Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe

Overview

General Information

Sample name:SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
Analysis ID:1431434
MD5:ffb4c4458546447f3bee304de21cd2eb
SHA1:002c2f32ee46dacb422e75f687d8f74690184d31
SHA256:2e823662bd36d30faea424591d4bf1557224007d9ee859917bb769a45cd4c0c6
Tags:exe
Infos:

Detection

Score:24
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Creates files in alternative data streams (ADS)
AV process strings found (often used to terminate AV products)
Creates files inside the system directory
Detected potential crypto function
Found potential string decryption / allocating functions
PE / OLE file has an invalid certificate
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\UninstallJump to behavior
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://aia.startssl.com/certs/sub.class2.code.ca.crt0#
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://blog.aloaha.com
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://crl.startssl.com/crtc2-crl.crl0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://crl.startssl.com/sfsca.crl0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://ocsp.startssl.com/sub/class2/code/ca0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://ocsp.thawte.com0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://www.aloaha.com/shop-en/aloaha-smart-login.php
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://www.aloaha.com/shop-en/aloaha-smart-login.php$Leaving
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2470982431.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2214764796.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1992240817.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2407966143.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1896431358.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1928775661.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2181469819.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2342547839.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2247901875.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2311192642.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2118500796.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1928655788.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1960719350.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2533960764.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2279753063.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2023977033.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2087013980.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2023817636.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000002.2637451643.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2565522617.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2439512762.00000000007B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.aloaha.com/shop-en/aloaha-smart-login.phpslator.dll945.exe:2172
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://www.aloaha.com/wi-software-en/uprade-your-aloaha-pdf-suite.php
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://www.startssl.com/0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://www.startssl.com/intermediate.pdf0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://www.startssl.com/policy.pdf0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://www.startssl.com/policy.pdf04
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://www.startssl.com/sfsca.crl0
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeString found in binary or memory: http://www.startssl.com/sfsca.crt0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeFile created: C:\Windows\FalseUserPass.iniJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeCode function: 0_2_004BDCB00_2_004BDCB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeCode function: 0_2_004AC9C00_2_004AC9C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeCode function: 0_2_004B4E600_2_004B4E60
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeCode function: 0_2_004C50700_2_004C5070
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeCode function: 0_2_004E33700_2_004E3370
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeCode function: 0_2_004E8F900_2_004E8F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeCode function: String function: 00523470 appears 33 times
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeStatic PE information: invalid certificate
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000000.1377279706.0000000000550000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamecredentialprovider.exe vs SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeBinary or memory string: OriginalFilenamecredentialprovider.exe vs SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engineClassification label: sus24.evad.winEXE@1/4@0/0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeFile created: C:\Users\user\Desktop\FalseUserPass.ini:SmartLogin.txtJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeMutant created: NULL
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeFile created: C:\Users\user~1\AppData\Local\Temp\~DF7FC1D6B129264C8B.TMPJump to behavior
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeFile read: C:\Windows\FalseUserPass.iniJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: msvbvm60.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: vb6zz.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: sxs.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: scrrun.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: winscard.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: devobj.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: winsta.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeFile written: C:\Windows\FalseUserPass.iniJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\UninstallJump to behavior
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeStatic file information: File size 1772168 > 1048576
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x14c000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeCode function: 0_2_004085C4 push es; ret 0_2_004085C5
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeCode function: 0_2_00404206 push eax; iretd 0_2_00404231

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeFile created: C:\Users\user\Desktop\FalseUserPass.ini:SmartLogin.txtJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exeBinary or memory string: Shell_TrayWnd
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmpBinary or memory string: ClamTray.exe
Source: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmpBinary or memory string: ClamWin.exe
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Windows Service
1
Windows Service
11
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Process Injection
1
Process Injection
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
Security Account Manager2
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
NTFS File Attributes
NTDS1
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts2
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ocsp.thawte.com00%URL Reputationsafe
http://www.startssl.com/sfsca.crt00%Avira URL Cloudsafe
http://aia.startssl.com/certs/sub.class2.code.ca.crt0#0%Avira URL Cloudsafe
http://www.startssl.com/sfsca.crl00%Avira URL Cloudsafe
http://www.startssl.com/policy.pdf040%Avira URL Cloudsafe
http://ocsp.startssl.com/sub/class2/code/ca00%Avira URL Cloudsafe
http://crl.startssl.com/sfsca.crl00%Avira URL Cloudsafe
http://blog.aloaha.com0%Avira URL Cloudsafe
http://www.startssl.com/policy.pdf00%Avira URL Cloudsafe
http://www.startssl.com/intermediate.pdf00%Avira URL Cloudsafe
http://www.aloaha.com/shop-en/aloaha-smart-login.php0%Avira URL Cloudsafe
http://www.aloaha.com/shop-en/aloaha-smart-login.php$Leaving0%Avira URL Cloudsafe
http://www.startssl.com/00%Avira URL Cloudsafe
http://crl.startssl.com/crtc2-crl.crl00%Avira URL Cloudsafe
http://www.aloaha.com/wi-software-en/uprade-your-aloaha-pdf-suite.php0%Avira URL Cloudsafe
http://www.aloaha.com/shop-en/aloaha-smart-login.phpslator.dll945.exe:21720%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.startssl.com/sfsca.crt0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
  • Avira URL Cloud: safe
unknown
http://ocsp.startssl.com/sub/class2/code/ca0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
  • Avira URL Cloud: safe
unknown
http://aia.startssl.com/certs/sub.class2.code.ca.crt0#SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
  • Avira URL Cloud: safe
unknown
http://crl.thawte.com/ThawteTimestampingCA.crl0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    high
    http://www.startssl.com/sfsca.crl0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://www.startssl.com/policy.pdf04SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://blog.aloaha.comSecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://ocsp.thawte.com0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • URL Reputation: safe
    unknown
    http://crl.startssl.com/sfsca.crl0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://www.startssl.com/policy.pdf0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://www.startssl.com/intermediate.pdf0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://www.aloaha.com/shop-en/aloaha-smart-login.phpSecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://www.aloaha.com/shop-en/aloaha-smart-login.php$LeavingSecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://www.startssl.com/0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://crl.startssl.com/crtc2-crl.crl0SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://www.aloaha.com/wi-software-en/uprade-your-aloaha-pdf-suite.phpSecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exefalse
    • Avira URL Cloud: safe
    unknown
    http://www.aloaha.com/shop-en/aloaha-smart-login.phpslator.dll945.exe:2172SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2470982431.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2214764796.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1992240817.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2407966143.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1896431358.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1928775661.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2181469819.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2342547839.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2247901875.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2311192642.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2118500796.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1928655788.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.1960719350.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2533960764.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2279753063.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2023977033.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2087013980.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2023817636.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000002.2637451643.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2565522617.00000000007B1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe, 00000000.00000003.2439512762.00000000007B1000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    No contacted IP infos
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1431434
    Start date and time:2024-04-25 05:24:22 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 5m 14s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:9
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
    Detection:SUS
    Classification:sus24.evad.winEXE@1/4@0/0
    EGA Information:
    • Successful, ratio: 100%
    HCA Information:
    • Successful, ratio: 59%
    • Number of executed functions: 53
    • Number of non-executed functions: 19
    Cookbook Comments:
    • Found application associated with file extension: .exe
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
    • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
    • Not all processes where analyzed, report is missing behavior information
    • Report size exceeded maximum capacity and may have missing disassembly code.
    • Report size getting too big, too many NtOpenFile calls found.
    • Report size getting too big, too many NtOpenKeyEx calls found.
    • Report size getting too big, too many NtQueryValueKey calls found.
    TimeTypeDescription
    05:26:21API Interceptor1x Sleep call for process: SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe modified
    No context
    No context
    No context
    No context
    No context
    Process:C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
    File Type:Composite Document File V2 Document, Cannot read section info
    Category:dropped
    Size (bytes):409600
    Entropy (8bit):5.702032552150412
    Encrypted:false
    SSDEEP:3072:/RZEfPnavcu54Qj2C7eWifYJ1EIZ8qMBwYcsYFRT:HEfSPpeWEU1EIZ8ZwYcsYFRT
    MD5:5CB901EE88427DCDEF0BA031088CD891
    SHA1:7991EDA7E07B0C2F17E51C61025D27476B0C3AB4
    SHA-256:9E708CFCDF9457F34E4FBEE8ECC9015052D594E9D07A8445EFC9A53DC27A4E6E
    SHA-512:72641685B5B9C5497062A3108D36F5A1B81D46D4EA222373B87788E374C52D232C39681C94A0E144299C492BDB99253F277CDC833F6B67D1DA85A05682E5D26B
    Malicious:false
    Reputation:low
    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
    File Type:ASCII text, with no line terminators
    Category:dropped
    Size (bytes):4
    Entropy (8bit):1.5
    Encrypted:false
    SSDEEP:3:T:T
    MD5:9978B7063E297D84BB2AC8E46C1C845F
    SHA1:E78E1C8A184B06B3CFAAF828461FB13F7DE798A6
    SHA-256:77334823791BEA53E508BA59387C1287C8DA962026769657B4686756DB4B7BC8
    SHA-512:E6DFA974084410B109A7AD9126245EAEF6ED460E3888728C26281523309C12D41161A1B61C88ECC6FBE4B87E2B6ED3A6E8716E64221177EE475D5256151C28A3
    Malicious:false
    Reputation:low
    Preview:2172
    Process:C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
    File Type:ASCII text, with no line terminators
    Category:dropped
    Size (bytes):4
    Entropy (8bit):1.5
    Encrypted:false
    SSDEEP:3:O:O
    MD5:EEDC6ED006E6F49A7010013CC1FD8A3F
    SHA1:72577F813E0B1012A020FBDC28028FFD80B7EA7B
    SHA-256:0D02233B2626A00CC924AC6C228433C46EC307678AD1D70687831FDFE73B25F7
    SHA-512:AFB76E6C9D03DC508A093F07DAB123306B724DF121CAE29BCBD58DD901C2A07FDE980F5F1376AFFE6962E1338349957AF09AD889EF651EE8629AC75617054681
    Malicious:true
    Reputation:low
    Preview:8900
    Process:C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
    File Type:ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):30
    Entropy (8bit):4.098068512058838
    Encrypted:false
    SSDEEP:3:1MwECwJOn:1MO
    MD5:D14429A2A43420229ACCE2BA85BCE909
    SHA1:23312D958EB7DB8AA494B74171E90EA01F8877AF
    SHA-256:477B77CB74AD7ABFA6200153B9B95BA849871B6278C122273A338A7474A2FF7C
    SHA-512:48B9A0DF77265D7E599F1DD6821E45E0B89ABA272B1574DAC97B8EF3B3B4C8E8A6ADE5C8719C5E3A4933F68346ED06ABC17CCC28A43AE3114C10564CAC20BCE5
    Malicious:false
    Reputation:low
    Preview:[Generic]..MonitorCertOnly=0..
    File type:PE32 executable (GUI) Intel 80386, for MS Windows
    Entropy (8bit):6.150051908780836
    TrID:
    • Win32 Executable (generic) a (10002005/4) 99.15%
    • Win32 Executable Microsoft Visual Basic 6 (82127/2) 0.81%
    • Generic Win/DOS Executable (2004/3) 0.02%
    • DOS Executable Generic (2002/1) 0.02%
    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
    File name:SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
    File size:1'772'168 bytes
    MD5:ffb4c4458546447f3bee304de21cd2eb
    SHA1:002c2f32ee46dacb422e75f687d8f74690184d31
    SHA256:2e823662bd36d30faea424591d4bf1557224007d9ee859917bb769a45cd4c0c6
    SHA512:a0879f813da4ae4a68f844dd20534c4cfc754e8c4a96a9c4498fde70ee0b3ab2261d71a5cbbe2c1f5239935e6c254d49df032c3466475d49dbd9c5f51c0f34be
    SSDEEP:24576:MMW7HssTOhL+0w6ZCNfNq8OPvTOiY+5dhhsqEyJ7VnHI4kyZHtwcy6FWEXGzt1WU:MRHssTOhLvPjYBK5T7rLRy
    TLSH:BC85F8A29940101EF1A5D9F1E4EB96221A0A3D364288944FB6DC7E46E1735C3BCB77CF
    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................6.......................Rich............PE..L...}:.R.....................@....................@................
    Icon Hash:8d684c541d2d2f62
    Entrypoint:0x411de8
    Entrypoint Section:.text
    Digitally signed:true
    Imagebase:0x400000
    Subsystem:windows gui
    Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
    DLL Characteristics:
    Time Stamp:0x52B33A7D [Thu Dec 19 18:27:09 2013 UTC]
    TLS Callbacks:
    CLR (.Net) Version:
    OS Version Major:4
    OS Version Minor:0
    File Version Major:4
    File Version Minor:0
    Subsystem Version Major:4
    Subsystem Version Minor:0
    Import Hash:2f37a530f5e6742f10a20c18ed4a30e0
    Signature Valid:false
    Signature Issuer:CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL
    Signature Validation Error:A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file
    Error Number:-2146762495
    Not Before, Not After
    • 05/04/2013 12:42:01 05/04/2015 18:32:50
    Subject Chain
    • E=info@wrocklage.de, CN=Wrocklage Intermedia GmbH, O=Wrocklage Intermedia GmbH, L=Ibbenbueren, S=Nordrhein-Westfalen, C=DE, Description=0xC3J0qHPGjDilu1
    Version:3
    Thumbprint MD5:3BBC60BE8DFEB5640F06CE2A6A3241D7
    Thumbprint SHA-1:5A117187BD5C360764F66E37C47958D94EA295FF
    Thumbprint SHA-256:B345BF99D3037AEF50BFB1FD74AE3B74688943C424BACF1CBCAFED83EA455CBD
    Serial:095B
    Instruction
    push 00472248h
    call 00007F6E88D958A3h
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    xor byte ptr [eax], al
    add byte ptr [eax], al
    dec eax
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add bl, ch
    jl 00007F6E88D958DAh
    dec ebx
    and al, 01h
    push cs
    inc edx
    mov sp, gs
    or byte ptr [edx-2Ah], cl
    mov bh, 4Ch
    fiadd word ptr [eax]
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [ecx], al
    add byte ptr [eax], al
    add byte ptr [eax], ah
    and byte ptr [eax], ah
    and byte ptr [eax], ah
    inc ebp
    inc ebx
    jc 00007F6E88D95917h
    outsb
    je 00007F6E88D9591Bh
    popad
    insb
    push eax
    jc 00007F6E88D95921h
    jbe 00007F6E88D9591Bh
    jc 00007F6E88D958B4h
    and byte ptr [eax], ah
    and byte ptr [eax], ah
    and byte ptr [eax], al
    add byte ptr [eax], al
    add bh, bh
    int3
    xor dword ptr [eax], eax
    push es
    mov dl, 2Ch
    add eax, 0F583C10h
    dec edx
    xchg eax, edx
    NameVirtual AddressVirtual Size Is in Section
    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IMPORT0x14b4d40x28.text
    IMAGE_DIRECTORY_ENTRY_RESOURCE0x1500000x60234.rsrc
    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
    IMAGE_DIRECTORY_ENTRY_SECURITY0x1af0000x1a88
    IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x2280x20
    IMAGE_DIRECTORY_ENTRY_IAT0x10000x3e8.text
    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
    .text0x10000x14b5200x14c00061878b0b27fb1249a783240ed8c9c9b3False0.2629997529179217data6.0978626075661575IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    .data0x14d0000x26880x1000620f0b67a91f7f74151bc5be745b7110False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
    .rsrc0x1500000x602340x6100005db5244864036c1088ca876c81b6ee8False0.209069950064433data5.79150754764298IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    NameRVASizeTypeLanguageCountryZLIB Complexity
    RT_ICON0x1afbcc0x668Device independent bitmap graphic, 48 x 96 x 4, image size 11520.2146341463414634
    RT_ICON0x1af8e40x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 5120.3172043010752688
    RT_ICON0x1af6fc0x1e8Device independent bitmap graphic, 24 x 48 x 4, image size 2880.38729508196721313
    RT_ICON0x1af5d40x128Device independent bitmap graphic, 16 x 32 x 4, image size 1280.4527027027027027
    RT_ICON0x19d1ac0x12428Device independent bitmap graphic, 256 x 512 x 8, image size 65536, 256 important colors0.12199165686169644
    RT_ICON0x19c3040xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors0.5229211087420043
    RT_ICON0x19ba5c0x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors0.6985559566787004
    RT_ICON0x19b3940x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors0.7684331797235023
    RT_ICON0x19ae2c0x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors0.6026011560693642
    RT_ICON0x158e040x42028Device independent bitmap graphic, 256 x 512 x 32, image size 2703360.1946141669378939
    RT_ICON0x154bdc0x4228Device independent bitmap graphic, 64 x 128 x 32, image size 168960.33656117146906
    RT_ICON0x1526340x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 96000.4545643153526971
    RT_ICON0x15158c0x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 42240.47607879924953095
    RT_ICON0x150c040x988Device independent bitmap graphic, 24 x 48 x 32, image size 24000.5823770491803278
    RT_ICON0x15079c0x468Device independent bitmap graphic, 16 x 32 x 32, image size 10880.6223404255319149
    RT_GROUP_ICON0x1506c40xd8data0.6111111111111112
    RT_VERSION0x1503900x334dataEnglishUnited States0.4146341463414634
    DLLImport
    MSVBVM60.DLL__vbaR8FixI4, __vbaVarSub, __vbaVarTstGt, __vbaStrI2, __vbaNextEachAry, _CIcos, _adj_fptan, __vbaVarMove, __vbaStrI4, __vbaRedimPreserveVar, __vbaVarVargNofree, __vbaFreeVar, __vbaAryMove, __vbaStrVarMove, __vbaLenBstr, __vbaFreeVarList, _adj_fdiv_m64, __vbaFpCDblR8, __vbaAryRecMove, __vbaVarIndexStore, __vbaNextEachVar, __vbaFreeObjList, __vbaVarIndexLoadRef, __vbaStrErrVarCopy, _adj_fprem1, __vbaRecAnsiToUni, __vbaI2Abs, __vbaCopyBytes, __vbaForEachCollAd, __vbaStrCat, __vbaVarCmpNe, __vbaBoolErrVar, __vbaLsetFixstr, __vbaRecDestruct, __vbaSetSystemError, __vbaHresultCheckObj, __vbaLenVar, _adj_fdiv_m32, __vbaAryVar, __vbaAryDestruct, __vbaLateMemSt, __vbaVarIndexLoadRefLock, __vbaVarForInit, __vbaExitProc, __vbaBoolStr, __vbaStrBool, __vbaI4Abs, __vbaOnError, __vbaObjSet, _adj_fdiv_m16i, __vbaVarIndexStoreObj, __vbaObjSetAddref, _adj_fdivr_m16i, __vbaVarIndexLoad, __vbaStrFixstr, __vbaBoolVar, __vbaVarTstLt, __vbaVargVar, __vbaRefVarAry, __vbaFpR8, __vbaBoolVarNull, _CIsin, __vbaErase, __vbaVargVarMove, __vbaVarZero, __vbaVarCmpGt, __vbaChkstk, __vbaFileClose, EVENT_SINK_AddRef, __vbaVarAbs, __vbaGenerateBoundsError, __vbaExitEachColl, __vbaStrCmp, __vbaAryConstruct2, __vbaVarTstEq, __vbaDateR8, __vbaI2I4, __vbaObjVar, DllFunctionCall, __vbaVarLateMemSt, __vbaVarOr, __vbaFpUI1, __vbaCastObjVar, __vbaStrR4, __vbaRedimPreserve, __vbaLbound, _adj_fpatan, __vbaFixstrConstruct, __vbaLateIdCallLd, __vbaRedim, __vbaStrR8, __vbaUI1ErrVar, __vbaRecUniToAnsi, EVENT_SINK_Release, __vbaNew, __vbaUI1I2, _CIsqrt, __vbaObjIs, __vbaVarAnd, EVENT_SINK_QueryInterface, __vbaStr2Vec, __vbaUI1I4, __vbaStrUI1, __vbaExceptHandler, __vbaPrintFile, __vbaStrToUnicode, __vbaDateStr, __vbaR4ErrVar, __vbaExitEachAry, _adj_fprem, _adj_fdivr_m64, __vbaI2Str, __vbaR8ErrVar, __vbaFPException, __vbaInStrVar, __vbaUbound, __vbaStrVarVal, __vbaVarCat, __vbaDateVar, __vbaLsetFixstrFree, __vbaI2Var, __vbaExitEachVar, _CIlog, __vbaErrorOverflow, __vbaFileOpen, __vbaVarLateMemCallLdRf, __vbaVar2Vec, __vbaInStr, __vbaNew2, __vbaR8Str, __vbaCyMulI2, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaI4Str, __vbaFreeStrList, _adj_fdivr_m32, __vbaPowerR8, __vbaR8Var, _adj_fdiv_r, __vbaVarTstNe, __vbaVarSetVar, __vbaI4Var, __vbaForEachAry, __vbaVarCmpEq, __vbaLateMemCall, __vbaVarAdd, __vbaAryLock, __vbaStrComp, __vbaStrToAnsi, __vbaVarDup, __vbaUnkVar, __vbaVarTstGe, __vbaVarCopy, __vbaVarLateMemCallLd, __vbaFpI4, __vbaRecDestructAnsi, __vbaVarSetObjAddref, __vbaLateMemCallLd, _CIatan, __vbaUI1Str, __vbaI2ErrVar, __vbaCastObj, __vbaStrMove, __vbaAryCopy, __vbaR8IntI4, __vbaStrVarCopy, __vbaForEachVar, _allmul, __vbaLateIdSt, __vbaLateMemCallSt, __vbaAryRecCopy, _CItan, __vbaNextEachCollAd, __vbaFPInt, __vbaAryUnlock, __vbaVarForNext, _CIexp, __vbaMidStmtBstr, __vbaRecAssign, __vbaFreeObj, __vbaFreeStr, __vbaI4ErrVar
    Language of compilation systemCountry where language is spokenMap
    EnglishUnited States
    No network behavior found

    Click to jump to process

    Click to jump to process

    Click to dive into process behavior distribution

    Target ID:0
    Start time:05:25:30
    Start date:25/04/2024
    Path:C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Diple.31685.13945.exe"
    Imagebase:0x400000
    File size:1'772'168 bytes
    MD5 hash:FFB4C4458546447F3BEE304DE21CD2EB
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Reset < >

