash: 3c065522737470c5bc3f7426856c5649201b393ecdf4055a802535b9189bd7de
    • Instruction Fuzzy Hash: E2516973A29A46C6EF54DF29D450A7833A0EB48B68B518135EA1DCB399DF3CE540CBD0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 217 7ff67f381000-7ff67f383686 call 7ff67f38f080 call 7ff67f38f078 call 7ff67f387600 call 7ff67f38f078 call 7ff67f38adb0 call 7ff67f394270 call 7ff67f394f14 call 7ff67f381af0 235 7ff67f38368c-7ff67f38369b call 7ff67f383ba0 217->235 236 7ff67f38379a 217->236 235->236 241 7ff67f3836a1-7ff67f3836b4 call 7ff67f383a70 235->241 238 7ff67f38379f-7ff67f3837bf call 7ff67f38ad80 236->238 241->236 245 7ff67f3836ba-7ff67f3836cd call 7ff67f383b20 241->245 245->236 248 7ff67f3836d3-7ff67f3836fa call 7ff67f386990 245->248 251 7ff67f38373c-7ff67f383764 call 7ff67f386f90 call 7ff67f3819d0 248->251 252 7ff67f3836fc-7ff67f38370b call 7ff67f386990 248->252 262 7ff67f38384d-7ff67f38385e 251->262 263 7ff67f38376a-7ff67f383780 call 7ff67f3819d0 251->263 252->251 257 7ff67f38370d-7ff67f383713 252->257 260 7ff67f383715-7ff67f38371d 257->260 261 7ff67f38371f-7ff67f383739 call 7ff67f39409c call 7ff67f386f90 257->261 260->261 261->251 267 7ff67f383873-7ff67f38388b call 7ff67f387a30 262->267 268 7ff67f383860-7ff67f38386a call 7ff67f383280 262->268 274 7ff67f383782-7ff67f383795 call 7ff67f382770 263->274 275 7ff67f3837c0-7ff67f3837c3 263->275 278 7ff67f38388d-7ff67f383899 call 7ff67f382770 267->278 279 7ff67f38389e-7ff67f3838a5 SetDllDirectoryW 267->279 282 7ff67f38386c 268->282 283 7ff67f3838ab-7ff67f3838b8 call 7ff67f385e40 268->283 274->236 275->262 281 7ff67f3837c9-7ff67f3837e0 call 7ff67f383cb0 275->281 278->236 279->283 292 7ff67f3837e7-7ff67f383813 call 7ff67f387200 281->292 293 7ff67f3837e2-7ff67f3837e5 281->293 282->267 290 7ff67f3838ba-7ff67f3838ca call 7ff67f385ae0 283->290 291 7ff67f383906-7ff67f38390b call 7ff67f385dc0 283->291 290->291 307 7ff67f3838cc-7ff67f3838db call 7ff67f385640 290->307 300 7ff67f383910-7ff67f383913 291->300 302 7ff67f38383d-7ff67f38384b 292->302 303 7ff67f383815-7ff67f38381d call 7ff67f38f2ac 292->303 297 7ff67f383822-7ff67f383838 call 7ff67f382770 293->297 297->236 305 7ff67f383919-7ff67f383926 300->305 306 7ff67f3839c6-7ff67f3839d5 call 7ff67f383110 300->306 302->268 303->297 309 7ff67f383930-7ff67f38393a 305->309 306->236 317 7ff67f3839db-7ff67f383a12 call 7ff67f386f20 call 7ff67f386990 call 7ff67f3853e0 306->317 320 7ff67f3838dd-7ff67f3838e9 call 7ff67f3855d0 307->320 321 7ff67f3838fc-7ff67f383901 call 7ff67f385890 307->321 313 7ff67f38393c-7ff67f383941 309->313 314 7ff67f383943-7ff67f383945 309->314 313->309 313->314 318 7ff67f383947-7ff67f38396a call 7ff67f381b30 314->318 319 7ff67f383991-7ff67f38399c call 7ff67f383270 call 7ff67f3830b0 314->319 317->236 344 7ff67f383a18-7ff67f383a4d call 7ff67f383270 call 7ff67f386fd0 call 7ff67f385890 call 7ff67f385dc0 317->344 318->236 331 7ff67f383970-7ff67f38397b 318->331 338 7ff67f3839a1-7ff67f3839c1 call 7ff67f383260 call 7ff67f385890 call 7ff67f385dc0 319->338 320->321 332 7ff67f3838eb-7ff67f3838fa call 7ff67f385c90 320->332 321->291 335 7ff67f383980-7ff67f38398f 331->335 332->300 335->319 335->335 338->238 357 7ff67f383a57-7ff67f383a61 call 7ff67f381ab0 344->357 358 7ff67f383a4f-7ff67f383a52 call 7ff67f386c90 344->358 357->238 358->357
    APIs
      • Part of subcall function 00007FF67F383BA0: GetModuleFileNameW.KERNEL32(?,00007FF67F383699), ref: 00007FF67F383BD1
    • SetDllDirectoryW.KERNEL32 ref: 00007FF67F3838A5
      • Part of subcall function 00007FF67F386990: GetEnvironmentVariableW.KERNEL32(00007FF67F3836E7), ref: 00007FF67F3869CA
      • Part of subcall function 00007FF67F386990: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF67F3869E7
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Environment$DirectoryExpandFileModuleNameStringsVariable
    • String ID: Cannot open PyInstaller archive from executable (%s) or external archive (%s)$Cannot side-load external archive %s (code %d)!$Failed to convert DLL search path!$MEI$_MEIPASS2$_PYI_ONEDIR_MODE
    • API String ID: 2344891160-3602715111
    • Opcode ID: 8112d3d585c797d6373512e27b0d923afc52f30f080197f56f8e373327622072
    • Instruction ID: fb3663acc3ef1c538b141231325ab53bcd9e9f6343e43e68d8665867dd9e14f2
    • Opcode Fuzzy Hash: 8112d3d585c797d6373512e27b0d923afc52f30f080197f56f8e373327622072
    • Instruction Fuzzy Hash: 0DB18023A3C68381EE64AB21D451AFD2390BF447A4F404132EA5DCF796EF2CE60597E0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 362 7ff67f39af2c-7ff67f39af52 363 7ff67f39af54-7ff67f39af68 call 7ff67f394424 call 7ff67f394444 362->363 364 7ff67f39af6d-7ff67f39af71 362->364 378 7ff67f39b35e 363->378 365 7ff67f39b347-7ff67f39b353 call 7ff67f394424 call 7ff67f394444 364->365 366 7ff67f39af77-7ff67f39af7e 364->366 385 7ff67f39b359 call 7ff67f399db0 365->385 366->365 368 7ff67f39af84-7ff67f39afb2 366->368 368->365 372 7ff67f39afb8-7ff67f39afbf 368->372 375 7ff67f39afc1-7ff67f39afd3 call 7ff67f394424 call 7ff67f394444 372->375 376 7ff67f39afd8-7ff67f39afdb 372->376 375->385 381 7ff67f39afe1-7ff67f39afe7 376->381 382 7ff67f39b343-7ff67f39b345 376->382 383 7ff67f39b361-7ff67f39b378 378->383 381->382 386 7ff67f39afed-7ff67f39aff0 381->386 382->383 385->378 386->375 389 7ff67f39aff2-7ff67f39b017 386->389 391 7ff67f39b019-7ff67f39b01b 389->391 392 7ff67f39b04a-7ff67f39b051 389->392 393 7ff67f39b042-7ff67f39b048 391->393 394 7ff67f39b01d-7ff67f39b024 391->394 395 7ff67f39b053-7ff67f39b07b call 7ff67f39cacc call 7ff67f399e18 * 2 392->395 396 7ff67f39b026-7ff67f39b03d call 7ff67f394424 call 7ff67f394444 call 7ff67f399db0 392->396 398 7ff67f39b0c8-7ff67f39b0df 393->398 394->393 394->396 422 7ff67f39b098-7ff67f39b0c3 call 7ff67f39b754 395->422 423 7ff67f39b07d-7ff67f39b093 call 7ff67f394444 call 7ff67f394424 395->423 426 7ff67f39b1d0 396->426 401 7ff67f39b0e1-7ff67f39b0e9 398->401 402 7ff67f39b15a-7ff67f39b164 call 7ff67f3a2a3c 398->402 401->402 406 7ff67f39b0eb-7ff67f39b0ed 401->406 413 7ff67f39b1ee 402->413 414 7ff67f39b16a-7ff67f39b17f 402->414 406->402 410 7ff67f39b0ef-7ff67f39b105 406->410 410->402 415 7ff67f39b107-7ff67f39b113 410->415 418 7ff67f39b1f3-7ff67f39b213 ReadFile 413->418 414->413 420 7ff67f39b181-7ff67f39b193 GetConsoleMode 414->420 415->402 421 7ff67f39b115-7ff67f39b117 415->421 424 7ff67f39b219-7ff67f39b221 418->424 425 7ff67f39b30d-7ff67f39b316 GetLastError 418->425 420->413 427 7ff67f39b195-7ff67f39b19d 420->427 421->402 428 7ff67f39b119-7ff67f39b131 421->428 422->398 423->426 424->425 431 7ff67f39b227 424->431 434 7ff67f39b333-7ff67f39b336 425->434 435 7ff67f39b318-7ff67f39b32e call 7ff67f394444 call 7ff67f394424 425->435 436 7ff67f39b1d3-7ff67f39b1dd call 7ff67f399e18 426->436 427->418 433 7ff67f39b19f-7ff67f39b1c1 ReadConsoleW 427->433 428->402 429 7ff67f39b133-7ff67f39b13f 428->429 429->402 437 7ff67f39b141-7ff67f39b143 429->437 441 7ff67f39b22e-7ff67f39b243 431->441 443 7ff67f39b1c3 GetLastError 433->443 444 7ff67f39b1e2-7ff67f39b1ec 433->444 438 7ff67f39b1c9-7ff67f39b1cb call 7ff67f3943b8 434->438 439 7ff67f39b33c-7ff67f39b33e 434->439 435->426 436->383 437->402 448 7ff67f39b145-7ff67f39b155 437->448 438->426 439->436 441->436 450 7ff67f39b245-7ff67f39b250 441->450 443->438 444->441 448->402 454 7ff67f39b252-7ff67f39b26b call 7ff67f39ab44 450->454 455 7ff67f39b277-7ff67f39b27f 450->455 462 7ff67f39b270-7ff67f39b272 454->462 459 7ff67f39b281-7ff67f39b293 455->459 460 7ff67f39b2fb-7ff67f39b308 call 7ff67f39a984 455->460 463 7ff67f39b2ee-7ff67f39b2f6 459->463 464 7ff67f39b295 459->464 460->462 462->436 463->436 466 7ff67f39b29a-7ff67f39b2a1 464->466 467 7ff67f39b2a3-7ff67f39b2a7 466->467 468 7ff67f39b2dd-7ff67f39b2e8 466->468 469 7ff67f39b2c3 467->469 470 7ff67f39b2a9-7ff67f39b2b0 467->470 468->463 472 7ff67f39b2c9-7ff67f39b2d9 469->472 470->469 471 7ff67f39b2b2-7ff67f39b2b6 470->471 471->469 473 7ff67f39b2b8-7ff67f39b2c1 471->473 472->466 474 7ff67f39b2db 472->474 473->472 474->463
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 6f2067f9e2b798d7e4aa60285487f192dd8020c4dcad372bd04a148e1f9d7242
    • Instruction ID: aa83514fc6a2796506f5cf0731d3c6b61180b9dd79aad309a7bf73b6115ac101
    • Opcode Fuzzy Hash: 6f2067f9e2b798d7e4aa60285487f192dd8020c4dcad372bd04a148e1f9d7242
    • Instruction Fuzzy Hash: 61C1F423A2C78681EB60DB199440ABD7BA1FF80BA8F554135DA4D8B395CE7CE945C3C0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • GetLastError.KERNEL32(00000000,00000000,00000000,00007FF67F387744,?,?,?,?,?,?,?,?,?,?,?,00007FF67F38101D), ref: 00007FF67F382654
      • Part of subcall function 00007FF67F3874B0: GetLastError.KERNEL32(00000000,00007FF67F3826A0), ref: 00007FF67F3874D7
      • Part of subcall function 00007FF67F3874B0: FormatMessageW.KERNELBASE(00000000,00007FF67F3826A0), ref: 00007FF67F387506
      • Part of subcall function 00007FF67F387A30: MultiByteToWideChar.KERNEL32 ref: 00007FF67F387A6A
    • MessageBoxW.USER32 ref: 00007FF67F38272C
    • MessageBoxA.USER32 ref: 00007FF67F382748
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Message$ErrorLast$ByteCharFormatMultiWide
    • String ID: %s%s: %s$Fatal error detected
    • API String ID: 2806210788-2410924014
    • Opcode ID: bd2085b38ade222d48c53e4b242a54a19eedc60d0d0276a39b8304b5fd6b5430
