Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
MSI629D.exe

Overview

General Information

Sample name:MSI629D.exe
(renamed file extension from tmp to exe)
Original sample name:MSI629D.tmp
Analysis ID:1431740
MD5:77fada8cefee7aa4f3a83f299b6bc550
SHA1:7745ac4ffb86f9a8d6f42683f34b1656d9c03a48
SHA256:c97c60f0aea64a0b7dc121c9d6889ee7350a25490a1062d1e4a5b3feb5427f9b
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Found potential dummy code loops (likely to delay analysis)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found large amount of non-executed APIs
May sleep (evasive loops) to hinder dynamic analysis
Program does not show much activity (idle)
Sample execution stops while process was sleeping (likely an evasion)
Uses 32bit PE files

Classification

  • System is w10x64native
  • MSI629D.exe (PID: 1640 cmdline: "C:\Users\user\Desktop\MSI629D.exe" MD5: 77FADA8CEFEE7AA4F3A83F299B6BC550)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: MSI629D.exeReversingLabs: Detection: 13%
Source: MSI629D.exeVirustotal: Detection: 15%Perma Link
Source: MSI629D.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: MSI629D.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD4AFA FindFirstFileExW,1_2_00FD4AFA
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FDAF8D1_2_00FDAF8D
Source: MSI629D.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: mal52.evad.winEXE@1/0@0/0
Source: MSI629D.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\MSI629D.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: MSI629D.exeReversingLabs: Detection: 13%
Source: MSI629D.exeVirustotal: Detection: 15%
Source: C:\Users\user\Desktop\MSI629D.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\MSI629D.exeSection loaded: edgegdi.dllJump to behavior
Source: MSI629D.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: MSI629D.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: MSI629D.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: MSI629D.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: MSI629D.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: MSI629D.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: MSI629D.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: MSI629D.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: MSI629D.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: MSI629D.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: MSI629D.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: MSI629D.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: MSI629D.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\MSI629D.exeWindow / User API: threadDelayed 1028Jump to behavior
Source: C:\Users\user\Desktop\MSI629D.exeWindow / User API: threadDelayed 8971Jump to behavior
Source: C:\Users\user\Desktop\MSI629D.exeAPI coverage: 3.5 %
Source: C:\Users\user\Desktop\MSI629D.exe TID: 6220Thread sleep count: 1028 > 30Jump to behavior
Source: C:\Users\user\Desktop\MSI629D.exe TID: 6220Thread sleep time: -205600s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\MSI629D.exe TID: 6220Thread sleep count: 8971 > 30Jump to behavior
Source: C:\Users\user\Desktop\MSI629D.exe TID: 6220Thread sleep time: -1794200s >= -30000sJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\MSI629D.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\MSI629D.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD4AFA FindFirstFileExW,1_2_00FD4AFA

Anti Debugging

barindex
Source: C:\Users\user\Desktop\MSI629D.exeProcess Stats: CPU usage > 5% for more than 60s
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD4442 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00FD4442
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD34CF mov eax, dword ptr fs:[00000030h]1_2_00FD34CF
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD5C27 mov eax, dword ptr fs:[00000030h]1_2_00FD5C27
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD6D42 GetProcessHeap,1_2_00FD6D42
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD4442 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00FD4442
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD196E SetUnhandledExceptionFilter,1_2_00FD196E
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD17DA IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00FD17DA
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD134E SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,1_2_00FD134E
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD1A75 cpuid 1_2_00FD1A75
Source: C:\Users\user\Desktop\MSI629D.exeCode function: 1_2_00FD16C1 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,1_2_00FD16C1
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
DLL Side-Loading
111
Virtualization/Sandbox Evasion
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
DLL Side-Loading
LSASS Memory12
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager111
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS1
Application Window Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials12
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
MSI629D.exe13%ReversingLabs
MSI629D.exe15%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1431740
Start date and time:2024-04-25 17:33:57 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 8m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
Number of analysed new started processes analysed:3
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:MSI629D.exe
(renamed file extension from tmp to exe)
Original Sample Name:MSI629D.tmp
Detection:MAL
Classification:mal52.evad.winEXE@1/0@0/0
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 1
  • Number of non-executed functions: 15
Cookbook Comments:
  • Override analysis time to 240000 for current running targets taking high CPU consumption
  • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
  • Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
  • Excluded domains from analysis (whitelisted): spclient.wg.spotify.com
TimeTypeDescription
17:36:28API Interceptor5976234x Sleep call for process: MSI629D.exe modified
No context
No context
No context
No context
No context
No created / dropped files found
File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):6.2019867409486835
TrID:
  • Win32 Executable (generic) a (10002005/4) 99.96%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:MSI629D.exe
File size:74'240 bytes
MD5:77fada8cefee7aa4f3a83f299b6bc550
SHA1:7745ac4ffb86f9a8d6f42683f34b1656d9c03a48
SHA256:c97c60f0aea64a0b7dc121c9d6889ee7350a25490a1062d1e4a5b3feb5427f9b
SHA512:a01e49154922e6d181b788747802c0f9c7177d81c5b7ebbe91eaef373bc20087ebe9560e69d81e21910f62b9f0d0d4ec7338fa4e0ecc794f40faefff25bc9cbf
SSDEEP:1536:5wbThllWpdKHbXw3u0Kln5DJrz9MEwyGdsZwsWIcdeFo52i:gT4pcHbX7n5DJrz9ME2sqeFo52i
TLSH:69734B43B5E188B1E9771D352870CAA09E3FB9210E659EAB2344067E1F305C29E35F7B
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........X........................5...................................................z.......z.......z.......Rich...................
Icon Hash:90cececece8e8eb0
Entrypoint:0x401344
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x64BA6E8F [Fri Jul 21 11:39:59 2023 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:e05d62af8b1580a04c6c01f16ea1d0cb
Instruction
call 00007FC0546A3BAAh
jmp 00007FC0546A365Fh
push ebp
mov ebp, esp
push 00000000h
call dword ptr [0040C014h]
push dword ptr [ebp+08h]
call dword ptr [0040C010h]
push C0000409h
call dword ptr [0040C018h]
push eax
call dword ptr [0040C01Ch]
pop ebp
ret
push ebp
mov ebp, esp
sub esp, 00000324h
push 00000017h
call dword ptr [0040C020h]
test eax, eax
je 00007FC0546A37E7h
push 00000002h
pop ecx
int 29h
mov dword ptr [00412980h], eax
mov dword ptr [0041297Ch], ecx
mov dword ptr [00412978h], edx
mov dword ptr [00412974h], ebx
mov dword ptr [00412970h], esi
mov dword ptr [0041296Ch], edi
mov word ptr [00412998h], ss
mov word ptr [0041298Ch], cs
mov word ptr [00412968h], ds
mov word ptr [00412964h], es
mov word ptr [00412960h], fs
mov word ptr [0041295Ch], gs
pushfd
pop dword ptr [00412990h]
mov eax, dword ptr [ebp+00h]
mov dword ptr [00412984h], eax
mov eax, dword ptr [ebp+04h]
mov dword ptr [00412988h], eax
lea eax, dword ptr [ebp+08h]
mov dword ptr [00412994h], eax
mov eax, dword ptr [ebp-00000324h]
mov dword ptr [004128D0h], 00010001h
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x114140x3c.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x140000x1e8.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x150000xdb0.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x10c5c0x38.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x10c980x40.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0xc0000x110.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000xa7880xa8000213cb3fd44e32a1150e62f9dba3e4ebFalse0.6081891741071429data6.578346720442577IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0xc0000x5a2e0x5c00bd26716b0743f4ebbbc366467ec46441False0.41193953804347827data4.768984935940302IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x120000x12ac0xa008245e874002ffac1699edd3578be0b90False0.13671875data1.8066449089245316IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc0x140000x1e80x200f3e56eddbe8fc87469d99b8983dd36f7False0.537109375data4.7644199514493595IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x150000xdb00xe00134f12380b5ebfb5d5ab645cb78b0047False0.7731584821428571data6.440107108868493IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_MANIFEST0x140600x188XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5892857142857143
DLLImport
KERNEL32.dllSleep, WriteConsoleW, CloseHandle, CreateFileW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleW, RtlUnwind, GetLastError, SetLastError, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, GetProcAddress, LoadLibraryExW, RaiseException, GetStdHandle, WriteFile, GetModuleFileNameW, ExitProcess, GetModuleHandleExW, HeapAlloc, HeapFree, FindClose, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, MultiByteToWideChar, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetStdHandle, GetFileType, GetStringTypeW, LCMapStringW, GetProcessHeap, HeapSize, HeapReAlloc, FlushFileBuffers, GetConsoleOutputCP, GetConsoleMode, SetFilePointerEx, DecodePointer
USER32.dllFindWindowW, SetWindowPos
Language of compilation systemCountry where language is spokenMap
EnglishUnited States
No network behavior found

Click to jump to process

Click to jump to process

Target ID:1
Start time:17:35:57
Start date:25/04/2024
Path:C:\Users\user\Desktop\MSI629D.exe
Wow64 process (32bit):true
Commandline:"C:\Users\user\Desktop\MSI629D.exe"
Imagebase:0xfd0000
File size:74'240 bytes
MD5 hash:77FADA8CEFEE7AA4F3A83F299B6BC550
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Reset < >

