Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe

Overview

General Information

Sample URL:https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
Analysis ID:1432100
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Drops large PE files
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Writes many files with high entropy
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to communicate with device drivers
Contains functionality to create guard pages, often used to hinder reverse engineering and debugging
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates COM task schedule object (often to register a task for autostart)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Installs a raw input device (often for capturing keystrokes)
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Usage Of Web Request Commands And Cmdlets
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • cmd.exe (PID: 2800 cmdline: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
    • conhost.exe (PID: 6508 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • wget.exe (PID: 4112 cmdline: wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" MD5: 3DADB6E2ECE9C4B3E1E322E617658B60)
  • Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe (PID: 1436 cmdline: "C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" MD5: DFD4A19DE50A68477EDAC8DBB25FAF9A)
    • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 5952 cmdline: "C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe" /silent /install MD5: 8D32A91401F3C062EE93502BD79D28D8)
      • MicrosoftEdgeUpdate.exe (PID: 6108 cmdline: "C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=True" MD5: 0F11E6717C1FE6DD20AE2D12F63AF3F7)
        • MicrosoftEdgeUpdate.exe (PID: 4276 cmdline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvc MD5: 0F11E6717C1FE6DD20AE2D12F63AF3F7)
        • MicrosoftEdgeUpdate.exe (PID: 3856 cmdline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserver MD5: 0F11E6717C1FE6DD20AE2D12F63AF3F7)
        • MicrosoftEdgeUpdate.exe (PID: 6848 cmdline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNTMuNDciIHNoZWxsX3ZlcnNpb249IjEuMy4xNTMuNDciIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7MEFFNDg4MjEtNDIxRC00MEYwLTlCOTMtOUZEMjhFQzhBRTREfSIgdXNlcmlkPSJ7MEVBMkNGRkQtMUMyRS00NEUyLTgzMjAtNTI5NzQ5QkU3NDE1fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins0RjU1MDU0RC04NzAwLTREMjAtQUZDMS1DODVEQTU4MzFDRjd9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iOCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjIwMDYiIHNwPSIiIGFyY2g9Ing2NCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9Imp3dGFpaywgSW5jLiIgcHJvZHVjdF9uYW1lPSJqd3RhaWsyMCwxIi8-PGV4cCBldGFnPSImcXVvdDtxV0pTeld3UGZkY0xSK1hHSXY2eHJaZmlZT3hoUFUyczFOV21qV2NhRlBnPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGM0M0RkUwMC1FRkQ1LTQwM0ItOTU2OS0zOThBMjBGMUJBNEF9IiB2ZXJzaW9uPSIxLjMuMTc3LjExIiBuZXh0dmVyc2lvbj0iMS4zLjE1My40NyIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSIxOTY5Ii8-PC9hcHA-PC9yZXF1ZXN0Pg MD5: 0F11E6717C1FE6DD20AE2D12F63AF3F7)
        • MicrosoftEdgeUpdate.exe (PID: 1600 cmdline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=True" /installsource offline /sessionid "{0AE48821-421D-40F0-9B93-9FD28EC8AE4D}" /silent /offlinedir "{FAF4F54B-74F8-4FCD-81CD-4DFC19E93F21}" MD5: 0F11E6717C1FE6DD20AE2D12F63AF3F7)
  • MicrosoftEdgeUpdate.exe (PID: 5748 cmdline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc MD5: 0F11E6717C1FE6DD20AE2D12F63AF3F7)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1, CommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 5744, ProcessCommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1, ProcessId: 2800, ProcessName: cmd.exe
Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1, CommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 5744, ProcessCommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1, ProcessId: 2800, ProcessName: cmd.exe
Source: Process startedAuthor: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: Data: Command: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1, CommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 5744, ProcessCommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1, ProcessId: 2800, ProcessName: cmd.exe
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeWindow detected: < &BackI &AgreeCancel License AgreementPlease review the license terms before installing Bambu Studio 01.08.04.51.Press Page Down to see the rest of the agreement.GNU AFFERO GENERAL PUBLIC LICENSEVersion 3 19 November 2007Copyright 2007 Free Software Foundation Inc. <https://fsf.org/>Everyone is permitted to copy and distribute verbatim copies of this license document but changing it is not allowed.PreambleThe GNU Affero General Public License is a free copyleft license for software and other kinds of works specifically designed to ensure cooperation with the community in the case of network server software.The licenses for most software and other practical works are designed to take away your freedom to share and change the works. By contrast our General Public Licenses are intended to guarantee your freedom to share and change all versions of a program--to make sure it remains free software for all its users.When we speak of free software we are referring to freedom not price. Our General Public Licenses are designed to make sure that you have the freedom to distribute copies of free software (and charge for them if you wish) that you receive source code or can get it if you want it that you can change the software or use pieces of it in new free programs and that you know you can do these things.Developers that use our General Public Licenses protect your rights with two steps: (1) assert copyright on the software and (2) offer you this License which gives you legal permission to copy distribute and/or modify the software.A secondary benefit of defending all users' freedom is that improvements made in alternate versions of the program if they receive widespread use become available for other developers to incorporate. Many developers of free software are heartened and encouraged by the resulting cooperation. However in the case of software used on network servers this result may fail to come about. The GNU General Public License permits making a modified version and letting the public access it on a server without ever releasing its source code to the public.The GNU Affero General Public License is designed specifically to ensure that in such cases the modified source code becomes available to the community. It requires the operator of a network server to provide the source code of the modified version running there to the users of that server. Therefore public use of a modified version on a publicly accessible server gives the public access to the source code of the modified version.An older license called the Affero General Public License and published by Affero was designed to accomplish similar goals. This is a different license not a version of the Affero GPL but Affero has released a new version of the Affero GPL which permits relicensing under this license.The precise terms and conditions for copying distribution and modification follow.TERMS AND CONDITIONS0. Definitions."This License" refers to version 3 of the GNU Affero Genera
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu StudioJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\BambuStudio.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\LICENSE.txtJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\README.mdJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKBO.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKBRep.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKCAF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKCDF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKG2d.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKG3d.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKGeomAlgo.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKGeomBase.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKHLR.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKLCAF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKMath.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKMesh.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKPrim.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKSTEP.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKSTEP209.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKSTEPAttr.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKSTEPBase.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKService.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKShHealing.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKTopAlgo.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKV3d.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKVCAF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKXCAF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKXDESTEP.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKXSBase.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKernel.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\WebView2Loader.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\bambu-studio.exeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\freetype.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\libgmp-10.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\libmpfr-4.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\includeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\include\mcutJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\include\mcut\mcut.hJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\include\mcut\platform.hJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\mesaJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\mesa\opengl32.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\pluginJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\plugin\CA.crtJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\plugin\vcredist2019_x64.exeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resourcesJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\Icon.icnsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\check_access_code.txtJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calibJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\filament_flowJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\filament_flow\flowrate-test-pass1.3mfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\filament_flow\flowrate-test-pass2.3mfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advanceJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advance\pa_pattern.3mfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advance\pressure_advance_test.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advance\tower.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advance\tower_with_seam.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\retractionJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\retraction\retraction_tower.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\temperature_towerJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\temperature_tower\temperature_tower.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\vfaJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\vfa\VFA.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\volumetric_speedJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\volumetric_speed\SpeedTestStructure.stepJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\certJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\cert\printer.cerJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\cert\slicer_base64.cerJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\dailytipJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\dailytip\index.htmlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\dataJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\data\hints.iniJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fontsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Black.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Bold.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Light.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Medium.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Regular.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Thin.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\NotoSansKR-Bold.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\NotoSansKR-Regular.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18nJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\csJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\cs\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\deJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\de\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\enJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\en\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\esJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\es\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\frJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\fr\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\huJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\hu\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\itJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\it\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\jaJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ja\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\koJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ko\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\nlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\nl\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ruJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ru\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\svJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\sv\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ukJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\uk\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\zh_cnJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\zh_cn\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\imagesJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio-mac_128px.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio-mac_256px.icoJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio.icnsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio.icoJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudioTitle.icoJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_128px.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_192px.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_192px_grayscale.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_192px_transparent.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_32px.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_about.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\add_filament.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\advanced.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_arrow.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_editable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_editable_light.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_extra_framework_mid.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_fila_sync.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_0.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_3.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_4.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_tips.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_item_examples.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_mapping_container.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_mapping_examples.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_readonly.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_readonly_light.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_refresh_normal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_refresh_selected.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_0.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_3.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_4.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_5.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_6.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_7.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_setting_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_setting_normal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_setting_press.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\assemble_return.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\automatic_material_renewal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_add_file.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_cover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_delete.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_delete_file.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_edit_mask.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_tab_picture.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\back_up_ts_bk.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\backup_current_use1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\backup_current_use2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\backup_tips_img.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bar_publish.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl-3dp-logo.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_ep_bottom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_ep_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pc_bottom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pc_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pei_bottom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pei_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pte_bottom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pte_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_cali_lines.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bind_machine.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\blank.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\blank2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\blank_14.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\blank_16.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\block_notification_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\block_notification_close_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\block_notification_error.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bullet_black.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bullet_blue.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bullet_white.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_fdc_editing_diagram.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_fdc_editing_diagram_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_after_pa.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_after_pa_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_before_pa.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_before_pa_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_caption_help.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_caption_help_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_caption_prev.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_caption_prev_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_flow_introduction.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_flow_introduction_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\calib_sf.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\calib_sf_inactive.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\camera_setting.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\camera_setting_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_half.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_half_disabled.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_half_focused.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_off_disabled.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_off_focused.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_on_disabled.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_on_focused.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\checked.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\circle_paint.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\circle_paint_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cog.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\collapse_btn.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\color_picker_border.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\color_picker_border_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\compare.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\completed.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\confirm.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\confirm_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\create_success.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cross.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cross_focus.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cross_focus_large.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cut_.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cut_connectors.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_AutoArrange.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_Brim.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_CutTool.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_LayOnFace.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_ObjectList.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_SimplifyModel.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_SlicingParamTable.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_SplitIntoPlates.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_StackObject.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_SubtractPart.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_TypesOfSupports.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_ZSeamLocation.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_placeholder.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\debugtool.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\default_thumbnail.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\degree.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\delete.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\delete_filament.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\disable_ams_demo_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dot.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\drop_down.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\edit.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\edit_button.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\empty.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\enable_ams.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\enable_ams_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\equal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\expand_btn.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_left_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_left_selected.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_right.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_right_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_right_selected.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_icon_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extrusion_calibrati_open_button.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extrusion_calibration_tips_en.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extrusion_calibration_tips_zh.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\face recognition.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_control_add.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_control_decrease.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_dash_bk.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_0.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_10.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_3.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_4.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_5.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_6.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_7.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_8.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_9.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_auto.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_manual.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_manual_result.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_manual_result_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_pattern_manual.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_pattern_manual_result.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_pattern_manual_result_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\filament.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fill_paint.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fill_paint_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flag_green.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flag_red.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_auto.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_coarse.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_coarse_result.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_coarse_result_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_fine.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_fine_result.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_fine_result_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flush_volumes.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\gap_fill.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\gap_fill_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\gcode.icnsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\go_last_plate.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\go_next_plate.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\height_range.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\height_range_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\hms_arrow.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\hms_notify_lv1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\hms_notify_lv2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\hms_notify_lv3.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_all_plates_stats.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_all_plates_stats_transparent.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_fold.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_gcode_custom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_gcode_pause.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_slider_delete.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_text_search.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_text_search_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_unfold.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\import_file.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\info.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_n1_cn.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_n1_en.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_p1p_cn.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_p1p_en.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_x1_cn.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_x1_en.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ip_address_step.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\link_more_error_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\link_more_error_open.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\link_wiki_img.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\live_stream_default.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\lock_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\lock_normal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\lock_normal_sys.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\machine_obejct_type.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\machine_object_owner.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\machine_object_printing.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mall_control_back.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mall_control_forward.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mall_control_refresh.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\max_volumetric_speed_calibration.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_empty.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_failed.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_loading.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_play.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_stop.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_add_modifier.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_add_negative.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_add_part.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_copy.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_cut.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_delete.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_edit_preset.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_exit.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_export_config.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_export_gcode.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_export_sliced_file.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_export_stl.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_fuzzy_skin.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_import.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_open.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_paste.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_redo.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_remove.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_save.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_support_blocker.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_support_enforcer.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_undo.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mmu_segmentation.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mmu_segmentation_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\model_time.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\model_weight.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitir_err_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitir_err_open.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_add_machine.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_ams_extruder.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_arrow.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_axis_home.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_axis_home_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_down.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_down_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_temp.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_temp_active.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_up.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_up_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_brokenimg.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_camera.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extrduer_down.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extrduer_down_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_down.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_empty_load.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_empty_unload.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_filled_load.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_filled_unload.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_up.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_up.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_up_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_fan.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_fan_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_fan_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_frame_temp.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_frame_temp_active.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_item_cost.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_item_prediction.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_item_print.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_lamp_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_lamp_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_network_wired.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_none_add.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_none_arrow.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_none_printer.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_nozzle_temp.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_nozzle_temp_active.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_placeholder.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_play.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_printer.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_recording_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_recording_off_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_recording_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_recording_on_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_sdcard_thumbnail.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_signal_middle.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_signal_no.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_signal_strong.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_signal_weak.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_speed.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_speed_active.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_status_empty.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_tasklist_print.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_tasklist_time.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_tasklist_weight.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_timelapse_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_timelapse_off_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_timelapse_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_timelapse_on_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_ams.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_busy.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_ext.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_offline.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_online.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_retry.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_vcamera_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_vcamera_off_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_vcamera_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_vcamera_on_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\new_folder.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\node_dot.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\not_equal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_arrow_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_arrow_open.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_arrow_right.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_cancel.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_cancel_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_close_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_close_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_close_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_collapse.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_documentation.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_documentation_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_documentation_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_documentation_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_eject_sd.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_eject_sd_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_expand.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_minimalize.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_minimalize_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_minimalize_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_minimalize_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_preferences.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_preferences_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_preferences_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_preferences_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_right.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_right_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_right_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_right_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_slicing_complete.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\obj_printable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\obj_unprintable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\obj_warning.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\objlist_sinking.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_off_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_off_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_off_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_on_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_on_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_on_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\LICENSE.txtJump to behavior
Source: Binary string: psmachine_unsigned.pdb source: MicrosoftEdgeUpdate.exe
Source: Binary string: msedgeupdateres_unsigned_en.pdb source: MicrosoftEdgeUpdate.exe, 00000009.00000002.3520137794.0000000002A60000.00000002.00000001.00040000.0000000E.sdmp, MicrosoftEdgeUpdate.exe, 00000011.00000002.3519852042.0000000001580000.00000002.00000001.00040000.0000000E.sdmp
Source: Binary string: mi_exe_stub.pdb source: MicrosoftEdgeWebView2RuntimeInstallerX64.exe, 00000008.00000000.3246206348.000000000007B000.00000002.00000001.01000000.00000009.sdmp
Source: Binary string: MicrosoftEdgeUpdate_unsigned.pdb source: MicrosoftEdgeUpdate.exe
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServerJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ElevationJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053C380 FindClose,FindFirstFileExW,GetLastError,FindFirstFileExW,GetLastError,9_2_0053C380
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053C3A0 FindFirstFileExW,GetLastError,FindFirstFileExW,GetLastError,9_2_0053C3A0
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053C400 GetFileAttributesExW,GetLastError,___std_fs_open_handle@16,GetLastError,GetFileInformationByHandle,FindFirstFileExW,FindClose,9_2_0053C400
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_00541D12 FindFirstFileExW,9_2_00541D12
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CC40EC8 FindFirstFileW,GetLastError,PathStripPathW,PathStripPathW,PathStripPathW,FindNextFileW,GetLastError,FindClose,9_2_6CC40EC8
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB73B3A FindFirstFileW,FindNextFileW,FindClose,9_2_6CB73B3A
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CBAEF10 FindFirstFileW,FindClose,FindNextFileW,9_2_6CBAEF10
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6EA55 FindFirstFileW,FindNextFileW,FindClose,9_2_6CB6EA55
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6C109 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindNextFileW,FindClose,RemoveDirectoryW,9_2_6CB6C109
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6BE82 FindFirstFileW,FindNextFileW,GetLastError,FindClose,9_2_6CB6BE82
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6BFB9 FindFirstFileW,GetLastError,DeleteFileW,FindNextFileW,GetLastError,FindClose,9_2_6CB6BFB9
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB9FFC8 FindFirstFileW,FindNextFileW,FindClose,9_2_6CB9FFC8
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084C380 FindClose,FindFirstFileExW,GetLastError,FindFirstFileExW,GetLastError,10_2_0084C380
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084C3A0 FindFirstFileExW,GetLastError,FindFirstFileExW,GetLastError,10_2_0084C3A0
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084C400 GetFileAttributesExW,GetLastError,___std_fs_open_handle@16,GetLastError,GetFileInformationByHandle,FindFirstFileExW,FindClose,10_2_0084C400
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_00851D12 FindFirstFileExW,10_2_00851D12
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D700DA4 FindFirstFileExW,12_2_00007FF76D700DA4
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C149616 FindFirstFileExW,16_2_6C149616
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CBAEF10 FindFirstFileW,FindClose,FindNextFileW,16_2_6CBAEF10
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB6EA55 FindFirstFileW,FindNextFileW,FindClose,16_2_6CB6EA55
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB6C109 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindNextFileW,FindClose,RemoveDirectoryW,16_2_6CB6C109
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB6BE82 FindFirstFileW,FindNextFileW,GetLastError,FindClose,16_2_6CB6BE82
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB6BFB9 FindFirstFileW,GetLastError,DeleteFileW,FindNextFileW,GetLastError,FindClose,16_2_6CB6BFB9
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB9FFC8 FindFirstFileW,FindNextFileW,FindClose,16_2_6CB9FFC8
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB73B3A FindFirstFileW,FindNextFileW,FindClose,16_2_6CB73B3A
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB7918E GetLogicalDriveStringsW,QueryDosDeviceW,9_2_6CB7918E
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiper\angularJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\includeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiper\angular\angular\srcJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiper\angular\angular\src\utilsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiperJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiper\angular\angularJump to behavior
Source: wget.exe, 00000002.00000003.2201031283.0000000000E00000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.2201031283.0000000000DF8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0
Source: wget.exe, 00000002.00000003.2201031283.0000000000E00000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.2201031283.0000000000DF8000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2243310913.0000000000E04000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2
Source: wget.exe, 00000002.00000003.2201031283.0000000000E00000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.2201031283.0000000000DF8000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2243310913.0000000000E04000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/root-r3.crl0G
Source: wget.exe, 00000002.00000003.2201031283.0000000000E00000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.2201031283.0000000000DF8000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2243310913.0000000000E04000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/root-r6.crl0G
Source: wget.exe, 00000002.00000003.2201031283.0000000000E00000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.2201031283.0000000000DF8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C
Source: wget.exe, 00000002.00000003.2201031283.0000000000E00000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.2201031283.0000000000DF8000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2243310913.0000000000E04000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp2.globalsign.com/rootr306
Source: wget.exe, 00000002.00000003.2201031283.0000000000E00000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.2201031283.0000000000DF8000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2243310913.0000000000E04000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp2.globalsign.com/rootr606
Source: wget.exe, 00000002.00000003.2201031283.0000000000E00000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.2201031283.0000000000DF8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
Source: Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe, 00000006.00000003.2525610645.0000000002843000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.gnu.org/licenses/
Source: MicrosoftEdgeUpdate.exe, 0000000F.00000003.3495239874.0000000000CD1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.153.47?clientId=s:92C86F7C-DB2B-4F6A-95AD-98B
Source: MicrosoftEdgeUpdate.exe, 0000000F.00000003.3495239874.0000000000CD1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ecs.nel.measure.office.net?TenantId=EdgeUpdate&DestinationEndpoint=Edge-Prod-MIAr4e&FrontEnd
Source: Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe, 00000006.00000003.2525610645.0000000002843000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/artem-ogre/CDT
Source: wget.exe, 00000002.00000002.2243167641.0000000000AC8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_S03
Source: wget.exe, 00000002.00000002.2243167641.0000000000AC0000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2243345875.0000000000F15000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.0
Source: Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe, 00000006.00000003.2784168733.0000000002846000.00000004.00000020.00020000.00000000.sdmp, Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe, 00000006.00000003.2781217128.0000000002841000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://localazy.com)
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: https://msedgesetup.azureedge.net/products
Source: wget.exe, 00000002.00000002.2243310913.0000000000E04000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://objects.githubusercontent.com/github-production-release-asset-2e65be/511797274/42e664ca-d493
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: https://to-be-replaced.invalid/cr/report
Source: wget.exe, 00000002.00000003.2201031283.0000000000E00000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000003.2201031283.0000000000DF8000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2243310913.0000000000E04000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.globalsign.com/repository/0
Source: Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe, 00000006.00000003.2524760787.0000000002AE4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: GetRawInputDatamemstr_651d3575-3

Spam, unwanted Advertisements and Ransom Demands

barindex
Source: C:\Windows\SysWOW64\wget.exeFile created: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe entropy: 7.99993926412Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\dailytips_ObjectList.PNG entropy: 7.99309950164Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\dailytips_SplitIntoPlates.png entropy: 7.99162262893Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\dailytips_TypesOfSupports.png entropy: 7.99560160217Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\dailytips_ZSeamLocation.png entropy: 7.99366436556Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_auto.png entropy: 7.99071463633Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_manual.png entropy: 7.99005784321Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_manual_result_CN.png entropy: 7.99159115439Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_coarse.png entropy: 7.9946647943Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_coarse_result.png entropy: 7.99232150623Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_coarse_result_CN.png entropy: 7.99255804381Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_fine.png entropy: 7.9954572636Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\web\homepage\img\3d_text.png entropy: 7.99578974644Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\web\homepage\img\high_speed_print_at_quality.png entropy: 7.99361736191Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\web\homepage\img\remote_control_and_monitoring.png entropy: 7.99142271813Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\web\homepage\img\multi_color_printing.png entropy: 7.99511190078Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\web\homepage\img\setting_guide_of_slicing_parameters.png entropy: 7.99122167661Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\web\homepage\img\wiki2.png entropy: 7.99409113482Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\resources\web\homepage\img\wiki.png entropy: 7.99597146016Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdge_X64_95.0.1020.40.exe.{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10} entropy: 7.99999610696Jump to dropped file

System Summary

barindex
Source: C:\Windows\SysWOW64\wget.exeFile dump: Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe.2.dr 227156280Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCA4FC5 NtdllDefWindowProc_W,16_2_6CCA4FC5
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCA434F NtdllDefWindowProc_W,16_2_6CCA434F
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCA3DF1 NtdllDefWindowProc_W,16_2_6CCA3DF1
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CBDDFE1 NtdllDefWindowProc_W,16_2_6CBDDFE1
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CC05870 GetCurrentThreadId,OpenEventW,WaitForSingleObject,PeekMessageW,CreateTimerQueue,NtdllDefWindowProc_W,CloseHandle,CloseHandle,16_2_6CC05870
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCA34E1 NtdllDefWindowProc_W,SetWindowLongW,16_2_6CCA34E1
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB81913: RegCloseKey,RegCloseKey,CreateFileW,DeviceIoControl,CloseHandle,RegCloseKey,RegCloseKey,9_2_6CB81913
Source: C:\Windows\SysWOW64\wget.exeCode function: 2_3_00DCE9342_3_00DCE934
Source: C:\Windows\SysWOW64\wget.exeCode function: 2_2_00DCE9342_2_00DCE934
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_00547A1D9_2_00547A1D
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CBCEFD89_2_6CBCEFD8
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCE6A1D9_2_6CCE6A1D
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCE6B3D9_2_6CCE6B3D
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CC0E0859_2_6CC0E085
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CBCE0D69_2_6CBCE0D6
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CBC82639_2_6CBC8263
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCA63C79_2_6CCA63C7
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCCBCCA9_2_6CCCBCCA
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCC7E109_2_6CCC7E10
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CBCF6779_2_6CBCF677
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_00857A1D10_2_00857A1D
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D6FBE4C12_2_00007FF76D6FBE4C
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D70021012_2_00007FF76D700210
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D70460C12_2_00007FF76D70460C
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D700DA412_2_00007FF76D700DA4
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D6FC50A12_2_00007FF76D6FC50A
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D700B9812_2_00007FF76D700B98
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C152D7916_2_6C152D79
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C150E4016_2_6C150E40
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C14EF9C16_2_6C14EF9C
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C1529D016_2_6C1529D0
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C14B9C816_2_6C14B9C8
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C14B53016_2_6C14B530
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C14574516_2_6C145745
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C14F0BC16_2_6C14F0BC
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CBCEFD816_2_6CBCEFD8
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCE6A1D16_2_6CCE6A1D
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCE6B3D16_2_6CCE6B3D
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CBCE0D616_2_6CBCE0D6
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CBC826316_2_6CBC8263
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCA63C716_2_6CCA63C7
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCCBCCA16_2_6CCCBCCA
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CBCF67716_2_6CBCF677
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CCC5A60 appears 69 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CB7FF2F appears 301 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CB66E68 appears 174 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CCC9869 appears 60 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CB66B74 appears 273 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CB74092 appears 66 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CBC69AC appears 35 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CCB16CF appears 41 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6C13F880 appears 42 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CB76F8E appears 31 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CCB1C80 appears 40 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CB66F63 appears 41 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CCB1344 appears 175 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CB8A80C appears 77 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 0084BD00 appears 33 times
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: String function: 6CB740BC appears 77 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CCC5A60 appears 107 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CB7FF2F appears 302 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CB66E68 appears 193 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CCC9869 appears 77 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CB66B74 appears 341 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CCCD1F2 appears 37 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CB74092 appears 67 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CBC69AC appears 61 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CBC6C3A appears 36 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CCB16CF appears 51 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CB76F8E appears 31 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CB8A80C appears 77 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CB7A585 appears 47 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CCB1C80 appears 40 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 0053BD00 appears 33 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CB66F63 appears 49 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CCB1344 appears 175 times
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: String function: 6CB740BC appears 77 times
Source: msedgeupdateres_cs.dll.8.drStatic PE information: Resource name: RT_STRING type: iAPX 286 executable large model (COFF) not stripped
Source: msedgeupdateres_bn.dll.8.drStatic PE information: Resource name: RT_STRING type: CLIPPER COFF executable C1 R1 not stripped - version 33 alignment trap enabled
Source: msedgeupdateres_ar.dll.8.drStatic PE information: Resource name: RT_STRING type: PDP-11 demand-paged pure executable not stripped
Source: msedgeupdateres_fil.dll.8.drStatic PE information: Resource name: RT_STRING type: VAX COFF pure executable, sections 80, created Wed Mar 25 10:30:57 1970, not stripped, version 110
Source: msedgeupdateres_lt.dll.8.drStatic PE information: Resource name: RT_STRING type: x86 executable (TV) not stripped
Source: msedgeupdateres_pt-BR.dll.8.drStatic PE information: Resource name: RT_STRING type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 0.111
Source: msedgeupdateres_ml.dll.8.drStatic PE information: Resource name: RT_STRING type: CLIPPER COFF executable C2 R1 not stripped - version 37 alignment trap enabled
Source: msedgeupdateres_pt-PT.dll.8.drStatic PE information: Resource name: RT_STRING type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 0.111
Source: msedgeupdateres_sv.dll.8.drStatic PE information: Resource name: RT_STRING type: 370 sysV executable not stripped
Source: msedgeupdateres_vi.dll.8.drStatic PE information: Resource name: RT_STRING type: MIPSEB-LE MIPS-III ECOFF executable not stripped - version 0.104
Source: msedgeupdateres_tr.dll.8.drStatic PE information: Resource name: RT_STRING type: x86 executable (TV) not stripped
Source: msedgeupdateres_bn-IN.dll.8.drStatic PE information: Resource name: RT_STRING type: CLIPPER COFF executable C1 R1 not stripped - version 33 alignment trap enabled
Source: msedgeupdateres_af.dll.8.drStatic PE information: Resource name: RT_STRING type: 370 XA sysV pure executable not stripped
Source: msedgeupdateres_af.dll.8.drStatic PE information: Resource name: RT_STRING type: 370 XA sysV pure executable not stripped
Source: msedgeupdateres_kk.dll.8.drStatic PE information: Resource name: RT_STRING type: MIPSEL MIPS-II ECOFF executable not stripped - version 4.48
Source: msedgeupdateres_gl.dll.8.drStatic PE information: Resource name: RT_STRING type: 370 XA sysV executable not stripped
Source: msedgeupdateres_gd.dll.8.drStatic PE information: Resource name: RT_STRING type: CLIPPER COFF executable C1 R1 not stripped - version 111 alignment trap enabled
Source: msedgeupdateres_mt.dll.8.drStatic PE information: Resource name: RT_STRING type: VAX COFF executable, sections 73, created Thu Mar 26 04:47:56 1970, not stripped, version 111
Source: msedgeupdateres_km.dll.8.drStatic PE information: Resource name: RT_STRING type: PDP-11 overlaid separate executable not stripped
Source: msedgeupdateres_km.dll.8.drStatic PE information: Resource name: RT_STRING type: PDP-11 overlaid separate executable not stripped
Source: msedgeupdateres_quz.dll.8.drStatic PE information: Resource name: RT_STRING type: iAPX 286 executable large model (COFF) not stripped
Source: MicrosoftEdge_X64_95.0.1020.40.exe.{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}.8.drStatic PE information: Resource name: B7 type: 7-zip archive data, version 0.4
Source: MicrosoftEdge_X64_95.0.1020.40.exe.{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}.8.drStatic PE information: Resource name: BL type: Microsoft Cabinet archive data, Windows 2000/XP setup, 1273296 bytes, 1 file, at 0x2c +A "setup.exe", number 1, 87 datablocks, 0x1 compression
Source: classification engineClassification label: mal56.rans.evad.win@24/1236@0/3
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB72063 GetLastError,GetLastError,SetLastError,SetLastError,FormatMessageW,GetLastError,SetLastError,LocalFree,9_2_6CB72063
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB75FC1 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,FindCloseChangeNotification,9_2_6CB75FC1
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB74D83 CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,9_2_6CB74D83
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB88F3A LoadLibraryExW,LoadLibraryExW,LoadLibraryExW,FindResourceW,LoadResource,SizeofResource,MultiByteToWideChar,FreeLibrary,9_2_6CB88F3A
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu StudioJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\Desktop\cmdline.outJump to behavior
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeMutant created: NULL
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMutant created: \Sessions\1\BaseNamedObjects\Global\EdgeUpdate{DDDDEAEB-04CC-4BAA-9C63-CCA5FE38F688}
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMutant created: \BaseNamedObjects\Global\EdgeUpdate{9FE41F29-8211-488D-B96A-81FCD0A8ACE3}
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeMutant created: \Sessions\1\BaseNamedObjects\Global\EdgeUpdate{F340B839-380B-4AA9-BA6F-B83F23E2DD05}
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMutant created: \BaseNamedObjects\Global\EdgeUpdate{76524F9B-42D7-48C8-B7DF-FAB9E93834BF}
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMutant created: \BaseNamedObjects\Global\EdgeUpdate{DDDDEAEB-04CC-4BAA-9C63-CCA5FE38F688}
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6508:120:WilError_03
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMutant created: \Sessions\1\BaseNamedObjects\Global\EdgeUpdate{921D73A1-67B6-4E73-81EA-8A162D92D990}
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMutant created: \BaseNamedObjects\_Microsoft_EdgeUpdate_logging_mutex_C:ProgramDataMicrosoftEdgeUpdateLogMicrosoftEdgeUpdate.log
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMutant created: \BaseNamedObjects\Global\EdgeUpdate{8A5FF6DC-FF03-4CB3-8834-D3AD1DE301DF}
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeMutant created: \Sessions\1\BaseNamedObjects\_Microsoft_EdgeUpdate_logging_mutex_C:ProgramDataMicrosoftEdgeUpdateLogMicrosoftEdgeUpdate.log
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Users\user\AppData\Local\Temp\nsx6395.tmpJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCommand line argument: kernel32.dll9_2_0053AA5B
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCommand line argument: DllEntry9_2_0053AA5B
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCommand line argument: kernel32.dll10_2_0084AA5B
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCommand line argument: DllEntry10_2_0084AA5B
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\wget.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: Application update/install
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: --do-not-launch-msedge
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: /installerdata=
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: on-finish-install
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: [CheckForUpdate][Over-install version was %s. Forcing it to be empty.]
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: Application update/install
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: /installerdata=
Source: MicrosoftEdgeUpdate.exeString found in binary or memory: on-finish-install
Source: unknownProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe"
Source: unknownProcess created: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe "C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe"
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeProcess created: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe "C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe" /silent /install
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeProcess created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=True"
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvc
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserver
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe"
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe"
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe"
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNTMuNDciIHNoZWxsX3ZlcnNpb249IjEuMy4xNTMuNDciIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7MEFFNDg4MjEtNDIxRC00MEYwLTlCOTMtOUZEMjhFQzhBRTREfSIgdXNlcmlkPSJ7MEVBMkNGRkQtMUMyRS00NEUyLTgzMjAtNTI5NzQ5QkU3NDE1fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins0RjU1MDU0RC04NzAwLTREMjAtQUZDMS1DODVEQTU4MzFDRjd9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iOCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjIwMDYiIHNwPSIiIGFyY2g9Ing2NCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9Imp3dGFpaywgSW5jLiIgcHJvZHVjdF9uYW1lPSJqd3RhaWsyMCwxIi8-PGV4cCBldGFnPSImcXVvdDtxV0pTeld3UGZkY0xSK1hHSXY2eHJaZmlZT3hoUFUyczFOV21qV2NhRlBnPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGM0M0RkUwMC1FRkQ1LTQwM0ItOTU2OS0zOThBMjBGMUJBNEF9IiB2ZXJzaW9uPSIxLjMuMTc3LjExIiBuZXh0dmVyc2lvbj0iMS4zLjE1My40NyIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSIxOTY5Ii8-PC9hcHA-PC9yZXF1ZXN0Pg
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=True" /installsource offline /sessionid "{0AE48821-421D-40F0-9B93-9FD28EC8AE4D}" /silent /offlinedir "{FAF4F54B-74F8-4FCD-81CD-4DFC19E93F21}"
Source: unknownProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" Jump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeProcess created: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe "C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe" /silent /installJump to behavior
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeProcess created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=True"Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvcJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNTMuNDciIHNoZWxsX3ZlcnNpb249IjEuMy4xNTMuNDciIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7MEFFNDg4MjEtNDIxRC00MEYwLTlCOTMtOUZEMjhFQzhBRTREfSIgdXNlcmlkPSJ7MEVBMkNGRkQtMUMyRS00NEUyLTgzMjAtNTI5NzQ5QkU3NDE1fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins0RjU1MDU0RC04NzAwLTREMjAtQUZDMS1DODVEQTU4MzFDRjd9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iOCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjIwMDYiIHNwPSIiIGFyY2g9Ing2NCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9Imp3dGFpaywgSW5jLiIgcHJvZHVjdF9uYW1lPSJqd3RhaWsyMCwxIi8-PGV4cCBldGFnPSImcXVvdDtxV0pTeld3UGZkY0xSK1hHSXY2eHJaZmlZT3hoUFUyczFOV21qV2NhRlBnPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGM0M0RkUwMC1FRkQ1LTQwM0ItOTU2OS0zOThBMjBGMUJBNEF9IiB2ZXJzaW9uPSIxLjMuMTc3LjExIiBuZXh0dmVyc2lvbj0iMS4zLjE1My40NyIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSIxOTY5Ii8-PC9hcHA-PC9yZXF1ZXN0PgJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=True" /installsource offline /sessionid "{0AE48821-421D-40F0-9B93-9FD28EC8AE4D}" /silent /offlinedir "{FAF4F54B-74F8-4FCD-81CD-4DFC19E93F21}"Jump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe" Jump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe" Jump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: explorerframe.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: version.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: iri.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: dsreg.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: msxml6.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: taskschd.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: edputil.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: slc.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: sppc.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: version.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iri.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dsreg.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: version.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iri.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dsreg.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iri.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iri.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iri.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: dsreg.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: wkscli.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: dsreg.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: wkscli.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: dsreg.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: version.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wtsapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wkscli.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iri.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dsreg.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iphlpapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: diagnosticdataquery.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msxml6.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: windows.system.diagnostics.telemetry.platformtelemetryclient.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: winhttp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: webio.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mswsock.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: winnsi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: sspicli.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dnsapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: rasadhlp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: fwpuclnt.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: schannel.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mskeyprotect.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ntasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ncrypt.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ncryptsslp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dpapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: version.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wtsapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wkscli.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iri.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dsreg.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: uxtheme.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iri.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: atlthunk.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: version.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wtsapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: wkscli.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: mdmregistration.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: omadmapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: powrprof.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dmcmnutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: iri.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: umpdc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: dsreg.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: msxml6.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: winhttp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeSection loaded: winsta.dll
Source: C:\Windows\SysWOW64\wget.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32Jump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile written: C:\Users\user\AppData\Local\Temp\nsj6730.tmp\ioSpecial.iniJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeAutomated click: Next >
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeAutomated click: I Agree
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeAutomated click: Install
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeWindow detected: < &BackI &AgreeCancel License AgreementPlease review the license terms before installing Bambu Studio 01.08.04.51.Press Page Down to see the rest of the agreement.GNU AFFERO GENERAL PUBLIC LICENSEVersion 3 19 November 2007Copyright 2007 Free Software Foundation Inc. <https://fsf.org/>Everyone is permitted to copy and distribute verbatim copies of this license document but changing it is not allowed.PreambleThe GNU Affero General Public License is a free copyleft license for software and other kinds of works specifically designed to ensure cooperation with the community in the case of network server software.The licenses for most software and other practical works are designed to take away your freedom to share and change the works. By contrast our General Public Licenses are intended to guarantee your freedom to share and change all versions of a program--to make sure it remains free software for all its users.When we speak of free software we are referring to freedom not price. Our General Public Licenses are designed to make sure that you have the freedom to distribute copies of free software (and charge for them if you wish) that you receive source code or can get it if you want it that you can change the software or use pieces of it in new free programs and that you know you can do these things.Developers that use our General Public Licenses protect your rights with two steps: (1) assert copyright on the software and (2) offer you this License which gives you legal permission to copy distribute and/or modify the software.A secondary benefit of defending all users' freedom is that improvements made in alternate versions of the program if they receive widespread use become available for other developers to incorporate. Many developers of free software are heartened and encouraged by the resulting cooperation. However in the case of software used on network servers this result may fail to come about. The GNU General Public License permits making a modified version and letting the public access it on a server without ever releasing its source code to the public.The GNU Affero General Public License is designed specifically to ensure that in such cases the modified source code becomes available to the community. It requires the operator of a network server to provide the source code of the modified version running there to the users of that server. Therefore public use of a modified version on a publicly accessible server gives the public access to the source code of the modified version.An older license called the Affero General Public License and published by Affero was designed to accomplish similar goals. This is a different license not a version of the Affero GPL but Affero has released a new version of the Affero GPL which permits relicensing under this license.The precise terms and conditions for copying distribution and modification follow.TERMS AND CONDITIONS0. Definitions."This License" refers to version 3 of the GNU Affero Genera
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu StudioJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\BambuStudio.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\LICENSE.txtJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\README.mdJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKBO.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKBRep.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKCAF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKCDF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKG2d.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKG3d.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKGeomAlgo.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKGeomBase.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKHLR.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKLCAF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKMath.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKMesh.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKPrim.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKSTEP.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKSTEP209.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKSTEPAttr.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKSTEPBase.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKService.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKShHealing.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKTopAlgo.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKV3d.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKVCAF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKXCAF.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKXDESTEP.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKXSBase.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\TKernel.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\WebView2Loader.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\bambu-studio.exeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\freetype.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\libgmp-10.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\libmpfr-4.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\includeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\include\mcutJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\include\mcut\mcut.hJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\include\mcut\platform.hJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\mesaJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\mesa\opengl32.dllJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\pluginJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\plugin\CA.crtJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\plugin\vcredist2019_x64.exeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resourcesJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\Icon.icnsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\check_access_code.txtJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calibJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\filament_flowJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\filament_flow\flowrate-test-pass1.3mfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\filament_flow\flowrate-test-pass2.3mfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advanceJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advance\pa_pattern.3mfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advance\pressure_advance_test.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advance\tower.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\pressure_advance\tower_with_seam.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\retractionJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\retraction\retraction_tower.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\temperature_towerJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\temperature_tower\temperature_tower.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\vfaJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\vfa\VFA.stlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\volumetric_speedJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\calib\volumetric_speed\SpeedTestStructure.stepJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\certJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\cert\printer.cerJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\cert\slicer_base64.cerJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\dailytipJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\dailytip\index.htmlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\dataJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\data\hints.iniJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fontsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Black.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Bold.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Light.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Medium.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Regular.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\HarmonyOS_Sans_SC_Thin.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\NotoSansKR-Bold.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\fonts\NotoSansKR-Regular.ttfJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18nJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\csJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\cs\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\deJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\de\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\enJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\en\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\esJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\es\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\frJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\fr\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\huJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\hu\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\itJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\it\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\jaJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ja\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\koJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ko\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\nlJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\nl\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ruJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ru\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\svJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\sv\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\ukJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\uk\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\zh_cnJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\i18n\zh_cn\BambuStudio.moJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\imagesJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio-mac_128px.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio-mac_256px.icoJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio.icnsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio.icoJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudioTitle.icoJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_128px.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_192px.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_192px_grayscale.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_192px_transparent.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_32px.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\BambuStudio_about.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\add_filament.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\advanced.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_arrow.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_editable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_editable_light.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_extra_framework_mid.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_fila_sync.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_0.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_3.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_4.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_humidity_tips.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_item_examples.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_mapping_container.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_mapping_examples.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_readonly.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_readonly_light.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_refresh_normal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_refresh_selected.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_0.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_3.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_4.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_5.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_6.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_rfid_7.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_setting_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_setting_normal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ams_setting_press.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\assemble_return.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\automatic_material_renewal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_add_file.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_cover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_delete.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_delete_file.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_edit_mask.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\auxiliary_tab_picture.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\back_up_ts_bk.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\backup_current_use1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\backup_current_use2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\backup_tips_img.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bar_publish.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl-3dp-logo.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_ep_bottom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_ep_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pc_bottom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pc_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pei_bottom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pei_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pte_bottom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_bed_pte_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bbl_cali_lines.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bind_machine.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\blank.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\blank2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\blank_14.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\blank_16.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\block_notification_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\block_notification_close_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\block_notification_error.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bullet_black.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bullet_blue.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\bullet_white.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_fdc_editing_diagram.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_fdc_editing_diagram_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_after_pa.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_after_pa_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_before_pa.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_before_pa_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_caption_help.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_caption_help_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_caption_prev.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_caption_prev_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_flow_introduction.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cali_page_flow_introduction_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\calib_sf.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\calib_sf_inactive.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\camera_setting.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\camera_setting_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_half.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_half_disabled.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_half_focused.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_off_disabled.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_off_focused.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_on_disabled.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\check_on_focused.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\checked.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\circle_paint.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\circle_paint_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cog.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\collapse_btn.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\color_picker_border.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\color_picker_border_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\compare.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\completed.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\confirm.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\confirm_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\create_success.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cross.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cross_focus.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cross_focus_large.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cut_.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\cut_connectors.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_AutoArrange.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_Brim.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_CutTool.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_LayOnFace.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_ObjectList.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_SimplifyModel.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_SlicingParamTable.PNGJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_SplitIntoPlates.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_StackObject.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_SubtractPart.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_TypesOfSupports.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_ZSeamLocation.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dailytips_placeholder.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\debugtool.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\default_thumbnail.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\degree.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\delete.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\delete_filament.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\disable_ams_demo_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\dot.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\drop_down.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\edit.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\edit_button.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\empty.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\enable_ams.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\enable_ams_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\equal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\expand_btn.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_left_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_left_selected.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_right.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_right_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_ams_tray_right_selected.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extra_icon_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extrusion_calibrati_open_button.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extrusion_calibration_tips_en.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\extrusion_calibration_tips_zh.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\face recognition.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_control_add.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_control_decrease.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_dash_bk.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_0.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_10.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_3.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_4.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_5.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_6.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_7.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_8.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fan_scale_9.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_auto.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_manual.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_manual_result.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_calibration_manual_result_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_pattern_manual.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_pattern_manual_result.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fd_pattern_manual_result_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\filament.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fill_paint.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\fill_paint_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flag_green.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flag_red.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_auto.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_coarse.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_coarse_result.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_coarse_result_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_fine.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_fine_result.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flow_rate_calibration_fine_result_CN.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\flush_volumes.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\gap_fill.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\gap_fill_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\gcode.icnsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\go_last_plate.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\go_next_plate.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\height_range.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\height_range_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\hms_arrow.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\hms_notify_lv1.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\hms_notify_lv2.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\hms_notify_lv3.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_all_plates_stats.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_all_plates_stats_transparent.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_fold.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_gcode_custom.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_gcode_pause.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_slider_delete.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_text_search.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_text_search_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\im_unfold.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\import_file.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\info.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_n1_cn.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_n1_en.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_p1p_cn.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_p1p_en.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_x1_cn.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\input_access_code_x1_en.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\ip_address_step.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\link_more_error_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\link_more_error_open.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\link_wiki_img.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\live_stream_default.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\lock_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\lock_normal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\lock_normal_sys.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\machine_obejct_type.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\machine_object_owner.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\machine_object_printing.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mall_control_back.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mall_control_forward.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mall_control_refresh.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\max_volumetric_speed_calibration.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_empty.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_failed.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_loading.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_play.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\media_stop.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_add_modifier.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_add_negative.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_add_part.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_copy.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_cut.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_delete.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_edit_preset.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_exit.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_export_config.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_export_gcode.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_export_sliced_file.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_export_stl.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_fuzzy_skin.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_import.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_open.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_paste.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_redo.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_remove.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_save.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_support_blocker.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_support_enforcer.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\menu_undo.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mmu_segmentation.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\mmu_segmentation_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\model_time.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\model_weight.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitir_err_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitir_err_open.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_add_machine.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_ams_extruder.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_arrow.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_axis_home.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_axis_home_icon.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_down.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_down_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_temp.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_temp_active.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_up.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_bed_up_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_brokenimg.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_camera.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extrduer_down.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extrduer_down_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_down.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_empty_load.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_empty_unload.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_filled_load.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_filled_unload.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_up.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_up.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_extruder_up_disable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_fan.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_fan_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_fan_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_frame_temp.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_frame_temp_active.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_item_cost.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_item_prediction.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_item_print.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_lamp_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_lamp_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_network_wired.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_none_add.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_none_arrow.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_none_printer.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_nozzle_temp.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_nozzle_temp_active.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_placeholder.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_play.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_printer.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_recording_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_recording_off_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_recording_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_recording_on_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_sdcard_thumbnail.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_signal_middle.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_signal_no.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_signal_strong.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_signal_weak.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_speed.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_speed_active.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_status_empty.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_tasklist_print.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_tasklist_time.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_tasklist_weight.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_timelapse_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_timelapse_off_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_timelapse_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_timelapse_on_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_ams.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_busy.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_ext.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_offline.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_online.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_upgrade_retry.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_vcamera_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_vcamera_off_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_vcamera_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\monitor_vcamera_on_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\new_folder.pngJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\node_dot.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\not_equal.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_arrow_left.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_arrow_open.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_arrow_right.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_cancel.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_cancel_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_close.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_close_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_close_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_close_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_collapse.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_documentation.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_documentation_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_documentation_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_documentation_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_eject_sd.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_eject_sd_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_expand.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_minimalize.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_minimalize_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_minimalize_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_minimalize_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_preferences.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_preferences_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_preferences_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_preferences_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_right.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_right_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_right_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_right_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\notification_slicing_complete.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\obj_printable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\obj_unprintable.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\obj_warning.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\objlist_sinking.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_off.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_off_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_off_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_off_hover_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_on.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_on_dark.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_on_hover.svgJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDirectory created: C:\Program Files\Bambu Studio\resources\images\one_layer_on_hover_dark.svgJump to behavior
Source: Binary string: psmachine_unsigned.pdb source: MicrosoftEdgeUpdate.exe
Source: Binary string: msedgeupdateres_unsigned_en.pdb source: MicrosoftEdgeUpdate.exe, 00000009.00000002.3520137794.0000000002A60000.00000002.00000001.00040000.0000000E.sdmp, MicrosoftEdgeUpdate.exe, 00000011.00000002.3519852042.0000000001580000.00000002.00000001.00040000.0000000E.sdmp
Source: Binary string: mi_exe_stub.pdb source: MicrosoftEdgeWebView2RuntimeInstallerX64.exe, 00000008.00000000.3246206348.000000000007B000.00000002.00000001.01000000.00000009.sdmp
Source: Binary string: MicrosoftEdgeUpdate_unsigned.pdb source: MicrosoftEdgeUpdate.exe
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6C3A7 LoadLibraryW,GetProcAddress,FreeLibrary,9_2_6CB6C3A7
Source: MicrosoftEdge_X64_95.0.1020.40.exe.{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}.8.drStatic PE information: section name: .00cfg
Source: MicrosoftEdge_X64_95.0.1020.40.exe.{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}.8.drStatic PE information: section name: .voltbl
Source: MicrosoftEdgeUpdateComRegisterShell64.exe.8.drStatic PE information: section name: _RDATA
Source: psuser_arm64.dll.8.drStatic PE information: section name: .orpc
Source: psuser_64.dll.8.drStatic PE information: section name: .orpc
Source: psuser_64.dll.8.drStatic PE information: section name: _RDATA
Source: psuser.dll.8.drStatic PE information: section name: .orpc
Source: psmachine_arm64.dll.8.drStatic PE information: section name: .orpc
Source: psmachine_64.dll.8.drStatic PE information: section name: .orpc
Source: psmachine_64.dll.8.drStatic PE information: section name: _RDATA
Source: psmachine.dll.8.drStatic PE information: section name: .orpc
Source: C:\Windows\SysWOW64\wget.exeCode function: 2_3_00DCB581 pushad ; retn 0078h2_3_00DCB585
Source: C:\Windows\SysWOW64\wget.exeCode function: 2_3_00DCCB68 push eax; retf 2_3_00DCCB69
Source: C:\Windows\SysWOW64\wget.exeCode function: 2_3_00DD4210 pushad ; ret 2_3_00DD4213
Source: C:\Windows\SysWOW64\wget.exeCode function: 2_3_00DCB405 pushad ; retn 0078h2_3_00DCB41D
Source: C:\Windows\SysWOW64\wget.exeCode function: 2_3_00DCB421 pushfd ; retn 0000h2_3_00DCB50B
Source: C:\Windows\SysWOW64\wget.exeCode function: 2_2_00DD4210 pushad ; ret 2_2_00DD4213
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053BD46 push ecx; ret 9_2_0053BD59
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CBF47CF push E9FFFFFFh; retf 0000h9_2_6CBF47D4
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCEA053 push ecx; ret 9_2_6CCEA066
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CBC117C push esi; ret 9_2_6CBC1186
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084BD46 push ecx; ret 10_2_0084BD59
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C13F8C6 push ecx; ret 16_2_6C13F8D9
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C1591ED push esi; ret 16_2_6C1591F6
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCEA053 push ecx; ret 16_2_6CCEA066
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CBDD039 push ebp; iretd 16_2_6CBDD03A
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CBC117C push esi; ret 16_2_6CBC1186
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_kok.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_en.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sr-Latn-RS.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_pt-PT.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_lv.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_vi.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdateCore.exeJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_gu.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psmachine.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sr-Cyrl-RS.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psuser.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_de.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_lv.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fil.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ru.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_zh-TW.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdateBroker.exeJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_pt-BR.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_id.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fi.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_hu.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_az.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_gd.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeComRegisterShellARM64.exeJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ja.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_lo.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ko.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_en-GB.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_gu.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psmachine_arm64.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_eu.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_uk.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_kok.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_nb.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_km.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sr-Latn-RS.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_as.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ro.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_cy.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_zh-TW.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_da.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sl.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateSetup.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_lb.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sq.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_tt.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_cs.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_de.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_en.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_lt.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ca.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sv.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_gd.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_bs.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateOnDemand.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ne.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_hr.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_te.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_iw.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_tr.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_quz.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_it.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_kn.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_hi.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ne.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_te.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_gl.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_bn.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_mr.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fi.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_hi.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sr.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_en-GB.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psuser.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_mi.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_el.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateCore.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psmachine_arm64.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ar.dllJump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Users\user\AppData\Local\Temp\nsj6730.tmp\InstallOptions.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_eu.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_el.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_nn.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_or.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_pt-PT.dll (copy)Jump to dropped file
Source: C:\Windows\SysWOW64\wget.exeFile created: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ko.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_quz.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psuser_arm64.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psmachine.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_gl.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_cs.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_is.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_am.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_as.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_zh-CN.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdateOnDemand.exeJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bs.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_lb.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_cy.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sr-Cyrl-BA.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ms.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_th.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_pl.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ml.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sr-Cyrl-RS.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_lt.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_nb.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_tr.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bg.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_km.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ur.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_nl.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ta.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psmachine_64.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_af.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sl.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeComRegisterShellARM64.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fil.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_hr.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ga.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fa.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_et.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_iw.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ca.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ka.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sq.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_mr.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_pl.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fr.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_da.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_zh-CN.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ar.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_af.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_or.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_kk.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_pa.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ja.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sr.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fr.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ms.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_et.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateBroker.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_es-419.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_is.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ta.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ga.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdateSetup.exeJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psuser_64.dll (copy)Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Users\user\AppData\Local\Temp\nsj6730.tmp\nsProcessW.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_es.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sr-Cyrl-BA.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_pa.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psmachine_64.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_nn.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ur.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sk.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_mk.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_tt.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ml.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_kk.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_mt.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ug.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bn.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_it.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_nl.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bn-IN.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ro.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fr-CA.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ca-Es-VALENCIA.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdge_X64_95.0.1020.40.exe.{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_vi.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psuser_64.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sk.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_uk.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ka.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fr-CA.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_es-419.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdate.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdate.exe (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_id.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ru.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_es.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_bg.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_az.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_bn-IN.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdate.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ca-Es-VALENCIA.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_pt-BR.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fa.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_th.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_mi.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sv.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_lo.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_hu.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_kn.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_am.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ug.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_mt.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_mk.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeFile created: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psuser_arm64.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeFile created: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdge_X64_95.0.1020.40.exe.{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB68301 GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,9_2_6CB68301
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D6F4298 GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,12_2_00007FF76D6F4298
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C1399C7 GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,16_2_6C1399C7
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB68301 GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,GetPrivateProfileIntW,16_2_6CB68301
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile created: C:\Program Files\Bambu Studio\LICENSE.txtJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeRegistry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\edgeupdateJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053CA33 GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,9_2_0053CA33
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_kok.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_en.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sr-Latn-RS.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_pt-PT.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_lv.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_vi.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdateCore.exeJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_gu.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psmachine.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sr-Cyrl-RS.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psuser.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_de.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_lv.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fil.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ru.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_zh-TW.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdateBroker.exeJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_pt-BR.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_id.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fi.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_hu.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_az.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_gd.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ja.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeComRegisterShellARM64.exeJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_lo.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ko.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_en-GB.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_gu.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psmachine_arm64.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_eu.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_uk.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_kok.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_nb.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_km.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sr-Latn-RS.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_as.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ro.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_cy.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_zh-TW.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sl.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_da.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateSetup.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_lb.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sq.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_tt.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_cs.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_de.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_en.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_lt.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ca.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sv.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_gd.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_bs.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateOnDemand.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ne.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_hr.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_te.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_iw.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_tr.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_quz.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_it.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_kn.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_hi.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ne.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_te.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_gl.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_bn.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fi.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_mr.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_hi.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sr.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_en-GB.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psuser.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_mi.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_el.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateCore.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psmachine_arm64.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ar.dllJump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsj6730.tmp\InstallOptions.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_eu.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_el.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_nn.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_or.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_pt-PT.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ko.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_quz.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psmachine.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psuser_arm64.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_gl.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_cs.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_is.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_as.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_am.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_zh-CN.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdateOnDemand.exeJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bs.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_lb.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_cy.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sr-Cyrl-BA.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ms.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_th.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_pl.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ml.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sr-Cyrl-RS.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_tr.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_lt.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_nb.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bg.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_km.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ur.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_nl.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ta.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psmachine_64.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_af.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sl.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeComRegisterShellARM64.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fil.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_hr.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ga.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_et.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fa.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_iw.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ca.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ka.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sq.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_mr.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_pl.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fr.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_da.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_zh-CN.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ar.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_af.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_or.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_kk.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_pa.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ja.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sr.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fr.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ms.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_et.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateBroker.exe (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_es-419.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_is.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ta.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ga.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdateSetup.exeJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psuser_64.dll (copy)Jump to dropped file
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsj6730.tmp\nsProcessW.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_es.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sr-Cyrl-BA.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_pa.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psmachine_64.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_nn.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ur.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_mk.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_sk.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_tt.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ml.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_kk.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_mt.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ug.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bn.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_it.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_nl.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bn-IN.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_fr-CA.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ro.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ca-Es-VALENCIA.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdge_X64_95.0.1020.40.exe.{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_vi.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sk.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\psuser_64.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_uk.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_ka.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fr-CA.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_es-419.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdate.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_id.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ru.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_es.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_bg.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_az.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_bn-IN.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ca-Es-VALENCIA.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdate.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_pt-BR.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_fa.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_th.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_mi.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_sv.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_lo.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_hu.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_kn.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_am.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ug.dll (copy)Jump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_mt.dllJump to dropped file
Source: C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\msedgeupdateres_mk.dllJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeDropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\psuser_arm64.dll (copy)Jump to dropped file
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeEvasive API call chain: GetSystemTimeAsFileTime,DecisionNodes
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeEvasive API call chain: GetSystemTimeAsFileTime,DecisionNodesgraph_9-103171
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_9-104270
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeAPI coverage: 8.2 %
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe TID: 5576Thread sleep time: -30000s >= -30000s
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile Volume queried: C:\Program Files FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile Volume queried: C:\Program Files FullSizeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053C380 FindClose,FindFirstFileExW,GetLastError,FindFirstFileExW,GetLastError,9_2_0053C380
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053C3A0 FindFirstFileExW,GetLastError,FindFirstFileExW,GetLastError,9_2_0053C3A0
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053C400 GetFileAttributesExW,GetLastError,___std_fs_open_handle@16,GetLastError,GetFileInformationByHandle,FindFirstFileExW,FindClose,9_2_0053C400
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_00541D12 FindFirstFileExW,9_2_00541D12
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CC40EC8 FindFirstFileW,GetLastError,PathStripPathW,PathStripPathW,PathStripPathW,FindNextFileW,GetLastError,FindClose,9_2_6CC40EC8
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB73B3A FindFirstFileW,FindNextFileW,FindClose,9_2_6CB73B3A
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CBAEF10 FindFirstFileW,FindClose,FindNextFileW,9_2_6CBAEF10
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6EA55 FindFirstFileW,FindNextFileW,FindClose,9_2_6CB6EA55
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6C109 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindNextFileW,FindClose,RemoveDirectoryW,9_2_6CB6C109
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6BE82 FindFirstFileW,FindNextFileW,GetLastError,FindClose,9_2_6CB6BE82
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6BFB9 FindFirstFileW,GetLastError,DeleteFileW,FindNextFileW,GetLastError,FindClose,9_2_6CB6BFB9
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB9FFC8 FindFirstFileW,FindNextFileW,FindClose,9_2_6CB9FFC8
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084C380 FindClose,FindFirstFileExW,GetLastError,FindFirstFileExW,GetLastError,10_2_0084C380
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084C3A0 FindFirstFileExW,GetLastError,FindFirstFileExW,GetLastError,10_2_0084C3A0
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084C400 GetFileAttributesExW,GetLastError,___std_fs_open_handle@16,GetLastError,GetFileInformationByHandle,FindFirstFileExW,FindClose,10_2_0084C400
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_00851D12 FindFirstFileExW,10_2_00851D12
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D700DA4 FindFirstFileExW,12_2_00007FF76D700DA4
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C149616 FindFirstFileExW,16_2_6C149616
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CBAEF10 FindFirstFileW,FindClose,FindNextFileW,16_2_6CBAEF10
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB6EA55 FindFirstFileW,FindNextFileW,FindClose,16_2_6CB6EA55
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB6C109 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindNextFileW,FindClose,RemoveDirectoryW,16_2_6CB6C109
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB6BE82 FindFirstFileW,FindNextFileW,GetLastError,FindClose,16_2_6CB6BE82
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB6BFB9 FindFirstFileW,GetLastError,DeleteFileW,FindNextFileW,GetLastError,FindClose,16_2_6CB6BFB9
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB9FFC8 FindFirstFileW,FindNextFileW,FindClose,16_2_6CB9FFC8
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CB73B3A FindFirstFileW,FindNextFileW,FindClose,16_2_6CB73B3A
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB7918E GetLogicalDriveStringsW,QueryDosDeviceW,9_2_6CB7918E
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053AD5E VirtualQuery,GetSystemInfo,9_2_0053AD5E
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiper\angularJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\includeJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiper\angular\angular\srcJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiper\angular\angular\src\utilsJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiperJump to behavior
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeFile opened: C:\Program Files\Bambu Studio\resources\web\include\swiper\angular\angularJump to behavior
Source: wget.exe, 00000002.00000002.2243167641.0000000000AC8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllb
Source: C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053BAA0 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,9_2_0053BAA0
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB67DDE GetFileInformationByHandle,GetLastError,OutputDebugStringW,9_2_6CB67DDE
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCCD23D VirtualProtect ?,-00000001,00000104,?,?,?,000000009_2_6CCCD23D
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6C3A7 LoadLibraryW,GetProcAddress,FreeLibrary,9_2_6CB6C3A7
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_005429A8 mov eax, dword ptr fs:[00000030h]9_2_005429A8
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_00540775 mov eax, dword ptr fs:[00000030h]9_2_00540775
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCD0301 mov eax, dword ptr fs:[00000030h]9_2_6CCD0301
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCE9E97 mov esi, dword ptr fs:[00000030h]9_2_6CCE9E97
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCDD066 mov eax, dword ptr fs:[00000030h]9_2_6CCDD066
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_008529A8 mov eax, dword ptr fs:[00000030h]10_2_008529A8
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_00850775 mov eax, dword ptr fs:[00000030h]10_2_00850775
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C14679C mov eax, dword ptr fs:[00000030h]16_2_6C14679C
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C149240 mov eax, dword ptr fs:[00000030h]16_2_6C149240
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCD0301 mov eax, dword ptr fs:[00000030h]16_2_6CCD0301
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCE9E97 mov esi, dword ptr fs:[00000030h]16_2_6CCE9E97
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCDD066 mov eax, dword ptr fs:[00000030h]16_2_6CCDD066
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_00543A66 GetProcessHeap,9_2_00543A66
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess token adjusted: DebugJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053B198 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,9_2_0053B198
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053BAA0 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,9_2_0053BAA0
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053BC33 SetUnhandledExceptionFilter,9_2_0053BC33
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053F7E7 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,9_2_0053F7E7
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCB1980 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,9_2_6CCB1980
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCC9442 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,9_2_6CCC9442
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CCB1758 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,9_2_6CCB1758
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084B198 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,10_2_0084B198
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084BAA0 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,10_2_0084BAA0
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084BC33 SetUnhandledExceptionFilter,10_2_0084BC33
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 10_2_0084F7E7 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,10_2_0084F7E7
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D6F5AF0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,12_2_00007FF76D6F5AF0
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D6F5EA8 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,12_2_00007FF76D6F5EA8
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D6F608C SetUnhandledExceptionFilter,12_2_00007FF76D6F608C
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeCode function: 12_2_00007FF76D6FA358 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,12_2_00007FF76D6FA358
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C13EC5B SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,16_2_6C13EC5B
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C143CC5 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,16_2_6C143CC5
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6C13F574 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,16_2_6C13F574
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCB1980 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,16_2_6CCB1980
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCC9442 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,16_2_6CCC9442
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeCode function: 16_2_6CCB1758 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,16_2_6CCB1758
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6C9C6 SetForegroundWindow,ShellExecuteExW,AllowSetForegroundWindow,GetLastError,GetLastError,DestroyWindow,SetLastError,9_2_6CB6C9C6
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=True" /installsource offline /sessionid "{0AE48821-421D-40F0-9B93-9FD28EC8AE4D}" /silent /offlinedir "{FAF4F54B-74F8-4FCD-81CD-4DFC19E93F21}"Jump to behavior
Source: unknownProcess created: C:\Windows\SysWOW64\cmd.exe c:\windows\system32\cmd.exe /c wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "https://github.com/bambulab/bambustudio/releases/download/v01.08.04.51/bambu_studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "https://github.com/bambulab/bambustudio/releases/download/v01.08.04.51/bambu_studio_win_public-v01.08.04.51-20240117164301.exe"
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "c:\program files (x86)\microsoft\edgeupdate\microsoftedgeupdate.exe" /ping pd94bwwgdmvyc2lvbj0ims4wiiblbmnvzgluzz0ivvrgltgipz48cmvxdwvzdcbwcm90b2nvbd0imy4wiib1cgrhdgvypsjpbwfoysigdxbkyxrlcnzlcnnpb249ijeumy4xntmundciihnozwxsx3zlcnnpb249ijeumy4xntmundciiglzbwfjagluzt0imsigc2vzc2lvbmlkpsj7meffndg4mjetndixrc00meywltlcotmtouzemjhfqzhbrtrefsigdxnlcmlkpsj7mevbmkngrkqtmumyrs00neuyltgzmjatnti5nzq5qku3nde1fsigaw5zdgfsbhnvdxjjzt0ib3rozxjpbnn0ywxsy21kiibyzxf1zxn0awq9ins0rju1mdu0rc04nzawltremjatquzdms1dodveqtu4mzfdrjd9iibkzwr1cd0iy3iiigrvbwfpbmpvaw5lzd0imci-pgh3igxvz2ljywxfy3b1cz0incigcgh5c21lbw9yet0iocigzglza190exblpsiyiibzc2u9ijeiihnzzti9ijeiihnzztm9ijeiihnzc2uzpsixiibzc2u0mt0imsigc3nlndi9ijeiigf2ed0imsivpjxvcybwbgf0zm9ybt0id2luiib2zxjzaw9upsixmc4wlje5mdq1ljiwmdyiihnwpsiiigfyy2g9ing2ncivpjxvzw0gchjvzhvjdf9tyw51zmfjdhvyzxi9imp3dgfpaywgsw5jliigchjvzhvjdf9uyw1lpsjqd3rhawsymcwxii8-pgv4ccbldgfnpsimcxvvddtxv0pteld3ugzky0xsk1hhsxy2ehjazmlzt3houfuyczfov21qv2nhrlbnpszxdw90oyivpjxhchagyxbwawq9intgm0m0rkuwmc1frkq1ltqwm0itotu2os0zothbmjbgmujbnef9iib2zxjzaw9upsixljmumtc3ljexiibuzxh0dmvyc2lvbj0ims4zlje1my40nyigbgfuzz0iiibicmfuzd0iiibjbgllbnq9iii-pgv2zw50igv2zw50dhlwzt0imiigzxzlbnryzxn1bhq9ijeiigvycm9yy29kzt0imcigzxh0cmfjb2rlmt0imcigaw5zdgfsbf90aw1lx21zpsixoty5ii8-pc9hcha-pc9yzxf1zxn0pg
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "c:\program files (x86)\microsoft\edgeupdate\microsoftedgeupdate.exe" /handoff "appguid={f3017226-fe2a-4295-8bdf-00c3a9a7e4c5}&appname=microsoft%20edge%20webview2%20runtime&needsadmin=true" /installsource offline /sessionid "{0ae48821-421d-40f0-9b93-9fd28ec8ae4d}" /silent /offlinedir "{faf4f54b-74f8-4fcd-81cd-4dfc19e93f21}"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "https://github.com/bambulab/bambustudio/releases/download/v01.08.04.51/bambu_studio_win_public-v01.08.04.51-20240117164301.exe" Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "c:\program files (x86)\microsoft\edgeupdate\microsoftedgeupdate.exe" /ping pd94bwwgdmvyc2lvbj0ims4wiiblbmnvzgluzz0ivvrgltgipz48cmvxdwvzdcbwcm90b2nvbd0imy4wiib1cgrhdgvypsjpbwfoysigdxbkyxrlcnzlcnnpb249ijeumy4xntmundciihnozwxsx3zlcnnpb249ijeumy4xntmundciiglzbwfjagluzt0imsigc2vzc2lvbmlkpsj7meffndg4mjetndixrc00meywltlcotmtouzemjhfqzhbrtrefsigdxnlcmlkpsj7mevbmkngrkqtmumyrs00neuyltgzmjatnti5nzq5qku3nde1fsigaw5zdgfsbhnvdxjjzt0ib3rozxjpbnn0ywxsy21kiibyzxf1zxn0awq9ins0rju1mdu0rc04nzawltremjatquzdms1dodveqtu4mzfdrjd9iibkzwr1cd0iy3iiigrvbwfpbmpvaw5lzd0imci-pgh3igxvz2ljywxfy3b1cz0incigcgh5c21lbw9yet0iocigzglza190exblpsiyiibzc2u9ijeiihnzzti9ijeiihnzztm9ijeiihnzc2uzpsixiibzc2u0mt0imsigc3nlndi9ijeiigf2ed0imsivpjxvcybwbgf0zm9ybt0id2luiib2zxjzaw9upsixmc4wlje5mdq1ljiwmdyiihnwpsiiigfyy2g9ing2ncivpjxvzw0gchjvzhvjdf9tyw51zmfjdhvyzxi9imp3dgfpaywgsw5jliigchjvzhvjdf9uyw1lpsjqd3rhawsymcwxii8-pgv4ccbldgfnpsimcxvvddtxv0pteld3ugzky0xsk1hhsxy2ehjazmlzt3houfuyczfov21qv2nhrlbnpszxdw90oyivpjxhchagyxbwawq9intgm0m0rkuwmc1frkq1ltqwm0itotu2os0zothbmjbgmujbnef9iib2zxjzaw9upsixljmumtc3ljexiibuzxh0dmvyc2lvbj0ims4zlje1my40nyigbgfuzz0iiibicmfuzd0iiibjbgllbnq9iii-pgv2zw50igv2zw50dhlwzt0imiigzxzlbnryzxn1bhq9ijeiigvycm9yy29kzt0imcigzxh0cmfjb2rlmt0imcigaw5zdgfsbf90aw1lx21zpsixoty5ii8-pc9hcha-pc9yzxf1zxn0pgJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe "c:\program files (x86)\microsoft\edgeupdate\microsoftedgeupdate.exe" /handoff "appguid={f3017226-fe2a-4295-8bdf-00c3a9a7e4c5}&appname=microsoft%20edge%20webview2%20runtime&needsadmin=true" /installsource offline /sessionid "{0ae48821-421d-40f0-9b93-9fd28ec8ae4d}" /silent /offlinedir "{faf4f54b-74f8-4fcd-81cd-4dfc19e93f21}"Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB6AB86 GetSecurityDescriptorDacl,SetSecurityDescriptorDacl,9_2_6CB6AB86
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB74525 AllocateAndInitializeSid,CheckTokenMembership,FreeSid,9_2_6CB74525
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053BD7E cpuid 9_2_0053BD7E
Source: C:\Windows\SysWOW64\wget.exeQueries volume information: C:\Users\user\Desktop\download VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformation
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_0053B98A GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,9_2_0053B98A
Source: C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exeCode function: 9_2_6CB73964 GetVersionExW,9_2_6CB73964
Source: C:\Windows\SysWOW64\wget.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts13
Command and Scripting Interpreter
1
Windows Service
1
Exploitation for Privilege Escalation
13
Masquerading
11
Input Capture
1
System Time Discovery
Remote Services11
Input Capture
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts1
Scheduled Task/Job
1
Scheduled Task/Job
1
Access Token Manipulation
1
Virtualization/Sandbox Evasion
LSASS Memory31
Security Software Discovery
Remote Desktop Protocol1
Archive Collected Data
Junk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain Accounts3
Native API
1
DLL Side-Loading
1
Windows Service
1
Disable or Modify Tools
Security Account Manager1
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook11
Process Injection
1
Access Token Manipulation
NTDS2
Process Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
Scheduled Task/Job
11
Process Injection
LSA Secrets5
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC Scripts1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
Cached Domain Credentials26
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items2
Obfuscated Files or Information
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
DLL Side-Loading
Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1432100 URL: https://github.com/bambulab... Startdate: 26/04/2024 Architecture: WINDOWS Score: 56 76 Sigma detected: Invoke-Obfuscation CLIP+ Launcher 2->76 78 Writes many files with high entropy 2->78 80 Sigma detected: Invoke-Obfuscation VAR+ Launcher 2->80 9 Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe 1002 2->9         started        13 cmd.exe 2 2->13         started        15 MicrosoftEdgeUpdate.exe 2->15         started        process3 file4 54 C:\Program Files\Bambu Studio\...\wiki2.png, PNG 9->54 dropped 56 C:\Program Files\Bambu Studio\...\wiki.png, PNG 9->56 dropped 58 setting_guide_of_slicing_parameters.png, PNG 9->58 dropped 60 19 other files (15 malicious) 9->60 dropped 86 Writes many files with high entropy 9->86 17 MicrosoftEdgeWebView2RuntimeInstallerX64.exe 109 9->17         started        20 wget.exe 2 13->20         started        24 conhost.exe 13->24         started        signatures5 process6 dnsIp7 44 MicrosoftEdge_X64_...-964C-C7416E3ACB10}, PE32+ 17->44 dropped 46 C:\Program Files (x86)\...\psuser_arm64.dll, PE32+ 17->46 dropped 48 C:\Program Files (x86)\...\psuser_64.dll, PE32+ 17->48 dropped 52 98 other files (none is malicious) 17->52 dropped 26 MicrosoftEdgeUpdate.exe 2 8 17->26         started        70 140.82.112.3 GITHUBUS United States 20->70 72 185.199.110.133 FASTLYUS Netherlands 20->72 50 Bambu_Studio_win_p...-20240117164301.exe, PE32 20->50 dropped 82 Drops large PE files 20->82 84 Writes many files with high entropy 20->84 file8 signatures9 process10 file11 62 C:\...\MicrosoftEdgeUpdate.exe, PE32 26->62 dropped 64 C:\...\psuser_arm64.dll (copy), PE32+ 26->64 dropped 66 C:\...\psuser_64.dll (copy), PE32+ 26->66 dropped 68 98 other files (none is malicious) 26->68 dropped 29 MicrosoftEdgeUpdate.exe 78 26->29         started        31 MicrosoftEdgeUpdate.exe 26->31         started        34 MicrosoftEdgeUpdate.exe 28 26->34         started        36 MicrosoftEdgeUpdate.exe 26->36         started        process12 dnsIp13 38 MicrosoftEdgeUpdateComRegisterShell64.exe 9 29->38         started        40 MicrosoftEdgeUpdateComRegisterShell64.exe 29->40         started        42 MicrosoftEdgeUpdateComRegisterShell64.exe 29->42         started        74 13.107.42.16 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 31->74 process14

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe0%Avira URL Cloudsafe
https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe0%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeComRegisterShellARM64.exe (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeComRegisterShellARM64.exe (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdate.exe (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdate.exe (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateBroker.exe (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateBroker.exe (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateCore.exe (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateCore.exe (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateOnDemand.exe (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateOnDemand.exe (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateSetup.exe (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateSetup.exe (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdate.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdate.dll (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_af.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_af.dll (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_am.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_am.dll (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ar.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_ar.dll (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_as.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_as.dll (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_az.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_az.dll (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bg.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bg.dll (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bn-IN.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bn-IN.dll (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bn.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bn.dll (copy)0%VirustotalBrowse
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bs.dll (copy)0%ReversingLabs
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\msedgeupdateres_bs.dll (copy)0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://localazy.com)0%Avira URL Cloudsafe
https://to-be-replaced.invalid/cr/report0%Avira URL Cloudsafe
https://objects.githubusercontent.com/github-production-release-asset-2e65be/511797274/42e664ca-d4930%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://to-be-replaced.invalid/cr/reportMicrosoftEdgeUpdate.exefalse
  • Avira URL Cloud: safe
unknown
https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.0wget.exe, 00000002.00000002.2243167641.0000000000AC0000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2243345875.0000000000F15000.00000004.00000020.00020000.00000000.sdmpfalse
    high
    https://objects.githubusercontent.com/github-production-release-asset-2e65be/511797274/42e664ca-d493wget.exe, 00000002.00000002.2243310913.0000000000E04000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://github.com/artem-ogre/CDTBambu_Studio_win_public-v01.08.04.51-20240117164301.exe, 00000006.00000003.2525610645.0000000002843000.00000004.00000020.00020000.00000000.sdmpfalse
      high
      https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_S03wget.exe, 00000002.00000002.2243167641.0000000000AC8000.00000004.00000020.00020000.00000000.sdmpfalse
        high
        https://localazy.com)Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe, 00000006.00000003.2784168733.0000000002846000.00000004.00000020.00020000.00000000.sdmp, Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe, 00000006.00000003.2781217128.0000000002841000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        low
        https://ecs.nel.measure.office.net?TenantId=EdgeUpdate&DestinationEndpoint=Edge-Prod-MIAr4e&FrontEndMicrosoftEdgeUpdate.exe, 0000000F.00000003.3495239874.0000000000CD1000.00000004.00000020.00020000.00000000.sdmpfalse
          high
          http://www.gnu.org/licenses/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe, 00000006.00000003.2525610645.0000000002843000.00000004.00000020.00020000.00000000.sdmpfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            140.82.112.3
            unknownUnited States
            36459GITHUBUSfalse
            185.199.110.133
            unknownNetherlands
            54113FASTLYUSfalse
            13.107.42.16
            unknownUnited States
            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1432100
            Start date and time:2024-04-26 13:10:29 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 11m 38s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:urldownload.jbs
            Sample URL:https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:18
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal56.rans.evad.win@24/1236@0/3
            EGA Information:
            • Successful, ratio: 80%
            HCA Information:
            • Successful, ratio: 96%
            • Number of executed functions: 135
            • Number of non-executed functions: 319
            • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
            • Execution Graph export aborted for target wget.exe, PID 4112 because there are no executed function
            • Not all processes where analyzed, report is missing behavior information
            • Report size exceeded maximum capacity and may have missing behavior information.