    • Instruction ID: bcbd85bf5cc785ea1f4d00e78bfde3725db9cc00b784dbeb98ccda7612359e7b
    • Opcode Fuzzy Hash: bd2085b38ade222d48c53e4b242a54a19eedc60d0d0276a39b8304b5fd6b5430
    • Instruction Fuzzy Hash: 6F315673638A8191EA30DB51E451BEA6395FB84794F404036EA8D8B699DF3CD345C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_initialize_crt__scrt_release_startup_lock
    • String ID:
    • API String ID: 1452418845-0
    • Opcode ID: 90a7fcc3a81af5bf04ad81541e301d7d9fb9f11ea0fdd18d74326f9016f6428e
    • Instruction ID: 797904afc71d7930e8885d3d43ef003c64e3eef542334d0f1995a3aa783a09ee
    • Opcode Fuzzy Hash: 90a7fcc3a81af5bf04ad81541e301d7d9fb9f11ea0fdd18d74326f9016f6428e
    • Instruction Fuzzy Hash: 68313E63E3C14785FE64AB699412BFD2391AF953A8F844034E95DCF2D3DE2CA40983E1
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Process$CurrentExitTerminate
    • String ID:
    • API String ID: 1703294689-0
    • Opcode ID: d426427e4f48dbbb9dc5f253e5f2c69f0b75b8518679dacd75070a6bbb583433
    • Instruction ID: 40bf9063dd1aec68eaff5c1874df043d9edd4f9efa3321ae6a9ec28986498572
    • Opcode Fuzzy Hash: d426427e4f48dbbb9dc5f253e5f2c69f0b75b8518679dacd75070a6bbb583433
    • Instruction Fuzzy Hash: 3DD05E53F3C70282FE147B315C4487813516F88764F401438D82BCE383CD2CA40842D0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 598 7ff67f38f39c-7ff67f38f3c9 599 7ff67f38f3e5 598->599 600 7ff67f38f3cb-7ff67f38f3ce 598->600 601 7ff67f38f3e7-7ff67f38f3fb 599->601 600->599 602 7ff67f38f3d0-7ff67f38f3d3 600->602 603 7ff67f38f3d5-7ff67f38f3da call 7ff67f394444 602->603 604 7ff67f38f3fc-7ff67f38f3ff 602->604 616 7ff67f38f3e0 call 7ff67f399db0 603->616 605 7ff67f38f40f-7ff67f38f413 604->605 606 7ff67f38f401-7ff67f38f40d 604->606 609 7ff67f38f415-7ff67f38f41f call 7ff67f38c210 605->609 610 7ff67f38f427-7ff67f38f42a 605->610 606->605 608 7ff67f38f43a-7ff67f38f443 606->608 614 7ff67f38f445-7ff67f38f448 608->614 615 7ff67f38f44a 608->615 609->610 610->603 613 7ff67f38f42c-7ff67f38f438 610->613 613->603 613->608 618 7ff67f38f44f-7ff67f38f46e 614->618 615->618 616->599 620 7ff67f38f474-7ff67f38f482 618->620 621 7ff67f38f5b5-7ff67f38f5b8 618->621 622 7ff67f38f484-7ff67f38f48b 620->622 623 7ff67f38f4fa-7ff67f38f4ff 620->623 621->601 622->623 626 7ff67f38f48d 622->626 624 7ff67f38f501-7ff67f38f50d 623->624 625 7ff67f38f56c-7ff67f38f56f call 7ff67f39b37c 623->625 629 7ff67f38f50f-7ff67f38f516 624->629 630 7ff67f38f519-7ff67f38f51f 624->630 636 7ff67f38f574-7ff67f38f577 625->636 627 7ff67f38f5e0 626->627 628 7ff67f38f493-7ff67f38f49d 626->628 635 7ff67f38f5e5-7ff67f38f5f0 627->635 632 7ff67f38f4a3-7ff67f38f4a9 628->632 633 7ff67f38f5bd-7ff67f38f5c1 628->633 629->630 630->633 634 7ff67f38f525-7ff67f38f542 call 7ff67f399184 call 7ff67f39af2c 630->634 637 7ff67f38f4e1-7ff67f38f4f5 632->637 638 7ff67f38f4ab-7ff67f38f4ae 632->638 639 7ff67f38f5d0-7ff67f38f5db call 7ff67f394444 633->639 640 7ff67f38f5c3-7ff67f38f5cb call 7ff67f38c210 633->640 657 7ff67f38f547-7ff67f38f549 634->657 635->601 636->635 642 7ff67f38f579-7ff67f38f57c 636->642 649 7ff67f38f59c-7ff67f38f5a7 637->649 643 7ff67f38f4b0-7ff67f38f4b6 638->643 644 7ff67f38f4cc-7ff67f38f4d7 call 7ff67f394444 call 7ff67f399db0 638->644 639->616 640->639 642->633 648 7ff67f38f57e-7ff67f38f595 642->648 651 7ff67f38f4c2-7ff67f38f4c7 call 7ff67f38c210 643->651 652 7ff67f38f4b8-7ff67f38f4c0 call 7ff67f38bb60 643->652 664 7ff67f38f4dc 644->664 648->649 649->620 650 7ff67f38f5ad 649->650 650->621 651->644 652->664 661 7ff67f38f54f 657->661 662 7ff67f38f5f5-7ff67f38f5fa 657->662 661->627 665 7ff67f38f555-7ff67f38f56a 661->665 662->635 664->637 665->649
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: bd665411d6c8cb657e02e9163d495b47fe1eb31481a6a537198dee777c004d3e
    • Instruction ID: 14d4d4a739aae5ec7e1b04170eede95194cd25c29bbf78b505b305f7f2e4972a
    • Opcode Fuzzy Hash: bd665411d6c8cb657e02e9163d495b47fe1eb31481a6a537198dee777c004d3e
    • Instruction Fuzzy Hash: 0951C463B2964286EA689E359400E7A6381BF54BB8F144635DE7DCF7C9CF3CE40186E0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • FindCloseChangeNotification.KERNELBASE(?,?,?,00007FF67F399EA5,?,?,00000000,00007FF67F399F5A), ref: 00007FF67F39A096
    • GetLastError.KERNEL32(?,?,?,00007FF67F399EA5,?,?,00000000,00007FF67F399F5A), ref: 00007FF67F39A0A0
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ChangeCloseErrorFindLastNotification
    • String ID:
    • API String ID: 1687624791-0
    • Opcode ID: 649148bb364a2e2bb6c01b4b98e8ba63ccdb9764b03dbbc10b4a89a301f042aa
    • Instruction ID: c01fb24a5a1e95a5f7b7d5ce3d62ecae616e54c1e33a5a93b1d1d539a71a1eaf
    • Opcode Fuzzy Hash: 649148bb364a2e2bb6c01b4b98e8ba63ccdb9764b03dbbc10b4a89a301f042aa
    • Instruction Fuzzy Hash: B0218E23F2868381FE90D725A594A791391AF847B8F184335DA7E8B7C5CE6CA44582C0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • SetFilePointerEx.KERNELBASE(?,?,?,?,00000000,00007FF67F39B79D), ref: 00007FF67F39B650
    • GetLastError.KERNEL32(?,?,?,?,00000000,00007FF67F39B79D), ref: 00007FF67F39B65A
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ErrorFileLastPointer
    • String ID:
    • API String ID: 2976181284-0
    • Opcode ID: ff2257711b1d275b862e663729d543ef4812b290fbf882e2e1232765a84f7875
    • Instruction ID: 80a1d87d7b2ba14fe19ea3700262d1f5c0807eec7af1087f71be9b87151823de
    • Opcode Fuzzy Hash: ff2257711b1d275b862e663729d543ef4812b290fbf882e2e1232765a84f7875
    • Instruction Fuzzy Hash: 6B11C163A28B8281DA10CB2AF404569A361BB44BF8F544331EE7D8B7E9CF3CE11187C0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 7edcb5c19051daea02f21c4053ec30bf8603933813fd22e9cae156a3527bc5bd
    • Instruction ID: 23a8ae7e4a4ef9ecc6369747a4d5e04b9db9245dd3a3b4a45fb31ea284fcfb0a
    • Opcode Fuzzy Hash: 7edcb5c19051daea02f21c4053ec30bf8603933813fd22e9cae156a3527bc5bd
    • Instruction Fuzzy Hash: 5A41E13392864183FB34DB19E580A7973A4EB95BA8F100235DA8ECB6D1CF2CE502D7D1
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _fread_nolock
    • String ID:
    • API String ID: 840049012-0
    • Opcode ID: e9032aa6d9b55eac528051dccc3408ce21bdab3594e0e76e6c36bec994bc223f
    • Instruction ID: a2e7c07cd46e65216304dd20fc4b80bf43153bf487f3d485ec15cfc46444cea5
    • Opcode Fuzzy Hash: e9032aa6d9b55eac528051dccc3408ce21bdab3594e0e76e6c36bec994bc223f
    • Instruction Fuzzy Hash: DE21A823B3929246FA119A226504BFAA752BF45BE5F885430EE4DCF786CE7CE141C3D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 36b0fbc90b3b462680d3b6a13c035726274d9c74de2b43bcb58660ea55cb43b3
    • Instruction ID: a1812180bfccaf81cd094c299c43bd485365e9dd65e376b255379f46b598c53d
    • Opcode Fuzzy Hash: 36b0fbc90b3b462680d3b6a13c035726274d9c74de2b43bcb58660ea55cb43b3
    • Instruction Fuzzy Hash: 9F318923E3C65281FB61EB15D840A783790AB40BB9F414235EA6D8B3D6CF7CE84186D1
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: HandleModule$AddressFreeLibraryProc
    • String ID:
    • API String ID: 3947729631-0
    • Opcode ID: e9a7e304643df4a79f5f92f113a909c0855d61e5f1cd2648997e34e72053eb35
    • Instruction ID: bbce3f1591571c61f226b926749c7f17685cf0a7122d5482f72298fb472300ea
    • Opcode Fuzzy Hash: e9a7e304643df4a79f5f92f113a909c0855d61e5f1cd2648997e34e72053eb35
    • Instruction Fuzzy Hash: 98216B73E2860689EB24DF64D4406BC33A0FB8476CF94163AD62C8AAD5DF38D544C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: be1079961907d1906d587a3e65c1e024338dd0a3e917ec7f85ba85c18500dcb2
    • Instruction ID: d888e8552ef00410ee71ae9b5cce6811c100f3f319d4a8bd1e917bd23f0f0828
    • Opcode Fuzzy Hash: be1079961907d1906d587a3e65c1e024338dd0a3e917ec7f85ba85c18500dcb2
    • Instruction Fuzzy Hash: E8114223A2D64241EAA0DF519501A79A3E0AF85BA8F444432EA8C9B796CF7DD48087C1
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: bc68aba4551d34184bb05bda2552568f64e358e9307c55527e30db01171bb599
    • Instruction ID: 9748ceff30393eeb4d949d130f90867224bc358e236f69319f5590baa237f391
    • Opcode Fuzzy Hash: bc68aba4551d34184bb05bda2552568f64e358e9307c55527e30db01171bb599
    • Instruction Fuzzy Hash: 08216533A2864187DBA18F19E440B7977A0FB84BA4F144235E65D8B6D9DF3DD4018BC0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: f8ccbbb08b6b64fca274b3102351a157ba9f641dbe881e0fbefe782dfe020abd
    • Instruction ID: 60ceea89b809d004f5aab93e6064cd5ae66202a8a9bc7876b2a6e72041a001ed
    • Opcode Fuzzy Hash: f8ccbbb08b6b64fca274b3102351a157ba9f641dbe881e0fbefe782dfe020abd
    • Instruction Fuzzy Hash: A5016522A2874241E904DB629901969A795BB55FF4F488731DE6CDBBD6CE3CD40147D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • RtlAllocateHeap.NTDLL(?,?,00000000,00007FF67F39A8B6,?,?,?,00007FF67F399A73,?,?,00000000,00007FF67F399D0E), ref: 00007FF67F39DD95
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: AllocateHeap
    • String ID:
    • API String ID: 1279760036-0
    • Opcode ID: 2e0f3e4b2c9ccc38d96cb592f5054ed38be707e8bf6a1ab6843b3be497aa41a7
    • Instruction ID: e57ea24f8e60e068a430adb2d4b020ba44b9ad7a9b31217fbb4e6e3e46766467
    • Opcode Fuzzy Hash: 2e0f3e4b2c9ccc38d96cb592f5054ed38be707e8bf6a1ab6843b3be497aa41a7
    • Instruction Fuzzy Hash: DBF06256B3960241FE94E767950ABB503905F85BA8F4CA430D94DCE2D2DD1CE44081E0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF67F387A30: MultiByteToWideChar.KERNEL32 ref: 00007FF67F387A6A