      Execution Graph

      Execution Coverage:12.9%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:2.6%
      Total number of Nodes:2000
      Total number of Limit Nodes:215
      execution_graph 18353 4d0440 11 API calls 18354 4d06d2 #685 __vbaObjSet 18353->18354 18355 4d05a2 18353->18355 18356 4d0702 __vbaFreeObj 18354->18356 18357 4d05ae 10 API calls 18355->18357 18358 4d075f __vbaFreeStr __vbaFreeStr __vbaFreeStr 18356->18358 18361 4d22a0 __vbaChkstk __vbaStrCopy __vbaAryConstruct2 __vbaOnError 18357->18361 18360 4d0684 __vbaStrMove __vbaFreeStrList __vbaFreeVarList 18360->18354 18362 4d1000 18361->18362 18363 4d231d __vbaStrCopy __vbaStrCmp 18362->18363 18364 4d234e __vbaInStr 18363->18364 18365 4d2383 __vbaStrCopy __vbaLenBstr 18363->18365 18364->18365 18366 4d236e __vbaStrCopy 18364->18366 18367 4d2b3f #685 __vbaObjSet 18365->18367 18368 4d23b1 __vbaStrCopy 18365->18368 18366->18365 18370 4d2b6f __vbaFreeObj 18367->18370 18412 50e600 6 API calls 18368->18412 18372 4d2bf3 7 API calls 18370->18372 18371 4d23d8 __vbaStrMove __vbaStrCat __vbaStrMove __vbaFreeStrList __vbaInStr 18373 4d2426 #712 __vbaStrMove 18371->18373 18374 4d2452 6 API calls 18371->18374 18372->18360 18373->18374 18375 4d24ed 18374->18375 18376 4d2c5b __vbaErrorOverflow 18374->18376 18377 4d250d 18375->18377 18378 4d2519 __vbaGenerateBoundsError 18375->18378 18379 4d2525 __vbaAryLock 18377->18379 18378->18379 18380 4d2539 18379->18380 18381 4d2584 __vbaGenerateBoundsError 18379->18381 18380->18381 18382 4d2542 18380->18382 18383 4d2590 __vbaStrToAnsi 18381->18383 18384 4d255e 18382->18384 18385 4d256a __vbaGenerateBoundsError 18382->18385 18444 47485c 18383->18444 18384->18383 18385->18384 18413 50e6ae __vbaFreeObj __vbaStrCmp 18412->18413 18414 50e6d3 __vbaStrCopy 18413->18414 18415 50e6e8 #685 __vbaObjSet 18413->18415 18414->18415 18416 50e718 __vbaFreeObj __vbaObjSetAddref __vbaStrCopy __vbaStrCopy 18415->18416 18417 523470 18416->18417 18418 50e773 24 API calls 18417->18418 18419 50ea05 18418->18419 18420 50ea16 __vbaHresultCheckObj 18419->18420 18421 50ea39 18419->18421 18422 50ea43 __vbaFreeObj 18420->18422 18421->18422 18423 50ede3 #685 __vbaObjSet 18422->18423 18424 50ea6d #685 __vbaObjSet 18422->18424 18426 50ee17 18423->18426 18425 50ea9d 6 API calls 18424->18425 18429 523470 18425->18429 18427 50ee28 __vbaHresultCheckObj 18426->18427 18428 50ee4b 18426->18428 18430 50ee55 __vbaFreeObj 18427->18430 18428->18430 18431 50eb20 23 API calls 18429->18431 18432 50eeb7 __vbaObjSetAddref __vbaStrCopy #685 __vbaObjSet 18430->18432 18433 50ee7b __vbaStrCopy __vbaStrCopy 18430->18433 18434 50ed93 __vbaStrCopy 18431->18434 18435 50edbc __vbaStrCopy 18431->18435 18440 50ef0f __vbaFreeObj 18432->18440 18436 4fa530 18433->18436 18437 4fa530 18434->18437 18438 4fa530 18435->18438 18439 50eeae __vbaFreeStr 18436->18439 18441 50edb1 __vbaFreeStr 18437->18441 18442 50edda __vbaFreeStr 18438->18442 18439->18432 18443 50ef58 __vbaFreeObj __vbaFreeStr 18440->18443 18441->18423 18442->18423 18443->18371 18445 474865 18444->18445 18446 4a7650 __vbaChkstk __vbaOnError __vbaStrCopy __vbaStrCmp __vbaStrCmp 18447 4a7702 18446->18447 18448 4a7c50 #685 __vbaObjSet 18446->18448 18449 4cc360 18 API calls 18447->18449 18451 4a7c80 __vbaFreeObj 18448->18451 18450 4a770e 18449->18450 18452 51d000 110 API calls 18450->18452 18453 4a7cde 18451->18453 18454 4a771c 18452->18454 18454->18448 18455 4d2c70 14 API calls 18454->18455 18456 4a7740 __vbaStrI4 __vbaStrMove __vbaStrCat __vbaStrMove 18455->18456 18487 4d0ae0 __vbaChkstk __vbaStrCopy __vbaOnError 18456->18487 18458 4a776a #518 #520 __vbaVarTstNe __vbaFreeStrList __vbaFreeVarList 18458->18448 18459 4a77f5 __vbaStrCmp 18458->18459 18459->18448 18460 4a7819 9 API calls 18459->18460 18460->18448 18461 4a7930 __vbaStrCmp __vbaStrCmp 18460->18461 18462 4a7977 __vbaStrCopy 18461->18462 18463 4a7a84 __vbaStrCmp __vbaStrCmp 18461->18463 18464 51c3a0 3421 API calls 18462->18464 18463->18448 18465 4a7acb 7 API calls 18463->18465 18466 4a799e __vbaStrMove __vbaStrCopy 18464->18466 18467 4fa530 18465->18467 18468 5071e0 18466->18468 18469 4a7b49 __vbaFreeStrList 18467->18469 18471 4a79d8 __vbaFreeStrList 18468->18471 18470 51c3a0 3421 API calls 18469->18470 18472 4a7b6c __vbaStrMove __vbaStrCopy 18470->18472 18473 51c3a0 3421 API calls 18471->18473 18474 5071e0 18472->18474 18475 4a79f7 __vbaStrMove __vbaStrCopy 18473->18475 18476 4a7ba5 __vbaFreeStrList 18474->18476 18477 5071e0 18475->18477 18478 51c3a0 3421 API calls 18476->18478 18479 4a7a31 __vbaFreeStrList __vbaStrCat __vbaStrMove 18477->18479 18480 4a7bc4 __vbaStrMove __vbaStrCopy 18478->18480 18481 4d0d30 18479->18481 18482 5071e0 18480->18482 18483 4a7a7b __vbaFreeStr 18481->18483 18484 4a7bfd __vbaFreeStrList __vbaStrCat __vbaStrMove 18482->18484 18483->18463 18485 4d0d30 18484->18485 18486 4a7c47 __vbaFreeStr 18485->18486 18486->18448 18488 4d1000 18487->18488 18489 4d0b4c #520 __vbaStrVarMove __vbaStrMove __vbaFreeVar __vbaStrCmp 18488->18489 18490 4d0bfd #520 __vbaVarTstEq __vbaFreeVar 18489->18490 18491 4d0ba6 __vbaStrCopy __vbaStrCat __vbaStrMove 18489->18491 18492 4d0c65 __vbaStrCopy #685 __vbaObjSet 18490->18492 18493 4d0c50 __vbaStrCopy 18490->18493 18494 4d22a0 307 API calls 18491->18494 18496 4d0ca8 __vbaFreeObj 18492->18496 18493->18492 18495 4d0bdf __vbaStrMove __vbaFreeStrList 18494->18495 18495->18490 18497 4d0cfb __vbaFreeStr __vbaFreeStr 18496->18497 18497->18458 13880 506cf0 9 API calls 13881 506dc9 #685 __vbaObjSet 13880->13881 13882 50715b #685 __vbaObjSet 13880->13882 13883 506df4 13881->13883 13884 50718b __vbaFreeObj 13882->13884 13885 506e19 13883->13885 13886 506dff __vbaHresultCheckObj 13883->13886 13887 5071ae __vbaFreeStr __vbaFreeStr 13884->13887 13888 506e20 __vbaFreeObj 13885->13888 13886->13888 13888->13882 13889 506e44 13888->13889 13889->13882 13890 506e7d #685 __vbaObjSet 13889->13890 13891 506ea4 __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 13890->13891 13892 507110 13891->13892 13893 506f05 #685 __vbaObjSet 13891->13893 13892->13882 13894 506f30 13893->13894 13895 506f55 13894->13895 13896 506f3b __vbaHresultCheckObj 13894->13896 13897 506f5c __vbaFreeObj 13895->13897 13896->13897 13897->13892 13898 506f80 13897->13898 13899 506f8e __vbaSetSystemError #598 13898->13899 13900 506fb2 #685 __vbaObjSet 13899->13900 13901 50710e #685 __vbaObjSet 13899->13901 13903 506fd9 __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 13900->13903 13906 507146 __vbaFreeObj 13901->13906 13904 5070d5 #685 __vbaObjSet 13903->13904 13905 50703a #685 __vbaObjSet 13903->13905 13907 507105 __vbaFreeObj 13904->13907 13908 507065 13905->13908 13906->13882 13907->13901 13909 507070 __vbaHresultCheckObj 13908->13909 13910 50708d 13908->13910 13911 507097 __vbaFreeObj 13909->13911 13910->13911 13911->13904 13912 5070b7 #529 13911->13912 13912->13904 13913 411de8 #100 13914 411e07 13913->13914 18498 49f060 __vbaChkstk 18499 49f0b5 __vbaOnError __vbaStrCopy __vbaStrCopy 18498->18499 18500 4fa530 18499->18500 18501 49f100 __vbaFreeStr __vbaStrCopy __vbaStrCopy 18500->18501 18502 4efae0 18501->18502 18503 49f139 __vbaFreeStrList __vbaVarDup __vbaVarDup 18502->18503 18572 4ebb80 __vbaChkstk __vbaOnError __vbaStrCmp 18503->18572 18505 49f1b5 __vbaFreeVarList __vbaStrCmp 18506 49f1e9 __vbaStrCopy 18505->18506 18507 49f202 __vbaStrCmp 18505->18507 18506->18507 18508 49f353 18507->18508 18509 49f223 18507->18509 18689 510480 __vbaChkstk __vbaOnError __vbaStrCmp 18508->18689 18510 51c3a0 3421 API calls 18509->18510 18512 49f22f __vbaStrMove __vbaStrCopy 18510->18512 18644 508110 __vbaChkstk __vbaOnError __vbaStrCat __vbaStrMove 18512->18644 18513 49f35f __vbaStrMove __vbaStrCopy __vbaStrCopy __vbaStrCopy 18515 506210 116 API calls 18513->18515 18517 49f3a9 __vbaStrMove __vbaStrCmp __vbaFreeStrList 18515->18517 18516 49f25c __vbaFreeStrList 18518 51c3a0 3421 API calls 18516->18518 18519 49f3fd 18517->18519 18520 49f4b3 __vbaObjSet 18517->18520 18521 49f27b __vbaStrMove __vbaStrCopy 18518->18521 18522 510480 304 API calls 18519->18522 18528 49f4ee 18520->18528 18524 508110 252 API calls 18521->18524 18525 49f409 __vbaStrMove __vbaStrCopy __vbaStrCopy 18522->18525 18526 49f2a8 __vbaFreeStrList 18524->18526 18527 508110 252 API calls 18525->18527 18529 51c3a0 3421 API calls 18526->18529 18530 49f441 __vbaFreeStrList 18527->18530 18531 49f4ff __vbaHresultCheckObj 18528->18531 18532 49f522 18528->18532 18533 49f2c7 __vbaStrMove __vbaStrCopy 18529->18533 18534 510480 304 API calls 18530->18534 18535 49f52c __vbaFreeObj 18531->18535 18532->18535 18536 508110 252 API calls 18533->18536 18537 49f464 __vbaStrMove __vbaStrCopy __vbaStrCopy 18534->18537 18542 49f54b __vbaObjSet 18535->18542 18539 49f2f4 __vbaFreeStrList 18536->18539 18538 508110 252 API calls 18537->18538 18541 49f49c __vbaFreeStrList 18538->18541 18540 51c3a0 3421 API calls 18539->18540 18543 49f313 __vbaStrMove __vbaStrCopy 18540->18543 18541->18520 18545 49f570 18542->18545 18544 508110 252 API calls 18543->18544 18546 49f340 __vbaFreeStrList 18544->18546 18547 49f581 __vbaHresultCheckObj 18545->18547 18548 49f5a4 18545->18548 18546->18508 18549 49f5ae __vbaFreeObj 18547->18549 18548->18549 18550 49f5cd __vbaObjSet 18549->18550 18551 49f5f2 18550->18551 18552 49f603 __vbaHresultCheckObj 18551->18552 18553 49f626 18551->18553 18554 49f630 __vbaFreeObj 18552->18554 18553->18554 18555 49f64f __vbaObjSet 18554->18555 18556 49f674 18555->18556 18557 49f6a8 18556->18557 18558 49f685 __vbaHresultCheckObj 18556->18558 18559 49f6b2 __vbaFreeObj 18557->18559 18558->18559 18560 49f6d1 __vbaObjSet 18559->18560 18561 49f6f6 18560->18561 18562 49f72a 18561->18562 18563 49f707 __vbaHresultCheckObj 18561->18563 18564 49f734 __vbaFreeObj 18562->18564 18563->18564 18565 49f753 __vbaObjSet 18564->18565 18566 49f778 18565->18566 18567 49f789 __vbaHresultCheckObj 18566->18567 18568 49f7ac 18566->18568 18569 49f7b6 __vbaFreeObj #685 __vbaObjSet 18567->18569 18568->18569 18570 49f7ef __vbaFreeObj 18569->18570 18571 49f846 18570->18571 18573 4ecbd6 #685 __vbaObjSet 18572->18573 18574 4ebbf4 __vbaVarVargNofree __vbaI4ErrVar 18572->18574 18576 4ecc06 __vbaFreeObj 18573->18576 18715 50ff90 __vbaChkstk __vbaOnError 18574->18715 18578 4ecc55 __vbaFreeVar __vbaFreeStr __vbaFreeStr __vbaFreeStr 18576->18578 18578->18505 18579 4ebc7f __vbaFreeObj 18580 4ebd4c __vbaVarVargNofree __vbaVarCopy __vbaVarTstEq 18579->18580 18581 4ebcab 18579->18581 18582 4ebda6 __vbaStrCopy 18580->18582 18583 4ebdc0 __vbaVarTstEq 18580->18583 18584 4f2d70 20 API calls 18581->18584 18585 4ec088 10 API calls 18582->18585 18586 4ebdf6 __vbaStrCopy 18583->18586 18587 4ebe10 __vbaVarTstEq 18583->18587 18588 4ebcb7 __vbaStrMove __vbaStrCmp __vbaStrCmp __vbaStrCmp __vbaFreeStr 18584->18588 18589 4ec4f2 10 API calls 18585->18589 18590 4ec173 43 API calls 18585->18590 18586->18585 18591 4ebe46 __vbaStrCopy 18587->18591 18592 4ebe60 __vbaVarTstEq 18587->18592 18588->18580 18593 4ebd2a 18588->18593 18594 4ec68b __vbaStrCmp 18589->18594 18595 4ec5d8 #518 #617 __vbaVarTstEq __vbaFreeVarList 18589->18595 18590->18589 18591->18585 18596 4ebe96 __vbaStrCopy 18592->18596 18597 4ebeb0 __vbaVarTstEq 18592->18597 18593->18580 18602 4ec6bb #685 __vbaObjSet 18594->18602 18605 4ec6a5 18594->18605 18598 4ec65d __vbaStrCopy 18595->18598 18599 4ec675 __vbaStrCopy 18595->18599 18596->18585 18600 4ebee6 __vbaStrCopy 18597->18600 18601 4ebf00 __vbaVarTstEq 18597->18601 18598->18594 18599->18594 18600->18585 18603 4ebf36 __vbaStrCopy 18601->18603 18604 4ebf50 __vbaVarTstEq 18601->18604 18609 4ec6eb __vbaFreeObj __vbaStrCopy 18602->18609 18603->18585 18606 4ebf86 __vbaStrCopy 18604->18606 18607 4ebfa0 __vbaVarTstEq 18604->18607 18605->18602 18608 4ecb8b __vbaStrCopy __vbaStrCopy 18605->18608 18606->18585 18612 4ebfd6 __vbaStrCopy 18607->18612 18613 4ebff0 __vbaVarTstEq 18607->18613 18611 5071e0 18608->18611 18731 51dae0 __vbaChkstk __vbaOnError __vbaStrCopy __vbaStrCmp 18609->18731 18617 4ecbc3 __vbaFreeStrList 18611->18617 18612->18585 18615 4ec03d __vbaVarTstEq 18613->18615 18616 4ec026 __vbaStrCopy 18613->18616 18614 4ec716 __vbaFreeStr 18618 4ec74e 7 API calls 18614->18618 18619 4ec73c 18614->18619 18615->18585 18620 4ec073 __vbaStrCopy 18615->18620 18616->18585 18617->18573 18621 4ec804 18618->18621 18619->18573 18620->18585 18622 4ec838 18621->18622 18623 4ec815 __vbaHresultCheckObj 18621->18623 18624 4ec842 __vbaFreeObj 18622->18624 18623->18624 18625 4ec86f #685 __vbaObjSet 18624->18625 18626 4ec9f1 18624->18626 18629 4ec89f 8 API calls 18625->18629 18839 5181b0 __vbaChkstk __vbaOnError __vbaStrCmp 18626->18839 18631 4ec92a 18629->18631 18630 4eca34 18632 4eca68 18630->18632 18633 4eca45 __vbaHresultCheckObj 18630->18633 18634 4ec95e 18631->18634 18635 4ec93b __vbaHresultCheckObj 18631->18635 18637 4eca72 __vbaFreeObj 18632->18637 18633->18637 18636 4ec968 __vbaFreeObj 18634->18636 18635->18636 18636->18626 18638 4ec991 __vbaStrCopy 18636->18638 18639 4eca9b 9 API calls 18637->18639 18641 4fa530 18638->18641 18639->18619 18642 4ec9af __vbaFreeStr #685 __vbaObjSet 18641->18642 18643 4ec9e8 __vbaFreeObj 18642->18643 18643->18626 18855 506cf0 9 API calls 18644->18855 18646 508199 __vbaStrCmp 18647 508412 __vbaStrCopy 18646->18647 18648 5081ba 18646->18648 18888 519db0 __vbaChkstk __vbaOnError 18647->18888 18648->18647 18650 5081ff __vbaStrCmp 18648->18650 18652 50821c 18650->18652 18665 50823f 18650->18665 18655 50822a __vbaSetSystemError #598 18652->18655 18653 4bd210 95 API calls 18654 50846d __vbaFreeStr __vbaInStr 18653->18654 18656 50849a #518 __vbaInStrVar __vbaVarTstEq __vbaFreeVarList 18654->18656 18657 50854b __vbaVarTstEq 18654->18657 18658 508244 18655->18658 18656->18657 18659 508536 __vbaStrCopy 18656->18659 18660 508587 __vbaStrCmp 18657->18660 18661 50857b 18657->18661 18664 508255 __vbaStrCopy #685 __vbaObjSet 18658->18664 18658->18665 18659->18657 18662 5085a7 __vbaStrToAnsi __vbaStrToAnsi __vbaStrToAnsi 18660->18662 18663 50862f #685 __vbaObjSet 18660->18663 18893 509000 __vbaChkstk __vbaOnError __vbaVarTstEq 18661->18893 18912 475330 18662->18912 18669 50866f __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 18663->18669 18670 50829c __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 18664->18670 18665->18647 18671 5086dc #685 __vbaObjSet 18669->18671 18672 50879e #685 __vbaObjSet 18669->18672 18673 508309 #685 __vbaObjSet 18670->18673 18674 5083cb #685 __vbaObjSet 18670->18674 18677 508713 18671->18677 18675 5087ce __vbaFreeObj __vbaStrCopy #685 __vbaObjSet 18672->18675 18678 508340 18673->18678 18676 5083fb __vbaFreeObj 18674->18676 18683 50881e __vbaFreeObj 18675->18683 18676->18647 18679 508724 __vbaHresultCheckObj 18677->18679 18680 508747 18677->18680 18681 508351 __vbaHresultCheckObj 18678->18681 18682 508374 18678->18682 18684 508751 __vbaFreeObj 18679->18684 18680->18684 18685 50837e __vbaFreeObj 18681->18685 18682->18685 18687 508866 __vbaFreeVar __vbaFreeStr 18683->18687 18684->18672 18688 50877a #529 18684->18688 18685->18674 18686 5083a7 #529 18685->18686 18686->18674 18687->18516 18688->18672 18690 5104f0 __vbaStrCopy 18689->18690 18691 51050b 18689->18691 18692 510765 #685 __vbaObjSet 18690->18692 18693 501700 20 API calls 18691->18693 18695 510795 __vbaFreeObj 18692->18695 18694 510517 __vbaStrMove __vbaStrCmp 18693->18694 18696 510553 __vbaStrCmp 18694->18696 18697 51053c 18694->18697 18701 5107de __vbaFreeStr __vbaFreeStr 18695->18701 18699 510571 18696->18699 18700 51066d __vbaStrCmp 18696->18700 18698 5110e0 60 API calls 18697->18698 18702 510548 __vbaStrMove 18698->18702 18704 510581 __vbaNew2 18699->18704 18709 51059d 18699->18709 18700->18692 18703 51068b #619 __vbaVarTstNe __vbaFreeVar 18700->18703 18701->18513 18702->18696 18705 510701 __vbaStrCat __vbaStrMove 18703->18705 18706 5106e0 __vbaStrCat __vbaStrMove 18703->18706 18704->18709 18914 52de40 6 API calls 18705->18914 18706->18705 18708 510732 __vbaStrMove __vbaStrCopy __vbaStrCopy 18708->18692 18710 5105ea 18709->18710 18711 5105cd __vbaHresultCheckObj 18709->18711 18712 51063b 18710->18712 18713 51061b __vbaHresultCheckObj 18710->18713 18711->18710 18714 510645 __vbaStrMove __vbaFreeObj 18712->18714 18713->18714 18714->18700 18716 510150 18715->18716 18717 50ffff __vbaStrCmp 18716->18717 18718 51003c __vbaStrCmp 18717->18718 18719 51001c 18717->18719 18720 5100d4 #685 __vbaObjSet 18718->18720 18721 510058 18718->18721 18722 510028 __vbaStrMove __vbaFreeStr 18719->18722 18725 51010c __vbaFreeObj 18720->18725 18721->18720 18724 510089 __vbaR8Str 18721->18724 18722->18718 18726 510147 18724->18726 18727 5100ab __vbaStrR8 __vbaStrMove 18724->18727 18728 4ebc30 __vbaVargVarMove #685 __vbaObjSet 18725->18728 18726->18726 18729 4fa530 18727->18729 18728->18579 18730 5100cb __vbaFreeStr 18729->18730 18730->18720 18732 51dd33 __vbaStrCmp __vbaStrCmp 18731->18732 18733 51db76 __vbaInStr 18731->18733 18735 51dd72 11 API calls 18732->18735 18736 51e207 __vbaStrCopy #685 __vbaObjSet 18732->18736 18733->18732 18734 51db9a 12 API calls 18733->18734 18737 51e2e4 __vbaErrorOverflow 18734->18737 18738 51dcef __vbaLenBstr 18734->18738 18735->18737 18739 51de96 18735->18739 18740 51e24a __vbaFreeObj 18736->18740 18742 51e2f0 8 API calls 18737->18742 18738->18737 18741 51dd03 #617 __vbaStrVarMove __vbaStrMove __vbaFreeVar 18738->18741 18739->18737 18743 51de9f 6 API calls 18739->18743 18744 51e17d __vbaFreeStr __vbaFreeStr __vbaFreeStr __vbaFreeStr __vbaFreeStr 18740->18744 18741->18732 18745 51e460 11 API calls 18742->18745 18746 51e408 #712 __vbaStrMove #712 __vbaStrMove 18742->18746 18747 51df02 7 API calls 18743->18747 18748 51df15 __vbaStrCmp 18743->18748 18744->18614 18752 51f159 __vbaErrorOverflow 18745->18752 18753 51e58f 18745->18753 18746->18745 18755 51e110 __vbaStrToAnsi 18747->18755 18756 51e0b8 #712 __vbaStrMove #712 __vbaStrMove 18747->18756 18748->18747 18750 51df45 __vbaStrCmp 18748->18750 18750->18747 18754 51df72 __vbaStrCmp 18750->18754 18753->18752 18757 51e598 16 API calls 18753->18757 18754->18747 18759 51df9f __vbaStrCmp 18754->18759 18760 475c20 18755->18760 18756->18755 18757->18752 18758 51e729 __vbaLenBstr 18757->18758 18758->18752 18761 51e73b 8 API calls 18758->18761 18759->18747 18762 51e13a __vbaSetSystemError __vbaStrToUnicode __vbaFreeStr 18760->18762 18763 51e7c4 __vbaStrCopy __vbaStrToAnsi 18761->18763 18764 51e7d7 __vbaStrCmp 18761->18764 18762->18744 18765 51e182 __vbaStrToAnsi 18762->18765 18851 475c20 18763->18851 18764->18763 18768 51e807 __vbaStrCmp 18764->18768 18853 475b84 18765->18853 18768->18763 18770 51e834 __vbaStrCmp 18768->18770 18770->18763 18773 51e861 __vbaStrCmp 18770->18773 18773->18763 18840 518224 __vbaStrCmp 18839->18840 18841 51837a #685 __vbaObjSet 18839->18841 18840->18841 18842 518245 7 API calls 18840->18842 18843 5183aa __vbaFreeObj 18841->18843 18845 5182de 18842->18845 18844 4ec9fd #685 __vbaObjSet 18843->18844 18844->18630 18846 518306 18845->18846 18847 5182e9 __vbaHresultCheckObj 18845->18847 18848 518310 __vbaFreeObj 18846->18848 18847->18848 18849 518336 __vbaStrCopy 18848->18849 18850 51834f __vbaObjSetAddref __vbaStrCopy 18848->18850 18849->18841 18850->18841 18852 475c29 18851->18852 18854 475b8d 18853->18854 18856 506dc9 #685 __vbaObjSet 18855->18856 18857 50715b #685 __vbaObjSet 18855->18857 18858 506df4 18856->18858 18859 50718b __vbaFreeObj 18857->18859 18860 506e19 18858->18860 18861 506dff __vbaHresultCheckObj 18858->18861 18862 5071ae __vbaFreeStr __vbaFreeStr 18859->18862 18863 506e20 __vbaFreeObj 18860->18863 18861->18863 18862->18646 18863->18857 18864 506e44 18863->18864 18864->18857 18865 506e7d #685 __vbaObjSet 18864->18865 18866 506ea4 __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 18865->18866 18867 507110 18866->18867 18868 506f05 #685 __vbaObjSet 18866->18868 18867->18857 18869 506f30 18868->18869 18870 506f55 18869->18870 18871 506f3b __vbaHresultCheckObj 18869->18871 18872 506f5c __vbaFreeObj 18870->18872 18871->18872 18872->18867 18873 506f80 18872->18873 18874 506f8e __vbaSetSystemError #598 18873->18874 18875 506fb2 #685 __vbaObjSet 18874->18875 18876 50710e #685 __vbaObjSet 18874->18876 18878 506fd9 __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 18875->18878 18881 507146 __vbaFreeObj 18876->18881 18879 5070d5 #685 __vbaObjSet 18878->18879 18880 50703a #685 __vbaObjSet 18878->18880 18882 507105 __vbaFreeObj 18879->18882 18883 507065 18880->18883 18881->18857 18882->18876 18884 507070 __vbaHresultCheckObj 18883->18884 18885 50708d 18883->18885 18886 507097 __vbaFreeObj 18884->18886 18885->18886 18886->18879 18887 5070b7 #529 18886->18887 18887->18879 18889 519c90 10 API calls 18888->18889 18890 519e10 #685 __vbaObjSet 18889->18890 18891 519e3a __vbaFreeObj 18890->18891 18892 508435 __vbaStrI4 __vbaStrMove 18891->18892 18892->18653 18894 5090d1 __vbaVarTstEq 18893->18894 18895 509087 __vbaStrCat __vbaStrMove 18893->18895 18897 509232 7 API calls 18894->18897 18898 509108 18894->18898 18896 4ecd60 18895->18896 18899 5090b2 __vbaVarMove __vbaFreeStr 18896->18899 18900 509321 #619 __vbaVarTstNe __vbaFreeVar 18897->18900 18901 5092e6 __vbaVarAdd __vbaVarMove 18897->18901 18902 509134 18898->18902 18903 509118 __vbaNew2 18898->18903 18899->18894 18904 5093b3 __vbaFreeVar 18900->18904 18905 509378 __vbaVarAdd __vbaVarMove 18900->18905 18901->18900 18907 509173 __vbaHresultCheckObj 18902->18907 18908 509196 18902->18908 18903->18902 18904->18660 18905->18904 18907->18908 18909 5091d0 __vbaHresultCheckObj 18908->18909 18910 5091f3 18908->18910 18911 5091fd __vbaVarMove __vbaFreeObj 18909->18911 18910->18911 18911->18897 18913 475339 18912->18913 18913->18913 18915 52df39 __vbaStrCopy __vbaInStr 18914->18915 18916 52df0d #712 __vbaStrMove 18914->18916 18917 52df6e __vbaStrCmp 18915->18917 18918 52ed4f #685 __vbaObjSet 18915->18918 18916->18915 18919 52e6fb 17 API calls 18917->18919 18920 52df8f 18 API calls 18917->18920 18925 52ed7f __vbaFreeObj 18918->18925 18923 52e91a #619 __vbaVarTstEq __vbaFreeVar 18919->18923 18924 52e8ec __vbaStrCopy __vbaStrCopy 18919->18924 18921 52e1b2 __vbaStrCopy __vbaStrCopy 18920->18921 18922 52e197 __vbaStrCopy 18920->18922 18962 52d9d0 __vbaChkstk __vbaOnError __vbaStrCopy __vbaStrCmp 18921->18962 18926 52e6b2 __vbaStrCmp 18922->18926 18928 52ea75 #518 #619 __vbaVarTstEq __vbaFreeVarList 18923->18928 18929 52e98b 18923->18929 18924->18918 18930 52edff 6 API calls 18925->18930 18933 52e6df __vbaStrCopy 18926->18933 18934 52e6cc __vbaStrCopy 18926->18934 18928->18918 18931 52eafe 12 API calls 18928->18931 18935 52d9d0 46 API calls 18929->18935 18930->18708 18931->18918 18936 52ec33 18931->18936 18932 52e1ec __vbaStrMove __vbaStrCmp 18932->18926 18937 52e215 #520 __vbaVarTstEq __vbaFreeVar 18932->18937 18933->18918 18934->18933 18938 52e997 __vbaStrMove __vbaStrCmp __vbaStrCmp 18935->18938 18939 52d9d0 46 API calls 18936->18939 18940 52e280 18937->18940 18941 52e2ac 18937->18941 18942 52ea70 18938->18942 18943 52e9dd #619 __vbaVarTstEq __vbaFreeVar 18938->18943 18944 52ec3f __vbaStrMove __vbaStrCmp __vbaStrCmp 18939->18944 18945 501700 20 API calls 18940->18945 18946 501700 20 API calls 18941->18946 18942->18918 18943->18942 18947 52ea4a __vbaStrCopy __vbaStrCopy 18943->18947 18944->18918 18948 52ec85 #619 __vbaVarTstEq __vbaFreeVar 18944->18948 18949 52e28c __vbaStrMove __vbaStrCopy 18945->18949 18950 52e2b8 __vbaStrMove 18946->18950 18947->18942 18948->18918 18951 52ecf2 __vbaStrCat __vbaStrMove __vbaStrCopy __vbaStrCopy __vbaStrCopy 18948->18951 18952 52e2c3 __vbaStrCmp 18949->18952 18950->18952 18951->18918 18952->18926 18953 52e2e1 #518 #518 __vbaInStrVar __vbaVarTstGt __vbaFreeVarList 18952->18953 18954 52e395 __vbaLenBstr __vbaLenBstr 18953->18954 18955 52e45b #619 #619 __vbaLenBstr __vbaLenBstr 18953->18955 18957 52ee4c __vbaErrorOverflow 18954->18957 18958 52e3e0 7 API calls 18954->18958 18956 52e4f5 6 API calls 18955->18956 18955->18957 18956->18926 18959 52e594 __vbaLenBstr 18956->18959 18958->18926 18959->18957 18960 52e5c1 6 API calls 18959->18960 18960->18957 18961 52e63c 7 API calls 18960->18961 18961->18926 18963 52dd93 #685 __vbaObjSet 18962->18963 18964 52da59 __vbaStrCopy __vbaStrCmp 18962->18964 18970 52ddc3 __vbaFreeObj 18963->18970 18965 52daa8 __vbaStrCmp 18964->18965 18966 52da8d __vbaStrCopy 18964->18966 18968 52dac5 __vbaStrCopy __vbaStrCopy __vbaStrCopy __vbaStrCopy 18965->18968 18969 52db3a #520 __vbaStrVarMove __vbaStrMove __vbaFreeVar __vbaStrCmp 18965->18969 18967 52dd7c __vbaStrCopy 18966->18967 18967->18963 18971 4ecd60 18968->18971 18969->18967 18972 52db98 #619 __vbaVarTstNe __vbaFreeVar 18969->18972 18973 52de16 __vbaFreeStr 18970->18973 18974 52db26 __vbaStrMove __vbaFreeStr 18971->18974 18975 52dc0e #531 #619 __vbaVarTstNe __vbaFreeVar 18972->18975 18976 52dbed __vbaStrCat __vbaStrMove 18972->18976 18973->18932 18974->18969 18977 52dc74 __vbaStrCat __vbaStrMove 18975->18977 18978 52dc95 #685 __vbaObjSet 18975->18978 18976->18975 18977->18978 18979 52dcc5 __vbaFreeObj __vbaStrCopy __vbaStrCopy __vbaStrCopy 18978->18979 18980 4ecd60 18979->18980 18981 52dd14 __vbaStrMove __vbaStrCmp __vbaFreeStrList 18980->18981 18981->18967 18982 52dd51 __vbaStrCopy 18981->18982 18983 4efae0 18982->18983 18984 52dd73 __vbaFreeStr 18983->18984 18984->18967 16310 4d4360 __vbaChkstk 16311 4d43aa __vbaOnError __vbaStrCopy 16310->16311 16312 4fa530 16311->16312 16313 4d43de __vbaFreeStr __vbaStrToAnsi __vbaStrToAnsi 16312->16313 16403 483ef0 16313->16403 16404 483ef9 16403->16404 16405 4f9be0 16 API calls 16406 4f9d3e 16405->16406 16407 4f9d4f __vbaHresultCheckObj 16406->16407 16408 4f9d72 16406->16408 16409 4f9d7c __vbaFreeObj 16407->16409 16408->16409 16410 4f9dba #685 __vbaObjSet 16409->16410 16411 4f9da5 __vbaStrCopy 16409->16411 16412 4f9dea __vbaFreeObj 16410->16412 16411->16410 16413 4f9e45 16412->16413 16414 50ca60 __vbaChkstk __vbaOnError __vbaStrCopy #685 __vbaObjSet 16415 50caf9 __vbaFreeObj 16414->16415 16416 50cb18 __vbaVarForInit 16415->16416 16417 50ce7d #685 __vbaObjSet 16415->16417 16429 50cd0a 16416->16429 16420 50cebe __vbaFreeObj 16417->16420 16418 50cde0 6 API calls 16421 50cf40 59 API calls 16418->16421 16419 50cb8a 6 API calls 16422 50cf40 59 API calls 16419->16422 16423 50cef8 __vbaFreeVarList __vbaFreeVar __vbaFreeStr 16420->16423 16424 50ce5d __vbaFreeStr __vbaFreeVarList 16421->16424 16425 50cc07 __vbaFreeStr __vbaFreeVarList #685 __vbaObjSet 16422->16425 16424->16417 16426 50cc57 9 API calls 16425->16426 16426->16429 16427 50cd1b __vbaHresultCheckObj 16428 50cd48 __vbaStrCmp __vbaFreeObj 16427->16428 16428->16429 16430 50cd9c 16428->16430 16429->16418 16429->16419 16429->16427 16429->16428 16431 50cdae __vbaVarForNext 16429->16431 16430->16418 16431->16429 18281 4d3770 __vbaChkstk 18282 4d37ba __vbaOnError __vbaStrCopy 18281->18282 18283 4fa530 18282->18283 18284 4d37ee __vbaFreeStr #520 __vbaVarTstEq __vbaFreeVar 18283->18284 18285 4d38cc 12 API calls 18284->18285 18286 4d386b 18284->18286 18287 4d3a76 __vbaStrCmp 18285->18287 18288 4d3fb0 #685 __vbaObjSet 18285->18288 18289 4d3877 #520 __vbaStrVarMove __vbaStrMove __vbaFreeVarList 18286->18289 18290 4d3aab 9 API calls 18287->18290 18291 4d3a93 __vbaStrCopy 18287->18291 18292 4d3fe0 __vbaFreeObj 18288->18292 18289->18285 18290->18288 18293 4d3be0 __vbaStrCopy __vbaStrCopy __vbaInStr 18290->18293 18291->18290 18294 4d3fe9 __vbaFreeStr __vbaFreeStr 18292->18294 18295 4d3c2d __vbaStrCopy 18293->18295 18296 4d3c5b __vbaStrCat __vbaStrMove 18293->18296 18299 4fa530 18295->18299 18298 4fa530 18296->18298 18301 4d3c87 __vbaFreeStr __vbaStrToAnsi __vbaStrToAnsi 18298->18301 18300 4d3c4b __vbaFreeStr 18299->18300 18300->18294 18302 483ef0 18301->18302 18303 4d3cc0 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStrList 18302->18303 18304 4d3f54 __vbaStrCopy 18303->18304 18305 4d3d07 __vbaStrToAnsi 18303->18305 18307 4fa530 18304->18307 18336 483f24 18305->18336 18309 4d3f72 __vbaFreeStr 18307->18309 18312 4d3f7b __vbaStrCat __vbaStrMove 18309->18312 18314 4fa530 18312->18314 18317 4d3fa7 __vbaFreeStr 18314->18317 18317->18288 18337 483f2d 18336->18337 13915 4b4400 __vbaChkstk __vbaOnError __vbaStrCmp __vbaStrCmp 13916 4b44e7 13915->13916 13917 4b44a6 __vbaStrCmp 13915->13917 13980 51fb00 __vbaChkstk __vbaOnError #546 #663 13916->13980 13918 4b44c6 13917->13918 13921 4b4d9a #685 __vbaObjSet 13918->13921 13923 4b4dca __vbaFreeObj 13921->13923 13922 4b4550 __vbaFreeObj __vbaStrCopy 13924 4ecd60 13922->13924 13926 4b4e1a __vbaFreeStr __vbaFreeStr __vbaFreeStr 13923->13926 13925 4b4585 __vbaStrMove __vbaI4Str __vbaFreeStrList #685 __vbaObjSet 13924->13925 13927 4b45e4 13925->13927 13928 4b4618 13927->13928 13929 4b45f5 __vbaHresultCheckObj 13927->13929 13930 4b4622 __vbaFreeObj 13928->13930 13929->13930 13931 4b4659 __vbaI4Str __vbaStrCopy 13930->13931 13932 4b4697 #685 __vbaObjSet 13930->13932 13987 4f0ca0 __vbaChkstk __vbaOnError 13931->13987 13936 4b46e3 __vbaFreeObj __vbaStrCopy 13932->13936 13935 4b468e __vbaFreeStr 13935->13932 13937 4ecd60 13936->13937 13938 4b4718 __vbaStrMove __vbaI4Str __vbaFreeStrList #685 __vbaObjSet 13937->13938 13939 4b4777 13938->13939 13940 4b47ab 13939->13940 13941 4b4788 __vbaHresultCheckObj 13939->13941 13942 4b47b5 __vbaFreeObj 13940->13942 13941->13942 13943 4b482a #685 __vbaObjSet 13942->13943 13944 4b47ec __vbaI4Str __vbaStrCopy 13942->13944 13948 4b4876 __vbaFreeObj 13943->13948 13945 4f0ca0 418 API calls 13944->13945 13947 4b4821 __vbaFreeStr 13945->13947 13947->13943 14062 51c3a0 __vbaChkstk __vbaOnError __vbaStrCmp 13948->14062 13950 4b4899 __vbaStrMove __vbaStrCat __vbaStrMove 14134 4bd720 __vbaChkstk __vbaOnError __vbaStrCopy #685 __vbaObjSet 13950->14134 13952 4b48c4 __vbaStrMove __vbaI4Str __vbaFreeStrList #685 __vbaObjSet 13953 4b4927 13952->13953 13954 4b495b 13953->13954 13955 4b4938 __vbaHresultCheckObj 13953->13955 13956 4b4965 __vbaFreeObj 13954->13956 13955->13956 13957 4b4a21 #685 __vbaObjSet 13956->13957 13958 4b49a0 13956->13958 13963 4b4a6d __vbaFreeObj __vbaR8Str 13957->13963 13959 51c3a0 3421 API calls 13958->13959 13961 4b49ac __vbaStrMove __vbaStrMove __vbaStrCat __vbaStrMove 13959->13961 14156 4bd210 __vbaChkstk __vbaStrCopy __vbaOnError 13961->14156 13964 4b4aa2 __vbaFpI4 13963->13964 13965 4b4e55 13963->13965 13967 4b4bae __vbaStrCopy 13964->13967 13968 4b4abc #685 __vbaObjSet 13964->13968 13965->13965 13969 4b4bac 13967->13969 13970 4b4af3 13968->13970 13969->13921 13971 4b4be8 15 API calls 13969->13971 13972 4b4b27 13970->13972 13973 4b4b04 __vbaHresultCheckObj 13970->13973 13974 4b4d2c __vbaStrCopy 13971->13974 13975 4b4d54 __vbaInStr 13971->13975 13976 4b4b31 __vbaFreeObj 13972->13976 13973->13976 13974->13975 13975->13921 13977 4b4d72 __vbaStrCopy 13975->13977 13978 4b4b5a __vbaStrCopy 13976->13978 13979 4b4b84 __vbaStrCopy 13976->13979 13977->13921 13978->13969 13979->13969 14196 51f9f0 8 API calls 13980->14196 13983 51fca5 13983->13983 13984 51fbd4 __vbaFreeVarList __vbaStrR8 __vbaStrMove #685 __vbaObjSet 13985 51fc47 __vbaFreeObj 13984->13985 13986 4b4501 __vbaStrMove __vbaStrCopy __vbaFreeStr #685 __vbaObjSet 13985->13986 13986->13922 14199 51cef0 __vbaChkstk __vbaOnError __vbaStrCmp 13987->14199 13990 4f1968 #685 __vbaObjSet 13994 4f1998 __vbaFreeObj 13990->13994 13991 4f0d37 17 API calls 13992 50fba0 13991->13992 13993 4f0ec5 6 API calls 13992->13993 13995 4f0f47 __vbaStrCmp 13993->13995 14002 4f0f95 13993->14002 13996 4f19dc __vbaFreeStr __vbaFreeStr 13994->13996 13997 4f0f63 13995->13997 13995->14002 13996->13935 13999 4f0f77 __vbaStrCmp 13997->13999 13997->14002 13998 4f0fb0 14000 4f1907 __vbaStrCopy __vbaStrCopy 13998->14000 13999->14002 14000->13990 14001 4f0fdf 14004 4f1083 14001->14004 14278 4f2d70 __vbaChkstk __vbaOnError __vbaStrCmp 14001->14278 14002->13998 14002->14001 14273 50af90 __vbaChkstk __vbaOnError 14002->14273 14005 4f10ba #518 #617 __vbaVarTstEq __vbaFreeVarList 14004->14005 14006 4f1164 14004->14006 14008 4f114e __vbaStrCopy 14005->14008 14009 4f1136 __vbaStrCopy 14005->14009 14205 4fe150 __vbaChkstk __vbaOnError __vbaLenBstr 14006->14205 14008->14006 14009->14006 14011 4f1011 __vbaStrMove __vbaStrCmp __vbaStrCmp __vbaStrCmp __vbaFreeStr 14011->14004 14013 4f119b 14015 4f1395 __vbaStrCmp 14013->14015 14018 4f11ed __vbaStrCmp 14013->14018 14019 4f11c3 __vbaStrCopy 14013->14019 14014 4f1186 __vbaStrCopy 14014->14013 14016 4f13af 14015->14016 14017 4f13be #685 __vbaObjSet 14015->14017 14016->14017 14020 4f1689 #685 __vbaObjSet 14016->14020 14025 4f13ee 8 API calls 14017->14025 14022 4f120a 14018->14022 14245 4f2ff0 __vbaChkstk __vbaOnError __vbaStrCmp 14019->14245 14027 4f16b9 __vbaFreeObj __vbaStrCmp 14020->14027 14022->14015 14023 4f122f __vbaInStr 14022->14023 14023->14015 14026 4f1253 #712 __vbaStrMove __vbaStrCopy 14023->14026 14024 4f11de __vbaFreeStr 14024->14018 14028 4f149c 14025->14028 14029 50fba0 14026->14029 14030 4f16dc 14027->14030 14031 4f16eb __vbaChkstk __vbaChkstk __vbaChkstk __vbaLateMemCall 14027->14031 14032 4f14ad __vbaHresultCheckObj 14028->14032 14033 4f14d0 14028->14033 14034 4f129f __vbaStrMove __vbaFreeStr 14029->14034 14030->14031 14035 4f17c0 __vbaStrI4 __vbaStrMove __vbaStrCopy 14030->14035 14036 4f1814 #685 __vbaObjSet 14031->14036 14037 4f14da __vbaFreeObj 14032->14037 14033->14037 14034->14015 14038 4f12c8 #518 #617 __vbaVarTstEq __vbaFreeVarList 14034->14038 14039 5071e0 14035->14039 14044 4f184b 14036->14044 14037->14020 14040 4f1507 #685 __vbaObjSet 14037->14040 14041 4f135c __vbaStrCopy 14038->14041 14042 4f1344 __vbaStrCopy 14038->14042 14043 4f1801 __vbaFreeStrList 14039->14043 14048 4f1537 8 API calls 14040->14048 14045 4f1372 14041->14045 14042->14045 14043->14036 14046 4f187f 14044->14046 14047 4f185c __vbaHresultCheckObj 14044->14047 14045->14015 14049 4f1380 __vbaStrCopy 14045->14049 14050 4f1889 __vbaFreeObj 14046->14050 14047->14050 14053 4f15c2 14048->14053 14049->14015 14051 4f18b2 #685 __vbaObjSet 14050->14051 14056 4f18fe __vbaFreeObj 14051->14056 14054 4f15f6 14053->14054 14055 4f15d3 __vbaHresultCheckObj 14053->14055 14057 4f1600 __vbaFreeObj 14054->14057 14055->14057 14056->14000 14057->14020 14058 4f1629 __vbaStrCopy 14057->14058 14059 4fa530 14058->14059 14060 4f1647 __vbaFreeStr #685 __vbaObjSet 14059->14060 14061 4f1680 __vbaFreeObj 14060->14061 14061->14020 14063 51c410 __vbaStrCopy 14062->14063 14064 51c42b __vbaStrCopy 14062->14064 14065 51ce2d #685 __vbaObjSet 14063->14065 14066 4ecd60 14064->14066 14068 51ce5d __vbaFreeObj 14065->14068 14067 51c449 6 API calls 14066->14067 14069 4ecd60 14067->14069 14070 51ceb5 __vbaFreeStr __vbaFreeStr __vbaFreeStr 14068->14070 14071 51c4b0 7 API calls 14069->14071 14070->13950 14072 51c529 __vbaFreeObj __vbaStrCmp 14071->14072 14073 51c550 #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 14072->14073 14074 51c685 __vbaStrCopy 14072->14074 14075 51c5b7 #685 __vbaObjSet 14073->14075 14076 51c66e __vbaStrCopy 14073->14076 14077 51c69a #685 __vbaObjSet 14074->14077 14078 51c5ee 14075->14078 14089 51c655 14076->14089 14079 51c6ca __vbaFreeObj #685 __vbaObjSet 14077->14079 14080 51c622 14078->14080 14081 51c5ff __vbaHresultCheckObj 14078->14081 14082 51c703 __vbaFreeObj __vbaStrCmp 14079->14082 14083 51c62c __vbaFreeObj 14080->14083 14081->14083 14084 51c72a #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 14082->14084 14085 51c85f __vbaStrCopy 14082->14085 14086 51c657 __vbaStrCopy 14083->14086 14083->14089 14087 51c791 #685 __vbaObjSet 14084->14087 14088 51c848 __vbaStrCopy 14084->14088 14090 51c874 #685 __vbaObjSet 14085->14090 14086->14089 14093 51c7c8 14087->14093 14091 51c82f 14088->14091 14089->14077 14092 51c8a4 __vbaFreeObj __vbaStrCmp 14090->14092 14091->14090 14094 51c9a3 #685 __vbaObjSet 14092->14094 14095 51c8cb __vbaStrCmp 14092->14095 14096 51c7d9 __vbaHresultCheckObj 14093->14096 14097 51c7fc 14093->14097 14101 51c9d3 __vbaFreeObj __vbaStrCmp 14094->14101 14095->14094 14098 51c8e9 6 API calls 14095->14098 14099 51c806 __vbaFreeObj 14096->14099 14097->14099 14098->14094 14100 51c98f 14098->14100 14099->14091 14102 51c831 __vbaStrCopy 14099->14102 14387 4c1250 __vbaChkstk __vbaOnError #685 __vbaObjSet 14100->14387 14104 51cdc1 __vbaStrCopy 14101->14104 14105 51c9fa __vbaStrCopy 14101->14105 14102->14091 14107 51cdd4 __vbaStrCmp 14104->14107 14378 501700 __vbaChkstk __vbaOnError __vbaStrCmp __vbaLenBstr 14105->14378 14109 51ce18 __vbaStrCopy 14107->14109 14110 51cdee __vbaStrCopy __vbaStrCopy 14107->14110 14108 51ca1b __vbaStrMove __vbaStrCmp 14111 51cb61 __vbaStrCmp 14108->14111 14112 51ca44 14108->14112 14109->14065 14110->14065 14113 51cdbf 14111->14113 14114 51cb7f #619 __vbaVarTstNe __vbaFreeVar 14111->14114 14115 51ca70 14112->14115 14116 51ca54 __vbaNew2 14112->14116 14113->14107 14117 51cc1b __vbaStrCat __vbaStrMove #685 __vbaObjSet 14114->14117 14118 51cbec __vbaStrCmp __vbaStrBool __vbaStrMove 14114->14118 14120 51cad2 14115->14120 14121 51caaf __vbaHresultCheckObj 14115->14121 14116->14115 14119 51cc6c __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 14117->14119 14118->14117 14119->14113 14122 51ccdc #685 __vbaObjSet 14119->14122 14127 51cb0c __vbaHresultCheckObj 14120->14127 14128 51cb2f 14120->14128 14121->14120 14123 51cd13 14122->14123 14124 51cd24 __vbaHresultCheckObj 14123->14124 14125 51cd47 14123->14125 14126 51cd51 __vbaFreeObj 14124->14126 14125->14126 14126->14113 14129 51cd7a __vbaStrCmp 14126->14129 14130 51cb39 __vbaStrMove __vbaFreeObj 14127->14130 14128->14130 14129->14113 14131 51cd94 __vbaStrCopy 14129->14131 14130->14111 14135 4bd7b0 __vbaFreeObj 14134->14135 14136 518650 22 API calls 14135->14136 14137 4bd7cb 14136->14137 14138 4bd8e8 14137->14138 14139 4bd7d5 #685 __vbaObjSet 14137->14139 15542 4bdcb0 __vbaOnError 14138->15542 14141 4bd800 14139->14141 14144 4bd80b __vbaHresultCheckObj 14141->14144 14145 4bd825 14141->14145 14146 4bd82c __vbaFreeObj 14144->14146 14145->14146 14148 4bd8cb 14146->14148 14149 4bd84c 14146->14149 14147 4bd946 __vbaFreeObj 14150 4bd988 __vbaAryDestruct __vbaFreeStr 14147->14150 14152 4bdcb0 3596 API calls 14148->14152 14151 4c5070 1561 API calls 14149->14151 14150->13952 14153 4bd860 7 API calls 14151->14153 14154 4bd8db __vbaStrMove 14152->14154 14155 4bd8e6 __vbaStrCopy #685 __vbaObjSet 14153->14155 14154->14155 14155->14147 14157 4bd3e2 #685 __vbaObjSet 14156->14157 14158 4bd285 14156->14158 14160 4bd412 __vbaFreeObj 14157->14160 14159 4c2e80 46 API calls 14158->14159 14161 4bd295 #685 __vbaObjSet 14159->14161 14162 4bd509 #685 __vbaObjSet 14160->14162 14163 4bd42f #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 14160->14163 14165 4bd2bc __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 14161->14165 14168 4bd539 __vbaFreeObj __vbaLenBstr __vbaStrToAnsi 14162->14168 14163->14162 14164 4bd487 #685 __vbaObjSet 14163->14164 14170 4bd4b2 14164->14170 14166 4bd31d #685 __vbaObjSet 14165->14166 14167 4bd3b2 #685 __vbaObjSet 14165->14167 14169 477350 14168->14169 14197 51fab7 __vbaFreeObj 14196->14197 14198 51fae4 __vbaStrErrVarCopy #619 __vbaR8ErrVar 14197->14198 14198->13983 14198->13984 14200 51cf60 #685 __vbaObjSet 14199->14200 14201 51cf6f __vbaStrCmp 14199->14201 14203 51cfcf __vbaFreeObj 14200->14203 14201->14200 14204 4f0d0d __vbaStrCmp 14203->14204 14204->13990 14204->13991 14206 4fe1cc #518 __vbaVarDup #518 __vbaVarTstEq __vbaFreeVarList 14205->14206 14244 4fef4d #685 __vbaObjSet 14205->14244 14208 4fe25c 14206->14208 14209 4fe269 #518 __vbaVarDup #518 __vbaVarTstEq __vbaFreeVarList 14206->14209 14208->14209 14210 4fe2f9 14209->14210 14211 4fe306 #518 __vbaVarDup #518 __vbaVarTstEq __vbaFreeVarList 14209->14211 14210->14211 14212 4fe396 14211->14212 14213 4fe3a3 #518 __vbaVarDup #518 __vbaVarTstEq __vbaFreeVarList 14211->14213 14212->14213 14215 4fe433 14213->14215 14216 4fe440 6 API calls 14213->14216 14214 4fef99 __vbaFreeObj 14217 4f1174 14214->14217 14215->14216 14218 4fe4fe 14216->14218 14219 4fe50b 6 API calls 14216->14219 14217->14013 14217->14014 14218->14219 14220 4fe5c9 14219->14220 14221 4fe5d6 6 API calls 14219->14221 14220->14221 14222 4fe694 14221->14222 14223 4fe6a1 6 API calls 14221->14223 14222->14223 14224 4fe75f 14223->14224 14225 4fe76c 6 API calls 14223->14225 14224->14225 14226 4fe82a 14225->14226 14227 4fe837 6 API calls 14225->14227 14226->14227 14228 4fe8f5 14227->14228 14229 4fe902 6 API calls 14227->14229 14228->14229 14230 4fe9cd 6 API calls 14229->14230 14231 4fe9c0 14229->14231 14232 4fea8b 14230->14232 14233 4fea98 6 API calls 14230->14233 14231->14230 14232->14233 14234 4feb56 14233->14234 14235 4feb63 6 API calls 14233->14235 14234->14235 14236 4fec2e 6 API calls 14235->14236 14237 4fec21 14235->14237 14238 4fecec 14236->14238 14239 4fecf9 6 API calls 14236->14239 14237->14236 14238->14239 14240 4fedb7 14239->14240 14241 4fedc4 6 API calls 14239->14241 14240->14241 14242 4fee8f 6 API calls 14241->14242 14243 4fee82 14241->14243 14242->14244 14243->14242 14244->14214 14246 4f3319 #685 __vbaObjSet 14245->14246 14247 4f3064 __vbaStrCmp 14245->14247 14251 4f3340 __vbaFreeObj 14246->14251 14248 4f32cf __vbaStrCmp 14247->14248 14249 4f3085 __vbaStrCopy __vbaStrCopy 14247->14249 14248->14246 14250 4f3309 14248->14250 14292 50cf40 __vbaChkstk __vbaOnError __vbaStrCmp 14249->14292 14250->14246 14253 4f3363 __vbaFreeStr 14251->14253 14253->14024 14254 4f30ba __vbaFreeStr 14255 4f2d70 20 API calls 14254->14255 14256 4f30cf __vbaStrMove 14255->14256 14257 4f30f0 __vbaStrCmp 14256->14257 14271 4f31d3 14256->14271 14258 4f310c __vbaStrCmp 14257->14258 14259 4f3140 __vbaStrCmp 14257->14259 14261 4f313e 14258->14261 14262 4f3128 __vbaStrCopy 14258->14262 14263 4f315d __vbaStrCopy 14259->14263 14264 4f3174 __vbaStrCmp 14259->14264 14260 4f327f __vbaStrCopy 14265 50cf40 59 API calls 14260->14265 14261->14264 14262->14261 14263->14264 14266 4f31a5 14264->14266 14267 4f3190 __vbaStrCopy 14264->14267 14268 4f32ad __vbaFreeStr __vbaStrCopy 14265->14268 14332 4f92b0 __vbaChkstk __vbaOnError __vbaStrCmp 14266->14332 14267->14266 14268->14246 14270 4f31cd 14270->14271 14272 4f31f2 __vbaStrCmp 14270->14272 14271->14260 14272->14271 14376 474cf0 14273->14376 14279 4f2de4 __vbaStrCmp 14278->14279 14280 4f2f60 #685 __vbaObjSet 14278->14280 14281 4f2ede __vbaStrCopy 14279->14281 14282 4f2e05 __vbaStrCopy __vbaStrCopy 14279->14282 14285 4f2f87 __vbaFreeObj 14280->14285 14284 4f2ef4 __vbaStrCmp __vbaStrCmp 14281->14284 14283 4feff0 14282->14283 14286 4f2e47 __vbaStrMove __vbaFreeStrList __vbaFreeVar __vbaStrCmp __vbaStrCmp 14283->14286 14287 4f2f4d __vbaStrCopy 14284->14287 14288 4f2f2d 14284->14288 14289 4f2fd0 __vbaFreeStr 14285->14289 14290 4f2ec7 __vbaStrCopy 14286->14290 14291 4f2ea7 14286->14291 14287->14280 14288->14287 14289->14011 14290->14284 14291->14290 14293 50cfb4 14292->14293 14294 50d4de #685 __vbaObjSet 14292->14294 14295 50cfca #685 __vbaObjSet 14293->14295 14296 50d13d __vbaStrCmp 14293->14296 14298 50d50e __vbaFreeObj 14294->14298 14301 50d00a __vbaFreeObj __vbaStrCopy __vbaStrCopy 14295->14301 14296->14294 14297 50d15d 14296->14297 14297->14294 14299 50d16a #685 __vbaObjSet 14297->14299 14300 50d54e __vbaFreeStr 14298->14300 14303 50d19a __vbaFreeObj __vbaFileOpen #685 __vbaObjSet 14299->14303 14300->14254 14302 509410 14301->14302 14304 50d055 __vbaStrMove __vbaFreeStrList __vbaFreeVar #685 __vbaObjSet 14302->14304 14305 50d206 14303->14305 14306 50d0a7 14304->14306 14309 50d211 __vbaHresultCheckObj 14305->14309 14310 50d22e 14305->14310 14307 50d0b2 __vbaHresultCheckObj 14306->14307 14308 50d0cf 14306->14308 14311 50d0d9 __vbaStrCmp __vbaFreeObj 14307->14311 14308->14311 14312 50d238 __vbaFreeObj 14309->14312 14310->14312 14313 50d112 __vbaStrCopy 14311->14313 14314 50d127 __vbaI4Str 14311->14314 14315 50d2b8 #685 __vbaObjSet 14312->14315 14316 50d258 __vbaFileClose #685 __vbaObjSet 14312->14316 14313->14314 14314->14296 14318 50d2e3 14315->14318 14317 50d297 __vbaFreeObj __vbaFileOpen 14316->14317 14317->14315 14319 50d30b 14318->14319 14320 50d2ee __vbaHresultCheckObj 14318->14320 14321 50d315 __vbaFreeObj 14319->14321 14320->14321 14322 50d395 #685 __vbaObjSet 14321->14322 14323 50d335 __vbaFileClose #685 __vbaObjSet 14321->14323 14325 50d3c0 14322->14325 14324 50d374 __vbaFreeObj __vbaFileOpen 14323->14324 14324->14322 14326 50d3e8 14325->14326 14327 50d3cb __vbaHresultCheckObj 14325->14327 14328 50d3f2 __vbaFreeObj 14326->14328 14327->14328 14329 50d496 __vbaFileClose #685 __vbaObjSet 14328->14329 14330 50d416 6 API calls 14328->14330 14331 50d4d5 __vbaFreeObj 14329->14331 14330->14329 14331->14294 14333 51cef0 7 API calls 14332->14333 14334 4f9328 __vbaStrCmp 14333->14334 14335 4f935b 16 API calls 14334->14335 14336 4f9b33 #685 __vbaObjSet 14334->14336 14337 50fba0 14335->14337 14338 4f9b63 __vbaFreeObj 14336->14338 14339 4f94d2 __vbaStrMove __vbaFreeStr #712 __vbaStrMove __vbaStrCopy 14337->14339 14340 4f9ba7 __vbaFreeStr __vbaFreeStr 14338->14340 14341 4f954e 14339->14341 14350 4f95cd 14339->14350 14340->14270 14342 4f2d70 20 API calls 14341->14342 14346 4f955a __vbaStrMove __vbaStrCmp __vbaStrCmp __vbaStrCmp __vbaFreeStr 14342->14346 14343 4f96ae 14345 4fe150 110 API calls 14343->14345 14344 4f9604 #518 #617 __vbaVarTstEq __vbaFreeVarList 14347 4f9698 __vbaStrCopy 14344->14347 14348 4f9680 __vbaStrCopy 14344->14348 14349 4f96be 14345->14349 14346->14350 14347->14343 14348->14343 14350->14343 14350->14344 14377 474cf9 14376->14377 14379 5037f9 __vbaStrCopy __vbaStrCopy __vbaStrCopy __vbaStrCmp 14378->14379 14380 5041c3 __vbaLenBstr 14379->14380 14381 504404 #685 __vbaObjSet 14380->14381 14382 5041dd #619 __vbaVarTstEq __vbaFreeVar 14380->14382 14385 504434 __vbaFreeObj 14381->14385 14382->14381 14383 50424e __vbaLenBstr 14382->14383 14383->14381 14384 5044bf __vbaErrorOverflow 14383->14384 14386 50448f __vbaFreeStr __vbaFreeStr __vbaFreeStr 14385->14386 14386->14108 14388 4c12e1 8 API calls 14387->14388 14389 4c13f0 #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 14388->14389 14390 4c14f5 14388->14390 14391 4c1457 #685 __vbaObjSet 14389->14391 14392 4c153e 14390->14392 14393 4c1550 #685 __vbaObjSet 14390->14393 14394 4c148e __vbaHresultCheckObj 14391->14394 14395 4c21d9 #685 __vbaObjSet 14392->14395 14396 4c1580 __vbaFreeObj 14393->14396 14399 4c14cc __vbaFreeObj 14394->14399 14400 4c2209 __vbaFreeObj 14395->14400 14472 518650 16 API calls 14396->14472 14399->14390 14402 4c226e __vbaFreeVar __vbaAryDestruct 14400->14402 14401 4c159b 14403 518650 22 API calls 14401->14403 14402->14094 14404 4c15af 14403->14404 14405 4c1ded #518 __vbaInStrVar __vbaVarTstNe __vbaFreeVarList 14404->14405 14406 4c15c2 #518 #518 __vbaVarTstNe __vbaFreeVarList 14404->14406 14407 4c214d __vbaStrCmp 14405->14407 14408 4c1e90 14405->14408 14406->14392 14409 4c1648 #685 __vbaObjSet 14406->14409 14411 4c2169 __vbaStrCopy 14407->14411 14412 4c2180 14407->14412 14542 4c5070 __vbaChkstk __vbaOnError 14408->14542 14415 4c1678 __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 14409->14415 14411->14412 14757 515040 7 API calls 14412->14757 14417 4c17ad 14415->14417 14418 4c16e8 #685 __vbaObjSet 14415->14418 14479 4c22a0 __vbaChkstk __vbaOnError #685 __vbaObjSet 14417->14479 14425 4c171f 14418->14425 14473 518896 #685 __vbaObjSet 14472->14473 14474 51884d __vbaInStr 14472->14474 14477 5188c6 __vbaFreeObj 14473->14477 14474->14473 14475 51886b __vbaInStr 14474->14475 14475->14473 14476 518889 14475->14476 14476->14473 14478 518929 __vbaFreeStr 14477->14478 14478->14401 14543 4c50d6 #685 __vbaObjSet 14542->14543 14545 4c5132 __vbaFreeObj #518 #617 __vbaVarTstNe __vbaFreeVarList 14543->14545 14758 5150e4 7 API calls 14757->14758 14759 516d9e #685 __vbaObjSet 14757->14759 15823 4bd9c0 __vbaChkstk __vbaStrCopy __vbaOnError #685 __vbaObjSet 15542->15823 15544 4bdd3c __vbaRedim __vbaStrToAnsi 15545 477350 15544->15545 15546 4bdd80 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStr 15545->15546 15547 4be5c1 __vbaStrToAnsi 15546->15547 15548 4bddb5 __vbaAryLock 15546->15548 15549 477350 15547->15549 15550 4bddca 15548->15550 15551 4bdde7 __vbaGenerateBoundsError 15548->15551 15553 4be5e5 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStr 15549->15553 15550->15551 15554 4bddd0 15550->15554 15552 4bdde3 15551->15552 15558 4bde06 __vbaSetSystemError __vbaAryUnlock #685 __vbaObjSet 15552->15558 15555 4becf3 15553->15555 15556 4be617 __vbaAryLock 15553->15556 15554->15552 15557 4bddda __vbaGenerateBoundsError 15554->15557 15875 4f1a10 __vbaChkstk __vbaOnError __vbaStrCopy __vbaStrCmp 15555->15875 15560 4be649 __vbaGenerateBoundsError 15556->15560 15561 4be62c 15556->15561 15557->15552 15565 4bde37 __vbaFreeObj __vbaUbound 15558->15565 15564 4be645 15560->15564 15561->15560 15563 4be632 15561->15563 15563->15564 15567 4be63c __vbaGenerateBoundsError 15563->15567 15571 4be668 __vbaSetSystemError __vbaAryUnlock #685 __vbaObjSet 15564->15571 15568 4be0ce #685 __vbaObjSet 15565->15568 15569 4bde54 15565->15569 15567->15564 15575 4be0dd __vbaFreeObj #685 __vbaObjSet 15568->15575 15572 4bde81 __vbaGenerateBoundsError 15569->15572 15576 4bde61 __vbaUbound 15569->15576 15574 4be699 __vbaFreeObj __vbaUbound 15571->15574 15578 4bde7d 15572->15578 15579 4be930 #685 __vbaObjSet 15574->15579 15580 4be6b6 15574->15580 15585 4be0f7 __vbaFreeObj __vbaAryCopy __vbaUbound 15575->15585 15576->15578 15581 4bde77 __vbaGenerateBoundsError 15576->15581 15578->15568 15583 4bde97 #685 __vbaObjSet 15578->15583 15593 4be93f __vbaFreeObj #685 __vbaObjSet 15579->15593 15584 4be6e3 __vbaGenerateBoundsError 15580->15584 15588 4be6c3 __vbaUbound 15580->15588 15581->15578 15587 4bdeaf 15583->15587 15591 4be6df 15584->15591 15589 4be4eb #685 __vbaObjSet 15585->15589 15590 4be11f #685 __vbaObjSet 15585->15590 15594 4bdeb5 __vbaHresultCheckObj 15587->15594 15595 4bdec4 __vbaFreeObj 15587->15595 15588->15591 15596 4be6d9 __vbaGenerateBoundsError 15588->15596 15601 4be4fe __vbaFreeObj #518 #619 __vbaVarTstEq __vbaFreeVarList 15589->15601 15600 4be137 15590->15600 15591->15579 15604 4be959 __vbaFreeObj __vbaAryCopy __vbaUbound 15593->15604 15594->15595 15595->15568 15596->15591 15609 4be13d __vbaHresultCheckObj 15600->15609 15610 4be14c __vbaFreeObj 15600->15610 15844 4c0d20 __vbaChkstk __vbaOnError #685 __vbaObjSet 15601->15844 15604->15589 15609->15610 15610->15589 15824 4bda47 __vbaFreeObj #578 #685 __vbaObjSet 15823->15824 15825 4bda9d 15824->15825 15826 4bdaa8 __vbaHresultCheckObj 15825->15826 15827 4bdac2 15825->15827 15828 4bdac9 __vbaFreeObj 15826->15828 15827->15828 15829 4bdafb #685 __vbaObjSet 15828->15829 15830 4bdc2e #685 __vbaObjSet 15828->15830 15831 4bdb22 __vbaFreeObj __vbaStrToAnsi 15829->15831 15832 4bdc62 __vbaFreeObj 15830->15832 15928 476f40 15831->15928 15834 4bdc85 __vbaFreeStr 15832->15834 15834->15544 15876 4f1a95 __vbaStrCopy 15875->15876 15877 4f1ab0 #525 __vbaStrMove __vbaStrToAnsi __vbaLenBstr 15875->15877 15879 4f1d84 __vbaStrCmp 15876->15879 15930 475a14 15877->15930 15881 4f1dd3 #685 __vbaObjSet 15879->15881 15882 4f1da1 15879->15882 15890 4f1e03 __vbaFreeObj 15881->15890 15932 4f1e80 9 API calls 15882->15932 15893 4f1e4c __vbaFreeStr __vbaFreeStr 15890->15893 15929 476f49 15928->15929 15931 475a1d 15930->15931 15933 4f1f58 #619 __vbaVarTstNe __vbaFreeVar 15932->15933 15934 4f1fe6 14 API calls 15932->15934 15933->15934 19392 4bc080 __vbaChkstk __vbaOnError __vbaStrCopy __vbaStrCmp 19393 4bc151 __vbaInStr 19392->19393 19394 4bc120 19392->19394 19396 4bc179 19393->19396 19397 4bc2ef __vbaStrCmp 19393->19397 19428 52d4c0 __vbaChkstk __vbaOnError __vbaStrCmp __vbaStrCmp 19394->19428 19446 4d5390 __vbaChkstk __vbaOnError __vbaStrCmp 19396->19446 19398 4bc62f __vbaStrCopy #685 __vbaObjSet 19397->19398 19399 4bc313 __vbaStrCat __vbaStrMove 19397->19399 19405 4bc672 __vbaFreeObj 19398->19405 19402 4d0ae0 330 API calls 19399->19402 19400 4bc12c __vbaStrMove __vbaStrCopy __vbaFreeStr 19400->19393 19404 4bc340 6 API calls 19402->19404 19403 4bc185 __vbaStrMove __vbaStrCmp __vbaFreeStr 19403->19397 19406 4bc1c3 19403->19406 19407 4bc43b __vbaStrMove __vbaStrCmp 19404->19407 19408 4bc3a7 8 API calls 19404->19408 19409 4bc6dc __vbaFreeStr 19405->19409 19410 4d5390 1111 API calls 19406->19410 19415 4bc48e __vbaStrCat __vbaStrMove 19407->19415 19416 4bc4cd #520 __vbaVarTstNe __vbaFreeVar 19407->19416 19411 4fa530 19408->19411 19412 4bc1cf 12 API calls 19410->19412 19413 4bc41b __vbaFreeStrList 19411->19413 19412->19397 19413->19398 19417 4d0d30 19415->19417 19418 4bc541 19416->19418 19425 4bc607 19416->19425 19419 4bc4bf __vbaFreeStr 19417->19419 19420 51c3a0 3421 API calls 19418->19420 19419->19398 19421 4bc54d __vbaStrMove __vbaStrCopy __vbaStrCopy 19420->19421 19422 506210 116 API calls 19421->19422 19423 4bc58f __vbaStrMove __vbaFreeStrList __vbaStrCmp 19422->19423 19424 4bc5cb __vbaStrCat __vbaStrMove 19423->19424 19423->19425 19426 4d0d30 19424->19426 19425->19398 19427 4bc5fc __vbaFreeStr 19426->19427 19427->19425 19429 52d550 __vbaStrCopy 19428->19429 19430 52d56b 19428->19430 19431 52d90f #685 __vbaObjSet 19429->19431 19581 52d280 8 API calls 19430->19581 19436 52d93f __vbaFreeObj 19431->19436 19439 52d99c __vbaFreeStr __vbaFreeStr __vbaFreeStr 19436->19439 19439->19400 19447 4d5469 __vbaStrCopy 19446->19447 19448 4d541a __vbaStrCmp 19446->19448 19449 4ecd60 19447->19449 19450 4d544f __vbaStrCopy 19448->19450 19451 4d5437 __vbaStrCopy 19448->19451 19452 4d5487 6 API calls 19449->19452 19453 4d5464 19450->19453 19451->19453 19454 4d553c __vbaStrCopy 19452->19454 19455 4d54ea 19452->19455 19456 4d6689 #685 __vbaObjSet 19453->19456 19457 4d555e 19454->19457 19459 4d54fa #520 __vbaStrVarMove __vbaStrMove __vbaFreeVarList 19455->19459 19458 4d66b9 __vbaFreeObj 19456->19458 19690 4d4e80 __vbaChkstk __vbaOnError __vbaStrCmp 19457->19690 19461 4d671f __vbaFreeStr __vbaFreeStr __vbaFreeStr 19458->19461 19459->19457 19461->19403 19462 4d556a __vbaStrMove __vbaStrCmp 19463 4d558f __vbaStrCat __vbaStrMove 19462->19463 19464 4d5602 __vbaStrCmp 19462->19464 19465 4ecd60 19463->19465 19466 4d5949 __vbaStrCat __vbaStrMove 19464->19466 19467 4d5620 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19464->19467 19468 4d55b9 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 19465->19468 19469 4fa530 19466->19469 19470 4ecd60 19467->19470 19468->19464 19471 4d5973 __vbaFreeStr __vbaStrCmp 19469->19471 19472 4d5662 6 API calls 19470->19472 19473 4d5996 19471->19473 19488 4d585b 19471->19488 19474 4d586f __vbaStrCat __vbaStrMove 19472->19474 19475 4d56d3 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19472->19475 19473->19488 19494 4d59af __vbaStrCat __vbaStrMove __vbaStrCopy 19473->19494 19476 4fa530 19474->19476 19477 4ecd60 19475->19477 19482 4d5899 __vbaFreeStr __vbaStrCmp 19476->19482 19483 4d5715 6 API calls 19477->19483 19478 4d5a10 __vbaStrCopy 19484 4ecd60 19478->19484 19479 4d60e2 __vbaStrCmp 19480 4d60fc 19479->19480 19481 4d6107 __vbaStrCopy 19479->19481 19480->19481 19485 4d633e __vbaStrCmp 19480->19485 19486 4ecd60 19481->19486 19487 4d58c0 19482->19487 19482->19488 19483->19488 19489 4d5786 __vbaStrCat __vbaStrMove 19483->19489 19490 4d5a2e 6 API calls 19484->19490 19492 4d635c 19485->19492 19493 4d6606 __vbaStrCopy __vbaStrCopy 19485->19493 19491 4d6125 6 API calls 19486->19491 19487->19488 19522 4d58d9 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy 19487->19522 19488->19478 19488->19479 19495 4fa530 19489->19495 19496 4d5a95 __vbaStrCopy __vbaStrCopy __vbaStrCopy 19490->19496 19497 4d5b41 __vbaStrCopy 19490->19497 19501 4d618c __vbaStrCopy __vbaStrCopy __vbaStrCopy 19491->19501 19502 4d622a __vbaStrCmp 19491->19502 19503 52d4c0 261 API calls 19492->19503 19498 4d662e __vbaStrCmp 19493->19498 19504 4efae0 19494->19504 19505 4d57b0 __vbaFreeStr __vbaStrCmp 19495->19505 19499 4d13b0 335 API calls 19496->19499 19500 4d5b63 __vbaStrCmp 19497->19500 19506 4d6648 __vbaStrCopy 19498->19506 19507 4d6661 __vbaStrCopy 19498->19507 19508 4d5adb #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList 19499->19508 19509 4d5fea __vbaStrCat __vbaStrMove 19500->19509 19510 4d5b81 7 API calls 19500->19510 19511 4d13b0 335 API calls 19501->19511 19502->19485 19514 4d6248 19502->19514 19512 4d6368 __vbaStrMove __vbaInStr 19503->19512 19513 4d59eb __vbaFreeStrList 19504->19513 19505->19488 19515 4d57d7 19505->19515 19516 4d6676 __vbaStrCopy 19506->19516 19507->19516 19508->19500 19518 4fa530 19509->19518 19858 4d13b0 __vbaChkstk __vbaStrCopy __vbaOnError 19510->19858 19519 4d61d3 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList 19511->19519 19520 4d63a6 __vbaStrCmp 19512->19520 19521 4d6391 __vbaStrCopy 19512->19521 19513->19488 19534 4d625e __vbaStrCat __vbaStrMove __vbaStrCopy 19514->19534 19535 4d6329 __vbaStrCopy 19514->19535 19515->19488 19537 4d57f0 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy 19515->19537 19516->19456 19524 4d6014 __vbaFreeStr __vbaStrCmp 19518->19524 19519->19502 19525 4d65ef __vbaStrCopy 19520->19525 19526 4d63c4 __vbaInStr 19520->19526 19521->19520 19527 4efae0 19522->19527 19523 4d5bf6 6 API calls 19528 4d5eaf __vbaStrCat __vbaStrMove 19523->19528 19529 4d5c73 7 API calls 19523->19529 19524->19479 19530 4d603b 19524->19530 19533 4d65d6 19525->19533 19531 4d65d8 __vbaStrCopy 19526->19531 19532 4d63e6 8 API calls 19526->19532 19536 4d592d __vbaFreeStrList 19527->19536 19539 4fa530 19528->19539 19538 4d13b0 335 API calls 19529->19538 19530->19479 19556 4d605c __vbaStrCat __vbaStrMove __vbaStrCopy 19530->19556 19531->19533 19540 4d64c9 19532->19540 19541 4d65c1 __vbaStrCopy 19532->19541 19533->19498 19542 4efae0 19534->19542 19535->19485 19536->19488 19544 4efae0 19537->19544 19545 4d5ce8 6 API calls 19538->19545 19546 4d5ed9 __vbaFreeStr __vbaStrCmp 19539->19546 19552 4d64df __vbaStrCat __vbaStrMove __vbaStrCopy 19540->19552 19553 4d65aa __vbaStrCopy 19540->19553 19541->19533 19543 4d629b __vbaFreeStrList __vbaStrCat __vbaStrMove 19542->19543 19547 4efae0 19543->19547 19548 4d5844 __vbaFreeStrList 19544->19548 19549 4d5e9b 19545->19549 19550 4d5d65 __vbaStrCat __vbaStrMove 19545->19550 19546->19549 19551 4d5f00 19546->19551 19554 4d62dd __vbaFreeStr __vbaStrCopy __vbaStrCopy 19547->19554 19548->19488 19549->19479 19555 4fa530 19550->19555 19551->19549 19564 4d5f21 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy 19551->19564 19557 4efae0 19552->19557 19553->19533 19558 4efae0 19554->19558 19559 4d5d8f __vbaFreeStr __vbaStrCmp 19555->19559 19560 4efae0 19556->19560 19561 4d651c __vbaFreeStrList __vbaStrCat __vbaStrMove 19557->19561 19562 4d6316 __vbaFreeStrList 19558->19562 19559->19549 19567 4d5db6 19559->19567 19563 4d6098 __vbaFreeStrList __vbaStrCat __vbaStrMove 19560->19563 19566 4efae0 19561->19566 19562->19535 19565 4efae0 19563->19565 19568 4efae0 19564->19568 19569 4d60d9 __vbaFreeStr 19565->19569 19570 4d655e __vbaFreeStr __vbaStrCopy __vbaStrCopy 19566->19570 19567->19549 19573 4d5dd7 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy 19567->19573 19571 4d5f75 __vbaFreeStrList __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19568->19571 19569->19479 19572 4efae0 19570->19572 19574 4efae0 19571->19574 19575 4d6597 __vbaFreeStrList 19572->19575 19576 4efae0 19573->19576 19577 4d5fd2 __vbaFreeStrList 19574->19577 19575->19553 19578 4d5e2b __vbaFreeStrList __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19576->19578 19577->19549 19579 4efae0 19578->19579 19580 4d5e88 __vbaFreeStrList 19579->19580 19580->19549 19686 47520c 19581->19686 19687 475215 19686->19687 19691 4d4f0b __vbaStrCopy 19690->19691 19692 4d4ef0 __vbaStrCopy 19690->19692 19694 4ecd60 19691->19694 19693 4d52d3 #685 __vbaObjSet 19692->19693 19696 4d5303 __vbaFreeObj 19693->19696 19695 4d4f29 __vbaStrMove __vbaFreeStr __vbaStrCmp 19694->19695 19697 4d519b __vbaStrCmp 19695->19697 19698 4d4f5b __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19695->19698 19699 4d5356 __vbaFreeStr __vbaFreeStr 19696->19699 19700 4d51ca __vbaStrCmp 19697->19700 19701 4d51b5 __vbaStrCopy 19697->19701 19702 4ecd60 19698->19702 19699->19462 19703 4d51e8 #619 __vbaVarTstEq __vbaFreeVar 19700->19703 19704 4d5291 __vbaStrCmp 19700->19704 19701->19700 19705 4d4f9d 6 API calls 19702->19705 19703->19704 19708 4d523d __vbaLenBstr 19703->19708 19704->19693 19709 4d52ab __vbaStrCopy __vbaStrCopy 19704->19709 19706 4d514e __vbaStrCat __vbaStrMove __vbaStrCopy 19705->19706 19707 4d500e __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19705->19707 19713 4efae0 19706->19713 19710 4ecd60 19707->19710 19711 4d537d __vbaErrorOverflow 19708->19711 19712 4d5264 #617 __vbaStrVarMove __vbaStrMove __vbaFreeVar 19708->19712 19709->19693 19714 4d5050 6 API calls 19710->19714 19715 4d5390 __vbaChkstk __vbaOnError __vbaStrCmp 19711->19715 19712->19704 19716 4d5192 __vbaFreeStr 19713->19716 19717 4d50bd __vbaStrCopy __vbaStrCopy 19714->19717 19718 4d50ff __vbaStrCat __vbaStrMove __vbaStrCopy 19714->19718 19719 4d5469 __vbaStrCopy 19715->19719 19720 4d541a __vbaStrCmp 19715->19720 19716->19697 19721 4efae0 19717->19721 19723 4efae0 19718->19723 19722 4ecd60 19719->19722 19724 4d544f __vbaStrCopy 19720->19724 19725 4d5437 __vbaStrCopy 19720->19725 19726 4d50f4 __vbaFreeStr 19721->19726 19727 4d5487 6 API calls 19722->19727 19728 4d5143 __vbaFreeStr 19723->19728 19729 4d5464 19724->19729 19725->19729 19730 4d514c 19726->19730 19731 4d553c __vbaStrCopy 19727->19731 19732 4d54ea 19727->19732 19728->19730 19733 4d6689 #685 __vbaObjSet 19729->19733 19730->19697 19734 4d555e 19731->19734 19736 4d54fa #520 __vbaStrVarMove __vbaStrMove __vbaFreeVarList 19732->19736 19735 4d66b9 __vbaFreeObj 19733->19735 19737 4d4e80 596 API calls 19734->19737 19738 4d671f __vbaFreeStr __vbaFreeStr __vbaFreeStr 19735->19738 19736->19734 19739 4d556a __vbaStrMove __vbaStrCmp 19737->19739 19738->19462 19740 4d558f __vbaStrCat __vbaStrMove 19739->19740 19741 4d5602 __vbaStrCmp 19739->19741 19742 4ecd60 19740->19742 19743 4d5949 __vbaStrCat __vbaStrMove 19741->19743 19744 4d5620 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19741->19744 19745 4d55b9 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 19742->19745 19746 4fa530 19743->19746 19747 4ecd60 19744->19747 19745->19741 19748 4d5973 __vbaFreeStr __vbaStrCmp 19746->19748 19749 4d5662 6 API calls 19747->19749 19763 4d5996 19748->19763 19764 4d585b 19748->19764 19750 4d586f __vbaStrCat __vbaStrMove 19749->19750 19751 4d56d3 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19749->19751 19752 4fa530 19750->19752 19753 4ecd60 19751->19753 19758 4d5899 __vbaFreeStr __vbaStrCmp 19752->19758 19759 4d5715 6 API calls 19753->19759 19754 4d5a10 __vbaStrCopy 19760 4ecd60 19754->19760 19755 4d60e2 __vbaStrCmp 19756 4d60fc 19755->19756 19757 4d6107 __vbaStrCopy 19755->19757 19756->19757 19761 4d633e __vbaStrCmp 19756->19761 19762 4ecd60 19757->19762 19758->19764 19765 4d58c0 19758->19765 19759->19764 19766 4d5786 __vbaStrCat __vbaStrMove 19759->19766 19767 4d5a2e 6 API calls 19760->19767 19769 4d635c 19761->19769 19770 4d6606 __vbaStrCopy __vbaStrCopy 19761->19770 19768 4d6125 6 API calls 19762->19768 19763->19764 19771 4d59af __vbaStrCat __vbaStrMove __vbaStrCopy 19763->19771 19764->19754 19764->19755 19765->19764 19799 4d58d9 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy 19765->19799 19772 4fa530 19766->19772 19773 4d5a95 __vbaStrCopy __vbaStrCopy __vbaStrCopy 19767->19773 19774 4d5b41 __vbaStrCopy 19767->19774 19778 4d618c __vbaStrCopy __vbaStrCopy __vbaStrCopy 19768->19778 19779 4d622a __vbaStrCmp 19768->19779 19780 52d4c0 261 API calls 19769->19780 19775 4d662e __vbaStrCmp 19770->19775 19781 4efae0 19771->19781 19782 4d57b0 __vbaFreeStr __vbaStrCmp 19772->19782 19776 4d13b0 335 API calls 19773->19776 19777 4d5b63 __vbaStrCmp 19774->19777 19783 4d6648 __vbaStrCopy 19775->19783 19784 4d6661 __vbaStrCopy 19775->19784 19785 4d5adb #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList 19776->19785 19786 4d5fea __vbaStrCat __vbaStrMove 19777->19786 19787 4d5b81 7 API calls 19777->19787 19788 4d13b0 335 API calls 19778->19788 19779->19761 19791 4d6248 19779->19791 19789 4d6368 __vbaStrMove __vbaInStr 19780->19789 19790 4d59eb __vbaFreeStrList 19781->19790 19782->19764 19792 4d57d7 19782->19792 19793 4d6676 __vbaStrCopy 19783->19793 19784->19793 19785->19777 19795 4fa530 19786->19795 19794 4d13b0 335 API calls 19787->19794 19796 4d61d3 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList 19788->19796 19797 4d63a6 __vbaStrCmp 19789->19797 19798 4d6391 __vbaStrCopy 19789->19798 19790->19764 19811 4d625e __vbaStrCat __vbaStrMove __vbaStrCopy 19791->19811 19812 4d6329 __vbaStrCopy 19791->19812 19792->19764 19814 4d57f0 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy 19792->19814 19793->19733 19800 4d5bf6 6 API calls 19794->19800 19801 4d6014 __vbaFreeStr __vbaStrCmp 19795->19801 19796->19779 19802 4d65ef __vbaStrCopy 19797->19802 19803 4d63c4 __vbaInStr 19797->19803 19798->19797 19804 4efae0 19799->19804 19805 4d5eaf __vbaStrCat __vbaStrMove 19800->19805 19806 4d5c73 7 API calls 19800->19806 19801->19755 19807 4d603b 19801->19807 19810 4d65d6 19802->19810 19808 4d65d8 __vbaStrCopy 19803->19808 19809 4d63e6 8 API calls 19803->19809 19813 4d592d __vbaFreeStrList 19804->19813 19816 4fa530 19805->19816 19815 4d13b0 335 API calls 19806->19815 19807->19755 19833 4d605c __vbaStrCat __vbaStrMove __vbaStrCopy 19807->19833 19808->19810 19817 4d64c9 19809->19817 19818 4d65c1 __vbaStrCopy 19809->19818 19810->19775 19819 4efae0 19811->19819 19812->19761 19813->19764 19821 4efae0 19814->19821 19822 4d5ce8 6 API calls 19815->19822 19823 4d5ed9 __vbaFreeStr __vbaStrCmp 19816->19823 19829 4d64df __vbaStrCat __vbaStrMove __vbaStrCopy 19817->19829 19830 4d65aa __vbaStrCopy 19817->19830 19818->19810 19820 4d629b __vbaFreeStrList __vbaStrCat __vbaStrMove 19819->19820 19824 4efae0 19820->19824 19825 4d5844 __vbaFreeStrList 19821->19825 19826 4d5e9b 19822->19826 19827 4d5d65 __vbaStrCat __vbaStrMove 19822->19827 19823->19826 19828 4d5f00 19823->19828 19831 4d62dd __vbaFreeStr __vbaStrCopy __vbaStrCopy 19824->19831 19825->19764 19826->19755 19832 4fa530 19827->19832 19828->19826 19842 4d5f21 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy 19828->19842 19834 4efae0 19829->19834 19830->19810 19835 4efae0 19831->19835 19836 4d5d8f __vbaFreeStr __vbaStrCmp 19832->19836 19837 4efae0 19833->19837 19838 4d651c __vbaFreeStrList __vbaStrCat __vbaStrMove 19834->19838 19839 4d6316 __vbaFreeStrList 19835->19839 19836->19826 19840 4d5db6 19836->19840 19841 4d6098 __vbaFreeStrList __vbaStrCat __vbaStrMove 19837->19841 19844 4efae0 19838->19844 19839->19812 19840->19826 19850 4d5dd7 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy 19840->19850 19843 4efae0 19841->19843 19845 4efae0 19842->19845 19846 4d60d9 __vbaFreeStr 19843->19846 19847 4d655e __vbaFreeStr __vbaStrCopy __vbaStrCopy 19844->19847 19848 4d5f75 __vbaFreeStrList __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19845->19848 19846->19755 19849 4efae0 19847->19849 19851 4efae0 19848->19851 19852 4d6597 __vbaFreeStrList 19849->19852 19853 4efae0 19850->19853 19854 4d5fd2 __vbaFreeStrList 19851->19854 19852->19830 19855 4d5e2b __vbaFreeStrList __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove 19853->19855 19854->19826 19856 4efae0 19855->19856 19857 4d5e88 __vbaFreeStrList 19856->19857 19857->19826 19859 4d1000 19858->19859 19860 4d141c #520 __vbaVarTstNe __vbaFreeVar 19859->19860 19861 4d148b 8 API calls 19860->19861 19862 4d1623 __vbaStrCopy #685 __vbaObjSet 19860->19862 19863 4d22a0 307 API calls 19861->19863 19865 4d1666 __vbaFreeObj 19862->19865 19864 4d1553 7 API calls 19863->19864 19864->19862 19866 4d160e __vbaStrCopy 19864->19866 19867 4d16cc __vbaFreeStr __vbaFreeStr 19865->19867 19866->19862 19867->19523 16295 4d0280 __vbaChkstk __vbaOnError __vbaStrCmp 16296 4d02f4 __vbaStrCopy 16295->16296 16297 4d03e0 #685 __vbaObjSet 16295->16297 16308 4762a0 16296->16308 16299 4d0407 __vbaFreeObj 16297->16299 16301 4d0421 16299->16301 16309 4762a9 16308->16309 16432 523380 __vbaChkstk __vbaOnError 16468 474240 16432->16468 16469 474249 16468->16469 16470 53f280 6 API calls 16471 53f323 16470->16471 16472 53f338 16470->16472 16471->16472 16473 53f3c7 __vbaErrorOverflow 16471->16473 16478 53f3d0 __vbaChkstk __vbaOnError 16472->16478 16475 53f351 __vbaStrMove #685 __vbaObjSet 16476 53f383 __vbaFreeObj 16475->16476 16477 53f3b0 16476->16477 16479 53f8bf __vbaErrorOverflow 16478->16479 16484 53f439 16478->16484 16480 53f8d0 __vbaChkstk __vbaOnError 16479->16480 16510 530720 11 API calls 16480->16510 16482 53f812 __vbaStrCopy #685 __vbaObjSet 16488 53f855 __vbaFreeObj 16482->16488 16483 53f930 __vbaStrCopy 16492 5445b4 #685 __vbaObjSet 16483->16492 16484->16482 16485 53f4d9 __vbaGenerateBoundsError 16484->16485 16489 53f491 16484->16489 16486 53f4b3 16485->16486 16490 53f530 _adj_fdiv_m64 16486->16490 16491 53f528 16486->16491 16493 53f89a __vbaFreeStr 16488->16493 16489->16486 16494 53f4bf __vbaGenerateBoundsError 16489->16494 16490->16491 16495 53f54b __vbaR8FixI4 16491->16495 16496 53f8ba 16491->16496 16497 5445e7 __vbaFreeObj 16492->16497 16493->16475 16494->16486 16498 53f5f2 16495->16498 16499 53f565 16495->16499 16496->16479 16500 5446ea 22 API calls 16497->16500 16498->16479 16502 53f687 16498->16502 16504 53f62f #607 __vbaVarAdd __vbaStrVarMove __vbaStrMove __vbaFreeVarList 16498->16504 16499->16498 16501 53f56f 16499->16501 16500->16475 16501->16479 16503 53f595 #607 __vbaVarAdd __vbaStrVarMove __vbaStrMove __vbaFreeVarList 16501->16503 16505 53f747 16502->16505 16506 53f6c1 16502->16506 16503->16502 16504->16502 16505->16479 16507 53f7e5 __vbaStrCat __vbaStrMove 16505->16507 16509 53f78c #607 __vbaVarAdd __vbaStrVarMove __vbaStrMove __vbaFreeVarList 16505->16509 16506->16479 16508 53f6e9 #607 __vbaVarAdd __vbaStrVarMove __vbaStrMove __vbaFreeVarList 16506->16508 16507->16482 16508->16507 16509->16507 16511 530952 __vbaStrCopy 16510->16511 16512 5308ad #518 #520 __vbaVarTstEq __vbaFreeVarList 16510->16512 16513 51c3a0 3421 API calls 16511->16513 16537 530931 16512->16537 16514 530973 __vbaStrMove __vbaStrCopy __vbaStrCopy __vbaStrCopy 16513->16514 16576 506210 11 API calls 16514->16576 16516 5309bd 9 API calls 16519 530ac2 16516->16519 16520 530a89 __vbaStrCopy __vbaStrCopy 16516->16520 16517 531387 __vbaStrCopy 16521 53139e #685 __vbaObjSet 16517->16521 16518 53136e __vbaStrCopy 16518->16521 16522 51c3a0 3421 API calls 16519->16522 16520->16519 16524 5313ce __vbaFreeObj 16521->16524 16523 530ace 6 API calls 16522->16523 16525 530b47 #685 __vbaObjSet 16523->16525 16523->16537 16526 531439 __vbaFreeStr __vbaFreeStr __vbaFreeStr __vbaAryDestruct __vbaFreeStr 16524->16526 16527 530b7e 16525->16527 16526->16483 16528 530bb2 16527->16528 16529 530b8f __vbaHresultCheckObj 16527->16529 16530 530bbc __vbaFreeObj 16528->16530 16529->16530 16531 530be9 16530->16531 16530->16537 16532 51c3a0 3421 API calls 16531->16532 16533 530bf5 __vbaStrMove __vbaStrCopy 16532->16533 16610 50d570 8 API calls 16533->16610 16537->16517 16537->16518 16577 506365 #520 __vbaStrVarMove __vbaStrMove __vbaFreeVar 16576->16577 16578 50634e __vbaStrCopy 16576->16578 16579 5063ae 9 API calls 16577->16579 16578->16579 16580 506498 __vbaStrCopy 16579->16580 16581 5064af #520 __vbaStrVarMove __vbaStrMove __vbaFreeVar 16579->16581 16582 5064f8 #608 __vbaInStrVar __vbaVarTstGt __vbaFreeVarList 16580->16582 16581->16582 16583 5065d2 __vbaInStr 16582->16583 16584 50657e 6 API calls 16582->16584 16585 5065f0 #712 __vbaStrMove 16583->16585 16586 50661c 9 API calls 16583->16586 16584->16583 16585->16586 16587 5066d2 #518 __vbaInStrVar __vbaVarTstEq __vbaFreeVarList 16586->16587 16588 506786 6 API calls 16586->16588 16587->16588 16589 506771 __vbaStrCopy 16587->16589 16590 506869 #525 __vbaStrMove __vbaLenBstr __vbaStrCmp 16588->16590 16591 50684d __vbaStrVarCopy __vbaStrMove 16588->16591 16589->16588 16592 506ad7 __vbaStrCopy 16590->16592 16593 5068ba __vbaStrToAnsi __vbaStrToAnsi __vbaStrToAnsi __vbaStrToAnsi __vbaStrToAnsi 16590->16593 16591->16590 16595 506aec __vbaStrCmp 16592->16595 16617 4752dc 16593->16617 16596 506b0a __vbaStrCopy __vbaInStr 16595->16596 16597 506bec #685 __vbaObjSet 16595->16597 16599 506b67 __vbaInStr 16596->16599 16600 506b3b #712 __vbaStrMove 16596->16600 16605 506c2c __vbaFreeObj 16597->16605 16603 506b85 6 API calls 16599->16603 16604 506bd9 __vbaStrCopy 16599->16604 16600->16599 16603->16604 16604->16597 16608 506cae __vbaFreeVar __vbaFreeStr __vbaFreeStr __vbaFreeStr 16605->16608 16608->16516 16619 4753d8 16610->16619 16618 4752e5 16617->16618 16620 4753e1 16619->16620 16621 53d500 __vbaChkstk __vbaFixstrConstruct __vbaOnError #685 __vbaObjSet 16622 53d599 __vbaFreeObj 16621->16622 16797 531fd0 7 API calls 16622->16797 16624 53d5d3 16625 53d622 __vbaUbound 16624->16625 16628 53d5fc __vbaSetSystemError 16624->16628 16626 53ddfe 16625->16626 16627 53d63f #685 __vbaObjSet 16625->16627 16629 53de4e __vbaAryCopy #685 __vbaObjSet 16626->16629 16632 53de37 __vbaSetSystemError 16626->16632 16631 53d679 16627->16631 16628->16625 16630 53d611 16628->16630 16633 53de99 __vbaFreeObj 16629->16633 16630->16625 16634 53d68a __vbaHresultCheckObj 16631->16634 16635 53d6ad 16631->16635 16632->16629 16636 53df3e __vbaAryDestruct __vbaFreeStr __vbaFreeStr 16633->16636 16637 53d6b7 __vbaFreeObj 16634->16637 16635->16637 16637->16626 16638 53d6e7 __vbaAryLock 16637->16638 16639 53d70a 16638->16639 16640 53d75e __vbaGenerateBoundsError 16638->16640 16639->16640 16642 53d716 16639->16642 16641 53d738 16640->16641 16643 53d780 16641->16643 16644 53d78c __vbaGenerateBoundsError 16641->16644 16642->16641 16645 53d744 __vbaGenerateBoundsError 16642->16645 16646 53d798 __vbaUbound 16643->16646 16644->16646 16645->16641 16647 53d7af 16646->16647 16648 53df7c 9 API calls 16646->16648 16649 53d7d3 __vbaSetSystemError __vbaAryUnlock __vbaLenBstr 16647->16649 16650 53e05f __vbaFreeObj #520 __vbaVarTstNe __vbaFreeVar 16648->16650 16651 53d8a5 __vbaStrToAnsi 16649->16651 16652 53d814 __vbaStrToAnsi 16649->16652 16653 53e0e6 #685 __vbaObjSet 16650->16653 16654 53e736 16650->16654 16658 4744e0 16651->16658 16990 4744e0 16652->16990 16659 53e120 16653->16659 16655 53e864 __vbaGenerateBoundsError 16654->16655 16656 53e858 16654->16656 16660 53e870 __vbaRecAssign #685 __vbaObjSet 16655->16660 16656->16660 16662 53d8dc __vbaSetSystemError __vbaStrToUnicode __vbaLsetFixstr __vbaFreeStrList 16658->16662 16664 53e131 __vbaHresultCheckObj 16659->16664 16665 53e154 16659->16665 16668 53e8c1 __vbaFreeObj 16660->16668 16663 53d92e 16662->16663 16663->16626 16666 53d93f 14 API calls 16663->16666 16667 53e15e __vbaFreeObj 16664->16667 16665->16667 16666->16626 16669 53da88 16666->16669 16667->16654 16670 53e18e 16667->16670 16671 53e92d 6 API calls 16668->16671 16669->16626 16674 53dacd 17 API calls 16669->16674 16672 53e1b4 __vbaGenerateBoundsError 16670->16672 16673 53e1a8 16670->16673 16675 53e1c0 __vbaStrCopy 16672->16675 16673->16675 16674->16626 16676 53dc81 __vbaRedimPreserve 16674->16676 16677 531fd0 1002 API calls 16675->16677 16678 53dcb6 16676->16678 16679 53dd08 __vbaGenerateBoundsError 16676->16679 16680 53e1e6 16677->16680 16678->16679 16681 53dcbf 16678->16681 16684 53dd14 __vbaStrCopy __vbaStrCopy __vbaLenBstr __vbaLenBstr 16679->16684 16682 53e1f0 16680->16682 16683 53e74b 16680->16683 16685 53dceb __vbaGenerateBoundsError 16681->16685 16686 53dcdf 16681->16686 16687 53e216 __vbaGenerateBoundsError 16682->16687 16688 53e20a 16682->16688 16683->16654 16690 53e790 __vbaGenerateBoundsError 16683->16690 16691 53e784 16683->16691 16684->16648 16689 53dd7f 16684->16689 16685->16686 16686->16684 16687->16688 16694 53e250 16688->16694 16695 53e25c __vbaGenerateBoundsError 16688->16695 16689->16648 16692 53dd88 6 API calls 16689->16692 16693 53e79c __vbaRecUniToAnsi 16690->16693 16691->16693 16692->16626 16692->16648 16992 4743ac 16693->16992 16697 53e2a2 __vbaGenerateBoundsError 16694->16697 16698 53e296 16694->16698 16695->16694 16697->16698 16905 534a20 __vbaChkstk __vbaStrCopy __vbaAryConstruct2 __vbaOnError 16698->16905 16704 53e2d5 __vbaAryMove #685 __vbaObjSet 16705 53e31f __vbaFreeObj __vbaUbound 16704->16705 16705->16654 16706 53e347 16705->16706 16707 53e361 16706->16707 16708 53e36d __vbaGenerateBoundsError 16706->16708 16709 53e3a2 16707->16709 16710 53e3ae __vbaGenerateBoundsError 16707->16710 16708->16707 16711 53e3ba __vbaLbound __vbaUbound __vbaRedim __vbaAryLock 16709->16711 16710->16711 16712 53e429 16711->16712 16713 53e47d __vbaGenerateBoundsError 16711->16713 16712->16713 16714 53e435 16712->16714 16715 53e489 __vbaAryLock 16713->16715 16716 53e463 __vbaGenerateBoundsError 16714->16716 16717 53e457 16714->16717 16718 53e4a3 16715->16718 16719 53e501 __vbaGenerateBoundsError 16715->16719 16716->16717 16717->16715 16718->16719 16720 53e4af __vbaLbound 16718->16720 16721 53e50d __vbaUbound 16719->16721 16722 53e4e7 __vbaGenerateBoundsError 16720->16722 16723 53e4db 16720->16723 16724 53e522 16721->16724 16725 53e9b1 6 API calls 16721->16725 16722->16723 16723->16721 16728 53e548 __vbaSetSystemError __vbaAryUnlock __vbaAryUnlock __vbaAryLock 16724->16728 16726 5447f0 16725->16726 16727 53ea56 __vbaStrCopy 16726->16727 16731 4fa530 16727->16731 16729 53e5e7 __vbaGenerateBoundsError 16728->16729 16730 53e589 16728->16730 16733 53e5c1 16729->16733 16730->16729 16732 53e595 __vbaLbound 16730->16732 16734 53ea7a __vbaFreeStr 16731->16734 16732->16733 16735 53e5cd __vbaGenerateBoundsError 16732->16735 16736 53e612 __vbaGenerateBoundsError 16733->16736 16737 53e606 16733->16737 16738 531fd0 1002 API calls 16734->16738 16735->16733 16736->16737 16742 53e631 16737->16742 16743 53e63d __vbaGenerateBoundsError 16737->16743 16739 53eaa2 16738->16739 16740 53eaeb 16739->16740 16741 53eaa8 16739->16741 16746 53e649 __vbaLbound 16742->16746 16743->16746 16751 53e680 16746->16751 16752 53e68c __vbaGenerateBoundsError 16746->16752 16798 5320bb __vbaStrCopy 16797->16798 16799 53239d #520 __vbaVarTstEq __vbaFreeVar 16797->16799 16802 4ecd60 16798->16802 16800 532416 __vbaStrCopy 16799->16800 16801 5326f8 #520 __vbaVarTstEq __vbaFreeVar 16799->16801 16804 4ecd60 16800->16804 16803 53279c __vbaStrCmp 16801->16803 16807 53276d 16801->16807 16805 5320d9 8 API calls 16802->16805 16803->16807 16808 5327e8 16803->16808 16809 532434 8 API calls 16804->16809 16810 5321ae __vbaStrCopy 16805->16810 16811 53222c #520 __vbaVarTstEq __vbaFreeVar 16805->16811 16806 533509 #685 __vbaObjSet 16822 533539 __vbaFreeObj 16806->16822 16807->16806 17159 5393d0 __vbaChkstk __vbaOnError #520 __vbaVarTstNe __vbaFreeVar 16808->17159 16813 532587 #520 __vbaVarTstEq __vbaFreeVar 16809->16813 16814 532509 __vbaStrCopy 16809->16814 16815 4ecd60 16810->16815 16816 532311 #520 __vbaVarTstNe __vbaFreeVar 16811->16816 16817 5322a1 __vbaStrCopy 16811->16817 16824 53266c #520 __vbaVarTstNe __vbaFreeVar 16813->16824 16825 5325fc __vbaStrCopy 16813->16825 16821 4ecd60 16814->16821 16823 5321cc #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 16815->16823 16816->16799 16819 532386 __vbaStrCopy 16816->16819 16818 4f0ca0 418 API calls 16817->16818 16826 5322d0 __vbaFreeStr __vbaStrCopy 16818->16826 16819->16799 16820 5327f4 16828 532830 __vbaStrCmp 16820->16828 16829 5327fb 16820->16829 16830 532527 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 16821->16830 16831 5335a5 6 API calls 16822->16831 16823->16811 16824->16801 16827 5326e1 __vbaStrCopy 16824->16827 16832 4f0ca0 418 API calls 16825->16832 16834 4f0ca0 418 API calls 16826->16834 16827->16801 16836 532872 __vbaStrCopy 16828->16836 16837 53284d 16828->16837 16835 5334f2 __vbaStrCopy 16829->16835 16830->16813 16831->16624 16833 53262b __vbaFreeStr __vbaStrCopy 16832->16833 16840 4f0ca0 418 API calls 16833->16840 16841 532308 __vbaFreeStr 16834->16841 16835->16806 16838 53289a #546 16836->16838 16839 5328fd 16836->16839 16842 5334db __vbaStrCopy 16837->16842 17227 517740 12 API calls 16838->17227 16845 5329b4 16839->16845 16846 532928 #546 16839->16846 16844 532663 __vbaFreeStr 16840->16844 16841->16816 16842->16835 16844->16824 16849 5329e6 #520 __vbaVarTstEq __vbaFreeVar 16845->16849 16850 5334b5 16845->16850 16848 517740 42 API calls 16846->16848 16847 5328d4 __vbaFreeVar 16851 5334c4 __vbaStrCopy 16847->16851 16852 532948 __vbaFreeVar 16848->16852 16853 532ae6 #520 __vbaVarTstEq __vbaFreeVar 16849->16853 16854 532a68 __vbaStrCopy 16849->16854 16850->16851 16851->16842 16852->16845 16857 53296e 16852->16857 16855 532b5b __vbaStrCopy 16853->16855 16856 532bd9 #520 __vbaVarTstEq __vbaFreeVar 16853->16856 16858 4ecd60 16854->16858 16859 4ecd60 16855->16859 16860 532c65 #520 __vbaVarTstEq __vbaFreeVar 16856->16860 16861 532c4e __vbaStrCopy 16856->16861 16857->16845 16865 5329a1 __vbaFpR8 16857->16865 16866 5335fa 16857->16866 16862 532a86 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 16858->16862 16863 532b79 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 16859->16863 16864 532cec __vbaStrCmp 16860->16864 16897 532cda #546 16860->16897 16861->16860 16862->16853 16863->16856 16870 532d28 16864->16870 16864->16897 16865->16845 16866->16866 16868 517740 42 API calls 16869 533491 __vbaFreeVar 16868->16869 16869->16850 16871 532dd6 16870->16871 16873 532dc1 __vbaSetSystemError 16870->16873 16870->16897 16872 532e0f 16871->16872 16875 532dfa __vbaSetSystemError 16871->16875 16874 532e48 16872->16874 16876 532e33 __vbaSetSystemError 16872->16876 16873->16871 16877 532e6d 8 API calls 16874->16877 16874->16897 16875->16872 16876->16874 17238 47443c 16877->17238 16897->16868 16906 534aa2 __vbaAryCopy 16905->16906 16907 534abd __vbaStrCmp 16905->16907 16908 53543b __vbaAryCopy #685 __vbaObjSet 16906->16908 16909 534ad7 __vbaStrCmp 16907->16909 16910 534b45 #520 __vbaVarTstEq __vbaFreeVar 16907->16910 16914 535480 __vbaFreeObj 16908->16914 16909->16910 16911 534af3 __vbaStrCmp 16909->16911 16912 534bc3 #520 __vbaVarTstEq __vbaFreeVar 16910->16912 16913 534bad __vbaStrCopy 16910->16913 16911->16910 16915 534b0f 16911->16915 16916 534cb7 16912->16916 16917 534c2f 16912->16917 16913->16912 16918 5354cd __vbaAryDestruct __vbaAryDestruct __vbaAryDestruct __vbaFreeStr 16914->16918 17325 5341b0 __vbaChkstk __vbaOnError __vbaObjIs 16915->17325 16921 535530 1053 API calls 16916->16921 16920 536150 1002 API calls 16917->16920 16918->16704 16923 534c4c __vbaChkstk __vbaVarIndexLoad __vbaStrVarMove __vbaStrMove __vbaFreeVarList 16920->16923 16924 534cc7 16921->16924 16923->16916 16924->16908 16926 534cd1 #685 __vbaObjSet 16924->16926 16925 534b35 17332 535530 __vbaChkstk __vbaStrCopy __vbaOnError __vbaStrCmp __vbaStrCmp 16925->17332 16928 534d01 __vbaFreeObj __vbaUbound #685 __vbaObjSet 16926->16928 16929 534d65 16928->16929 16930 534d76 __vbaHresultCheckObj 16929->16930 16931 534d99 16929->16931 16932 534da3 __vbaFreeObj 16930->16932 16931->16932 16932->16908 16933 534dde __vbaLbound 16932->16933 16934 534df5 16933->16934 16935 535520 __vbaErrorOverflow 16934->16935 16936 534e34 __vbaGenerateBoundsError 16934->16936 16937 534e28 16934->16937 16938 534e40 7 API calls 16936->16938 16937->16938 16939 534f26 16938->16939 16940 534f37 __vbaHresultCheckObj 16939->16940 16941 534f5a 16939->16941 16942 534f64 __vbaFreeObj 16940->16942 16941->16942 16943 5350e4 16942->16943 16944 534fbb 16942->16944 16945 5341b0 15 API calls 16943->16945 16944->16935 16946 534fd0 __vbaRedim 16944->16946 16947 5350f0 16945->16947 16948 535012 __vbaGenerateBoundsError 16946->16948 16949 535006 16946->16949 16950 535530 1053 API calls 16947->16950 16951 53501e __vbaAryLock 16948->16951 16949->16951 16991 4744e9 16990->16991 16993 4743b5 16992->16993 17160 5394aa 17159->17160 17161 53956c __vbaStrCmp 17159->17161 17160->17161 17164 5394c8 #546 17160->17164 17162 5395d6 17161->17162 17163 539589 17161->17163 17166 5395e9 __vbaStrCopy 17162->17166 17167 539ea8 #685 __vbaObjSet 17162->17167 17163->17162 17165 539591 __vbaStrCopy __vbaStrCopy 17163->17165 17240 517b40 12 API calls 17164->17240 17165->17162 17169 4fa530 17166->17169 17171 539edb __vbaFreeObj 17167->17171 17172 539607 __vbaFreeStr 17169->17172 17170 5394e8 __vbaFreeVar 17173 539513 __vbaFpR8 17170->17173 17174 539fb2 __vbaErrorOverflow 17170->17174 17175 539f32 8 API calls 17171->17175 17257 53a6d0 6 API calls 17172->17257 17173->17161 17177 539526 __vbaStrCmp 17173->17177 17175->16820 17180 539550 17177->17180 17180->17161 17228 517b26 17227->17228 17229 517886 __vbaFreeVarList __vbaLenBstr 17227->17229 17231 517b2b __vbaErrorOverflow 17228->17231 17230 5178c0 7 API calls 17229->17230 17229->17231 17230->17228 17232 517949 __vbaFreeVarList __vbaLenBstr 17230->17232 17232->17231 17233 517983 7 API calls 17232->17233 17233->17228 17234 517a12 __vbaFreeVarList __vbaLenBstr 17233->17234 17234->17231 17235 517a4c 7 API calls 17234->17235 17236 517ad4 __vbaFreeObj 17235->17236 17237 517b06 __vbaFreeStr 17236->17237 17237->16847 17239 474445 17238->17239 17241 5181a5 17240->17241 17242 517c86 __vbaFreeVarList __vbaLenBstr 17240->17242 17244 5181aa __vbaErrorOverflow 17241->17244 17243 517cc0 7 API calls 17242->17243 17242->17244 17243->17241 17245 517d49 __vbaFreeVarList __vbaLenBstr 17243->17245 17245->17244 17246 517d83 7 API calls 17245->17246 17246->17241 17247 517e12 __vbaFreeVarList __vbaLenBstr 17246->17247 17247->17244 17248 517e4c 7 API calls 17247->17248 17248->17241 17249 517ee1 __vbaFreeVarList __vbaLenBstr 17248->17249 17249->17244 17250 517f1b 7 API calls 17249->17250 17250->17241 17251 517fb6 __vbaFreeVarList __vbaLenBstr 17250->17251 17251->17244 17252 517ff0 7 API calls 17251->17252 17252->17241 17253 518091 __vbaFreeVarList __vbaLenBstr 17252->17253 17253->17244 17254 5180cb 7 API calls 17253->17254 17255 518153 __vbaFreeObj 17254->17255 17256 518185 __vbaFreeStr 17255->17256 17256->17170 17319 4776dc 17257->17319 17320 4776e5 17319->17320 17326 534222 __vbaObjSetAddref 17325->17326 17327 534220 17325->17327 17326->17327 17369 533dc0 __vbaChkstk __vbaOnError __vbaStrCmp 17327->17369 17330 534276 __vbaFreeObj 17331 534299 __vbaStrCmp 17330->17331 17331->16910 17331->16925 17333 5355e1 __vbaStrCmp __vbaStrCmp __vbaStrCmp 17332->17333 17334 5355cb __vbaStrCopy 17332->17334 17335 535644 __vbaStrCmp 17333->17335 17336 535638 17333->17336 17334->17333 17338 535660 17335->17338 17339 535676 17335->17339 17337 5341b0 15 API calls 17336->17337 17337->17335 17338->17339 17344 5341b0 15 API calls 17338->17344 17340 535a68 #685 __vbaObjSet 17339->17340 17341 53568c #520 __vbaVarTstEq __vbaFreeVar 17339->17341 17347 535a98 __vbaFreeObj #685 __vbaObjSet 17340->17347 17342 5356f2 17341->17342 17343 535771 #520 __vbaVarTstNe __vbaFreeVar 17341->17343 17345 536150 1002 API calls 17342->17345 17343->17340 17346 5357ce 17343->17346 17344->17339 17348 53570c __vbaChkstk __vbaVarIndexLoad __vbaStrVarMove __vbaStrMove __vbaFreeVarList 17345->17348 17375 5377e0 __vbaChkstk __vbaOnError 17346->17375 17350 535ae2 __vbaFreeObj 17347->17350 17348->17343 17352 535b24 __vbaAryDestruct __vbaAryDestruct __vbaFreeStr 17350->17352 17352->16910 17370 533e34 __vbaStrCopy 17369->17370 17371 5340dc #685 __vbaObjSet 17369->17371 17372 5341b0 8 API calls 17370->17372 17373 53410c __vbaFreeObj 17371->17373 17372->17371 17374 534172 __vbaFreeVar #685 __vbaObjSet 17373->17374 17374->17330 17376 5393d0 315 API calls 17375->17376 17638 4abd10 __vbaChkstk __vbaOnError 17639 4abd79 17638->17639 17640 4abd85 17638->17640 17641 531fd0 1002 API calls 17639->17641 17642 4abde3 __vbaStrCopy 17640->17642 17643 4abda3 17640->17643 17641->17640 17645 53b510 17642->17645 17924 535b60 __vbaChkstk __vbaOnError __vbaStrCmp 17643->17924 17646 4abe06 __vbaAryRecMove #685 __vbaObjSet 17645->17646 17647 4abe5f __vbaFreeObj 17646->17647 17648 4abeb1 __vbaGenerateBoundsError 17647->17648 17649 4abe75 17647->17649 17651 4abeba __vbaStrCmp 17648->17651 17649->17648 17650 4abe7e 17649->17650 17652 4abe9d __vbaGenerateBoundsError 17650->17652 17653 4abe94 17650->17653 17654 4abeda #685 __vbaObjSet 17651->17654 17662 4abdaf 17651->17662 17652->17653 17653->17651 17656 4abf05 17654->17656 17655 4ac019 #685 __vbaObjSet 17657 4ac04d __vbaFreeObj 17655->17657 17658 4abf2a 17656->17658 17659 4abf10 __vbaHresultCheckObj 17656->17659 17660 4ac067 __vbaAryDestruct __vbaAryDestruct 17657->17660 17661 4abf31 __vbaFreeObj 17658->17661 17659->17661 17661->17662 17663 4abf55 __vbaUbound 17661->17663 17662->17655 17664 4ac0a3 __vbaErrorOverflow __vbaChkstk 17663->17664 17665 4abf71 #685 __vbaObjSet 17663->17665 17666 4ac105 __vbaOnError __vbaStrCopy __vbaStrCmp 17664->17666 17667 4abf9f 17665->17667 17670 4ac14f __vbaStrCopy 17666->17670 17671 4ac176 #685 __vbaObjSet 17666->17671 17668 4abfaa __vbaHresultCheckObj 17667->17668 17669 4abfc4 17667->17669 17673 4abfcb __vbaFreeObj 17668->17673 17669->17673 17672 4fa530 17670->17672 17675 4ac1a6 __vbaFreeObj __vbaStrCmp 17671->17675 17674 4ac16d __vbaFreeStr 17672->17674 17673->17662 17674->17671 17744 4cc360 __vbaChkstk __vbaOnError __vbaStrToAnsi 17675->17744 17955 477c5c 17744->17955 17925 535bd0 17924->17925 17926 535be5 __vbaStrCopy 17924->17926 17927 535e59 #685 __vbaObjSet 17925->17927 17928 536150 1002 API calls 17926->17928 17930 535e80 __vbaFreeObj 17927->17930 17929 535c08 __vbaAryMove #685 __vbaObjSet 17928->17929 17932 535c40 __vbaFreeObj __vbaUbound #685 __vbaObjSet 17929->17932 17931 535e9a __vbaAryDestruct __vbaAryDestruct 17930->17931 17931->17662 17933 535c8a 17932->17933 17934 535c95 __vbaHresultCheckObj 17933->17934 17935 535caf 17933->17935 17936 535cb6 __vbaFreeObj 17934->17936 17935->17936 17937 535cd6 17936->17937 17938 535ce9 #685 __vbaObjSet 17936->17938 17937->17938 17939 535ec7 __vbaErrorOverflow 17937->17939 17941 535d23 __vbaFreeObj 17938->17941 17942 535d75 __vbaGenerateBoundsError 17941->17942 17943 535d39 17941->17943 17944 535d7e __vbaStrCmp 17942->17944 17943->17942 17945 535d42 17943->17945 17946 535d9e #685 __vbaObjSet 17944->17946 17954 535e15 __vbaStrCopy 17944->17954 17947 535d61 __vbaGenerateBoundsError 17945->17947 17948 535d58 17945->17948 17950 535dc9 17946->17950 17947->17948 17948->17944 17951 535dd4 __vbaHresultCheckObj 17950->17951 17952 535dee 17950->17952 17953 535df5 __vbaFreeObj 17951->17953 17952->17953 17953->17954 17954->17927 17956 477c65 17955->17956 18192 4bc710 __vbaChkstk __vbaOnError 18193 4cc360 18 API calls 18192->18193 18194 4bc779 18193->18194 18195 51d000 110 API calls 18194->18195 18196 4bc787 18195->18196 18197 531fd0 1002 API calls 18196->18197 18198 4bc79d 18197->18198 18199 4bcc8e #685 __vbaObjSet 18198->18199 18234 4d2c70 __vbaChkstk __vbaOnError #685 __vbaObjSet 18198->18234 18202 4bccbe __vbaFreeObj 18199->18202 18204 4bcd17 __vbaFreeStr __vbaFreeObj 18202->18204 18235 4d2ceb __vbaFreeObj 18234->18235 18248 4775bc 18235->18248 18249 4775c5 18248->18249 18338 4f2a90 __vbaChkstk __vbaOnError __vbaStrCmp 18339 4f2c1b __vbaStrCopy 18338->18339 18340 4f2b04 #525 __vbaStrMove __vbaLenBstr __vbaStrToAnsi 18338->18340 18342 4f2c31 __vbaLenBstr 18339->18342 18341 475ab0 18340->18341 18343 4f2b47 6 API calls 18341->18343 18344 4f2c4b #619 __vbaVarTstNe __vbaFreeVar 18342->18344 18345 4f2cd6 #685 __vbaObjSet 18342->18345 18346 4f2c19 18343->18346 18347 4f2ba3 #619 __vbaVarTstNe __vbaFreeVar 18343->18347 18348 4f2cc1 __vbaStrCopy 18344->18348 18349 4f2ca0 __vbaStrCat __vbaStrMove 18344->18349 18350 4f2d06 __vbaFreeObj 18345->18350 18346->18342 18347->18346 18351 4f2bf8 __vbaStrCat __vbaStrMove 18347->18351 18348->18345 18349->18348 18352 4f2d4f __vbaFreeStr 18350->18352 18351->18346 18250 4d2e30 __vbaChkstk __vbaOnError #685 __vbaObjSet 18251 4d2eb4 __vbaFreeObj 18250->18251 18252 4775bc 18251->18252 18253 4d2ec9 __vbaSetSystemError 18252->18253 18279 474a54 18253->18279 18280 474a5d 18279->18280
      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004AC9DE
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004ACA25
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004ACA99
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004ACADF
      • __vbaFreeObj.MSVBVM60 ref: 004ACAFD
      • __vbaStrCopy.MSVBVM60 ref: 004ACB43
      • __vbaFreeStr.MSVBVM60(?), ref: 004ACB55
        • Part of subcall function 004D0AE0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00411816), ref: 004D0AFE
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D0B2B
        • Part of subcall function 004D0AE0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D0B3A
        • Part of subcall function 004D0AE0: #520.MSVBVM60(?,00004008), ref: 004D0B68
        • Part of subcall function 004D0AE0: __vbaStrVarMove.MSVBVM60(?), ref: 004D0B72
        • Part of subcall function 004D0AE0: __vbaStrMove.MSVBVM60 ref: 004D0B7D
        • Part of subcall function 004D0AE0: __vbaFreeVar.MSVBVM60 ref: 004D0B86
        • Part of subcall function 004D0AE0: __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D0B9C
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60 ref: 004D0BB5
        • Part of subcall function 004D0AE0: __vbaStrCat.MSVBVM60(?,get:,?), ref: 004D0BC8
        • Part of subcall function 004D0AE0: __vbaStrMove.MSVBVM60 ref: 004D0BD3
        • Part of subcall function 004D0AE0: __vbaStrMove.MSVBVM60(00000000), ref: 004D0BE4
        • Part of subcall function 004D0AE0: __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004D0BF4
        • Part of subcall function 004D0AE0: #520.MSVBVM60(?,00004008), ref: 004D0C19
        • Part of subcall function 004D0AE0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004D0C35
        • Part of subcall function 004D0AE0: __vbaFreeVar.MSVBVM60 ref: 004D0C42
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60 ref: 004D0C5F
      • __vbaStrMove.MSVBVM60(CardLogon), ref: 004ACB87
      • __vbaStrCmp.MSVBVM60(true,00000000), ref: 004ACB93
      • __vbaFreeStr.MSVBVM60 ref: 004ACBAA
      • __vbaStrMove.MSVBVM60(MonitorI2C), ref: 004ACBED
      • __vbaStrCmp.MSVBVM60(true,00000000), ref: 004ACBF9
      • __vbaFreeStr.MSVBVM60 ref: 004ACC10
      • __vbaStrMove.MSVBVM60(MonitorKerberos), ref: 004ACC53
      • __vbaStrCmp.MSVBVM60(true,00000000), ref: 004ACC5F
      • __vbaFreeStr.MSVBVM60 ref: 004ACC76
      • __vbaStrCopy.MSVBVM60 ref: 004ACCC4
      • __vbaFreeStr.MSVBVM60(?), ref: 004ACCD6
      • #520.MSVBVM60(?,00004008), ref: 004ACD35
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004ACD5D
      • __vbaFreeVar.MSVBVM60 ref: 004ACD70
      • __vbaStrMove.MSVBVM60 ref: 004ACD92
      • __vbaStrCopy.MSVBVM60 ref: 004ACDA3
      • __vbaFreeStr.MSVBVM60 ref: 004ACDAC
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004ACDC8
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001), ref: 004ACDF0
      • __vbaStrMove.MSVBVM60 ref: 004ACE0F
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004ACE1B
      • __vbaFreeStr.MSVBVM60 ref: 004ACE33
      • __vbaStrMove.MSVBVM60 ref: 004ACE59
      • __vbaStrCat.MSVBVM60(004775E8,00000000), ref: 004ACE65
      • __vbaVarDup.MSVBVM60 ref: 004ACEAF
      • #711.MSVBVM60(?,?,?,000000FF,00000000), ref: 004ACED1
      • __vbaChkstk.MSVBVM60(00000008), ref: 004ACEE3
      • __vbaVarIndexLoad.MSVBVM60(?,?,00000001,00000008), ref: 004ACF1D
      • __vbaVarAdd.MSVBVM60(?,00000000,?,?,?,?,?,?,00411816), ref: 004ACF2E
      • __vbaStrVarMove.MSVBVM60(00000000,?,?,?,?,?,?,00411816), ref: 004ACF35
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004ACF40
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004ACF51
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?,?,?,00411816), ref: 004ACF61
      • __vbaFreeVarList.MSVBVM60(00000005,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004ACF8F
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004ACFAB
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001), ref: 004ACFD3
      • __vbaVarDup.MSVBVM60 ref: 004AD01C
      • #711.MSVBVM60(?,?,?,000000FF,00000000), ref: 004AD03E
      • __vbaChkstk.MSVBVM60 ref: 004AD049
      • __vbaVarIndexLoad.MSVBVM60(?,?,00000001), ref: 004AD083
      • __vbaStrVarMove.MSVBVM60(00000000,?,?,?,?,?,?,00411816), ref: 004AD08D
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004AD098
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004AD0A6
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004AD0AF
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?,?,?,?,?,?,?,00411816), ref: 004AD0CC
      • __vbaStrCopy.MSVBVM60 ref: 004AD0ED
      • __vbaStrCat.MSVBVM60(?,UDomName: ), ref: 004AD109
      • __vbaStrMove.MSVBVM60 ref: 004AD114
      • __vbaFreeStr.MSVBVM60(?), ref: 004AD126