    Execution Graph

    Execution Coverage:1.1%
    Dynamic/Decrypted Code Coverage:0%
    Signature Coverage:2.6%
    Total number of Nodes:1627
    Total number of Limit Nodes:3
    execution_graph 6689 fd12fd 6690 fd192b GetModuleHandleW 6689->6690 6691 fd1305 6690->6691 6692 fd1309 6691->6692 6693 fd133b 6691->6693 6695 fd1314 6692->6695 6698 fd3573 6692->6698 6694 fd3591 23 API calls 6693->6694 6696 fd1343 6694->6696 6699 fd346b 23 API calls 6698->6699 6700 fd357e 6699->6700 6700->6695 6701 fd43fc 6709 fd6a9c 6701->6709 6704 fd4410 6705 fd4347 14 API calls 6706 fd4418 6705->6706 6707 fd4425 6706->6707 6714 fd4428 6706->6714 6710 fd69ba 5 API calls 6709->6710 6711 fd6ab8 6710->6711 6712 fd6ad0 TlsAlloc 6711->6712 6713 fd4406 6711->6713 6712->6713 6713->6704 6713->6705 6715 fd4438 6714->6715 6716 fd4432 6714->6716 6715->6704 6718 fd6adb 6716->6718 6719 fd69ba 5 API calls 6718->6719 6720 fd6af7 6719->6720 6721 fd6b00 6720->6721 6722 fd6b12 TlsFree 6720->6722 6721->6715 6723 fd3aff 6726 fd322f 6723->6726 6727 fd323e 6726->6727 6732 fd31a1 6727->6732 6730 fd31a1 14 API calls 6731 fd3263 6730->6731 6733 fd31cb 6732->6733 6734 fd31ae 6732->6734 6733->6730 6735 fd31c5 6734->6735 6736 fd471b 14 API calls 6734->6736 6737 fd471b 14 API calls 6735->6737 6736->6734 6737->6733 7178 fd307f 7179 fd5642 69 API calls 7178->7179 7180 fd3091 7179->7180 7189 fd5b03 GetEnvironmentStringsW 7180->7189 7184 fd471b 14 API calls 7185 fd30cb 7184->7185 7187 fd471b 14 API calls 7188 fd309c 7187->7188 7188->7184 7190 fd5b1a 7189->7190 7200 fd5b70 7189->7200 7193 fd5a15 WideCharToMultiByte 7190->7193 7191 fd5b79 FreeEnvironmentStringsW 7192 fd3096 7191->7192 7192->7188 7201 fd30d1 7192->7201 7194 fd5b33 7193->7194 7195 fd639a 15 API calls 7194->7195 7194->7200 7196 fd5b43 7195->7196 7197 fd5b5b 7196->7197 7198 fd5a15 WideCharToMultiByte 7196->7198 7199 fd471b 14 API calls 7197->7199 7198->7197 7199->7200 7200->7191 7200->7192 7202 fd30e6 7201->7202 7203 fd46be 14 API calls 7202->7203 7214 fd310d 7203->7214 7204 fd3172 7205 fd471b 14 API calls 7204->7205 7206 fd30a7 7205->7206 7206->7187 7207 fd46be 14 API calls 7207->7214 7208 fd3174 7210 fd31a1 14 API calls 7208->7210 7211 fd317a 7210->7211 7212 fd471b 14 API calls 7211->7212 7212->7204 7213 fd3194 7215 fd45fe 6 API calls 7213->7215 7214->7204 7214->7207 7214->7208 7214->7213 7216 fd471b 14 API calls 7214->7216 7218 fd3ccb 7214->7218 7217 fd31a0 7215->7217 7216->7214 7219 fd3ce6 7218->7219 7220 fd3cd8 7218->7220 7221 fd46ab 14 API calls 7219->7221 7220->7219 7224 fd3cfd 7220->7224 7222 fd3cee 7221->7222 7223 fd45ee 20 API calls 7222->7223 7225 fd3cf8 7223->7225 7224->7225 7226 fd46ab 14 API calls 7224->7226 7225->7214 7226->7222 7416 fd3b3e 7419 fd3ba5 7416->7419 7420 fd3bb9 7419->7420 7422 fd3b51 7419->7422 7421 fd471b 14 API calls 7420->7421 7420->7422 7421->7422 6738 fd31f9 6739 fd320b 6738->6739 6740 fd3211 6738->6740 6741 fd31a1 14 API calls 6739->6741 6741->6740 6985 fd36bb 6988 fd3620 6985->6988 6989 fd362c 6988->6989 6996 fd5bc8 EnterCriticalSection 6989->6996 6991 fd3664 6997 fd3682 6991->6997 6993 fd3636 6993->6991 6995 fd6855 14 API calls 6993->6995 6995->6993 6996->6993 7000 fd5c10 LeaveCriticalSection 6997->7000 6999 fd3670 7000->6999 7227 fd2d7a 7228 fd2d8a 7227->7228 7229 fd2d91 7227->7229 7230 fd2db2 7229->7230 7231 fd2d9c 7229->7231 7232 fd5642 69 API calls 7230->7232 7234 fd46ab 14 API calls 7231->7234 7233 fd2db8 7232->7233 7251 fd5089 GetModuleFileNameW 7233->7251 7236 fd2da1 7234->7236 7238 fd45ee 20 API calls 7236->7238 7237 fd2dcb 7259 fd2eb0 7237->7259 7238->7228 7243 fd2e16 7245 fd46ab 14 API calls 7243->7245 7244 fd2e22 7246 fd2eb0 61 API calls 7244->7246 7250 fd2e1b 7245->7250 7247 fd2e3a 7246->7247 7249 fd471b 14 API calls 7247->7249 7247->7250 7248 fd471b 14 API calls 7248->7228 7249->7250 7250->7248 7252 fd50c9 7251->7252 7253 fd50b8 GetLastError 7251->7253 7271 fd4e02 7252->7271 7254 fd4675 14 API calls 7253->7254 7258 fd50c4 7254->7258 7258->7237 7261 fd2ed5 7259->7261 7260 fd5968 61 API calls 7260->7261 7261->7260 7263 fd2f35 7261->7263 7262 fd2e00 7265 fd3024 7262->7265 7263->7262 7264 fd5968 61 API calls 7263->7264 7264->7263 7266 fd3035 7265->7266 7267 fd2e0d 7265->7267 7266->7267 7268 fd46be 14 API calls 7266->7268 7267->7243 7267->7244 7269 fd305e 7268->7269 7270 fd471b 14 API calls 7269->7270 7270->7267 7272 fd3d74 61 API calls 7271->7272 7273 fd4e14 7272->7273 7274 fd4e26 7273->7274 7297 fd6a7d 7273->7297 7276 fd4f87 7274->7276 7277 fd4f94 7276->7277 7278 fd4fa3 7276->7278 7277->7258 7279 fd4fab 7278->7279 7280 fd4fd0 7278->7280 7279->7277 7303 fd504e 7279->7303 7281 fd5a15 WideCharToMultiByte 7280->7281 7282 fd4fe0 7281->7282 7284 fd4ffd 7282->7284 7285 fd4fe7 GetLastError 7282->7285 7287 fd500e 7284->7287 7289 fd504e 14 API calls 7284->7289 7286 fd4675 14 API calls 7285->7286 7288 fd4ff3 7286->7288 7287->7277 7290 fd5a15 WideCharToMultiByte 7287->7290 7291 fd46ab 14 API calls 7288->7291 7289->7287 7292 fd5026 7290->7292 7291->7277 7292->7277 7293 fd502d GetLastError 7292->7293 7294 fd4675 14 API calls 7293->7294 7295 fd5039 7294->7295 7296 fd46ab 14 API calls 7295->7296 7296->7277 7300 fd68a5 7297->7300 7301 fd69ba 5 API calls 7300->7301 7302 fd68bb 7301->7302 7302->7274 7304 fd5059 7303->7304 7305 fd46ab 14 API calls 7304->7305 7306 fd5062 7305->7306 7306->7277 7307 fd197a 7308 fd19b1 7307->7308 7310 fd198c 7307->7310 7310->7308 7316 fd1f3a 7310->7316 7314 fd3c74 61 API calls 7315 fd19cf 7314->7315 7317 fd2263 71 API calls 7316->7317 7318 fd19be 7317->7318 7319 fd1f43 7318->7319 7320 fd2263 71 API calls 7319->7320 7321 fd19c8 7320->7321 7321->7314 6742 fd4ef5 6743 fd4f07 6742->6743 6752 fd4f03 6742->6752 6744 fd4f0c 6743->6744 6745 fd4f32 6743->6745 6746 fd46be 14 API calls 6744->6746 6745->6752 6753 fd6cd5 6745->6753 6747 fd4f15 6746->6747 6749 fd471b 14 API calls 6747->6749 6749->6752 6750 fd4f52 6751 fd471b 14 API calls 6750->6751 6751->6752 6754 fd6cfd 6753->6754 6755 fd6ce2 6753->6755 6757 fd6d0c 6754->6757 6762 fd8531 6754->6762 6755->6754 6756 fd6cee 6755->6756 6758 fd46ab 14 API calls 6756->6758 6769 fd8564 6757->6769 6761 fd6cf3 6758->6761 6761->6750 6763 fd853c 6762->6763 6764 fd8551 HeapSize 6762->6764 6765 fd46ab 14 API calls 6763->6765 6764->6757 6766 fd8541 6765->6766 6767 fd45ee 20 API calls 6766->6767 6768 fd854c 6767->6768 6768->6757 6770 fd857c 6769->6770 6771 fd8571 6769->6771 6773 fd8584 6770->6773 6779 fd858d 6770->6779 6772 fd639a 15 API calls 6771->6772 6777 fd8579 6772->6777 6774 fd471b 14 API calls 6773->6774 6774->6777 6775 fd85b7 HeapReAlloc 6775->6777 6775->6779 6776 fd8592 6778 fd46ab 14 API calls 6776->6778 6777->6761 6778->6777 6779->6775 6779->6776 6780 fd6e05 2 API calls 6779->6780 6780->6779 7423 fd3b35 7424 fd1e1d 7 API calls 7423->7424 7425 fd3b3c 7424->7425 7001 fd40b7 7002 fd40c2 7001->7002 7006 fd40d2 7001->7006 7007 fd40d8 7002->7007 7005 fd471b 14 API calls 7005->7006 7008 fd40ed 7007->7008 7009 fd40f3 7007->7009 7010 fd471b 14 API calls 7008->7010 7011 fd471b 14 API calls 7009->7011 7010->7009 7012 fd40ff 7011->7012 7013 fd471b 14 API calls 7012->7013 7014 fd410a 7013->7014 7015 fd471b 14 API calls 7014->7015 7016 fd4115 7015->7016 7017 fd471b 14 API calls 7016->7017 7018 fd4120 7017->7018 7019 fd471b 14 API calls 7018->7019 7020 fd412b 7019->7020 7021 fd471b 14 API calls 7020->7021 7022 fd4136 7021->7022 7023 fd471b 14 API calls 7022->7023 7024 fd4141 7023->7024 7025 fd471b 14 API calls 7024->7025 7026 fd414c 7025->7026 7027 fd471b 14 API calls 7026->7027 7028 fd415a 7027->7028 7033 fd3f04 7028->7033 7034 fd3f10 7033->7034 7049 fd5bc8 EnterCriticalSection 7034->7049 7036 fd3f44 7050 fd3f63 7036->7050 7038 fd3f1a 7038->7036 7040 fd471b 14 API calls 7038->7040 7040->7036 7041 fd3f6f 7042 fd3f7b 7041->7042 7054 fd5bc8 EnterCriticalSection 7042->7054 7044 fd3f85 7045 fd41a5 14 API calls 7044->7045 7046 fd3f98 7045->7046 7055 fd3fb8 7046->7055 7049->7038 7053 fd5c10 LeaveCriticalSection 7050->7053 7052 fd3f51 7052->7041 7053->7052 7054->7044 7058 fd5c10 LeaveCriticalSection 7055->7058 7057 fd3fa6 7057->7005 7058->7057 7059 fd11b6 7064 fd196e SetUnhandledExceptionFilter 7059->7064 7061 fd11bb 7065 fd374b 7061->7065 7063 fd11c6 7064->7061 7066 fd3757 7065->7066 7067 fd3771 7065->7067 7066->7067 7068 fd46ab 14 API calls 7066->7068 7067->7063 