            • Report size exceeded maximum capacity and may have missing disassembly code.
            • Report size getting too big, too many NtCreateFile calls found.
            • Report size getting too big, too many NtOpenKeyEx calls found.
            • Report size getting too big, too many NtQueryAttributesFile calls found.
            • Report size getting too big, too many NtQueryValueKey calls found.
            • Report size getting too big, too many NtSetInformationFile calls found.
            • Report size getting too big, too many NtWriteFile calls found.
            • Skipping network analysis since amount of network traffic is too extensive
            TimeTypeDescription
            13:13:45API Interceptor1x Sleep call for process: MicrosoftEdgeUpdate.exe modified
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:MS Windows registry file, NT/2000 or above
            Category:dropped
            Size (bytes):12288
            Entropy (8bit):2.78712366527347
            Encrypted:false
            SSDEEP:96:x8fvS9V3rAXcjA6VZkS9oA9fczR+qkqUHvNWLiA1qkqUHvkO:evEZ7JIAasJqJ
            MD5:369BBC37CFF290ADB8963DC5E518B9B8
            SHA1:DE0EF569F7EF55032E4B18D3A03542CC2BBAC191
            SHA-256:3D7EC761BEF1B1AF418B909F1C81CE577C769722957713FDAFBC8131B0A0C7D3
            SHA-512:4F8EC1FD4DE8D373A4973513AA95E646DFC5B1069549FAFE0D125614116C902BFC04B0E6AFD12554CC13CA6C53E1F258A3B14E54AC811F6B06ED50C9AC9890B1
            Malicious:false
            Reputation:low
            Preview:regf........V.S~.................... .... .......................................................................+..om.....T.f.+..om.....T.f.....+..om.....T.frmtm................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32+ executable (GUI) Aarch64, for MS Windows
            Category:dropped
            Size (bytes):164240
            Entropy (8bit):5.78401085275409
            Encrypted:false
            SSDEEP:1536:xdRGOvXRKePiGZWSDy3bNYoyKH+K76sK1aK8Awcghygs84d/qptHswZHkue/XpK0:xdRGOfPiGZWRrN6XcdRDw12HkuwXcYKu
            MD5:F29AB94BAC11CC4650BEFDB29BFF7372
            SHA1:7721A22AD3C1CB74DE854CBA0FD3E751D9743F46
            SHA-256:57A2E3C11E31686E858AD68EE903BCC9E64AE7D12F2DA91C67DF6DF5E4AFFFC7
            SHA-512:D9EA66341B5E5660FAA775ED75C325384B1AAD2085A27FDF0142281E35F6987633CEE07436BA10B0F772FC1C26C26038C79C6B2D886B8D43F8267CD5055066B1
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&8.FGV.FGV.FGV.R,U.DGV.R,S..GV..(R.UGV..(U.OGV..(S..GV.R,R.YGV.R,P.GGV.R,W.EGV.FGW..FV..7_.uGV..7..GGV..7T.GGV.RichFGV.................PE..d....G_a.........."......6...F...... n.........@....................................K.....`.................................................@;..(....................^...#........... ..T.................... ..(...@...0............P..0...`8.......................text...d4.......6.................. ..`.rdata.......P.......:..............@..@.data....1...P.......0..............@....pdata...............@..............@..@.rsrc................N..............@..@.reloc...............T..............@..B........................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):214928
            Entropy (8bit):5.63023795365664
            Encrypted:false
            SSDEEP:3072:ZgNpVWuxi/7gKNkhSC+t+MMCTs0kH+Bkx6uyXnZeiB+P+HNmYy95ZbmEfhzrgeoX:F7gKNkhSR/5kHouyXnZhB+x8WHW
            MD5:0F11E6717C1FE6DD20AE2D12F63AF3F7
            SHA1:B7F856842320D7BE1E4D6E098B979B4658092742
            SHA-256:6737D628504E1AD1B117600383D137BD975F51D0CDF351F6FDB9C714EDB45D14
            SHA-512:A12E4AD5B6DD85CD179BFA0FFA9BF2D958C1217EDCA061534C7A1145DE490180AD62EBB4C7155395530EE5BA7C2169EA0F6FA39499E5AB94A61FE3D693F1EBEF
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........w............}.....}.C...}.....y.....y.....y.....}.....}..........Hf....Hf+......C....Hf....Rich...........................PE..L....G_a..........................................@..........................p......|v....@.................................P...<........q...........$...#...P..<....u..T...............................@...............L...$...`....................text............................... ..`.data...............................@....idata..............................@..@.rsrc....q.......r..................@..@.reloc..<....P......................@..B................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):101264
            Entropy (8bit):6.421682089874464
            Encrypted:false
            SSDEEP:3072:CYCkuRieOVETT+jYPnau3fVGAhoAqzB+PCGHW:CYCk3ET+Tu3fC3zB+ZHW
            MD5:EEF652991949DB1FC0D738F520E67551
            SHA1:EF44647E32CD6467F34D156D78735CA44E0FA23A
            SHA-256:F6BDA32E3F3141BECAFB4908F5BEB0A086E17DC585703BCF948C736B2DDB0241
            SHA-512:FABCAAC24645D425DC47E7286A625AD5B88EB2BC14BAC870C9813C53D503BA7B495FE1B94EECF01CB0379185B8FC0393F9DB3DDE0317D3DA7A0DEFA6EFCB3000
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................$.......b.....b.....b.............../...../.n......../.....Rich...........PE..L....G_a..........................................@.......................................@..................................'..(....P..X3...........h...#..............T...............................@....................'..@....................text............................... ..`.rdata...].......^..................@..@.data........0......................@....rsrc...X3...P...4...$..............@..@.reloc...............X..............@..B........................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32+ executable (GUI) x86-64, for MS Windows
            Category:dropped
            Size (bytes):208784
            Entropy (8bit):6.028442358184757
            Encrypted:false
            SSDEEP:3072:o3F4ybfH29tBArqxqrpa9NeKt7/naUmG/WoY46by8lNkNVZwGNL:oyyq9XArqQVaKOLVgohtvL
            MD5:3DACF7CC11DE65C60616DC29C41397BE
            SHA1:525383A5FFF58295760D311F3FA6C09C97F90881
            SHA-256:F38C70879B558C534233995436F822B5038BEB2788F03C9705AB8F6218717888
            SHA-512:FDA5C886D98D76E7DEB2F4B441792E1704ABD8AB3D72893270F55092C873EDBA6D4DC57A2372E162CCEFB7E09906C9C20F24AFF68F92D7BDFBBC3BF2C6219744
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............T...T...T...U...T...U...Tc.U...Tc.U...Tc.U.T..U...T...U...T...U...T...U...T...T3..T..U...T..|T...T..U...TRich...T................PE..d....G_a.........."......b...........U.........@..........................................`.....................................................(....`.......0..t........#...p.........T...................8...(...pH..0...............(............................text... a.......b.................. ..`.rdata..bf.......h...f..............@..@.data...(5..........................@....pdata..t....0......................@..@_RDATA.......P......................@..@.rsrc........`......................@..@.reloc.......p......................@..B........................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):247184
            Entropy (8bit):6.429457453051207
            Encrypted:false
            SSDEEP:6144:RDOufOo7D5csZKxPYC3aBVqu1x47bjAOkIsKTDh+TPCg:zfOuD5csZKxPYeu1x4fjK7Knh+TPCg
            MD5:F40373187E4494F2764CA145A7F9387D
            SHA1:B27EEB366C706977B67F1A2DCDCC361FA5A17B72
            SHA-256:52C865AF24C645166ADD3E6367730108C2A35D1AE58391B52F722542842960CC
            SHA-512:B3551439252BE9B5CA042CDFD4D7E100C87F855FADB7D5763EEEA7E40DCFF97D6AD272B4F0564723DFAFEB01BF039973AA0540EFBF5A8BBB0BA12CC88642BC0C
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Ozt...'...'...'.E.&...'.E.&...'kA.&...'kA.&...'kA.&...'.E.&...'.E.&...'.E.&...'...'7/.'&^.&...'&^.'...'&^.&...'Rich...'........................PE..L....G_a............................F.............@.......................................@..................................D..........H3...............#...... "...3..T....................3..........@....................C.......................text..._........................... ..`.rdata..>U.......V..................@..@.data....'...`.......<..............@....rsrc...H3.......4...J..............@..@.reloc.. ".......$...~..............@..B........................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):101264
            Entropy (8bit):6.420708060641305
            Encrypted:false
            SSDEEP:3072:nXqUuxi6mVETT+jYfnau3fO2guzBoMqjB+PCl5H0:nXqUHAT+ju3fADjB+a5H0
            MD5:26EFCA27BD20C6E20B545AEE72277947
            SHA1:D0C6D65462B2931B9C21E043DFA2425313A19BB8
            SHA-256:081CB7A3D248F004851ADD9413BC2AC5EA7CE21D762F0BD4EE8D088270851C71
            SHA-512:0354944C1431A12252385F4A5762EB8BF7A806DC3AC83DE423C3ECB483943608C461BE7F44EDAA66EB1F7E42533DCE6CB7A0A3F48393F37C9896FC008F6D714A
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................$.......b.....b.....b.............../...../.n......../.....Rich...........PE..L....G_a..........................................@..................................}....@..................................'..(....P..X3...........h...#..............T...............................@....................'..@....................text............................... ..`.rdata...].......^..................@..@.data........0......................@....rsrc...X3...P...4...$..............@..@.reloc...............X..............@..B........................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):1777056
            Entropy (8bit):7.942726812716285
            Encrypted:false
            SSDEEP:49152:VSz3J4vtRV2t+uFnU/GH8zr1cTNfVnWOKGF1gnQTGqqf8:VSevXVI+ZOG1OtRViMof8
            MD5:51E7979AE4FA5381E5020B423CDA7947
            SHA1:D03BC5F93A967AD41C7B61B7B009BDEFFEE4EC7D
            SHA-256:7D139DD9C562A5B9EF9F7D4DDB2CAAB4DC90958DE503E1E1741DEFEB413120DC
            SHA-512:4CF3C73E383FCCF2F916F2947B21F2D17C71629779FBFB11523F852BFF8FC6B9ECE3B07C50D5FE6E98BF8A43DA2872FCBAC420C2E92A1F7B05F6EF7A96A63D38
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......I.c......................................................9..............................................[...........Rich............................PE..L....G_a.....................Z.......t............@..........................@............@..................................)..x....`...................#... ..|.......T...................X...........@...............H...4(..`....................text............................... ..`.rdata.............................@..@.data...\....@.......(..............@....rsrc........`.......2..............@..@.reloc..|.... ......................@..B................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:ASCII text, with CRLF line terminators
            Category:dropped
            Size (bytes):4172
            Entropy (8bit):5.1817564359072925
            Encrypted:false
            SSDEEP:96:rYpPbDCkOmjFHFJoirt6d5y9EygHEN80t6d5y9EygHEn:rYnjFHV4U2ygHEN8VU2ygHEn
            MD5:6DD5BF0743F2366A0BDD37E302783BCD
            SHA1:E5FF6E044C40C02B1FC78304804FE1F993FED2E6
            SHA-256:91D3FC490565DED7621FF5198960E501B6DB857D5DD45AF2FE7C3ECD141145F5
            SHA-512:F546C1DFF8902A3353C0B7C10CA9F69BB77EBD276E4D5217DA9E0823A0D8D506A5267773F789343D8C56B41A0EE6A97D4470A44BBD81CEAA8529E5E818F4951E
            Malicious:false
            Reputation:low
            Preview:NOTICES AND INFORMATION..Do Not Translate or Localize....This software incorporates material from third parties. Microsoft makes certain..open source code available at http://3rdpartysource.microsoft.com, or you may..send a check or money order for US $5.00, including the product name, the open..source component name, and version number, to:....Source Code Compliance Team..Microsoft Corporation..One Microsoft Way..Redmond, WA 98052..USA....Notwithstanding any other terms, you may reverse engineer this software to the..extent required to debug changes to any libraries licensed under the GNU Lesser..General Public License.....======....(1) omaha.."Copyright 2005-2019 Google Inc.....Licensed under the Apache License, Version 2.0 (the ""License"");..you may not use this file except in compliance with the License...You may obtain a copy of the License at.... http://www.apache.org/licenses/LICENSE-2.0....Unless required by applicable law or agreed to in writing, software..distributed unde
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):2500496
            Entropy (8bit):6.836806780972678
            Encrypted:false
            SSDEEP:49152:ludNz2fZHghOpzzU0esw7LPtL0WyKxNxBqHcTxaIF7cYc+T5vGn1v0Ax8U:lgNz8zzUDswdLLTxaIJlcveq
            MD5:10A3F0FBBABCC80F07EF8E6D2FE1F7F4
            SHA1:2FE7508268DD47CB8EE65AB8270BA67973DFE086
            SHA-256:F86E054AA35E6DE35346885D2427BD5C61F380ECAFB5521DF33BBD5C2419906B
            SHA-512:BCA899FE6BDEB499EDE0A9645B95C8E3C9E05568619608ABC00FF6D3634CF3BF2A8ACC2CB151A16EC3EA0112DEC0479F3AE887D7B65CD01C8B74117F2F97D6C5
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........v..b.Q.b.Q.b.Q...P.b.Q...P.b.Q...Plb.Qj..P.b.Qj..P.b.Qj..P9b.Q...P.b.Q...P.b.Q...P.b.Q.b.Qb`.Q'..P"c.Q'..P.b.Q'..Q.b.Q.b.Q.b.Q'..P.b.QRich.b.Q........PE..L...)G_a...........!.........................................................`&.......&...@...........................!.X.....!.d.....!..8............&..#...0%..-... .T...................<. .....P...@...............0..... .`....................text...r........................... ..`.rdata..............................@..@.data........@!..r...*!.............@....rsrc....8....!..:....!.............@..@.reloc...-...0%.......$.............@..B................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.019844401362494
            Encrypted:false
            SSDEEP:384:utVFXh7pWm1IWMjrY+VDxlwC3j+s014gHRN7+5Q3Jll36:0fmj+sg+Mi
            MD5:37ADB2A5B6CB813A0F8F61523FD44EFE
            SHA1:4140FD1C19DB61F934E5F0E22BF49D3BE710C490
            SHA-256:CBB8C69E9DDBB38241F5AFFDDF9D70497FAA1217B9E46E43ECD7DB80BEEA4155
            SHA-512:A00C56A8E79E6F62EEC83E9A5D264AD714D308190B153DB508C99BE6C6E67CAB21F8281F7AAFDE114C5D99A9673BEBF06EFCAF179EE4A7772FDB2094BC2D6ED0
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ............................................@.............................H....0..(....@..P=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...P=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):23952
            Entropy (8bit):5.784706117270377
            Encrypted:false
            SSDEEP:384:COVFXh7pWm1IWK0Ku8fHN14gHRN7OhR1lCz/S:dPl8fHTO3G6
            MD5:016E63D184B363BC737828E6B0485F42
            SHA1:BBBB6DA4E5162867C5EBE6384EDCC0DC67820796
            SHA-256:C753971FA39446F0359C169BC206FFCACFAB202339B6EB158B74AEAF853B26B4
            SHA-512:A40A0C3EDDA4E38246933EBE6F59033B2119F30E8105224FAD981FA01990A14029513F319478CFA29B78A3E59931105DC659CAFA325EEDA1DD74C41C8444D6D8
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........4......p........ ......................................0.....@.............................H....0..(....@...+...........:...#...p.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....+...@...,..................@..@.reloc.. ....p.......8..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):26000
            Entropy (8bit):5.537377416142749
            Encrypted:false
            SSDEEP:384:B75PBbpWm1IW7YwTYsQ8VGk14gHRN7ORzlZqf:NlUQVrus
            MD5:C44790318E11F4C4DB797E53C5DCF6A3
            SHA1:DD21E47201B02106182854305FD4D0364EF25E0A
            SHA-256:A53120093689BBBDE792DAF49B83A8DF9D4362DF5E37D4601992F67E43265574
            SHA-512:5DC285C463D8E059919BC8C77510C9BC015CBF43FD8460121D97DD4C9FC254B7CCB610528255DCB483047CB667A8744E249A79EF1B44C6BF5416EFB1CAEF8394
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........<......p........ ......................................(Q....@.............................H....0..(....@...2...........B...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....2...@...4..................@..@.reloc.. ............@..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.59276442280315
            Encrypted:false
            SSDEEP:384:yGVFXh7pWm1IWnKnFUFw4sC+7mHuAsuUu3BUF/Dqt96Dc3RRSjJKlF7NH11Vl14I:JoZ4lODuUu3+F/D06DpJK5HZra47
            MD5:9C9DA2427A31601AEAF5DEB98B72B626
            SHA1:E2EF4E64D899D9E2623A047212566B86C420B3EC
            SHA-256:09CE105C0AEC7940AF0BB98B74960908A042652E6958C6CB9E53E0A22B617A0D
            SHA-512:DF9B87AACD9B428F4C63CFB0B9492EFE5C208084C6CF3D09E3A7A024144F5A7D4CEBC1BCF07E8052EFAFE4A32D5E2D824D702EE65B9E2A824B806EA4AF438CD8
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ .......................................#....@.............................H....0..(....@...<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.168745357136877
            Encrypted:false
            SSDEEP:768:kGIOFe5FE5Sn/rtkPFS5OrF9FTFYF+2GIa:kYFe5FE5SzuFJrF9FTFYFi1
            MD5:41005C8A9A21EC93E9002128FA61A111
            SHA1:D821FF7584BBF3EB724CADC0E981A569A721780A
            SHA-256:5DB1FCF0A5910BB20A5620D0623463C2DD4ED36F8E4DEEC100E5E1355BA814C8
            SHA-512:A392280E1C050A6CF384BE3D929ABCCB39BA38532EACDB45BE4C3622B061575A13A34E8FBC90F2DBF23ECCF57D8CBE6ABA07302CDC1E7FFFC574A7A989CEB34A
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ............................................@.............................H....0..(....@..X>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...X>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.432913010195923
            Encrypted:false
            SSDEEP:384:3OVFXh7pWm1IWKdshCCdrwdPMQgv6AnI6gO814gHRN7TR1lCbV/:mcds8CJCgC16MlI/
            MD5:ED3D5BBFA479A3C423045550522EB9F8
            SHA1:6D44D93B8F7C4910CD6FFF16EFD8F58976D60729
            SHA-256:3FACFE5DEA406819364CDCF37FAACC0C7FD8A149DE375164CA241918D01A4F3F
            SHA-512:DDFFBBB1EF96627C5B4895D7C3A76A232FFDEDFA714464E9C67D44093A7E815B9B44285F79AA167BBCF52300E65A142C3A41EBF8E7C1DA8493CA4F4407D65FF7
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ......................................t.....@.............................H....0..(....@...?...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....?...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.570835667857593
            Encrypted:false
            SSDEEP:768:+4vAGEtqtVWCZsnM9/r94amPdQ8J7HPLSf:+IAGE4OhLSf
            MD5:4A0A3ED39B1A810295EAE674657E9AF2
            SHA1:84AE672DF870DC685B6962363C4FC543B68A559C
            SHA-256:3F9BE498101D3181161E24A8700C4B0C777097A50F8C0BEC465D460F63C37F10
            SHA-512:F3F38799FB2FDCA7CE3AA0588B34A45FDA22A10B1CA4DD8A4CEB96EE83DF51998765F04CEA3DD0BF521297AFA27CD83328D9BB34E398016B6700E6ABA51341D1
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......t........ ............................................@.............................K....0..(....@...>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.570475474934581
            Encrypted:false
            SSDEEP:768:4FvAGEtqtVWCZsnM9/r94amPdQ8J7H7HNHA:4BAGE4ONHNHA
            MD5:BE921B8B5F2851E97BD14E71CE23051E
            SHA1:8EA75FEF23AD675ED4F2B3D01215880181981395
            SHA-256:D976062B2BAA5A1B34663860B3DEF90238E71B18A0D9BE5A954CD028C0E0F9BB
            SHA-512:DB75B4B1B28C2521D8CFFB0052916B9FD3B94D0331D4FE348A77BC08B4D707E653264CDD627326D5088DEF432AF61D43F73487B008CB09D1A508D677119507AB
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ......................................Ci....@.............................H....0..(....@...>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.031948379511458
            Encrypted:false
            SSDEEP:384:VdHVFXh7pWm1IW9aDAmqRD0hNLCdJlwcSXp+Uys47p14gHRN7IAQ3Jll3m:vlQ6lwcSXp+Fs4D6u
            MD5:9522A48278DC23AAFD2F4439ABEEF753
            SHA1:9B087433DE727C39A7DE25379CEE1E8D6203C0B5
            SHA-256:11E672754ECD04657FA3C1B9D4F01C5A3279F015922418DC9F5221A1B8985FD5
            SHA-512:96F2042B246C2C65E3E99236EEDA653C5398B0E17093A968605AD6A92A1680B56D23F84C487720FB0439BFE9710B647A7710B640D9642BF483F52F4CDB7956F6
            Malicious:false
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 0%
            • Antivirus: Virustotal, Detection: 0%, Browse
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ...........................................@.............................H....0..(....@...<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):4.994263520844649
            Encrypted:false
            SSDEEP:384:KVVFXh7KWm1IW1bkbOnGNdoFoBGk5S0MEB14gHRN7kQ3Jll3g1:djbkbOnMdKoBGf14T41
            MD5:21E6788B8786324981BC6AE28B505D79
            SHA1:8440D3DB54D4F133C3E7A2BCE281A621977B523F
            SHA-256:B149245D132391C24E9790C384472EE38D5068F804CDDA1AB203DCD4F288A49B
            SHA-512:0146C7126A032414936D198EC801A5ED4514EF7962CBCB2B887A7421C051EC08BC70B93FF5D4D5B261614BB2A73212A2D5CC67BCED3EF56E462B248A417B8E4D
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......|........ ............................................@.............................T....0..(....@..8A...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...8A...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):4.987215583974734
            Encrypted:false
            SSDEEP:384:GtVFXh7pWm1IW8HEWdvDNdoFoBa1ZqSo14gHRN7fKrQ3Jll3i:UqHEWdvpdKoBalsfKG6
            MD5:A0B12220C5A733BC6238495D28269F81
            SHA1:AF8C0AB4287A2D7464FD8C93EB37638CB0840EA7
            SHA-256:335BBED7EFB60E729C2D34D7479593A047F5C426F6804BD8D7B99F455DA84A78
            SHA-512:37ED217799FBF6FB1557623C7C285CA1FB1F2675136BA0C9CC058F6B469D0AB1AD4B74A820AE85BEA6645CBF2DA4A2945A8457CD37FBECFBDF08A339A8154CAC
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......p........ ......................................_S....@.............................H....0..(....@..PA...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...PA...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.134314988603825
            Encrypted:false
            SSDEEP:384:u5VFXh7pWm1IWoTL7PGmxQEnwm/s14gHRN7pR1lC45E:0+TL7xYfN5E
            MD5:3C55C8119C4BEA73AAF9EC3DCCBE7F5B
            SHA1:C3A347EA2B67C5872A2F48A73DB56B5E93F598E6
            SHA-256:6B79A198C5CB2DAF93B2CDD12FF24A71CAE09146A9AED45FE936DC692D4CD843
            SHA-512:68F31F0C7AD220BF823E15564D150607536BB33829BFA97F49A27298DD0492D7D3C309A382F9E560322398178A4BAD579080786FF7C2DAFD0D2127438993A6FB
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................5/....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.041347992126984
            Encrypted:false
            SSDEEP:384:EZVFXh7pWm1IW4tZEmiuTHsyi7zAaaQvWYylVb2UFxOFEdJ714gHRN7zR1lCxDg:26DQIEUjjdJdF4Dg
            MD5:9DE5E5305EB387FF795D1668B3747EB5
            SHA1:07159EEC382A7BC2F344C3788F256653522F4526
            SHA-256:05ACB253F0549033C38AB8C5E2D4E242B1F71AD160035A3B7BC8D7DC0591BB25
            SHA-512:5F4BBBB3EF382C69DA7145EF233C5E0F61EEC4DFE16815A477FD1E668B0BCABE4DFC375AF40BD4E2B297FD0B9EF3215B3F9099EE509664083B1F37B23E6A8386
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................HA....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28056
            Entropy (8bit):5.067596530893269
            Encrypted:false
            SSDEEP:384:nTmVFXh7pWm1IWnHgHcyvBdGk14gHRN7i17s/Al3RX0c:i5gPGwQg/Qt
            MD5:FC5EE545CF8B1CD44614848A1833F5BB
            SHA1:CCED0B62A736CD1D560B2ECCA48E1EA53941D495
            SHA-256:33153B40D17C01DF7CD89E199F81ECA5CF9DB594A16F7C8BF25D45F5E4AE1890
            SHA-512:69E995D467A0C99C50B00724C5AEFBF1954F6000322538AD90815C1C8B87158423AEF6CE9CF7F1001F58CFE1684FF5C3A89314F50F6E4778CA11A2A5881DF8C5
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ .......................................8....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30608
            Entropy (8bit):4.9187196615362945
            Encrypted:false
            SSDEEP:384:4hVFXh7pWm1IWleI4tChj3ZnswxWbP/14gHRN7t+zlZ/:qjeOj3Zn7xWbPJt+H
            MD5:23CCAA642C7F5680FF1158D0F13560F1
            SHA1:5045C9AB63858ADDF86BA4C21492CD60BAFE689D
            SHA-256:FAA0E32772556D7806A9E6C5511A207377FE382AC9100DD44D92086C221106F2
            SHA-512:6D55569319A57E8C6D4B494816006830CA81D8396E9D0A21F26BF99D9641CF8E061BD78D7821536C42EF10EC7980409A7B606953F12920775780093557A107B1
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........N......p........ ......................................A.....@.............................H....0..(....@...D...........T...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....D...@...F..................@..@.reloc.. ............R..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):5.537267322434617
            Encrypted:false
            SSDEEP:384:PjHVFXh7pWm1IWKnBzBUBOTG94vuZtfFtSmFK9q85PgbC14gHRN7XQ3Jll3/8:pkpKxmF51CM
            MD5:25E73EFDF67007784851B0EB3AAD6F42
            SHA1:41D1A351B1341F54B10E47019F7A8AEC8F0D80DC
            SHA-256:C71F98E508724853387E0EFE6DD5C39A133BE23E5EB5D746A0A44E962456A072
            SHA-512:2F28A88024E4C15778CA2113DF2FA40C890E27B95B6D3EDFDA205259433E706FEAA3B2B0DEB99B7917482B60DFFF7F1B69BFD86EEB14BF1963DDDD0B9003B6FF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......p........ .......................................Y....@.............................H....0..(....@...C...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....C...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.085779178023325
            Encrypted:false
            SSDEEP:384:U4CVFXh7VWm1IWakagyvrT/H14gHRN7TVYR1lCWl:Ur1agyvnRT6rl
            MD5:91F1EFA4237B25EF4DE5091A8522CED2
            SHA1:F8CA12373E9DC14DB40E71372BC09B34A84D97CE
            SHA-256:7FB71465F1EBC289AB782EA2731DFC05CDD7E4C951083CFA9A3DA4F055EB8EDE
            SHA-512:5E95C82C0A08AD5D3795A550ADDA6472B34D854B9F1058C95006EF2779A6F48C10B91F4E71F4A25621B7CAD4081C8F24F7EC9A220669D52254D42C9604301930
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......t........ ......................................{.....@.............................K....0..(....@...6...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....6...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.080053021104189
            Encrypted:false
            SSDEEP:384:ZPVFXh7pWm1IWjkagyEl9KR7n14gHRN7bIR1lCv4:TaagyElstbgu4
            MD5:0C372F709DB7D5541961A5766E3DED52
            SHA1:B1DA0E90026A5663751662DAF714545AFA4BD8F3
            SHA-256:495AC5311E57411226F06BFDFCF3F6BEBC33C78B4ED197EBDE6B9CF2BD1D1A9E
            SHA-512:515F6689B0767B3B053D870AFBF1494136AB52214165292FE0D280A6954DC8753AB79AAC0D70A1F26F83768C78F153E8916D1605D4C5BB410E3846BB40222DE3
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......p........ ............................................@.............................H....0..(....@...6...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....6...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.027092985915544
            Encrypted:false
            SSDEEP:384:sETVFXh7xWm1IW8GduUrdaV14gHRN7FR1lCpzn:RBBr47TIzn
            MD5:1ADCAFA26E8A2F54C6D12946D3103C9A
            SHA1:34CFC13AFE66DE9F1632AF1D6525CD265C4739AC
            SHA-256:56B0A8C59CEF12BD3B81828134D7B9403063BCF4C87A9D681FB645E4746F3854
            SHA-512:185F9EB1199B5ABBACA82273392238AFF484050FDF63DE80F34C8B1011AE5CFCF91C6E2D65B3EF656079AAFDBD7D2CA821113DE1A0474C81698F04A6AFF97CAA
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......t........ ............................................@.............................L....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.014692140602505
            Encrypted:false
            SSDEEP:384:XKTVFXh7pWm1IWOti4jOI714gHRN7jPSzlZeS:XeUti4jOIdTSGS
            MD5:DFCD44C2D1636BFFB0A3A0C277CDE874
            SHA1:CC769D021161E269979081D6D7C8D3BA9C45EE13
            SHA-256:3098ADEB8BE598A79D379399E2794B1D27EE4BA2213C051DCB0AEFF1397AE9DA
            SHA-512:D80651B2CBA98B31738AE65E27469F6748DDD0B0D05E42A2AA5FE60CFBCE158C1EB919938FACBD614D8B609A4680D700C37DAE574879797C2BF03186318BB817
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ............................................@.............................H....0..(....@..@=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...@=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.100627170532004
            Encrypted:false
            SSDEEP:384:69K2VFXh7pWm1IWTVc0dEyjE/lX7gid1LFdXjwAiDiX14gHRN7hzlZW:6g+15jE/5gG1LFdsAw6he
            MD5:8C4CD9F4601650DE19B44B30C3FA9FFE
            SHA1:8A9423A07B5C772A6D80E419B3436F0108908DF8
            SHA-256:A159F54C88E6735E9912B9FDECB8C9441F9F41358178CEE9E6C092E6E47E5400
            SHA-512:D46456968948E6F615D544E257945D29D319FC5440D43271D92BF007FC8DF17A52E5F2EA8064A39E881B20B15D0993A689EBB21472EF8413AE32BC0B04D27D23
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................R.....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.050750157064671
            Encrypted:false
            SSDEEP:384:YkpVFXh7pWm1IWpcLpNsX58FOXAzp4O114gHRN7NizlZS:frYKuFOkp4SQ6
            MD5:3233A301AC0DB0EF788FA09F3B1296A8
            SHA1:DC031BB1B85FD83221AC0A985700A3B7C4956EF9
            SHA-256:97AE7D3402E6091F2FD985DFD0A221D22748EC635BAAEE0CB3B7DA6018AAD3D3
            SHA-512:48EDC0AFB00BB0A691C5D5435DB71F74C25BDE0C83DF7352B239E2862A16626386D075DE2E79BD42C326D2EF7E478EF4BB6740D403CE9A80F2A6D82599BC3368
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................j.....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.490034199165937
            Encrypted:false
            SSDEEP:384:woIPBbpWm1IWGXd3EqtOW0QIGf814gHRN7dDEQ3Jll3Z:wxsn8CIxzh
            MD5:2DC5047FF8F6D3EE5FFBE9E8E797EA1A
            SHA1:BE94969A631AC9C37A1DCE0E6B1DE96CC933310F
            SHA-256:77F3F899E10AC718E3A97FD51AD78AF0DC38E08FDDE2A56EB413AE806D819641
            SHA-512:132003C603591FC740A63BCCE985F3358828AEF71408F89E3D44470A9580A3669B1D7A00E3FBC68BF26E827CB5AEDE3BD0F2D9595B47889311DD650DCCBB51D4
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ............................................@.............................H....0..(....@..`9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...`9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.043742836060103
            Encrypted:false
            SSDEEP:384:vPVFXh7pWm1IWcJWHJWEFIxlyELZWEYXSN6ZKFl+EoJth0vDqm14gHRN75rmzlZp:FyJOJkURvu5rmqm
            MD5:3A78D8D434D7DD1157006AD888A30C84
            SHA1:2240A01B9ED7A4DE46778075F79408E1AC447876
            SHA-256:3A2281D948D91578036257F7C0B9C6322A88CD368014A4A42521650F96C298C4
            SHA-512:CD1403B1203ED058265F0DE06C2A38228C278F0021E28F496A82026169C5BAC67BD5EED4E53B917B8E4F1E6CA5B302E6DF2D9E8347F39C03AD2E4A5F7AD5F229
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................?.....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):4.982224545078734
            Encrypted:false
            SSDEEP:384:hZNVFXh7pWm1IWXsXsjNjkbZz9IrJqPDYiuY14gHRN7nzlZsO+:XdsXsjNoFz9IrJqLYT8ng
            MD5:3093FC67671B422E3A9249CBF9534474
            SHA1:42B5AE63D11AD7314E5C9DA5D35E79ED70D60C56
            SHA-256:D1042BD75E7F59BA0DA5BC9F36BC0B749FB1B8FF8EDE3381AAEDE60642A03E4E
            SHA-512:513FE93AE59AB267BA03E679FA7AD683849C0A2CBDACF93FB3D7543B17D9859EB9C19274AA722646EF76E34E074F5CF4424E2E22B92173A89AC6AE86885C0CD6
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......t........ ............................................@.............................I....0..(....@..@?...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...@?...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):4.9700204242854
            Encrypted:false
            SSDEEP:384:qIwVFXh7VWm1IWFs7oaIR3yZ14gHRN7eQ1TzlZj:qdDIqR3y3BNr
            MD5:36AF4C291BFEBD91664919156959C9B1
            SHA1:2A06E2F2443EC68525A816364BD16A2EEFB155A1
            SHA-256:AF50B36C0B6DD39EEAB66EC9F5A57EB9193FEB64B5D036A4CC374702BF8CCDDA
            SHA-512:23F27BAB93014F2374B9DA3071BF31AA4A555EFFA816F34915A34ED639E51B35F93B836130F107203D699D7F4F5C0E8E96C0582ACED16B682551474C1B299742
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......t........ ............................................@.............................K....0..(....@...B...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....B...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):4.961775809823286
            Encrypted:false
            SSDEEP:384:V0BVFXh7pWm1IWF8bEqhiP14gHRN7Bd8VR1lCSt:Vmj8lhi5Bdi/t
            MD5:DCD187DBDAE619DA1ADA587DC7F067DA
            SHA1:5ACA91600D32081B8CF1DED0E666519ED053E6EC
            SHA-256:1F7F8ED1140EE99241E27E3D9A12608F68B94B99E3E6A4717A494509E37B5659
            SHA-512:E4F54C5E411840A5A02CE46D76E4A9D89EFF52C3A47ED989D40EB9B456D36DE23C795304A0B97533432C0071C7BD7C765027147D7A8F79DE8E3DA87E4CBACF73
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......p........ .......................................R....@.............................H....0..(....@...B...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....B...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.032143048556202
            Encrypted:false
            SSDEEP:384:9CkVFXh7pWm1IW45vCQkFYoIoAHscTLGK14gHRN7VNzlZL:9Pe5v6YoIoAHseSqVNz
            MD5:0A2528CEC925BC4E1B0980A641996AEF
            SHA1:BD38A9372C1C750884ACE7BF3D84BA65B4D1BA2E
            SHA-256:EF938AE7242B499CBA81EC167D2493D42120A9FC5E939CF5E91A85A5289E3D93
            SHA-512:34387F4720FD4E6D0F3E352AE8CF1AEF9C54E7BF5058B8C76FE147D6BF7EF44E7205E31F331DA6D9D6708630ED31243D63E9C30CC24C701169CD131C476C5965
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................l.....@.............................H....0..(....@...<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):4.951097819303206
            Encrypted:false
            SSDEEP:384:DSVFXh7pWm1IW5FYiA7VzpfDfqegs2/jgRX14gHRN7ysQ3Jll3Ub:W/FYiA7V9bqpSRB0q
            MD5:37784CE8C8648C4B9EAFEF1B29ED28AD
            SHA1:70F0E8B6583F94E4AAF99B49C66D58675E17C971
            SHA-256:37476C2D99CE936C5AD784E91A96F5FEB85B19A7E1DE78EEABB0336C74B50176
            SHA-512:C077C3A36D4426867B293E5A4B850C17756457E876B3737EFA8F6FCE5C79C93675598313F5CB727578F717AF783F31A069115CD7B937D0A5B4E9B4C8D44F76B6
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......p........ ............................................@.............................H....0..(....@...B...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....B...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.0475255724921055
            Encrypted:false
            SSDEEP:384:qtVFXh7pWm1IWTscDi2RK1HoC614gHRN7IOR1lCkc:MVscH81HoV9Fc
            MD5:7B5456FCB1894496A2155453D0A9FFE7
            SHA1:3F1807CF1B429C4C836AC923F07BF7F30C94B950
            SHA-256:5812BC492A00671AD05796CF02296357BED4A205F2EAE41C3FE540E606FDE8C4
            SHA-512:B2337648FEBA636357448309ABDBC8067E0E51CA80A86759D3A30538CF19DAEA25EA48B9BD6BEE8C70FB69F05A26B8A1CA0E7921AC24FCFFA4BD2FFB4F301D45
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ .......................................\....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.573052423675078
            Encrypted:false
            SSDEEP:384:m7zVFXh7pWm1IWPt7X1QrsojGtCAPPFZdxjACy6xytd14gHRN7rQ3Jll3/:mN3CrwGDGn
            MD5:55725F82EB8831B7BF6267192725177C
            SHA1:545DA7CB05A4379142A9746AED569EC812E7188C
            SHA-256:557E9B3C0C8E13E6C68980A2D7CF2CAA4C8E8314233544A1412535921AAA3699
            SHA-512:9A4EC8BCE7A96B4181D7B6ED50775D2E6512785A57D9511F5B5967BDC8803114C8EB55604EF8ABB421F4D555FD7CDAAD6073756D224A9E072773FCF747B64467
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ............................................@.............................H....0..(....@..(<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...(<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.468809283819709
            Encrypted:false
            SSDEEP:384:7iVFXh7pWm1IWaUQj9qYmsqkK914gHRN7fzlZO0:OIUQxqYmsqkafW0
            MD5:EF945C12CE1248E80B44A6B6B66E6BE6
            SHA1:63543F506F0CF7AB5D12265C65891F42FF03A6E2
            SHA-256:41C9039875AB923D5D90389AE237F6FDE34F515DB68B5D8368A421CEEAF9047A
            SHA-512:ABB92ED17FF33A389F857240ACABFE04A97845D9BABE942A8BE728F0BEE094E2C6B8630D71E4399681CC7E19755C4997013BB02F8ECFDBA2ACA04B0FEE64A015
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ .......................................d....@.............................H....0..(....@..p<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...p<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.071819349247978
            Encrypted:false
            SSDEEP:384:R+VFXh7pWm1IWt/fbmNCCa9PNV8qaX/jt14gHRN70zlZ9:sosDJ0//0V
            MD5:E3AE3F74A9CFB3F69A450F5634AC829B
            SHA1:463EBBB4489F7545D064EC89B5CCC1996D09FF16
            SHA-256:7FBFA700C530E673D5A00C9CC1DAC00AE703050F6BDDC386E473454148E5C677
            SHA-512:29D92DF378AA1B94C287F19ADE48BE2DBFDAE567FD6660630F45CB7F7B7983E6A9312072DCA72438ED2A36010C3EAAD78EF9D3164A9E79A0DFB90059489C6CAA
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ .......................................Q....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.074176707522236
            Encrypted:false
            SSDEEP:384:A8VFXh7pWm1IWWYhYkZ2hUrVyh8bfkWupxitLbufJHwHBNJV14gHRN7xFQ3Jll3d:1fKkZ2hSVyh8+i5bufJHwhNJ7xI1
            MD5:41441A0614DDC6F587BFF4A23BD02B6D
            SHA1:38EDD14A9B7888CA3D321AE6E8126E56D16A36A6
            SHA-256:96165BBAF85FBC23692E8F36252535B9040BC1B3B023C5979EA532FC04CB4FEC
            SHA-512:5C402B5B983667D395B7EA608C60804F975DFCCF4BEB0311DDA27C36155C6ADDFD874299F11B495A43B240AFE4DF0CAD9B9C13FAC5A20475497C9AD55C1D73AD
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ............................................@.............................H....0..(....@..p>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...p>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.071853352350367
            Encrypted:false
            SSDEEP:384:WzVFXh7pWm1IWXPC8kbhT9rLVcBQCOG14gHRN7rQ3Jll30:uBtPGc
            MD5:22A4ED2EC54EFA967A66F65E619936BB
            SHA1:E5366EBADC15A49B402E72A2C420855BDE46F5C4
            SHA-256:2216FC1F7713F800D2E0FBC627D2D6C843AFD1692A8002A42C7C39667049CB90
            SHA-512:2A598CC548FE73667BF301EBC3861A1132706FFD14686645B11599AA706EABED212ADDAD3155C69C5A6CAB229CD08C8123F8CDA4B40487892318AC8C00037A33
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ............................................@.............................H....0..(....@..h9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...h9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.133639891686493
            Encrypted:false
            SSDEEP:384:liVFXh7pWm1IWWz2D29UHVm5TpA40XLai+8wo8SKkGIokBZpO3kTPSfc14gHRN7c:wsBqQ5TpAhr+8wh0xo8pGkTPRNu1tF
            MD5:1D51E5246374433B6A7BEBFC844E0EA9
            SHA1:088300E92CDE509179D2FCFD985EC9EF3AE4AFBA
            SHA-256:6C0EA6BAE2C71598C8460C3F395A4A9FF8686B202999EEA809D5A18E56FDF080
            SHA-512:18D70D59D2471D42374AE08F873FF407674716B0F6195B5772FA97F34282797FD9C78BB9AA10BB66853C9BB497AF930CAFA40B07F73401E6C06D854B2EECB07C
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ .......................................M....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):4.981393397902628
            Encrypted:false
            SSDEEP:384:egVFXh7pWm1IW6uu1+psJfo914gHRN7uyQ3Jll37v:r61+pCfcuZ7
            MD5:1BEFA33963448D7DB02105C360AC2B78
            SHA1:8DF3D755E505AFE5820B3DBB93190C30BDC431FF
            SHA-256:EFA8D3EEFC6090FE944407F1C084B21176B4D5AB39D73E8E1F408027525F58A9
            SHA-512:951FFFEE06A854D14FEF120BF36CA2F6C8BE276D85A10E327A1347A5D5C69B682B6E3ADE1DF0BD09F87404B371A36153C2C0ACF970496A1A3E007BA3894BA361
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......p........ .......................................f....@.............................H....0..(....@...A...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....A...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):24976
            Entropy (8bit):5.6625602261455334
            Encrypted:false
            SSDEEP:384:Ie3PBbpWm1IWxbW1x4SCJl4LGA/t2QL14gHRN7EzlZf:9PcCHYEH
            MD5:4561C4DE2A2099DB54708E39D74E6EE2
            SHA1:1C915384C9F44827BD4EA5A8DC4A661A5B73D5FE
            SHA-256:A91DF3135FC0D1720A4FF08E931482E1B082E8F90BEBACCAFA8C70CD95C3AF1B
            SHA-512:C5E3F730E9D180C3964811ED74B2A8A3DA9EB3A4939298488077E4BBEAECBAF3D88172C36914E2F7EF778D1A793600D67B791C604A8A5E09CA9359EB1BE511BB
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........8......p........ ............................................@.............................H....0..(....@..X/...........>...#...p.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...X/...@...0..................@..@.reloc.. ....p.......<..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):23952
            Entropy (8bit):5.825448963144067
            Encrypted:false
            SSDEEP:384:rTVFXh7pWm1IW/9Vu2/JuQX14gHRN72jszlZqh:187Q2YSh
            MD5:3F84FC101468952D6FFD225795C9D970
            SHA1:7782DEDB4EF9889A947A288355900EF5F69D27A5
            SHA-256:A865887FA427EEEB9E14591161DFB115097DC76E8BD072D838D95D8AA7F362A3
            SHA-512:1AA052D0B32411363E00FA6E53A4851AD022E0849A995447073BED9657F90212107098A6B46B62800EF0BAF20FE181746480ADD9B887CF5C0576395026E1D8B4
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........4......p........ ............................................@.............................H....0..(....@...*...........:...#...p.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....*...@...,..................@..@.reloc.. ....p.......8..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.578965423095346
            Encrypted:false
            SSDEEP:384:WSVFXh7pWm1IWJodoA7s4THmtl4cA+kq14gHRN7S5qR1lCEq8:1IBKkuVT
            MD5:B047AC273A9151860D68A5DD606C368C
            SHA1:287502C4765719E5184C4BF748A214F0CF1F0693
            SHA-256:7EE1FBD8A2AF38356492D930EEF90534E075993804458FF70A805F5411FF9132
            SHA-512:6C8C667F5E6D6336E7EEB52608820B31AFBA35FFBFE70CBA36C12FB8DB450CE240B113B9987FE9B5237DE92F4953A91C5853A7381B2BC6762D6745ABC5C8CF3D
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................F.....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.51196589426949
            Encrypted:false
            SSDEEP:384:90TVFXh7pWm1IWm9RsvJQwt14gHRN7mLQ3Jll3e3:6ALsvJQwzxm3
            MD5:481484EB1C2A00F407D94BFDDCD03686
            SHA1:F84DB37DC7F2D9FB609225BD6D2C4E7A4A923DCD
            SHA-256:A8AF974ED6056E1D257C9B9205716C0794722521DD6FE902F94A4878F582E8A5
            SHA-512:B985999D2B0E19A61F5D30CFFBF6E0DBCFAED64CD51E27ABF74F440EFFE0F052A73F2ECC5062991A5B60557C248ED951A90F182BAD1A23CD22A345864A2E33CF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................>.....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.740190965039821
            Encrypted:false
            SSDEEP:384:1gEVFXh7pWm1IWSfJoxeUnPcse7ceGBAuOCNpkc14gHRN793Q3Jll3Zsy:/hxdPxe1GBAuN/ko9i/
            MD5:7F85D2DAF4437A918A31854075872912
            SHA1:868F838F0E88CC3B289E471CF39C14952072C287
            SHA-256:95F7BA62E5E1F2FABDC7E8AC5DFE32D7837B6CBE7182FE90453A9CC5BFA66E33
            SHA-512:F0F929E747E27939E505F89CF77BA2DAFCC9E69D8BAB846347E1EEFA16F51AF15B5C82DE9C82C0161350C10E5013034DB3E2E8928A8414FC8449714298CA90BC
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......p........ ......................................:.....@.............................H....0..(....@..H7...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...H7...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.639263652622013
            Encrypted:false
            SSDEEP:384:8MVFXh7pWm1IW6QdbSMXPHw714gHRN7xzlZ8:xoQB6dx0
            MD5:4D738D3E26AC09DCD6DD6977B5CE1979
            SHA1:EF6C0835F0613A70B984E621A60148E9579B0E67
            SHA-256:A196D8429FCFC43DD930F0EC54A7CCEAD33DCE7E618A598F8ACA45949A47E5BA
            SHA-512:C5DA65708240C349D3299C3D9C81076EA3917FD831938B827C7BDD5552F4D29A8B228948BA6DA03DD11AFE1AEE37280BBABAA86EB9630652CC34EEDBD9CF45D8
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ............................................@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):22928
            Entropy (8bit):5.951860698702779
            Encrypted:false
            SSDEEP:384:TrVFXh7pWm1IWmlte7yuVDeYhHNjLUJCB1SGGgrxYQ8pDuZ14gHRN7STQ3Jll3A7:VMF+OWFx3Xk
            MD5:938CC55126A99CEC15203772300FEE32
            SHA1:1C7CA3347278D901B499C5033892131676D212CC
            SHA-256:0C327F1F7EA95B7B2A44A395B05F361763E2B58A56DCFB2141518B6804C0132C
            SHA-512:4E9285CA447D255EA0B8427F88139416579814A527B4694E14EB4A9B0B8284DB8D7932C6E1164CF48B4BEBE56449A99F6852C277E2ACE33A84DEE2EEC305CEAB
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........0......p........ ......................................Z.....@.............................H....0..(....@...&...........6...#...p.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....&...@...(..................@..@.reloc.. ....p.......4..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.540539050370516
            Encrypted:false
            SSDEEP:384:N0n7VFXh7pWm1IWBRr+hjZ+hjgOcWtGQQ14gHRN7V8Q3Jll3CI:qpQMLI9VL6I
            MD5:FDE6E86F87C4CEA5B9900F03E70DF575
            SHA1:9520A07D407B4E52B07CE6E98D957910CFCEBEE5
            SHA-256:952975C3CDD8ABC35E49AF273BFCAF8BDB54B0A232AB1E51DAE0FBB52AB89A72
            SHA-512:B5BDF29D5B782C92A224E475E3E32E67BE084012FA112590B3B5E3F4CBE4D321C9F97FC82901AF1752C9F01DB00DD790FF58C7A5446886820E0127D2938E2489
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......t........ ............................................@.............................I....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):4.978483898492548
            Encrypted:false
            SSDEEP:384:dsVFXh7pWm1IW6se3swt/MiqTRhgNDOR14gHRN7ZWzlZHH:uMs4sSk1nDvAvH
            MD5:5942EF33C3D37ACBC0870467D5DB7831
            SHA1:9891A1A6CFDC4A829AFFA551780F925CCA14E639
            SHA-256:9C74F009157A3BB341B363CAA3BFBA8862DFC92928D3AF43200C4471BF6852AA
            SHA-512:47F984B9A6D08FE2C48ECBDC750AED8846E739BDB8E0D1965B625D8B946AE89399645407C36BB41F7189FB9CD4FBC55EE2A35E2A6B5ACCBD67956B9CD710B036
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......p........ ......................................d.....@.............................H....0..(....@...B...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....B...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.694719789676639
            Encrypted:false
            SSDEEP:384:NvlVFXh7pWm1IWx5Afr6mMAVr64b61NU3lH01XvluiPFNkJZXbME/hbIwiTdOCUm:BpADgApB01duiHkJhbMEpcZ5PU0EUcA3
            MD5:025E94ABB7502CA448DC5B137DF0331A
            SHA1:98A2F75EAE810F0C3C8CFF0FFB6F9FD3D453730E
            SHA-256:A8240F066B808613449531BFE257DF022A3987419554A0ED8C6B8C4BC3AAEB96
            SHA-512:8FE9DD555E73F00F99C901FAD18DC06CED2550DCCB806BC56218BE2DD401E73E1E4E4CCA38AB2744F2EA6EA83658B07C60C9C8B4E948D4E04191699D1C35140B
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......p........ ............................................@.............................H....0..(....@...6...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....6...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.139095913949562
            Encrypted:false
            SSDEEP:384:VgnoVFXh7pWm1IWDrVs2BZJ1f+jmei5z6B60Amq6yDx14gHRN7pPzlZ6:ucvrB31f+jmeIz6B60wDPpPS
            MD5:1A73B031287BAA6853F2A8D8AA5F5A8F
            SHA1:E9DA2861CD84960364AEE9F4AB1E9A981240946F
            SHA-256:C981B5F22958DED896F2D2DAADFAB4D533A6D862563DE4790401F49295C9D4E7
            SHA-512:E6DF58DA7E812809C12397CA239384D989FF22C8361EEFB098C00E605E0250239A5E2EC9800A59CB91861A52D291CEB57CF295F43E28EAAD0631F4C8D8873A10
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................e&....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.08892036656604
            Encrypted:false
            SSDEEP:384:vIVFXh7pWm1IWTYppSepDakK5xYhv14gHRN7vR1lCKG:EYZZvG
            MD5:99C0C72FE90DD8CC14AC49423BF6957A
            SHA1:3F31AA0570DB59FD7350AF88F5AC244268517337
            SHA-256:540A4D63AAD97E7BCE21A20B85ECF6DADE727D6CC43AC08D494C671CB4B37FD3
            SHA-512:C929855F17408FBF1CCEDA66980CDA1DA5EECD478E8B3C57E9659A9BA246EA67DC8341684713D1441FED7E13A00D66DC3FD8B060560C9E347B966AA5AD9107DA
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................f.....@.............................H....0..(....@..`<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...`<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.080171353753909
            Encrypted:false
            SSDEEP:384:xyVFXh7pWm1IWjHDPvhHXBRDQHUDrF1/rzLOWY8iwwH9hlnyqpNC914gHRN77Q3h:89RslSWRJ
            MD5:D71604ACFDC531943EBE9F12B0500E24
            SHA1:8D296727FE82448A3530EB7A8D865FD427EFD3C8
            SHA-256:399EC155D374575DF99EFE6166FC331CCC9221A230E6778729B49D72C6050E22
            SHA-512:336254951D198039DFDDD271639FFEDD1C84FAD3FB0F0892C67C89573707C9D20B7AD2CBA6CC40CBE7B0564E24922C3F9D24F6847FBDBE737F4FB89F4E67F19D
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................d.....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28576
            Entropy (8bit):5.454767588126985
            Encrypted:false
            SSDEEP:384:pdVFXh7pWm1IWpobnGAYeBxVHpEXtR5q314gHRN7vjlGs0h:x3Ej/9p0FA4T
            MD5:DB4B018180A9010BC0004075779CD6EF
            SHA1:5CCFA41CE54B89B8961F4B6BE914534B2421D9A4
            SHA-256:4A5C8FEC913AB2C1857F274ACA199A803A7B93D13041AC7C14F2C536253D661C
            SHA-512:434842B12C6F8152EC2A39384F6E1D632F5C1B826423C4F24674376E80B00C20CD1792082EE26834951787AA6B94B21522BA66640BB4206E51EDD1CD54CE0DD0
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................Y.....@.............................H....0..(....@...>...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....>...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30608
            Entropy (8bit):5.4462399147164025
            Encrypted:false
            SSDEEP:384:zcVFXh7pWm1IWKh3l/cdGK089cGOR/uLnsIqCXY1SGL14gHRN7RQ3Jll3huU:U/dE1hk5X
            MD5:A71E513AC800F312D426D3BA7607367F
            SHA1:A1319ABD3E0C6F968EAF5F3D7D97B2BB6FD9D5C7
            SHA-256:0FD756D2AEF58187785A6E506F3D8BE2E11D66CC6314A2FE1A9DDBA0004E06EF
            SHA-512:2327993E0F4A216518C163D67A614F32A6DA87C394911E2510D6CDEC133419264C26DE40E915AF5DFBBC21FEBB6C2D815DBFE92D14F0A018BFE36269B0829C8A
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........N......p........ ............................................@.............................H....0..(....@...D...........T...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....D...@...F..................@..@.reloc.. ............R..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.518044368208673
            Encrypted:false
            SSDEEP:384:IQVVFXh7pWm1IWTMdGDh+F+0DkAv2uJT14gHRN7N8Q3Jll3Kf:HD+eaZif
            MD5:0AEB243715CA50E67AB34B48EB073984
            SHA1:675D51FD4AAE6748835870DC0F5DCC8D15ECF245
            SHA-256:E826EA81FDC7AD89745AEE7C427F4EEB64D0E0510E38234C6FCAB789A244AED6
            SHA-512:EC34F9F1491B89E5D2373CE5DAEF95F88CDF20596DE36AB36F1FEE36F027B22B47D442970D18A27D5EC254330386B29827F19E9C45389135054BC311634C2849
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................X.....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.075329032349387
            Encrypted:false
            SSDEEP:384:pv4VFXh7pWm1IWKn1QHdtfEjyq/D3ySj6rQcCWmXGEZPy//xXUNH14gHRN77BR1b:JMEHj1vm//yL7XKXaR
            MD5:2083368EFC931EDEE0B1BBDA8DA7ECD5
            SHA1:DA815DD18ABA3B874B577184E9A4EA4240B17B72
            SHA-256:F526D856AD47971EEE38057CE1975FDB53AC7319A2BA644AC364E0EC25C03684
            SHA-512:E7699F9347DD277E7F6D598E9A45E054F04888BB04A819EE96D39E1E884CA5D0B4C915CFBCF1F8C1C5BD65AC1F72663D54BE941C76A2FFF2F4A881FF751B6AE0
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ .......................................Z....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.082092984398133
            Encrypted:false
            SSDEEP:384:dqVFXh7pWm1IWXN/BHpAmBV7wX/0FtMW/xn7ELd14gHRN7AKpR1lC7hd:kf8DBf2b
            MD5:DF9329877EC7488FC0606F7C96D2C0E5
            SHA1:8C653FA335A61452D62665153126D5424996388B
            SHA-256:465CEF85BB813157219F47F11143F392FA4EFC78BD61A543A21B23156333FCA4
            SHA-512:13D5EB219C683875B9E1C05EA459278FA0949CE708A641AF6350C4FBA8161366C4CBA3F848474F6ABDDCAEFB4E24186D54D7C201978FAC30A54ADCB5DAFFA06E
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ......................................$.....@.............................H....0..(....@...>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.049864539216793
            Encrypted:false
            SSDEEP:384:Hvaq6Kaq6Kaq6KafoVFXh7pWm1IWgDrq/O9OpMI1npowi14gHRN7vYzlZmV:Vcq/AUTnpowCAeV
            MD5:A8A43C378D4133061907EAB4E38E1F6F
            SHA1:100410CAE573AFF6DA92BDC5CE66602768D13D2F
            SHA-256:9DC4C9CBF1A1E1625F12788BD4DA65FA32F490E20BCF9BC420594FF05EE48B37
            SHA-512:C4C8E69746450BE445D7DC98F7E30FCF0A99EAA841CFD2265AB9F4177E4B334794B1FED8D2D324D4513B89E53165144ADE65700B746703C590EDC035F1C8DFDD
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................Y.....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.488510715575394
            Encrypted:false
            SSDEEP:384:cNVFXh7pWm1IWvUopGYnHaRWEaq5v/MX14gHRN7HR1lCwh6:uJ3nHrEaq5v/MBxZh6
            MD5:D442A2975A566A158315913FA6AFC2BF
            SHA1:958F3F5FC2F71E90105064BC8FC9D49CBEFC99FE
            SHA-256:DC109C0FF701A803E87841624829F7DD41D3E05CCEF01A144E1F9F301AD9FC73
            SHA-512:1BE62FCCB488A2E73FD429DEB637D652D29A7C92F610BCEED87E4B8400FE239DC4C8E8DBA546FEC81A3B4B9ECA7B386CD4CBE5981902DEC61E56DC587B98F526
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ...........................................@.............................H....0..(....@...<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):4.976381247228039
            Encrypted:false
            SSDEEP:384:3qVFXh7pWm1IWgxpmHzwrXoZSW14gHRN77zlZw:SeeHzwDz+7I
            MD5:80BB083A9AC85C265EA66D2AC32D182A
            SHA1:58D9FF68CCB5A605074FF12B6401A55C301C5CB4
            SHA-256:69011BBA80B78E1DFD7C3F0FB5B301DEE68CE4491E56CDF8C0145509C42DF959
            SHA-512:9F98E6E016339404228A163E3D207B1436D119E0226D407555F31F422E85308F787D82A6CD94DD5292D8DBB71D405CB46BFA9D03A4D59D4966A52A137C86D8D8
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......p........ ......................................t.....@.............................H....0..(....@...A...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....A...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.070097535344014
            Encrypted:false
            SSDEEP:384:v67VFXh7pWm1IW5aOzTGEsQYe+I6pEpyFDW14gHRN79AzlZH:SpLaBWo5pEp0D+ef
            MD5:FC838858544D0E726328360966B515D4
            SHA1:CBB70F233ACC897FFA24822618929A98D2F25BB3
            SHA-256:4403B46A2C6057BA81076159FC67CABB3529C3E0F8B61FF905B4EC74CA86FD2F
            SHA-512:B5F0AE1E6C06DC12785EC7236B4DF3B6022A0C0039D999856A2E224BFD423AB0A71A6A6F74957A36AAD8697F120CB2F20B30D5C36C1401593AD449E78444DEDE
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ............................................@.............................H....0..(....@..x;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...x;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.526685456567645
            Encrypted:false
            SSDEEP:384:4BVFXh7pWm1IWYdiXCKIJy4JzYhnEEquL1MG14gHRN77R1lCsd:++KIJy4VYhEEJL1ftBd
            MD5:583EAA3E3D78044CFF06EAC088233942
            SHA1:245A92CEAC71842AF42E615026D7396D31C538C7
            SHA-256:984E540A04A45C294A4A9A643108757CA57268ABD526172C264AEDFA2FDFFC90
            SHA-512:C7FEB17B35743079499395E5570A310EA6EF4A578E23F50370FEBD85E37F6A40E69907115D0CDF19C4E4EFB09FE7AE4F9F96DBFD700E4CD3635434A92CA8069A
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................dz....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.487285712300697
            Encrypted:false
            SSDEEP:384:TNPBbpWm1IWp6PK4xvn+bL/xzr0Y14gHRN7m6zlZJ:Lr6P5nYbxzr08m6x
            MD5:3A1D1D3A70381E27FD7660A717DC5466
            SHA1:77C6C52D3B1F15C85A9DB06F95FA97D30D439FF4
            SHA-256:A0528090B5B8E399BA299A6208D1BB6B4570DB62A0D2B4FBBCCAC7DA3A09A54B
            SHA-512:B6DD30AE844AF32CCC14E557F4B2FC2A25335C05FDE5A714AF0187D5D44245309528D03706AE3CF6E60C1344DF91849215480DA533512DE4BF3D5FD84884E34A
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................J>....@.............................H....0..(....@..(<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...(<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):5.080019744392318
            Encrypted:false
            SSDEEP:384:DLVFXh7pWm1IWNQ7+yHcVQlTUU5Pi5daxch4c5LSFw14gHRN7naVzlZh2:NGXcVQlB5awBKLDSZ2
            MD5:F6C6DE5DA1FD0F2FE3465BCE4D0DAD66
            SHA1:3C76FC0E7460429B54B99F8411A5AD2D900B08CD
            SHA-256:4BBCC263B0903E3BBF8ED0CBE4572622000EF28F8820618CF280CAB2F5EDC10C
            SHA-512:028E639A92E094C15068146952102ED7C266C81398182EEF337D38A8572DF67EC6781838DAD6CFF335AC80250696B24973A424EFE21BBD33A2392E1068B1D083