      • __vbaStrMove.MSVBVM60 ref: 004AD13D
      • __vbaStrCopy.MSVBVM60 ref: 004AD14B
      • __vbaStrCopy.MSVBVM60 ref: 004AD159
      • __vbaStrCopy.MSVBVM60 ref: 004AD167
      • #520.MSVBVM60(?,00000008,?,?,?,?), ref: 004AD1A0
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004AD1C8
      • __vbaFreeStrList.MSVBVM60(00000004,?,?,?,?), ref: 004AD1E7
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,?,?,?,00411816), ref: 004AD200
      • __vbaStrMove.MSVBVM60(MonitorI2C,?,?,?,?,?,?,?,00411816), ref: 004AD22E
      • __vbaStrCmp.MSVBVM60(true,00000000,?,?,?,?,?,?,?,00411816), ref: 004AD23A
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,00411816), ref: 004AD251
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,?,?,?,00411816), ref: 004AD284
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004AD2CA
      • #520.MSVBVM60(?,00004008), ref: 004AD31B
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 004AD343
      • __vbaFreeVar.MSVBVM60 ref: 004AD356
      • __vbaStrCat.MSVBVM60(?,MonitorI2C_), ref: 004AD381
      • __vbaStrMove.MSVBVM60 ref: 004AD38C
      • __vbaStrMove.MSVBVM60(00000000), ref: 004AD39D
      • __vbaStrCmp.MSVBVM60(true,00000000), ref: 004AD3A9
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004AD3C7
      • __vbaStrCat.MSVBVM60(?,MonitorPKI_,false), ref: 004AD429
      • __vbaStrMove.MSVBVM60 ref: 004AD434
      • __vbaFreeStr.MSVBVM60(00000000), ref: 004AD443
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,00411816), ref: 004AD484
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,00411816), ref: 004AD496
      • __vbaStrMove.MSVBVM60(MonitorKerberos,?,?,?,?,?,?,?,00411816), ref: 004AD4C5
      • __vbaStrCmp.MSVBVM60(true,00000000,?,?,?,?,?,?,?,00411816), ref: 004AD4D1
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,00411816), ref: 004AD4E8
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,?,?,?,00411816), ref: 004AD51B
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004AD561
      • __vbaFreeObj.MSVBVM60 ref: 004AD57F
      • __vbaStrCat.MSVBVM60(?,MonitorPKI_), ref: 004AD59B
      • __vbaStrMove.MSVBVM60 ref: 004AD5A6
      • __vbaStrMove.MSVBVM60(00000000), ref: 004AD5B7
      • __vbaStrCmp.MSVBVM60(true,00000000), ref: 004AD5C3
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004AD5E1
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,00411816), ref: 004AD641
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,00411816), ref: 004AD653
      • __vbaStrCopy.MSVBVM60 ref: 004AD68D
      • __vbaFreeStr.MSVBVM60(?), ref: 004AD69F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AD6C3
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,00000064), ref: 004AD70C
      • __vbaFreeObj.MSVBVM60 ref: 004AD72A
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AD74E
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004AD794
      • __vbaFreeObj.MSVBVM60 ref: 004AD7B2
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AD7DB
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,00000058), ref: 004AD826
      • __vbaFreeObj.MSVBVM60 ref: 004AD85A
      • __vbaStrCopy.MSVBVM60 ref: 004AD87E
      • __vbaFreeStr.MSVBVM60(?), ref: 004AD890
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AD8B4
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004AD8FA
      • __vbaFreeObj.MSVBVM60 ref: 004AD918
      • __vbaStrCopy.MSVBVM60 ref: 004AD92F
      • __vbaFreeStr.MSVBVM60(?), ref: 004AD941
      • __vbaStrCopy.MSVBVM60 ref: 004AD97B
      • __vbaFreeStr.MSVBVM60(?), ref: 004AD98D
      • __vbaStrI4.MSVBVM60(00000000,readers counted: ), ref: 004AD9FE
      • __vbaStrMove.MSVBVM60 ref: 004ADA09
      • __vbaStrCat.MSVBVM60(00000000), ref: 004ADA10
      • __vbaStrMove.MSVBVM60 ref: 004ADA1B
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004ADA34
      • __vbaStrCopy.MSVBVM60 ref: 004ADA71
      • __vbaFreeStr.MSVBVM60(?), ref: 004ADA83
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004ADAA7
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004ADAED
      • __vbaFreeObj.MSVBVM60 ref: 004ADB0B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004ADB2F
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,00000058), ref: 004ADB7A
      • __vbaFreeObj.MSVBVM60 ref: 004ADBAE
      • __vbaStrCopy.MSVBVM60 ref: 004ADBD2
      • __vbaFreeStr.MSVBVM60(?), ref: 004ADBE4
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004ADC08
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004ADC4E
      • __vbaFreeObj.MSVBVM60 ref: 004ADC6C
      • __vbaStrCopy.MSVBVM60 ref: 004ADC83
      • __vbaFreeStr.MSVBVM60(?), ref: 004ADC95
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004ADCB9
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,00000058), ref: 004ADD04
      • __vbaFreeObj.MSVBVM60 ref: 004ADD47
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004ADD7A
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004ADDC0
      • __vbaFreeObj.MSVBVM60 ref: 004ADDDE
      • __vbaStrCopy.MSVBVM60 ref: 004ADDF3
      • __vbaFreeStr.MSVBVM60(?), ref: 004ADE05
      • __vbaStrCopy.MSVBVM60 ref: 004ADE1F
      • __vbaFreeStr.MSVBVM60(?), ref: 004ADE31
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004ADE4D
      • __vbaStrCopy.MSVBVM60 ref: 004ADE6A
      • __vbaStrMove.MSVBVM60(?), ref: 004ADE7E
      • __vbaStrCopy.MSVBVM60 ref: 004ADE8F
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004ADE9F
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,00411816), ref: 004ADEBE
      • __vbaStrCopy.MSVBVM60(?,?,00411816), ref: 004ADED7
      • __vbaStrMove.MSVBVM60(?,?,?,00411816), ref: 004ADEEB
      • __vbaStrCopy.MSVBVM60(?,?,00411816), ref: 004ADEFC
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,00411816), ref: 004ADF0C
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,00411816), ref: 004ADF2B
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,00411816), ref: 004ADF45
      • __vbaStrMove.MSVBVM60(?,?,00411816), ref: 004ADF6B
      • __vbaStrCopy.MSVBVM60(?,?,00411816), ref: 004ADF79
      • __vbaStrCopy.MSVBVM60(?,?,00411816), ref: 004ADF87
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004ADFAA
      • __vbaStrCopy.MSVBVM60(?,?,00411816), ref: 004ADFBB
      • __vbaFreeStrList.MSVBVM60(00000004,?,?,?,?,?,?,00411816), ref: 004ADFD3
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,00411816), ref: 004ADFF2
      • __vbaStrCopy.MSVBVM60(?,?,00411816), ref: 004AE011
      • #518.MSVBVM60(?,00004008), ref: 004AE045
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 004AE08C
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 004AE09A
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004AE0B7
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004AE106
      • __vbaStrCopy.MSVBVM60 ref: 004AE11F
      • __vbaFreeStr.MSVBVM60(?), ref: 004AE131
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004AE14A
      • __vbaStrCopy.MSVBVM60 ref: 004AE16A
      • __vbaObjSet.MSVBVM60(00000000,00000000), ref: 004AE18E
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004AE1D4
      • __vbaFreeObj.MSVBVM60 ref: 004AE1F2
      • __vbaFreeVar.MSVBVM60 ref: 004AE21B
      • __vbaSetSystemError.MSVBVM60(000000C8), ref: 004AE2A6
        • Part of subcall function 004CC360: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,?,00411816), ref: 004CC37E
        • Part of subcall function 004CC360: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004CC3AE
        • Part of subcall function 004CC360: __vbaStrToAnsi.MSVBVM60(00000000,screen-saver,00000000,00000000,00000040), ref: 004CC3D7
        • Part of subcall function 004CC360: __vbaSetSystemError.MSVBVM60(00000000), ref: 004CC3E6
        • Part of subcall function 004CC360: __vbaFreeStr.MSVBVM60 ref: 004CC3F5
        • Part of subcall function 004CC360: __vbaSetSystemError.MSVBVM60(00000000), ref: 004CC428
        • Part of subcall function 004CC360: #685.MSVBVM60 ref: 004CC55A
        • Part of subcall function 004CC360: __vbaObjSet.MSVBVM60(?,00000000), ref: 004CC565
        • Part of subcall function 004CC360: __vbaFreeObj.MSVBVM60 ref: 004CC57D
      • #520.MSVBVM60(?,00004008), ref: 004AE32C
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?,0000000B), ref: 004AE362
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004AE370
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004AE377
      • __vbaFreeVarList.MSVBVM60(00000002,?,0000000B), ref: 004AE394
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,?,00411816), ref: 004AE3BF
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,00411816), ref: 004AE3F7
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,00411816), ref: 004AE405
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,00411816), ref: 004AE413
      • #520.MSVBVM60(?,00000008), ref: 004AE44F
      • __vbaStrVarMove.MSVBVM60(?), ref: 004AE45C
      • __vbaStrMove.MSVBVM60 ref: 004AE467
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?), ref: 004AE47B
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AE494
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AE4AD
      • __vbaStrCopy.MSVBVM60 ref: 004AE4FA
      • __vbaStrMove.MSVBVM60 ref: 004AE511
      • __vbaStrCopy.MSVBVM60 ref: 004AE51F
      • __vbaStrCopy.MSVBVM60 ref: 004AE52D
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?,?,?), ref: 004AE559
      • __vbaStrMove.MSVBVM60 ref: 004AE573
      • __vbaStrCopy.MSVBVM60 ref: 004AE581
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?), ref: 004AE5A5
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AE5C1
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AE5E0
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AE5EE
      • __vbaStrMove.MSVBVM60(?,?,?,?), ref: 004AE61F
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AE62D
      • __vbaFreeStrList.MSVBVM60(00000004,?,?,?,?), ref: 004AE645
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004AE661
      • __vbaStrCopy.MSVBVM60 ref: 004AE67E
      • __vbaAryMove.MSVBVM60(?,?), ref: 004AE6D6
      • __vbaVarDup.MSVBVM60 ref: 004AE703
      • __vbaVarDup.MSVBVM60 ref: 004AE73C
      • #710.MSVBVM60(00006008,?), ref: 004AE763
      • __vbaStrMove.MSVBVM60 ref: 004AE76E
      • __vbaStrCat.MSVBVM60(004787B4,00000000), ref: 004AE77A
      • __vbaStrMove.MSVBVM60 ref: 004AE785
      • #710.MSVBVM60(00006008,?,00000000), ref: 004AE79A
      • __vbaStrMove.MSVBVM60 ref: 004AE7A5
      • __vbaStrCat.MSVBVM60(00000000), ref: 004AE7AC
      • __vbaStrMove.MSVBVM60 ref: 004AE7B7
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?), ref: 004AE7CB
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004AE7E4
      • #518.MSVBVM60(?,00004008), ref: 004AE815
      • #617.MSVBVM60(?,00004008,00000002), ref: 004AE841
      • #518.MSVBVM60(?,?), ref: 004AE855
      • __vbaInStrVar.MSVBVM60(?,00000000,?,?,00000001), ref: 004AE888
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 004AE896
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 004AE8C1
      • #685.MSVBVM60 ref: 004AE8E0
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AE8EE
      • __vbaFreeObj.MSVBVM60 ref: 004AE912
      • #617.MSVBVM60(?,00004008,00000001), ref: 004AE945
      • __vbaVarAdd.MSVBVM60(?,00000008,?,00000000), ref: 004AE976
      • #645.MSVBVM60(00000000), ref: 004AE97D
      • __vbaStrMove.MSVBVM60 ref: 004AE988
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004AE994
      • __vbaFreeStr.MSVBVM60 ref: 004AE9AC
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004AE9C2
      • #685.MSVBVM60 ref: 004AE9E1
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AE9EF
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004AEA3A
      • __vbaFreeObj.MSVBVM60 ref: 004AEA6D
      • #617.MSVBVM60(?,00004008,00000001), ref: 004AEAAF
      • __vbaVarAdd.MSVBVM60(?,00000008,?), ref: 004AEADE
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 004AEAE5
      • __vbaStrMove.MSVBVM60 ref: 004AEAF0
      • __vbaStrCopy.MSVBVM60 ref: 004AEAFE
      • __vbaFreeStr.MSVBVM60 ref: 004AEB07
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004AEB1D
      • __vbaStrCopy.MSVBVM60 ref: 004AEB3A
      • __vbaStrCopy.MSVBVM60 ref: 004AEB54
      • __vbaStrCopy.MSVBVM60 ref: 004AEB6E
      • __vbaStrCopy.MSVBVM60 ref: 004AEB83
      • __vbaFreeStr.MSVBVM60(?), ref: 004AEB95
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?), ref: 004AEEF4
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004AEF0D
      • #518.MSVBVM60(?,00004008), ref: 004AEF3E
      • #617.MSVBVM60(?,00004008,00000002), ref: 004AEF6A
      • #518.MSVBVM60(?,?), ref: 004AEF7E
      • __vbaInStrVar.MSVBVM60(?,00000000,?,?,00000001), ref: 004AEFB1
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 004AEFBF
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 004AEFEA
      • #685.MSVBVM60 ref: 004AF009
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AF017
      • __vbaFreeObj.MSVBVM60 ref: 004AF03B
      • #617.MSVBVM60(?,00004008,00000001), ref: 004AF06E
      • __vbaVarAdd.MSVBVM60(?,00000008,?,00000000), ref: 004AF09F
      • #645.MSVBVM60(00000000), ref: 004AF0A6
      • __vbaStrMove.MSVBVM60 ref: 004AF0B1
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004AF0BD
      • __vbaFreeStr.MSVBVM60 ref: 004AF0D5
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004AF0EB
      • #685.MSVBVM60 ref: 004AF10A
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AF118
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004AF163
      • __vbaFreeObj.MSVBVM60 ref: 004AF196
      • #617.MSVBVM60(?,00004008,00000001), ref: 004AF1D8
      • __vbaVarAdd.MSVBVM60(?,00000008,?), ref: 004AF207
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 004AF20E
      • __vbaStrMove.MSVBVM60 ref: 004AF219
      • __vbaStrCopy.MSVBVM60 ref: 004AF227
      • __vbaFreeStr.MSVBVM60 ref: 004AF230
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004AF246
      • __vbaStrCopy.MSVBVM60 ref: 004AF263
      • __vbaStrCopy.MSVBVM60 ref: 004AF27D
      • __vbaStrCopy.MSVBVM60 ref: 004AF297
      • __vbaStrCopy.MSVBVM60 ref: 004AF2AC
      • __vbaFreeStr.MSVBVM60(?), ref: 004AF2BE
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004AF2D7
      • __vbaAryMove.MSVBVM60(?,?), ref: 004AF314
      • __vbaAryMove.MSVBVM60(?,?), ref: 004AE6B3
        • Part of subcall function 004CDEB0: __vbaChkstk.MSVBVM60(00000000,00411816), ref: 004CDECE
        • Part of subcall function 004CDEB0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004CDEFE
        • Part of subcall function 004CDEB0: __vbaAryMove.MSVBVM60(?,?,?,?,?,00000000,00411816), ref: 004CDF1B
        • Part of subcall function 004CDEB0: __vbaAryCopy.MSVBVM60(?,?,?,00000003,?,?,?,00000000,00411816), ref: 004CDF42
        • Part of subcall function 004CDEB0: #685.MSVBVM60(?,?,?,00000000,00411816), ref: 004CDF4F
        • Part of subcall function 004CDEB0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 004CDF5A
        • Part of subcall function 004CDEB0: __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 004CDF72
        • Part of subcall function 004CDEB0: __vbaAryDestruct.MSVBVM60(00000000,?,004CDFB8,?,?,?,00000000,00411816), ref: 004CDFA5
        • Part of subcall function 004CDEB0: __vbaAryDestruct.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 004CDFB1
      • __vbaFreeStr.MSVBVM60(?), ref: 004AE690
        • Part of subcall function 004CDFD0: __vbaChkstk.MSVBVM60(?,00411816), ref: 004CDFEE
        • Part of subcall function 004CDFD0: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004CE01E
        • Part of subcall function 004CDFD0: __vbaAryMove.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004CE03B
        • Part of subcall function 004CDFD0: __vbaAryCopy.MSVBVM60(?,?,?,00000002,?,?,?,?,00411816), ref: 004CE062
        • Part of subcall function 004CDFD0: #685.MSVBVM60(?,?,?,?,00411816), ref: 004CE06F
        • Part of subcall function 004CDFD0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00411816), ref: 004CE07A
        • Part of subcall function 004CDFD0: __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 004CE092
        • Part of subcall function 004CDFD0: __vbaAryDestruct.MSVBVM60(00000000,?,004CE0D8,?,?,?,?,00411816), ref: 004CE0C5
        • Part of subcall function 004CDFD0: __vbaAryDestruct.MSVBVM60(00000000,?,?,?,?,?,00411816), ref: 004CE0D1
      • __vbaStrMove.MSVBVM60(0000FFFF,?,?,?), ref: 004AED48
      • __vbaStrCopy.MSVBVM60 ref: 004AED56
      • __vbaFreeStrList.MSVBVM60(00000004,0000FFFF,?,?,?), ref: 004AED6E
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004AED8A
      • __vbaStrCopy.MSVBVM60 ref: 004AEDA7
      • __vbaFreeStr.MSVBVM60(?), ref: 004AEDB9
      • __vbaAryMove.MSVBVM60(?,?), ref: 004AEDDC
      • __vbaAryMove.MSVBVM60(?,?), ref: 004AEDFF
      • __vbaVarDup.MSVBVM60 ref: 004AEE2C
      • __vbaVarDup.MSVBVM60 ref: 004AEE65
      • #710.MSVBVM60(00006008,?), ref: 004AEE8C
      • __vbaStrMove.MSVBVM60 ref: 004AEE97
      • __vbaStrCat.MSVBVM60(004787B4,00000000), ref: 004AEEA3
      • __vbaStrMove.MSVBVM60 ref: 004AEEAE
      • #710.MSVBVM60(00006008,?,00000000), ref: 004AEEC3
      • __vbaStrMove.MSVBVM60 ref: 004AEECE
      • __vbaStrCat.MSVBVM60(00000000), ref: 004AEED5
      • __vbaStrMove.MSVBVM60 ref: 004AEEE0
      • __vbaAryMove.MSVBVM60(?,?), ref: 004AF337
      • __vbaVarDup.MSVBVM60 ref: 004AF364
      • __vbaVarDup.MSVBVM60 ref: 004AF39D
      • #710.MSVBVM60(00006008,?), ref: 004AF3C4
      • __vbaStrMove.MSVBVM60 ref: 004AF3CF
      • __vbaStrCat.MSVBVM60(004787B4,00000000), ref: 004AF3DB
      • __vbaStrMove.MSVBVM60 ref: 004AF3E6
      • #710.MSVBVM60(00006008,?,00000000), ref: 004AF3FB
      • __vbaStrMove.MSVBVM60 ref: 004AF406
      • __vbaStrCat.MSVBVM60(00000000), ref: 004AF40D
      • __vbaStrMove.MSVBVM60 ref: 004AF418
      • __vbaFreeStrList.MSVBVM60(00000003,0000FFFF,?,?), ref: 004AF42C
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004AF445
      • #518.MSVBVM60(?,00004008), ref: 004AF476
      • #617.MSVBVM60(?,00004008,00000002), ref: 004AF4A2
      • #518.MSVBVM60(?,?), ref: 004AF4B6
      • __vbaInStrVar.MSVBVM60(?,00000000,?,?,00000001), ref: 004AF4E9
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 004AF4F7
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 004AF522
      • #685.MSVBVM60 ref: 004AF541
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AF54F
      • __vbaFreeObj.MSVBVM60 ref: 004AF573
      • #645.MSVBVM60(00004008,00000000), ref: 004AF59F
      • __vbaStrMove.MSVBVM60 ref: 004AF5AA
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004AF5B6
      • __vbaFreeStr.MSVBVM60 ref: 004AF5CE
      • #685.MSVBVM60 ref: 004AF5EA
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AF5F8
      • __vbaStrMove.MSVBVM60 ref: 004AF69D
      • __vbaStrCopy.MSVBVM60 ref: 004AF6AB
      • __vbaStrCopy.MSVBVM60 ref: 004AF6B9
      • __vbaStrMove.MSVBVM60 ref: 004AF6FF
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?), ref: 004AF731
      • __vbaStrCopy.MSVBVM60 ref: 004AF74C
      • __vbaStrCopy.MSVBVM60 ref: 004AF781
      • __vbaStrCopy.MSVBVM60 ref: 004AF796
      • __vbaFreeStr.MSVBVM60(?), ref: 004AF7A8
      • __vbaFreeStrList.MSVBVM60(00000005,?,?,?,?,?), ref: 004AFBEE
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004AFC0A
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AFC41
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AFC4F
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AFC5D
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AFC6B
      • __vbaFreeStrList.MSVBVM60(00000004,?,?,?,?,?,?,?,?), ref: 004AFC98
      • __vbaAryMove.MSVBVM60(?,?), ref: 004AFE1A
      • #685.MSVBVM60 ref: 004AFE27
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AFE35
      • __vbaFreeObj.MSVBVM60 ref: 004AFE59
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004AFE9D
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004AFEBA
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004AFEDB
      • #685.MSVBVM60 ref: 004AFEF0
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AFEFE
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004AFF49
      • __vbaFreeObj.MSVBVM60 ref: 004AFF7C
      • __vbaUbound.MSVBVM60(00000001,00000000), ref: 004AFF9E
      • __vbaVarDup.MSVBVM60 ref: 004AFFE4
      • #710.MSVBVM60(00006008,?), ref: 004B000B
      • __vbaStrMove.MSVBVM60 ref: 004B0016
      • __vbaFreeVar.MSVBVM60 ref: 004B0022
      • #619.MSVBVM60(?,00004008,00000001), ref: 004B0052
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004B007A
      • __vbaFreeVar.MSVBVM60 ref: 004B008D
      • __vbaLenBstr.MSVBVM60(?), ref: 004B00BC
      • #617.MSVBVM60(?,00004008,-00000001), ref: 004B00DA
      • __vbaStrVarMove.MSVBVM60(?), ref: 004B00E7
      • __vbaStrMove.MSVBVM60 ref: 004B00F2
      • __vbaFreeVar.MSVBVM60 ref: 004B00FE
      • #617.MSVBVM60(?,00004008,00000001), ref: 004B012E
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004B0156
      • __vbaFreeVar.MSVBVM60 ref: 004B0169
      • __vbaLenBstr.MSVBVM60(?), ref: 004B0198
      • #619.MSVBVM60(?,00004008,-00000001), ref: 004B01B6
      • __vbaStrVarMove.MSVBVM60(?), ref: 004B01C3
      • __vbaStrMove.MSVBVM60 ref: 004B01CE
      • __vbaFreeVar.MSVBVM60 ref: 004B01DA
      • __vbaLenBstr.MSVBVM60(?), ref: 004B01EB
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004B0208
      • __vbaUbound.MSVBVM60(00000001,00000000), ref: 004B022A
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AFC2A
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60 ref: 0051C666
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60 ref: 0051C67D
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C694
        • Part of subcall function 0051C3A0: #685.MSVBVM60 ref: 0051C798
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000), ref: 0051C7A3
        • Part of subcall function 0051C3A0: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0051C7EE
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60 ref: 0051C81E
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C87B
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051C886
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C8A7
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00000000,00411816), ref: 0051C8BD
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00000000,00411816), ref: 0051C8DB
        • Part of subcall function 0051C3A0: #520.MSVBVM60(?,00004008), ref: 0051C90E
        • Part of subcall function 0051C3A0: #518.MSVBVM60(?,?), ref: 0051C91C
      • __vbaStrMove.MSVBVM60 ref: 004AFCDD
      • __vbaStrCopy.MSVBVM60 ref: 004AFCEB
      • __vbaStrCopy.MSVBVM60 ref: 004AFCF9
      • __vbaStrMove.MSVBVM60(?,0000FFFF,?,?), ref: 004AFD1C
      • __vbaStrCmp.MSVBVM60(004740D4,00000000), ref: 004AFD28
      • __vbaFreeStrList.MSVBVM60(00000004,0000FFFF,?,?,?), ref: 004AFD4F
      • __vbaStrMove.MSVBVM60 ref: 004AFD78
      • __vbaStrCopy.MSVBVM60 ref: 004AFD86
      • __vbaStrCopy.MSVBVM60 ref: 004AFD94
      • __vbaStrMove.MSVBVM60(?,?,?,?), ref: 004AFDB7
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?), ref: 004AFDCB
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004AFDE4
      • __vbaStrCopy.MSVBVM60 ref: 004AF70D
        • Part of subcall function 00508110: __vbaChkstk.MSVBVM60(?,00411816,?,?,0049F441,?,?,?), ref: 0050812E
        • Part of subcall function 00508110: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 0050815E
        • Part of subcall function 00508110: __vbaStrCat.MSVBVM60(.lock,?,?,?,?,?,00411816), ref: 00508176
        • Part of subcall function 00508110: __vbaStrMove.MSVBVM60(?,?,?,?,?,00411816), ref: 00508181
        • Part of subcall function 00508110: __vbaStrCmp.MSVBVM60(true,007C07AC,00000000,?,?,?,?,?,00411816), ref: 005081AC
        • Part of subcall function 00508110: __vbaStrCmp.MSVBVM60(true,007C07AC), ref: 00508212
        • Part of subcall function 00508110: __vbaSetSystemError.MSVBVM60(00000064), ref: 0050822A
        • Part of subcall function 00508110: #598.MSVBVM60 ref: 00508237
        • Part of subcall function 00508110: __vbaStrCopy.MSVBVM60 ref: 00508266
        • Part of subcall function 00508110: #685.MSVBVM60 ref: 00508273
        • Part of subcall function 00508110: __vbaObjSet.MSVBVM60(?,00000000), ref: 0050827E
        • Part of subcall function 00508110: __vbaFreeObj.MSVBVM60 ref: 0050829F
        • Part of subcall function 00508110: #645.MSVBVM60(00004008,00000000), ref: 005082C5
        • Part of subcall function 00508110: __vbaStrMove.MSVBVM60 ref: 005082D0
        • Part of subcall function 00508110: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 005082DC
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?,?,?), ref: 004AF6E5
        • Part of subcall function 0051C3A0: #685.MSVBVM60 ref: 0051C5BE
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000), ref: 0051C5C9
        • Part of subcall function 0051C3A0: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0051C614
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60 ref: 0051C644
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C6A1
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051C6AC
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C6CD
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C6DA
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051C6E5
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C706
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00000000,00411816), ref: 0051C71C
        • Part of subcall function 0051C3A0: #645.MSVBVM60(00004008,00000000), ref: 0051C74D
        • Part of subcall function 0051C3A0: __vbaStrMove.MSVBVM60 ref: 0051C758
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0051C764
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60 ref: 0051C77C
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004AF643
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051C43A
        • Part of subcall function 0051C3A0: #520.MSVBVM60(?,00000008), ref: 0051C45B
        • Part of subcall function 0051C3A0: __vbaStrVarMove.MSVBVM60(?), ref: 0051C465
        • Part of subcall function 0051C3A0: __vbaStrMove.MSVBVM60 ref: 0051C470
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60 ref: 0051C479
        • Part of subcall function 0051C3A0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 0051C489
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,00000000,00411816), ref: 0051C4A1
        • Part of subcall function 0051C3A0: #520.MSVBVM60(?,00000008), ref: 0051C4C2
        • Part of subcall function 0051C3A0: __vbaStrVarMove.MSVBVM60(?), ref: 0051C4CC
        • Part of subcall function 0051C3A0: __vbaStrMove.MSVBVM60 ref: 0051C4D7
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60 ref: 0051C4E0
        • Part of subcall function 0051C3A0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 0051C4F0
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C500
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051C50B
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C52C
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00000000,00411816), ref: 0051C542
        • Part of subcall function 0051C3A0: #645.MSVBVM60(00004008,00000000), ref: 0051C573
        • Part of subcall function 0051C3A0: __vbaStrMove.MSVBVM60 ref: 0051C57E
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0051C58A
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60 ref: 0051C5A2
      • __vbaFreeObj.MSVBVM60 ref: 004AF676
      • __vbaStrMove.MSVBVM60 ref: 004AF7C4
      • __vbaStrCopy.MSVBVM60 ref: 004AF7D2
      • __vbaStrCopy.MSVBVM60 ref: 004AF7E0
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?,?,?), ref: 004AF80C
      • __vbaStrMove.MSVBVM60 ref: 004AF826
      • __vbaStrCopy.MSVBVM60 ref: 004AF834
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?), ref: 004AF858
      • __vbaStrCopy.MSVBVM60 ref: 004AF873
      • __vbaStrCopy.MSVBVM60 ref: 004AF8A5
      • __vbaFreeStr.MSVBVM60(?), ref: 004AF8B7
      • __vbaStrCopy.MSVBVM60 ref: 004AF8CF
      • #685.MSVBVM60 ref: 004AF8DC
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AF8EA
      • __vbaFreeObj.MSVBVM60 ref: 004AF90E
      • __vbaStrMove.MSVBVM60 ref: 004AF92A
      • __vbaStrCopy.MSVBVM60 ref: 004AF938
      • __vbaStrCopy.MSVBVM60 ref: 004AF946
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?,?,?), ref: 004AF972
      • __vbaStrMove.MSVBVM60 ref: 004AF98C
      • __vbaStrCopy.MSVBVM60 ref: 004AF99A
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?), ref: 004AF9BE
      • __vbaStrCopy.MSVBVM60 ref: 004AF9D9
      • __vbaStrCopy.MSVBVM60 ref: 004AFA0B
      • __vbaFreeStr.MSVBVM60(?), ref: 004AFA1D
      • __vbaStrCopy.MSVBVM60 ref: 004AFA35
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004AFA4E
      • __vbaStrCopy.MSVBVM60 ref: 004AFA7D
      • __vbaStrMove.MSVBVM60(0000FFFF), ref: 004AFA91
      • __vbaStrCopy.MSVBVM60 ref: 004AFA9F
      • __vbaFreeStrList.MSVBVM60(00000002,0000FFFF,?), ref: 004AFAAF
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004AFACB
      • __vbaStrCopy.MSVBVM60 ref: 004AFAE7
      • __vbaStrCopy.MSVBVM60 ref: 004AFAFC
      • __vbaStrCopy.MSVBVM60 ref: 004AFB0A
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 004AFB27
      • __vbaStrCmp.MSVBVM60(004740DC,?), ref: 004AFB43
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00411816), ref: 004AFB63
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,00411816), ref: 004AFB7A
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00411816), ref: 004AFB88
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00411816), ref: 004AFB96
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00411816), ref: 004AFBA4
      • __vbaStrMove.MSVBVM60(?,?,?,?), ref: 004AFBC4
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00411816), ref: 004AFBD2
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004AE5FC
        • Part of subcall function 00506210: __vbaChkstk.MSVBVM60(?,00411816,?,005309BD,?,?,?,?,?,00000000,?,00000000,00411816), ref: 0050622E
        • Part of subcall function 00506210: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 0050625E
        • Part of subcall function 00506210: #619.MSVBVM60(?,00004008,00000001), ref: 0050628B
        • Part of subcall function 00506210: #608.MSVBVM60(?,00000022), ref: 00506297
        • Part of subcall function 00506210: #617.MSVBVM60(?,00004008,00000001), ref: 005062C0
        • Part of subcall function 00506210: #608.MSVBVM60(?,00000022), ref: 005062CF
        • Part of subcall function 00506210: __vbaVarCmpEq.MSVBVM60(?,?,?), ref: 005062E4
        • Part of subcall function 00506210: __vbaVarCmpEq.MSVBVM60(?,?,?,00000000), ref: 00506300
        • Part of subcall function 00506210: __vbaVarAnd.MSVBVM60(?,00000000), ref: 0050630E
        • Part of subcall function 00506210: __vbaBoolVarNull.MSVBVM60(00000000), ref: 00506315
        • Part of subcall function 00506210: __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 0050633A
        • Part of subcall function 00506210: __vbaStrCopy.MSVBVM60(?,00000000,?,?,00411816), ref: 0050635D
        • Part of subcall function 00506210: #619.MSVBVM60(?,00004008,00000001), ref: 005063D5
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004AEBFA
      • __vbaStrCat.MSVBVM60(?,FCert: ), ref: 004AEC29
      • __vbaStrMove.MSVBVM60 ref: 004AEC34
      • __vbaFreeStr.MSVBVM60(0000FFFF), ref: 004AEC46
      • __vbaStrCopy.MSVBVM60 ref: 004AECAF
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004AECD8
      • __vbaStrMove.MSVBVM60 ref: 004AED09
      • __vbaStrCopy.MSVBVM60 ref: 004AED17
      • __vbaStrCopy.MSVBVM60 ref: 004AED25
        • Part of subcall function 0051C3A0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00530973,?,00000000,?,00000000,00411816), ref: 0051C3BE
        • Part of subcall function 0051C3A0: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 0051C3EE
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,00773364,?,00000000,?,00000000,00411816), ref: 0051C406
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051C420
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE34
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051CE3F
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE60
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(0051CED1,?,?,?,?,00000000,00411816), ref: 0051CEB8
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CEC1
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CECA
      • __vbaFreeObj.MSVBVM60 ref: 004AD2E8
        • Part of subcall function 004D5390: __vbaChkstk.MSVBVM60(00000000,00411816,004B1C27), ref: 004D53AE
        • Part of subcall function 004D5390: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,004B1C27), ref: 004D53DE
        • Part of subcall function 004D5390: __vbaStrCmp.MSVBVM60(00473D9C,0077EF34), ref: 004D5410
        • Part of subcall function 004D5390: __vbaStrCmp.MSVBVM60(null,0077EF34), ref: 004D542D
        • Part of subcall function 004D5390: __vbaStrCopy.MSVBVM60 ref: 004D5447
        • Part of subcall function 004D5390: #685.MSVBVM60 ref: 004D6690
        • Part of subcall function 004D5390: __vbaObjSet.MSVBVM60(?,00000000), ref: 004D669B
        • Part of subcall function 004D5390: __vbaFreeObj.MSVBVM60 ref: 004D66BC
        • Part of subcall function 004D5390: __vbaFreeStr.MSVBVM60(004D673B), ref: 004D6722
        • Part of subcall function 004D5390: __vbaFreeStr.MSVBVM60 ref: 004D672B
        • Part of subcall function 004D5390: __vbaFreeStr.MSVBVM60 ref: 004D6734
      • __vbaStrCopy.MSVBVM60 ref: 004B18D4
      • __vbaFreeStr.MSVBVM60(?), ref: 004B18E6
      • #685.MSVBVM60 ref: 004B18F3
      • __vbaObjSet.MSVBVM60(00000000,00000000), ref: 004B1901
      • __vbaFreeObj.MSVBVM60 ref: 004B1925
      • __vbaAryDestruct.MSVBVM60(00000000,?,004B1A7E), ref: 004B199C
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 004B19AB
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 004B19BA
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 004B19C9
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 004B19D8
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 004B19E7
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 004B19F6
        • Part of subcall function 00531FD0: __vbaChkstk.MSVBVM60(00000000,00411816,004CB93C,?,00000001,?,00000000,00411816), ref: 00531FEE
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053201E
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053202D
        • Part of subcall function 00531FD0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,004CB93C), ref: 0053203C
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 0053206B
        • Part of subcall function 00531FD0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532093
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 005320A6
        • Part of subcall function 00531FD0: __vbaStrCopy.MSVBVM60 ref: 005320CA
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00000008,?), ref: 005320F7
        • Part of subcall function 00531FD0: __vbaStrVarMove.MSVBVM60(?), ref: 00532104
        • Part of subcall function 00531FD0: __vbaStrMove.MSVBVM60 ref: 00532111
        • Part of subcall function 00531FD0: __vbaFreeStr.MSVBVM60 ref: 0053211A
        • Part of subcall function 00531FD0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532130
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 00532162
        • Part of subcall function 00531FD0: __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0053218A
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 0053219D
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Copy$Move$List$#685$CheckHresult$Error$#520$Chkstk$Destruct$#617$#518$#710$#645$#619System$Bstr$#608#711BoolBoundsConstructFixstrGenerateIndexLoadNullUbound$#598Ansi
      • String ID: .dll$:\SmartToken.ini$Action because Card Counter changed$Action because no Card found$Action: Screen is locked already$Action: is system process$AllowI2c$AllowI2c = true$Aloaha Smart Login$Aloaha Smartlogin$AloahaPKCS11.Connector$AutoLock$Card went missing. Will do Action: $CardLogon$Cert is gone$CloseToken$Considering I2C or Kerberos$Disable I2c_PKI Monitor$Doing Timer1$Done USB Softtoken/Sticklogon$Done trying USB Softtoken/Sticklogon$Enable I2c_PKI Monitor$Entering Action$Entering the Timer$FCert: $Generic$HKCU\Software\Aloaha\CSP\PKCS11Lib$HKCU\Software\Aloaha\csp\RemoveAction$HKLM\SOFTWARE\Aloaha\CSP\NoRemoveAction$HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\scremoveoption$HKLM\Software\Aloaha\CSP\PKCS11Lib$HKLM\Software\Aloaha\GINA\MonitorCertOnly$HKLM\Software\Aloaha\csp\RemoveAction$Hash$I2c_PKI Monitor was already disabled$I2c_PKI_Monitor already enabled$IDVal$Is System Process$LastCardCount: $LastReaderCount: $Leaving the timer$LightTimer: $MonitorCertOnly$MonitorCertOnly <> 1 And PKMode = False$MonitorI2C$MonitorI2C_$MonitorKerberos$MonitorPKI_$PKCS11Path$PKCSLock$PKLib$PolicyAction$RemoveAction$RemoveAction: $RemoveActionM$Reset$Settings$SoftToken is gone$Software\Aloaha\csp$StickLogon$Stopping Timer1$Trying USB Softtoken/Sticklogon$UDomName: $UserLoggedOnViaI2c = true$UserNameAndDomain is empty$UserNameAndDomain: $Using USB Softtoken/Sticklogon$WasLoggedOff = True$doing action 1$doing action 2$false$found a reader$going to count readers$going to disable the timer$going to enable I2c_PKI_Monitor$localnetwork$localsystem$network$null$readers counted: $system$timer is locked$tokenList$true$~
      • API String ID: 126214151-1364562389
      • Opcode ID: 9181668cd58c5a572318712952539cf6c71b8bd9b66fb1e705a2819cd31e2125
      • Instruction ID: 4ee7b796960acc7e304f822095a0738ff651d840935a446d35c40f36c76a3f86
      • Opcode Fuzzy Hash: 9181668cd58c5a572318712952539cf6c71b8bd9b66fb1e705a2819cd31e2125
      • Instruction Fuzzy Hash: 27F32A75900218EFDB14DFA0DD48BEEBBB4FF48305F1081A9E50AA72A1DB749A85CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004B4E7E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004B4EB7
      • __vbaStrCopy.MSVBVM60 ref: 004B4EE9
      • __vbaFreeStr.MSVBVM60(?), ref: 004B4F01
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004B4F1D
      • __vbaStrMove.MSVBVM60 ref: 004B4F3F
      • __vbaStrCopy.MSVBVM60 ref: 004B4F50
      • __vbaFreeStr.MSVBVM60 ref: 004B4F5C
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004B4F78
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001), ref: 004B4FA0
      • __vbaStrMove.MSVBVM60 ref: 004B4FC2
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004B4FCE
      • __vbaFreeStr.MSVBVM60 ref: 004B4FE9
      • __vbaStrMove.MSVBVM60 ref: 004B5012
      • __vbaStrCat.MSVBVM60(004775E8,00000000), ref: 004B501E
      • __vbaVarDup.MSVBVM60 ref: 004B5068
      • #711.MSVBVM60(?,?,?,000000FF,00000000), ref: 004B508A
      • __vbaChkstk.MSVBVM60(00000008), ref: 004B509C
      • __vbaVarIndexLoad.MSVBVM60(?,?,00000001,00000008), ref: 004B50D6
      • __vbaVarAdd.MSVBVM60(?,00000000,?,?,?,?,?,?,00411816), ref: 004B50E7
      • __vbaStrVarMove.MSVBVM60(00000000,?,?,?,?,?,?,00411816), ref: 004B50EE
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004B50FC
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004B510D
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?,?,?,00411816), ref: 004B5123
      • __vbaFreeVarList.MSVBVM60(00000005,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B5151
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004B516D
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001), ref: 004B5195
      • __vbaVarDup.MSVBVM60 ref: 004B51DE
      • #711.MSVBVM60(?,?,?,000000FF,00000000), ref: 004B5200
      • __vbaChkstk.MSVBVM60 ref: 004B520B
      • __vbaVarIndexLoad.MSVBVM60(?,?,00000001), ref: 004B5245
      • __vbaStrVarMove.MSVBVM60(00000000,?,?,?,?,?,?,00411816), ref: 004B524F
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004B525D
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004B526B
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004B5277
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?,?,?,?,?,?,?,00411816), ref: 004B5294
      • __vbaStrCopy.MSVBVM60 ref: 004B52B5
      • __vbaInStr.MSVBVM60(00000000,00477B8C,?,00000001), ref: 004B52D5
      • __vbaStrCopy.MSVBVM60 ref: 004B52F4
      • #520.MSVBVM60(?,00004008), ref: 004B5328
      • #518.MSVBVM60(?,?), ref: 004B533C
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004B5364
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004B5381
      • __vbaStrCopy.MSVBVM60(?,?,00411816), ref: 004B53AA
      • #520.MSVBVM60(?,00004008), ref: 004B53DE
      • #518.MSVBVM60(?,?), ref: 004B53F2
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004B541A
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004B5437
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,00411816), ref: 004B5460
        • Part of subcall function 0052D4C0: __vbaChkstk.MSVBVM60(?,00411816,004B1BE8), ref: 0052D4DE
        • Part of subcall function 0052D4C0: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816,004B1BE8), ref: 0052D50E
        • Part of subcall function 0052D4C0: __vbaStrCmp.MSVBVM60(00473D9C,00772F2C,?,?,?,?,00411816,004B1BE8), ref: 0052D526
        • Part of subcall function 0052D4C0: __vbaStrCmp.MSVBVM60(null,00772F2C,?,?,?,?,00411816,004B1BE8), ref: 0052D53F
        • Part of subcall function 0052D4C0: __vbaStrCopy.MSVBVM60(?,?,?,?,00411816,004B1BE8), ref: 0052D560
        • Part of subcall function 0052D4C0: #685.MSVBVM60(?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D916
        • Part of subcall function 0052D4C0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D921
        • Part of subcall function 0052D4C0: __vbaFreeObj.MSVBVM60(?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D942
        • Part of subcall function 0052D4C0: __vbaFreeStr.MSVBVM60(0052D9B8,?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D99F
        • Part of subcall function 0052D4C0: __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D9A8
        • Part of subcall function 0052D4C0: __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D9B1
      • #520.MSVBVM60(?,00004008), ref: 004B5493
      • #518.MSVBVM60(?,?), ref: 004B54A7
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004B54CF
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004B54EC
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00411816), ref: 004B5515
      • __vbaStrCmp.MSVBVM60(true,?,?,?,?,?,?,?,?,?,00411816), ref: 004B5531
      • #520.MSVBVM60(?,00004008), ref: 004B5576
      • #520.MSVBVM60(?,00004008), ref: 004B55B6
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?,0000000B), ref: 004B560F
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B561D
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?,00000000), ref: 004B5639
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B5647
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 004B565C
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004B5663
      • __vbaFreeVarList.MSVBVM60(00000004,?,0000000B,?,0000000B), ref: 004B568E
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004B57F7
        • Part of subcall function 004D5390: __vbaChkstk.MSVBVM60(00000000,00411816,004B1C27), ref: 004D53AE
        • Part of subcall function 004D5390: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,004B1C27), ref: 004D53DE
        • Part of subcall function 004D5390: __vbaStrCmp.MSVBVM60(00473D9C,0077EF34), ref: 004D5410
        • Part of subcall function 004D5390: __vbaStrCmp.MSVBVM60(null,0077EF34), ref: 004D542D
        • Part of subcall function 004D5390: __vbaStrCopy.MSVBVM60 ref: 004D5447
        • Part of subcall function 004D5390: #685.MSVBVM60 ref: 004D6690
        • Part of subcall function 004D5390: __vbaObjSet.MSVBVM60(?,00000000), ref: 004D669B
        • Part of subcall function 004D5390: __vbaFreeObj.MSVBVM60 ref: 004D66BC
        • Part of subcall function 004D5390: __vbaFreeStr.MSVBVM60(004D673B), ref: 004D6722
        • Part of subcall function 004D5390: __vbaFreeStr.MSVBVM60 ref: 004D672B
        • Part of subcall function 004D5390: __vbaFreeStr.MSVBVM60 ref: 004D6734
      • __vbaStrCat.MSVBVM60(?,Not doing Checkreader: ,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B56BD
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B56CB
      • __vbaStrCat.MSVBVM60(00477FFC,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B56D7
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B56E5
      • __vbaStrCat.MSVBVM60(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B56F6
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B5704
      • __vbaStrCat.MSVBVM60(00477FFC,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B5710
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B571E
      • __vbaStrCat.MSVBVM60(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B572F
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B573D
      • __vbaStrCat.MSVBVM60(00477FFC,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B5749
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B5757
      • __vbaStrBool.MSVBVM60(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B5769
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B5777
      • __vbaStrCat.MSVBVM60(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B577E
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004B578C
      • __vbaFreeStrList.MSVBVM60(00000008,?,?,?,?,?,?,?,?,?), ref: 004B57D8
      • #520.MSVBVM60(?,00004008), ref: 004B583D
      • #520.MSVBVM60(?,00004008), ref: 004B587E
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?,0000000B), ref: 004B58D7
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B58E5
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?,00000000), ref: 004B5901
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B590F
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 004B5924
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004B592B
      • __vbaFreeVarList.MSVBVM60(00000004,?,0000000B,?,0000000B), ref: 004B5956
      • __vbaStrCopy.MSVBVM60 ref: 004B5983
        • Part of subcall function 004CC360: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,?,00411816), ref: 004CC37E
        • Part of subcall function 004CC360: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004CC3AE
        • Part of subcall function 004CC360: __vbaStrToAnsi.MSVBVM60(00000000,screen-saver,00000000,00000000,00000040), ref: 004CC3D7
        • Part of subcall function 004CC360: __vbaSetSystemError.MSVBVM60(00000000), ref: 004CC3E6
        • Part of subcall function 004CC360: __vbaFreeStr.MSVBVM60 ref: 004CC3F5
        • Part of subcall function 004CC360: __vbaSetSystemError.MSVBVM60(00000000), ref: 004CC428
        • Part of subcall function 004CC360: #685.MSVBVM60 ref: 004CC55A
        • Part of subcall function 004CC360: __vbaObjSet.MSVBVM60(?,00000000), ref: 004CC565
        • Part of subcall function 004CC360: __vbaFreeObj.MSVBVM60 ref: 004CC57D
      • __vbaSetSystemError.MSVBVM60(000000C8), ref: 004B59ED
        • Part of subcall function 004CC360: __vbaStrToAnsi.MSVBVM60(00000000,Default,00000000,00000000,00000100), ref: 004CC452
        • Part of subcall function 004CC360: __vbaSetSystemError.MSVBVM60(00000000), ref: 004CC461
        • Part of subcall function 004CC360: __vbaFreeStr.MSVBVM60 ref: 004CC470
      • #518.MSVBVM60(?,00004008), ref: 004B5A6B
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001,0000000B), ref: 004B5AD7
      • __vbaVarCmpEq.MSVBVM60(?,00008002,00000000), ref: 004B5AEC
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B5AFA
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 004B5B0F
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004B5B16
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,0000000B,0000000B), ref: 004B5B41
      • __vbaStrCopy.MSVBVM60 ref: 004B5B6A
      • __vbaStrCopy.MSVBVM60 ref: 004B5B82
      • __vbaFreeStr.MSVBVM60(?), ref: 004B5B9A
      • #518.MSVBVM60(?,00004008), ref: 004B5BFA
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004B5C55
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004B5C83
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001,0000000B), ref: 004B5CC1
      • __vbaVarCmpEq.MSVBVM60(?,00008002,00000000), ref: 004B5CD6
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B5CE4
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 004B5CF9
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 004B5D0E
      • __vbaVarOr.MSVBVM60(?,0000000B,00000000), ref: 004B5D23
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004B5D2A
      • __vbaFreeVarList.MSVBVM60(00000006,?,?,0000000B,0000000B,0000000B,0000000B), ref: 004B5D63
      • __vbaStrBool.MSVBVM60(00000000,abort the timer: ), ref: 004B5D8E
      • __vbaStrMove.MSVBVM60 ref: 004B5D9C
      • __vbaStrCat.MSVBVM60(00000000), ref: 004B5DA3
      • __vbaStrMove.MSVBVM60 ref: 004B5DB1
      • __vbaStrCat.MSVBVM60(00477FFC,00000000), ref: 004B5DBD
      • __vbaStrMove.MSVBVM60 ref: 004B5DCB
        • Part of subcall function 0051D000: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,00000000,00411816), ref: 0051D01E
        • Part of subcall function 0051D000: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 0051D04E
        • Part of subcall function 0051D000: __vbaStrCmp.MSVBVM60(true,0077F45C,?,?,?,?,00411816), ref: 0051D066
        • Part of subcall function 0051D000: #685.MSVBVM60 ref: 0051D326
        • Part of subcall function 0051D000: __vbaObjSet.MSVBVM60(00000000,00000000), ref: 0051D331
        • Part of subcall function 0051D000: __vbaFreeObj.MSVBVM60 ref: 0051D352
        • Part of subcall function 0051D000: __vbaFreeStr.MSVBVM60(0051D393), ref: 0051D383
        • Part of subcall function 0051D000: __vbaFreeStr.MSVBVM60 ref: 0051D38C
      • __vbaStrBool.MSVBVM60(00000000,00000000), ref: 004B5DD8
      • __vbaStrMove.MSVBVM60 ref: 004B5DE6
      • __vbaStrCat.MSVBVM60(00000000), ref: 004B5DED
      • __vbaStrMove.MSVBVM60 ref: 004B5DFB
      • __vbaStrCat.MSVBVM60(00477FFC,00000000), ref: 004B5E07
      • __vbaStrMove.MSVBVM60 ref: 004B5E15
      • __vbaStrCat.MSVBVM60(0075AC14,00000000), ref: 004B5E23
      • __vbaStrMove.MSVBVM60 ref: 004B5E31
      • __vbaStrCat.MSVBVM60(00477FFC,00000000), ref: 004B5E3D
      • __vbaStrMove.MSVBVM60 ref: 004B5E4B
      • __vbaStrBool.MSVBVM60(00000000,00000000), ref: 004B5E58
      • __vbaStrMove.MSVBVM60 ref: 004B5E66
      • __vbaStrCat.MSVBVM60(00000000), ref: 004B5E6D
      • __vbaStrMove.MSVBVM60 ref: 004B5E7B
      • __vbaStrCat.MSVBVM60(00477FFC,00000000), ref: 004B5E87
      • __vbaStrMove.MSVBVM60 ref: 004B5E95
      • __vbaStrCat.MSVBVM60(?,00000000), ref: 004B5EA6
      • __vbaStrMove.MSVBVM60 ref: 004B5EB4
      • __vbaStrCat.MSVBVM60(00477FFC,00000000), ref: 004B5EC0
      • __vbaStrMove.MSVBVM60 ref: 004B5ECE
      • __vbaStrCat.MSVBVM60(?,00000000), ref: 004B5EDF
      • __vbaStrMove.MSVBVM60 ref: 004B5EED
      • __vbaFreeStrList.MSVBVM60(0000000E,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004B5F63
      • #518.MSVBVM60(?,00004008), ref: 004B5FC6
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004B6021
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004B604F
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001,0000000B), ref: 004B608D
      • __vbaVarCmpEq.MSVBVM60(?,00008002,00000000), ref: 004B60A2
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B60B0
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 004B60C5
        • Part of subcall function 004CC360: __vbaSetSystemError.MSVBVM60(00000000), ref: 004CC49B
        • Part of subcall function 004CC360: #685.MSVBVM60 ref: 004CC4AE
        • Part of subcall function 004CC360: __vbaObjSet.MSVBVM60(?,00000000), ref: 004CC4B9
        • Part of subcall function 004CC360: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000004C), ref: 004CC4EC
        • Part of subcall function 004CC360: __vbaFreeObj.MSVBVM60 ref: 004CC507
        • Part of subcall function 004CC360: __vbaSetSystemError.MSVBVM60(00000000), ref: 004CC547
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 004B60DA
      • __vbaVarOr.MSVBVM60(?,0000000B,00000000), ref: 004B60EF
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004B60F6
      • __vbaFreeVarList.MSVBVM60(00000006,?,?,0000000B,0000000B,0000000B,0000000B), ref: 004B612F
      • __vbaStrCopy.MSVBVM60 ref: 004B6159
      • __vbaFreeStr.MSVBVM60(?), ref: 004B6171
      • #520.MSVBVM60(?,00004008), ref: 004B61A5
      • #520.MSVBVM60(?,00004008), ref: 004B61D2
      • #617.MSVBVM60(?,?,00000001), ref: 004B61E8
      • #619.MSVBVM60(?,?,00000001), ref: 004B6212
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?), ref: 004B6241
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?,00000000), ref: 004B625D
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B626B
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004B6272
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 004B629D
      • __vbaStrMove.MSVBVM60 ref: 004B62C9
      • __vbaStrCopy.MSVBVM60 ref: 004B62DA
      • __vbaStrMove.MSVBVM60(?,?,?,?), ref: 004B631A
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?), ref: 004B6337
        • Part of subcall function 004D0AE0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00411816), ref: 004D0AFE
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D0B2B
        • Part of subcall function 004D0AE0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D0B3A
        • Part of subcall function 004D0AE0: #520.MSVBVM60(?,00004008), ref: 004D0B68
        • Part of subcall function 004D0AE0: __vbaStrVarMove.MSVBVM60(?), ref: 004D0B72
        • Part of subcall function 004D0AE0: __vbaStrMove.MSVBVM60 ref: 004D0B7D
        • Part of subcall function 004D0AE0: __vbaFreeVar.MSVBVM60 ref: 004D0B86
        • Part of subcall function 004D0AE0: __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D0B9C
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60 ref: 004D0BB5
        • Part of subcall function 004D0AE0: __vbaStrCat.MSVBVM60(?,get:,?), ref: 004D0BC8
        • Part of subcall function 004D0AE0: __vbaStrMove.MSVBVM60 ref: 004D0BD3
        • Part of subcall function 004D0AE0: __vbaStrMove.MSVBVM60(00000000), ref: 004D0BE4
        • Part of subcall function 004D0AE0: __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004D0BF4
        • Part of subcall function 004D0AE0: #520.MSVBVM60(?,00004008), ref: 004D0C19
        • Part of subcall function 004D0AE0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004D0C35
        • Part of subcall function 004D0AE0: __vbaFreeVar.MSVBVM60 ref: 004D0C42
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60 ref: 004D0C5F
      • #520.MSVBVM60(?,00000008,LastUCN), ref: 004B6501
      • #518.MSVBVM60(?,?), ref: 004B6515
      • __vbaStrVarMove.MSVBVM60(?), ref: 004B6522
      • __vbaStrMove.MSVBVM60 ref: 004B6530
      • __vbaFreeVarList.MSVBVM60(00000003,00000008,?,?), ref: 004B654D
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60 ref: 004D0C72
        • Part of subcall function 004D0AE0: #685.MSVBVM60 ref: 004D0C7F
        • Part of subcall function 004D0AE0: __vbaObjSet.MSVBVM60(?,00000000), ref: 004D0C8A
        • Part of subcall function 004D0AE0: __vbaFreeObj.MSVBVM60 ref: 004D0CAB
        • Part of subcall function 004D0AE0: __vbaFreeStr.MSVBVM60(004D0D0E), ref: 004D0CFE
        • Part of subcall function 004D0AE0: __vbaFreeStr.MSVBVM60 ref: 004D0D07
      • #520.MSVBVM60(?,00000008,LastUCN), ref: 004B6585
      • #518.MSVBVM60(?,?), ref: 004B6599
      • __vbaStrVarMove.MSVBVM60(?), ref: 004B65A6
      • __vbaStrMove.MSVBVM60 ref: 004B65B1
      • __vbaFreeVarList.MSVBVM60(00000003,00000008,?,?), ref: 004B65CE
      • __vbaInStr.MSVBVM60(00000000,\\.\,?,00000001), ref: 004B65EB
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004B6608
      • __vbaStrCopy.MSVBVM60 ref: 004B6622
      • #520.MSVBVM60(00000008,00004008), ref: 004B6688
      • #518.MSVBVM60(?,00000008), ref: 004B669C
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 004B66C4
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004B66E1
      • #520.MSVBVM60(?,00000008,CardLogon), ref: 004B6728
      • #518.MSVBVM60(?,?), ref: 004B673C
      • __vbaStrVarMove.MSVBVM60(?), ref: 004B6749
      • __vbaStrMove.MSVBVM60 ref: 004B6757
      • __vbaStrCopy.MSVBVM60 ref: 004B6768
      • __vbaFreeStr.MSVBVM60 ref: 004B6774
      • __vbaFreeVarList.MSVBVM60(00000003,00000008,?,?), ref: 004B6791
      • #520.MSVBVM60(00000008,00004008), ref: 004B67C7
      • #518.MSVBVM60(?,00000008), ref: 004B67DB
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 004B6803
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004B6820
      • #520.MSVBVM60(?,00000008,CardLogon), ref: 004B6867
      • #518.MSVBVM60(?,?), ref: 004B687B
      • __vbaStrVarMove.MSVBVM60(?), ref: 004B6888
      • __vbaStrMove.MSVBVM60 ref: 004B6896
      • __vbaStrCopy.MSVBVM60 ref: 004B68A7
      • __vbaFreeStr.MSVBVM60 ref: 004B68B3
      • __vbaFreeVarList.MSVBVM60(00000003,00000008,?,?), ref: 004B68D0
      • #520.MSVBVM60(00000008,00004008), ref: 004B6906
      • #518.MSVBVM60(?,00000008), ref: 004B691A
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 004B6942
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004B695F
      • #520.MSVBVM60(?,00000008,CardLogon), ref: 004B69A6
      • #518.MSVBVM60(?,?), ref: 004B69BA
      • __vbaStrVarMove.MSVBVM60(?), ref: 004B69C7
      • __vbaStrMove.MSVBVM60 ref: 004B69D5
      • __vbaStrCopy.MSVBVM60 ref: 004B69E6
      • __vbaFreeStr.MSVBVM60 ref: 004B69F2
      • __vbaFreeVarList.MSVBVM60(00000003,00000008,?,?), ref: 004B6A0F
      • #520.MSVBVM60(00000008,00004008), ref: 004B6A78
      • #518.MSVBVM60(?,00000008), ref: 004B6A8C
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 004B6AB4
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004B6AD1
      • __vbaNew2.MSVBVM60(00477E14,0054ED28), ref: 004B6B03
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00477E04,00000014), ref: 004B6B6C
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,0047A994,00000058), ref: 004B6BCF
      • #518.MSVBVM60(?,00000008), ref: 004B6C21
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 004B6C68
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 004B6C76
      • __vbaFreeObj.MSVBVM60 ref: 004B6C89
      • __vbaFreeVarList.MSVBVM60(00000003,00000008,?,?), ref: 004B6CA6
      • __vbaStrCopy.MSVBVM60 ref: 004B6CCF
      • #520.MSVBVM60(00000008,00004008), ref: 004B6D19
      • #518.MSVBVM60(?,00000008), ref: 004B6D2D
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 004B6D55
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004B6D72
      • #518.MSVBVM60(?,00000008), ref: 004B6DB4
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 004B6DFB
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 004B6E09
      • __vbaFreeVarList.MSVBVM60(00000003,00000008,?,?), ref: 004B6E2D
      • __vbaStrCopy.MSVBVM60 ref: 004B6E56
      • #520.MSVBVM60(00000008,00004008), ref: 004B6EA0
      • #518.MSVBVM60(?,00000008), ref: 004B6EB4
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004B6EDD
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?), ref: 004B6F10
      • __vbaVarOr.MSVBVM60(?,0000000B,00000000), ref: 004B6F25
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004B6F2C
      • __vbaFreeVarList.MSVBVM60(00000003,00000008,?,0000000B), ref: 004B6F50
      • __vbaStrCopy.MSVBVM60 ref: 004B6F7A
      • __vbaFreeStr.MSVBVM60(?), ref: 004B6F92
      • __vbaStrCopy.MSVBVM60 ref: 004B6FAD
      • __vbaAryRecMove.MSVBVM60(004741C8,?,?), ref: 004B6FD8
      • #520.MSVBVM60(00000008,00004008), ref: 004B700C
      • __vbaVarTstNe.MSVBVM60(00008008,00000008), ref: 004B7034
      • __vbaFreeVar.MSVBVM60 ref: 004B7047
      • __vbaStrCopy.MSVBVM60 ref: 004B706D
      • __vbaStrCopy.MSVBVM60 ref: 004B7085
      • #520.MSVBVM60(00000008,00004008), ref: 004B70B2
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,00000000), ref: 004B70E9
      • __vbaFreeVar.MSVBVM60 ref: 004B70F8
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004B710E
      • #520.MSVBVM60(00000008,00004008), ref: 004B714A
      • __vbaVarAdd.MSVBVM60(?,00000008,00000008), ref: 004B7179
      • __vbaStrVarVal.MSVBVM60(?,00000000), ref: 004B7187
      • __vbaStrMove.MSVBVM60(00000000), ref: 004B719B
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004B71A7
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004B71CB
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004B71E4
      • #520.MSVBVM60(00000008,00004008), ref: 004B722A
      • __vbaVarAdd.MSVBVM60(?,00000008,00000008,?), ref: 004B725D
      • __vbaStrVarVal.MSVBVM60(?,00000000), ref: 004B726B
      • __vbaFreeStr.MSVBVM60(00000000), ref: 004B727D
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004B7293
      • #520.MSVBVM60(00000008,00004008), ref: 004B72DD
      • __vbaVarAdd.MSVBVM60(?,00000008,00000008), ref: 004B731F
      • __vbaVarAdd.MSVBVM60(?,00000008,00000000), ref: 004B7334
      • __vbaVarAdd.MSVBVM60(?,00000008,00000000), ref: 004B7349
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 004B7350
      • __vbaStrMove.MSVBVM60 ref: 004B735E
      • __vbaFreeStr.MSVBVM60(?), ref: 004B7376
      • __vbaFreeVarList.MSVBVM60(00000004,00000008,?,?,?), ref: 004B739A
      • __vbaStrCopy.MSVBVM60 ref: 004B73B4
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004B7443
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004B7460
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004B75A9
      • __vbaFreeObj.MSVBVM60 ref: 004B75DC
      • __vbaAryRecCopy.MSVBVM60(004741C8,?,00000000), ref: 004B760B
      • __vbaUbound.MSVBVM60(00000001,00000000), ref: 004B7621
      • __vbaLbound.MSVBVM60(00000001,00000000), ref: 004B7640
      • #685.MSVBVM60 ref: 004B7673
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B7681
      • __vbaFreeObj.MSVBVM60 ref: 004B76A5
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004B7737
      • #685.MSVBVM60 ref: 004B774C
      • __vbaStrVarVal.MSVBVM60(?,00000008,?), ref: 004B70CD
        • Part of subcall function 004D1700: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,004BACFC,00000000), ref: 004D171E
        • Part of subcall function 004D1700: __vbaStrCopy.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 004D174B
        • Part of subcall function 004D1700: __vbaOnError.MSVBVM60(000000FF,?,00000001,00000000,00000000,00411816), ref: 004D175A
        • Part of subcall function 004D1700: __vbaStrMove.MSVBVM60 ref: 004D178B
        • Part of subcall function 004D1700: __vbaNew2.MSVBVM60(00477E14,0054ED28), ref: 004D17AB
        • Part of subcall function 004D1700: __vbaHresultCheckObj.MSVBVM60(00000000,?,00477E04,00000014), ref: 004D1811
        • Part of subcall function 004D1700: __vbaHresultCheckObj.MSVBVM60(00000000,?,0047A994,00000058), ref: 004D186E
        • Part of subcall function 004D1700: __vbaStrMove.MSVBVM60 ref: 004D189F
        • Part of subcall function 004D1700: __vbaFreeObj.MSVBVM60 ref: 004D18A8
        • Part of subcall function 004D1700: __vbaStrCmp.MSVBVM60(true,00000000), ref: 004D18C1
      • #685.MSVBVM60 ref: 004B73C1
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B73CF
      • __vbaFreeObj.MSVBVM60 ref: 004B73F3
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004B7484
      • #520.MSVBVM60(00000008,00004008), ref: 004B74C9
      • __vbaVarCmpNe.MSVBVM60(?,00008008,00000008,0000000B), ref: 004B74FF
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B750D
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004B7514
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,0000000B), ref: 004B7531
      • #685.MSVBVM60 ref: 004B7550
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B755E
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?,00000000), ref: 004BAF20
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004BAF2E
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004BAF35
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 004BAF60
      • __vbaStrMove.MSVBVM60 ref: 004BAF8C
      • __vbaStrCopy.MSVBVM60 ref: 004BAF9D
      • __vbaStrCopy.MSVBVM60 ref: 004BAFAE
      • __vbaStrCopy.MSVBVM60 ref: 004B62EB
        • Part of subcall function 00506210: __vbaChkstk.MSVBVM60(?,00411816,?,005309BD,?,?,?,?,?,00000000,?,00000000,00411816), ref: 0050622E
        • Part of subcall function 00506210: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 0050625E
        • Part of subcall function 00506210: #619.MSVBVM60(?,00004008,00000001), ref: 0050628B
        • Part of subcall function 00506210: #608.MSVBVM60(?,00000022), ref: 00506297
        • Part of subcall function 00506210: #617.MSVBVM60(?,00004008,00000001), ref: 005062C0
        • Part of subcall function 00506210: #608.MSVBVM60(?,00000022), ref: 005062CF
        • Part of subcall function 00506210: __vbaVarCmpEq.MSVBVM60(?,?,?), ref: 005062E4
        • Part of subcall function 00506210: __vbaVarCmpEq.MSVBVM60(?,?,?,00000000), ref: 00506300
        • Part of subcall function 00506210: __vbaVarAnd.MSVBVM60(?,00000000), ref: 0050630E
        • Part of subcall function 00506210: __vbaBoolVarNull.MSVBVM60(00000000), ref: 00506315
        • Part of subcall function 00506210: __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 0050633A
        • Part of subcall function 00506210: __vbaStrCopy.MSVBVM60(?,00000000,?,?,00411816), ref: 0050635D
        • Part of subcall function 00506210: #619.MSVBVM60(?,00004008,00000001), ref: 005063D5
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004B6350
      • #518.MSVBVM60(?,00004008), ref: 004B6386
      • #518.MSVBVM60(?,00004008), ref: 004B63D8
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 004B640B
      • __vbaVarCmpGt.MSVBVM60(?,00008002,00000000), ref: 004B6420
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?,00000000), ref: 004B643C
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004B644A
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004B6451
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 004B6475
      • __vbaStrCopy.MSVBVM60 ref: 004B649B
      • __vbaStrCopy.MSVBVM60(NoCardMissingDialog,true), ref: 004B64C7
      • __vbaInStr.MSVBVM60(00000000,\\.\,?,00000001), ref: 004B663C
      • __vbaStrMove.MSVBVM60(?,?,?,?), ref: 004BAFE0
      • __vbaStrCopy.MSVBVM60 ref: 004BAFF1
      • __vbaFreeStrList.MSVBVM60(00000004,?,?,?,?), ref: 004BB015
      • __vbaInStr.MSVBVM60(00000000,004778FC,?,00000001), ref: 004BB038
      • __vbaStrCopy.MSVBVM60 ref: 004BB057
      • #520.MSVBVM60(?,00004008), ref: 004BB08A
      • __vbaStrCopy.MSVBVM60 ref: 004B6655
        • Part of subcall function 0051C3A0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00530973,?,00000000,?,00000000,00411816), ref: 0051C3BE
        • Part of subcall function 0051C3A0: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 0051C3EE
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,00773364,?,00000000,?,00000000,00411816), ref: 0051C406
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051C420
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE34
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051CE3F
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE60
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(0051CED1,?,?,?,?,00000000,00411816), ref: 0051CEB8
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CEC1
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CECA
      • #520.MSVBVM60(?,00004008), ref: 004BAD65
      • #520.MSVBVM60(?,00004008), ref: 004BADA5
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?), ref: 004BADD4
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?,00000000), ref: 004BADF0
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004BADFE
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004BAE05
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004BAE22
      • #520.MSVBVM60(?,00004008), ref: 004BAE68
      • #520.MSVBVM60(?,00004008), ref: 004BAE95
      • #617.MSVBVM60(?,?,00000001), ref: 004BAEAB
      • #619.MSVBVM60(?,?,00000001), ref: 004BAED5
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?), ref: 004BAF04
      • __vbaStrCopy.MSVBVM60 ref: 004BBAC8
      • __vbaFreeStr.MSVBVM60(?), ref: 004BBAE0
      • #685.MSVBVM60 ref: 004BBAED
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BBAFB
      • __vbaFreeObj.MSVBVM60 ref: 004BBB1F
      • __vbaAryDestruct.MSVBVM60(004741C8,?,004BBCCD), ref: 004BBC1E
      • __vbaFreeStr.MSVBVM60 ref: 004BBC27
      • __vbaFreeStr.MSVBVM60 ref: 004BBC30
      • __vbaFreeStr.MSVBVM60 ref: 004BBC39
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 004BBC45
      • __vbaFreeStr.MSVBVM60 ref: 004BBC4E
      • __vbaFreeStr.MSVBVM60 ref: 004BBC57
      • __vbaFreeStr.MSVBVM60 ref: 004BBC60
      • __vbaFreeStr.MSVBVM60 ref: 004BBC69
      • __vbaFreeStr.MSVBVM60 ref: 004BBC72
      • __vbaFreeStr.MSVBVM60 ref: 004BBC7B
      • __vbaFreeStr.MSVBVM60 ref: 004BBC84
      • __vbaFreeStr.MSVBVM60 ref: 004BBC8D
      • __vbaFreeObj.MSVBVM60 ref: 004BBC96
      • __vbaFreeStr.MSVBVM60 ref: 004BBC9F
      • __vbaFreeStr.MSVBVM60 ref: 004BBCA8
      • __vbaFreeStr.MSVBVM60 ref: 004BBCB4
      • __vbaAryDestruct.MSVBVM60(004741C8,?), ref: 004BBCC6
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$Copy$List$#520$#518$Error$Bool$#685Null$Chkstk$CheckHresultSystem$#619$#617Destruct$#608#711AnsiBoundsGenerateIndexLoadNew2$LboundUbound
      • String ID: / $(T$AloahaCredentialsDLL.Provider$AloahaCredentialsdll.Provider$CapiUser from NativeCryptAPI is: $CapiUser: $CardLogon$Could not find Kerberos Card$Entering CheckReader$Found Kerberos Card: $Going to try AloahaCredentials.Provider$Going to try AloahaCredentialsDLL.Provider$HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableChangePassword$HKLM\Software\Aloaha\CSP\DisableChangePassword$LastRealUCN $LastUCN$Leaving CheckReader$LogonPKICard is equal UCNs$NoCardMissingDialog$Not doing Checkreader: $RealUCN$RetrievContainerName$RetrievContainerNameDoNotUseCache$Splash$UCNS$UdomName: $WasLoggedOnViaCard = true$WasLoggedOnViaCard is true$Workstation is NOT locked, reading WasLoggedOnViaCard, UserWasLoggedOn <> true$Workstation is locked, clearing UserWasLoggedON$WriteUCN $Writing userpass: $\\.\$_ATRs$_LogonCard$_UCNs$_UCNs = $_UCNsStamp$abort the timer: $aloaha_$disconnect$localsystem$network$system$true$vb6$~
      • API String ID: 1858184382-2722706244
      • Opcode ID: 9acb626a01edd8320fa53069d4b1519c6511411dc49d00bf076651c396ea74f3
      • Instruction ID: 835fc3f60f703cbd504f9c3ca1998a452352655656a13418400faedb9303a1bf
      • Opcode Fuzzy Hash: 9acb626a01edd8320fa53069d4b1519c6511411dc49d00bf076651c396ea74f3
      • Instruction Fuzzy Hash: 55E3EA75900219DFDB24DFA0DD48BDEB778BB48305F00C5EAE60AB6260DB745A89CF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaOnError.MSVBVM60(00000001), ref: 004BDD2B
        • Part of subcall function 004BD9C0: __vbaChkstk.MSVBVM60(00000000,00411816,?,004C0046,00000000,?,00000000), ref: 004BD9DE
        • Part of subcall function 004BD9C0: __vbaStrCopy.MSVBVM60(00000000,?,?,00000000,00411816), ref: 004BDA0B
        • Part of subcall function 004BD9C0: __vbaOnError.MSVBVM60(000000FF,?,00000000,00411816), ref: 004BDA1A
        • Part of subcall function 004BD9C0: #685.MSVBVM60(?,00000000,00411816), ref: 004BDA27
        • Part of subcall function 004BD9C0: __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004BDA32
        • Part of subcall function 004BD9C0: __vbaFreeObj.MSVBVM60(?,00000000,00411816), ref: 004BDA4A
        • Part of subcall function 004BD9C0: #578.MSVBVM60(?), ref: 004BDA69
        • Part of subcall function 004BD9C0: #685.MSVBVM60 ref: 004BDA79
        • Part of subcall function 004BD9C0: __vbaObjSet.MSVBVM60(?,00000000), ref: 004BDA84
        • Part of subcall function 004BD9C0: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004BDAB7
        • Part of subcall function 004BD9C0: __vbaFreeObj.MSVBVM60 ref: 004BDAE9
        • Part of subcall function 004BD9C0: #685.MSVBVM60 ref: 004BDB02
        • Part of subcall function 004BD9C0: __vbaObjSet.MSVBVM60(?,00000000), ref: 004BDB0D
        • Part of subcall function 004BD9C0: __vbaFreeObj.MSVBVM60 ref: 004BDB25
      • __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,00000000,00000000,00000000), ref: 004BDD50
      • __vbaStrToAnsi.MSVBVM60(?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDD78
      • __vbaSetSystemError.MSVBVM60(00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDD86
      • __vbaStrToUnicode.MSVBVM60(?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDD97
      • __vbaFreeStr.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDDA5
      • __vbaAryLock.MSVBVM60(?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDDBD
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDDDA
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDDE7
      • __vbaSetSystemError.MSVBVM60(000000FF,00000000,00000000,?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE0C
      • __vbaAryUnlock.MSVBVM60(?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE16
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE22
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE2F
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE3A
      • __vbaUbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE46
      • __vbaUbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE64
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE77
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE81
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE97
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDE9E
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDEBE
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDED8
      • __vbaLbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDEED
      • __vbaUbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDEFB
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDF14
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDF1B
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDF3F
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDF65
      • __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,-00000003,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDF91
      • __vbaAryLock.MSVBVM60(?,?), ref: 004BDFA2
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BDFBF
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BDFCD
      • __vbaAryLock.MSVBVM60(?,?), ref: 004BDFE1
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BDFFE
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BE00B
      • __vbaSetSystemError.MSVBVM60(00000000,?,-00000002), ref: 004BE036
      • __vbaAryUnlock.MSVBVM60(?), ref: 004BE046
      • __vbaAryUnlock.MSVBVM60(?), ref: 004BE04C
      • #685.MSVBVM60 ref: 004BE04E
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BE055
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C), ref: 004BE079
      • __vbaFreeObj.MSVBVM60 ref: 004BE093
      • __vbaAryCopy.MSVBVM60(?,?), ref: 004BE0A6
      • __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,00000000,00000000), ref: 004BE0BF
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE0CE
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE0D5
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE0E6
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE0E8
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE0EF
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE0FA
      • __vbaAryCopy.MSVBVM60(?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE104
      • __vbaUbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE110
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE11F
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE126
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE146
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE160
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE18C
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE19F
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE1C1
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE1CA
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE1E8
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE1F5
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE217
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE224
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE246
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE253
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE275
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE282
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE2A4
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE2AD
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE2CF
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE2D7
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE389
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE396
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE3B6
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE3DA
      • __vbaVar2Vec.MSVBVM60(?,?,?,00000000,?,00000004,00000080,00000000), ref: 004BE430
      • __vbaAryMove.MSVBVM60(?,?,?,00000004,00000080,00000000), ref: 004BE441
      • __vbaFreeVar.MSVBVM60(?,00000004,00000080,00000000), ref: 004BE44A
      • #685.MSVBVM60(?,00000004,00000080,00000000), ref: 004BE450
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000004,00000080,00000000), ref: 004BE457
      • __vbaFreeObj.MSVBVM60(?,00000004,00000080,00000000), ref: 004BE462
      • __vbaUbound.MSVBVM60(00000001,?,?,00000004,00000080,00000000), ref: 004BE46A
      • #685.MSVBVM60(?,00000004,00000080,00000000), ref: 004BE475
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000004,00000080,00000000), ref: 004BE47C
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C,?,00000004,00000080,00000000), ref: 004BE49C
      • __vbaFreeObj.MSVBVM60(?,00000004,00000080,00000000), ref: 004BE4B6
      • __vbaAryCopy.MSVBVM60(?,?,?,00000004,00000080,00000000), ref: 004BE4C9
      • __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,00000000,00000000,?,00000004,00000080,00000000), ref: 004BE4E2
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE4EB
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE4F2
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE501
      • #518.MSVBVM60(?,00004008,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE525
      • #619.MSVBVM60(?,?,00000004,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE535
      • __vbaVarTstEq.MSVBVM60(00008008,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE55A
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE56C
      • __vbaStrMove.MSVBVM60(?,00000004,00000080,00000000), ref: 004BE592
      • __vbaStrCopy.MSVBVM60 ref: 004BE5A7
      • __vbaSetSystemError.MSVBVM60(000000FF), ref: 004BE5B6
      • __vbaStrToAnsi.MSVBVM60(?,00000000,80000000,00000000,00000000,00000004,00000080,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE5DD
      • __vbaSetSystemError.MSVBVM60(00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE5EB
      • __vbaStrToUnicode.MSVBVM60(?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE5F9
      • __vbaFreeStr.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE607
      • __vbaAryLock.MSVBVM60(?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE61F
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE63C
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE649
      • __vbaSetSystemError.MSVBVM60(000000FF,00000000,00000000,?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE66E
      • __vbaAryUnlock.MSVBVM60(?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE678
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE684
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE691
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE69C
      • __vbaUbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE6A8
      • __vbaUbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE6C6
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE6D9
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE6E3
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE6F9
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE700
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE720
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE73A
      • __vbaLbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE74F
      • __vbaUbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE75D
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE776
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE77D
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE7A1
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE7C7
      • __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,-00000003,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE7F3
      • __vbaAryLock.MSVBVM60(?,?), ref: 004BE804
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BE821
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BE82F
      • __vbaAryLock.MSVBVM60(?,?), ref: 004BE843
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BE860
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BE86D
      • __vbaSetSystemError.MSVBVM60(00000000,?,-00000002), ref: 004BE898
      • __vbaAryUnlock.MSVBVM60(?), ref: 004BE8A8
      • __vbaAryUnlock.MSVBVM60(?), ref: 004BE8AE
      • #685.MSVBVM60 ref: 004BE8B0
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BE8B7
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C), ref: 004BE8DB
      • __vbaFreeObj.MSVBVM60 ref: 004BE8F5
      • __vbaAryCopy.MSVBVM60(?,?), ref: 004BE908
      • __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,00000000,00000000), ref: 004BE921
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE930
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE937
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE948
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE94A
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE951
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE95C
      • __vbaAryCopy.MSVBVM60(?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE966
      • __vbaUbound.MSVBVM60(00000001,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE972
      • #685.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE981
      • __vbaObjSet.MSVBVM60(?,00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE988
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE9A8
      • __vbaFreeObj.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE9C2
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BE9EE
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEA01
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEA23
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEA30
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEA52
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEA5F
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEA81
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEA8E
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEAB0
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEABD
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEADF
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEAEC
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEB0E
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEB1B
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEB3D
      • __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BEB41
      • __vbaVar2Vec.MSVBVM60(?,?,?,00000000,?,00000004,00000080,00000000), ref: 004BEC3C
      • __vbaAryMove.MSVBVM60(?,?,?,00000004,00000080,00000000), ref: 004BEC4D
      • __vbaFreeVar.MSVBVM60(?,00000004,00000080,00000000), ref: 004BEC56
      • #685.MSVBVM60(?,00000004,00000080,00000000), ref: 004BEC62
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000004,00000080,00000000), ref: 004BEC6F
      • __vbaFreeObj.MSVBVM60(?,00000004,00000080,00000000), ref: 004BEC80
      • __vbaUbound.MSVBVM60(00000001,?,?,00000004,00000080,00000000), ref: 004BEC88
      • #685.MSVBVM60(?,00000004,00000080,00000000), ref: 004BEC97
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000004,00000080,00000000), ref: 004BEC9E
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C,?,00000004,00000080,00000000), ref: 004BECBE
      • __vbaFreeObj.MSVBVM60(?,00000004,00000080,00000000), ref: 004BECD8
        • Part of subcall function 004F1A10: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,004C015E), ref: 004F1A2E
        • Part of subcall function 004F1A10: __vbaOnError.MSVBVM60(000000FF,?,?,6D641654,00000000,00411816), ref: 004F1A5E
        • Part of subcall function 004F1A10: __vbaStrCopy.MSVBVM60 ref: 004F1A73
        • Part of subcall function 004F1A10: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004F1A8B
        • Part of subcall function 004F1A10: __vbaStrCopy.MSVBVM60 ref: 004F1AA5
        • Part of subcall function 004F1A10: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004F1D97
        • Part of subcall function 004F1A10: __vbaStrMove.MSVBVM60(00000000), ref: 004F1DBA
        • Part of subcall function 004F1A10: __vbaStrCopy.MSVBVM60 ref: 004F1DCD
        • Part of subcall function 004F1A10: #685.MSVBVM60 ref: 004F1DDA
        • Part of subcall function 004F1A10: __vbaObjSet.MSVBVM60(?,00000000), ref: 004F1DE5
        • Part of subcall function 004F1A10: __vbaFreeObj.MSVBVM60 ref: 004F1E06
        • Part of subcall function 004F1A10: __vbaFreeStr.MSVBVM60(004F1E5F), ref: 004F1E4F
        • Part of subcall function 004F1A10: __vbaFreeStr.MSVBVM60 ref: 004F1E58
      • __vbaStrMove.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BECFD
        • Part of subcall function 005114A0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,004C0171,00000000), ref: 005114BE
        • Part of subcall function 005114A0: __vbaOnError.MSVBVM60(000000FF,6D62D8B1,?,6D641654,00000000,00411816), ref: 005114EE
        • Part of subcall function 005114A0: __vbaSetSystemError.MSVBVM60(?), ref: 00511504
        • Part of subcall function 005114A0: __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,00000027,00000000), ref: 00511546
        • Part of subcall function 005114A0: __vbaAryLock.MSVBVM60(?,?), ref: 0051155E
        • Part of subcall function 005114A0: #644.MSVBVM60(?), ref: 005115CE
        • Part of subcall function 005114A0: __vbaAryUnlock.MSVBVM60(00000000), ref: 005115DE
        • Part of subcall function 005114A0: __vbaSetSystemError.MSVBVM60(?,?,?), ref: 005115FE
        • Part of subcall function 005114A0: __vbaStrVarCopy.MSVBVM60(00002011,?), ref: 0051163B
      • __vbaStrMove.MSVBVM60(00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BED0E
      • __vbaStrCat.MSVBVM60(00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BED15
      • __vbaStrMove.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BED20
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BED30
        • Part of subcall function 004C2E80: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,00000000,00000000,?,00411816), ref: 004C2E9E
        • Part of subcall function 004C2E80: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816,?), ref: 004C2ECE
        • Part of subcall function 004C2E80: __vbaStrCmp.MSVBVM60(00473D9C,?,?,00000000,00000000,00000000,00411816,?), ref: 004C2EE6
        • Part of subcall function 004C2E80: #518.MSVBVM60(?,00004008), ref: 004C2F17
        • Part of subcall function 004C2E80: __vbaVarCmpNe.MSVBVM60(?,00008008,?,0000000B), ref: 004C2F3E
        • Part of subcall function 004C2E80: __vbaVarAnd.MSVBVM60(?,00000000), ref: 004C2F49
        • Part of subcall function 004C2E80: __vbaBoolVarNull.MSVBVM60(00000000), ref: 004C2F50
        • Part of subcall function 004C2E80: __vbaFreeVarList.MSVBVM60(00000002,?,0000000B), ref: 004C2F6A
        • Part of subcall function 004C2E80: __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001,00000000,00000000,00411816,?), ref: 004C2F98
        • Part of subcall function 004C2E80: #685.MSVBVM60(?,00000001,00000000,00000000,00411816,?), ref: 004C2FAD
        • Part of subcall function 004C2E80: __vbaObjSet.MSVBVM60(00000001,00000000,?,00000001,00000000,00000000,00411816,?), ref: 004C2FB8
        • Part of subcall function 004C2E80: __vbaFreeObj.MSVBVM60(?,00000001,00000000,00000000,00411816,?), ref: 004C2FD9
        • Part of subcall function 004C2E80: __vbaChkstk.MSVBVM60 ref: 004C3006
        • Part of subcall function 004C1250: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,0051C9A3,?,?,?,?,?,?,?,?,?,?), ref: 004C126E
        • Part of subcall function 004C1250: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 004C129E
        • Part of subcall function 004C1250: #685.MSVBVM60 ref: 004C12B8
        • Part of subcall function 004C1250: __vbaObjSet.MSVBVM60(?,00000000), ref: 004C12C3
        • Part of subcall function 004C1250: __vbaFreeObj.MSVBVM60 ref: 004C12E4
        • Part of subcall function 004C1250: #632.MSVBVM60(?,00004008,00000003,00000002), ref: 004C1323
        • Part of subcall function 004C1250: #617.MSVBVM60(?,00004008,00000002), ref: 004C1360
        • Part of subcall function 004C1250: __vbaVarCmpEq.MSVBVM60(?,00008008,?), ref: 004C1389
        • Part of subcall function 004C1250: __vbaVarCmpEq.MSVBVM60(?,00008008,?,00000000), ref: 004C13A5
        • Part of subcall function 004C1250: __vbaVarOr.MSVBVM60(?,00000000), ref: 004C13B3
        • Part of subcall function 004C1250: __vbaBoolVarNull.MSVBVM60(00000000), ref: 004C13BA
        • Part of subcall function 004C1250: __vbaFreeVarList.MSVBVM60(00000003,00000002,?,?), ref: 004C13D8
        • Part of subcall function 004C43A0: __vbaChkstk.MSVBVM60(?,00411816,?,004C01B5,?,?,?,?), ref: 004C43BE
        • Part of subcall function 004C43A0: __vbaOnError.MSVBVM60(000000FF,6D62D8B1,?,6D641654,?,00411816), ref: 004C43EE
        • Part of subcall function 004C43A0: #518.MSVBVM60(?,00004008), ref: 004C4410
        • Part of subcall function 004C43A0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004C4432
        • Part of subcall function 004C43A0: __vbaFreeVar.MSVBVM60 ref: 004C4442
        • Part of subcall function 004C43A0: #685.MSVBVM60(?), ref: 004C455B
        • Part of subcall function 004C43A0: __vbaObjSet.MSVBVM60(?,00000000), ref: 004C4566
        • Part of subcall function 004C43A0: __vbaFreeObj.MSVBVM60 ref: 004C4587
      • __vbaStrToAnsi.MSVBVM60(?,?,C0000000,00000000,00000000,00000004,00000080,00000000,?,?,?,?,00000004,00000080,00000000), ref: 004BED7C
      • __vbaSetSystemError.MSVBVM60(00000000), ref: 004BED8A
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 004BED98
      • __vbaFreeStr.MSVBVM60 ref: 004BEDA6
      • __vbaAryLock.MSVBVM60(?,?), ref: 004BEDBD
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEDDA
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEDE7
      • __vbaSetSystemError.MSVBVM60(000000FF,00000000,00000000,?,00000000), ref: 004BEE0C
      • __vbaAryUnlock.MSVBVM60(?), ref: 004BEE16
      • #685.MSVBVM60 ref: 004BEE22
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BEE2F
      • __vbaFreeObj.MSVBVM60 ref: 004BEE3A
      • __vbaAryCopy.MSVBVM60(?,?), ref: 004BEE48
      • __vbaUbound.MSVBVM60(00000001,?), ref: 004BEE54
      • #685.MSVBVM60 ref: 004BEE63
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BEE6A
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C), ref: 004BEE8A
      • __vbaFreeObj.MSVBVM60 ref: 004BEEA4
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEED0
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEEE3
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEF05
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEF12
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEF34
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEF41
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEF63
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEF70
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEF92
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEF9F
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEFC1
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEFCE
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEFF0
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BEFFD
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BF01F
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004BF023
      • __vbaVar2Vec.MSVBVM60(?,?,?,00000000), ref: 004BF11A
      • __vbaAryMove.MSVBVM60(?,?), ref: 004BF12B
      • __vbaFreeVar.MSVBVM60 ref: 004BF134
      • #685.MSVBVM60 ref: 004BF140
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BF14D
      • __vbaFreeObj.MSVBVM60 ref: 004BF158
      • __vbaUbound.MSVBVM60(00000001,?), ref: 004BF164
      • #685.MSVBVM60 ref: 004BF173
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BF17A
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004747A8,0000001C), ref: 004BF19A
      • __vbaFreeObj.MSVBVM60 ref: 004BF1B4
      • __vbaAryCopy.MSVBVM60(?,?), ref: 004BF1C7
      • __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,00000000,00000000), ref: 004BF1E0
      • #685.MSVBVM60 ref: 004BF1F7
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BF1FE
      • __vbaFreeObj.MSVBVM60 ref: 004BF209
      • #518.MSVBVM60(?,00004008), ref: 004BF22D
      • #619.MSVBVM60(?,?,00000004), ref: 004BF23D
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004BF262
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004BF274
      • __vbaStrMove.MSVBVM60(?), ref: 004BF29A
      • __vbaStrCopy.MSVBVM60 ref: 004BF2AF
      • __vbaSetSystemError.MSVBVM60(000000FF), ref: 004BF2BE
      • #685.MSVBVM60(?,?,?,?,?,00000004,00000080,00000000), ref: 004BF2CD
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BF2D8
      • __vbaFreeObj.MSVBVM60 ref: 004BF2E7
      • __vbaExitProc.MSVBVM60 ref: 004BF2ED
      • __vbaAryDestruct.MSVBVM60(00000000,?,004BF388), ref: 004BF36D
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 004BF375
      • __vbaFreeStr.MSVBVM60 ref: 004BF380
      • __vbaFreeStr.MSVBVM60 ref: 004BF385
      • __vbaErrorOverflow.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BF39E
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Error$BoundsGenerate$Free$#685$CheckCopyHresult$SystemUbound$Move$LockRedimUnlock$Chkstk$List$#518$AnsiUnicodeVar2$#619BoolDestructLboundNull$#578#617#632#644ExitOverflowProc
      • String ID: .pdf
      • API String ID: 1123823117-2417493391
      • Opcode ID: da0f265534499804ef5066421521ed21883d48636a4419ec4844a939776b25e9
      • Instruction ID: 7a0ddeacd2a6f6e9b1e2d193799c705364be4a3597f37b9405b9559b03db540c
      • Opcode Fuzzy Hash: da0f265534499804ef5066421521ed21883d48636a4419ec4844a939776b25e9
      • Instruction Fuzzy Hash: 05E29D31A002189FDB24DFA5CD44BEEB7B5BF88700F1485A9E506BB250DB74AD85CFA4
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 0053D51E
      • __vbaFixstrConstruct.MSVBVM60(00000800,?,?,?,?,?,00411816), ref: 0053D551
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 0053D560
      • #685.MSVBVM60(?,?,?,?,00411816), ref: 0053D56D
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00411816), ref: 0053D57B
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 0053D59F
        • Part of subcall function 00531FD0: __vbaChkstk.MSVBVM60(00000000,00411816,004CB93C,?,00000001,?,00000000,00411816), ref: 00531FEE
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053201E
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053202D
        • Part of subcall function 00531FD0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,004CB93C), ref: 0053203C
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 0053206B
        • Part of subcall function 00531FD0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532093
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 005320A6
        • Part of subcall function 00531FD0: __vbaStrCopy.MSVBVM60 ref: 005320CA
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00000008,?), ref: 005320F7
        • Part of subcall function 00531FD0: __vbaStrVarMove.MSVBVM60(?), ref: 00532104
        • Part of subcall function 00531FD0: __vbaStrMove.MSVBVM60 ref: 00532111
        • Part of subcall function 00531FD0: __vbaFreeStr.MSVBVM60 ref: 0053211A
        • Part of subcall function 00531FD0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532130
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 00532162
        • Part of subcall function 00531FD0: __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0053218A