7069 fd3761 7068->7069 7070 fd45ee 20 API calls 7069->7070 7071 fd376c 7070->7071 7071->7063 7322 fd1376 IsProcessorFeaturePresent 7323 fd138b 7322->7323 7326 fd134e SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 7323->7326 7325 fd146e 7326->7325 6781 fd99f1 6782 fd9a15 6781->6782 6783 fd9a2e 6782->6783 6785 fda917 6782->6785 6784 fd9a78 6783->6784 6789 fda723 6783->6789 6788 fda959 6785->6788 6797 fdacb1 6785->6797 6790 fda736 DecodePointer 6789->6790 6791 fda746 6789->6791 6790->6791 6792 fda78a 6791->6792 6793 fda775 6791->6793 6794 fda7d1 6791->6794 6792->6794 6796 fd46ab 14 API calls 6792->6796 6793->6794 6795 fd46ab 14 API calls 6793->6795 6794->6784 6795->6794 6796->6794 6798 fdacea 6797->6798 6800 fdad11 6798->6800 6806 fdaf8d 6798->6806 6801 fdad54 6800->6801 6802 fdad2f 6800->6802 6818 fdb283 6801->6818 6810 fdb2b2 6802->6810 6805 fdad4f 6805->6788 6807 fdafb8 6806->6807 6808 fdb1b1 RaiseException 6807->6808 6809 fdb1ca 6808->6809 6809->6800 6811 fdb2c1 6810->6811 6812 fdb335 6811->6812 6813 fdb2e0 6811->6813 6814 fdb283 14 API calls 6812->6814 6816 fdb32e 6813->6816 6817 fdb283 14 API calls 6813->6817 6815 fdb34a 6814->6815 6815->6805 6816->6805 6817->6816 6819 fdb2a5 6818->6819 6820 fdb290 6818->6820 6821 fd46ab 14 API calls 6819->6821 6822 fdb2aa 6820->6822 6823 fd46ab 14 API calls 6820->6823 6821->6822 6822->6805 6824 fdb29d 6823->6824 6824->6805 6825 fd74ef 6826 fd741e 61 API calls 6825->6826 6827 fd74f7 6826->6827 6835 fd9133 6827->6835 6829 fd74fc 6845 fd91de 6829->6845 6832 fd7526 6833 fd471b 14 API calls 6832->6833 6834 fd7531 6833->6834 6836 fd913f 6835->6836 6849 fd5bc8 EnterCriticalSection 6836->6849 6838 fd91b6 6863 fd91d5 6838->6863 6840 fd914a 6840->6838 6842 fd918a DeleteCriticalSection 6840->6842 6850 fd96b4 6840->6850 6844 fd471b 14 API calls 6842->6844 6844->6840 6846 fd750b DeleteCriticalSection 6845->6846 6847 fd91f5 6845->6847 6846->6829 6846->6832 6847->6846 6848 fd471b 14 API calls 6847->6848 6848->6846 6849->6840 6851 fd96c0 6850->6851 6852 fd96df 6851->6852 6853 fd96ca 6851->6853 6859 fd96da 6852->6859 6866 fd753b EnterCriticalSection 6852->6866 6854 fd46ab 14 API calls 6853->6854 6855 fd96cf 6854->6855 6857 fd45ee 20 API calls 6855->6857 6857->6859 6858 fd96fc 6867 fd963d 6858->6867 6859->6840 6861 fd9707 6883 fd972e 6861->6883 6942 fd5c10 LeaveCriticalSection 6863->6942 6865 fd91c2 6865->6829 6866->6858 6868 fd965f 6867->6868 6869 fd964a 6867->6869 6872 fd7371 61 API calls 6868->6872 6876 fd965a 6868->6876 6870 fd46ab 14 API calls 6869->6870 6871 fd964f 6870->6871 6873 fd45ee 20 API calls 6871->6873 6874 fd9674 6872->6874 6873->6876 6875 fd91de 14 API calls 6874->6875 6877 fd967c 6875->6877 6876->6861 6878 fd7b5f 20 API calls 6877->6878 6879 fd9682 6878->6879 6886 fd9ca7 6879->6886 6882 fd471b 14 API calls 6882->6876 6941 fd754f LeaveCriticalSection 6883->6941 6885 fd9736 6885->6859 6887 fd9ccd 6886->6887 6888 fd9cb8 6886->6888 6889 fd9d16 6887->6889 6894 fd9cf4 6887->6894 6890 fd4698 14 API calls 6888->6890 6892 fd4698 14 API calls 6889->6892 6891 fd9cbd 6890->6891 6893 fd46ab 14 API calls 6891->6893 6895 fd9d1b 6892->6895 6898 fd9688 6893->6898 6901 fd9c1b 6894->6901 6897 fd46ab 14 API calls 6895->6897 6899 fd9d23 6897->6899 6898->6876 6898->6882 6900 fd45ee 20 API calls 6899->6900 6900->6898 6902 fd9c27 6901->6902 6912 fd5da6 EnterCriticalSection 6902->6912 6904 fd9c35 6905 fd9c5c 6904->6905 6906 fd9c67 6904->6906 6913 fd9d34 6905->6913 6908 fd46ab 14 API calls 6906->6908 6909 fd9c62 6908->6909 6928 fd9c9b 6909->6928 6912->6904 6914 fd5e7d 20 API calls 6913->6914 6917 fd9d44 6914->6917 6915 fd9d4a 6931 fd5dec 6915->6931 6917->6915 6918 fd9d7c 6917->6918 6921 fd5e7d 20 API calls 6917->6921 6918->6915 6919 fd5e7d 20 API calls 6918->6919 6923 fd9d88 CloseHandle 6919->6923 6922 fd9d73 6921->6922 6925 fd5e7d 20 API calls 6922->6925 6923->6915 6926 fd9d94 GetLastError 6923->6926 6924 fd9dc4 6924->6909 6925->6918 6926->6915 6927 fd4675 14 API calls 6927->6924 6940 fd5dc9 LeaveCriticalSection 6928->6940 6930 fd9c84 6930->6898 6932 fd5dfb 6931->6932 6933 fd5e62 6931->6933 6932->6933 6937 fd5e25 6932->6937 6934 fd46ab 14 API calls 6933->6934 6935 fd5e67 6934->6935 6936 fd4698 14 API calls 6935->6936 6938 fd5e52 6936->6938 6937->6938 6939 fd5e4c SetStdHandle 6937->6939 6938->6924 6938->6927 6939->6938 6940->6930 6941->6885 6942->6865 7426 fd992f 7427 fd9938 7426->7427 7428 fd995f 7427->7428 7429 fd99a0 7427->7429 7430 fda5de 7428->7430 7433 fda6e7 15 API calls 7428->7433 7429->7430 7431 fda6e7 15 API calls 7429->7431 7432 fd99ee 7431->7432 7434 fda60e 7433->7434 6943 fd12e9 6946 fd2b80 6943->6946 6947 fd4347 14 API calls 6946->6947 6948 fd12fa 6947->6948 7327 fd6067 7328 fd6073 7327->7328 7339 fd5bc8 EnterCriticalSection 7328->7339 7330 fd607a 7340 fd5d08 7330->7340 7338 fd6098 7364 fd60be 7338->7364 7339->7330 7341 fd5d14 7340->7341 7342 fd5d1d 7341->7342 7343 fd5d3e 7341->7343 7344 fd46ab 14 API calls 7342->7344 7367 fd5bc8 EnterCriticalSection 7343->7367 7346 fd5d22 7344->7346 7348 fd45ee 20 API calls 7346->7348 7347 fd5d4a 7352 fd5d76 7347->7352 7368 fd5c58 7347->7368 7349 fd5d2c 7348->7349 7349->7338 7353 fd5efd GetStartupInfoW 7349->7353 7375 fd5d9d 7352->7375 7354 fd5f1a 7353->7354 7355 fd5fae 7353->7355 7354->7355 7356 fd5d08 21 API calls 7354->7356 7359 fd5fb3 7355->7359 7357 fd5f42 7356->7357 7357->7355 7358 fd5f72 GetFileType 7357->7358 7358->7357 7360 fd5fba 7359->7360 7361 fd5ffd GetStdHandle 7360->7361 7362 fd6063 7360->7362 7363 fd6010 GetFileType 7360->7363 7361->7360 7362->7338 7363->7360 7379 fd5c10 LeaveCriticalSection 7364->7379 7366 fd60a9 7367->7347 7369 fd46be 14 API calls 7368->7369 7371 fd5c6a 7369->7371 7370 fd5c77 7372 fd471b 14 API calls 7370->7372 7371->7370 7373 fd6b9b 6 API calls 7371->7373 7374 fd5ccc 7372->7374 7373->7371 7374->7347 7378 fd5c10 LeaveCriticalSection 7375->7378 7377 fd5da4 7377->7349 7378->7377 7379->7366 7435 fd7427 7436 fd7434 7435->7436 7437 fd46be 14 API calls 7436->7437 7438 fd744e 7437->7438 7439 fd471b 14 API calls 7438->7439 7440 fd745a 7439->7440 7441 fd46be 14 API calls 7440->7441 7445 fd7480 7440->7445 7443 fd7474 7441->7443 7442 fd6b9b 6 API calls 7442->7445 7444 fd471b 14 API calls 7443->7444 7444->7445 7445->7442 7446 fd748c 7445->7446 7447 fd74ea 7445->7447 6949 fd98e1 6950 fd9901 6949->6950 6953 fd9938 6950->6953 6952 fd992b 6954 fd993f 6953->6954 6955 fd99a0 6954->6955 6959 fd995f 6954->6959 6957 fda5de 6955->6957 6962 fda6e7 6955->6962 6957->6952 6959->6957 6960 fda6e7 15 API calls 6959->6960 6961 fda60e 6960->6961 6961->6952 6963 fda6f0 6962->6963 6966 fdab5f 6963->6966 6965 fd99ee 6965->6952 6967 fdab9e 6966->6967 6968 fdac20 6967->6968 6972 fdaf6a 6967->6972 6970 fdb283 14 API calls 6968->6970 6971 fdac55 6968->6971 6970->6971 6971->6965 6973 fdaf8d RaiseException 6972->6973 6974 fdaf88 6973->6974 6974->6968 7072 fd3ca0 7073 fd3ca3 7072->7073 7074 fd3d25 61 API calls 7073->7074 7075 fd3caf 7074->7075 7076 fd1ca0 7079 fd1cbe 7076->7079 7077 fd1d3e 7079->7077 7081 fd21e0 RtlUnwind 7079->7081 7080 fd1dc7 7081->7080 7082 fd6c9f 7083 fd6caa 7082->7083 7085 fd6cd0 7082->7085 7084 fd6cba FreeLibrary 7083->7084 7083->7085 7084->7083 7380 fd3b55 7381 fd471b 14 API calls 7380->7381 7382 fd3b63 7381->7382 7383 fd471b 14 API calls 7382->7383 7384 fd3b76 7383->7384 7385 fd471b 14 API calls 7384->7385 7386 fd3b87 7385->7386 7387 fd471b 14 API calls 7386->7387 7388 fd3b98 7387->7388 7448 fda615 7449 fda63d 7448->7449 7450 fda675 7449->7450 7451 fda66e 7449->7451 7452 fda667 7449->7452 7457 fda6d0 7451->7457 7453 fda6e7 15 API calls 7452->7453 7456 fda66c 7453->7456 7458 fda6f0 7457->7458 7459 fdab5f 15 API calls 7458->7459 7460 fda673 7459->7460 7086 fd1e94 7089 fd1ee2 7086->7089 7090 fd1e9f 7089->7090 7091 fd1eeb 7089->7091 7091->7090 7098 fd2263 7091->7098 7093 fd1f26 7094 fd2263 71 API calls 7093->7094 7095 fd1f31 7094->7095 7111 fd3c74 7095->7111 7117 fd2271 7098->7117 7100 fd2268 7100->7093 7101 fd6f5c 2 API calls 7100->7101 7102 fd3d2a 7101->7102 7103 fd3d35 7102->7103 7105 fd6fa1 61 API calls 7102->7105 7104 fd3d3f IsProcessorFeaturePresent 7103->7104 7110 fd3d5e 7103->7110 7106 fd3d4b 7104->7106 7105->7103 7108 fd4442 3 API calls 7106->7108 7107 fd3591 23 API calls 7109 fd3d68 7107->7109 7108->7110 7110->7107 7112 fd3c80 7111->7112 7113 