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......p........ .......................................8....@.............................H....0..(....@..`A...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...`A...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.065799210085844
            Encrypted:false
            SSDEEP:384:kqVFXh7VWm1IWjiOE6kL6xgY+0s14gHRN7fozlZh8k:zIOErMYwB
            MD5:142DDE075B44AD1BC5A39E040CFC00A4
            SHA1:B6E34462E6A42A9922E1983FB49CF9533A326D77
            SHA-256:B8E2582D6B878DBCF99710D7A2BCFD88A4641D9919C89FDB0B23A860DEF7C77D
            SHA-512:5DEB8CA89438638C4B49B7A38A5F557FDC8CDB6889816F7374BDDA0ADD12BEFB0AD0FB5019B5452F201ABCC00D55013A2D353B87C8E93012688F2C5B3D0271BF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......t........ ......................................0.....@.............................K....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.0277148162985155
            Encrypted:false
            SSDEEP:384:2lVFXh7VWm1IWSeGGhJzDKyLgFRZkK6p414gHRN7qcR1lCaf0:Us34zSvh6cqsHf0
            MD5:BC0C6EAEC78A331E2B1AF9D9466ACA1A
            SHA1:B9F98641D0261B2B6181B98744D0EDC34615B213
            SHA-256:1E3280C9CE516D68ED337261E65B5F3F9A86D4B45ED03ED6BF3BB9B723E597E5
            SHA-512:3382B9DEC5AF145DEB51264EF6DDAA11FDEB9E1345E5FCDD234C1255893C65E4C71057BAD1174CA1E3A82ADAB0DCC6ECD4C5ACB487CDD274B6C49BD061F8EB07
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......t........ ......................................?M....@.............................K....0..(....@..@=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...@=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.049654510730145
            Encrypted:false
            SSDEEP:384:O10VFXh7pWm1IWsqN+NPKl5v14gHRN7UzR1lCcc:NKMPl5ZYNc
            MD5:C8046D9657A540D9F401A24E30868249
            SHA1:DF743A8FFB87B36675488D3CF61BEC4A33274045
            SHA-256:1F8D1FD8F767243E0A06889EEDAF06A89A3091F0283791E16CD34DB04980F99F
            SHA-512:251AF9926CA2B347AFAEDF3112D850EF1ADFDDAE55DE35C16D50AA1D54F493FE7C40362045A80E4C33ED6AE74F3AD9A5E8979503120AC173C8F5513F23D6E134
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......t........ ............................................@.............................I....0..(....@..H;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...H;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.0137570799885385
            Encrypted:false
            SSDEEP:384:8YuVFXh7pWm1IWQQ72oJzoBpFPAfsVx1hbjp+PZ14gHRN7zzlZ2cr:+X72oJsBpyfsVx1hHpmzfr
            MD5:141524FC8A86F93BD4F948CBDC0F4180
            SHA1:7FF8DA2F8BED417E6BB6DA4A5BB98832BB86DB06
            SHA-256:1A9DDE05D33A2E96ABB1658AB08D695ED7A5846F11664B93F9AF8FA3BC7E044E
            SHA-512:092605B4A65E4ED89121C48B9A15897300248D38066968C61B1BD44D1ECD88756C3A8397BDF45E8784545858BA18A8B09AFA582D62949BA1BF5120BF3A007CEF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ .......................................|....@.............................H....0..(....@.. >...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc... >...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.506726281268631
            Encrypted:false
            SSDEEP:384:8bVFXh7pWm1IWaFjOvZdkstI+EpRYRYhgz14gHRN7BzlZ7:shI+WSVBj
            MD5:A16FA69AA0B1EA708AE85F761ABC9DB9
            SHA1:D81F370949766F356AD579EDA7A2417A03BB97B9
            SHA-256:DCDEAD957AF80CE7594CC7F67289B79CE37C6B285E420385B75642C04670029C
            SHA-512:8618A398C189015F7D58950CF3BB78AB298688943D8A779926D029F8960A7861B80A52673B02C6C371F9598151394BC11AC20AA7247BC06FF5FC932CB070ED23
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ .......................................[....@.............................H....0..(....@..8;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...8;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.135404679946939
            Encrypted:false
            SSDEEP:384:d3nVFXh7pWm1IWDyZFB9qpA0iFT0ywblr5qJUH14gHRN7uR1lCBBd:PggtPGURKsBd
            MD5:5FE057EA6F306A8D8CC044460D906A82
            SHA1:591AE9EAD68996599119FF5DA7B06D55610E6E5D
            SHA-256:60601E08FE45EEC253C977E5EEE0293DE81E6B524D2705C29C506B2489A0F5E1
            SHA-512:A3EB76A9218D1CF90DE671E152C1B915CA0CDC14BBCADA325F7ED4C77FF202A7A22364546C8E414DD970D8B14F58F89B7EDA137393B0D038E255FD1131E68377
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ .......................................O....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.009900782263759
            Encrypted:false
            SSDEEP:384:QsVFXh7pWm1IWNLUphsWGMYVxJtWFPzm7m4tmkmGkfBQZy8ZK7mBsvYp6NcLoICd:BqQntDkBFsi5k2
            MD5:4D63AB8BD528FCF5D6339665CC55B4BE
            SHA1:EB6AC6B5CD6844BC9E5ED0175AC6286DC5BB057B
            SHA-256:55816FCEE316702FAF6F59D448C696ED27C4018CA1454E4CAF8348D5F9505611
            SHA-512:F8C63CB05B2AFA59209969C71B8578210A6C4EDE04C04584BE4CADEA57B345723CD3C0FB8A9C86CA13F67BF6A0AD19FD8B60B86705119D50553699C3E8803483
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ .......................................;....@.............................H....0..(....@..H>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...H>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.067511119292097
            Encrypted:false
            SSDEEP:384:zxgVFXh7pWm1IW0mY4c4zbqhTwV41LjYBUeuQa14gHRN79QQ3Jll3tqwF:1UOmY1Obqh641LjYBUevaxnF
            MD5:7B532239A16CED0262078578886940DA
            SHA1:3BACE5CF030EB30E2C56E10D0186A24BC3547ABE
            SHA-256:D2566BF0681370D9313671AF76A5D9C317B42F97255B9D290767AE7146CBC80C
            SHA-512:D6512AEBA16C1E195AD6932D3D9B0D5B5E04660D4D95D0CEE9A1D556DA7EA50110383CC6103FF0379455953146DCBBB8971AFF831CCD11A1AF02345198C837BB
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................./....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.480943511048745
            Encrypted:false
            SSDEEP:384:IElVFXh7CWm1IW1Tu2++Wed7gHKM8Uf14gHRN76nQ3Jll3P4h:ILq/fQ7gHF8I6Snw
            MD5:480ED7F260C4DEE3F6AFD6FB2F7A2BBD
            SHA1:EAB92765539ED45B120401126A6A1AA2750D8892
            SHA-256:6D2A9047E95B808E640A4D1B94856ACC30D86C5B2D8ECFEC5B38A09917723215
            SHA-512:253DEC4A5FB20769F6836B4CA476B3006F6E672410C32439F1392EA5EC2669D0117809BB1D5D7546726C313600BE4A92C59BAB86A2AB982602E11F0549BFB6F6
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......x........ ......................................k]....@.............................P....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.474926206358726
            Encrypted:false
            SSDEEP:384:rOIVFXh7CWm1IWC8Flve66SXX5FpMXw5C14gHRN7JR1lCc61vFg:ruHTXXpFGw5i/J61q
            MD5:E904DCA00117E67996FA231621CB844A
            SHA1:FB2CC73E785EC32FA63C5CB51112D69D8D51F221
            SHA-256:438414FA7A4348365576C5BA45ED2C1051F396628BD26A4DBBABFB81D7DA3FCB
            SHA-512:C01657786C15AE6C82B9DCEA35DE73C2DE8BEB9D0CB396004895BD659C9ED25A590AE5D0C753345FA4107F8EBF5B7576117436724A9411590A466A06FA33F5E2
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......x........ ............................................@.............................P....0..(....@..`=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...`=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.061303840468723
            Encrypted:false
            SSDEEP:384:5luVFXh7CWm1IWmdeB8sLV1rh2r14gHRN7LR1lCkQQ:51kdeB8sL3rh2tdzQQ
            MD5:372C4828C5D77C6D4F9387E24696D165
            SHA1:942395E73A7D596FC970983BC7454D993C0196DD
            SHA-256:29F21305FAA9A9F7971B5AE3D19139D25A60CF326FBC03D4D06F131E2C0794EF
            SHA-512:4B7BFBF6C0DF20DFB58EDE65125DED28F90D2498B58ABD49837C42B9B5B1CBE0D442139301DD99CD9D75412419911B0B94C56B48114F1ABB4283E3EFD0A1188F
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......x........ .......................................,....@.............................P....0..(....@..X=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...X=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.472394584016559
            Encrypted:false
            SSDEEP:384:INkVFXh7pWm1IW6Tu2++Wed7gHKM8E14gHRN7yQ3Jll3O:0Yj/fQ7gHF8QZ2
            MD5:0E7111E4DDE070EB1599A88F473E286D
            SHA1:4978569C1E44150E4C599B169BD2C239D98E0A25
            SHA-256:301B76D9920AF43D006DE528C35932AE8914048D7D1E0F2FA17A06AD516B4512
            SHA-512:B06042292B8FF95D80BFA17D0D33EEFA05BB4BA5C422425776A166DD87EA53254667ED27B520AEAD0AC70DF287A5AD609145750A7E1866A040C95798E713445C
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................b.....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.013223504039355
            Encrypted:false
            SSDEEP:384:4QtVFXh7pWm1IW5j5l8M0yD/U958fP14gHRN7ejR1lCfKt:H/T83y4b8f5Y4Kt
            MD5:E3284BB7177F1BB3CFAC848C7E696714
            SHA1:6ABC27B727A1BF5180194F985E8B6772D4BC1B08
            SHA-256:445F73A610E76EC62E851846B9744BC0800EB9E90DB42552E3DFEE6D5ADA8E54
            SHA-512:CC7CED92953B5FA6A447BC927AAB1B559424BD76BF8EF450E9D7529A5E66A5F0EDC21C48EC461E4E6CB87B81B702113CD0043287516F8D85260D8F0BA40E12F4
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ....................................... ....@.............................H....0..(....@..P<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...P<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.580548621346359
            Encrypted:false
            SSDEEP:384:IAVFXh7pWm1IW9uoVfjuXVfMf2SXRDkcYM14gHRN7ADzlZx:ZDuoVfjuXVf+2SXRDkcY4AD5
            MD5:ADEDD303534101D2398C58BB8D03234B
            SHA1:97B288790014DE5C58F59E0F9D7C1C70BB67BBD0
            SHA-256:8230FA24866080C85FBB23868C310D7FA8170996C8537615DAE234191D4AA9A6
            SHA-512:9C5708E904076F601417CDC4AF8D7F390CA46C31EE43A7FD336C87A1611575FC796D2A01D2BA3CE5AE124258857976436BCFEDA99385B25A1E8247F6E45459DF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................!.....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.523235355820772
            Encrypted:false
            SSDEEP:384:JAVFXh7pWm1IWiUhBBeTuQbepP/NFd7ygOffu14gHRN7vR1lC1m:ugUhBBeMP/fd7ygOf+Zsm
            MD5:29B940BFBC2809D9CD25EBC0A492EE2E
            SHA1:6C8E91ABBD17381BC7CC25341452FBE46AC19E2E
            SHA-256:23715C0190CB1E9FDEC5A931408477AD48C0EAF6DA5B0D2F878194C96356B918
            SHA-512:123431C8C7D9EE56E6A02E519F74F168FB3DB98C1D6A33D8EED9BC414CD151CF6E6175699D532E8FF21F02DF1984EE1F0CE1AF9D3E59D57A846D0E1F60B168FE
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ .......................................N....@.............................H....0..(....@.. =...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc... =...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.632692089559041
            Encrypted:false
            SSDEEP:384:wFVFXh7pWm1IWzubufuOu8wIxFqutbwfmtRgb3u3axcY4WXh14gHRN7TR1lCwX:OoSG58JxFVtbwfmtRgbe3Z4fl9X
            MD5:8B2467B30C04CA272AEA90775BAF19E3
            SHA1:248D04FD51DA0979428E21DF81F6D366B7B3B1C8
            SHA-256:79989FE4A6A09278147988CEC6A87A939787FE7B71B45495E2E3FC20EF5AC19B
            SHA-512:29700700A4EEC678FE32AD6E0B6C62BD8BDE91395697EC8A5CD61B21784A31DE85BDBACB2CB9621F43F551D2E2FC19B7355176538273CBFD0F1112F360F92B2C
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......p........ ...........................................@.............................H....0..(....@...7...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....7...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.127503597086757
            Encrypted:false
            SSDEEP:768:JmH0Ou6E3mGyf1LV7Z85lerwrI5zyesQ7u2VlwO:JF6E3mGw1L1ZNCIiQy2VlwO
            MD5:27C9C09E561AA6861926EC550406BB2A
            SHA1:597ECC7D65BD0F46B871BBB468DF1EEA7B8F41C0
            SHA-256:7837AA654E1CDA3E853B2E8C86CBA4F73AD2BADAE51537EBBC8B2CA5A582C234
            SHA-512:E86863FD1E854085A12AA0EF7357473E5E6A35700846B17F6356A4924F5E75492729F7499B10AE3A29032DB577869360D52C0DA694270913A414A1224E3E40BC
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................,.....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.536050952562876
            Encrypted:false
            SSDEEP:384:cwVFXh7pWm1IW7Q6Qfd9L8AwXiE914gHRN7bUeR1lCXXw:lg9L85/j5SXw
            MD5:A67A66B824D031F41B973D62530EAAB8
            SHA1:297A13659E6C3136B34599A288FE1742C2A9A646
            SHA-256:A9786B5CAADEFB4540FA0A8D41E293F0A0F3B5D6826C974681BD5953D7881EA5
            SHA-512:61911F2DB63654460B0283514DBA129721EE231BABD57EDDB259F295F1F3D4A3A68E23C06C22C04B0AA5ECB4BC4E644224AEBE0CF11BE882D76FF3438F9D218F
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................P.....@.............................H....0..(....@..h9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...h9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):26512
            Entropy (8bit):5.56032267360284
            Encrypted:false
            SSDEEP:384:D9PBbpWm1IWikg1osHo3tNZxWTCT0a14gHRN7+zlZgw:bgQz+l
            MD5:7508A9BB2035430A3B721A2B055646CD
            SHA1:9E9028E28498118B3BC93310BE4D61C7F92D3633
            SHA-256:0D4C1E704369750CEE5CEDFAFEEB77F33D4815997E63CE672ACF330549287679
            SHA-512:D22692CE25361E1EA61433CFA0BA607692E5EBCC6AFD98DD819AFFC294628460C46862A033E36103D985D5852199176E0D6EE91A5138AD064234C27715E0C227
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........>......p........ ............................................@.............................H....0..(....@...4...........D...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....4...@...6..................@..@.reloc.. ............B..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.531808364875229
            Encrypted:false
            SSDEEP:384:8KVFXh7pWm1IWiUFMruYGu8moHPoybE6ya4I14gHRN7MzlZZ2:7g2YbMMY
            MD5:719B575FED0675C17E30ACBF53111901
            SHA1:192ED6FB2411D37D18482C47C2724228FDE95D19
            SHA-256:7070D76B4C711CE52A2E026AB26E8158ED46B8DD8844CAA2B28573EF55B5FEA1
            SHA-512:2C089ACAFBFA71EE25926D500E96AA15CC5821B473D98CD1B035D973D14A0581272ABBE9AA8251C040E74EB51BFF12319F81EB6CFFA159EAD59A2887A119FAE7
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................5.....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.494386311988992
            Encrypted:false
            SSDEEP:384:O/PBbpWm1IWizuZdZZMsCpA/NieavYWr14gHRN7oZzlZ+:igzuTZZMwaYKmm
            MD5:AEE19BA0D1353DDFE58BE036C62A18DF
            SHA1:2E53CF1A7C4C0A1CF7DDAF08E64EAA68B1684D96
            SHA-256:7CEFF8F3E9D590AFF454918906273CD446DC9503E0FC18C72FADE98E3D0CD258
            SHA-512:C0EDC013CE713BD233A3EBC350C176527A6C45963C1B9F559752B8FC285C0FCC5D7ABCDB5DA368416590229130B126D661362FD3DB26ED17A51F33548B8FD419
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ............................................@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.331826150776246
            Encrypted:false
            SSDEEP:384:9MVFXh7pWm1IWpCBnJT14gHRN7C4R1lCIo:WyJ17po
            MD5:AF765CD345C9CFD6EAA6F43592853F7E
            SHA1:967749B089EDCB7D9C4ED866C8392B5C9D168D9A
            SHA-256:F53F72633A0D0148D1E471E2C17075A7BD34B2EA6C09FE78A2B76570FC35C751
            SHA-512:100E23F0DD363F8372BDDF74FE51F84420A8F67CDA68A1D12A822CEB8B89581518FB9713CD2A7A2DF54278870FE8C8F9B9B1BDF7BC18AE09BAC84407A27513DA
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................}.....@.............................H....0..(....@..x9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...x9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):20880
            Entropy (8bit):5.987637889684451
            Encrypted:false
            SSDEEP:384:B4KVFXh7VWm1IWCIHtnp14gHRN7ZnR1lCkn:bUIHtnnbhn
            MD5:C710D576ECD456F7BB088F4458620809
            SHA1:9B85812F1971E23281D58697D66BF21A95BFE690
            SHA-256:14914692C2B576BD26132B5EF3FFB1F17512377881C13972A3362F4F5202D10C
            SHA-512:8FCDBEBBF7B94735AE3DF3CE904753F1B1D6F65E9FF3A3DF20748D45DECD1C19D60FE5B9E10AEB015FFA9BCD9E8057BBF86B98BE79F425A87C7EEA33F3034FC0
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........(......t........ ...............................p......M.....@.............................K....0..(....@..0................#...`.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...0....@... ..................@..@.reloc.. ....`.......,..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):20880
            Entropy (8bit):6.016334298139521
            Encrypted:false
            SSDEEP:384:NxJVFXh7VWm1IW7gu14gHRN7JQ3Jll3Rb:jlg2c5b
            MD5:EAE6A96B835B1BF4C44DBAD036339CF1
            SHA1:2CD7E4C3007BBE1C249108DED592FE6E1F68F612
            SHA-256:4A68372E6CEE6C78AB6875457236256D0632150B4754404788B107BB44B5DEDE
            SHA-512:D4A1D904623D03D1AB6543A9FC7A2680A8A1497134DD48E67E44754C4159AC62AADE2526627B5F6A9CDD642B8F9E1829E648EA10D3F17477E792489855F8112B
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........(......t........ ...............................p............@.............................K....0..(....@..H................#...`.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...H....@... ..................@..@.reloc.. ....`.......,..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):306064
            Entropy (8bit):6.36823015650917
            Encrypted:false
            SSDEEP:6144:Dvau4VkA+DDpAu4Uy1AtMeUHZW5qAuORz+AOzLZ9KmFv/aqrN3xk8:+u4yAgDx4Uy1AtMevuOR6NLDK6BN3xk8
            MD5:F1470ADC12C0B896DD11F0647344C17D
            SHA1:00446F5D4107185D79D72BB10C932DB81A23B624
            SHA-256:6C9FAD496A1F487200F8CC89592CFE46BDD82084E0A2BA3C09DF96418B500E42
            SHA-512:26B49204B4E9533BE5D31949C0F469C32A1480A30F80E09A8F1489E4B5E2D8E56E99716CDB52F99D8F7DB2D931CE41F3A3CEAD4D8CDB88E0835CB1BC6B3DBE1B
            Malicious:false
            Reputation:low
            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......8..P|...|...|...h...r...h..........m.......k.......,...h...f...h...}...h.......|..........H......}.....P.}...|.8.}......}...Rich|...........................PE..L....G_a...........!.....0...n...... ........P............................................@.................................P...(....0..`i...............#.......1..8...T...........................`...@............P.......... ....................text....,.......................... ..`.orpc...c....@.......2.............. ..`.rdata..4....P.......4..............@..@.data....5..........................@....rsrc...`i...0...j..................@..@.reloc...1.......2...V..............@..B................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
            Category:dropped
            Size (bytes):376208
            Entropy (8bit):6.045202309915156
            Encrypted:false
            SSDEEP:6144:m1OYOIFvV4Oq5SO2H28uzqli/44wz6Aoh1bR7WKJAcg5v/aqEq:m1ORm4RSkDOK44wlodSK5OCq
            MD5:6F9BEFBAE010CD180867218051CD8A13
            SHA1:9B311F82E0AE1438C0DD933CC01208A9CCB8FDE1
            SHA-256:378AB2C06454E4AB7BCD7BF37FA125D4F7AF03E31755173B750339DF31C759BB
            SHA-512:014D9EE288ADEA7DDEAD56FC228D39EE5B8806D99CCD777CB7D9BFAA6F894BB4D482381F53C070634C7B6B7D6E1946636484BCC346A630E32A54CC21971C1145
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........6~\HW..HW..HW..\<..CW..\<...W...8..XW...8..BW...8...W..\<..PW..\<..IW..\<..KW..HW...V...'..|W...'..IW...'..IW..HW..IW...'..IW..RichHW..................PE..d..."G_a.........." .................K..............................................].....`.....................................................(.......`i...@..,%.......#..........D...T.......................(....I..0...................(... ....................text............................... ..`.orpc...$........................... ..`.rdata..............................@..@.data....S.......,..................@....pdata..,%...@...&..................@..@_RDATA.......p......................@..@.rsrc...`i.......j..................@..@.reloc..............................@..B........................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32+ executable (DLL) (GUI) Aarch64, for MS Windows
            Category:dropped
            Size (bytes):341392
            Entropy (8bit):5.888992019871646
            Encrypted:false
            SSDEEP:6144:/5+IesxMv/NL+QPO+ojj2zUAatpZuOzdWbTo6Ms7WKXTGuv/aqLD:oIe9xv+pYOzdWdSKDVZD
            MD5:092914A6DF5AD3C26B949A7FC0242C09
            SHA1:0EFD3B6C017AAF79785442B400A313188746700C
            SHA-256:794F703B2A92297BF27CDDD0E7C3ABD3AD22C48940CDF0A137D25B243F1E7066
            SHA-512:9693C12BB4F22834DB9910E4367C63963510CA65E8673179A4D6794B822D6086ECC50373C61B0F9EEFE1029CCB9BB8D9F639EE8E294FF772AA97E9EC0B9E67B5
            Malicious:false
            Reputation:low
            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......h-.,L..,L..,L..8'...L..8'..L...#..=L...#..%L...#..bL..8'...L..8'..-L..8'../L..,L...M..<...L..<..-L..<E.-L..,L-.-L..<..-L..Rich,L..........................PE..d...!G_a.........." ................X{....................................................`.........................................pf......(g..(.......`i...............#...p.......3..T....................3..(....1..0....................U.. ....................text.............................. ..`.orpc... ........................... ..`.rdata..@...........................@..@.data....P.......,...N..............@....pdata...............z..............@..@.rsrc...`i.......j..................@..@.reloc.......p......................@..B........................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):306064
            Entropy (8bit):6.368480596125887
            Encrypted:false
            SSDEEP:6144:uvau4V8o+Drp4WAcy1AtMGkH+2W5q4uORr+AO1p89KEFv/aqrN3xi:/u4qogrhAcy1AtMGbTuORCvpiKUBN3xi
            MD5:53C292F0750122F03F8D1272FA890392
            SHA1:6800D50A1805783E181DEF21026E7CFEC74193A2
            SHA-256:100F692A1F4F36043394EAB4B77CA1CE1C55DF7C1277CF323ED23B5BAAE5A020
            SHA-512:5DD78C603195F5DFE19D985E40CB14FA5318AEDC789F3B219A906F4C698DE00378CD4FBC6722A465F9CB2714A987ED711A8350359AE1AFA581CF41EA66CD8099
            Malicious:false
            Reputation:low
            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......8..P|...|...|...h...r...h..........m.......k.......,...h...f...h...}...h.......|..........H......}.....P.}...|.8.}......}...Rich|...........................PE..L....G_a...........!.....0...n...... ........P............................................@.................................L...(....0..`i...............#.......1..8...T...........................`...@............P.......... ....................text....,.......................... ..`.orpc...c....@.......2.............. ..`.rdata..0....P.......4..............@..@.data....5..........................@....rsrc...`i...0...j..................@..@.reloc...1.......2...V..............@..B................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
            Category:dropped
            Size (bytes):376208
            Entropy (8bit):6.045099929766453
            Encrypted:false
            SSDEEP:6144:+1OYOIFvV4Oq5SO2H28uzqli/44wJ6Aohvbz1WKfAcg5v/aqW:+1ORm4RSkDOK44w/op4KnOg
            MD5:952FE51CE5A72FD464095EC3C7AD1AD7
            SHA1:AB106F65B5E78B2FF5EFED25FF0EC0234EB59F61
            SHA-256:311AF22D1005B320EFC0725B14785AA1024938E1AC185B7BCD24007CC1D22349
            SHA-512:77640844BED8463BB43600F9150B1C40B37C4898203CF5FDEBCE96F9E2DFFF0D02C21B4A48A638F39E2A679B656757660F2E67DE4EB2FA28CEB5D59205DF5C6C
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........6~\HW..HW..HW..\<..CW..\<...W...8..XW...8..BW...8...W..\<..PW..\<..IW..\<..KW..HW...V...'..|W...'..IW...'..IW..HW..IW...'..IW..RichHW..................PE..d..."G_a.........." .................K..............................................F#....`.....................................................(.......`i...@..,%.......#..........D...T.......................(....I..0...................(... ....................text............................... ..`.orpc...$........................... ..`.rdata..............................@..@.data....S.......,..................@....pdata..,%...@...&..................@..@_RDATA.......p......................@..@.rsrc...`i.......j..................@..@.reloc..............................@..B........................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32+ executable (DLL) (GUI) Aarch64, for MS Windows
            Category:dropped
            Size (bytes):341392
            Entropy (8bit):5.888923069144354
            Encrypted:false
            SSDEEP:6144:dU+IesxMv/NL+QPO+ojlJiUAatpZugzdsbWocMs8WKcTUdv/aqeJ:fIe9xvCpYgzds+pKMscJ
            MD5:9C752C6ED66470E25D469CCC3F28E000
            SHA1:EF184022D3ED0684DF6C73D371DDAAE6F7FCF81B
            SHA-256:C8493BA63526B5BD4CC8422ABB3A8A8679FE42D6BE8F4A09E071A016D2D0BDB1
            SHA-512:FC62F0BF88EA83CFB1D79A057DFC0D0B155D1EB22B6C073470CBB6A52E2C2D8315C0BB1F86BBB728B67B260E9EE89DC2CFF704197B4AA40F5715AC92E05C05AE
            Malicious:false
            Reputation:low
            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......h-.,L..,L..,L..8'...L..8'..L...#..=L...#..%L...#..bL..8'...L..8'..-L..8'../L..,L...M..<...L..<..-L..<E.-L..,L-.-L..<..-L..Rich,L..........................PE..d..."G_a.........." ................X{..............................................`.....`.........................................`f.......g..(.......`i...............#...p.......3..T....................3..(....1..0....................U.. ....................text.............................. ..`.orpc... ........................... ..`.rdata..0...........................@..@.data....P.......,...N..............@....pdata...............z..............@..@.rsrc...`i.......j..................@..@.reloc.......p......................@..B........................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):214928
            Entropy (8bit):5.63023795365664
            Encrypted:false
            SSDEEP:3072:ZgNpVWuxi/7gKNkhSC+t+MMCTs0kH+Bkx6uyXnZeiB+P+HNmYy95ZbmEfhzrgeoX:F7gKNkhSR/5kHouyXnZhB+x8WHW
            MD5:0F11E6717C1FE6DD20AE2D12F63AF3F7
            SHA1:B7F856842320D7BE1E4D6E098B979B4658092742
            SHA-256:6737D628504E1AD1B117600383D137BD975F51D0CDF351F6FDB9C714EDB45D14
            SHA-512:A12E4AD5B6DD85CD179BFA0FFA9BF2D958C1217EDCA061534C7A1145DE490180AD62EBB4C7155395530EE5BA7C2169EA0F6FA39499E5AB94A61FE3D693F1EBEF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........w............}.....}.C...}.....y.....y.....y.....}.....}..........Hf....Hf+......C....Hf....Rich...........................PE..L....G_a..........................................@..........................p......|v....@.................................P...<........q...........$...#...P..<....u..T...............................@...............L...$...`....................text............................... ..`.data...............................@....idata..............................@..@.rsrc....q.......r..................@..@.reloc..<....P......................@..B................................................................................................................................................................................................................................................................................
            Process:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
            Category:dropped
            Size (bytes):2792
            Entropy (8bit):5.160495841561298
            Encrypted:false
            SSDEEP:48:c8c1+6KUb81xu6tbsHkRz1+6KUb81xu6tGsHkee1+6KUb81xu6tZsHk81+6PUb8Q:5I81oCsbI81oVs3JI81o0sGR81FuaE
            MD5:7A22D1858A173A960C46D0ACC07B0B92
            SHA1:009EE1A61DFD6A15C22F63FE9BD6EBB766B018EB
            SHA-256:D5266319691639BDC6742AF8A4201E558119F70A34F2D74B74E39309AAC34C9A
            SHA-512:AA9ECC078D970142A4E02F597F42F2FD43B59FA5A77417176668213FFF02241E03004624D898A30657029905A6A7821C2FFE6D5C76D40BC2354EDCC571FDEDDA
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="UTF-8"?>..<response protocol="3.0">.. <app appid="{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}" status="ok">.. <updatecheck status="ok">.. <manifest version="95.0.1020.40">.. <packages>.. <package name="MicrosoftEdge_X64_95.0.1020.40.exe" hash_sha256="0362358f49ffa83305500a248f17337c82daa677559be1717b47fb85a0b38b95" size="110306208" required="true"/>.. </packages>.. <actions>.. <action event="install" run="MicrosoftEdge_X64_95.0.1020.40.exe" arguments="--msedge --verbose-logging --do-not-launch-msedge --system-level" needsadmin="true"/>.. </actions>.. </manifest>.. </updatecheck>.. </app>.. <app appid="{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}" status="ok">.. <updatecheck status="ok">.. <manifest version="95.0.1020.40">.. <packages>.. <package name="MicrosoftEdge_X64_95.0.1020.40.exe" hash_sha256="0362358f49ffa83305500a248f17337c82daa677559be1717b47fb85a0b38b95" size="11030620
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:MS Windows registry file, NT/2000 or above
            Category:dropped
            Size (bytes):12288
            Entropy (8bit):2.78712366527347
            Encrypted:false
            SSDEEP:96:x8fvS9V3rAXcjA6VZkS9oA9fczR+qkqUHvNWLiA1qkqUHvkO:evEZ7JIAasJqJ
            MD5:369BBC37CFF290ADB8963DC5E518B9B8
            SHA1:DE0EF569F7EF55032E4B18D3A03542CC2BBAC191
            SHA-256:3D7EC761BEF1B1AF418B909F1C81CE577C769722957713FDAFBC8131B0A0C7D3
            SHA-512:4F8EC1FD4DE8D373A4973513AA95E646DFC5B1069549FAFE0D125614116C902BFC04B0E6AFD12554CC13CA6C53E1F258A3B14E54AC811F6B06ED50C9AC9890B1
            Malicious:false
            Reputation:low
            Preview:regf........V.S~.................... .... .......................................................................+..om.....T.f.+..om.....T.f.....+..om.....T.frmtm................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32+ executable (GUI) Aarch64, for MS Windows
            Category:dropped
            Size (bytes):164240
            Entropy (8bit):5.78401085275409
            Encrypted:false
            SSDEEP:1536:xdRGOvXRKePiGZWSDy3bNYoyKH+K76sK1aK8Awcghygs84d/qptHswZHkue/XpK0:xdRGOfPiGZWRrN6XcdRDw12HkuwXcYKu
            MD5:F29AB94BAC11CC4650BEFDB29BFF7372
            SHA1:7721A22AD3C1CB74DE854CBA0FD3E751D9743F46
            SHA-256:57A2E3C11E31686E858AD68EE903BCC9E64AE7D12F2DA91C67DF6DF5E4AFFFC7
            SHA-512:D9EA66341B5E5660FAA775ED75C325384B1AAD2085A27FDF0142281E35F6987633CEE07436BA10B0F772FC1C26C26038C79C6B2D886B8D43F8267CD5055066B1
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&8.FGV.FGV.FGV.R,U.DGV.R,S..GV..(R.UGV..(U.OGV..(S..GV.R,R.YGV.R,P.GGV.R,W.EGV.FGW..FV..7_.uGV..7..GGV..7T.GGV.RichFGV.................PE..d....G_a.........."......6...F...... n.........@....................................K.....`.................................................@;..(....................^...#........... ..T.................... ..(...@...0............P..0...`8.......................text...d4.......6.................. ..`.rdata.......P.......:..............@..@.data....1...P.......0..............@....pdata...............@..............@..@.rsrc................N..............@..@.reloc...............T..............@..B........................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):214928
            Entropy (8bit):5.63023795365664
            Encrypted:false
            SSDEEP:3072:ZgNpVWuxi/7gKNkhSC+t+MMCTs0kH+Bkx6uyXnZeiB+P+HNmYy95ZbmEfhzrgeoX:F7gKNkhSR/5kHouyXnZhB+x8WHW
            MD5:0F11E6717C1FE6DD20AE2D12F63AF3F7
            SHA1:B7F856842320D7BE1E4D6E098B979B4658092742
            SHA-256:6737D628504E1AD1B117600383D137BD975F51D0CDF351F6FDB9C714EDB45D14
            SHA-512:A12E4AD5B6DD85CD179BFA0FFA9BF2D958C1217EDCA061534C7A1145DE490180AD62EBB4C7155395530EE5BA7C2169EA0F6FA39499E5AB94A61FE3D693F1EBEF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........w............}.....}.C...}.....y.....y.....y.....}.....}..........Hf....Hf+......C....Hf....Rich...........................PE..L....G_a..........................................@..........................p......|v....@.................................P...<........q...........$...#...P..<....u..T...............................@...............L...$...`....................text............................... ..`.data...............................@....idata..............................@..@.rsrc....q.......r..................@..@.reloc..<....P......................@..B................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):101264
            Entropy (8bit):6.421682089874464
            Encrypted:false
            SSDEEP:3072:CYCkuRieOVETT+jYPnau3fVGAhoAqzB+PCGHW:CYCk3ET+Tu3fC3zB+ZHW
            MD5:EEF652991949DB1FC0D738F520E67551
            SHA1:EF44647E32CD6467F34D156D78735CA44E0FA23A
            SHA-256:F6BDA32E3F3141BECAFB4908F5BEB0A086E17DC585703BCF948C736B2DDB0241
            SHA-512:FABCAAC24645D425DC47E7286A625AD5B88EB2BC14BAC870C9813C53D503BA7B495FE1B94EECF01CB0379185B8FC0393F9DB3DDE0317D3DA7A0DEFA6EFCB3000
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................$.......b.....b.....b.............../...../.n......../.....Rich...........PE..L....G_a..........................................@.......................................@..................................'..(....P..X3...........h...#..............T...............................@....................'..@....................text............................... ..`.rdata...].......^..................@..@.data........0......................@....rsrc...X3...P...4...$..............@..@.reloc...............X..............@..B........................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32+ executable (GUI) x86-64, for MS Windows
            Category:dropped
            Size (bytes):208784
            Entropy (8bit):6.028442358184757
            Encrypted:false
            SSDEEP:3072:o3F4ybfH29tBArqxqrpa9NeKt7/naUmG/WoY46by8lNkNVZwGNL:oyyq9XArqQVaKOLVgohtvL
            MD5:3DACF7CC11DE65C60616DC29C41397BE
            SHA1:525383A5FFF58295760D311F3FA6C09C97F90881
            SHA-256:F38C70879B558C534233995436F822B5038BEB2788F03C9705AB8F6218717888
            SHA-512:FDA5C886D98D76E7DEB2F4B441792E1704ABD8AB3D72893270F55092C873EDBA6D4DC57A2372E162CCEFB7E09906C9C20F24AFF68F92D7BDFBBC3BF2C6219744
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............T...T...T...U...T...U...Tc.U...Tc.U...Tc.U.T..U...T...U...T...U...T...U...T...T3..T..U...T..|T...T..U...TRich...T................PE..d....G_a.........."......b...........U.........@..........................................`.....................................................(....`.......0..t........#...p.........T...................8...(...pH..0...............(............................text... a.......b.................. ..`.rdata..bf.......h...f..............@..@.data...(5..........................@....pdata..t....0......................@..@_RDATA.......P......................@..@.rsrc........`......................@..@.reloc.......p......................@..B........................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):247184
            Entropy (8bit):6.429457453051207
            Encrypted:false
            SSDEEP:6144:RDOufOo7D5csZKxPYC3aBVqu1x47bjAOkIsKTDh+TPCg:zfOuD5csZKxPYeu1x4fjK7Knh+TPCg
            MD5:F40373187E4494F2764CA145A7F9387D
            SHA1:B27EEB366C706977B67F1A2DCDCC361FA5A17B72
            SHA-256:52C865AF24C645166ADD3E6367730108C2A35D1AE58391B52F722542842960CC
            SHA-512:B3551439252BE9B5CA042CDFD4D7E100C87F855FADB7D5763EEEA7E40DCFF97D6AD272B4F0564723DFAFEB01BF039973AA0540EFBF5A8BBB0BA12CC88642BC0C
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Ozt...'...'...'.E.&...'.E.&...'kA.&...'kA.&...'kA.&...'.E.&...'.E.&...'.E.&...'...'7/.'&^.&...'&^.'...'&^.&...'Rich...'........................PE..L....G_a............................F.............@.......................................@..................................D..........H3...............#...... "...3..T....................3..........@....................C.......................text..._........................... ..`.rdata..>U.......V..................@..@.data....'...`.......<..............@....rsrc...H3.......4...J..............@..@.reloc.. ".......$...~..............@..B........................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):101264
            Entropy (8bit):6.420708060641305
            Encrypted:false
            SSDEEP:3072:nXqUuxi6mVETT+jYfnau3fO2guzBoMqjB+PCl5H0:nXqUHAT+ju3fADjB+a5H0
            MD5:26EFCA27BD20C6E20B545AEE72277947
            SHA1:D0C6D65462B2931B9C21E043DFA2425313A19BB8
            SHA-256:081CB7A3D248F004851ADD9413BC2AC5EA7CE21D762F0BD4EE8D088270851C71
            SHA-512:0354944C1431A12252385F4A5762EB8BF7A806DC3AC83DE423C3ECB483943608C461BE7F44EDAA66EB1F7E42533DCE6CB7A0A3F48393F37C9896FC008F6D714A
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................$.......b.....b.....b.............../...../.n......../.....Rich...........PE..L....G_a..........................................@..................................}....@..................................'..(....P..X3...........h...#..............T...............................@....................'..@....................text............................... ..`.rdata...].......^..................@..@.data........0......................@....rsrc...X3...P...4...$..............@..@.reloc...............X..............@..B........................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):1777056
            Entropy (8bit):7.942726812716285
            Encrypted:false
            SSDEEP:49152:VSz3J4vtRV2t+uFnU/GH8zr1cTNfVnWOKGF1gnQTGqqf8:VSevXVI+ZOG1OtRViMof8
            MD5:51E7979AE4FA5381E5020B423CDA7947
            SHA1:D03BC5F93A967AD41C7B61B7B009BDEFFEE4EC7D
            SHA-256:7D139DD9C562A5B9EF9F7D4DDB2CAAB4DC90958DE503E1E1741DEFEB413120DC
            SHA-512:4CF3C73E383FCCF2F916F2947B21F2D17C71629779FBFB11523F852BFF8FC6B9ECE3B07C50D5FE6E98BF8A43DA2872FCBAC420C2E92A1F7B05F6EF7A96A63D38
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......I.c......................................................9..............................................[...........Rich............................PE..L....G_a.....................Z.......t............@..........................@............@..................................)..x....`...................#... ..|.......T...................X...........@...............H...4(..`....................text............................... ..`.rdata.............................@..@.data...\....@.......(..............@....rsrc........`.......2..............@..@.reloc..|.... ......................@..B................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32+ executable (GUI) x86-64, for MS Windows
            Category:dropped
            Size (bytes):110306208
            Entropy (8bit):7.999996106962114
            Encrypted:true
            SSDEEP:3145728:7MsvrQtsnoWqpbQQScuQjW7Db0zVe7C9:7JstsnoWKbuQjW7DbKl
            MD5:21AFA9580781808E816F9F3EC8C54ADE
            SHA1:9A8AC87800CBE70754BB3336F736054FADB00300
            SHA-256:0362358F49FFA83305500A248F17337C82DAA677559BE1717B47FB85A0B38B95
            SHA-512:08BD3354B49E878E395A757254A8A799CEDC1EB076C4E6344A047874C981AD316DDA189D3818E91EC6B25692767352C4EEFF3A0AD774350CB008B80CB00029EE
            Malicious:true
            Reputation:low
            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...q.{a.........."......2....................@.............................p......z.....`.................................................a\..<.......x.......L........#...`..P...tZ..............................PP..8...........P^.......Z..@....................text...U1.......2.................. ..`.rdata.......P.......6..............@..@.data........p.......L..............@....pdata..L............N..............@..@.00cfg..(............R..............@..@.voltbl..............T...................rsrc...x............V..............@..@.reloc..P....`......................@..B........................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:ASCII text, with CRLF line terminators
            Category:dropped
            Size (bytes):4172
            Entropy (8bit):5.1817564359072925
            Encrypted:false
            SSDEEP:96:rYpPbDCkOmjFHFJoirt6d5y9EygHEN80t6d5y9EygHEn:rYnjFHV4U2ygHEN8VU2ygHEn
            MD5:6DD5BF0743F2366A0BDD37E302783BCD
            SHA1:E5FF6E044C40C02B1FC78304804FE1F993FED2E6
            SHA-256:91D3FC490565DED7621FF5198960E501B6DB857D5DD45AF2FE7C3ECD141145F5
            SHA-512:F546C1DFF8902A3353C0B7C10CA9F69BB77EBD276E4D5217DA9E0823A0D8D506A5267773F789343D8C56B41A0EE6A97D4470A44BBD81CEAA8529E5E818F4951E
            Malicious:false
            Reputation:low
            Preview:NOTICES AND INFORMATION..Do Not Translate or Localize....This software incorporates material from third parties. Microsoft makes certain..open source code available at http://3rdpartysource.microsoft.com, or you may..send a check or money order for US $5.00, including the product name, the open..source component name, and version number, to:....Source Code Compliance Team..Microsoft Corporation..One Microsoft Way..Redmond, WA 98052..USA....Notwithstanding any other terms, you may reverse engineer this software to the..extent required to debug changes to any libraries licensed under the GNU Lesser..General Public License.....======....(1) omaha.."Copyright 2005-2019 Google Inc.....Licensed under the Apache License, Version 2.0 (the ""License"");..you may not use this file except in compliance with the License...You may obtain a copy of the License at.... http://www.apache.org/licenses/LICENSE-2.0....Unless required by applicable law or agreed to in writing, software..distributed unde
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
            Category:dropped
            Size (bytes):2792
            Entropy (8bit):5.160495841561298
            Encrypted:false
            SSDEEP:48:c8c1+6KUb81xu6tbsHkRz1+6KUb81xu6tGsHkee1+6KUb81xu6tZsHk81+6PUb8Q:5I81oCsbI81oVs3JI81o0sGR81FuaE
            MD5:7A22D1858A173A960C46D0ACC07B0B92
            SHA1:009EE1A61DFD6A15C22F63FE9BD6EBB766B018EB
            SHA-256:D5266319691639BDC6742AF8A4201E558119F70A34F2D74B74E39309AAC34C9A
            SHA-512:AA9ECC078D970142A4E02F597F42F2FD43B59FA5A77417176668213FFF02241E03004624D898A30657029905A6A7821C2FFE6D5C76D40BC2354EDCC571FDEDDA
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="UTF-8"?>..<response protocol="3.0">.. <app appid="{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}" status="ok">.. <updatecheck status="ok">.. <manifest version="95.0.1020.40">.. <packages>.. <package name="MicrosoftEdge_X64_95.0.1020.40.exe" hash_sha256="0362358f49ffa83305500a248f17337c82daa677559be1717b47fb85a0b38b95" size="110306208" required="true"/>.. </packages>.. <actions>.. <action event="install" run="MicrosoftEdge_X64_95.0.1020.40.exe" arguments="--msedge --verbose-logging --do-not-launch-msedge --system-level" needsadmin="true"/>.. </actions>.. </manifest>.. </updatecheck>.. </app>.. <app appid="{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}" status="ok">.. <updatecheck status="ok">.. <manifest version="95.0.1020.40">.. <packages>.. <package name="MicrosoftEdge_X64_95.0.1020.40.exe" hash_sha256="0362358f49ffa83305500a248f17337c82daa677559be1717b47fb85a0b38b95" size="11030620
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):2500496
            Entropy (8bit):6.836806780972678
            Encrypted:false
            SSDEEP:49152:ludNz2fZHghOpzzU0esw7LPtL0WyKxNxBqHcTxaIF7cYc+T5vGn1v0Ax8U:lgNz8zzUDswdLLTxaIJlcveq
            MD5:10A3F0FBBABCC80F07EF8E6D2FE1F7F4
            SHA1:2FE7508268DD47CB8EE65AB8270BA67973DFE086
            SHA-256:F86E054AA35E6DE35346885D2427BD5C61F380ECAFB5521DF33BBD5C2419906B
            SHA-512:BCA899FE6BDEB499EDE0A9645B95C8E3C9E05568619608ABC00FF6D3634CF3BF2A8ACC2CB151A16EC3EA0112DEC0479F3AE887D7B65CD01C8B74117F2F97D6C5
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........v..b.Q.b.Q.b.Q...P.b.Q...P.b.Q...Plb.Qj..P.b.Qj..P.b.Qj..P9b.Q...P.b.Q...P.b.Q...P.b.Q.b.Qb`.Q'..P"c.Q'..P.b.Q'..Q.b.Q.b.Q.b.Q'..P.b.QRich.b.Q........PE..L...)G_a...........!.........................................................`&.......&...@...........................!.X.....!.d.....!..8............&..#...0%..-... .T...................<. .....P...@...............0..... .`....................text...r........................... ..`.rdata..............................@..@.data........@!..r...*!.............@....rsrc....8....!..:....!.............@..@.reloc...-...0%.......$.............@..B................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.019844401362494
            Encrypted:false
            SSDEEP:384:utVFXh7pWm1IWMjrY+VDxlwC3j+s014gHRN7+5Q3Jll36:0fmj+sg+Mi
            MD5:37ADB2A5B6CB813A0F8F61523FD44EFE
            SHA1:4140FD1C19DB61F934E5F0E22BF49D3BE710C490
            SHA-256:CBB8C69E9DDBB38241F5AFFDDF9D70497FAA1217B9E46E43ECD7DB80BEEA4155
            SHA-512:A00C56A8E79E6F62EEC83E9A5D264AD714D308190B153DB508C99BE6C6E67CAB21F8281F7AAFDE114C5D99A9673BEBF06EFCAF179EE4A7772FDB2094BC2D6ED0
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ............................................@.............................H....0..(....@..P=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...P=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):23952
            Entropy (8bit):5.784706117270377
            Encrypted:false
            SSDEEP:384:COVFXh7pWm1IWK0Ku8fHN14gHRN7OhR1lCz/S:dPl8fHTO3G6
            MD5:016E63D184B363BC737828E6B0485F42
            SHA1:BBBB6DA4E5162867C5EBE6384EDCC0DC67820796
            SHA-256:C753971FA39446F0359C169BC206FFCACFAB202339B6EB158B74AEAF853B26B4
            SHA-512:A40A0C3EDDA4E38246933EBE6F59033B2119F30E8105224FAD981FA01990A14029513F319478CFA29B78A3E59931105DC659CAFA325EEDA1DD74C41C8444D6D8
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........4......p........ ......................................0.....@.............................H....0..(....@...+...........:...#...p.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....+...@...,..................@..@.reloc.. ....p.......8..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):26000
            Entropy (8bit):5.537377416142749
            Encrypted:false
            SSDEEP:384:B75PBbpWm1IW7YwTYsQ8VGk14gHRN7ORzlZqf:NlUQVrus
            MD5:C44790318E11F4C4DB797E53C5DCF6A3
            SHA1:DD21E47201B02106182854305FD4D0364EF25E0A
            SHA-256:A53120093689BBBDE792DAF49B83A8DF9D4362DF5E37D4601992F67E43265574
            SHA-512:5DC285C463D8E059919BC8C77510C9BC015CBF43FD8460121D97DD4C9FC254B7CCB610528255DCB483047CB667A8744E249A79EF1B44C6BF5416EFB1CAEF8394
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........<......p........ ......................................(Q....@.............................H....0..(....@...2...........B...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....2...@...4..................@..@.reloc.. ............@..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.59276442280315
            Encrypted:false
            SSDEEP:384:yGVFXh7pWm1IWnKnFUFw4sC+7mHuAsuUu3BUF/Dqt96Dc3RRSjJKlF7NH11Vl14I:JoZ4lODuUu3+F/D06DpJK5HZra47
            MD5:9C9DA2427A31601AEAF5DEB98B72B626
            SHA1:E2EF4E64D899D9E2623A047212566B86C420B3EC
            SHA-256:09CE105C0AEC7940AF0BB98B74960908A042652E6958C6CB9E53E0A22B617A0D
            SHA-512:DF9B87AACD9B428F4C63CFB0B9492EFE5C208084C6CF3D09E3A7A024144F5A7D4CEBC1BCF07E8052EFAFE4A32D5E2D824D702EE65B9E2A824B806EA4AF438CD8
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ .......................................#....@.............................H....0..(....@...<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.168745357136877
            Encrypted:false
            SSDEEP:768:kGIOFe5FE5Sn/rtkPFS5OrF9FTFYF+2GIa:kYFe5FE5SzuFJrF9FTFYFi1
            MD5:41005C8A9A21EC93E9002128FA61A111
            SHA1:D821FF7584BBF3EB724CADC0E981A569A721780A
            SHA-256:5DB1FCF0A5910BB20A5620D0623463C2DD4ED36F8E4DEEC100E5E1355BA814C8
            SHA-512:A392280E1C050A6CF384BE3D929ABCCB39BA38532EACDB45BE4C3622B061575A13A34E8FBC90F2DBF23ECCF57D8CBE6ABA07302CDC1E7FFFC574A7A989CEB34A
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ............................................@.............................H....0..(....@..X>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...X>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.432913010195923
            Encrypted:false
            SSDEEP:384:3OVFXh7pWm1IWKdshCCdrwdPMQgv6AnI6gO814gHRN7TR1lCbV/:mcds8CJCgC16MlI/
            MD5:ED3D5BBFA479A3C423045550522EB9F8
            SHA1:6D44D93B8F7C4910CD6FFF16EFD8F58976D60729
            SHA-256:3FACFE5DEA406819364CDCF37FAACC0C7FD8A149DE375164CA241918D01A4F3F
            SHA-512:DDFFBBB1EF96627C5B4895D7C3A76A232FFDEDFA714464E9C67D44093A7E815B9B44285F79AA167BBCF52300E65A142C3A41EBF8E7C1DA8493CA4F4407D65FF7
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ......................................t.....@.............................H....0..(....@...?...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....?...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.570835667857593
            Encrypted:false
            SSDEEP:768:+4vAGEtqtVWCZsnM9/r94amPdQ8J7HPLSf:+IAGE4OhLSf
            MD5:4A0A3ED39B1A810295EAE674657E9AF2
            SHA1:84AE672DF870DC685B6962363C4FC543B68A559C
            SHA-256:3F9BE498101D3181161E24A8700C4B0C777097A50F8C0BEC465D460F63C37F10
            SHA-512:F3F38799FB2FDCA7CE3AA0588B34A45FDA22A10B1CA4DD8A4CEB96EE83DF51998765F04CEA3DD0BF521297AFA27CD83328D9BB34E398016B6700E6ABA51341D1
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......t........ ............................................@.............................K....0..(....@...>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.570475474934581
            Encrypted:false
            SSDEEP:768:4FvAGEtqtVWCZsnM9/r94amPdQ8J7H7HNHA:4BAGE4ONHNHA
            MD5:BE921B8B5F2851E97BD14E71CE23051E
            SHA1:8EA75FEF23AD675ED4F2B3D01215880181981395
            SHA-256:D976062B2BAA5A1B34663860B3DEF90238E71B18A0D9BE5A954CD028C0E0F9BB
            SHA-512:DB75B4B1B28C2521D8CFFB0052916B9FD3B94D0331D4FE348A77BC08B4D707E653264CDD627326D5088DEF432AF61D43F73487B008CB09D1A508D677119507AB
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ......................................Ci....@.............................H....0..(....@...>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.031948379511458
            Encrypted:false
            SSDEEP:384:VdHVFXh7pWm1IW9aDAmqRD0hNLCdJlwcSXp+Uys47p14gHRN7IAQ3Jll3m:vlQ6lwcSXp+Fs4D6u
            MD5:9522A48278DC23AAFD2F4439ABEEF753
            SHA1:9B087433DE727C39A7DE25379CEE1E8D6203C0B5
            SHA-256:11E672754ECD04657FA3C1B9D4F01C5A3279F015922418DC9F5221A1B8985FD5
            SHA-512:96F2042B246C2C65E3E99236EEDA653C5398B0E17093A968605AD6A92A1680B56D23F84C487720FB0439BFE9710B647A7710B640D9642BF483F52F4CDB7956F6
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ...........................................@.............................H....0..(....@...<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):4.994263520844649
            Encrypted:false
            SSDEEP:384:KVVFXh7KWm1IW1bkbOnGNdoFoBGk5S0MEB14gHRN7kQ3Jll3g1:djbkbOnMdKoBGf14T41
            MD5:21E6788B8786324981BC6AE28B505D79
            SHA1:8440D3DB54D4F133C3E7A2BCE281A621977B523F
            SHA-256:B149245D132391C24E9790C384472EE38D5068F804CDDA1AB203DCD4F288A49B
            SHA-512:0146C7126A032414936D198EC801A5ED4514EF7962CBCB2B887A7421C051EC08BC70B93FF5D4D5B261614BB2A73212A2D5CC67BCED3EF56E462B248A417B8E4D
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......|........ ............................................@.............................T....0..(....@..8A...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...8A...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):4.987215583974734
            Encrypted:false
            SSDEEP:384:GtVFXh7pWm1IW8HEWdvDNdoFoBa1ZqSo14gHRN7fKrQ3Jll3i:UqHEWdvpdKoBalsfKG6
            MD5:A0B12220C5A733BC6238495D28269F81
            SHA1:AF8C0AB4287A2D7464FD8C93EB37638CB0840EA7
            SHA-256:335BBED7EFB60E729C2D34D7479593A047F5C426F6804BD8D7B99F455DA84A78
            SHA-512:37ED217799FBF6FB1557623C7C285CA1FB1F2675136BA0C9CC058F6B469D0AB1AD4B74A820AE85BEA6645CBF2DA4A2945A8457CD37FBECFBDF08A339A8154CAC
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......p........ ......................................_S....@.............................H....0..(....@..PA...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...PA...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.134314988603825
            Encrypted:false
            SSDEEP:384:u5VFXh7pWm1IWoTL7PGmxQEnwm/s14gHRN7pR1lC45E:0+TL7xYfN5E
            MD5:3C55C8119C4BEA73AAF9EC3DCCBE7F5B
            SHA1:C3A347EA2B67C5872A2F48A73DB56B5E93F598E6
            SHA-256:6B79A198C5CB2DAF93B2CDD12FF24A71CAE09146A9AED45FE936DC692D4CD843
            SHA-512:68F31F0C7AD220BF823E15564D150607536BB33829BFA97F49A27298DD0492D7D3C309A382F9E560322398178A4BAD579080786FF7C2DAFD0D2127438993A6FB
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................5/....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.041347992126984
            Encrypted:false
            SSDEEP:384:EZVFXh7pWm1IW4tZEmiuTHsyi7zAaaQvWYylVb2UFxOFEdJ714gHRN7zR1lCxDg:26DQIEUjjdJdF4Dg
            MD5:9DE5E5305EB387FF795D1668B3747EB5
            SHA1:07159EEC382A7BC2F344C3788F256653522F4526
            SHA-256:05ACB253F0549033C38AB8C5E2D4E242B1F71AD160035A3B7BC8D7DC0591BB25
            SHA-512:5F4BBBB3EF382C69DA7145EF233C5E0F61EEC4DFE16815A477FD1E668B0BCABE4DFC375AF40BD4E2B297FD0B9EF3215B3F9099EE509664083B1F37B23E6A8386
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................HA....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28056
            Entropy (8bit):5.067596530893269
            Encrypted:false
            SSDEEP:384:nTmVFXh7pWm1IWnHgHcyvBdGk14gHRN7i17s/Al3RX0c:i5gPGwQg/Qt
            MD5:FC5EE545CF8B1CD44614848A1833F5BB
            SHA1:CCED0B62A736CD1D560B2ECCA48E1EA53941D495
            SHA-256:33153B40D17C01DF7CD89E199F81ECA5CF9DB594A16F7C8BF25D45F5E4AE1890
            SHA-512:69E995D467A0C99C50B00724C5AEFBF1954F6000322538AD90815C1C8B87158423AEF6CE9CF7F1001F58CFE1684FF5C3A89314F50F6E4778CA11A2A5881DF8C5
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ .......................................8....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30608
            Entropy (8bit):4.9187196615362945
            Encrypted:false
            SSDEEP:384:4hVFXh7pWm1IWleI4tChj3ZnswxWbP/14gHRN7t+zlZ/:qjeOj3Zn7xWbPJt+H
            MD5:23CCAA642C7F5680FF1158D0F13560F1
            SHA1:5045C9AB63858ADDF86BA4C21492CD60BAFE689D
            SHA-256:FAA0E32772556D7806A9E6C5511A207377FE382AC9100DD44D92086C221106F2
            SHA-512:6D55569319A57E8C6D4B494816006830CA81D8396E9D0A21F26BF99D9641CF8E061BD78D7821536C42EF10EC7980409A7B606953F12920775780093557A107B1
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........N......p........ ......................................A.....@.............................H....0..(....@...D...........T...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....D...@...F..................@..@.reloc.. ............R..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):5.537267322434617
            Encrypted:false
            SSDEEP:384:PjHVFXh7pWm1IWKnBzBUBOTG94vuZtfFtSmFK9q85PgbC14gHRN7XQ3Jll3/8:pkpKxmF51CM
            MD5:25E73EFDF67007784851B0EB3AAD6F42
            SHA1:41D1A351B1341F54B10E47019F7A8AEC8F0D80DC
            SHA-256:C71F98E508724853387E0EFE6DD5C39A133BE23E5EB5D746A0A44E962456A072
            SHA-512:2F28A88024E4C15778CA2113DF2FA40C890E27B95B6D3EDFDA205259433E706FEAA3B2B0DEB99B7917482B60DFFF7F1B69BFD86EEB14BF1963DDDD0B9003B6FF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......p........ .......................................Y....@.............................H....0..(....@...C...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....C...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.085779178023325
            Encrypted:false
            SSDEEP:384:U4CVFXh7VWm1IWakagyvrT/H14gHRN7TVYR1lCWl:Ur1agyvnRT6rl
            MD5:91F1EFA4237B25EF4DE5091A8522CED2
            SHA1:F8CA12373E9DC14DB40E71372BC09B34A84D97CE
            SHA-256:7FB71465F1EBC289AB782EA2731DFC05CDD7E4C951083CFA9A3DA4F055EB8EDE
            SHA-512:5E95C82C0A08AD5D3795A550ADDA6472B34D854B9F1058C95006EF2779A6F48C10B91F4E71F4A25621B7CAD4081C8F24F7EC9A220669D52254D42C9604301930
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......t........ ......................................{.....@.............................K....0..(....@...6...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....6...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.080053021104189
            Encrypted:false
            SSDEEP:384:ZPVFXh7pWm1IWjkagyEl9KR7n14gHRN7bIR1lCv4:TaagyElstbgu4
            MD5:0C372F709DB7D5541961A5766E3DED52