    • LoadLibraryW.KERNELBASE(?,?,00000000,00007FF67F3830BE), ref: 00007FF67F3871D3
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ByteCharLibraryLoadMultiWide
    • String ID:
    • API String ID: 2592636585-0
    • Opcode ID: 63080640ee8bd5a5197bc5957a639ee791a00d05320db4a40cef4a6e5ab977c0
    • Instruction ID: b1cd998302a6a9c2713875507983c4dc6ec720d4b3ef511c9070c1d6bc36cfe5
    • Opcode Fuzzy Hash: 63080640ee8bd5a5197bc5957a639ee791a00d05320db4a40cef4a6e5ab977c0
    • Instruction Fuzzy Hash: C5E08613B3814582EE5897A7E55586AA352AF88BD0B489035EE1D8B755DD2CD8904A80
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: AddressProc$LibraryLoad
    • String ID: Failed to get address for Tcl_Alloc$Failed to get address for Tcl_ConditionFinalize$Failed to get address for Tcl_ConditionNotify$Failed to get address for Tcl_ConditionWait$Failed to get address for Tcl_CreateInterp$Failed to get address for Tcl_CreateObjCommand$Failed to get address for Tcl_CreateThread$Failed to get address for Tcl_DeleteInterp$Failed to get address for Tcl_DoOneEvent$Failed to get address for Tcl_EvalEx$Failed to get address for Tcl_EvalFile$Failed to get address for Tcl_EvalObjv$Failed to get address for Tcl_Finalize$Failed to get address for Tcl_FinalizeThread$Failed to get address for Tcl_FindExecutable$Failed to get address for Tcl_Free$Failed to get address for Tcl_GetCurrentThread$Failed to get address for Tcl_GetObjResult$Failed to get address for Tcl_GetString$Failed to get address for Tcl_GetVar2$Failed to get address for Tcl_Init$Failed to get address for Tcl_MutexLock$Failed to get address for Tcl_MutexUnlock$Failed to get address for Tcl_NewByteArrayObj$Failed to get address for Tcl_NewStringObj$Failed to get address for Tcl_SetVar2$Failed to get address for Tcl_SetVar2Ex$Failed to get address for Tcl_ThreadAlert$Failed to get address for Tcl_ThreadQueueEvent$Failed to get address for Tk_GetNumMainWindows$Failed to get address for Tk_Init$GetProcAddress$LOADER: Failed to load tcl/tk libraries$Tcl_Alloc$Tcl_ConditionFinalize$Tcl_ConditionNotify$Tcl_ConditionWait$Tcl_CreateInterp$Tcl_CreateObjCommand$Tcl_CreateThread$Tcl_DeleteInterp$Tcl_DoOneEvent$Tcl_EvalEx$Tcl_EvalFile$Tcl_EvalObjv$Tcl_Finalize$Tcl_FinalizeThread$Tcl_FindExecutable$Tcl_Free$Tcl_GetCurrentThread$Tcl_GetObjResult$Tcl_GetString$Tcl_GetVar2$Tcl_Init$Tcl_MutexLock$Tcl_MutexUnlock$Tcl_NewByteArrayObj$Tcl_NewStringObj$Tcl_SetVar2$Tcl_SetVar2Ex$Tcl_ThreadAlert$Tcl_ThreadQueueEvent$Tk_GetNumMainWindows$Tk_Init
    • API String ID: 2238633743-1453502826
    • Opcode ID: 4c3d84e7267adeddf6e2c1c525ba4fa7748455c51c362dfb67f89ee1dca86c34
    • Instruction ID: 13771af8098103ba00b5c49f2d696d5833c751844393cd8a49c661ae3f3596a1
    • Opcode Fuzzy Hash: 4c3d84e7267adeddf6e2c1c525ba4fa7748455c51c362dfb67f89ee1dca86c34
    • Instruction Fuzzy Hash: 78E19266A3DB03D0EE95CB16A85097423E5AF047B4B846535E81ECE3A8EF7CE558C3D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: MessageSend$Window$Create$Move$ObjectSelect$#380BaseClientDialogDrawFontIndirectInfoParametersRectReleaseSystemTextUnits
    • String ID: BUTTON$Close$EDIT$Failed to execute script '%ls' due to unhandled exception: %ls$STATIC
    • API String ID: 2446303242-1601438679
    • Opcode ID: 47b3578659853d453a5822a751c8e2f63cfdf798862dd1eeebf7592aa26dc86d
    • Instruction ID: c6e316c2a6b189013c9af32169c5093e4f1324f65593d1cc0012ae6c204fbd4a
    • Opcode Fuzzy Hash: 47b3578659853d453a5822a751c8e2f63cfdf798862dd1eeebf7592aa26dc86d
    • Instruction Fuzzy Hash: 2FA14C37228B81C6DB148F12E554BAAB3A0F748BA4F504125EB9D87B14DF7DE165CB80
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
    • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
    • API String ID: 808467561-2761157908
    • Opcode ID: 46fb5d0366b8e1e712cdd684d815614daf2c7cda5b16cac76ba58e706ef79b66
    • Instruction ID: 93da4a0fba4111c89d3b528c5b45bc61dd4a2807ce1febdf7079c1162f9bab4c
    • Opcode Fuzzy Hash: 46fb5d0366b8e1e712cdd684d815614daf2c7cda5b16cac76ba58e706ef79b66
    • Instruction Fuzzy Hash: D9B2C673E282928BEB658E66D440BFD77E1FB54354F405135EA0D9BA88DF3DA9009BC0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetTempPathW.KERNEL32(?,00000000,?,00007FF67F38674D), ref: 00007FF67F38681A
      • Part of subcall function 00007FF67F386990: GetEnvironmentVariableW.KERNEL32(00007FF67F3836E7), ref: 00007FF67F3869CA
      • Part of subcall function 00007FF67F386990: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF67F3869E7
      • Part of subcall function 00007FF67F3966B4: _invalid_parameter_noinfo.LIBCMT ref: 00007FF67F3966CD
    • SetEnvironmentVariableW.KERNEL32(?,TokenIntegrityLevel), ref: 00007FF67F3868D1
      • Part of subcall function 00007FF67F382770: MessageBoxW.USER32 ref: 00007FF67F382841
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Environment$Variable$ExpandMessagePathStringsTemp_invalid_parameter_noinfo
    • String ID: LOADER: Failed to set the TMP environment variable.$TMP$TMP$_MEI%d
    • API String ID: 3752271684-1116378104
    • Opcode ID: b4ad522e37175ac7074a900ecec4c645a4870e05ba81b0992846085732047fb7
    • Instruction ID: 84caf832925a8dc4327a28c06b9565923773a306fa1cb9d234706699ee3f9b5c
    • Opcode Fuzzy Hash: b4ad522e37175ac7074a900ecec4c645a4870e05ba81b0992846085732047fb7
    • Instruction Fuzzy Hash: C8516D13B3D64280FE54EB729965ABA53819F89BE0F444035ED0ECF796ED2CE90187D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
    • String ID:
    • API String ID: 3140674995-0
    • Opcode ID: 24fff5600ca101af0e2334446d678d156eb325a0e0e0c0538aba544f51e330ab
    • Instruction ID: 86e559cf28b1ce4561a0e1871e11dc96856e97772c89554012149fe00327042b
    • Opcode Fuzzy Hash: 24fff5600ca101af0e2334446d678d156eb325a0e0e0c0538aba544f51e330ab
    • Instruction Fuzzy Hash: 9C314F73618B8285EB608F65E8807ED73A0FB44754F44443ADA4D8BB98DF3CD548C790
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _get_daylight.LIBCMT ref: 00007FF67F3A4E65
      • Part of subcall function 00007FF67F3A47B8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF67F3A47CC
      • Part of subcall function 00007FF67F399E18: HeapFree.KERNEL32(?,?,?,00007FF67F3A1E42,?,?,?,00007FF67F3A1E7F,?,?,00000000,00007FF67F3A2345,?,?,?,00007FF67F3A2277), ref: 00007FF67F399E2E
      • Part of subcall function 00007FF67F399E18: GetLastError.KERNEL32(?,?,?,00007FF67F3A1E42,?,?,?,00007FF67F3A1E7F,?,?,00000000,00007FF67F3A2345,?,?,?,00007FF67F3A2277), ref: 00007FF67F399E38
      • Part of subcall function 00007FF67F399DD0: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF67F399DAF,?,?,?,?,?,00007FF67F3921EC), ref: 00007FF67F399DD9
      • Part of subcall function 00007FF67F399DD0: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF67F399DAF,?,?,?,?,?,00007FF67F3921EC), ref: 00007FF67F399DFE
    • _get_daylight.LIBCMT ref: 00007FF67F3A4E54
      • Part of subcall function 00007FF67F3A4818: _invalid_parameter_noinfo.LIBCMT ref: 00007FF67F3A482C
    • _get_daylight.LIBCMT ref: 00007FF67F3A50CA
    • _get_daylight.LIBCMT ref: 00007FF67F3A50DB
    • _get_daylight.LIBCMT ref: 00007FF67F3A50EC
    • GetTimeZoneInformation.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,00007FF67F3A532C), ref: 00007FF67F3A5113
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
    • String ID:
    • API String ID: 4070488512-0
    • Opcode ID: a9f1dad40c5644c1829df854b35cf2cff202b4769108a1d535aac39d904cb9be
    • Instruction ID: c3cf9051fbfd4e6f96edd07123c0e02c9588aa180c27863ea0c562d4fc0e58d3
    • Opcode Fuzzy Hash: a9f1dad40c5644c1829df854b35cf2cff202b4769108a1d535aac39d904cb9be
    • Instruction Fuzzy Hash: EAD19F27A2825286EB60DF26D8919B963A1FF847A4F444136FA1DCBB95DF3CE441C7C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
    • String ID:
    • API String ID: 1239891234-0
    • Opcode ID: 4204087c2144b4154cc610f07160e172692864cccd6c23e577d201b1c5d7dbdf
    • Instruction ID: fe4ccb3287b8256262d6cef625112d69b37f0bd68de1d5cd9eedd4da49eedc2e
    • Opcode Fuzzy Hash: 4204087c2144b4154cc610f07160e172692864cccd6c23e577d201b1c5d7dbdf
    • Instruction Fuzzy Hash: DE315233628B8195EB60CF25E8406AE73A4FB84764F500135EA9D87B95DF3CD555CBC0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: FileFindFirst_invalid_parameter_noinfo
    • String ID:
    • API String ID: 2227656907-0
    • Opcode ID: 0bdd7a8416f1e28eb8c09c6b5c037a8b7871395a979be626bc7410ef92a9cb5d
    • Instruction ID: 4524e34ce5885e7204125089a743e3c7f24f2b19f3e429be699e23488c63c7eb
    • Opcode Fuzzy Hash: 0bdd7a8416f1e28eb8c09c6b5c037a8b7871395a979be626bc7410ef92a9cb5d
    • Instruction Fuzzy Hash: D5B190A3B2969681EE60DB369540ABA6390EB44BB4F444131FE5E8FB85DE3CE44183C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _get_daylight.LIBCMT ref: 00007FF67F3A50CA
      • Part of subcall function 00007FF67F3A4818: _invalid_parameter_noinfo.LIBCMT ref: 00007FF67F3A482C
    • _get_daylight.LIBCMT ref: 00007FF67F3A50DB
      • Part of subcall function 00007FF67F3A47B8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF67F3A47CC
    • _get_daylight.LIBCMT ref: 00007FF67F3A50EC
      • Part of subcall function 00007FF67F3A47E8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF67F3A47FC