fd41f0 61 API calls 7112->7113 7114 fd3c85 7113->7114 7115 fd3d25 61 API calls 7114->7115 7116 fd3caf 7115->7116 7118 fd227d GetLastError 7117->7118 7119 fd227a 7117->7119 7131 fd253c 7118->7131 7119->7100 7122 fd22b1 7123 fd22f7 SetLastError 7122->7123 7123->7100 7124 fd2577 6 API calls 7125 fd22ab 7124->7125 7125->7122 7126 fd22d3 7125->7126 7128 fd2577 6 API calls 7125->7128 7127 fd2577 6 API calls 7126->7127 7129 fd22e7 7126->7129 7127->7129 7128->7126 7136 fd3cb0 7129->7136 7132 fd247d 5 API calls 7131->7132 7133 fd2556 7132->7133 7134 fd256e TlsGetValue 7133->7134 7135 fd2292 7133->7135 7134->7135 7135->7122 7135->7123 7135->7124 7137 fd471b 14 API calls 7136->7137 7138 fd3cc8 7137->7138 7138->7122 7389 fd8457 7390 fd5642 69 API calls 7389->7390 7391 fd845c 7390->7391 7465 fda917 7466 fda930 7465->7466 7467 fdacb1 15 API calls 7466->7467 7468 fda959 7466->7468 7467->7468 7139 fd7b90 7140 fd7bca 7139->7140 7141 fd46ab 14 API calls 7140->7141 7144 fd7bde 7140->7144 7142 fd7bd3 7141->7142 7143 fd45ee 20 API calls 7142->7143 7143->7144 7144->7144 7392 fd344f 7393 fd3c74 61 API calls 7392->7393 7394 fd3457 7393->7394 5658 fd11c8 5659 fd11d4 5658->5659 5686 fd14e6 5659->5686 5661 fd11db 5662 fd132e 5661->5662 5670 fd1205 5661->5670 5727 fd17da IsProcessorFeaturePresent 5662->5727 5664 fd1335 5731 fd35cd 5664->5731 5669 fd1224 5670->5669 5677 fd12a5 5670->5677 5710 fd35a7 5670->5710 5694 fd18f5 5677->5694 5678 fd12c0 5716 fd192b GetModuleHandleW 5678->5716 5681 fd12cb 5682 fd12d4 5681->5682 5718 fd3582 5681->5718 5721 fd1657 5682->5721 5687 fd14ef 5686->5687 5737 fd1a75 IsProcessorFeaturePresent 5687->5737 5691 fd1500 5692 fd1504 5691->5692 5747 fd1e1d 5691->5747 5692->5661 5809 fd1f50 5694->5809 5697 fd12ab 5698 fd326b 5697->5698 5811 fd5642 5698->5811 5700 fd12b3 5703 fd1000 5700->5703 5701 fd3274 5701->5700 5817 fd5968 5701->5817 5704 fd1015 FindWindowW FindWindowW 5703->5704 5706 fd1035 5704->5706 5705 fd10a2 SetWindowPos SetWindowPos Sleep SetWindowPos SetWindowPos 5705->5678 5706->5705 5707 fd1092 Sleep 5706->5707 5708 fd103f SetWindowPos SetWindowPos Sleep 5706->5708 5709 fd1070 SetWindowPos SetWindowPos 5706->5709 5707->5704 5708->5704 5709->5707 5711 fd35bd 5710->5711 5711->5677 5712 fd41f0 61 API calls 5711->5712 5713 fd3c85 5712->5713 5714 fd3d25 61 API calls 5713->5714 5715 fd3caf 5714->5715 5717 fd12c7 5716->5717 5717->5664 5717->5681 6613 fd346b 5718->6613 5722 fd1663 5721->5722 5723 fd12dc 5722->5723 6681 fd3be5 5722->6681 5723->5669 5725 fd1671 5726 fd1e1d 7 API calls 5725->5726 5726->5723 5728 fd17f0 5727->5728 5729 fd189b IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 5728->5729 5730 fd18e6 5729->5730 5730->5664 5732 fd346b 23 API calls 5731->5732 5733 fd133b 5732->5733 5734 fd3591 5733->5734 5735 fd346b 23 API calls 5734->5735 5736 fd1343 5735->5736 5738 fd14fb 5737->5738 5739 fd1dfe 5738->5739 5753 fd2351 5739->5753 5742 fd1e07 5742->5691 5744 fd1e0f 5745 fd1e1a 5744->5745 5767 fd238d 5744->5767 5745->5691 5748 fd1e26 5747->5748 5749 fd1e30 5747->5749 5750 fd2336 6 API calls 5748->5750 5749->5692 5751 fd1e2b 5750->5751 5752 fd238d DeleteCriticalSection 5751->5752 5752->5749 5754 fd235a 5753->5754 5756 fd2383 5754->5756 5757 fd1e03 5754->5757 5771 fd25b5 5754->5771 5758 fd238d DeleteCriticalSection 5756->5758 5757->5742 5759 fd2303 5757->5759 5758->5757 5790 fd24c6 5759->5790 5762 fd2318 5762->5744 5765 fd2333 5765->5744 5768 fd23b7 5767->5768 5769 fd2398 5767->5769 5768->5742 5770 fd23a2 DeleteCriticalSection 5769->5770 5770->5768 5770->5770 5776 fd247d 5771->5776 5774 fd25ed InitializeCriticalSectionAndSpinCount 5775 fd25d8 5774->5775 5775->5754 5777 fd2495 5776->5777 5780 fd24b8 5776->5780 5777->5780 5782 fd23e3 5777->5782 5780->5774 5780->5775 5781 fd24aa GetProcAddress 5781->5780 5784 fd23ef 5782->5784 5783 fd2463 5783->5780 5783->5781 5784->5783 5785 fd2405 LoadLibraryExW 5784->5785 5789 fd2445 LoadLibraryExW 5784->5789 5786 fd246a 5785->5786 5787 fd2423 GetLastError 5785->5787 5786->5783 5788 fd2472 FreeLibrary 5786->5788 5787->5784 5788->5783 5789->5784 5789->5786 5791 fd247d 5 API calls 5790->5791 5792 fd24e0 5791->5792 5793 fd24f9 TlsAlloc 5792->5793 5794 fd230d 5792->5794 5794->5762 5795 fd2577 5794->5795 5796 fd247d 5 API calls 5795->5796 5797 fd2591 5796->5797 5798 fd25ac TlsSetValue 5797->5798 5799 fd2326 5797->5799 5798->5799 5799->5765 5800 fd2336 5799->5800 5801 fd2346 5800->5801 5802 fd2340 5800->5802 5801->5762 5804 fd2501 5802->5804 5805 fd247d 5 API calls 5804->5805 5806 fd251b 5805->5806 5807 fd2533 TlsFree 5806->5807 5808 fd2527 5806->5808 5807->5808 5808->5801 5810 fd1908 GetStartupInfoW 5809->5810 5810->5697 5812 fd564b 5811->5812 5813 fd567d 5811->5813 5820 fd42ad 5812->5820 5813->5701 6610 fd5911 5817->6610 5821 fd42b8 5820->5821 5822 fd42be 5820->5822 5864 fd6b1a 5821->5864 5829 fd42c4 5822->5829 5869 fd6b59 5822->5869 5833 fd433d 5829->5833 5892 fd3d25 5829->5892 5831 fd4305 5834 fd6b59 6 API calls 5831->5834 5832 fd42f0 5835 fd6b59 6 API calls 5832->5835 5845 fd548e 5833->5845 5836 fd4311 5834->5836 5837 fd42fc 5835->5837 5838 fd4315 5836->5838 5839 fd4324 5836->5839 5881 fd471b 5837->5881 5840 fd6b59 6 API calls 5838->5840 5887 fd401e 5839->5887 5840->5837 5844 fd471b 14 API calls 5844->5829 6416 fd55a2 5845->6416 5850 fd54ba 5850->5813 5854 fd471b 14 API calls 5856 fd550b 5854->5856 5855 fd54f0 5857 fd54f8 5855->5857 5860 fd5513 5855->5860 5856->5813 5858 fd46ab 14 API calls 5857->5858 5859 fd54fd 5858->5859 5859->5854 5861 fd471b 14 API calls 5860->5861 5863 fd553f 5860->5863 5861->5863 5863->5859 6450 fd512a 5863->6450 5903 fd69ba 5864->5903 5866 fd6b36 5867 fd6b3f 5866->5867 5868 fd6b51 TlsGetValue 5866->5868 5867->5822 5870 fd69ba 5 API calls 5869->5870 5871 fd6b75 5870->5871 5872 fd42d8 5871->5872 5873 fd6b93 TlsSetValue 5871->5873 5872->5829 5874 fd46be 5872->5874 5880 fd46cb 5874->5880 5875 fd470b 5919 fd46ab 5875->5919 5876 fd46f6 HeapAlloc 5878 fd42e8 5876->5878 5876->5880 5878->5831 5878->5832 5880->5875 5880->5876 5916 fd6e05 5880->5916 5882 fd4726 HeapFree 5881->5882 5886 fd474f 5881->5886 5883 fd473b 5882->5883 5882->5886 5884 fd46ab 12 API calls 5883->5884 5885 fd4741 GetLastError 5884->5885 5885->5886 5886->5829 5956 fd3eb2 5887->5956 6098 fd6f5c 5892->6098 5895 fd3d3f IsProcessorFeaturePresent 5898 fd3d4b 5895->5898 5897 fd3d35 5897->5895 5902 fd3d5e 5897->5902 6134 fd4442 5898->6134 5899 fd3591 23 API calls 5901 fd3d68 5899->5901 5902->5899 5904 fd69e8 5903->5904 5908 fd69e4 5903->5908 5904->5908 5909 fd68f3 5904->5909 5907 fd6a02 GetProcAddress 5907->5908 5908->5866 5914 fd6904 5909->5914 5910 fd69af 5910->5907 5910->5908 5911 fd6922 LoadLibraryExW 5912 fd693d GetLastError 5911->5912 5911->5914 5912->5914 5913 fd6998 FreeLibrary 5913->5914 5914->5910 5914->5911 5914->5913 5915 fd6970 LoadLibraryExW 5914->5915 5915->5914 5922 fd6e32 5916->5922 5933 fd4347 GetLastError 5919->5933 5921 fd46b0 5921->5878 5923 fd6e3e 5922->5923 5928 fd5bc8 EnterCriticalSection 5923->5928 5925 fd6e49 5929 fd6e85 5925->5929 5928->5925 5932 fd5c10 LeaveCriticalSection 5929->5932 5931 fd6e10 5931->5880 5932->5931 5934 fd435e 5933->5934 5938 fd4364 5933->5938 5935 fd6b1a 6 API calls 5934->5935 5935->5938 5936 fd6b59 6 API calls 5937 fd4382 5936->5937 5939 fd46be 12 API calls 5937->5939 5955 fd436a SetLastError 5937->5955 5938->5936 5938->5955 5940 fd4392 5939->5940 5942 fd439a 5940->5942 5943 fd43b1 5940->5943 5944 fd6b59 6 API calls 5942->5944 5945 fd6b59 6 API calls 5943->5945 5946 fd43a8 5944->5946 5947 fd43bd 5945->5947 5951 fd471b 12 API calls 5946->5951 5948 fd43c1 5947->5948 5949 fd43d2 5947->5949 5952 fd6b59 6 API calls 5948->5952 5950 fd401e 12 API calls 5949->5950 5953 fd43dd 5950->5953 5951->5955 5952->5946 5954 fd471b 12 API calls 5953->5954 5954->5955 5955->5921 5957 fd3ebe 5956->5957 5970 fd5bc8 EnterCriticalSection 5957->5970 5959 fd3ec8 5971 fd3ef8 5959->5971 5962 fd3fc4 5963 fd3fd0 5962->5963 5975 fd5bc8 EnterCriticalSection 5963->5975 5965 fd3fda 5976 fd41a5 5965->5976 5967 fd3ff2 5980 fd4012 5967->5980 5970->5959 5974 fd5c10 LeaveCriticalSection 5971->5974 5973 fd3ee6 5973->5962 5974->5973 5975->5965 5977 fd41b4 5976->5977 5978 fd41db 5976->5978 5977->5978 5983 fd6588 5977->5983 5978->5967 6097 fd5c10 LeaveCriticalSection 5980->6097 5982 fd4000 5982->5844 5985 fd6608 5983->5985 