            SHA1:B1DA0E90026A5663751662DAF714545AFA4BD8F3
            SHA-256:495AC5311E57411226F06BFDFCF3F6BEBC33C78B4ED197EBDE6B9CF2BD1D1A9E
            SHA-512:515F6689B0767B3B053D870AFBF1494136AB52214165292FE0D280A6954DC8753AB79AAC0D70A1F26F83768C78F153E8916D1605D4C5BB410E3846BB40222DE3
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......p........ ............................................@.............................H....0..(....@...6...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....6...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.027092985915544
            Encrypted:false
            SSDEEP:384:sETVFXh7xWm1IW8GduUrdaV14gHRN7FR1lCpzn:RBBr47TIzn
            MD5:1ADCAFA26E8A2F54C6D12946D3103C9A
            SHA1:34CFC13AFE66DE9F1632AF1D6525CD265C4739AC
            SHA-256:56B0A8C59CEF12BD3B81828134D7B9403063BCF4C87A9D681FB645E4746F3854
            SHA-512:185F9EB1199B5ABBACA82273392238AFF484050FDF63DE80F34C8B1011AE5CFCF91C6E2D65B3EF656079AAFDBD7D2CA821113DE1A0474C81698F04A6AFF97CAA
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......t........ ............................................@.............................L....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.014692140602505
            Encrypted:false
            SSDEEP:384:XKTVFXh7pWm1IWOti4jOI714gHRN7jPSzlZeS:XeUti4jOIdTSGS
            MD5:DFCD44C2D1636BFFB0A3A0C277CDE874
            SHA1:CC769D021161E269979081D6D7C8D3BA9C45EE13
            SHA-256:3098ADEB8BE598A79D379399E2794B1D27EE4BA2213C051DCB0AEFF1397AE9DA
            SHA-512:D80651B2CBA98B31738AE65E27469F6748DDD0B0D05E42A2AA5FE60CFBCE158C1EB919938FACBD614D8B609A4680D700C37DAE574879797C2BF03186318BB817
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ............................................@.............................H....0..(....@..@=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...@=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.100627170532004
            Encrypted:false
            SSDEEP:384:69K2VFXh7pWm1IWTVc0dEyjE/lX7gid1LFdXjwAiDiX14gHRN7hzlZW:6g+15jE/5gG1LFdsAw6he
            MD5:8C4CD9F4601650DE19B44B30C3FA9FFE
            SHA1:8A9423A07B5C772A6D80E419B3436F0108908DF8
            SHA-256:A159F54C88E6735E9912B9FDECB8C9441F9F41358178CEE9E6C092E6E47E5400
            SHA-512:D46456968948E6F615D544E257945D29D319FC5440D43271D92BF007FC8DF17A52E5F2EA8064A39E881B20B15D0993A689EBB21472EF8413AE32BC0B04D27D23
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................R.....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.050750157064671
            Encrypted:false
            SSDEEP:384:YkpVFXh7pWm1IWpcLpNsX58FOXAzp4O114gHRN7NizlZS:frYKuFOkp4SQ6
            MD5:3233A301AC0DB0EF788FA09F3B1296A8
            SHA1:DC031BB1B85FD83221AC0A985700A3B7C4956EF9
            SHA-256:97AE7D3402E6091F2FD985DFD0A221D22748EC635BAAEE0CB3B7DA6018AAD3D3
            SHA-512:48EDC0AFB00BB0A691C5D5435DB71F74C25BDE0C83DF7352B239E2862A16626386D075DE2E79BD42C326D2EF7E478EF4BB6740D403CE9A80F2A6D82599BC3368
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................j.....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.490034199165937
            Encrypted:false
            SSDEEP:384:woIPBbpWm1IWGXd3EqtOW0QIGf814gHRN7dDEQ3Jll3Z:wxsn8CIxzh
            MD5:2DC5047FF8F6D3EE5FFBE9E8E797EA1A
            SHA1:BE94969A631AC9C37A1DCE0E6B1DE96CC933310F
            SHA-256:77F3F899E10AC718E3A97FD51AD78AF0DC38E08FDDE2A56EB413AE806D819641
            SHA-512:132003C603591FC740A63BCCE985F3358828AEF71408F89E3D44470A9580A3669B1D7A00E3FBC68BF26E827CB5AEDE3BD0F2D9595B47889311DD650DCCBB51D4
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ............................................@.............................H....0..(....@..`9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...`9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.043742836060103
            Encrypted:false
            SSDEEP:384:vPVFXh7pWm1IWcJWHJWEFIxlyELZWEYXSN6ZKFl+EoJth0vDqm14gHRN75rmzlZp:FyJOJkURvu5rmqm
            MD5:3A78D8D434D7DD1157006AD888A30C84
            SHA1:2240A01B9ED7A4DE46778075F79408E1AC447876
            SHA-256:3A2281D948D91578036257F7C0B9C6322A88CD368014A4A42521650F96C298C4
            SHA-512:CD1403B1203ED058265F0DE06C2A38228C278F0021E28F496A82026169C5BAC67BD5EED4E53B917B8E4F1E6CA5B302E6DF2D9E8347F39C03AD2E4A5F7AD5F229
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................?.....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):4.982224545078734
            Encrypted:false
            SSDEEP:384:hZNVFXh7pWm1IWXsXsjNjkbZz9IrJqPDYiuY14gHRN7nzlZsO+:XdsXsjNoFz9IrJqLYT8ng
            MD5:3093FC67671B422E3A9249CBF9534474
            SHA1:42B5AE63D11AD7314E5C9DA5D35E79ED70D60C56
            SHA-256:D1042BD75E7F59BA0DA5BC9F36BC0B749FB1B8FF8EDE3381AAEDE60642A03E4E
            SHA-512:513FE93AE59AB267BA03E679FA7AD683849C0A2CBDACF93FB3D7543B17D9859EB9C19274AA722646EF76E34E074F5CF4424E2E22B92173A89AC6AE86885C0CD6
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......t........ ............................................@.............................I....0..(....@..@?...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...@?...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):4.9700204242854
            Encrypted:false
            SSDEEP:384:qIwVFXh7VWm1IWFs7oaIR3yZ14gHRN7eQ1TzlZj:qdDIqR3y3BNr
            MD5:36AF4C291BFEBD91664919156959C9B1
            SHA1:2A06E2F2443EC68525A816364BD16A2EEFB155A1
            SHA-256:AF50B36C0B6DD39EEAB66EC9F5A57EB9193FEB64B5D036A4CC374702BF8CCDDA
            SHA-512:23F27BAB93014F2374B9DA3071BF31AA4A555EFFA816F34915A34ED639E51B35F93B836130F107203D699D7F4F5C0E8E96C0582ACED16B682551474C1B299742
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......t........ ............................................@.............................K....0..(....@...B...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....B...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):4.961775809823286
            Encrypted:false
            SSDEEP:384:V0BVFXh7pWm1IWF8bEqhiP14gHRN7Bd8VR1lCSt:Vmj8lhi5Bdi/t
            MD5:DCD187DBDAE619DA1ADA587DC7F067DA
            SHA1:5ACA91600D32081B8CF1DED0E666519ED053E6EC
            SHA-256:1F7F8ED1140EE99241E27E3D9A12608F68B94B99E3E6A4717A494509E37B5659
            SHA-512:E4F54C5E411840A5A02CE46D76E4A9D89EFF52C3A47ED989D40EB9B456D36DE23C795304A0B97533432C0071C7BD7C765027147D7A8F79DE8E3DA87E4CBACF73
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......p........ .......................................R....@.............................H....0..(....@...B...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....B...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.032143048556202
            Encrypted:false
            SSDEEP:384:9CkVFXh7pWm1IW45vCQkFYoIoAHscTLGK14gHRN7VNzlZL:9Pe5v6YoIoAHseSqVNz
            MD5:0A2528CEC925BC4E1B0980A641996AEF
            SHA1:BD38A9372C1C750884ACE7BF3D84BA65B4D1BA2E
            SHA-256:EF938AE7242B499CBA81EC167D2493D42120A9FC5E939CF5E91A85A5289E3D93
            SHA-512:34387F4720FD4E6D0F3E352AE8CF1AEF9C54E7BF5058B8C76FE147D6BF7EF44E7205E31F331DA6D9D6708630ED31243D63E9C30CC24C701169CD131C476C5965
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................l.....@.............................H....0..(....@...<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):4.951097819303206
            Encrypted:false
            SSDEEP:384:DSVFXh7pWm1IW5FYiA7VzpfDfqegs2/jgRX14gHRN7ysQ3Jll3Ub:W/FYiA7V9bqpSRB0q
            MD5:37784CE8C8648C4B9EAFEF1B29ED28AD
            SHA1:70F0E8B6583F94E4AAF99B49C66D58675E17C971
            SHA-256:37476C2D99CE936C5AD784E91A96F5FEB85B19A7E1DE78EEABB0336C74B50176
            SHA-512:C077C3A36D4426867B293E5A4B850C17756457E876B3737EFA8F6FCE5C79C93675598313F5CB727578F717AF783F31A069115CD7B937D0A5B4E9B4C8D44F76B6
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......p........ ............................................@.............................H....0..(....@...B...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....B...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.0475255724921055
            Encrypted:false
            SSDEEP:384:qtVFXh7pWm1IWTscDi2RK1HoC614gHRN7IOR1lCkc:MVscH81HoV9Fc
            MD5:7B5456FCB1894496A2155453D0A9FFE7
            SHA1:3F1807CF1B429C4C836AC923F07BF7F30C94B950
            SHA-256:5812BC492A00671AD05796CF02296357BED4A205F2EAE41C3FE540E606FDE8C4
            SHA-512:B2337648FEBA636357448309ABDBC8067E0E51CA80A86759D3A30538CF19DAEA25EA48B9BD6BEE8C70FB69F05A26B8A1CA0E7921AC24FCFFA4BD2FFB4F301D45
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ .......................................\....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.573052423675078
            Encrypted:false
            SSDEEP:384:m7zVFXh7pWm1IWPt7X1QrsojGtCAPPFZdxjACy6xytd14gHRN7rQ3Jll3/:mN3CrwGDGn
            MD5:55725F82EB8831B7BF6267192725177C
            SHA1:545DA7CB05A4379142A9746AED569EC812E7188C
            SHA-256:557E9B3C0C8E13E6C68980A2D7CF2CAA4C8E8314233544A1412535921AAA3699
            SHA-512:9A4EC8BCE7A96B4181D7B6ED50775D2E6512785A57D9511F5B5967BDC8803114C8EB55604EF8ABB421F4D555FD7CDAAD6073756D224A9E072773FCF747B64467
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ............................................@.............................H....0..(....@..(<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...(<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.468809283819709
            Encrypted:false
            SSDEEP:384:7iVFXh7pWm1IWaUQj9qYmsqkK914gHRN7fzlZO0:OIUQxqYmsqkafW0
            MD5:EF945C12CE1248E80B44A6B6B66E6BE6
            SHA1:63543F506F0CF7AB5D12265C65891F42FF03A6E2
            SHA-256:41C9039875AB923D5D90389AE237F6FDE34F515DB68B5D8368A421CEEAF9047A
            SHA-512:ABB92ED17FF33A389F857240ACABFE04A97845D9BABE942A8BE728F0BEE094E2C6B8630D71E4399681CC7E19755C4997013BB02F8ECFDBA2ACA04B0FEE64A015
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ .......................................d....@.............................H....0..(....@..p<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...p<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.071819349247978
            Encrypted:false
            SSDEEP:384:R+VFXh7pWm1IWt/fbmNCCa9PNV8qaX/jt14gHRN70zlZ9:sosDJ0//0V
            MD5:E3AE3F74A9CFB3F69A450F5634AC829B
            SHA1:463EBBB4489F7545D064EC89B5CCC1996D09FF16
            SHA-256:7FBFA700C530E673D5A00C9CC1DAC00AE703050F6BDDC386E473454148E5C677
            SHA-512:29D92DF378AA1B94C287F19ADE48BE2DBFDAE567FD6660630F45CB7F7B7983E6A9312072DCA72438ED2A36010C3EAAD78EF9D3164A9E79A0DFB90059489C6CAA
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ .......................................Q....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.074176707522236
            Encrypted:false
            SSDEEP:384:A8VFXh7pWm1IWWYhYkZ2hUrVyh8bfkWupxitLbufJHwHBNJV14gHRN7xFQ3Jll3d:1fKkZ2hSVyh8+i5bufJHwhNJ7xI1
            MD5:41441A0614DDC6F587BFF4A23BD02B6D
            SHA1:38EDD14A9B7888CA3D321AE6E8126E56D16A36A6
            SHA-256:96165BBAF85FBC23692E8F36252535B9040BC1B3B023C5979EA532FC04CB4FEC
            SHA-512:5C402B5B983667D395B7EA608C60804F975DFCCF4BEB0311DDA27C36155C6ADDFD874299F11B495A43B240AFE4DF0CAD9B9C13FAC5A20475497C9AD55C1D73AD
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ............................................@.............................H....0..(....@..p>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...p>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.071853352350367
            Encrypted:false
            SSDEEP:384:WzVFXh7pWm1IWXPC8kbhT9rLVcBQCOG14gHRN7rQ3Jll30:uBtPGc
            MD5:22A4ED2EC54EFA967A66F65E619936BB
            SHA1:E5366EBADC15A49B402E72A2C420855BDE46F5C4
            SHA-256:2216FC1F7713F800D2E0FBC627D2D6C843AFD1692A8002A42C7C39667049CB90
            SHA-512:2A598CC548FE73667BF301EBC3861A1132706FFD14686645B11599AA706EABED212ADDAD3155C69C5A6CAB229CD08C8123F8CDA4B40487892318AC8C00037A33
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ............................................@.............................H....0..(....@..h9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...h9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.133639891686493
            Encrypted:false
            SSDEEP:384:liVFXh7pWm1IWWz2D29UHVm5TpA40XLai+8wo8SKkGIokBZpO3kTPSfc14gHRN7c:wsBqQ5TpAhr+8wh0xo8pGkTPRNu1tF
            MD5:1D51E5246374433B6A7BEBFC844E0EA9
            SHA1:088300E92CDE509179D2FCFD985EC9EF3AE4AFBA
            SHA-256:6C0EA6BAE2C71598C8460C3F395A4A9FF8686B202999EEA809D5A18E56FDF080
            SHA-512:18D70D59D2471D42374AE08F873FF407674716B0F6195B5772FA97F34282797FD9C78BB9AA10BB66853C9BB497AF930CAFA40B07F73401E6C06D854B2EECB07C
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ .......................................M....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):4.981393397902628
            Encrypted:false
            SSDEEP:384:egVFXh7pWm1IW6uu1+psJfo914gHRN7uyQ3Jll37v:r61+pCfcuZ7
            MD5:1BEFA33963448D7DB02105C360AC2B78
            SHA1:8DF3D755E505AFE5820B3DBB93190C30BDC431FF
            SHA-256:EFA8D3EEFC6090FE944407F1C084B21176B4D5AB39D73E8E1F408027525F58A9
            SHA-512:951FFFEE06A854D14FEF120BF36CA2F6C8BE276D85A10E327A1347A5D5C69B682B6E3ADE1DF0BD09F87404B371A36153C2C0ACF970496A1A3E007BA3894BA361
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......p........ .......................................f....@.............................H....0..(....@...A...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....A...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):24976
            Entropy (8bit):5.6625602261455334
            Encrypted:false
            SSDEEP:384:Ie3PBbpWm1IWxbW1x4SCJl4LGA/t2QL14gHRN7EzlZf:9PcCHYEH
            MD5:4561C4DE2A2099DB54708E39D74E6EE2
            SHA1:1C915384C9F44827BD4EA5A8DC4A661A5B73D5FE
            SHA-256:A91DF3135FC0D1720A4FF08E931482E1B082E8F90BEBACCAFA8C70CD95C3AF1B
            SHA-512:C5E3F730E9D180C3964811ED74B2A8A3DA9EB3A4939298488077E4BBEAECBAF3D88172C36914E2F7EF778D1A793600D67B791C604A8A5E09CA9359EB1BE511BB
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........8......p........ ............................................@.............................H....0..(....@..X/...........>...#...p.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...X/...@...0..................@..@.reloc.. ....p.......<..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):23952
            Entropy (8bit):5.825448963144067
            Encrypted:false
            SSDEEP:384:rTVFXh7pWm1IW/9Vu2/JuQX14gHRN72jszlZqh:187Q2YSh
            MD5:3F84FC101468952D6FFD225795C9D970
            SHA1:7782DEDB4EF9889A947A288355900EF5F69D27A5
            SHA-256:A865887FA427EEEB9E14591161DFB115097DC76E8BD072D838D95D8AA7F362A3
            SHA-512:1AA052D0B32411363E00FA6E53A4851AD022E0849A995447073BED9657F90212107098A6B46B62800EF0BAF20FE181746480ADD9B887CF5C0576395026E1D8B4
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........4......p........ ............................................@.............................H....0..(....@...*...........:...#...p.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....*...@...,..................@..@.reloc.. ....p.......8..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.578965423095346
            Encrypted:false
            SSDEEP:384:WSVFXh7pWm1IWJodoA7s4THmtl4cA+kq14gHRN7S5qR1lCEq8:1IBKkuVT
            MD5:B047AC273A9151860D68A5DD606C368C
            SHA1:287502C4765719E5184C4BF748A214F0CF1F0693
            SHA-256:7EE1FBD8A2AF38356492D930EEF90534E075993804458FF70A805F5411FF9132
            SHA-512:6C8C667F5E6D6336E7EEB52608820B31AFBA35FFBFE70CBA36C12FB8DB450CE240B113B9987FE9B5237DE92F4953A91C5853A7381B2BC6762D6745ABC5C8CF3D
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................F.....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.51196589426949
            Encrypted:false
            SSDEEP:384:90TVFXh7pWm1IWm9RsvJQwt14gHRN7mLQ3Jll3e3:6ALsvJQwzxm3
            MD5:481484EB1C2A00F407D94BFDDCD03686
            SHA1:F84DB37DC7F2D9FB609225BD6D2C4E7A4A923DCD
            SHA-256:A8AF974ED6056E1D257C9B9205716C0794722521DD6FE902F94A4878F582E8A5
            SHA-512:B985999D2B0E19A61F5D30CFFBF6E0DBCFAED64CD51E27ABF74F440EFFE0F052A73F2ECC5062991A5B60557C248ED951A90F182BAD1A23CD22A345864A2E33CF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................>.....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.740190965039821
            Encrypted:false
            SSDEEP:384:1gEVFXh7pWm1IWSfJoxeUnPcse7ceGBAuOCNpkc14gHRN793Q3Jll3Zsy:/hxdPxe1GBAuN/ko9i/
            MD5:7F85D2DAF4437A918A31854075872912
            SHA1:868F838F0E88CC3B289E471CF39C14952072C287
            SHA-256:95F7BA62E5E1F2FABDC7E8AC5DFE32D7837B6CBE7182FE90453A9CC5BFA66E33
            SHA-512:F0F929E747E27939E505F89CF77BA2DAFCC9E69D8BAB846347E1EEFA16F51AF15B5C82DE9C82C0161350C10E5013034DB3E2E8928A8414FC8449714298CA90BC
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......p........ ......................................:.....@.............................H....0..(....@..H7...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...H7...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.639263652622013
            Encrypted:false
            SSDEEP:384:8MVFXh7pWm1IW6QdbSMXPHw714gHRN7xzlZ8:xoQB6dx0
            MD5:4D738D3E26AC09DCD6DD6977B5CE1979
            SHA1:EF6C0835F0613A70B984E621A60148E9579B0E67
            SHA-256:A196D8429FCFC43DD930F0EC54A7CCEAD33DCE7E618A598F8ACA45949A47E5BA
            SHA-512:C5DA65708240C349D3299C3D9C81076EA3917FD831938B827C7BDD5552F4D29A8B228948BA6DA03DD11AFE1AEE37280BBABAA86EB9630652CC34EEDBD9CF45D8
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ............................................@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):22928
            Entropy (8bit):5.951860698702779
            Encrypted:false
            SSDEEP:384:TrVFXh7pWm1IWmlte7yuVDeYhHNjLUJCB1SGGgrxYQ8pDuZ14gHRN7STQ3Jll3A7:VMF+OWFx3Xk
            MD5:938CC55126A99CEC15203772300FEE32
            SHA1:1C7CA3347278D901B499C5033892131676D212CC
            SHA-256:0C327F1F7EA95B7B2A44A395B05F361763E2B58A56DCFB2141518B6804C0132C
            SHA-512:4E9285CA447D255EA0B8427F88139416579814A527B4694E14EB4A9B0B8284DB8D7932C6E1164CF48B4BEBE56449A99F6852C277E2ACE33A84DEE2EEC305CEAB
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........0......p........ ......................................Z.....@.............................H....0..(....@...&...........6...#...p.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....&...@...(..................@..@.reloc.. ....p.......4..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.540539050370516
            Encrypted:false
            SSDEEP:384:N0n7VFXh7pWm1IWBRr+hjZ+hjgOcWtGQQ14gHRN7V8Q3Jll3CI:qpQMLI9VL6I
            MD5:FDE6E86F87C4CEA5B9900F03E70DF575
            SHA1:9520A07D407B4E52B07CE6E98D957910CFCEBEE5
            SHA-256:952975C3CDD8ABC35E49AF273BFCAF8BDB54B0A232AB1E51DAE0FBB52AB89A72
            SHA-512:B5BDF29D5B782C92A224E475E3E32E67BE084012FA112590B3B5E3F4CBE4D321C9F97FC82901AF1752C9F01DB00DD790FF58C7A5446886820E0127D2938E2489
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......t........ ............................................@.............................I....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30096
            Entropy (8bit):4.978483898492548
            Encrypted:false
            SSDEEP:384:dsVFXh7pWm1IW6se3swt/MiqTRhgNDOR14gHRN7ZWzlZHH:uMs4sSk1nDvAvH
            MD5:5942EF33C3D37ACBC0870467D5DB7831
            SHA1:9891A1A6CFDC4A829AFFA551780F925CCA14E639
            SHA-256:9C74F009157A3BB341B363CAA3BFBA8862DFC92928D3AF43200C4471BF6852AA
            SHA-512:47F984B9A6D08FE2C48ECBDC750AED8846E739BDB8E0D1965B625D8B946AE89399645407C36BB41F7189FB9CD4FBC55EE2A35E2A6B5ACCBD67956B9CD710B036
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........L......p........ ......................................d.....@.............................H....0..(....@...B...........R...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....B...@...D..................@..@.reloc.. ............P..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.694719789676639
            Encrypted:false
            SSDEEP:384:NvlVFXh7pWm1IWx5Afr6mMAVr64b61NU3lH01XvluiPFNkJZXbME/hbIwiTdOCUm:BpADgApB01duiHkJhbMEpcZ5PU0EUcA3
            MD5:025E94ABB7502CA448DC5B137DF0331A
            SHA1:98A2F75EAE810F0C3C8CFF0FFB6F9FD3D453730E
            SHA-256:A8240F066B808613449531BFE257DF022A3987419554A0ED8C6B8C4BC3AAEB96
            SHA-512:8FE9DD555E73F00F99C901FAD18DC06CED2550DCCB806BC56218BE2DD401E73E1E4E4CCA38AB2744F2EA6EA83658B07C60C9C8B4E948D4E04191699D1C35140B
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......p........ ............................................@.............................H....0..(....@...6...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....6...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.139095913949562
            Encrypted:false
            SSDEEP:384:VgnoVFXh7pWm1IWDrVs2BZJ1f+jmei5z6B60Amq6yDx14gHRN7pPzlZ6:ucvrB31f+jmeIz6B60wDPpPS
            MD5:1A73B031287BAA6853F2A8D8AA5F5A8F
            SHA1:E9DA2861CD84960364AEE9F4AB1E9A981240946F
            SHA-256:C981B5F22958DED896F2D2DAADFAB4D533A6D862563DE4790401F49295C9D4E7
            SHA-512:E6DF58DA7E812809C12397CA239384D989FF22C8361EEFB098C00E605E0250239A5E2EC9800A59CB91861A52D291CEB57CF295F43E28EAAD0631F4C8D8873A10
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................e&....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.08892036656604
            Encrypted:false
            SSDEEP:384:vIVFXh7pWm1IWTYppSepDakK5xYhv14gHRN7vR1lCKG:EYZZvG
            MD5:99C0C72FE90DD8CC14AC49423BF6957A
            SHA1:3F31AA0570DB59FD7350AF88F5AC244268517337
            SHA-256:540A4D63AAD97E7BCE21A20B85ECF6DADE727D6CC43AC08D494C671CB4B37FD3
            SHA-512:C929855F17408FBF1CCEDA66980CDA1DA5EECD478E8B3C57E9659A9BA246EA67DC8341684713D1441FED7E13A00D66DC3FD8B060560C9E347B966AA5AD9107DA
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................f.....@.............................H....0..(....@..`<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...`<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.080171353753909
            Encrypted:false
            SSDEEP:384:xyVFXh7pWm1IWjHDPvhHXBRDQHUDrF1/rzLOWY8iwwH9hlnyqpNC914gHRN77Q3h:89RslSWRJ
            MD5:D71604ACFDC531943EBE9F12B0500E24
            SHA1:8D296727FE82448A3530EB7A8D865FD427EFD3C8
            SHA-256:399EC155D374575DF99EFE6166FC331CCC9221A230E6778729B49D72C6050E22
            SHA-512:336254951D198039DFDDD271639FFEDD1C84FAD3FB0F0892C67C89573707C9D20B7AD2CBA6CC40CBE7B0564E24922C3F9D24F6847FBDBE737F4FB89F4E67F19D
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................d.....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28576
            Entropy (8bit):5.454767588126985
            Encrypted:false
            SSDEEP:384:pdVFXh7pWm1IWpobnGAYeBxVHpEXtR5q314gHRN7vjlGs0h:x3Ej/9p0FA4T
            MD5:DB4B018180A9010BC0004075779CD6EF
            SHA1:5CCFA41CE54B89B8961F4B6BE914534B2421D9A4
            SHA-256:4A5C8FEC913AB2C1857F274ACA199A803A7B93D13041AC7C14F2C536253D661C
            SHA-512:434842B12C6F8152EC2A39384F6E1D632F5C1B826423C4F24674376E80B00C20CD1792082EE26834951787AA6B94B21522BA66640BB4206E51EDD1CD54CE0DD0
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................Y.....@.............................H....0..(....@...>...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....>...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):30608
            Entropy (8bit):5.4462399147164025
            Encrypted:false
            SSDEEP:384:zcVFXh7pWm1IWKh3l/cdGK089cGOR/uLnsIqCXY1SGL14gHRN7RQ3Jll3huU:U/dE1hk5X
            MD5:A71E513AC800F312D426D3BA7607367F
            SHA1:A1319ABD3E0C6F968EAF5F3D7D97B2BB6FD9D5C7
            SHA-256:0FD756D2AEF58187785A6E506F3D8BE2E11D66CC6314A2FE1A9DDBA0004E06EF
            SHA-512:2327993E0F4A216518C163D67A614F32A6DA87C394911E2510D6CDEC133419264C26DE40E915AF5DFBBC21FEBB6C2D815DBFE92D14F0A018BFE36269B0829C8A
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........N......p........ ............................................@.............................H....0..(....@...D...........T...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....D...@...F..................@..@.reloc.. ............R..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.518044368208673
            Encrypted:false
            SSDEEP:384:IQVVFXh7pWm1IWTMdGDh+F+0DkAv2uJT14gHRN7N8Q3Jll3Kf:HD+eaZif
            MD5:0AEB243715CA50E67AB34B48EB073984
            SHA1:675D51FD4AAE6748835870DC0F5DCC8D15ECF245
            SHA-256:E826EA81FDC7AD89745AEE7C427F4EEB64D0E0510E38234C6FCAB789A244AED6
            SHA-512:EC34F9F1491B89E5D2373CE5DAEF95F88CDF20596DE36AB36F1FEE36F027B22B47D442970D18A27D5EC254330386B29827F19E9C45389135054BC311634C2849
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................X.....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.075329032349387
            Encrypted:false
            SSDEEP:384:pv4VFXh7pWm1IWKn1QHdtfEjyq/D3ySj6rQcCWmXGEZPy//xXUNH14gHRN77BR1b:JMEHj1vm//yL7XKXaR
            MD5:2083368EFC931EDEE0B1BBDA8DA7ECD5
            SHA1:DA815DD18ABA3B874B577184E9A4EA4240B17B72
            SHA-256:F526D856AD47971EEE38057CE1975FDB53AC7319A2BA644AC364E0EC25C03684
            SHA-512:E7699F9347DD277E7F6D598E9A45E054F04888BB04A819EE96D39E1E884CA5D0B4C915CFBCF1F8C1C5BD65AC1F72663D54BE941C76A2FFF2F4A881FF751B6AE0
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ .......................................Z....@.............................H....0..(....@...9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.082092984398133
            Encrypted:false
            SSDEEP:384:dqVFXh7pWm1IWXN/BHpAmBV7wX/0FtMW/xn7ELd14gHRN7AKpR1lC7hd:kf8DBf2b
            MD5:DF9329877EC7488FC0606F7C96D2C0E5
            SHA1:8C653FA335A61452D62665153126D5424996388B
            SHA-256:465CEF85BB813157219F47F11143F392FA4EFC78BD61A543A21B23156333FCA4
            SHA-512:13D5EB219C683875B9E1C05EA459278FA0949CE708A641AF6350C4FBA8161366C4CBA3F848474F6ABDDCAEFB4E24186D54D7C201978FAC30A54ADCB5DAFFA06E
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ ......................................$.....@.............................H....0..(....@...>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.049864539216793
            Encrypted:false
            SSDEEP:384:Hvaq6Kaq6Kaq6KafoVFXh7pWm1IWgDrq/O9OpMI1npowi14gHRN7vYzlZmV:Vcq/AUTnpowCAeV
            MD5:A8A43C378D4133061907EAB4E38E1F6F
            SHA1:100410CAE573AFF6DA92BDC5CE66602768D13D2F
            SHA-256:9DC4C9CBF1A1E1625F12788BD4DA65FA32F490E20BCF9BC420594FF05EE48B37
            SHA-512:C4C8E69746450BE445D7DC98F7E30FCF0A99EAA841CFD2265AB9F4177E4B334794B1FED8D2D324D4513B89E53165144ADE65700B746703C590EDC035F1C8DFDD
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................Y.....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.488510715575394
            Encrypted:false
            SSDEEP:384:cNVFXh7pWm1IWvUopGYnHaRWEaq5v/MX14gHRN7HR1lCwh6:uJ3nHrEaq5v/MBxZh6
            MD5:D442A2975A566A158315913FA6AFC2BF
            SHA1:958F3F5FC2F71E90105064BC8FC9D49CBEFC99FE
            SHA-256:DC109C0FF701A803E87841624829F7DD41D3E05CCEF01A144E1F9F301AD9FC73
            SHA-512:1BE62FCCB488A2E73FD429DEB637D652D29A7C92F610BCEED87E4B8400FE239DC4C8E8DBA546FEC81A3B4B9ECA7B386CD4CBE5981902DEC61E56DC587B98F526
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ...........................................@.............................H....0..(....@...<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):4.976381247228039
            Encrypted:false
            SSDEEP:384:3qVFXh7pWm1IWgxpmHzwrXoZSW14gHRN77zlZw:SeeHzwDz+7I
            MD5:80BB083A9AC85C265EA66D2AC32D182A
            SHA1:58D9FF68CCB5A605074FF12B6401A55C301C5CB4
            SHA-256:69011BBA80B78E1DFD7C3F0FB5B301DEE68CE4491E56CDF8C0145509C42DF959
            SHA-512:9F98E6E016339404228A163E3D207B1436D119E0226D407555F31F422E85308F787D82A6CD94DD5292D8DBB71D405CB46BFA9D03A4D59D4966A52A137C86D8D8
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......p........ ......................................t.....@.............................H....0..(....@...A...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....A...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.070097535344014
            Encrypted:false
            SSDEEP:384:v67VFXh7pWm1IW5aOzTGEsQYe+I6pEpyFDW14gHRN79AzlZH:SpLaBWo5pEp0D+ef
            MD5:FC838858544D0E726328360966B515D4
            SHA1:CBB70F233ACC897FFA24822618929A98D2F25BB3
            SHA-256:4403B46A2C6057BA81076159FC67CABB3529C3E0F8B61FF905B4EC74CA86FD2F
            SHA-512:B5F0AE1E6C06DC12785EC7236B4DF3B6022A0C0039D999856A2E224BFD423AB0A71A6A6F74957A36AAD8697F120CB2F20B30D5C36C1401593AD449E78444DEDE
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ............................................@.............................H....0..(....@..x;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...x;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.526685456567645
            Encrypted:false
            SSDEEP:384:4BVFXh7pWm1IWYdiXCKIJy4JzYhnEEquL1MG14gHRN77R1lCsd:++KIJy4VYhEEJL1ftBd
            MD5:583EAA3E3D78044CFF06EAC088233942
            SHA1:245A92CEAC71842AF42E615026D7396D31C538C7
            SHA-256:984E540A04A45C294A4A9A643108757CA57268ABD526172C264AEDFA2FDFFC90
            SHA-512:C7FEB17B35743079499395E5570A310EA6EF4A578E23F50370FEBD85E37F6A40E69907115D0CDF19C4E4EFB09FE7AE4F9F96DBFD700E4CD3635434A92CA8069A
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................dz....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.487285712300697
            Encrypted:false
            SSDEEP:384:TNPBbpWm1IWp6PK4xvn+bL/xzr0Y14gHRN7m6zlZJ:Lr6P5nYbxzr08m6x
            MD5:3A1D1D3A70381E27FD7660A717DC5466
            SHA1:77C6C52D3B1F15C85A9DB06F95FA97D30D439FF4
            SHA-256:A0528090B5B8E399BA299A6208D1BB6B4570DB62A0D2B4FBBCCAC7DA3A09A54B
            SHA-512:B6DD30AE844AF32CCC14E557F4B2FC2A25335C05FDE5A714AF0187D5D44245309528D03706AE3CF6E60C1344DF91849215480DA533512DE4BF3D5FD84884E34A
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................J>....@.............................H....0..(....@..(<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...(<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29584
            Entropy (8bit):5.080019744392318
            Encrypted:false
            SSDEEP:384:DLVFXh7pWm1IWNQ7+yHcVQlTUU5Pi5daxch4c5LSFw14gHRN7naVzlZh2:NGXcVQlB5awBKLDSZ2
            MD5:F6C6DE5DA1FD0F2FE3465BCE4D0DAD66
            SHA1:3C76FC0E7460429B54B99F8411A5AD2D900B08CD
            SHA-256:4BBCC263B0903E3BBF8ED0CBE4572622000EF28F8820618CF280CAB2F5EDC10C
            SHA-512:028E639A92E094C15068146952102ED7C266C81398182EEF337D38A8572DF67EC6781838DAD6CFF335AC80250696B24973A424EFE21BBD33A2392E1068B1D083
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........J......p........ .......................................8....@.............................H....0..(....@..`A...........P...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...`A...@...B..................@..@.reloc.. ............N..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.065799210085844
            Encrypted:false
            SSDEEP:384:kqVFXh7VWm1IWjiOE6kL6xgY+0s14gHRN7fozlZh8k:zIOErMYwB
            MD5:142DDE075B44AD1BC5A39E040CFC00A4
            SHA1:B6E34462E6A42A9922E1983FB49CF9533A326D77
            SHA-256:B8E2582D6B878DBCF99710D7A2BCFD88A4641D9919C89FDB0B23A860DEF7C77D
            SHA-512:5DEB8CA89438638C4B49B7A38A5F557FDC8CDB6889816F7374BDDA0ADD12BEFB0AD0FB5019B5452F201ABCC00D55013A2D353B87C8E93012688F2C5B3D0271BF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......t........ ......................................0.....@.............................K....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.0277148162985155
            Encrypted:false
            SSDEEP:384:2lVFXh7VWm1IWSeGGhJzDKyLgFRZkK6p414gHRN7qcR1lCaf0:Us34zSvh6cqsHf0
            MD5:BC0C6EAEC78A331E2B1AF9D9466ACA1A
            SHA1:B9F98641D0261B2B6181B98744D0EDC34615B213
            SHA-256:1E3280C9CE516D68ED337261E65B5F3F9A86D4B45ED03ED6BF3BB9B723E597E5
            SHA-512:3382B9DEC5AF145DEB51264EF6DDAA11FDEB9E1345E5FCDD234C1255893C65E4C71057BAD1174CA1E3A82ADAB0DCC6ECD4C5ACB487CDD274B6C49BD061F8EB07
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......t........ ......................................?M....@.............................K....0..(....@..@=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...@=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.049654510730145
            Encrypted:false
            SSDEEP:384:O10VFXh7pWm1IWsqN+NPKl5v14gHRN7UzR1lCcc:NKMPl5ZYNc
            MD5:C8046D9657A540D9F401A24E30868249
            SHA1:DF743A8FFB87B36675488D3CF61BEC4A33274045
            SHA-256:1F8D1FD8F767243E0A06889EEDAF06A89A3091F0283791E16CD34DB04980F99F
            SHA-512:251AF9926CA2B347AFAEDF3112D850EF1ADFDDAE55DE35C16D50AA1D54F493FE7C40362045A80E4C33ED6AE74F3AD9A5E8979503120AC173C8F5513F23D6E134
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......t........ ............................................@.............................I....0..(....@..H;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...H;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.0137570799885385
            Encrypted:false
            SSDEEP:384:8YuVFXh7pWm1IWQQ72oJzoBpFPAfsVx1hbjp+PZ14gHRN7zzlZ2cr:+X72oJsBpyfsVx1hHpmzfr
            MD5:141524FC8A86F93BD4F948CBDC0F4180
            SHA1:7FF8DA2F8BED417E6BB6DA4A5BB98832BB86DB06
            SHA-256:1A9DDE05D33A2E96ABB1658AB08D695ED7A5846F11664B93F9AF8FA3BC7E044E
            SHA-512:092605B4A65E4ED89121C48B9A15897300248D38066968C61B1BD44D1ECD88756C3A8397BDF45E8784545858BA18A8B09AFA582D62949BA1BF5120BF3A007CEF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ .......................................|....@.............................H....0..(....@.. >...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc... >...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.506726281268631
            Encrypted:false
            SSDEEP:384:8bVFXh7pWm1IWaFjOvZdkstI+EpRYRYhgz14gHRN7BzlZ7:shI+WSVBj
            MD5:A16FA69AA0B1EA708AE85F761ABC9DB9
            SHA1:D81F370949766F356AD579EDA7A2417A03BB97B9
            SHA-256:DCDEAD957AF80CE7594CC7F67289B79CE37C6B285E420385B75642C04670029C
            SHA-512:8618A398C189015F7D58950CF3BB78AB298688943D8A779926D029F8960A7861B80A52673B02C6C371F9598151394BC11AC20AA7247BC06FF5FC932CB070ED23
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ .......................................[....@.............................H....0..(....@..8;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...8;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.135404679946939
            Encrypted:false
            SSDEEP:384:d3nVFXh7pWm1IWDyZFB9qpA0iFT0ywblr5qJUH14gHRN7uR1lCBBd:PggtPGURKsBd
            MD5:5FE057EA6F306A8D8CC044460D906A82
            SHA1:591AE9EAD68996599119FF5DA7B06D55610E6E5D
            SHA-256:60601E08FE45EEC253C977E5EEE0293DE81E6B524D2705C29C506B2489A0F5E1
            SHA-512:A3EB76A9218D1CF90DE671E152C1B915CA0CDC14BBCADA325F7ED4C77FF202A7A22364546C8E414DD970D8B14F58F89B7EDA137393B0D038E255FD1131E68377
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ .......................................O....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):29072
            Entropy (8bit):5.009900782263759
            Encrypted:false
            SSDEEP:384:QsVFXh7pWm1IWNLUphsWGMYVxJtWFPzm7m4tmkmGkfBQZy8ZK7mBsvYp6NcLoICd:BqQntDkBFsi5k2
            MD5:4D63AB8BD528FCF5D6339665CC55B4BE
            SHA1:EB6AC6B5CD6844BC9E5ED0175AC6286DC5BB057B
            SHA-256:55816FCEE316702FAF6F59D448C696ED27C4018CA1454E4CAF8348D5F9505611
            SHA-512:F8C63CB05B2AFA59209969C71B8578210A6C4EDE04C04584BE4CADEA57B345723CD3C0FB8A9C86CA13F67BF6A0AD19FD8B60B86705119D50553699C3E8803483
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........H......p........ .......................................;....@.............................H....0..(....@..H>...........N...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...H>...@...@..................@..@.reloc.. ............L..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.067511119292097
            Encrypted:false
            SSDEEP:384:zxgVFXh7pWm1IW0mY4c4zbqhTwV41LjYBUeuQa14gHRN79QQ3Jll3tqwF:1UOmY1Obqh641LjYBUevaxnF
            MD5:7B532239A16CED0262078578886940DA
            SHA1:3BACE5CF030EB30E2C56E10D0186A24BC3547ABE
            SHA-256:D2566BF0681370D9313671AF76A5D9C317B42F97255B9D290767AE7146CBC80C
            SHA-512:D6512AEBA16C1E195AD6932D3D9B0D5B5E04660D4D95D0CEE9A1D556DA7EA50110383CC6103FF0379455953146DCBBB8971AFF831CCD11A1AF02345198C837BB
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................./....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.480943511048745
            Encrypted:false
            SSDEEP:384:IElVFXh7CWm1IW1Tu2++Wed7gHKM8Uf14gHRN76nQ3Jll3P4h:ILq/fQ7gHF8I6Snw
            MD5:480ED7F260C4DEE3F6AFD6FB2F7A2BBD
            SHA1:EAB92765539ED45B120401126A6A1AA2750D8892
            SHA-256:6D2A9047E95B808E640A4D1B94856ACC30D86C5B2D8ECFEC5B38A09917723215
            SHA-512:253DEC4A5FB20769F6836B4CA476B3006F6E672410C32439F1392EA5EC2669D0117809BB1D5D7546726C313600BE4A92C59BAB86A2AB982602E11F0549BFB6F6
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......x........ ......................................k]....@.............................P....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.474926206358726
            Encrypted:false
            SSDEEP:384:rOIVFXh7CWm1IWC8Flve66SXX5FpMXw5C14gHRN7JR1lCc61vFg:ruHTXXpFGw5i/J61q
            MD5:E904DCA00117E67996FA231621CB844A
            SHA1:FB2CC73E785EC32FA63C5CB51112D69D8D51F221
            SHA-256:438414FA7A4348365576C5BA45ED2C1051F396628BD26A4DBBABFB81D7DA3FCB
            SHA-512:C01657786C15AE6C82B9DCEA35DE73C2DE8BEB9D0CB396004895BD659C9ED25A590AE5D0C753345FA4107F8EBF5B7576117436724A9411590A466A06FA33F5E2
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......x........ ............................................@.............................P....0..(....@..`=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...`=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.061303840468723
            Encrypted:false
            SSDEEP:384:5luVFXh7CWm1IWmdeB8sLV1rh2r14gHRN7LR1lCkQQ:51kdeB8sL3rh2tdzQQ
            MD5:372C4828C5D77C6D4F9387E24696D165
            SHA1:942395E73A7D596FC970983BC7454D993C0196DD
            SHA-256:29F21305FAA9A9F7971B5AE3D19139D25A60CF326FBC03D4D06F131E2C0794EF
            SHA-512:4B7BFBF6C0DF20DFB58EDE65125DED28F90D2498B58ABD49837C42B9B5B1CBE0D442139301DD99CD9D75412419911B0B94C56B48114F1ABB4283E3EFD0A1188F
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......x........ .......................................,....@.............................P....0..(....@..X=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...X=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.472394584016559
            Encrypted:false
            SSDEEP:384:INkVFXh7pWm1IW6Tu2++Wed7gHKM8E14gHRN7yQ3Jll3O:0Yj/fQ7gHF8QZ2
            MD5:0E7111E4DDE070EB1599A88F473E286D
            SHA1:4978569C1E44150E4C599B169BD2C239D98E0A25
            SHA-256:301B76D9920AF43D006DE528C35932AE8914048D7D1E0F2FA17A06AD516B4512
            SHA-512:B06042292B8FF95D80BFA17D0D33EEFA05BB4BA5C422425776A166DD87EA53254667ED27B520AEAD0AC70DF287A5AD609145750A7E1866A040C95798E713445C
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................b.....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.013223504039355
            Encrypted:false
            SSDEEP:384:4QtVFXh7pWm1IW5j5l8M0yD/U958fP14gHRN7ejR1lCfKt:H/T83y4b8f5Y4Kt
            MD5:E3284BB7177F1BB3CFAC848C7E696714
            SHA1:6ABC27B727A1BF5180194F985E8B6772D4BC1B08
            SHA-256:445F73A610E76EC62E851846B9744BC0800EB9E90DB42552E3DFEE6D5ADA8E54
            SHA-512:CC7CED92953B5FA6A447BC927AAB1B559424BD76BF8EF450E9D7529A5E66A5F0EDC21C48EC461E4E6CB87B81B702113CD0043287516F8D85260D8F0BA40E12F4
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ....................................... ....@.............................H....0..(....@..P<...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...P<...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.580548621346359
            Encrypted:false
            SSDEEP:384:IAVFXh7pWm1IW9uoVfjuXVfMf2SXRDkcYM14gHRN7ADzlZx:ZDuoVfjuXVf+2SXRDkcY4AD5
            MD5:ADEDD303534101D2398C58BB8D03234B
            SHA1:97B288790014DE5C58F59E0F9D7C1C70BB67BBD0
            SHA-256:8230FA24866080C85FBB23868C310D7FA8170996C8537615DAE234191D4AA9A6
            SHA-512:9C5708E904076F601417CDC4AF8D7F390CA46C31EE43A7FD336C87A1611575FC796D2A01D2BA3CE5AE124258857976436BCFEDA99385B25A1E8247F6E45459DF
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ ......................................!.....@.............................H....0..(....@...=...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....=...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28560
            Entropy (8bit):5.523235355820772
            Encrypted:false
            SSDEEP:384:JAVFXh7pWm1IWiUhBBeTuQbepP/NFd7ygOffu14gHRN7vR1lC1m:ugUhBBeMP/fd7ygOf+Zsm
            MD5:29B940BFBC2809D9CD25EBC0A492EE2E
            SHA1:6C8E91ABBD17381BC7CC25341452FBE46AC19E2E
            SHA-256:23715C0190CB1E9FDEC5A931408477AD48C0EAF6DA5B0D2F878194C96356B918
            SHA-512:123431C8C7D9EE56E6A02E519F74F168FB3DB98C1D6A33D8EED9BC414CD151CF6E6175699D532E8FF21F02DF1984EE1F0CE1AF9D3E59D57A846D0E1F60B168FE
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........F......p........ .......................................N....@.............................H....0..(....@.. =...........L...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc... =...@...>..................@..@.reloc.. ............J..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27024
            Entropy (8bit):5.632692089559041
            Encrypted:false
            SSDEEP:384:wFVFXh7pWm1IWzubufuOu8wIxFqutbwfmtRgb3u3axcY4WXh14gHRN7TR1lCwX:OoSG58JxFVtbwfmtRgbe3Z4fl9X
            MD5:8B2467B30C04CA272AEA90775BAF19E3
            SHA1:248D04FD51DA0979428E21DF81F6D366B7B3B1C8
            SHA-256:79989FE4A6A09278147988CEC6A87A939787FE7B71B45495E2E3FC20EF5AC19B
            SHA-512:29700700A4EEC678FE32AD6E0B6C62BD8BDE91395697EC8A5CD61B21784A31DE85BDBACB2CB9621F43F551D2E2FC19B7355176538273CBFD0F1112F360F92B2C
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........@......p........ ...........................................@.............................H....0..(....@...7...........F...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....7...@...8..................@..@.reloc.. ............D..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.127503597086757
            Encrypted:false
            SSDEEP:768:JmH0Ou6E3mGyf1LV7Z85lerwrI5zyesQ7u2VlwO:JF6E3mGw1L1ZNCIiQy2VlwO
            MD5:27C9C09E561AA6861926EC550406BB2A
            SHA1:597ECC7D65BD0F46B871BBB468DF1EEA7B8F41C0
            SHA-256:7837AA654E1CDA3E853B2E8C86CBA4F73AD2BADAE51537EBBC8B2CA5A582C234
            SHA-512:E86863FD1E854085A12AA0EF7357473E5E6A35700846B17F6356A4924F5E75492729F7499B10AE3A29032DB577869360D52C0DA694270913A414A1224E3E40BC
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................,.....@.............................H....0..(....@...:...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....:...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.536050952562876
            Encrypted:false
            SSDEEP:384:cwVFXh7pWm1IW7Q6Qfd9L8AwXiE914gHRN7bUeR1lCXXw:lg9L85/j5SXw
            MD5:A67A66B824D031F41B973D62530EAAB8
            SHA1:297A13659E6C3136B34599A288FE1742C2A9A646
            SHA-256:A9786B5CAADEFB4540FA0A8D41E293F0A0F3B5D6826C974681BD5953D7881EA5
            SHA-512:61911F2DB63654460B0283514DBA129721EE231BABD57EDDB259F295F1F3D4A3A68E23C06C22C04B0AA5ECB4BC4E644224AEBE0CF11BE882D76FF3438F9D218F
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................P.....@.............................H....0..(....@..h9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...h9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):26512
            Entropy (8bit):5.56032267360284
            Encrypted:false
            SSDEEP:384:D9PBbpWm1IWikg1osHo3tNZxWTCT0a14gHRN7+zlZgw:bgQz+l
            MD5:7508A9BB2035430A3B721A2B055646CD
            SHA1:9E9028E28498118B3BC93310BE4D61C7F92D3633
            SHA-256:0D4C1E704369750CEE5CEDFAFEEB77F33D4815997E63CE672ACF330549287679
            SHA-512:D22692CE25361E1EA61433CFA0BA607692E5EBCC6AFD98DD819AFFC294628460C46862A033E36103D985D5852199176E0D6EE91A5138AD064234C27715E0C227
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........>......p........ ............................................@.............................H....0..(....@...4...........D...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....4...@...6..................@..@.reloc.. ............B..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.531808364875229
            Encrypted:false
            SSDEEP:384:8KVFXh7pWm1IWiUFMruYGu8moHPoybE6ya4I14gHRN7MzlZZ2:7g2YbMMY
            MD5:719B575FED0675C17E30ACBF53111901
            SHA1:192ED6FB2411D37D18482C47C2724228FDE95D19
            SHA-256:7070D76B4C711CE52A2E026AB26E8158ED46B8DD8844CAA2B28573EF55B5FEA1
            SHA-512:2C089ACAFBFA71EE25926D500E96AA15CC5821B473D98CD1B035D973D14A0581272ABBE9AA8251C040E74EB51BFF12319F81EB6CFFA159EAD59A2887A119FAE7
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ......................................5.....@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):28048
            Entropy (8bit):5.494386311988992
            Encrypted:false
            SSDEEP:384:O/PBbpWm1IWizuZdZZMsCpA/NieavYWr14gHRN7oZzlZ+:igzuTZZMwaYKmm
            MD5:AEE19BA0D1353DDFE58BE036C62A18DF
            SHA1:2E53CF1A7C4C0A1CF7DDAF08E64EAA68B1684D96
            SHA-256:7CEFF8F3E9D590AFF454918906273CD446DC9503E0FC18C72FADE98E3D0CD258
            SHA-512:C0EDC013CE713BD233A3EBC350C176527A6C45963C1B9F559752B8FC285C0FCC5D7ABCDB5DA368416590229130B126D661362FD3DB26ED17A51F33548B8FD419
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........D......p........ ............................................@.............................H....0..(....@...;...........J...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc....;...@...<..................@..@.reloc.. ............H..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):27536
            Entropy (8bit):5.331826150776246
            Encrypted:false
            SSDEEP:384:9MVFXh7pWm1IWpCBnJT14gHRN7C4R1lCIo:WyJ17po
            MD5:AF765CD345C9CFD6EAA6F43592853F7E
            SHA1:967749B089EDCB7D9C4ED866C8392B5C9D168D9A
            SHA-256:F53F72633A0D0148D1E471E2C17075A7BD34B2EA6C09FE78A2B76570FC35C751
            SHA-512:100E23F0DD363F8372BDDF74FE51F84420A8F67CDA68A1D12A822CEB8B89581518FB9713CD2A7A2DF54278870FE8C8F9B9B1BDF7BC18AE09BAC84407A27513DA
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........B......p........ ......................................}.....@.............................H....0..(....@..x9...........H...#...... .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...x9...@...:..................@..@.reloc.. ............F..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):20880
            Entropy (8bit):5.987637889684451
            Encrypted:false
            SSDEEP:384:B4KVFXh7VWm1IWCIHtnp14gHRN7ZnR1lCkn:bUIHtnnbhn
            MD5:C710D576ECD456F7BB088F4458620809
            SHA1:9B85812F1971E23281D58697D66BF21A95BFE690
            SHA-256:14914692C2B576BD26132B5EF3FFB1F17512377881C13972A3362F4F5202D10C
            SHA-512:8FCDBEBBF7B94735AE3DF3CE904753F1B1D6F65E9FF3A3DF20748D45DECD1C19D60FE5B9E10AEB015FFA9BCD9E8057BBF86B98BE79F425A87C7EEA33F3034FC0
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........(......t........ ...............................p......M.....@.............................K....0..(....@..0................#...`.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...0....@... ..................@..@.reloc.. ....`.......,..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):20880
            Entropy (8bit):6.016334298139521
            Encrypted:false
            SSDEEP:384:NxJVFXh7VWm1IW7gu14gHRN7JQ3Jll3Rb:jlg2c5b
            MD5:EAE6A96B835B1BF4C44DBAD036339CF1
            SHA1:2CD7E4C3007BBE1C249108DED592FE6E1F68F612
            SHA-256:4A68372E6CEE6C78AB6875457236256D0632150B4754404788B107BB44B5DEDE
            SHA-512:D4A1D904623D03D1AB6543A9FC7A2680A8A1497134DD48E67E44754C4159AC62AADE2526627B5F6A9CDD642B8F9E1829E648EA10D3F17477E792489855F8112B
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k..Q.@.Q.@.Q.@..eD.T.@.EaA.R.@.Q.A.W.@..zI.P.@..z@.P.@..z..P.@..zB.P.@.RichQ.@.................PE..L....F_a...........!.........(......t........ ...............................p............@.............................K....0..(....@..H................#...`.. .......T...........................`...@............0...............................text............................... ..`.data...$.... ......................@....idata..f....0......................@..@.rsrc...H....@... ..................@..@.reloc.. ....`.......,..............@..B........................................................................................................................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):306064
            Entropy (8bit):6.36823015650917
            Encrypted:false
            SSDEEP:6144:Dvau4VkA+DDpAu4Uy1AtMeUHZW5qAuORz+AOzLZ9KmFv/aqrN3xk8:+u4yAgDx4Uy1AtMevuOR6NLDK6BN3xk8
            MD5:F1470ADC12C0B896DD11F0647344C17D
            SHA1:00446F5D4107185D79D72BB10C932DB81A23B624
            SHA-256:6C9FAD496A1F487200F8CC89592CFE46BDD82084E0A2BA3C09DF96418B500E42
            SHA-512:26B49204B4E9533BE5D31949C0F469C32A1480A30F80E09A8F1489E4B5E2D8E56E99716CDB52F99D8F7DB2D931CE41F3A3CEAD4D8CDB88E0835CB1BC6B3DBE1B
            Malicious:false
            Reputation:low
            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......8..P|...|...|...h...r...h..........m.......k.......,...h...f...h...}...h.......|..........H......}.....P.}...|.8.}......}...Rich|...........................PE..L....G_a...........!.....0...n...... ........P............................................@.................................P...(....0..`i...............#.......1..8...T...........................`...@............P.......... ....................text....,.......................... ..`.orpc...c....@.......2.............. ..`.rdata..4....P.......4..............@..@.data....5..........................@....rsrc...`i...0...j..................@..@.reloc...1.......2...V..............@..B................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
            Category:dropped
            Size (bytes):376208
            Entropy (8bit):6.045202309915156
            Encrypted:false
            SSDEEP:6144:m1OYOIFvV4Oq5SO2H28uzqli/44wz6Aoh1bR7WKJAcg5v/aqEq:m1ORm4RSkDOK44wlodSK5OCq
            MD5:6F9BEFBAE010CD180867218051CD8A13
            SHA1:9B311F82E0AE1438C0DD933CC01208A9CCB8FDE1
            SHA-256:378AB2C06454E4AB7BCD7BF37FA125D4F7AF03E31755173B750339DF31C759BB
            SHA-512:014D9EE288ADEA7DDEAD56FC228D39EE5B8806D99CCD777CB7D9BFAA6F894BB4D482381F53C070634C7B6B7D6E1946636484BCC346A630E32A54CC21971C1145
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........6~\HW..HW..HW..\<..CW..\<...W...8..XW...8..BW...8...W..\<..PW..\<..IW..\<..KW..HW...V...'..|W...'..IW...'..IW..HW..IW...'..IW..RichHW..................PE..d..."G_a.........." .................K..............................................].....`.....................................................(.......`i...@..,%.......#..........D...T.......................(....I..0...................(... ....................text............................... ..`.orpc...$........................... ..`.rdata..............................@..@.data....S.......,..................@....pdata..,%...@...&..................@..@_RDATA.......p......................@..@.rsrc...`i.......j..................@..@.reloc..............................@..B........................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32+ executable (DLL) (GUI) Aarch64, for MS Windows
            Category:dropped
            Size (bytes):341392
            Entropy (8bit):5.888992019871646
            Encrypted:false
            SSDEEP:6144:/5+IesxMv/NL+QPO+ojj2zUAatpZuOzdWbTo6Ms7WKXTGuv/aqLD:oIe9xv+pYOzdWdSKDVZD
            MD5:092914A6DF5AD3C26B949A7FC0242C09
            SHA1:0EFD3B6C017AAF79785442B400A313188746700C
            SHA-256:794F703B2A92297BF27CDDD0E7C3ABD3AD22C48940CDF0A137D25B243F1E7066
            SHA-512:9693C12BB4F22834DB9910E4367C63963510CA65E8673179A4D6794B822D6086ECC50373C61B0F9EEFE1029CCB9BB8D9F639EE8E294FF772AA97E9EC0B9E67B5
            Malicious:false
            Reputation:low
            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......h-.,L..,L..,L..8'...L..8'..L...#..=L...#..%L...#..bL..8'...L..8'..-L..8'../L..,L...M..<...L..<..-L..<E.-L..,L-.-L..<..-L..Rich,L..........................PE..d...!G_a.........." ................X{....................................................`.........................................pf......(g..(.......`i...............#...p.......3..T....................3..(....1..0....................U.. ....................text.............................. ..`.orpc... ........................... ..`.rdata..@...........................@..@.data....P.......,...N..............@....pdata...............z..............@..@.rsrc...`i.......j..................@..@.reloc.......p......................@..B........................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):306064
            Entropy (8bit):6.368480596125887
            Encrypted:false
            SSDEEP:6144:uvau4V8o+Drp4WAcy1AtMGkH+2W5q4uORr+AO1p89KEFv/aqrN3xi:/u4qogrhAcy1AtMGbTuORCvpiKUBN3xi
            MD5:53C292F0750122F03F8D1272FA890392
            SHA1:6800D50A1805783E181DEF21026E7CFEC74193A2
            SHA-256:100F692A1F4F36043394EAB4B77CA1CE1C55DF7C1277CF323ED23B5BAAE5A020
            SHA-512:5DD78C603195F5DFE19D985E40CB14FA5318AEDC789F3B219A906F4C698DE00378CD4FBC6722A465F9CB2714A987ED711A8350359AE1AFA581CF41EA66CD8099
            Malicious:false
            Reputation:low
            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......8..P|...|...|...h...r...h..........m.......k.......,...h...f...h...}...h.......|..........H......}.....P.}...|.8.}......}...Rich|...........................PE..L....G_a...........!.....0...n...... ........P............................................@.................................L...(....0..`i...............#.......1..8...T...........................`...@............P.......... ....................text....,.......................... ..`.orpc...c....@.......2.............. ..`.rdata..0....P.......4..............@..@.data....5..........................@....rsrc...`i...0...j..................@..@.reloc...1.......2...V..............@..B................................................................................................................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
            Category:dropped
            Size (bytes):376208
            Entropy (8bit):6.045099929766453
            Encrypted:false
            SSDEEP:6144:+1OYOIFvV4Oq5SO2H28uzqli/44wJ6Aohvbz1WKfAcg5v/aqW:+1ORm4RSkDOK44w/op4KnOg
            MD5:952FE51CE5A72FD464095EC3C7AD1AD7
            SHA1:AB106F65B5E78B2FF5EFED25FF0EC0234EB59F61
            SHA-256:311AF22D1005B320EFC0725B14785AA1024938E1AC185B7BCD24007CC1D22349
            SHA-512:77640844BED8463BB43600F9150B1C40B37C4898203CF5FDEBCE96F9E2DFFF0D02C21B4A48A638F39E2A679B656757660F2E67DE4EB2FA28CEB5D59205DF5C6C
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........6~\HW..HW..HW..\<..CW..\<...W...8..XW...8..BW...8...W..\<..PW..\<..IW..\<..KW..HW...V...'..|W...'..IW...'..IW..HW..IW...'..IW..RichHW..................PE..d..."G_a.........." .................K..............................................F#....`.....................................................(.......`i...@..,%.......#..........D...T.......................(....I..0...................(... ....................text............................... ..`.orpc...$........................... ..`.rdata..............................@..@.data....S.......,..................@....pdata..,%...@...&..................@..@_RDATA.......p......................@..@.rsrc...`i.......j..................@..@.reloc..............................@..B........................................................................................................................................