      • Part of subcall function 00007FF67F399E18: HeapFree.KERNEL32(?,?,?,00007FF67F3A1E42,?,?,?,00007FF67F3A1E7F,?,?,00000000,00007FF67F3A2345,?,?,?,00007FF67F3A2277), ref: 00007FF67F399E2E
      • Part of subcall function 00007FF67F399E18: GetLastError.KERNEL32(?,?,?,00007FF67F3A1E42,?,?,?,00007FF67F3A1E7F,?,?,00000000,00007FF67F3A2345,?,?,?,00007FF67F3A2277), ref: 00007FF67F399E38
    • GetTimeZoneInformation.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,00007FF67F3A532C), ref: 00007FF67F3A5113
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
    • String ID:
    • API String ID: 3458911817-0
    • Opcode ID: 8dda7e1bb43cce3069c61b2343a9d469707a009ccb87a98b23344d3931a91aef
    • Instruction ID: a1c72c2c219c6b2b2fc33f7d2d30cb4a4900269e55a33a8ac60565872e1f7919
    • Opcode Fuzzy Hash: 8dda7e1bb43cce3069c61b2343a9d469707a009ccb87a98b23344d3931a91aef
    • Instruction Fuzzy Hash: 9D516333A2865286EB50DF22E9919B967A0FB487A4F444136FA5DCBB95DF3CE401C7C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: memcpy_s
    • String ID:
    • API String ID: 1502251526-0
    • Opcode ID: 723df14fe8405c9280d13974b9e0b256372cd2939c4def8ecbac686ef57d643c
    • Instruction ID: 882346453d7c41ac0ba0d9d611ead3fe94e0e0411a13bd9a67082327091ee92a
    • Opcode Fuzzy Hash: 723df14fe8405c9280d13974b9e0b256372cd2939c4def8ecbac686ef57d643c
    • Instruction Fuzzy Hash: 45C1D373B2868687EB25CF16A044E6AB7D1F784B94F448134EB4A9B744DE3DE841CBC0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ExceptionRaise_clrfp
    • String ID:
    • API String ID: 15204871-0
    • Opcode ID: 34bf4ba4d1f77b159a602f4f3a79dc58b46c4397abc6f90fe1b78d3c276b8e03
    • Instruction ID: 22b0ebba10423e1aaf03b774009215b18c016f3b749da50dfc195653d7b418ce
    • Opcode Fuzzy Hash: 34bf4ba4d1f77b159a602f4f3a79dc58b46c4397abc6f90fe1b78d3c276b8e03
    • Instruction Fuzzy Hash: 89B17C73610B89CBEB19CF2AC8467687BE0F744B58F148921EA6D877A4CF39D451C780
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Find$CloseFileFirst
    • String ID:
    • API String ID: 2295610775-0
    • Opcode ID: b154a429360a9d8fc422caeeb97d2d39407f5ca637504bf6a4efef03296319f0
    • Instruction ID: 95fb42ea49781a108fbbe388f5f21cc1c1c88f4e621878c5efc27a9152c1d8aa
    • Opcode Fuzzy Hash: b154a429360a9d8fc422caeeb97d2d39407f5ca637504bf6a4efef03296319f0
    • Instruction Fuzzy Hash: 5FF0A433A3878186EBA08F60E455BA67391FB44774F000735E66D8A6D4DF3CD049CAD0
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID: $
    • API String ID: 0-227171996
    • Opcode ID: 2d8c388a4af4e59f7aa018185c24a80b808f927c20487c79df8fa8b9671cd73b
    • Instruction ID: 0b76cbd08ff438e87bdf938d7b24d17ac86e3a28c19c773bcc6086f8da60b540
    • Opcode Fuzzy Hash: 2d8c388a4af4e59f7aa018185c24a80b808f927c20487c79df8fa8b9671cd73b
    • Instruction Fuzzy Hash: 2EE1C173A28A4286EB68CA258150D7933A0FF45B6CF161235DE5E8B794DF3DE842C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID: e+000$gfff
    • API String ID: 0-3030954782
    • Opcode ID: e8ad3313ac50deca76865dcff50c63e8317fb702a62c77948e89599ff08dba86
    • Instruction ID: 953e9bf0f60d02628e00bc46c9c9bfb27e29132f584310f674024d40c39e1053
    • Opcode Fuzzy Hash: e8ad3313ac50deca76865dcff50c63e8317fb702a62c77948e89599ff08dba86
    • Instruction Fuzzy Hash: 55515823B282C646E765CE359845B697B91F744BA8F489231CBD8CFAD5CE3DD440C780
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: CurrentFeaturePresentProcessProcessor
    • String ID:
    • API String ID: 1010374628-0
    • Opcode ID: 9dfe81cf2fe2aeaa94458c05073b55d9d909155f94b1b315d38edc8d3fe764ba
    • Instruction ID: 92b68f32301717354e493051c4f98d761d9650e2c0c7164c92dd013f09f44518
    • Opcode Fuzzy Hash: 9dfe81cf2fe2aeaa94458c05073b55d9d909155f94b1b315d38edc8d3fe764ba
    • Instruction Fuzzy Hash: A9029D23E3E64681FF65EB22A410A796784AF41BB8F444635ED6DCE3D2DE3CA41183D0
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID: gfffffff
    • API String ID: 0-1523873471
    • Opcode ID: 24567b7b7ad9cc25883cfe86a0af8cdb31fb8148e1153fa934f37376d4be2ae6
    • Instruction ID: 55b1bafe1b9a002f0c2f9129aca73bd085f2f63661194050fae2cfa0e1dc4503
    • Opcode Fuzzy Hash: 24567b7b7ad9cc25883cfe86a0af8cdb31fb8148e1153fa934f37376d4be2ae6
    • Instruction Fuzzy Hash: A9A15A63B287C646EB21CB299410BB97B90EB55BE8F059032DE4E8B795DE3DD501CBC0
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: TMP
    • API String ID: 3215553584-3125297090
    • Opcode ID: 00c9b183540a5d61f6ae08d2a164c54d0dbd9f8471d374810534ff2672e287f6
    • Instruction ID: e184692785fce8d7d147f9c5bf09357f344c7dbad7755b2796c329b21a82f5d1
    • Opcode Fuzzy Hash: 00c9b183540a5d61f6ae08d2a164c54d0dbd9f8471d374810534ff2672e287f6
    • Instruction Fuzzy Hash: C3516D13F3964242FA68EB3659119BA5391AF84BE9F484435DE0DCF7D6EE3DE44282C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: HeapProcess
    • String ID:
    • API String ID: 54951025-0
    • Opcode ID: 6aaf01db4fcd6d8e5e92a2165bcca8bef3bc9097c29bcaeff3790f5a52787e5b
    • Instruction ID: 4f88ad06c277032a95244e1d0b35e9a38f3083c3b4a3eabfe32518bec8de3422
    • Opcode Fuzzy Hash: 6aaf01db4fcd6d8e5e92a2165bcca8bef3bc9097c29bcaeff3790f5a52787e5b
    • Instruction Fuzzy Hash: E5B09222E27A02D2EE092B22AC82A2423B4BF48720F990138D01C84320DF2C20AA97C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 720b0f885fc535c3a242e303a59ba9c626026de2633fd245c18c7096fc28f432
    • Instruction ID: 1e65f9692908ec0d45564505f3a6d2609ab6c20c324e5770cd7c8b9e4814c641
    • Opcode Fuzzy Hash: 720b0f885fc535c3a242e303a59ba9c626026de2633fd245c18c7096fc28f432
    • Instruction Fuzzy Hash: B6D1DE63A28A4286EB68CF298450E7D27A0FF45B6CF164235CE4D8B695CF3DE855C3C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 25b4879d951165098d7d9ad8dfdbe188c5f26750c92d05a39af3c572e9b4c9ce
    • Instruction ID: 1ef9788692094442db88e936adea9716861df07be675b5b2c24292a51011bef4
    • Opcode Fuzzy Hash: 25b4879d951165098d7d9ad8dfdbe188c5f26750c92d05a39af3c572e9b4c9ce
    • Instruction Fuzzy Hash: 94C184731141E04BE2C9EB29E56987E7791F78930DB94403BEB8787B89CB3CA514D790
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 3511ad376341763adbf03eaa1481790c1cd7a3e825f7d6c297581565e8b6740f
    • Instruction ID: efb1ff9b9f8f47098dc77e3c879cae731cbd721fcd8850ad3e3b3c1b64feb433
    • Opcode Fuzzy Hash: 3511ad376341763adbf03eaa1481790c1cd7a3e825f7d6c297581565e8b6740f
    • Instruction Fuzzy Hash: 31B15B77A28A858AE765CF29C450A3C3BA4E749B6CF254236CB4E8B395CF39D451C7C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: b482d32cf4439f597672c93949c919f143e2d798b80af63496daf47fa9f459cc
    • Instruction ID: f3d5d3b9119dc17cf86c7a5b8e33b2730637ce4772e042b5c47bdd2b8018b985
    • Opcode Fuzzy Hash: b482d32cf4439f597672c93949c919f143e2d798b80af63496daf47fa9f459cc
    • Instruction Fuzzy Hash: B281E473A2C78185EB74DF19944AB79A790FB457A8F504235DADE8BB89CF3CD4008B80
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 093da9d804f6d3f0dcf011766d3ac1044083a14a82be884a6ec622c588f21297
    • Instruction ID: 408e6176bd64da1ec06a8797e689082727e811605e637c699147c0f78c85cb2b
    • Opcode Fuzzy Hash: 093da9d804f6d3f0dcf011766d3ac1044083a14a82be884a6ec622c588f21297
    • Instruction Fuzzy Hash: 3261B723F2829286FFA5852A9450A7D67D1BF41370F14423AFA5ECE6D5EE7DE80087C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: d861661aa08db629cc23cdca8c369b076586a2e450c00db1ba5d57a294e44a4f
    • Instruction ID: f4bf9f7e13cbf431d61eefcc79e1a6aad1ac7b55277d22f3cffc421b390f7f0c
    • Opcode Fuzzy Hash: d861661aa08db629cc23cdca8c369b076586a2e450c00db1ba5d57a294e44a4f
    • Instruction Fuzzy Hash: 25515377A386518AE764DB29C44462937A0EB45BBCF244131CA8DAB795CF7BE843C7C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: c32b4ddfd43473a216dec7aa9a0be5b617892f75f4149cffacdc7470c95e978f
    • Instruction ID: 521e04f7df12be273d040f355444b0d2e38abc0bb2d59af9efa8f150e9d76381
    • Opcode Fuzzy Hash: c32b4ddfd43473a216dec7aa9a0be5b617892f75f4149cffacdc7470c95e978f
    • Instruction Fuzzy Hash: 565142B7A2865186E724CB39D044A2937A0EB55B7CF245131CE4D9F7A5CF3AE842CBC0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 867914ff4df0b6b44d704adc42bbe88cde9096fdc707783f05752eff833c7ffe
    • Instruction ID: 84c189f2f2035093bf379bbf372100a40e06df7266dae5f3c59053ec161523dd
    • Opcode Fuzzy Hash: 867914ff4df0b6b44d704adc42bbe88cde9096fdc707783f05752eff833c7ffe
    • Instruction Fuzzy Hash: 61514777A286518AE764DB19D040A2937B0EB59B7CF254131CE4DAB7A4CF3AE842C7C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 1de1d42fcd570761cca71ddda72003ed022ec41b6526507f8e47f89f031e3167
    • Instruction ID: 8a95203336d94516503f682c4fbb4d943755743ed42785b5997e8617031ec8a6
    • Opcode Fuzzy Hash: 1de1d42fcd570761cca71ddda72003ed022ec41b6526507f8e47f89f031e3167
    • Instruction Fuzzy Hash: A7517DB7A28A5186E764CB39C040A3937A1EB48B6CF245131DE4D9F795CF3AE952C7C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 876697f8e8f5cbbdb44752562e3cb115d809b93d1bac5633a342ac63b65505f1
    • Instruction ID: bbb9a6db845bf45a6c75c25df2475e36ddc00d9c791f88322cc4c1c1d913d342
    • Opcode Fuzzy Hash: 876697f8e8f5cbbdb44752562e3cb115d809b93d1bac5633a342ac63b65505f1
    • Instruction Fuzzy Hash: B1514DB7A2865586E764CB39C040A2927A1EB45B6CF284131CE4D9F7A5DF3AEC42C7C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 6b4a4146db3bd1fe649265067838c8b0d7c1a5e97031d62dd0eb31e0fdd0228e