5986 fd659e 5983->5986 5987 fd471b 14 API calls 5985->5987 6010 fd6656 5985->6010 5986->5985 5991 fd471b 14 API calls 5986->5991 5993 fd65d1 5986->5993 5988 fd662a 5987->5988 5989 fd471b 14 API calls 5988->5989 5994 fd663d 5989->5994 5990 fd471b 14 API calls 5995 fd65fd 5990->5995 5997 fd65c6 5991->5997 5992 fd6664 5996 fd66c4 5992->5996 6005 fd471b 14 API calls 5992->6005 5998 fd471b 14 API calls 5993->5998 6009 fd65f3 5993->6009 5999 fd471b 14 API calls 5994->5999 6000 fd471b 14 API calls 5995->6000 6001 fd471b 14 API calls 5996->6001 6011 fd60f3 5997->6011 6003 fd65e8 5998->6003 6004 fd664b 5999->6004 6000->5985 6006 fd66ca 6001->6006 6039 fd61f1 6003->6039 6008 fd471b 14 API calls 6004->6008 6005->5992 6006->5978 6008->6010 6009->5990 6051 fd66f9 6010->6051 6012 fd6104 6011->6012 6038 fd61ed 6011->6038 6013 fd6115 6012->6013 6014 fd471b 14 API calls 6012->6014 6015 fd6127 6013->6015 6016 fd471b 14 API calls 6013->6016 6014->6013 6017 fd6139 6015->6017 6018 fd471b 14 API calls 6015->6018 6016->6015 6019 fd614b 6017->6019 6021 fd471b 14 API calls 6017->6021 6018->6017 6020 fd615d 6019->6020 6022 fd471b 14 API calls 6019->6022 6023 fd616f 6020->6023 6024 fd471b 14 API calls 6020->6024 6021->6019 6022->6020 6025 fd471b 14 API calls 6023->6025 6028 fd6181 6023->6028 6024->6023 6025->6028 6026 fd6193 6027 fd61a5 6026->6027 6030 fd471b 14 API calls 6026->6030 6031 fd61b7 6027->6031 6032 fd471b 14 API calls 6027->6032 6028->6026 6029 fd471b 14 API calls 6028->6029 6029->6026 6030->6027 6033 fd61c9 6031->6033 6034 fd471b 14 API calls 6031->6034 6032->6031 6035 fd61db 6033->6035 6036 fd471b 14 API calls 6033->6036 6034->6033 6037 fd471b 14 API calls 6035->6037 6035->6038 6036->6035 6037->6038 6038->5993 6040 fd61fe 6039->6040 6041 fd6256 6039->6041 6042 fd620e 6040->6042 6043 fd471b 14 API calls 6040->6043 6041->6009 6044 fd6220 6042->6044 6046 fd471b 14 API calls 6042->6046 6043->6042 6045 fd6232 6044->6045 6047 fd471b 14 API calls 6044->6047 6048 fd6244 6045->6048 6049 fd471b 14 API calls 6045->6049 6046->6044 6047->6045 6048->6041 6050 fd471b 14 API calls 6048->6050 6049->6048 6050->6041 6052 fd6725 6051->6052 6053 fd6706 6051->6053 6052->5992 6053->6052 6057 fd6292 6053->6057 6056 fd471b 14 API calls 6056->6052 6058 fd6370 6057->6058 6059 fd62a3 6057->6059 6058->6056 6093 fd625a 6059->6093 6062 fd625a 14 API calls 6063 fd62b6 6062->6063 6064 fd625a 14 API calls 6063->6064 6065 fd62c1 6064->6065 6066 fd625a 14 API calls 6065->6066 6067 fd62cc 6066->6067 6068 fd625a 14 API calls 6067->6068 6069 fd62da 6068->6069 6070 fd471b 14 API calls 6069->6070 6071 fd62e5 6070->6071 6072 fd471b 14 API calls 6071->6072 6073 fd62f0 6072->6073 6074 fd471b 14 API calls 6073->6074 6075 fd62fb 6074->6075 6076 fd625a 14 API calls 6075->6076 6077 fd6309 6076->6077 6078 fd625a 14 API calls 6077->6078 6079 fd6317 6078->6079 6080 fd625a 14 API calls 6079->6080 6081 fd6328 6080->6081 6082 fd625a 14 API calls 6081->6082 6083 fd6336 6082->6083 6084 fd625a 14 API calls 6083->6084 6085 fd6344 6084->6085 6086 fd471b 14 API calls 6085->6086 6087 fd634f 6086->6087 6088 fd471b 14 API calls 6087->6088 6089 fd635a 6088->6089 6090 fd471b 14 API calls 6089->6090 6091 fd6365 6090->6091 6092 fd471b 14 API calls 6091->6092 6092->6058 6094 fd628d 6093->6094 6095 fd627d 6093->6095 6094->6062 6095->6094 6096 fd471b 14 API calls 6095->6096 6096->6095 6097->5982 6138 fd6e8e 6098->6138 6101 fd6fa1 6102 fd6fad 6101->6102 6103 fd4347 14 API calls 6102->6103 6107 fd6fda 6102->6107 6110 fd6fd4 6102->6110 6103->6110 6104 fd7021 6106 fd46ab 14 API calls 6104->6106 6105 fd700b 6105->5897 6108 fd7026 6106->6108 6109 fd704d 6107->6109 6152 fd5bc8 EnterCriticalSection 6107->6152 6149 fd45ee 6108->6149 6114 fd708f 6109->6114 6115 fd7180 6109->6115 6125 fd70be 6109->6125 6110->6104 6110->6105 6110->6107 6114->6125 6153 fd41f0 GetLastError 6114->6153 6116 fd718b 6115->6116 6184 fd5c10 LeaveCriticalSection 6115->6184 6119 fd3591 23 API calls 6116->6119 6126 fd7193 6119->6126 6120 fd7113 6120->6105 6128 fd41f0 61 API calls 6120->6128 6122 fd41f0 61 API calls 6122->6120 6124 fd41f0 61 API calls 6124->6125 6180 fd712d 6125->6180 6185 fd753b EnterCriticalSection 6126->6185 6128->6105 6129 fd71aa 6130 fd71e3 6129->6130 6186 fd73d6 6129->6186 6196 fd7214 6130->6196 6135 fd445e 6134->6135 6136 fd448a IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 6135->6136 6137 fd455b 6136->6137 6137->5902 6139 fd6e9a 6138->6139 6144 fd5bc8 EnterCriticalSection 6139->6144 6141 fd6ea8 6145 fd6ee6 6141->6145 6144->6141 6148 fd5c10 LeaveCriticalSection 6145->6148 6147 fd3d2a 6147->5897 6147->6101 6148->6147 6199 fd458a 6149->6199 6151 fd45fa 6151->6105 6152->6109 6154 fd4207 6153->6154 6155 fd420d 6153->6155 6157 fd6b1a 6 API calls 6154->6157 6156 fd6b59 6 API calls 6155->6156 6179 fd4213 SetLastError 6155->6179 6158 fd422b 6156->6158 6157->6155 6159 fd46be 14 API calls 6158->6159 6158->6179 6161 fd423b 6159->6161 6162 fd425a 6161->6162 6163 fd4243 6161->6163 6166 fd6b59 6 API calls 6162->6166 6167 fd6b59 6 API calls 6163->6167 6164 fd42a7 6168 fd3d25 59 API calls 6164->6168 6165 fd42a1 6165->6124 6169 fd4266 6166->6169 6170 fd4251 6167->6170 6171 fd42ac 6168->6171 6172 fd427b 6169->6172 6173 fd426a 6169->6173 6176 fd471b 14 API calls 6170->6176 6175 fd401e 14 API calls 6172->6175 6174 fd6b59 6 API calls 6173->6174 6174->6170 6177 fd4286 6175->6177 6176->6179 6178 fd471b 14 API calls 6177->6178 6178->6179 6179->6164 6179->6165 6181 fd7104 6180->6181 6182 fd7133 6180->6182 6181->6105 6181->6120 6181->6122 6211 fd5c10 LeaveCriticalSection 6182->6211 6184->6116 6185->6129 6187 fd73ec 6186->6187 6188 fd73e3 6186->6188 6215 fd7371 6187->6215 6212 fd72cc 6188->6212 6193 fd7408 6228 fd866f 6193->6228 6195 fd73e9 6195->6130 6415 fd754f LeaveCriticalSection 6196->6415 6198 fd7202 6198->5897 6200 fd4347 14 API calls 6199->6200 6201 fd4595 6200->6201 6202 fd45a3 6201->6202 6207 fd45fe IsProcessorFeaturePresent 6201->6207 6202->6151 6204 fd45ed 6205 fd458a 20 API calls 6204->6205 6206 fd45fa 6205->6206 6206->6151 6208 fd460a 6207->6208 6209 fd4442 3 API calls 6208->6209 6210 fd461f GetCurrentProcess TerminateProcess 6209->6210 6210->6204 6211->6181 6239 fd7220 6212->6239 6216 fd7389 6215->6216 6217 fd73ae 6215->6217 6216->6217 6218 fd7b5f 20 API calls 6216->6218 6217->6195 6221 fd7b5f 6217->6221 6219 fd73a7 6218->6219 6261 fd8e67 6219->6261 6222 fd7b6b 6221->6222 6223 fd7b80 6221->6223 6224 fd46ab 14 API calls 6222->6224 6223->6193 6225 fd7b70 6224->6225 6226 fd45ee 20 API calls 6225->6226 6227 fd7b7b 6226->6227 6227->6193 6229 fd8680 6228->6229 6232 fd868d 6228->6232 6230 fd46ab 14 API calls 6229->6230 6238 fd8685 6230->6238 6231 fd86d6 6233 fd46ab 14 API calls 6231->6233 6232->6231 6234 fd86b4 6232->6234 6235 fd86db 6233->6235 6383 fd85cd 6234->6383 6236 fd45ee 20 API calls 6235->6236 6236->6238 6238->6195 6240 fd722c 6239->6240 6247 fd5bc8 EnterCriticalSection 6240->6247 6242 fd72a2 6256 fd72c0 6242->6256 6244 fd7236 6244->6242 6248 fd7194 6244->6248 6247->6244 6249 fd71a0 6248->6249 6259 fd753b EnterCriticalSection 6249->6259 6251 fd71aa 6253 fd73d6 61 API calls 6251->6253 6255 fd71e3 6251->6255 6252 fd7214 LeaveCriticalSection 6254 fd7202 6252->6254 6253->6255 6254->6244 6255->6252 6260 fd5c10 LeaveCriticalSection 6256->6260 6258 fd72ae 6258->6195 6259->6251 6260->6258 6262 fd8e73 6261->6262 6263 fd8e7b 6262->6263 6264 fd8e93 6262->6264 6286 fd4698 6263->6286 6265 fd8f2e 6264->6265 6270 fd8ec5 6264->6270 6267 fd4698 14 API calls 6265->6267 6269 fd8f33 6267->6269 6272 fd46ab 14 API calls 6269->6272 6289 fd5da6 EnterCriticalSection 6270->6289 6271 fd46ab 14 API calls 6276 fd8e88 6271->6276 6274 fd8f3b 6272->6274 6277 fd45ee 20 API calls 6274->6277 6275 fd8ecb 6278 fd8efc 6275->6278 6279 fd8ee7 6275->6279 6276->6217 6277->6276 6290 fd8f59 6278->6290 6280 fd46ab 14 API calls 6279->6280 6282 fd8eec 6280->6282 6284 fd4698 14 API calls 6282->6284 6283 fd8ef7 6332 fd8f26 6283->6332 6284->6283 6287 fd4347 14 API calls 6286->6287 6288 fd469d 6287->6288 6288->6271 6289->6275 6291 fd8f7b 6290->6291 6327 fd8f97 6290->6327 6292 fd8f7f 6291->6292 6294 fd8fcf 6291->6294 6293 fd4698 14 API calls 6292->6293 6295 fd8f84 6293->6295 6296 fd8fe5 6294->6296 6335 fd95f0 6294->6335 6297 fd46ab 14 API calls 6295->6297 6338 fd8b00 6296->6338 6300 fd8f8c 