            Process:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            File Type:PE32+ executable (DLL) (GUI) Aarch64, for MS Windows
            Category:dropped
            Size (bytes):341392
            Entropy (8bit):5.888923069144354
            Encrypted:false
            SSDEEP:6144:dU+IesxMv/NL+QPO+ojlJiUAatpZugzdsbWocMs8WKcTUdv/aqeJ:fIe9xvCpYgzds+pKMscJ
            MD5:9C752C6ED66470E25D469CCC3F28E000
            SHA1:EF184022D3ED0684DF6C73D371DDAAE6F7FCF81B
            SHA-256:C8493BA63526B5BD4CC8422ABB3A8A8679FE42D6BE8F4A09E071A016D2D0BDB1
            SHA-512:FC62F0BF88EA83CFB1D79A057DFC0D0B155D1EB22B6C073470CBB6A52E2C2D8315C0BB1F86BBB728B67B260E9EE89DC2CFF704197B4AA40F5715AC92E05C05AE
            Malicious:false
            Reputation:low
            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......h-.,L..,L..,L..8'...L..8'..L...#..=L...#..%L...#..bL..8'...L..8'..-L..8'../L..,L...M..<...L..<..-L..<E.-L..,L-.-L..<..-L..Rich,L..........................PE..d..."G_a.........." ................X{..............................................`.....`.........................................`f.......g..(.......`i...............#...p.......3..T....................3..(....1..0....................U.. ....................text.............................. ..`.orpc... ........................... ..`.rdata..0...........................@..@.data....P.......,...N..............@....pdata...............z..............@..@.rsrc...`i.......j..................@..@.reloc.......p......................@..B........................................................................................................................................................................
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3495
            Entropy (8bit):4.252910656744403
            Encrypted:false
            SSDEEP:96:pI37cwesgABqdpKyPVAEgmMqzTXQ3Vx36xnhno30yD2C:pQn3qzKwZgWXQlcp9Y0yD2C
            MD5:0EFE6740AA6791EAC85B57BAF6730D4C
            SHA1:5A517F0A84CAFCDF66A10DA80921C9F4CEA5B41C
            SHA-256:CD8BFFC69B9F490651E45F4A33C32BB0050F1F9A9A4E72E47AB3703812D9561B
            SHA-512:151F539CDAD87A5A175F1B35701A60271964B2BACF91267AF91416FF5168B2BFCBDC29D6AC47B6894F4B211136A683DB71768B581EF7396F91212BD42BC516FE
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">..<g clip-path="url(#clip0_1159_10366)">..<path d="M11.547 7C11.547 6.77376 11.5301 6.55123 11.4969 6.3345C11.4773 6.20605 11.5349 6.07647 11.6478 6.01213L12.7362 5.392C12.8814 5.30928 12.931 5.12389 12.8465 4.97971L11.6951 3.01396C11.6121 2.87226 11.4306 2.82363 11.2879 2.90486L10.1866 3.5316C10.0761 3.59454 9.93839 3.58009 9.83849 3.50128C9.48476 3.22225 9.08805 2.99452 8.65871 2.82827C8.53838 2.78168 8.45548 2.66801 8.45548 2.53897V1.3C8.45548 1.13431 8.32117 1 8.15548 1H5.84452C5.67883 1 5.54452 1.13431 5.54452 1.3V2.53858C5.54452 2.66781 5.46138 2.78159 5.34084 2.82817C4.91254 2.99369 4.51525 3.22217 4.1615 3.50127C4.06161 3.58009 3.92394 3.59454 3.81335 3.5316L2.71215 2.90486C2.56942 2.82363 2.3879 2.87226 2.3049 3.01396L1.15346 4.97971C1.069 5.12389 1.11862 5.30928 1.26381 5.392L2.35358 6.0129C2.46584 6.07686 2.52355 6.20538 2.50411 6.33312C2.47097 6.55074 2.45297 6.77304 2.45297 7C2.4
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):915
            Entropy (8bit):5.106434842476683
            Encrypted:false
            SSDEEP:24:2dgAOLf3nTY2Kqj3AhlH2xqj3AhlHKIqj3AhlH2PGqj3AhlHK:cgAqf3nkLxsxhxVxK
            MD5:4FC49BBB9A423AD41F56152B624D142D
            SHA1:6BCA4EF491B456D8170F5FF300BE20D1F2CB5830
            SHA-256:55F21C6D1316AA07E2A1B8DB59DD0F40BA989AA2DDD507D5A76A3B67D64E9AAA
            SHA-512:D55A906FF9021166E12D7737D30199BC5A145FA1E221B89E1E3EAA81175ABDD4E88241A1AB81C769FAA07026FD455B563506044E286723E5C7F27FDEB2123E36
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="utf-8"?>. Generator: Adobe Illustrator 23.0.3, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->.<svg version="1.0" id="Layer_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px".. viewBox="0 0 16 16" enable-background="new 0 0 16 16" xml:space="preserve">.<g id="expand">..<g><line fill="none" stroke="#FFFFFF" stroke-width="1" stroke-linecap="round" stroke-miterlimit="10" x1="4" y1="4" x2="8" y2="8"/></g>..<g><line fill="none" stroke="#FFFFFF" stroke-width="1" stroke-linecap="round" stroke-miterlimit="10" x1="8" y1="8" x2="12" y2="4"/></g>...<g><line fill="none" stroke="#FFFFFF" stroke-width="1" stroke-linecap="round" stroke-miterlimit="10" x1="4" y1="8" x2="8" y2="12"/></g>..<g><line fill="none" stroke="#FFFFFF" stroke-width="1" stroke-linecap="round" stroke-miterlimit="10" x1="8" y1="12" x2="12" y2="8"/></g>.</g>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):331
            Entropy (8bit):4.958480502461408
            Encrypted:false
            SSDEEP:6:tnrLnl/GKumc4slvtM65twO82XmHtUMHVQKD9qsmkJijMXwQJA38n:trLnl/GKuXM65E2WX6smkb238n
            MD5:54594FCB490F7BFCED356DA88DEE72FF
            SHA1:8C95B1D376CAE185ECD2BBE8EC56D13C49CEF590
            SHA-256:684F56349DFC527ECF8530A444A2D954F0AE50F98185BD413E46BAF81687A645
            SHA-512:2ADF20E88E02B8C9B3BF2B6FB993CE58BF01A14EE3E05D15B0B439674A3426E495432D88B3EF34DBC3C32B2473B0091D0D4DF271AD93B1FA352CDC3524B7C841
            Malicious:false
            Reputation:low
            Preview:<svg width="25" height="25" viewBox="0 0 25 25" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.5 0H0V12.5V25H12.5H25V12.5V0H12.5ZM12.5 0C19.4033 0 25 5.59644 25 12.5C25 19.4036 19.4033 25 12.5 25C5.59668 25 0 19.4036 0 12.5C0 5.59644 5.59668 0 12.5 0Z" fill="#FFFFFF"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):331
            Entropy (8bit):4.933726392728333
            Encrypted:false
            SSDEEP:6:tnrLnl/GKumc4slvtM65twO82XmHtUMHVQKD9qsmkJijMXwQJAMJn:trLnl/GKuXM65E2WX6smkb2Mx
            MD5:3E047DCAAC0E0D8D478ADA10CEC8CBF4
            SHA1:7B484623E3E6396D3B64A2A72EB70F5A2E70C6DF
            SHA-256:2773340D8FD1D07D6E4C206FDB5302365D973E3A08D0697A8FB165D0539C413A
            SHA-512:8FA0F94E2CBB02C51F4C2D9BDE86F55DFAF799380FD5FF20394414728CBA1B975C6190503B7ED8F468C52F0AFE4400CF082A9651020238A298BA5D2753A6B009
            Malicious:false
            Reputation:low
            Preview:<svg width="25" height="25" viewBox="0 0 25 25" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.5 0H0V12.5V25H12.5H25V12.5V0H12.5ZM12.5 0C19.4033 0 25 5.59644 25 12.5C25 19.4036 19.4033 25 12.5 25C5.59668 25 0 19.4036 0 12.5C0 5.59644 5.59668 0 12.5 0Z" fill="#2D2D31"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3595
            Entropy (8bit):3.872488959866118
            Encrypted:false
            SSDEEP:96:FsnalfCj5M7liYY1/PC3TWldlR6wpv9BcwfoeRbMx+HaFe:FsnMfCj5M7liDtPyTWlb11TXo8YmaM
            MD5:E699BE2C757DB3B109935AE2372BDF17
            SHA1:2A89437E302EA53682E54E5EE087F748ED25705A
            SHA-256:261F7109C512EF09C7A4681BA392D887FE3054E1E9F2B60963AB7C7C3D5ABE2C
            SHA-512:D0D7AD320F8291713B81AAD509CB8AF4865CE84EBBABD49262648DFA6C7262A2BDC131E3661B9E1ACD14649D1F34A1E41B3A6293B4217A68035462713A2ACC6D
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M7.87009 2.23001C6.33009 0.690012 3.83009 0.690012 2.28009 2.23001C0.730091 3.77001 0.740091 6.27001 2.28009 7.82001C3.71009 9.25001 5.97009 9.35001 7.52009 8.13001L8.85009 9.46001C8.85009 9.46001 8.52009 9.79001 8.85009 10.12C9.18009 10.45 12.1401 13.41 12.1401 13.41C12.1401 13.41 12.4701 13.74 12.8001 13.41C13.1301 13.08 13.4601 12.75 13.4601 12.75C13.4601 12.75 13.7901 12.42 13.4601 12.09C13.1301 11.76 10.1701 8.80001 10.1701 8.80001C9.84009 8.47001 9.51009 8.80001 9.51009 8.80001L8.18009 7.47001C9.41009 5.92001 9.30009 3.67001 7.87009 2.23001ZM7.52009 7.47001C6.17009 8.82001 3.98009 8.82001 2.63009 7.47001C1.28009 6.12001 1.28009 3.93001 2.63009 2.58001C3.98009 1.23001 6.17009 1.23001 7.52009 2.58001C8.87009 3.93001 8.87009 6.12001 7.52009 7.47001Z" fill="#73CA94"/>.<path d="M7.49016 4.34999C7.43016 4.15999 7.36016 3.96999 7.26016 3.79999L7.44016 3.25999L6.85016 2.66999L6.31016
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):345
            Entropy (8bit):5.17415130018141
            Encrypted:false
            SSDEEP:6:tnrLnRmc4sliy5qOKgR0n0CbSlI0+ILHSuRSC+mqZlZFkAHcrLPbvNZ/CvcY:trLnRIoqOzu0CbSKZILHSuQC+hljkAH3
            MD5:F57E89F96EC45E2B22347076483C6EB8
            SHA1:5B22D031A7A0FA3767BC13E62FF1127A97D499A8
            SHA-256:5F7B7983C015B170FF54365AAFC7247148CA43FB3ED156A2C0757792E0D61102
            SHA-512:6D02B434D38B5739DEE4981A5039F3854FA459C2FB307FBCA3EC019B1004C889283E7F04EF10C24D93BAFC2B4291F9C6579A879C3AA49E0176B682E65F4B5D1A
            Malicious:false
            Reputation:low
            Preview:<svg width="25" height="25" xmlns="http://www.w3.org/2000/svg" fill="none">.. <g>. <title>Layer 1</title>. <circle id="svg_1" fill="#00AE42" r="12.5" cy="12.5" cx="12.5"/>. <path id="svg_2" stroke-linecap="round" stroke-width="2" stroke="white" d="m6,12.0189l3.57518,3.57c0.78082,0.7796 2.04552,0.7796 2.82642,0l6.5984,-6.5889"/>. </g>.</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):456
            Entropy (8bit):4.595687723934498
            Encrypted:false
            SSDEEP:12:trCv0uC2gB2Yh3adniqkhRXoEFafg9sAAP6bSiM:tuv0ucBH4nrkHoseg9sABSiM
            MD5:F09CE76CA1E9CC96C96260D76B6E5048
            SHA1:A4ED76F787B333112D71987800EAA56533E9F087
            SHA-256:502EA0BDCC11EF08A91F930CD6C49CAFFA47C9934F5B1FAD09CAB790A6D8B430
            SHA-512:F818A906FFB7CDED07C7D73B01C5B8E8A37BB58278CB2CCF20E25F5FC2E173E3934951F1A619852187C082CF470DF264AF9B94E4A82F40EAE3C267940D437BF1
            Malicious:false
            Reputation:low
            Preview:<svg width="17" height="16" viewBox="0 0 17 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M15.0882 3.21873C15.3736 3.51248 15.3736 3.98748 15.0882 4.2781L7.07395 12.5312C6.78859 12.825 6.32717 12.825 6.04484 12.5312L1.91324 8.28123C1.62788 7.98748 1.62788 7.51248 1.91324 7.22185C2.19859 6.93123 2.66002 6.9281 2.94234 7.22185L6.55484 10.9406L14.0561 3.21873C14.3415 2.92498 14.8029 2.92498 15.0852 3.21873H15.0882Z" fill="#00AE42"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):456
            Entropy (8bit):4.595687723934498
            Encrypted:false
            SSDEEP:12:trCv0uC2gB2Yh3adniqkhRXoEFafg9sAAP6bSiM:tuv0ucBH4nrkHoseg9sABSiM
            MD5:F09CE76CA1E9CC96C96260D76B6E5048
            SHA1:A4ED76F787B333112D71987800EAA56533E9F087
            SHA-256:502EA0BDCC11EF08A91F930CD6C49CAFFA47C9934F5B1FAD09CAB790A6D8B430
            SHA-512:F818A906FFB7CDED07C7D73B01C5B8E8A37BB58278CB2CCF20E25F5FC2E173E3934951F1A619852187C082CF470DF264AF9B94E4A82F40EAE3C267940D437BF1
            Malicious:false
            Reputation:low
            Preview:<svg width="17" height="16" viewBox="0 0 17 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M15.0882 3.21873C15.3736 3.51248 15.3736 3.98748 15.0882 4.2781L7.07395 12.5312C6.78859 12.825 6.32717 12.825 6.04484 12.5312L1.91324 8.28123C1.62788 7.98748 1.62788 7.51248 1.91324 7.22185C2.19859 6.93123 2.66002 6.9281 2.94234 7.22185L6.55484 10.9406L14.0561 3.21873C14.3415 2.92498 14.8029 2.92498 15.0852 3.21873H15.0882Z" fill="#00AE42"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1344
            Entropy (8bit):4.505776078958631
            Encrypted:false
            SSDEEP:24:tYRUyKut+fT29iIGHXT3o2tRhzLT3ZjXagG6YBDD/gIW4/mo4m5G4iVaG9oBW7TG:gxtU/c2tpzgjYIh/msQ4eaMoBntD
            MD5:FFE45E0F7E491D743B45BC6A2D71585D
            SHA1:D9944EB79E54BDD98994E940AF5CA94DFB9F2896
            SHA-256:3277C4E76699B2294E44D4FBC9DE9D0DE6B2DB375A76EC776741BC1348ABBE0F
            SHA-512:F574C874601A2146E6EB653F1B0629CF1D668C5ACEEFA779EDA57AFABB90AE5D7A8B174BB3D8E45445975B8F359D8EBBB2F46055DF772516E4C54E4FEBC85EF5
            Malicious:false
            Reputation:low
            Preview:<svg width="24" height="25" viewBox="0 0 24 25" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_13578_18912)">.<path d="M12 1.86133C14.7848 1.86133 17.4555 2.96757 19.4246 4.93671C21.3938 6.90584 22.5 9.57656 22.5 12.3613C22.5 15.1461 21.3938 17.8168 19.4246 19.7859C17.4555 21.7551 14.7848 22.8613 12 22.8613C9.21523 22.8613 6.54451 21.7551 4.57538 19.7859C2.60625 17.8168 1.5 15.1461 1.5 12.3613C1.5 9.57656 2.60625 6.90584 4.57538 4.93671C6.54451 2.96757 9.21523 1.86133 12 1.86133ZM12 24.3613C15.1826 24.3613 18.2348 23.097 20.4853 20.8466C22.7357 18.5962 24 15.5439 24 12.3613C24 9.17873 22.7357 6.12648 20.4853 3.87605C18.2348 1.62561 15.1826 0.361328 12 0.361328C8.8174 0.361328 5.76516 1.62561 3.51472 3.87605C1.26428 6.12648 0 9.17873 0 12.3613C0 15.5439 1.26428 18.5962 3.51472 20.8466C5.76516 23.097 8.8174 24.3613 12 24.3613ZM17.0297 9.89102C17.3203 9.60039 17.3203 9.12227 17.0297 8.83164C16.7391 8.54102 16.2609 8.54102 15.9703 8.83164L10.5 14.302L8.02969 11.83
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):521
            Entropy (8bit):5.220169191375485
            Encrypted:false
            SSDEEP:12:tvbA91nRiUliA8vW4bECIRXYblgjhh4Xsqjhh+l5aK/:tE91nRiUlwvRbERRXYbajhhhqjhh+Dai
            MD5:3EAA9BDD973D3648B6099297CA43B715
            SHA1:9509FA55EE616F5AF6E023DD2CBA2DCFBABE95A0
            SHA-256:C7E927CF099BEDD1C198F322FA99B7C0B8BFDA634B5171716D67F6881F04CF35
            SHA-512:3E075B3DDA81F0A5E91594F5974B7866E1FB162EEA6DAC9C5DCE6965900272A6A530F9B3DB25A9D5BBB91BA297C4E6451517F67E147226CA2731FE09CE1B8909
            Malicious:false
            Reputation:low
            Preview:<svg id=".._1" data-name=".. 1" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 16 16">. <defs>. <style>.cls-1,.cls-2,.cls-3{fill:none;}.cls-2,.cls-3{stroke:#2b3436;stroke-linecap:round;}</style>. </defs>. <title>Slice 41</title>. <rect fill="none" x="-202.7" y="-112" width="1440" height="909"/>. <path fill="none" stroke="#262E30" stroke-linecap="round" d="M3.62,3.25l9,9.29"/>. <line fill="none" stroke="#262E30" stroke-linecap="round" x1="12.37" y1="3.47" x2="3.35" y2="12.75"/></svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):309
            Entropy (8bit):4.971698449284844
            Encrypted:false
            SSDEEP:6:tnrZvUYltumc4slvIyl39/flW6/qHpumqZtXIDoW49/flW6/qHpumqZR:trZvnltuCylJlSHcht4P4JlSHchR
            MD5:001E8DDECB55A8B8EF592C9656CD9F50
            SHA1:AB0174E266F40DB583933F4C012A1076BA5C87E1
            SHA-256:AA3437A0DBBBA7633AF0FBDBE349DD4D74A8E60616FE55BB0CEDADFC885709E5
            SHA-512:8E953DE9F0295A3F51EF84CD8868E00F427526BC6228140B50C6B25C2D43EB56864A854FD6C2A14E2A7D5C426D9AA1B7C71716342F428951687C7B8C71D3F3F3
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M14 2L2 14" stroke="#00AE42" stroke-width="3" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M2 2L14 14" stroke="#00AE42" stroke-width="3" stroke-miterlimit="10" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):489
            Entropy (8bit):5.2011752271572345
            Encrypted:false
            SSDEEP:12:trZvnltutWnBKnP3JlK4Hcht48rtj3JlK4HchQLqiHAie:tVvnjutWnC/JlrHchtnrZJlrHchIqHb
            MD5:70E82C8D6A3FA2DE6CAE40F87430250C
            SHA1:5A707F20DFB08510851664970FDE1377CB81406E
            SHA-256:840DA76D76ECD5644349CC6700FBD79F33541D3FC0AA685DB1CA9E88FEBEE4A7
            SHA-512:5D47CF307A1570B89707B5BB5D2D26598293BC5DF6929B5DEBC9399CC520DE1B8D221DF0AB6AA710925820486D0793069E67E164E721BE67BCD4E2A99AAE1E58
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_23_257)">.<path d="M14.5999 1.40002L1.3999 14.6" stroke="#00AE42" stroke-width="3.3" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M1.3999 1.40002L14.5999 14.6" stroke="#00AE42" stroke-width="3.3" stroke-miterlimit="10" stroke-linecap="round"/>.</g>.<defs>.<clipPath id="clip0_23_257">.<rect width="16" height="16" fill="white"/>.</clipPath>.</defs>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):983
            Entropy (8bit):4.549710102911978
            Encrypted:false
            SSDEEP:24:tVvnjuXMMWVUMEWxb8xXVZGkrOi0mGzpyBiaKgn9MMpeZHoQ0Lr6ol0SiM:rnZpJE4IZ0mGzABn3h5
            MD5:2FBE73F51FF0CA465D5582365A32A57D
            SHA1:D61083D829A6BD9A312672120E1B94A2F98D6674
            SHA-256:8588865E4603DA54B28C3638878E4DDEC10492A08361C0610F2BEFC15C91EDFA
            SHA-512:D1961CA3D47650721096D91701503D4E22673CEDF6A11AA03486F5B0B543EF59D1786A423FA470A733EF5CFAF8F5C8F0F5B568C6FCB7023C70F789FF7F7C6C53
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M1.5 4C1.5 2.61929 2.61929 1.5 4 1.5H12C13.3807 1.5 14.5 2.61929 14.5 4V5.5C14.5 5.77614 14.2761 6 14 6C13.7239 6 13.5 5.77614 13.5 5.5V4C13.5 3.17157 12.8284 2.5 12 2.5H4C3.17157 2.5 2.5 3.17157 2.5 4V5.5C2.5 5.77614 2.27614 6 2 6C1.72386 6 1.5 5.77614 1.5 5.5V4ZM2 10C2.27614 10 2.5 10.2239 2.5 10.5V12C2.5 12.8284 3.17157 13.5 4 13.5H12C12.8284 13.5 13.5 12.8284 13.5 12V10.5C13.5 10.2239 13.7239 10 14 10C14.2761 10 14.5 10.2239 14.5 10.5V12C14.5 13.3807 13.3807 14.5 12 14.5H4C2.61929 14.5 1.5 13.3807 1.5 12V10.5C1.5 10.2239 1.72386 10 2 10Z" fill="#323A3D"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M1.5 8C1.5 7.72386 1.72386 7.5 2 7.5H3V8.5H2C1.72386 8.5 1.5 8.27614 1.5 8ZM7 8.5H5V7.5H7V8.5ZM11 8.5H9V7.5H11V8.5ZM14 8.5H13V7.5H14C14.2761 7.5 14.5 7.72386 14.5 8C14.5 8.27614 14.2761 8.5 14 8.5Z" fill="#00AE42"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):987
            Entropy (8bit):4.504647361065947
            Encrypted:false
            SSDEEP:24:tVvnjuXMMpeZHoQ0Lr6ol0Sie9MME9a1r2vBaJ80afMo9kaaWML+tFAQ7bNAng/n:rnGh/BGbkmCEV
            MD5:CEAA210E16F46174F80391963CF8B3CF
            SHA1:9172BAE120A1450F436E1508E1D30ACBB2783CBC
            SHA-256:DAD86FEA754C0F6E42A1D943E8267AC23CE878A969205385B46638E305DA32B4
            SHA-512:6039A3D2C07DD5CBBA61D4FBEE967A3656DE9ECBCCBCC58F2F89919E2CAB70B7C5CDBC1E6C6C7747F02101FCBE0D1A2FFB710660CAFD113C2078B9EB62319126
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M1.5 8C1.5 7.72386 1.72386 7.5 2 7.5H3V8.5H2C1.72386 8.5 1.5 8.27614 1.5 8ZM7 8.5H5V7.5H7V8.5ZM11 8.5H9V7.5H11V8.5ZM14 8.5H13V7.5H14C14.2761 7.5 14.5 7.72386 14.5 8C14.5 8.27614 14.2761 8.5 14 8.5Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M2 1.5C2.27614 1.5 2.5 1.72386 2.5 2V3.5C2.5 4.32843 3.17157 5 4 5H12C12.8284 5 13.5 4.32843 13.5 3.5V2C13.5 1.72386 13.7239 1.5 14 1.5C14.2761 1.5 14.5 1.72386 14.5 2V3.5C14.5 4.88071 13.3807 6 12 6H4C2.61929 6 1.5 4.88071 1.5 3.5V2C1.5 1.72386 1.72386 1.5 2 1.5ZM1.5 12.5C1.5 11.1193 2.61929 10 4 10H12C13.3807 10 14.5 11.1193 14.5 12.5V14C14.5 14.2761 14.2761 14.5 14 14.5C13.7239 14.5 13.5 14.2761 13.5 14V12.5C13.5 11.6716 12.8284 11 12 11H4C3.17157 11 2.5 11.6716 2.5 12.5V14C2.5 14.2761 2.27614 14.5 2 14.5C1.72386 14.5 1.5 14.2761 1.5 14V12.5Z" fill="#323A3D"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):203108
            Entropy (8bit):7.979534705468338
            Encrypted:false
            SSDEEP:6144:9KMxn0bBrkMeY9V3jKk0OFxuaUlFu6YG2:TFSrFeY9pKPOFxulFFYG2
            MD5:5366D4ECDAC930B6E8D0BFE2F772963E
            SHA1:7C41593CE2396DD7357A901022AA9E412DFCC918
            SHA-256:525C0F69342294A7075F967E9B852A87F0EF6845BA92149F7CF701F16455FFF8
            SHA-512:B3F7B1EB4668E58AC46D221E6B616888D926F1CA97E5461731ADD7D6A4BD97662936587231A6898586CADE94629C88FB46541B52D4D767BBE47C97D5B6F34DA4
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx...ip$...wff.U..g.}..v..II<F<..83K....3>&.v.k.....]....c....X..F.gF...u..!.#Q$.-...&....o.......h..Y.......&.....b..]b||...........V...................;..0.................# ..................;..0.................# ..................;..0.................# ..................;..0.................# ..................;..0.................# ..................;..0.................# ..................;..0.................# ..................;..0.................# ..................;..0.................# ..................;..0.................#..>.X.&...P............x{1.PB.Tr..u..9x...............b8a.Q.VO...{d...n..A..........x...X......|.L.p..K..X|...x.a.&..........I...0..._...o.}..~....n...g^.|jQf.........>..[O.m.6.j.....oY..W.......'.....O..(.&......uC..b....y.....xv..d.....c....c.VO.ju.<..........c..R4.w.-...=7.\......w.w.V=......Tx...y...`......uB..2.......O...G./.'.....wsw.U...:..S._......w.d.#.b-$.......A.....$.C...
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):361167
            Entropy (8bit):7.984196973538781
            Encrypted:false
            SSDEEP:6144:8UANEhfuTBd4LgAajT7hXh/yRNMtnUAXLxfChp8GeX1h4FYr:/ANgfuTBRTx/yHAXVfChp8ZP4mr
            MD5:C7053C8F6DC5D76ABA1EC2260417A2AE
            SHA1:69D7534417958E1AFAD6D3D6446EEB91F8EB34A7
            SHA-256:DA23A3468ACFDE8C54449D0FADA135CC59F1EF5587B4590B76E01C11F61315B7
            SHA-512:D707FDEA22BE969EDC5B185DA363DBFEDC11616B0787C2955AA79689500411140FFC4F7BFF42B20C9AABEB2CA391F296ED9A810085063A69A55465403AC2A780
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx...w..W....>.. .LY.R...Gx..9.s&.~....D.X..&...'*.T.W").....EtG..&6.+.^~Q....b.?...........Z...x.1.2..w~.^.+..z.^,.i.R...#.. ..A0,syy..Z.s}....A@.w}.?.!$I...rv..x....d.. ....;.A.!..j.~.F.w..Q..\9|...z.-X.[......@...uH<^..(Z]+...p..........47..v........=T.;..@...C....d<Y.m.8*a..8....A..,."G..j.!.. .].m7<*.I...(....>..#S.....S......b.^...iP=9.z....b....}.......a.....%Y.7....q%IZZ..x.....9..P.....n.Y...G..."<./..<.a8..9(}.]..8A.^.V3M....h....;...D....t. .E.h4$Y"....,...{{.C...a.(...A..ww.i...S.q.....<.x....B,MS..v}..(...;.f..j.......[.!.</....i..,M}?(#...M..P...tC'(b<.x..t..%p.OK.(.B.E.e..Y..N....5...[g:...X.....).g...0.&.sI..a.....A.$I...zqy!7..by..*..].m..q<I..|.E.n.''.z...)..(...J......p.1,.k.Q....|6.|.T.. .C..dY...aA.....).....n..g....h4.l..........c..N...y.G.@...;..(...V[.u............dY.j..U.,..*..e......&.....w}.g.b0I..r..iKU9....n..i)...i*M........S<.y.{.O..n..'I..A.."......#I.d<Y..GpY<-..(...%I..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):386638
            Entropy (8bit):7.969044469205919
            Encrypted:false
            SSDEEP:6144:CX/Mb1Bgtp0m8d1yED1xLsgCfcURa5pQAYGMYUJCyr1BgnaJ2PXcL+H9ba:e/Mb8p8dkE5SphRysGXJc1KXXcydba
            MD5:11E1120F3B6997BEEDAFB2DC8EDB69FA
            SHA1:14095A7EADFF8ED05A2EC2C83FBB2055247997EC
            SHA-256:7E669DFAF9F91D06835DA90579E7E210F2CB8A99608B0AB5F3AE2511D4801148
            SHA-512:C0D82D634CD76F5B44E2A8DCACA1A75255BFE688A78957B2648F6309AB1CB9A1063E258276044177E07AFA86404692ABB0F1C124BC236FDD9A90093FD0DA2BC5
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx....r.W.....y....H..Z}.....?.7p........t...E.@UeU..<8*7YB.%...Ta.......W...^.......9.....(..p..T.........2..,......Jp..$IU..,W.uUU8...>......(J...r...z[s.y....I.</..IS.E).L.TQ.Q..EQ.U2...c?.!...*.....A...W..@..p\..I.h.F....k...*...i..H....+..0l.e......;....x..<o.:.bI.x...).a}.m..8.r."1,... {..Y..Q...p&.2..GQT.eEQ.q]/...W[..p1.eYUUh..P.......8M.;.....iUS.. pa.]]^y._7.C..#..{.eeY.D...n.EQ.....E1.aTEaX...~..eQFQ.$i..OVs..'.b42x...u.,K.......'..e.Y.$Q.%Q....Y..q..a.%qR...-.. .......v.0..........y^Vd..{..n.8.....{}?(i..(.0.$...cx.w}.We..I.......m.2.3......$.b.v<..[...w...+..........E.Eq.Z..a.....j..a..F..c..\.e...t:..u7.;w.......i.4..ZQ.].q...a.U.f......t.q\..Q....j..7...y......)...P.E.......:.8..$....*.... .....,.........E.,.j.Z............,M]..u..9.@Q.].a..0.$I....*)2..Q.....{;.O....4.q..8.e..t......$K..j.&...aq.l6..8EQ.p......*.aDY.i....91.:..UU.i...$..E..l....f.!....^.$A.I.1M.....y?... .1..E
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):403477
            Entropy (8bit):7.973222631283028
            Encrypted:false
            SSDEEP:12288:npkqbyXnL5wdFEgZi3fAjQbIUaXEfAuvRz:3k54F7ivAEbIUa0jz
            MD5:146CDBB6B663D352F4A0E57F694AEEC4
            SHA1:2C4143AA9C9C956065553512ED05BF0757ACA8EA
            SHA-256:AE7E8719E6CBAF93911F5CDEF808A75E437EA73EB632571C68629949B450AB26
            SHA-512:7649815E0AE0E0DA184719715EC4AF4EA2723B5759BCB1883EEDC243DD0C5F090405695BE837F757F20A18084AFBC9F8E0A6453D7CC2DDBE79443EC37E75AF7D
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx..is.I.&V.Y.^.....~..c.o.;.../.a.#._9.....-....B.[f:*.P..Hd.Z.$.E(..,..O.<'...._.U.........m....D....Q.../....s~.....qt]c.).j9.i..ip..F..!.$I....k..c,......$q)M.......u..YmK..._a.sEQdE.=O.u..cM]./..."I.B....a.3,..z.;....,.,...}8....c.....Wpr.6.q..C..).b...e1.0.k...h0$!"..q..,..$..i..U.....c..E.e.uhK....g.R.$f...~AI...Qd.0.....F.......u]....S..\.eEQ6.6].....<==.&.x,..O.O..... ..."....t..x..:..".9....(..).R.1..:.....2F.s..+.s...~.E.i.........u....wo..m<..~_.9WUU....h.fYf0.NON.Y....i.....g....\xj9.....b...e...g9c.#T.uYVUU6U-..!...*.......2.b.$.MJ.F.....h..MkC..li.m8.'....i.f0.+....Bba.vvw...:..>|..(Cx>...6..}...!.s...1...M..Ea..j......c.P].EY.E.65.m.4.x.v..0..{.RL0.X..EU6..(..@>.....,.#..}.8G.._Jd".FC..7..:=9.N...._7(}T.y?.8..i.".t}}}0.tq....i...Y.-B.R..ESUEY@.....i.........?Fa......1.l..w1..o*..s.*K..eE.t..M....d.%u../.8X~..."..]..].L]..c..lt..i.c....v).BM...g..u].E.$p.(.........7.bw..d".m.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):416859
            Entropy (8bit):7.993099501638156
            Encrypted:true
            SSDEEP:6144:bPdyyzyJ2eVvovKTn9Jb7WJDbSZmtzBWTn139d1KgE1kZBeGZOJRDjylvg8NpOIl:hy8yJ2Sr/KVbKR4gE1eeGmDjym+OIl
            MD5:3049E2BD5C5EF94F75B9C81D56BDD826
            SHA1:4AB748E1221ACAFC6F90B979BC51BA8AFAB66752
            SHA-256:2B00DCD90A04C0230F171BF2AA709D1364705CC6F8DE461B830F2AB92EAFBA60
            SHA-512:77758CC8E2D3528BA4C90785A344CA857164F16CF35A993D0C202D369043A3342DE5E76002E72AB80B3597F290DE09BD682C264A38D08C23FBECFDDEEEB85155
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx....|\.u'..........$...%R.%Y..U....{..8.........N..&.cGnr.].XT.(.E$........A....-..;...... .R.z7..7..w.......S....0.)L...!.....g.E.]...`.l.f.].ga.!...kqs..c,I.w@.p......,SJ'..F...6.sZ....@#...[m.....fz,..._...^...R..%YB...._..pW..16u.?%I..x.!..9...!HFS.>......g...vj.{E.s...o.~..[:...7.gF...-W....CA).t+.IE{.U..W...G....!d...?.!$....!d..Xm(..r..t..0.)La.S....0.@)%..M}.&."..J..1._{Q.^.a....;....'......0b....<ux.t.8...8..0....p.. .. @..y>i.......'t.H.#I...~.(I...'.B0...i>....\,...8..IR..z.4}.0....%4jO......J.t...B.....m....0.0......S.x.S....0.)L!M. .."..%..;o...x..EI....R.e...x.....fM..wg.p..6-.4,C.W2w..|y._..."... r<.(.....%..Xz...$<..a...0....1z}H...Gu...H...@../.[. w.$~..*......./+2...ti..mb.I....i.)X.........E.!t..*BHP_.q.y....O6.<E..0.)La.S..{..Q)B..N..f......'.".YP_.@.....cL...%..:.)..R.....v.rBCa....0W~.O...#..Q.(....2./...2...#....c..W.....gj.m.rK...........G..fC4M|)e....a..i.[.L..o.b.@..{.X.D
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):458257
            Entropy (8bit):7.984541114580673
            Encrypted:false
            SSDEEP:12288:IC5ADQ8+YsGK3q1MW/5K0coxZXvcxJYmG:R5AM5Y4EF5xZYS
            MD5:64B745CF1F3D790856E95F442BAFB0D0
            SHA1:4807255460894407C923E2AD58B9DAD24A22C193
            SHA-256:3B1DF47790D59D5C6FEA9E0419946BE9E8E1FA82EB819EA6D289F71AD996F2CB
            SHA-512:E635428788C562F0F74590039CFCF3385BDB2E3EF054EBB160257B85745D03694459608BED0D3F74D85658947822A5226C742EB087F781DFD58273A2107867EA
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx....].}.x......U...*..l.%.Z.Z.e[.%..O.9#[6..L.$....xb.... ...0..3.X.`..d.-.....l....}..}?.wO...".{........z..{......n...>v....A0.CQ....=....m.....tC.(.C1)......t*..).EQ.l.5M.Z.....7o..}..<..A..g....$...A.kkU.p...A=4Pt........1.ch...\>........CUU}?...8.......:.. AN...G...V...^Y[..`....xW.(.....N.:}... .......Ib.C3<.11.H..I.$..d..e........_....V.$I. .\.../$....q..........E&..:.............7V.......U.1.....`.....R\Z[...m........^x.3.X..<8<.....N`(.....o..G...~....h.$..I$......kz..... Dt..]..x.?p`.0.f..8....^...T....Q..0. p.f8..d..|.~..L$.....'?....o8..}?.8.@.....f...h|...h......n..".Hd2.F.9............e...H..3..MS........%...y4$..C..4M_^^VU. .....Bt.....L.$A..(.>. IR0...].M.T..^.[..E.N.}..EQ....IR.n.0...I.x4D...,......%JB&..q.q\e..l.Vt.{H..MU*s..@....VVV.n.$.e....N...(.'....iz.?...n./..y@..EQ,.LOMK.$....$I.!.........V.u..^..<?...P.U..i.j4Z..y..a{.}7.......<A.bL.(*.L`...t4M7M....~.....,{...?..s....q......./_. ....I>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):86001
            Entropy (8bit):7.905448296052747
            Encrypted:false
            SSDEEP:1536:Crts+JphJKO2UYDCPMIRq6BK5S8tGPepk2VMU/wVFzZvcesd1RNvYWDzPdrRXcPg:C57KvU6+1R5BGS8eepPMUOZkeGPYWPPt
            MD5:0407F0F7AF623DF24CCC43D3F76C2512
            SHA1:1E3725963045EBDAFDA1850F144328E169572E00
            SHA-256:AE179032234CFF03DF90E27B0D2ECF58CFABDE500798F614650DA02E867FCA9B
            SHA-512:727263D4C78930AF9D9099446994B2B3DA1B6B12591A6273784F98A07C00E0C0EFB3BCF8C177C893CFBB2C5FC6261326AFD3AA7CE84EC713B4770746A54324C3
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx...g..i...|.......7.......Yw{.#.<..O.qb.HJ...E!}b..D.t...3......3...........UYi....b13...@.&....E.]..U....kU.u%.........>.........0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ .................0.... ........@ ............
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):299046
            Entropy (8bit):7.991622628929847
            Encrypted:true
            SSDEEP:6144:oMIqs5HeBS1wCCV5g6rRrtlTMJjt4w/GB01Vrb0Rov:oM85l1wCCRrdthGB4MG6VrARov
            MD5:6B24B4D23BB8C8A81FAAF644D13EF3AC
            SHA1:C4321C9D56E1920746814B9229C0136D716996F8
            SHA-256:BE096FAA11D8521481835F1977C00667FBB7801D1C2916E2B8649EA4ACDACF5C
            SHA-512:F32C4080C864F040D0DA71D165D4459D7AAB398D4F3CED0E88A7C1F0FD78F12E1496F95F5F904A62CCAE510F5A6F00A4404702A35EB786AE797909A6D385FE7E
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx..i.d....Yr.Z...z.bw.Ev.".Z(..;......./....w...`..............f,A#J.I5..f.[u.[.g...8..y........T.Yb=..?.'.0VVV..........................8.@...........'................0.........p"..............@...........'................0.........p"..............@...........'................0.........p"..............@...........'................0.........p"..............@...........'................0.........p"..............@...........'................0.........p"..............@...........'................0.........p"..............@...........'................0.........p"..............@...........'................0.........p"..............@...........'................0.........p"..............@...........'................0.........p".......Eg........^......x5..a...?p."b..........W....p .@.#.D..%.3..L.....F..|..........W......\..E.m.O7|..P.bL0>.;.....7V..nJt.-D.dM.v..G.}T(............@...A.Lp.q.K./G. <v..."`...f...v.E2m..8.|.q._....w....=......
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):309861
            Entropy (8bit):7.974239390540617
            Encrypted:false
            SSDEEP:6144:uNLqdvdSJDXhEveNpa0t35IpeTQnRhRl4He4ArjInwEtUSAWnPK4yRGpCKJt:uzJb3PtpoeTQnRhRlWeRr8wEtUXR2CUt
            MD5:EB568E58AD228606EE0AC75CE0AB6139
            SHA1:49DEA2F388443EDB5B12EAA53701945D4C6F21E5
            SHA-256:C0070BA940D447BDE555587AFCB7C0C69CE01995818C4FC37242D8E0E3464F98
            SHA-512:8C6993E46E2ADADB493340A12EAD4D5671282A9758043173A4D58C5C725F9123049F435D0FFC88B1AA866180F9BA23F30C6C539A8C7EDD6598CA3BD2414675D0
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx....w$I.............<.R$?..DJG.(.O.>H...e...:...[../..n.'..:++......g.....~....C./...#..@(..L&....O.T......*..P..0..p?.5.5@......7.....E..a..m.(....c...(..).";..8...v... ..E.x.w@....Da6....M..?.. ...z.....dYVT.4MA.....C.r...-..c.....4..0..R..4I.......7.<uP..$I...d...k.MS..@G......_.zZ04M#.....I.q.Ga..I.c.<.... .A.q\...d..m.Q..Y...q..B.E....u}:3Q.I.4..4..{...y.`..H...).A........!......i.. ..`.IUU0H.,../.,...4.u]]....?-.:.t.o..7......:..O.I...XU6W.W...o....<G>.Q.mZ. ....|%KR.e..^....o~..[...P.@..$....3AP$..</.$N.lLK.,......N.&.s]...8.0.=M....0..q..i..A.$...n.4..v.C........a...T..(.,.vl7....=.e~u..EQDQX..4M..e.~.p......C_m.u].a..*..Q.....`.q.......r...A....s=.......$.E.u$E...A..m....K...... .i.A.D.5G...x<.%.W.7.E.@......s...$q./.". c..<..CQ.e'.$...aX]..7M......rp....SS.5.A.(v]/M38.?.y6.[.0..z.o...../.K.f:.uh.|...E.......?6..d2..A.gG!..."...L.@Qt...y1.N....7....C`\.U-J.b9.0..E.L...<.I.|....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):212159
            Entropy (8bit):7.983364363701902
            Encrypted:false
            SSDEEP:6144:Dp3x4n8NpvUdVMDTz1KStJvSx5M2HQ3M4:xx4naOdOTz19tcHRMf
            MD5:A7A17C5455094606CD5581815E5379AE
            SHA1:EF47A89D57FB7DF40CBEB3DE873EB6B7DCA90B2D
            SHA-256:E0AE8D309D8FDF4B208065307A883DEDA29417D4CAD5DC982011571E80118076
            SHA-512:2FD5119AB522A8D9FB11DBF04CA0047A27AA4CD6122EB4252FD0E966EF2B722551A17BA4F8EC9942A3AA1D0720F9E7024CC3CD19AD50DF5320ED4E9FE394DFD3
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx......y ..:.........p. A.........%Yko..v.O....mW...W86^Y.[.xm...E..f.....|c*..H.....>..E."..L.LUf>y<....~.Y-</..\(.r..l6...A.".....vQJ.A.T.,O..~..$...y..<..X.u.r...8..(..y7...J.....q\..u..q.....c.iy.eY.<...B....6.6.Z...7wZA..l..!.(.I.PJm..j<B.O..|...u.....w....T.E.6..*B....`0 .@....B.....,..r.PBh........<......(..f...c.....:.Ba.&.VUU......v.`u..EQ...F.'...n.......~.GYI...R1...z..y..X`.1.1...b..K/.......+...(...i.H.L)E..r9.,....x.j.`..,&...8..N.2...a....`.H.d..s..L&w.l.a..&p..BQ..A`....8.. .......0.....{..m.._.u..L'S.P.4.E...M.X.?l4.!.....r.Z....q...S.\.R....J@+p......UUO....y..=X;...!$.|.h+.:..F..[..(..P6.=s.4.[.n;....8l.....Q.5.-.ua..b._.V+.....3.O.:......;.........N..J.....#........}.\,.,....+f.w..N.....k'Nm.l7.....P.1...1v]7..L...d<..8xx...../....k....l.....8...8.g3GU.M..8....y..<-.{.<o.....Bh{.9.L`V.......\..*.r......s..B.B..p.......O/_.T)..E.w...X.....A..kZ~kkS.I7o..'a."..C..`.8A.p._..t]..0.bx
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):490707
            Entropy (8bit):7.995601602173468
            Encrypted:true
            SSDEEP:12288:F+nVUDI3DsJjKWv8LfCdf5hsxCRtHPDZczb7/Tw:js3DsULrCdRKctrarw
            MD5:7D856655A5D4B007EFBF2BC5E87926D6
            SHA1:3F53EAC7FE6AF9BD6FFBDEDEE8056B80B2AE97BE
            SHA-256:F05E33855C65447CE32CAB70EBC571AE2FD7024934AEF5AB9B8B945C5A4F7C0C
            SHA-512:BC485B83CCFCC85F7A6A556C67B3D282DE7AE79856C798C04AD6C0F60CAE44E1802CEF5271BB58B9A1E6ABDAA390DD40FA24701F846DDDCC351FFC55331B47BD
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx...Y.e.}....M{8c.=..I.j.mQ..8..%0...3<./F. @...+.A..A...B.....V,).(..%Y3%...K......N.i.k..U.}.%...8..p~.....]...Z....k...C.........S...........n@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@........F@
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 720, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):740834
            Entropy (8bit):7.993664365562589
            Encrypted:true
            SSDEEP:12288:4ZIE6PZc2LGWkzx6G60R+oxouhedL+A0NkhTmc/ozqN2LHaUpGvlOsybz21Qy:kic2Ldc9xnhOx0N9U5klGv7IzgQy
            MD5:501CEF350E3EEF52AEFB07CF517C3A59
            SHA1:DACA4EA7FFFDB9323F008EACA233DC3505B43170
            SHA-256:8198C5A33733E8091D364CEA33343DD5F4E48B2F505B8DAFCE07835AEFE745F3
            SHA-512:94E42AE6C99B5F134EBCF55378CE730D7626AB251E4D2A39806BB96AEFF3FEAEAD1A00EF617FA11AC161ED870A6DB35D6ED7A2F19FE414E638689E6E8D7072C0
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.............@.J.....IDATx..Y.e.u..+.=.1..L..R...Zn\[..l.0..0`.O.._........_.~3..........(..l.....y:..cX.;"s.03+.HV.UR..J.<g...#b.^.Z.Z.......s..D.._DD.....?....P..`0.....eY..xx..Zic.!`.n...[....ZU..^/..$(.....0....~...?|........pX.Dktb...... .F....-......&Zl..]...RZcT^.J.P0.x(h (..(.....y.A..Z..W.....J.oa0...i..j$...Z.B....".....'))j.u...@U2).....-.I.I*8 ....{b....5h.^ ..L..0)H.!...Z...GZ.....U.!..cF......!....U.,...z...e...R.h-.S.4.#n.K.....,X...W.....g.....L._<.I....@p.ygsaa!..k.d2..>.....c...gY..1...'....B+k.....=..A..*|....s....h.#.X__.}...f...d4.MgeU.\.g...y.......=......d.....H.qrr.....r[.......Q.....VL...pss....Y.=xp..G..s....|[.....h.twv.L.#J....../.. .$....A..%G)...z...k.....].......#.`.!b..Z.,.R.../.8O..1..u._...V..n..8..^{.Z9..f=..s".|.._../f...+...l..g....v..9'..2'.y..TmI........_.x6K.5W.......K....(.x............l6+......z...,.....N.[..v;..V.ZX.S.a.J)......~.....!xpt4.N.........tZ.......+..G.8....(......