    • Instruction ID: 799bf33c599f2b600157941c1539fa6df7f9a77887ea08449450f8e23e1e7cdb
    • Opcode Fuzzy Hash: 6b4a4146db3bd1fe649265067838c8b0d7c1a5e97031d62dd0eb31e0fdd0228e
    • Instruction Fuzzy Hash: E7514677A2465189E764DB29C04062C37A1EB45B7CF644135CE8DAB798CF3AE853C7C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
    • Instruction ID: e01eaaf3840f1d6add87fe7565a770179066d0cf6b8e8de00e8414e65b494269
    • Opcode Fuzzy Hash: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
    • Instruction Fuzzy Hash: 7F41D353C2D74F48F9D5C9188500EB827C0AF22BB9E6892B1DC9B9B3D6CD1C25CAC2C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ErrorFreeHeapLast
    • String ID:
    • API String ID: 485612231-0
    • Opcode ID: 5ea786bf6f8cd91bfc05a08c0c92a1f9982b351c0a184c2e6e7479b7886dc32f
    • Instruction ID: 0563c67aa60141adcb3aca45f0d61f7ce208ff18de6ae5863fd6db137204dc08
    • Opcode Fuzzy Hash: 5ea786bf6f8cd91bfc05a08c0c92a1f9982b351c0a184c2e6e7479b7886dc32f
    • Instruction Fuzzy Hash: B5411973B28A5581EF58CF2AD954969B3A1B748FE4B449432EE0DCBB54DE3CC04683C0
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: acfb330f7f9e9d51a6719fb60a794d6094d3cb8e4174533331f0489c7a291eae
    • Instruction ID: bd834340f38ef25a586b08399ebedb397c480622e561d2b67d00678ed42b0fc3
    • Opcode Fuzzy Hash: acfb330f7f9e9d51a6719fb60a794d6094d3cb8e4174533331f0489c7a291eae
    • Instruction Fuzzy Hash: A7319433729B4282EB24DF25A44153E67D5AB84BB4F144238EA5D9BB99DF3CD0128784
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: b98f8205f4dd5ad0f3b4c63852b6076f32f3a1b530b1ff8e23dc59df104b107b
    • Instruction ID: 3212676807d134663192748e4932cc12e23c13ee1f20f06a2da2454ca93e8db8
    • Opcode Fuzzy Hash: b98f8205f4dd5ad0f3b4c63852b6076f32f3a1b530b1ff8e23dc59df104b107b
    • Instruction Fuzzy Hash: 0AF068727282658ADB988F6DA802A2977D0F7483D0F409139E59DC7B44DE3C9051CF84
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 03ec394501486fefa8e68c4fc5f22486c81951ca79d36a27091b1f9b4683aa64
    • Instruction ID: cea1d52ac2b87c180d0ba0a964987b61d62d60ca01ce9355733c2726065e6461
    • Opcode Fuzzy Hash: 03ec394501486fefa8e68c4fc5f22486c81951ca79d36a27091b1f9b4683aa64
    • Instruction Fuzzy Hash: E0A0022392CC47E0EE459B05E85083023B0FB50320F400131E41DC90B09F3CA440D3D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: AddressProc
    • String ID: Failed to get address for PyDict_GetItemString$Failed to get address for PyErr_Clear$Failed to get address for PyErr_Fetch$Failed to get address for PyErr_NormalizeException$Failed to get address for PyErr_Occurred$Failed to get address for PyErr_Print$Failed to get address for PyErr_Restore$Failed to get address for PyEval_EvalCode$Failed to get address for PyImport_AddModule$Failed to get address for PyImport_ExecCodeModule$Failed to get address for PyImport_ImportModule$Failed to get address for PyList_Append$Failed to get address for PyList_New$Failed to get address for PyLong_AsLong$Failed to get address for PyMarshal_ReadObjectFromString$Failed to get address for PyMem_RawFree$Failed to get address for PyModule_GetDict$Failed to get address for PyObject_CallFunction$Failed to get address for PyObject_CallFunctionObjArgs$Failed to get address for PyObject_GetAttrString$Failed to get address for PyObject_SetAttrString$Failed to get address for PyObject_Str$Failed to get address for PyRun_SimpleStringFlags$Failed to get address for PySys_AddWarnOption$Failed to get address for PySys_GetObject$Failed to get address for PySys_SetArgvEx$Failed to get address for PySys_SetObject$Failed to get address for PySys_SetPath$Failed to get address for PyUnicode_AsUTF8$Failed to get address for PyUnicode_Decode$Failed to get address for PyUnicode_DecodeFSDefault$Failed to get address for PyUnicode_FromFormat$Failed to get address for PyUnicode_FromString$Failed to get address for PyUnicode_Join$Failed to get address for PyUnicode_Replace$Failed to get address for Py_BuildValue$Failed to get address for Py_DecRef$Failed to get address for Py_DecodeLocale$Failed to get address for Py_DontWriteBytecodeFlag$Failed to get address for Py_FileSystemDefaultEncoding$Failed to get address for Py_Finalize$Failed to get address for Py_FrozenFlag$Failed to get address for Py_GetPath$Failed to get address for Py_IgnoreEnvironmentFlag$Failed to get address for Py_IncRef$Failed to get address for Py_Initialize$Failed to get address for Py_NoSiteFlag$Failed to get address for Py_NoUserSiteDirectory$Failed to get address for Py_OptimizeFlag$Failed to get address for Py_SetPath$Failed to get address for Py_SetProgramName$Failed to get address for Py_SetPythonHome$Failed to get address for Py_UTF8Mode$Failed to get address for Py_UnbufferedStdioFlag$Failed to get address for Py_VerboseFlag$GetProcAddress$PyDict_GetItemString$PyErr_Clear$PyErr_Fetch$PyErr_NormalizeException$PyErr_Occurred$PyErr_Print$PyErr_Restore$PyEval_EvalCode$PyImport_AddModule$PyImport_ExecCodeModule$PyImport_ImportModule$PyList_Append$PyList_New$PyLong_AsLong$PyMarshal_ReadObjectFromString$PyMem_RawFree$PyModule_GetDict$PyObject_CallFunction$PyObject_CallFunctionObjArgs$PyObject_GetAttrString$PyObject_SetAttrString$PyObject_Str$PyRun_SimpleStringFlags$PySys_AddWarnOption$PySys_GetObject$PySys_SetArgvEx$PySys_SetObject$PySys_SetPath$PyUnicode_AsUTF8$PyUnicode_Decode$PyUnicode_DecodeFSDefault$PyUnicode_FromFormat$PyUnicode_FromString$PyUnicode_Join$PyUnicode_Replace$Py_BuildValue$Py_DecRef$Py_DecodeLocale$Py_DontWriteBytecodeFlag$Py_FileSystemDefaultEncoding$Py_Finalize$Py_FrozenFlag$Py_GetPath$Py_IgnoreEnvironmentFlag$Py_IncRef$Py_Initialize$Py_NoSiteFlag$Py_NoUserSiteDirectory$Py_OptimizeFlag$Py_SetPath$Py_SetProgramName$Py_SetPythonHome$Py_UTF8Mode$Py_UnbufferedStdioFlag$Py_VerboseFlag
    • API String ID: 190572456-3109299426
    • Opcode ID: 9a46f94a5db316c904c1dd688f1073b3c37aa512f8c778aadf3faf8dd6919ce6
    • Instruction ID: 7107e4921eb8a292c0050465d21eef89b735e4c169e3e8183924ca1e15d29716
    • Opcode Fuzzy Hash: 9a46f94a5db316c904c1dd688f1073b3c37aa512f8c778aadf3faf8dd6919ce6
    • Instruction Fuzzy Hash: 3542CE67A2DB07D1FE59CB0AA85097823E1AF047B4B845535E80ECE364FF7CB56892D0
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID:
    • String ID: Failed to extract %s: failed to allocate temporary buffer!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to open target file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$Failed to extract %s: failed to write data chunk!$fopen$fread$fseek$fwrite$malloc
    • API String ID: 0-666925554
    • Opcode ID: 37c913440f915224949b5f530199302c5c5691bc55ee7d51d886240c9f5de79b
    • Instruction ID: 9f1e11d1bbd3731aca20a3e9ada59d443734d003dbd108df80f9fae3b42c6bcf
    • Opcode Fuzzy Hash: 37c913440f915224949b5f530199302c5c5691bc55ee7d51d886240c9f5de79b
    • Instruction Fuzzy Hash: B8518163B2864281EE10EB22E414EB963A0AF55BF4F444531EE5DCF796EE3CE54583E0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Token$ConvertDescriptorInformationProcessSecurityString$CloseCreateCurrentDirectoryErrorFreeHandleLastLocalOpen
    • String ID: D:(A;;FA;;;%s)$S-1-3-4
    • API String ID: 4998090-2855260032
    • Opcode ID: 325d64cfb385d23493eb0389c0ea059c6d59262dbafda5a72abe8264351e6c2a
    • Instruction ID: 377c8cd43708b1f45d91e36a92d9b6aba6d73d9706d31b83ac9296006baf1b07
    • Opcode Fuzzy Hash: 325d64cfb385d23493eb0389c0ea059c6d59262dbafda5a72abe8264351e6c2a
    • Instruction Fuzzy Hash: CC413E3362C68382EA509F61E444AAA73A1FB847A5F440231EA6ECA6D5DF3CD448C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: MoveWindow$ObjectSelect$DrawReleaseText
    • String ID: P%
    • API String ID: 2147705588-2959514604
    • Opcode ID: 2abf96d7e756ec95747b6225775113f5ca3bbb9c1d9d148edce5ba3104c9dbe9
    • Instruction ID: bb0785aa15ecf59f3a4824dcaaa2810cd9d840267f02109ab78a6332e1c88c2d
    • Opcode Fuzzy Hash: 2abf96d7e756ec95747b6225775113f5ca3bbb9c1d9d148edce5ba3104c9dbe9
    • Instruction Fuzzy Hash: 8F511527618BA186DA349F22E4185BAB7A1FB98B61F004121EFDF83784DF3CD045DB50
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: f$f$p$p$f
    • API String ID: 3215553584-1325933183
    • Opcode ID: 864902cbb2e935f55fbb0b0f358a3d1305b233c90ffe52d12db1516ed6b7c985
    • Instruction ID: 390d8ec1319a1ef512cde00b24fd35eb3d53927ff9fbc7bd5bc75ee2997a567d
    • Opcode Fuzzy Hash: 864902cbb2e935f55fbb0b0f358a3d1305b233c90ffe52d12db1516ed6b7c985
    • Instruction Fuzzy Hash: AB1283A3F2C15386FB24DA35E054ABA77A1FB80768F844035D6998E6D4DF7CE4848BD0
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Message
    • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
    • API String ID: 2030045667-3659356012
    • Opcode ID: cde6a528f24137f5304f8cb319a168ab15695774dc73d278eb1ed96202088a3e
    • Instruction ID: b5cb2fad521e1b7572d1560dbae4c0d45b3d9f9856bb7667cc1605dd30278beb
    • Opcode Fuzzy Hash: cde6a528f24137f5304f8cb319a168ab15695774dc73d278eb1ed96202088a3e
    • Instruction Fuzzy Hash: FA417363B2864282EE24EB12E440ABA63A0FF547B4F544431DE5DCBB55EE7CE542C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Process_invalid_parameter_noinfo$ByteCharCodeCommandConsoleCreateCtrlExitHandlerInfoLineMultiObjectSingleStartupWaitWide
    • String ID: CreateProcessW$Error creating child process!