6297->6300 6302 fd45ee 20 API calls 6300->6302 6302->6327 6303 fd902c 6305 fd9086 WriteFile 6303->6305 6306 fd9040 6303->6306 6304 fd8ff3 6307 fd9019 6304->6307 6308 fd8ff7 6304->6308 6309 fd90a9 GetLastError 6305->6309 6314 fd900f 6305->6314 6311 fd9048 6306->6311 6312 fd9076 6306->6312 6350 fd86ec GetConsoleOutputCP 6307->6350 6313 fd90f3 6308->6313 6345 fd8a98 6308->6345 6309->6314 6315 fd904d 6311->6315 6316 fd9066 6311->6316 6372 fd8b71 6312->6372 6319 fd46ab 14 API calls 6313->6319 6313->6327 6314->6313 6322 fd90c9 6314->6322 6314->6327 6315->6313 6361 fd8c4c 6315->6361 6366 fd8d35 6316->6366 6321 fd9114 6319->6321 6324 fd4698 14 API calls 6321->6324 6325 fd90e7 6322->6325 6326 fd90d0 6322->6326 6324->6327 6377 fd4675 6325->6377 6328 fd46ab 14 API calls 6326->6328 6327->6283 6330 fd90d5 6328->6330 6331 fd4698 14 API calls 6330->6331 6331->6327 6382 fd5dc9 LeaveCriticalSection 6332->6382 6334 fd8f2c 6334->6276 6336 fd9574 22 API calls 6335->6336 6337 fd9606 6336->6337 6337->6296 6339 fd921e 20 API calls 6338->6339 6340 fd8b11 6339->6340 6341 fd41f0 60 API calls 6340->6341 6344 fd8b67 6340->6344 6342 fd8b34 6341->6342 6343 fd8b4e GetConsoleMode 6342->6343 6342->6344 6343->6344 6344->6303 6344->6304 6346 fd8aba 6345->6346 6349 fd8aef 6345->6349 6347 fd960b CreateFileW CloseHandle WriteConsoleW GetLastError WriteConsoleW 6346->6347 6348 fd8af1 GetLastError 6346->6348 6346->6349 6347->6346 6348->6349 6349->6314 6351 fd3d74 57 API calls 6350->6351 6357 fd8748 6351->6357 6352 fd6376 57 API calls 6352->6357 6353 fd89ee 6353->6314 6354 fd7aeb 57 API calls 6354->6357 6355 fd5a15 WideCharToMultiByte 6355->6357 6356 fd8971 WriteFile 6356->6357 6358 fd8a66 GetLastError 6356->6358 6357->6352 6357->6353 6357->6354 6357->6355 6357->6356 6359 fd943e 14 API calls 6357->6359 6360 fd89a9 WriteFile 6357->6360 6358->6353 6359->6357 6360->6357 6360->6358 6363 fd8c5b 6361->6363 6362 fd8d1a 6362->6314 6363->6362 6364 fd8cd0 WriteFile 6363->6364 6364->6363 6365 fd8d1c GetLastError 6364->6365 6365->6362 6371 fd8d44 6366->6371 6367 fd8e4c 6367->6314 6368 fd5a15 WideCharToMultiByte 6368->6371 6369 fd8e4e GetLastError 6369->6367 6370 fd8e03 WriteFile 6370->6369 6370->6371 6371->6367 6371->6368 6371->6369 6371->6370 6376 fd8b80 6372->6376 6373 fd8c31 6373->6314 6374 fd8bf0 WriteFile 6375 fd8c33 GetLastError 6374->6375 6374->6376 6375->6373 6376->6373 6376->6374 6378 fd4698 14 API calls 6377->6378 6379 fd4680 6378->6379 6380 fd46ab 14 API calls 6379->6380 6381 fd4693 6380->6381 6381->6327 6382->6334 6384 fd85d9 6383->6384 6397 fd5da6 EnterCriticalSection 6384->6397 6386 fd85e8 6387 fd862f 6386->6387 6398 fd5e7d 6386->6398 6389 fd46ab 14 API calls 6387->6389 6391 fd8634 6389->6391 6390 fd8614 FlushFileBuffers 6390->6391 6392 fd8620 6390->6392 6411 fd8663 6391->6411 6394 fd4698 14 API calls 6392->6394 6396 fd8625 GetLastError 6394->6396 6396->6387 6397->6386 6399 fd5e8a 6398->6399 6402 fd5e9f 6398->6402 6400 fd4698 14 API calls 6399->6400 6401 fd5e8f 6400->6401 6404 fd46ab 14 API calls 6401->6404 6403 fd4698 14 API calls 6402->6403 6405 fd5ec4 6402->6405 6406 fd5ecf 6403->6406 6407 fd5e97 6404->6407 6405->6390 6408 fd46ab 14 API calls 6406->6408 6407->6390 6409 fd5ed7 6408->6409 6410 fd45ee 20 API calls 6409->6410 6410->6407 6414 fd5dc9 LeaveCriticalSection 6411->6414 6413 fd864c 6413->6238 6414->6413 6415->6198 6417 fd55ae 6416->6417 6418 fd55c8 6417->6418 6458 fd5bc8 EnterCriticalSection 6417->6458 6420 fd54a1 6418->6420 6423 fd3d25 61 API calls 6418->6423 6427 fd5238 6420->6427 6421 fd5604 6459 fd5621 6421->6459 6425 fd5641 6423->6425 6424 fd55d8 6424->6421 6426 fd471b 14 API calls 6424->6426 6426->6421 6463 fd3d74 6427->6463 6430 fd5259 GetOEMCP 6432 fd5282 6430->6432 6431 fd526b 6431->6432 6433 fd5270 GetACP 6431->6433 6432->5850 6434 fd639a 6432->6434 6433->6432 6435 fd63d8 6434->6435 6440 fd63a8 6434->6440 6436 fd46ab 14 API calls 6435->6436 6438 fd54cb 6436->6438 6437 fd63c3 HeapAlloc 6437->6438 6437->6440 6438->5859 6441 fd569d 6438->6441 6439 fd6e05 2 API calls 6439->6440 6440->6435 6440->6437 6440->6439 6442 fd5238 63 API calls 6441->6442 6443 fd56bd 6442->6443 6444 fd56f7 IsValidCodePage 6443->6444 6448 fd5733 6443->6448 6445 fd5709 6444->6445 6444->6448 6446 fd5738 GetCPInfo 6445->6446 6449 fd5712 6445->6449 6446->6448 6446->6449 6448->5855 6506 fd530e 6449->6506 6451 fd5136 6450->6451 6584 fd5bc8 EnterCriticalSection 6451->6584 6453 fd5140 6585 fd5177 6453->6585 6458->6424 6462 fd5c10 LeaveCriticalSection 6459->6462 6461 fd5628 6461->6418 6462->6461 6464 fd3d8b 6463->6464 6465 fd3d94 6463->6465 6464->6430 6464->6431 6465->6464 6466 fd41f0 61 API calls 6465->6466 6467 fd3db4 6466->6467 6471 fd7b05 6467->6471 6472 fd3dca 6471->6472 6473 fd7b18 6471->6473 6475 fd7b32 6472->6475 6473->6472 6479 fd67d4 6473->6479 6476 fd7b5a 6475->6476 6477 fd7b45 6475->6477 6476->6464 6477->6476 6501 fd568a 6477->6501 6480 fd67e0 6479->6480 6481 fd41f0 61 API calls 6480->6481 6482 fd67e9 6481->6482 6483 fd682f 6482->6483 6492 fd5bc8 EnterCriticalSection 6482->6492 6483->6472 6485 fd6807 6493 fd6855 6485->6493 6490 fd3d25 61 API calls 6491 fd6854 6490->6491 6492->6485 6494 fd6863 6493->6494 6496 fd6818 6493->6496 6495 fd6588 14 API calls 6494->6495 6494->6496 6495->6496 6497 fd6834 6496->6497 6500 fd5c10 LeaveCriticalSection 6497->6500 6499 fd682b 6499->6483 6499->6490 6500->6499 6502 fd41f0 61 API calls 6501->6502 6503 fd5694 6502->6503 6504 fd55a2 61 API calls 6503->6504 6505 fd569a 6504->6505 6505->6476 6507 fd5336 GetCPInfo 6506->6507 6508 fd53ff 6506->6508 6507->6508 6512 fd534e 6507->6512 6508->6448 6510 fd53b6 6528 fd840e 6510->6528 6515 fd63e8 6512->6515 6514 fd840e 63 API calls 6514->6508 6516 fd3d74 61 API calls 6515->6516 6517 fd6408 6516->6517 6533 fd5999 6517->6533 6519 fd64c6 6519->6510 6520 fd6435 6520->6519 6522 fd639a 15 API calls 6520->6522 6524 fd645b 6520->6524 6521 fd64c0 6536 fd64eb 6521->6536 6522->6524 6524->6521 6525 fd5999 MultiByteToWideChar 6524->6525 6526 fd64a9 6525->6526 6526->6521 6527 fd64b0 GetStringTypeW 6526->6527 6527->6521 6529 fd3d74 61 API calls 6528->6529 6530 fd8421 6529->6530 6540 fd8224 6530->6540 6532 fd53d7 6532->6514 6534 fd59aa MultiByteToWideChar 6533->6534 6534->6520 6537 fd6508 6536->6537 6538 fd64f7 6536->6538 6537->6519 6538->6537 6539 fd471b 14 API calls 6538->6539 6539->6537 6541 fd823f 6540->6541 6542 fd5999 MultiByteToWideChar 6541->6542 6544 fd8283 6542->6544 6543 fd83e8 6543->6532 6544->6543 6546 fd639a 15 API calls 6544->6546 6550 fd82a8 6544->6550 6545 fd834d 6549 fd64eb 14 API calls 6545->6549 6546->6550 6547 fd5999 MultiByteToWideChar 6548 fd82ee 6547->6548 6548->6545 6566 fd6be6 6548->6566 6549->6543 6550->6545 6550->6547 6553 fd835c 6555 fd639a 15 API calls 6553->6555 6559 fd836e 6553->6559 6554 fd8324 6554->6545 6557 fd6be6 6 API calls 6554->6557 6555->6559 6556 fd83d9 6558 fd64eb 14 API calls 6556->6558 6557->6545 6558->6545 6559->6556 6560 fd6be6 6 API calls 6559->6560 6561 fd83b6 6560->6561 6561->6556 6572 fd5a15 6561->6572 6563 fd83d0 6563->6556 6564 fd8405 6563->6564 6565 fd64eb 14 API calls 6564->6565 6565->6545 6575 fd68bf 6566->6575 6570 fd6c37 LCMapStringW 6571 fd6bf7 6570->6571 6571->6545 6571->6553 6571->6554 6574 fd5a2c WideCharToMultiByte 6572->6574 6574->6563 6576 fd69ba 5 API calls 6575->6576 6577 fd68d5 6576->6577 6577->6571 6578 fd6c43 6577->6578 6581 fd68d9 6578->6581 6580 fd6c4e 6580->6570 6582 fd69ba LoadLibraryExW GetLastError LoadLibraryExW FreeLibrary GetProcAddress 6581->6582 6583 fd68ef 6582->6583 6583->6580 6584->6453 6595 fd5890 6585->6595 6587 fd5199 6588 fd5890 20 API calls 6587->6588 6589 fd51b8 6588->6589 6590 fd514d 6589->6590 6591 fd471b 14 API calls 6589->6591 6592 fd516b 6590->6592 6591->6590 6609 fd5c10 LeaveCriticalSection 6592->6609 6594 fd5159 6594->5859 6596 fd58a1 6595->6596 6600 fd589d 6595->6600 6597 fd58a8 6596->6597 6601 fd58bb 6596->6601 6598 fd46ab 14 API calls 6597->6598 6599 fd58ad 6598->6599 6602 fd45ee 20 API calls 6599->6602 6600->6587 6601->6600 6603 fd58e9 6601->6603 6604 fd58f2 6601->6604 6602->6600 6605 fd46ab 14 API calls 6603->6605 6604->6600 6606 fd46ab 14 API calls 6604->6606 6607 fd58ee 6605->6607 6606->6607 6608 fd45ee 20 API calls 6607->6608 6608->6600 6609->6594 6611 fd3d74 61 API calls 6610->6611 6612 fd5925 6611->6612 6612->5701 6614 fd3479 