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 704 x 422, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):73603
            Entropy (8bit):7.988112458455393
            Encrypted:false
            SSDEEP:1536:EL50nce0f8VaN5FXvGxh246mbE9bg+rQIFhf+6SwTB9Q5gREuPu:y0c9hvXvGxh246m4pgo/Tkgju
            MD5:DDDE3DE45512FCD2B09104CFF476439A
            SHA1:C7177540696175306865C0E238A232E48A9C95F4
            SHA-256:6295F57E9AD7B645A97AF12A28A0B2594197C474B9B0908769B0CA098D4B45AE
            SHA-512:987B506C624DF424F4841012652BAED393A7EBE39AE8C11D0C54DB4F825A54D54DB483FF7F88CBEC51194F20B64D388EA281D0FEACDA869E6A1108EF29D39412
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............rj25....pHYs...%...%.IR$.....sRGB.........gAMA......a.....IDATx...w.d.u..~..p.....*.\.7......HT..I.%J"(i.D..g...Q....Z..zZ...4k.........:.E. . \......J.7..=}.9.F...^<....*.q]D.....7.0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0.3...9..a..a...!X`..a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...a..a...Q..f..a..av.,...a..a....`.a..a.fG...0....B...Y..o.m......j.V..>.0;.....0L_...$`...^...[}.^...H.....=Z.*.K....0.0;.....0.........`...Y...`.-.n
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2097
            Entropy (8bit):4.53843498150348
            Encrypted:false
            SSDEEP:24:qexaqXiWYn++70uZ1dvKTrlcXzXgXsQSnlHqHqfJWBrL9f4OX6OhuOHuXawItsA:LgqSWYdNZ1B7Ss7zItlVYav
            MD5:FB7A91F80B99543605EE81A7057758D7
            SHA1:9FB23AE8DDBDC3ABBA85878D3934ED85F76CB078
            SHA-256:C041727746ACABD616B3BD6AE6C736DF72941493B22FAAE81AF99BE52869FF4C
            SHA-512:324014F2B1FCFAFEC73518F1D26602C061014281624B88191B1BAFC2FC2B23CAE626E8106143D146ABAA5AA32254D81A510A09B70AACF32F0C9B3A89228F2E0B
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" standalone="no"?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"><svg t="1634302375772" class="icon" viewBox="0 0 1170 1024" version="1.1" xmlns="http://www.w3.org/2000/svg" p-id="2705" xmlns:xlink="http://www.w3.org/1999/xlink" width="73.125" height="64"><defs><style type="text/css"></style></defs><path d="M1024 0H146.285714C65.828571 0 0 65.828571 0 146.285714v585.142857c0 80.457143 65.828571 146.285714 146.285714 146.285715h402.285715v73.142857h-292.571429c-21.942857 0-36.571429 14.628571-36.571429 36.571428s14.628571 36.571429 36.571429 36.571429h658.285714c21.942857 0 36.571429-14.628571 36.571429-36.571429s-14.628571-36.571429-36.571429-36.571428h-292.571428v-73.142857H1024c80.457143 0 146.285714-65.828571 146.285714-146.285715V146.285714c0-80.457143-65.828571-146.285714-146.285714-146.285714z m73.142857 731.428571c0 43.885714-29.257143 73.142857-73.142857 73.142858H146.285714c-43.885714 0-73.142857-29.257143-7
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):149
            Entropy (8bit):4.761205588245347
            Encrypted:false
            SSDEEP:3:tRBRNqXH3AR+3HpkKcvdvyq7SLvDmJS4RKb58ZQGuMncXH3AR+3H50qGThgqL8v:tnriQo38Numc4sl7an0Qo3jPqL+
            MD5:41F9FA0CB4FCB660B341FF115F304080
            SHA1:BFE87B6A38000C4012D3A583CE802DDCD6458E1E
            SHA-256:FD8326EE29EE34058A4CFDDCE1D2187F0A13BB924E811B3AE9A30714EA5B6CEF
            SHA-512:2E3A2D1A4A3F8970ADB9393EAC71DC9BBB19A3303CDDD974D563769DFA43E6C38025DC38D11553FD3D07A153D13067C2ECEF2B10797A8108D2890A57D5BEF922
            Malicious:false
            Reputation:low
            Preview:<svg width="80" height="80" viewBox="0 0 80 80" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="80" height="80" fill="#675E5E"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1715
            Entropy (8bit):4.199463917360153
            Encrypted:false
            SSDEEP:48:H+iI6c1y0SE8s0kYZoaVrcnpoluV1i/lWXEIDayOjsRPQgn7:HDI6c1ydE8srooaRcnpolei9So4PN7
            MD5:7F15A1E04AC1874B675C5DFD7382BE90
            SHA1:2E84C7B68D43D5893ED960F5B711C099D5AFA6BA
            SHA-256:6C400F618D4B1C7EE7338BB8DBAA249304CD41C6FF0BAC4504A14A9C453F871F
            SHA-512:CF3CCAF1DB0ADFD336D49676EFD430929349020C856099E6DA98D0C75DD2627BA46DDDB33FC01A2077BED2FCA0A9BC450AAB08621B4769295E70F7E006FB41C7
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="13" xmlns="http://www.w3.org/2000/svg" fill="none">.. <g>. <title>Layer 1</title>. <path id="svg_1" fill="#6B6B6B" d="m0.91117,2.312c0,-0.37333 0.08867,-0.714 0.266,-1.022c0.17733,-0.31733 0.41533,-0.56467 0.714,-0.742c0.308,-0.17733 0.644,-0.266 1.008,-0.266c0.57867,0 1.05467,0.196 1.428,0.588c0.38267,0.38267 0.574,0.86333 0.574,1.442c0,0.56933 -0.19133,1.04533 -0.574,1.428c-0.37333,0.38267 -0.84933,0.574 -1.428,0.574c-0.364,0 -0.7,-0.08867 -1.008,-0.266c-0.29867,-0.17733 -0.53667,-0.41533 -0.714,-0.714c-0.17733,-0.308 -0.266,-0.64867 -0.266,-1.022zm0.924,0c0,0.336 0.098,0.61133 0.294,0.826c0.196,0.20533 0.45267,0.308 0.77,0.308c0.32667,0 0.588,-0.10267 0.784,-0.308c0.20533,-0.21467 0.308,-0.49 0.308,-0.826c0,-0.34533 -0.10267,-0.62533 -0.308,-0.84c-0.196,-0.21467 -0.45733,-0.322 -0.784,-0.322c-0.31733,0 -0.574,0.10733 -0.77,0.322c-0.196,0.21467 -0.294,0.49467 -0.294,0.84zm7.812,8.694c1.12003,0 1.94133,-0.518 2.46403,-1.554l1.008,0.588c-0.2894,0.6627 -0.7374,
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):1257
            Entropy (8bit):7.785840207667797
            Encrypted:false
            SSDEEP:24:qkWzlOzS74Vq0ySdo7C1uhdzPQ7db06wkRr+K6Dyy6/F2CRV:qnld+qC1uvWdo6JRraUgMV
            MD5:2070A6C203644A9EEC7AC448609F6E17
            SHA1:ADC96F0BE83CBA8EAA5F9113D334D1DB16B48011
            SHA-256:417E8EBBB7A6A2D9DCCCA69F2C6D22BDA43278CF44C86E2F68E511F25D274350
            SHA-512:82D4A4EDC3D8A2C521756E61A2878007C4547AF96DFEDDC73C3F705DF39A8FE2DA4829ECC7546E577D06D6C048EDD945FA91E77ED3AD65D005D6ED483092DA2F
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR...@...@......iq.....sRGB.........IDATx^.[]l.U.....yP.E.'5.2b.H...B.&........$.e.@4.....1>.HvV#Qb....Q_4."1Q......". .......=f......l;.mz.ig.9.9.{.=s.\B...7.....n.w.L.0p..'.].s........aD}.\......f....._y..|0...!.0......f.~..jF7.N...F.=.^..P..._.tmc3.Au"' m.E.:..1p.6X....-..e....B...EJ@&?p7.r..).%.W...Q.0.<......J..>..XP.I.n~.-IA.TPx@I.p.........%kq.B.bR.....+b..`...J..l......MDe.JE.W.m;..m4.v..3Wwj..;..d.b..[.,.....N..%}Y.R.B.BtrN...y..s."..4.1....).w>..Tv.i..&.........o.'..AX..!`.....v..n..S..gY.......iP...,]..6...i.<.&@........$@.../2r... ..o..,1 .AY..`!.,.Z..aG.S....a...H... n.#.&.~..A+.U.C.\.c`.C...a.?..%}.!?=.......[.....;..C.../..0...T%...k/....a.........|..3.....$].......C@....q.:..d..a ..(..L.2..Y@N.........=d),K..K.y.(:..'_n..._~.........S. w.g~w.O...Fb....._w..v5o...j....V.i.<N.CN......j..F..l..b;..w.(#...]..x....S.|d.7.6w....s..|..o..z.......a.......pVk...U.<.>.F...k....M..@..0.X.Z{.O..=.0...:..+.C..:.O..\......rQ.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):163
            Entropy (8bit):5.022581130633185
            Encrypted:false
            SSDEEP:3:tRBRNq6FNpO+aFTMacvUj6FDMJA7SLvDmJS4RKb58ZSFuHeeVFA9DwW2AmYHZZv:tnrLJUGFcAumc4slvI/M9DwWnmqZR
            MD5:5A5BFBAA271CA9D8DAD10487CA519012
            SHA1:F964C549F26F823D89D3FFBEC738DF40096AC4D6
            SHA-256:75D06633454F3B0A9D797A7C34390C83EB774709F361C8FB7031DC8163500530
            SHA-512:F30B35D6CE94EF5F8B24A511582A90FC3BCB2AFCCB60C34DAF08A7333A10136C475720E644C4DA3A23E83B461D8FE4B9AA3F29B595498818665B4596DA80108C
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M2 7H12" stroke="#262E30" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):156807
            Entropy (8bit):3.836961172741476
            Encrypted:false
            SSDEEP:1536:mdA+hbwawprpXkp7wKD7aNb9G9FzR23qjx9MiiwNbqBrC9nOsG8LMc+kDqSJw5s5:fcMqHRqaiJC
            MD5:533E1B4FDED4B655849B78D069458B68
            SHA1:2D56D46AADE3E7C054C41454D01E465865256FE3
            SHA-256:5BA24D303695519A7A2DE1E7B3FE6665FA448B01FFBD06058A47D9786A71BDD3
            SHA-512:CC615742E1BDF818CEB75482626DE56FF8A990E46D96F9B44CB3464A923A1404CE01D1A21EAD98C2C014F55DA81847690AC0455F92FD922106050EA4655FBEF9
            Malicious:false
            Reputation:low
            Preview:<svg width="96" height="110" viewBox="0 0 96 110" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_7669_29792)">.<path d="M32.164 80.4225C32.1063 80.3652 32.0485 80.3652 31.9908 80.3652C31.9331 80.3652 31.9331 80.3652 31.8754 80.3652C31.8177 80.4225 31.76 80.4797 31.7022 80.537C31.7022 80.5942 31.6445 80.6515 31.6445 80.7087C31.6445 80.8232 31.7022 80.995 31.76 81.1095C31.8177 81.1667 31.8754 81.2239 31.9331 81.2812C31.9908 81.3384 32.0485 81.3384 32.1063 81.3384H32.164C32.164 81.3384 32.164 81.3384 32.2217 81.3384C32.2794 81.2812 32.3371 81.2239 32.3948 81.1667C32.3948 81.1095 32.4526 81.0522 32.4526 80.995C32.4526 80.8805 32.3948 80.7087 32.3371 80.5942C32.2794 80.537 32.2217 80.4797 32.164 80.4225ZM32.164 80.9377C32.164 80.995 32.164 80.995 32.164 80.9377H32.1063C32.0485 80.8805 32.0485 80.8232 32.0485 80.766C32.0485 80.766 32.0485 80.766 32.0485 80.7087C32.0485 80.7087 32.1063 80.7087 32.1063 80.766C32.164 80.8232 32.164 80.8805 32.164 80.9377Z" fill="#323A3
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):102
            Entropy (8bit):5.0024381220927
            Encrypted:false
            SSDEEP:3:tvQ8/oJDDmJS4RKb5ykKcvUJUT7Bin:tvQ8A9mc4sl3UY7Bi
            MD5:06E89AA1307B3F65F0DE3AA914F71793
            SHA1:8F5D537C2DF580CC2C5E064A06CF75BFC3749D1F
            SHA-256:FCA45940F7F7A1B1BC80EFCF3C692B781C8837198C1D84301E76B0809D88058A
            SHA-512:FAF54DBC112B490D4609EEEC3DDC53951ED36531714E1009076C44AB5C900B2F4C75420FCDA2D073295F60B63DC0EE9A93A49BCAF57CC79CC11A7D1F1EB62F92
            Malicious:false
            Reputation:low
            Preview:<svg id=".._1" data-name=".. 1" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 16 16">.</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):187
            Entropy (8bit):5.114117309074947
            Encrypted:false
            SSDEEP:3:tRBRNqcwR+8XcvUJUTlt7SLvDmJS4RKb58ZSFuHYQlAHp3pLAlQVA9kcO1RFAmYn:tnrZvUYltumc4slvI9lip3pL3q9Vw4mW
            MD5:AF0628B1B7B6BC65505F8E58AC60DFC7
            SHA1:32E8D11EF60164E65324CA178662FD9F7BA7E026
            SHA-256:6DED9A618C92C31E2F7F20D6814CD792A0F89D411A3CB61F87B37DFFF358F618
            SHA-512:F91434B832D238E94B8FED14947203954B60C681366A0866D60B2DA2F621CE7CC54C129DF6F92219886B8606085525FE75123E3F3ADCFE2722F0ED367C960632
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M12.75 6.25L7.75 9.75L2.75 6.25" stroke="#A9A9A9" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):863
            Entropy (8bit):4.28752352376341
            Encrypted:false
            SSDEEP:24:t3JfDu4y9ycvtZempHOou2+j74tNRD5ujM5fSzvi0R:3fYHOoA72wM5azv3
            MD5:2C40CCD7F34BED788847DEA3C0CFF666
            SHA1:DC70FE030E6D4AD555606217343F61837E64BCB1
            SHA-256:3EE40882C963A40940BD0B746D7521B0151969DAF2AFC6099BC8042AF69BFB03
            SHA-512:6C59CC42F5F43A063869B9A85CA320C82506D2F98933FB8BF164ABEF81C1A4D3871703A93F907333E1F7C46B04F1E6130CC642D52A417A4BD2CB7486480207C3
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M12.0769 6.84171C12.0769 6.58678 12.2835 6.38017 12.5385 6.38017C12.7934 6.38017 13 6.58678 13 6.84171V10.6923C13 11.9668 11.9668 13 10.6923 13H3.30769C2.03323 13 1 11.9668 1 10.6923V3.30769C1 2.03323 2.03323 1 3.30769 1H7.7006C7.95553 1 8.16214 1.20661 8.16214 1.46154C8.16214 1.71647 7.95553 1.92308 7.7006 1.92308H3.30769C2.54309 1.92308 1.92308 2.54309 1.92308 3.30769V10.6923C1.92308 11.4569 2.54309 12.0769 3.30769 12.0769H10.6923C11.4569 12.0769 12.0769 11.4571 12.0769 10.6923V6.84171ZM11.8775 1.74946C12.0528 1.57007 12.3392 1.5634 12.5226 1.73431C12.706 1.90541 12.7191 2.19171 12.5523 2.37885L7.51689 7.77975C7.34309 7.96617 7.05102 7.97644 6.86442 7.80264C6.67801 7.62885 6.66773 7.33678 6.84153 7.15018L11.8775 1.74946Z" fill="#6B6B6B"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1517
            Entropy (8bit):4.173957305916156
            Encrypted:false
            SSDEEP:24:tKT8FuWhWHHUDeNKqPMMLPLbRaQU6E4wfeF34TPjomOmaiiFyqC2sQoozaRRMEdu:a8EHFNKOFT0ZGAsm7j3F21mRRldAfQs
            MD5:863B67B52E887DA2970009B722A3FF4F
            SHA1:517E4280CA6DF93FBEB144665849737E6AC583CC
            SHA-256:76193498E9FCB470F353FF0BEF5A4425B7253057F6FC528C4EBC66FFE668F505
            SHA-512:F7E71A746683E8E807AF79A51B70B5C0FF32AA8678CE27482C3CA3DA96D94D1A6FE5AF25CA2532281A4536DE93E2A0B13E8743C7E1A93FBDA1B1A36C1C68A6F8
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M38.2923 1.34808L38.2441 1.30417C37.3235 0.463194 36.1301 0 34.8837 0C33.4864 0 32.1449 0.591489 31.2029 1.62267L13.3916 21.1224C13.2293 21.3002 13.1061 21.5099 13.03 21.7381L10.9357 28.0167C10.6935 28.7426 10.815 29.5453 11.2607 30.164C11.7099 30.7875 12.4336 31.1598 13.1967 31.1598H13.1968C13.5269 31.1598 13.8495 31.0919 14.1555 30.958L20.2195 28.3052C20.44 28.2087 20.6377 28.0671 20.8 27.8894L38.6114 8.38977C40.4648 6.36078 40.3219 3.20211 38.2923 1.34808ZM14.9484 26.8569L16.1773 23.1726L16.281 23.0591L18.6102 25.1866L18.5066 25.3001L14.9484 26.8569ZM36.0718 6.07002L20.93 22.6472L18.6007 20.5197L33.7426 3.94242C34.0387 3.61819 34.444 3.43956 34.8838 3.43956C35.2696 3.43956 35.6391 3.5831 35.9251 3.84428L35.9731 3.88819C36.6019 4.46248 36.6461 5.44127 36.0718 6.07002V6.07002Z" fill="#73CA94"/>.<path d="M34.8369 15.8664C33.8871 15.8664 33.1171 16.6364 33.1171 17.5862V32.1868C33.117
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):400
            Entropy (8bit):5.254988015593268
            Encrypted:false
            SSDEEP:6:TMVBdbjeXdgXRxVnzVEn6Vf3qmc4slZKYnic4sf3nUYlaJWYlnXGBJAWP4fC:TMHdPYi/nzVk/KYf3nnlcWYln7WV
            MD5:34C405632CF7304A0170CEDAC5EC6A42
            SHA1:C29CEA4FD28A49DBD550633931C4BC16863E563D
            SHA-256:D37829F2CFC6B2047C5271410C6E41F7CC208D8F107902605B9CAB5AC0B64076
            SHA-512:D1FC67AC6AF487D0325D2D8124768E9388DDE21E393E3B8DF4279E89B68D75BFF957B440FE98759C3AE8A6218D96AA0326E9988FAFC8D64B0A6F4E1460A4A4F6
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="utf-8"?>. Generator: Adobe Illustrator 23.0.3, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->.<svg version="1.0" id="Layer_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px".. viewBox="0 0 16 16" enable-background="new 0 0 16 16" xml:space="preserve">.<g>..<circle fill="#808080" cx="8" cy="8" r="0"/>.</g>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1701
            Entropy (8bit):4.133331958446783
            Encrypted:false
            SSDEEP:24:tVv4muzFvmnIO3fR5C7CPWu/eWQ/YFeWwZcH3I2c880UgKSlYj0TZ9mIxnoLEIfl:z4xgn5fbfNQGwZcH3g880L7ij0GIO61A
            MD5:A6452340EE2F8AB005EF12DAEF608345
            SHA1:3711377387CB2786FCED94770C9ACFEBBC2F024A
            SHA-256:054F4CC1038AD54B501013C5658F0166AB9B21574E236D5C3FC19CC85184968D
            SHA-512:4296787B943E0A0E5B8A115AD07C7056CD823A23B3ABE31D256FC17FAAA399C3CBCAC73619747E126A6DE5F4BBFC06FB1EA9AE2633B50712FA2FDFA030A4C678
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="17" viewBox="0 0 16 17" fill="none" xmlns="http://www.w3.org/2000/svg">.<circle cx="8" cy="8.5" r="7.5" stroke="#CECECE"/>.<path d="M8.43066 10.5674H6.90625C6.91081 10.1436 6.94727 9.78809 7.01562 9.50098C7.08398 9.20931 7.19792 8.94499 7.35742 8.70801C7.52148 8.47103 7.73796 8.22038 8.00684 7.95605C8.21647 7.75553 8.4056 7.56641 8.57422 7.38867C8.74284 7.20638 8.87728 7.01497 8.97754 6.81445C9.0778 6.60938 9.12793 6.37467 9.12793 6.11035C9.12793 5.82324 9.08008 5.57943 8.98438 5.37891C8.88867 5.17839 8.7474 5.02572 8.56055 4.9209C8.37826 4.81608 8.15039 4.76367 7.87695 4.76367C7.64909 4.76367 7.4349 4.80924 7.23438 4.90039C7.03385 4.98698 6.87207 5.1237 6.74902 5.31055C6.62598 5.49284 6.5599 5.73438 6.55078 6.03516H4.90332C4.91243 5.46094 5.04915 4.97786 5.31348 4.58594C5.5778 4.19401 5.93327 3.90007 6.37988 3.7041C6.8265 3.50814 7.32552 3.41016 7.87695 3.41016C8.48763 3.41016 9.00944 3.51497 9.44238 3.72461C9.87533 3.92969 10.2057 4.23047 10.4336 4.62695C10.66
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):169
            Entropy (8bit):4.835362644345388
            Encrypted:false
            SSDEEP:3:tRBRNqcwR+8XcvUJUTlt7SLvDmJS4RKb58ZQGuMnccwR+8DGWCrVCqbv0/v:tnrZvUYltumc4sl7anLq6l4n
            MD5:BD92163A6E82B7FAC9E449428F4CD305
            SHA1:8596C8C0B98C971A76E4F6A80BF961BF2690041F
            SHA-256:F683ABC7047CEA1C0A29ED6DA1D73595839F70F53E853E053112C2529052ADD1
            SHA-512:C176632EE9CDF71F084E2ED7D726E6B8A9847239D94DB6A5AEF961F0BE15FFD630AE041736D58F3770E2FA70772D109EA383051F88AE6D4993CAED136658B5A7
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="16" height="16" fill="#FFFFFF" fill-opacity="0.01"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):901
            Entropy (8bit):5.445782732182063
            Encrypted:false
            SSDEEP:24:2dVH5AOx2LfqNbUsoKArKHoH+3aXrQtpMoM+6r2mqWs:cVZAOEfq6soK0Kr3aXrQfj6r2vZ
            MD5:241B375C2A29F9E5041BC33400FBB527
            SHA1:BCDA7504FDF8F21F9015773A4D75AD82202DE17D
            SHA-256:F2A72EF87B8F42EFD01FE6034E3B6854258D04889E355EEFE6377859149DCE2F
            SHA-512:F5997484845859D8C22102E8ABACDAE23C62F504EA4B9F9E98349191A6C81C76FA55DB67B69CE14CC3D41D2BF578ECCF5F990E99BC437E0BCAA7926B423CCC17
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="iso-8859-1"?>. Generator: Adobe Illustrator 16.0.0, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->.<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">.<svg version="1.1" id="Capa_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px".. width="121.805px" height="121.805px" viewBox="0 0 121.805 121.805" style="enable-background:new 0 0 121.805 121.805;".. xml:space="preserve">.<g>..<g>...<path fill="#808080" d="M7.308,85.264h107.188c4.037,0,7.309-3.271,7.309-7.31s-3.271-7.309-7.309-7.309H7.308C3.271,70.646,0,73.916,0,77.954....S3.271,85.264,7.308,85.264z"/>...<path fill="#808080" d="M7.308,51.158h107.188c4.037,0,7.309-3.272,7.309-7.309c0-4.037-3.271-7.308-7.309-7.308H7.308....C3.271,36.541,0,39.812,0,43.849C0,47.886,3.271,51.158,7.308,51.158z"/>..</g>.</g>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):919
            Entropy (8bit):5.100187192903761
            Encrypted:false
            SSDEEP:24:2dgAOLf3nTY2Kqj3AhlH2Pxqj3AhlHmSqj3AhlH2gqj3AhlHKr:cgAqf3nkLxkxmSxbxG
            MD5:9037041677BA4F798E948B1BE7E7B706
            SHA1:3095D2415541A614F4566B18BFCCD2E3589690C3
            SHA-256:9591DCCF71A65DA35B5610337C79C1B9099A9AF6B700E164D1E5DB0BD3A155B8
            SHA-512:255F5CEDDBB36F43653E051973F04592A76007287AE2A701E3077749B982ADBF7C054FD77DCF1F196BACCFFCA1DF4FECDA248FA76E2D344022FCA81EBEB280CC
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="utf-8"?>. Generator: Adobe Illustrator 23.0.3, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->.<svg version="1.0" id="Layer_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px".. viewBox="0 0 16 16" enable-background="new 0 0 16 16" xml:space="preserve">.<g id="expand">..<g><line fill="none" stroke="#FFFFFF" stroke-width="1" stroke-linecap="round" stroke-miterlimit="10" x1="4" y1="8" x2="8" y2="4"/></g>..<g><line fill="none" stroke="#FFFFFF" stroke-width="1" stroke-linecap="round" stroke-miterlimit="10" x1="8" y1="4" x2="12" y2="8"/></g>. ..<g><line fill="none" stroke="#FFFFFF" stroke-width="1" stroke-linecap="round" stroke-miterlimit="10" x1="4" y1="12" x2="8" y2="8"/></g>..<g><line fill="none" stroke="#FFFFFF" stroke-width="1" stroke-linecap="round" stroke-miterlimit="10" x1="8" y1="8" x2="12" y2="12"/></g>. .</g>.</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2489
            Entropy (8bit):4.36843565347414
            Encrypted:false
            SSDEEP:48:ymCztrHYxrLulpIM52EzUSqLvzOtGBPFgx20YJXA00TP:8zt6rLG2M5EL7OtGBNgQLV0L
            MD5:90FCAAE217C188FD54E85242FEFB5A8F
            SHA1:140BF132429C8C98AA35002F264ABE64DB9C0BA5
            SHA-256:8685D6D1E1E367FC2682A352254C3774374B0B63800FF26BEA0F0E57AB39C9E6
            SHA-512:78CBF490E50B2DAB71A87B64F2C33216EC0E45B3619571425364CE4F97AE0F71EF53099A7275512CCF9916D3FD53C925EEF82C855C0FA1AA5E755D7D8DC1C80A
            Malicious:false
            Reputation:low
            Preview:<svg width="58" height="80" viewBox="0 0 58 80" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M58 45V35L51 35.7812V44.2187L58 45Z" fill="#ACACAC"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M44.9704 3.63623C43.208 3.63623 41.2116 6.70995 39.875 10.909L43.0738 10.9092C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H40.0518C41.4218 73.6574 43.1249 76.3635 44.9704 76.3635C49.4971 76.3635 53.1667 60.083 53.1667 39.9999C53.1667 19.9168 49.4971 3.63623 44.9704 3.63623Z" fill="#EEEEEE"/>.<path d="M15.7085 10.9092H43.0738C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H15.7085" stroke="#ACACAC"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M40.9265 10.9092C41.5573 9.00098 42.3148 7.39151 43.0881 6.26334C43.4956 5.6689 43.8846 5.24175 44.232 4.97214C44.5822 4.70037 44.8266 4.63623 44.9707 4.63623C45.2153 4.63623 45.5388 4.74176 45.9503 5.1154C46.3676 5.49423 46.8181 6.10021 47.2785 6.96415C48.1984 8.69037 49.0576 11.2541 49.7908 14.5068C51.2534 20.99
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2489
            Entropy (8bit):4.362395011102785
            Encrypted:false
            SSDEEP:48:ymCzt3HYxrLulpIM52EzUSqLvzOtGBPFgx20YJ/A00T3:8ztWrLG2M5EL7OtGBNgEL50L
            MD5:0BA26ADA597D07FA1CB19369CA65D53F
            SHA1:0757F35FF67162120C0C6BCD5859D9982AC7FB92
            SHA-256:FE330B1E01B064FC2E162261ED5C05035958D003B923F4BF71C5525B505EAD75
            SHA-512:87DAEE7CA4396BD6F9854B70C115448EAA84D8E217CCFBA3D31425BFE4F21FCE0AFEB96E706D3DECA569CB61D3D14653DC8C8610BFB37B061C868FC6053E91E1
            Malicious:false
            Reputation:low
            Preview:<svg width="58" height="80" viewBox="0 0 58 80" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M58 45V35L51 35.7812V44.2187L58 45Z" fill="#ACACAC"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M44.9704 3.63623C43.208 3.63623 41.2116 6.70995 39.875 10.909L43.0738 10.9092C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H40.0518C41.4218 73.6574 43.1249 76.3635 44.9704 76.3635C49.4971 76.3635 53.1667 60.083 53.1667 39.9999C53.1667 19.9168 49.4971 3.63623 44.9704 3.63623Z" fill="#EEEEEE"/>.<path d="M15.7085 10.9092H43.0738C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H15.7085" stroke="#6B6B6B"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M40.9265 10.9092C41.5573 9.00098 42.3148 7.39151 43.0881 6.26334C43.4956 5.6689 43.8846 5.24175 44.232 4.97214C44.5822 4.70037 44.8266 4.63623 44.9707 4.63623C45.2153 4.63623 45.5388 4.74176 45.9503 5.1154C46.3676 5.49423 46.8181 6.10021 47.2785 6.96415C48.1984 8.69037 49.0576 11.2541 49.7908 14.5068C51.2534 20.99
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2489
            Entropy (8bit):4.351760335828701
            Encrypted:false
            SSDEEP:48:ymCzt4HYxrLulpIM52EzUSqLvzOtGBPFgxX0YJEA00TM:8ztvrLG2M5EL7OtGBNgBLq0Y
            MD5:D2775013983B8BDE969138EE7DEC5DAA
            SHA1:6DA83B0F1615F311A2C32812A4ED57CC5B27EAC8
            SHA-256:E470D2CB6C9F43051D2A813236DA6B8C15CD1AF75391D3D3A3052ED48C60DED3
            SHA-512:8E029EB17B56E7803473EAECEF64205C97D493E54358AC8040B55561703294AD2804826D7919012CCDFDCC4EEF129803F526DEF95AC0DEFC5FEAC7D6FA1735B2
            Malicious:false
            Reputation:low
            Preview:<svg width="58" height="80" viewBox="0 0 58 80" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M58 45V35L51 35.7812V44.2187L58 45Z" fill="#ACACAC"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M44.9704 3.63623C43.208 3.63623 41.2116 6.70995 39.875 10.909L43.0738 10.9092C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H40.0518C41.4218 73.6574 43.1249 76.3635 44.9704 76.3635C49.4971 76.3635 53.1667 60.083 53.1667 39.9999C53.1667 19.9168 49.4971 3.63623 44.9704 3.63623Z" fill="#EEEEEE"/>.<path d="M15.7085 10.9092H43.0738C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H15.7085" stroke="#262F30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M40.9265 10.9092C41.5573 9.00098 42.3148 7.39151 43.0881 6.26334C43.4956 5.6689 43.8846 5.24175 44.232 4.97214C44.5822 4.70037 44.8266 4.63623 44.9707 4.63623C45.2153 4.63623 45.5388 4.74176 45.9503 5.1154C46.3676 5.49423 46.8181 6.10021 47.2785 6.96415C48.1984 8.69037 49.0576 11.2541 49.7908 14.5068C51.2534 20.99
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2542
            Entropy (8bit):4.407895870637986
            Encrypted:false
            SSDEEP:48:y1CztrHYxrLulpIM52EzUSqLvzOtGBPFgx20YJXA00TS:1zt6rLG2M5EL7OtGBNgQLV02
            MD5:303EF069BD489F821ABBA5398FB58B1E
            SHA1:8C60124EC357155F8973FC63325B1E7BA5D4DCF7
            SHA-256:357E722E86473B984D0AF0ADD85A070EB5267B121DA76EBA6A90983340A750AD
            SHA-512:4521886D622651F330A97A877CB5F294A47E4685CBF5BAD3C661951DAB647FC09B017CE97DDDBB04098315D93CC41951AF155F8938A6A95070EA1B4CD03D2965
            Malicious:false
            Reputation:low
            Preview:<svg width="58" height="80" viewBox="0 0 58 80" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M44.9704 3.63623C43.208 3.63623 41.2116 6.70995 39.875 10.909L43.0738 10.9092C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H40.0518C41.4218 73.6574 43.1249 76.3635 44.9704 76.3635C49.4971 76.3635 53.1667 60.083 53.1667 39.9999C53.1667 19.9168 49.4971 3.63623 44.9704 3.63623Z" fill="#EEEEEE"/>.<path d="M15.7085 10.9092H43.0738C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H15.7085" stroke="#ACACAC"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M40.9265 10.9092C41.5573 9.00098 42.3148 7.39151 43.0881 6.26334C43.4956 5.6689 43.8846 5.24175 44.232 4.97214C44.5822 4.70037 44.8266 4.63623 44.9707 4.63623C45.2153 4.63623 45.5388 4.74176 45.9503 5.1154C46.3676 5.49423 46.8181 6.10021 47.2785 6.96415C48.1984 8.69037 49.0576 11.2541 49.7908 14.5068C51.2534 20.9959 52.167 30.0096 52.167 39.9999C52.167 49.9901 51.2534 59.0038
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2542
            Entropy (8bit):4.405788014944274
            Encrypted:false
            SSDEEP:48:y1Czt3HYxrLulpIM52EzUSqLvzOtGBPFgx20YJ/A00TS:1ztWrLG2M5EL7OtGBNgEL502
            MD5:D3F3E92B8AAA4783E2BAAB8BB7CEC043
            SHA1:446DE38EC692BC948DE0FF0774AFD332A1344B28
            SHA-256:B844C2825E091B745EF98949CB75F208D9D0FDDA690C4CDC5494D015E3B11375
            SHA-512:0FEFCB916956EE676F41D911FA626EC64CB1695D1387333AEBC082E308B79029044A8CD22C0235C82D6AB8F8A5A1FD166D2E1B09509FB3CF253B6EEDEFA479A8
            Malicious:false
            Reputation:low
            Preview:<svg width="58" height="80" viewBox="0 0 58 80" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M44.9704 3.63623C43.208 3.63623 41.2116 6.70995 39.875 10.909L43.0738 10.9092C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H40.0518C41.4218 73.6574 43.1249 76.3635 44.9704 76.3635C49.4971 76.3635 53.1667 60.083 53.1667 39.9999C53.1667 19.9168 49.4971 3.63623 44.9704 3.63623Z" fill="#EEEEEE"/>.<path d="M15.7085 10.9092H43.0738C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H15.7085" stroke="#6B6B6B"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M40.9265 10.9092C41.5573 9.00098 42.3148 7.39151 43.0881 6.26334C43.4956 5.6689 43.8846 5.24175 44.232 4.97214C44.5822 4.70037 44.8266 4.63623 44.9707 4.63623C45.2153 4.63623 45.5388 4.74176 45.9503 5.1154C46.3676 5.49423 46.8181 6.10021 47.2785 6.96415C48.1984 8.69037 49.0576 11.2541 49.7908 14.5068C51.2534 20.9959 52.167 30.0096 52.167 39.9999C52.167 49.9901 51.2534 59.0038
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2542
            Entropy (8bit):4.397358109494101
            Encrypted:false
            SSDEEP:48:y1Czt4HYxrLulpIM52EzUSqLvzOtGBPFgxX0YJEA00TS:1ztvrLG2M5EL7OtGBNgBLq02
            MD5:CEB6F5061C16DFF65E59C90BF4AA781D
            SHA1:03CDFD4404F58F2C2221FFCEE2CE4EA29D2FBA99
            SHA-256:B79FEE0E38CCBFAA1DA73F854E0803F367702EC7B3563645446EEE234E19F67C
            SHA-512:FEA6F86378433856D18FF385BD0F9CB3489F937D5A76F5DA161FC87038EB3517EC4F109C97FACF2118E60E0B264DB426A6D10FCA954E1036D74D569296025453
            Malicious:false
            Reputation:low
            Preview:<svg width="58" height="80" viewBox="0 0 58 80" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M44.9704 3.63623C43.208 3.63623 41.2116 6.70995 39.875 10.909L43.0738 10.9092C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H40.0518C41.4218 73.6574 43.1249 76.3635 44.9704 76.3635C49.4971 76.3635 53.1667 60.083 53.1667 39.9999C53.1667 19.9168 49.4971 3.63623 44.9704 3.63623Z" fill="#EEEEEE"/>.<path d="M15.7085 10.9092H43.0738C45 14 47 28.2357 47 40.5C47 52.0393 45.5 65 43.0738 69.091H15.7085" stroke="#262F30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M40.9265 10.9092C41.5573 9.00098 42.3148 7.39151 43.0881 6.26334C43.4956 5.6689 43.8846 5.24175 44.232 4.97214C44.5822 4.70037 44.8266 4.63623 44.9707 4.63623C45.2153 4.63623 45.5388 4.74176 45.9503 5.1154C46.3676 5.49423 46.8181 6.10021 47.2785 6.96415C48.1984 8.69037 49.0576 11.2541 49.7908 14.5068C51.2534 20.9959 52.167 30.0096 52.167 39.9999C52.167 49.9901 51.2534 59.0038
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):259897
            Entropy (8bit):4.33528005434889
            Encrypted:false
            SSDEEP:1536:J6/5slj77yqrjCCMbwA8LHwAoVPUHIFM1gKDx7yfHDh4O25P80oD7Em+d7Ew9Eep:5sQGxxedD
            MD5:32B4DB0859C5BC6BAE99928E70E29966
            SHA1:327B98410B2A7DE242921A6D7F070833F244BAA9
            SHA-256:1C1BAE3B749C35DEDE3E32B09F15C23D0D68E7D1285513A9CF01931ABB46D0F6
            SHA-512:B27DF9F1B9A17F976BB782268365EA80CF5C41B2DC469FD2BD2E7BF87A193EAE8247014B9CEBE7AD3D5AA14100DCEE454DF72E0445B8E5B134D8C84175ADAA6A
            Malicious:false
            Reputation:low
            Preview:<svg width="1200" height="1200" viewBox="0 0 1200 1200" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M870.792 225.945L869.632 226.105" stroke="#010100" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M164.892 643.065L164.342 643.665" stroke="#010100" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M409.752 846.725C409.932 847.085 410.102 847.435 410.272 847.795C409.592 850.215 408.902 852.625 408.222 855.045" stroke="#010100" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M379.582 742.985L378.422 743.145" stroke="#010100" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M900.952 329.685C900.962 329.685 900.962 329.685 900.952 329.685ZM900.952 329.685C901.132 330.045 901.302 330.395 901.472 330.755C900.792 333.175 900.102 335.585 899.422 338.005" stroke="#010100" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M527.532 1149.04C526.2
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):259897
            Entropy (8bit):4.375476096318541
            Encrypted:false
            SSDEEP:1536:RaTtEhvnPy67/KyMbEEYzXgIERTUPY5QxAirxDKfHXF4OGxPkkgT3A+OZ7Eclse5:R4M+5ZydT
            MD5:93C83D6A73B974AC273B467D2ABBA721
            SHA1:E26227BA2424983260B6E606C84F0AF90D2D491E
            SHA-256:2B0633FBBD5A1AE97D11F9E4BA559559CB9103FDC02CF6198BC2F44407A617D5
            SHA-512:0F2A11E41A5C4152DD9867D780F2E5430F924F1D884A50CBA42BBD4972C3A1ED15B8E1639916A04D72EB4CCBFA5180279A55B07A94B70CAC7425940F24B01D4D
            Malicious:false
            Reputation:low
            Preview:<svg width="1200" height="1200" viewBox="0 0 1200 1200" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M870.792 225.945L869.632 226.105" stroke="#ffffff" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M164.892 643.065L164.342 643.665" stroke="#ffffff" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M409.752 846.725C409.932 847.085 410.102 847.435 410.272 847.795C409.592 850.215 408.902 852.625 408.222 855.045" stroke="#ffffff" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M379.582 742.985L378.422 743.145" stroke="#ffffff" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M900.952 329.685C900.962 329.685 900.962 329.685 900.952 329.685ZM900.952 329.685C901.132 330.045 901.302 330.395 901.472 330.755C900.792 333.175 900.102 335.585 899.422 338.005" stroke="#ffffff" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M527.532 1149.04C526.2
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1872
            Entropy (8bit):4.430989256134043
            Encrypted:false
            SSDEEP:24:tVvnjuXMMaKQHs3XGHOww7Y+q79MMdSItUZ2kuCpEnq79MMEADGMa8NNWQg29lQU:rnl0uj5TA73Vcynn
            MD5:D7441E9F420600FC0FFF97EEBA49DEA0
            SHA1:47E804D731BD98C355D0A998C97244B89AE98E32
            SHA-256:8C53DC851FBFABFEAF15F2066D4648977EA199649EB944EBC96F8F6111E1B2F6
            SHA-512:50AAAE6D1372F2C0B4E71C8FEC3F8081562AB0054624B1ADE3ABCA965325CDF349FA8B01DC3682BF5F4C5A179D6FC9E81B18D34F20D9733442D1E7C9A578F5B2
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M1.30078 2.00078C1.30078 1.61418 1.61418 1.30078 2.00078 1.30078H6.00078C6.38738 1.30078 6.70078 1.61418 6.70078 2.00078C6.70078 2.38738 6.38738 2.70078 6.00078 2.70078H2.70078V6.00078C2.70078 6.38738 2.38738 6.70078 2.00078 6.70078C1.61418 6.70078 1.30078 6.38738 1.30078 6.00078V2.00078Z" fill="white" fill-opacity="0.88"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M14.0008 9.30078C14.3874 9.30078 14.7008 9.61418 14.7008 10.0008V14.0008C14.7008 14.3874 14.3874 14.7008 14.0008 14.7008H10.0008C9.61418 14.7008 9.30078 14.3874 9.30078 14.0008C9.30078 13.6142 9.61418 13.3008 10.0008 13.3008H13.3008V10.0008C13.3008 9.61418 13.6142 9.30078 14.0008 9.30078Z" fill="white" fill-opacity="0.88"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M13.9982 1.30078H14.0008C14.3874 1.30078 14.7008 1.61418 14.7008 2.00078V6.00078C14.7008 6.38738 14.3874
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 1280, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):1424025
            Entropy (8bit):7.974708838353537
            Encrypted:false
            SSDEEP:24576:+UQVGKsZf2poZdeg6Z3pSORe4V26Zq2pnt+/Zi2LDK/GrYCxG5oUD3uCR:qGKeC6dQ5SORe4VHq2R2i2LDUGrY82ow
            MD5:205CAB93BBD108C87FB2312F2AF99F96
            SHA1:2C1A6BF432212B7C0E2C358E7CA4329C6689EB41
            SHA-256:18B8B7346413C245CC0157ACBFEE242112306DB3FFC6E0F2B0396EAB8D9D07E4
            SHA-512:4F27BB6BC3EBF7BA8A8C88CB30044F93FBA5C1BD58E2EDF4BA3D99810FB319AE875336222EA93BF5ACCC5C97C9AFC2F27B18D1B4C71009F297C5EF64352378BF
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.....................pHYs.................sRGB.........gAMA......a.....IDATx.....m.U..f..j....y.06......~\..1......O.Sl._...F....?.... ....CH.C`...#....B.Z.zt.~T.Z3..../..s.U.........c..#Gf....#...n..q.O)..B...w....8..7.......G...8....AJ....n...].n..!....g.1O.$...9....:...u.y..=..f.......1..V.0....QF.s.e./.D...?.=^O...H..I.<O......o.%....pS....L.9..1..{K...M........].6...P.......K...1z...G.\....O.z9...]/}.Z....:."Q)..*...K....B.-.....,...d.}.Z...........,=.=O.Mc..5..^.,..u..X..r....y.@.!..k.[.+w.Xdi......s.k.....:.X....].....)wV.2=k;@O{..y.c<]..B.#..c.v^..;..xs.n..#..=.s..W......XO..L...Y...I...y....u<t...4..3V......m.....b.......>....s..q.=...xR..c..x.>y:.......:.u.{^.V....Zh...z3..1.f.$`.5...D(.3.u..9E2...&u|.d&.5.....]..k...G......1...._.....g.=7-..[...srr..//.f......M....a...Zh!......B.-..[..{...xRi~.7...W..F0...m{F.`.m..x...(...{Yz......>..{..@..c.h.q..O..:...I..O.:|...p..}.8s.B.-..Bom.!.x.%..TKT.........P.....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 1280, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):1421317
            Entropy (8bit):7.974116687337133
            Encrypted:false
            SSDEEP:24576:RUQVGKsZf2p+5+6SXt24waOXVglgLOA2R+8VuOAeKMlRUUz7uQYlStOetg:7GKeCZTt8XFCxPVUeKM/7u1Scetg
            MD5:F15989CB1C76C1A0D55EEA800CBDAA1E
            SHA1:5E13666207989D169F45DA5AC67BC5259FFCB2B2
            SHA-256:52837831752431FA6DEBB2410A984A6EBFC269B56D92CBA622A5D35DC2F53D61
            SHA-512:FB8D79234277BCD290D3D4BDCE1CF8E85AB366B08AAAEFF3EE732E3CA67679DBA056D10E3C5A07EB38264ADAF4FF5F0347DABD422D48CED6FCC7D94B1F0AE24F
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.....................pHYs.................sRGB.........gAMA......a.....IDATx.....m.U..f..j....y.06......~\..1......O.Sl._...F....?.... ....CH.C`...#....B.Z.zt.~T.Z3..../..s.U.........c..#Gf....#...n..q.O)..B...w....8..7.......G...8....AJ....n...].n..!....g.1O.$...9....:...u.y..=..f.......1..V.0....QF.s.e./.D...?.=^O...H..I.<O......o.%....pS....L.9..1..{K...M........].6...P.......K...1z...G.\....O.z9...]/}.Z....:."Q)..*...K....B.-.....,...d.}.Z...........,=.=O.Mc..5..^.,..u..X..r....y.@.!..k.[.+w.Xdi......s.k.....:.X....].....)wV.2=k;@O{..y.c<]..B.#..c.v^..;..xs.n..#..=.s..W......XO..L...Y...I...y....u<t...4..3V......m.....b.......>....s..q.=...xR..c..x.>y:.......:.u.{^.V....Zh...z3..1.f.$`.5...D(.3.u..9E2...&u|.d&.5.....]..k...G......1...._.....g.=7-..[...srr..//.f......M....a...Zh!......B.-..[..{...xRi~.7...W..F0...m{F.`.m..x...(...{Yz......>..{..@..c.h.q..O..:...I..O.:|...p..}.8s.B.-..Bom.!.x.%..TKT.........P.....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2832
            Entropy (8bit):4.314719309493404
            Encrypted:false
            SSDEEP:48:LOJ+qsR/zm2BCSPXlnUC9584DsGpL0xdQb/9dTpoO7GbBJTu3:LOJoZSILNUCQ4npLx/B7Gu3
            MD5:CD8B54DEFDE83CB1435184DC04033A5D
            SHA1:A267209DFB1DB7FB5A4D08D971255D211B28E48C
            SHA-256:C788A6247ED3F820BD8B22A90C2CC8FBFCBF2E80FC208644F2933A9294270A04
            SHA-512:BEFE09812DE921B3A215087BB7AD60E447FC791D7BCCCC83061E6725036C3CF2910DD148890EA56DAD8FD2C6C749A034481C5184C8C88A3EFEF6E54655AD080E
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" standalone="no"?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"><svg t="1638946359959" class="icon" viewBox="0 0 1024 1024" version="1.1" xmlns="http://www.w3.org/2000/svg" p-id="2341" xmlns:xlink="http://www.w3.org/1999/xlink" width="64" height="64"><defs><style type="text/css"></style></defs><path d="M64 490.666667m8.533333 0l878.933334 0q8.533333 0 8.533333 8.533333l0 46.933333q0 8.533333-8.533333 8.533334l-878.933334 0q-8.533333 0-8.533333-8.533334l0-46.933333q0-8.533333 8.533333-8.533333Z" fill="#1296db" p-id="2342"></path><path d="M128 669.866667v154.133333a72 72 0 0 0 67.776 71.893333l4.224 0.106667H354.133333c4.693333 0 8.533333 3.84 8.533334 8.533333v46.933334a8.533333 8.533333 0 0 1-8.533334 8.533333H205.482667A141.482667 141.482667 0 0 1 64 818.517333V669.866667c0-4.693333 3.84-8.533333 8.533333-8.533334h46.933334c4.693333 0 8.533333 3.84 8.533333 8.533334z m832 0v148.650666A141.482667 141.482667 0 0 1 81
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):711
            Entropy (8bit):4.735528526415422
            Encrypted:false
            SSDEEP:12:trLJfDuXM65gcLCc3HxCjhIdAI9M65VQPHXS04jUMTDy0D7yxhJ4Vj5Di:t3JfDuXMMjB3RbAI9MMiPirrWdJYti
            MD5:380B3887F19478734EB17FF005A7BD1E
            SHA1:F85329331787E22356E9610D325801AEB9BD40DB
            SHA-256:0080D79D85DB6F8C491B7B550BD31727F6FFF1D3B39E86FBBDA9209AE42944C3
            SHA-512:B10A504482B160CC2E41F3B340E108144ACD078DC639D0816DADC17E3919AE7734737130A904A2DF7B0FBA9B21A414460D3F1387E22266DF4E25A4DB108E817A
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M0.329102 7.14591C0.329102 6.7317 0.664888 6.39591 1.0791 6.39591H12.2525C12.6667 6.39591 13.0025 6.7317 13.0025 7.14591C13.0025 7.56013 12.6667 7.89591 12.2525 7.89591H1.0791C0.664888 7.89591 0.329102 7.56013 0.329102 7.14591Z" fill="#828280"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.66504 0.809425C7.07925 0.809425 7.41504 1.14521 7.41504 1.55943L7.41504 12.7329C7.41504 13.1471 7.07925 13.4829 6.66504 13.4829C6.25082 13.4829 5.91504 13.1471 5.91504 12.7329L5.91504 1.55943C5.91504 1.14521 6.25083 0.809425 6.66504 0.809425Z" fill="#828280"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):374
            Entropy (8bit):4.893478499205935
            Encrypted:false
            SSDEEP:6:tnr2n0UWRumc4slvtM65tzF5OKIPJktUbkj3F/PdhfdisuFa6FLxR66DFqlti:tr2n0vRuXM65Nixktkk7dqLxxaji
            MD5:80DA9DE6305CBE80ECE1F3DE8E2ADC8C
            SHA1:E44C2CAC9DF00A2D80953467B0973AB09DE235B8
            SHA-256:84EF6523966EB90104113B0E0A61E6E3A26285247E5C8E01A29512575A4D758A
            SHA-512:1F74AD1295D0A7B13521753E08A2B6AED3EA8F342A57B372E666AA72C3517E614A431403D4686631A7729C512EF79D3B81E17E36A881DD5290E8F1A43D25BC62
            Malicious:false
            Reputation:low
            Preview:<svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M0.160156 6.5C0.160156 6.08579 0.495943 5.75 0.910156 5.75H12.0836C12.4978 5.75 12.8336 6.08579 12.8336 6.5C12.8336 6.91421 12.4978 7.25 12.0836 7.25H0.910156C0.495943 7.25 0.160156 6.91421 0.160156 6.5Z" fill="#828280"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2058
            Entropy (8bit):4.513398997220808
            Encrypted:false
            SSDEEP:48:9N2ptn3U2+pr+A+2e/9REFM/0nf7JWiNlIAANLo8oA9qN1qp:T2bEzpZ+2eD/Of7JWibIAANLo8Qqp
            MD5:8FD835DA47E7E75F18DB4B1042B0740A
            SHA1:9089CA368FC2141BD3A4D4F7A41715D0F3A4BB1E
            SHA-256:B7F8F006143933BCEA47ECFD0DAAD0A765EDD11A852031A23FBFCE951486A6BA
            SHA-512:58613E2601EED11BE95136018B3501D8B007B08A0DFE025906B2A99E8D28912A43B3537EC91D619E2FF3B0B88E33866B0D5A77663C15DAB98CB5CFB9375E2A24
            Malicious:false
            Reputation:low
            Preview:<svg width="100" height="100" viewBox="0 0 100 100" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_44_12301)">.<path fill-rule="evenodd" clip-rule="evenodd" d="M32.2533 15.2624C37.018 12.8234 42.3505 11.3358 48 11.0504V13.0531C42.7143 13.3347 37.7231 14.7256 33.2549 16.9972L32.2533 15.2624ZM28.791 17.2656C24.1876 20.2544 20.2542 24.1879 17.2655 28.7913L19.0002 29.7929C21.81 25.4912 25.4909 21.8102 29.7926 19.0004L28.791 17.2656ZM11.0504 48C11.3358 42.3506 12.8233 37.0183 15.2623 32.2536L16.997 33.2552C14.7255 37.7233 13.3347 42.7145 13.0532 48H11.0504ZM70.2069 81C74.5088 78.1901 78.1899 74.509 80.9998 70.2072L82.7345 71.2087C79.7457 75.8124 75.8121 79.7459 71.2084 82.7347L70.2069 81ZM88.9496 52C88.6643 57.6494 87.1767 62.9818 84.7377 67.7465L83.003 66.7449C85.2745 62.2768 86.6654 57.2856 86.9469 52H88.9496ZM52 11.0504V13.0531C57.2855 13.3347 62.2765 14.7254 66.7446 16.9969L67.7462 15.2621C62.9816 12.8232 57.6493 11.3358 52 11.0504ZM71.2085 17.2653L70.2069 19C7
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):4442
            Entropy (8bit):3.895319526576014
            Encrypted:false
            SSDEEP:96:yyMMlJ4Z/JTeniIOBp5MmT6nitXAy+FUFphbTm:LTja/d9VzRWid+FUhbTm
            MD5:4DBE86CE25118951A1C558E454D7F271
            SHA1:FB62C2EE13A0A1BDF73EA3D31215B73539E56983
            SHA-256:D9E346A123C20F80337DBD3AAEFDEB982F2FCD4D1855C95EFCDFF1A481669688
            SHA-512:245421A0A7B0061D9897E5B1CD30AF2EBD027D8085F33D46B8ED407BDFD6D3C89C4ACD069F4539CE50AA70FB76348B8927029D514FD607B267AEA17A544D61B8
            Malicious:false
            Reputation:low
            Preview:<svg width="19" height="19" viewBox="0 0 19 19" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M8.74075 11.2603C8.73545 10.9437 8.33311 10.5663 7.82345 10.0884C7.26132 9.56146 6.56204 8.90549 6.07884 8.00648C5.30352 6.5646 3.59261 5.55827 2.45248 5.45239C2.39039 5.44661 2.33024 5.44373 2.27345 5.44373C1.99239 5.44373 1.78063 5.51495 1.67619 5.64393C1.07653 6.38846 0.664082 7.56083 0.600554 8.70384C0.528845 9.99171 0.899422 11.0423 1.64298 11.6622C2.42986 12.3182 3.79185 12.6912 5.28812 12.6594C6.70594 12.6295 7.94473 12.2532 8.52129 11.6766C8.67096 11.527 8.74267 11.3908 8.74075 11.2603ZM7.70361 11.3975C7.15544 11.7123 6.22419 11.9206 5.2732 11.9409C5.22122 11.9418 5.16876 11.9423 5.11727 11.9423C3.85586 11.9423 2.72921 11.6309 2.10404 11.1097C1.53903 10.639 1.26037 9.79873 1.31909 8.74378C1.36866 7.84574 1.67523 6.89619 2.11896 6.26621L2.195 6.15793L2.32735 6.16467C2.5959 6.17814 2.9607 6.2821 3.32743 6.45006C4.23943 6.8678 5.03112 7.57671 5.44549 8.34722C5.74436 8.90309 6.1
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):401
            Entropy (8bit):4.685736380554166
            Encrypted:false
            SSDEEP:12:trIdc/QKuCnnUBzpQDiqHZiftfBV2LhOizn/jy:tQ6QKuyUB6DiqH4lfb2VOGn/jy
            MD5:582FBB185FD62EA7AF1F0B7BB071C91C
            SHA1:FD95C804D151E0CDBF140B85DFB908383261EF39
            SHA-256:54B5C9C96EBCFB22018CD394190BC8E74EFB1C8F69D209720899F39C67112E28
            SHA-512:8D7DCBA7181C50A8021731266A187F5F773FBD6AE7B12DF8F57D761AC73D9A8D801F11B7AE303F6055513F92CB1EC1256AF0F2AF1B29952269DE4E5C8430A6E5
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M32.6757 31.6386L19.3114 49.7398C18.957 50.2199 18.2112 49.7875 18.4515 49.2414L27.5142 28.6531C27.5577 28.5543 27.6321 28.4722 27.7261 28.4191L31.9128 26.0568C32.2415 25.8713 32.6494 26.103 32.6583 26.4804L32.7733 31.3297C32.776 31.4407 32.7416 31.5493 32.6757 31.6386Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):401
            Entropy (8bit):4.692910367114882
            Encrypted:false
            SSDEEP:12:trIdc/QKuCOmcwYDHy+zX/V4n8QWgOxmmT0TrYy:tQ6QKubmcwYDHyWXs/OxmkeYy
            MD5:5B0493B143D8B72D1E540E945A5DB4E6
            SHA1:C943E1BAB44C7BACE61E0D2C877D375922F37AE4
            SHA-256:6BF6B6CF6A30970EB20C19E87F83D107FC013FE3D1C63CB6C9A1C96D1BB5BFA9
            SHA-512:144392AE3DFB5648B3F267C635899BF5C90B5051292A3EFB014BE30C401490D2B8DBB5D51E01A3A9193916DCCA8EBBB32281C93E74E3C743C906BFE1C53F64DC
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M31.5152 32.6674L10.8908 41.6614C10.3439 41.8999 9.91409 41.1525 10.3953 40.7998L28.538 27.5012C28.6251 27.4373 28.7305 27.4034 28.8385 27.4044L33.6454 27.4519C34.0229 27.4556 34.2602 27.8603 34.0793 28.1916L31.7542 32.4487C31.701 32.5461 31.6169 32.623 31.5152 32.6674Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):398
            Entropy (8bit):4.681109197677699
            Encrypted:false
            SSDEEP:12:trIdc/QKuCaiY2Q54Thk7yadvkbCrIcEztJonOsNVty:tQ6QKu+dGyk77dc+rIcEzTo/ty
            MD5:6E0B3E4FC3F36074F9D3873FA5F5C335
            SHA1:E911BFB7272648048578E8D4B97EE6C45BDE9BE0
            SHA-256:8430B256FC71428BC844ECF12685EA004D6D478C03B94BA7C55B592FE0AC9A3E
            SHA-512:8E1791DAB21BCDA66189D52E1B8D2162F7F0DBE223FA1FA8F9BBC7002BF2772209294764D304CD085DC382FB4D6C2A68F2C279E868903DF703D8557582A6192B
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M32.8413 28.657L41.8353 49.2814C42.0738 49.8284 41.3264 50.2581 40.9737 49.7769L27.6751 31.6342C27.6112 31.5471 27.5773 31.4417 27.5783 31.3337L27.6258 26.5268C27.6295 26.1493 28.0342 25.912 28.3655 26.0929L32.6226 28.418C32.72 28.4712 32.7969 28.5553 32.8413 28.657Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):400
            Entropy (8bit):4.6620737202264575
            Encrypted:false
            SSDEEP:6:tnrId5C/QKumc4slvIXVTGL6uEe2f3YTSZAYKtS4qn0VrWHDDFsCUltNM:trIdc/QKuCFBuEndKt3VWBUlty
            MD5:D9ACB0ECE7C07C8C69A948D5F99D7F8D
            SHA1:680DB52978538D269D5F4E8E091965BA071A5C73
            SHA-256:9D243BD6280C57797913AF79AE11D7A2340F0A77F6988C141ADFA52E33AE5D47
            SHA-512:A08E88BF0E9F6A3087B274E4E24EEB617F22FFAEDF44E96EF4854D15E001A12FEFDD4CC184AA5D05F185A67D616353978DEE4B1A6142AF5C0A4E04D2D913A815
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M30.0024 32.9817L7.64413 30.4585C7.05119 30.3916 7.05268 29.5295 7.64583 29.4646L30.0071 27.019C30.1145 27.0072 30.2227 27.0306 30.3157 27.0855L34.4549 29.53C34.7799 29.722 34.7832 30.1911 34.4608 30.3875L30.3187 32.9118C30.2239 32.9695 30.1127 32.9941 30.0024 32.9817Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):402
            Entropy (8bit):4.664183608805393
            Encrypted:false
            SSDEEP:12:trIdc/QKuC/PqRvuSrMLTcZfqaVsVy64e5bU+y:tQ6QKuZxLZZfqPLbly
            MD5:ECBCB91CB7EFCC3FDD6E9839B1971C7B
            SHA1:978E509B05F96A0E66673358B64640B18662F230
            SHA-256:20C7D999D4F3F9915D567D8745238E9F5685823DE546F2717F427348E1C61FD4
            SHA-512:71739F6BE0E42D4FDF7C73B3463D2C5B5B016E2303029456B378B6B34BE03247E72442783F350E10BBDC444237F0621899E2782B014D2D0A24E301A68ED028FC
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M28.5379 32.4973L10.4367 19.133C9.95666 18.7786 10.389 18.0327 10.9351 18.2731L31.5234 27.3358C31.6222 27.3793 31.7043 27.4536 31.7574 27.5477L34.1197 31.7343C34.3052 32.0631 34.0735 32.4709 33.6961 32.4799L28.8468 32.5949C28.7358 32.5975 28.6272 32.5632 28.5379 32.4973Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):398
            Entropy (8bit):4.682052959491246
            Encrypted:false
            SSDEEP:6:tnrId5C/QKumc4slvIJtfdD1rmeWAFjzCNxcj++aLYN3SBqWoFuaqUF/FX4aKNM:trIdc/QKuC5hrmeJFjOoGLY5SBho/Fiy
            MD5:D089FDD5D56640746073F6A27B52256C
            SHA1:B2FD40318A8BB30B47D047312563D51ED5132015
            SHA-256:9E2E634849592BF997DC1841490991138F0001A025580DE5FD7CB3CFEDE8AC19
            SHA-512:992E161F8C2397FEB26FC877778C3F4D2EC967AF49D5E8B86416F1E56B9A117123F9408579ED62042C03DB3C76949CB0CE2C105FE55B1A4273F9AA0318C49E50
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M27.5093 31.344L18.5153 10.7195C18.2768 10.1726 19.0241 9.74283 19.3769 10.2241L32.6755 28.3667C32.7394 28.4538 32.7733 28.5592 32.7722 28.6672L32.7248 33.4741C32.721 33.8516 32.3164 34.089 31.9851 33.908L27.728 31.5829C27.6306 31.5297 27.5537 31.4457 27.5093 31.344Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):402
            Entropy (8bit):4.69059712158462
            Encrypted:false
            SSDEEP:12:trIdc/QKuCjDgry828VZuJgFyXhALRKRGrty:tQ6QKuZ1wAWuRny
            MD5:4A0B8D0D5AD49F2A81A4E8BE315C3C3F
            SHA1:122DA5CB3F827C7CCFB81A04B6A472629F317588
            SHA-256:A30FD0A65FB57EA968FD149DEB9487FB67AFB2999D9451F8B2EF777721A2E1A2
            SHA-512:C980CAE158C9D763F86EFBA1F620288CCC99CFAB89B5C5DA6146F8FD6F8050E162FC056ACB5B91DF16283A66AE22F98AA3687E41ABB19232CC012085075A8C85
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M27.1946 29.8308L29.7178 7.47251C29.7847 6.87958 30.6468 6.88106 30.7116 7.47422L33.1573 29.8355C33.169 29.9429 33.1457 30.0511 33.0908 30.1441L30.6462 34.2833C30.4542 34.6083 29.9851 34.6116 29.7887 34.2892L27.2644 30.1471C27.2067 30.0523 27.1821 29.941 27.1946 29.8308Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):401
            Entropy (8bit):4.6847441830796965
            Encrypted:false
            SSDEEP:12:trIdc/QKuCb7UIVHVRULVpv152FeRa12KvZ7maAy:tQ6QKuKQIpVyd0eR8ZqaAy
            MD5:4CC9857309E3293F85E95D8C2AEBB276
            SHA1:0F218F14C85897B16F8B773655D8B146F4A4B659
            SHA-256:E05C331AA09DA765BE218C135FEC9B1F12E82A5523DD5CB50F2F670904941A5C
            SHA-512:7955035B82D9A95A5A2EB4794217D48EC901472F27C5B2910731325EC8F448A1BAAA7379CFCDAAEDCBE3F33D905B371FDA63485E602F5E27D8C1AC3B0EBFE025
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M27.6866 28.3631L41.0509 10.2618C41.4053 9.78179 42.1512 10.2141 41.9108 10.7603L32.8481 31.3485C32.8046 31.4474 32.7302 31.5295 32.6362 31.5825L28.4495 33.9449C28.1208 34.1304 27.7129 33.8986 27.704 33.5213L27.589 28.6719C27.5863 28.561 27.6207 28.4523 27.6866 28.3631Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):401
            Entropy (8bit):4.687513557212208
            Encrypted:false
            SSDEEP:12:trIdc/QKuC2IJ7UNR127lXRjE6MR6XCM0ddxIKy:tQ6QKuLsIeG6MRGCMcdxLy
            MD5:82D14DA5FBBBDAD5A7101CCD2B1142EA
            SHA1:F4FFEFF98FB926F8AAD2DC49D9BC7FE53C2D99FB
            SHA-256:663F8028F12F826030F8156EC45921907CE85D9529D8C86F98393F5F5E239BA3
            SHA-512:5CF3D5E5E94EE0CC76D9AECD1E19A10375AD04EBD70920DFC2E6094128B2748F7A3A8E258B5F258093EB437A2F358064D6BFFF56CC322E797E39AB2707FA02C9
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M28.8392 27.3343L49.4637 18.3403C50.0106 18.1018 50.4404 18.8491 49.9591 19.2019L31.8165 32.5005C31.7294 32.5643 31.624 32.5983 31.516 32.5972L26.7091 32.5497C26.3316 32.546 26.0943 32.1414 26.2752 31.8101L28.6003 27.5529C28.6535 27.4555 28.7375 27.3786 28.8392 27.3343Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):397
            Entropy (8bit):4.6431289376561145
            Encrypted:false
            SSDEEP:12:trIdc/QKuCCNWQYRmdwkWH3otoACxSPTTHTEiQy:tQ6QKu1QQ8mdGJ96T3EiQy
            MD5:42F89F6842A00BBB3D719307DEC87A6A
            SHA1:63FDEF4E99CA14132CD413818437602BAE843270
            SHA-256:549BF5BF46DFD2168F3CA1380AA1FF3535E9C6EC7AFAFA084A15358396314DE5
            SHA-512:AB66317E41FFF4334DE13CD9F6B3BC77F5164079D02840DCA1523D379390C81653EBC18803DF0BAC3A5497F90236A0C2516F1B4988E52BFD412595469D2F22C9
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M30.3521 27.02L52.7104 29.5432C53.3033 29.6101 53.3018 30.4722 52.7087 30.537L30.3474 32.9827C30.24 32.9944 30.1317 32.9711 30.0387 32.9162L25.8996 30.4716C25.5746 30.2796 25.5713 29.8105 25.8936 29.6141L30.0358 27.0898C30.1306 27.0321 30.2418 27.0075 30.3521 27.02Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):399
            Entropy (8bit):4.678061792259343
            Encrypted:false
            SSDEEP:6:tnrId5C/QKumc4slvIOKKXFRHPcL3QY2dYX6fYNBOpp2+JHgd2tf0EStNM:trIdc/QKuCOKKXFRvc8dCyLHaty
            MD5:10A8CE9B993846F9E6F24F65277213CA
            SHA1:8B2D6EB2C35C37E24E2217271EF13FF3A4B492C8
            SHA-256:B099122AB05B22DCFEB08A6FE5A24A30D7F99C0F5A50C1B2F6C412724B03AFBC
            SHA-512:2F5F82DF08C586EFA98B98A64E7EE27602CB8F74A37AF268A6B7878BE0955A3EA1DAF3D0026595178FCAE9270F0EF2846E6302E0242031CB0119EF8C233ACCBA
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M31.8459 27.504L49.9471 40.8683C50.4271 41.2227 49.9948 41.9686 49.4487 41.7282L28.8604 32.6655C28.7616 32.622 28.6795 32.5477 28.6264 32.4536L26.2641 28.267C26.0786 27.9382 26.3103 27.5304 26.6877 27.5214L31.537 27.4064C31.6479 27.4038 31.7566 27.4381 31.8459 27.504Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 852 x 432, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):485507
            Entropy (8bit):7.99071463633451
            Encrypted:true
            SSDEEP:12288:APaFOwKgfnCh+cXfRr/yYOneg9yNk84AuDwsVk6:Ab7xhpJrKYOnf9E1P8p
            MD5:C2202EC8DE17F77B2FC5D1EA50ADC905
            SHA1:BF3B45DD05340E9CFFE84F25F390450409B13C11
            SHA-256:6F9F728FF895557FB5BC30FA40B5BD3C1831971778FD246A52715B711E1DA770
            SHA-512:C919D4F02FC6A5E571E3134BF0B0608F7EF7A821F1E29473325F63CDA604A59781954E8E87BAF16D85F07D970AB0451E7B8DD50B71748BE4213A60B76367B302
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR...T..........+$.....pHYs.................sRGB.........gAMA......a...h.IDATx.....mKv....s}.....f7.^Zl.d.M.&.)....-y.....K.b.....8.G.. N..p".y...A.)A .j..)....f.}.{......W..Q.N{v.5.u..1j........R.R6..*..y......~.T9k.}.\...r..sz.;.......9.C.z......(.......{..........|......]........c...]n....~.....S.C...<l......9..m...q.5n..6..w.3......m.6...........v..]......]hc.w{..f<..q\o.y...j.3.......7._u..[..Q....3l..l.l.vul.wmT......l.{.:.m.aTG.....W.....fs..=.s{.W..96.x+....{;6n..~..:..;......`p..W........i.t..y;.@.L?:.}V.J.....g...H.5..8...6..X.}....xfA...p.w....4.:..r&.....S..v.y.}.+...b.../6F...Dn..18>..S..am.......s.....q.....2\3|..t...-1.7..6.n..x.o.....u...><N.$y...v.7.#.%.<>>.l.WYV..l...W..V.0..D7.&..]..g....r.6..,k.W..B...3.....x.....w.E.}..9.\.Ma..).U....>....>N;.0F....D[...........P..0(..%N..J......O..<.|...l'd...n.xr9...]|.x..e....|.r.r......]t..g.vi.p...Zj..{..m.....`.a.!?.~V....t.m".......L..S..6..f..Ls.?...h..9.X
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 424 x 433, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):235285
            Entropy (8bit):7.990057843209558
            Encrypted:true
            SSDEEP:6144:vsuEYm98qSbqBDtidmbIjGC91LOUE5AUmrqSp6CYexbsq+B:vsZ8q0aBidHGCO5AU0WeBsq+B
            MD5:C45D4DABCBFFA11D69F7AA46C272099F
            SHA1:0FB7BFF1322F5198BBEF411B30B04A66114DF70F
            SHA-256:E60AE3F11638C1D592DA350FAECCB6B969647863B8918B800F69EEBA31AFC00B