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 0053219D
      • __vbaSetSystemError.MSVBVM60(00000000,?,?,00000000), ref: 0053D602
      • __vbaUbound.MSVBVM60(00000001,00000000), ref: 0053D631
      • #685.MSVBVM60 ref: 0053D646
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0053D654
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0053D69F
      • __vbaFreeObj.MSVBVM60 ref: 0053D6D2
      • __vbaAryLock.MSVBVM60(?), ref: 0053D6FB
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0053D744
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0053D75E
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0053D78C
      • __vbaUbound.MSVBVM60(00000001), ref: 0053D7A0
      • __vbaSetSystemError.MSVBVM60(?,?,-00000001), ref: 0053D7D3
      • __vbaAryUnlock.MSVBVM60(00000000), ref: 0053D7E0
      • __vbaLenBstr.MSVBVM60(?), ref: 0053D7F4
      • __vbaStrToAnsi.MSVBVM60(?,?,?), ref: 0053D830
      • __vbaSetSystemError.MSVBVM60(00000000,?,00000000,00000000,00000000), ref: 0053D854
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 0053D868
      • __vbaLsetFixstr.MSVBVM60(00000000,?,00000000), ref: 0053D878
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 0053D897
      • __vbaStrToAnsi.MSVBVM60(?,?,?), ref: 0053D8C1
      • __vbaSetSystemError.MSVBVM60(?,?,00000000,00000000,00000000), ref: 0053D8E2
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 0053D8F6
      • __vbaLsetFixstr.MSVBVM60(00000000,?,00000000), ref: 0053D906
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 0053D925
      • #608.MSVBVM60(?,00000000), ref: 0053D94F
      • __vbaStrCopy.MSVBVM60(00477FFC,00473D9C,00000001,000000FF,00000000), ref: 0053D971
      • #712.MSVBVM60(00000000), ref: 0053D978
      • __vbaStrMove.MSVBVM60 ref: 0053D986
      • __vbaLsetFixstr.MSVBVM60(00000000,?,?), ref: 0053D99C
      • __vbaStrVarVal.MSVBVM60(?,?,00473D9C,00000001,000000FF,00000000), ref: 0053D9BB
      • __vbaStrCopy.MSVBVM60(00000000), ref: 0053D9CE
      • #712.MSVBVM60(00000000), ref: 0053D9D5
      • __vbaStrMove.MSVBVM60 ref: 0053D9E3
      • __vbaLsetFixstr.MSVBVM60(00000000,?,?), ref: 0053D9F9
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 0053DA0B
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 0053DA27
      • __vbaFreeStrList.MSVBVM60(00000005,?,?,?,?,?), ref: 0053DA64
      • __vbaFreeVar.MSVBVM60 ref: 0053DA73
      • __vbaStrCopy.MSVBVM60 ref: 0053DADF
      • #608.MSVBVM60(?,00000000), ref: 0053DAF5
      • __vbaStrCopy.MSVBVM60(?,000000FF,00000000), ref: 0053DB26
      • #711.MSVBVM60(?,00000000), ref: 0053DB34
      • __vbaLsetFixstr.MSVBVM60(00000000,?,?), ref: 0053DB4A
      • __vbaChkstk.MSVBVM60 ref: 0053DB55
      • __vbaVarIndexLoadRefLock.MSVBVM60(?,?,?,00000001), ref: 0053DB96
      • #520.MSVBVM60(?,00000000), ref: 0053DBA7
      • __vbaAryUnlock.MSVBVM60(?), ref: 0053DBB4
      • #608.MSVBVM60(?,00000000), ref: 0053DBC3
      • __vbaStrVarVal.MSVBVM60(?,?,00473D9C,00000001,000000FF,00000000), ref: 0053DBE2
      • __vbaStrVarVal.MSVBVM60(?,?,00000000), ref: 0053DBF7
      • #712.MSVBVM60(00000000), ref: 0053DBFE
      • __vbaStrMove.MSVBVM60 ref: 0053DC0C
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?), ref: 0053DC29
      • __vbaFreeVarList.MSVBVM60(00000005,?,?,?,?,?), ref: 0053DC57
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 0053DC73
      • __vbaRedimPreserve.MSVBVM60(00000180,00000004,?,00000008,00000001,?,00000000), ref: 0053DCA0
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0053DCEB
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0053DD08
      • __vbaStrCopy.MSVBVM60 ref: 0053DD26
      • __vbaStrCopy.MSVBVM60 ref: 0053DD3F
      • __vbaLenBstr.MSVBVM60(?), ref: 0053DD62
      • __vbaLenBstr.MSVBVM60(?), ref: 0053DD71
      • #619.MSVBVM60(?,00004008,-00000001), ref: 0053DD97
      • __vbaLsetFixstr.MSVBVM60(00000000,?,?), ref: 0053DDAD
      • __vbaStrVarMove.MSVBVM60(?), ref: 0053DDBA
      • __vbaLsetFixstrFree.MSVBVM60(00000000,?,00000000), ref: 0053DDCA
      • __vbaFreeStr.MSVBVM60 ref: 0053DDD6
      • __vbaFreeVar.MSVBVM60 ref: 0053DDE2
      • __vbaSetSystemError.MSVBVM60(00000000), ref: 0053DE37
      • __vbaAryCopy.MSVBVM60(?,?), ref: 0053DE60
      • #685.MSVBVM60 ref: 0053DE6D
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0053DE7B
      • __vbaFreeObj.MSVBVM60 ref: 0053DE9F
      • __vbaAryDestruct.MSVBVM60(00000000,?,0053DF63), ref: 0053DF44
      • __vbaFreeStr.MSVBVM60 ref: 0053DF50
      • __vbaFreeStr.MSVBVM60 ref: 0053DF5C
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Error$Fixstr$Copy$Lset$ListMove$BoundsGenerateSystem$#520$#608#685#712BstrChkstkConstruct$AnsiLockUboundUnicodeUnlock$#619#711CheckDestructHresultIndexLoadPreserveRedim
      • String ID: in readers $#$$$0u$Could not get context to winscard: $Entering Readers$Invalid Context in Readers$Readers found: $SCardListReaders returned $got context to winscard in hcontext: $true
      • API String ID: 1375779911-1287176704
      • Opcode ID: aa5e615aac95572ac477ed67de3b1d9ef24a5dcd2dd719f00966636214f75fb1
      • Instruction ID: 37d4ff7eb3e29ecd8366f5e0f85b7e179589c9740587ea566e4df71f9dcad29b
      • Opcode Fuzzy Hash: aa5e615aac95572ac477ed67de3b1d9ef24a5dcd2dd719f00966636214f75fb1
      • Instruction Fuzzy Hash: 8DF2F775900219EFDB24DFA0DE89BDDBBB4BB48305F1081D9E50AB72A0DB745A84CF64
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 2077 4d5390-4d5418 __vbaChkstk __vbaOnError __vbaStrCmp 2078 4d5469-4d5482 __vbaStrCopy call 4ecd60 2077->2078 2079 4d541a-4d5435 __vbaStrCmp 2077->2079 2083 4d5487-4d54e8 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList __vbaStrCmp 2078->2083 2081 4d544f-4d545e __vbaStrCopy 2079->2081 2082 4d5437-4d544d __vbaStrCopy 2079->2082 2084 4d5464 2081->2084 2082->2084 2085 4d553c-4d5558 __vbaStrCopy 2083->2085 2086 4d54ea-4d553a call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeVarList 2083->2086 2087 4d6689-4d673a #685 __vbaObjSet __vbaFreeObj __vbaFreeStr * 3 2084->2087 2089 4d555e-4d5565 call 4d4e80 2085->2089 2086->2089 2094 4d556a-4d558d __vbaStrMove __vbaStrCmp 2089->2094 2095 4d558f-4d55b4 __vbaStrCat __vbaStrMove call 4ecd60 2094->2095 2096 4d5602-4d561a __vbaStrCmp 2094->2096 2100 4d55b9-4d55ff #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 2095->2100 2098 4d5949-4d5994 __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStr __vbaStrCmp 2096->2098 2099 4d5620-4d565d __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove call 4ecd60 2096->2099 2105 4d59fe-4d5a0a 2098->2105 2106 4d5996-4d599b 2098->2106 2104 4d5662-4d56cd #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList __vbaStrCmp 2099->2104 2100->2096 2107 4d586f-4d58ba __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStr __vbaStrCmp 2104->2107 2108 4d56d3-4d5710 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove call 4ecd60 2104->2108 2112 4d5a10-4d5a29 __vbaStrCopy call 4ecd60 2105->2112 2113 4d60e2-4d60fa __vbaStrCmp 2105->2113 2106->2105 2109 4d599d-4d59ad call 4eb090 2106->2109 2123 4d5944 2107->2123 2124 4d58c0-4d58c5 2107->2124 2118 4d5715-4d5780 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList __vbaStrCmp 2108->2118 2109->2105 2132 4d59af-4d59fb __vbaStrCat __vbaStrMove __vbaStrCopy call 4efae0 __vbaFreeStrList 2109->2132 2127 4d5a2e-4d5a8f #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList __vbaStrCmp 2112->2127 2114 4d60fc-4d6101 2113->2114 2115 4d6107-4d6120 __vbaStrCopy call 4ecd60 2113->2115 2114->2115 2120 4d633e-4d6356 __vbaStrCmp 2114->2120 2129 4d6125-4d6186 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList __vbaStrCmp 2115->2129 2125 4d585d-4d5864 2118->2125 2126 4d5786-4d57d1 __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStr __vbaStrCmp 2118->2126 2130 4d635c-4d638f call 52d4c0 __vbaStrMove __vbaInStr 2120->2130 2131 4d6606-4d6628 __vbaStrCopy * 2 2120->2131 2123->2105 2124->2123 2133 4d58c7-4d58d7 call 4eb090 2124->2133 2128 4d586a 2125->2128 2156 4d585b 2126->2156 2157 4d57d7-4d57dc 2126->2157 2135 4d5a95-4d5b3f __vbaStrCopy * 3 call 4d13b0 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList 2127->2135 2136 4d5b41-4d5b5d __vbaStrCopy 2127->2136 2128->2123 2140 4d618c-4d61ce __vbaStrCopy * 3 call 4d13b0 2129->2140 2141 4d622a-4d6242 __vbaStrCmp 2129->2141 2162 4d63a6-4d63be __vbaStrCmp 2130->2162 2163 4d6391-4d63a0 __vbaStrCopy 2130->2163 2137 4d662e-4d6646 __vbaStrCmp 2131->2137 2132->2105 2133->2123 2165 4d58d9-4d5941 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy call 4efae0 __vbaFreeStrList 2133->2165 2139 4d5b63-4d5b7b __vbaStrCmp 2135->2139 2136->2139 2146 4d6648-4d665f __vbaStrCopy 2137->2146 2147 4d6661-4d6670 __vbaStrCopy 2137->2147 2149 4d5fea-4d6035 __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStr __vbaStrCmp 2139->2149 2150 4d5b81-4d5bf1 __vbaStrCopy * 3 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove call 4d13b0 2139->2150 2161 4d61d3-4d6227 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList 2140->2161 2141->2120 2154 4d6248-4d6258 call 4eb090 2141->2154 2158 4d6676-4d6683 __vbaStrCopy 2146->2158 2147->2158 2149->2113 2176 4d603b-4d6040 2149->2176 2167 4d5bf6-4d5c6d #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList __vbaStrCmp 2150->2167 2180 4d625e-4d6326 __vbaStrCat __vbaStrMove __vbaStrCopy call 4efae0 __vbaFreeStrList __vbaStrCat __vbaStrMove call 4efae0 __vbaFreeStr __vbaStrCopy * 2 call 4efae0 __vbaFreeStrList 2154->2180 2181 4d6329-4d6338 __vbaStrCopy 2154->2181 2156->2128 2157->2156 2166 4d57de-4d57ee call 4eb090 2157->2166 2158->2087 2161->2141 2169 4d65ef-4d65fe __vbaStrCopy 2162->2169 2170 4d63c4-4d63e0 __vbaInStr 2162->2170 2163->2162 2165->2123 2166->2156 2184 4d57f0-4d5858 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy call 4efae0 __vbaFreeStrList 2166->2184 2174 4d5eaf-4d5efa __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStr __vbaStrCmp 2167->2174 2175 4d5c73-4d5ce3 __vbaStrCopy * 3 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove call 4d13b0 2167->2175 2179 4d6604 2169->2179 2177 4d65d8-4d65e7 __vbaStrCopy 2170->2177 2178 4d63e6-4d64c3 __vbaVarDup #711 __vbaChkstk __vbaVarIndexLoad __vbaStrVarMove __vbaStrMove __vbaFreeVarList __vbaStrCmp 2170->2178 2204 4d5fe5 2174->2204 2205 4d5f00-4d5f05 2174->2205 2194 4d5ce8-4d5d5f #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList __vbaStrCmp 2175->2194 2176->2113 2187 4d6046-4d6056 call 4eb090 2176->2187 2188 4d65ed 2177->2188 2189 4d64c9-4d64d9 call 4eb090 2178->2189 2190 4d65c1-4d65d0 __vbaStrCopy 2178->2190 2179->2137 2180->2181 2181->2120 2184->2156 2187->2113 2213 4d605c-4d60dc __vbaStrCat __vbaStrMove __vbaStrCopy call 4efae0 __vbaFreeStrList __vbaStrCat __vbaStrMove call 4efae0 __vbaFreeStr 2187->2213 2188->2179 2207 4d64df-4d6592 __vbaStrCat __vbaStrMove __vbaStrCopy call 4efae0 __vbaFreeStrList __vbaStrCat __vbaStrMove call 4efae0 __vbaFreeStr __vbaStrCopy * 2 call 4efae0 2189->2207 2208 4d65aa-4d65bf __vbaStrCopy 2189->2208 2195 4d65d6 2190->2195 2202 4d5e9d-4d5ea4 2194->2202 2203 4d5d65-4d5db0 __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStr __vbaStrCmp 2194->2203 2195->2188 2210 4d5eaa 2202->2210 2221 4d5e9b 2203->2221 2222 4d5db6-4d5dbb 2203->2222 2204->2113 2205->2204 2212 4d5f0b-4d5f1b call 4eb090 2205->2212 2238 4d6597-4d65a7 __vbaFreeStrList 2207->2238 2208->2195 2210->2204 2212->2204 2225 4d5f21-4d5fe2 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy call 4efae0 __vbaFreeStrList __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove call 4efae0 __vbaFreeStrList 2212->2225 2213->2113 2221->2210 2222->2221 2228 4d5dc1-4d5dd1 call 4eb090 2222->2228 2225->2204 2228->2221 2236 4d5dd7-4d5e98 __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCopy call 4efae0 __vbaFreeStrList __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove call 4efae0 __vbaFreeStrList 2228->2236 2236->2221 2238->2208
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,004B1C27), ref: 004D53AE
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,004B1C27), ref: 004D53DE
      • __vbaStrCmp.MSVBVM60(00473D9C,0077EF34), ref: 004D5410
      • __vbaStrCmp.MSVBVM60(null,0077EF34), ref: 004D542D
      • __vbaStrCopy.MSVBVM60 ref: 004D5447
      • __vbaStrCopy.MSVBVM60 ref: 004D545E
      • __vbaStrCopy.MSVBVM60 ref: 004D5478
      • #520.MSVBVM60(?,00000008,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D5499
      • __vbaStrVarMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D54A3
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D54AE
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D54B7
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D54C7
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D54E0
      • #520.MSVBVM60(?,00000008), ref: 004D550C
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D5516
      • __vbaStrMove.MSVBVM60 ref: 004D5521
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004D5531
      • __vbaStrCopy.MSVBVM60 ref: 004D5558
      • __vbaStrMove.MSVBVM60(?,?,?), ref: 004D556F
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D5585
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,?), ref: 004D559F
      • __vbaStrMove.MSVBVM60(?,?,?), ref: 004D55AA
      • #520.MSVBVM60(?,00000008), ref: 004D55CB
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D55D5
      • __vbaStrMove.MSVBVM60 ref: 004D55E0
      • __vbaFreeStr.MSVBVM60 ref: 004D55E9
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004D55F9
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D5612
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei\HH,HKLM\), ref: 004D5631
      • __vbaStrMove.MSVBVM60(?,?,?), ref: 004D563C
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000), ref: 004D5648
      • __vbaStrMove.MSVBVM60(?,?,?), ref: 004D5653
      • #520.MSVBVM60(?,00000008), ref: 004D5674
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D567E
      • __vbaStrMove.MSVBVM60 ref: 004D5689
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004D5699
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,?,?), ref: 004D56AC
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D56C5
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei,HKLM\), ref: 004D56E4
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?), ref: 004D56EF
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000), ref: 004D56FB
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?), ref: 004D5706
      • #520.MSVBVM60(?,00000008), ref: 004D5727
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D5731
      • __vbaStrMove.MSVBVM60 ref: 004D573C
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004D574C
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,?,?), ref: 004D575F
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D5778
      • __vbaStrCat.MSVBVM60(?,LogonDomain: ), ref: 004D5796
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D57A1
      • __vbaFreeStr.MSVBVM60(?), ref: 004D57B3
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D57C9
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei,HKLM\), ref: 004D5801
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D580C
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000), ref: 004D5818
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D5823
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D5831
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?), ref: 004D5852
      • __vbaStrCat.MSVBVM60(?,LogonDomain: ), ref: 004D587F
      • __vbaStrMove.MSVBVM60 ref: 004D588A
      • __vbaFreeStr.MSVBVM60(?), ref: 004D589C
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D58B2
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei\HH,HKLM\), ref: 004D58EA
      • __vbaStrMove.MSVBVM60 ref: 004D58F5
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000), ref: 004D5901
      • __vbaStrMove.MSVBVM60 ref: 004D590C
      • __vbaStrCopy.MSVBVM60 ref: 004D591A
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?), ref: 004D593B
      • __vbaStrCat.MSVBVM60(?,LogonDomain: ), ref: 004D5959
      • __vbaStrMove.MSVBVM60 ref: 004D5964
      • __vbaFreeStr.MSVBVM60(?), ref: 004D5976
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D598C
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,?), ref: 004D59BF
      • __vbaStrMove.MSVBVM60 ref: 004D59CA
      • __vbaStrCopy.MSVBVM60 ref: 004D59D8
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 004D59F5
      • __vbaStrCopy.MSVBVM60 ref: 004D5A1F
      • #520.MSVBVM60(?,00000008,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D5A40
      • __vbaStrVarMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D5A4A
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D5A55
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D5A5E
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D5A6E
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D5A87
      • __vbaStrCopy.MSVBVM60 ref: 004D5AA4
      • __vbaStrCopy.MSVBVM60 ref: 004D5AB2
      • __vbaStrCopy.MSVBVM60 ref: 004D5AC0
      • #520.MSVBVM60(?,00000008), ref: 004D5AED
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D5AF7
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D5B02
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?), ref: 004D5B16
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,?,?,?), ref: 004D5B29
      • __vbaStrCopy.MSVBVM60 ref: 004D5B5D
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D5B73
      • __vbaStrCopy.MSVBVM60 ref: 004D5B90
      • __vbaStrCopy.MSVBVM60 ref: 004D5B9E
      • __vbaStrCopy.MSVBVM60 ref: 004D5BAC
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei\HH,HKLM\,?,?,?), ref: 004D5BC8
      • __vbaStrMove.MSVBVM60 ref: 004D5BD3
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000), ref: 004D5BDF
      • __vbaStrMove.MSVBVM60 ref: 004D5BEA
      • #520.MSVBVM60(?,00000008), ref: 004D5C08
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D5C12
      • __vbaStrMove.MSVBVM60 ref: 004D5C1D
      • __vbaFreeStrList.MSVBVM60(00000005,?,?,?,?,?), ref: 004D5C39
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,?,?,?,?,00000000), ref: 004D5C4C
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,?,?,?,?,00000000), ref: 004D5C65
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00000000), ref: 004D5C82
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00000000), ref: 004D5C90
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00000000), ref: 004D5C9E
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei,HKLM\,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004D5CBA
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,00000000), ref: 004D5CC5
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000,?,?,?,?,?,?,?,?,00000000), ref: 004D5CD1
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,00000000), ref: 004D5CDC
      • #520.MSVBVM60(?,00000008), ref: 004D5CFA
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D5D04
      • __vbaStrMove.MSVBVM60 ref: 004D5D0F
      • __vbaFreeStrList.MSVBVM60(00000005,?,?,?,?,?), ref: 004D5D2B
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004D5D3E
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D5D57
      • __vbaStrCat.MSVBVM60(?,LogonDomain: ), ref: 004D5D75
      • __vbaStrMove.MSVBVM60 ref: 004D5D80
      • __vbaFreeStr.MSVBVM60(?), ref: 004D5D92
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D5DA8
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei,HKLM\), ref: 004D5DE8
      • __vbaStrMove.MSVBVM60 ref: 004D5DF3
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000), ref: 004D5DFF
      • __vbaStrMove.MSVBVM60 ref: 004D5E0A
      • __vbaStrCopy.MSVBVM60 ref: 004D5E18
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?), ref: 004D5E39
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei,HKLM\), ref: 004D5E53
      • __vbaStrMove.MSVBVM60 ref: 004D5E5E
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000), ref: 004D5E6A
      • __vbaStrMove.MSVBVM60 ref: 004D5E75
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 004D5E92
      • __vbaStrCat.MSVBVM60(?,LogonDomain: ,?,?,?,?,?,?,?,?,00000000), ref: 004D5EBF
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,00000000), ref: 004D5ECA
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,?,00000000), ref: 004D5EDC
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,?,?,?,?,00000000), ref: 004D5EF2
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei\HH,HKLM\,?,?,?,?,?,?,?,?,00000000), ref: 004D5F32
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,00000000), ref: 004D5F3D
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000,?,?,?,?,?,?,?,?,00000000), ref: 004D5F49
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,00000000), ref: 004D5F54
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,00000000), ref: 004D5F62
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004D5F83
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei\HH,HKLM\,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004D5F9D
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004D5FA8
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004D5FB4
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004D5FBF
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 004D5FDC
      • __vbaStrCat.MSVBVM60(?,LogonDomain: ), ref: 004D5FFA
      • __vbaStrMove.MSVBVM60 ref: 004D6005
      • __vbaFreeStr.MSVBVM60(?), ref: 004D6017
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D602D
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,?), ref: 004D606C
      • __vbaStrMove.MSVBVM60 ref: 004D6077
      • __vbaStrCopy.MSVBVM60 ref: 004D6085
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 004D60A2
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,?), ref: 004D60BB
      • __vbaStrMove.MSVBVM60 ref: 004D60C6
      • __vbaFreeStr.MSVBVM60(?,?), ref: 004D60DC
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D60F2
      • __vbaStrCopy.MSVBVM60 ref: 004D6116
      • #520.MSVBVM60(?,00000008,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D6137
      • __vbaStrVarMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D6141
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D614C
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D6155
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 004D6165
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D617E
      • __vbaStrCopy.MSVBVM60 ref: 004D619B
      • __vbaStrCopy.MSVBVM60 ref: 004D61A9
      • __vbaStrCopy.MSVBVM60 ref: 004D61B7
      • #520.MSVBVM60(?,00000008), ref: 004D61E5
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D61EF
      • __vbaStrMove.MSVBVM60 ref: 004D61FA
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?), ref: 004D620E
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultDomainName,?,?,?), ref: 004D6221
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D623A
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,HKLM\SOFTWARE\Aloaha\RKK\Settings), ref: 004D626F
      • __vbaStrMove.MSVBVM60 ref: 004D627A
      • __vbaStrCopy.MSVBVM60 ref: 004D6288
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 004D62A5
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,HKLM\SOFTWARE\Aloaha\RKK\Settings), ref: 004D62BF
      • __vbaStrMove.MSVBVM60 ref: 004D62CA
      • __vbaFreeStr.MSVBVM60(?,?), ref: 004D62E0
      • __vbaStrCopy.MSVBVM60 ref: 004D62F5
      • __vbaStrCopy.MSVBVM60 ref: 004D6303
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 004D6320
      • __vbaStrCopy.MSVBVM60 ref: 004D6338
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D634E
      • __vbaStrMove.MSVBVM60 ref: 004D636D
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001), ref: 004D6387
      • __vbaStrCopy.MSVBVM60 ref: 004D63A0
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D63B6
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001), ref: 004D63D8
      • __vbaVarDup.MSVBVM60 ref: 004D641E
      • #711.MSVBVM60(?,?,?,000000FF,00000000), ref: 004D6434
      • __vbaChkstk.MSVBVM60 ref: 004D643F
      • __vbaVarIndexLoad.MSVBVM60(?,?,00000001), ref: 004D6476
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 004D6480
      • __vbaStrMove.MSVBVM60 ref: 004D648B
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 004D64A2
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D64BB
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,HKLM\SOFTWARE\Aloaha\RKK\Settings), ref: 004D64F0
      • __vbaStrMove.MSVBVM60 ref: 004D64FB
      • __vbaStrCopy.MSVBVM60 ref: 004D6509
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 004D6526
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,HKLM\SOFTWARE\Aloaha\RKK\Settings), ref: 004D6540
      • __vbaStrMove.MSVBVM60 ref: 004D654B
      • __vbaFreeStr.MSVBVM60(?,?), ref: 004D6561
      • __vbaStrCopy.MSVBVM60 ref: 004D6576
      • __vbaStrCopy.MSVBVM60 ref: 004D6584
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 004D65A1
      • __vbaStrCopy.MSVBVM60 ref: 004D65B9
      • __vbaStrCopy.MSVBVM60 ref: 004D65D0
      • __vbaStrCopy.MSVBVM60 ref: 004D65E7
      • __vbaStrCopy.MSVBVM60 ref: 004D65FE
      • __vbaStrCopy.MSVBVM60 ref: 004D6615
      • __vbaStrCopy.MSVBVM60 ref: 004D6628
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D663E
      • __vbaStrCopy.MSVBVM60 ref: 004D6659
      • __vbaStrCopy.MSVBVM60 ref: 004D6670
      • __vbaStrCopy.MSVBVM60 ref: 004D6683
      • #685.MSVBVM60 ref: 004D6690
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004D669B
      • __vbaFreeObj.MSVBVM60 ref: 004D66BC
      • __vbaFreeStr.MSVBVM60(004D673B), ref: 004D6722
      • __vbaFreeStr.MSVBVM60 ref: 004D672B
      • __vbaFreeStr.MSVBVM60 ref: 004D6734
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Move$Free$Copy$List$#520$Chkstk$#685#711ErrorIndexLoad
      • String ID: 4w$HKLM\$HKLM\SOFTWARE\Aloaha\RKK\Settings$HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultDomainName$HKLM\Software\Aloaha\RKK\LogonDomain$HKLM\Software\Aloaha\RKK\StandardHive$LogonDomain: $SOFTWARE\Polizei$SOFTWARE\Polizei\HH$\Logon\Standard\LogonDomain$null$~
      • API String ID: 98941349-2821057421
      • Opcode ID: cac0364168061781c48d229a3665889d81515ba5e33f946cbab644c751a32c17
      • Instruction ID: 7a4856617ab015afe4e6ab81a340d9d2a7f9265a438b746efddb3f08a71f5103
      • Opcode Fuzzy Hash: cac0364168061781c48d229a3665889d81515ba5e33f946cbab644c751a32c17
      • Instruction Fuzzy Hash: 04C21C75900209DFDB14DFE0DE58AEEB778FF44305F20812AE506B76A0EB745A4ACB58
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,00546A11,?,?,?,00000000,00411816), ref: 00546B2E
      • __vbaAryConstruct2.MSVBVM60(?,004982B0,00000008,?,?,?,00000000,00411816,00546A11), ref: 00546B60
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,00546A11), ref: 00546B6F
        • Part of subcall function 0054A720: __vbaChkstk.MSVBVM60(00000000,00411816,00546B91,?,?,?,00000000,00411816,00546A11), ref: 0054A73E
        • Part of subcall function 0054A720: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,00546B91), ref: 0054A76E
        • Part of subcall function 0054A720: #520.MSVBVM60(?,00004008), ref: 0054A7A7
        • Part of subcall function 0054A720: #518.MSVBVM60(?,00004008), ref: 0054A7E0
        • Part of subcall function 0054A720: #520.MSVBVM60(?,?), ref: 0054A7EE
        • Part of subcall function 0054A720: __vbaVarCmpEq.MSVBVM60(?,00008008,?), ref: 0054A817
        • Part of subcall function 0054A720: __vbaVarCmpEq.MSVBVM60(?,00008008,?,00000000), ref: 0054A830
        • Part of subcall function 0054A720: __vbaVarOr.MSVBVM60(?,00000000), ref: 0054A83E
        • Part of subcall function 0054A720: __vbaBoolVarNull.MSVBVM60(00000000), ref: 0054A845
        • Part of subcall function 0054A720: __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 0054A860
        • Part of subcall function 0054A720: __vbaStrCopy.MSVBVM60 ref: 0054A887
        • Part of subcall function 0054A720: __vbaStrMove.MSVBVM60(?), ref: 0054A89D
        • Part of subcall function 0054A720: __vbaFreeStr.MSVBVM60 ref: 0054A8A6
        • Part of subcall function 0054A720: __vbaInStr.MSVBVM60(00000000,0047BCF8,0075AB4C,00000001), ref: 0054A8C2
      • __vbaAryMove.MSVBVM60(?,?,?,?,?,00000000,00411816,00546A11), ref: 00546BB8
      • #685.MSVBVM60(?,?,?,00000000,00411816,00546A11), ref: 00546BC5
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816,00546A11), ref: 00546BD3
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816,00546A11), ref: 00546BF7
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00546C3B
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00546C58
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00546C79
      • #685.MSVBVM60 ref: 00546C8E
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00546C9C
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00546CE7
      • __vbaFreeObj.MSVBVM60 ref: 00546D1A
      • __vbaAryCopy.MSVBVM60(?,00000000), ref: 00546D3A
      • __vbaAryCopy.MSVBVM60(0054D8DC,00000000), ref: 00546D50
      • __vbaStrCopy.MSVBVM60 ref: 00546D69
      • __vbaStrCopy.MSVBVM60 ref: 00546D80
      • __vbaStrCopy.MSVBVM60 ref: 00546D99
      • __vbaStrCopy.MSVBVM60 ref: 00546DB0
      • __vbaAryCopy.MSVBVM60(?,?,?,?,?,00000000,00411816,00546A11), ref: 00546DD6
      • #685.MSVBVM60(?,?,?,00000000,00411816,00546A11), ref: 00546E05
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816,00546A11), ref: 00546E13
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816,00546A11), ref: 00546E37
      • #520.MSVBVM60(?,00004008), ref: 00546E66
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00546EC2
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00546EDF
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00546F03
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?), ref: 00546F37
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 00546F4C
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 00546F53
      • __vbaFreeVarList.MSVBVM60(00000002,?,0000000B), ref: 00546F70
      • #685.MSVBVM60(?,00000000,00411816,00546A11), ref: 00546F8F
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00411816,00546A11), ref: 00546F9D
        • Part of subcall function 0054ABF0: __vbaChkstk.MSVBVM60(00000000,00411816,00546BA7,?,?,?,00000000,00411816,00546A11), ref: 0054AC0E
        • Part of subcall function 0054ABF0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,00546BA7), ref: 0054AC3E
        • Part of subcall function 0054ABF0: __vbaInStr.MSVBVM60(00000000,0047BCF8,0075AB4C,00000001,?,?,?,00000000,00411816,00546BA7), ref: 0054AC70
        • Part of subcall function 0054ABF0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816,00546BA7), ref: 0054AC8D
        • Part of subcall function 0054ABF0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816,00546BA7), ref: 0054AC9B
        • Part of subcall function 0054ABF0: __vbaObjSet.MSVBVM60(?,00000000,0075AB4C,00000000,?,?), ref: 0054ACC4
        • Part of subcall function 0054ABF0: __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 0054ACD4
        • Part of subcall function 0054ABF0: __vbaLateMemCallLd.MSVBVM60(?,?,info,00000000), ref: 0054AD01
        • Part of subcall function 0054ABF0: __vbaVarTstGt.MSVBVM60(?,00000000,?,?,?,?,?,00000000,00411816,00546BA7), ref: 0054AD0F
        • Part of subcall function 0054ABF0: __vbaFreeVar.MSVBVM60(?,?,?,?,?,00000000,00411816,00546BA7), ref: 0054AD1C
        • Part of subcall function 0054ABF0: #685.MSVBVM60(?,?,?,?,?,00000000,00411816,00546BA7), ref: 0054AD35
        • Part of subcall function 0054ABF0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,?,00000000,00411816,00546BA7), ref: 0054AD40
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00546FE8
      • __vbaFreeObj.MSVBVM60 ref: 0054701B
      • #546.MSVBVM60(?), ref: 0054703E
      • __vbaStrR8.MSVBVM60(?,?,?,00000000,00411816,00546A11), ref: 00547056
      • __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816,00546A11), ref: 00547061
      • __vbaFreeVar.MSVBVM60(?,?,?,00000000,00411816,00546A11), ref: 0054706D
      • #520.MSVBVM60(?,00004008), ref: 0054709B
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 005470C3
      • __vbaFreeVar.MSVBVM60 ref: 005470D6
      • #685.MSVBVM60 ref: 005470F2
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00547100
      • __vbaFreeObj.MSVBVM60 ref: 00547124
      • __vbaR8Str.MSVBVM60(?), ref: 00547135
      • __vbaR8Str.MSVBVM60(0077F5EC), ref: 00547147
      • __vbaFpCDblR8.MSVBVM60 ref: 0054715F
      • #685.MSVBVM60 ref: 0054716F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0054717D
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 005471C8
      • __vbaFreeObj.MSVBVM60 ref: 005471FB
      • __vbaAryCopy.MSVBVM60(?,0054D8DC), ref: 005472E1
        • Part of subcall function 00545DF0: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,?,?,?,?,?,00000000,00411816,00546A11), ref: 00545E0E
        • Part of subcall function 00545DF0: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 00545E3E
        • Part of subcall function 00545DF0: __vbaStrMove.MSVBVM60 ref: 00545E62
        • Part of subcall function 00545DF0: __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 00545E78
        • Part of subcall function 00545DF0: __vbaStrCat.MSVBVM60(?,MiniCSP SessionID: ), ref: 00545E96
        • Part of subcall function 00545DF0: __vbaStrMove.MSVBVM60 ref: 00545EA1
        • Part of subcall function 00545DF0: __vbaFreeStr.MSVBVM60(?), ref: 00545EB3
        • Part of subcall function 00545DF0: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00545ECB
        • Part of subcall function 00545DF0: __vbaStrCmp.MSVBVM60(?,00000000), ref: 00545EEB
        • Part of subcall function 00545DF0: __vbaStrCopy.MSVBVM60 ref: 00545F0A
        • Part of subcall function 00545DF0: __vbaStrCopy.MSVBVM60 ref: 00545F21
        • Part of subcall function 00545DF0: __vbaStrCopy.MSVBVM60 ref: 00545F38
        • Part of subcall function 00545DF0: __vbaStrCopy.MSVBVM60 ref: 00545F4F
        • Part of subcall function 00545DF0: __vbaRedim.MSVBVM60(00000180,00000004,0054D854,00000008,00000001,00000000,00000000), ref: 00545F70
        • Part of subcall function 00545DF0: __vbaRedim.MSVBVM60(00000180,00000004,0054D8DC,00000008,00000001,00000000,00000000), ref: 00545F94
      • __vbaStrCopy.MSVBVM60 ref: 00547260
      • __vbaFreeStr.MSVBVM60(?), ref: 00547272
      • #685.MSVBVM60 ref: 005472F3
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00547301
      • __vbaFreeObj.MSVBVM60 ref: 00547325
      • __vbaStrCopy.MSVBVM60 ref: 0054733A
      • __vbaStrCopy.MSVBVM60 ref: 00547348
      • __vbaObjSet.MSVBVM60(?,00000000,AloahaInter.SemaPhore,00000000,?,?), ref: 00547375
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 00547385
      • #685.MSVBVM60(?,?,?,?,00000000,00411816,00546A11), ref: 00547395
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816,00546A11), ref: 005473A3
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 005473EE
      • __vbaFreeObj.MSVBVM60 ref: 00547421
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 00547443
      • #685.MSVBVM60 ref: 00547450
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0054745E
      • __vbaFreeObj.MSVBVM60 ref: 00547482
      • __vbaStrMove.MSVBVM60 ref: 00547499
      • __vbaChkstk.MSVBVM60 ref: 005474C8
      • __vbaStrMove.MSVBVM60 ref: 005474FB
      • __vbaStrCat.MSVBVM60(AloahaInter.dll,00000000), ref: 00547507
      • __vbaStrMove.MSVBVM60 ref: 00547512
        • Part of subcall function 0050D740: __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0050D75E
        • Part of subcall function 0050D740: __vbaStrCopy.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0050D78B
        • Part of subcall function 0050D740: __vbaVarDup.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0050D797
        • Part of subcall function 0050D740: __vbaOnError.MSVBVM60(000000FF,?,00000001,00000000,00000000,00411816), ref: 0050D7A6
        • Part of subcall function 0050D740: __vbaStrCmp.MSVBVM60(true,00000000,?,00000001,00000000,00000000,00411816), ref: 0050D7BE
        • Part of subcall function 0050D740: #520.MSVBVM60(?,00004008), ref: 0050D7FB
        • Part of subcall function 0050D740: __vbaVarCmpNe.MSVBVM60(?,00008008,?,0000000B), ref: 0050D82B
        • Part of subcall function 0050D740: __vbaVarAnd.MSVBVM60(?,00000000), ref: 0050D839
        • Part of subcall function 0050D740: __vbaBoolVarNull.MSVBVM60(00000000), ref: 0050D840
        • Part of subcall function 0050D740: __vbaFreeVarList.MSVBVM60(00000002,?,0000000B), ref: 0050D85A
        • Part of subcall function 0050D740: __vbaStrCopy.MSVBVM60(00000000,00000000,00411816), ref: 0050D883
        • Part of subcall function 0050D740: #518.MSVBVM60(?,00004008), ref: 0050D8AE
        • Part of subcall function 0050D740: #619.MSVBVM60(?,?,00000004), ref: 0050D8BE
        • Part of subcall function 0050D740: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 0050D8E3
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,00000000,00000000), ref: 0054752C
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,00000000,00411816,00546A11), ref: 00547546
      • __vbaChkstk.MSVBVM60 ref: 00547575
      • __vbaStrMove.MSVBVM60 ref: 005475A8
      • __vbaStrCat.MSVBVM60(aloaha\AloahaInter.dll,00000000), ref: 005475B4
      • __vbaStrMove.MSVBVM60 ref: 005475BF
        • Part of subcall function 0050D740: __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0050D8FA
        • Part of subcall function 0050D740: __vbaBoolVar.MSVBVM60(?), ref: 0050D919
        • Part of subcall function 0050D740: __vbaStrCopy.MSVBVM60 ref: 0050DC8C
        • Part of subcall function 0050D740: #685.MSVBVM60(00000000,00000000,00411816), ref: 0050DC99
        • Part of subcall function 0050D740: __vbaObjSet.MSVBVM60(?,00000000), ref: 0050DCA4
        • Part of subcall function 0050D740: __vbaFreeObj.MSVBVM60 ref: 0050DCC5
        • Part of subcall function 0050D740: __vbaFreeVar.MSVBVM60(0050DD12), ref: 0050DD02
        • Part of subcall function 0050D740: __vbaFreeStr.MSVBVM60 ref: 0050DD0B
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,00000000,00000000), ref: 005475D9
      • #685.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816,00546A11), ref: 005475E9
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 005475F7
      • __vbaFreeObj.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816,00546A11), ref: 0054761B
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816,00546A11), ref: 00547630
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816,00546A11), ref: 0054763E
        • Part of subcall function 00523380: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 0052348E
        • Part of subcall function 00523380: __vbaStrCopy.MSVBVM60(?,00000000,?,?,00411816), ref: 005234BB
        • Part of subcall function 00523380: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 005234CA
        • Part of subcall function 00523380: #518.MSVBVM60(?,00004008), ref: 00523515
        • Part of subcall function 00523380: __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 00523556
        • Part of subcall function 00523380: __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 00523564
        • Part of subcall function 00523380: __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0052357B
        • Part of subcall function 00523380: #518.MSVBVM60(?,00004008), ref: 005235D4
        • Part of subcall function 00523380: __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 00523615
        • Part of subcall function 00523380: __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 00523623
      • __vbaObjSet.MSVBVM60(?,00000000,AloahaInter.SemaPhore,00000000,?,?), ref: 0054766B
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 0054767B
      • __vbaChkstk.MSVBVM60 ref: 005476CC
      • __vbaChkstk.MSVBVM60 ref: 005476FB
      • __vbaChkstk.MSVBVM60 ref: 0054772A
      • __vbaLateMemCall.MSVBVM60(?,WaitingForSemaphore,00000003), ref: 0054775F
      • #685.MSVBVM60 ref: 0054776F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0054777D
      • __vbaFreeObj.MSVBVM60 ref: 005477A1
      • __vbaVarDup.MSVBVM60 ref: 00547813
      • #607.MSVBVM60(?,00000200,?), ref: 0054782C
      • __vbaStrVarMove.MSVBVM60(?), ref: 00547839
      • __vbaLsetFixstrFree.MSVBVM60(00000000,0077108C,00000000), ref: 00547849
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0054785F
      • __vbaAryCopy.MSVBVM60(?,?), ref: 00547936
      • __vbaVarMove.MSVBVM60 ref: 0054798E
      • __vbaLenBstr.MSVBVM60(0077108C), ref: 005479A1
      • __vbaStrCopy.MSVBVM60 ref: 005479BC
      • __vbaLsetFixstr.MSVBVM60(00000000,0077108C,?,00000000,00000000,?,0054D8D8), ref: 005479F0
      • __vbaFreeStr.MSVBVM60 ref: 00547A04
      • __vbaStrCopy.MSVBVM60(00477FFC,00473D9C,00000001,000000FF,00000000), ref: 00547A6F
      • #712.MSVBVM60(00000000), ref: 00547A76
      • __vbaStrMove.MSVBVM60 ref: 00547A81
      • __vbaLsetFixstr.MSVBVM60(00000000,0077108C,?), ref: 00547A94
      • #520.MSVBVM60(?,00000008), ref: 00547ACE
      • #608.MSVBVM60(?,00000000), ref: 00547ADD
      • __vbaStrVarVal.MSVBVM60(?,?,00473D9C,00000001,000000FF,00000000), ref: 00547AFC
      • __vbaStrVarVal.MSVBVM60(?,?,00000000), ref: 00547B0E
      • #712.MSVBVM60(00000000), ref: 00547B15
      • __vbaStrMove.MSVBVM60 ref: 00547B23
      • __vbaStrMove.MSVBVM60(00480108,00473D9C,00000001,000000FF,00000000), ref: 00547B5B
      • #712.MSVBVM60(00000000), ref: 00547B62
      • __vbaStrMove.MSVBVM60 ref: 00547B70
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00547B7C
      • __vbaFreeStrList.MSVBVM60(00000006,?,?,?,?,?,00000000), ref: 00547BB7
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 00547BD7
      • __vbaStrCopy.MSVBVM60 ref: 00547C01
      • __vbaStrCopy.MSVBVM60 ref: 00547C19
        • Part of subcall function 0054B1E0: __vbaChkstk.MSVBVM60(00000001,00411816), ref: 0054B1FE
        • Part of subcall function 0054B1E0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000001,00411816), ref: 0054B22E
        • Part of subcall function 0054B1E0: __vbaStrCmp.MSVBVM60(true,0077F2F4), ref: 0054B291
        • Part of subcall function 0054B1E0: __vbaStrErrVarCopy.MSVBVM60(?,MiniCSP_HID get_ScardContext returned: ), ref: 0054B2AB
        • Part of subcall function 0054B1E0: __vbaStrMove.MSVBVM60 ref: 0054B2B6
        • Part of subcall function 0054B1E0: __vbaStrCat.MSVBVM60(00000000), ref: 0054B2BD
        • Part of subcall function 0054B1E0: __vbaStrMove.MSVBVM60 ref: 0054B2C8
        • Part of subcall function 0054B1E0: __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 0054B2E1
        • Part of subcall function 0054B1E0: #685.MSVBVM60(?,?,?,00000001,00411816), ref: 0054B32E
        • Part of subcall function 0054B1E0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000001,00411816), ref: 0054B339
        • Part of subcall function 0054B1E0: __vbaFreeObj.MSVBVM60(?,?,?,00000001,00411816), ref: 0054B351
        • Part of subcall function 0054B1E0: __vbaFreeVar.MSVBVM60(0054B385,?,?,?,00000001,00411816), ref: 0054B37E
      • __vbaStrCopy.MSVBVM60 ref: 00547C2F
        • Part of subcall function 00548720: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,00547C3B,00000000), ref: 0054873E
        • Part of subcall function 00548720: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 0054876B
        • Part of subcall function 00548720: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 0054877A
        • Part of subcall function 00548720: #712.MSVBVM60(000000FF,00477FFC,00473D9C,00000001,000000FF,00000000,?,?,?,00000000,00411816), ref: 0054879B
        • Part of subcall function 00548720: #520.MSVBVM60(?,00000008), ref: 005487B3
        • Part of subcall function 00548720: #608.MSVBVM60(?,00000000), ref: 005487C2
        • Part of subcall function 00548720: __vbaStrVarVal.MSVBVM60(?,?,00473D9C,00000001,000000FF,00000000), ref: 005487DE
        • Part of subcall function 00548720: __vbaStrVarVal.MSVBVM60(?,?,00000000), ref: 005487ED
        • Part of subcall function 00548720: #712.MSVBVM60(00000000), ref: 005487F4
        • Part of subcall function 00548720: __vbaStrMove.MSVBVM60 ref: 005487FF
        • Part of subcall function 00548720: __vbaStrMove.MSVBVM60(00480108,00473D9C,00000001,000000FF,00000000), ref: 0054882E
        • Part of subcall function 00548720: #712.MSVBVM60(00000000), ref: 00548835
        • Part of subcall function 00548720: __vbaStrMove.MSVBVM60 ref: 00548840
        • Part of subcall function 00548720: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0054884C
        • Part of subcall function 00548720: __vbaFreeStrList.MSVBVM60(00000005,?,?,?,?,00000000), ref: 00548877
      • __vbaLsetFixstr.MSVBVM60(00000000,0077108C,?,00000000), ref: 00547C4D
      • __vbaAryMove.MSVBVM60(?,?), ref: 00547C6A
      • __vbaFreeStr.MSVBVM60 ref: 00547C73
      • #685.MSVBVM60 ref: 00547C80
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00547C8E
      • __vbaFreeObj.MSVBVM60 ref: 00547CB2
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00547CF6
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00547D13
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00547D34
      • #685.MSVBVM60 ref: 00547D49
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00547D57
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00547DA2
      • __vbaFreeObj.MSVBVM60 ref: 00547DD5
      • __vbaAryCopy.MSVBVM60(?,00000000), ref: 00547E01
      • __vbaAryCopy.MSVBVM60(?,00000000), ref: 00547E22
      • __vbaAryCopy.MSVBVM60(?,00000000), ref: 00547E39
      • __vbaAryCopy.MSVBVM60(?,00000000), ref: 00547E4E
      • __vbaAryCopy.MSVBVM60(?,?), ref: 00547E71
      • __vbaAryCopy.MSVBVM60(?,?), ref: 00547E92
      • __vbaAryCopy.MSVBVM60(?,?), ref: 00547EB5
      • __vbaAryCopy.MSVBVM60(?,?), ref: 00547ED6
      • #685.MSVBVM60 ref: 00547F67
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00547F75
      • __vbaFreeObj.MSVBVM60 ref: 00547F99
      • __vbaAryLock.MSVBVM60(?,?), ref: 00547FAE
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00547FEB
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00548008
      • #520.MSVBVM60(?,00004008), ref: 0054803E
      • __vbaAryUnlock.MSVBVM60(00000000), ref: 00548048
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 00548070
      • __vbaFreeVar.MSVBVM60 ref: 00548083
      • #685.MSVBVM60 ref: 0054809F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 005480AD
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 005480F8
      • __vbaFreeObj.MSVBVM60 ref: 0054812B
      • __vbaAryCopy.MSVBVM60(?,?), ref: 0054814B
      • __vbaAryCopy.MSVBVM60(?,?), ref: 00548160
      • #685.MSVBVM60 ref: 00548172
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00548180
      • __vbaFreeObj.MSVBVM60 ref: 005481A4
      • __vbaAryLock.MSVBVM60(00000000,?), ref: 005481B9
      • __vbaGenerateBoundsError.MSVBVM60 ref: 005481F6
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00548213
      • #520.MSVBVM60(?,00004008), ref: 00548249
      • __vbaAryUnlock.MSVBVM60(00000000), ref: 00548253
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0054827B
      • __vbaFreeVar.MSVBVM60 ref: 0054828E
      • #685.MSVBVM60 ref: 005482AA
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 005482B8
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00548303
      • __vbaFreeObj.MSVBVM60 ref: 00548336
      • #685.MSVBVM60 ref: 00548350
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0054835E
      • __vbaFreeObj.MSVBVM60 ref: 00548382
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00548434
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00548451
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00548472
      • #685.MSVBVM60 ref: 00548487
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00548495
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 005484E0
      • __vbaFreeObj.MSVBVM60 ref: 00548513
      • #546.MSVBVM60(?), ref: 00548532
      • __vbaStrR8.MSVBVM60 ref: 0054854A
      • __vbaStrMove.MSVBVM60 ref: 00548557
      • __vbaFreeVar.MSVBVM60 ref: 00548563
      • __vbaAryCopy.MSVBVM60(0054D8DC,00000000), ref: 00548579
      • __vbaStrCopy.MSVBVM60 ref: 00548592
      • __vbaStrCopy.MSVBVM60 ref: 005485AB
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 005485BE
      • #685.MSVBVM60 ref: 005485CB
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 005485D9
      • __vbaFreeObj.MSVBVM60 ref: 005485FD
      • __vbaAryDestruct.MSVBVM60(00000000,?,005486F8), ref: 00548697
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 005486A6
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 005486BE
      • __vbaFreeObj.MSVBVM60 ref: 005486C7
      • __vbaAryDestruct.MSVBVM60(00000000,00000000), ref: 005486D3
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Copy$Move$#685$Error$List$Chkstk$BoundsGenerate$#520$CheckHresult$#712$#518BoolDestructFixstrLset$Null$#546#608AddrefCallLateLockRedimUnlock$#607#619BstrConstruct2
      • String ID: AloahaInter.SemaPhore$AloahaInter.dll$PCSCCardReaders$Using MiniCSP Readers from Cache$WaitingForSemaphore$aloaha\AloahaInter.dll$c$null$}
      • API String ID: 1480323436-1235721303
      • Opcode ID: 73e9851ffd989a5c4bdefee8ea63de6df8a06c0aff590f61d1ffed411da96872
      • Instruction ID: 1b7c3f4d082794a5ba59352de44e835b2d36676df4636629d4ad14bb59d1d13d
      • Opcode Fuzzy Hash: 73e9851ffd989a5c4bdefee8ea63de6df8a06c0aff590f61d1ffed411da96872
      • Instruction Fuzzy Hash: FBF21875900218DFDB24DFA0DE48BEDBBB4FF48305F108599E60AA72A0DB745A89CF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 2452 51dae0-51db70 __vbaChkstk __vbaOnError __vbaStrCopy __vbaStrCmp 2453 51dd33-51dd6c __vbaStrCmp * 2 2452->2453 2454 51db76-51db94 __vbaInStr 2452->2454 2456 51dd72-51de90 __vbaVarDup #711 __vbaChkstk __vbaVarIndexLoadRefLock #518 __vbaAryUnlock __vbaStrVarMove __vbaStrMove __vbaFreeVarList __vbaLenBstr * 2 2453->2456 2457 51e207-51e24d __vbaStrCopy #685 __vbaObjSet __vbaFreeObj 2453->2457 2454->2453 2455 51db9a-51dce9 __vbaVarDup #711 __vbaRefVarAry __vbaUbound __vbaVarDup #711 __vbaChkstk __vbaVarIndexLoad __vbaStrVarMove __vbaStrMove __vbaFreeVarList __vbaLenBstr 2454->2455 2458 51e2e4-51e406 __vbaErrorOverflow __vbaChkstk __vbaStrCopy __vbaOnError __vbaStrCopy #518 __vbaInStrVar __vbaVarTstGt __vbaFreeVarList 2455->2458 2459 51dcef-51dcfd __vbaLenBstr 2455->2459 2456->2458 2460 51de96-51de99 2456->2460 2465 51e253-51e2cc __vbaFreeStr * 5 2457->2465 2466 51e460-51e589 __vbaVarDup #711 __vbaChkstk __vbaVarIndexLoadRefLock #518 __vbaAryUnlock __vbaStrVarMove __vbaStrMove __vbaFreeVarList __vbaLenBstr * 2 2458->2466 2467 51e408-51e45a #712 __vbaStrMove #712 __vbaStrMove 2458->2467 2459->2458 2462 51dd03-51dd2d #617 __vbaStrVarMove __vbaStrMove __vbaFreeVar 2459->2462 2460->2458 2464 51de9f-51df00 #619 __vbaStrVarMove __vbaStrMove __vbaFreeVar __vbaStrCopy __vbaStrCmp 2460->2464 2462->2453 2468 51df02-51df10 2464->2468 2469 51df15-51df30 __vbaStrCmp 2464->2469 2474 51f159-51f15f __vbaErrorOverflow 2466->2474 2475 51e58f-51e592 2466->2475 2467->2466 2470 51dfda-51e0b6 __vbaStrCopy * 3 #518 __vbaInStrVar __vbaVarTstGt __vbaFreeVarList 2468->2470 2471 51df32-51df40 2469->2471 2472 51df45-51df60 __vbaStrCmp 2469->2472 2478 51e110-51e17b __vbaStrToAnsi call 475c20 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStr 2470->2478 2479 51e0b8-51e10a #712 __vbaStrMove #712 __vbaStrMove 2470->2479 2471->2470 2476 51df72-51df8d __vbaStrCmp 2472->2476 2477 51df62-51df70 2472->2477 2475->2474 2480 51e598-51e723 #619 __vbaStrVarMove __vbaStrMove __vbaFreeVar __vbaVarDup #711 __vbaRefVarAry __vbaUbound __vbaVarDup #711 __vbaChkstk __vbaVarIndexLoad __vbaStrVarMove __vbaStrMove __vbaFreeVarList __vbaLenBstr 2475->2480 2482 51df9f-51dfba __vbaStrCmp 2476->2482 2483 51df8f-51df9d 2476->2483 2477->2470 2491 51e182-51e1e1 __vbaStrToAnsi call 475b84 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStr 2478->2491 2492 51e17d 2478->2492 2479->2478 2480->2474 2481 51e729-51e735 __vbaLenBstr 2480->2481 2481->2474 2485 51e73b-51e7c2 #617 __vbaStrVarMove __vbaStrMove __vbaFreeVar __vbaStrCopy * 3 __vbaStrCmp 2481->2485 2486 51dfcc-51dfd3 2482->2486 2487 51dfbc-51dfca 2482->2487 2483->2470 2489 51e7c4-51e7d2 2485->2489 2490 51e7d7-51e7f2 __vbaStrCmp 2485->2490 2486->2470 2487->2470 2494 51e89c-51e91c __vbaStrCopy __vbaStrToAnsi call 475c20 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStr 2489->2494 2495 51e7f4-51e802 2490->2495 2496 51e807-51e822 __vbaStrCmp 2490->2496 2491->2457 2501 51e1e3-51e200 call 475af4 __vbaSetSystemError 2491->2501 2492->2465 2508 51e986-51e9a3 2494->2508 2509 51e91e-51e981 __vbaVarCopy #685 __vbaObjSet __vbaFreeObj 2494->2509 2495->2494 2498 51e834-51e84f __vbaStrCmp 2496->2498 2499 51e824-51e832 2496->2499 2502 51e861-51e87c __vbaStrCmp 2498->2502 2503 51e851-51e85f 2498->2503 2499->2494 2501->2457 2506 51e88e-51e895 2502->2506 2507 51e87e-51e88c 2502->2507 2503->2494 2506->2494 2507->2494 2508->2474 2510 51e9a9-51e9db __vbaRedim __vbaAryLock 2508->2510 2515 51f05c-51f10c __vbaFreeStr * 3 __vbaAryDestruct __vbaFreeStr * 4 2509->2515 2513 51ea28-51ea2e __vbaGenerateBoundsError 2510->2513 2514 51e9dd-51e9e4 2510->2514 2517 51ea34-51eaa7 __vbaStrToAnsi call 475c6c __vbaSetSystemError __vbaStrToUnicode __vbaAryUnlock __vbaFreeStr 2513->2517 2514->2513 2516 51e9e6-51ea00 2514->2516 2518 51ea02-51ea0c 2516->2518 2519 51ea0e-51ea14 __vbaGenerateBoundsError 2516->2519 2524 51ebb2-51ebe4 2517->2524 2525 51eaad-51eabc 2517->2525 2522 51ea1a-51ea26 2518->2522 2519->2522 2522->2517 2526 51ef70-51ef7b 2524->2526 2527 51ebea-51ebf0 2524->2527 2525->2474 2528 51eac2-51eaf4 __vbaRedim __vbaAryLock 2525->2528 2529 51efa1-51efd9 __vbaStrCopy __vbaVarCopy 2526->2529 2530 51ef7d-51ef88 call 475af4 2526->2530 2527->2526 2531 51ecc2-51eccf 2527->2531 2532 51ee59-51ee66 2527->2532 2533 51eddc-51edf2 __vbaUbound 2527->2533 2534 51ebfc-51ec15 __vbaAryLock 2527->2534 2535 51eb41-51eb47 __vbaGenerateBoundsError 2528->2535 2536 51eaf6-51eafd 2528->2536 2542 51efdf-51efea 2529->2542 2551 51ef8d-51ef9a RegCloseKey 2530->2551 2531->2474 2540 51ecd5-51ed00 #525 __vbaStrMove __vbaAryLock 2531->2540 2532->2474 2543 51ee6c-51ee97 #525 __vbaStrMove __vbaAryLock 2532->2543 2533->2474 2538 51edf8-51edfb 2533->2538 2544 51ec62-51ec68 __vbaGenerateBoundsError 2534->2544 2545 51ec17-51ec1e 2534->2545 2541 51eb4d-51ebac __vbaStrToAnsi call 475c6c __vbaSetSystemError __vbaStrToUnicode __vbaAryUnlock __vbaFreeStr 2535->2541 2536->2535 2537 51eaff-51eb19 2536->2537 2546 51eb27-51eb2d __vbaGenerateBoundsError 2537->2546 2547 51eb1b-51eb25 2537->2547 2549 51ee2b-51ee54 __vbaVarCopy 2538->2549 2550 51edfd-51ee0c 2538->2550 2552 51ed02-51ed09 2540->2552 2553 51ed4d-51ed53 __vbaGenerateBoundsError 2540->2553 2541->2524 2555 51f010-51f056 __vbaStrCopy #685 __vbaObjSet __vbaFreeObj 2542->2555 2556 51efec-51eff7 call 475af4 2542->2556 2557 51eee4-51eeea __vbaGenerateBoundsError 2543->2557 2558 51ee99-51eea0 2543->2558 2548 51ec6e-51ecbd call 474240 __vbaSetSystemError __vbaAryUnlock __vbaStrI4 __vbaVarMove 2544->2548 2545->2544 2559 51ec20-51ec3a 2545->2559 2564 51eb33-51eb3f 2546->2564 2547->2564 2548->2542 2549->2542 2550->2474 2565 51ee12-51ee28 __vbaRedimPreserve 2550->2565 2551->2529 2552->2553 2561 51ed0b-51ed25 2552->2561 2563 51ed59-51ed5f 2553->2563 2555->2515 2574 51effc-51f009 RegCloseKey 2556->2574 2568 51eef0-51eef6 2557->2568 2558->2557 2567 51eea2-51eebc 2558->2567 2569 51ec48-51ec4e __vbaGenerateBoundsError 2559->2569 2570 51ec3c-51ec46 2559->2570 2572 51ed33-51ed39 __vbaGenerateBoundsError 2561->2572 2573 51ed27-51ed31 2561->2573 2563->2474 2578 51ed65-51edd7 __vbaStrToAnsi call 474240 __vbaSetSystemError __vbaStrToUnicode __vbaAryUnlock __vbaFreeStr __vbaVarCopy 2563->2578 2564->2541 2565->2549 2575 51eeca-51eed0 __vbaGenerateBoundsError 2567->2575 2576 51eebe-51eec8 2567->2576 2568->2474 2579 51eefc-51ef6e __vbaStrToAnsi call 474240 __vbaSetSystemError __vbaStrToUnicode __vbaAryUnlock __vbaFreeStr __vbaVarCopy 2568->2579 2580 51ec54-51ec60 2569->2580 2570->2580 2581 51ed3f-51ed4b 2572->2581 2573->2581 2574->2555 2583 51eed6-51eee2 2575->2583 2576->2583 2578->2542 2579->2542 2580->2548 2581->2563 2583->2568
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,004EC716,?,?), ref: 0051DAFE
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 0051DB2E
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 0051DB43
      • __vbaStrCmp.MSVBVM60(00473D9C), ref: 0051DB68
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001), ref: 0051DB8C
      • __vbaVarDup.MSVBVM60 ref: 0051DBBE
      • #711.MSVBVM60(?,?,?,000000FF,00000000), ref: 0051DBD6
      • __vbaRefVarAry.MSVBVM60(?,?,?,000000FF,00000000), ref: 0051DBE0
      • __vbaUbound.MSVBVM60(00000001,?,?,?,000000FF,00000000), ref: 0051DBEB
      • __vbaVarDup.MSVBVM60(?,?,?,?,?,?,000000FF,00000000), ref: 0051DC1E
      • #711.MSVBVM60(?,?,?,000000FF,00000000,?,?,?,?,?,?,000000FF,00000000), ref: 0051DC39
      • __vbaChkstk.MSVBVM60(?,?,000000FF,00000000,?,?,?,?,?,?,000000FF,00000000), ref: 0051DC44
      • __vbaVarIndexLoad.MSVBVM60(?,?,00000001,?,?,000000FF,00000000,?,?,?,?,?,?,000000FF,00000000), ref: 0051DC7E
      • __vbaStrVarMove.MSVBVM60(00000000,?,?,?,?,?,00000000,00411816), ref: 0051DC88
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,00000000,00411816), ref: 0051DC93
      • __vbaFreeVarList.MSVBVM60(00000005,?,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 0051DCB5
      • __vbaLenBstr.MSVBVM60(00000000), ref: 0051DCDE
      • __vbaLenBstr.MSVBVM60 ref: 0051DCF5
      • #617.MSVBVM60(?,00004008,-00000001), ref: 0051DD0F
      • __vbaStrVarMove.MSVBVM60(?), ref: 0051DD19
      • __vbaStrMove.MSVBVM60 ref: 0051DD24
      • __vbaFreeVar.MSVBVM60 ref: 0051DD2D
      • __vbaStrCmp.MSVBVM60(00473D9C), ref: 0051DD45
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0051DD5D
      • __vbaVarDup.MSVBVM60 ref: 0051DDAA
      • #711.MSVBVM60(?,00000000,?,000000FF,00000000), ref: 0051DDC2
      • __vbaChkstk.MSVBVM60 ref: 0051DDCD
      • __vbaVarIndexLoadRefLock.MSVBVM60(?,?,?,00000001), ref: 0051DE05
      • #518.MSVBVM60(?,00000000), ref: 0051DE16
      • __vbaAryUnlock.MSVBVM60(?), ref: 0051DE20
      • __vbaStrVarMove.MSVBVM60(?), ref: 0051DE2D
      • __vbaStrMove.MSVBVM60 ref: 0051DE38
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 0051DE53
      • __vbaLenBstr.MSVBVM60 ref: 0051DE7C
      • __vbaLenBstr.MSVBVM60(?), ref: 0051DE88
      • #619.MSVBVM60(?,00004008,-00000001), ref: 0051DEAB
      • __vbaStrVarMove.MSVBVM60(?), ref: 0051DEB5
      • __vbaStrMove.MSVBVM60 ref: 0051DEC0
      • __vbaFreeVar.MSVBVM60 ref: 0051DEC9
      • __vbaStrCopy.MSVBVM60 ref: 0051DEDF
      • __vbaStrCmp.MSVBVM60(hklm,?), ref: 0051DEF8
      • __vbaStrCmp.MSVBVM60(hkcu,?), ref: 0051DF28
      • __vbaStrCmp.MSVBVM60(hkcr,?), ref: 0051DF58
      • __vbaStrCopy.MSVBVM60 ref: 0051DFE9
      • __vbaStrCopy.MSVBVM60 ref: 0051DFFE
      • __vbaStrCopy.MSVBVM60 ref: 0051E013
      • #518.MSVBVM60(?,00004008), ref: 0051E03E
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 0051E07F
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 0051E08D
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0051E0A4
      • #712.MSVBVM60(?,Software,SOFTWARE,00000001,000000FF,00000000), ref: 0051E0D3
      • __vbaStrMove.MSVBVM60 ref: 0051E0DE
      • #712.MSVBVM60(?,software,SOFTWARE,00000001,000000FF,00000000), ref: 0051E0FF
      • __vbaStrMove.MSVBVM60 ref: 0051E10A
      • __vbaStrToAnsi.MSVBVM60(?,?,00000000,00020006,?), ref: 0051E12A
      • __vbaSetSystemError.MSVBVM60(80000002,00000000), ref: 0051E140
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 0051E14E
      • __vbaFreeStr.MSVBVM60 ref: 0051E16C
      • __vbaStrToAnsi.MSVBVM60(?,?), ref: 0051E191
      • __vbaSetSystemError.MSVBVM60(?,00000000), ref: 0051E1A7
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 0051E1B5
      • __vbaFreeStr.MSVBVM60 ref: 0051E1D0
      • __vbaSetSystemError.MSVBVM60(00000000), ref: 0051E1F3
      • __vbaStrCopy.MSVBVM60 ref: 0051E214
      • #685.MSVBVM60 ref: 0051E221
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0051E22C
      • __vbaFreeObj.MSVBVM60 ref: 0051E24D
      • __vbaFreeStr.MSVBVM60(0051E2CD), ref: 0051E2A2
      • __vbaFreeStr.MSVBVM60 ref: 0051E2AB
      • __vbaFreeStr.MSVBVM60 ref: 0051E2B4
      • __vbaFreeStr.MSVBVM60 ref: 0051E2BD
      • __vbaFreeStr.MSVBVM60 ref: 0051E2C6
      • __vbaErrorOverflow.MSVBVM60 ref: 0051E2E4
      • __vbaChkstk.MSVBVM60(00000000,00411816,HKLM\Software\Aloaha\forceHKLM,?,?,00000000,00000000,00411816,0050FC37), ref: 0051E30E
      • __vbaStrCopy.MSVBVM60(?,?,00000000,00000000,00411816,HKLM\Software\Aloaha\forceHKLM), ref: 0051E33B
      • __vbaOnError.MSVBVM60(000000FF,?,?,00000000,00000000,00411816,HKLM\Software\Aloaha\forceHKLM), ref: 0051E34A
      • __vbaStrCopy.MSVBVM60(?,?,00000000,00000000,00411816,HKLM\Software\Aloaha\forceHKLM), ref: 0051E35D
      • #518.MSVBVM60(?,00004008), ref: 0051E388
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 0051E3CC
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 0051E3DA
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0051E3F4
      • #712.MSVBVM60(?,Software,SOFTWARE,00000001,000000FF,00000000,?,00000000,00411816), ref: 0051E423
      • __vbaStrMove.MSVBVM60(?,00000000,00411816), ref: 0051E42E
      • #712.MSVBVM60(?,software,SOFTWARE,00000001,000000FF,00000000,?,00000000,00411816), ref: 0051E44F
      • __vbaStrMove.MSVBVM60(?,00000000,00411816), ref: 0051E45A
      • __vbaVarDup.MSVBVM60 ref: 0051E498
      • #711.MSVBVM60(?,?,?,000000FF,00000000), ref: 0051E4B1
      • __vbaChkstk.MSVBVM60 ref: 0051E4BC
      • __vbaVarIndexLoadRefLock.MSVBVM60(?,?,?,00000001), ref: 0051E4FA
      • #518.MSVBVM60(?,00000000,?,?,?,?,?,?,?,?,00000000,00000000,00411816,HKLM\Software\Aloaha\forceHKLM), ref: 0051E50B
      • __vbaAryUnlock.MSVBVM60(?,?,?,?,?,?,?,?,?,00000000,00000000,00411816,HKLM\Software\Aloaha\forceHKLM), ref: 0051E515
      • __vbaStrVarMove.MSVBVM60(?,?,?,?,?,?,?,?,?,00000000,00000000,00411816,HKLM\Software\Aloaha\forceHKLM), ref: 0051E522
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,00000000,00000000,00411816,HKLM\Software\Aloaha\forceHKLM), ref: 0051E52D
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00411816), ref: 0051E54E
      • __vbaLenBstr.MSVBVM60(?), ref: 0051E575
      • __vbaLenBstr.MSVBVM60(?), ref: 0051E581
      • #619.MSVBVM60(?,00004008,-00000001), ref: 0051E5A4
      • __vbaStrVarMove.MSVBVM60(?), ref: 0051E5AE
      • __vbaStrMove.MSVBVM60 ref: 0051E5B9
      • __vbaFreeVar.MSVBVM60 ref: 0051E5C2
      • __vbaVarDup.MSVBVM60 ref: 0051E5EC
      • #711.MSVBVM60(?,?,?,000000FF,00000000), ref: 0051E605
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$FreeMove$Copy$BstrError$#711ChkstkList$#518#712$IndexLoadSystem$#619AnsiLockUnicodeUnlock$#617#685OverflowUbound
      • String ID: G$SOFTWARE$Software$hkcc$hkcr$hkcu$hklm$hku$software
      • API String ID: 3325186235-4133662486
      • Opcode ID: c29337e6679869b13eba084e544c75a92605dfc60ddc59e6625f03eb072d3662
      • Instruction ID: eefe90d2ab6bb5cecb8d98e018882a98682701749757069dec786a6ebc3639a7
      • Opcode Fuzzy Hash: c29337e6679869b13eba084e544c75a92605dfc60ddc59e6625f03eb072d3662
      • Instruction Fuzzy Hash: BDD2F675900218EFDB14DFA0DD88BDDBBB5FB48304F1085A9E50ABB2A0DB745A89CF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 2587 531fd0-5320b5 __vbaChkstk __vbaFixstrConstruct * 2 __vbaOnError #520 __vbaVarTstEq __vbaFreeVar 2588 5320bb-5321ac __vbaStrCopy call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList #520 __vbaVarTstNe __vbaFreeVar 2587->2588 2589 53239d-532410 #520 __vbaVarTstEq __vbaFreeVar 2587->2589 2601 5321ae-5321c7 __vbaStrCopy call 4ecd60 2588->2601 2602 53222c-53229f #520 __vbaVarTstEq __vbaFreeVar 2588->2602 2590 532416-532507 __vbaStrCopy call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList #520 __vbaVarTstNe __vbaFreeVar 2589->2590 2591 5326f8-53276b #520 __vbaVarTstEq __vbaFreeVar 2589->2591 2604 532587-5325fa #520 __vbaVarTstEq __vbaFreeVar 2590->2604 2605 532509-532522 __vbaStrCopy call 4ecd60 2590->2605 2593 53276d-532797 2591->2593 2594 53279c-5327b7 __vbaStrCmp 2591->2594 2597 533509-5335e4 #685 __vbaObjSet __vbaFreeObj __vbaAryDestruct __vbaFreeStr __vbaAryDestruct __vbaFreeStr * 3 2593->2597 2598 5327b9-5327e3 2594->2598 2599 5327e8-5327f9 call 5393d0 2594->2599 2598->2597 2619 532830-53284b __vbaStrCmp 2599->2619 2620 5327fb-53282b 2599->2620 2614 5321cc-532229 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 2601->2614 2607 532311-532384 #520 __vbaVarTstNe __vbaFreeVar 2602->2607 2608 5322a1-532303 __vbaStrCopy call 4f0ca0 __vbaFreeStr __vbaStrCopy call 4f0ca0 2602->2608 2615 53266c-5326df #520 __vbaVarTstNe __vbaFreeVar 2604->2615 2616 5325fc-53265e __vbaStrCopy call 4f0ca0 __vbaFreeStr __vbaStrCopy call 4f0ca0 2604->2616 2621 532527-532584 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 2605->2621 2607->2589 2610 532386-532397 __vbaStrCopy 2607->2610 2632 532308-53230b __vbaFreeStr 2608->2632 2610->2589 2614->2602 2615->2591 2618 5326e1-5326f2 __vbaStrCopy 2615->2618 2635 532663-532666 __vbaFreeStr 2616->2635 2618->2591 2627 532872-532898 __vbaStrCopy 2619->2627 2628 53284d-53286d 2619->2628 2626 5334f2-533503 __vbaStrCopy 2620->2626 2621->2604 2626->2597 2629 53289a-5328f8 #546 call 517740 __vbaFreeVar 2627->2629 2630 5328fd-532922 2627->2630 2633 5334db-5334ec __vbaStrCopy 2628->2633 2642 5334c4-5334d5 __vbaStrCopy 2629->2642 2636 5329d3-5329e0 2630->2636 2637 532928-53296c #546 call 517740 __vbaFreeVar 2630->2637 2632->2607 2633->2626 2635->2615 2640 5329e6-532a66 #520 __vbaVarTstEq __vbaFreeVar 2636->2640 2641 5334b5-5334c0 2636->2641 2637->2636 2648 53296e-532983 2637->2648 2644 532ae6-532b59 #520 __vbaVarTstEq __vbaFreeVar 2640->2644 2645 532a68-532ae3 __vbaStrCopy call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 2640->2645 2641->2642 2642->2633 2646 532b5b-532bd6 __vbaStrCopy call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 2644->2646 2647 532bd9-532c4c #520 __vbaVarTstEq __vbaFreeVar 2644->2647 2645->2644 2646->2647 2651 532c65-532cd8 #520 __vbaVarTstEq __vbaFreeVar 2647->2651 2652 532c4e-532c5f __vbaStrCopy 2647->2652 2648->2636 2653 532985-53299b 2648->2653 2656 532cda-532ce7 2651->2656 2657 532cec-532d07 __vbaStrCmp 2651->2657 2652->2651 2658 5329a1-5329b2 __vbaFpR8 2653->2658 2659 5335fa 2653->2659 2660 533471-5334ae #546 call 517740 __vbaFreeVar 2656->2660 2661 532d09-532d23 2657->2661 2662 532d28-532d76 2657->2662 2658->2636 2663 5329b4-5329cd 2658->2663 2659->2659 2660->2641 2665 533447-533453 2661->2665 2662->2665 2670 532d7c-532d89 2662->2670 2663->2636 2667 533455-533462 2665->2667 2668 533464-53346b 2665->2668 2667->2660 2668->2660 2671 53343b 2670->2671 2672 532d8f-532da9 2670->2672 2671->2665 2673 532dd6-532de2 2672->2673 2674 532dab-532dd3 call 4742a4 __vbaSetSystemError 2672->2674 2675 532de4-532e0c call 4742a4 __vbaSetSystemError 2673->2675 2676 532e0f-532e1b 2673->2676 2674->2673 2675->2676 2680 532e48-532e53 2676->2680 2681 532e1d-532e45 call 4742a4 __vbaSetSystemError 2676->2681 2680->2671 2684 532e59-532e5d 2680->2684 2681->2680 2684->2671 2686 532e63-532e67 2684->2686 2686->2671 2687 532e6d-532fa8 __vbaVarDup #607 __vbaStrVarMove __vbaLsetFixstrFree __vbaFreeVarList __vbaLenBstr __vbaStrToAnsi * 2 call 47443c __vbaSetSystemError __vbaStrToUnicode * 2 __vbaLsetFixstr __vbaFreeStrList 2686->2687 2690 532fb4-532fd5 __vbaStrCopy 2687->2690 2691 532faa-532fae 2687->2691 2692 532fd7-532fde 2690->2692 2693 532ff6-533018 __vbaLenBstr 2690->2693 2691->2671 2691->2690 2692->2693 2694 532fe0-532ff0 call 4777ec __vbaSetSystemError 2692->2694 2695 533228-53327a #685 __vbaObjSet __vbaFreeObj __vbaAryLock 2693->2695 2696 53301e-533194 __vbaStrCopy #712 __vbaStrMove __vbaLsetFixstr #520 #608 __vbaStrVarVal * 2 #712 __vbaStrMove * 2 #712 __vbaStrMove __vbaStrCmp __vbaFreeStrList __vbaFreeVarList 2693->2696 2694->2693 2703 5332ca-5332d0 __vbaGenerateBoundsError 2695->2703 2704 53327c-533283 2695->2704 2696->2695 2698 53319a-533222 __vbaStrCopy call 533610 __vbaLsetFixstr __vbaAryMove __vbaFreeStr #685 __vbaObjSet __vbaFreeObj 2696->2698 2698->2695 2706 5332d6-533354 #520 __vbaAryUnlock __vbaVarTstNe __vbaFreeVar 2703->2706 2704->2703 2705 533285-53329f 2704->2705 2707 5332a1-5332ab 2705->2707 2708 5332ad-5332b3 __vbaGenerateBoundsError 2705->2708 2709 53342b-533437 2706->2709 2710 53335a-5333a0 #685 __vbaObjSet 2706->2710 2712 5332b9-5332c8 2707->2712 2708->2712 2709->2671 2713 533439 2709->2713 2715 5333a2-5333c3 __vbaHresultCheckObj 2710->2715 2716 5333c5 2710->2716 2712->2706 2713->2665 2717 5333cf-5333f6 __vbaFreeObj 2715->2717 2716->2717 2717->2709 2718 5333f8-533429 __vbaStrCopy 2717->2718 2718->2665
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,004CB93C,?,00000001,?,00000000,00411816), ref: 00531FEE
      • __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053201E
      • __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053202D
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,004CB93C), ref: 0053203C
      • #520.MSVBVM60(?,00004008), ref: 0053206B
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532093
      • __vbaFreeVar.MSVBVM60 ref: 005320A6
      • __vbaStrCopy.MSVBVM60 ref: 005320CA
      • #520.MSVBVM60(?,00000008,?), ref: 005320F7
      • __vbaStrVarMove.MSVBVM60(?), ref: 00532104
      • __vbaStrMove.MSVBVM60 ref: 00532111
      • __vbaFreeStr.MSVBVM60 ref: 0053211A
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532130
      • #520.MSVBVM60(?,00004008), ref: 00532162
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0053218A
      • __vbaFreeVar.MSVBVM60 ref: 0053219D
      • __vbaStrCopy.MSVBVM60 ref: 005321BD
      • #520.MSVBVM60(?,00000008,?), ref: 005321EA
      • __vbaStrVarMove.MSVBVM60(?), ref: 005321F7
      • __vbaStrMove.MSVBVM60 ref: 00532204
      • __vbaFreeStr.MSVBVM60 ref: 0053220D
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532223
        • Part of subcall function 004F0CA0: __vbaChkstk.MSVBVM60(?,00411816), ref: 004F0CBE
        • Part of subcall function 004F0CA0: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,?,00411816), ref: 004F0CEE
        • Part of subcall function 004F0CA0: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004F0D21
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D54
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D5F
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D82
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D8D
        • Part of subcall function 004F0CA0: #712.MSVBVM60(00000000,hkcu\,HKCU\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001), ref: 004F0DB0
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0DBB
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001), ref: 004F0DDE
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001), ref: 004F0DE9
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F0E0C
      • #520.MSVBVM60(?,00004008), ref: 00532255
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 0053227D
      • __vbaFreeVar.MSVBVM60 ref: 00532290
      • __vbaStrCopy.MSVBVM60 ref: 005322BA
      • __vbaFreeStr.MSVBVM60(?,?), ref: 005322D3
      • __vbaStrCopy.MSVBVM60 ref: 005322F2
      • __vbaFreeStr.MSVBVM60(?,?), ref: 0053230B
      • #520.MSVBVM60(?,00004008), ref: 0053233A
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 00532362
      • __vbaFreeVar.MSVBVM60 ref: 00532375
      • __vbaStrCopy.MSVBVM60 ref: 00532397
      • #520.MSVBVM60(?,00004008), ref: 005323C6
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 005323EE
      • __vbaFreeVar.MSVBVM60 ref: 00532401
      • __vbaStrCopy.MSVBVM60 ref: 00532425
      • #520.MSVBVM60(?,00000008,?), ref: 00532452
      • __vbaStrVarMove.MSVBVM60(?), ref: 0053245F
      • __vbaStrMove.MSVBVM60 ref: 0053246C
      • __vbaFreeStr.MSVBVM60 ref: 00532475
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 0053248B
      • #520.MSVBVM60(?,00004008), ref: 005324BD
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 005324E5
      • __vbaFreeVar.MSVBVM60 ref: 005324F8
      • __vbaStrCopy.MSVBVM60 ref: 00532518
      • #520.MSVBVM60(?,00000008,?), ref: 00532545
      • __vbaStrVarMove.MSVBVM60(?), ref: 00532552
      • __vbaStrMove.MSVBVM60 ref: 0053255F
      • __vbaFreeStr.MSVBVM60 ref: 00532568
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 0053257E
      • #520.MSVBVM60(?,00004008), ref: 005325B0
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 005325D8
      • __vbaFreeVar.MSVBVM60 ref: 005325EB
      • __vbaStrCopy.MSVBVM60 ref: 00532615
      • __vbaFreeStr.MSVBVM60(?,?), ref: 0053262E
      • __vbaStrCopy.MSVBVM60 ref: 0053264D
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F0E17
        • Part of subcall function 004F0CA0: #712.MSVBVM60(00000000,Software\,SOFTWARE\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001), ref: 004F0E3A
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F0E45
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001), ref: 004F0E68
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001), ref: 004F0E73
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F0E96
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F0EA1
        • Part of subcall function 004F0CA0: __vbaStrCopy.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F0EB6
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(00000001,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\), ref: 004F0ECA
        • Part of subcall function 004F0CA0: __vbaFreeStr.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F0ED3
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F0EF6
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F0F01
        • Part of subcall function 004F0CA0: __vbaStrCopy.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F0F18
        • Part of subcall function 004F0CA0: __vbaStrCmp.MSVBVM60(00473D9C,007B8E94,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F0F3D
        • Part of subcall function 004F0CA0: __vbaStrCmp.MSVBVM60(00473D9C,?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F0F59
        • Part of subcall function 004F0CA0: __vbaStrCmp.MSVBVM60(007B8E94,00000000,?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F0F8B
      • __vbaFreeStr.MSVBVM60(?,?), ref: 00532666
      • #520.MSVBVM60(?,00004008), ref: 00532695
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 005326BD
      • __vbaFreeVar.MSVBVM60 ref: 005326D0
      • __vbaStrCopy.MSVBVM60 ref: 005326F2
      • #520.MSVBVM60(?,00004008), ref: 00532721
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532749
      • __vbaFreeVar.MSVBVM60 ref: 0053275C
      • __vbaStrCmp.MSVBVM60(004740D4,0077F024), ref: 005327AF
      • __vbaStrCopy.MSVBVM60 ref: 00533503
      • #685.MSVBVM60 ref: 00533510
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0053351B
      • __vbaFreeObj.MSVBVM60 ref: 0053353C
      • __vbaAryDestruct.MSVBVM60(00000000,?,005335E5), ref: 005335AE
      • __vbaFreeStr.MSVBVM60 ref: 005335B7
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 005335C3
      • __vbaFreeStr.MSVBVM60 ref: 005335CC
      • __vbaFreeStr.MSVBVM60 ref: 005335D5
      • __vbaFreeStr.MSVBVM60 ref: 005335DE
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$#520Copy$#712$List$ChkstkConstructDestructErrorFixstr$#685
      • String ID: HKCU\Software\Aloaha\CSP\AllowHID$HKCU\Software\Aloaha\CSP\ForceHID$HKCU\Software\Aloaha\CSP\UseCSPReg$HKLM\Software\Aloaha\CSP\AllowHID$HKLM\Software\Aloaha\CSP\ForceHID$HKLM\Software\Aloaha\CSP\UseCSPReg$c$true$}
      • API String ID: 2189096737-3431907794
      • Opcode ID: 8f1efa809be1b47e29a893329d55eb50f54468ca3da5245536f26fff67b0e5bc
      • Instruction ID: 3d3e2d1ac360625775707747988ee26c51c76dbd5c17377a486424ac71e44daf
      • Opcode Fuzzy Hash: 8f1efa809be1b47e29a893329d55eb50f54468ca3da5245536f26fff67b0e5bc
      • Instruction Fuzzy Hash: B5D2D675801218DBDB14DFA0DE48BEDBBB4FF48305F1085AAE509B72A0DB745A89CF64
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 2719 5006b0-500714 __vbaChkstk __vbaOnError call 51f160 2722 500730-5007c6 #526 __vbaStrVarMove __vbaStrMove __vbaFreeVar __vbaStrToAnsi call 4751b4 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStr 2719->2722 2723 500716-50072b __vbaStrCopy 2719->2723 2728 5007f3-500802 __vbaStrCopy 2722->2728 2729 5007c8-5007d5 2722->2729 2724 500808-500877 #685 __vbaObjSet __vbaFreeObj __vbaFreeStr 2723->2724 2728->2724 2731 5007db-5007f1 #616 __vbaStrMove 2729->2731 2732 50088c-50092f __vbaErrorOverflow __vbaChkstk __vbaOnError __vbaStrCmp * 2 2729->2732 2731->2724 2734 500935-50095c __vbaStrCopy call 51f160 2732->2734 2735 5012ea-50159b __vbaStrCopy #518 #520 #518 #520 #518 #520 #518 #520 #518 #520 __vbaVarCmpEq * 2 __vbaVarOr __vbaVarCmpEq __vbaVarOr __vbaVarCmpEq __vbaVarOr __vbaVarCmpEq __vbaVarOr __vbaBoolVarNull __vbaFreeVarList 2732->2735 2742 500975-500990 __vbaStrCmp 2734->2742 2743 50095e-50096f __vbaStrCopy 2734->2743 2737 5015b4-5015cf __vbaStrCmp 2735->2737 2738 50159d-5015ae __vbaStrCopy 2735->2738 2739 5015d1-5015e2 __vbaStrCopy 2737->2739 2740 5015e8-5016dc #685 __vbaObjSet __vbaFreeObj 2737->2740 2738->2737 2739->2740 2745 500992-5009ac __vbaStrCmp 2742->2745 2746 5009c6-5009f0 2742->2746 2743->2742 2745->2746 2748 5009ae-5009c0 __vbaStrCopy 2745->2748 2750 5012d3-5012e4 __vbaStrCopy 2746->2750 2751 5009f6-500a11 __vbaStrCmp 2746->2751 2748->2746 2750->2735 2752 500a13-500a57 __vbaVarDup #667 __vbaStrMove __vbaFreeVar 2751->2752 2753 500a5d-500a78 __vbaStrCmp 2751->2753 2752->2753 2754 500ab4-500ace __vbaStrCmp 2753->2754 2755 500a7a-500a99 __vbaInStr 2753->2755 2757 500ad0-500b14 __vbaVarDup #667 __vbaStrMove __vbaFreeVar 2754->2757 2758 500b1a-500b35 __vbaStrCmp 2754->2758 2755->2754 2756 500a9b-500aae call 5006b0 __vbaStrMove 2755->2756 2756->2754 2757->2758 2760 500ba2-500bbd __vbaStrCmp 2758->2760 2761 500b37-500b9c __vbaStrCopy * 2 call 509410 __vbaStrMove __vbaFreeStrList __vbaFreeVar 2758->2761 2764 500bc3-500bed __vbaStrCmp 2760->2764 2765 500c6a-500c85 __vbaStrCmp 2760->2765 2761->2760 2769 500c26-500c54 __vbaStrCopy call 4ecd60 __vbaStrMove __vbaFreeStr 2764->2769 2770 500bef-500c24 call 51e2f0 __vbaStrVarMove __vbaStrMove __vbaFreeVar 2764->2770 2766 500ca0-500cbb __vbaStrCmp 2765->2766 2767 500c87-500c9a call 5006b0 __vbaStrMove 2765->2767 2773 500d28-500d43 __vbaStrCmp 2766->2773 2774 500cbd-500d22 __vbaStrCopy * 2 call 509410 __vbaStrMove __vbaFreeStrList __vbaFreeVar 2766->2774 2767->2766 2782 500c5a-500c61 2769->2782 2770->2782 2779 500d49-500d73 __vbaStrCmp 2773->2779 2780 500e1d-500e38 __vbaStrCmp 2773->2780 2774->2773 2786 500d75-500dca __vbaStrCat __vbaStrMove call 51e2f0 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVar 2779->2786 2787 500dcc-500e07 __vbaStrCat __vbaStrMove call 4ecd60 __vbaStrMove __vbaFreeStr 2779->2787 2783 500e84-500ea2 __vbaInStr 2780->2783 2784 500e3a-500e7e __vbaVarDup #667 __vbaStrMove __vbaFreeVar 2780->2784 2782->2765 2789 500fc1-500fe0 __vbaInStr 2783->2789 2790 500ea8-500fbe __vbaVarDup #711 __vbaRefVarAry __vbaUbound __vbaVarDup #711 __vbaChkstk __vbaVarIndexLoad __vbaStrVarMove __vbaStrMove __vbaFreeVarList 2783->2790 2784->2783 2796 500e0d-500e14 2786->2796 2787->2796 2793 500fe6-5010a6 __vbaVarDup #711 __vbaChkstk __vbaVarIndexLoad __vbaStrVarMove __vbaStrMove __vbaFreeVarList 2789->2793 2794 5010a9-5010e5 __vbaStrCmp * 2 2789->2794 2790->2789 2793->2794 2797 5010e7-5010f9 __vbaStrCopy 2794->2797 2798 5010ff-501119 __vbaStrCmp 2794->2798 2796->2780 2797->2798 2799 5012ba-5012d1 __vbaStrCopy 2798->2799 2800 50111f-50114a __vbaStrCmp 2798->2800 2799->2735 2801 501150-5011c3 __vbaStrCat __vbaStrMove call 51e2f0 __vbaVarTstEq __vbaFreeStr __vbaFreeVar 2800->2801 2802 501203-50126f __vbaStrCat __vbaStrMove call 4ecd60 __vbaStrMove __vbaStrCmp __vbaFreeStrList 2800->2802 2807 5011c5-5011f8 __vbaStrCat __vbaStrMove call 4efae0 __vbaFreeStr 2801->2807 2808 5011fe 2801->2808 2809 501271-50129c __vbaStrCat __vbaStrMove call 4efae0 2802->2809 2810 5012aa-5012b1 2802->2810 2807->2808 2808->2810 2814 5012a1-5012a4 __vbaFreeStr 2809->2814 2810->2799 2814->2810
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,0052D608,?,?,?,?,00411816,004B1BE8), ref: 005006CE
      • __vbaStrCopy.MSVBVM60(?,00000001,?,00000000,00411816,0052D608), ref: 00500725
      • #526.MSVBVM60(?,000000FF,?,00000001,?,00000000,00411816,0052D608), ref: 00500740
      • __vbaStrVarMove.MSVBVM60(?,?,00000001,?,00000000,00411816,0052D608), ref: 0050074A
      • __vbaStrMove.MSVBVM60(?,00000001,?,00000000,00411816,0052D608), ref: 00500755
      • __vbaFreeVar.MSVBVM60(?,00000001,?,00000000,00411816,0052D608), ref: 0050075E
      • __vbaStrToAnsi.MSVBVM60(000000FF,?,000000FF), ref: 00500785
      • __vbaSetSystemError.MSVBVM60(00000000), ref: 00500794
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 005007A2
      • __vbaFreeStr.MSVBVM60 ref: 005007BA
      • #616.MSVBVM60(?,000000FE), ref: 005007E0
      • __vbaStrMove.MSVBVM60 ref: 005007EB
      • #685.MSVBVM60 ref: 0050080F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050081A
      • __vbaFreeObj.MSVBVM60 ref: 00500832
      • __vbaFreeStr.MSVBVM60(00500878), ref: 00500871
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,0052D608), ref: 005006FE
        • Part of subcall function 0051F160: __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0051F17E
        • Part of subcall function 0051F160: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 0051F1AE
        • Part of subcall function 0051F160: __vbaStrCmp.MSVBVM60(true,0075A9E4), ref: 0051F1E0
        • Part of subcall function 0051F160: __vbaStrCmp.MSVBVM60(false,0075A9E4), ref: 0051F1FA
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$ErrorMove$Chkstk$#526#616#685AnsiCopySystemUnicode
      • String ID: HKCU\SOFTWARE\Aloaha\pdf\$HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Logon User Name$Logon User Name$NWUSERNAME$P$Qh|GG$SOFTWARE\Aloaha\pdf$Software\Microsoft\Windows\CurrentVersion\Explorer$USERNAME$Z$alias$local service$local system$localservice$network$system$true$username$usernotfound$winpe
      • API String ID: 3916836903-3299935217
      • Opcode ID: be0db7e2fa4d07a1ef1cf2f2dcae3907a2b178d877658b4a3810346d30624071
      • Instruction ID: 7f06321d92f5faa0d0fcf736e03f437fc9aa4c669c5addd304c33c4bdaa734da
      • Opcode Fuzzy Hash: be0db7e2fa4d07a1ef1cf2f2dcae3907a2b178d877658b4a3810346d30624071
      • Instruction Fuzzy Hash: 89923975A00209DBDB14DFA0DE48BEEBBB8FB48305F14816DE506B72A0DB745A49CF64
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 2815 4f0ca0-4f0d31 __vbaChkstk __vbaOnError call 51cef0 __vbaStrCmp 2818 4f1968-4f19ee #685 __vbaObjSet __vbaFreeObj __vbaFreeStr * 2 2815->2818 2819 4f0d37-4f0f45 #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove __vbaStrCopy call 50fba0 __vbaStrMove __vbaFreeStr #712 __vbaStrMove __vbaStrCopy __vbaStrCmp 2815->2819 2823 4f0f47-4f0f61 __vbaStrCmp 2819->2823 2824 4f0fa2-4f0fae 2819->2824 2823->2824 2826 4f0f63-4f0f75 2823->2826 2827 4f0fc2-4f0fd1 2824->2827 2828 4f0fb0-4f0fbd 2824->2828 2826->2824 2829 4f0f77-4f0f93 __vbaStrCmp 2826->2829 2831 4f0fdf-4f0fff 2827->2831 2832 4f0fd3-4f0fda call 50af90 2827->2832 2830 4f1907-4f195f __vbaStrCopy * 2 2828->2830 2829->2824 2833 4f0f95-4f0f9c 2829->2833 2830->2818 2835 4f10a5-4f10b4 2831->2835 2836 4f1005-4f1081 call 4f2d70 __vbaStrMove __vbaStrCmp * 3 __vbaFreeStr 2831->2836 2832->2831 2833->2824 2837 4f10ba-4f1134 #518 #617 __vbaVarTstEq __vbaFreeVarList 2835->2837 2838 4f1164-4f1184 call 4fe150 2835->2838 2836->2835 2845 4f1083-4f109c call 4f3390 2836->2845 2840 4f114e-4f115e __vbaStrCopy 2837->2840 2841 4f1136-4f114c __vbaStrCopy 2837->2841 2846 4f119b-4f11ab 2838->2846 2847 4f1186-4f1195 __vbaStrCopy 2838->2847 2840->2838 2841->2838 2845->2835 2850 4f1395-4f13ad __vbaStrCmp 2846->2850 2851 4f11b1-4f11c1 2846->2851 2847->2846 2852 4f13af-4f13b8 2850->2852 2853 4f13be-4f1498 #685 __vbaObjSet __vbaFreeObj __vbaChkstk __vbaLateMemCallLd __vbaStrVarMove __vbaStrMove __vbaFreeVar #685 __vbaObjSet 2850->2853 2854 4f11ed-4f1208 __vbaStrCmp 2851->2854 2855 4f11c3-4f11d9 __vbaStrCopy call 4f2ff0 2851->2855 2852->2853 2856 4f1689-4f16da #685 __vbaObjSet __vbaFreeObj __vbaStrCmp 2852->2856 2865 4f149c-4f14ab 2853->2865 2858 4f121a-4f1229 2854->2858 2859 4f120a-4f1211 2854->2859 2861 4f11de-4f11e7 __vbaFreeStr 2855->2861 2867 4f16dc-4f16e5 2856->2867 2868 4f16eb-4f17be __vbaChkstk * 3 __vbaLateMemCall 2856->2868 2858->2850 2860 4f122f-4f124d __vbaInStr 2858->2860 2859->2858 2860->2850 2863 4f1253-4f12c2 #712 __vbaStrMove __vbaStrCopy call 50fba0 __vbaStrMove __vbaFreeStr 2860->2863 2861->2854 2863->2850 2875 4f12c8-4f1342 #518 #617 __vbaVarTstEq __vbaFreeVarList 2863->2875 2869 4f14ad-4f14ce __vbaHresultCheckObj 2865->2869 2870 4f14d0 2865->2870 2867->2868 2872 4f17c0-4f1811 __vbaStrI4 __vbaStrMove __vbaStrCopy call 5071e0 __vbaFreeStrList 2867->2872 2873 4f1814-4f185a #685 __vbaObjSet 2868->2873 2874 4f14da-4f1501 __vbaFreeObj 2869->2874 2870->2874 2872->2873 2883 4f187f 2873->2883 2884 4f185c-4f187d __vbaHresultCheckObj 2873->2884 2874->2856 2877 4f1507-4f15d1 #685 __vbaObjSet __vbaFreeObj __vbaObjSetAddref #716 __vbaObjVar __vbaObjSetAddref __vbaFreeVar #685 __vbaObjSet 2874->2877 2878 4f135c-4f136c __vbaStrCopy 2875->2878 2879 4f1344-4f135a __vbaStrCopy 2875->2879 2892 4f15f6 2877->2892 2893 4f15d3-4f15f4 __vbaHresultCheckObj 2877->2893 2882 4f1372-4f137e 2878->2882 2879->2882 2882->2850 2886 4f1380-4f138f __vbaStrCopy 2882->2886 2887 4f1889-4f18b0 __vbaFreeObj 2883->2887 2884->2887 2886->2850 2888 4f18b2-4f18bf 2887->2888 2889 4f18c1-4f18c8 2887->2889 2890 4f18ce-4f1901 #685 __vbaObjSet __vbaFreeObj 2888->2890 2889->2890 2890->2830 2895 4f1600-4f1627 __vbaFreeObj 2892->2895 2893->2895 2895->2856 2896 4f1629-4f1683 __vbaStrCopy call 4fa530 __vbaFreeStr #685 __vbaObjSet __vbaFreeObj 2895->2896 2896->2856
      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004F0CBE
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,?,00411816), ref: 004F0CEE
        • Part of subcall function 0051CEF0: __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0051CF0E
        • Part of subcall function 0051CEF0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 0051CF3E
        • Part of subcall function 0051CEF0: __vbaStrCmp.MSVBVM60(true,00000000,?,?,?,00000000,00411816), ref: 0051CF56
        • Part of subcall function 0051CEF0: #685.MSVBVM60 ref: 0051CFAF
        • Part of subcall function 0051CEF0: __vbaObjSet.MSVBVM60(00000000,00000000), ref: 0051CFBA
        • Part of subcall function 0051CEF0: __vbaFreeObj.MSVBVM60 ref: 0051CFD2
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004F0D21
      • #712.MSVBVM60(?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D54
      • __vbaStrMove.MSVBVM60(?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D5F
      • #712.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D82
      • __vbaStrMove.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D8D
      • #712.MSVBVM60(00000000,hkcu\,HKCU\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001), ref: 004F0DB0
      • __vbaStrMove.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0DBB
      • #712.MSVBVM60(?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001), ref: 004F0DDE
      • __vbaStrMove.MSVBVM60(?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001), ref: 004F0DE9
      • #712.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F0E0C
      • __vbaStrMove.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F0E17
      • #712.MSVBVM60(00000000,Software\,SOFTWARE\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001), ref: 004F0E3A
      • __vbaStrMove.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F0E45
      • #712.MSVBVM60(?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001), ref: 004F0E68
      • __vbaStrMove.MSVBVM60(?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001), ref: 004F0E73
      • #712.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F0E96
      • __vbaStrMove.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F0EA1
      • __vbaStrCopy.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F0EB6
      • __vbaStrMove.MSVBVM60(00000001,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\), ref: 004F0ECA
      • __vbaFreeStr.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F0ED3
      • #712.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F0EF6
      • __vbaStrMove.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F0F01
      • __vbaStrCopy.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F0F18
      • __vbaStrCmp.MSVBVM60(00473D9C,007B8E94,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F0F3D
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F0F59
      • __vbaStrCmp.MSVBVM60(007B8E94,00000000,?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F0F8B
      • __vbaStrMove.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F1016
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F1022
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F103C
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F1058
      • __vbaFreeStr.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F1072
      • #518.MSVBVM60(00000001,00004008,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F10D6
      • #617.MSVBVM60(00000000,00000001,00000004,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F10E6
      • __vbaVarTstEq.MSVBVM60(00008008,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F110B
      • __vbaFreeVarList.MSVBVM60(00000002,00000001,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F1122
      • __vbaStrCopy.MSVBVM60(00000000,?,00411816), ref: 004F1146
      • __vbaStrCopy.MSVBVM60(00000000,?,00411816), ref: 004F115E
      • __vbaStrCopy.MSVBVM60(?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\), ref: 004F1195
      • __vbaStrCopy.MSVBVM60(?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\), ref: 004F11CF
      • __vbaFreeStr.MSVBVM60(00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\), ref: 004F11E7
      • __vbaStrCmp.MSVBVM60(true,0075AE44,?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F1200
      • __vbaInStr.MSVBVM60(00000000,HKLM\SOFTWARE\Aloaha\pdf,?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F1245
      • #712.MSVBVM60(00000000,HKLM\SOFTWARE\Aloaha\pdf,HKCU\SOFTWARE\Aloaha\pdf,00000001,000000FF,00000000,?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\), ref: 004F1270
      • __vbaStrMove.MSVBVM60(?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F127B
      • __vbaStrCopy.MSVBVM60(?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F1290
      • __vbaStrMove.MSVBVM60(00000001,?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F12A4
      • __vbaFreeStr.MSVBVM60(?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F12AD
      • #518.MSVBVM60(00000001,00004008,?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F12E4
      • #617.MSVBVM60(00000000,00000001,00000004,?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF), ref: 004F12F4
      • __vbaVarTstEq.MSVBVM60(00008008,00000000,?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F1319
      • __vbaFreeVarList.MSVBVM60(00000002,00000001,00000000,?,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF), ref: 004F1330
      • __vbaStrCopy.MSVBVM60(00000000,?,00411816), ref: 004F1354
      • __vbaStrCopy.MSVBVM60(00000000,?,00411816), ref: 004F136C
      • __vbaStrCopy.MSVBVM60 ref: 004F138F
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F13A5
      • #685.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F13C5
      • __vbaObjSet.MSVBVM60(?,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F13D0
      • __vbaFreeObj.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F13F1
      • __vbaChkstk.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F1411
      • __vbaLateMemCallLd.MSVBVM60(00000001,022C1040,RegRead,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F1441
      • __vbaStrVarMove.MSVBVM60(00000000,00000001), ref: 004F144B
      • __vbaStrMove.MSVBVM60 ref: 004F1456
      • __vbaFreeVar.MSVBVM60 ref: 004F145F
      • #685.MSVBVM60 ref: 004F146C
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F1477
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004F14C2
      • __vbaFreeObj.MSVBVM60 ref: 004F14F2
      • #685.MSVBVM60 ref: 004F150E
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F1519
      • __vbaFreeObj.MSVBVM60 ref: 004F153A
      • __vbaObjSetAddref.MSVBVM60(0054D554,00000000), ref: 004F154E
      • #716.MSVBVM60(?,WScript.Shell,00000000), ref: 004F1566
      • __vbaObjVar.MSVBVM60(?), ref: 004F1570
      • __vbaObjSetAddref.MSVBVM60(0054D554,00000000), ref: 004F157C
      • __vbaFreeVar.MSVBVM60 ref: 004F1585
      • #685.MSVBVM60 ref: 004F1592
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F159D
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004F15E8
      • __vbaFreeObj.MSVBVM60 ref: 004F1618
      • __vbaStrCopy.MSVBVM60 ref: 004F1638
      • __vbaFreeStr.MSVBVM60(?), ref: 004F164A
      • #685.MSVBVM60 ref: 004F1657
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F1662
      • __vbaFreeObj.MSVBVM60 ref: 004F1683
      • #685.MSVBVM60 ref: 004F1690
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F169B
      • __vbaFreeObj.MSVBVM60 ref: 004F16BC
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004F16D2
      • __vbaChkstk.MSVBVM60 ref: 004F172B
      • __vbaChkstk.MSVBVM60 ref: 004F174E
      • __vbaChkstk.MSVBVM60 ref: 004F177D
      • __vbaLateMemCall.MSVBVM60(022C1040,Regwrite,00000003), ref: 004F17B5
      • __vbaStrI4.MSVBVM60(00000000), ref: 004F17CD
      • __vbaStrMove.MSVBVM60 ref: 004F17D8
      • __vbaStrCopy.MSVBVM60 ref: 004F17E6
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,00000000), ref: 004F180B
      • #685.MSVBVM60 ref: 004F181B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F1826
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004F1871
      • __vbaFreeObj.MSVBVM60 ref: 004F18A1
      • #685.MSVBVM60 ref: 004F18D5
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F18E0
      • __vbaFreeObj.MSVBVM60 ref: 004F1901
      • __vbaStrCopy.MSVBVM60 ref: 004F1918
      • __vbaStrCopy.MSVBVM60 ref: 004F1940
      • #685.MSVBVM60 ref: 004F196F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F197A
      • __vbaFreeObj.MSVBVM60 ref: 004F199B
      • __vbaFreeStr.MSVBVM60(004F19EF), ref: 004F19DF
      • __vbaFreeStr.MSVBVM60 ref: 004F19E8
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$Copy$#685#712$Chkstk$CheckHresultList$#518#617AddrefCallErrorLate$#716
      • String ID: HKCR\$HKCU\$HKCU\SOFTWARE\Aloaha\pdf$HKLM\$HKLM\SOFTWARE\Aloaha\ctest$HKLM\SOFTWARE\Aloaha\pdf$PDF$REG_DWORD$RegRead$Regwrite$SOFTWARE\$SYSTEM\$Software\$Sofware\$System\$WScript.Shell$hYH$hkcu$hkcu\$hklm\$hlcr\$j$regi.CreateCOMObject wscript.shell failed in regwrite_dw$software\$system\$true
      • API String ID: 2945476557-1962897271
      • Opcode ID: 8a25559b589aaa2dec2b92b0df61e715c9e38d457ab28f282ca4db867e3d01a0
      • Instruction ID: b1efe63cbbb945048ad09546138e8bbcaaeec40a80b12b684528fba53bdd7763
      • Opcode Fuzzy Hash: 8a25559b589aaa2dec2b92b0df61e715c9e38d457ab28f282ca4db867e3d01a0