6613->6614 6615 fd348a 6613->6615 6617 fd192b GetModuleHandleW 6614->6617 6629 fd3331 6615->6629 6618 fd347e 6617->6618 6618->6615 6624 fd3511 GetModuleHandleExW 6618->6624 6620 fd34c4 6620->5682 6625 fd3530 GetProcAddress 6624->6625 6628 fd3545 6624->6628 6625->6628 6626 fd3559 FreeLibrary 6627 fd3562 6626->6627 6627->6615 6628->6626 6628->6627 6630 fd333d 6629->6630 6645 fd5bc8 EnterCriticalSection 6630->6645 6632 fd3347 6646 fd337e 6632->6646 6634 fd3354 6650 fd3372 6634->6650 6637 fd34cf 6674 fd5c27 GetPEB 6637->6674 6640 fd34fe 6643 fd3511 3 API calls 6640->6643 6641 fd34de GetPEB 6641->6640 6642 fd34ee GetCurrentProcess TerminateProcess 6641->6642 6642->6640 6644 fd3506 ExitProcess 6643->6644 6645->6632 6647 fd338a 6646->6647 6649 fd33eb 6647->6649 6653 fd3a4f 6647->6653 6649->6634 6673 fd5c10 LeaveCriticalSection 6650->6673 6652 fd3360 6652->6620 6652->6637 6656 fd3780 6653->6656 6657 fd378c 6656->6657 6664 fd5bc8 EnterCriticalSection 6657->6664 6659 fd379a 6665 fd395f 6659->6665 6664->6659 6666 fd37a7 6665->6666 6667 fd397e 6665->6667 6669 fd37cf 6666->6669 6667->6666 6668 fd471b 14 API calls 6667->6668 6668->6666 6672 fd5c10 LeaveCriticalSection 6669->6672 6671 fd37b8 6671->6649 6672->6671 6673->6652 6675 fd5c41 6674->6675 6676 fd34d9 6674->6676 6678 fd6a3d 6675->6678 6676->6640 6676->6641 6679 fd69ba 5 API calls 6678->6679 6680 fd6a59 6679->6680 6680->6676 6682 fd3bf0 6681->6682 6683 fd3c02 6681->6683 6684 fd3bfe 6682->6684 6686 fd741e 6682->6686 6683->5725 6684->5725 6687 fd72cc 61 API calls 6686->6687 6688 fd7425 6687->6688 6688->6684 7469 fd490b 7470 fd491b 7469->7470 7480 fd492f 7469->7480 7471 fd46ab 14 API calls 7470->7471 7472 fd4920 7471->7472 7473 fd45ee 20 API calls 7472->7473 7475 fd492a 7473->7475 7474 fd3024 14 API calls 7478 fd4a0b 7474->7478 7477 fd4a14 7479 fd471b 14 API calls 7477->7479 7478->7477 7486 fd4aef 7478->7486 7508 fd8131 7478->7508 7485 fd4a1f 7479->7485 7481 fd49a6 7480->7481 7480->7485 7490 fd4afa 7480->7490 7481->7474 7483 fd4adb 7484 fd471b 14 API calls 7483->7484 7484->7475 7485->7483 7487 fd471b 14 API calls 7485->7487 7488 fd45fe 6 API calls 7486->7488 7487->7485 7489 fd4af9 7488->7489 7491 fd4b06 7490->7491 7492 fd46be 14 API calls 7491->7492 7493 fd4b34 7492->7493 7494 fd8131 20 API calls 7493->7494 7495 fd4b60 7494->7495 7496 fd45fe 6 API calls 7495->7496 7497 fd4baa 7496->7497 7498 fd4e02 61 API calls 7497->7498 7499 fd4c72 7498->7499 7517 fd48ee 7499->7517 7502 fd4cc0 7503 fd4e02 61 API calls 7502->7503 7504 fd4cfd 7503->7504 7520 fd481f 7504->7520 7507 fd4afa 65 API calls 7510 fd807e 7508->7510 7509 fd8096 7511 fd80aa 7509->7511 7512 fd46ab 14 API calls 7509->7512 7510->7509 7510->7511 7514 fd80ce 7510->7514 7511->7478 7516 fd80a0 7512->7516 7513 fd45ee 20 API calls 7513->7511 7514->7511 7515 fd46ab 14 API calls 7514->7515 7515->7516 7516->7513 7543 fd476d 7517->7543 7521 fd482d 7520->7521 7522 fd4849 7520->7522 7523 fd4e41 14 API calls 7521->7523 7524 fd4870 7522->7524 7525 fd4850 7522->7525 7527 fd4837 7523->7527 7526 fd5a15 WideCharToMultiByte 7524->7526 7525->7527 7573 fd4e5b 7525->7573 7528 fd4880 7526->7528 7527->7507 7530 fd489d 7528->7530 7531 fd4887 GetLastError 7528->7531 7534 fd4e5b 15 API calls 7530->7534 7538 fd48ae 7530->7538 7532 fd4675 14 API calls 7531->7532 7533 fd4893 7532->7533 7537 fd46ab 14 API calls 7533->7537 7534->7538 7535 fd5a15 WideCharToMultiByte 7536 fd48c6 7535->7536 7536->7527 7539 fd48cd GetLastError 7536->7539 7537->7527 7538->7527 7538->7535 7540 fd4675 14 API calls 7539->7540 7541 fd48d9 7540->7541 7542 fd46ab 14 API calls 7541->7542 7542->7527 7544 fd477b 7543->7544 7545 fd4795 7543->7545 7561 fd4e41 7544->7561 7546 fd479c 7545->7546 7547 fd47bb 7545->7547 7549 fd4785 FindFirstFileExW 7546->7549 7565 fd4e97 7546->7565 7550 fd5999 MultiByteToWideChar 7547->7550 7549->7502 7552 fd47ca 7550->7552 7553 fd47d1 GetLastError 7552->7553 7555 fd47f7 7552->7555 7556 fd4e97 15 API calls 7552->7556 7554 fd4675 14 API calls 7553->7554 7558 fd47dd 7554->7558 7555->7549 7557 fd5999 MultiByteToWideChar 7555->7557 7556->7555 7559 fd480e 7557->7559 7560 fd46ab 14 API calls 7558->7560 7559->7549 7559->7553 7560->7549 7562 fd4e4c 7561->7562 7563 fd4e54 7561->7563 7564 fd471b 14 API calls 7562->7564 7563->7549 7564->7563 7566 fd4e41 14 API calls 7565->7566 7567 fd4ea5 7566->7567 7570 fd4ed6 7567->7570 7571 fd639a 15 API calls 7570->7571 7572 fd4eb6 7571->7572 7572->7549 7574 fd4e41 14 API calls 7573->7574 7575 fd4e69 7574->7575 7576 fd4ed6 15 API calls 7575->7576 7577 fd4e77 7576->7577 7577->7527 7578 fd9e0b IsProcessorFeaturePresent 7395 fd1344 7398 fd170e 7395->7398 7397 fd1349 7397->7397 7399 fd1724 7398->7399 7401 fd172d 7399->7401 7402 fd16c1 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 7399->7402 7401->7397 7402->7401 6975 fd60c7 6976 fd60cc 6975->6976 6978 fd60ef 6976->6978 6979 fd5cd3 6976->6979 6980 fd5d02 6979->6980 6981 fd5ce0 6979->6981 6980->6976 6982 fd5cfc 6981->6982 6983 fd5cee DeleteCriticalSection 6981->6983 6984 fd471b 14 API calls 6982->6984 6983->6982 6983->6983 6984->6980 7145 fd5b87 7146 fd5b92 7145->7146 7148 fd5bbb 7146->7148 7149 fd5bb7 7146->7149 7151 fd6b9b 7146->7151 7156 fd5bdf 7148->7156 7152 fd69ba 5 API calls 7151->7152 7153 fd6bb7 7152->7153 7154 fd6bd5 InitializeCriticalSectionAndSpinCount 7153->7154 7155 fd6bc0 7153->7155 7154->7155 7155->7146 7157 fd5bec 7156->7157 7159 fd5c0b 7156->7159 7158 fd5bf6 DeleteCriticalSection 7157->7158 7158->7158 7158->7159 7159->7149 7403 fd2247 7404 fd225e 7403->7404 7405 fd2251 7403->7405 7405->7404 7406 fd3cb0 14 API calls 7405->7406 7406->7404 7160 fd8180 7163 fd8197 7160->7163 7162 fd8192 7164 fd81b9 7163->7164 7165 fd81a5 7163->7165 7166 fd81c1 7164->7166 7167 fd81d3 7164->7167 7168 fd46ab 14 API calls 7165->7168 7169 fd46ab 14 API calls 7166->7169 7172 fd3d74 61 API calls 7167->7172 7175 fd81d1 7167->7175 7170 fd81aa 7168->7170 7171 fd81c6 7169->7171 7173 fd45ee 20 API calls 7170->7173 7174 fd45ee 20 API calls 7171->7174 7172->7175 7176 fd81b5 7173->7176 7174->7175 7175->7162 7176->7162 7177 fd5980 GetCommandLineA GetCommandLineW 7407 fd9e40 7410 fd9e5e 7407->7410 7409 fd9e56 7411 fd9e63 7410->7411 7412 fda723 15 API calls 7411->7412 7413 fd9ef8 7411->7413 7414 fda08f 7412->7414 7413->7409 7414->7409 7579 fd1103 7580 fd110b 7579->7580 7596 fd35e3 7580->7596 7582 fd1116 7603 fd151f 7582->7603 7584 fd1188 7585 fd17da 4 API calls 7584->7585 7595 fd11a5 7584->7595 7587 fd11ad 7585->7587 7586 fd112b 7586->7584 7609 fd16ac 7586->7609 7589 fd1144 7589->7584 7612 fd1766 InitializeSListHead 7589->7612 7591 fd115a 7613 fd1775 7591->7613 7593 fd117d 7619 fd36e2 7593->7619 7597 fd3615 7596->7597 7598 fd35f2 7596->7598 7597->7582 7598->7597 7599 fd46ab 14 API calls 7598->7599 7600 fd3605 7599->7600 7601 fd45ee 20 API calls 7600->7601 7602 fd3610 7601->7602 7602->7582 7604 fd152f 7603->7604 7605 fd152b 7603->7605 7606 fd17da 4 API calls 7604->7606 7608 fd153c 7604->7608 7605->7586 7607 fd15a5 7606->7607 7608->7586 7626 fd167f 7609->7626 7612->7591 7661 fd3c15 7613->7661 7615 fd1786 7616 fd178d 7615->7616 7617 fd17da 4 API calls 7615->7617 7616->7593 7618 fd1795 7617->7618 7618->7593 7620 fd41f0 61 API calls 7619->7620 7621 fd36ed 7620->7621 7622 fd46ab 14 API calls 7621->7622 7625 fd3725 7621->7625 7623 fd371a 7622->7623 7624 fd45ee 20 API calls 7623->7624 7624->7625 7625->7584 7627 fd168e 7626->7627 7628 fd1695 7626->7628 7632 fd3a39 7627->7632 7635 fd3aa5 7628->7635 7631 fd1693 7631->7589 7633 fd3aa5 23 API calls 7632->7633 7634 fd3a4b 7633->7634 7634->7631 7638 fd37db 7635->7638 7639 fd37e7 7638->7639 7646 fd5bc8 EnterCriticalSection 7639->7646 7641 fd37f5 7647 fd3836 7641->7647 7643 fd3802 7657 fd382a 7643->7657 7646->7641 7648 fd3852 7647->7648 7656 fd38c9 7647->7656 7649 fd6cd5 23 API calls 7648->7649 7655 fd38a9 7648->7655 7648->7656 7651 fd389f 7649->7651 7650 fd6cd5 23 API calls 7652 fd38bf 7650->7652 7653 fd471b 14 API calls 7651->7653 7654 fd471b 14 API calls 7652->7654 7653->7655 7654->7656 7655->7650 7655->7656 7656->7643 7656->7656 7660 fd5c10 LeaveCriticalSection 7657->7660 7659 fd3813 7659->7631 7660->7659 7662 fd3c33 7661->7662 7666 fd3c53 7661->7666 7663 fd46ab 14 API calls 7662->7663 7664 fd3c49 7663->7664 7665 fd45ee 20 API calls 7664->7665 7665->7666 7666->7615 7415 fd6d42 GetProcessHeap