    • API String ID: 2895956056-3524285272
    • Opcode ID: abaaef525a4316cf0ad8ae1602483ebc482a8e395ee8b6b4db4649471e4f68f4
    • Instruction ID: 2ff9a31d62b4135d4e460788a3f2ded42d0bf52d898c426bbfb7c5994ebca33a
    • Opcode Fuzzy Hash: abaaef525a4316cf0ad8ae1602483ebc482a8e395ee8b6b4db4649471e4f68f4
    • Instruction Fuzzy Hash: 11413033A1878282DE20DB65E5556AAB3A4FB94374F400735E6AD8BBD5DF7CD0448BC0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
    • String ID: csm$csm$csm
    • API String ID: 849930591-393685449
    • Opcode ID: 64a04dea20eab758f09741b49381e36ae6aa3d4dbdf263ead872da10faeebcc4
    • Instruction ID: 944305cc4426b16efb3afad3f5d6541e6ca7e58e7240583d21baac7773e582d3
    • Opcode Fuzzy Hash: 64a04dea20eab758f09741b49381e36ae6aa3d4dbdf263ead872da10faeebcc4
    • Instruction Fuzzy Hash: 39E17D73A287418AEB209F659440AAD37A0FB447A8F100535EE8DDBB95CF3CE484C7E1
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Message
    • String ID: 1.2.13$Failed to extract %s: decompression resulted in return code %d!$Failed to extract %s: failed to allocate temporary input buffer!$Failed to extract %s: failed to allocate temporary output buffer!$Failed to extract %s: inflateInit() failed with return code %d!$malloc
    • API String ID: 2030045667-1655038675
    • Opcode ID: 16cfe9308c4c9ecd15c27d970c4b813c3cdd434660d0b5ae915340d975fce95f
    • Instruction ID: bd6d8db29e4dfeece9785501978afca1a0c4b070ac268d42028c22edb354dc8e
    • Opcode Fuzzy Hash: 16cfe9308c4c9ecd15c27d970c4b813c3cdd434660d0b5ae915340d975fce95f
    • Instruction Fuzzy Hash: 3551BF63A2968285EA60EB52E440BFA6390FB84BB4F444131EE4DCB795EF3CE545C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • FreeLibrary.KERNEL32(?,00000000,?,00007FF67F39E152,?,?,-00000018,00007FF67F39A223,?,?,?,00007FF67F39A11A,?,?,?,00007FF67F395472), ref: 00007FF67F39DF34
    • GetProcAddress.KERNEL32(?,00000000,?,00007FF67F39E152,?,?,-00000018,00007FF67F39A223,?,?,?,00007FF67F39A11A,?,?,?,00007FF67F395472), ref: 00007FF67F39DF40
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: AddressFreeLibraryProc
    • String ID: api-ms-$ext-ms-
    • API String ID: 3013587201-537541572
    • Opcode ID: 01869d8b0b1ae08ce046380e8c955ca032c286979885a37836ee5a28d8bde6d1
    • Instruction ID: 3176595ffd952db3f9116dffa27a57f2a9801132cd7bc93712240fa4d9f0cce6
    • Opcode Fuzzy Hash: 01869d8b0b1ae08ce046380e8c955ca032c286979885a37836ee5a28d8bde6d1
    • Instruction Fuzzy Hash: 0541EE73B3AA1281FA56CB169805D752392BF18BB4F094535DD5DCF788EE3CE80582C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF67F38101D), ref: 00007FF67F38769F
    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF67F38101D), ref: 00007FF67F3876EF
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ByteCharMultiWide
    • String ID: Failed to encode wchar_t as UTF-8.$Failed to get UTF-8 buffer size.$Out of memory.$WideCharToMultiByte$win32_utils_to_utf8
    • API String ID: 626452242-27947307
    • Opcode ID: 4abb123c1e290ab0bf431a9e29adde0d703b54356917db0efbe6b96a2176b62e
    • Instruction ID: 2206533c69a288767b6e6099aee1df80499cbc1e563471942133fd19b01cce66
    • Opcode Fuzzy Hash: 4abb123c1e290ab0bf431a9e29adde0d703b54356917db0efbe6b96a2176b62e
    • Instruction Fuzzy Hash: F0415D33A2CB8281EA20CF15A44097AA7A5FB847A5F584135EE8DCBB94DF3CD491C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • WideCharToMultiByte.KERNEL32(?,00007FF67F383699), ref: 00007FF67F387B81
      • Part of subcall function 00007FF67F382620: GetLastError.KERNEL32(00000000,00000000,00000000,00007FF67F387744,?,?,?,?,?,?,?,?,?,?,?,00007FF67F38101D), ref: 00007FF67F382654
      • Part of subcall function 00007FF67F382620: MessageBoxW.USER32 ref: 00007FF67F38272C
    • WideCharToMultiByte.KERNEL32(?,00007FF67F383699), ref: 00007FF67F387BF5
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ByteCharMultiWide$ErrorLastMessage
    • String ID: Failed to encode wchar_t as UTF-8.$Failed to get UTF-8 buffer size.$Out of memory.$WideCharToMultiByte$win32_utils_to_utf8
    • API String ID: 3723044601-27947307
    • Opcode ID: 31ebc9b81e4e3fd2a5d7efff630c0257bd489d4360170f7ed3ae77706e921571
    • Instruction ID: 55c2e880c788de2fff15b68d41f1a9f9d39629a94484a9b3c9d212375bf228bb
    • Opcode Fuzzy Hash: 31ebc9b81e4e3fd2a5d7efff630c0257bd489d4360170f7ed3ae77706e921571
    • Instruction Fuzzy Hash: 5C218032A28B4285EB10DF26E84087977A2EB94BE0F544535DA4DCB754EF7CE591C3D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: f$p$p
    • API String ID: 3215553584-1995029353
    • Opcode ID: 8b43f30c9b627f105c9440690760d813b6cbc2015482011a3dd154e3df4de9b0
    • Instruction ID: 07f394c39505fc019a87bad7b3485c3c4a9d953cec8b3dc1b5522c3203701a3b
    • Opcode Fuzzy Hash: 8b43f30c9b627f105c9440690760d813b6cbc2015482011a3dd154e3df4de9b0
    • Instruction Fuzzy Hash: 7F129163E2E14386FB24DB15E054AB97799EB80778F884035E6998E6C4DF3DE5808BD0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ByteCharMultiWide
    • String ID: Failed to decode wchar_t from UTF-8$Failed to get wchar_t buffer size.$MultiByteToWideChar$Out of memory.$win32_utils_from_utf8
    • API String ID: 626452242-876015163
    • Opcode ID: aaebe4b278efda81e931b0d8d3375374a2de1692e4ac414a8128f5c0242ab0be
    • Instruction ID: bd17ee32731d3bd783f4c599e9babf7bc75d3398b8b5027035e16f61225636e2
    • Opcode Fuzzy Hash: aaebe4b278efda81e931b0d8d3375374a2de1692e4ac414a8128f5c0242ab0be
    • Instruction Fuzzy Hash: 5E419433A2CA4282EA20DF25E440979A7A6FB447A1F144135EA4ECBBA4EF3CD455C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • LoadLibraryExW.KERNEL32(?,?,?,00007FF67F38D19A,?,?,?,00007FF67F38CE8C,?,?,00000001,00007FF67F38CAA9), ref: 00007FF67F38CF6D
    • GetLastError.KERNEL32(?,?,?,00007FF67F38D19A,?,?,?,00007FF67F38CE8C,?,?,00000001,00007FF67F38CAA9), ref: 00007FF67F38CF7B
    • LoadLibraryExW.KERNEL32(?,?,?,00007FF67F38D19A,?,?,?,00007FF67F38CE8C,?,?,00000001,00007FF67F38CAA9), ref: 00007FF67F38CFA5
    • FreeLibrary.KERNEL32(?,?,?,00007FF67F38D19A,?,?,?,00007FF67F38CE8C,?,?,00000001,00007FF67F38CAA9), ref: 00007FF67F38CFEB
    • GetProcAddress.KERNEL32(?,?,?,00007FF67F38D19A,?,?,?,00007FF67F38CE8C,?,?,00000001,00007FF67F38CAA9), ref: 00007FF67F38CFF7
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Library$Load$AddressErrorFreeLastProc
    • String ID: api-ms-
    • API String ID: 2559590344-2084034818
    • Opcode ID: 46f8882ba5516ded8d0f67aa9085a497a0d646e74245b223b6bb25c85e55adca
    • Instruction ID: 5f8d229787299c6fe9b657a7707c8b41ef8fc5c71c8cb1dd989bd0d222007556
    • Opcode Fuzzy Hash: 46f8882ba5516ded8d0f67aa9085a497a0d646e74245b223b6bb25c85e55adca
    • Instruction Fuzzy Hash: 89319E63A2AB4291FE529B02A40097563D4FF48BB0F594535ED1DCE380EF3CE44587E0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF67F387A30: MultiByteToWideChar.KERNEL32 ref: 00007FF67F387A6A
    • ExpandEnvironmentStringsW.KERNEL32(00000000,00007FF67F3867CF,?,00000000,?,TokenIntegrityLevel), ref: 00007FF67F3864DF
      • Part of subcall function 00007FF67F382770: MessageBoxW.USER32 ref: 00007FF67F382841
    Strings
    • LOADER: Failed to convert runtime-tmpdir to a wide string., xrefs: 00007FF67F3864B6
    • LOADER: Failed to expand environment variables in the runtime-tmpdir., xrefs: 00007FF67F3864F3
    • LOADER: Failed to obtain the absolute path of the runtime-tmpdir., xrefs: 00007FF67F38653A
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ByteCharEnvironmentExpandMessageMultiStringsWide
    • String ID: LOADER: Failed to convert runtime-tmpdir to a wide string.$LOADER: Failed to expand environment variables in the runtime-tmpdir.$LOADER: Failed to obtain the absolute path of the runtime-tmpdir.