      • Instruction Fuzzy Hash: 1B825C74A00208EFDB14DFA0DD48BEEBBB5FF48705F1081A9E509AB2A0DB749A45DF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 2900 4cf630-4cf69e __vbaChkstk __vbaOnError __vbaStrCmp 2901 4cf6a4-4cf732 #685 __vbaObjSet __vbaFreeObj call 519660 #685 __vbaObjSet 2900->2901 2902 4d01d6-4d0266 #685 __vbaObjSet __vbaFreeObj __vbaFreeStr * 3 2900->2902 2909 4cf734-4cf755 __vbaHresultCheckObj 2901->2909 2910 4cf757 2901->2910 2911 4cf761-4cf788 __vbaFreeObj 2909->2911 2910->2911 2912 4cf798-4cf7dc #685 __vbaObjSet __vbaFreeObj 2911->2912 2913 4cf78a-4cf791 2911->2913 2915 4d01bf-4d01d0 __vbaStrCopy 2912->2915 2916 4cf7e2-4cf84a call 51fb00 __vbaStrMove __vbaInStr * 2 2912->2916 2913->2912 2915->2902 2919 4cf95c-4cf9fa __vbaStrCopy call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList __vbaStrCmp * 2 2916->2919 2920 4cf850-4cf8ee __vbaStrCopy call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList __vbaStrCmp * 2 2916->2920 2925 4cf9fc-4cfa60 __vbaStrCopy call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 2919->2925 2926 4cfa63-4cfa9a __vbaStrCmp * 2 2919->2926 2927 4cf957 2920->2927 2928 4cf8f0-4cf909 __vbaStrCopy call 4ecd60 2920->2928 2925->2926 2930 4cfabc-4cfb63 #685 __vbaObjSet __vbaFreeObj __vbaR8Str __vbaStrR8 __vbaStrMove #685 __vbaObjSet 2926->2930 2931 4cfa9c-4cfab6 __vbaStrCopy 2926->2931 2927->2926 2934 4cf90e-4cf954 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList 2928->2934 2937 4cfb88 2930->2937 2938 4cfb65-4cfb86 __vbaHresultCheckObj 2930->2938 2931->2930 2934->2927 2939 4cfb92-4cfbb9 __vbaFreeObj 2937->2939 2938->2939 2940 4cfbbb-4cfc0e __vbaStrCopy #685 __vbaObjSet __vbaFreeObj 2939->2940 2941 4cfc14-4cfc6c #685 __vbaObjSet __vbaFreeObj __vbaI4Str * 2 2939->2941 2940->2941 2944 4d0278-4d027f __vbaErrorOverflow 2941->2944 2945 4cfc72-4cfc8e __vbaI4Abs call 51d000 2941->2945 2948 4cfce5-4cfd2b #685 __vbaObjSet 2945->2948 2949 4cfc90-4cfc94 2945->2949 2954 4cfd2d-4cfd4e __vbaHresultCheckObj 2948->2954 2955 4cfd50 2948->2955 2949->2948 2950 4cfc96-4cfce2 __vbaStrI4 __vbaStrMove __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStrList 2949->2950 2950->2948 2956 4cfd5a-4cfd81 __vbaFreeObj 2954->2956 2955->2956 2957 4cfdea-4cfdf6 2956->2957 2958 4cfd83-4cfde4 __vbaStrCopy #685 __vbaObjSet __vbaFreeObj 2956->2958 2959 4cfdfc-4cfe40 __vbaInStr * 2 2957->2959 2960 4cfef0-4cff01 call 51d000 2957->2960 2958->2957 2963 4cfe9a-4cfeea __vbaStrCopy call 4efae0 __vbaFreeStr __vbaStrCopy call 4efae0 __vbaFreeStr 2959->2963 2964 4cfe42-4cfe8a __vbaStrCopy call 4efae0 __vbaFreeStr __vbaStrCopy call 4efae0 2959->2964 2960->2915 2968 4cff07-4cff0b 2960->2968 2963->2960 2976 4cfe8f-4cfe98 __vbaFreeStr 2964->2976 2968->2915 2971 4cff11-4cffaf #518 __vbaInStrVar __vbaVarTstEq __vbaFreeVarList 2968->2971 2971->2915 2975 4cffb5-4cffc6 call 5138b0 2971->2975 2975->2915 2979 4cffcc-4d001f #685 __vbaObjSet __vbaFreeObj call 518950 2975->2979 2976->2960 2983 4d002f-4d003c 2979->2983 2984 4d0021-4d0028 2979->2984 2983->2944 2985 4d0042-4d0052 2983->2985 2984->2983 2986 4d0054-4d0061 2985->2986 2987 4d0070-4d007d 2985->2987 2986->2944 2988 4d0067-4d006d __vbaI4Abs 2986->2988 2989 4d007f-4d0083 2987->2989 2990 4d0085-4d0092 2987->2990 2988->2987 2989->2990 2991 4d00a1-4d00c3 2989->2991 2990->2944 2992 4d0098-4d009e __vbaI4Abs 2990->2992 2993 4d00d7-4d00e0 2991->2993 2992->2991 2994 4d0140-4d019a __vbaStrI4 __vbaStrMove __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStrList 2993->2994 2995 4d00e2-4d00ed 2993->2995 2994->2915 3001 4d019c-4d01b9 call 4ceef0 __vbaStrCopy 2994->3001 2997 4d00ef-4d0113 call 518950 2995->2997 2998 4d0135 2995->2998 2997->2944 3004 4d0119-4d012f __vbaI4Abs 2997->3004 2998->2994 3001->2915 3005 4d0131 3004->3005 3006 4d0133-4d013e 3004->3006 3005->2994 3006->2944 3010 4d00d4 3006->3010 3010->2993
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 004CF64E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 004CF67E
      • __vbaStrCmp.MSVBVM60(true,0077F59C,?,00000000,?,00000000,00411816), ref: 004CF696
      • #685.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004CF6AB
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,?,00000000,00411816), ref: 004CF6B6
      • __vbaFreeObj.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004CF6D7
        • Part of subcall function 00519660: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 0051967E
        • Part of subcall function 00519660: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816), ref: 005196AE
        • Part of subcall function 00519660: __vbaStrCopy.MSVBVM60(?,00000001,?,00000000,00411816), ref: 005196C3
        • Part of subcall function 00519660: __vbaFreeStr.MSVBVM60(?,?,00000001,?,00000000,00411816), ref: 005196D5
        • Part of subcall function 00519660: __vbaStrCmp.MSVBVM60(true,0077F574,?,00000001,?,00000000,00411816), ref: 005196EE
        • Part of subcall function 00519660: __vbaStrCopy.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0051970D
        • Part of subcall function 00519660: #685.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0051971A
        • Part of subcall function 00519660: __vbaObjSet.MSVBVM60(?,00000000,?,00000001,?,00000000,00411816), ref: 00519725
        • Part of subcall function 00519660: __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00519746
        • Part of subcall function 00519660: __vbaLateMemCallLd.MSVBVM60(?,00000000,info,00000000), ref: 00519772
        • Part of subcall function 00519660: __vbaVarTstLt.MSVBVM60(?,00000000,00000001,?,00000000,00411816), ref: 00519780
        • Part of subcall function 00519660: __vbaFreeVar.MSVBVM60(?,00000000,00411816), ref: 0051978D
        • Part of subcall function 00519660: __vbaObjSetAddref.MSVBVM60(0054D334,00000000,?,00000000,00411816), ref: 005197A9
        • Part of subcall function 00519660: #685.MSVBVM60 ref: 0051988B
        • Part of subcall function 00519660: __vbaObjSet.MSVBVM60(?,00000000), ref: 00519896
        • Part of subcall function 00519660: __vbaFreeObj.MSVBVM60 ref: 005198B7
      • #685.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004CF6F3
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,?,00000000,00411816), ref: 004CF6FE
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004CF749
      • __vbaFreeObj.MSVBVM60 ref: 004CF779
      • #685.MSVBVM60 ref: 004CF79F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004CF7AA
      • __vbaFreeObj.MSVBVM60 ref: 004CF7CB
      • __vbaStrMove.MSVBVM60 ref: 004CF800
      • __vbaInStr.MSVBVM60(00000000,smart,007C035C,00000001), ref: 004CF81C
      • __vbaInStr.MSVBVM60(00000000,login,007C035C,00000001), ref: 004CF839
      • __vbaStrCopy.MSVBVM60 ref: 004CF85F
      • #520.MSVBVM60(?,00000008,?), ref: 004CF880
      • __vbaStrVarMove.MSVBVM60(?), ref: 004CF88A
      • __vbaStrMove.MSVBVM60 ref: 004CF895
      • __vbaFreeStr.MSVBVM60 ref: 004CF89E
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004CF8AE
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,00000000,00411816), ref: 004CF8C7
      • __vbaStrCmp.MSVBVM60(004740D4,?,?,00000000,00411816), ref: 004CF8DE
      • __vbaStrCopy.MSVBVM60(?,00000000,00411816), ref: 004CF8FF
      • #520.MSVBVM60(?,00000008), ref: 004CF920
      • __vbaStrVarMove.MSVBVM60(?), ref: 004CF92A
      • __vbaStrMove.MSVBVM60 ref: 004CF935
      • __vbaFreeStr.MSVBVM60 ref: 004CF93E
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004CF94E
      • __vbaStrCopy.MSVBVM60 ref: 004CF96B
      • #520.MSVBVM60(?,00000008,?), ref: 004CF98C
      • __vbaStrVarMove.MSVBVM60(?), ref: 004CF996
      • __vbaStrMove.MSVBVM60 ref: 004CF9A1
      • __vbaFreeStr.MSVBVM60 ref: 004CF9AA
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004CF9BA
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,00000000,00411816), ref: 004CF9D3
      • __vbaStrCmp.MSVBVM60(004740D4,?,?,00000000,00411816), ref: 004CF9EA
      • __vbaStrCopy.MSVBVM60(?,00000000,00411816), ref: 004CFA0B
      • #520.MSVBVM60(?,00000008), ref: 004CFA2C
      • __vbaStrVarMove.MSVBVM60(?), ref: 004CFA36
      • __vbaStrMove.MSVBVM60 ref: 004CFA41
      • __vbaFreeStr.MSVBVM60 ref: 004CFA4A
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004CFA5A
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,00000000,00411816), ref: 004CFA73
      • __vbaStrCmp.MSVBVM60(004740D4,?,?,00000000,00411816), ref: 004CFA8A
      • __vbaStrCopy.MSVBVM60(?,00000000,00411816), ref: 004CFAA9
      • #685.MSVBVM60(?,00000000,00411816), ref: 004CFAC3
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004CFACE
      • __vbaFreeObj.MSVBVM60(?,00000000,00411816), ref: 004CFAEF
      • __vbaR8Str.MSVBVM60(?,?,00000000,00411816), ref: 004CFB00
      • __vbaStrR8.MSVBVM60(?,?,?,?,00411816), ref: 004CFB0C
      • __vbaStrMove.MSVBVM60(?,?,?,?,00411816), ref: 004CFB17
      • #685.MSVBVM60(?,?,?,?,00411816), ref: 004CFB24
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00411816), ref: 004CFB2F
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004CFB7A
      • __vbaFreeObj.MSVBVM60 ref: 004CFBAA
      • __vbaStrCopy.MSVBVM60 ref: 004CFBC8
      • #685.MSVBVM60 ref: 004CFBE2
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004CFBED
      • __vbaFreeObj.MSVBVM60 ref: 004CFC0E
      • #685.MSVBVM60 ref: 004CFC1B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004CFC26
      • __vbaFreeObj.MSVBVM60 ref: 004CFC47
      • __vbaI4Str.MSVBVM60(?), ref: 004CFC58
      • __vbaI4Str.MSVBVM60(?), ref: 004CFC64
      • __vbaI4Abs.MSVBVM60 ref: 004CFC74
      • __vbaStrI4.MSVBVM60(00000007,Do Action: ), ref: 004CFCA6
      • __vbaStrMove.MSVBVM60 ref: 004CFCB1
      • __vbaStrCat.MSVBVM60(00000000), ref: 004CFCB8
      • __vbaStrMove.MSVBVM60 ref: 004CFCC3
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004CFCDC
      • #685.MSVBVM60(?,?,?,?,?,?,?,00411816), ref: 004CFCEC
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004CFCF7
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004CFD42
      • __vbaFreeObj.MSVBVM60 ref: 004CFD72
      • __vbaStrCopy.MSVBVM60 ref: 004CFD9E
      • #685.MSVBVM60 ref: 004CFDB8
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004CFDC3
      • __vbaFreeObj.MSVBVM60 ref: 004CFDE4
      • __vbaInStr.MSVBVM60(00000000,smart,007C035C,00000001), ref: 004CFE12
      • __vbaInStr.MSVBVM60(00000000,login,007C035C,00000001), ref: 004CFE2F
      • __vbaStrCopy.MSVBVM60 ref: 004CFE51
      • __vbaFreeStr.MSVBVM60(?,?), ref: 004CFE67
      • __vbaStrCopy.MSVBVM60 ref: 004CFE7C
      • __vbaFreeStr.MSVBVM60(?,?), ref: 004CFE92
      • __vbaStrCopy.MSVBVM60 ref: 004CFEA9
      • __vbaFreeStr.MSVBVM60(?,?), ref: 004CFEBF
      • __vbaStrCopy.MSVBVM60 ref: 004CFED4
      • __vbaFreeStr.MSVBVM60(?,?), ref: 004CFEEA
      • #518.MSVBVM60(?,00004008), ref: 004CFF37
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 004CFF78
      • __vbaVarTstEq.MSVBVM60(00008002,00000000), ref: 004CFF86
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004CFF9D
      • #685.MSVBVM60 ref: 004CFFD3
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004CFFDE
      • __vbaFreeObj.MSVBVM60 ref: 004CFFFF
        • Part of subcall function 00518950: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,004D0011), ref: 0051896E
        • Part of subcall function 00518950: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 0051899E
        • Part of subcall function 00518950: #594.MSVBVM60(0000000A), ref: 005189BD
        • Part of subcall function 00518950: __vbaFreeVar.MSVBVM60 ref: 005189C6
        • Part of subcall function 00518950: #593.MSVBVM60(0000000A), ref: 005189E5
        • Part of subcall function 00518950: __vbaFpI4.MSVBVM60 ref: 005189FB
        • Part of subcall function 00518950: #573.MSVBVM60(?,00000003), ref: 00518A13
        • Part of subcall function 00518950: __vbaStrErrVarCopy.MSVBVM60(?,00478678), ref: 00518A36
        • Part of subcall function 00518950: __vbaStrMove.MSVBVM60 ref: 00518A41
        • Part of subcall function 00518950: __vbaStrCat.MSVBVM60(00000000), ref: 00518A48
        • Part of subcall function 00518950: #619.MSVBVM60(?,00000008,00000002), ref: 00518A62
        • Part of subcall function 00518950: __vbaVarAdd.MSVBVM60(?,?,00000008), ref: 00518A7A
        • Part of subcall function 00518950: __vbaStrVarVal.MSVBVM60(?,00000000), ref: 00518A85
        • Part of subcall function 00518950: #581.MSVBVM60(00000000), ref: 00518A8C
        • Part of subcall function 00518950: __vbaFpI4.MSVBVM60 ref: 00518A92
        • Part of subcall function 00518950: __vbaFreeStrList.MSVBVM60(00000002,00000000,?), ref: 00518AA5
      • __vbaI4Abs.MSVBVM60 ref: 004D0067
      • __vbaI4Abs.MSVBVM60 ref: 004D0098
      • __vbaI4Abs.MSVBVM60 ref: 004D011B
      • __vbaStrI4.MSVBVM60(?,Random: ), ref: 004D0150
      • __vbaStrMove.MSVBVM60 ref: 004D015B
      • __vbaStrCat.MSVBVM60(00000000), ref: 004D0162
      • __vbaStrMove.MSVBVM60 ref: 004D016D
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004D0186
      • __vbaStrCopy.MSVBVM60 ref: 004D01B9
      • __vbaStrCopy.MSVBVM60 ref: 004D01D0
      • #685.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004D01DD
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,?,00000000,00411816), ref: 004D01E8
      • __vbaFreeObj.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004D0209
      • __vbaFreeStr.MSVBVM60(004D0267,?,00000000,?,00000000,00411816), ref: 004D024E
      • __vbaFreeStr.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004D0257
      • __vbaFreeStr.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004D0260
      • __vbaErrorOverflow.MSVBVM60 ref: 004D0278
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Copy$Move$#685$List$#520Error$CheckChkstkHresult$#518#573#581#593#594#619AddrefCallLateOverflow
      • String ID: 3$Do Action: $HKCU\Software\Aloaha\csp\Permissions$HKCU\Software\Aloaha\pdf\FinePrint$HKLM\Software\Aloaha\csp\Permissions$HKLM\Software\Aloaha\pdf\FinePrint$Random: $[$login$smart$system$true
      • API String ID: 3176523432-1327735644
      • Opcode ID: 6f84bc1d9eef428c178aadc373e140c3cffc7facf171b05321b38d72bf8117f9
      • Instruction ID: 84a6524aecff1442f9ac6403fa0d15472be6eec4c0ac4778de55105c61d5b656
      • Opcode Fuzzy Hash: 6f84bc1d9eef428c178aadc373e140c3cffc7facf171b05321b38d72bf8117f9
      • Instruction Fuzzy Hash: 05726875900209DFDB14DFA0DA48BDEBBB5FF48305F1081AAE506B72A0DB785A49CF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3011 506210-50634c __vbaChkstk __vbaOnError #619 #608 #617 #608 __vbaVarCmpEq * 2 __vbaVarAnd __vbaBoolVarNull __vbaFreeVarList 3012 506365-5063a8 #520 __vbaStrVarMove __vbaStrMove __vbaFreeVar 3011->3012 3013 50634e-506363 __vbaStrCopy 3011->3013 3014 5063ae-506496 #619 #608 #617 #608 __vbaVarCmpEq * 2 __vbaVarAnd __vbaBoolVarNull __vbaFreeVarList 3012->3014 3013->3014 3015 506498-5064ad __vbaStrCopy 3014->3015 3016 5064af-5064f2 #520 __vbaStrVarMove __vbaStrMove __vbaFreeVar 3014->3016 3017 5064f8-50657c #608 __vbaInStrVar __vbaVarTstGt __vbaFreeVarList 3015->3017 3016->3017 3018 5065d2-5065ee __vbaInStr 3017->3018 3019 50657e-5065cc #608 __vbaStrVarVal #712 __vbaStrMove __vbaFreeStr __vbaFreeVar 3017->3019 3020 5065f0-506616 #712 __vbaStrMove 3018->3020 3021 50661c-5066cc #520 __vbaStrVarMove __vbaStrMove __vbaFreeVar #520 __vbaStrVarMove __vbaStrMove __vbaFreeVar __vbaInStr 3018->3021 3019->3018 3020->3021 3022 5066d2-50676f #518 __vbaInStrVar __vbaVarTstEq __vbaFreeVarList 3021->3022 3023 506786-50684b __vbaStrCmp __vbaInStrVar __vbaVarCmpGt __vbaVarAnd __vbaBoolVarNull __vbaFreeVarList 3021->3023 3022->3023 3024 506771-506780 __vbaStrCopy 3022->3024 3025 506869-5068b4 #525 __vbaStrMove __vbaLenBstr __vbaStrCmp 3023->3025 3026 50684d-506863 __vbaStrVarCopy __vbaStrMove 3023->3026 3024->3023 3027 506ad7-506ae6 __vbaStrCopy 3025->3027 3028 5068ba-506914 __vbaStrToAnsi * 5 call 4752dc 3025->3028 3026->3025 3030 506aec-506b04 __vbaStrCmp 3027->3030 3033 506919-50699e __vbaSetSystemError __vbaStrToUnicode * 5 __vbaFreeStrList 3028->3033 3031 506b0a-506b39 __vbaStrCopy __vbaInStr 3030->3031 3032 506bec-506cd2 #685 __vbaObjSet __vbaFreeObj __vbaFreeVar __vbaFreeStr * 3 3030->3032 3034 506b67-506b83 __vbaInStr 3031->3034 3035 506b3b-506b61 #712 __vbaStrMove 3031->3035 3036 506ac0-506acf __vbaStrCopy 3033->3036 3037 5069a4-506a45 #616 __vbaStrMove #617 __vbaVarTstEq __vbaFreeStr __vbaFreeVarList 3033->3037 3038 506b85-506bd3 #608 __vbaStrVarVal #712 __vbaStrMove __vbaFreeStr __vbaFreeVar 3034->3038 3039 506bd9-506be6 __vbaStrCopy 3034->3039 3035->3034 3043 506ad5 3036->3043 3041 506a47-506a67 #616 __vbaStrMove 3037->3041 3042 506a69-506abb #616 #520 __vbaStrVarMove __vbaStrMove __vbaFreeVarList 3037->3042 3038->3039 3039->3032 3045 506abe 3041->3045 3042->3045 3043->3030 3045->3043
      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,005309BD,?,?,?,?,?,00000000,?,00000000,00411816), ref: 0050622E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 0050625E
      • #619.MSVBVM60(?,00004008,00000001), ref: 0050628B
      • #608.MSVBVM60(?,00000022), ref: 00506297
      • #617.MSVBVM60(?,00004008,00000001), ref: 005062C0
      • #608.MSVBVM60(?,00000022), ref: 005062CF
      • __vbaVarCmpEq.MSVBVM60(?,?,?), ref: 005062E4
      • __vbaVarCmpEq.MSVBVM60(?,?,?,00000000), ref: 00506300
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 0050630E
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 00506315
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 0050633A
      • __vbaStrCopy.MSVBVM60(?,00000000,?,?,00411816), ref: 0050635D
      • #520.MSVBVM60(?,00004008), ref: 0050638A
      • __vbaStrVarMove.MSVBVM60(?), ref: 00506394
      • __vbaStrMove.MSVBVM60 ref: 0050639F
      • __vbaFreeVar.MSVBVM60 ref: 005063A8
      • #619.MSVBVM60(?,00004008,00000001), ref: 005063D5
      • #608.MSVBVM60(?,00000022), ref: 005063E1
      • #617.MSVBVM60(?,00004008,00000001), ref: 0050640A
      • #608.MSVBVM60(?,00000022), ref: 00506419
      • __vbaVarCmpEq.MSVBVM60(?,?,?), ref: 0050642E
      • __vbaVarCmpEq.MSVBVM60(?,?,?,00000000), ref: 0050644A
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 00506458
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 0050645F
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 00506484
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,00000000,?,?,00411816), ref: 005064A7
      • #520.MSVBVM60(?,00004008), ref: 005064D4
      • __vbaStrVarMove.MSVBVM60(?), ref: 005064DE
      • __vbaStrMove.MSVBVM60 ref: 005064E9
      • __vbaFreeVar.MSVBVM60 ref: 005064F2
      • #608.MSVBVM60(?,00000009), ref: 00506518
      • __vbaInStrVar.MSVBVM60(?,00000000,?,00000008,00000001), ref: 00506545
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 00506553
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0050656A
      • #608.MSVBVM60(?,00000009,?,?,?,?,?,?,?,?,?,00000000,?,?,00411816), ref: 0050658B
      • __vbaStrVarVal.MSVBVM60(?,?,@@tab@@,00000001,000000FF,00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 005065A4
      • #712.MSVBVM60(?,00000000,?,?,?,?,?,?,?,?,?,00000000,?,?,00411816), ref: 005065AF
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,00000000,?,?,00411816), ref: 005065BA
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,?,00000000,?,?,00411816), ref: 005065C3
      • __vbaFreeVar.MSVBVM60(?,?,?,?,?,?,?,?,?,00000000,?,?,00411816), ref: 005065CC
      • __vbaInStr.MSVBVM60(00000000,0047C158,?,00000001,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 005065E6
      • #712.MSVBVM60(?,0047C158,@@vbcrlf@@,00000001,000000FF,00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 0050660B
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,00000000,?,?,00411816), ref: 00506616
      • #520.MSVBVM60(?,00004008), ref: 00506641
      • __vbaStrVarMove.MSVBVM60(?), ref: 0050664B
      • __vbaStrMove.MSVBVM60 ref: 00506656
      • __vbaFreeVar.MSVBVM60 ref: 0050665F
      • #520.MSVBVM60(?,00004008), ref: 0050668A
      • __vbaStrVarMove.MSVBVM60(?), ref: 00506694
      • __vbaStrMove.MSVBVM60 ref: 0050669F
      • __vbaFreeVar.MSVBVM60 ref: 005066A8
      • __vbaInStr.MSVBVM60(00000000,004866E4,?,00000001), ref: 005066C4
      • #518.MSVBVM60(?,00004008,?,00000001), ref: 005066F7
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001,?,?,?,?,?,?,?,00000001), ref: 00506738
      • __vbaVarTstEq.MSVBVM60(00008002,00000000,?,?,?,?,?,?,?,00000001), ref: 00506746
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,?,?,?,?,?,?,00000001), ref: 0050675D
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?,00411816), ref: 00506780
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,00000001), ref: 00506798
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001,0000000B,?,?,?,?,?,?,?,00000001), ref: 005067F8
      • __vbaVarCmpGt.MSVBVM60(?,00008002,00000000,?,?,?,?,?,?,?,00000001), ref: 0050680A
      • __vbaVarAnd.MSVBVM60(?,00000000,?,?,?,?,?,?,?,00000001), ref: 00506818
      • __vbaBoolVarNull.MSVBVM60(00000000,?,?,?,?,?,?,?,00000001), ref: 0050681F
      • __vbaFreeVarList.MSVBVM60(00000002,?,0000000B,?,?,?,?,?,?,?,00000001), ref: 00506839
      • __vbaStrVarCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506858
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?,00411816), ref: 00506863
      • #525.MSVBVM60(00000800,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506875
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?,00411816), ref: 00506880
      • __vbaLenBstr.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506891
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 005068AC
      • __vbaStrToAnsi.MSVBVM60(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 005068CB
      • __vbaStrToAnsi.MSVBVM60(?,?,?,00000000), ref: 005068DE
      • __vbaStrToAnsi.MSVBVM60(?,?,00000000), ref: 005068ED
      • __vbaStrToAnsi.MSVBVM60(?,?,00000000), ref: 005068FC
      • __vbaStrToAnsi.MSVBVM60(?,?,00000000), ref: 0050690D
      • __vbaSetSystemError.MSVBVM60(00000000,?,00000000), ref: 0050691F
      • __vbaStrToUnicode.MSVBVM60(?,?,?,00000000), ref: 0050692D
      • __vbaStrToUnicode.MSVBVM60(?,?,?,00000000), ref: 0050693B
      • __vbaStrToUnicode.MSVBVM60(?,?,?,00000000), ref: 00506949
      • __vbaStrToUnicode.MSVBVM60(?,?,?,00000000), ref: 00506957
      • __vbaStrToUnicode.MSVBVM60(0040AF78,?,?,00000000), ref: 00506965
      • __vbaFreeStrList.MSVBVM60(00000005,?,?,?,?,?,?,00000000), ref: 0050698A
      • #616.MSVBVM60(?,00000000), ref: 005069B3
      • __vbaStrMove.MSVBVM60 ref: 005069BE
      • #617.MSVBVM60(?,00000008,00000001), ref: 005069EE
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00506A13
      • __vbaFreeStr.MSVBVM60 ref: 00506A23
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00506A33
      • #616.MSVBVM60(?,00000000), ref: 00506A56
      • __vbaStrMove.MSVBVM60 ref: 00506A61
      • #616.MSVBVM60(?,00000000), ref: 00506A78
      • #520.MSVBVM60(00000008,00000008), ref: 00506A90
      • __vbaStrVarMove.MSVBVM60(?), ref: 00506A9A
      • __vbaStrMove.MSVBVM60 ref: 00506AA5
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00506AB5
      • __vbaStrCopy.MSVBVM60 ref: 00506ACF
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506AE6
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00506AFC
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506B17
      • __vbaInStr.MSVBVM60(00000000,@@vbcrlf@@,?,00000001), ref: 00506B31
      • #712.MSVBVM60(?,@@vbcrlf@@,0047C158,00000001,000000FF,00000000), ref: 00506B56
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506B61
      • __vbaInStr.MSVBVM60(00000000,@@tab@@,?,00000001), ref: 00506B7B
      • #608.MSVBVM60(?,00000009,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00506B92
      • __vbaStrVarVal.MSVBVM60(?,?,00000001,000000FF,00000000), ref: 00506BA6
      • #712.MSVBVM60(?,@@tab@@,00000000), ref: 00506BB6
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506BC1
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506BCA
      • __vbaFreeVar.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506BD3
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506BE6
      • #685.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506C03
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00506C0E
      • __vbaFreeObj.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506C2F
      • __vbaFreeVar.MSVBVM60(00506CD3,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00506CB1
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506CBA
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 00506CC3
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$CopyList$#608$#520AnsiUnicode$#712$#616#617BoolNull$#619Error$#518#525#685BstrChkstkSystem
      • String ID: .ini$8$@@tab@@$@@vbcrlf@@$\vos\
      • API String ID: 2289446423-692020445
      • Opcode ID: e6339e9e0a6bd0ae2461222e536a9c8628c8d1339660b8d63db6603d21d46588
      • Instruction ID: 57df3c725ae645480cfa056dc30c1f447576bb434099fc8a57575f8490cccaa2
      • Opcode Fuzzy Hash: e6339e9e0a6bd0ae2461222e536a9c8628c8d1339660b8d63db6603d21d46588
      • Instruction Fuzzy Hash: 85621AB5900218EFDB14DFA0DD88BEEBBB8BB48701F10859DE606B71A0DB745A49CF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3046 530720-5308a7 __vbaChkstk __vbaOnError #518 #520 #518 #520 __vbaVarCmpEq * 2 __vbaVarOr __vbaBoolVarNull __vbaFreeVarList 3047 530952-530a87 __vbaStrCopy call 51c3a0 __vbaStrMove __vbaStrCopy * 3 call 506210 #520 #518 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList __vbaStrCmp * 3 3046->3047 3048 5308ad-53092f #518 #520 __vbaVarTstEq __vbaFreeVarList 3046->3048 3059 530ac2-530b41 call 51c3a0 #645 __vbaStrMove __vbaStrCmp * 2 __vbaFreeStr __vbaFreeVar 3047->3059 3060 530a89-530abc __vbaStrCopy * 2 3047->3060 3050 530931-53093e 3048->3050 3051 530940-530947 3048->3051 3053 53094d 3050->3053 3051->3053 3055 531360-53136c 3053->3055 3057 531387-531398 __vbaStrCopy 3055->3057 3058 53136e-531385 __vbaStrCopy 3055->3058 3061 53139e-531469 #685 __vbaObjSet __vbaFreeObj __vbaFreeStr * 3 __vbaAryDestruct __vbaFreeStr 3057->3061 3058->3061 3059->3055 3065 530b47-530b8d #685 __vbaObjSet 3059->3065 3060->3059 3068 530bb2 3065->3068 3069 530b8f-530bb0 __vbaHresultCheckObj 3065->3069 3070 530bbc-530be3 __vbaFreeObj 3068->3070 3069->3070 3070->3055 3071 530be9-530c86 call 51c3a0 __vbaStrMove __vbaStrCopy call 50d570 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStrList __vbaFreeVarList __vbaStrCmp 3070->3071 3071->3055 3076 530c8c-530ca8 __vbaInStr 3071->3076 3077 531353-53135a 3076->3077 3078 530cae-530d5e #685 __vbaObjSet __vbaFreeObj #608 #711 __vbaAryVar __vbaAryCopy __vbaFreeVarList __vbaUbound 3076->3078 3077->3055 3080 531351 3078->3080 3081 530d64-530daa #685 __vbaObjSet 3078->3081 3080->3055 3083 530dcf 3081->3083 3084 530dac-530dcd __vbaHresultCheckObj 3081->3084 3085 530dd9-530e00 __vbaFreeObj 3083->3085 3084->3085 3085->3080 3086 530e06-530e62 __vbaUbound __vbaLbound 3085->3086 3086->3080 3088 530e68-530ed6 __vbaStrCopy * 2 #685 __vbaObjSet __vbaFreeObj 3086->3088 3090 530f27-530f2d __vbaGenerateBoundsError 3088->3090 3091 530ed8-530edf 3088->3091 3093 530f33-530f54 __vbaInStr 3090->3093 3091->3090 3092 530ee1-530efc 3091->3092 3094 530f0a-530f10 __vbaGenerateBoundsError 3092->3094 3095 530efe-530f08 3092->3095 3096 531311-53131e 3093->3096 3097 530f5a-530fa0 #685 __vbaObjSet 3093->3097 3100 530f16-530f25 3094->3100 3095->3100 3098 531324-531332 3096->3098 3099 53147f-531485 __vbaErrorOverflow 3096->3099 3106 530fa2-530fc3 __vbaHresultCheckObj 3097->3106 3107 530fc5 3097->3107 3101 531336-531341 3098->3101 3102 531334 3098->3102 3100->3093 3104 531343 3101->3104 3105 531345 3101->3105 3102->3080 3104->3080 3105->3080 3108 530fcf-530ff6 __vbaFreeObj 3106->3108 3107->3108 3108->3096 3109 530ffc-53103e __vbaVarDup 3108->3109 3110 531040-531047 3109->3110 3111 53108f-531095 __vbaGenerateBoundsError 3109->3111 3110->3111 3112 531049-531064 3110->3112 3113 53109b-531170 #711 __vbaChkstk __vbaVarIndexLoad __vbaStrVarMove __vbaStrMove __vbaFreeVarList __vbaVarDup 3111->3113 3114 531072-531078 __vbaGenerateBoundsError 3112->3114 3115 531066-531070 3112->3115 3116 531172-531179 3113->3116 3117 5311c1-5311c7 __vbaGenerateBoundsError 3113->3117 3118 53107e-53108d 3114->3118 3115->3118 3116->3117 3119 53117b-531196 3116->3119 3120 5311cd-531295 #711 __vbaChkstk __vbaVarIndexLoad __vbaStrVarMove __vbaStrMove __vbaFreeVarList __vbaStrCmp * 2 3117->3120 3118->3113 3121 5311a4-5311aa __vbaGenerateBoundsError 3119->3121 3122 531198-5311a2 3119->3122 3120->3096 3123 531297-531300 #520 __vbaVarTstEq __vbaFreeVar 3120->3123 3124 5311b0-5311bf 3121->3124 3122->3124 3123->3096 3125 531302-53130f 3123->3125 3124->3120 3125->3080
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 0053073E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 0053076E
      • #518.MSVBVM60(?,00004008), ref: 005307B5
      • #520.MSVBVM60(?,?), ref: 005307C3
      • #518.MSVBVM60(?,00004008), ref: 005307FF
      • #520.MSVBVM60(?,?), ref: 00530813
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?), ref: 0053083F
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?,00000000), ref: 0053085B
      • __vbaVarOr.MSVBVM60(?,00000000), ref: 00530869
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 00530870
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 00530895
      • #518.MSVBVM60(?,00004008), ref: 005308D3
      • #520.MSVBVM60(?,?), ref: 005308E1
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00530906
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0053091D
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00530961
      • __vbaStrMove.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00530978
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00530986
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00530994
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 005309A2
      • #520.MSVBVM60(?,00000008), ref: 005309CF
      • #518.MSVBVM60(?,?), ref: 005309E0
      • __vbaStrVarMove.MSVBVM60(?), ref: 005309ED
      • __vbaStrMove.MSVBVM60 ref: 005309F8
      • __vbaFreeStrList.MSVBVM60(00000004,?,?,?,?), ref: 00530A10
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?,?,?,?,?,?,?,00000000,?,00000000,00411816), ref: 00530A2A
      • __vbaStrCmp.MSVBVM60(004740DC,00000000,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,00411816), ref: 00530A43
      • __vbaStrCmp.MSVBVM60(true,00000000,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,00411816), ref: 00530A5A
      • __vbaStrCmp.MSVBVM60(wahr,00000000,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,00411816), ref: 00530A77
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,00411816), ref: 00530A98
      • __vbaStrCopy.MSVBVM60 ref: 00530ABC
        • Part of subcall function 0051C3A0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00530973,?,00000000,?,00000000,00411816), ref: 0051C3BE
        • Part of subcall function 0051C3A0: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 0051C3EE
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,00773364,?,00000000,?,00000000,00411816), ref: 0051C406
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051C420
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE34
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051CE3F
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE60
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(0051CED1,?,?,?,?,00000000,00411816), ref: 0051CEB8
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CEC1
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CECA
      • #645.MSVBVM60(00000008,00000000), ref: 00530ADE
      • __vbaStrMove.MSVBVM60 ref: 00530AE9
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00530AF5
      • __vbaStrCmp.MSVBVM60(004740DC,00000000), ref: 00530B0E
      • __vbaFreeStr.MSVBVM60 ref: 00530B29
      • __vbaFreeVar.MSVBVM60 ref: 00530B32
      • #685.MSVBVM60 ref: 00530B4E
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00530B59
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00530BA4
      • __vbaFreeObj.MSVBVM60 ref: 00530BD4
      • __vbaStrMove.MSVBVM60 ref: 00530BFA
      • __vbaStrCopy.MSVBVM60 ref: 00530C08
      • #520.MSVBVM60(?,00000008,?,?), ref: 00530C2D
      • __vbaStrVarMove.MSVBVM60(?), ref: 00530C37
      • __vbaStrMove.MSVBVM60 ref: 00530C42
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 00530C52
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00530C65
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 00530C7E
      • __vbaInStr.MSVBVM60(00000000,004740DC,?,00000001), ref: 00530CA0
      • #685.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00530CB5
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00530CC0
      • __vbaFreeObj.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00530CE1
      • #608.MSVBVM60(?,00000000), ref: 00530CF4
      • #711.MSVBVM60(?,?,?,000000FF,00000000), ref: 00530D0A
      • __vbaAryVar.MSVBVM60(00002008,?), ref: 00530D19
      • __vbaAryCopy.MSVBVM60(?,?), ref: 00530D30
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 00530D40
      • __vbaUbound.MSVBVM60(00000001,?), ref: 00530D56
      • #685.MSVBVM60 ref: 00530D6B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00530D76
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00530DC1
      • __vbaFreeObj.MSVBVM60 ref: 00530DF1
      • __vbaUbound.MSVBVM60(00000001,?), ref: 00530E20
      • __vbaLbound.MSVBVM60(00000001,?), ref: 00530E3C
      • __vbaStrCopy.MSVBVM60 ref: 00530E77
      • __vbaStrCopy.MSVBVM60 ref: 00530E8C
      • #685.MSVBVM60 ref: 00530E99
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00530EA4
      • __vbaFreeObj.MSVBVM60 ref: 00530EC5
      • __vbaInStr.MSVBVM60(00000000,0047B29C,00000000,00000001), ref: 00530F4C
      • #685.MSVBVM60 ref: 00530F61
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00530F6C
      • __vbaStrCopy.MSVBVM60 ref: 0053137F
      • __vbaStrCopy.MSVBVM60 ref: 00531398
      • #685.MSVBVM60 ref: 005313A5
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 005313B0
      • __vbaFreeObj.MSVBVM60 ref: 005313D1
      • __vbaFreeStr.MSVBVM60(0053146A), ref: 0053143C
      • __vbaFreeStr.MSVBVM60 ref: 00531445
      • __vbaFreeStr.MSVBVM60 ref: 0053144E
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 0053145A
      • __vbaFreeStr.MSVBVM60 ref: 00531463
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Copy$#685ListMove$#520$#518$CheckChkstkErrorHresultUbound$#608#645#711BoolDestructLboundNull
      • String ID: C$DisableKerberos$Generic$Kerberos$d$d$false$true$wahr
      • API String ID: 1763576159-3137797705
      • Opcode ID: 52030bb9977dd941f3a13e3a88f33a979aaf03ae8b5a29fc43eeddff16f063ba
      • Instruction ID: bbee9b466fd957961ff4d7ab2087b4f87df83c884bf0bf364d3d54db21c2fca0
      • Opcode Fuzzy Hash: 52030bb9977dd941f3a13e3a88f33a979aaf03ae8b5a29fc43eeddff16f063ba
      • Instruction Fuzzy Hash: 3182F875900218DFDB14DFA0DE48BDDBBB4BF48305F1085A9E60ABB2A0DB745A89CF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3126 4abd10-4abd77 __vbaChkstk __vbaOnError 3127 4abd79-4abd88 call 531fd0 3126->3127 3128 4abd8f-4abda1 3126->3128 3127->3128 3130 4abde3-4abe73 __vbaStrCopy call 53b510 __vbaAryRecMove #685 __vbaObjSet __vbaFreeObj 3128->3130 3131 4abda3-4abdde call 535b60 call 4d0d30 * 2 3128->3131 3141 4abeb1-4abeb7 __vbaGenerateBoundsError 3130->3141 3142 4abe75-4abe7c 3130->3142 3150 4ac019-4ac085 #685 __vbaObjSet __vbaFreeObj __vbaAryDestruct * 2 3131->3150 3144 4abeba-4abed4 __vbaStrCmp 3141->3144 3142->3141 3143 4abe7e-4abe92 3142->3143 3146 4abe9d-4abea3 __vbaGenerateBoundsError 3143->3146 3147 4abe94-4abe9b 3143->3147 3148 4abeda-4abf0e #685 __vbaObjSet 3144->3148 3149 4ac00b-4ac012 3144->3149 3151 4abea6-4abeaf 3146->3151 3147->3151 3154 4abf2a 3148->3154 3155 4abf10-4abf28 __vbaHresultCheckObj 3148->3155 3149->3150 3151->3144 3157 4abf31-4abf4f __vbaFreeObj 3154->3157 3155->3157 3158 4abffb-4ac002 3157->3158 3159 4abf55-4abf6b __vbaUbound 3157->3159 3160 4ac009 3158->3160 3161 4ac0a3-4ac14d __vbaErrorOverflow __vbaChkstk __vbaOnError __vbaStrCopy __vbaStrCmp 3159->3161 3162 4abf71-4abfa8 #685 __vbaObjSet 3159->3162 3160->3150 3167 4ac14f-4ac170 __vbaStrCopy call 4fa530 __vbaFreeStr 3161->3167 3168 4ac176-4ac1e0 #685 __vbaObjSet __vbaFreeObj __vbaStrCmp call 4cc360 3161->3168 3165 4abfaa-4abfc2 __vbaHresultCheckObj 3162->3165 3166 4abfc4 3162->3166 3170 4abfcb-4abfe9 __vbaFreeObj 3165->3170 3166->3170 3167->3168 3177 4ac8bf-4ac8da __vbaStrCmp 3168->3177 3178 4ac1e6-4ac22c #685 __vbaObjSet 3168->3178 3172 4abfeb-4abff2 3170->3172 3173 4abff9 3170->3173 3172->3173 3173->3160 3179 4ac8dc-4ac8f5 __vbaStrCopy call 4fa530 3177->3179 3180 4ac903-4ac99d __vbaStrCopy #685 __vbaObjSet __vbaFreeObj __vbaFreeStr 3177->3180 3184 4ac22e-4ac24f __vbaHresultCheckObj 3178->3184 3185 4ac251 3178->3185 3186 4ac8fa-4ac8fd __vbaFreeStr 3179->3186 3188 4ac25b-4ac282 __vbaFreeObj 3184->3188 3185->3188 3186->3180 3188->3177 3189 4ac288-4ac39f call 51d000 #518 call 5138b0 __vbaInStrVar __vbaVarCmpEq __vbaVarAnd * 2 __vbaBoolVarNull __vbaFreeVarList 3188->3189 3189->3177 3194 4ac3a5-4ac3ef __vbaObjSet 3189->3194 3197 4ac3f1-4ac412 __vbaHresultCheckObj 3194->3197 3198 4ac414 3194->3198 3199 4ac41e-4ac44c __vbaFreeObj 3197->3199 3198->3199 3199->3177 3201 4ac452-4ac46d __vbaStrCmp 3199->3201 3202 4ac46f-4ac490 __vbaStrCopy call 4fa530 __vbaFreeStr 3201->3202 3203 4ac496-4ac4cc call 519660 __vbaStrI4 __vbaStrMove __vbaStrCmp 3201->3203 3202->3203 3208 4ac4ce-4ac4dd __vbaStrCopy 3203->3208 3209 4ac4e3-4ac585 #685 __vbaObjSet __vbaFreeObj __vbaI4Str __vbaStrI4 __vbaStrMove #685 __vbaObjSet 3203->3209 3208->3209 3212 4ac5aa 3209->3212 3213 4ac587-4ac5a8 __vbaHresultCheckObj 3209->3213 3214 4ac5b4-4ac5db __vbaFreeObj 3212->3214 3213->3214 3215 4ac5dd-4ac5ec __vbaStrCopy 3214->3215 3216 4ac5f2-4ac63f #685 __vbaObjSet __vbaFreeObj __vbaI4Str 3214->3216 3215->3216 3216->3177 3218 4ac645-4ac68b #685 __vbaObjSet 3216->3218 3220 4ac68d-4ac6ae __vbaHresultCheckObj 3218->3220 3221 4ac6b0 3218->3221 3222 4ac6ba-4ac6e1 __vbaFreeObj 3220->3222 3221->3222 3222->3177 3223 4ac6e7-4ac702 __vbaStrCmp 3222->3223 3224 4ac72b-4ac76c __vbaStrCmp __vbaInStr 3223->3224 3225 4ac704-4ac725 __vbaStrCopy call 4fa530 __vbaFreeStr 3223->3225 3227 4ac76e-4ac787 __vbaStrCopy call 4cd790 3224->3227 3228 4ac7a2-4ac7e4 __vbaStrCmp __vbaInStr 3224->3228 3225->3224 3235 4ac78c-4ac79c __vbaStrMove __vbaFreeStr 3227->3235 3231 4ac81a-4ac821 call 4cf630 3228->3231 3232 4ac7e6-4ac7ff __vbaStrCopy call 4cd790 3228->3232 3237 4ac826-4ac887 __vbaStrCopy __vbaObjSet 3231->3237 3236 4ac804-4ac814 __vbaStrMove __vbaFreeStr 3232->3236 3235->3228 3236->3231 3240 4ac889-4ac8aa __vbaHresultCheckObj 3237->3240 3241 4ac8ac 3237->3241 3242 4ac8b6-4ac8b9 __vbaFreeObj 3240->3242 3241->3242 3242->3177
      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004ABD2E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004ABD5E
      • __vbaStrCopy.MSVBVM60 ref: 004ABDF4
      • __vbaAryRecMove.MSVBVM60(004741C8,?,?), ref: 004ABE16
      • #685.MSVBVM60 ref: 004ABE3F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004ABE4A
      • __vbaFreeObj.MSVBVM60 ref: 004ABE62
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004ABE9D
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004ABEB1
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004ABECC
      • #685.MSVBVM60 ref: 004ABEE1
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004ABEEC
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004ABF1F
      • __vbaFreeObj.MSVBVM60 ref: 004ABF43
      • __vbaUbound.MSVBVM60(00000001,00000000), ref: 004ABF62
      • #685.MSVBVM60 ref: 004ABF7B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004ABF86
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004ABFB9
      • __vbaFreeObj.MSVBVM60 ref: 004ABFDD
      • #685.MSVBVM60 ref: 004AC02D
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004AC038
      • __vbaFreeObj.MSVBVM60 ref: 004AC050
      • __vbaAryDestruct.MSVBVM60(004741C8,?,004AC086), ref: 004AC070
      • __vbaAryDestruct.MSVBVM60(004741C8,00000000), ref: 004AC07F
        • Part of subcall function 00531FD0: __vbaChkstk.MSVBVM60(00000000,00411816,004CB93C,?,00000001,?,00000000,00411816), ref: 00531FEE
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053201E
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053202D
        • Part of subcall function 00531FD0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,004CB93C), ref: 0053203C
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 0053206B
        • Part of subcall function 00531FD0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532093
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 005320A6
        • Part of subcall function 00531FD0: __vbaStrCopy.MSVBVM60 ref: 005320CA
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00000008,?), ref: 005320F7
        • Part of subcall function 00531FD0: __vbaStrVarMove.MSVBVM60(?), ref: 00532104
        • Part of subcall function 00531FD0: __vbaStrMove.MSVBVM60 ref: 00532111
        • Part of subcall function 00531FD0: __vbaFreeStr.MSVBVM60 ref: 0053211A
        • Part of subcall function 00531FD0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532130
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 00532162
        • Part of subcall function 00531FD0: __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0053218A
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 0053219D
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685Error$#520Move$BoundsCheckChkstkConstructCopyDestructFixstrGenerateHresult$ListUbound
      • String ID: 2$@@LIGHTLOGIN@@$CardMonitor.log$Do Action if no license$Entering LightTimer$Leaving LightTimer$MonitorI2C$MonitorKerberos$No License$false$http://www.aloaha.com/shop-en/aloaha-smart-login.php$system$true
      • API String ID: 2711117452-2474159113
      • Opcode ID: 15bf1acabe08494757112df98fd75d29658c54f6b85c878a0e1a1e4a18e31c9b
      • Instruction ID: 1e5812541a77607f3e7246cc6a51f9f6836a12feb8b85faa6f964d097e51f32f
      • Opcode Fuzzy Hash: 15bf1acabe08494757112df98fd75d29658c54f6b85c878a0e1a1e4a18e31c9b
      • Instruction Fuzzy Hash: B8723D75900218EFDB14DFA4D948BDEBBB4FF48305F10819AE506B72A0DB789A85CF64
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3243 51c3a0-51c40e __vbaChkstk __vbaOnError __vbaStrCmp 3244 51c410-51c426 __vbaStrCopy 3243->3244 3245 51c42b-51c54a __vbaStrCopy call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList __vbaStrCopy call 4ecd60 #520 __vbaStrVarMove __vbaStrMove __vbaFreeStr __vbaFreeVarList #685 __vbaObjSet __vbaFreeObj __vbaStrCmp 3243->3245 3246 51ce2d-51ced0 #685 __vbaObjSet __vbaFreeObj __vbaFreeStr * 3 3244->3246 3254 51c550-51c5b1 #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 3245->3254 3255 51c685-51c694 __vbaStrCopy 3245->3255 3256 51c5b7-51c5fd #685 __vbaObjSet 3254->3256 3257 51c66e-51c67d __vbaStrCopy 3254->3257 3258 51c69a-51c724 #685 __vbaObjSet __vbaFreeObj #685 __vbaObjSet __vbaFreeObj __vbaStrCmp 3255->3258 3262 51c622 3256->3262 3263 51c5ff-51c620 __vbaHresultCheckObj 3256->3263 3259 51c683 3257->3259 3266 51c72a-51c78b #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 3258->3266 3267 51c85f-51c86e __vbaStrCopy 3258->3267 3259->3258 3265 51c62c-51c653 __vbaFreeObj 3262->3265 3263->3265 3268 51c655 3265->3268 3269 51c657-51c666 __vbaStrCopy 3265->3269 3270 51c791-51c7d7 #685 __vbaObjSet 3266->3270 3271 51c848-51c857 __vbaStrCopy 3266->3271 3273 51c874-51c8c5 #685 __vbaObjSet __vbaFreeObj __vbaStrCmp 3267->3273 3272 51c66c 3268->3272 3269->3272 3279 51c7d9-51c7fa __vbaHresultCheckObj 3270->3279 3280 51c7fc 3270->3280 3274 51c85d 3271->3274 3272->3259 3277 51c9a3-51c9f4 #685 __vbaObjSet __vbaFreeObj __vbaStrCmp 3273->3277 3278 51c8cb-51c8e3 __vbaStrCmp 3273->3278 3274->3273 3288 51cdc1-51cdce __vbaStrCopy 3277->3288 3289 51c9fa-51ca3e __vbaStrCopy call 501700 __vbaStrMove __vbaStrCmp 3277->3289 3278->3277 3281 51c8e9-51c98d #520 #518 #520 #518 __vbaVarTstNe __vbaFreeVarList 3278->3281 3282 51c806-51c82d __vbaFreeObj 3279->3282 3280->3282 3281->3277 3283 51c98f-51c99e call 4c1250 3281->3283 3285 51c831-51c840 __vbaStrCopy 3282->3285 3286 51c82f 3282->3286 3283->3277 3290 51c846 3285->3290 3286->3290 3292 51cdd4-51cdec __vbaStrCmp 3288->3292 3296 51cb61-51cb79 __vbaStrCmp 3289->3296 3297 51ca44-51ca52 3289->3297 3290->3274 3294 51ce18-51ce27 __vbaStrCopy 3292->3294 3295 51cdee-51ce16 __vbaStrCopy * 2 3292->3295 3294->3246 3295->3246 3298 51cdbf 3296->3298 3299 51cb7f-51cbea #619 __vbaVarTstNe __vbaFreeVar 3296->3299 3300 51ca70 3297->3300 3301 51ca54-51ca6e __vbaNew2 3297->3301 3298->3292 3302 51cc1b-51ccd6 __vbaStrCat __vbaStrMove #685 __vbaObjSet __vbaFreeObj #645 __vbaStrMove __vbaStrCmp __vbaFreeStr 3299->3302 3303 51cbec-51cc15 __vbaStrCmp __vbaStrBool __vbaStrMove 3299->3303 3304 51ca7a-51caad 3300->3304 3301->3304 3302->3298 3309 51ccdc-51cd22 #685 __vbaObjSet 3302->3309 3303->3302 3307 51cad2 3304->3307 3308 51caaf-51cad0 __vbaHresultCheckObj 3304->3308 3310 51cadc-51cb0a 3307->3310 3308->3310 3312 51cd24-51cd45 __vbaHresultCheckObj 3309->3312 3313 51cd47 3309->3313 3316 51cb0c-51cb2d __vbaHresultCheckObj 3310->3316 3317 51cb2f 3310->3317 3315 51cd51-51cd78 __vbaFreeObj 3312->3315 3313->3315 3315->3298 3318 51cd7a-51cd92 __vbaStrCmp 3315->3318 3319 51cb39-51cb5b __vbaStrMove __vbaFreeObj 3316->3319 3317->3319 3318->3298 3320 51cd94-51cdb9 __vbaStrCopy call 4efae0 __vbaFreeStr 3318->3320 3319->3296 3320->3298
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00530973,?,00000000,?,00000000,00411816), ref: 0051C3BE
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 0051C3EE
      • __vbaStrCmp.MSVBVM60(00473D9C,00773364,?,00000000,?,00000000,00411816), ref: 0051C406
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051C420
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051C43A
      • #520.MSVBVM60(?,00000008), ref: 0051C45B
      • __vbaStrVarMove.MSVBVM60(?), ref: 0051C465
      • __vbaStrMove.MSVBVM60 ref: 0051C470
      • __vbaFreeStr.MSVBVM60 ref: 0051C479
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 0051C489
      • __vbaStrCopy.MSVBVM60(?,00000000,00411816), ref: 0051C4A1
      • #520.MSVBVM60(?,00000008), ref: 0051C4C2
      • __vbaStrVarMove.MSVBVM60(?), ref: 0051C4CC
      • __vbaStrMove.MSVBVM60 ref: 0051C4D7
      • __vbaFreeStr.MSVBVM60 ref: 0051C4E0
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 0051C4F0
      • #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C500
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051C50B
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C52C
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00000000,00411816), ref: 0051C542
      • #645.MSVBVM60(00004008,00000000), ref: 0051C573
      • __vbaStrMove.MSVBVM60 ref: 0051C57E
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0051C58A
      • __vbaFreeStr.MSVBVM60 ref: 0051C5A2
      • #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE34
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051CE3F
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE60
      • __vbaFreeStr.MSVBVM60(0051CED1,?,?,?,?,00000000,00411816), ref: 0051CEB8
      • __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CEC1
      • __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CECA
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$Copy$#520#685List$#645ChkstkError
      • String ID: (T$HKLM\Software\Aloaha\CSP\MasterUserPassIni$HKLM\Software\Aloaha\CSP\UserPassIni$J$UserPass.ini$d3w
      • API String ID: 3178620943-504289576
      • Opcode ID: 2c8d53685e3d8852a9695350982d8cc644bfc7455ce966deaa9f51a9821c8105
      • Instruction ID: da3f37fccf87a46a9599642f315e91d1b0f9fb416be4b4b3b62a06e5f522cec0
      • Opcode Fuzzy Hash: 2c8d53685e3d8852a9695350982d8cc644bfc7455ce966deaa9f51a9821c8105
      • Instruction Fuzzy Hash: 5B623C75900218EFDB14DFA0DA48BDEBBB5FF48305F1081A9E50AB7260DB749A89CF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3323 518b80-518c68 __vbaChkstk __vbaOnError #685 __vbaObjSet __vbaFreeObj __vbaLateMemCallLd __vbaVarTstGt __vbaFreeVar 3325 518d16-518d23 3323->3325 3326 518c6e-518ca8 #685 __vbaObjSet 3323->3326 3327 518d29-518d9c #685 __vbaObjSet __vbaFreeObj __vbaStrCopy * 2 call 523470 3325->3327 3328 518eac-518eb9 3325->3328 3332 518cca 3326->3332 3333 518caa-518cc8 __vbaHresultCheckObj 3326->3333 3344 518da1-518e0d __vbaObjSet __vbaFreeStrList __vbaLateMemCallLd __vbaVarTstGt __vbaFreeVar 3327->3344 3330 51942f-51943c 3328->3330 3331 518ebf-518f27 #685 __vbaObjSet __vbaFreeObj call 50dfc0 __vbaStrMove __vbaStrCmp 3328->3331 3335 519442-5194b5 #685 __vbaObjSet __vbaFreeObj __vbaStrCopy * 2 call 523470 3330->3335 3336 5195c6-51963f #685 __vbaObjSet __vbaFreeObj __vbaFreeStr 3330->3336 3331->3330 3351 518f2d-518f80 #619 __vbaVarTstNe __vbaFreeVar 3331->3351 3337 518cd4-518cf8 __vbaFreeObj 3332->3337 3333->3337 3350 5194ba-519527 __vbaObjSet __vbaFreeStrList __vbaLateMemCallLd __vbaVarTstGt __vbaFreeVar 3335->3350 3340 518d09-518d10 3337->3340 3341 518cfa-518d07 3337->3341 3340->3325 3341->3325 3344->3328 3348 518e13-518e4d #685 __vbaObjSet 3344->3348 3356 518e6f 3348->3356 3357 518e4f-518e6d __vbaHresultCheckObj 3348->3357 3350->3336 3352 51952d-519567 #685 __vbaObjSet 3350->3352 3353 518fa3-519043 #685 __vbaObjSet __vbaFreeObj __vbaStrCat #645 __vbaStrMove __vbaStrCmp __vbaFreeStr __vbaFreeVar 3351->3353 3354 518f82-518f9d __vbaStrCat __vbaStrMove 3351->3354 3362 519589 3352->3362 3363 519569-519587 __vbaHresultCheckObj 3352->3363 3364 519049-519083 #685 __vbaObjSet 3353->3364 3365 51919b-51925c #685 __vbaObjSet __vbaFreeObj __vbaStrCat __vbaStrMove __vbaStrCat #645 __vbaStrMove __vbaStrCmp __vbaFreeStrList __vbaFreeVar 3353->3365 3354->3353 3358 518e79-518e9d __vbaFreeObj 3356->3358 3357->3358 3358->3328 3361 518e9f-518ea6 3358->3361 3361->3328 3366 519593-5195b7 __vbaFreeObj 3362->3366 3363->3366 3370 5190a5 3364->3370 3371 519085-5190a3 __vbaHresultCheckObj 3364->3371 3372 519262-51929c #685 __vbaObjSet 3365->3372 3373 5193f6-519429 #685 __vbaObjSet __vbaFreeObj 3365->3373 3366->3336 3368 5195b9-5195c0 3366->3368 3368->3336 3374 5190af-5190d3 __vbaFreeObj 3370->3374 3371->3374 3378 5192be 3372->3378 3379 51929e-5192bc __vbaHresultCheckObj 3372->3379 3373->3330 3374->3365 3375 5190d9-519195 __vbaChkstk __vbaStrCat __vbaStrMove call 50d740 __vbaFreeStr __vbaChkstk __vbaStrCat __vbaStrMove call 50d740 __vbaFreeStr 3374->3375 3375->3365 3381 5192c8-5192ec __vbaFreeObj 3378->3381 3379->3381 3381->3373 3383 5192f2-5193f3 __vbaChkstk __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove call 50d740 __vbaFreeStrList __vbaChkstk __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove call 50d740 __vbaFreeStrList 3381->3383 3383->3373
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,00000000,00411816), ref: 00518B9E
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816), ref: 00518BCE
      • #685.MSVBVM60 ref: 00518BE8
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00518BF3
      • __vbaFreeObj.MSVBVM60 ref: 00518C14
      • __vbaLateMemCallLd.MSVBVM60(?,00000000,info,00000000), ref: 00518C41
      • __vbaVarTstGt.MSVBVM60(?,00000000), ref: 00518C4F
      • __vbaFreeVar.MSVBVM60 ref: 00518C5C
      • #685.MSVBVM60 ref: 00518C75
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00518C80
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00518CBC
      • __vbaFreeObj.MSVBVM60 ref: 00518CE9
      • #685.MSVBVM60 ref: 00518D30
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00518D3B
      • __vbaFreeObj.MSVBVM60 ref: 00518D5C
      • __vbaStrCopy.MSVBVM60 ref: 00518D71
      • __vbaStrCopy.MSVBVM60 ref: 00518D7F
      • __vbaObjSet.MSVBVM60(0054D334,00000000,AloahaLic.Licensing,00000000,?,?), ref: 00518DA7
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 00518DB7
      • __vbaLateMemCallLd.MSVBVM60(?,00000000,info,00000000), ref: 00518DE6
      • __vbaVarTstGt.MSVBVM60(?,00000000), ref: 00518DF4
      • __vbaFreeVar.MSVBVM60 ref: 00518E01
      • #685.MSVBVM60 ref: 00518E1A
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00518E25
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00518E61
      • __vbaFreeObj.MSVBVM60 ref: 00518E8E
      • #685.MSVBVM60 ref: 00518EC6
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00518ED1
      • __vbaFreeObj.MSVBVM60 ref: 00518EF2
      • __vbaStrMove.MSVBVM60 ref: 00518F09
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 00518F1F
      • #619.MSVBVM60(?,00004008,00000001), ref: 00518F4B
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 00518F67
      • __vbaFreeVar.MSVBVM60 ref: 00518F74
      • __vbaStrCat.MSVBVM60(004775E8,?), ref: 00518F92
      • __vbaStrMove.MSVBVM60 ref: 00518F9D
      • #685.MSVBVM60 ref: 00518FAA
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00518FB5
      • __vbaFreeObj.MSVBVM60 ref: 00518FD6
      • __vbaStrCat.MSVBVM60(AloahaLic.dll,?), ref: 00518FEC
      • #645.MSVBVM60(00000008,00000000), ref: 00519002
      • __vbaStrMove.MSVBVM60 ref: 0051900D
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00519019
      • __vbaFreeStr.MSVBVM60 ref: 0051902E
      • __vbaFreeVar.MSVBVM60 ref: 00519037
      • #685.MSVBVM60 ref: 00519050
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0051905B
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00519097
      • __vbaFreeObj.MSVBVM60 ref: 005190C4
      • __vbaChkstk.MSVBVM60 ref: 005190F3
      • __vbaStrCat.MSVBVM60(alosecurcom.dll,?), ref: 0051911A
      • __vbaStrMove.MSVBVM60 ref: 00519125
      • __vbaFreeStr.MSVBVM60(00000000), ref: 00519134
      • __vbaChkstk.MSVBVM60 ref: 00519154
      • __vbaStrCat.MSVBVM60(AloahaLic.dll,?), ref: 0051917B
      • __vbaStrMove.MSVBVM60 ref: 00519186
      • __vbaFreeStr.MSVBVM60(00000000), ref: 00519195
      • #685.MSVBVM60 ref: 005191A2
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 005191AD
      • __vbaFreeObj.MSVBVM60 ref: 005191CE
      • __vbaStrCat.MSVBVM60(aloaha\,?), ref: 005191E4
      • __vbaStrMove.MSVBVM60 ref: 005191EF
      • __vbaStrCat.MSVBVM60(AloahaLic.dll,00000000), ref: 005191FB
      • #645.MSVBVM60(00000008,00000000), ref: 00519211
      • __vbaStrMove.MSVBVM60 ref: 0051921C
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00519228
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 00519244
      • __vbaFreeVar.MSVBVM60 ref: 00519250
      • #685.MSVBVM60 ref: 00519269
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00519274
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 005192B0
      • __vbaFreeObj.MSVBVM60 ref: 005192DD
      • __vbaChkstk.MSVBVM60 ref: 0051930C
      • __vbaStrCat.MSVBVM60(aloaha\,?), ref: 00519333
      • __vbaStrMove.MSVBVM60 ref: 0051933E
      • __vbaStrCat.MSVBVM60(alosecurcom.dll,00000000), ref: 0051934A
      • __vbaStrMove.MSVBVM60 ref: 00519355
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,00000000), ref: 0051936B
      • __vbaChkstk.MSVBVM60 ref: 0051938E
      • __vbaStrCat.MSVBVM60(aloaha\,?), ref: 005193B5
      • __vbaStrMove.MSVBVM60 ref: 005193C0
      • __vbaStrCat.MSVBVM60(AloahaLic.dll,00000000), ref: 005193CC
      • __vbaStrMove.MSVBVM60 ref: 005193D7
        • Part of subcall function 0050D740: __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0050D75E
        • Part of subcall function 0050D740: __vbaStrCopy.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0050D78B
        • Part of subcall function 0050D740: __vbaVarDup.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0050D797
        • Part of subcall function 0050D740: __vbaOnError.MSVBVM60(000000FF,?,00000001,00000000,00000000,00411816), ref: 0050D7A6
        • Part of subcall function 0050D740: __vbaStrCmp.MSVBVM60(true,00000000,?,00000001,00000000,00000000,00411816), ref: 0050D7BE
        • Part of subcall function 0050D740: #520.MSVBVM60(?,00004008), ref: 0050D7FB
        • Part of subcall function 0050D740: __vbaVarCmpNe.MSVBVM60(?,00008008,?,0000000B), ref: 0050D82B
        • Part of subcall function 0050D740: __vbaVarAnd.MSVBVM60(?,00000000), ref: 0050D839
        • Part of subcall function 0050D740: __vbaBoolVarNull.MSVBVM60(00000000), ref: 0050D840
        • Part of subcall function 0050D740: __vbaFreeVarList.MSVBVM60(00000002,?,0000000B), ref: 0050D85A
        • Part of subcall function 0050D740: __vbaStrCopy.MSVBVM60(00000000,00000000,00411816), ref: 0050D883
        • Part of subcall function 0050D740: #518.MSVBVM60(?,00004008), ref: 0050D8AE
        • Part of subcall function 0050D740: #619.MSVBVM60(?,?,00000004), ref: 0050D8BE
        • Part of subcall function 0050D740: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 0050D8E3
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,00000000), ref: 005193ED
      • #685.MSVBVM60 ref: 005193FD
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00519408
      • __vbaFreeObj.MSVBVM60 ref: 00519429
      • #685.MSVBVM60 ref: 00519449
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00519454
      • __vbaFreeObj.MSVBVM60 ref: 00519475
      • __vbaStrCopy.MSVBVM60 ref: 0051948A
      • __vbaStrCopy.MSVBVM60 ref: 00519498
        • Part of subcall function 00523380: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 0052348E
        • Part of subcall function 00523380: __vbaStrCopy.MSVBVM60(?,00000000,?,?,00411816), ref: 005234BB
        • Part of subcall function 00523380: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 005234CA
        • Part of subcall function 00523380: #518.MSVBVM60(?,00004008), ref: 00523515
        • Part of subcall function 00523380: __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 00523556
        • Part of subcall function 00523380: __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 00523564
        • Part of subcall function 00523380: __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0052357B
        • Part of subcall function 00523380: #518.MSVBVM60(?,00004008), ref: 005235D4
        • Part of subcall function 00523380: __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 00523615
        • Part of subcall function 00523380: __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 00523623
      • __vbaObjSet.MSVBVM60(0054D334,00000000,AloahaLic.Licensing,00000000,?,?), ref: 005194C0
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 005194D0
      • __vbaLateMemCallLd.MSVBVM60(?,00000000,info,00000000), ref: 00519500
      • __vbaVarTstGt.MSVBVM60(?,00000000), ref: 0051950E
      • __vbaFreeVar.MSVBVM60 ref: 0051951B
      • #685.MSVBVM60 ref: 00519534
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0051953F
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0051957B
      • __vbaFreeObj.MSVBVM60 ref: 005195A8
      • #685.MSVBVM60 ref: 005195CD
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 005195D8
      • __vbaFreeObj.MSVBVM60 ref: 005195F9
      • __vbaFreeStr.MSVBVM60(00519640), ref: 00519639
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685$Move$ChkstkCopyList$CheckHresult$#518CallErrorLate$#619#645$#520BoolNull
      • String ID: 6$AloahaLic.Licensing$AloahaLic.dll$aloaha\$alosecurcom.dll$info
      • API String ID: 151962266-3584654631
      • Opcode ID: 826cc7a79ce24b7554634e8dc2c8fab9c09f906f9dd95ec3701061265b258dff
      • Instruction ID: 5ba21848b0a5b777e4b3ee2ce72f5b73617dc6c4302841b0a0da0ad9a6f170ab
      • Opcode Fuzzy Hash: 826cc7a79ce24b7554634e8dc2c8fab9c09f906f9dd95ec3701061265b258dff
      • Instruction Fuzzy Hash: A4623675900208DFDB14DFA4DA88BEEBBB5FF48705F208169E506A72A0DB745A88CF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3390 4d4360-4d4454 __vbaChkstk __vbaOnError __vbaStrCopy call 4fa530 __vbaFreeStr __vbaStrToAnsi * 2 call 483ef0 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStrList 3396 4d472a-4d479d #685 __vbaObjSet __vbaFreeObj __vbaAryDestruct 3390->3396 3397 4d445a-4d44ae __vbaStrToAnsi call 483f24 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStr 3390->3397 3401 4d4714-4d4724 call 483e88 __vbaSetSystemError 3397->3401 3402 4d44b4-4d44fe __vbaRedim __vbaAryLock 3397->3402 3401->3396 3405 4d4500-4d4507 3402->3405 3406 4d4542-4d4548 __vbaGenerateBoundsError 3402->3406 3405->3406 3408 4d4509-4d451d 3405->3408 3409 4d454e-4d45a1 call 484028 __vbaSetSystemError __vbaAryUnlock 3406->3409 3410 4d451f-4d4529 3408->3410 3411 4d452b-4d4531 __vbaGenerateBoundsError 3408->3411 3415 4d47c8-4d488d __vbaErrorOverflow __vbaChkstk __vbaOnError __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStr __vbaStrCmp 3409->3415 3416 4d45a7-4d45d9 __vbaRedim __vbaAryLock 3409->3416 3413 4d4537-4d4540 3410->3413 3411->3413 3413->3409 3431 4d4dd7-4d4e4a #685 __vbaObjSet __vbaFreeObj __vbaAryDestruct 3415->3431 3432 4d4893-4d48c0 __vbaStrToAnsi * 2 call 483ef0 3415->3432 3417 4d461d-4d4623 __vbaGenerateBoundsError 3416->3417 3418 4d45db-4d45e2 3416->3418 3420 4d4629-4d4679 call 484028 __vbaSetSystemError __vbaAryUnlock __vbaAryLock 3417->3420 3418->3417 3419 4d45e4-4d45f8 3418->3419 3422 4d45fa-4d4604 3419->3422 3423 4d4606-4d460c __vbaGenerateBoundsError 3419->3423 3429 4d46bd-4d46c3 __vbaGenerateBoundsError 3420->3429 3430 4d467b-4d4682 3420->3430 3426 4d4612-4d461b 3422->3426 3423->3426 3426->3420 3435 4d46c9-4d470e call 474240 __vbaSetSystemError __vbaAryUnlock call 483e88 __vbaSetSystemError 3429->3435 3430->3429 3434 4d4684-4d4698 3430->3434 3436 4d48c5-4d4900 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStrList 3432->3436 3437 4d469a-4d46a4 3434->3437 3438 4d46a6-4d46ac __vbaGenerateBoundsError 3434->3438 3435->3401 3436->3431 3442 4d4906-4d495d __vbaStrToAnsi call 483f24 __vbaSetSystemError __vbaStrToUnicode __vbaFreeStr 3436->3442 3443 4d46b2-4d46bb 3437->3443 3438->3443 3449 4d4dc1-4d4dd1 call 483e88 __vbaSetSystemError 3442->3449 3450 4d4963-4d49d4 __vbaStrCopy call 4fa530 __vbaFreeStr __vbaRedim __vbaAryLock 3442->3450 3443->3435 3449->3431 3455 4d4a18-4d4a1e __vbaGenerateBoundsError 3450->3455 3456 4d49d6-4d49dd 3450->3456 3458 4d4a24-4d4a66 call 484028 __vbaSetSystemError __vbaAryUnlock 3455->3458 3456->3455 3457 4d49df-4d49f3 3456->3457 3459 4d49f5-4d49ff 3457->3459 3460 4d4a01-4d4a07 __vbaGenerateBoundsError 3457->3460 3464 4d4a6c-4d4a70 3458->3464 3465 4d4dab-4d4dbb call 483e88 __vbaSetSystemError 3458->3465 3463 4d4a0d-4d4a16 3459->3463 3460->3463 3463->3458 3464->3465 3466 4d4a76-4d4ab9 __vbaStrCopy call 4fa530 __vbaFreeStr 3464->3466 3465->3449 3471 4d4abf-4d4af1 __vbaRedim __vbaAryLock 3466->3471 3472 4d4e75-4d4e7b __vbaErrorOverflow 3466->3472 3473 4d4b35-4d4b3b __vbaGenerateBoundsError 3471->3473 3474 4d4af3-4d4afa 3471->3474 3476 4d4b41-4d4b83 call 484028 __vbaSetSystemError __vbaAryUnlock 3473->3476 3474->3473 3475 4d4afc-4d4b10 3474->3475 3477 4d4b1e-4d4b24 __vbaGenerateBoundsError 3475->3477 3478 4d4b12-4d4b1c 3475->3478 3476->3465 3482 4d4b89-4d4b8e 3476->3482 3480 4d4b2a-4d4b33 3477->3480 3478->3480 3480->3476 3482->3465 3483 4d4b94-4d4bce #685 __vbaObjSet 3482->3483 3485 4d4bf0 3483->3485 3486 4d4bd0-4d4bee __vbaHresultCheckObj 3483->3486 3487 4d4bfa-4d4c1e __vbaFreeObj 3485->3487 3486->3487 3487->3465 3488 4d4c24-4d4c64 __vbaStrCopy call 4fa530 __vbaFreeStr __vbaAryLock 3487->3488 3491 4d4ca8-4d4cae __vbaGenerateBoundsError 3488->3491 3492 4d4c66-4d4c6d 3488->3492 3494 4d4cb4-4d4da8 call 474240 __vbaSetSystemError __vbaAryUnlock __vbaStrI4 __vbaStrMove __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStrList __vbaStrI4 __vbaStrMove __vbaStrToAnsi call 483fdc __vbaSetSystemError __vbaFreeStrList 3491->3494 3492->3491 3493 4d4c6f-4d4c83 3492->3493 3496 4d4c85-4d4c8f 3493->3496 3497 4d4c91-4d4c97 __vbaGenerateBoundsError 3493->3497 3494->3465 3499 4d4c9d-4d4ca6 3496->3499 3497->3499 3499->3494
      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004D437E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004D43BA
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 004D43CF
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,00411816), ref: 004D43E1
      • __vbaStrToAnsi.MSVBVM60(?,ServicesActive,000F003F,?,?,?,?,00411816), ref: 004D43FC
      • __vbaStrToAnsi.MSVBVM60(?,00000000,00000000,?,?,?,?,00411816), ref: 004D440D
      • __vbaSetSystemError.MSVBVM60(00000000,?,?,?,?,00411816), ref: 004D441C
      • __vbaStrToUnicode.MSVBVM60(00000000,?,?,?,?,?,00411816), ref: 004D442A
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?,00411816), ref: 004D4440
      • __vbaStrToAnsi.MSVBVM60(?,?,00000004), ref: 004D446D
      • __vbaSetSystemError.MSVBVM60(00000000,00000000,?,00000004), ref: 004D4480
      • __vbaStrToUnicode.MSVBVM60(00000000,?,?,00000004), ref: 004D448E
      • __vbaFreeStr.MSVBVM60(?,00000004), ref: 004D449D
      • __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,00000000,00000000,?,00000004), ref: 004D44DC
      • __vbaAryLock.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004D44F4
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D452B
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D4542
      • __vbaSetSystemError.MSVBVM60(?,?,?,?), ref: 004D456F
      • __vbaAryUnlock.MSVBVM60(00000000), ref: 004D4579
      • __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,?,00000000), ref: 004D45B7
      • __vbaAryLock.MSVBVM60(?,?), ref: 004D45CF
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D4606
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D461D
      • __vbaSetSystemError.MSVBVM60(?,?,?,?), ref: 004D464A
      • __vbaAryUnlock.MSVBVM60(00000000), ref: 004D4654
      • __vbaAryLock.MSVBVM60(00000000,?), ref: 004D466F
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D46A6
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D46BD
      • __vbaSetSystemError.MSVBVM60(?,?,00000024), ref: 004D46E1
      • __vbaAryUnlock.MSVBVM60(00000000), ref: 004D46EB
      • __vbaSetSystemError.MSVBVM60(?), ref: 004D470E
      • __vbaSetSystemError.MSVBVM60(00000000,?,00000004), ref: 004D4724
      • #685.MSVBVM60 ref: 004D4731
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004D473C
      • __vbaFreeObj.MSVBVM60 ref: 004D475D
      • __vbaAryDestruct.MSVBVM60(00000000,?,004D479E), ref: 004D4797
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Error$System$BoundsGenerate$Free$AnsiLockUnlock$RedimUnicode$#685ChkstkCopyDestructList
      • String ID: "$AloahaCredentialsServiceCommand:QueryStatus$AloahaCredentialsServiceCommand:entering ServiceAutoStart $Got number of bytes needed$Got service Status$Got service Status: $Got service handle$ServicesActive$c
      • API String ID: 1712364497-2849272966
      • Opcode ID: fb19e729292218d29c61c97ade2854a97c423d81066074491149e51e1bbd2131
      • Instruction ID: ce088f840b82409eca24fa4ffe7676b1420648b3f3fea42552ce9b8abf51c55a
      • Opcode Fuzzy Hash: fb19e729292218d29c61c97ade2854a97c423d81066074491149e51e1bbd2131
      • Instruction Fuzzy Hash: A5722774D00208EFDB14DFA4D988BDEBBB5BF48305F20855EE506AB2A1DB749A84CF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3504 4d22a0-4d234c __vbaChkstk __vbaStrCopy __vbaAryConstruct2 __vbaOnError call 4d1000 __vbaStrCopy __vbaStrCmp 3507 4d234e-4d236c __vbaInStr 3504->3507 3508 4d2383-4d23ab __vbaStrCopy __vbaLenBstr 3504->3508 3507->3508 3509 4d236e-4d237d __vbaStrCopy 3507->3509 3510 4d2b3f-4d2c44 #685 __vbaObjSet __vbaFreeObj __vbaFreeStr * 3 __vbaAryDestruct __vbaFreeStr * 2 __vbaAryDestruct 3508->3510 3511 4d23b1-4d2424 __vbaStrCopy call 50e600 __vbaStrMove __vbaStrCat __vbaStrMove __vbaFreeStrList __vbaInStr 3508->3511 3509->3508 3516 4d2426-4d244c #712 __vbaStrMove 3511->3516 3517 4d2452-4d24e7 __vbaStrCat #717 __vbaVar2Vec __vbaAryMove __vbaFreeVarList __vbaUbound 3511->3517 3516->3517 3518 4d24ed-4d250b 3517->3518 3519 4d2c5b-4d2c61 __vbaErrorOverflow 3517->3519 3520 4d250d-4d2517 3518->3520 3521 4d2519-4d251f __vbaGenerateBoundsError 3518->3521 3522 4d2525-4d2537 __vbaAryLock 3520->3522 3521->3522 3523 4d2539-4d2540 3522->3523 3524 4d2584-4d258a __vbaGenerateBoundsError 3522->3524 3523->3524 3525 4d2542-4d255c 3523->3525 3526 4d2590-4d25c5 __vbaStrToAnsi call 47485c 3524->3526 3527 4d255e-4d2568 3525->3527 3528 4d256a-4d2570 __vbaGenerateBoundsError 3525->3528 3531 4d25ca-4d260b __vbaSetSystemError __vbaStrToUnicode __vbaAryUnlock __vbaFreeStr 3526->3531 3530 4d2576-4d2582 3527->3530 3528->3530 3530->3526 3531->3510 3532 4d2611-4d261c 3531->3532 3533 4d2a5b-4d2aa1 #685 __vbaObjSet 3532->3533 3534 4d2622-4d2755 #717 #617 __vbaStrVarMove __vbaStrMove __vbaFreeVarList #619 #608 __vbaVarAdd __vbaVarTstEq __vbaFreeVarList 3532->3534 3543 4d2ac6 3533->3543 3544 4d2aa3-4d2ac4 __vbaHresultCheckObj 3533->3544 3535 4d27bd-4d2831 #619 __vbaVarTstEq __vbaFreeVar 3534->3535 3536 4d2757-4d277e __vbaLenBstr 3534->3536 3539 4d2899-4d28b5 __vbaInStr 3535->3539 3540 4d2833-4d285a __vbaLenBstr 3535->3540 3536->3519 3538 4d2784-4d27b7 #617 __vbaStrVarMove __vbaStrMove __vbaFreeVar 3536->3538 3538->3535 3541 4d28b7-4d28dd #712 __vbaStrMove 3539->3541 3542 4d28e3-4d2957 #617 __vbaVarTstEq __vbaFreeVar 3539->3542 3540->3519 3545 4d2860-4d2893 #617 __vbaStrVarMove __vbaStrMove __vbaFreeVar 3540->3545 3541->3542 3546 4d295d-4d2984 __vbaLenBstr 3542->3546 3547 4d29f9-4d2a15 __vbaInStr 3542->3547 3548 4d2ad0-4d2b39 __vbaStrI4 __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove call 4fa530 __vbaFreeStrList __vbaFreeObj 3543->3548 3544->3548 3545->3539 3546->3519 3550 4d298a-4d29f3 #619 __vbaStrVarMove __vbaStrMove __vbaFreeVar __vbaStrCopy call 50ef90 __vbaStrMove __vbaFreeStr 3546->3550 3551 4d2a17-4d2a3d #712 __vbaStrMove 3547->3551 3552 4d2a43-4d2a56 __vbaStrCopy 3547->3552 3548->3510 3550->3547 3551->3552 3552->3510
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,00000000,00411816), ref: 004D22BE
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D22EB
      • __vbaAryConstruct2.MSVBVM60(?,004842F4,00000011,?,?,?,00000000,00411816), ref: 004D22FC
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D230B
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D232C
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,00000000,00411816), ref: 004D2344
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001,?,?,?,?,00000000,00411816), ref: 004D2364
      • __vbaStrCopy.MSVBVM60(?,00000001,?,?,?,?,00000000,00411816), ref: 004D237D
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2392
      • __vbaLenBstr.MSVBVM60(?,?,?,?,?,00000000,00411816), ref: 004D23A3
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D23C0
      • __vbaStrMove.MSVBVM60(?,?,encrypted:,?,?,?,?,00000000,00411816), ref: 004D23DD
      • __vbaStrCat.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 004D23E4
      • __vbaStrMove.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D23EF
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?,00000000,00411816), ref: 004D23FF
      • __vbaInStr.MSVBVM60(00000000,0047C158,?,00000001,?,00000000,00411816), ref: 004D241C
      • #712.MSVBVM60(?,0047C158,{{{vbcrlf}}},00000001,000000FF,00000000,?,00000000,00411816), ref: 004D2441
      • __vbaStrMove.MSVBVM60(?,00000000,00411816), ref: 004D244C
      • __vbaStrCat.MSVBVM60(0047C158,?,?,00000000,00411816), ref: 004D2462
      • #717.MSVBVM60(?,00000008,00000080,00000000), ref: 004D248D
      • __vbaVar2Vec.MSVBVM60(?,?), ref: 004D24A1
      • __vbaAryMove.MSVBVM60(?,?), ref: 004D24B2
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004D24C8
      • __vbaUbound.MSVBVM60(00000001,?,?,?,?,?,00000000,00411816), ref: 004D24DE
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D2519
      • __vbaAryLock.MSVBVM60(?,?), ref: 004D252D
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D256A
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D2584
      • __vbaStrToAnsi.MSVBVM60(?,?,?,?,00030D40,00030D40,?,0000000A), ref: 004D25BE
      • __vbaSetSystemError.MSVBVM60(00000000), ref: 004D25D0
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 004D25DE
      • __vbaAryUnlock.MSVBVM60(00000000), ref: 004D25E8
      • __vbaFreeStr.MSVBVM60 ref: 004D25FA
      • #717.MSVBVM60(?,00006011,00000040,00000000), ref: 004D265A
      • #617.MSVBVM60(?,?,00000000), ref: 004D2672
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D267F
      • __vbaStrMove.MSVBVM60 ref: 004D268A
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004D26A0
      • #619.MSVBVM60(?,00004008,00000003), ref: 004D26D3
      • #608.MSVBVM60(?,00000000), ref: 004D26F6
      • __vbaVarAdd.MSVBVM60(?,?,00000008,?), ref: 004D2718
      • __vbaVarTstEq.MSVBVM60(00000000), ref: 004D271F
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 004D2743
      • __vbaLenBstr.MSVBVM60(?), ref: 004D2775
      • #617.MSVBVM60(?,00004008,-00000003), ref: 004D2793
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D27A0
      • __vbaStrMove.MSVBVM60 ref: 004D27AB
      • __vbaFreeVar.MSVBVM60 ref: 004D27B7
      • #619.MSVBVM60(?,00004008,00000002), ref: 004D27E7
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004D280F
      • __vbaFreeVar.MSVBVM60 ref: 004D2822
      • __vbaLenBstr.MSVBVM60(?), ref: 004D2851
      • #617.MSVBVM60(?,00004008,-00000002), ref: 004D286F
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D287C
      • __vbaStrMove.MSVBVM60 ref: 004D2887
      • __vbaFreeVar.MSVBVM60 ref: 004D2893
      • __vbaInStr.MSVBVM60(00000000,{{{vbcrlf}}},?,00000001), ref: 004D28AD
      • #712.MSVBVM60(?,{{{vbcrlf}}},0047C158,00000001,000000FF,00000000), ref: 004D28D2
      • __vbaStrMove.MSVBVM60 ref: 004D28DD
      • #617.MSVBVM60(?,00004008,0000000A), ref: 004D290D
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004D2935
      • __vbaFreeVar.MSVBVM60 ref: 004D2948
      • __vbaLenBstr.MSVBVM60(?), ref: 004D297B
      • #619.MSVBVM60(?,00004008,-0000000A), ref: 004D2999
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D29A6
      • __vbaStrMove.MSVBVM60 ref: 004D29B1
      • __vbaFreeVar.MSVBVM60 ref: 004D29BD
      • __vbaStrCopy.MSVBVM60 ref: 004D29D2
        • Part of subcall function 0050EF90: __vbaChkstk.MSVBVM60(?,00411816), ref: 0050EFAE
        • Part of subcall function 0050EF90: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 0050EFDE
        • Part of subcall function 0050EF90: __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 0050EFF3
        • Part of subcall function 0050EF90: __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 0050F008
        • Part of subcall function 0050EF90: #685.MSVBVM60(?,?,?,?,00411816), ref: 0050F015
        • Part of subcall function 0050EF90: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00411816), ref: 0050F020
        • Part of subcall function 0050EF90: __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 0050F041
        • Part of subcall function 0050EF90: __vbaStrCmp.MSVBVM60(true,00000000,?,?,?,?,00411816), ref: 0050F05A
        • Part of subcall function 0050EF90: __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 0050F079
        • Part of subcall function 0050EF90: __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 0050F08E
        • Part of subcall function 0050EF90: #520.MSVBVM60(?,00004008), ref: 0050F0B0
        • Part of subcall function 0050EF90: __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0050F0D2
        • Part of subcall function 0050EF90: __vbaFreeVar.MSVBVM60 ref: 0050F0E2
        • Part of subcall function 0050EF90: __vbaStrMove.MSVBVM60(Decrypt: ), ref: 0050F10D
        • Part of subcall function 0050EF90: __vbaStrCat.MSVBVM60(00000000), ref: 0050F114
        • Part of subcall function 0050EF90: __vbaStrMove.MSVBVM60 ref: 0050F11F
        • Part of subcall function 0050EF90: __vbaStrCat.MSVBVM60(00477FFC,00000000), ref: 0050F12B
        • Part of subcall function 0050EF90: __vbaStrMove.MSVBVM60 ref: 0050F136
      • __vbaStrMove.MSVBVM60(?,?), ref: 004D29EA
      • __vbaFreeStr.MSVBVM60 ref: 004D29F3
      • __vbaInStr.MSVBVM60(00000000,{{{vbcrlf}}},?,00000001), ref: 004D2A0D
      • #712.MSVBVM60(?,{{{vbcrlf}}},0047C158,00000001,000000FF,00000000), ref: 004D2A32
      • __vbaStrMove.MSVBVM60 ref: 004D2A3D
      • __vbaStrCopy.MSVBVM60 ref: 004D2A50
      • #685.MSVBVM60 ref: 004D2A62
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004D2A6D
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000004C), ref: 004D2AB8
      • __vbaStrI4.MSVBVM60(?,Pipe Error: Error number ), ref: 004D2ADC
      • __vbaStrMove.MSVBVM60 ref: 004D2AE7
      • __vbaStrCat.MSVBVM60(00000000), ref: 004D2AEE
      • __vbaStrMove.MSVBVM60 ref: 004D2AF9
      • __vbaStrCat.MSVBVM60( attempting to call CallNamedPipe.,00000000), ref: 004D2B05
      • __vbaStrMove.MSVBVM60 ref: 004D2B10
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?), ref: 004D2B2D
      • __vbaFreeObj.MSVBVM60 ref: 004D2B39
      • #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2B46
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 004D2B51
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2B72
      • __vbaFreeStr.MSVBVM60(004D2C45,?,?,?,?,00000000,00411816), ref: 004D2BF6
      • __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2BFF
      • __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2C08
      • __vbaAryDestruct.MSVBVM60(00000000,?,?,?,?,?,00000000,00411816), ref: 004D2C14
      • __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2C1D
      • __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2C26
      • __vbaAryDestruct.MSVBVM60(00000000,?,?,?,?,?,00000000,00411816), ref: 004D2C3E
      • __vbaErrorOverflow.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2C5B
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$FreeMove$Copy$Error$List$#617Bstr$#619#685#712BoundsGenerate$#717ChkstkDestruct$#520#608AnsiCheckConstruct2HresultLockOverflowSystemUboundUnicodeUnlockVar2
      • String ID: attempting to call CallNamedPipe.$,$1alsfj92348sv|@x2vs2asdaddwd$Pipe Error: Error number $\\.\pipe\AloahaCPMPipe$encrypted:${{{vbcrlf}}}
      • API String ID: 2813674213-4232403591
      • Opcode ID: 2447b3db1bf7eeae4f01e45a3841cf8626c167b0673d84f0518624c82721d6ea
      • Instruction ID: ab875d80d86e2f2424f840362790ff141281ccfb63c6b2ce818fab208bb2c1ba
      • Opcode Fuzzy Hash: 2447b3db1bf7eeae4f01e45a3841cf8626c167b0673d84f0518624c82721d6ea
      • Instruction Fuzzy Hash: 16422A75900219DBEB14DFA0DE48FDDB7B8BB44301F10C5AAE50AB72A0DB745A89CF64
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3556 50e600-50e6d1 __vbaChkstk __vbaOnError __vbaStrCopy * 2 #685 __vbaObjSet __vbaFreeObj __vbaStrCmp 3558 50e6d3-50e6e2 __vbaStrCopy 3556->3558 3559 50e6e8-50ea14 #685 __vbaObjSet __vbaFreeObj __vbaObjSetAddref __vbaStrCopy * 2 call 523470 __vbaObjSet __vbaFreeStrList __vbaChkstk __vbaLateMemSt __vbaChkstk __vbaLateMemCallLd __vbaVarLateMemSt __vbaFreeVar __vbaChkstk __vbaLateMemCallLd __vbaVarLateMemSt __vbaFreeVar __vbaChkstk * 2 __vbaLateMemCall __vbaChkstk __vbaLateMemSt __vbaChkstk __vbaLateMemCallLd __vbaStrVarMove __vbaStrMove __vbaFreeVar #685 __vbaObjSet 3556->3559 3558->3559 3564 50ea16-50ea37 __vbaHresultCheckObj 3559->3564 3565 50ea39 3559->3565 3566 50ea43-50ea67 __vbaFreeObj 3564->3566 3565->3566 3567 50ede3-50ee26 #685 __vbaObjSet 3566->3567 3568 50ea6d-50ed91 #685 __vbaObjSet __vbaFreeObj __vbaStrCopy * 2 __vbaObjSetAddref __vbaStrCopy * 2 call 523470 __vbaObjSet __vbaFreeStrList __vbaChkstk __vbaLateMemSt __vbaChkstk __vbaLateMemCallLd __vbaVarLateMemSt __vbaFreeVar __vbaChkstk __vbaLateMemCallLd __vbaVarLateMemSt __vbaFreeVar __vbaChkstk * 2 __vbaLateMemCall __vbaChkstk __vbaLateMemSt __vbaChkstk __vbaLateMemCallLd __vbaStrVarMove __vbaStrMove __vbaFreeVar __vbaLenBstr 3566->3568 3571 50ee28-50ee49 __vbaHresultCheckObj 3567->3571 3572 50ee4b 3567->3572 3578 50ed93-50edba __vbaStrCopy call 4fa530 __vbaFreeStr 3568->3578 3579 50edbc-50edd5 __vbaStrCopy call 4fa530 3568->3579 3574 50ee55-50ee79 __vbaFreeObj 3571->3574 3572->3574 3576 50eeb7-50ef6a __vbaObjSetAddref __vbaStrCopy #685 __vbaObjSet __vbaFreeObj * 2 __vbaFreeStr 3574->3576 3577 50ee7b-50eeb1 __vbaStrCopy * 2 call 4fa530 __vbaFreeStr 3574->3577 3577->3576 3578->3567 3586 50edda-50eddd __vbaFreeStr 3579->3586 3586->3567
      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,00000000,00411816), ref: 0050E61E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 0050E64E
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 0050E663
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 0050E678
      • #685.MSVBVM60(?,?,?,00000000,00411816), ref: 0050E685
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 0050E690
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 0050E6B1
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,?,?,00000000,00411816), ref: 0050E6C9
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 0050E6E2
      • #685.MSVBVM60(?,?,?,00000000,00411816), ref: 0050E6EF
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 0050E6FA
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 0050E71B
      • __vbaObjSetAddref.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 0050E72E
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 0050E743
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 0050E751
      • __vbaObjSet.MSVBVM60(?,00000000,CAPICOM.EncryptedData,00000000,?,?), ref: 0050E778
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 0050E788
      • __vbaChkstk.MSVBVM60 ref: 0050E7AB
      • __vbaLateMemSt.MSVBVM60(?,Algorithm), ref: 0050E7D2
      • __vbaChkstk.MSVBVM60 ref: 0050E7F2
      • __vbaLateMemCallLd.MSVBVM60(?,?,Algorithm,00000000,KeyLength), ref: 0050E824
      • __vbaVarLateMemSt.MSVBVM60(00000000,?,?,?,?,?,00000000,00411816), ref: 0050E82E
      • __vbaFreeVar.MSVBVM60(?,?,?,?,?,00000000,00411816), ref: 0050E837
      • __vbaChkstk.MSVBVM60 ref: 0050E857
      • __vbaLateMemCallLd.MSVBVM60(?,?,Algorithm,00000000,Name), ref: 0050E889
      • __vbaVarLateMemSt.MSVBVM60(00000000,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 0050E893
      • __vbaFreeVar.MSVBVM60(?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 0050E89C
      • __vbaChkstk.MSVBVM60 ref: 0050E8C9
      • __vbaChkstk.MSVBVM60 ref: 0050E8EC
      • __vbaLateMemCall.MSVBVM60(?,SetSecret,00000002), ref: 0050E915
      • __vbaChkstk.MSVBVM60 ref: 0050E939
      • __vbaLateMemSt.MSVBVM60(?,Content), ref: 0050E960
      • __vbaChkstk.MSVBVM60 ref: 0050E980
      • __vbaLateMemCallLd.MSVBVM60(?,?,encrypt,00000001), ref: 0050E9AD
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0050E9B7
      • __vbaStrMove.MSVBVM60 ref: 0050E9C2
      • __vbaFreeVar.MSVBVM60 ref: 0050E9CB
      • #685.MSVBVM60 ref: 0050E9D8
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050E9E3
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050EA2B
      • __vbaFreeObj.MSVBVM60 ref: 0050EA58
      • #685.MSVBVM60 ref: 0050EA74
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050EA7F
      • __vbaFreeObj.MSVBVM60 ref: 0050EAA0
      • __vbaStrCopy.MSVBVM60 ref: 0050EAB5
      • __vbaStrCopy.MSVBVM60 ref: 0050EAC8
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 0050EADB
      • __vbaStrCopy.MSVBVM60 ref: 0050EAF0
      • __vbaStrCopy.MSVBVM60 ref: 0050EAFE
      • __vbaObjSet.MSVBVM60(?,00000000,CAPICOM.EncryptedData,00000000,?,?), ref: 0050EB25
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 0050EB35
      • __vbaChkstk.MSVBVM60 ref: 0050EB58
      • __vbaLateMemSt.MSVBVM60(?,Algorithm), ref: 0050EB7F
      • __vbaChkstk.MSVBVM60 ref: 0050EB9F
      • __vbaLateMemCallLd.MSVBVM60(?,?,Algorithm,00000000,KeyLength), ref: 0050EBD1
      • __vbaVarLateMemSt.MSVBVM60(00000000), ref: 0050EBDB
      • __vbaFreeVar.MSVBVM60 ref: 0050EBE4
      • __vbaChkstk.MSVBVM60 ref: 0050EC04
      • __vbaLateMemCallLd.MSVBVM60(?,?,Algorithm,00000000,Name), ref: 0050EC36
      • __vbaVarLateMemSt.MSVBVM60(00000000), ref: 0050EC40
      • __vbaFreeVar.MSVBVM60 ref: 0050EC49
      • __vbaChkstk.MSVBVM60 ref: 0050EC76
      • __vbaChkstk.MSVBVM60 ref: 0050EC99
      • __vbaLateMemCall.MSVBVM60(?,SetSecret,00000002), ref: 0050ECC2
      • __vbaChkstk.MSVBVM60 ref: 0050ECE6
      • __vbaLateMemSt.MSVBVM60(?,Content), ref: 0050ED0D
      • __vbaChkstk.MSVBVM60 ref: 0050ED2D
      • __vbaLateMemCallLd.MSVBVM60(?,?,encrypt,00000001), ref: 0050ED5A
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0050ED64
      • __vbaStrMove.MSVBVM60 ref: 0050ED6F
      • __vbaFreeVar.MSVBVM60 ref: 0050ED78
      • __vbaLenBstr.MSVBVM60(?), ref: 0050ED89
      • __vbaStrCopy.MSVBVM60 ref: 0050EDA2
      • __vbaFreeStr.MSVBVM60(?), ref: 0050EDB4
      • __vbaStrCopy.MSVBVM60 ref: 0050EDCB
      • __vbaFreeStr.MSVBVM60(?), ref: 0050EDDD
      • #685.MSVBVM60 ref: 0050EDEA
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050EDF5
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050EE3D
      • __vbaFreeObj.MSVBVM60 ref: 0050EE6A
      • __vbaStrCopy.MSVBVM60 ref: 0050EE8A
      • __vbaStrCopy.MSVBVM60 ref: 0050EE9F
      • __vbaFreeStr.MSVBVM60(?), ref: 0050EEB1
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 0050EEC4
      • __vbaStrCopy.MSVBVM60 ref: 0050EED9
      • #685.MSVBVM60 ref: 0050EEE6
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050EEF1
      • __vbaFreeObj.MSVBVM60 ref: 0050EF12
      • __vbaFreeObj.MSVBVM60(0050EF6B), ref: 0050EF5B
      • __vbaFreeStr.MSVBVM60 ref: 0050EF64
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Late$Chkstk$Copy$Call$#685$Move$Addref$CheckHresultList$BstrError
      • String ID: *$@@NULL@@$Algorithm$CAPICOM.EncryptedData$Content$Encrypted$Encryption Error$KeyLength$Name$SetSecret$encrypt
      • API String ID: 2850594790-706667730
      • Opcode ID: f8cd9d973d8f6d43779a5d348d49e2d377e15f75c94424f51ebc49f01c54d04f
      • Instruction ID: c88af309dd1543ae8c0fd230ab5a268b05ad11ca566684005a2a8fabfe85d2c7
      • Opcode Fuzzy Hash: f8cd9d973d8f6d43779a5d348d49e2d377e15f75c94424f51ebc49f01c54d04f
      • Instruction Fuzzy Hash: E352C3B4A00208DFDB04DF94D988BDDBBB5FF48304F20C569E505AB2A5DB74AA89CF54
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3588 4f92b0-4f9355 __vbaChkstk __vbaOnError __vbaStrCmp call 51cef0 __vbaStrCmp 3591 4f935b-4f9548 __vbaStrCopy #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove #712 __vbaStrMove __vbaStrCopy call 50fba0 __vbaStrMove __vbaFreeStr #712 __vbaStrMove __vbaStrCopy 3588->3591 3592 4f9b33-4f9bb9 #685 __vbaObjSet __vbaFreeObj __vbaFreeStr * 2 3588->3592 3597 4f95ef-4f95fe 3591->3597 3598 4f954e-4f95cb call 4f2d70 __vbaStrMove __vbaStrCmp * 3 __vbaFreeStr 3591->3598 3600 4f96ae-4f96ce call 4fe150 3597->3600 3601 4f9604-4f967e #518 #617 __vbaVarTstEq __vbaFreeVarList 3597->3601 3598->3597 3607 4f95cd-4f95e6 call 4f3390 3598->3607 3608 4f96e5-4f96fd __vbaStrCmp 3600->3608 3609 4f96d0-4f96df __vbaStrCopy 3600->3609 3604 4f9698-4f96a8 __vbaStrCopy 3601->3604 3605 4f9680-4f9696 __vbaStrCopy 3601->3605 3604->3600 3605->3600 3607->3597 3611 4f96ff-4f9708 3608->3611 3612 4f970e-4f97e7 #685 __vbaObjSet __vbaFreeObj __vbaChkstk __vbaLateMemCallLd __vbaStrVarMove __vbaStrMove __vbaFreeVar #685 __vbaObjSet 3608->3612 3609->3608 3611->3612 3614 4f98da-4f992b #685 __vbaObjSet __vbaFreeObj __vbaStrCmp 3611->3614 3619 4f97eb-4f97fa 3612->3619 3617 4f992d-4f9936 3614->3617 3618 4f993c-4f9a0c __vbaChkstk * 3 __vbaLateMemCall 3614->3618 3617->3618 3620 4f9a0e-4f9a5f __vbaStrI4 __vbaStrMove __vbaStrCopy call 5071e0 __vbaFreeStrList 3617->3620 3621 4f9a62-4f9aa8 #685 __vbaObjSet 3618->3621 3622 4f981f 3619->3622 3623 4f97fc-4f981d __vbaHresultCheckObj 3619->3623 3620->3621 3629 4f9acd 3621->3629 3630 4f9aaa-4f9acb __vbaHresultCheckObj 3621->3630 3625 4f9829-4f9850 __vbaFreeObj 3622->3625 3623->3625 3625->3614 3628 4f9856-4f98d4 #685 __vbaObjSet __vbaFreeObj __vbaObjSetAddref #716 __vbaObjVar __vbaObjSetAddref __vbaFreeVar 3625->3628 3628->3614 3631 4f9ad7-4f9afe __vbaFreeObj 3629->3631 3630->3631 3633 4f9b0f-4f9b16 3631->3633 3634 4f9b00-4f9b0d 3631->3634 3635 4f9b1c-4f9b2d __vbaStrCopy 3633->3635 3634->3635 3635->3592
      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004F92CE
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,?,00411816), ref: 004F92FE
      • __vbaStrCmp.MSVBVM60(00485A8C,0077F04C,?,00000000,00000000,?,00411816), ref: 004F9316
        • Part of subcall function 0051CEF0: __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0051CF0E
        • Part of subcall function 0051CEF0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 0051CF3E
        • Part of subcall function 0051CEF0: __vbaStrCmp.MSVBVM60(true,00000000,?,?,?,00000000,00411816), ref: 0051CF56
        • Part of subcall function 0051CEF0: #685.MSVBVM60 ref: 0051CFAF
        • Part of subcall function 0051CEF0: __vbaObjSet.MSVBVM60(00000000,00000000), ref: 0051CFBA
        • Part of subcall function 0051CEF0: __vbaFreeObj.MSVBVM60 ref: 0051CFD2
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,?,00411816), ref: 004F9345
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004F936C
      • #712.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,00000000,00000000,?,00411816), ref: 004F938F
      • __vbaStrMove.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,00000000,00000000,?,00411816), ref: 004F939A
      • #712.MSVBVM60(00000000,hkcu\,HKCU\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,00000000,00000000,?), ref: 004F93BD
      • __vbaStrMove.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,00000000,00000000,?,00411816), ref: 004F93C8
      • #712.MSVBVM60(?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,00000000,00000000,?), ref: 004F93EB
      • __vbaStrMove.MSVBVM60(?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,00000000,00000000,?), ref: 004F93F6
      • #712.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F9419
      • __vbaStrMove.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F9424
      • #712.MSVBVM60(00000000,Software\,SOFTWARE\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001), ref: 004F9447
      • __vbaStrMove.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F9452
      • #712.MSVBVM60(?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001), ref: 004F9475
      • __vbaStrMove.MSVBVM60(?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001), ref: 004F9480
      • #712.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F94A3
      • __vbaStrMove.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F94AE
      • __vbaStrCopy.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F94C3
      • __vbaStrMove.MSVBVM60(000000FF,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\), ref: 004F94D7
      • __vbaFreeStr.MSVBVM60(?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001,000000FF,00000000,?,software\,SOFTWARE\,00000001), ref: 004F94E0
      • #712.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F9503
      • __vbaStrMove.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F950E
      • __vbaStrCopy.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F9525
      • __vbaStrMove.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F955F
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F956B
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F9586
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F95A2
      • __vbaFreeStr.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F95BC
      • #518.MSVBVM60(000000FF,00004008,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F9620
      • #617.MSVBVM60(?,000000FF,00000004,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F9630
      • __vbaVarTstEq.MSVBVM60(00008008,?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F9655
      • __vbaFreeVarList.MSVBVM60(00000002,000000FF,?,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F966C
      • __vbaStrCopy.MSVBVM60(00000000,?,00411816), ref: 004F9690
      • __vbaStrCopy.MSVBVM60(00000000,?,00411816), ref: 004F96A8
      • __vbaStrCopy.MSVBVM60(00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\), ref: 004F96DF
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F96F5
      • #685.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F9715
      • __vbaObjSet.MSVBVM60(?,00000000,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\), ref: 004F9720
      • __vbaFreeObj.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F9741
      • __vbaChkstk.MSVBVM60(?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000,?,system\,SYSTEM\,00000001), ref: 004F9761
      • __vbaLateMemCallLd.MSVBVM60(000000FF,022C1040,RegRead,00000001,?,004778FC,004775E8,00000001,000000FF,00000000,?,System\,SYSTEM\,00000001,000000FF,00000000), ref: 004F9790
        • Part of subcall function 004F2D70: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,00000000,00000000,?,00411816), ref: 004F2D8E
        • Part of subcall function 004F2D70: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 004F2DBE
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816), ref: 004F2DD6
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(00473D9C,0075ACDC,?,00000000,00000000,00000000,00411816), ref: 004F2DF7
        • Part of subcall function 004F2D70: __vbaStrCopy.MSVBVM60 ref: 004F2E22
        • Part of subcall function 004F2D70: __vbaStrCopy.MSVBVM60 ref: 004F2E30
        • Part of subcall function 004F2D70: __vbaStrMove.MSVBVM60(?,?,0000000A), ref: 004F2E4C
        • Part of subcall function 004F2D70: __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004F2E5C
        • Part of subcall function 004F2D70: __vbaFreeVar.MSVBVM60(00000000,00000000,00411816), ref: 004F2E68
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004F2E7E
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(004740D4,?), ref: 004F2E95
        • Part of subcall function 004F2D70: __vbaStrCopy.MSVBVM60 ref: 004F2ED6
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816), ref: 004F2F04
      • __vbaStrVarMove.MSVBVM60(00000000,00000001,000000FF), ref: 004F979A
      • __vbaStrMove.MSVBVM60 ref: 004F97A5
      • __vbaFreeVar.MSVBVM60 ref: 004F97AE
      • #685.MSVBVM60 ref: 004F97BB
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F97C6
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004F9811
      • __vbaFreeObj.MSVBVM60 ref: 004F9841
      • #685.MSVBVM60 ref: 004F985D
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F9868
      • __vbaFreeObj.MSVBVM60 ref: 004F9889
      • __vbaObjSetAddref.MSVBVM60(0054D554,00000000), ref: 004F989D
      • #716.MSVBVM60(?,WScript.Shell,00000000), ref: 004F98B5
      • __vbaObjVar.MSVBVM60(?), ref: 004F98BF
      • __vbaObjSetAddref.MSVBVM60(0054D554,00000000), ref: 004F98CB
      • __vbaFreeVar.MSVBVM60 ref: 004F98D4
      • #685.MSVBVM60 ref: 004F98E1
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F98EC
      • __vbaFreeObj.MSVBVM60 ref: 004F990D
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004F9923
      • __vbaChkstk.MSVBVM60 ref: 004F997C
      • __vbaChkstk.MSVBVM60 ref: 004F999F
      • __vbaChkstk.MSVBVM60 ref: 004F99CB
      • __vbaLateMemCall.MSVBVM60(022C1040,Regwrite,00000003), ref: 004F9A03
      • __vbaStrI4.MSVBVM60(00000000), ref: 004F9A1B
      • __vbaStrMove.MSVBVM60 ref: 004F9A26
      • __vbaStrCopy.MSVBVM60 ref: 004F9A34
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,00000000,?,00000000), ref: 004F9A59
      • #685.MSVBVM60 ref: 004F9A69
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F9A74
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004F9ABF
      • __vbaFreeObj.MSVBVM60 ref: 004F9AEF
      • __vbaStrCopy.MSVBVM60 ref: 004F9B2D
      • #685.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004F9B3A
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,?,00411816), ref: 004F9B45
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004F9B66
      • __vbaFreeStr.MSVBVM60(004F9BBA,?,00000000,00000000,?,00411816), ref: 004F9BAA
      • __vbaFreeStr.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004F9BB3
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$Copy$#712$#685Chkstk$ErrorList$AddrefCallCheckHresultLate$#518#617#716
      • String ID: 7$HKCR\$HKCU\$HKLM\$HKLM\SOFTWARE\Aloaha\ctest$PDF$REG_DWORD$RegRead$Regwrite$SOFTWARE\$SYSTEM\$Software\$System\$WScript.Shell$hYH$hkcu$hkcu\$hklm\$hlcr\$software\$system\
      • API String ID: 4162271779-1415178065
      • Opcode ID: 033c7a41dca3a870541966c81299968ee05bdfd75140c06fcd8ca8b5d35e8b18
      • Instruction ID: 482b755cb55fa00f188f28bb2234017ff7e4b0549eb935024b2e55b9ae5dcc78
      • Opcode Fuzzy Hash: 033c7a41dca3a870541966c81299968ee05bdfd75140c06fcd8ca8b5d35e8b18
      • Instruction Fuzzy Hash: 4A423A74A00208EFDB14DFA4DD48BDDBBB5FF48705F2081A9E90AA72A0DB749A45CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004B441E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004B444E
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004B4477
      • __vbaStrCmp.MSVBVM60(false,?), ref: 004B4494
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004B44BC
      • __vbaStrMove.MSVBVM60 ref: 004B4506
      • __vbaStrCopy.MSVBVM60 ref: 004B4511
      • __vbaFreeStr.MSVBVM60 ref: 004B451A
      • #685.MSVBVM60 ref: 004B4527
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B4532
      • __vbaFreeObj.MSVBVM60 ref: 004B4553
      • __vbaStrCopy.MSVBVM60 ref: 004B4576
      • __vbaStrMove.MSVBVM60(?), ref: 004B458A
      • __vbaI4Str.MSVBVM60(00000000), ref: 004B4591
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004B45A4
      • #685.MSVBVM60 ref: 004B45B4
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B45BF
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004B460A
      • __vbaFreeObj.MSVBVM60 ref: 004B4648
      • __vbaI4Str.MSVBVM60(?), ref: 004B4664
      • __vbaStrCopy.MSVBVM60 ref: 004B4678