    Control-flow Graph

    APIs
    • FindWindowW.USER32(00000000,DameWare Licensor), ref: 00FD1022
    • FindWindowW.USER32(00000000,DameWare Server Configuration Wizard), ref: 00FD102D
    • SetWindowPos.USER32(00000000,000000FF,00000000,00000000,00000000,00000000,00000003), ref: 00FD1048
    • SetWindowPos.USER32(00000000,000000FE,00000000,00000000,00000000,00000000,00000003), ref: 00FD1053
    • Sleep.KERNEL32(000000C8), ref: 00FD105E
    • SetWindowPos.USER32(00000000,000000FF,00000000,00000000,00000000,00000000,00000003), ref: 00FD107D
    • SetWindowPos.USER32(00000000,000000FE,00000000,00000000,00000000,00000000,00000003), ref: 00FD108C
    • Sleep.KERNELBASE(000000C8), ref: 00FD1097
    • SetWindowPos.USER32(00000000,000000FF,00000000,00000000,00000000,00000000,00000003), ref: 00FD10AF
    • SetWindowPos.USER32(00000000,000000FF,00000000,00000000,00000000,00000000,00000003), ref: 00FD10BE
    • Sleep.KERNEL32(000000C8), ref: 00FD10C5
    • SetWindowPos.USER32(00000000,000000FE,00000000,00000000,00000000,00000000,00000003), ref: 00FD10D8
    • SetWindowPos.USER32(00000000,000000FE,00000000,00000000,00000000,00000000,00000003), ref: 00FD10E7
    Strings
    • DameWare Licensor, xrefs: 00FD101B
    • DameWare Server Configuration Wizard, xrefs: 00FD1024
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: Window$Sleep$Find
    • String ID: DameWare Licensor$DameWare Server Configuration Wizard
    • API String ID: 3962709634-922529585
    • Opcode ID: ecafc6324311c65fdb9b540e8cd0573e643f2ccd4c9e8a68bd2ca1fb84b17c88
    • Instruction ID: 488a54b0f73f58e409cc777b505bb0ff2b1bb6b9ed0899c531ca0563c3370efc
    • Opcode Fuzzy Hash: ecafc6324311c65fdb9b540e8cd0573e643f2ccd4c9e8a68bd2ca1fb84b17c88
    • Instruction Fuzzy Hash: B13192317CA3A975F631226A5C4FF5B6E1D9F82F30F354301F3247D2D189E46A44A2A9
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 00FD17E6
    • IsDebuggerPresent.KERNEL32 ref: 00FD18B2
    • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00FD18D2
    • UnhandledExceptionFilter.KERNEL32(?), ref: 00FD18DC
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
    • String ID:
    • API String ID: 254469556-0
    • Opcode ID: bfb75d94e71255e1913bdd6bfa7036af9d2e9d37c38721776ea86d121b8a539a
    • Instruction ID: 4d8171007115bdd971205ce41d1ef55cbeef65ba5342af767f6589f3bbd9abef
    • Opcode Fuzzy Hash: bfb75d94e71255e1913bdd6bfa7036af9d2e9d37c38721776ea86d121b8a539a
    • Instruction Fuzzy Hash: 78312975D0121DDBDB20DFA4D9497CDBBB8BF08304F1041AAE40CA7250EB749A84DF45
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • GetSystemTimeAsFileTime.KERNEL32(00000000), ref: 00FD16D3
    • GetCurrentThreadId.KERNEL32 ref: 00FD16E2
    • GetCurrentProcessId.KERNEL32 ref: 00FD16EB
    • QueryPerformanceCounter.KERNEL32(?), ref: 00FD16F8
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
    • String ID:
    • API String ID: 2933794660-0
    • Opcode ID: 138152a38e1144a3208f8ea41d175e9bb120d71fd9ecbf768657af34b94d43e2
    • Instruction ID: 281251279267e49a7a3e679825a86a482ea61f789a30b8971a6dbe0c64dd0a61
    • Opcode Fuzzy Hash: 138152a38e1144a3208f8ea41d175e9bb120d71fd9ecbf768657af34b94d43e2
    • Instruction Fuzzy Hash: C2F04D75C1120DEBCB00DBB4D949A9EBBF8EF18315F518496D412E6150D634AB04DB91
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00FD1353
    • UnhandledExceptionFilter.KERNEL32(?), ref: 00FD135C
    • GetCurrentProcess.KERNEL32(C0000409), ref: 00FD1367
    • TerminateProcess.KERNEL32(00000000), ref: 00FD136E
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: ExceptionFilterProcessUnhandled$CurrentTerminate
    • String ID:
    • API String ID: 3231755760-0
    • Opcode ID: 0fb33453e7241c167556250cd9ed7371b9343a5dab67221f32b336bbd9e878b5
    • Instruction ID: 39fcce165a91a80ce409373f1a743bfec0a41ed1b7dd63da7caafcdd781ee432
    • Opcode Fuzzy Hash: 0fb33453e7241c167556250cd9ed7371b9343a5dab67221f32b336bbd9e878b5
    • Instruction Fuzzy Hash: 58D0123300110DEBCB102BF0EC0CA48BF2AEB04A86F004402F309C1031CB314401FBE1
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    APIs
    • IsDebuggerPresent.KERNEL32(?,?,?,?,?,?), ref: 00FD453A
    • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,?), ref: 00FD4544
    • UnhandledExceptionFilter.KERNEL32(?,?,?,?,?,?,?), ref: 00FD4551
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: ExceptionFilterUnhandled$DebuggerPresent
    • String ID:
    • API String ID: 3906539128-0
    • Opcode ID: 06a4e6239a5e8dfce0987c48aa99ec5a1019aa524ca372e6784c3e20bbeede41
    • Instruction ID: 205b167e92d4d451657c30a6dfa295870e2b3877f79dd9eb892d0631a66fae11
    • Opcode Fuzzy Hash: 06a4e6239a5e8dfce0987c48aa99ec5a1019aa524ca372e6784c3e20bbeede41
    • Instruction Fuzzy Hash: 0131D27490122CABCB21DF64DC8978CBBB9BF08350F5441EAE40CA7290E7349F859F45
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 264 fd34cf-fd34dc call fd5c27 267 fd34fe-fd350a call fd3511 ExitProcess 264->267 268 fd34de-fd34ec GetPEB 264->268 268->267 269 fd34ee-fd34f8 GetCurrentProcess TerminateProcess 268->269 269->267
    APIs
    • GetCurrentProcess.KERNEL32(?,?,00FD34CE,?,?,?,?,?,00FD8FEE), ref: 00FD34F1
    • TerminateProcess.KERNEL32(00000000,?,00FD34CE,?,?,?,?,?,00FD8FEE), ref: 00FD34F8
    • ExitProcess.KERNEL32 ref: 00FD350A
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: Process$CurrentExitTerminate
    • String ID:
    • API String ID: 1703294689-0
    • Opcode ID: b6457ae785191d2657333eacc6c9a2857173a93038684a3c9e7f4cfec99b2ea8
    • Instruction ID: 45ba2fe2722edadea06d8ba4d8e575b8885d41cf8cdf7abf171d6ff6cd47efb7
    • Opcode Fuzzy Hash: b6457ae785191d2657333eacc6c9a2857173a93038684a3c9e7f4cfec99b2ea8
    • Instruction Fuzzy Hash: 28E04632401109EBCF226B34DC4DA493B6BEB00B92B088512F904C6231CB39DE82FA91
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,00000008,?,?,00FDAF88,?,?,00000008,?,?,00FDAC20,00000000), ref: 00FDB1BA
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: ExceptionRaise
    • String ID:
    • API String ID: 3997070919-0
    • Opcode ID: 168df17ccec3fcfe331a0f288d4d8c6415759059e2936384f8abc1b7507e82a6
    • Instruction ID: f2a49daaaef79963c04ebfad182bf82fa2c83036ffbfa6d84a98a772d60ec6ad
    • Opcode Fuzzy Hash: 168df17ccec3fcfe331a0f288d4d8c6415759059e2936384f8abc1b7507e82a6
    • Instruction Fuzzy Hash: 9EB18032610604CFDB15CF28C48AB657BE1FF45365F2A8659E899CF3A1C336E981DB40
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • IsProcessorFeaturePresent.KERNEL32(0000000A), ref: 00FD1A8B
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: FeaturePresentProcessor
    • String ID:
    • API String ID: 2325560087-0
    • Opcode ID: 3811bf2ed86bfc82f9ad0b52d03716493608d8cb7b0271e4c34f57609ce058f9
    • Instruction ID: b8d7704942ad86540d03a4e52e8bdb409d08269ac40739dc16b9134a48fa043e
    • Opcode Fuzzy Hash: 3811bf2ed86bfc82f9ad0b52d03716493608d8cb7b0271e4c34f57609ce058f9
    • Instruction Fuzzy Hash: 26516EB1D152099FDB24CF54DC957AABBF6FB88320F18896BD445EB350E3B49A00EB50
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: d73a0d2fdd0ad494dfa1f143080eea8e8b6201a89862874c6b029e59a7f40ba7
    • Instruction ID: c80801fe75d18fcb07689b42ef4925373ec960e31c0b5f10484a1abd307248f2
    • Opcode Fuzzy Hash: d73a0d2fdd0ad494dfa1f143080eea8e8b6201a89862874c6b029e59a7f40ba7
    • Instruction Fuzzy Hash: 2A419371C0421CAFDB20DF69CC89AAAB7BAEF45310F1842DAE41DD3341DA35AE849F50
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • SetUnhandledExceptionFilter.KERNEL32(Function_0000197A,00FD11BB), ref: 00FD1973
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: ExceptionFilterUnhandled
    • String ID:
    • API String ID: 3192549508-0
    • Opcode ID: 8c5159a4e451ffe4e5128e7723dfc8694932a169fe1c5e90c8dc00a2f7c32e5d
    • Instruction ID: bf6f29d2741c0c77a2c732cac6e616c726b3036ecc28a946c5c1f50bc726901f
    • Opcode Fuzzy Hash: 8c5159a4e451ffe4e5128e7723dfc8694932a169fe1c5e90c8dc00a2f7c32e5d
    • Instruction Fuzzy Hash:
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: HeapProcess
    • String ID:
    • API String ID: 54951025-0
    • Opcode ID: 3a3dfd33a06af22ad57213dd2c58dbe5d6842b86c82f18f22ee5c6758b669840
    • Instruction ID: 8934615dae18010a14127e2d137db6bca5cd73caf1c920cf8e7113956d3e8696
    • Opcode Fuzzy Hash: 3a3dfd33a06af22ad57213dd2c58dbe5d6842b86c82f18f22ee5c6758b669840
    • Instruction Fuzzy Hash: 6AA01230201185DB43004F30694C308379966401D0300C0155001C6030D6204240B601
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 284f938f10376bfbf95834657a6d04f28244e4b62c26eaf15e5c7356afc3666f
    • Instruction ID: ffd020eb26270bf1079340ab10e5a416b1433238363f6f54208b964674e3518c
    • Opcode Fuzzy Hash: 284f938f10376bfbf95834657a6d04f28244e4b62c26eaf15e5c7356afc3666f
    • Instruction Fuzzy Hash: 8BE08C32921628EBCB15EFD8C90498AF3EDEB44F50B194497B501E3200C274DE00DBD0
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 69 fd68f3-fd68ff 70 fd69a6-fd69a9 69->70 71 fd69af 70->71 72 fd6904-fd6915 70->72 75 fd69b1-fd69b5 71->75 73 fd6917-fd691a 72->73 74 fd6922-fd693b LoadLibraryExW 72->74 76 fd6920 73->76 77 fd69a3 73->77 78 fd698d-fd6996 74->78 79 fd693d-fd6946 GetLastError 74->79 80 fd699f-fd69a1 76->80 77->70 78->80 81 fd6998-fd6999 FreeLibrary 78->81 82 fd697d 79->82 83 fd6948-fd695a call fd3e78 79->83 80->77 85 fd69b6-fd69b8 80->85 81->80 84 fd697f-fd6981 82->84 83->82 89 fd695c-fd696e call fd3e78 83->89 84->78 88 fd6983-fd698b 84->88 85->75 88->77 89->82 92 fd6970-fd697b LoadLibraryExW 89->92 92->84
    Strings
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID:
    • String ID: api-ms-$ext-ms-
    • API String ID: 0-537541572
    • Opcode ID: b8e3be79327ef95765662b3d02a0e1f66ffb86a7e38fc68ab3c62887ec9a6a26
    • Instruction ID: ac521ca4dca901d3b2ee6155e5646fca629c4c5b92665711e0d7e6ac5222ab03
    • Opcode Fuzzy Hash: b8e3be79327ef95765662b3d02a0e1f66ffb86a7e38fc68ab3c62887ec9a6a26
    • Instruction Fuzzy Hash: 1221D572E02225EBDB218B349C95B1A776A9F517B0F1C0213E905E7390D630ED08F5D2
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 93 fd23e3-fd23ed 94 fd245e-fd2461 93->94 95 fd23ef-fd23fc 94->95 96 fd2463 94->96 98 fd23fe-fd2401 95->98 99 fd2405-fd2421 LoadLibraryExW 95->99 97 fd2465-fd2469 96->97 100 fd2479-fd247b 98->100 101 fd2403 98->101 102 fd246a-fd2470 99->102 103 fd2423-fd242c GetLastError 99->103 100->97 105 fd245b 101->105 102->100 104 fd2472-fd2473 FreeLibrary 102->104 106 fd242e-fd2443 call fd3e78 103->106 107 fd2456-fd2459 103->107 104->100 105->94 106->107 110 fd2445-fd2454 LoadLibraryExW 106->110 107->105 110->102 110->107
    APIs
    • FreeLibrary.KERNEL32(00000000,?,?,?,00FD24A4,?,?,00FE2C14,00000000,?,00FD25CF,00000004,InitializeCriticalSectionEx,00FDCC04,InitializeCriticalSectionEx,00000000), ref: 00FD2473
    Strings
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: FreeLibrary
    • String ID: api-ms-
    • API String ID: 3664257935-2084034818
    • Opcode ID: f3ec9fa5494d494a8c7eb208511e454c87a133bb1518a4f364d05cd6d3cd6ce1
    • Instruction ID: 12987a9def85cc19c51a685ad650ad190a5e6b661e330174b80018f06ec3a48a
    • Opcode Fuzzy Hash: f3ec9fa5494d494a8c7eb208511e454c87a133bb1518a4f364d05cd6d3cd6ce1
    • Instruction Fuzzy Hash: 0511C132E02625EBDB62CB28EC45B593396AB22771F190312ED54E7381D660ED00A6D1
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 111 fd3511-fd352e GetModuleHandleExW 112 fd3530-fd3543 GetProcAddress 111->112 113 fd3553-fd3557 111->113 116 fd3545-fd3550 112->116 117 fd3552 112->117 114 fd3559-fd355c FreeLibrary 113->114 115 fd3562-fd3563 113->115 114->115 116->117 117->113
    APIs
    • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,00FD3506,?,?,00FD34CE,?,?,?), ref: 00FD3526
    • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00FD3539
    • FreeLibrary.KERNEL32(00000000,?,?,00FD3506,?,?,00FD34CE,?,?,?), ref: 00FD355C
    Strings
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: AddressFreeHandleLibraryModuleProc
    • String ID: CorExitProcess$mscoree.dll
    • API String ID: 4061214504-1276376045
    • Opcode ID: 822e373f60996e4bfcd4553446ae599535c155ff5bc64071251543e45972a474
    • Instruction ID: 1b1cbe8fb2415023abd4d753874de7e1611411f33980f1b9f222ed10098f14ba
    • Opcode Fuzzy Hash: 822e373f60996e4bfcd4553446ae599535c155ff5bc64071251543e45972a474
    • Instruction Fuzzy Hash: 83F0823190111AFBCB119B65ED0DB9D7B76EB00755F084062E605E22A0CB708F00FBD1
    Uniqueness

    Uniqueness Score: -1.00%

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 119 fd86ec-fd8764 GetConsoleOutputCP call fd3d74 122 fd8a6f 119->122 123 fd876a-fd878f 119->123 124 fd8a72 122->124 125 fd88c8-fd88cf 123->125 126 fd8795-fd879f 123->126 127 fd8a7e-fd8a97 call fd10f5 124->127 128 fd8a74-fd8a77 124->128 130 fd88ef-fd8901 call fd6376 125->130 131 fd88d1-fd88ed 125->131 129 fd87a2-fd87a5 126->129 128->127 133 fd87ad-fd87b7 129->133 134 fd87a7-fd87ab 129->134 147 fd892f-fd8931 130->147 148 fd8903-fd890c 130->148 135 fd8932-fd8941 call fd7aeb 131->135 139 fd87bd-fd87d8 133->139 140 fd886e-fd887e 133->140 134->129 134->133 135->122 154 fd8947-fd896b call fd5a15 135->154 145 fd89ee-fd89f0 139->145 146 fd87de-fd87e3 139->146 142 fd8884-fd88ba call fd943e 140->142 143 fd8a22-fd8a24 140->143 142->122 166 fd88c0 142->166 151 fd8a17 143->151 156 fd8a26 143->156 145->151 152 fd89f2 145->152 155 fd87e6-fd87f0 146->155 147->135 149 fd8a43-fd8a64 148->149 150 fd8912-fd8924 call fd7aeb 148->150 160 fd8a19-fd8a20 149->160 150->122 171 fd892a-fd892d 150->171 151->160 158 fd89f4-fd8a12 152->158 154->122 173 fd8971-fd8986 WriteFile 154->173 155->155 162 fd87f2-fd87fa 155->162 163 fd8a29-fd8a3f 156->163 158->158 165 fd8a14 158->165 160->124 168 fd87fc-fd880f call fd2600 162->168 169 fd8812-fd8815 162->169 163->163 170 fd8a41 163->170 165->151 172 fd88c3-fd88c6 166->172 168->169 175 fd8817-fd8827 169->175 170->165 171->154 172->154 177 fd898c-fd899d 173->177 178 fd8a66-fd8a6c GetLastError 173->178 175->175 176 fd8829-fd8866 call fd943e 175->176 176->122 186 fd886c 176->186 177->122 181 fd89a3-fd89a7 177->181 178->122 183 fd89dd-fd89e0 181->183 184 fd89a9-fd89c6 WriteFile 181->184 183->122 185 fd89e6-fd89e9 183->185 184->178 187 fd89cc-fd89d0 184->187 185->123 186->172 187->122 188 fd89d6-fd89da 187->188 188->183
    APIs
    • GetConsoleOutputCP.KERNEL32(?,00000001,?), ref: 00FD8734
    • WriteFile.KERNEL32(?,00FD729A,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00FD897E
    • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00FD89BE
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 00FD8A66
    Memory Dump Source
    • Source File: 00000001.00000002.52942187125.0000000000FD1000.00000020.00000001.01000000.00000004.sdmp, Offset: 00FD0000, based on PE: true
    • Associated: 00000001.00000002.52942158869.0000000000FD0000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942223273.0000000000FDC000.00000002.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942254388.0000000000FE2000.00000004.00000001.01000000.00000004.sdmpDownload File
    • Associated: 00000001.00000002.52942278476.0000000000FE4000.00000002.00000001.01000000.00000004.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_1_2_fd0000_MSI629D.jbxd
    Similarity
    • API ID: FileWrite$ConsoleErrorLastOutput
    • String ID:
    • API String ID: 2718003287-0
    • Opcode ID: 0c0d85d71eef60c5491e0edd63cd70a3eef64864e5bf90084bd142b395f73ef0
    • Instruction ID: e93bce66397f85f645ef7ced52a87e3763e703cddbd793a282bf5742e06a7960
    • Opcode Fuzzy Hash: 0c0d85d71eef60c5491e0edd63cd70a3eef64864e5bf90084bd142b395f73ef0
    • Instruction Fuzzy Hash: B9C17E75D002989FCB15CFA8C8809EDBBB6EF08314F28416BE855FB345E6359E42DB60
    Uniqueness

    Uniqueness Score: -1.00%