            SHA-512:58CB0A64BD4DE6A24D710E4AEFA9D47B81830499633812B4A20D397CE741B95E097CCE3B17FF53FDE7734B84480954AFC506A99E346B751CCA427CC5828B5005
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.............7k".....pHYs.................sRGB.........gAMA......a.....IDATx.l...l.q.L.......3RH$A.....&fb..<.......I.(.....]w/3.e.*{.}...U..../..........l.n.....p....M.v..-..M..?o6..{....q.C.....;..6.2..!~?M|4..~.................V.....1........t..p.....}......|P......6......w_....[....c.1....n/.;.y..{...~......<....<..oc.{...A.X..=s.Z..........C....s..t..........xo.}..u...G....M.O..........n<.......M].y...7....>.5...7....U.+O.2.aw+c........U..l...g.w.....]_.........V.CsU^..W........{mlM..>ZN...~.k...|..dvb.U.7....K.j.........y^}..._..}...Y....U.X...Mu.=.shn..9..9N.....h.o......o..t-}..oc~7]{*..g...lcscsZ....|...b......4G..K..$..w.....e29...?.7l......em..........s<......[.A.i.|..=...cws......u._.....L..8G..|.6.|./..\....e.1..W..Z......n.ze....gmqm.]?2N]C{...`z...s$.8.~h:.3}.M..l.C..7.A].5.]{r].~..x.y.|o:.w.k..k.on.l+.>..s.k..e.~.u...t}w...7.....?).e.....u].F.s..e9u....{.})_.....n....r..n....R'sZ...My...e..vW.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1026 x 335, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):267703
            Entropy (8bit):7.989239604474473
            Encrypted:false
            SSDEEP:6144:w8lykMbL1P665NkTYaxxzZlcpucxZsWvO5M57EMFQQMON:b3Mbh665iPluZxZsWlz
            MD5:5BDB1C680984F517C7601DD948156A2F
            SHA1:97A26D5B60D6A035B3D0214A1FE9ABCB84AA9490
            SHA-256:91F213A83222DD73DAD6955D2114071687BFDB6DD9207C56E2CDF00CA944FF2F
            SHA-512:AEE17038510F922617CC36160A2CA3CDE83FE5DB1972F668299CB7D94F527A7E3663D7171BFAA3945656BF7E1D34547248084BC7F8C75BE27D138A5DB6B4668B
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.......O.......l.....pHYs.................sRGB.........gAMA......a....LIDATx...y.}[z..}k..9......{U*DI.... d.I..#...a...ac.H.C.i`g0........qL.? . ...2`.,DI....jTU..u.....,.9...T...4l.zu.....f...Ys~....6...mns....6...mns....o..O.0X.4.c....pzr..O?...]g...R..}o}......[.&.....k....-..5...mc.~......./....6.......}..>b.2...^~.h.`..s....n.f.8.f...3.:__..=....f1..56.?N..m.........3.#...\.........m...E...M......_..~.].......y...........5.|...k....>[..O6.C.}.9v-_..k....s...x>.X>..=.s?lx........n..;\..7...s.#.>..r?..1...`...+..c:.w..~._..;...b.......{......;..6.....M........w..cL0N..............8..\.k..:?......?'...sy~.c<..=.~..}......k.x....8........yZ....c.7..vI.v..{...c.B..M...Z...,.........|..{:.-.....yk.\.n...i..a.q....0...8.Op.!...Fs...g'.>..qn..1.......6..7....gi..x.2.p.8'...........cZbnb...{{+....s..q\wy.Cx.s.K.?}......>....'......x....5.?.\...kt.)...[.V.'...vqq....q..s....6\3....r.g....*.....Z.s_E.......P}.^_.......M.k.../.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 727 x 335, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):259898
            Entropy (8bit):7.991591154389836
            Encrypted:true
            SSDEEP:6144:30koYb7PrUt27rTOli88VD+1A6ec7XVxoFDFadsl4:30tYfz027/Y/8V61A6hX8hFhl4
            MD5:1B0A670F0F0BE3D8F0CF6DA7913812B9
            SHA1:787220E87E86DBFBB0F231D160362C4728C87FDA
            SHA-256:4BF278A30A2D5D4BD765ADBC490B2D7AF040D561A0F9547553FBB23D63DE391C
            SHA-512:BC3E35310B234101414F6A4B13E9592587686234E5E99BA3C3500D8107DC09109BBF50C7956FE6907F09B38C49A8527850F358EB36CA90A98A09B92ECE9FDDB8
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.......O......S......pHYs.................sRGB.........gAMA......a.....IDATx...y.m[v...........jTU*UI%!J*!.h$.........86..'N...?..D....Gb....}h..8.>ED .!. .5...^.n...9{.5.s...U ...~g.w.....f..^k.1..3.K../..q4....'../.....=...........m........m?..k..../G.w._.._...7...G........>.....P.......:?..o......./...1.~|'........`.:?.~~....k;.}....~.....}..y.l.]W....E.......y..~......=<c..~._i.c.........}?...?h.i..w...U....;........u.ml.8..&.3..sl..q'....\y....~.O........g...ob.^~........'\..nY\...Z......yyo.{...[.{...........}.G......>..g.}vo..4.S.....m.w..v.o..[.....[.8...-..-..........|...k.....{.....s.:N*...s....F.9Y.l..I]/.xv.x6..`M.x^.m^.....Z.........cx.c...k.].z....h......9.;~.3.qo0.0~8....v.'uQ.k.....q-.9.\O..k.....{.K..K....c?`..o.f.m........>..r......s.....K...y.|\m.9..>...1x.>.v..\k,w.....o...Y.).n..?...G....''.~..x.w.b{6Mc......p..|....{.....?.../.}G.F.....h)M6.3....C{.;.iV....l.&;.yh...6...z+9.z..R............4'..~D.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 718 x 670, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):826222
            Entropy (8bit):7.973731515159344
            Encrypted:false
            SSDEEP:24576:DjrMjha1E4aDLDRKvk7nNmhxtAN6qZQYOC3+W:/40psB3whkNftF3+W
            MD5:BA9017C7DEC99AC707D4C48CA565C8FC
            SHA1:4F2EAAE58CDE99B2C5222B256FF2C349E9F719CA
            SHA-256:77C7138D09BD2555DD8B211270BFD52ACE434CEE63829474BBE39895FED67C02
            SHA-512:FAD055BBE26922A5AE1DC2EC1850E053E1CF3A2BBBEEC2690804BBE195181A001528382B45ED990384D93E183C000642E11388D174B8E21EEBBA4E41DF3E8FC7
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............:.......sRGB....... .IDATx.L.W...u..9.>9OF.. HQt.r.e_.......v.\.B..)QD...N..sz/~....`.....~....|||l...pH.T.4.0,..*...PU..UU....#....=......w...v......n.\..(..(.e..*IR.$UU5..Y..8.,.2UU...;.......]....z.i...M.\.M.$.......\....H..(.I.4M.,.mI..<.$.0.UU.8...,.(..v...}.>...8N.E..,.^.gYV.$..%Irtt4.N.(.}.(.Y..<.4m0.....z-I..p.l6UU=z.h4.-...v.eY...v.q..f..vm...4..|.O..4..p..b..}.<....E.$Ia....'O....K..I...O.._....p8...eY.F..<..EQ...h4bm/.....(i....l6.,..L.T*.4M].......p8..(eYVU..i..m.i:.....F.f.0.<.y..~/.eYQ...i....iZ..n......y..(..x:..6..l............o...O..,.2..q..E...a...Z.....s.....8.F..h4...4m.q. L.$...t]WU...0...t....v...d9_,....p8(..$IY..Z-L..w.,.Z..db.&..$I.Ea.b.y.WU.].z..`.e....y.i:...:...yQ.eY...l6.,+..(.....i.eY.{.p...E.......>MS.0.=z4.N..<..4]..a...j.m...PQ...?.V..h..7..q|}}.c...(..[XE.$...q|{{k.....(..2...t...~.W.....y...$..x.Z).b.F...$..Y.......F...t:.i.y^...y..[..n....r..GQ../..f...*{TU..?..F.Q.....p8.Z..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1796 x 670, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):1093725
            Entropy (8bit):7.968529806070978
            Encrypted:false
            SSDEEP:24576:AuFzhYj30gsZ3xhZoYi8U2OBqiTitYOElgm1+gzSXphBM/B:jMEgUhqZHKigElh+FBM/B
            MD5:B93435F7891C84D2CF62EF086C09E59D
            SHA1:EA55702A063C991F35865C4E54C5D875DB9DAE86
            SHA-256:446316E3E6055A65FF564ADBE84ABC70BAC1400BFB45C38C8600768DBF384853
            SHA-512:E25FAE357898B066125353CF53332E100E9633C314D7C9A85FB0E831BDFAE0D115CA29E24541E8CF61DBD11D8FD2C3CB0C3C49F9D45CAB17982139524734E5BF
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................... .IDATx..I.$.u.....o....H....H..v......,!..D.....dLo......f.XWK.P..&$2#......s.g.z.H....0....m....I..........B..g...>}.s:.8..\__.w..w.f3....~.....l.B.i....8...!..,K....}4M#.2....kt]..W.f3>|....{.I.|...m.$.0.. .(K.4..{...mZ...}G..eI......8x.K..M..eY.N^..yN.utmK4...!q.....y8.K..IB.u..sl.,K..UUsww....yQ..1]...M.a.,.K.$a....i....@...Y]]..l8..4uM..D......m...8.CY..E...IBY...r...}6.5q.p}}M...yN...y..|...._...E4.PU.........(.V.....t]GQ..y...#i."4...\_]...~.z...l..iTU......4uM.u.u.mGUU.A.b..t:.$..ib.&...u.}.SU.M...UU...H...V+.0.m..!.cy..g...!.sl..v.t...m....eQ..:}.}..p>...............GN...=.?.).....;.>..,.(...m....9..DQ.....4.8...qL.$\_]..."MSl...<.,..+...:y-t.8>..9}..y.|v4..t.....'6...m..=I..i.A...o.E...._....(......m..{.$.s.,..}..4MC....1..Y...u...=..y...iR.%e].-]..u=....!u].-m...=...8.C.v8....3.#..8...B.......x..Jl........R.%]..4.UU.....].q]..u.Z..4.........~...S.%.?.'.2<..m..aY6.....,.4..(...#.e..|..il6k..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1280 x 670, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):1049673
            Entropy (8bit):7.976706903829768
            Encrypted:false
            SSDEEP:24576:fA7NUGJWlwA7pphO+l0CJHqgl9BM5mkswin:47PJWlzppIeH39TksHn
            MD5:C19DD2B7737546448097528AE588BE22
            SHA1:E7FE554892A3C938777741BACC372AD87715E7C4
            SHA-256:0DD91D8106F3EC9B7F4E57F44978410DA07C97C641169EDE8A9A76ED0D25CE55
            SHA-512:266792DB3EAA31845B4E65DE3AD2D20AB9D6CF342A72A8A3BAFC2BD441DF75F548374CF769B1A1BA51E077DBCB21C5782179647C86D70B6BE76F0E11050D0ADA
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR............../.J.. .IDATx..G.$.y......232K....@.\.f...q.?......I.c....].R)BG.V.......s..,..EeF.....+.g...m..)u]c.&.m.8..M..)}...!}.i..}..A...=.......5.....l6..o..?.)...M..u.].q].]..4...... ..u.<.i..i0..W.^1..x..=.....b..8di.i..aHYUdYF...!...M..{A.uTUE.u.X.....G.tm..m...AQ..E....uDqL4..$........y.EA...!...8.KUU\.g......zMQ.$I..:.4...4M..%i.....,.8......Y]]..n9...MC.fD. ...w.gs\.*+...{.4.*K..a.Z.....$I...&.C....{..r...g......E...u......(..j...5B...(J.....M.....k.C..W.^1..0t...y......i.i...u]..!....L..X..eY......m.<...yxx..{V......qh.$I.\.p]..(p...u1L..qp].4....0.{......i..7....G...8.N..g.={.O~..<....r~.A..eI...8\...(....4MM....G.$!MS...X]].e.....>E.S.5].!....0H..YQ.....r..:...z....v..8.}O...N.......a....7h.F.E..k..i.....*.. .s. @.4....q}..s..%M.pww..r...eYTUE..]..:..1..p2.i.D..u.}.s}}..t..u..~.8..{.$.(J..=./g.3u].8.._.f}{CUU...m[.f...9.a.y...q.Z..:o..Gv....5?.....w..Q.9~..:...c....S..UU..:eY....l..{...]..n7tm.....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):5666
            Entropy (8bit):3.9790210325376933
            Encrypted:false
            SSDEEP:96:BmgDEPW9Jg10SQSdfk6VlqcoJXFElXwBn3ntvGoVGASZAuG:dDfJg1Jds6Vl4NG4npGvtG
            MD5:8B19ABF166D700782B5B4CCC177AA885
            SHA1:D5F7B294866BC3B644827C1EE972E86C736628EB
            SHA-256:03B4FEF8AA5BBAACB2BA15346B12B8F2C37D5ACF8769C040FAF8137F83949E38
            SHA-512:A0213EC78152BED23A62100D238C0A5FB05855B2FE22BF439CAD267C27812E8B006398FDBBE8C7662CB71F3FBCD24618429422BF5C44030B4274A7341F5EBEDA
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M9.33588 3.76194C9.07655 4.7013 8.91113 6.02735 8.91113 7.51158C8.91113 8.9958 9.07655 10.3219 9.33588 11.2612C9.46652 11.7344 9.61331 12.0809 9.75541 12.2974C9.83934 12.4253 9.8985 12.4751 9.92755 12.494C9.93252 12.4906 9.93828 12.4865 9.94482 12.4814C9.9912 12.4453 10.0542 12.3776 10.1167 12.2709C10.2561 12.0326 10.5624 11.9524 10.8007 12.0919C11.0391 12.2314 11.1192 12.5377 10.9797 12.776C10.8665 12.9694 10.7246 13.1418 10.5587 13.2708C10.3964 13.397 10.1813 13.5036 9.93341 13.5036C9.46152 13.5036 9.12952 13.1663 8.91939 12.8461C8.69647 12.5065 8.51575 12.0482 8.37194 11.5273C8.08237 10.4785 7.91113 9.05848 7.91113 7.51158C7.91113 5.96467 8.08237 4.5447 8.37194 3.49582C8.51575 2.97492 8.69647 2.5167 8.91939 2.17706C9.12952 1.8569 9.46152 1.51953 9.93341 1.51953C10.3928 1.51953 10.7291 1.84579 10.9381 2.1671C11.0886 2.3986 11.023 2.70831 10.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):821
            Entropy (8bit):5.043431220128797
            Encrypted:false
            SSDEEP:12:TMbeIMu5E4BauqWGRRHE0cYpPPHMaJWwF14s5AfKGAAf0SclSRJCMBOqU6Ye:qexWqW8k0ppPPD50KGA00SMS2MBO8f
            MD5:3D3AF9C97D40251E038D0C4D9F01D64B
            SHA1:68FFA11127C3389A52DDC040F2365FAB29C9DEA8
            SHA-256:80C066486B25AE8A27917BD64A930EEC08795262EAFAE5A52CC1CEB5743E47F4
            SHA-512:0E8D3BAF72639CB953497C4BAA9249A1FD6C19AE78E4AEB41644D6170D27533CFA81C22AA87C42913D2435990DA94ADED59963F3F8044B469D2985F0B7202C48
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" standalone="no"?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"><svg t="1644659998386" class="icon" viewBox="0 0 1024 1024" version="1.1" xmlns="http://www.w3.org/2000/svg" p-id="2140" xmlns:xlink="http://www.w3.org/1999/xlink" width="200" height="200"><defs><style type="text/css"></style></defs><path d="M820.394667 799.232l75.434666-75.434667 75.392 75.434667a106.666667 106.666667 0 1 1-150.826666 0zM378.794667 46.08l482.730666 482.688a42.666667 42.666667 0 0 1 0 60.373333l-362.026666 362.026667a42.666667 42.666667 0 0 1-60.330667 0l-362.026667-362.026667a42.666667 42.666667 0 0 1 0-60.373333l331.861334-331.861333-90.538667-90.496L378.88 46.08zM469.333333 257.28L167.637333 558.933333H770.986667L469.333333 257.28z" p-id="2141"></path></svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3332
            Entropy (8bit):4.213825505498953
            Encrypted:false
            SSDEEP:96:1EWt+DGL/9C5hyfr1PoLilz2jzOqxi3ArOhwXZPVSBsvFPt2:dID+/9GI1P07Cqx60OSNSavZt2
            MD5:193A3142338B7BF73695F1494955AC2D
            SHA1:D7A1F80331BC0546A752390CD2A75962D5ECFE39
            SHA-256:1E185C0E6015008429B450A7C26D31C93EBF866505A063EADD18DEEBDB2214AA
            SHA-512:0EF6D276BEDECCFB6D349635625E3AD0271FFE7EF8406207E588B1C6128ECF77321EC9A7F67BEC926971667BE13242F71FF37510AD40A87AFF694FFB5F5EBD9B
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M17.1895 9.86816L8.73591 18.3217C8.54065 18.517 8.22406 18.517 8.0288 18.3217L0.346886 10.6398C0.151624 10.4446 0.151624 10.128 0.346886 9.93272L0.411443 9.86816H17.1895Z" fill="#54545A"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M18.0623 11.3705L17.6241 11.6113L17.1862 11.3701C17.2742 11.2104 17.4421 11.1112 17.6244 11.1113C17.8067 11.1114 17.9745 11.2107 18.0623 11.3705ZM19.8145 15.5488C19.8145 15.5488 19.8145 15.5487 19.8145 15.5488V15.5488ZM19.8145 15.5488C19.9034 16.6116 19.6888 17.3534 19.1836 17.8066C18.6985 18.2419 18.0669 18.2932 17.6241 18.2932C17.1809 18.2932 16.536 18.2389 16.0436 17.8063C15.5228 17.3487 15.3094 16.599 15.4355 15.5317C15.4774 15.1768 15.6202 14.7344 15.7876 14.3012C15.959 13.8575 16.1721 13.3835 16.378 12.9523C16.5844 12.52 16.786 12.1253 16.9359 11.8388C17.0109 11.6954 17.0732 11.5788 17.1168 11.4978C17.13
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):168
            Entropy (8bit):4.8907140362995225
            Encrypted:false
            SSDEEP:3:tRBRNqcwR+8XcvUJUTlt7SLvDmJS4RKb58ZQGuMnccwR+8DGVPRXlcJ3CrVZ8v:tnrZvUYltumc4sl7anLqSlckm
            MD5:27BF75AB7A92D199AC473C1FCA8830DB
            SHA1:E179820CF9EE47B32BDFC2EC7675AFD9512B35C3
            SHA-256:6C5EE2333EC8E6DB37BD238E7E9531305D988F2BA2C902A1C54E6A29F3132EB6
            SHA-512:B171113B60DBD773B55941A002B940E9691F24B0651527A75823942EE6E445325C4B571C0C5F8C97A1E99EA2E9C86D0F8698DF7D5B481C9483CE4B2A2247C6D5
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="16" height="16" fill="#00AE42" fill-opacity="0.5"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):168
            Entropy (8bit):4.8907140362995225
            Encrypted:false
            SSDEEP:3:tRBRNqcwR+8XcvUJUTlt7SLvDmJS4RKb58ZQGuMnccwR+8DGVPRXlcJ3CrVZ8v:tnrZvUYltumc4sl7anLqSlckm
            MD5:27BF75AB7A92D199AC473C1FCA8830DB
            SHA1:E179820CF9EE47B32BDFC2EC7675AFD9512B35C3
            SHA-256:6C5EE2333EC8E6DB37BD238E7E9531305D988F2BA2C902A1C54E6A29F3132EB6
            SHA-512:B171113B60DBD773B55941A002B940E9691F24B0651527A75823942EE6E445325C4B571C0C5F8C97A1E99EA2E9C86D0F8698DF7D5B481C9483CE4B2A2247C6D5
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="16" height="16" fill="#00AE42" fill-opacity="0.5"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 725 x 432, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):352380
            Entropy (8bit):7.989599258875478
            Encrypted:false
            SSDEEP:6144:UH0Tn7MHUryLeDHshYaZCaRjzXoM/tBn56/LS/MWt4/GWR7Nk7AlLloEMKIQ/WN:Yan7MHUrweZc5ho+BSgKN77ua/Y
            MD5:615B7E360E12726254B0C47E4F1AC546
            SHA1:EB948443F4485A45A06251F63691A7F839EF588C
            SHA-256:164440C22C0F9B56C4FE7C0C0998C691A52AA41DA12E3FB58FDCF72267D4062D
            SHA-512:0151180FD58F0DB21C2C9D0393A1400FA94C2FA6D90B12A628B9A041B3F053262F7BDFBFAECBF0AC140914C19CDDF773DC15D40BFFC712174B90DC2E4FBBD1A3
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............fb......pHYs.................sRGB.........gAMA......a...`.IDATx...].-..%..3..>.mw[.v[...~.lH~...^.:.~0`..~i@0`..[V..{N..k&=..#88...r..V.L2..F........?.../..5;.....k..8...~>?..........g...u..}F..[....|....O.....s\...w.{..^...g..,.u..x...........>.....Z.g.y.g.q.....t....p>=.........._.Ym...{L..F.x..3O..?..v................g..z.g......;.k...<.s]x.....>.>2_...7..n...{..:.....m.....<..g<.6.~.......GVRf...)7.[.c<s]O...c.m................x~.I.g../......d..a...z....<.:..k?AO0=.W...s}.r......,A.T?A/..............I..:.o....}......w....:..2h.g.....>...(o....m}yv.,.|..b..g..h.......rp..\...7.H;._{....m'...]mfZ....},.*.L...g@.?....c].....=~...;.k..r.u..._..3.}.X......A.YO.Ol.6.5..&..NG.F..W~..`;..q....3..ha~...P>......(.+.c.....|.W[.../YG.....N7.k..S.....h#..v,z..<tM;..}>d.............v...P............../..........r =....K.....%.?.!<...VV.:.X......Q......-..x..wQ...\<...g....7.J0.....~..OJ.....hW..K.".A.S.........~.>.}..4
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 694 x 429, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):491466
            Entropy (8bit):7.99466479429818
            Encrypted:true
            SSDEEP:12288:/m7OpIzoaH8lgUAG/GUuBYJ03hlD+fM0Yr8:/oOam1/Gz5hlDidYg
            MD5:3472BA30B89599DC4220DAFA20864B8A
            SHA1:3137D31B3026F8EC6DE2CE4CCC35C6D459A30610
            SHA-256:E46E2C8A7290C0C331A6229B94F2ADD86DD91D803F64F112879C837F2F82A143
            SHA-512:FA1224A1B9B3CD2C78546C887E36BA176CF8265BA94A62F21702B44F1F4EC59BA1E5BE7ADC02FB4A145A69CA4E468524F05CE409AA868648FEAADBEE326B93A7
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR...............7)....pHYs.................sRGB.........gAMA......a...._IDATx.T.Y..i...~g>.G'..|....p.......F......h..j....p.w...~.\#..".uA..dFx........a?k.....x....ox...q.;...._m.'....7..Y,....n....\N..l6k6.....z.n./..I.l7.{..q..N..v.i.E3....j.L....t]~..q|o8.....0~.`o.Y./...N..g...y......v{...Y<I...A..^|........gGGG.4...n..`...n...c}o7.}6..W../..\^^6_}.M\w.....m.yv..'O..{......o..y......5~..W...O...N...g..:....\..B.dmy.Y\.{p?...nt.N|.g.t.q..~....... ....^s..4....9<<..OOO..;.....'<w/>..u..E.:..c_..Ys.......z...X...is..e.;........+.^.|.m..|..'..d(.`...;!.....^.x.N....\.v.y......|..c-......Z<..7...*...59.g{1..}`..C.Xgd.....s...../..3..h4.>...x.M..y.......;....w........5........l^{....{...;.....^...O.>O. '..y.]K....8.{{...;....W_yE...q......qCk...w....u<.i....k..Y...E......B~.B.....3y~q...y....}~......d_.>.=......isxp.u..........o7.....A<.N.../.g.z..R..~........?..R..{.^.......u\.s.|....)..o...;...._.?.h...>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 877 x 301, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):266346
            Entropy (8bit):7.992321506229279
            Encrypted:true
            SSDEEP:6144:oRTW+f51Nvz+YHJWUkFMw0GC4S9ruDDvGeUFnfp0Dd8lLBSF:45TvzvHJKF1014orESfI8lLBI
            MD5:D039C69D0EF3B2973E75AF32ED802004
            SHA1:4592B2259C44308D99AB0153BEC73F6531504C02
            SHA-256:D00871E1E02A1FCACF8DA0F5B9DFE03F9874448E3B7F12312AF4C4F26AE9F294
            SHA-512:3C4A7F0F7548B12115AB4812CAE69503EABD4470D4393418AF6BE860458783D6DD87E3D8CFDDD75466109359D0048D1B1D1137E11D94F176F3E8088B6616DE8E
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR...m...-......5......pHYs.................sRGB.........gAMA......a.....IDATx....eY...{.O..Z.{x.....T....6h...l..........!a...8...=..F.Q...J.XUWeUe..p...'...~.Z...8;-.....}.:.[..Z.....Yomm..lZV.U...e.Z..tV:..L.....w{e6..2..K....R.}...G..~...~yutd......'..j..|6+../=...;;=-..TUU.67...bQ..e...(....L'e.*ess.......\.r......{...~..........>...c..J?.....?.I[..eow....2....Fz..?.s.u.j..zm.n....<k...u.~...p....W...b...e..s..]]....e..5.q.....G_u]..q...?....G.f...\.....}fwgG..n..o..w..k...7....;..*...WG....rjsqrrZ.U.t.....'.+..|Q:...3L./.f..y[........iS.o...)c_.u_..........j.......8W.....s.U...n.'O.....ak.q......k.=_w...d...O.N5.S[;......V..~...Y.u..-.._....o.k.3.........d...^x....`M.......C..r..l..1.5.....s^.zU}...AY...s............5........`N.vw.\\.....k....|2..A..&M{.5...........&cb.......f..|...K.....=.1ct...]......5.:_.:g....Qn.....l...m.O...u..g.>../^.|Y>..w....~._.[...A...5......Y.'...'..?..?..f^.....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 829 x 301, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):264347
            Entropy (8bit):7.992558043812196
            Encrypted:true
            SSDEEP:6144:6oI47xebS0I69zGlZClmby3e/KHF24uDUac9K97W:3JgbD99mUeUF24uD667W
            MD5:F606CED5FAA44B0E6FFFD10127442579
            SHA1:309EF9EBC864CEF1C41C8F5241E244F5489B4386
            SHA-256:222A8C7A63CDA648DD8D0EEDB790800D32990EE3D6754BF15397BAEE9CDF9BC6
            SHA-512:C19983FE5EDBA8CFB5FC7E436C671D9AAEFEA800ADC5D3F52376A4C65C108191D7DA9A712130D60AAEDD3BED41D596B026EA62C87A77CFDF33CE5FA723E09DE3
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR...=...-....."!......pHYs.................sRGB.........gAMA......a....0IDATx....ei..}..7.l....1dDfDdF.TYh.`............P \p..$.......w\4.(4..U@.......2f..G...C...u...D...{.~.....=.......rcc..'./J../..L..jUel.V.g..).).o..pX..fi.R6...?...3...v....}..f.2..J..(...;..t.^<.......RUU.X_..g.Y...emm...{.s4............r..r68+.../=.Y.....w..~..g......lgg..g..x&.|1/;.;e:.....p0.;p.3>G[..FY,....}i..3i..X..v{z..m...t..E..g......../.=kb.b7,M.....'.<.Z{.=.k...~.../}K.........l.....o...+.g.{..._.].-.G....rjcqrrZ.U.........+..tVZ..;.y..f..}.........i].k...)}_.}....}..lj.5..?..'67....r...g....................a.~.Zyds...z.%......S........l....fe?....a...j...#...u.v.}..>...b}2....S[....sY..3....yppx`..W.....).C.c.....W......../.9wn.\.p..w.\.p^c...Z.......dg{[..=y......'...dLm.F..3{....[.km.'6/^.|.6po.......1......G..^.}.m.Ol......s.:.z..r...g..uhc.s...n.].=....u..._.....'O.n.[^X...^...9....Y..Y.'......?..?..f\^........
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 578 x 432, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):508733
            Entropy (8bit):7.995457263598979
            Encrypted:true
            SSDEEP:12288:41VRMAytBmQgz71hZ0OaRm13cww1JD7YGrbrvuokJGyH0PR0ib3II:kn1ytBpgFKRscwqXrvuzJGy4xbH
            MD5:695FE24C0C99F68E3D936EFA3042655E
            SHA1:04DA34C1DBFCAA6D09C99255CC3FDE835E771C93
            SHA-256:651AAE3085A74FC46895240CF6D5FCEC0845F6059C1A6C3A562220649F56E827
            SHA-512:325EB77F4B38B370E37980E150E3BF86DB6CCE3D1D5A22CADB15EE8FA58A66D8A04396278F2AE6698636A89A7D07440E2290BC11F938CB51CDAC1511C69B081B
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR...B.........E.......pHYs.................sRGB.........gAMA......a.....IDATx.L.gs.Y..m...{.'@.f2.i*.t.LwO...W..)..Bz./..D/..P(.H.s...5].UYY..4.!...{....>.g.O.e..L...{..,........C^^H..BAAA(*,..L&.....Q....!...p||.......Y()+.......2T.W....PRR...k}F..^.R.....$._..67....lV.u...*...U.....NOOCyyY(.....C]]m8;=............e%.`g7....y..R~.T. TT...n....&C."..n.......Ik...~.C(-+.e.e...,.i]WW..{.>...$..g'''z.t8;;...... ..s..-........J..\......=.qx7.>tuw.|....~8?...Z.#....9...u....pH...}.c.....J...^..O..3ar.}.ho.k.[.....T....M..a.`?.....!{Z...V..#amm3.......}^EX]].E.....y}}EXZ..zj.....B. ..KJCm}Y..?.U.Uaks;..........W.JMu..-.N..':....pyu.6...i.}E8.>.o)=...V(..r.UU....(...JJ...SaxX..........wp.2W..p.@...-.....Thjj..z.T*..........PYQ.=.~.}.z.r..rr..8>9....................k.9K.S=oJr.I..~..g+.k...............f.g%C.*...j..</C...(.......M.r....s...S.yz.k....F.h....=................F......Z...._~..<}..........?..6.M...E{.r.w.{........^.-P.W-.<....%.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 763 x 302, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):229119
            Entropy (8bit):7.986934628802921
            Encrypted:false
            SSDEEP:3072:0o+ZhcbaNaOXuWQ0L2LiW/kEYPT7QTeYPc/nzJAXDR4RYRTmKp3NBqeJNX7MTv:0oeNaOeWbCLj1YLMTBS494iRyaBJLMTv
            MD5:85484ED51E34A74B83AD85347656A009
            SHA1:C6BAD39183DAE51F4F29AD1D3929BD6B0070AA90
            SHA-256:F9329E95B080F7E16C1D2E4CF6478A26269AD5B29C2723AFE172E8B564092D5D
            SHA-512:EA4A4E6C5BEFB993871154DE4521589C3441CCD946B7F5CB2986D872516139BFB1570EA7F1BE6F2D1BD2869D2E16F610C088B9E55FB6F059A134D4632646068C
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................O....pHYs.................sRGB.........gAMA......a...~.IDATx....d..m3...j.....=t<./U)V7............p.... ..hP6..`s.IVUWfVf.|".#\.....D....{d..g?.s.{..g.s...../._.o.....0?....R.....l......04.....CGGG....''gao./.....Y............{.:;.C.T.;{..{G89=..BgWkhl,../.C{[..u.j.Ym.<\.]...V....r.l(.K.\)....p.}__...W*.CmmM..~..OB.\..............*...NOCO.oh.....K.f9.......PWW..L&\....+.......<vCSS...&...p|....u.B.oh.1....s.s..}tt....t..P(....u.5ak{;.i_...>...04.......}&..`..&..KW.6.........pq~.V.Vu<.q..oBCC!..w.u|7.#m..R.-....p..^^Z.5...:...9\.......F......a}}...f5....E.........3]....s|r.6.w.?.........v_......;.s...."p.........s<;...@....]....].m.A....u}.u.u.....]..................==]Z..024....tny.y..~.}vv...&..B..........}d.].ol8./..\[Ck{K8.;.5m.*.7t......P.h.|...k..<W.....y..y.........kR.....:...o......._=./_...6..}].z....059.....y.g......>.tOv._.y.s..nmk?..]..!.-..FG.t/......}.........C.X.\...|(.j.........Z..qpQ
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 715 x 302, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):226283
            Entropy (8bit):7.985180747492277
            Encrypted:false
            SSDEEP:6144:8t1p6a1l24BMIH7rM1ZlzPN/qSKwHxmRIb1ulDOX/C:8trB1lRMIH7oAYkD
            MD5:69625DDA373126A462B8F24BF1F7D878
            SHA1:CCC0E811A020C9396888218DDB75748A4F6F2274
            SHA-256:A9C69044D456E99586FE1996A3EF706116343DB2B28ECB006508251B3AE99CE1
            SHA-512:E57A48388DF12D84958FEA7A8CAC78D3434F576D506AE8C32A67B0A82D2CEB1B6919FAD319007256CEDD7F32E93850B14DF433CB70075778DF2656B58702B6D9
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............xi_w....pHYs.................sRGB.........gAMA......a...s.IDATx...W.dY....U5S5.9..,.#<X...j..A.......@.G0..<8... .@d.t...`.2.t.tUuUg%.....8.+...s..#g~.?.M.tw3.K.=....^{....._..j....R(.....:..PSS......p.8>>.......&.........fC*......pt|.F.....y..h..b9.........T....]...1..Z..m-:.M....py~...Z}.|..2.t(...T.....p.c.\.CV.+.J...&..G..\*...................BO.oh...+...g).......PW...T*\.......q...u.{...Ic...B1...8._]6....t....B...c......:.o1.ru...]CM....}:......%..u....~W.I.<8n.I...u..h.5.....1\^\...5.Oc...|hh...N.../.1.>..t.Bhii.g...u.A..3\k......imM&..l.....X.666}..oZ...[.....18;;..!...8'..akc/...0.n%t....].]...A]K..7...................}.4....N..l..:.-.=...s.....-.~.......8......-..~....|M......k...wf.{...+4.6.8.........t.m.#..2f}c.aciE...Z.[.....i..UN..{.......C...p.@cQ.jll.e...{..(L.L..m...hm8......lC]X|.....Qx...)....>.{.^^....xHk...4.....k.......3..~.v.......qt....C6..5....Y<.m..ao.0.....1\._.b.....M.P.s......3>...y...
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2059
            Entropy (8bit):4.448687160680312
            Encrypted:false
            SSDEEP:24:t3JfDut7rWMM7S+V86cAIhZMlPwhjpyBAO6wChhwlrlLr4mcxcsLmPqc3IPJRCJ1:3iZukjpeVy6pn9JCOh4RRCJx20/
            MD5:91E2CDE04BDBB024EE0255C324CE430F
            SHA1:7702BA755E4F1EEF1F6CB2CE4A2313433F4B5AC1
            SHA-256:2BC395B42C4FA1148794D04656225EBD7CED24EAE779CC84E056359D67A78E2C
            SHA-512:380CE99C5CAF3FD4A71273FE36AD7273D1AF521D3BA23FFA814049465ABB8E11C1D60FBC891C2CFD4F016CEFBB4AC720E7AB3F0D2630EF651E18849D2AB18F69
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_6859_29267)">.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.4935 0.318359C5.7203 0.318359 5.0935 0.945161 5.0935 1.71836V3.24784C5.0935 3.57921 4.82487 3.84784 4.4935 3.84784H2.10361C1.33042 3.84784 0.703613 4.47464 0.703613 5.24784V6.43262C0.703613 7.12336 1.20385 7.69726 1.8618 7.81181C1.81196 7.9125 1.77367 8.02049 1.7488 8.13426L0.907354 11.984C0.716532 12.8571 1.38142 13.683 2.27506 13.683H11.7505C12.6322 13.683 13.2944 12.8778 13.1242 12.0127L12.3669 8.16298C12.3409 8.03066 12.2967 7.90577 12.2373 7.79071C12.8455 7.63831 13.2959 7.08807 13.2959 6.43262V5.24784C13.2959 4.47464 12.6691 3.84784 11.8959 3.84784H9.50613C9.17476 3.84784 8.90613 3.57921 8.90613 3.24784V1.71836C8.90613 0.94516 8.27933 0.318359 7.50613 0.318359H6.4935ZM5.8935 1.71836C5.8935 1.38699 6.16213 1.11836 6.4935 1.11836H7.50613C7.8375 1.11836 8.10613 1.38699 8.10613 1.71836V3.24784C8.1061
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1561
            Entropy (8bit):4.339691317209299
            Encrypted:false
            SSDEEP:24:t2liurV4ok8tt+pwYkAW+7jMtLYd+nqP+AE/+ruLO6wH+LXutuqc+paJs:uDfRUpMtICOEetuqp
            MD5:5BDFEFFB1CE943BC4844C743C5F6A5F5
            SHA1:0CBE66F06967B9FF62B33BB4B20CD9789D4ABFA7
            SHA-256:018F38BE6554A906413E4A310FBB9A8B3E41E0DF323869780EF8E102A5852233
            SHA-512:A57774843691ADD7D00108B20AA1D67C6BE6C95AE210F00DF63AD5A40A83B9FC2407F647E1520E65AA8AE60BB6D31E2E54B2FFD0998B7D37BE840DC53CF989D7
            Malicious:false
            Reputation:low
            Preview:<svg width="35" height="36" viewBox="0 0 35 36" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M4.52458 9.58637C0.307453 12.2711 7.28167 15.5558 12.1803 17.5783C14.8309 16.3003 13.1476 11.5558 12.1803 10.5685C10.2307 8.57854 9.79598 6.23048 4.52458 9.58637Z" fill="#262E30"/>.<path d="M25.1696 15.1938C24.5835 14.0214 22.1104 13.3011 21.1837 14.4904C20.257 15.6797 21.1837 19.0099 23.2939 19.0099C25.4041 19.0099 25.7558 16.3661 25.1696 15.1938Z" fill="#262E30"/>.<path d="M15.6738 24.4552C13.798 22.4857 9.10872 24.1035 6.99852 25.1586C6.99852 25.9011 7.25644 27.5736 8.28809 28.3239C9.57765 29.2617 13.9491 30.0824 15.6738 29.379C17.3985 28.6756 18.0184 26.9171 15.6738 24.4552Z" fill="#262E30"/>.<path d="M26.8109 23.7518C25.873 22.8139 23.9587 23.2376 23.2939 24.4552C22.6292 25.6728 22.8953 30.5513 25.5213 30.5513C28.8039 30.5513 27.9832 24.9241 26.8109 23.7518Z" fill="#262E30"/>.<path d="M20.4438 19.8966C20.4438 18.6796 18.8417 19.3895 18.0407 19.8966C17.1989 21.1791 17.2399 21.45
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3982
            Entropy (8bit):4.528716837105482
            Encrypted:false
            SSDEEP:96:Nbq/RKqDEkxE3ELqgRboLjF0PbtIULMc1T2FZJg:NbqJKE3xVLFRkL50PbtDQIiZy
            MD5:343EF40A4FA35D1D6A0589170D075CB8
            SHA1:0A06946A81EB31EAA7055EF6864AF2F577342356
            SHA-256:5548C1AC43B01DF8BD0BAACE9B1056BF9B891C69667FB7B6AA3CC8E955A52466
            SHA-512:6BA98C5A47277BB99662BFA4A8844AF0A7429C8803824DA2FF21461DD217AD42D9DB756EC071A47D533F46C958F2B0F725A2355F56224B68FAD01DCBC479F30F
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M2.37524 7.07324C2.37524 5.41639 3.71839 4.07324 5.37524 4.07324H14.2421C15.899 4.07324 17.2421 5.41639 17.2421 7.07324V13.2871C17.2421 14.944 15.899 16.2871 14.2421 16.2871H5.37524C3.71839 16.2871 2.37524 14.944 2.37524 13.2871V7.07324Z" fill="#54545A"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M14.2421 5.07324H5.37524C4.27067 5.07324 3.37524 5.96867 3.37524 7.07324V13.2871C3.37524 14.3917 4.27067 15.2871 5.37524 15.2871H14.2421C15.3467 15.2871 16.2421 14.3917 16.2421 13.2871V7.07324C16.2421 5.96867 15.3467 5.07324 14.2421 5.07324ZM5.37524 4.07324C3.71839 4.07324 2.37524 5.41639 2.37524 7.07324V13.2871C2.37524 14.944 3.71839 16.2871 5.37524 16.2871H14.2421C15.899 16.2871 17.2421 14.944 17.2421 13.2871V7.07324C17.2421 5.41639 15.899 4.07324 14.2421 4.07324H5.37524Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.48804 1.73156C6.76418 1.7315 6.98809 1.95
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Mac OS X icon, 57628 bytes, "ic10" type
            Category:dropped
            Size (bytes):57628
            Entropy (8bit):7.979075785793285
            Encrypted:false
            SSDEEP:1536:6uT7W6sbDMYL9TxWTm5Wc/Dn7e0B1yX97+FPV:6uOMsTxWSN/DnX1E97u
            MD5:895879CB7212948AB7D6A423A3C1D9C0
            SHA1:4A78966231F439FAA2A7971231B80AA4BE8C1E26
            SHA-256:56E3D96BADE5CEA62C75B9D5AC31E9ED3B543EE44A8848D0D8B83E71E7050D06
            SHA-512:7AB6D6D6E10B78DCFA036125DCA7C3777E69566B84C6660F87B248DE03F9FA58ED0AE318C287E12AA863EEACE15415146155848197FE36CDA229669577345BF4
            Malicious:false
            Reputation:low
            Preview:icns....ic10........jP ........ftypjp2 ....jp2 ...Ojp2h....ihdr..................colr.........."cdef..............................jp2c.O.Q.2.................................................d.#..Creator: JasPer Version 1.900.1.R.............\..@@HHPHHPHHPHHPHHP.]...@@HHPHHPHHPHHPHHP.]...@@HHPHHPHHPHHPHHP.]...@@HHPHHPHHPHHPHHP..................PT.#E....36.>.9o.3.i.@......h...E.K...Pxj..P3..i9...Z\R.j.A.L.b$M..=m1..B.z....0.."..p..iI..1..B?......h..ZT...E...V=....F.<.....*.t..`.7......0". ...u@.p.$%3...x..;y<0.m...nk......<.<0...."rNet.n 1.S.Mw..!.."4.xX._.KT...J-....*...b....x..9....5....bF23...:o.3.p..._...,...Y...8.4...X...H..0..HT.LP.;P...%...g\.....W...b.HH.H.L_I^....2.<%.Gb...........HHk{.o@.d{..T..3.&-'su$p..%.......O......7.*._.i.R.E\.pC"..d.7....... .p...\.{K..:7....S. .Qh../....{JHJ-4l..3.mQ..B....XK%J>.z...3...X...uUd'.N.lu.fQ3U)c....c.a.c..&~?#.V6{...Jz...H.>....f...W....a.4S..!....Y..I1...v:.c.k..+......<.........R.B..ap...Rc.G..#.k$.]n.%'.!3
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1151
            Entropy (8bit):5.257284781273581
            Encrypted:false
            SSDEEP:24:t/l/uGARtT7jvHJPV85ZiSpI9xArHxl6zXTYpVT8+CHD6nQ5hIHA:TyP8ZTHOzDYb8+cM8iHA
            MD5:F563480FAA41ABC4F1EBB9690D52A6D9
            SHA1:2FF76D1840D17AF6469070D2F145D46724F2B24C
            SHA-256:12D6B2288083205EF30F3AE0D667F16CC91EDF3FB108173ED058B60BFD08D8F7
            SHA-512:BF6D801D4B0CD00DCA8048E4171503F6EDEEE91481324F569FC37186561ADF7B4D9542890905213A0ED5F853C2895F80B910A78FA3CFAE98F34F0E47231598DB
            Malicious:false
            Reputation:low
            Preview:<svg width="36" height="36" viewBox="0 0 36 36" fill="none" xmlns="http://www.w3.org/2000/svg">.<g filter="url(#filter0_d_12_4)">.<rect x="2" y="34" width="32" height="32" rx="2" transform="rotate(-90 2 34)" fill="#EEEEEE"/>.</g>.<path d="M13.3006 18.65C12.8998 18.3331 12.8998 17.6669 13.3006 17.35L19.8807 12.1469C20.351 11.7751 21 12.152 21 12.7969L21 23.2031C21 23.848 20.351 24.2249 19.8807 23.8531L13.3006 18.65Z" fill="#909090"/>.<defs>.<filter id="filter0_d_12_4" x="0.953722" y="0.953723" width="34.0926" height="34.0926" filterUnits="userSpaceOnUse" color-interpolation-filters="sRGB">.<feFlood flood-opacity="0" result="BackgroundImageFix"/>.<feColorMatrix in="SourceAlpha" type="matrix" values="0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 127 0" result="hardAlpha"/>.<feOffset/>.<feGaussianBlur stdDeviation="0.523139"/>.<feComposite in2="hardAlpha" operator="out"/>.<feColorMatrix type="matrix" values="0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.15 0"/>.<feBlend mode="normal" in2="BackgroundImageFix
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1150
            Entropy (8bit):5.26003082358421
            Encrypted:false
            SSDEEP:24:t/l/uGCnYyK0EXFSYB0HtSpxx9xArHxl6zXTYpVT8+CHD6nQzBhEHA:TqYyEX9aHOzDYb8+cMUB+HA
            MD5:0D5C45AD1F5035D1A710E13A9C9A7CC1
            SHA1:9EF691A046A8DCF3F78A656241C888B97C47891B
            SHA-256:6F53A5391E57B58BED1BB243ED53C6B23B84DC9CD26C77E489794C8E9948DBB0
            SHA-512:E9AB1775E8BC9909C36CA5F143E6F46EC0D760D910C3A92BA3A98C143C63C8145AFC12A2AAD52A038E535F8F5877946081E50DF0AEB1579A9602B552BB234306
            Malicious:false
            Reputation:low
            Preview:<svg width="36" height="36" viewBox="0 0 36 36" fill="none" xmlns="http://www.w3.org/2000/svg">.<g filter="url(#filter0_d_12_8)">.<rect x="34" y="2" width="32" height="32" rx="2" transform="rotate(90 34 2)" fill="#EEEEEE"/>.</g>.<path d="M22.6994 17.35C23.1002 17.6669 23.1002 18.3331 22.6994 18.65L16.1193 23.8531C15.649 24.2249 15 23.848 15 23.2031L15 12.7969C15 12.152 15.649 11.7751 16.1193 12.1469L22.6994 17.35Z" fill="#909090"/>.<defs>.<filter id="filter0_d_12_8" x="0.953722" y="0.953722" width="34.0926" height="34.0926" filterUnits="userSpaceOnUse" color-interpolation-filters="sRGB">.<feFlood flood-opacity="0" result="BackgroundImageFix"/>.<feColorMatrix in="SourceAlpha" type="matrix" values="0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 127 0" result="hardAlpha"/>.<feOffset/>.<feGaussianBlur stdDeviation="0.523139"/>.<feComposite in2="hardAlpha" operator="out"/>.<feColorMatrix type="matrix" values="0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0.15 0"/>.<feBlend mode="normal" in2="BackgroundImageFix"
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):718
            Entropy (8bit):5.241044991619759
            Encrypted:false
            SSDEEP:12:TMbeIMu5E4BCihqWGRRH8YpPPHMaJ99+TlrWnN01wX8or7cQS0:qexnQqW8ppPPIdWN01A8wX
            MD5:3EA9067754C1DCABD8442D8A8AD42387
            SHA1:7BB000DC8270F5991C453A88C102D7B9BDF0A73A
            SHA-256:59FC31DEF87CA53CC7C290E261F9EF6C0B75BAF03A63A3F2405CB8EBF17D87AA
            SHA-512:A97CA8BC67EB321DC55649F8142A62DA1A15E8CC30FB9AB137E72C83FD98228995B3BFA58F57B8697BE174DDFD6E96CA08648F0DBE1C189F196472579B199D0E
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" standalone="no"?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"><svg t="1646824599365" class="icon" viewBox="0 0 1024 1024" version="1.1" xmlns="http://www.w3.org/2000/svg" p-id="7716" xmlns:xlink="http://www.w3.org/1999/xlink" width="200" height="200"><defs><style type="text/css"></style></defs><path d="M780.336 576.704l80.272 46.56L513.92 844.672 167.264 623.264l80.288-46.56-75.904-48.48L13.504 620 513.92 939.6 1014.4 619.984l-158.16-91.744-75.888 48.464zM1014.4 351.28L513.92 60.992 13.504 351.28 513.92 670.896 1014.4 351.28zM513.92 153.472L860.608 354.56 513.92 576 167.264 354.56 513.92 153.472z" fill="#2c2c2c" p-id="7717"></path></svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2244
            Entropy (8bit):4.142372758714232
            Encrypted:false
            SSDEEP:48:68RpLEV9lSRe5Mk7Szq/YsD4Ywu8LFO7CFHLuRcC:JSfNYR7LFe6rI/
            MD5:F58882EE59853112ED7B01FF91284F71
            SHA1:219C959121926C2A1A6CDE26E03B332B63D37C7C
            SHA-256:8C986D2CB6CF8B7975EDCD675141BB3C009FDDD70BD57D52B2A0601DB096CC1F
            SHA-512:82F1B4182C09AB059570CE3511C033CD4A81F4C14ED4180EB8D0667684A45876EFBC06E28994CD5F353D9F321E221801D8680FE43BC21CF68EFF4B695B55A18B
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M5.92009 10.2489C6.0542 10.4903 5.96725 10.7947 5.72586 10.9289L2.12609 12.929C2.05004 12.9747 2.01444 13.0139 2.00025 13.0342C2.01465 13.0548 2.05111 13.0949 2.1295 13.1415L9.34396 17.3224C9.50336 17.4167 9.74663 17.479 10.0183 17.479C10.29 17.479 10.5333 17.4167 10.6927 17.3224L10.6975 17.3195L17.8712 13.1843C17.9492 13.1378 17.9856 13.0979 18 13.0773C17.9857 13.0569 17.9498 13.0174 17.8729 12.9713L14.2896 10.9488C14.0492 10.813 13.9642 10.508 14.1 10.2676C14.2357 10.0271 14.5407 9.94217 14.7812 10.0779L18.3782 12.1082C18.7214 12.3112 19.0061 12.6432 19.0061 13.0773C19.0061 13.5114 18.7213 13.8433 18.3781 14.0463L18.3733 14.0492L11.1992 18.1847C10.849 18.3909 10.4195 18.479 10.0183 18.479C9.6169 18.479 9.18718 18.3908 8.83698 18.1844L1.62208 14.0032C1.27887 13.8002 0.994141 13.4683 0.994141 13.0342C0.994141 12.6001 1.27888 12.2682 1.62209 12
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):260
            Entropy (8bit):5.05824205502193
            Encrypted:false
            SSDEEP:6:tnrLJUGFcAumc4slvIEDAlLPVjjLtTF2Faqe69VylmqZR:trLJfDuCEYLtjjLhF2Rn4hR
            MD5:3361287AB7DBEDCA6A21FA85C5F2919D
            SHA1:D3C817864C22EF36494ACCF04D7F2B911D8FB5B3
            SHA-256:37D74601C409A37B64331FD3B218124BF45D814795FCBC8EC38C77D5E9464892
            SHA-512:CCDF626DEF6041D133E1F7001E2F9D233A4AC5BDE1076E0D79C26026CA642523F0ED567CB874BF64E017AC29C0A19F162FAC9BCE7626EF8E121ED6F0F69A7150
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M5 12L8.50024 7.6247C8.79242 7.25948 8.79204 6.74005 8.49986 6.37483C7.23348 4.79185 6.38744 3.73431 5 2" stroke="#909090" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):800
            Entropy (8bit):4.385817585733437
            Encrypted:false
            SSDEEP:24:tT1zuMWdTmKfKEcwJSkE1jeEgQekkQkfXWnzQHr+:v+dKKfKELofg4afXKG+
            MD5:49CB7C70BCD8EC17BC28FA2BFEC06C2A
            SHA1:65F28599C2D39D74B18DED7AA7911506AE2210D9
            SHA-256:8971FBF73F3DC15E3322C4A08CF7B57A7018A6AD1BC48C5D0B1C148ED4BB0334
            SHA-512:139DC5BE2984975226F9D505085454E8264B68564C40B985DF81655E0D8FEDBAAB807BA6D6227BEFFD6F6059453512EE3D4E87E81CD12D8B4E86D1D6065AD768
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M8.422 11.116L8.24 3.374H9.486L9.304 11.116H8.422ZM8.87 14.154C8.65533 14.154 8.46867 14.0747 8.31 13.916C8.16067 13.7573 8.086 13.5707 8.086 13.356C8.086 13.132 8.16067 12.9407 8.31 12.782C8.46867 12.6233 8.65533 12.544 8.87 12.544C9.094 12.544 9.28067 12.6233 9.43 12.782C9.58867 12.9407 9.668 13.132 9.668 13.356C9.668 13.5707 9.58867 13.7573 9.43 13.916C9.28067 14.0747 9.094 14.154 8.87 14.154Z" fill="#352F2D"/>.<path d="M9 15.5C5.41015 15.5 2.5 12.5899 2.5 9C2.5 5.41015 5.41015 2.5 9 2.5C12.5899 2.5 15.5 5.41015 15.5 9C15.5 12.5899 12.5899 15.5 9 15.5ZM9 17C13.4183 17 17 13.4183 17 9C17 4.58172 13.4183 1 9 1C4.58172 1 1 4.58172 1 9C1 13.4183 4.58172 17 9 17Z" fill="#D01B1B"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):851
            Entropy (8bit):4.399986853962383
            Encrypted:false
            SSDEEP:24:tT1zuCv4uk2HY4n/sqvCwotuqPAVi2E02vjmZxUSv+DKn:vCl2AqKwoMEZd0mCLtvJ
            MD5:EDB5BBB9FC934AD609A62CAD58EE784D
            SHA1:B3CEAE297361827B657048957A4E08C6EECBD8C4
            SHA-256:E38B47ED84B7A04ADEA63F9B719746DB84F1E3767EA8376FB4A5C759B36B997A
            SHA-512:600BE621F1595093DFE27B9F0DFA497F5E98CD08633B4773F0E033EBD1055B8774ACB92996864BB5A7B36AD0134903BC381D46D81361BCF4B973F1C30F581005
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M8.94694 4L16.0264 16.2619H1.86752L8.94694 4ZM9.81297 2.5C9.42807 1.83333 8.46581 1.83333 8.08091 2.5L0.135466 16.2619C-0.249434 16.9286 0.231692 17.7619 1.00149 17.7619H16.8924C17.6622 17.7619 18.1433 16.9286 17.7584 16.2619L9.81297 2.5Z" fill="#FF6F00"/>.<path d="M8.54394 13.1747L8.36194 5.43271H9.60794L9.42594 13.1747H8.54394ZM8.99194 16.2127C8.77727 16.2127 8.5906 16.1334 8.43194 15.9747C8.2826 15.816 8.20794 15.6294 8.20794 15.4147C8.20794 15.1907 8.2826 14.9994 8.43194 14.8407C8.5906 14.682 8.77727 14.6027 8.99194 14.6027C9.21594 14.6027 9.4026 14.682 9.55194 14.8407C9.7106 14.9994 9.78994 15.1907 9.78994 15.4147C9.78994 15.6294 9.7106 15.816 9.55194 15.9747C9.4026 16.1334 9.21594 16.2127 8.99194 16.2127Z" fill="#352F2D"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3335
            Entropy (8bit):4.053827091660919
            Encrypted:false
            SSDEEP:96:FnSaj8RF0YQtvb43alTS2HCsSkhnLS+ELOs8:FTgXQxbuCTSSCvkZS+B
            MD5:CD6333FDFCF77CA69F0C74D093BCC3C4
            SHA1:C96105F2B27E58E03C100BA604DAAB3EA2F4585E
            SHA-256:DE6B3BE74FF338450F6F0597BD06BF97C3FC5CF54F6E76420A78248C9D06480F
            SHA-512:CA0A9BBFB76B9B20F2A2C74F63EE9EA17D102449F89D305E9199F3FB8104059FB4E07BE9EAB96C8A261EB417976273DE4E7BEFE5AB92B210A471658B13B1D2DE
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="17" viewBox="0 0 18 17" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M9.44686 0.760658C9.44688 0.760632 9.44705 0.761358 9.44734 0.762916L9.44686 0.760658ZM9.45702 1.30902V16.0838L4.34788 12.5881C4.34553 12.5865 4.34262 12.5844 4.33918 12.582C4.30441 12.5576 4.21551 12.4952 4.10842 12.4621C4.00133 12.429 3.89274 12.4303 3.85027 12.4308C3.84606 12.4308 3.84251 12.4308 3.83966 12.4308H1.00002V5.46331H3.82577C3.8289 5.46331 3.83283 5.46336 3.83747 5.46342C3.88445 5.46403 4.00502 5.46559 4.12235 5.42522C4.23969 5.38484 4.33377 5.30941 4.37042 5.28003C4.37405 5.27712 4.37711 5.27466 4.37958 5.27274L9.45702 1.30902ZM9.44803 16.588C9.44801 16.588 9.44814 16.5873 9.44846 16.5859L9.44803 16.588ZM9.39368 0.114326C9.51273 0.0465355 9.77431 -0.0762185 10.064 0.0651441C10.3537 0.206507 10.4179 0.488235 10.4377 0.623795C10.4572 0.756805 10.4571 0.923 10.457 1.07685C10.457 1.08598 10.457 1.09506 10.457 1.1041V16.2734C10.457 1
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):956
            Entropy (8bit):4.991306446644244
            Encrypted:false
            SSDEEP:24:tQ6QKutxf9MMVbUpWJUVbSie9MMBLSie9MMM0tSie9MMVSie9MMREoch6BKqgerp:/I2WSYv0Hy0tl
            MD5:B02036B6072C599375D231713D49BB35
            SHA1:358C3A73E49B30BEFA6A07833EA7CC3145CE6309
            SHA-256:EF3D2274B6A67B318F9B4020B830FE7A436DB54676092DBD040D60956EC79D1A
            SHA-512:1267B6B42B92922594E740457A5B5A9242AFCB9E70DA5267DC17FEAED6B430BB832B81C74F9ED1F7145F936A9E9C61047D4231E20EFAE49862DEDD379B7311CD
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="60" height="60" fill="none"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M20 11.4C19.6686 11.4 19.4 11.6686 19.4 12V19.4H16.6V12C16.6 10.1222 18.1222 8.6 20 8.6H40C41.8778 8.6 43.4 10.1222 43.4 12V19.4H40.6V12C40.6 11.6686 40.3314 11.4 40 11.4H20Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M36.732 20.6V28.0667H33.932V20.6H36.732Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M31.4 14.6V28.0667H28.6V14.6H31.4Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M26.068 17.266V28.066H23.268V17.266H26.068Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M19.4 24.6V32C19.4 32.3314 19.6686 32.6 20 32.6H40C40.3314 32.6 40.6 32.3314 40.6 32V24.6H43.4V32C43.4 33.8778 41.8778 35.4 40 35.4H20C18.1223 35.4 16.6 33.8778 16.6 32V24.6H19.4Z" fill="#00AE42"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):956
            Entropy (8bit):5.042003659273436
            Encrypted:false
            SSDEEP:24:tQ6QKutxf9MMVbUpWJUVbl9MMBLl9MMM0tl9MMVl9MMREoch6BKqgerEp:/I2WSp00Vy0ty
            MD5:C0706BF0A13944DB67B0F0950ECB8B60
            SHA1:5B26C26867F0112BCA648D3D6FFFD21B7861708D
            SHA-256:742877525EA8E1CBC807347D3D123F85EE3720960F4F87A1F5D738714273E41C
            SHA-512:5C1F56483459CB14968DAC66B67AB164DAF8311E183B1DEC3D2D93C18F4F5919F1CA9B5DC1B442470B546D9E2FF585114563B07F23EF70520709DD091B2073E9
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="60" height="60" fill="none"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M20 11.4C19.6686 11.4 19.4 11.6686 19.4 12V19.4H16.6V12C16.6 10.1222 18.1222 8.6 20 8.6H40C41.8778 8.6 43.4 10.1222 43.4 12V19.4H40.6V12C40.6 11.6686 40.3314 11.4 40 11.4H20Z" fill="#C8EBD5"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M36.732 20.6V28.0667H33.932V20.6H36.732Z" fill="#C8EBD5"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M31.4 14.6V28.0667H28.6V14.6H31.4Z" fill="#C8EBD5"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M26.068 17.266V28.066H23.268V17.266H26.068Z" fill="#C8EBD5"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M19.4 24.6V32C19.4 32.3314 19.6686 32.6 20 32.6H40C40.3314 32.6 40.6 32.3314 40.6 32V24.6H43.4V32C43.4 33.8778 41.8778 35.4 40 35.4H20C18.1223 35.4 16.6 33.8778 16.6 32V24.6H19.4Z" fill="#C8EBD5"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):403
            Entropy (8bit):5.03228928691369
            Encrypted:false
            SSDEEP:12:trLJfDuCegJYTl4B84ht4zwpLJgTPB84hR:t3JfDu3Xl4rhtZiTPrhR
            MD5:8E30FAE4FFF6FA8D5449172506B68F2D
            SHA1:A60AABD30C5C0D00CE4F6BC57D4EC94019CE1EBC
            SHA-256:2900F854F7B286A466FCB9961C59A317D7DD929A8955C85DE40ADE6A3D2BF856
            SHA-512:42CE577BF9DFAC69B332420632723AFD9B5E883EC4114ECD1EEFB566250867A8402CCB314C3DAF91502AA8862158E786907A5F3709319BE62A69A46F78D30684
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M12 10L7.6 6.7C7.24444 6.43333 6.75507 6.4337 6.39952 6.70036C4.80281 7.89789 3.74331 8.69252 2 10" stroke="#F2F2F2" stroke-linecap="round"/>.<path d="M12 7L7.6 3.7C7.24444 3.43333 6.75507 3.4337 6.39952 3.70036C4.80281 4.89789 3.74331 5.69252 2 7" stroke="#F2F2F2" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1158
            Entropy (8bit):4.256754875453877
            Encrypted:false
            SSDEEP:24:t3JfDuF1qNaEGLjnMuTBuE5UikNcflN2afd+dKRmO5yDlbH2:3U3b35T0rkL2afEsmRZK
            MD5:6B3678D32FC5DD42C75869EA5B64A894
            SHA1:56256A15CE332F45C518B23D6641A40282B694ED
            SHA-256:3C3E3FE08D63A1D9A18114ED37A9E497A58B830209A1FBB5D5F8ADBDE7174BF8
            SHA-512:C256F27F9C06AC45E10A852C3B4082DBB7A3C78F240C3A8D96D451235C314D33314746279732F691E4CABCFD5DD4BBF2E9A107A9370CA584DF96FE3345944DC8
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M13.5 7C13.5 10.5899 10.5899 13.5 7 13.5C3.41015 13.5 0.5 10.5899 0.5 7C0.5 3.41015 3.41015 0.5 7 0.5C10.5899 0.5 13.5 3.41015 13.5 7Z" fill="#909090" stroke="#909090"/>.<path d="M7 11.5C6.44684 11.5 5.96085 11.396 5.54203 11.188C5.13111 10.972 4.81106 10.672 4.5819 10.288C4.36063 9.896 4.25 9.436 4.25 8.908V5.092C4.25 4.556 4.36063 4.096 4.5819 3.712C4.81106 3.328 5.13111 3.032 5.54203 2.824C5.96085 2.608 6.44684 2.5 7 2.5C7.56106 2.5 8.0431 2.608 8.44612 2.824C8.85704 3.032 9.17708 3.328 9.40625 3.712C9.63542 4.096 9.75 4.556 9.75 5.092H8.25647C8.25647 4.676 8.14583 4.36 7.92457 4.144C7.71121 3.928 7.40302 3.82 7 3.82C6.59698 3.82 6.28484 3.928 6.06358 4.144C5.84231 4.36 5.73168 4.672 5.73168 5.08V8.908C5.73168 9.316 5.84231 9.632 6.06358 9.856C6.28484 10.08 6.59698 10.192 7 10.192C7.40302 10.192 7.71121 10.08 7.92457 9.856C8.14583 9.632 8.25647 9.316 8.25647 8.908V8.02H6.78664V6.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):408
            Entropy (8bit):4.8348259990736935
            Encrypted:false
            SSDEEP:12:trLJfDuQojiHFnnCIn5ajn4PpCIn5ajn4Ps:t3JfDuQojInCI5ajn4PgI5ajn4Ps
            MD5:4A92950A9AE88D5810B4E15C3AF7A6B7
            SHA1:6F57D75E25B490947BC9A9545B183F18D2EF8C98
            SHA-256:3A601EA32FB2E0CB828A8484544E1FBD6BBF1FBDBE3E35306FF376555DBBF2D7
            SHA-512:0261625A05A8B11B4B15612787E8EAEA15D435F5911A78D5D9F5748F5123211231A760FEFEB0FF479AE6443D772AAADE9CEE752C9AF50581244C9C53FFA5EB40
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<circle cx="7" cy="7" r="6.5" fill="white" stroke="#909090"/>.<rect x="4.9013" y="3.96576" width="0.466667" height="6.06667" fill="#909090" stroke="#909090" stroke-width="0.466667"/>.<rect x="8.63372" y="3.96576" width="0.466667" height="6.06667" fill="#909090" stroke="#909090" stroke-width="0.466667"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):349
            Entropy (8bit):5.125747043182021
            Encrypted:false
            SSDEEP:6:tnrLJUGFcAumc4sl/NJ80YHDL2yl9jXDXITbXQ3kAHw6mqZtXITxO8OX4FkAHw6P:trLJfDu/fsjBXD4nQ3kAHFht4t9OskAN
            MD5:F9ABF084C8FF91C3AA5E2FD86E8CE7BA
            SHA1:9BC540E8AB8409BE53DFCE0BA4220E113CF2D880
            SHA-256:CAF4894C0EE88C3A3A672C5B7D525CA0B52661FEAB2814159C2583A091E40724
            SHA-512:D62597D9C1B5B4A24307D6E62E32D2F3C32B15AD9AD56C7BAAAFD0423D9241CA3A4627E31BD950EEBDBEDE19B04D756F61F2D0216DC93DDB666284718A021392
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<circle cx="7.12012" cy="7.12012" r="6.12012" fill="#909090" stroke="#F8F8F8"/>.<path d="M4.27734 4.27734L9.96031 9.96031" stroke="white" stroke-linecap="round"/>.<path d="M4.27734 9.96289L9.96031 4.27992" stroke="white" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):762
            Entropy (8bit):4.268990722211641
            Encrypted:false
            SSDEEP:12:trZvnltuCV/4QwH+PIYZLnVTQTZDPidAnOLbW3DfpIMGpFEG11uvzp0NmMKLR6js:tVvnjuI/4Q++wD2Z+FGdCp0MMQRO6O7e
            MD5:DCE6AB6D8E97F509C314B05B08BFCD22
            SHA1:BDA02BCDAC1019BC77BCEC26E43C5162B8D6CCFF
            SHA-256:064DEDDAE58E8E8D2215CEA0964FAC6BA39AD2C0375A12D90E5632E46C5A4F74
            SHA-512:5B481C221632B8F11D4D6D899BFCB01C80336A69CD1D0BBECCB5BB5656F73D8560F6E29DF66812A334411F750E1DDF4106F3D82381E465AF840994B76694DC25
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M6.90032 11.7091C7.96458 11.7091 8.946 11.3682 9.74897 10.8001L12.7697 13.7922C12.9099 13.9311 13.0947 14.0005 13.2923 14.0005C13.7065 14.0005 13.9996 13.6849 13.9996 13.2809C13.9996 13.0915 13.9359 12.9084 13.7957 12.7759L10.7941 9.79639C11.425 8.97576 11.801 7.95946 11.801 6.85478C11.801 4.1846 9.59602 2.00049 6.90032 2.00049C4.211 2.00049 1.99963 4.17829 1.99963 6.85478C1.99963 9.52495 4.20463 11.7091 6.90032 11.7091ZM6.90032 10.6612C4.7973 10.6612 3.05752 8.93789 3.05752 6.85478C3.05752 4.77166 4.7973 3.04836 6.90032 3.04836C9.00335 3.04836 10.7431 4.77166 10.7431 6.85478C10.7431 8.93789 9.00335 10.6612 6.90032 10.6612Z" fill="#898989"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):712
            Entropy (8bit):4.756446802014737
            Encrypted:false
            SSDEEP:12:trZvnltuXM65Jl3uCo8LEO8TD1J58Thg57NjKWwkCR29M65JmUhAcydCyGCDf4Sa:tVvnjuXMMJl3go1ogu7pKGCR29MMJmUH
            MD5:361C976093B61958F88B52A9A5231FCA
            SHA1:EF564C5E96EC46819F071D1EAF152A14610CE8BF
            SHA-256:596A0DECB760CD638153DA74AE19EB3A26DC715D070A6D3B2052D6281E13F5E9
            SHA-512:B4B25CF786FF8BB350CBE71D4CE2B456EA301FA5A25AC207F3B750363AA7C49D45CCD9FFE3EA70683592E05082EB5FE90112F2DB55C027F5DB48FA871EAC39CC
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.0735 3.92964C12.3078 4.16396 12.3078 4.54386 12.0735 4.77817L4.78208 12.0696C4.54776 12.3039 4.16786 12.3039 3.93355 12.0696C3.69923 11.8353 3.69923 11.4554 3.93355 11.2211L11.225 3.92964C11.4593 3.69533 11.8392 3.69533 12.0735 3.92964Z" fill="#AAAAAA"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.0743 12.0696C11.8399 12.3039 11.4601 12.3039 11.2257 12.0696L3.93432 4.77817C3.7 4.54386 3.7 4.16396 3.93432 3.92964C4.16863 3.69533 4.54853 3.69533 4.78285 3.92964L12.0743 11.2211C12.3086 11.4554 12.3086 11.8353 12.0743 12.0696Z" fill="#AAAAAA"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):403
            Entropy (8bit):5.033256294186426
            Encrypted:false
            SSDEEP:12:trLJfDuCPQUXa3LM1jVg4B84ht47Hh6TwtA2z1XB84hR:t3JfDuWQ/3LMlrhtY6TwtTzJrhR
            MD5:E88E4CFEBED233B089ACD3FD0A0C9A96
            SHA1:2BF127AE182B1D6EBCDE3758708920250E8A3166
            SHA-256:C9630CDC02450D81AECCB267725BA2BBE02C681C6E3C5967569B16C29F85E883
            SHA-512:4A5779D1F2203230FD393DAC09F8D76A5B9805C80DE5AA5A9393224EBDF59EB3C65B9103EF95AE885BA472672B2A54304CF17E02704B70F74240CE2DA817A2F6
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M2 4L6.4 7.3C6.75556 7.56667 7.24493 7.5663 7.60048 7.29964C9.19719 6.10211 10.2567 5.30748 12 4" stroke="#F2F2F2" stroke-linecap="round"/>.<path d="M2 7L6.4 10.3C6.75556 10.5667 7.24493 10.5663 7.60048 10.2996C9.19719 9.10211 10.2567 8.30748 12 7" stroke="#F2F2F2" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):1519
            Entropy (8bit):7.813923637838524
            Encrypted:false
            SSDEEP:24:iyMkzeuMG6mnB7drC7SNqjon1IyRl241KkshDTUM62pq1HHLW0+EvNXPY/XYliBq:iyMQ9bt7dWr0nqyH25hDIM68on3+4dYy
            MD5:AF473AF9FDF6E89D6EC4F520BCC921EE
            SHA1:E9FF543E7F88C14F0050B81E7037E6B1EB256578
            SHA-256:ED5C2B6921DB5D224A2FDA687BC200FD56FE77598929E0717300B4C40433333D
            SHA-512:51E5C9DCA58BD3C5D622A09325D364904AB7D8686E933D3C6CFA2875D1995F4E2C3C37EABFFB993DBCFF2F98BD954BDD621E220F29BE39D2B82D4CA4D1F286B7
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR...@...@......iq.....sRGB.........IDATx^.k.Te........e...!...~()5E..B.b.!....Z.M. .@.Y.4,..>Dje.IBJ).!V..!.F....f..9O..l.9.9.....<..y....{;.Q..r.)..Qj."S..>Wj.....Y...i.>%.|E..v.'..8....3X..~....r........`...HgHw...L...3.6-........<z3F....TEG....4....W..@&....2a.>D6`./nP_.C.../.".....p..V..r........".."N.....u.Ef.Nn.....@6.+p.@.<F.|.. ..\..RPK.u.R..s..2v.P...L.-.....}..8......zJ.%.|/j....4@6.L..=..O.B[.(....SY..BT.H1.!..}X.....,...J..(..F.x.^.s.......k..X.Q.v...cA..... m-o....y......D.Q....n:#.mX.......7=...e.....{.3.mx6".@..[VP6..P.CD.`..<e...P..z.CqSP...\.`%....'.l....E.Z..2.......5.4....l.....:.{-.~... ...i...1.l..DSE0.....q44LF...t..E...F........N...}..h..t;O.:.l.T.......m.i]...nV....C....wX..c....l.Yp.-b..;I..b.........+q.Y..I...KgH.../=SQ.4...... .rn.V.5wF...0d.be...,..S.O...0.........b....\=...Q.lM"......n0...N.X..9A...7..............9...o)..Ax...@i.^..... .|/......./->."N#%.]{....b.W.)...].^..UI..||..P.>F..t...Gq.q........