      • __vbaFreeStr.MSVBVM60(?,00000000), ref: 004B4691
      • #685.MSVBVM60 ref: 004B46BA
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B46C5
      • __vbaFreeObj.MSVBVM60 ref: 004B46E6
      • __vbaStrCopy.MSVBVM60 ref: 004B4709
      • __vbaStrMove.MSVBVM60(?), ref: 004B471D
      • __vbaI4Str.MSVBVM60(00000000), ref: 004B4724
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004B4737
      • #685.MSVBVM60 ref: 004B4747
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B4752
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004B479D
      • __vbaFreeObj.MSVBVM60 ref: 004B47DB
      • __vbaI4Str.MSVBVM60(?), ref: 004B47F7
      • __vbaStrCopy.MSVBVM60 ref: 004B480B
      • __vbaFreeStr.MSVBVM60(?,00000000), ref: 004B4824
      • #685.MSVBVM60 ref: 004B484D
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B4858
      • __vbaFreeObj.MSVBVM60 ref: 004B4879
        • Part of subcall function 0051C3A0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00530973,?,00000000,?,00000000,00411816), ref: 0051C3BE
        • Part of subcall function 0051C3A0: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 0051C3EE
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,00773364,?,00000000,?,00000000,00411816), ref: 0051C406
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051C420
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE34
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051CE3F
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE60
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(0051CED1,?,?,?,?,00000000,00411816), ref: 0051CEB8
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CEC1
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CECA
      • __vbaStrMove.MSVBVM60 ref: 004B489E
      • __vbaStrCat.MSVBVM60(:SmartLogin.txt,00000000), ref: 004B48AA
      • __vbaStrMove.MSVBVM60 ref: 004B48B5
        • Part of subcall function 004BD720: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,0052029D,?,?,?,00000000,00411816), ref: 004BD73E
        • Part of subcall function 004BD720: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004BD76E
        • Part of subcall function 004BD720: __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 004BD783
        • Part of subcall function 004BD720: #685.MSVBVM60(?,?,?,?,00411816), ref: 004BD790
        • Part of subcall function 004BD720: __vbaObjSet.MSVBVM60(00000000,00000000,?,?,?,?,00411816), ref: 004BD79B
        • Part of subcall function 004BD720: __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 004BD7B3
        • Part of subcall function 004BD720: #685.MSVBVM60(00000000,?,?,?,?,00411816), ref: 004BD7DC
        • Part of subcall function 004BD720: __vbaObjSet.MSVBVM60(00000000,00000000,?,?,?,?,00411816), ref: 004BD7E7
        • Part of subcall function 004BD720: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004BD81A
        • Part of subcall function 004BD720: __vbaFreeObj.MSVBVM60 ref: 004BD83E
        • Part of subcall function 004BD720: __vbaVar2Vec.MSVBVM60(?,?,?,0052029D), ref: 004BD868
        • Part of subcall function 004BD720: __vbaAryMove.MSVBVM60(?,?), ref: 004BD876
      • __vbaStrMove.MSVBVM60(?), ref: 004B48C9
      • __vbaI4Str.MSVBVM60(00000000), ref: 004B48D0
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?), ref: 004B48E7
      • #685.MSVBVM60 ref: 004B48F7
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B4902
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004B494D
      • __vbaFreeObj.MSVBVM60 ref: 004B498B
      • __vbaStrMove.MSVBVM60 ref: 004B49B1
      • __vbaStrMove.MSVBVM60 ref: 004B49D9
      • __vbaStrCat.MSVBVM60(:SmartLogin.txt,00000000), ref: 004B49E5
      • __vbaStrMove.MSVBVM60 ref: 004B49F0
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,00000000,?,?,00000000), ref: 004B4A18
      • #685.MSVBVM60 ref: 004B4A44
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B4A4F
      • __vbaFreeObj.MSVBVM60 ref: 004B4A70
      • __vbaR8Str.MSVBVM60(?), ref: 004B4A8A
      • __vbaFpI4.MSVBVM60 ref: 004B4AA2
      • #685.MSVBVM60 ref: 004B4AC3
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B4ACE
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004B4B19
      • __vbaFreeObj.MSVBVM60 ref: 004B4B49
      • __vbaStrCopy.MSVBVM60 ref: 004B4B7C
      • __vbaStrCopy.MSVBVM60 ref: 004B4BA6
      • __vbaStrCopy.MSVBVM60 ref: 004B4BD0
      • __vbaVarDup.MSVBVM60 ref: 004B4C0C
      • #667.MSVBVM60(?), ref: 004B4C16
      • #520.MSVBVM60(?,00000008), ref: 004B4C2E
      • #518.MSVBVM60(?,?), ref: 004B4C3F
      • __vbaStrVarMove.MSVBVM60(?), ref: 004B4C4C
      • __vbaStrMove.MSVBVM60 ref: 004B4C57
      • __vbaFreeVarList.MSVBVM60(00000004,?,00000008,?,?), ref: 004B4C72
      • __vbaVarDup.MSVBVM60 ref: 004B4C9F
      • #667.MSVBVM60(?), ref: 004B4CA9
      • #520.MSVBVM60(?,00000008), ref: 004B4CC1
      • #518.MSVBVM60(?,?), ref: 004B4CD2
      • __vbaStrVarMove.MSVBVM60(?), ref: 004B4CDF
      • __vbaStrMove.MSVBVM60 ref: 004B4CEA
      • __vbaFreeVarList.MSVBVM60(00000004,?,00000008,?,?), ref: 004B4D05
      • __vbaInStr.MSVBVM60(00000000,thales,?,00000001), ref: 004B4D22
      • __vbaStrCopy.MSVBVM60 ref: 004B4D4E
      • __vbaInStr.MSVBVM60(00000000,thales,?,00000001), ref: 004B4D68
      • __vbaStrCopy.MSVBVM60 ref: 004B4D94
      • #685.MSVBVM60 ref: 004B4DA1
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004B4DAC
      • __vbaFreeObj.MSVBVM60 ref: 004B4DCD
      • __vbaFreeStr.MSVBVM60(004B4E36), ref: 004B4E1D
      • __vbaFreeStr.MSVBVM60 ref: 004B4E26
      • __vbaFreeStr.MSVBVM60 ref: 004B4E2F
        • Part of subcall function 004F0CA0: __vbaChkstk.MSVBVM60(?,00411816), ref: 004F0CBE
        • Part of subcall function 004F0CA0: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,?,00411816), ref: 004F0CEE
        • Part of subcall function 004F0CA0: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004F0D21
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D54
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D5F
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D82
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0D8D
        • Part of subcall function 004F0CA0: #712.MSVBVM60(00000000,hkcu\,HKCU\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001), ref: 004F0DB0
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001,000000FF,00000000), ref: 004F0DBB
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001), ref: 004F0DDE
        • Part of subcall function 004F0CA0: __vbaStrMove.MSVBVM60(?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001,000000FF,00000000,?,Sofware\,Software\,00000001), ref: 004F0DE9
        • Part of subcall function 004F0CA0: #712.MSVBVM60(?,software\,SOFTWARE\,00000001,000000FF,00000000,?,hlcr\,HKCR\,00000001,000000FF,00000000,?,hklm\,HKLM\,00000001), ref: 004F0E0C
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$#685Copy$List$#712CheckHresult$ChkstkError$#518#520#667$Var2
      • String ID: :SmartLogin.txt$C$HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\[119D030E-70FA-4F86-A944-ECAF4495A798]$HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\[119D030E-70FA-4F86-A944-ECAF4495A798]$USERDNSDOMAIN$USERDOMAIN$false$thales$true
      • API String ID: 353099511-246192409
      • Opcode ID: 28b22e0c01ad7bf04c83a4551f7d6948837b333cbaf182212bba683c35ad6839
      • Instruction ID: f49eb719054b8a7060e955ae29fb01a696a803020c5230ea065ad7c5839b1c64
      • Opcode Fuzzy Hash: 28b22e0c01ad7bf04c83a4551f7d6948837b333cbaf182212bba683c35ad6839
      • Instruction Fuzzy Hash: E5522875900218EFDB14DFA0DA48BEEBBB5BF48305F1081A9E50AB72A0DB745A85CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004D378E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004D37CA
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 004D37DF
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,00411816), ref: 004D37F1
      • #520.MSVBVM60(?,00004008), ref: 004D381F
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004D3847
      • __vbaFreeVar.MSVBVM60 ref: 004D385A
      • #520.MSVBVM60(?,00000008), ref: 004D3895
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D38A2
      • __vbaStrMove.MSVBVM60 ref: 004D38AD
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 004D38C3
      • #518.MSVBVM60(?,00004008), ref: 004D38F4
      • #518.MSVBVM60(?,00004008), ref: 004D392F
      • #518.MSVBVM60(?,00004008), ref: 004D396A
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004D3990
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?), ref: 004D39C3
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?,00000000), ref: 004D39DF
      • __vbaVarOr.MSVBVM60(?,00000000), ref: 004D39ED
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?,00000000), ref: 004D3A09
      • __vbaVarOr.MSVBVM60(?,00000000), ref: 004D3A17
      • __vbaVarOr.MSVBVM60(?,0000000B,00000000), ref: 004D3A2C
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004D3A33
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,0000000B), ref: 004D3A5E
        • Part of subcall function 005006B0: __vbaChkstk.MSVBVM60(00000000,00411816,0050A09D,?,00000000,00000000,00000000,00411816), ref: 005008BE
        • Part of subcall function 005006B0: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816,0050A09D), ref: 005008EE
        • Part of subcall function 005006B0: __vbaStrCmp.MSVBVM60(00473D9C,0075AA5C,?,00000000,00000000,00000000,00411816,0050A09D), ref: 00500906
        • Part of subcall function 005006B0: __vbaStrCmp.MSVBVM60(true,007796A4,?,00000000,00000000,00000000,00411816,0050A09D), ref: 00500920
        • Part of subcall function 005006B0: __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816,0050A09D), ref: 00500946
        • Part of subcall function 005006B0: __vbaStrCopy.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0050096F
        • Part of subcall function 005006B0: __vbaStrCmp.MSVBVM60(00473D9C,0075AA5C,?,00000000,00000000,00000000,00411816,0050A09D), ref: 00500988
        • Part of subcall function 005006B0: __vbaStrCmp.MSVBVM60(00473D9C,0075AC14,?,00000001,?,00000000,00411816), ref: 005009A4
        • Part of subcall function 005006B0: __vbaStrCopy.MSVBVM60(?,00000001,?,00000000,00411816), ref: 005009C0
        • Part of subcall function 005006B0: __vbaStrCmp.MSVBVM60(00473D9C,0075AA5C,?,00000001,?,00000000,00411816), ref: 00500A09
        • Part of subcall function 005006B0: __vbaVarDup.MSVBVM60 ref: 00500A37
        • Part of subcall function 005006B0: #667.MSVBVM60(?), ref: 00500A41
        • Part of subcall function 005006B0: __vbaStrMove.MSVBVM60 ref: 00500A4E
        • Part of subcall function 005006B0: __vbaFreeVar.MSVBVM60 ref: 00500A57
      • __vbaStrCmp.MSVBVM60(true,?,?,?,?,?,00411816), ref: 004D3A89
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 004D3AA5
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00411816), ref: 004D3ABE
      • #518.MSVBVM60(?,00004008), ref: 004D3B00
      • #518.MSVBVM60(?,00004008), ref: 004D3B27
      • __vbaStrCmp.MSVBVM60(00473D9C), ref: 004D3B38
      • __vbaVarCmpNe.MSVBVM60(?,?,?,0000000B), ref: 004D3B73
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 004D3B88
      • __vbaVarOr.MSVBVM60(?,00000000), ref: 004D3B96
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004D3B9D
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,0000000B,0000000B), ref: 004D3BC8
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,00411816), ref: 004D3BF2
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,00411816), ref: 004D3C07
      • __vbaInStr.MSVBVM60(00000000,00477FFC,?,00000001,?,?,?,?,?,?,?,?,?,00411816), ref: 004D3C23
      • __vbaStrCopy.MSVBVM60(?,00000001,?,?,?,?,?,?,?,?,?,00411816), ref: 004D3C3C
      • __vbaFreeStr.MSVBVM60(?,?,00000001,?,?,?,?,?,?,?,?,?,00411816), ref: 004D3C4E
      • __vbaFreeStr.MSVBVM60(004D406A,?,?,?,?,00411816), ref: 004D405A
      • __vbaFreeStr.MSVBVM60(?,?,?,?,00411816), ref: 004D4063
      Strings
      • Could not retrieve Service Handle for Service, xrefs: 004D3F1C
      • Service Status is 0, xrefs: 004D3EA5
      • Starting Service : , xrefs: 004D3E6E
      • Could not retrieve Service Handle for ServiceManager, xrefs: 004D3F5B
      • going to start: , xrefs: 004D3C62
      • HKLM\Software\Aloaha\CSP\AloahaCPMRunning, xrefs: 004D3EEC
      • 1, xrefs: 004D3FB0
      • Service names cannot contain spaces. Use the 'Service Name' of the service, not the 'Display Name', xrefs: 004D3C34
      • localsystem, xrefs: 004D3970
      • true, xrefs: 004D398B, 004D3A84
      • network, xrefs: 004D3935
      • ServicesActive, xrefs: 004D3C9C
      • system, xrefs: 004D38FA
      • AloahaCredentialsServiceCommand:Start_Service, xrefs: 004D37D7
      • Unpausing : , xrefs: 004D3E0E
      • Started: , xrefs: 004D3F82
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Copy$#518$ListMove$#520BoolChkstkErrorNull$#667
      • String ID: 1$AloahaCredentialsServiceCommand:Start_Service$Could not retrieve Service Handle for Service$Could not retrieve Service Handle for ServiceManager$HKLM\Software\Aloaha\CSP\AloahaCPMRunning$Service Status is 0$Service names cannot contain spaces. Use the 'Service Name' of the service, not the 'Display Name'$ServicesActive$Started: $Starting Service : $Unpausing : $going to start: $localsystem$network$system$true
      • API String ID: 3860041542-4268503911
      • Opcode ID: 5cd116b31090af3c97ba774067e002c9bd0ae9543a51b805f06a2be2fb78b4fb
      • Instruction ID: 8edad0c6d253505bba0838b01763dd033b10d6ccdc65f6a2f4e54b97dd005d61
      • Opcode Fuzzy Hash: 5cd116b31090af3c97ba774067e002c9bd0ae9543a51b805f06a2be2fb78b4fb
      • Instruction Fuzzy Hash: 6932F9B5900218EFDB24DFA0DE48BDDB778BF48305F1085AAE50AA7660DB745B48CF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0054604E
      • __vbaAryConstruct2.MSVBVM60(?,00497A3C,00000011,?,?,?,00000000,00411816), ref: 00546083
      • __vbaAryConstruct2.MSVBVM60(?,00497A3C,00000011,?,?,?,00000000,00411816), ref: 00546097
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 005460A6
        • Part of subcall function 00531FD0: __vbaChkstk.MSVBVM60(00000000,00411816,004CB93C,?,00000001,?,00000000,00411816), ref: 00531FEE
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053201E
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053202D
        • Part of subcall function 00531FD0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,004CB93C), ref: 0053203C
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 0053206B
        • Part of subcall function 00531FD0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532093
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 005320A6
        • Part of subcall function 00531FD0: __vbaStrCopy.MSVBVM60 ref: 005320CA
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00000008,?), ref: 005320F7
        • Part of subcall function 00531FD0: __vbaStrVarMove.MSVBVM60(?), ref: 00532104
        • Part of subcall function 00531FD0: __vbaStrMove.MSVBVM60 ref: 00532111
        • Part of subcall function 00531FD0: __vbaFreeStr.MSVBVM60 ref: 0053211A
        • Part of subcall function 00531FD0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532130
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 00532162
        • Part of subcall function 00531FD0: __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0053218A
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 0053219D
      • __vbaAryMove.MSVBVM60(?,?,?,?,?,00000000,00411816), ref: 005460D9
      • #685.MSVBVM60(?,?,?,00000000,00411816), ref: 005460F6
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 00546101
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 00546122
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00546160
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0054617A
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0054619B
      • #685.MSVBVM60 ref: 005461B0
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 005461BB
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 005461EE
      • __vbaFreeObj.MSVBVM60 ref: 00546218
      • __vbaAryCopy.MSVBVM60(0054D854,00000000), ref: 0054623A
      • __vbaStrCopy.MSVBVM60 ref: 00546288
      • __vbaStrCopy.MSVBVM60 ref: 005462FF
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 00546315
      • __vbaAryMove.MSVBVM60(?,?,?,?,?,00000000,00411816), ref: 00546A1C
      • #685.MSVBVM60(?,?,?,00000000,00411816), ref: 00546A29
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 00546A34
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 00546A55
      • __vbaAryDestruct.MSVBVM60(00000000,?,00546AF4,?,?,?,00000000,00411816), ref: 00546AA5
      • __vbaAryDestruct.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 00546AB1
      • __vbaAryDestruct.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 00546AC0
      • __vbaFreeStr.MSVBVM60(?,?,?,00000000,00411816), ref: 00546AC9
      • __vbaAryDestruct.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 00546AD5
      • __vbaAryDestruct.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 00546AE1
      • __vbaAryDestruct.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 00546AED
        • Part of subcall function 00536150: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,00000001), ref: 0053616E
        • Part of subcall function 00536150: __vbaAryConstruct2.MSVBVM60(?,00496A00,00000011,?,00000001,?,00000000,00411816), ref: 005361A0
        • Part of subcall function 00536150: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816), ref: 005361AF
        • Part of subcall function 00536150: #685.MSVBVM60(?,00000001,?,00000000,00411816), ref: 005361D1
        • Part of subcall function 00536150: __vbaObjSet.MSVBVM60(?,00000000,?,00000001,?,00000000,00411816), ref: 005361DC
        • Part of subcall function 00536150: __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 005361FD
        • Part of subcall function 00536150: __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000001,?,00000000,00411816), ref: 0053628D
        • Part of subcall function 00536150: #685.MSVBVM60(?,00000001,?,00000000,00411816), ref: 005362A2
        • Part of subcall function 00536150: __vbaObjSet.MSVBVM60(?,00000000,?,00000001,?,00000000,00411816), ref: 005362AD
        • Part of subcall function 00536150: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 005362F8
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Destruct$#685Error$CopyMove$#520ChkstkConstruct2$BoundsCheckConstructFixstrGenerateHresult$List
      • String ID: $$+
      • API String ID: 156982937-2639343560
      • Opcode ID: a7516d9c11d82ff9e8849a977aa7a92a5cfc63cd9075ab21fd8ffdba9afec736
      • Instruction ID: 17e7b93128e3f0d459893d1fc6b35e20561e1e825f0e64e4e5d9986d31467aca
      • Opcode Fuzzy Hash: a7516d9c11d82ff9e8849a977aa7a92a5cfc63cd9075ab21fd8ffdba9afec736
      • Instruction Fuzzy Hash: 2D622974D00209DFDB18CF90DA88BEDBBB1FB49308F1084A9E506BB264DB709A85CF55
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004BC72E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004BC767
        • Part of subcall function 004CC360: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,?,00411816), ref: 004CC37E
        • Part of subcall function 004CC360: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004CC3AE
        • Part of subcall function 004CC360: __vbaStrToAnsi.MSVBVM60(00000000,screen-saver,00000000,00000000,00000040), ref: 004CC3D7
        • Part of subcall function 004CC360: __vbaSetSystemError.MSVBVM60(00000000), ref: 004CC3E6
        • Part of subcall function 004CC360: __vbaFreeStr.MSVBVM60 ref: 004CC3F5
        • Part of subcall function 004CC360: __vbaSetSystemError.MSVBVM60(00000000), ref: 004CC428
        • Part of subcall function 004CC360: #685.MSVBVM60 ref: 004CC55A
        • Part of subcall function 004CC360: __vbaObjSet.MSVBVM60(?,00000000), ref: 004CC565
        • Part of subcall function 004CC360: __vbaFreeObj.MSVBVM60 ref: 004CC57D
        • Part of subcall function 0051D000: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,00000000,00411816), ref: 0051D01E
        • Part of subcall function 0051D000: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 0051D04E
        • Part of subcall function 0051D000: __vbaStrCmp.MSVBVM60(true,0077F45C,?,?,?,?,00411816), ref: 0051D066
        • Part of subcall function 0051D000: #685.MSVBVM60 ref: 0051D326
        • Part of subcall function 0051D000: __vbaObjSet.MSVBVM60(00000000,00000000), ref: 0051D331
        • Part of subcall function 0051D000: __vbaFreeObj.MSVBVM60 ref: 0051D352
        • Part of subcall function 0051D000: __vbaFreeStr.MSVBVM60(0051D393), ref: 0051D383
        • Part of subcall function 0051D000: __vbaFreeStr.MSVBVM60 ref: 0051D38C
        • Part of subcall function 00531FD0: __vbaChkstk.MSVBVM60(00000000,00411816,004CB93C,?,00000001,?,00000000,00411816), ref: 00531FEE
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053201E
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053202D
        • Part of subcall function 00531FD0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,004CB93C), ref: 0053203C
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 0053206B
        • Part of subcall function 00531FD0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532093
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 005320A6
        • Part of subcall function 00531FD0: __vbaStrCopy.MSVBVM60 ref: 005320CA
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00000008,?), ref: 005320F7
        • Part of subcall function 00531FD0: __vbaStrVarMove.MSVBVM60(?), ref: 00532104
        • Part of subcall function 00531FD0: __vbaStrMove.MSVBVM60 ref: 00532111
        • Part of subcall function 00531FD0: __vbaFreeStr.MSVBVM60 ref: 0053211A
        • Part of subcall function 00531FD0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532130
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 00532162
        • Part of subcall function 00531FD0: __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0053218A
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 0053219D
      • __vbaStrI4.MSVBVM60(00000000,Splash,?,?,?,?,00411816), ref: 004BC7C2
      • __vbaStrMove.MSVBVM60(?,?,?,?,00411816), ref: 004BC7CD
      • __vbaStrCat.MSVBVM60(00000000,?,?,?,?,00411816), ref: 004BC7D4
      • __vbaStrMove.MSVBVM60(?,?,?,?,00411816), ref: 004BC7DF
      • __vbaStrCat.MSVBVM60( is false,00000000,?,?,?,?,00411816), ref: 004BC7EB
      • __vbaStrMove.MSVBVM60(?,?,?,?,00411816), ref: 004BC7F6
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?,?,?,?,00411816), ref: 004BC813
      • #716.MSVBVM60(?,AloahaCredentialsdll.Provider,00000000,?,?,?,00411816), ref: 004BC82E
      • __vbaObjVar.MSVBVM60(?,?,?,?,00411816), ref: 004BC838
      • __vbaObjSetAddref.MSVBVM60(?,00000000,?,?,?,00411816), ref: 004BC843
      • __vbaFreeVar.MSVBVM60(?,?,?,00411816), ref: 004BC84C
      • #685.MSVBVM60(?,?,?,00411816), ref: 004BC859
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00411816), ref: 004BC864
      • __vbaFreeObj.MSVBVM60(?,?,?,00411816), ref: 004BC885
      • __vbaLateMemCallLd.MSVBVM60(?,?,CardReaderWithI2c,00000000,?,?,?,00411816), ref: 004BC8A1
      • __vbaI4ErrVar.MSVBVM60(00000000), ref: 004BC8AB
      • __vbaFreeVar.MSVBVM60 ref: 004BC8B7
      • __vbaStrI4.MSVBVM60(?,FirstCard is: ), ref: 004BC8CD
      • __vbaStrMove.MSVBVM60 ref: 004BC8D8
      • __vbaStrCat.MSVBVM60(00000000), ref: 004BC8DF
      • __vbaStrMove.MSVBVM60 ref: 004BC8EA
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004BC903
      • __vbaStrI4.MSVBVM60(0000000A,Found I2c Card: ), ref: 004BC937
      • __vbaStrMove.MSVBVM60 ref: 004BC942
      • __vbaStrCat.MSVBVM60(00000000), ref: 004BC949
      • __vbaStrMove.MSVBVM60 ref: 004BC954
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004BC96D
      • __vbaChkstk.MSVBVM60 ref: 004BC98F
      • __vbaLateMemCallLd.MSVBVM60(?,?,SmartCardNumber,00000001), ref: 004BC9BC
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 004BC9C6
      • __vbaStrMove.MSVBVM60 ref: 004BC9D1
      • __vbaFreeVar.MSVBVM60 ref: 004BC9DA
      • __vbaStrCat.MSVBVM60(?,StackID is: ), ref: 004BC9F0
      • __vbaStrMove.MSVBVM60 ref: 004BC9FB
      • __vbaFreeStr.MSVBVM60(?), ref: 004BCA0D
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004BCA23
      • __vbaStrCat.MSVBVM60(?,Found for User: ), ref: 004BCA47
      • __vbaStrMove.MSVBVM60 ref: 004BCA52
      • __vbaStrCat.MSVBVM60( CardID ,00000000), ref: 004BCA5E
      • __vbaStrMove.MSVBVM60 ref: 004BCA69
      • __vbaStrCat.MSVBVM60(?,00000000), ref: 004BCA74
      • __vbaStrMove.MSVBVM60 ref: 004BCA7F
      • __vbaStrCat.MSVBVM60( in ,00000000), ref: 004BCA8B
      • __vbaStrMove.MSVBVM60 ref: 004BCA96
      • __vbaStrI4.MSVBVM60(0000000A,00000000), ref: 004BCAA1
      • __vbaStrMove.MSVBVM60 ref: 004BCAAC
      • __vbaStrCat.MSVBVM60(00000000), ref: 004BCAB3
      • __vbaStrMove.MSVBVM60 ref: 004BCABE
      • __vbaFreeStrList.MSVBVM60(00000006,?,?,?,?,?,?,?), ref: 004BCAE7
      • __vbaStrCopy.MSVBVM60 ref: 004BCAFD
      • __vbaLateMemCall.MSVBVM60(?,disconnect,00000000), ref: 004BCB15
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004BCB2B
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004BCB47
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004BCB65
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BCB8E
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00474890,0000005C), ref: 004BCBC8
      • __vbaFreeObj.MSVBVM60 ref: 004BCBE3
      • __vbaStrMove.MSVBVM60 ref: 004BCBFA
      • __vbaStrCopy.MSVBVM60 ref: 004BCC08
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?), ref: 004BCC32
      • __vbaStrMove.MSVBVM60 ref: 004BCC4C
      • __vbaStrCopy.MSVBVM60 ref: 004BCC5A
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?), ref: 004BCC85
      • #685.MSVBVM60(?,?,?,?,00411816), ref: 004BCC95
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00411816), ref: 004BCCA0
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 004BCCC1
      • __vbaFreeStr.MSVBVM60(004BCD2A,?,?,?,?,00411816), ref: 004BCD1A
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 004BCD23
        • Part of subcall function 004D2C70: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,004A7331), ref: 004D2C8E
        • Part of subcall function 004D2C70: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D2CBE
        • Part of subcall function 004D2C70: #685.MSVBVM60(?,?,?,00000000,00411816), ref: 004D2CCB
        • Part of subcall function 004D2C70: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 004D2CD6
        • Part of subcall function 004D2C70: __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 004D2CEE
        • Part of subcall function 004D2C70: __vbaSetSystemError.MSVBVM60(?,?,?,00000000,00411816), ref: 004D2D03
        • Part of subcall function 004D2C70: __vbaSetSystemError.MSVBVM60(0000087C,0054D658,?,?,?,00000000,00411816), ref: 004D2D2A
        • Part of subcall function 004D2C70: #685.MSVBVM60(?,?,?,00000000,00411816), ref: 004D2D46
        • Part of subcall function 004D2C70: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 004D2D51
        • Part of subcall function 004D2C70: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004D2D84
        • Part of subcall function 004D2C70: __vbaFreeObj.MSVBVM60 ref: 004D2DA8
        • Part of subcall function 004D2C70: #685.MSVBVM60 ref: 004D2DCB
        • Part of subcall function 004D2C70: __vbaObjSet.MSVBVM60(?,00000000), ref: 004D2DD6
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$Error$#685List$Chkstk$CopySystem$#520CallLate$AddrefCheckConstructFixstrHresult$#716Ansi
      • String ID: CardID $ in $ is false$AloahaCredentialsdll.Provider$CardReaderWithI2c$FirstCard is: $Found I2c Card: $Found for User: $I2CS$SmartCardNumber$Splash$StackID is: $disconnect
      • API String ID: 316601251-1124518436
      • Opcode ID: 354a119ca8310ef90918f269b6173e736b913ab154d35cf9f4eacbe3b0ff264c
      • Instruction ID: 17bdf1e011723c5cd01b2597caae88ef8d9138b36573ed85175c1a84f1945115
      • Opcode Fuzzy Hash: 354a119ca8310ef90918f269b6173e736b913ab154d35cf9f4eacbe3b0ff264c
      • Instruction Fuzzy Hash: AD022A75900208EFDB04DFA0EE48BDEBBB9FF48305F108169F506A76A0DB745A45CB68
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 0052339E
      • __vbaOnError.MSVBVM60(000000FF,6D65285F,6D721D9E,6D6517CC,?,00411816), ref: 005233CE
      • __vbaSetSystemError.MSVBVM60(?,00000000,00000001), ref: 005233EC
      • #685.MSVBVM60(?,00000000,00000001), ref: 0052340F
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000001), ref: 0052341A
      • __vbaFreeObj.MSVBVM60(?,00000000,00000001), ref: 00523432
      • __vbaErrorOverflow.MSVBVM60(?,00000000,00000001), ref: 0052345D
      • __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 0052348E
      • __vbaStrCopy.MSVBVM60(?,00000000,?,?,00411816), ref: 005234BB
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 005234CA
      • #518.MSVBVM60(?,00004008), ref: 00523515
      • __vbaInStrVar.MSVBVM60(?,00000000,00000008,?,00000001), ref: 00523556
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 00523564
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0052357B
      • #518.MSVBVM60(?,00004008), ref: 005235D4
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Error$#518ChkstkFree$#685CopyListOverflowSystem
      • String ID: 8$<$Qh|GG$adodb$aloahapopup$cdo.$certinstaller$microsoft$msxml$scripting$true$winhttp$wscript$xml2csv$xmlhttp
      • API String ID: 2292410906-2525992247
      • Opcode ID: 4feea5b8cc2b4a284e519558808c6758656ec438384714f7b52e8e3010b32d99
      • Instruction ID: 9766edd9eb3996ccca7d33dab98fd766162e2851dd9909ec08af54ebe7e51b54
      • Opcode Fuzzy Hash: 4feea5b8cc2b4a284e519558808c6758656ec438384714f7b52e8e3010b32d99
      • Instruction Fuzzy Hash: 6552F7B1901258EADB50CF90DD48BDEBBB8FF04704F108699E149BB1A0EBB55B88CF55
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,004D556A), ref: 004D4E9E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D4ECE
      • __vbaStrCmp.MSVBVM60(00473D9C,007802FC,?,?,?,00000000,00411816), ref: 004D4EE6
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D4F00
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D4F1A
      • __vbaStrMove.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D4F2E
      • __vbaFreeStr.MSVBVM60(?,?,?,00000000,00411816), ref: 004D4F37
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,00000000,00411816), ref: 004D4F4D
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei\HH,HKLM\,?,?,?,00000000,00411816), ref: 004D4F6C
      • __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816), ref: 004D4F77
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000,?,?,?,00000000,00411816), ref: 004D4F83
      • __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816), ref: 004D4F8E
      • #520.MSVBVM60(?,00000008), ref: 004D4FAF
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D4FB9
      • __vbaStrMove.MSVBVM60 ref: 004D4FC4
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004D4FD4
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,00000000,00411816), ref: 004D4FE7
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D5000
      • __vbaStrCat.MSVBVM60(SOFTWARE\Polizei,HKLM\), ref: 004D501F
      • __vbaStrMove.MSVBVM60 ref: 004D502A
      • __vbaStrCat.MSVBVM60(\Logon\Standard\LogonDomain,00000000), ref: 004D5036
      • __vbaStrMove.MSVBVM60 ref: 004D5041
      • #520.MSVBVM60(?,00000008), ref: 004D5062
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D506C
      • __vbaStrMove.MSVBVM60 ref: 004D5077
      • #685.MSVBVM60(?,?,?,00000000,00411816), ref: 004D52DA
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 004D52E5
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 004D5306
      • __vbaFreeStr.MSVBVM60(004D5369,?,?,?,00000000,00411816), ref: 004D5359
      • __vbaFreeStr.MSVBVM60(?,?,?,00000000,00411816), ref: 004D5362
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Move$Free$#520CopyList$#685ChkstkError
      • String ID: $$4w$HKLM\$HKLM\SOFTWARE\Aloaha\RKK\Settings$HKLM\Software\Aloaha\RKK\StandardHive$SOFTWARE\Polizei$SOFTWARE\Polizei\HH$\Logon\Standard\LogonDomain$null
      • API String ID: 2309052633-4154475983
      • Opcode ID: 3598d41e47d2fe804a7bdd6dfc4e2779b6f03ab700c26e4934d4ee04ff925116
      • Instruction ID: 53908c96de9d9482387fcc2d48368804342b4ce569a7f890d608871c2705f88a
      • Opcode Fuzzy Hash: 3598d41e47d2fe804a7bdd6dfc4e2779b6f03ab700c26e4934d4ee04ff925116
      • Instruction Fuzzy Hash: 00F12871900209EBDB04DFA0EA58BDEBB78FF08705F10806AE506B76A0DB745A49CB58
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 0051967E
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816), ref: 005196AE
      • __vbaStrCopy.MSVBVM60(?,00000001,?,00000000,00411816), ref: 005196C3
      • __vbaFreeStr.MSVBVM60(?,?,00000001,?,00000000,00411816), ref: 005196D5
      • __vbaStrCmp.MSVBVM60(true,0077F574,?,00000001,?,00000000,00411816), ref: 005196EE
      • __vbaStrCopy.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0051970D
      • #685.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0051971A
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000001,?,00000000,00411816), ref: 00519725
      • __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00519746
      • __vbaLateMemCallLd.MSVBVM60(?,00000000,info,00000000), ref: 00519772
      • __vbaVarTstLt.MSVBVM60(?,00000000,00000001,?,00000000,00411816), ref: 00519780
      • __vbaFreeVar.MSVBVM60(?,00000000,00411816), ref: 0051978D
      • __vbaObjSetAddref.MSVBVM60(0054D334,00000000,?,00000000,00411816), ref: 005197A9
      • #685.MSVBVM60(?,00000000,00411816), ref: 005197BB
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00411816), ref: 005197C6
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 005197F9
      • __vbaFreeObj.MSVBVM60 ref: 00519826
      • __vbaObjSetAddref.MSVBVM60(0054D334,00000000), ref: 00519845
      • #685.MSVBVM60 ref: 00519852
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0051985D
      • __vbaFreeObj.MSVBVM60 ref: 0051987E
      • #685.MSVBVM60 ref: 0051988B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00519896
      • __vbaFreeObj.MSVBVM60 ref: 005198B7
      • __vbaChkstk.MSVBVM60 ref: 005198ED
      • __vbaLateMemSt.MSVBVM60(00000000,AnaCalled), ref: 00519916
      • #685.MSVBVM60 ref: 00519923
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0051992E
      • __vbaFreeObj.MSVBVM60 ref: 0051994F
      • __vbaLateMemCallLd.MSVBVM60(?,00000000,HighestLicenseCount,00000000), ref: 0051996E
      • __vbaI4Var.MSVBVM60(00000000,?,?,?,?,?,?,00000000,00411816), ref: 00519978
      • __vbaFreeVar.MSVBVM60(?,?,?,?,?,?,00000000,00411816), ref: 00519984
      • #685.MSVBVM60(?,?,?,?,?,?,00000000,00411816), ref: 005199A1
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 005199AC
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 005199DF
      • __vbaFreeObj.MSVBVM60 ref: 00519A0C
      • #685.MSVBVM60 ref: 00519A32
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00519A3D
      • __vbaFreeObj.MSVBVM60 ref: 00519A5E
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00519A77
      • __vbaI4Str.MSVBVM60(00000000), ref: 00519A92
      • __vbaI4Str.MSVBVM60(00000000), ref: 00519AAE
      • #685.MSVBVM60 ref: 00519AC4
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00519ACF
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00519B02
      • __vbaFreeObj.MSVBVM60 ref: 00519B2F
      • __vbaI4Str.MSVBVM60(00000000), ref: 00519B4E
      • #685.MSVBVM60 ref: 00519B5E
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00519B69
      • __vbaFreeObj.MSVBVM60 ref: 00519B8A
      • __vbaStrCopy.MSVBVM60 ref: 00519BA1
      • __vbaStrI4.MSVBVM60(?,highest license count: ,?,00000001,?,00000000,00411816), ref: 00519BC4
      • __vbaStrMove.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00519BCF
      • __vbaStrCat.MSVBVM60(00000000,?,00000001,?,00000000,00411816), ref: 00519BD6
      • __vbaStrMove.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00519BE1
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,00000001,?,00000000,00411816), ref: 00519BFA
      • #685.MSVBVM60(?,00000000,00411816), ref: 00519C0A
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00519C15
      • __vbaFreeObj.MSVBVM60(?,00000000,00411816), ref: 00519C36
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685$CheckCopyHresultLate$AddrefCallChkstkMove$ErrorList
      • String ID: )$AnaCalled$HighestLicenseCount$going to find highest license count$highest license count: $info$true
      • API String ID: 754081290-3881071883
      • Opcode ID: f7debca005518700aba3e27149140df188f5f3c446fa4977de6c84be161b36f0
      • Instruction ID: af87369607805730326605d3909c552a80991829f514a1ce16ada7f528050750
      • Opcode Fuzzy Hash: f7debca005518700aba3e27149140df188f5f3c446fa4977de6c84be161b36f0
      • Instruction Fuzzy Hash: 76023975D01208EFEB14DFA4DA48BDEBBB5FF48305F2081A9E506A72A0DB749A44DF14
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,?,00000001,00000000,00000000,00411816,004F38EA), ref: 0050CF5E
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,00000000,?,00411816,?), ref: 0050CF8E
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000001,00000000,?,00411816,?), ref: 0050CFA6
      • #685.MSVBVM60(?,00000001,00000000,?,00411816,?), ref: 0050CFE1
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,00000001,00000000,?,00411816,?), ref: 0050CFEC
      • __vbaFreeObj.MSVBVM60(?,00000001,00000000,?,00411816,?), ref: 0050D00D
      • __vbaStrCopy.MSVBVM60 ref: 0050D030
      • __vbaStrCopy.MSVBVM60 ref: 0050D03E
      • __vbaStrMove.MSVBVM60(00000001,?,0000000A), ref: 0050D05A
      • __vbaFreeStrList.MSVBVM60(00000002,00000001,?), ref: 0050D06A
      • __vbaFreeVar.MSVBVM60(00000000,?,00411816,?), ref: 0050D076
      • #685.MSVBVM60 ref: 0050D083
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050D08E
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050D0C1
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 0050D0E2
      • __vbaFreeObj.MSVBVM60 ref: 0050D104
      • __vbaStrCopy.MSVBVM60 ref: 0050D121
      • __vbaI4Str.MSVBVM60(?), ref: 0050D132
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,00000001,00000000,?,00411816,?), ref: 0050D14F
      • #685.MSVBVM60(?,?,00000001,00000000,?,00411816,?), ref: 0050D171
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,00000001,00000000,?,00411816,?), ref: 0050D17C
      • __vbaFreeObj.MSVBVM60(?,?,00000001,00000000,?,00411816,?), ref: 0050D19D
      • __vbaFileOpen.MSVBVM60(00000008,000000FF,00000001,c:\aloaha.log,?,?,00000001,00000000,?,00411816,?), ref: 0050D1D5
      • #685.MSVBVM60(?,?,00000001,00000000,?,00411816,?), ref: 0050D1E2
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,00000001,00000000,?,00411816,?), ref: 0050D1ED
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050D220
      • __vbaFreeObj.MSVBVM60 ref: 0050D24A
      • __vbaFileClose.MSVBVM60(00000001), ref: 0050D261
      • #685.MSVBVM60 ref: 0050D26E
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050D279
      • __vbaFreeObj.MSVBVM60 ref: 0050D29A
      • __vbaFileOpen.MSVBVM60(00000008,000000FF,00000001,d:\aloaha.log), ref: 0050D2B2
      • #685.MSVBVM60 ref: 0050D2BF
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050D2CA
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050D2FD
      • __vbaFreeObj.MSVBVM60 ref: 0050D327
      • __vbaFileClose.MSVBVM60(00000001), ref: 0050D33E
      • #685.MSVBVM60 ref: 0050D34B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050D356
      • __vbaFreeObj.MSVBVM60 ref: 0050D377
      • __vbaFileOpen.MSVBVM60(00000008,000000FF,00000001,e:\aloaha.log), ref: 0050D38F
      • #685.MSVBVM60 ref: 0050D39C
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050D3A7
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050D3DA
      • __vbaFreeObj.MSVBVM60 ref: 0050D404
      • #712.MSVBVM60(?,0047C158,00473D9C,00000001,000000FF,00000000), ref: 0050D433
      • #520.MSVBVM60(?,00000008,?,0047C158,00473D9C,00000001,000000FF,00000000), ref: 0050D44B
      • __vbaStrVarMove.MSVBVM60(?,?,0047C158,00473D9C,00000001,000000FF,00000000), ref: 0050D455
      • __vbaStrMove.MSVBVM60(?,0047C158,00473D9C,00000001,000000FF,00000000), ref: 0050D460
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?,?,0047C158,00473D9C,00000001,000000FF,00000000), ref: 0050D470
      • __vbaPrintFile.MSVBVM60(00484480,00000001,?,00000000,?,00411816,?), ref: 0050D48D
      • __vbaFileClose.MSVBVM60(00000001), ref: 0050D49F
      • #685.MSVBVM60(?,?,?,?,?,00411816,?), ref: 0050D4AC
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050D4B7
      • __vbaFreeObj.MSVBVM60(?,?,?,?,?,00411816,?), ref: 0050D4D8
      • #685.MSVBVM60(?,00000001,00000000,?,00411816,?), ref: 0050D4E5
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,00000001,00000000,?,00411816,?), ref: 0050D4F0
      • __vbaFreeObj.MSVBVM60(?,00000001,00000000,?,00411816,?), ref: 0050D511
      • __vbaFreeStr.MSVBVM60(0050D558,?,00000001,00000000,?,00411816,?), ref: 0050D551
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685$File$CheckHresult$CloseCopyMoveOpen$List$#520#712ChkstkErrorPrint
      • String ID: $$Software\Aloaha\pdf$c:\aloaha.log$clog$d:\aloaha.log$e:\aloaha.log
      • API String ID: 504476220-1490951336
      • Opcode ID: 16488c1b217ba50f9db8ce51de278bf525abf4c0f0c4292a9f0746d90d485f0e
      • Instruction ID: aaf877663dc4545fba403a8b3a3959a0b6ab3d3627320e85fe1798df9a22910a
      • Opcode Fuzzy Hash: 16488c1b217ba50f9db8ce51de278bf525abf4c0f0c4292a9f0746d90d485f0e
      • Instruction Fuzzy Hash: B2020475900318EFDB14DFA0DE48BDEBBB4BF48705F108169E50AAB2A0DBB45A44DF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,?,00000001,?,?,00411816), ref: 0053F3EE
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,?,?,00411816), ref: 0053F41E
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0053F4BF
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0053F4D9
      • _adj_fdiv_m64.MSVBVM60 ref: 0053F53C
      • __vbaR8FixI4.MSVBVM60 ref: 0053F54B
      • #607.MSVBVM60(?,00000001,00000003), ref: 0053F5A9
      • __vbaVarAdd.MSVBVM60(?,?,00000008), ref: 0053F5BE
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0053F5C5
      • __vbaStrMove.MSVBVM60 ref: 0053F5D0
      • __vbaFreeVarList.MSVBVM60(00000003,00000003,?,?), ref: 0053F5E4
      • #607.MSVBVM60(?,00000001,00000003), ref: 0053F643
      • __vbaVarAdd.MSVBVM60(?,?,00000008), ref: 0053F658
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0053F65F
      • __vbaStrMove.MSVBVM60 ref: 0053F66A
      • __vbaFreeVarList.MSVBVM60(00000003,00000003,?,?), ref: 0053F67E
      • #607.MSVBVM60(?,00000001,00000002), ref: 0053F6FE
      • __vbaVarAdd.MSVBVM60(?,?,00000008), ref: 0053F713
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0053F71A
      • __vbaStrMove.MSVBVM60 ref: 0053F725
      • __vbaFreeVarList.MSVBVM60(00000003,00000002,?,?), ref: 0053F739
      • #607.MSVBVM60(?,00000001,00000002), ref: 0053F7A1
      • __vbaVarAdd.MSVBVM60(?,?,00000008), ref: 0053F7B6
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0053F7BD
      • __vbaStrMove.MSVBVM60 ref: 0053F7C8
      • __vbaFreeVarList.MSVBVM60(00000003,00000002,?,?), ref: 0053F7DC
      • __vbaStrCat.MSVBVM60(00477FFC,?), ref: 0053F7F5
      • __vbaStrMove.MSVBVM60 ref: 0053F800
      • __vbaStrCopy.MSVBVM60 ref: 0053F81F
      • #685.MSVBVM60 ref: 0053F82C
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0053F837
      • __vbaFreeObj.MSVBVM60 ref: 0053F858
      • __vbaFreeStr.MSVBVM60(0053F8A4), ref: 0053F89D
      • __vbaErrorOverflow.MSVBVM60(?,00000001,?,?,00411816), ref: 0053F8BF
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 0053F8EE
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,?,?,00411816), ref: 0053F91E
      • __vbaStrCopy.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0053F958
      • #685.MSVBVM60(?,00000001,?,00000000,00411816), ref: 005445BB
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 005445C9
      • __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 005445ED
      • __vbaFreeObj.MSVBVM60(005447C9), ref: 005446F0
      • __vbaAryDestruct.MSVBVM60(004741C8,?), ref: 00544702
      • __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0054470B
      • __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544714
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0054471D
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544726
      • __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0054472F
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544738
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544741
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0054474A
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544753
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0054475C
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544765
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 0054476E
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544777
      • __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544780
      • __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544789
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00544792
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$Error$#607List$#685BoundsChkstkCopyGenerate$DestructOverflow_adj_fdiv_m64
      • String ID:
      • API String ID: 3471061930-0
      • Opcode ID: 90955c64f4c339ff3a23cfb0b7edb520c12bf5ea6736a6b0f075adc3aa2ba04b
      • Instruction ID: 3ea0dd90c2d85410f175e6fa0dda96c02a9998031f539c8c8f7562fb50ff3f92
      • Opcode Fuzzy Hash: 90955c64f4c339ff3a23cfb0b7edb520c12bf5ea6736a6b0f075adc3aa2ba04b
      • Instruction Fuzzy Hash: 86022675C00209EFEB04DFA0DA48BDDBBB4FF04305F1081A9E516A76A0DB746A89CF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,004B1BE8), ref: 0052D4DE
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816,004B1BE8), ref: 0052D50E
      • __vbaStrCmp.MSVBVM60(00473D9C,00772F2C,?,?,?,?,00411816,004B1BE8), ref: 0052D526
      • __vbaStrCmp.MSVBVM60(null,00772F2C,?,?,?,?,00411816,004B1BE8), ref: 0052D53F
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816,004B1BE8), ref: 0052D560
      • __vbaStrMove.MSVBVM60(?,?,?,?,00411816,004B1BE8), ref: 0052D57C
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001,?,?,?,?,00411816,004B1BE8), ref: 0052D596
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816,004B1BE8), ref: 0052D5AF
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00411816,004B1BE8), ref: 0052D5C5
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816,004B1BE8), ref: 0052D5DE
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816,004B1BE8), ref: 0052D5F1
      • #685.MSVBVM60(?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D916
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D921
      • __vbaFreeObj.MSVBVM60(?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D942
      • __vbaFreeStr.MSVBVM60(0052D9B8,?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D99F
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D9A8
      • __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,00411816,004B1BE8), ref: 0052D9B1
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$CopyFree$#685ChkstkErrorMove
      • String ID: ,/w$USERDOMAIN$USERNAME$null
      • API String ID: 3359174267-1620325221
      • Opcode ID: 30da333b105c3e64b37d43671934e97d0b4f9fc030355e0cc7228c5563f0cf97
      • Instruction ID: e0f11b7ed9490c396aeee1661230520942dcf7ca1f18e7877b83b4eb6f909733
      • Opcode Fuzzy Hash: 30da333b105c3e64b37d43671934e97d0b4f9fc030355e0cc7228c5563f0cf97
      • Instruction Fuzzy Hash: B0D11776900209DBDB14DFA0DE48BDEBBB8FB08305F1085A9E606B71A0DB745B49CF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(0040B120,00411816,?,?,00000000,00000000,?,00411816), ref: 00506D0E
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,0040B120,00411816), ref: 00506D3B
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,0040B120,00411816), ref: 00506D4A
      • __vbaStrCat.MSVBVM60(.lock,00000000,?,00000000,00000000,0040B120,00411816), ref: 00506D60
      • __vbaStrMove.MSVBVM60(?,00000000,00000000,0040B120,00411816), ref: 00506D6B
      • #645.MSVBVM60(00004008,00000000), ref: 00506D8B
      • __vbaStrMove.MSVBVM60 ref: 00506D96
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00506DA2
      • __vbaFreeStr.MSVBVM60 ref: 00506DB7
      • #685.MSVBVM60 ref: 00506DD0
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00506DDB
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00506E0E
      • __vbaFreeObj.MSVBVM60 ref: 00506E32
      • #685.MSVBVM60 ref: 00506E84
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00506E8F
      • __vbaFreeObj.MSVBVM60 ref: 00506EA7
      • #645.MSVBVM60(00004008,00000000), ref: 00506EC7
      • __vbaStrMove.MSVBVM60 ref: 00506ED2
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00506EDE
      • __vbaFreeStr.MSVBVM60 ref: 00506EF3
      • #685.MSVBVM60 ref: 00506F0C
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00506F17
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 00506F4A
      • __vbaFreeObj.MSVBVM60 ref: 00506F6E
      • __vbaSetSystemError.MSVBVM60(00000064), ref: 00506F8E
      • #598.MSVBVM60 ref: 00506F9B
      • #685.MSVBVM60 ref: 00507162
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050716D
      • __vbaFreeObj.MSVBVM60 ref: 0050718E
      • __vbaFreeStr.MSVBVM60(005071C1), ref: 005071B1
      • __vbaFreeStr.MSVBVM60 ref: 005071BA
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685$Move$#645CheckErrorHresult$#598ChkstkCopySystem
      • String ID: .lock$Z$d
      • API String ID: 3495278122-3276679207
      • Opcode ID: cb18210faf9e05ff2e9ba7645b02ec4141777525903ea09fa90143d99de494aa
      • Instruction ID: ba1c5f1086975590c743d684263368a958f03391c478e0a4182efd6bfb00136f
      • Opcode Fuzzy Hash: cb18210faf9e05ff2e9ba7645b02ec4141777525903ea09fa90143d99de494aa
      • Instruction Fuzzy Hash: EBE1E475D00209EFDB14DFA0DA48BEEBBB4BF08706F208569E506B72A0DB745A49CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,00546B91,?,?,?,00000000,00411816,00546A11), ref: 0054A73E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,00546B91), ref: 0054A76E
      • #520.MSVBVM60(?,00004008), ref: 0054A7A7
      • #518.MSVBVM60(?,00004008), ref: 0054A7E0
      • #520.MSVBVM60(?,?), ref: 0054A7EE
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?), ref: 0054A817
      • __vbaVarCmpEq.MSVBVM60(?,00008008,?,00000000), ref: 0054A830
      • __vbaVarOr.MSVBVM60(?,00000000), ref: 0054A83E
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 0054A845
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 0054A860
      • __vbaStrCopy.MSVBVM60 ref: 0054A887
      • __vbaStrMove.MSVBVM60(?), ref: 0054A89D
      • __vbaFreeStr.MSVBVM60 ref: 0054A8A6
      • __vbaInStr.MSVBVM60(00000000,0047BCF8,0075AB4C,00000001), ref: 0054A8C2
      • __vbaStrCopy.MSVBVM60 ref: 0054A8DD
        • Part of subcall function 005088A0: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,0054A98F,?,?), ref: 005088BE
        • Part of subcall function 005088A0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,?,00411816), ref: 005088EE
        • Part of subcall function 005088A0: __vbaStrCat.MSVBVM60(.lock,?,?,00000001,?,?,00411816), ref: 00508906
        • Part of subcall function 005088A0: __vbaStrMove.MSVBVM60(?,?,00000001,?,?,00411816), ref: 00508911
        • Part of subcall function 005088A0: __vbaStrCmp.MSVBVM60(true,007C07AC,00000000,?,?,00000001,?,?,00411816), ref: 0050893C
        • Part of subcall function 005088A0: __vbaStrCmp.MSVBVM60(true,007C07AC), ref: 005089A2
        • Part of subcall function 005088A0: __vbaSetSystemError.MSVBVM60(00000064), ref: 005089BA
        • Part of subcall function 005088A0: #598.MSVBVM60 ref: 005089C7
        • Part of subcall function 005088A0: __vbaStrCopy.MSVBVM60 ref: 005089F6
        • Part of subcall function 005088A0: #685.MSVBVM60 ref: 00508A03
        • Part of subcall function 005088A0: __vbaObjSet.MSVBVM60(?,00000000), ref: 00508A0E
        • Part of subcall function 005088A0: __vbaFreeObj.MSVBVM60 ref: 00508A2F
        • Part of subcall function 005088A0: #645.MSVBVM60(00004008,00000000), ref: 00508A55
        • Part of subcall function 005088A0: __vbaStrMove.MSVBVM60 ref: 00508A60
        • Part of subcall function 005088A0: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 00508A6C
      • __vbaStrCmp.MSVBVM60(00473D9C,0075AB4C), ref: 0054A8F6
      • __vbaStrCopy.MSVBVM60 ref: 0054A911
      • __vbaStrCmp.MSVBVM60(00473D9C,0075AB4C), ref: 0054A92A
      • __vbaInStr.MSVBVM60(00000000,0047BCF8,0075AB4C,00000001), ref: 0054A946
      • __vbaStrMove.MSVBVM60 ref: 0054A96E
      • __vbaStrCopy.MSVBVM60 ref: 0054A97C
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 0054A999
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,00411816,00546B91), ref: 0054A9B3
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,00411816,00546B91), ref: 0054A9C1
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?,?,?,?,?,00411816,00546B91), ref: 0054A9DE
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,00411816,00546B91), ref: 0054A9F8
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,00411816,00546B91), ref: 0054AA06
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816,00546B91), ref: 0054AA23
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00411816,00546B91), ref: 0054AA3D
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00411816,00546B91), ref: 0054AA4B
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 0054AA68
        • Part of subcall function 00510480: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,0049F35F,?,?,?,?,?,?,00411816), ref: 0051049E
        • Part of subcall function 00510480: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 005104CE
        • Part of subcall function 00510480: __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,?,?,00000000,00411816), ref: 005104E6
        • Part of subcall function 00510480: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 00510500
        • Part of subcall function 00510480: #685.MSVBVM60(?,?,?,00000000,00411816), ref: 0051076C
        • Part of subcall function 00510480: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 00510777
        • Part of subcall function 00510480: __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 00510798
        • Part of subcall function 00510480: __vbaFreeStr.MSVBVM60(005107F1,?,?,?,00000000,00411816), ref: 005107E1
        • Part of subcall function 00510480: __vbaFreeStr.MSVBVM60(?,?,?,00000000,00411816), ref: 005107EA
      • __vbaStrMove.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 0054AA82
      • __vbaStrCopy.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 0054AA90
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 0054AAAD
        • Part of subcall function 00510480: __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816), ref: 0051051C
        • Part of subcall function 00510480: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,00000000,00411816), ref: 00510532
        • Part of subcall function 00510480: __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816), ref: 0051054D
        • Part of subcall function 00510480: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,00000000,00411816), ref: 00510563
        • Part of subcall function 00510480: __vbaNew2.MSVBVM60(00477E14,0054ED28,?,?,?,00000000,00411816), ref: 0051058B
        • Part of subcall function 00510480: __vbaHresultCheckObj.MSVBVM60(00000000,?,00477E04,00000014), ref: 005105DC
        • Part of subcall function 00510480: __vbaHresultCheckObj.MSVBVM60(00000000,?,0047A994,00000050), ref: 0051062D
        • Part of subcall function 00510480: __vbaStrMove.MSVBVM60 ref: 0051065E
        • Part of subcall function 00510480: __vbaFreeObj.MSVBVM60 ref: 00510667
        • Part of subcall function 00510480: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,00000000,00411816), ref: 0051067D
      • __vbaStrMove.MSVBVM60 ref: 0054AAC7
      • __vbaStrCopy.MSVBVM60 ref: 0054AAD5
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?), ref: 0054AAF2
      • __vbaStrCmp.MSVBVM60(00473D9C,0075AB4C), ref: 0054AB0E
      • __vbaInStr.MSVBVM60(00000000,0047BCF8,0075AB4C,00000001), ref: 0054AB2A
      • #685.MSVBVM60 ref: 0054AB51
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0054AB5C
      • __vbaFreeObj.MSVBVM60 ref: 0054AB7D
      • __vbaFreeStr.MSVBVM60(0054ABDA), ref: 0054ABD3
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$Copy$List$Error$#685Chkstk$#520CheckHresult$#518#598#645BoolNew2NullSystem
      • String ID: Certificates$CertificatesCtype$FingerPrints$Global$HKLM\Software\Aloaha\csp\plugin$LastReaderNames$Reader$null
      • API String ID: 1277236490-3177415632
      • Opcode ID: c06f29fe32006f1bff200080b6da762bbfb209beeff0fbbc10078cd7e937160e
      • Instruction ID: 1433fe4c36b94c09f2db299f276f5d3647102819e8d5d13ae204a24ada6f5ada
      • Opcode Fuzzy Hash: c06f29fe32006f1bff200080b6da762bbfb209beeff0fbbc10078cd7e937160e
      • Instruction Fuzzy Hash: 57C13B76900209ABDB14DFA0DE48BEEBB78FF48705F10C169E606B65A0DB745A08DF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,?,00000000,00000000,?,00411816), ref: 004BD22E
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004BD25B
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,?,00411816), ref: 004BD26A
      • #685.MSVBVM60(?,?,00000000,00000000,?,00411816), ref: 004BD29C
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,?,00411816), ref: 004BD2A7
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004BD2BF
      • #645.MSVBVM60(00004008,00000000), ref: 004BD2DF
      • __vbaStrMove.MSVBVM60 ref: 004BD2EA
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004BD2F6
      • __vbaFreeStr.MSVBVM60 ref: 004BD30B
      • #685.MSVBVM60 ref: 004BD324
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BD32F
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004BD362
      • __vbaFreeObj.MSVBVM60 ref: 004BD386
      • #529.MSVBVM60(00004008), ref: 004BD3AC
      • #685.MSVBVM60 ref: 004BD3B9
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BD3C4
      • __vbaFreeObj.MSVBVM60 ref: 004BD3DC
      • #685.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004BD3E9
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,?,00411816), ref: 004BD3F4
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004BD415
      • #645.MSVBVM60(00004008,00000000), ref: 004BD449
      • __vbaStrMove.MSVBVM60 ref: 004BD454
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004BD460
      • __vbaFreeStr.MSVBVM60 ref: 004BD475
      • #685.MSVBVM60 ref: 004BD48E
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BD499
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004BD4CC
      • __vbaFreeObj.MSVBVM60 ref: 004BD4F6
      • __vbaFreeStr.MSVBVM60(004BD702), ref: 004BD6FB
        • Part of subcall function 004C2E80: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,00000000,00000000,?,00411816), ref: 004C2E9E
        • Part of subcall function 004C2E80: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816,?), ref: 004C2ECE
        • Part of subcall function 004C2E80: __vbaStrCmp.MSVBVM60(00473D9C,?,?,00000000,00000000,00000000,00411816,?), ref: 004C2EE6
        • Part of subcall function 004C2E80: #518.MSVBVM60(?,00004008), ref: 004C2F17
        • Part of subcall function 004C2E80: __vbaVarCmpNe.MSVBVM60(?,00008008,?,0000000B), ref: 004C2F3E
        • Part of subcall function 004C2E80: __vbaVarAnd.MSVBVM60(?,00000000), ref: 004C2F49
        • Part of subcall function 004C2E80: __vbaBoolVarNull.MSVBVM60(00000000), ref: 004C2F50
        • Part of subcall function 004C2E80: __vbaFreeVarList.MSVBVM60(00000002,?,0000000B), ref: 004C2F6A
        • Part of subcall function 004C2E80: __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001,00000000,00000000,00411816,?), ref: 004C2F98
        • Part of subcall function 004C2E80: #685.MSVBVM60(?,00000001,00000000,00000000,00411816,?), ref: 004C2FAD
        • Part of subcall function 004C2E80: __vbaObjSet.MSVBVM60(00000001,00000000,?,00000001,00000000,00000000,00411816,?), ref: 004C2FB8
        • Part of subcall function 004C2E80: __vbaFreeObj.MSVBVM60(?,00000001,00000000,00000000,00411816,?), ref: 004C2FD9
        • Part of subcall function 004C2E80: __vbaChkstk.MSVBVM60 ref: 004C3006
      • #685.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004BD510
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,?,00411816), ref: 004BD51B
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004BD53C
      • __vbaLenBstr.MSVBVM60(?,?,00000000,00000000,?,00411816), ref: 004BD54D
      • __vbaStrToAnsi.MSVBVM60(00000000,00000000,C0000000,00000000,00000000,00000004,00000080,00000000,?,00000000,00000000,?,00411816), ref: 004BD579
      • __vbaSetSystemError.MSVBVM60(00000000,?,00000000,00000000,?,00411816), ref: 004BD588
      • __vbaStrToUnicode.MSVBVM60(?,?,?,00000000,00000000,?,00411816), ref: 004BD596
      • __vbaFreeStr.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004BD5A5
      • __vbaStrToAnsi.MSVBVM60(?,?,?,00000000,00000000), ref: 004BD5D5
      • __vbaSetSystemError.MSVBVM60(000000FF,00000000), ref: 004BD5E8
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 004BD5F6
      • __vbaFreeStr.MSVBVM60 ref: 004BD610
      • __vbaSetSystemError.MSVBVM60(000000FF), ref: 004BD636
      • __vbaSetSystemError.MSVBVM60(000000FF), ref: 004BD655
      • __vbaSetSystemError.MSVBVM60(000000FF), ref: 004BD673
      • __vbaSetSystemError.MSVBVM60(000000FF), ref: 004BD689
      • #685.MSVBVM60 ref: 004BD6AC
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BD6B7
      • __vbaFreeObj.MSVBVM60 ref: 004BD6D8
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685Error$System$Chkstk$#645AnsiCheckHresultMoveUnicode$#518#529BoolBstrCopyListNull
      • String ID: $
      • API String ID: 1614413082-3993045852
      • Opcode ID: 8291f8f37f810a4de2e6f2d0b1704e329a57b79a631b40e38a7507e30da4c21c
      • Instruction ID: e4b8471c3a8923e26fae9ac223887bf74711bf0fd3675cffb62b20b0176dfe29
      • Opcode Fuzzy Hash: 8291f8f37f810a4de2e6f2d0b1704e329a57b79a631b40e38a7507e30da4c21c
      • Instruction Fuzzy Hash: BAE10775D00208EFDB14DFE0DA88BDEBBB4BF08705F108169E506AB2A4DB789A45DF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,0052EC3F), ref: 0052D9EE
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 0052DA1E
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DA33
      • __vbaStrCmp.MSVBVM60(true,0077F204,?,00000000,?,00000000,00411816), ref: 0052DA4B
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DA6A
      • __vbaStrCmp.MSVBVM60(00473D9C,0077F1DC,?,00000000,?,00000000,00411816), ref: 0052DA83
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DA9D
      • __vbaStrCmp.MSVBVM60(true,0077F40C,?,00000000,?,00000000,00411816), ref: 0052DABB
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DAD4
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DAEB
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DB02
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DB17
      • __vbaStrMove.MSVBVM60(?,?,00000000,?,00000000,00411816), ref: 0052DB2B
      • __vbaFreeStr.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DB34
      • #520.MSVBVM60(?,00004008), ref: 0052DB56
      • __vbaStrVarMove.MSVBVM60(?), ref: 0052DB60
      • __vbaStrMove.MSVBVM60 ref: 0052DB6B
      • __vbaFreeVar.MSVBVM60 ref: 0052DB74
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 0052DB8A
      • #619.MSVBVM60(?,00004008,00000001), ref: 0052DBB6
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0052DBD2
      • __vbaFreeVar.MSVBVM60 ref: 0052DBDF
      • __vbaStrCat.MSVBVM60(004775E8,?), ref: 0052DBFD
      • __vbaStrMove.MSVBVM60 ref: 0052DC08
      • #531.MSVBVM60(?), ref: 0052DC19
      • #619.MSVBVM60(?,00004008,00000001), ref: 0052DC3D
      • __vbaStrCopy.MSVBVM60(?,00000000,00411816), ref: 0052DD8D
      • #685.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DD9A
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,?,00000000,00411816), ref: 0052DDA5
      • __vbaFreeObj.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0052DDC6
      • __vbaFreeStr.MSVBVM60(0052DE20,?,00000000,?,00000000,00411816), ref: 0052DE19
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Copy$Free$Move$#619$#520#531#685ChkstkError
      • String ID: "$HKLM\Software\Aloaha\AlternativeWritePath$HKLM\Software\Aloaha\debugpath$true
      • API String ID: 3829872818-957309409
      • Opcode ID: 6b9f38b4ee14996dc19849ed08e803a19db7f2785aadd7f0e602cb1959fa560d
      • Instruction ID: a74e74d8edba39e26f7f793e021303dc174187127ba658051d712e29c9120581
      • Opcode Fuzzy Hash: 6b9f38b4ee14996dc19849ed08e803a19db7f2785aadd7f0e602cb1959fa560d
      • Instruction Fuzzy Hash: B5C129B5900208DFEB04DFA0DA58ADDBBB4FF48705F20806DE506B76A0DB759A09DF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,00000001), ref: 0050CA7E
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,00000000,00000000,00411816,00000001), ref: 0050CAAE
      • __vbaStrCopy.MSVBVM60(?,00000001,00000000,00000000,00411816,00000001), ref: 0050CAC3
      • #685.MSVBVM60(?,00000001,00000000,00000000,00411816,00000001), ref: 0050CAD0
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000001,00000000,00000000,00411816,00000001), ref: 0050CADB
      • __vbaFreeObj.MSVBVM60(?,00000001,00000000,00000000,00411816,00000001), ref: 0050CAFC
      • __vbaVarForInit.MSVBVM60(?,?,?,00000002,00000002,00000002), ref: 0050CB79
      • __vbaI4Var.MSVBVM60(?), ref: 0050CBA3
      • #608.MSVBVM60(?,00000000), ref: 0050CBAE
      • __vbaVarAdd.MSVBVM60(?,?,00000008), ref: 0050CBD4
      • __vbaVarAdd.MSVBVM60(?,00000008,00000000), ref: 0050CBE6
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0050CBED
      • __vbaStrMove.MSVBVM60 ref: 0050CBF8
      • __vbaFreeStr.MSVBVM60(?), ref: 0050CC0A
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 0050CC1E
      • #685.MSVBVM60(00000001,00000000,00000000,00411816,00000001), ref: 0050CC2E
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050CC39
      • __vbaFreeObj.MSVBVM60 ref: 0050CC5A
      • __vbaI4Var.MSVBVM60(?), ref: 0050CC6B
      • #608.MSVBVM60(?,00000000), ref: 0050CC76
      • __vbaVarAdd.MSVBVM60(?,00000008,?,00000000), ref: 0050CC98
      • #645.MSVBVM60(00000000), ref: 0050CC9F
      • __vbaStrMove.MSVBVM60 ref: 0050CCAA
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0050CCBA
      • #685.MSVBVM60 ref: 0050CCDA
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050CCE5
      • __vbaI4Var.MSVBVM60(?), ref: 0050CDF9
      • #608.MSVBVM60(?,00000000), ref: 0050CE04
      • __vbaVarAdd.MSVBVM60(?,?,00000008), ref: 0050CE2A
      • __vbaVarAdd.MSVBVM60(?,00000008,00000000), ref: 0050CE3C
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0050CE43
      • __vbaStrMove.MSVBVM60 ref: 0050CE4E
        • Part of subcall function 0050CF40: __vbaChkstk.MSVBVM60(?,00411816,?,?,00000001,00000000,00000000,00411816,004F38EA), ref: 0050CF5E
        • Part of subcall function 0050CF40: __vbaOnError.MSVBVM60(000000FF,?,00000001,00000000,?,00411816,?), ref: 0050CF8E
        • Part of subcall function 0050CF40: __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000001,00000000,?,00411816,?), ref: 0050CFA6
        • Part of subcall function 0050CF40: #685.MSVBVM60(?,00000001,00000000,?,00411816,?), ref: 0050CFE1
        • Part of subcall function 0050CF40: __vbaObjSet.MSVBVM60(00000000,00000000,?,00000001,00000000,?,00411816,?), ref: 0050CFEC
        • Part of subcall function 0050CF40: __vbaFreeObj.MSVBVM60(?,00000001,00000000,?,00411816,?), ref: 0050D00D
        • Part of subcall function 0050CF40: __vbaStrCopy.MSVBVM60 ref: 0050D030
        • Part of subcall function 0050CF40: __vbaStrCopy.MSVBVM60 ref: 0050D03E
        • Part of subcall function 0050CF40: __vbaStrMove.MSVBVM60(00000001,?,0000000A), ref: 0050D05A
        • Part of subcall function 0050CF40: __vbaFreeStrList.MSVBVM60(00000002,00000001,?), ref: 0050D06A
        • Part of subcall function 0050CF40: __vbaFreeVar.MSVBVM60(00000000,?,00411816,?), ref: 0050D076
        • Part of subcall function 0050CF40: #685.MSVBVM60 ref: 0050D083
        • Part of subcall function 0050CF40: __vbaObjSet.MSVBVM60(?,00000000), ref: 0050D08E
        • Part of subcall function 0050CF40: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050D0C1
      • __vbaFreeStr.MSVBVM60(?), ref: 0050CE60
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 0050CE74
      • #685.MSVBVM60(?,00000001,00000000,00000000,00411816,00000001), ref: 0050CE95
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000001,00000000,00000000,00411816,00000001), ref: 0050CEA0
      • __vbaFreeObj.MSVBVM60(?,00000001,00000000,00000000,00411816,00000001), ref: 0050CEC1
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,0050CF24,?,00000001,00000000,00000000,00411816,00000001), ref: 0050CF08
      • __vbaFreeVar.MSVBVM60(?,00000000,00411816,00000001), ref: 0050CF14
      • __vbaFreeStr.MSVBVM60(?,00000000,00411816,00000001), ref: 0050CF1D
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685Move$List$#608Copy$ChkstkError$#645CheckHresultInit
      • String ID: C$Z$entering shall I use dir: $finished shall I use dir:
      • API String ID: 3837349526-861938115
      • Opcode ID: 09d17ff9a77a12cd107801166099c7e75e8189dd3ea97f2ae8b072260c26a258
      • Instruction ID: 55064201913ea73bc20bb8d54a6b8259368488e536aec993fd1c1447cb530e09
      • Opcode Fuzzy Hash: 09d17ff9a77a12cd107801166099c7e75e8189dd3ea97f2ae8b072260c26a258
      • Instruction Fuzzy Hash: 72D119B5800218EFDB14DFA0DD48BEEBBB8BF48305F1085ADE506A75A0DBB45A48DF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0051F17E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 0051F1AE
      • __vbaStrCmp.MSVBVM60(true,0075A9E4), ref: 0051F1E0
      • __vbaStrCmp.MSVBVM60(false,0075A9E4), ref: 0051F1FA
      • __vbaStrCmp.MSVBVM60(true,0076557C), ref: 0051F287
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$ChkstkError
      • String ID: (T$B$Software\Aloaha$WinPE$bootmgr$false$true$winpe$|Uv
      • API String ID: 3554142864-978549697
      • Opcode ID: d08cc315d5142a3f7bf6893785e4d19295f43eacd448125daa7062d6958a89a4
      • Instruction ID: dc65e333dcd0516c2a213a2d112c6aa7bfe93a3a98688c474067f05a980d6c2b
      • Opcode Fuzzy Hash: d08cc315d5142a3f7bf6893785e4d19295f43eacd448125daa7062d6958a89a4
      • Instruction Fuzzy Hash: 8ED13974901208DFEB14DFA0DA48BEDBBB4FF48705F1081A9E506BB2A0DBB45A45DF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004D2E4E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004D2E7E
      • #685.MSVBVM60(?,?,?,?,00411816), ref: 004D2E8B
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00411816), ref: 004D2E96
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 004D2EB7
      • __vbaSetSystemError.MSVBVM60(?,?,?,?,00411816), ref: 004D2ECF
      • __vbaSetSystemError.MSVBVM60(0000087C,0054D658,?,?,?,?,00411816), ref: 004D2EF9
      • __vbaSetSystemError.MSVBVM60(00000000,00000001,0000000E,?,?,?,?,?,?,00411816), ref: 004D2F24
      • #685.MSVBVM60(?,?,?,?,00411816), ref: 004D2F3A
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00411816), ref: 004D2F45
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004D2F90
      • __vbaFreeObj.MSVBVM60 ref: 004D2FD0
      • __vbaSetSystemError.MSVBVM60(?,?,?), ref: 004D300A
      • __vbaSetSystemError.MSVBVM60(?), ref: 004D3020
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D304C
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D3077
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D30A2
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004D30CD
      • __vbaStrUI1.MSVBVM60(?), ref: 004D30E4
      • __vbaStrMove.MSVBVM60 ref: 004D30EF
      • __vbaStrCat.MSVBVM60(0047BCF8,00000000), ref: 004D30FB
      • __vbaStrMove.MSVBVM60 ref: 004D3106
      • __vbaStrUI1.MSVBVM60(?,00000000), ref: 004D3118
      • __vbaStrMove.MSVBVM60 ref: 004D3123
      • __vbaStrCat.MSVBVM60(00000000), ref: 004D312A
      • __vbaStrMove.MSVBVM60 ref: 004D3135
      • __vbaStrCat.MSVBVM60(0047BCF8,00000000), ref: 004D3141
      • __vbaStrMove.MSVBVM60 ref: 004D314C
      • __vbaStrUI1.MSVBVM60(?,00000000), ref: 004D315E
      • __vbaStrMove.MSVBVM60 ref: 004D3169
      • __vbaStrCat.MSVBVM60(00000000), ref: 004D3170
      • __vbaStrMove.MSVBVM60 ref: 004D317B
      • __vbaStrCat.MSVBVM60(0047BCF8,00000000), ref: 004D3187
      • __vbaStrMove.MSVBVM60 ref: 004D3192
      • __vbaStrUI1.MSVBVM60(?,00000000), ref: 004D31A4
      • __vbaStrMove.MSVBVM60 ref: 004D31AF
      • __vbaStrCat.MSVBVM60(00000000), ref: 004D31B6
      • #520.MSVBVM60(?,00000008), ref: 004D31D7
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D31E4
      • __vbaStrMove.MSVBVM60 ref: 004D31EF
      • __vbaFreeStrList.MSVBVM60(00000009,?,?,?,?,?,?,?,?,?), ref: 004D321B
      • __vbaFreeVarList.MSVBVM60(00000002,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004D3234
      • #685.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004D325B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004D3266
      • __vbaFreeObj.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00411816), ref: 004D3287
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Move$Error$FreeSystem$BoundsGenerate$#685$List$#520CheckChkstkHresult
      • String ID:
      • API String ID: 1664256157-0
      • Opcode ID: dae4933ae7d4d1316ea47641e56e66a8c6ea3fa9dee7b1aa07f924da64acadef
      • Instruction ID: 4beaf55a7378a895b72ecf20a83ea0352029b6b60a09dd0c5c19cf05b5c1ec6f
      • Opcode Fuzzy Hash: dae4933ae7d4d1316ea47641e56e66a8c6ea3fa9dee7b1aa07f924da64acadef
      • Instruction Fuzzy Hash: C6C11775900218DFDB14DFA0DE58BDEBBB4BF48301F1081AAE50AB7661DB745A88CF25
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816), ref: 004FF9CE
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 004FF9FE
      • __vbaStrCmp.MSVBVM60(true,0075AB24), ref: 004FFA23
      • __vbaStrCmp.MSVBVM60(00485A8C,0077EF5C), ref: 004FFA52
      • __vbaStrCopy.MSVBVM60 ref: 004FFA71
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$ChkstkCopyError
      • String ID: R$Software\Aloaha$\w$administrator$localsystem$service$system$true
      • API String ID: 3863658848-1761860351
      • Opcode ID: cd16dca36f6ed9bae4e82f970186e692ed2d96118a956c629b89946e0cfc5078
      • Instruction ID: 8595c13980977fb1240c153add120830e08a824e0dfc42339b40b4a68563db81
      • Opcode Fuzzy Hash: cd16dca36f6ed9bae4e82f970186e692ed2d96118a956c629b89946e0cfc5078
      • Instruction Fuzzy Hash: C3A1FCB6800218EFDB65DF90DD48BDEBBB8BF48305F008699E60AA7550DB745B88CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,00000000,00411816,004FA5C7), ref: 005110FE
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 0051112E
      • __vbaStrCmp.MSVBVM60(00473D9C,00773514,?,00000000,?,00000000,00411816), ref: 00511146
      • __vbaInStr.MSVBVM60(00000000,004775E8,00773514,00000001,?,00000000,?,00000000,00411816), ref: 00511163
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00511186
      • __vbaStrMove.MSVBVM60(?,00000000,?,00000000,00411816), ref: 005111A2
      • __vbaStrMove.MSVBVM60(?,00000000,?,00000000,00411816), ref: 005111B9
      • #712.MSVBVM60(00000000,?,00473D9C,00000001,000000FF,00000000,?,00000000,?,00000000,00411816), ref: 005111D9
      • __vbaStrMove.MSVBVM60(?,00000000,?,00000000,00411816), ref: 005111E4
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,?,00000000,00411816), ref: 005111FA
      • __vbaNew2.MSVBVM60(00477E14,0054ED28,?,00000000,?,00000000,00411816), ref: 00511222
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00477E04,00000014), ref: 00511273
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,0047A994,00000050), ref: 005112C4
      • __vbaStrMove.MSVBVM60 ref: 005112F5
      • __vbaFreeObj.MSVBVM60 ref: 005112FE
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,?,00000000,00411816), ref: 00511314
      • #685.MSVBVM60(?,00000000,?,00000000,00411816), ref: 005113FA
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,?,00000000,00411816), ref: 00511405
      • __vbaFreeObj.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00511426
      • __vbaFreeStr.MSVBVM60(0051147F,?,00000000,?,00000000,00411816), ref: 0051146F
      • __vbaFreeStr.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00511478
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$FreeMove$CheckHresult$#685#712ChkstkCopyErrorNew2
      • String ID: (T$Processpath: $|Gw
      • API String ID: 742036553-1548088333
      • Opcode ID: 25986c7e18b244eef12919234353fd1ebc836a14239759895a2e26a39d3cf8cb
      • Instruction ID: 81aa96a777040ceaae1781c100e25de1f45a36bd15a10a0a332891b140ff0ae3
      • Opcode Fuzzy Hash: 25986c7e18b244eef12919234353fd1ebc836a14239759895a2e26a39d3cf8cb
      • Instruction Fuzzy Hash: 35A13C75900208EFEB14DFA0DA48BDDBBB4FF48705F2085A9E506B76A0DBB45A84CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,00000000), ref: 004F300E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816,00000000), ref: 004F303E
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816,00000000), ref: 004F3056
      • __vbaStrCmp.MSVBVM60(00485A8C,00779704,?,00000000,00000000,00000000,00411816,00000000), ref: 004F3077
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816,00000000), ref: 004F3096
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816,00000000), ref: 004F30AB
        • Part of subcall function 0050CF40: __vbaChkstk.MSVBVM60(?,00411816,?,?,00000001,00000000,00000000,00411816,004F38EA), ref: 0050CF5E
        • Part of subcall function 0050CF40: __vbaOnError.MSVBVM60(000000FF,?,00000001,00000000,?,00411816,?), ref: 0050CF8E
        • Part of subcall function 0050CF40: __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000001,00000000,?,00411816,?), ref: 0050CFA6
        • Part of subcall function 0050CF40: #685.MSVBVM60(?,00000001,00000000,?,00411816,?), ref: 0050CFE1
        • Part of subcall function 0050CF40: __vbaObjSet.MSVBVM60(00000000,00000000,?,00000001,00000000,?,00411816,?), ref: 0050CFEC
        • Part of subcall function 0050CF40: __vbaFreeObj.MSVBVM60(?,00000001,00000000,?,00411816,?), ref: 0050D00D
        • Part of subcall function 0050CF40: __vbaStrCopy.MSVBVM60 ref: 0050D030
        • Part of subcall function 0050CF40: __vbaStrCopy.MSVBVM60 ref: 0050D03E
        • Part of subcall function 0050CF40: __vbaStrMove.MSVBVM60(00000001,?,0000000A), ref: 0050D05A
        • Part of subcall function 0050CF40: __vbaFreeStrList.MSVBVM60(00000002,00000001,?), ref: 0050D06A
        • Part of subcall function 0050CF40: __vbaFreeVar.MSVBVM60(00000000,?,00411816,?), ref: 0050D076
        • Part of subcall function 0050CF40: #685.MSVBVM60 ref: 0050D083
        • Part of subcall function 0050CF40: __vbaObjSet.MSVBVM60(?,00000000), ref: 0050D08E
        • Part of subcall function 0050CF40: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050D0C1
      • __vbaFreeStr.MSVBVM60(?,?,00000000,00000000,00000000,00411816,00000000), ref: 004F30BD
        • Part of subcall function 004F2D70: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,00000000,00000000,?,00411816), ref: 004F2D8E
        • Part of subcall function 004F2D70: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 004F2DBE
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816), ref: 004F2DD6
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(00473D9C,0075ACDC,?,00000000,00000000,00000000,00411816), ref: 004F2DF7
        • Part of subcall function 004F2D70: __vbaStrCopy.MSVBVM60 ref: 004F2E22
        • Part of subcall function 004F2D70: __vbaStrCopy.MSVBVM60 ref: 004F2E30
        • Part of subcall function 004F2D70: __vbaStrMove.MSVBVM60(?,?,0000000A), ref: 004F2E4C
        • Part of subcall function 004F2D70: __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004F2E5C
        • Part of subcall function 004F2D70: __vbaFreeVar.MSVBVM60(00000000,00000000,00411816), ref: 004F2E68
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004F2E7E
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(004740D4,?), ref: 004F2E95
        • Part of subcall function 004F2D70: __vbaStrCopy.MSVBVM60 ref: 004F2ED6
        • Part of subcall function 004F2D70: __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816), ref: 004F2F04
      • __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,00000000), ref: 004F30D4
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,00000000,00000000,00000000,00411816,00000000), ref: 004F3102
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,?,00000000,00000000,00000000,00411816,00000000), ref: 004F311E
      • __vbaStrCopy.MSVBVM60(?,?,00000000,00000000,00000000,00411816,00000000), ref: 004F3138
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,?,00000000,00000000,00000000,00411816,00000000), ref: 004F3153
      • __vbaStrCopy.MSVBVM60(?,?,00000000,00000000,00000000,00411816,00000000), ref: 004F316E
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,00000000,00000000,00000000,00411816,00000000), ref: 004F3186
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00000000,00000000,00411816,00000000), ref: 004F319F
      • __vbaStrCmp.MSVBVM60(true,0075AE44,?,00000001), ref: 004F3222
      • __vbaStrCopy.MSVBVM60 ref: 004F329E
      • __vbaFreeStr.MSVBVM60(?), ref: 004F32B0
      • __vbaStrCopy.MSVBVM60 ref: 004F32C7
      • __vbaStrCmp.MSVBVM60(true,0075AE44), ref: 004F32FF
      • #685.MSVBVM60(?,00000000,00000000,00000000,00411816,00000000), ref: 004F3320
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,00000000,00000000,00000000,00411816,00000000), ref: 004F332B
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,00000000,00411816,00000000), ref: 004F3343
      • __vbaFreeStr.MSVBVM60(004F336D,?,00000000,00000000,00000000,00411816,00000000), ref: 004F3366
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Copy$Free$#685ChkstkErrorMove$List$CheckHresult
      • String ID: 2$HKLM\SOFTWARE\Aloaha\ctest$entering permtest$finished permtest$true
      • API String ID: 1325987103-472686419
      • Opcode ID: 3746e8495369085c8d29817987ff6da4cf1e2983adca173c45b2d99558cde612
      • Instruction ID: 687ff7720ea1f631f69a17531aff2719f294c881d718b9354260147d309a8830
      • Opcode Fuzzy Hash: 3746e8495369085c8d29817987ff6da4cf1e2983adca173c45b2d99558cde612
      • Instruction Fuzzy Hash: 4B914D74901208EFEB14DF90DA487ED7BB4FF05709F20805DE501AB2A0D7B94A09EB59
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,004D61D3,HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultDomainName,?,?,?), ref: 004D13CE
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 004D13FB
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004D140A
      • #520.MSVBVM60(?,00004008), ref: 004D1441
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 004D1466
      • __vbaFreeVar.MSVBVM60 ref: 004D1476
      • #608.MSVBVM60(?,00000000), ref: 004D1498
      • #608.MSVBVM60(?,00000000), ref: 004D14A7
      • __vbaStrCat.MSVBVM60(?,regread:), ref: 004D14B6
      • __vbaVarAdd.MSVBVM60(?,?,00000008,00406188), ref: 004D1500
      • __vbaVarAdd.MSVBVM60(?,00000008,00000000), ref: 004D1512
      • __vbaVarAdd.MSVBVM60(?,?,00000000), ref: 004D1527
      • __vbaVarAdd.MSVBVM60(?,00000008,00000000), ref: 004D153C
      • __vbaStrVarVal.MSVBVM60(?,00000000), ref: 004D1547
        • Part of subcall function 004D22A0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,00000000,00411816), ref: 004D22BE
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D22EB
        • Part of subcall function 004D22A0: __vbaAryConstruct2.MSVBVM60(?,004842F4,00000011,?,?,?,00000000,00411816), ref: 004D22FC
        • Part of subcall function 004D22A0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D230B
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D232C
        • Part of subcall function 004D22A0: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,00000000,00411816), ref: 004D2344
        • Part of subcall function 004D22A0: __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001,?,?,?,?,00000000,00411816), ref: 004D2364
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,00000001,?,?,?,?,00000000,00411816), ref: 004D237D
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2392
        • Part of subcall function 004D22A0: __vbaLenBstr.MSVBVM60(?,?,?,?,?,00000000,00411816), ref: 004D23A3
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D23C0
        • Part of subcall function 004D22A0: __vbaStrMove.MSVBVM60(?,?,encrypted:,?,?,?,?,00000000,00411816), ref: 004D23DD
        • Part of subcall function 004D22A0: __vbaStrCat.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 004D23E4
        • Part of subcall function 004D22A0: __vbaStrMove.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D23EF
        • Part of subcall function 004D22A0: __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?,00000000,00411816), ref: 004D23FF
        • Part of subcall function 004D22A0: __vbaInStr.MSVBVM60(00000000,0047C158,?,00000001,?,00000000,00411816), ref: 004D241C
      • __vbaStrMove.MSVBVM60(00000000), ref: 004D1558
      • __vbaFreeStr.MSVBVM60 ref: 004D1561
      • __vbaFreeVarList.MSVBVM60(00000007,00000008,?,?,?,?,?,?), ref: 004D158E
      • __vbaLenBstr.MSVBVM60(regread:), ref: 004D15B6
      • #617.MSVBVM60(?,00004008,00000000), ref: 004D15C8
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004D15ED
      • __vbaFreeVar.MSVBVM60 ref: 004D15FD
      • __vbaStrCopy.MSVBVM60 ref: 004D161D
      • __vbaStrCopy.MSVBVM60 ref: 004D1630
      • #685.MSVBVM60 ref: 004D163D
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004D1648
      • __vbaFreeObj.MSVBVM60 ref: 004D1669
      • __vbaFreeStr.MSVBVM60(004D16DF), ref: 004D16CF
      • __vbaFreeStr.MSVBVM60 ref: 004D16D8
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$CopyFree$Move$#608BstrChkstkErrorList$#520#617#685Construct2
      • String ID: regread:
      • API String ID: 1549070028-1179285436
      • Opcode ID: 83c893fb644eea8ea089ec7dff9268e91f9d82fa8e8c9815e12b2a686723371c
      • Instruction ID: cd445f6cb1f70d48e8a2c9005177e5c0f1c9a2d346c13d21ec1ad5d0bcde7b3e
      • Opcode Fuzzy Hash: 83c893fb644eea8ea089ec7dff9268e91f9d82fa8e8c9815e12b2a686723371c
      • Instruction Fuzzy Hash: 2681D8B6800218DFDB14DF90DE58FDEB778BB48305F10819AE606B7260DB745A48CF65
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004BCFAE
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004BCFDE
      • __vbaStrCopy.MSVBVM60 ref: 004BD02C
        • Part of subcall function 004D0AE0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00411816), ref: 004D0AFE
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D0B2B
        • Part of subcall function 004D0AE0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D0B3A
        • Part of subcall function 004D0AE0: #520.MSVBVM60(?,00004008), ref: 004D0B68
        • Part of subcall function 004D0AE0: __vbaStrVarMove.MSVBVM60(?), ref: 004D0B72
        • Part of subcall function 004D0AE0: __vbaStrMove.MSVBVM60 ref: 004D0B7D
        • Part of subcall function 004D0AE0: __vbaFreeVar.MSVBVM60 ref: 004D0B86
        • Part of subcall function 004D0AE0: __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D0B9C
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60 ref: 004D0BB5
        • Part of subcall function 004D0AE0: __vbaStrCat.MSVBVM60(?,get:,?), ref: 004D0BC8
        • Part of subcall function 004D0AE0: __vbaStrMove.MSVBVM60 ref: 004D0BD3
        • Part of subcall function 004D0AE0: __vbaStrMove.MSVBVM60(00000000), ref: 004D0BE4
        • Part of subcall function 004D0AE0: __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004D0BF4
        • Part of subcall function 004D0AE0: #520.MSVBVM60(?,00004008), ref: 004D0C19
        • Part of subcall function 004D0AE0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004D0C35
        • Part of subcall function 004D0AE0: __vbaFreeVar.MSVBVM60 ref: 004D0C42
        • Part of subcall function 004D0AE0: __vbaStrCopy.MSVBVM60 ref: 004D0C5F
      • #518.MSVBVM60(?,00000008,changepass), ref: 004BD055
      • #520.MSVBVM60(?,?), ref: 004BD063
      • __vbaStrVarMove.MSVBVM60(?), ref: 004BD06D
      • __vbaStrMove.MSVBVM60 ref: 004BD078
      • __vbaFreeVarList.MSVBVM60(00000003,00000008,?,?), ref: 004BD08C
      • __vbaStrCmp.MSVBVM60(true,?), ref: 004BD0A5
      • __vbaStrCmp.MSVBVM60(wahr,?), ref: 004BD0BC
      • __vbaStrCmp.MSVBVM60(004740DC,?), ref: 004BD0D9
      • __vbaStrI4.MSVBVM60(00000001,WaitForChangePassTool: ), ref: 004BD0FB
      • __vbaStrMove.MSVBVM60 ref: 004BD106
      • __vbaStrCat.MSVBVM60(00000000), ref: 004BD10D
      • __vbaStrMove.MSVBVM60 ref: 004BD118
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004BD131
      • __vbaSetSystemError.MSVBVM60(000003E7,?,?,?,?,?,?,00411816), ref: 004BD14B
      • #598.MSVBVM60(?,?,?,?,?,?,00411816), ref: 004BD158
      • #685.MSVBVM60 ref: 004BD175
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BD180
      • __vbaFreeObj.MSVBVM60 ref: 004BD1A1
      • __vbaFreeStr.MSVBVM60(004BD1EC), ref: 004BD1E5
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Move$Free$Copy$#520ErrorList$Chkstk$#518#598#685System
      • String ID: 0u$WaitForChangePassTool: $changepass$true$wahr
      • API String ID: 2787215770-4038981338
      • Opcode ID: 614373412d2a5e02e90db36bc7c75db8934dd33cd647a6cfe5fdf78b74abb5d7
      • Instruction ID: 851abde453d84e3efe5a303c1680e15ba7bdb91d5a02ed750dbaf087682e5425
      • Opcode Fuzzy Hash: 614373412d2a5e02e90db36bc7c75db8934dd33cd647a6cfe5fdf78b74abb5d7
      • Instruction Fuzzy Hash: 5B512D71D00209EFDB04DFE4DE49BEEBBB8AB08705F208159E506B75A0DB785A49CB64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,00510F40,?,?,?,00000000,00411816,004FA5C7), ref: 00510B9E
      • __vbaAryConstruct2.MSVBVM60(?,0048B42C,00000003,?,?,?,00000000,00411816,00510F40), ref: 00510BD0
      • __vbaFixstrConstruct.MSVBVM60(00000104,?,?,?,?,00000000,00411816,00510F40), ref: 00510BDF
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,00510F40), ref: 00510BEE
      • __vbaStrCmp.MSVBVM60(00473D9C,00774F8C,?,?,?,00000000,00411816,00510F40), ref: 00510C07
      • __vbaSetSystemError.MSVBVM60(?,?,?,00000000,00411816,00510F40), ref: 00510C24
      • __vbaSetSystemError.MSVBVM60(00000410,00000000,?,?,?,?,00000000,00411816,00510F40), ref: 00510C4A
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00510C8E
      • __vbaSetSystemError.MSVBVM60(00000000,?,000000C8,?), ref: 00510CB9
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00510CFD
      • __vbaStrToAnsi.MSVBVM60(?,?,000001F4), ref: 00510D16
      • __vbaSetSystemError.MSVBVM60(00000000,00000000,00000000), ref: 00510D33
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 00510D41
      • __vbaLsetFixstr.MSVBVM60(00000000,?,00000000), ref: 00510D4E
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 00510D64
      • __vbaStrCopy.MSVBVM60(?,?,00000000,00411816,00510F40), ref: 00510D7E
      • #616.MSVBVM60(00000000,?,00000000,00411816,00510F40), ref: 00510D85
      • __vbaStrMove.MSVBVM60(?,00000000,00411816,00510F40), ref: 00510D90
      • __vbaLsetFixstr.MSVBVM60(00000000,?,?,?,00000000,00411816,00510F40), ref: 00510DA0
      • __vbaStrMove.MSVBVM60 ref: 00510DB9
      • __vbaFreeStr.MSVBVM60 ref: 00510DC2
      • __vbaStrCopy.MSVBVM60 ref: 00510DD7
      • __vbaSetSystemError.MSVBVM60(00000000), ref: 00510DF0
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816,00510F40), ref: 00510E0E
      • #685.MSVBVM60(?,?,?,00000000,00411816,00510F40), ref: 00510E1B
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816,00510F40), ref: 00510E26
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816,00510F40), ref: 00510E47
      • __vbaAryDestruct.MSVBVM60(00000000,?,00510EA0,?,?,?,00000000,00411816,00510F40), ref: 00510E90
      • __vbaFreeStr.MSVBVM60(?,?,?,00000000,00411816,00510F40), ref: 00510E99
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Error$System$Free$CopyFixstr$BoundsGenerateLsetMove$#616#685AnsiChkstkConstructConstruct2DestructListUnicode
      • String ID:
      • API String ID: 1407977808-0
      • Opcode ID: 96d88efbd2c86c1bb7efa3df7a1d6dbb91e533e020dcb80b72a1b7b205e0db75
      • Instruction ID: 61aae459b20e88ee7b92aa73a2f2a7dbc075ece33f52a9c62382403083107cc6
      • Opcode Fuzzy Hash: 96d88efbd2c86c1bb7efa3df7a1d6dbb91e533e020dcb80b72a1b7b205e0db75
      • Instruction Fuzzy Hash: 5791E875D00208DFEB04DFE4DA48BDDBBB4FB48305F108169E506AB2A4DBB46A85CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,004C0046,00000000,?,00000000), ref: 004BD9DE
      • __vbaStrCopy.MSVBVM60(00000000,?,?,00000000,00411816), ref: 004BDA0B
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00411816), ref: 004BDA1A
      • #685.MSVBVM60(?,00000000,00411816), ref: 004BDA27
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00411816), ref: 004BDA32
      • __vbaFreeObj.MSVBVM60(?,00000000,00411816), ref: 004BDA4A
      • #578.MSVBVM60(?), ref: 004BDA69
      • #685.MSVBVM60 ref: 004BDA79
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BDA84
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004BDAB7
      • __vbaFreeObj.MSVBVM60 ref: 004BDAE9
      • #685.MSVBVM60 ref: 004BDB02
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BDB0D
      • __vbaFreeObj.MSVBVM60 ref: 004BDB25
      • __vbaStrToAnsi.MSVBVM60(?,?,00000000), ref: 004BDB3C
      • __vbaSetSystemError.MSVBVM60(00000000), ref: 004BDB4B
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 004BDB59
      • __vbaFreeStr.MSVBVM60 ref: 004BDB68
      • #685.MSVBVM60 ref: 004BDB75
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BDB80
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004BDBB3
      • __vbaFreeObj.MSVBVM60 ref: 004BDBD7
      • __vbaSetSystemError.MSVBVM60(?,?), ref: 004BDBFC
      • __vbaSetSystemError.MSVBVM60(?), ref: 004BDC28
      • #685.MSVBVM60 ref: 004BDC42
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004BDC4D
      • __vbaFreeObj.MSVBVM60 ref: 004BDC65
      • __vbaFreeStr.MSVBVM60(004BDC8F), ref: 004BDC88
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685$Error$System$CheckHresult$#578AnsiChkstkCopyUnicode
      • String ID:
      • API String ID: 2269764201-0
      • Opcode ID: d6a6b8cf02c4de68ba2708724704ba57b623f65ff7b54e7bc68c7374617a1ef5
      • Instruction ID: a31f3be3b043828a8bf9a66bc95dffcb922f301b3e94250530a9b0130af5cdaa
      • Opcode Fuzzy Hash: d6a6b8cf02c4de68ba2708724704ba57b623f65ff7b54e7bc68c7374617a1ef5
      • Instruction Fuzzy Hash: A891C3B5D00208EFDB04DFE4EA48BDEBBB5BF48705F208569E502A72A0DB785A45CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 004F9BFE
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004F9C2E
      • #610.MSVBVM60(?,?,?,?,?,00411816), ref: 004F9C3F
      • #612.MSVBVM60(?,?,?,?,?,00411816), ref: 004F9C49
      • __vbaVarDup.MSVBVM60 ref: 004F9C63
      • __vbaVarDup.MSVBVM60 ref: 004F9C86
      • #650.MSVBVM60(?,?,00000001,00000001), ref: 004F9C98
      • __vbaStrMove.MSVBVM60 ref: 004F9CA3
      • #650.MSVBVM60(?,?,00000001,00000001,00000000), ref: 004F9CB6
      • __vbaStrMove.MSVBVM60 ref: 004F9CC1
      • __vbaStrCat.MSVBVM60(00000000), ref: 004F9CC8
      • __vbaStrMove.MSVBVM60 ref: 004F9CD3
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004F9CE3
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?,?,?,00411816), ref: 004F9CFE
      • #685.MSVBVM60 ref: 004F9D0E
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F9D19
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004F9D64
      • __vbaFreeObj.MSVBVM60 ref: 004F9D94
      • __vbaStrCopy.MSVBVM60 ref: 004F9DB4
      • #685.MSVBVM60 ref: 004F9DC1
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004F9DCC
      • __vbaFreeObj.MSVBVM60 ref: 004F9DED
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$#650#685List$#610#612CheckChkstkCopyErrorHresult
      • String ID: hhnnss$yyyymmdd
      • API String ID: 1324253332-2771916313
      • Opcode ID: 9774cb22cb2649cc1a13a3ffe9263e82d818f625f11768f8ae98775c09b62eea
      • Instruction ID: c1e48578a573ce9100569cfcfb1de71f199c0a9e64b3ed6bd8797ff50b545682
      • Opcode Fuzzy Hash: 9774cb22cb2649cc1a13a3ffe9263e82d818f625f11768f8ae98775c09b62eea