    • API String ID: 1662231829-3498232454
    • Opcode ID: 2dc19ef5ba30c1755b370eb24f27a07330b7d4ecbeaa7c6206d14ea3a4c7ebc1
    • Instruction ID: bc2af25063f0b3a82f772dd51b8f292091555e0c362ec60eb759d938f0014b52
    • Opcode Fuzzy Hash: 2dc19ef5ba30c1755b370eb24f27a07330b7d4ecbeaa7c6206d14ea3a4c7ebc1
    • Instruction Fuzzy Hash: 52317813B3C78281FE64D721E555BBA5391AF987E0F844432DA4ECE7DAEE2CE50486D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • MultiByteToWideChar.KERNEL32 ref: 00007FF67F387A6A
      • Part of subcall function 00007FF67F382620: GetLastError.KERNEL32(00000000,00000000,00000000,00007FF67F387744,?,?,?,?,?,?,?,?,?,?,?,00007FF67F38101D), ref: 00007FF67F382654
      • Part of subcall function 00007FF67F382620: MessageBoxW.USER32 ref: 00007FF67F38272C
    • MultiByteToWideChar.KERNEL32 ref: 00007FF67F387AF0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ByteCharMultiWide$ErrorLastMessage
    • String ID: Failed to decode wchar_t from UTF-8$Failed to get wchar_t buffer size.$MultiByteToWideChar$Out of memory.$win32_utils_from_utf8
    • API String ID: 3723044601-876015163
    • Opcode ID: f722377c5addd92d766e9fa13234db446ce1d84bd25aa6405d278129d592b402
    • Instruction ID: 114983d58b149500e5a08581728195266bd4360c9d3ca270511733cd6a8425c5
    • Opcode Fuzzy Hash: f722377c5addd92d766e9fa13234db446ce1d84bd25aa6405d278129d592b402
    • Instruction Fuzzy Hash: D2217623B28A4281EF50CB26F400569A7A1FF847E4F584531EB5CDBB69EF6CD54187C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetLastError.KERNEL32(?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F,?,?,?,00007FF67F399313), ref: 00007FF67F39A62F
    • FlsGetValue.KERNEL32(?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F,?,?,?,00007FF67F399313), ref: 00007FF67F39A644
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F,?,?,?,00007FF67F399313), ref: 00007FF67F39A665
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F,?,?,?,00007FF67F399313), ref: 00007FF67F39A692
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F,?,?,?,00007FF67F399313), ref: 00007FF67F39A6A3
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F,?,?,?,00007FF67F399313), ref: 00007FF67F39A6B4
    • SetLastError.KERNEL32(?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F,?,?,?,00007FF67F399313), ref: 00007FF67F39A6CF
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Value$ErrorLast
    • String ID:
    • API String ID: 2506987500-0
    • Opcode ID: 8ff2e8f234801333ca104f51e052509623115d46483bc0ab35df31335539f603
    • Instruction ID: ed5b7c1211305a894845e258278dab8cbeb816533830bfa69bffd51cca45292f
    • Opcode Fuzzy Hash: 8ff2e8f234801333ca104f51e052509623115d46483bc0ab35df31335539f603
    • Instruction Fuzzy Hash: AB215E23E2D60381FE68E721965593A63925F45BB8F140734E97E8F7D6DE2CB44082D1
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
    • String ID: CONOUT$
    • API String ID: 3230265001-3130406586
    • Opcode ID: 1a41989b306c04176fbb8ce5d038fb17b2eb18ca34d01c5ff4cda60dd112554e
    • Instruction ID: 022f2fe3d7b54f8d96725ad8a37cfa7240d0d32d145b80978eaf77d5c2830d7c
    • Opcode Fuzzy Hash: 1a41989b306c04176fbb8ce5d038fb17b2eb18ca34d01c5ff4cda60dd112554e
    • Instruction Fuzzy Hash: 56117C23A28A4186EB908B56A854B2967E0FB88BF4F040234EA6DCB794CF3CD41487C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetLastError.KERNEL32(?,?,?,00007FF67F39444D,?,?,?,?,00007FF67F39DDA7,?,?,00000000,00007FF67F39A8B6,?,?,?), ref: 00007FF67F39A7A7
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F39444D,?,?,?,?,00007FF67F39DDA7,?,?,00000000,00007FF67F39A8B6,?,?,?), ref: 00007FF67F39A7DD
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F39444D,?,?,?,?,00007FF67F39DDA7,?,?,00000000,00007FF67F39A8B6,?,?,?), ref: 00007FF67F39A80A
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F39444D,?,?,?,?,00007FF67F39DDA7,?,?,00000000,00007FF67F39A8B6,?,?,?), ref: 00007FF67F39A81B
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F39444D,?,?,?,?,00007FF67F39DDA7,?,?,00000000,00007FF67F39A8B6,?,?,?), ref: 00007FF67F39A82C
    • SetLastError.KERNEL32(?,?,?,00007FF67F39444D,?,?,?,?,00007FF67F39DDA7,?,?,00000000,00007FF67F39A8B6,?,?,?), ref: 00007FF67F39A847
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Value$ErrorLast
    • String ID:
    • API String ID: 2506987500-0
    • Opcode ID: 56467da9cbf0f7ea7726befb455c23c7da3468b21c05826552355134373c4563
    • Instruction ID: e708b46d6e96a653b2b5dac9de8781791cdb57a47acb87992431848db4360143
    • Opcode Fuzzy Hash: 56467da9cbf0f7ea7726befb455c23c7da3468b21c05826552355134373c4563
    • Instruction Fuzzy Hash: 26118123E2C64382FD58DB21965283E63915F447B8F144734D87E8F7D6DE2CA44283D1
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
    • String ID: csm$f
    • API String ID: 2395640692-629598281
    • Opcode ID: 42fbbb83cedbe148bfcc1de87ea3e914151e174f0a46670c6939306692d2d31c
    • Instruction ID: 37a8418e9d6543c7477c3683033748b91d384d75d8c20c8ce98eae6f5b6a8d19
    • Opcode Fuzzy Hash: 42fbbb83cedbe148bfcc1de87ea3e914151e174f0a46670c6939306692d2d31c
    • Instruction Fuzzy Hash: A4517C33A297428AEB14CB25E444E6937A5FB45BE8F518131DA4ECB788DF3CE94187D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: DeleteDestroyDialogHandleIconIndirectModuleObjectParam
    • String ID: Unhandled exception in script
    • API String ID: 3081866767-2699770090
    • Opcode ID: fcf731bf2ceca6e070dbdbaa780c49a73cf052ed135755c936a54f607c2ce467
    • Instruction ID: 904125e92c1e3eec90a94d9e5176c701625f90d05a1a1e790e1da057eb695bc5
    • Opcode Fuzzy Hash: fcf731bf2ceca6e070dbdbaa780c49a73cf052ed135755c936a54f607c2ce467
    • Instruction Fuzzy Hash: 41312F33A29A8289EB24DF61E8559E963A0FF887A4F440135EA4ECFB55DF3CD145C780
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: AddressFreeHandleLibraryModuleProc
    • String ID: CorExitProcess$mscoree.dll
    • API String ID: 4061214504-1276376045
    • Opcode ID: 611779d08fafb8db9f6fab045cd04065641a8af0ffd245d6ff06f44facfa83ea
    • Instruction ID: 9af269ec05fcbc40f90a4d463343ca1c8ae6472cde39b1d071ab06f08866b5fb
    • Opcode Fuzzy Hash: 611779d08fafb8db9f6fab045cd04065641a8af0ffd245d6ff06f44facfa83ea
    • Instruction Fuzzy Hash: F5F06263A29A02C1EF109B25E455B396361FF857B5F940636D56D8D6F4CF2CD049C3C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _set_statfp
    • String ID:
    • API String ID: 1156100317-0
    • Opcode ID: 69d38c35bd33e64192705e47d806ebaffe6519085bb8d16871af39b095092657
    • Instruction ID: be7d56e26af7aff0b6fe4a8abaae5346b77507ef7e767b6c9a6346ba98d96503
    • Opcode Fuzzy Hash: 69d38c35bd33e64192705e47d806ebaffe6519085bb8d16871af39b095092657
    • Instruction Fuzzy Hash: 6B118F73E78A0711FE982226E445B791AC5BF583B4F140674F97E8E6DADE2CAC4142C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • FlsGetValue.KERNEL32(?,?,?,00007FF67F399A73,?,?,00000000,00007FF67F399D0E,?,?,?,?,?,00007FF67F3921EC), ref: 00007FF67F39A87F
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F399A73,?,?,00000000,00007FF67F399D0E,?,?,?,?,?,00007FF67F3921EC), ref: 00007FF67F39A89E
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F399A73,?,?,00000000,00007FF67F399D0E,?,?,?,?,?,00007FF67F3921EC), ref: 00007FF67F39A8C6
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F399A73,?,?,00000000,00007FF67F399D0E,?,?,?,?,?,00007FF67F3921EC), ref: 00007FF67F39A8D7
    • FlsSetValue.KERNEL32(?,?,?,00007FF67F399A73,?,?,00000000,00007FF67F399D0E,?,?,?,?,?,00007FF67F3921EC), ref: 00007FF67F39A8E8
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Value
    • String ID:
    • API String ID: 3702945584-0
    • Opcode ID: 52e75b61ebb49defa444412e8fee66804bfa3f6c547067b9182500d2680da77e
    • Instruction ID: f4e534e7cb6cf268df38290683fc56c2ff0afc1d9e8b8b4e15054a1f860b645f
    • Opcode Fuzzy Hash: 52e75b61ebb49defa444412e8fee66804bfa3f6c547067b9182500d2680da77e
    • Instruction Fuzzy Hash: 7E11AC22F2C60781FE58D722995197A63416F817B8F044734E8BECE7C6DE2CA84282D1
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • FlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F), ref: 00007FF67F39A705
    • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F), ref: 00007FF67F39A724
    • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F), ref: 00007FF67F39A74C
    • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F), ref: 00007FF67F39A75D
    • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF67F3A2433,?,?,?,00007FF67F39CB8C,?,?,00000000,00007FF67F393A5F), ref: 00007FF67F39A76E
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Value
    • String ID:
    • API String ID: 3702945584-0
    • Opcode ID: 8a1bb1fb30c776521f71cd7f268cc6825f5a57dec437cff5255c4fa0cbf0b49a
    • Instruction ID: 612cdf199785dd4583b6f4d78725a4948b3d43b442a51574aa7cdc991841d20d
    • Opcode Fuzzy Hash: 8a1bb1fb30c776521f71cd7f268cc6825f5a57dec437cff5255c4fa0cbf0b49a
    • Instruction Fuzzy Hash: 4C11F726E2D20741FDA8EA758862D7E13924F85778F181B34D87ECE2D2DD3CB84142E2
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: UTF-16LEUNICODE$UTF-8$ccs
    • API String ID: 3215553584-1196891531
    • Opcode ID: e657aeb740c2ac826b77e83addb2cc82262a2e6e3b5be7210a8d66ad85871f1f
    • Instruction ID: 21483029892d568cf676d2eaf879f8d427df3cafda3d4cb2e952854e0642425f
    • Opcode Fuzzy Hash: e657aeb740c2ac826b77e83addb2cc82262a2e6e3b5be7210a8d66ad85871f1f
    • Instruction Fuzzy Hash: 2181A137E2C20285F7A5DE358191A7827A0AB11BACF558039CA6DDF685DF2DE90193C1
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: CallEncodePointerTranslator
    • String ID: MOC$RCC
    • API String ID: 3544855599-2084237596
    • Opcode ID: e66b2a899b3be21a272ca3efbe1e1fab7eec351de36f73ff2a6cc06a45c4f2b1
    • Instruction ID: fc55266deb9cdf911a2e1e0512de49980683dff24bcc24fc1fc5d41ff40344da
    • Opcode Fuzzy Hash: e66b2a899b3be21a272ca3efbe1e1fab7eec351de36f73ff2a6cc06a45c4f2b1
    • Instruction Fuzzy Hash: 9E618C33A18B458AE7109FA5D4807AD7BA0FB44B98F144225EE4D9BB98CF7CE085C791
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
    • String ID: csm$csm
    • API String ID: 3896166516-3733052814
    • Opcode ID: 37bca86698e542f9df3f1c5971c843800452ce466371b2576d682bdca002ed1e
    • Instruction ID: fbd91111d9f4f497fd8e2a0efbeb44deae86df2cde8d3c47f3f5a2e21bb6d415