      • Instruction Fuzzy Hash: D6512875900218DFDB10DFA4DD48BEEB7B8FB08705F1081A9E60AB76A1DB745A88CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000001,00411816,0052D577,?,?,?,?,00411816,004B1BE8), ref: 0052D29E
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000001,00411816,0052D577), ref: 0052D2CE
      • #607.MSVBVM60(?,00000100,00000002), ref: 0052D2F6
      • __vbaStrVarMove.MSVBVM60(?), ref: 0052D300
      • __vbaStrMove.MSVBVM60 ref: 0052D30B
      • __vbaFreeVarList.MSVBVM60(00000002,00000002,?), ref: 0052D31B
      • __vbaLenBstr.MSVBVM60(?,?,00000001,00411816,0052D577), ref: 0052D32F
      • __vbaStrToAnsi.MSVBVM60(?,?,?,?,00000001,00411816,0052D577), ref: 0052D34B
      • __vbaSetSystemError.MSVBVM60(00000002,00000000,?,00000001,00411816,0052D577), ref: 0052D35C
      • __vbaStrToUnicode.MSVBVM60(?,?,?,00000001,00411816,0052D577), ref: 0052D36A
      • __vbaFreeStr.MSVBVM60 ref: 0052D382
      • #616.MSVBVM60(?,?), ref: 0052D39F
      • __vbaStrMove.MSVBVM60 ref: 0052D3AA
      • __vbaStrCat.MSVBVM60(?,UNameDom: ), ref: 0052D3C0
      • __vbaStrMove.MSVBVM60 ref: 0052D3CB
      • __vbaFreeStr.MSVBVM60(?), ref: 0052D3DD
      • __vbaStrCopy.MSVBVM60 ref: 0052D3F4
      • __vbaStrCopy.MSVBVM60 ref: 0052D409
      • __vbaFreeStr.MSVBVM60(?), ref: 0052D41B
      • #685.MSVBVM60 ref: 0052D428
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0052D433
      • __vbaFreeObj.MSVBVM60 ref: 0052D454
      • __vbaFreeStr.MSVBVM60(0052D4A4), ref: 0052D49D
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$CopyError$#607#616#685AnsiBstrChkstkListSystemUnicode
      • String ID: UNameDom:
      • API String ID: 1732254648-2483048728
      • Opcode ID: 4018fe286762d098fffb29d09dad441b8fc834295653304cf860b91b3e7a2bdb
      • Instruction ID: d54f3a41fcff9a8a446edc56c0d758d08d48c064899d315c6772de5799e9bf66
      • Opcode Fuzzy Hash: 4018fe286762d098fffb29d09dad441b8fc834295653304cf860b91b3e7a2bdb
      • Instruction Fuzzy Hash: 4D51EC71910208EFDB04DFE0EA48BDDBBB8FF48705F108569E506B75A0DB745A45CB64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00411816), ref: 004D0AFE
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D0B2B
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D0B3A
      • #520.MSVBVM60(?,00004008), ref: 004D0B68
      • __vbaStrVarMove.MSVBVM60(?), ref: 004D0B72
      • __vbaStrMove.MSVBVM60 ref: 004D0B7D
      • __vbaFreeVar.MSVBVM60 ref: 004D0B86
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D0B9C
      • __vbaStrCopy.MSVBVM60 ref: 004D0BB5
      • __vbaStrCat.MSVBVM60(?,get:,?), ref: 004D0BC8
      • __vbaStrMove.MSVBVM60 ref: 004D0BD3
        • Part of subcall function 004D22A0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,00000000,00411816), ref: 004D22BE
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D22EB
        • Part of subcall function 004D22A0: __vbaAryConstruct2.MSVBVM60(?,004842F4,00000011,?,?,?,00000000,00411816), ref: 004D22FC
        • Part of subcall function 004D22A0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D230B
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D232C
        • Part of subcall function 004D22A0: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,00000000,00411816), ref: 004D2344
        • Part of subcall function 004D22A0: __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001,?,?,?,?,00000000,00411816), ref: 004D2364
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,00000001,?,?,?,?,00000000,00411816), ref: 004D237D
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2392
        • Part of subcall function 004D22A0: __vbaLenBstr.MSVBVM60(?,?,?,?,?,00000000,00411816), ref: 004D23A3
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D23C0
        • Part of subcall function 004D22A0: __vbaStrMove.MSVBVM60(?,?,encrypted:,?,?,?,?,00000000,00411816), ref: 004D23DD
        • Part of subcall function 004D22A0: __vbaStrCat.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 004D23E4
        • Part of subcall function 004D22A0: __vbaStrMove.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D23EF
        • Part of subcall function 004D22A0: __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?,00000000,00411816), ref: 004D23FF
        • Part of subcall function 004D22A0: __vbaInStr.MSVBVM60(00000000,0047C158,?,00000001,?,00000000,00411816), ref: 004D241C
      • __vbaStrMove.MSVBVM60(00000000), ref: 004D0BE4
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004D0BF4
      • #520.MSVBVM60(?,00004008), ref: 004D0C19
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004D0C35
      • __vbaFreeVar.MSVBVM60 ref: 004D0C42
      • __vbaStrCopy.MSVBVM60 ref: 004D0C5F
      • __vbaStrCopy.MSVBVM60 ref: 004D0C72
      • #685.MSVBVM60 ref: 004D0C7F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004D0C8A
      • __vbaFreeObj.MSVBVM60 ref: 004D0CAB
      • __vbaFreeStr.MSVBVM60(004D0D0E), ref: 004D0CFE
      • __vbaFreeStr.MSVBVM60 ref: 004D0D07
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Copy$Free$Move$#520ChkstkErrorList$#685BstrConstruct2
      • String ID: get:
      • API String ID: 1155568759-1157004333
      • Opcode ID: 616730630219b9a10d74fced0ba62dbc29de93e0d4b17b5ac2ffc36577aa0d85
      • Instruction ID: 56806339efd6c9056578ed7e6bfb7bacbc4212b26187ff9dcdf57a3f763245b0
      • Opcode Fuzzy Hash: 616730630219b9a10d74fced0ba62dbc29de93e0d4b17b5ac2ffc36577aa0d85
      • Instruction Fuzzy Hash: FD51E575900209EFDB04DFA0DA58BDEBBB4FF08705F20816AE506B76A0DB745A49CF58
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,00000000,00000000,?,00411816), ref: 004F2D8E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 004F2DBE
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816), ref: 004F2DD6
      • __vbaStrCmp.MSVBVM60(00473D9C,0075ACDC,?,00000000,00000000,00000000,00411816), ref: 004F2DF7
      • __vbaStrCopy.MSVBVM60 ref: 004F2E22
      • __vbaStrCopy.MSVBVM60 ref: 004F2E30
      • __vbaStrMove.MSVBVM60(?,?,0000000A), ref: 004F2E4C
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004F2E5C
      • __vbaFreeVar.MSVBVM60(00000000,00000000,00411816), ref: 004F2E68
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004F2E7E
      • __vbaStrCmp.MSVBVM60(004740D4,?), ref: 004F2E95
      • __vbaStrCopy.MSVBVM60 ref: 004F2ED6
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004F2EEE
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816), ref: 004F2F04
      • __vbaStrCmp.MSVBVM60(004740D4,00000000,?,00000000,00000000,00000000,00411816), ref: 004F2F1B
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004F2F5A
      • #685.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004F2F67
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,00000000,00411816), ref: 004F2F72
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004F2F8A
      • __vbaFreeStr.MSVBVM60(004F2FDA,?,00000000,00000000,00000000,00411816), ref: 004F2FD3
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Copy$Free$#685ChkstkErrorListMove
      • String ID: Software\Aloaha$useini
      • API String ID: 442541815-249623257
      • Opcode ID: a1e684f62844b2fab893522356771a9ada1a806333bc0d7f0c6aedbe042605da
      • Instruction ID: cfa25c6bf3be59ea39faf4443acacfd37063d57d86142dd94b79ecfa3a54d6a9
      • Opcode Fuzzy Hash: a1e684f62844b2fab893522356771a9ada1a806333bc0d7f0c6aedbe042605da
      • Instruction Fuzzy Hash: 53516F75900209DFDB10DF94DE49BEDBB74FF08709F208159E601BB2A0DBB45A09DB64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,0052029D,?,?,?,00000000,00411816), ref: 004BD73E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 004BD76E
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 004BD783
      • #685.MSVBVM60(?,?,?,?,00411816), ref: 004BD790
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,?,?,?,00411816), ref: 004BD79B
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 004BD7B3
        • Part of subcall function 00518650: __vbaChkstk.MSVBVM60(?,00411816), ref: 0051866E
        • Part of subcall function 00518650: __vbaStrCopy.MSVBVM60(?,00000000,?,?,00411816), ref: 0051869B
        • Part of subcall function 00518650: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 005186AA
        • Part of subcall function 00518650: #518.MSVBVM60(?,00004008), ref: 005186E2
        • Part of subcall function 00518650: #518.MSVBVM60(?,00004008), ref: 00518706
        • Part of subcall function 00518650: #518.MSVBVM60(?,00004008), ref: 0051872D
        • Part of subcall function 00518650: #617.MSVBVM60(?,?,00000005), ref: 0051873D
        • Part of subcall function 00518650: #617.MSVBVM60(?,?,00000006), ref: 00518761
        • Part of subcall function 00518650: #617.MSVBVM60(?,?,00000004), ref: 0051878B
        • Part of subcall function 00518650: __vbaVarCmpEq.MSVBVM60(?,00008008,?), ref: 005187B4
        • Part of subcall function 00518650: __vbaVarCmpEq.MSVBVM60(?,00008008,?,00000000), ref: 005187CD
        • Part of subcall function 00518650: __vbaVarOr.MSVBVM60(?,00000000), ref: 005187DB
      • #685.MSVBVM60(00000000,?,?,?,?,00411816), ref: 004BD7DC
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,?,?,?,00411816), ref: 004BD7E7
      • __vbaStrMove.MSVBVM60(0052029D), ref: 004BD8E0
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004BD81A
        • Part of subcall function 004BDCB0: __vbaOnError.MSVBVM60(00000001), ref: 004BDD2B
        • Part of subcall function 004BDCB0: __vbaRedim.MSVBVM60(00000080,00000001,?,00000011,00000001,00000000,00000000,00000000), ref: 004BDD50
        • Part of subcall function 004BDCB0: __vbaStrToAnsi.MSVBVM60(?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDD78
        • Part of subcall function 004BDCB0: __vbaSetSystemError.MSVBVM60(00000000,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDD86
        • Part of subcall function 004BDCB0: __vbaStrToUnicode.MSVBVM60(?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDD97
        • Part of subcall function 004BDCB0: __vbaFreeStr.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDDA5
        • Part of subcall function 004BDCB0: __vbaAryLock.MSVBVM60(?,?,?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDDBD
        • Part of subcall function 004BDCB0: __vbaGenerateBoundsError.MSVBVM60(?,C0000000,00000000,00000000,00000004,00000080,00000000), ref: 004BDDDA
      • __vbaFreeObj.MSVBVM60 ref: 004BD83E
      • __vbaVar2Vec.MSVBVM60(?,?,?,0052029D), ref: 004BD868
      • __vbaAryMove.MSVBVM60(?,?), ref: 004BD876
      • __vbaFreeVar.MSVBVM60 ref: 004BD87F
      • #717.MSVBVM60(?,00006011,00000040,00000000), ref: 004BD8A5
      • __vbaStrVarMove.MSVBVM60(?), ref: 004BD8AF
      • __vbaStrMove.MSVBVM60 ref: 004BD8BA
      • __vbaFreeVar.MSVBVM60 ref: 004BD8C3
      • __vbaStrMove.MSVBVM60(0052029D,00000000,?,?,?,?,00411816), ref: 004BD8FD
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 004BD910
      • #685.MSVBVM60(?,?,?,?,00411816), ref: 004BD91D
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,?,?,?,00411816), ref: 004BD928
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 004BD949
      • __vbaAryDestruct.MSVBVM60(00000000,?,004BD99E,?,?,?,?,00411816), ref: 004BD98E
      • __vbaFreeStr.MSVBVM60(?,?,?,?,00411816), ref: 004BD997
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$ErrorMove$#518#617#685Copy$Chkstk$#717AnsiBoundsCheckDestructGenerateHresultLockRedimSystemUnicodeVar2
      • String ID:
      • API String ID: 2320873246-0
      • Opcode ID: 4a537bf709d4547368dfdc5ade77a81eaeb7a5ef9f13bbf33c9793888d514d4f
      • Instruction ID: 5d6043bca74229f17e930ae029f18018f7593ce28530b8955bcca7b5a99d8a74
      • Opcode Fuzzy Hash: 4a537bf709d4547368dfdc5ade77a81eaeb7a5ef9f13bbf33c9793888d514d4f
      • Instruction Fuzzy Hash: 8471D675D00209EFDB04DFA4DA48BDEBBB4BF48305F108569E502A72A0DB789A45DF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,00499C87,?,?,?,?,00411816), ref: 004D029E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,00499C87), ref: 004D02CE
      • __vbaStrCmp.MSVBVM60(true,0076575C,?,?,?,00000000,00411816,00499C87), ref: 004D02E6
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816,00499C87), ref: 004D0305
      • __vbaSetSystemError.MSVBVM60(?), ref: 004D0357
      • #685.MSVBVM60 ref: 004D0364
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004D036F
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004D03A2
      • __vbaFreeObj.MSVBVM60 ref: 004D03C6
      • SetProcessDEPPolicy.KERNEL32(00000000), ref: 004D03DA
      • #685.MSVBVM60(?,?,?,00000000,00411816,00499C87), ref: 004D03E7
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,?,?,00000000,00411816,00499C87), ref: 004D03F2
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816,00499C87), ref: 004D040A
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$#685ErrorFree$CheckChkstkCopyHresultPolicyProcessSystem
      • String ID: \Wv$true
      • API String ID: 880356173-3025869392
      • Opcode ID: 21eaa26b84aafe2ad1668fbe8edf97d9f22b8005765ae6b72716fb84248a8161
      • Instruction ID: 0b39f65f23b400f194479823f842bfb30112e6d873ecb9f9bba753a7fd8ab2de
      • Opcode Fuzzy Hash: 21eaa26b84aafe2ad1668fbe8edf97d9f22b8005765ae6b72716fb84248a8161
      • Instruction Fuzzy Hash: 8341E4B5900208EFDB04EFE4DA48BDEBBB4FF08749F50815AE505A72A0CBB85A44CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000001,00411816), ref: 0054B1FE
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000001,00411816), ref: 0054B22E
        • Part of subcall function 00531FD0: __vbaChkstk.MSVBVM60(00000000,00411816,004CB93C,?,00000001,?,00000000,00411816), ref: 00531FEE
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053201E
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053202D
        • Part of subcall function 00531FD0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,004CB93C), ref: 0053203C
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 0053206B
        • Part of subcall function 00531FD0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532093
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 005320A6
        • Part of subcall function 00531FD0: __vbaStrCopy.MSVBVM60 ref: 005320CA
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00000008,?), ref: 005320F7
        • Part of subcall function 00531FD0: __vbaStrVarMove.MSVBVM60(?), ref: 00532104
        • Part of subcall function 00531FD0: __vbaStrMove.MSVBVM60 ref: 00532111
        • Part of subcall function 00531FD0: __vbaFreeStr.MSVBVM60 ref: 0053211A
        • Part of subcall function 00531FD0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532130
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 00532162
        • Part of subcall function 00531FD0: __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0053218A
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 0053219D
      • __vbaStrCmp.MSVBVM60(true,0077F2F4), ref: 0054B291
      • __vbaStrErrVarCopy.MSVBVM60(?,MiniCSP_HID get_ScardContext returned: ), ref: 0054B2AB
      • __vbaStrMove.MSVBVM60 ref: 0054B2B6
      • __vbaStrCat.MSVBVM60(00000000), ref: 0054B2BD
      • __vbaStrMove.MSVBVM60 ref: 0054B2C8
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 0054B2E1
      • __vbaSetSystemError.MSVBVM60(?,00000000,00000000,00411750,?,?,?,00000001,00411816), ref: 0054B31B
      • #685.MSVBVM60(?,?,?,00000001,00411816), ref: 0054B32E
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000001,00411816), ref: 0054B339
      • __vbaFreeObj.MSVBVM60(?,?,?,00000001,00411816), ref: 0054B351
      • __vbaFreeVar.MSVBVM60(0054B385,?,?,?,00000001,00411816), ref: 0054B37E
        • Part of subcall function 005377E0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,00000001), ref: 005377FE
        • Part of subcall function 005377E0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816), ref: 0053782E
        • Part of subcall function 005377E0: __vbaStrCmp.MSVBVM60(true,00000000,?,00000001,?,00000000,00411816), ref: 0053785C
        • Part of subcall function 005377E0: #685.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00537A6F
        • Part of subcall function 005377E0: __vbaObjSet.MSVBVM60(?,00000000,?,00000001,?,00000000,00411816), ref: 00537A7A
        • Part of subcall function 005377E0: __vbaFreeObj.MSVBVM60(?,00000001,?,00000000,00411816), ref: 00537A92
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$ErrorMove$#520Chkstk$#685ConstructCopyFixstrList$System
      • String ID: MiniCSP_HID get_ScardContext returned: $true
      • API String ID: 1557156342-336068393
      • Opcode ID: c942b080303099fa1c939329039950d86ed2bc58302c5c6952c927f87a117c3f
      • Instruction ID: 2ff068b0ed3735216cb0f6a46c3d48c19f9f1c058544d7522cd5d41d6ddf4fc1
      • Opcode Fuzzy Hash: c942b080303099fa1c939329039950d86ed2bc58302c5c6952c927f87a117c3f
      • Instruction Fuzzy Hash: 79414FB5900209EFDB00DFD4DA48BEEBBB4FF48308F108459F505A76A0D7B85A05DB55
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0054595E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 0054598E
        • Part of subcall function 00531FD0: __vbaChkstk.MSVBVM60(00000000,00411816,004CB93C,?,00000001,?,00000000,00411816), ref: 00531FEE
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053201E
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053202D
        • Part of subcall function 00531FD0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,004CB93C), ref: 0053203C
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 0053206B
        • Part of subcall function 00531FD0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532093
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 005320A6
        • Part of subcall function 00531FD0: __vbaStrCopy.MSVBVM60 ref: 005320CA
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00000008,?), ref: 005320F7
        • Part of subcall function 00531FD0: __vbaStrVarMove.MSVBVM60(?), ref: 00532104
        • Part of subcall function 00531FD0: __vbaStrMove.MSVBVM60 ref: 00532111
        • Part of subcall function 00531FD0: __vbaFreeStr.MSVBVM60 ref: 0053211A
        • Part of subcall function 00531FD0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532130
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 00532162
        • Part of subcall function 00531FD0: __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0053218A
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 0053219D
      • __vbaSetSystemError.MSVBVM60(00000000,00000000,00000000,xA,?,?,?,00000000,00411816), ref: 005459C6
      • #685.MSVBVM60 ref: 00545A1B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00545A26
      • __vbaFreeObj.MSVBVM60 ref: 00545A3E
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#520Error$ChkstkConstructFixstrMove$#685CopyListSystem
      • String ID: xA
      • API String ID: 3365449785-299298737
      • Opcode ID: 90f0ee6a55c37e626c9b9ecd3654e388efea941e341bb048a015b941be6eb635
      • Instruction ID: 9a4ce7320b208d3379e7d468124d79811d07a1c97646c30e9bb1bbbb0227a054
      • Opcode Fuzzy Hash: 90f0ee6a55c37e626c9b9ecd3654e388efea941e341bb048a015b941be6eb635
      • Instruction Fuzzy Hash: EA315AB0901649EFDB00DFD4CA48BDEBBB4FF08349F208159E501BB291D7B99A44CB65
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: #100
      • String ID: VB5!6&*
      • API String ID: 1341478452-3593831657
      • Opcode ID: a915472e1d41b36aa2eec8b432f14369d9302e1397c4addb749c1587440f1ac4
      • Instruction ID: 4857fa7a8368d95cb3c5180038f1c91bfc8c94c82a72cd81e715389278c1ab62
      • Opcode Fuzzy Hash: a915472e1d41b36aa2eec8b432f14369d9302e1397c4addb749c1587440f1ac4
      • Instruction Fuzzy Hash: 625162A6A9E7C15FC70357B49A660913FB1AE2322430F44DBC581DF0B3E6984C4AC776
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,?,?,004C1EA4,?,?,?,?,?,00000000,?,?,00411816), ref: 004C508E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 004C50BE
      • #685.MSVBVM60(?,00000000), ref: 004C5109
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000), ref: 004C5114
      • __vbaFreeObj.MSVBVM60(?,00000000), ref: 004C5135
      • #518.MSVBVM60(?,00004008), ref: 004C5160
      • #617.MSVBVM60(?,?,00000004), ref: 004C5173
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 004C519B
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004C51B5
      • __vbaStrCat.MSVBVM60(?,http://), ref: 004C51DB
      • __vbaStrMove.MSVBVM60(?,http://), ref: 004C51E6
      • __vbaStrCat.MSVBVM60(00000000,going to fetch: ), ref: 004C51FE
      • __vbaStrMove.MSVBVM60(?,http://), ref: 004C5209
      • __vbaFreeStr.MSVBVM60(?), ref: 004C521B
      • #685.MSVBVM60(?,http://), ref: 004C5228
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C5233
      • __vbaFreeObj.MSVBVM60(?,http://), ref: 004C5254
      • #716.MSVBVM60(?,WinHttp.WinHttpRequest,00000000), ref: 004C526C
      • __vbaObjVar.MSVBVM60(?), ref: 004C5276
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C5281
      • __vbaFreeVar.MSVBVM60(?,http://), ref: 004C528A
      • #685.MSVBVM60(?,http://), ref: 004C5297
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C52A2
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C52ED
      • __vbaFreeObj.MSVBVM60 ref: 004C531D
      • __vbaStrCopy.MSVBVM60 ref: 004C5341
      • __vbaFreeStr.MSVBVM60(?), ref: 004C5353
      • #685.MSVBVM60 ref: 004C5360
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C536B
      • __vbaFreeObj.MSVBVM60 ref: 004C538C
      • #716.MSVBVM60(?,Microsoft.XMLHTTP,00000000), ref: 004C53A4
      • __vbaObjVar.MSVBVM60(?), ref: 004C53AE
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C53B9
      • __vbaFreeVar.MSVBVM60 ref: 004C53C2
      • #685.MSVBVM60 ref: 004C53CF
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C53DA
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C5425
      • __vbaFreeObj.MSVBVM60 ref: 004C5455
      • __vbaStrCopy.MSVBVM60 ref: 004C5479
      • __vbaFreeStr.MSVBVM60(?), ref: 004C548B
      • #685.MSVBVM60 ref: 004C5498
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C54A3
      • __vbaFreeObj.MSVBVM60 ref: 004C54C4
      • #716.MSVBVM60(?,MSXML2.ServerXMLHTTP,00000000), ref: 004C54DC
      • __vbaObjVar.MSVBVM60(?), ref: 004C54E6
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C54F1
      • __vbaFreeVar.MSVBVM60 ref: 004C54FA
      • #685.MSVBVM60 ref: 004C5507
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C5512
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C555D
      • __vbaFreeObj.MSVBVM60 ref: 004C558D
      • __vbaStrCopy.MSVBVM60 ref: 004C55B1
      • __vbaFreeStr.MSVBVM60(?), ref: 004C55C3
      • #685.MSVBVM60 ref: 004C55D0
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C55DB
      • __vbaFreeObj.MSVBVM60 ref: 004C55FC
      • #716.MSVBVM60(?,WinHttp.WinHttpRequest.5.1,00000000), ref: 004C5614
      • __vbaObjVar.MSVBVM60(?), ref: 004C561E
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C5629
      • __vbaFreeVar.MSVBVM60 ref: 004C5632
      • #685.MSVBVM60 ref: 004C563F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C564A
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C5695
      • __vbaFreeObj.MSVBVM60 ref: 004C56C5
      • __vbaStrCopy.MSVBVM60 ref: 004C56E9
      • __vbaFreeStr.MSVBVM60(?), ref: 004C56FB
      • #685.MSVBVM60 ref: 004C5708
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C5713
      • __vbaFreeObj.MSVBVM60 ref: 004C5734
      • #716.MSVBVM60(?,WinHttp.WinHttpRequest,00000000), ref: 004C574C
      • __vbaObjVar.MSVBVM60(?), ref: 004C5756
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C5761
      • __vbaFreeVar.MSVBVM60 ref: 004C576A
      • #685.MSVBVM60 ref: 004C5777
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C5782
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C57CD
      • __vbaFreeObj.MSVBVM60 ref: 004C57FD
      • __vbaStrCopy.MSVBVM60 ref: 004C5821
      • __vbaFreeStr.MSVBVM60(?), ref: 004C5833
      • __vbaStrMove.MSVBVM60 ref: 004C585E
      • __vbaChkstk.MSVBVM60 ref: 004C5879
      • __vbaChkstk.MSVBVM60 ref: 004C58A8
      • __vbaLateMemCallSt.MSVBVM60(?,Option,00000001), ref: 004C58DD
      • __vbaFreeStr.MSVBVM60 ref: 004C58E9
      • #518.MSVBVM60(?,00004008), ref: 004C5914
      • #617.MSVBVM60(?,?,00000005), ref: 004C5927
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004C594F
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 004C5969
      • __vbaChkstk.MSVBVM60 ref: 004C59B5
      • __vbaChkstk.MSVBVM60 ref: 004C59E4
      • __vbaLateMemCallSt.MSVBVM60(?,Option,00000001), ref: 004C5A19
      • __vbaChkstk.MSVBVM60 ref: 004C5A69
      • __vbaChkstk.MSVBVM60 ref: 004C5A98
      • __vbaChkstk.MSVBVM60 ref: 004C5AC7
      • __vbaLateMemCall.MSVBVM60(?,Open,00000003), ref: 004C5AFC
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004C5B18
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004C5B30
      • __vbaChkstk.MSVBVM60 ref: 004C5B8D
      • __vbaChkstk.MSVBVM60 ref: 004C5BBC
      • __vbaChkstk.MSVBVM60 ref: 004C5BEB
      • __vbaLateMemCall.MSVBVM60(?,SetCredentials,00000003), ref: 004C5C20
      • __vbaChkstk.MSVBVM60 ref: 004C5C49
      • __vbaLateMemCall.MSVBVM60(?,SetAutoLogonPolicy,00000001), ref: 004C5C7E
      • __vbaChkstk.MSVBVM60 ref: 004C5CBB
      • __vbaChkstk.MSVBVM60 ref: 004C5CEA
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C5D1F
      • __vbaChkstk.MSVBVM60 ref: 004C5D5C
      • __vbaChkstk.MSVBVM60 ref: 004C5D8B
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C5DC0
      • __vbaChkstk.MSVBVM60 ref: 004C5DFD
      • __vbaChkstk.MSVBVM60 ref: 004C5E2C
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C5E61
      • __vbaLateMemCall.MSVBVM60(?,send,00000000), ref: 004C5E7C
      • __vbaChkstk.MSVBVM60 ref: 004C5EBE
      • __vbaChkstk.MSVBVM60 ref: 004C5EED
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C5F22
      • __vbaChkstk.MSVBVM60 ref: 004C5F5F
      • __vbaChkstk.MSVBVM60 ref: 004C5F8E
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C5FC3
      • __vbaChkstk.MSVBVM60 ref: 004C6000
      • __vbaChkstk.MSVBVM60 ref: 004C602F
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C6064
      • __vbaLateMemCallLd.MSVBVM60(?,?,Status,00000000,First answer: ), ref: 004C60A3
      • __vbaStrErrVarCopy.MSVBVM60(00000000), ref: 004C60AD
      • __vbaStrMove.MSVBVM60 ref: 004C60B8
      • __vbaStrCat.MSVBVM60(00000000), ref: 004C60BF
      • __vbaStrMove.MSVBVM60 ref: 004C60CA
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004C60E3
      • __vbaFreeVar.MSVBVM60 ref: 004C60EF
      • __vbaLateMemCallLd.MSVBVM60(?,?,responseText,00000000), ref: 004C610B
      • #617.MSVBVM60(?,?,00000064), ref: 004C6121
      • __vbaStrErrVarCopy.MSVBVM60(?,ResponseText: ), ref: 004C6133
      • __vbaStrMove.MSVBVM60 ref: 004C613E
      • __vbaStrCat.MSVBVM60(00000000), ref: 004C6145
      • __vbaStrMove.MSVBVM60 ref: 004C6150
      • __vbaStrCat.MSVBVM60( .....,00000000), ref: 004C615C
      • __vbaStrMove.MSVBVM60 ref: 004C6167
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?), ref: 004C6184
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 004C61A1
      • #685.MSVBVM60 ref: 004C61B1
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C61BC
      • __vbaFreeObj.MSVBVM60 ref: 004C61DD
      • __vbaLateMemCallLd.MSVBVM60(?,?,Status,00000000), ref: 004C61F9
      • __vbaStrErrVarCopy.MSVBVM60(?), ref: 004C6206
      • #617.MSVBVM60(?,00000008,00000001), ref: 004C6229
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004C6251
      • __vbaFreeVarList.MSVBVM60(00000003,?,00000008,?), ref: 004C6272
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004C629D
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004C62B7
      • __vbaStrMove.MSVBVM60(WEBUser), ref: 004C62E1
        • Part of subcall function 005130F0: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 005131F9
        • Part of subcall function 005130F0: __vbaStrCmp.MSVBVM60(00000000,00000000), ref: 00513210
        • Part of subcall function 005130F0: __vbaStrCopy.MSVBVM60 ref: 00513232
      • __vbaStrMove.MSVBVM60(WEBpass), ref: 004C62FF
      • #685.MSVBVM60 ref: 004C630C
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C6317
      • __vbaFreeObj.MSVBVM60 ref: 004C6338
      • __vbaChkstk.MSVBVM60 ref: 004C6385
      • __vbaChkstk.MSVBVM60 ref: 004C63B4
      • __vbaChkstk.MSVBVM60 ref: 004C63E3
      • __vbaLateMemCall.MSVBVM60(?,Open,00000003), ref: 004C6418
      • __vbaChkstk.MSVBVM60 ref: 004C6469
      • __vbaChkstk.MSVBVM60 ref: 004C6498
      • __vbaChkstk.MSVBVM60 ref: 004C64C7
        • Part of subcall function 005130F0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,00515C4A,WEBUser), ref: 0051310E
        • Part of subcall function 005130F0: __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 0051313B
        • Part of subcall function 005130F0: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 0051314A
        • Part of subcall function 005130F0: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0051316F
        • Part of subcall function 005130F0: __vbaStrCopy.MSVBVM60 ref: 005131A9
        • Part of subcall function 005130F0: __vbaStrMove.MSVBVM60(?), ref: 005131C4
        • Part of subcall function 005130F0: __vbaStrCopy.MSVBVM60 ref: 005131DB
        • Part of subcall function 005130F0: #685.MSVBVM60 ref: 0051380A
        • Part of subcall function 005130F0: __vbaObjSet.MSVBVM60(?,00000000), ref: 00513815
        • Part of subcall function 005130F0: __vbaFreeObj.MSVBVM60 ref: 00513836
        • Part of subcall function 005130F0: __vbaFreeObj.MSVBVM60(00513893), ref: 00513883
        • Part of subcall function 005130F0: __vbaFreeStr.MSVBVM60 ref: 0051388C
      • __vbaLateMemCall.MSVBVM60(?,SetCredentials,00000003), ref: 004C64FC
      • __vbaChkstk.MSVBVM60 ref: 004C6525
      • __vbaLateMemCall.MSVBVM60(?,SetAutoLogonPolicy,00000001), ref: 004C655A
      • __vbaChkstk.MSVBVM60 ref: 004C6597
      • __vbaChkstk.MSVBVM60 ref: 004C65C6
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C65FB
      • __vbaChkstk.MSVBVM60 ref: 004C6638
      • __vbaChkstk.MSVBVM60 ref: 004C6667
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C669C
      • __vbaChkstk.MSVBVM60 ref: 004C66D9
      • __vbaChkstk.MSVBVM60 ref: 004C6708
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C673D
      • __vbaLateMemCall.MSVBVM60(?,send,00000000), ref: 004C6758
      • __vbaLateMemCallLd.MSVBVM60(?,?,Status,00000000,Second answer: ), ref: 004C677C
      • __vbaStrErrVarCopy.MSVBVM60(00000000), ref: 004C6786
      • __vbaStrMove.MSVBVM60 ref: 004C6791
      • __vbaStrCat.MSVBVM60(00000000), ref: 004C6798
      • __vbaStrMove.MSVBVM60 ref: 004C67A3
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004C67BC
      • __vbaFreeVar.MSVBVM60 ref: 004C67C8
      • __vbaLateMemCallLd.MSVBVM60(?,?,Status,00000000), ref: 004C67E4
      • __vbaStrErrVarCopy.MSVBVM60(?), ref: 004C67F1
      • #617.MSVBVM60(?,00000008,00000001), ref: 004C6814
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004C683C
      • __vbaFreeVarList.MSVBVM60(00000003,?,00000008,?), ref: 004C685D
      • #685.MSVBVM60 ref: 004C687C
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C6887
      • __vbaFreeObj.MSVBVM60 ref: 004C68A8
      • __vbaChkstk.MSVBVM60 ref: 004C68F5
      • __vbaChkstk.MSVBVM60 ref: 004C6924
      • __vbaChkstk.MSVBVM60 ref: 004C6953
      • __vbaLateMemCall.MSVBVM60(?,Open,00000003), ref: 004C6988
      • __vbaChkstk.MSVBVM60 ref: 004C69D9
      • __vbaChkstk.MSVBVM60 ref: 004C6A08
      • __vbaChkstk.MSVBVM60 ref: 004C6A37
      • __vbaLateMemCall.MSVBVM60(?,SetCredentials,00000003), ref: 004C6A6C
      • __vbaChkstk.MSVBVM60 ref: 004C6A95
      • __vbaLateMemCall.MSVBVM60(?,SetAutoLogonPolicy,00000001), ref: 004C6ACA
      • __vbaChkstk.MSVBVM60 ref: 004C6B07
      • __vbaChkstk.MSVBVM60 ref: 004C6B36
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C6B6B
      • __vbaChkstk.MSVBVM60 ref: 004C6BA8
      • __vbaChkstk.MSVBVM60 ref: 004C6BD7
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C6C0C
      • __vbaChkstk.MSVBVM60 ref: 004C6C49
      • __vbaChkstk.MSVBVM60 ref: 004C6C78
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C6CAD
      • __vbaLateMemCall.MSVBVM60(?,send,00000000), ref: 004C6CC8
      • __vbaLateMemCallLd.MSVBVM60(?,?,Status,00000000,Third answer: ), ref: 004C6CEC
      • __vbaStrErrVarCopy.MSVBVM60(00000000), ref: 004C6CF6
      • __vbaStrMove.MSVBVM60 ref: 004C6D01
      • __vbaStrCat.MSVBVM60(00000000), ref: 004C6D08
      • __vbaStrMove.MSVBVM60 ref: 004C6D13
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004C6D2C
      • __vbaFreeVar.MSVBVM60 ref: 004C6D38
      • __vbaLateMemCallLd.MSVBVM60(?,?,Status,00000000), ref: 004C6D54
      • __vbaStrErrVarCopy.MSVBVM60(?), ref: 004C6D61
      • #617.MSVBVM60(?,00000008,00000001), ref: 004C6D84
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004C6DAC
      • __vbaFreeVarList.MSVBVM60(00000003,?,00000008,?), ref: 004C6DCD
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C6DF2
      • #716.MSVBVM60(?,MSXML2.ServerXMLHTTP,00000000), ref: 004C6E0A
      • __vbaObjVar.MSVBVM60(?), ref: 004C6E14
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C6E1F
      • __vbaFreeVar.MSVBVM60 ref: 004C6E28
      • #685.MSVBVM60 ref: 004C6E35
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C6E40
      • __vbaFreeObj.MSVBVM60 ref: 004C6E61
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004C6E7A
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 004C6E93
      • __vbaChkstk.MSVBVM60 ref: 004C6F17
      • __vbaChkstk.MSVBVM60 ref: 004C6F46
      • __vbaChkstk.MSVBVM60 ref: 004C6F75
      • __vbaChkstk.MSVBVM60 ref: 004C6FA4
      • __vbaChkstk.MSVBVM60 ref: 004C6FD3
      • __vbaLateMemCall.MSVBVM60(?,Open,00000005), ref: 004C7008
      • __vbaChkstk.MSVBVM60 ref: 004C7045
      • __vbaChkstk.MSVBVM60 ref: 004C7074
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C70A9
      • __vbaChkstk.MSVBVM60 ref: 004C70E6
      • __vbaChkstk.MSVBVM60 ref: 004C7115
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C714A
      • __vbaChkstk.MSVBVM60 ref: 004C7187
      • __vbaChkstk.MSVBVM60 ref: 004C71B6
      • __vbaLateMemCall.MSVBVM60(?,setRequestHeader,00000002), ref: 004C71EB
      • __vbaChkstk.MSVBVM60 ref: 004C7214
      • __vbaLateMemCall.MSVBVM60(?,send,00000001), ref: 004C7249
      • #685.MSVBVM60 ref: 004C7259
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C7264
      • __vbaFreeObj.MSVBVM60 ref: 004C7285
      • __vbaLateMemCallLd.MSVBVM60(?,?,responseText,00000000), ref: 004C72B4
      • __vbaVarMove.MSVBVM60 ref: 004C72C2
      • __vbaStrCat.MSVBVM60(?,Response Text: ), ref: 004C72D8
      • __vbaStrMove.MSVBVM60 ref: 004C72E3
      • __vbaFreeStr.MSVBVM60(?), ref: 004C72F5
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 004C7321
      • __vbaStrCopy.MSVBVM60 ref: 004C733D
      • __vbaFreeStr.MSVBVM60(?), ref: 004C734F
      • __vbaLateMemCallLd.MSVBVM60(?,?,responseBody,00000000), ref: 004C7370
      • __vbaVarMove.MSVBVM60 ref: 004C737E
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 004C73AA
      • #685.MSVBVM60 ref: 004C73C2
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C73CD
      • __vbaFreeObj.MSVBVM60 ref: 004C73EE
      • __vbaStrCopy.MSVBVM60 ref: 004C7403
      • __vbaStrCopy.MSVBVM60 ref: 004C7411
      • __vbaObjSet.MSVBVM60(?,00000000,CAPICOM.Utilities,00000000,?,?), ref: 004C743E
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004C744E
      • __vbaChkstk.MSVBVM60 ref: 004C7476
      • __vbaLateMemCallLd.MSVBVM60(?,?,BinaryStringToByteArray,00000001), ref: 004C74AF
      • __vbaVar2Vec.MSVBVM60(?,00000000), ref: 004C74C0
      • __vbaAryMove.MSVBVM60(?,?), ref: 004C74D1
      • __vbaFreeVar.MSVBVM60 ref: 004C74DA
      • #685.MSVBVM60 ref: 004C74E7
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C74F2
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C753D
      • __vbaFreeObj.MSVBVM60 ref: 004C756D
      • __vbaVarCopy.MSVBVM60 ref: 004C75A1
      • #685.MSVBVM60 ref: 004C75B3
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C75BE
      • __vbaFreeObj.MSVBVM60 ref: 004C75DF
      • __vbaRefVarAry.MSVBVM60(?), ref: 004C75F0
      • __vbaUbound.MSVBVM60(00000001), ref: 004C75FB
      • #685.MSVBVM60 ref: 004C7611
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C761C
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C7667
      • __vbaFreeObj.MSVBVM60 ref: 004C7697
      • __vbaVar2Vec.MSVBVM60(?,?), ref: 004C76BE
      • __vbaAryMove.MSVBVM60(?,?), ref: 004C76CF
      • #685.MSVBVM60 ref: 004C76DC
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C76E7
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C7732
      • __vbaFreeObj.MSVBVM60 ref: 004C7762
      • __vbaVar2Vec.MSVBVM60(?,?), ref: 004C7785
      • __vbaAryMove.MSVBVM60(?,?), ref: 004C7796
      • __vbaVarCopy.MSVBVM60 ref: 004C77BF
      • #685.MSVBVM60 ref: 004C77CC
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C77D7
      • __vbaFreeObj.MSVBVM60 ref: 004C77F8
      • __vbaUbound.MSVBVM60(00000001,?), ref: 004C780B
      • #685.MSVBVM60 ref: 004C7821
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C782C
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C7877
      • __vbaFreeObj.MSVBVM60 ref: 004C78A7
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C78FA
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7914
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C795A
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7974
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C79BA
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C79D4
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7A1A
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7A34
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7A7A
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7A94
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7ADA
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7AF4
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7B3A
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7B54
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7B9A
      • __vbaGenerateBoundsError.MSVBVM60 ref: 004C7BB4
      • __vbaChkstk.MSVBVM60 ref: 004C7CE9
        • Part of subcall function 004CA210: __vbaChkstk.MSVBVM60(00473D9C,00411816,?,?,004C7D1E,?,00000000), ref: 004CA22E
        • Part of subcall function 004CA210: __vbaVarDup.MSVBVM60(?,00000001,?,00473D9C,00411816), ref: 004CA25B
        • Part of subcall function 004CA210: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00473D9C,00411816), ref: 004CA26A
        • Part of subcall function 004CA210: #685.MSVBVM60(?,00000001,?,00473D9C,00411816), ref: 004CA277
        • Part of subcall function 004CA210: __vbaObjSet.MSVBVM60(?,00000000,?,00000001,?,00473D9C,00411816), ref: 004CA282
        • Part of subcall function 004CA210: __vbaFreeObj.MSVBVM60(?,00000001,?,00473D9C,00411816), ref: 004CA2A3
        • Part of subcall function 004CA210: __vbaStrCopy.MSVBVM60(?,00000001,?,00473D9C,00411816), ref: 004CA2B8
        • Part of subcall function 004CA210: __vbaStrCopy.MSVBVM60(?,00000001,?,00473D9C,00411816), ref: 004CA2C6
        • Part of subcall function 004CA210: __vbaObjSet.MSVBVM60(?,00000000,CAPICOM.Utilities,00000000,?,?), ref: 004CA2F3
        • Part of subcall function 004CA210: __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004CA303
        • Part of subcall function 004CA210: #685.MSVBVM60(?,00473D9C,00411816), ref: 004CA313
        • Part of subcall function 004CA210: __vbaObjSet.MSVBVM60(?,00000000,?,00473D9C,00411816), ref: 004CA31E
        • Part of subcall function 004CA210: __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004CA369
        • Part of subcall function 004CA210: __vbaFreeObj.MSVBVM60 ref: 004CA399
      • __vbaVar2Vec.MSVBVM60(?,?,?,00000000), ref: 004C7D29
      • __vbaAryMove.MSVBVM60(00000000,?), ref: 004C7D3A
      • __vbaFreeVar.MSVBVM60 ref: 004C7D43
      • #685.MSVBVM60 ref: 004C7D50
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C7D5B
      • __vbaFreeObj.MSVBVM60 ref: 004C7D7C
      • __vbaUbound.MSVBVM60(00000001,00000000), ref: 004C7D8F
      • #685.MSVBVM60 ref: 004C7DA5
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C7DB0
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C7DFB
      • __vbaFreeObj.MSVBVM60 ref: 004C7E2B
      • __vbaVarCopy.MSVBVM60 ref: 004C7E5F
      • __vbaRedim.MSVBVM60(00000080,00000001,00000000,00000011,00000001,00000000,00000000), ref: 004C7E7F
      • #685.MSVBVM60 ref: 004C7E8F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C7E9A
      • __vbaFreeObj.MSVBVM60 ref: 004C7EBB
      • #685.MSVBVM60 ref: 004C7EC8
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C7ED3
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C7F1E
      • __vbaFreeObj.MSVBVM60 ref: 004C7F4E
      • #685.MSVBVM60 ref: 004C7F6A
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C7F75
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000002C), ref: 004C7FBD
      • __vbaStrCat.MSVBVM60(?,Problems with CAPI: ), ref: 004C7FDE
      • __vbaStrMove.MSVBVM60 ref: 004C7FE9
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004C8002
      • __vbaFreeObj.MSVBVM60 ref: 004C800E
      • #685.MSVBVM60 ref: 004C801B
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C8026
      • __vbaFreeObj.MSVBVM60 ref: 004C8047
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C805A
      • __vbaStrCopy.MSVBVM60 ref: 004C8071
      • __vbaFreeStr.MSVBVM60(?), ref: 004C8083
      • __vbaVarCopy.MSVBVM60 ref: 004C80AD
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C80C0
      • __vbaStrCopy.MSVBVM60 ref: 004C80D5
      • __vbaFreeStr.MSVBVM60(?), ref: 004C80E7
      • #685.MSVBVM60 ref: 004C80F9
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C8104
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000002C), ref: 004C814C
      • __vbaStrCat.MSVBVM60(?,Couldnt fetch anything: ), ref: 004C816D
      • __vbaStrMove.MSVBVM60 ref: 004C8178
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?), ref: 004C8191
      • __vbaFreeObj.MSVBVM60 ref: 004C819D
      • __vbaVarCopy.MSVBVM60 ref: 004C81C7
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C81DA
      • __vbaStrCopy.MSVBVM60 ref: 004C81F1
      • #685.MSVBVM60 ref: 004C81FE
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C8209
      • __vbaFreeObj.MSVBVM60 ref: 004C822A
      • __vbaAryDestruct.MSVBVM60(00000000,?,004C82DB), ref: 004C82A4
      • __vbaFreeVar.MSVBVM60 ref: 004C82AD
      • __vbaAryDestruct.MSVBVM60(00000000,?), ref: 004C82B9
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Chkstk$CallLate$#685$Copy$Move$Error$BoundsGenerate$CheckHresultList$Addref$#617#716$Var2$Ubound$#518Destruct$Redim
      • String ID: .....$2. Failed$3. Failed$4. Failed$BinaryStringToByteArray$CAPICOM.Utilities$Cache-Control$Couldnt fetch anything: $First Failed$First answer: $GET$Going finally to download$If-None-Match$MSXML2.ServerXMLHTTP$Microsoft.XMLHTTP$Open$Option$Pragma$Problems with CAPI: $Response Body empty$Response Text: $ResponseText: $Second answer: $SetAutoLogonPolicy$SetCredentials$Status$Third answer: $WEBUser$WEBpass$WinHttp.WinHttpRequest$WinHttp.WinHttpRequest.5.1$finished GetURL$going to fetch: $http$http://$https$no-cache$no-cache,max-age=0$responseBody$responseText$send$setRequestHeader$some-random-string$~
      • API String ID: 2967018790-873753605
      • Opcode ID: e49fc00d2777c839704e27559e76bdb76555b5b02c5cbae913ceb393196c3bd5
      • Instruction ID: a4166873ffb9cce9754ed04abb86a683d9a70660b8c2eb06b651dc55454f42db
      • Opcode Fuzzy Hash: e49fc00d2777c839704e27559e76bdb76555b5b02c5cbae913ceb393196c3bd5
      • Instruction Fuzzy Hash: 9D63F674A00218DFDB54DFA4C988BDDBBB5FF48304F10C1AAE509AB2A1DB749A85CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,00515C4A,WEBUser), ref: 0051310E
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 0051313B
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 0051314A
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0051316F
      • __vbaStrCopy.MSVBVM60 ref: 005131A9
        • Part of subcall function 0051AEC0: __vbaChkstk.MSVBVM60(00000000,00411816,?), ref: 0051AEDE
        • Part of subcall function 0051AEC0: __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816,?), ref: 0051AF0B
        • Part of subcall function 0051AEC0: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816,?), ref: 0051AF1A
        • Part of subcall function 0051AEC0: __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816,?), ref: 0051AF2D
        • Part of subcall function 0051AEC0: __vbaStrCmp.MSVBVM60(true,00000000,?,00000000,00000000,00000000,00411816,?), ref: 0051AF45
        • Part of subcall function 0051AEC0: #685.MSVBVM60(?,00000000,00000000,00000000,00411816,?), ref: 0051AF70
        • Part of subcall function 0051AEC0: __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,00000000,00411816,?), ref: 0051AF7B
        • Part of subcall function 0051AEC0: __vbaFreeObj.MSVBVM60(?,00000000,00000000,00000000,00411816,?), ref: 0051AF9C
        • Part of subcall function 0051AEC0: __vbaChkstk.MSVBVM60 ref: 0051AFC8
        • Part of subcall function 0051AEC0: __vbaChkstk.MSVBVM60 ref: 0051AFEB
        • Part of subcall function 0051AEC0: __vbaLateMemCallLd.MSVBVM60(?,00000000,scrmread,00000002), ref: 0051B01B
        • Part of subcall function 0051AEC0: __vbaI4Var.MSVBVM60(00000000,?,?,?,?,?,?,?,?,00000000,00000000,00000000,00411816,?), ref: 0051B025
        • Part of subcall function 0051AEC0: __vbaFreeVar.MSVBVM60(?,?,?,?,?,?,?,?,00000000,00000000,00000000,00411816,?), ref: 0051B031
        • Part of subcall function 0051AEC0: #685.MSVBVM60(?,?,?,?,?,?,?,?,00000000,00000000,00000000,00411816,?), ref: 0051B03E
        • Part of subcall function 0051AEC0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,?,?,?,?,00000000,00000000,00000000,00411816,?), ref: 0051B049
      • __vbaStrMove.MSVBVM60(?), ref: 005131C4
      • __vbaStrCopy.MSVBVM60 ref: 005131DB
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 005131F9
      • __vbaStrCmp.MSVBVM60(00000000,00000000), ref: 00513210
      • __vbaStrCopy.MSVBVM60 ref: 00513232
      • #685.MSVBVM60 ref: 0051380A
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00513815
      • __vbaFreeObj.MSVBVM60 ref: 00513836
      • __vbaFreeObj.MSVBVM60(00513893), ref: 00513883
      • __vbaFreeStr.MSVBVM60 ref: 0051388C
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Copy$Free$Chkstk$#685$Error$CallLateMove
      • String ID: *$AloahaInter.SemaPhore$AloahaInter.dll$J\Q$PermanentCache$WaitingForSemaphore$aloaha\AloahaInter.dll$crypterkey$cspkey$get_PIN$key$saverkey$true
      • API String ID: 635868966-1682404667
      • Opcode ID: 4effcf88229c56d175f70b0d8ea6cc2587eaa6fbf0b37200aa8d1c2e40efeeff
      • Instruction ID: 7b7c776a5e38135b2f859d6f1a6ed68aea7d87f58d87cc10409a646f1702d884
      • Opcode Fuzzy Hash: 4effcf88229c56d175f70b0d8ea6cc2587eaa6fbf0b37200aa8d1c2e40efeeff
      • Instruction Fuzzy Hash: C1224874A00219EFEB14DFA4DA48BDDBBB5FF48304F1081A9E506BB2A0DB749A45CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0051BCDE
      • __vbaStrCopy.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0051BD0B
      • __vbaStrCopy.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0051BD17
      • __vbaStrCopy.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0051BD23
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,00000000,00000000,00411816), ref: 0051BD32
      • __vbaStrCat.MSVBVM60(?,ProcessLauncher: ,?,00000001,00000000,00000000,00411816), ref: 0051BD48
      • __vbaStrMove.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0051BD53
      • __vbaStrCat.MSVBVM60( / ,00000000,?,00000001,00000000,00000000,00411816), ref: 0051BD5F
      • __vbaStrMove.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0051BD6A
      • __vbaStrCat.MSVBVM60(00000001,00000000,?,00000001,00000000,00000000,00411816), ref: 0051BD75
      • __vbaStrMove.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0051BD80
      • __vbaStrCat.MSVBVM60( / ,00000000,?,00000001,00000000,00000000,00411816), ref: 0051BD8C
      • __vbaStrMove.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0051BD97
      • __vbaStrCat.MSVBVM60(?,00000000,?,00000001,00000000,00000000,00411816), ref: 0051BDA2
      • __vbaStrMove.MSVBVM60(?,00000001,00000000,00000000,00411816), ref: 0051BDAD
      • __vbaFreeStrList.MSVBVM60(00000005,?,?,?,?,?,?,?,00000001,00000000,00000000,00411816), ref: 0051BDD2
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 0051BDEB
      • #619.MSVBVM60(?,00004008,00000001), ref: 0051BE20
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0051BE45
      • __vbaFreeVar.MSVBVM60 ref: 0051BE55
      • __vbaStrCat.MSVBVM60(004775E8,?), ref: 0051BE76
      • __vbaStrMove.MSVBVM60 ref: 0051BE81
      • __vbaStrCopy.MSVBVM60 ref: 0051BE94
      • __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001), ref: 0051BEAE
      • __vbaInStr.MSVBVM60(00000000,004775E8,00000001,00000001), ref: 0051BED0
      • #520.MSVBVM60(?,00004008), ref: 0051BF03
      • #520.MSVBVM60(?,00004008), ref: 0051BF27
      • __vbaVarAdd.MSVBVM60(?,?,?), ref: 0051BF39
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0051BF40
      • __vbaStrMove.MSVBVM60 ref: 0051BF4B
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?), ref: 0051BF5F
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 0051BF78
      • #685.MSVBVM60 ref: 0051BF8D
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0051BF98
      • __vbaFreeObj.MSVBVM60 ref: 0051BFB9
      • #520.MSVBVM60(?,00004008), ref: 0051BFE4
      • #645.MSVBVM60(?,00000000), ref: 0051BFF0
      • __vbaStrMove.MSVBVM60 ref: 0051BFFB
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0051C007
      • __vbaFreeStr.MSVBVM60 ref: 0051C01F
      • __vbaFreeVar.MSVBVM60 ref: 0051C028
      • #685.MSVBVM60 ref: 0051C044
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0051C04F
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0051C09A
      • __vbaFreeObj.MSVBVM60 ref: 0051C0CA
      • #608.MSVBVM60(?,00000022), ref: 0051C0EC
      • #608.MSVBVM60(?,00000022), ref: 0051C10B
      • __vbaVarAdd.MSVBVM60(?,00000008,?), ref: 0051C120
      • __vbaVarAdd.MSVBVM60(?,?,00000000), ref: 0051C132
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 0051C139
      • __vbaStrMove.MSVBVM60 ref: 0051C144
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 0051C15F
      • __vbaStrCopy.MSVBVM60 ref: 0051C175
      • #619.MSVBVM60(?,00004008,00000001), ref: 0051C1A2
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0051C1C7
      • __vbaFreeVar.MSVBVM60 ref: 0051C1D7
      • __vbaStrCat.MSVBVM60(004775E8,?), ref: 0051C1F8
      • __vbaStrMove.MSVBVM60 ref: 0051C203
      • #520.MSVBVM60(?,00004008), ref: 0051C22E
      • __vbaStrToAnsi.MSVBVM60(?,?,00000001), ref: 0051C23E
      • __vbaStrVarVal.MSVBVM60(?,?,00000000), ref: 0051C24D
      • __vbaStrToAnsi.MSVBVM60(?,00000000), ref: 0051C258
      • __vbaStrToAnsi.MSVBVM60(?,?,00000000), ref: 0051C267
      • __vbaStrToAnsi.MSVBVM60(?,Open,00000000), ref: 0051C277
      • __vbaSetSystemError.MSVBVM60(00000000,00000000), ref: 0051C285
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 0051C293
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 0051C2A1
      • __vbaFreeStrList.MSVBVM60(00000005,?,?,?,?,?), ref: 0051C2BD
      • __vbaFreeVar.MSVBVM60 ref: 0051C2C9
      • #685.MSVBVM60 ref: 0051C2D6
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0051C2E1
      • __vbaFreeObj.MSVBVM60 ref: 0051C302
      • __vbaFreeStr.MSVBVM60(0051C384), ref: 0051C359
      • __vbaFreeStr.MSVBVM60 ref: 0051C362
      • __vbaFreeStr.MSVBVM60 ref: 0051C36B
      • __vbaFreeStr.MSVBVM60 ref: 0051C374
      • __vbaFreeStr.MSVBVM60 ref: 0051C37D
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$Copy$#520AnsiList$#685$#608#619ErrorUnicode$#645CheckChkstkHresultSystem
      • String ID: / $Open$ProcessLauncher:
      • API String ID: 3165597936-1551329386
      • Opcode ID: 75c55a53eb253768d63508f386c46e002dd07f94a17613cdd003531365e4af04
      • Instruction ID: ea1ef4a85e0d3025dede44734f6f56361c5ed3474ec5343de6e0325b700a71c5
      • Opcode Fuzzy Hash: 75c55a53eb253768d63508f386c46e002dd07f94a17613cdd003531365e4af04
      • Instruction Fuzzy Hash: D912D675900208EFEB14DFE0DE48BDEBBB8BF48701F1085A9E606B6560DB745A49CF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,00411816), ref: 004C906E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 004C909E
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C90B3
      • __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C90D8
      • __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C90F1
      • #685.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C90FE
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,00000000,00411816), ref: 004C9109
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C912A
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816), ref: 004C9140
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C915D
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C916B
      • __vbaObjSet.MSVBVM60(00000000,00000000,CAPICOM.EncryptedData,00000000,?,?), ref: 004C9192
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004C91A2
      • #685.MSVBVM60(00000000,00000000,00411816), ref: 004C91B2
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C91BD
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C91F0
      • __vbaFreeObj.MSVBVM60 ref: 004C921A
      • __vbaChkstk.MSVBVM60 ref: 004C9246
        • Part of subcall function 004C8C90: __vbaChkstk.MSVBVM60(00000000,00411816,004C90D3,?,00000000,00000000,00000000,00411816), ref: 004C8CAE
        • Part of subcall function 004C8C90: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8CDE
        • Part of subcall function 004C8C90: __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8CF3
        • Part of subcall function 004C8C90: __vbaStrCat.MSVBVM60(MIIC3AYJKwYBBAGCN1gDoIICzTCCAskGCisGAQQBgjdYAwGgggK5MIICtQIDAgAB,00000000,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D09
        • Part of subcall function 004C8C90: __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D14
        • Part of subcall function 004C8C90: __vbaStrCat.MSVBVM60(AgJoAQICAIAEAAQQeVSZOWEBLf6wbkOKaXH3mASCApDl+CWmeiJz7v3rqgTPuzdU,00000000,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D2A
        • Part of subcall function 004C8C90: __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D35
        • Part of subcall function 004C8C90: __vbaStrCat.MSVBVM60(gI3dOWF1kcvcBmkkeMTmztgai9JdDKoz6XD/ydsKhFSuOqLUolyz8yxwpwfjLBbZ,00000000,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D4B
        • Part of subcall function 004C8C90: __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D56
        • Part of subcall function 004C8C90: __vbaStrCat.MSVBVM60(oLKO85GUdQDMQbKZFEhGu2bjB1J3PjI3VlK1c+b+mtDLuga0SMZ1peGEGvQZlj5t,00000000,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D6C
        • Part of subcall function 004C8C90: __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D77
        • Part of subcall function 004C8C90: __vbaStrCat.MSVBVM60(jdvHBwuI8WSP+MHAFIEoUklWOvM3yDR+DmbxoMyp+v04daNl7aKZL08na7VVTWAS,00000000,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D8D
        • Part of subcall function 004C8C90: __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8D98
        • Part of subcall function 004C8C90: __vbaStrCat.MSVBVM60(yzD+Y7dDIiWbQf5FYjKijsF5xz7hNGIcZw/j60PjXsFVBv/uw7ZlkNiyrOFJuwy6,00000000,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8DAE
        • Part of subcall function 004C8C90: __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8DB9
        • Part of subcall function 004C8C90: __vbaStrCat.MSVBVM60(fOlLZ7qpxbe1PVaB4CW00eBkRk2B2OPyCYVJ8W1k/Z56XDF3yBGxW8mZmjE0mJu7,00000000,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8DCF
        • Part of subcall function 004C8C90: __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8DDA
        • Part of subcall function 004C8C90: __vbaStrCat.MSVBVM60(1pTrk2f6I8fFRaHt+a2Nt6Io38v25dx8kfKi9BN2juGslJ86SSGuhmQOKrKK3XLi,00000000,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8DF0
        • Part of subcall function 004C8C90: __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8DFB
        • Part of subcall function 004C8C90: __vbaStrCat.MSVBVM60(0AQEildJ4rguV8NTVRF09JHDJUcHrrWkY4k+5r1of4CI7PMIbS3gjh48+tpkwaFf,00000000,?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8E11
        • Part of subcall function 004C8C90: __vbaStrMove.MSVBVM60(?,00000000,00000000,00000000,00411816,004C90D3), ref: 004C8E1C
      • __vbaLateMemSt.MSVBVM60(?,Algorithm), ref: 004C926D
      • __vbaChkstk.MSVBVM60 ref: 004C928D
      • __vbaLateMemCallLd.MSVBVM60(?,?,Algorithm,00000000,KeyLength), ref: 004C92BF
      • __vbaVarLateMemSt.MSVBVM60(00000000), ref: 004C92C9
      • __vbaFreeVar.MSVBVM60 ref: 004C92D2
      • __vbaChkstk.MSVBVM60 ref: 004C92F2
      • __vbaLateMemCallLd.MSVBVM60(?,?,Algorithm,00000000,Name), ref: 004C9324
      • __vbaVarLateMemSt.MSVBVM60(00000000), ref: 004C932E
      • __vbaFreeVar.MSVBVM60 ref: 004C9337
      • __vbaChkstk.MSVBVM60 ref: 004C9357
      • __vbaLateMemCall.MSVBVM60(?,SetSecret,00000001), ref: 004C9380
      • __vbaChkstk.MSVBVM60 ref: 004C93A2
      • __vbaLateMemCall.MSVBVM60(?,decrypt,00000001), ref: 004C93CB
      • __vbaLateMemCallLd.MSVBVM60(?,?,Content,00000000), ref: 004C93EA
      • __vbaStrVarMove.MSVBVM60(00000000), ref: 004C93F4
      • __vbaStrMove.MSVBVM60 ref: 004C93FF
      • __vbaFreeVar.MSVBVM60 ref: 004C9408
      • #685.MSVBVM60 ref: 004C9415
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004C9420
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004C9453
      • __vbaR8Str.MSVBVM60(?), ref: 004C946F
      • __vbaFreeObj.MSVBVM60 ref: 004C94B5
      • __vbaStrCopy.MSVBVM60 ref: 004C94D0
      • __vbaStrCopy.MSVBVM60 ref: 004C94E5
      • __vbaObjSetAddref.MSVBVM60(?,00000000), ref: 004C94F8
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C950D
      • #685.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C951A
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,00000000,00411816), ref: 004C9525
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C9546
      • __vbaFreeStr.MSVBVM60(004C95A0,?,00000000,00000000,00000000,00411816), ref: 004C9590
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004C9599
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Move$Free$Late$ChkstkCopy$Call$#685$CheckErrorHresult$AddrefList
      • String ID: Algorithm$CAPICOM.EncryptedData$Content$KeyLength$Name$NielsPhillip$SetSecret$decrypt
      • API String ID: 3820706982-1097305013
      • Opcode ID: 645484c6b9f22cc4740680d799325c8672a2e0a668149622b0a923d6af68f687
      • Instruction ID: ef41ada4d9597a34c7aa585e7105d985f75176a0e485b540f55a5a5b4d540d74
      • Opcode Fuzzy Hash: 645484c6b9f22cc4740680d799325c8672a2e0a668149622b0a923d6af68f687
      • Instruction Fuzzy Hash: C3F10675900208EFDB14DFA4DA48BDDBBB4FF48305F208169E506BB2A1DBB89A45CF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0050A81E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 0050A84E
      • #685.MSVBVM60(?,00000000), ref: 0050A868
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,00000000), ref: 0050A873
      • __vbaFreeObj.MSVBVM60(?,00000000), ref: 0050A88B
      • __vbaLenBstr.MSVBVM60(?,?,00000000), ref: 0050A89E
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,?,00000000), ref: 0050A8B6
      • __vbaStrCat.MSVBVM60(?,callit: ,?,?,00000000), ref: 0050A8DE
      • __vbaStrMove.MSVBVM60(?,callit: ,?,?,00000000), ref: 0050A8E9
      • __vbaFreeStr.MSVBVM60(?,?,callit: ,?,?,00000000), ref: 0050A8FB
      • #685.MSVBVM60(?,callit: ,?,?,00000000), ref: 0050A908
      • __vbaObjSet.MSVBVM60(?,00000000,?,callit: ,?,?,00000000), ref: 0050A913
      • __vbaFreeObj.MSVBVM60(?,callit: ,?,?,00000000), ref: 0050A934
      • __vbaChkstk.MSVBVM60 ref: 0050A961
      • __vbaLateMemCallLd.MSVBVM60(?,00000000,Run,00000001), ref: 0050A990
      • __vbaI4Var.MSVBVM60(00000000), ref: 0050A99A
      • __vbaFreeVar.MSVBVM60 ref: 0050A9A6
      • #685.MSVBVM60 ref: 0050A9B3
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050A9BE
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050A9F1
      • __vbaFreeObj.MSVBVM60 ref: 0050AA1B
      • __vbaObjSetAddref.MSVBVM60(0054D4D0,00000000), ref: 0050AA3B
      • __vbaStrCopy.MSVBVM60 ref: 0050AA50
      • __vbaFreeStr.MSVBVM60(?), ref: 0050AA62
      • #685.MSVBVM60 ref: 0050AA6F
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050AA7A
      • __vbaFreeObj.MSVBVM60 ref: 0050AA9B
      • #716.MSVBVM60(?,WScript.Shell,00000000), ref: 0050AAB3
      • __vbaObjVar.MSVBVM60(?), ref: 0050AABD
      • __vbaObjSetAddref.MSVBVM60(0054D4D0,00000000), ref: 0050AAC9
      • __vbaFreeVar.MSVBVM60 ref: 0050AAD2
      • __vbaChkstk.MSVBVM60 ref: 0050AAFF
      • __vbaLateMemCallLd.MSVBVM60(?,00000000,Run,00000001), ref: 0050AB2F
      • __vbaI4Var.MSVBVM60(00000000), ref: 0050AB39
      • __vbaFreeVar.MSVBVM60 ref: 0050AB45
      • #685.MSVBVM60 ref: 0050AB52
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 0050AB5D
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050AB90
      • __vbaFreeObj.MSVBVM60 ref: 0050ABBA
      • #600.MSVBVM60(00004008,00000001), ref: 0050ABE2
      • __vbaStrCat.MSVBVM60(00000000,Callit is false, but tried shell command: ), ref: 0050ABFD
      • __vbaStrMove.MSVBVM60 ref: 0050AC08
      • __vbaFreeStr.MSVBVM60(?), ref: 0050AC1A
      • #685.MSVBVM60(?,?,00000000), ref: 0050AC43
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,00000000), ref: 0050AC4E
      • __vbaFreeObj.MSVBVM60(?,?,00000000), ref: 0050AC6F
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685$Chkstk$AddrefCallCheckHresultLateMove$#600#716BstrCopyError
      • String ID: Callit is false, but tried shell command: $ObjShell could not start$Run$WScript.Shell$callit:
      • API String ID: 3526936777-3259931088
      • Opcode ID: f39e765a6d917249ecb25ba914de0c7cb0e52ee16edd29a20d4aa4c39b5405df
      • Instruction ID: 738eb606141f0ae1670b20015f8f260ee3fd127e8a741ef7ab524e01c47d64be
      • Opcode Fuzzy Hash: f39e765a6d917249ecb25ba914de0c7cb0e52ee16edd29a20d4aa4c39b5405df
      • Instruction Fuzzy Hash: BFD114B5900308EFDB04DFA4DA88BDDBBB4FF48705F108569E506BB2A0DB749A49CB54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,00000000,00411816), ref: 0051D01E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 0051D04E
      • __vbaStrCmp.MSVBVM60(true,0077F45C,?,?,?,?,00411816), ref: 0051D066
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 0051D093
      • __vbaStrCopy.MSVBVM60 ref: 0051D319
      • #685.MSVBVM60 ref: 0051D326
      • __vbaObjSet.MSVBVM60(00000000,00000000), ref: 0051D331
      • __vbaFreeObj.MSVBVM60 ref: 0051D352
      • __vbaFreeStr.MSVBVM60(0051D393), ref: 0051D383
      • __vbaFreeStr.MSVBVM60 ref: 0051D38C
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Copy$#685ChkstkError
      • String ID: &$lsass$lsass.exe$true
      • API String ID: 1101828390-3999059111
      • Opcode ID: ae07d415715089976d9f77baadf9b76b40ae6dcf89cae4c95cadedc57f15a196
      • Instruction ID: 6d2f597387584afad4bd1751348410e65c0fb36b0c92df7013818375d9a0f238
      • Opcode Fuzzy Hash: ae07d415715089976d9f77baadf9b76b40ae6dcf89cae4c95cadedc57f15a196
      • Instruction Fuzzy Hash: 3E912C75900208DFEB14DFD0DE48BEDBBB8FB48704F108469E505B72A0DBB45A49DB65
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00411816), ref: 0050901E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 0050904E
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 0050907A
      • __vbaStrCat.MSVBVM60(INSTALLDIR,HKLM\Software\Aloaha\pdf\), ref: 00509098
      • __vbaStrMove.MSVBVM60 ref: 005090A3
      • __vbaVarMove.MSVBVM60(?), ref: 005090C2
      • __vbaFreeStr.MSVBVM60 ref: 005090CB
      • __vbaVarTstEq.MSVBVM60(00008008,?), ref: 005090F7
      • __vbaNew2.MSVBVM60(00477E14,0054ED28), ref: 00509122
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00477E04,00000014), ref: 00509188
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,0047A994,00000050), ref: 005091E5
      • __vbaVarMove.MSVBVM60 ref: 00509223
      • __vbaFreeObj.MSVBVM60 ref: 0050922C
      • #619.MSVBVM60(?,?,00000001), ref: 00509243
      • #619.MSVBVM60(?,?,00000004), ref: 00509267
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?), ref: 00509290
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?,00000000), ref: 005092A6
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 005092B4
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 005092BB
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 005092D2
      • __vbaVarAdd.MSVBVM60(?,00000008,?), ref: 00509310
      • __vbaVarMove.MSVBVM60 ref: 0050931B
      • #619.MSVBVM60(?,?,00000004,?,00000000,00411816), ref: 00509332
      • __vbaVarTstNe.MSVBVM60(00008008,?), ref: 00509357
      • __vbaFreeVar.MSVBVM60 ref: 00509367
      • __vbaVarAdd.MSVBVM60(?,00000008,?), ref: 005093A2
      • __vbaVarMove.MSVBVM60 ref: 005093AD
      • __vbaFreeVar.MSVBVM60(005093F9), ref: 005093F2
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$FreeMove$#619$CheckHresult$BoolChkstkErrorListNew2Null
      • String ID: (T$.ini$HKLM\Software\Aloaha\pdf\$INSTALLDIR$aloaha.ini
      • API String ID: 1677252627-4150857336
      • Opcode ID: 6a318e11e4d4fe1add5308877a476dc4cd8a147e759e6ee30b20991bdd73af6b
      • Instruction ID: 050aa982c7ff0609d2b4a7bcd2d69300489016b9d7f04e0556b4172e589369ca
      • Opcode Fuzzy Hash: 6a318e11e4d4fe1add5308877a476dc4cd8a147e759e6ee30b20991bdd73af6b
      • Instruction Fuzzy Hash: 4FB139B5900218EFDB14DFA0DD48BDEBBB4BF44304F1085AAE509B72A0DB745A88CF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816), ref: 00531C6E
      • __vbaFixstrConstruct.MSVBVM60(000000FF,00000000,6D62D8B1,00000000,6D62D8CD,00000000,00411816), ref: 00531C9E
      • __vbaOnError.MSVBVM60(000000FF), ref: 00531CAD
      • __vbaStrToAnsi.MSVBVM60(?,?), ref: 00531CC2
      • __vbaLenBstr.MSVBVM60(?,00000000), ref: 00531CCD
      • __vbaSetSystemError.MSVBVM60(00000000), ref: 00531CDF
      • __vbaStrToUnicode.MSVBVM60(?,?), ref: 00531CED
      • __vbaLsetFixstr.MSVBVM60(00000000,?,00000000), ref: 00531CFA
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 00531D13
      • #608.MSVBVM60(?,00000000), ref: 00531D3C
      • __vbaInStrVar.MSVBVM60(?,00000000,?,00000008,00000001), ref: 00531D69
      • __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 00531D77
      • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 00531D8E
      • #608.MSVBVM60(?,00000000), ref: 00531DB3
      • __vbaStrCopy.MSVBVM60(?,000000FF,00000000), ref: 00531DDB
      • #711.MSVBVM60(?,00000000), ref: 00531DE6
      • __vbaLsetFixstr.MSVBVM60(00000000,?,?), ref: 00531DF6
      • __vbaChkstk.MSVBVM60 ref: 00531E01
      • __vbaVarIndexLoadRefLock.MSVBVM60(?,?,?,00000001), ref: 00531E39
      • #520.MSVBVM60(?,00000000), ref: 00531E47
      • __vbaAryUnlock.MSVBVM60(?), ref: 00531E51
      • __vbaStrVarMove.MSVBVM60(?), ref: 00531E5B
      • __vbaStrMove.MSVBVM60 ref: 00531E66
      • __vbaFreeStr.MSVBVM60 ref: 00531E6F
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 00531E87
      • __vbaStrCopy.MSVBVM60 ref: 00531E9F
      • #520.MSVBVM60(?,00004008), ref: 00531EC3
      • __vbaLsetFixstr.MSVBVM60(00000000,?,?), ref: 00531ED3
      • __vbaStrVarMove.MSVBVM60(?), ref: 00531EDD
      • __vbaStrMove.MSVBVM60 ref: 00531EE8
      • __vbaFreeStr.MSVBVM60 ref: 00531EF1
      • __vbaFreeVar.MSVBVM60 ref: 00531EFA
      • __vbaStrCopy.MSVBVM60 ref: 00531F0D
      • #685.MSVBVM60 ref: 00531F1A
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00531F25
      • __vbaFreeObj.MSVBVM60 ref: 00531F46
      • __vbaFreeStr.MSVBVM60(00531FBB), ref: 00531FAB
      • __vbaFreeStr.MSVBVM60 ref: 00531FB4
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$FixstrMove$CopyListLset$#520#608ChkstkError$#685#711AnsiBstrConstructIndexLoadLockSystemUnicodeUnlock
      • String ID:
      • API String ID: 756034873-0
      • Opcode ID: 123a9a798778a9c848f65578d24586875c36710e388746084d18dafff5c7861c
      • Instruction ID: cc4f320992b8934d00039fb8c0b3d1baa3e3d7c8fd715a6b6546f38c3e8b2e0b
      • Opcode Fuzzy Hash: 123a9a798778a9c848f65578d24586875c36710e388746084d18dafff5c7861c
      • Instruction Fuzzy Hash: 38A1D675900218EFDB04DFA0DD48BEEBB78BB48705F148169F606B72A0DB745A88CF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,004A735F,?,any,noreader,?), ref: 004D045E
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D048B
      • __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D0497
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D04A6
      • #520.MSVBVM60(?,00004008), ref: 004D04ED
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004D0510
      • __vbaVarCmpNe.MSVBVM60(?,00008008,?,0000000B), ref: 004D0545
      • __vbaVarAnd.MSVBVM60(?,00000000), ref: 004D0550
      • __vbaVarAnd.MSVBVM60(?,0000000B,00000000), ref: 004D0562
      • __vbaBoolVarNull.MSVBVM60(00000000), ref: 004D0569
      • __vbaFreeVarList.MSVBVM60(00000003,?,0000000B,0000000B), ref: 004D058A
      • #608.MSVBVM60(?,00000000,?,?,00000000,00411816), ref: 004D05BB
      • #608.MSVBVM60(?,00000000,?,?,00000000,00411816), ref: 004D05CA
      • __vbaStrI4.MSVBVM60(000000FF,doaction:,?,?,00000000,00411816), ref: 004D05D9
      • __vbaStrMove.MSVBVM60(?,?,00000000,00411816), ref: 004D05E4
      • __vbaStrCat.MSVBVM60(00000000,?,?,00000000,00411816), ref: 004D05EB
      • __vbaVarAdd.MSVBVM60(?,?,00000008,00405FA8), ref: 004D0631
      • __vbaVarAdd.MSVBVM60(?,00000008,00000000), ref: 004D0643
      • __vbaVarAdd.MSVBVM60(?,?,00000000), ref: 004D0658
      • __vbaVarAdd.MSVBVM60(?,00000008,00000000), ref: 004D066D
      • __vbaStrVarVal.MSVBVM60(?,00000000), ref: 004D0678
        • Part of subcall function 004D22A0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,00000000,00411816), ref: 004D22BE
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D22EB
        • Part of subcall function 004D22A0: __vbaAryConstruct2.MSVBVM60(?,004842F4,00000011,?,?,?,00000000,00411816), ref: 004D22FC
        • Part of subcall function 004D22A0: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D230B
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816), ref: 004D232C
        • Part of subcall function 004D22A0: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,00000000,00411816), ref: 004D2344
        • Part of subcall function 004D22A0: __vbaInStr.MSVBVM60(00000000,004775E8,?,00000001,?,?,?,?,00000000,00411816), ref: 004D2364
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,00000001,?,?,?,?,00000000,00411816), ref: 004D237D
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D2392
        • Part of subcall function 004D22A0: __vbaLenBstr.MSVBVM60(?,?,?,?,?,00000000,00411816), ref: 004D23A3
        • Part of subcall function 004D22A0: __vbaStrCopy.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D23C0
        • Part of subcall function 004D22A0: __vbaStrMove.MSVBVM60(?,?,encrypted:,?,?,?,?,00000000,00411816), ref: 004D23DD
        • Part of subcall function 004D22A0: __vbaStrCat.MSVBVM60(00000000,?,?,?,?,00000000,00411816), ref: 004D23E4
        • Part of subcall function 004D22A0: __vbaStrMove.MSVBVM60(?,?,?,?,00000000,00411816), ref: 004D23EF
        • Part of subcall function 004D22A0: __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,?,00000000,00411816), ref: 004D23FF
        • Part of subcall function 004D22A0: __vbaInStr.MSVBVM60(00000000,0047C158,?,00000001,?,00000000,00411816), ref: 004D241C
      • __vbaStrMove.MSVBVM60(00000000), ref: 004D0689
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 004D0699
      • __vbaFreeVarList.MSVBVM60(00000007,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00411816), ref: 004D06C9
      • #685.MSVBVM60(?,?,00000000,00411816), ref: 004D06D9
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,00000000,00411816), ref: 004D06E4
      • __vbaFreeObj.MSVBVM60(?,?,00000000,00411816), ref: 004D0705
      • __vbaFreeStr.MSVBVM60(004D077B,?,?,00000000,00411816), ref: 004D0762
      • __vbaFreeStr.MSVBVM60(?,?,00000000,00411816), ref: 004D076B
      • __vbaFreeStr.MSVBVM60(?,?,00000000,00411816), ref: 004D0774
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Copy$ListMove$#608ChkstkError$#520#685BoolBstrConstruct2Null
      • String ID: doaction:
      • API String ID: 616430837-2036965812
      • Opcode ID: dbfc6afe6ebab783b0244b79ca1a756d679931389d9a504d6005458c7ad58177
      • Instruction ID: b4d46bb93231143491e5caf5841957a6ddfbac34f7da2882b7b2ef3f5df3c879
      • Opcode Fuzzy Hash: dbfc6afe6ebab783b0244b79ca1a756d679931389d9a504d6005458c7ad58177
      • Instruction Fuzzy Hash: BF91DCB6800258ABDB15DFA0DD48FDEBB78BF48701F10859AF50AB7160DB745A88CF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,?,?,004B93A3,?,?), ref: 004E68EE
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004E691B
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,?,00411816), ref: 004E692A
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,?,00411816), ref: 004E6940
      • __vbaStrMove.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004E695F
      • __vbaStrCat.MSVBVM60(:UoDC,00000000,?,00000000,00000000,?,00411816), ref: 004E696B
      • __vbaStrMove.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004E6976
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004E6984
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004E6992
        • Part of subcall function 00506210: __vbaChkstk.MSVBVM60(?,00411816,?,005309BD,?,?,?,?,?,00000000,?,00000000,00411816), ref: 0050622E
        • Part of subcall function 00506210: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,?,00411816), ref: 0050625E
        • Part of subcall function 00506210: #619.MSVBVM60(?,00004008,00000001), ref: 0050628B
        • Part of subcall function 00506210: #608.MSVBVM60(?,00000022), ref: 00506297
        • Part of subcall function 00506210: #617.MSVBVM60(?,00004008,00000001), ref: 005062C0
        • Part of subcall function 00506210: #608.MSVBVM60(?,00000022), ref: 005062CF
        • Part of subcall function 00506210: __vbaVarCmpEq.MSVBVM60(?,?,?), ref: 005062E4
        • Part of subcall function 00506210: __vbaVarCmpEq.MSVBVM60(?,?,?,00000000), ref: 00506300
        • Part of subcall function 00506210: __vbaVarAnd.MSVBVM60(?,00000000), ref: 0050630E
        • Part of subcall function 00506210: __vbaBoolVarNull.MSVBVM60(00000000), ref: 00506315
        • Part of subcall function 00506210: __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 0050633A
        • Part of subcall function 00506210: __vbaStrCopy.MSVBVM60(?,00000000,?,?,00411816), ref: 0050635D
        • Part of subcall function 00506210: #619.MSVBVM60(?,00004008,00000001), ref: 005063D5
      • __vbaStrMove.MSVBVM60(?,00000000,?,?,?,00000000,00000000,?,00411816), ref: 004E69B2
      • __vbaFreeStrList.MSVBVM60(00000004,?,?,?,?,?,00000000,00000000,?,00411816), ref: 004E69CA
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004E69E3
      • __vbaStrCat.MSVBVM60(?,providerIsUC:), ref: 004E6A07
      • __vbaStrMove.MSVBVM60 ref: 004E6A12
        • Part of subcall function 004E6B60: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,004E6A1E,00000000), ref: 004E6B7E
        • Part of subcall function 004E6B60: __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004E6BAB
        • Part of subcall function 004E6B60: __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 004E6BB7
        • Part of subcall function 004E6B60: __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 004E6BC6
        • Part of subcall function 004E6B60: #518.MSVBVM60(?,00004008), ref: 004E6BF4
        • Part of subcall function 004E6B60: __vbaVarDup.MSVBVM60 ref: 004E6C1A
        • Part of subcall function 004E6B60: #518.MSVBVM60(?,?), ref: 004E6C2E
        • Part of subcall function 004E6B60: __vbaInStrVar.MSVBVM60(?,00000000,?,?,00000001), ref: 004E6C61
        • Part of subcall function 004E6B60: __vbaVarTstGt.MSVBVM60(00008002,00000000), ref: 004E6C6F
        • Part of subcall function 004E6B60: __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?), ref: 004E6C9A
        • Part of subcall function 004E6B60: __vbaLenBstr.MSVBVM60(?), ref: 004E6CD0
        • Part of subcall function 004E6B60: __vbaInStr.MSVBVM60(00000000,00477EEC,?,00000001), ref: 004E6CE5
        • Part of subcall function 004E6B60: #619.MSVBVM60(?,00004008,00000000), ref: 004E6D02
        • Part of subcall function 004E6B60: __vbaStrVarMove.MSVBVM60(?), ref: 004E6D0F
      • __vbaStrMove.MSVBVM60(00000000), ref: 004E6A23
      • __vbaFreeStr.MSVBVM60 ref: 004E6A2C
      • __vbaStrCmp.MSVBVM60(00473D9C,?), ref: 004E6A42
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051C43A
        • Part of subcall function 0051C3A0: #520.MSVBVM60(?,00000008), ref: 0051C45B
        • Part of subcall function 0051C3A0: __vbaStrVarMove.MSVBVM60(?), ref: 0051C465
        • Part of subcall function 0051C3A0: __vbaStrMove.MSVBVM60 ref: 0051C470
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60 ref: 0051C479
        • Part of subcall function 0051C3A0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 0051C489
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,00000000,00411816), ref: 0051C4A1
        • Part of subcall function 0051C3A0: #520.MSVBVM60(?,00000008), ref: 0051C4C2
        • Part of subcall function 0051C3A0: __vbaStrVarMove.MSVBVM60(?), ref: 0051C4CC
        • Part of subcall function 0051C3A0: __vbaStrMove.MSVBVM60 ref: 0051C4D7
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60 ref: 0051C4E0
        • Part of subcall function 0051C3A0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 0051C4F0
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C500
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051C50B
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051C52C
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00000000,00411816), ref: 0051C542
        • Part of subcall function 0051C3A0: #645.MSVBVM60(00004008,00000000), ref: 0051C573
        • Part of subcall function 0051C3A0: __vbaStrMove.MSVBVM60 ref: 0051C57E
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,00000000), ref: 0051C58A
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60 ref: 0051C5A2
      • __vbaStrMove.MSVBVM60 ref: 004E6A5D
      • __vbaStrCat.MSVBVM60(:UoDC,00000000), ref: 004E6A69
      • __vbaStrMove.MSVBVM60 ref: 004E6A74
      • __vbaStrCopy.MSVBVM60 ref: 004E6A82
      • __vbaFreeStrList.MSVBVM60(00000003,?,?,?,?,?,?,?), ref: 004E6AAB
      • __vbaStrCopy.MSVBVM60 ref: 004E6AC1
      • #685.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004E6ACE
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,?,00411816), ref: 004E6AD9
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004E6AF1
      • __vbaFreeStr.MSVBVM60(004E6B49,?,00000000,00000000,?,00411816), ref: 004E6B39
      • __vbaFreeStr.MSVBVM60(?,00000000,00000000,?,00411816), ref: 004E6B42
        • Part of subcall function 0051C3A0: __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,00530973,?,00000000,?,00000000,00411816), ref: 0051C3BE
        • Part of subcall function 0051C3A0: __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 0051C3EE
        • Part of subcall function 0051C3A0: __vbaStrCmp.MSVBVM60(00473D9C,00773364,?,00000000,?,00000000,00411816), ref: 0051C406
        • Part of subcall function 0051C3A0: __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051C420
        • Part of subcall function 0051C3A0: #685.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE34
        • Part of subcall function 0051C3A0: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,00000000,00411816), ref: 0051CE3F
        • Part of subcall function 0051C3A0: __vbaFreeObj.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CE60
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(0051CED1,?,?,?,?,00000000,00411816), ref: 0051CEB8
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CEC1
        • Part of subcall function 0051C3A0: __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,00411816), ref: 0051CECA
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$Move$Copy$List$ChkstkError$#619#685$#518#520#608$#617#645BoolBstrNull
      • String ID: :UoDC$UserOfDefaultCertificate$providerIsUC:
      • API String ID: 489622813-529920552
      • Opcode ID: 63c587997eff896dfe65c236d24bd43c2da25a44fe23c3e9faa15ed3ddd9f221
      • Instruction ID: b5bef91a7f567028a9733b66d1873b389a38bdb1aa5a2c0a064aaacb6db0d97d
      • Opcode Fuzzy Hash: 63c587997eff896dfe65c236d24bd43c2da25a44fe23c3e9faa15ed3ddd9f221
      • Instruction Fuzzy Hash: B9610971900249EFDB04EFE4DE48ADEBB78EF48705F108169F502B76A0DB746A09CB64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,00545E5D), ref: 005208EE
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,00545E5D), ref: 0052091E
      • __vbaSetSystemError.MSVBVM60(?,?,?,00000000,00411816,00545E5D), ref: 00520933
      • __vbaSetSystemError.MSVBVM60(?,?,?,?,?,00000000,00411816,00545E5D), ref: 00520953
      • __vbaStrI4.MSVBVM60(?,?,?,?,00000000,00411816,00545E5D), ref: 00520964
      • __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816,00545E5D), ref: 0052096F
      • __vbaStrCat.MSVBVM60(004787B4,00000000,?,?,?,00000000,00411816,00545E5D), ref: 0052097B
      • __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816,00545E5D), ref: 00520986
      • __vbaFreeStr.MSVBVM60(?,?,?,00000000,00411816,00545E5D), ref: 0052098F
      • __vbaStrI4.MSVBVM60(?,?,?,?,?,00000000,00411816,00545E5D), ref: 005209A4
      • __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816,00545E5D), ref: 005209AF
      • __vbaStrCat.MSVBVM60(00000000,?,?,?,00000000,00411816,00545E5D), ref: 005209B6
      • __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816,00545E5D), ref: 005209C1
      • __vbaStrCat.MSVBVM60(004787B4,00000000,?,?,?,00000000,00411816,00545E5D), ref: 005209CD
      • __vbaStrMove.MSVBVM60(?,?,?,00000000,00411816,00545E5D), ref: 005209D8
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,?,00000000,00411816,00545E5D), ref: 005209E8
      • __vbaSetSystemError.MSVBVM60(?,00000000,00411816,00545E5D), ref: 00520A00
      • __vbaStrI4.MSVBVM60(?,?,?,00000000,00411816,00545E5D), ref: 00520A0E
      • __vbaStrMove.MSVBVM60(?,00000000,00411816,00545E5D), ref: 00520A19
      • __vbaStrCat.MSVBVM60(00000000,?,00000000,00411816,00545E5D), ref: 00520A20
      • __vbaStrMove.MSVBVM60(?,00000000,00411816,00545E5D), ref: 00520A2B
      • __vbaFreeStr.MSVBVM60(?,00000000,00411816,00545E5D), ref: 00520A34
      • __vbaStrCopy.MSVBVM60(?,00000000,00411816,00545E5D), ref: 00520A47
      • __vbaStrCat.MSVBVM60(?,SessionID: ,?,00000000,00411816,00545E5D), ref: 00520A5D
      • __vbaStrMove.MSVBVM60(?,00000000,00411816,00545E5D), ref: 00520A68
      • __vbaFreeStr.MSVBVM60(?,?,00000000,00411816,00545E5D), ref: 00520A7A
      • #685.MSVBVM60(?,00000000,00411816,00545E5D), ref: 00520A87
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00411816,00545E5D), ref: 00520A92
      • __vbaFreeObj.MSVBVM60(?,00000000,00411816,00545E5D), ref: 00520AAA
      • __vbaFreeStr.MSVBVM60(00520AF1,?,00000000,00411816,00545E5D), ref: 00520AEA
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Move$Free$Error$System$#685ChkstkCopyList
      • String ID: SessionID:
      • API String ID: 2739133491-404888849
      • Opcode ID: a7ba0aa9dc5511d1d0c93cca8214319157d892109596afdad6fa01cd7099c864
      • Instruction ID: 6ce322db98a2071882d084d9b6556ca0d95c74d827ae0119cf10ef97139437fb
      • Opcode Fuzzy Hash: a7ba0aa9dc5511d1d0c93cca8214319157d892109596afdad6fa01cd7099c864
      • Instruction Fuzzy Hash: 1251C875900249EFDB04EFE0EE49ADEBBB5BF48305F108129F906B3660DB745A45CB54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816,?,?,?,00522545,?,?), ref: 00522C1E
      • __vbaAryConstruct2.MSVBVM60(?,00491EDC,00000011,6D65285F,6D721D9E,6D6517CC,?,00411816), ref: 00522C50
      • __vbaOnError.MSVBVM60(000000FF), ref: 00522C5F
      • __vbaGenerateBoundsError.MSVBVM60 ref: 00522C95
      • #644.MSVBVM60(0000EC00), ref: 00522CA8
      • __vbaUI1I2.MSVBVM60 ref: 00522CBD
      • __vbaUI1I2.MSVBVM60(?,?), ref: 00522CDF
      • __vbaUI1I2.MSVBVM60(?,?), ref: 00522D01
      • __vbaUI1I2.MSVBVM60(?,?), ref: 00522D23
      • __vbaUI1I2.MSVBVM60(?,?), ref: 00522D45
      • __vbaUI1I2.MSVBVM60(?,?), ref: 00522D67
      • #685.MSVBVM60(?,?), ref: 00522D84
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00522D8F
      • __vbaFreeObj.MSVBVM60 ref: 00522DB0
      • __vbaUbound.MSVBVM60(00000001), ref: 00522DD1
      • __vbaI2I4.MSVBVM60 ref: 00522DD9
      • #685.MSVBVM60 ref: 00522E0C
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 00522E17
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$#685Error$#644BoundsChkstkConstruct2FreeGenerateUbound
      • String ID:
      • API String ID: 2444365471-0
      • Opcode ID: 58e8559a1a341c4f9a8f42d8b7232dbc3bef3b2a8dbdc6acf93afdc16ceb9634
      • Instruction ID: dc40b2f828a6c42190409b9670c8d274a293b93f856794d3530834f8f58eea15
      • Opcode Fuzzy Hash: 58e8559a1a341c4f9a8f42d8b7232dbc3bef3b2a8dbdc6acf93afdc16ceb9634
      • Instruction Fuzzy Hash: 89D12474900218EFDB14DFA0DA48BEEBBB4BF49305F20855DE506AB2A1DBB45A44DF60
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(?,00411816), ref: 0051082E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 0051085E
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,?,?,?,00411816), ref: 00510876
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 00510890
      • __vbaStrCopy.MSVBVM60(?,?,?,?,00411816), ref: 005108AA
      • __vbaStrMove.MSVBVM60(?,?,?,?,00411816), ref: 005108C1
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00411816), ref: 005108D7
      • __vbaNew2.MSVBVM60(00477E14,0054ED28,?,?,?,?,00411816), ref: 005108FF
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00477E04,00000014), ref: 00510950
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,0047A994,00000050), ref: 00510998
      • __vbaStrMove.MSVBVM60 ref: 005109C9
      • __vbaFreeObj.MSVBVM60 ref: 005109D2
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,?,?,?,00411816), ref: 005109E8
      • #619.MSVBVM60(?,00004008,00000001), ref: 00510A14
      • #685.MSVBVM60(?,?,?,?,00411816), ref: 00510AED
      • __vbaObjSet.MSVBVM60(00000000,00000000,?,?,?,?,00411816), ref: 00510AF8
      • __vbaFreeObj.MSVBVM60(?,?,?,?,00411816), ref: 00510B19
      • __vbaFreeStr.MSVBVM60(00510B69,?,?,?,?,00411816), ref: 00510B62
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$CheckCopyHresultMove$#619#685ChkstkErrorNew2
      • String ID: (T$ReaderINI.ini
      • API String ID: 733303979-1789204238
      • Opcode ID: a859a44a6c0c1029ffaab5f9aa2a48a8f4694a03e81f017ca30664d8c7eae3c2
      • Instruction ID: 86458bb700f357c32fad6a2cff923efd5d88954ce99a8c504b6a10529cfa4273
      • Opcode Fuzzy Hash: a859a44a6c0c1029ffaab5f9aa2a48a8f4694a03e81f017ca30664d8c7eae3c2
      • Instruction Fuzzy Hash: 52911975900208DFEB14DFA0CA48BDEBBB4FF48705F208169E505B72A0DBB55A85DF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,0054D0DC,?,00000000,00000000,00000000,00411816), ref: 0050ACDE
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AD0E
      • #685.MSVBVM60(?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AD1B
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AD26
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AD47
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AD60
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AD80
      • __vbaStrCmp.MSVBVM60(00473D9C,?,?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AD98
      • #716.MSVBVM60(?,Scripting.FileSystemObject,00000000,?,?,00000000), ref: 0050ADCC
      • __vbaObjVar.MSVBVM60(?,?,?,00000000), ref: 0050ADD6
      • __vbaObjSetAddref.MSVBVM60(00000000,00000000,?,?,00000000), ref: 0050ADE1
      • __vbaFreeVar.MSVBVM60(?,?,00000000), ref: 0050ADEA
      • __vbaChkstk.MSVBVM60 ref: 0050AE16
      • __vbaChkstk.MSVBVM60 ref: 0050AE39
      • __vbaLateMemCall.MSVBVM60(00000000,CopyFile,00000002), ref: 0050AE62
      • #685.MSVBVM60(?,?,?,?,?,?,?,00000000), ref: 0050AE72
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,?,?,?,00000000), ref: 0050AE7D
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 0050AEB0
      • __vbaFreeObj.MSVBVM60 ref: 0050AEDA
      • __vbaObjSetAddref.MSVBVM60(00000000,00000000), ref: 0050AF02
      • #685.MSVBVM60(?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AF1E
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AF29
      • __vbaFreeObj.MSVBVM60(?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AF4A
      • __vbaFreeObj.MSVBVM60(0050AF74,?,00000000,00000000,00000000,00411816,0054D0DC), ref: 0050AF6D
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#685Chkstk$Addref$#716CallCheckErrorHresultLate
      • String ID: CopyFile$Scripting.FileSystemObject
      • API String ID: 1648761310-2836766061
      • Opcode ID: 7569d6688bc44fd1148a601bd1b83b8caf40726829a8cde21ae43422f7a55f1e
      • Instruction ID: 217e7c94eb118e15bacc9c6af9d4ae07b71197abe120d4aa48be90fe925b017d
      • Opcode Fuzzy Hash: 7569d6688bc44fd1148a601bd1b83b8caf40726829a8cde21ae43422f7a55f1e
      • Instruction Fuzzy Hash: 9981F3B5D00209DFDB14DFA4DA48BDEBBB4FF48705F108169E509AB2A0DB749A44CF64
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816), ref: 0051188E
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,?,00000000,00411816), ref: 005118BE
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,?,00000000,00411816), ref: 005118D6
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 005118EF
      • __vbaStrMove.MSVBVM60(00000000,?,00000000,?,00000000,00411816), ref: 00511905
      • __vbaFreeStr.MSVBVM60(?,00000000,?,00000000,00411816), ref: 0051190E
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,?,00000000,00411816), ref: 00511927
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00511942
      • __vbaStrCopy.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00511958
      • #685.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00511965
      • __vbaObjSet.MSVBVM60(?,00000000,?,00000000,?,00000000,00411816), ref: 00511970
      • __vbaFreeObj.MSVBVM60(?,00000000,?,00000000,00411816), ref: 00511988
      Strings
      • Aloaha PDF (www.aloaha.com), xrefs: 00511938
      • HKLM\Software\Aloaha\pdf\PDFAgent, xrefs: 005118E7
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Copy$Free$#685ChkstkErrorMove
      • String ID: Aloaha PDF (www.aloaha.com)$HKLM\Software\Aloaha\pdf\PDFAgent
      • API String ID: 2014732186-3193446157
      • Opcode ID: a242a23f55c32c3ec9ae98e1a6a7a66f70dcbdba68c20a9db0b0b143f3298b7c
      • Instruction ID: e3d6f15bfcc76d21bd0ed74fe54e8ee54972dd8a7e133152686944ff6e481156
      • Opcode Fuzzy Hash: a242a23f55c32c3ec9ae98e1a6a7a66f70dcbdba68c20a9db0b0b143f3298b7c
      • Instruction Fuzzy Hash: D5317175900208DFDB10DF90DE58BDEBFB8FB08709F208069E511B76A0D7795A45CB69
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,004A7331), ref: 004D2C8E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004D2CBE
      • #685.MSVBVM60(?,?,?,00000000,00411816), ref: 004D2CCB
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 004D2CD6
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 004D2CEE
      • __vbaSetSystemError.MSVBVM60(?,?,?,00000000,00411816), ref: 004D2D03
      • __vbaSetSystemError.MSVBVM60(0000087C,0054D658,?,?,?,00000000,00411816), ref: 004D2D2A
      • #685.MSVBVM60(?,?,?,00000000,00411816), ref: 004D2D46
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 004D2D51
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004747A8,0000001C), ref: 004D2D84
      • __vbaFreeObj.MSVBVM60 ref: 004D2DA8
      • #685.MSVBVM60 ref: 004D2DCB
      • __vbaObjSet.MSVBVM60(?,00000000), ref: 004D2DD6
      • __vbaFreeObj.MSVBVM60 ref: 004D2DF7
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$#685ErrorFree$System$CheckChkstkHresult
      • String ID:
      • API String ID: 110213536-0
      • Opcode ID: f831ba4fbd9abf6139129695e229c801e292d4fb70132b3b862f2a22e1da7751
      • Instruction ID: 74bba9e13135bc30f04da962857e81cb542f74fd9de24c2bc1997f0017276d74
      • Opcode Fuzzy Hash: f831ba4fbd9abf6139129695e229c801e292d4fb70132b3b862f2a22e1da7751
      • Instruction Fuzzy Hash: 5B4126B4D00208DFDB00DFE4DA48BDDBBB4BF08745F20815AE516AB2A4DB785A49DF54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004CB8EE
      • __vbaStrCopy.MSVBVM60(?,00000001,?,00000000,00411816), ref: 004CB91B
      • __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816), ref: 004CB92A
        • Part of subcall function 00531FD0: __vbaChkstk.MSVBVM60(00000000,00411816,004CB93C,?,00000001,?,00000000,00411816), ref: 00531FEE
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053201E
        • Part of subcall function 00531FD0: __vbaFixstrConstruct.MSVBVM60(00000100,?,?,00000001,?,00000000,00411816,004CB93C), ref: 0053202D
        • Part of subcall function 00531FD0: __vbaOnError.MSVBVM60(000000FF,?,00000001,?,00000000,00411816,004CB93C), ref: 0053203C
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 0053206B
        • Part of subcall function 00531FD0: __vbaVarTstEq.MSVBVM60(00008008,?), ref: 00532093
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 005320A6
        • Part of subcall function 00531FD0: __vbaStrCopy.MSVBVM60 ref: 005320CA
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00000008,?), ref: 005320F7
        • Part of subcall function 00531FD0: __vbaStrVarMove.MSVBVM60(?), ref: 00532104
        • Part of subcall function 00531FD0: __vbaStrMove.MSVBVM60 ref: 00532111
        • Part of subcall function 00531FD0: __vbaFreeStr.MSVBVM60 ref: 0053211A
        • Part of subcall function 00531FD0: __vbaFreeVarList.MSVBVM60(00000002,00000008,?), ref: 00532130
        • Part of subcall function 00531FD0: #520.MSVBVM60(?,00004008), ref: 00532162
        • Part of subcall function 00531FD0: __vbaVarTstNe.MSVBVM60(00008008,?), ref: 0053218A
        • Part of subcall function 00531FD0: __vbaFreeVar.MSVBVM60 ref: 0053219D
      • __vbaStrToAnsi.MSVBVM60(?,?,00000000,00405518,?,00411816,?,00000001,?,00000000,00411816), ref: 004CB962
      • __vbaSetSystemError.MSVBVM60(?,00000000,?,00000001,?,00000000,00411816), ref: 004CB975
      • __vbaStrToUnicode.MSVBVM60(?,?,?,00000001,?,00000000,00411816), ref: 004CB983
      • __vbaFreeStr.MSVBVM60(?,00000001,?,00000000,00411816), ref: 004CB992
      • __vbaFreeVar.MSVBVM60(?,?,00000001,?,00000000,00411816), ref: 004CB9C0
      • #685.MSVBVM60(?), ref: 004CBA41
      • __vbaObjSet.MSVBVM60(00000000,00000000), ref: 004CBA4C
      • __vbaFreeObj.MSVBVM60 ref: 004CBA64
      • __vbaFreeStr.MSVBVM60(004CBA97), ref: 004CBA90
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Free$#520Error$ChkstkConstructCopyFixstrMove$#685AnsiListSystemUnicode
      • String ID:
      • API String ID: 2490341460-0
      • Opcode ID: 481b98f19858ab9450d15d327674548578db01d80da14484085be1baf7cb8f0c
      • Instruction ID: c33aabf705f99ccfdd174f2b0bf0ad993a0d6cb5820b43c7e7fc5f92dfbe8fb8
      • Opcode Fuzzy Hash: 481b98f19858ab9450d15d327674548578db01d80da14484085be1baf7cb8f0c
      • Instruction Fuzzy Hash: A3411AB5800209EFDB00DFE4DA49BDEBBB8FF48304F20805AE501A7290D7799A45DFA4
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816,?,?,00000000,00000000,00000000,00411816), ref: 005044EE
      • __vbaOnError.MSVBVM60(000000FF,?,00000000,00000000,00000000,00411816), ref: 0050451E
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 00504533
      • __vbaStrCopy.MSVBVM60(?,00000000,00000000,00000000,00411816), ref: 00504548
      • __vbaStrCmp.MSVBVM60(00473D9C,00000000,?,00000000,00000000,00000000,00411816), ref: 00504560
      • __vbaStrCopy.MSVBVM60 ref: 005045A2
      • __vbaStrCopy.MSVBVM60 ref: 005045B0
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Copy$ChkstkError
      • String ID: MyDocuments$Software\Aloaha\pdf
      • API String ID: 1771118016-820968302
      • Opcode ID: 4c83cc4686318587bfe12ee31705d07fd5747acd0c6091a81ac892e83eb6e2b6
      • Instruction ID: 7521ac20d02b06770792b12d039c5d0e33bd08a9eca29259ba2b4fdfa89c278a
      • Opcode Fuzzy Hash: 4c83cc4686318587bfe12ee31705d07fd5747acd0c6091a81ac892e83eb6e2b6
      • Instruction Fuzzy Hash: EA212CB5901248EFDB10DF94DA09BDEBB78FB04708F20C02DE501776A0DBB85A09CB54
      Uniqueness

      Uniqueness Score: -1.00%

      APIs
      • __vbaChkstk.MSVBVM60(00000000,00411816), ref: 004CC85E
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816), ref: 004CC88E
        • Part of subcall function 0051D000: __vbaChkstk.MSVBVM60(?,00411816,?,?,?,?,00000000,00411816), ref: 0051D01E
        • Part of subcall function 0051D000: __vbaOnError.MSVBVM60(000000FF,?,?,?,?,00411816), ref: 0051D04E
        • Part of subcall function 0051D000: __vbaStrCmp.MSVBVM60(true,0077F45C,?,?,?,?,00411816), ref: 0051D066
        • Part of subcall function 0051D000: #685.MSVBVM60 ref: 0051D326
        • Part of subcall function 0051D000: __vbaObjSet.MSVBVM60(00000000,00000000), ref: 0051D331
        • Part of subcall function 0051D000: __vbaFreeObj.MSVBVM60 ref: 0051D352
        • Part of subcall function 0051D000: __vbaFreeStr.MSVBVM60(0051D393), ref: 0051D383
        • Part of subcall function 0051D000: __vbaFreeStr.MSVBVM60 ref: 0051D38C
      • __vbaSetSystemError.MSVBVM60(00000002,00000000,000000FF), ref: 004CC91A
      • #685.MSVBVM60(?,?,?,00000000,00411816), ref: 004CC927
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816), ref: 004CC932
      • __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816), ref: 004CC94A
        • Part of subcall function 004EAF90: __vbaChkstk.MSVBVM60(00000000,00411816,00000000,?,?,?,00000005,00411816), ref: 004EAFAE
        • Part of subcall function 004EAF90: __vbaOnError.MSVBVM60(000000FF,?,?,?,00000000,00411816,00000000), ref: 004EAFDE
        • Part of subcall function 004EAF90: __vbaStrCopy.MSVBVM60(?,?,?,00000000,00411816,00000000), ref: 004EB003
        • Part of subcall function 004EAF90: #685.MSVBVM60(?,?,?,00000000,00411816,00000000), ref: 004EB041
        • Part of subcall function 004EAF90: __vbaObjSet.MSVBVM60(?,00000000,?,?,?,00000000,00411816,00000000), ref: 004EB04C
        • Part of subcall function 004EAF90: __vbaFreeObj.MSVBVM60(?,?,?,00000000,00411816,00000000), ref: 004EB064
        • Part of subcall function 004CCBC0: __vbaSetSystemError.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004CCC17
        • Part of subcall function 004CCBC0: __vbaSetSystemError.MSVBVM60(00000000,00000028,?), ref: 004CCC2F
        • Part of subcall function 004CCBC0: __vbaStrToAnsi.MSVBVM60(?,SeShutdownPrivilege,?), ref: 004CCC42
        • Part of subcall function 004CCBC0: __vbaSetSystemError.MSVBVM60(00000000,00000000), ref: 004CCC51
        • Part of subcall function 004CCBC0: __vbaFreeStr.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004CCC61
        • Part of subcall function 004CCBC0: __vbaCopyBytes.MSVBVM60(00000008,?,?), ref: 004CCC7D
        • Part of subcall function 004CCBC0: __vbaSetSystemError.MSVBVM60(?,00000000,00000001,00000000,00000000,00000000), ref: 004CCC9D
      Memory Dump Source
      • Source File: 00000000.00000002.2637034256.0000000000469000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2637018909.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637034256.0000000000425000.00000020.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637148375.000000000054D000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.0000000000550000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.000000000059A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.2637164707.00000000005AF000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_SecuriteInfo.jbxd
      Similarity
      • API ID: __vba$Error$Free$System$#685Chkstk$Copy$AnsiBytes
      • String ID:
      • API String ID: 3529819506-0
      • Opcode ID: 9b767d6fba4e527b0ec35e5c4744b229864be18d27eac2e43db288cc9798c314
      • Instruction ID: a4ae9d724ae255af07576ab4b4b28b5a2ab011b85748dbf30ab981d596ff7ea1
      • Opcode Fuzzy Hash: 9b767d6fba4e527b0ec35e5c4744b229864be18d27eac2e43db288cc9798c314
      • Instruction Fuzzy Hash: 34315CB5C01219EFDB10DF94CA49BDEBBB4BB08708F208259E115B7290C7795A448BA5
      Uniqueness

      Uniqueness Score: -1.00%