    • Opcode Fuzzy Hash: 37bca86698e542f9df3f1c5971c843800452ce466371b2576d682bdca002ed1e
    • Instruction Fuzzy Hash: 3C51B33392824286EB748F519544B6977A0FB54BA8F144235EA9CCBBD5CF3CE490CBD2
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Message$ByteCharMultiWide
    • String ID: %s%s: %s$Fatal error detected
    • API String ID: 1878133881-2410924014
    • Opcode ID: 1ad8658de8dbd2e7b08889bff9c9537d6e44ae678795f4b96bc9f189f6c45e5f
    • Instruction ID: e9dd1259a6df2fa8da7b89108c0cae073410a2dbca79f5b5c86817d84e0ed75b
    • Opcode Fuzzy Hash: 1ad8658de8dbd2e7b08889bff9c9537d6e44ae678795f4b96bc9f189f6c45e5f
    • Instruction Fuzzy Hash: AD313273638A8191EA20EB51E451BEA63A5FB84794F404036EA8D8B699DF3CD345CBD0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetModuleFileNameW.KERNEL32(?,00007FF67F383699), ref: 00007FF67F383BD1
      • Part of subcall function 00007FF67F382620: GetLastError.KERNEL32(00000000,00000000,00000000,00007FF67F387744,?,?,?,?,?,?,?,?,?,?,?,00007FF67F38101D), ref: 00007FF67F382654
      • Part of subcall function 00007FF67F382620: MessageBoxW.USER32 ref: 00007FF67F38272C
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ErrorFileLastMessageModuleName
    • String ID: Failed to convert executable path to UTF-8.$Failed to get executable path.$GetModuleFileNameW
    • API String ID: 2581892565-1977442011
    • Opcode ID: d351f04d36ba2f15026850856bdbd3af76e02992a2015f4e41e7df4c5f482f4b
    • Instruction ID: 28fb4f94d2a3d6b5780a4f9207a0b5fb90ed2dcd47034d4644b2a796dc718eea
    • Opcode Fuzzy Hash: d351f04d36ba2f15026850856bdbd3af76e02992a2015f4e41e7df4c5f482f4b
    • Instruction Fuzzy Hash: 4B018423B3C64291FE61AB21E815BB92391AF483A4F400431E85ECF792EE5CE14597E0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: FileWrite$ConsoleErrorLastOutput
    • String ID:
    • API String ID: 2718003287-0
    • Opcode ID: f750311aff661a04a86bbbada4284786bf27b8065a17484a8f486471230e888d
    • Instruction ID: bdc25c1dd711cba22e241f07498cecd26045612a18d53894b456cd93c28b09ba
    • Opcode Fuzzy Hash: f750311aff661a04a86bbbada4284786bf27b8065a17484a8f486471230e888d
    • Instruction Fuzzy Hash: CAD1E173B29A8189E711CF79D4406AC37A5FB447A8B004235CE5E9BB99DE38D516C7C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,?,00000000,00000000,00007FF67F39C41B), ref: 00007FF67F39C54C
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,?,00000000,00000000,00007FF67F39C41B), ref: 00007FF67F39C5D7
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ConsoleErrorLastMode
    • String ID:
    • API String ID: 953036326-0
    • Opcode ID: f410d9e07cb2d854853af875ff306a0e9c9ee922f70c4cde11a48ef332fbc2ec
    • Instruction ID: 6d48ad3388c92e1a3bde8b0e9282f5ec27cba98d24a29582eee2c21dded7d9c3
    • Opcode Fuzzy Hash: f410d9e07cb2d854853af875ff306a0e9c9ee922f70c4cde11a48ef332fbc2ec
    • Instruction Fuzzy Hash: 0191A263B2865285F751CF669440ABD2BA0BB44BECF585139DE0E9BA84DF38D442CBC0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _get_daylight$_isindst
    • String ID:
    • API String ID: 4170891091-0
    • Opcode ID: d5d13d1c94d14ccfec0c44e7243bbda22246c77cf8c41a11f0b86d98f8b3a05c
    • Instruction ID: 530f32edb8fb74ebb2f6e110045e02d4c904a3eeca92936b9f6bbedd852b1270
    • Opcode Fuzzy Hash: d5d13d1c94d14ccfec0c44e7243bbda22246c77cf8c41a11f0b86d98f8b3a05c
    • Instruction Fuzzy Hash: D751F773F286118AFB14DB68D951ABC27A1BB0037CF144235ED1E9AAE5DF3CA44287C1
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: File$ErrorHandleInformationLastNamedPeekPipeType
    • String ID:
    • API String ID: 2780335769-0
    • Opcode ID: 1c70a69b05d9cb3f6248f84cd75ebf1bef0caf7e7cf88daad42b4853df974b62
    • Instruction ID: f0251765bb1b878284a53d88cca2ed85555273ffd726f1bb7d1205641719bfed
    • Opcode Fuzzy Hash: 1c70a69b05d9cb3f6248f84cd75ebf1bef0caf7e7cf88daad42b4853df974b62
    • Instruction Fuzzy Hash: 7B515923E2C6428AFB10DFA5D4507BD33A1AB48BA8F208535DE4D9B689DF38D49187C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
    • String ID:
    • API String ID: 1279662727-0
    • Opcode ID: 8a464286a4aee93ad09e46d96520f5fa22b2a313ca22bba1db5411dbdbef7e96
    • Instruction ID: 3cc0d6fa34700b376ae5b75110f3d81e230c56b2b91506475adab3b4e4b44fe0
    • Opcode Fuzzy Hash: 8a464286a4aee93ad09e46d96520f5fa22b2a313ca22bba1db5411dbdbef7e96
    • Instruction Fuzzy Hash: 43416D63D2C78283F754DB21D51076963A0FB95778F109334EAA84BAD6DF7CA5A087C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: LongWindow$DialogInvalidateRect
    • String ID:
    • API String ID: 1956198572-0
    • Opcode ID: 162ef6909b0da24e61350fefbcaa0130b5f771c4d53ef42d88aea1c24daf7f6c
    • Instruction ID: e51fd9f2d8e12b975ece3ca2d8567f73788975e7d50c6699baeb1dcbd329391d
    • Opcode Fuzzy Hash: 162ef6909b0da24e61350fefbcaa0130b5f771c4d53ef42d88aea1c24daf7f6c
    • Instruction Fuzzy Hash: 3911E923E3854282FE509B6AE544AB913D2EF89BB0F548130E949CEBCDCE2CD4C582D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: _get_daylight$_invalid_parameter_noinfo
    • String ID: ?
    • API String ID: 1286766494-1684325040
    • Opcode ID: 8b5d587ec6f6b7eed71ba39116b338de031c50ce5c8dd23bba2b14458f06a6e4
    • Instruction ID: 961b28df979eff43b3ad637893d33db0a0eade58e021e69a58c7e2d9ccf64ad8
    • Opcode Fuzzy Hash: 8b5d587ec6f6b7eed71ba39116b338de031c50ce5c8dd23bba2b14458f06a6e4
    • Instruction Fuzzy Hash: 0041E823A2C28245FF649B26D401B7A67D4EB807B4F144235FE5C8ABE6DE3CD45187C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _invalid_parameter_noinfo.LIBCMT ref: 00007FF67F397E9E
      • Part of subcall function 00007FF67F399E18: HeapFree.KERNEL32(?,?,?,00007FF67F3A1E42,?,?,?,00007FF67F3A1E7F,?,?,00000000,00007FF67F3A2345,?,?,?,00007FF67F3A2277), ref: 00007FF67F399E2E
      • Part of subcall function 00007FF67F399E18: GetLastError.KERNEL32(?,?,?,00007FF67F3A1E42,?,?,?,00007FF67F3A1E7F,?,?,00000000,00007FF67F3A2345,?,?,?,00007FF67F3A2277), ref: 00007FF67F399E38
    • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF67F38B105), ref: 00007FF67F397EBC
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ErrorFileFreeHeapLastModuleName_invalid_parameter_noinfo
    • String ID: C:\Users\user\Desktop\Clangen.exe
    • API String ID: 3580290477-787618453
    • Opcode ID: 7be78eb059dea3495cc358456d23a898a8a026444ba3d0a56d0d7994263981b4
    • Instruction ID: 287ec8434586aee0e45eeaf5b58c58376544c46985ead2f1ddc6523ef9763e47
    • Opcode Fuzzy Hash: 7be78eb059dea3495cc358456d23a898a8a026444ba3d0a56d0d7994263981b4
    • Instruction Fuzzy Hash: 3E414F33A28B5285EB15DF26D4808BD67A4EB44BE8B545035E94E9BB85DF3CE891C3C0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ErrorFileLastWrite
    • String ID: U
    • API String ID: 442123175-4171548499
    • Opcode ID: 4134df34369bde334de186fcdf44a7df93ab1702ff4cc21259579c47d67cfea1
    • Instruction ID: 3666c190833d4d32c1dd651c194c11182aabc497b94ebe2e326a2a3aa1be034f
    • Opcode Fuzzy Hash: 4134df34369bde334de186fcdf44a7df93ab1702ff4cc21259579c47d67cfea1
    • Instruction Fuzzy Hash: 70418123628A8296DB60CF65E4447A977A1FB887E4F804031EA8DCB798DF3CD445CBC0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: CurrentDirectory
    • String ID: :
    • API String ID: 1611563598-336475711
    • Opcode ID: 8d0047e3d49e2942e9dd2ecd46bdb5543a301835a32119f1e21a6d0f1ab18d67
    • Instruction ID: 2f318bc34deccafd706b9019ca1cc220d7d85e60599c10fac3f9d121b22140eb
    • Opcode Fuzzy Hash: 8d0047e3d49e2942e9dd2ecd46bdb5543a301835a32119f1e21a6d0f1ab18d67
    • Instruction Fuzzy Hash: 3521E463A2C68281FB20CB15D06467E73F1FB88B98F454135D68D8B284DF7CE98987E1
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Message$ByteCharMultiWide
    • String ID: Error detected
    • API String ID: 1878133881-3513342764
    • Opcode ID: 412921116a21d042ea7cc01f3b6226aa372ad23cfa1aaecee88db1efd33321aa
    • Instruction ID: a4a3eb88231b58a7b6dac034337612179d480d20e0b11e5d030e77ca0ec332cb
    • Opcode Fuzzy Hash: 412921116a21d042ea7cc01f3b6226aa372ad23cfa1aaecee88db1efd33321aa
    • Instruction Fuzzy Hash: 1C21747363CA8291EB209B51F461BEA6354FB84798F804135EA9DCB695DF3CD205C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: Message$ByteCharMultiWide
    • String ID: Fatal error detected
    • API String ID: 1878133881-4025702859
    • Opcode ID: f7448773671dbda672e22a82cfe80c2e0aa70ed18289780b2b9e604a2b102c49
    • Instruction ID: 4266ca5ed2de11c5fb2713a49b84abf72ffdc08631d1b4d139d3c9a16479635a
    • Opcode Fuzzy Hash: f7448773671dbda672e22a82cfe80c2e0aa70ed18289780b2b9e604a2b102c49
    • Instruction Fuzzy Hash: 91215173638A8191EA209B51F451BEA6354FB84798F804135EA8D8B695DF3CD245C7D0
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: ExceptionFileHeaderRaise
    • String ID: csm
    • API String ID: 2573137834-1018135373
    • Opcode ID: a9ac3328ea6075577af066dd04772514ea360050604432a87b0551bd96b2ca6b
    • Instruction ID: 5eb3e8efb19593e5c50115812f9979b832c0158b2e1761b0d0e68217a80a628a
    • Opcode Fuzzy Hash: a9ac3328ea6075577af066dd04772514ea360050604432a87b0551bd96b2ca6b
    • Instruction Fuzzy Hash: B4112B33618B8182EB618F25E44066977A4FB88BA4F184230EE9C4B768DF3DD5918780
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1727149537.00007FF67F381000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF67F380000, based on PE: true
    • Associated: 00000000.00000002.1727135874.00007FF67F380000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727172923.00007FF67F3AA000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3BD000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727192333.00007FF67F3CC000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1727235732.00007FF67F3CE000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff67f380000_Clangen.jbxd
    Similarity
    • API ID: DriveType_invalid_parameter_noinfo
    • String ID: :
    • API String ID: 2595371189-336475711
    • Opcode ID: f8eec6a66f3a594e824ddea09938586a7cad5545a492e04bdbecb8d953b03adc
    • Instruction ID: b844bc404dd9a119956fc36028b7a2984983dad746949c12cb84bb3bf0ed5b25
    • Opcode Fuzzy Hash: f8eec6a66f3a594e824ddea09938586a7cad5545a492e04bdbecb8d953b03adc
    • Instruction Fuzzy Hash: DB018F63A3C60286FB31EF60A461A7E23A4EF4472CF441035E55DCA795EE3CE544DAD4
    Uniqueness

    Uniqueness Score: -1.00%