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):616463
            Entropy (8bit):4.970528953853135
            Encrypted:false
            SSDEEP:6144:LIRbIj+56HwOiGrB5tlcCxknbZ3M49aR7w:0RMj+5y5B5tOCxknbZ3M49aRc
            MD5:4436B2125E89456EE7C99B11EC7D31E3
            SHA1:0173164F9ECDD708176520379B8A60AA167BB06F
            SHA-256:E67AE067BFED88C9BC21AF7A7A8A38243D8509BAFC90109CBB60B5E4FC966B79
            SHA-512:C790D5B4DFAC7566C61699A9E87DEAF791C9398745312AB52D6A396A2E3BE31CE14D4D519169C898455442A1B187C546850F53A1C828761F86CF5F9793D221FF
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="UTF-8"?>.<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 360 400">. <g id="th">. <path d="M227.99,15.99c.87,0,1.74,.02,2.61,.06,1.18,.05,2.38,.14,3.56,.27,2.34,.25,4.69,.64,6.97,1.17,1.13,.26,2.28,.57,3.4,.9,1.11,.33,2.23,.7,3.32,1.1,2.18,.8,4.32,1.73,6.38,2.79,4.16,2.13,8.07,4.78,11.63,7.88,.88,.77,1.75,1.57,2.59,2.39,.83,.82,1.66,1.67,2.44,2.54,.78,.86,1.56,1.77,2.3,2.68,.74,.91,.92,1.38,1.61,2.33,2.66,3.69,5,7.77,6.95,12.11,.95,2.11,1.82,4.32,2.59,6.58,.38,1.11,.8,2.55,1.13,3.69,.33,1.13,.65,2.27,.94,3.43,.56,2.21,1.04,4.49,1.44,6.8,.39,2.26,1.35,11.59,1.45,13.97,.09,2.32,.31,5,.27,7.39l-.3,18.16c.07,.21,.14,.41,.18,.59,.14,.55,.21,1.13,.21,1.69,0,0-.04,.76-.11,1.1,.09,.03,.25,.1,.25,.1,.24,.12,.35,.27,.35,.46v1.36c.24,.12,2.27,1.21,2.27,1.21,0,0,0,0,0,0,.3,.16,.28,.3,.28,.55,0,0,0,.11,0,.11l4.45,2.37c.15,.08,.4,.23,.55,.33,0,0,.55,.43,.74,.72,.17,.27,.29,.57,.37,.93,.13,.6,.12,1.27,.1,1.86,0,0-.41,21.23-.41,21.23,0,0-.02,1.08-.11,1.62-.11,.65-
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):601637
            Entropy (8bit):5.032307368882294
            Encrypted:false
            SSDEEP:6144:roXCaLipk3esgybxv3lcUPkpFr3sitsTDW:UXfLips5xv3OUPkpFr3sitsTi
            MD5:081B063F462937CA179D04409A3D1EB2
            SHA1:677063F9A57BCB4F023859C766966DB9172421CC
            SHA-256:B3A986BF376CB0835728BA45F4FDDD581C6F5189A167AC9BFB0D917CF37B6FA1
            SHA-512:6F9F366A64397D94E3DF95A5CF857CEF6C86C1355CAE78435279A832F6C28C4EDD1E41CB11E6403681B81EEB1E2A9A4DD1EB5F6ADB14BF2A099B46F9E6ACD3B3
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="UTF-8"?>.<svg id="Layer_3" data-name="Layer 3" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 360 400">. <path d="M227.99,15.99c.87,0,1.74,.02,2.61,.06,1.18,.05,2.38,.14,3.56,.27,2.34,.25,4.69,.64,6.97,1.17,1.13,.26,2.28,.57,3.4,.9,1.11,.33,2.23,.7,3.32,1.1,2.18,.8,4.32,1.73,6.38,2.79,4.16,2.13,8.07,4.78,11.63,7.88,.88,.77,1.75,1.57,2.59,2.39,.83,.82,1.66,1.67,2.44,2.54,.78,.86,1.56,1.77,2.3,2.68,.74,.91,.92,1.38,1.61,2.33,2.66,3.69,5,7.77,6.95,12.11,.95,2.11,1.82,4.32,2.59,6.58,.38,1.11,.8,2.55,1.13,3.69,.33,1.13,.65,2.27,.94,3.43,.55,2.21,1.04,4.49,1.44,6.8,.39,2.26,1.35,11.59,1.45,13.97,.09,2.32,.31,5,.27,7.39l-.3,18.16c.07,.21,.14,.41,.18,.59,.14,.55,.21,1.13,.21,1.69,0,0-.04,.76-.11,1.1,.09,.03,.25,.1,.25,.1,.24,.12,.35,.27,.35,.46v1.36c.24,.12,2.27,1.21,2.27,1.21,0,0,0,0,0,0,.3,.16,.28,.3,.28,.55,0,0,0,.11,0,.11l4.45,2.37c.15,.08,.4,.23,.55,.33,0,0,.55,.43,.74,.72,.17,.27,.29,.57,.37,.93,.13,.6,.12,1.27,.1,1.86,0,0-.41,21.23-.41,21.23,0,0-.02,1.08-
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):124530
            Entropy (8bit):4.081063404872996
            Encrypted:false
            SSDEEP:1536:L/8HKxpUmtZ5VIpXGdMXrI3H0CUt7v9xYBk2H1BvEYaEd7KjA4nfBoWI:BDv
            MD5:13782643B66C36CB1D7FBACF485C1EAD
            SHA1:51BC8A7019848FF883197D4F64BFD517A9C2E405
            SHA-256:916131B24AE9BBF55FA25C9A3A8986C2FFEFB65423FA9018C6751BE8349E246B
            SHA-512:5F2B4EE915A8432B0A6BDEA2C149EA00A5914E3E48EF3BB4E71BAED43F2BBABA945FAD6C1B810BDC49508759B5D27E34694819238A43D72D712591686387B111
            Malicious:false
            Reputation:low
            Preview:<svg width="160" height="160" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M76.707 81.022c-1.76-.235-2.88-.55-4.48-.942M72.228 148.768v-68.61M87.508 110.615c0 .078.16.235.4.235.16.079.4.079.56.157.16 0 .4.079.64.079h.8c.24 0 .56-.079.8-.079.24-.078.4-.078.56-.235M86.226 146.807c0-.157.24-.235.4-.314.16-.078.32-.078.64-.157M82.067 79.371l-5.36 1.649M81.349 148.611v1.02M82.227 148.531l-.16-69.16M62.868 55.979l3.04-.471M87.906 63.2l-.16-.235M114.944 57.158v1.492M113.187 57.39v1.492M110.704 57.94l.08 1.571M108.945 58.254v1.492M85.589 134.794v-4.003M133.663 47.422h.16M104.387 52.447l-4.159-.55M104.385 53.547h-.64M70.068 84.631l-.08-10.676M75.026 32.664l2.56-.392M71.83 33.214l2.159-.392M69.828 111.246h.24M76.07 34.002l.32-.08M94.706 40.28v1.255M94.548 39.416l-.08 2.669M93.507 40.28v.08M93.507 34.077c0 .078.16.235.24.235.16.079.24.079.4.079.16 0 .32-.079.32-.157M93.745 34.782l.32.08M69.828 124.982l.24-.08M70.066 133.619v-3.297M92.145 34.94v-.235M91.505 34.627h.32M101.587 38.867v-2.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):124749
            Entropy (8bit):4.08778382124307
            Encrypted:false
            SSDEEP:1536:L/8HxxpUmS727IpXGdMXRI3H0CUt7v9xYBMuH1FvM0aEeyKjA4nfBzWW:2fU
            MD5:FEFB229368FC54EB4CF4226A12F1794B
            SHA1:47A32066D3A611AC981C1B971CDB9D4FF17AC88B
            SHA-256:19C0D5E3EF5D38616A9EE5D0A40D0F42F4DB764E348AC67148CC6F194EE39952
            SHA-512:96E67B49202A1468857A05DC42673EAE4300DBB3BBB6B6A480B1B7714A447D30A5C62F59A0373EB45B91F03B4702165AFF5AC1B5829141666BDF124439125598
            Malicious:false
            Reputation:low
            Preview:<svg width="160" height="160" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M76.707 81.022c-1.76-.235-2.88-.55-4.48-.942M72.228 148.768v-68.61M87.508 110.615c0 .078.16.235.4.235.16.079.4.079.56.157.16 0 .4.079.64.079h.8c.24 0 .56-.079.8-.079.24-.078.4-.078.56-.235M86.226 146.807c0-.157.24-.235.4-.314.16-.078.32-.078.64-.157M82.067 79.371l-5.36 1.649M81.349 148.611v1.02M82.227 148.531l-.16-69.16M62.868 55.979l3.04-.471M87.906 63.2l-.16-.235M114.944 57.158v1.492M113.187 57.39v1.492M110.704 57.94l.08 1.571M108.945 58.254v1.492M85.589 134.794v-4.003M133.663 47.422h.16M104.387 52.447l-4.159-.55M104.385 53.547h-.64M70.068 84.631l-.08-10.676M75.026 32.664l2.56-.392M71.83 33.214l2.159-.392M69.828 111.246h.24M76.07 34.002l.32-.08M94.706 40.28v1.255M94.548 39.416l-.08 2.669M93.507 40.28v.08M93.507 34.077c0 .078.16.235.24.235.16.079.24.079.4.079.16 0 .32-.079.32-.157M93.745 34.782l.32.08M69.828 124.982l.24-.08M70.066 133.619v-3.297M92.145 34.94v-.235M91.505 34.627h.32M101.587 38.867v-2.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):144651
            Entropy (8bit):3.7475507953057576
            Encrypted:false
            SSDEEP:1536:IRFdw4i9NzlT4r6tzrNLCyI6c8x1q/4DTpz/ZND2Trp790kmbYnFgO3Re:dxBttvPiE
            MD5:CC68B41B33619BB9F8B9D62C35945FF8
            SHA1:BB8B2854F616B3364B4D59D45A6F13FBC170936A
            SHA-256:DEB3C9E490D1F4A7A81B70E1AF66DDB494883EE476A76B2C561974F009B84AC3
            SHA-512:B47F59A278B57AB498D45FA05AC3D8C03C9435D7AEFEB8082B45D15CAADFF1422632E1890B84431D52901BE2BDD6A91FFDB73832D10DB107CEFA9DB2C7620368
            Malicious:false
            Reputation:low
            Preview:<svg width="219" height="210" viewBox="0 0 219 210" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M74.3796 17.24L107.28 15.89C107.28 15.89 115.74 15.39 123.69 15.89C131.64 16.39 209.52 22.33 209.52 22.33L209.59 190.61V191.28H208.72L208.89 193.18H207.1L207.21 194.52H198.61L198.39 193.57L122.7 197.84V199.33H109.88V197.78L21.0796 194.9V195.83L10.9696 195.61V194.35L9.10965 194.32V192.6L8.38965 192.57L8.97965 20.86C8.97965 20.86 9.36965 20.41 11.0196 20.38C12.6696 20.35 14.0196 20.32 14.0196 20.32C14.0196 20.32 15.0396 17.89 16.1496 17.83C17.2596 17.77 48.9296 16.14 48.9296 16.14C48.9296 16.14 49.6396 15.95 50.7996 16.2C51.9596 16.45 53.7596 18.2 53.7596 18.2L64.3096 17.75L64.3697 16.59H62.5696L62.5096 15.11H74.4797L74.3896 17.25L74.3796 17.24Z" stroke="#050101" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M102.201 103.34L99.1008 103.37H98.9608C98.9608 103.37 98.9608 103.37 98.9508 103.37L96.7708 103.39C96.4808 103.39 96.2008 103.48 95.9308 103.65C95
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):139040
            Entropy (8bit):3.7562834432065126
            Encrypted:false
            SSDEEP:1536:bNaxLtD8j8LRxlzvWXnki9RwdSYImEDCdRjaD0+1QFUPT:SLRxlzvjTm
            MD5:5940C594E87D3155171BE08B8AD29EA0
            SHA1:F4DC335E32D8635B10336257A50E29001E49E0A9
            SHA-256:D0163511617C8BA7AB2E949A8C95A7D91AE3424B8474310DAAB04F283FBD6E42
            SHA-512:21116DD8E603995C1ADC0537648F56407E0403B385B4E0B1D155E27BF0C957C86BA1204900753B054DE37919FE893537F83377CF372D4A8ED8DE8BEE959418A3
            Malicious:false
            Reputation:low
            Preview:<svg width="219" height="210" viewBox="0 0 219 210" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M74.49 14.65L107.39 13.3C107.39 13.3 115.85 12.8 123.8 13.3C131.75 13.8 209.63 19.74 209.63 19.74L209.7 188.02V188.69H208.83L209 190.59H207.21L207.32 191.93H198.72L198.5 190.98L122.81 195.25V196.74H109.99V195.19L21.19 192.31V193.24L11.08 193.02V191.76L9.22 191.73V190.01L8.5 189.98L9.09 18.27C9.09 18.27 9.48 17.82 11.13 17.79C12.78 17.76 14.13 17.73 14.13 17.73C14.13 17.73 15.15 15.3 16.26 15.24C17.37 15.18 49.04 13.55 49.04 13.55C49.04 13.55 49.75 13.36 50.91 13.61C52.07 13.86 53.87 15.61 53.87 15.61L64.42 15.16L64.48 14H62.68L62.62 12.52H74.59L74.5 14.66L74.49 14.65Z" stroke="white" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>.<path d="M102.05 100.7L98.9504 100.73H98.8104C98.8104 100.73 98.8104 100.73 98.8004 100.73L96.6204 100.75C96.3304 100.75 96.0504 100.84 95.7804 101.01C95.5404 101.17 95.3204 101.39 95.1504 101.66C94.8304 102.15 94.6504 102.78 94.6504
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1846
            Entropy (8bit):4.4039818269609325
            Encrypted:false
            SSDEEP:48:rn9bJoSH0yT2zN6+30s1TR+hHgzQGx4gb98XdP:pmEpT2zN6+3DFKHgUG+gJ8XF
            MD5:A99D7CB7CE969BA8F024B4C5FA6072B9
            SHA1:C928FFDF9A21FA5F6F738522FBFB7AD4935F350D
            SHA-256:BF7AF9AB0FB070689AADEFEA41F9C36F27DA22AA710A182BB73689CD40F5043A
            SHA-512:E98501591B91655BB2FDCB2D64BE96F91F09D9EF121CBB6417234E9D999CB9E255BD5237DB63C5F65E19BCECE09BD4A0D1B16F11AA5C673984B12FBB617869EC
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M5.90353 2.57688L1.92959 6.25754H10.6119L14.5719 2.57688H5.90353ZM5.24348 1.7204C5.36414 1.60451 5.54925 1.5 5.77594 1.5H15.2009C15.6319 1.5 15.8847 1.81966 15.9642 2.09032C16.043 2.35847 16.0033 2.71966 15.7281 2.97248L11.2568 7.12831C11.0773 7.30059 10.8624 7.33441 10.7241 7.33441H1.29907C0.868108 7.33441 0.615342 7.01475 0.535805 6.7441C0.456962 6.4758 0.496745 6.11437 0.772377 5.86154L5.24348 1.7204Z" fill="#6B6B6B"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M13.6022 5.77281C13.6022 5.47544 13.8432 5.23438 14.1406 5.23438H15.2009C15.6319 5.23438 15.8847 5.55403 15.9642 5.82469C16.043 6.09298 16.0033 6.45439 15.7277 6.70722L11.2565 10.8484C11.1358 10.9643 10.9507 11.0688 10.7241 11.0688H1.29907C0.868108 11.0688 0.615342 10.7491 0.535805 10.4785C0.457061 10.2105 0.496646 9.84966 0.771342 9.59686L1.5795 8.842C1.79681 8.63901 2.13754 8
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):460
            Entropy (8bit):4.834379895329066
            Encrypted:false
            SSDEEP:12:trZvnltuCFPFu1FTDSRv6jHcht4GOdlipLBPMFy4:tVvnju4ATORv6jHchtbylilRMFy4
            MD5:491269951927518B7DAACDB3236A1AF0
            SHA1:51BB328722EAB66E859CA1EA8BC921503F5EF3DF
            SHA-256:830D7A61652161DDC3FCA91526F4F4F0EEFC9F941BF28C941DCC9FDC18BBD22B
            SHA-512:EC9A376F88C32504484A274F2C6032465DA748624FD51E2CE3F76C1311ADC3A10EED549C080F3A8C1E02D734F21D275DE251394D72096180E5B4C5158E1BBAF9
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M4 5C4 5 4 5 4 4C4 3 5 2 6 2C7 2 9 2 10 2C12 2 12 4 12 5V6C12 7 11 8 10 8C9 8 9 8 9 8C9 8 10 8 9 8C8 8 7 9 7 10C7 11 7 11 7 11" stroke="#73CA94" stroke-width="2" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M7 15C7.55228 15 8 14.5523 8 14C8 13.4477 7.55228 13 7 13C6.44772 13 6 13.4477 6 14C6 14.5523 6.44772 15 7 15Z" fill="#73CA94"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):205
            Entropy (8bit):4.877822298391742
            Encrypted:false
            SSDEEP:3:tRBRNqcwR+8IZDmJS4RKb5i0qlTY5qvWExXWKqRJfHCKKOA9kqFF+GRoumukq2WY:tnrZfmc4sliy5qOKgRRCKq93iQm5QY
            MD5:1ACB91F1C8E57AE94EE16D6B54DC009A
            SHA1:245F8AA52CA5122B726029DDE368384CF46ACC41
            SHA-256:272B94B87DCD6C3D283377EF770B979C50829441DDDCC8C518626CB6CC91F29A
            SHA-512:4C1C363483B16053643C1AB9E4A475C78CE2553A0B53EE9B1941D40DF64900D5537C99067A9CA8C9A836BF0EAA8AC3284C9C2138D4D8829CD9BE41DF123A3E45
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" xmlns="http://www.w3.org/2000/svg" fill="none">.. <g>. <title>Layer 1</title>. <rect id="svg_1" stroke="#ACACAC" rx="7.5" height="15" width="15" y="0.5" x="0.5"/>. </g>.</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):253
            Entropy (8bit):4.790721792622558
            Encrypted:false
            SSDEEP:6:tnrfB3mc4sliy5qOKgRRCbSlg4nAEzn0CAIA9AHq2cgbpY:trfFIoqOznCbSe4n9z0CnAiHq8b6
            MD5:C63E9524CD8806456F73A104095280D8
            SHA1:A72F40E37C5940F28B3E8896B347077FAE69E4A3
            SHA-256:CF4272C53F7693E56B3A58B04C84A43DA8EAF88AE96BAE45FF22F58E84F6B0FA
            SHA-512:77D4C6A8D29C037B4C00A7CA1CEE98AF3C3F83D643F191A98AFA13426B0F7F39F6913340F4B8AFB12BD442CEBFD0CE869AE12C6920C36EB6DA29DB0E51D7D036
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" xmlns="http://www.w3.org/2000/svg" fill="none">.. <g>. <title>Layer 1</title>. <rect id="svg_1" fill="#00AE42" rx="8" height="16" width="16" y="1" x="1"/>. <circle id="svg_2" fill="white" r="3" cy="9" cx="9"/>. </g>.</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2260
            Entropy (8bit):4.578120891673023
            Encrypted:false
            SSDEEP:48:Lcqfp3fUBeZq26zKUZUf6fwPvj9fZcKJ7PoToGc5P8gyncm:LZZf82KBiPvjrJ3z5kfncm
            MD5:C9291EE4C5ACE41D0319CBE673294311
            SHA1:4DF9D06D85A18270496DBD405FA7F48A94489B40
            SHA-256:AB4BBF49F4CD8736671E3D3C0258702391CAFF7697EE5A7B7B2A4A88EA7EE806
            SHA-512:F1DE166FA3703D214A3CF4508A6F76DFDFF2758DAE79D695EC559A6F80E2F9447C8078AA8170E325780B049113A51878D5B26C92C1CAEC5F84B2AF2DBB6811A3
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" standalone="no"?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"><svg t="1647872792667" class="icon" viewBox="0 0 1024 1024" version="1.1" xmlns="http://www.w3.org/2000/svg" p-id="1714" xmlns:xlink="http://www.w3.org/1999/xlink" width="200" height="200"><defs><style type="text/css"></style></defs><path d="M480 64C214.912 64 0 278.912 0 544s214.912 480 480 480c265.088 0 480-214.912 480-480S745.088 64 480 64z m271.584 640c8.576-40.448 13.984-83.392 15.744-128h127.456a411.712 411.712 0 0 1-30.688 128h-112.512zM208.416 384a763.36 763.36 0 0 0-15.744 128H65.216c3.328-44.192 13.632-87.104 30.688-128h112.512z m477.632 0c9.6 40.96 15.392 83.84 17.28 128H512v-128h174.048zM512 320V132.672c14.592 4.256 29.056 11.36 43.232 21.376 26.592 18.752 52 47.616 73.536 83.488 14.88 24.8 27.744 52.416 38.496 82.496H512z m-180.768-82.496c21.536-35.872 46.944-64.736 73.536-83.488A145.824 145.824 0 0 1 448 132.64v187.328H292.736c10.752-30.08
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):150
            Entropy (8bit):4.820515438981104
            Encrypted:false
            SSDEEP:3:tRBRNqL3s+pKcvTnq7SLvDmJS4RKb58ZSFuHqVLQpCRLQBZt+QAHKbUv:tnra3tB+umc4slvI3dBZt9AHKb2
            MD5:1772F61C9A40A7E63B35119AADD1DC32
            SHA1:BF4AA38FF0FE35D342276DD6D35121754A8D3865
            SHA-256:4408F0567BF80C25A95001A91F8DD6C2C9F50AD9F59CDE7276F5ADAF5572086B
            SHA-512:3272A51340286819C3F4C291429002F6A33D6D7F6FBB9907A5D7822B3C78C929139AECB9A80810B37B45B8A527A97ED173A3461D3C568DE767B753A7E9D6B150
            Malicious:false
            Reputation:low
            Preview:<svg width="6" height="5" viewBox="0 0 6 5" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M6 0.5L3 4.5L0 0.5L6 0.5Z" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):150
            Entropy (8bit):4.848001792690532
            Encrypted:false
            SSDEEP:3:tRBRNq7R+rpFcvQpFQK7SLvDmJS4RKb58ZSFuHK+zRkFNSb+QAHKbUv:tnrcorpqQpSKumc4slvID+A9AHKb2
            MD5:D020229310C75CC143905F789A6C1C5E
            SHA1:A1B8BBC45BB91A0BA9605E9107F86D6545B01516
            SHA-256:17DD757487543341E25C633CD14C60D85F28504D1BD30B24AD46377A6123EA98
            SHA-512:0FAB793228AA887ECC4A300D4739A3F6626F83E37212F3A203EC4A2DE0DEDD6A74BBD4E25D53A46EBCCAE6C7FE1EB65348C4BA75C643787BBE73779B1B82480D
            Malicious:false
            Reputation:low
            Preview:<svg width="5" height="6" viewBox="0 0 5 6" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M4.5 6L0.5 3L4.5 0L4.5 6Z" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):146
            Entropy (8bit):4.845660407548074
            Encrypted:false
            SSDEEP:3:tRBRNq7R+rpFcvQpFQK7SLvDmJS4RKb58ZSFuH2Qxh+zV/H6A+QAHKbUv:tnrcorpqQpSKumc4slvI3xhMVaA9AHKS
            MD5:9BB3DE2DB01E50567F454AC43084ED82
            SHA1:4F0B452320133F559C84DF4A77C079CE171BAD5C
            SHA-256:AE75A354E69F1526B4CBA7679E000C8C42DF231DB4A78FFD7017D2C3D0292DD4
            SHA-512:63CB6B31310BCAED7D4844421C62B67F5B9480602889B0A088E817FED6E1BA499DEC3A03195CBE21F4EBBAB8426F7739D116248C89CA404A45E2FF287AA07415
            Malicious:false
            Reputation:low
            Preview:<svg width="5" height="6" viewBox="0 0 5 6" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M0.5 0L4.5 3L0.5 6V0Z" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1713
            Entropy (8bit):5.023552918449118
            Encrypted:false
            SSDEEP:48:39eGtuDWuXUAjumFuvrrtu9N6lHu0pE97p0uHDiesuDjuYv:BEJjWGCpExpya5
            MD5:646057E5758FA918A09DB2BD55C2AEDE
            SHA1:AFB264CBEFE563FC8D3A6AE5F23A26278AD9A29B
            SHA-256:2ABD0C4CDF426FCBDFC137AEEABAD89CAFBA9397D93E107EBF380A3C0E3E9E80
            SHA-512:D8657AB2CCC9DB30004E385A4293560354336280E22DDFBD58C31DC65DC008D339D66E5F8F31036B9AA421E20BB3FC9DFA73723FEC40C50390F06BDCF7AC4897
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">..<path d="M8.14355 5.89721L12.9999 1" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10" stroke-linecap="round"/>..<path d="M5.73841 5.83622L1.09058 1.14844" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10" stroke-linecap="round"/>..<path d="M8.2522 8.26758L12.9009 12.9554" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10" stroke-linecap="round"/>..<path d="M5.72763 8.23242L1 13.0007" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10" stroke-linecap="round"/>..<path d="M12.2411 5.77274C12.3662 5.89897 12.2768 6.11357 12.099 6.11357H8.1303C8.01984 6.11357 7.9303 6.02402 7.9303 5.91357V1.91149C7.9303 1.73291 8.14656 1.64386 8.27231 1.77067L12.2411 5.77274Z" fill="#ACACAC" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10"/>..<path d="M1.70302 5.77275C1.57786 5.89899 1.66728 6.11357 1.84505 6.11357H5.81295C5.92341 6.11357 6.01295 6.02402 6.01295 5.9135
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):746
            Entropy (8bit):5.3774365299269045
            Encrypted:false
            SSDEEP:12:TMHdPYi/nzVk/KYf3nnlcWYlajPjhlHJkCTLiMzRCPjhlllH1O:2dgAOLf3nTY8jPjhlHJkQLiKMPjhlllE
            MD5:7B1F55FB0BF8E5A87F39518398F3CB4D
            SHA1:A05A0275C131AFF7B0D2F2F8505BAAF8B3F6E444
            SHA-256:8072C1809DAD4DA9553AC16BC4F73008BCC9FA7F70DCC05CC02404657B324870
            SHA-512:39DBEF998C6400CAA9EDE80150961BBD10ACD42D43A4D9EE790D51B4B246C69C3304E2B79335FF106F49C6E30A406A68358A933E3F5D6B13FE216E2095279CE5
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="utf-8"?>. Generator: Adobe Illustrator 23.0.3, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->.<svg version="1.0" id="Layer_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px".. viewBox="0 0 16 16" enable-background="new 0 0 16 16" xml:space="preserve">.<g id="undo">..<path fill="none" stroke="#ED6B21" stroke-width="2" stroke-linecap="round" stroke-miterlimit="10" d="M3,11...c0.91,1.78,2.76,3,4.89,3c3.04,0,5.5-2.46,5.5-5.5c0-3.04-2.46-5.5-5.5-5.5c-0.17,0-0.34,0.01-0.5,0.03"/>.....<polygon fill="#ED6B21" stroke="#ED6B21" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" stroke-miterlimit="10" points="...7.39,1 7.39,5 4.39,3 ."/>.</g>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):779
            Entropy (8bit):4.375085724243706
            Encrypted:false
            SSDEEP:24:tVvnjuKDJqdiWGHHFObbYVcWcodHzzZW9nLaKjHPGFufs:rn7Dgdd8wbbYVcWcolYlaKrGFu0
            MD5:1343503DFB63271B53140AB0E8CB3B0B
            SHA1:86789CA1B8A585761BD22FC983E8BA01028433A3
            SHA-256:22272CD4C0B2E8CB7E19F16A09CB7C150B7A426E036C0067CDE787DE3842E0FE
            SHA-512:15B84A2C139AE837E2CA73078B7A8C7A38992C948F7DF57793E1B4D3318AAEBFF9A371DB4C7B61C3EAB30E2671ECB8AB8FAA6B15A0E7293FB67AAD303EEBAF2A
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M13.7398 5.84619L10.1538 2.26016C9.98676 2.09311 9.76084 2 9.52533 2H2.88864C2.39708 2 2 2.39845 2 2.88864V13.1114C2 13.6029 2.39845 14 2.88864 14H13.1114C13.6029 14 14 13.6016 14 13.1114V6.47467C14 6.23916 13.9055 6.01324 13.7398 5.84619ZM4.88909 2.88864H7.55637V4.44409H4.88909V2.88864ZM11.1109 13.1114H4.88909V11.1109H11.1109V13.1114ZM13.1114 13.1114H12.0009V10.6673C12.0009 10.4222 11.8024 10.2223 11.5559 10.2223H4.44409C4.19899 10.2223 3.99909 10.4208 3.99909 10.6673V13.1114H2.88864V2.88864H3.99909V4.88909C3.99909 5.13419 4.19763 5.33409 4.44409 5.33409H8C8.24509 5.33409 8.445 5.13555 8.445 4.88909V2.88864H9.52533L13.1114 6.47467V13.1114Z" fill="#262E30"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):790
            Entropy (8bit):4.348080547265844
            Encrypted:false
            SSDEEP:24:t4lfXyuxn9RO+E5PMPDNMKy1fmeE3DGqf2xRYrna4Awn:2T1E5PyBqODGqf2xRY73
            MD5:548EE0328194784D49304634ED9A2EC9
            SHA1:F294206DE9BAD56FCC6E7A24B421B1AC5066A484
            SHA-256:5F98B9E37BA1017A1F1B825DB5EF8EB352DBA64E2EEB22C9E023A5F9D1917053
            SHA-512:51920C8A75CA6A47741E5F0D69371D15CBC70237B1775160053B948AF82490B21EA555A439AA7F803852EB144D005E59C46EE0E954420516507E80B6AAD3D409
            Malicious:false
            Reputation:low
            Preview:<svg width="28" height="27" viewBox="0 0 28 27" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M11.9888 2.01601C12.8984 0.494662 15.1024 0.494662 16.012 2.01601L18.8677 6.79237C19.1958 7.34113 19.7339 7.73201 20.3572 7.87447L25.7821 9.11446C27.5101 9.50943 28.1913 11.6056 27.0254 12.9408L23.3652 17.1327C22.9449 17.6143 22.7394 18.2469 22.7964 18.8836L23.2936 24.4263C23.4519 26.1918 21.6687 27.4873 20.0386 26.7911L14.9209 24.6056C14.3329 24.3545 13.6679 24.3545 13.0799 24.6056L7.96209 26.7911C6.33196 27.4873 4.54887 26.1918 4.70722 24.4263L5.20434 18.8836C5.26145 18.2469 5.05595 17.6143 4.63544 17.1327L0.97533 12.9408C-0.19048 11.6056 0.490599 9.50943 2.21859 9.11446L7.64364 7.87447C8.2669 7.73201 8.80494 7.34113 9.13302 6.79237L11.9888 2.01601Z" fill="#DDDDDD"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):793
            Entropy (8bit):4.343962491268984
            Encrypted:false
            SSDEEP:24:t4lfXyuxn9RO+E5PM1yMKy1fmenl0f2xRYSnQU4AT/n:2T1E5PZql0f2xRYGQMP
            MD5:53D70D78827D1816E8E6F497D325EA53
            SHA1:347BAC64F68DFA1C53BBF05D9A5F9BD94D37584E
            SHA-256:DD05526AD6191011C7DF21FAFC52A8C75D2687C59BFA0604C1B8F6ECF408716E
            SHA-512:3EBDD55861B75379CBA383CF002C14565FBD5239F0E83D73380B14B542D87B2EFEFF4CC9E473E8135EBF639CAE6CC9E372C566A896565A64D7C389B6BF9FF9E6
            Malicious:false
            Reputation:low
            Preview:<svg width="28" height="27" viewBox="0 0 28 27" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M11.9888 2.01601C12.8984 0.494662 15.1024 0.494662 16.012 2.01601L18.8677 6.79237C19.1958 7.34113 19.7339 7.73201 20.3572 7.87447L25.7821 9.11446C27.5101 9.50943 28.1913 11.6056 27.0254 12.9408L23.3653 17.1328C22.9449 17.6143 22.7394 18.2469 22.7964 18.8836L23.2936 24.4263C23.4519 26.1918 21.6688 27.4873 20.0386 26.7911L14.9209 24.6056C14.3329 24.3545 13.6679 24.3545 13.0799 24.6056L7.96209 26.7911C6.33196 27.4873 4.54888 26.1918 4.70722 24.4263L5.20434 18.8836C5.26145 18.2469 5.05595 17.6143 4.63545 17.1328L0.975334 12.9408C-0.190476 11.6056 0.490603 9.50943 2.21859 9.11446L7.64364 7.87447C8.26691 7.73201 8.80494 7.34113 9.13303 6.79237L11.9888 2.01601Z" fill="#FEC90D"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2642
            Entropy (8bit):4.533884425229839
            Encrypted:false
            SSDEEP:48:bETEuiPUM3T7MMUFQkAPom5g7wNcOPJuVWWtTyocHO4VSvLmj:oIUM3fMF/e+CcMuAzPu4VL
            MD5:77F849CE3A15F1F60B107ED93B88B698
            SHA1:F2A4E014333B5243339F2E62F8F5BBEA5ADB0824
            SHA-256:B47477088F62C4A8096A271FDDE31DC745B8E8B603C15D5F54E8A72138AA366A
            SHA-512:5D5F4D4489A104EBBD3618005BE796B798007817AC8293965C0416E12425078312AEF159E7E1C18F1816EEA35F47982FDB83F476932B5A0A96F90AC811E2F717
            Malicious:false
            Reputation:low
            Preview:<svg width="39" height="22" viewBox="0 0 39 22" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M28.9658 17.795V4.20532C28.9658 3.7635 28.6076 3.40533 28.1658 3.40533H15.6069C15.4073 3.40533 15.2149 3.47995 15.0675 3.61454L11.1051 7.23238C10.9391 7.38395 10.8445 7.59837 10.8445 7.82316V17.795C10.8445 18.2369 11.2027 18.595 11.6445 18.595H28.1658C28.6076 18.595 28.9658 18.2368 28.9658 17.795ZM30.1658 4.20532V17.795C30.1658 18.8996 29.2704 19.795 28.1658 19.795H11.6445C10.54 19.795 9.64453 18.8996 9.64453 17.795V7.82316C9.64453 7.26118 9.88097 6.72512 10.296 6.34619L14.2584 2.72835C14.6269 2.39188 15.1079 2.20533 15.6069 2.20533L28.1658 2.20532C29.2704 2.20532 30.1658 3.10076 30.1658 4.20532Z" fill="#54545A"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M13.043 14.5764V16.5409H16.8299V14.5764H13.043ZM12.043 16.5409C12.043 17.0932 12.4907 17.5409 13.043 17.5409H16.8299C17.3821 17.5409 17.8299 17.0932 17.8299 16.5409V14.5764C17.8299 14.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2940
            Entropy (8bit):4.467738495111454
            Encrypted:false
            SSDEEP:48:bUBjPoPl0pxkeimnv7C/HYaVek75RSyvO57V/cJwQjcfJwcH3Aho6dT:AZMl0pxtimzjTQSyvipcJwQjanXAnT
            MD5:CCC103B4AD0A650F079B210BEF6A2E84
            SHA1:67080FBB2523E302457DE67D463519D9CE255B15
            SHA-256:F9528795C4A23D438B5B79821BB9BF90E86AF39962ABE8E0D682C815F127B0E0
            SHA-512:62915131DC32D39B8CE3F406F38899EAD31D7F97D9776D75349B06644D72EDBB05AC2198D7D14641E456D46CC76AA5D3A37EC5D698E88FCFE0071174A3DB00D5
            Malicious:false
            Reputation:low
            Preview:<svg width="39" height="22" viewBox="0 0 39 22" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M28.9658 17.7949L28.9658 4.20525C28.9658 3.76343 28.6076 3.40526 28.1658 3.40526L15.6069 3.40526C15.4073 3.40526 15.2149 3.47988 15.0675 3.61447L11.1051 7.23231C10.9391 7.38388 10.8445 7.5983 10.8445 7.82309L10.8445 17.7949C10.8445 18.2368 11.2027 18.5949 11.6445 18.5949L28.1658 18.5949C28.6076 18.5949 28.9658 18.2367 28.9658 17.7949ZM30.1658 4.20525L30.1658 17.7949C30.1658 18.8995 29.2704 19.7949 28.1658 19.7949L11.6445 19.7949C10.54 19.7949 9.64453 18.8995 9.64453 17.7949L9.64453 7.82309C9.64453 7.26111 9.88097 6.72505 10.296 6.34612L14.2584 2.72828C14.6269 2.39181 15.1079 2.20526 15.6069 2.20526L28.1658 2.20525C29.2704 2.20525 30.1658 3.10069 30.1658 4.20525Z" fill="#ACACAC"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M13.043 14.5765L13.043 16.541L16.8299 16.541L16.8299 14.5765L13.043 14.5765ZM12.043 16.541C12.043 17.0933 12.4907 17.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2995
            Entropy (8bit):4.526940103285653
            Encrypted:false
            SSDEEP:48:UP+Rx+bmgTYQM23vrtLx3Ch7mf0GQuh5QPp5ia/6t+5KlcxBTe1d:FRTgYQMSVMNmNvg57/6t+5KyxBTy
            MD5:50734212358DEC083F72158D1969FD07
            SHA1:FDEBDABD6CCE49E02723CE70A2F668A5F1AC4798
            SHA-256:7B9650DC2D745C607E004DC1530320F2A39C07193CD588EAEFFE3D0D405378BC
            SHA-512:964EC06131421E90AC5892719BD37188FC9AE53B090FACB7D56C3186EA8DEC4F064462BC923FE066958828E0FC0066E51BD7C915BCA3116AE08F5E18832EEDD1
            Malicious:false
            Reputation:low
            Preview:<svg width="38" height="22" viewBox="0 0 38 22" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M28.0605 17.7948V4.20508C28.0605 3.76326 27.7024 3.40508 27.2605 3.40508H14.7017C14.502 3.40508 14.3096 3.47971 14.1622 3.6143L10.1998 7.23213C10.0338 7.38371 9.93926 7.59813 9.93926 7.82292V17.7948C9.93926 18.2366 10.2974 18.5948 10.7393 18.5948H27.2605C27.7024 18.5948 28.0605 18.2366 28.0605 17.7948ZM29.2605 4.20508V17.7948C29.2605 18.8993 28.3651 19.7948 27.2605 19.7948H10.7393C9.63469 19.7948 8.73926 18.8993 8.73926 17.7948V7.82292C8.73926 7.26094 8.9757 6.72488 9.39072 6.34595L13.3531 2.72811C13.7216 2.39164 14.2026 2.20508 14.7017 2.20508H27.2605C28.3651 2.20508 29.2605 3.10052 29.2605 4.20508Z" fill="#54545A"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.1396 14.5764V16.5409H15.9265V14.5764H12.1396ZM11.1396 16.5409C11.1396 17.0932 11.5874 17.5409 12.1396 17.5409H15.9265C16.4788 17.5409 16.9265 17.0932 16.9265 16.5409V14.5764C16
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3310
            Entropy (8bit):4.462524532548527
            Encrypted:false
            SSDEEP:96:Vi2vGfglE8mPt1fYHyhBTVzg/6t+5KyjBTU:VzvgUk1VXRzA6gpjBTU
            MD5:45B69C73E663CDD43D06505E5881A22E
            SHA1:D3E192C9D494002CBE99378538F7427F34B7DB17
            SHA-256:954901EF7006DD2DE3EEF5B7C1139D2C5185B0F0CBE04C3A8C8B891085DA3595
            SHA-512:5A2008350778B03522F4728900B42A25BA4E4B1E0A8F798DC10F980B8CF82777282950869828DC8B6FC37EFCDCF05C1BBF548D48B013A41A311AFB1ED747BEFA
            Malicious:false
            Reputation:low
            Preview:<svg width="38" height="22" viewBox="0 0 38 22" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M28.0605 17.7949L28.0605 4.20519C28.0605 3.76337 27.7024 3.40519 27.2605 3.40519L14.7017 3.40519C14.502 3.40519 14.3096 3.47982 14.1622 3.61441L10.1998 7.23224C10.0338 7.38382 9.93926 7.59824 9.93926 7.82303L9.93926 17.7949C9.93926 18.2367 10.2974 18.5949 10.7393 18.5949L27.2605 18.5949C27.7024 18.5949 28.0605 18.2367 28.0605 17.7949ZM29.2605 4.20519L29.2605 17.7949C29.2605 18.8994 28.3651 19.7949 27.2605 19.7949L10.7393 19.7949C9.63469 19.7949 8.73926 18.8994 8.73926 17.7949L8.73926 7.82303C8.73926 7.26105 8.9757 6.72499 9.39072 6.34606L13.3531 2.72822C13.7216 2.39175 14.2026 2.20519 14.7017 2.20519L27.2605 2.20519C28.3651 2.20519 29.2605 3.10063 29.2605 4.20519Z" fill="#ACACAC"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.1396 14.5765L12.1396 16.541L15.9265 16.541L15.9265 14.5765L12.1396 14.5765ZM11.1396 16.541C11.1396 17.0933 11.5
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3083
            Entropy (8bit):4.429171881041048
            Encrypted:false
            SSDEEP:96:gnWidnu0TMeeXRUgamgWCpp7ZUVYmEe/YeKGuu:CsXRUgn2r7ZUVYy/Yq
            MD5:B71F4FD26ADC2DDEC656697C2A8E7924
            SHA1:5EC6ACC23612CF5D2137F30DEF6762EBBDD15BA1
            SHA-256:CD4E6CE60FEE09FA10870BCD3134EC74F402BA37C48D07D4638CF5ED24581FC8
            SHA-512:3F8A7A85901C70442C545523A054566FD300CA9772909EB097528FB88D1D1777B94662FB3293525960BF3E1C0D703B38BE83C6F8131855F2D4CF389A31EE3E56
            Malicious:false
            Reputation:low
            Preview:<svg width="39" height="23" viewBox="0 0 39 23" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M28.9669 17.8339L28.9669 4.24423C28.9669 3.8024 28.6087 3.44423 28.1669 3.44423L15.608 3.44423C15.4084 3.44423 15.216 3.51885 15.0686 3.65344L11.1062 7.27128C10.9402 7.42285 10.8456 7.63727 10.8456 7.86207L10.8456 17.8339C10.8456 18.2757 11.2038 18.6339 11.6456 18.6339L28.1669 18.6339C28.6087 18.6339 28.9669 18.2757 28.9669 17.8339ZM30.1669 4.24423L30.1669 17.8339C30.1669 18.9385 29.2715 19.8339 28.1669 19.8339L11.6456 19.8339C10.541 19.8339 9.64561 18.9385 9.64561 17.8339L9.64561 7.86207C9.64561 7.30008 9.88205 6.76403 10.2971 6.3851L14.2595 2.76726C14.628 2.43078 15.109 2.24423 15.608 2.24423L28.1669 2.24423C29.2715 2.24423 30.1669 3.13966 30.1669 4.24423Z" fill="#323A3E"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M13.0459 14.6155L13.0459 16.58L16.8328 16.58L16.8328 14.6155L13.0459 14.6155ZM12.0459 16.58C12.0459 17.1323 12.4936 17.58
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2749
            Entropy (8bit):4.517503428506628
            Encrypted:false
            SSDEEP:48:8FT3kmRbMX35hzLcDtsm3GByPcqzwnThQ5ZDYyheLIBY1EfZuCaA5i+cN8VGFYKu:c31RbY/X+UyPP0ntW5MJOnaAdcNPeKGb
            MD5:EBFABB722693796C9E5C9F899F50CCD5
            SHA1:C794535852FB3E92534F4EAFA440B130EAE3DF71
            SHA-256:A9D0415C0CD805ED324CD57FB3A2C8314EFCDBEF5DD8EBCDFBC3196E78D710CE
            SHA-512:A27AA77DEFAB51FE78E596A2352ED7E8A8674472101DBF7FA596226DC430DF361C48F58ACDE518662E1DC3BA5E86E595ABCF9435768C034C1FC506CA712BF95E
            Malicious:false
            Reputation:low
            Preview:<svg width="39" height="23" viewBox="0 0 39 23" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M28.9668 17.8338V4.24414C28.9668 3.80231 28.6086 3.44414 28.1668 3.44414H15.6079C15.4083 3.44414 15.2159 3.51876 15.0685 3.65335L11.1061 7.27119C10.9401 7.42276 10.8455 7.63718 10.8455 7.86198V17.8338C10.8455 18.2756 11.2037 18.6338 11.6455 18.6338H28.1668C28.6086 18.6338 28.9668 18.2756 28.9668 17.8338ZM30.1668 4.24414V17.8338C30.1668 18.9384 29.2714 19.8338 28.1668 19.8338H11.6455C10.5409 19.8338 9.64551 18.9384 9.64551 17.8338V7.86198C9.64551 7.29999 9.88195 6.76394 10.297 6.38501L14.2594 2.76717C14.6279 2.43069 15.1089 2.24414 15.6079 2.24414H28.1668C29.2714 2.24414 30.1668 3.13957 30.1668 4.24414Z" fill="#B3B3B5"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M13.0459 14.6155V16.58H16.8328V14.6155H13.0459ZM12.0459 16.58C12.0459 17.1323 12.4936 17.58 13.0459 17.58H16.8328C17.385 17.58 17.8328 17.1323 17.8328 16.58V14.6155C17.8328 14.06
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):377
            Entropy (8bit):5.1174514409495
            Encrypted:false
            SSDEEP:6:tnrZvUYltumc4slcrQO6OCrQ69DwWowmcmLyUJapRq9DwWoAG86tvnLq9AHKbiA/:trZvnltutJQ6OjLyJYOlLqiHAie
            MD5:5D75229A638F4190C83D733E504E8764
            SHA1:1909F346CF994F3035813EB1B547B77C17FA2856
            SHA-256:96C314F7973E2F1F23EAAE24D2F919A6F9591E0BEE74AAF23AED5712DEC25E06
            SHA-512:9ABF5579F3F5B7F6DBB01EBCF8F40D66E3CE585E73AE1A410639135B0AB1936CDA27B02E4C724415835D3863E6676472E94516893DB4C17B12C923B1C2F6BA1F
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_2225_21739)">.<circle cx="6.5" cy="6.5" r="5" stroke="#262E30"/>.<line x1="10.8272" y1="10.9101" x2="15.564" y2="15.647" stroke="#262E30"/>.</g>.<defs>.<clipPath id="clip0_2225_21739">.<rect width="16" height="16" fill="white"/>.</clipPath>.</defs>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):923
            Entropy (8bit):6.759040131828666
            Encrypted:false
            SSDEEP:12:6v/7SY/6Ts/gmVnOVGMlkycc/bwKVgSPa1LPaX9TmmfIBIDcMsmF4I7:W/6DmVOsMlky1DwKiSPQiRTQI4Mse
            MD5:2B7B72CFE381B4754F769B3D2C381336
            SHA1:9B2DBF42854C00AB6A3CD8E14224489CECB6B72D
            SHA-256:F85792AF60882BCE6809DFB9B6E208FCBB378A8189AA143963956BE5291127EE
            SHA-512:C6D4841C274BD36219930B2A431BD43051D20609025D25C39BCE8051E0B2F2AD57CAB518A61A29E1EE65CC9FF11E9F86201C33C9CC6446F0A9FFCB492F7A4D57
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR..............>a.....pHYs.................sRGB.........gAMA......a....0IDATx...N.@.....H,.K.J66.........[a.ll.[Y...)....r"H.....-8iH..wgc..F.Q/....:...tZ.E...r..l\.e.L&...]UU..~....->..p8........o..@o...`...........x....6..........ae..?K.UP..#......7...v.~...:.v.........g'X......[.^.y..7..4.|..........:......1...Q3...p.....U/..9.............wu...)`/.j...v......O.....'|\y.e.................................................................................................................................................................................................................................................\9...AHy.e...b9.L...........]VUu.u.S.}....EQ....._.....N.._A(i...........t..".:.<./n.moo."....b3..".|>H...`.m....o...............|.+V}r8.V.&.Y:...^....u.1..zOOO'.j.8hc...|....U|..y7H_r.n...m.|c...^...\.Z.o}..\..b..)....n.R.t3....z.y.s...[....m..........IEND.B`.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):224
            Entropy (8bit):5.052713256960151
            Encrypted:false
            SSDEEP:3:tRBRNqFVZO+bTBcvX/ruA7SLvDmJS4RKb58ZSF4qQJ9rKB5KWUVoFtp4IdUDRGXj:tnr0PbCKAumc4slvtM65tKpDRV/L+
            MD5:4D921BFA3ECF2C9251EE25571D7492BE
            SHA1:AE70CEA64D9873AE3A4B104D13E4D6DE615245F1
            SHA-256:25309C9BC9E2A3A3715DD5705DA4EAFB1691F29E4887D7B0BA8A3512D5FE1579
            SHA-512:00C956A2AB67C6BE9982D88724E4D6D3AF16C6F1D8605CB8B350F44ACB491BEFABBF21D96B5CC669A431889BD8E4E1B9D898C028645A2EF06AABD3791DE231DA
            Malicious:false
            Reputation:low
            Preview:<svg width="200" height="484" viewBox="0 0 200 484" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M92 430.95L92 53L99.56 53L99.56 430.95L92 430.95Z" fill="#2B3436"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):169
            Entropy (8bit):4.87086560292527
            Encrypted:false
            SSDEEP:3:tRBRNqcwR+8XcvUJUTlt7SLvDmJS4RKb58ZQGuMnccwR+8DGR+eCrVCqbv0/v:tnrZvUYltumc4sl7anLq28l4n
            MD5:8354F3E67AB395C140EADCCA859F6F06
            SHA1:F934270E76D22BAE3626E5427EF943E5CF9DBFA1
            SHA-256:F296887DDEC7B84B8E4A7329425383F2E965AD926C40C8805F0DD369C2540416
            SHA-512:B262DA627B86095BD4F198E72BCE3DEAD702624B6B49A86804BA2A41341FE62C6174A996CA96DA87DBB544A02723125258DCCA9C1E16749588D1BBCBC715B424
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="16" height="16" fill="#C4C4C4" fill-opacity="0.01"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):4017
            Entropy (8bit):3.921484973780987
            Encrypted:false
            SSDEEP:96:DvSs9aXmbpABG8oqwm3ONjU4jJ92kH8p9S+DRKto8mzW8:tsml6GzYOe4H2A82oPW8
            MD5:5D55EEAFBE106169AC6D4AB034F775EC
            SHA1:B049482E8EF269C635A25EA5B1FEC7BA3B393C4E
            SHA-256:D3E2DCF88E7EAD2D14E233042D353C21A27BD12D213DAADB4B4DF44629C075FF
            SHA-512:DC08E905F893147232F3A8FC4F36FB95D6A5404E294F983008566786B27C6BD86C4C58246BE18DFFBBA33C049D3E3507BCE903944231C3FF48394BBCC91F53FE
            Malicious:false
            Reputation:low
            Preview:<svg width="13" height="13" viewBox="0 0 13 13" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M8.64416 0.0460923C9.40312 0.325341 10.1279 0.743368 10.7596 1.35304L10.7642 1.35751L10.7687 1.36213C10.8511 1.44734 10.9164 1.55445 10.9509 1.67142C10.9823 1.77755 10.996 1.92131 10.9375 2.0651C10.7651 2.61567 10.837 3.19845 11.1199 3.67232L11.1228 3.67711L11.1255 3.68198C11.4205 4.2112 11.8449 4.53241 12.3618 4.63795L12.3875 4.6432L12.4123 4.65199C12.6234 4.72701 12.8514 4.91193 12.8727 5.22281C12.9609 5.639 13 6.09568 13 6.50084C13 6.92104 12.958 7.34344 12.8672 7.80414L12.8629 7.82587L12.8561 7.84695C12.7827 8.07459 12.6342 8.23892 12.4589 8.32951L12.4236 8.34771L12.3854 8.35813C11.8277 8.51021 11.3726 8.84627 11.1305 9.3105L11.1265 9.31816C10.8427 9.83312 10.8004 10.3923 10.948 10.9706C11.0071 11.1822 10.9835 11.5124 10.721 11.6832C10.0936 12.2317 9.38676 12.6382 8.64669 12.9541L8.62946 12.9615L8.61158 12.9671C8.48719 13.0061 8.35108 13.0
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):251
            Entropy (8bit):5.048619297433678
            Encrypted:false
            SSDEEP:6:tnrLJUGFcAumc4slvIDTLlFVPjq5lWow6kAHw6mqZR:trLJfDuCJFVPjq59FkAHFhR
            MD5:51ED77511CAB3DA4814EE87460D6CD31
            SHA1:4E14845C6B75F99044B1D9F067BAD27BC6733091
            SHA-256:9D257EBC06C548323AB10406A67524BCE8A4C3ACF8541097292F98A615580201
            SHA-512:DBF83926C8631BCEB5C6721BA63EBB9D860299015CCA3A80BC061DD150D0F5D0E516BF5A890BA59DDC934D1D750EA924FEE3F633456F182BF4615DDAFF8044B7
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M3 6L6.4 8.55C6.75556 8.81667 7.24477 8.81642 7.60032 8.54976C8.81191 7.64107 9.64946 7.0129 11 6" stroke="white" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1390
            Entropy (8bit):4.582073113307883
            Encrypted:false
            SSDEEP:24:tYU/du7ysuy9MMvkyx3lHQibjE9MMhadvckdRahwnUD9MMaLXfZU7n:n/eysflwimaddRU9szfe7n
            MD5:36AA2A106D2583C254D2FA580A6EF727
            SHA1:4E8BE7F5B30B5439AAEAC2991F2A6D2A7CAE2907
            SHA-256:F2C6BF20D9FF4A730F5D4D67396AF0616C2DFED66D67DC1860756BA2B67BD95D
            SHA-512:98ACCB3DB4BAEB83A0BF52F2AC1B26B81B6DCB8B760CA838AE27C93BD1A6F60B8184D5C3EF97F30433BA47AB6F09D2D55B1E35F10085D05C5C2FD59FD39E2661
            Malicious:false
            Reputation:low
            Preview:<svg width="24" height="24" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M4 6C4 5.44772 4.44772 5 5 5H19C19.5523 5 20 5.44772 20 6V18C20 18.5523 19.5523 19 19 19H5C4.44772 19 4 18.5523 4 18V6Z" fill="#595959"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.5 6C3.5 5.17157 4.17157 4.5 5 4.5H19C19.8284 4.5 20.5 5.17157 20.5 6V18C20.5 18.8284 19.8284 19.5 19 19.5H5C4.17157 19.5 3.5 18.8284 3.5 18V6ZM5 5.5C4.72386 5.5 4.5 5.72386 4.5 6V18C4.5 18.2761 4.72386 18.5 5 18.5H19C19.2761 18.5 19.5 18.2761 19.5 18V6C19.5 5.72386 19.2761 5.5 19 5.5H5Z" fill="#353535"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M13.7306 10.7569L13.6702 10.839L10.785 15.3585L9.11563 12.7417C9.08006 12.686 9.03769 12.6355 8.98968 12.5916L8.91359 12.5306C8.60675 12.3169 8.20115 12.3785 7.96379 12.6596L7.90343 12.7417L5.62234 16.3167C5.54257 16.4418 5.5 16.5887 5.5 16.7389C5.5 17.1269 5.77789 17.4471 6.13706 17.4941L6.22844 17.5H17.7715C17.9153 17.5 18.0559 17.4555 18.1755 17
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1459
            Entropy (8bit):4.665363100030937
            Encrypted:false
            SSDEEP:24:tYU/du7ysuqbt9MMvkyx3lHQibqJ9MMhadvckdRahwnqJ9MMaLXfZqt:n/eysNlwi8addRUIzf6
            MD5:3C9004B1EFD2EE864C1F51CD938AB69D
            SHA1:F05D5736E09E97DFE0D57577A83E3C003AD7E028
            SHA-256:96B19BE7D8D238F89F4FCF88F7E437BDC760664FAA35636D02CEAC7EAA382573
            SHA-512:AA8849B594F05AA1625803436F9703FC40083C6BFB0DD7479EA6E3F2DCF1FA8800BEC642417B6CF5B92EB73B802B05CD1513510634CE5B90F153B46F4ADC2BBD
            Malicious:false
            Reputation:low
            Preview:<svg width="24" height="24" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M4 6C4 5.44772 4.44772 5 5 5H19C19.5523 5 20 5.44772 20 6V18C20 18.5523 19.5523 19 19 19H5C4.44772 19 4 18.5523 4 18V6Z" fill="white" fill-opacity="0.24"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.5 6C3.5 5.17157 4.17157 4.5 5 4.5H19C19.8284 4.5 20.5 5.17157 20.5 6V18C20.5 18.8284 19.8284 19.5 19 19.5H5C4.17157 19.5 3.5 18.8284 3.5 18V6ZM5 5.5C4.72386 5.5 4.5 5.72386 4.5 6V18C4.5 18.2761 4.72386 18.5 5 18.5H19C19.2761 18.5 19.5 18.2761 19.5 18V6C19.5 5.72386 19.2761 5.5 19 5.5H5Z" fill="white" fill-opacity="0.4"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M13.7306 10.7569L13.6702 10.839L10.785 15.3585L9.11563 12.7417C9.08006 12.686 9.03769 12.6355 8.98968 12.5916L8.91359 12.5306C8.60675 12.3169 8.20115 12.3785 7.96379 12.6596L7.90343 12.7417L5.62234 16.3167C5.54257 16.4418 5.5 16.5887 5.5 16.7389C5.5 17.1269 5.77789 17.4471 6.13706 17.4941L6.22844 17.5H17.7715C17.9
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):164
            Entropy (8bit):5.0734627925794475
            Encrypted:false
            SSDEEP:3:tRBRNqFFKN+pKcvdqH5MHq7SLvDmJS4RKb58ZSFuHsbzlWMOA9kcO1RFAmYHZZv:tnrw9BwH5MKumc4slvIgzM49Vw4mqZR
            MD5:F77EBB5B236098FB555EC0D5DF7CAC20
            SHA1:4C9F55F857A6BE5BA830402B374D267FD61B3C9A
            SHA-256:D1CE6E72A3F6AEDC6ADE9E9C60F06654BC242652CCEBC9261BA50CB6FF35CD7D
            SHA-512:C9FF697C37D2CCB23CD7E359F33FF00EC7CA82F6F1EF66023D6917D7826ED008FA401101F2A0757C08FEB81C1E4DFA1B802AE62510EAFD1A677DD652B759552E
            Malicious:false
            Reputation:low
            Preview:<svg width="8" height="5" viewBox="0 0 8 5" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M1 1L4 4L7 1" stroke="#A9A9A9" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):164
            Entropy (8bit):5.0734627925794475
            Encrypted:false
            SSDEEP:3:tRBRNqFFKN+pKcvdqH5MHq7SLvDmJS4RKb58ZSFuHFopglQVA9kcO1RFAmYHZZv:tnrw9BwH5MKumc4slvIFop69Vw4mqZR
            MD5:60D0DE0ED16E767163C825A497B45ABD
            SHA1:E473E539D6003F8319C0A1698B956D9BD8E2ED3A
            SHA-256:29E505CCEA3646C514BFFF8970F76E3DBB8BB1D3AA2D1A8CB0D05759AC87A776
            SHA-512:AC10E073667765130A378C7259F28D152BA41B928A74A49CADCB97A9A8BADF14FF9179FC5F0BE0AA7239F090AA2CA68B6DC20B5E88532E312647876DE8DD2618
            Malicious:false
            Reputation:low
            Preview:<svg width="8" height="5" viewBox="0 0 8 5" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M7 4L4 1L1 4" stroke="#A9A9A9" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):381
            Entropy (8bit):5.1034575877050585
            Encrypted:false
            SSDEEP:6:tnrDZcwumc4slvI/Axgc5GpjQA9HFQKSieXIiKg1tKSieXIfkwG05RSieXIZ+iMj:trDZpuC4xg0Av9HFtSie4mSSie4fe0DK
            MD5:1878026A157B8AED65682A1AA4412BCC
            SHA1:15BF4DFC779C86018F87C18A90919C6B2D317791
            SHA-256:2258EB3B56D03EED9C067A5D6AC73FC9237D18C847B966F90E0C59D292996B03
            SHA-512:14D970BC1FFE3D398CC64ED52AC0535BE4F0B453F730FF6C99384395CAD5C7C8051442E3BD0607BC8F4D6C762667CF51EA1B7D136A20E848DE7FB7B6EEFC0B73
            Malicious:false
            Reputation:low
            Preview:<svg width="94" height="122" viewBox="0 0 94 122" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M50.3856 45.5508V122H94V62.6627L50.3856 45.5508Z" fill="#00AE42"/>.<path d="M50.3856 0V38.2419L94 55.3884V0H50.3856Z" fill="#00AE42"/>.<path d="M0 76.4838V0H43.6143V59.3373L0 76.4838Z" fill="#00AE42"/>.<path d="M0 122V83.7927L43.6143 66.6462V122H0Z" fill="#00AE42"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1387
            Entropy (8bit):4.5872190745046595
            Encrypted:false
            SSDEEP:24:tKnguXMMm35AWkRU4Na6CDbRru0A2RDIzmcGxq9MMqJsERXtIEqlnjYWSie9MMjo:gi35AWkRBNtCH5s2RDKGLJsypqljYraX
            MD5:64E0A369214F5D16F907273EF7EEDF81
            SHA1:86BB5A418FF4EA6A51CFDB916D0B81BAF9179407
            SHA-256:D44B9A700A03414E565C708E200EE707A3BD3A6F683E8F62E444899BB89E9A2F
            SHA-512:55986482FFEC73C0C6CB4E50CBFCC81A105F17D3ECA5F8C262D30D9EDCB7A07EBCE73E701ACA01D9F0267604843D4029F5757CD69ACAED29A6C1F7D324D0DA5B
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.5 3.5C4.5 3.22386 4.72386 3 5 3H24.4325C24.5652 3 24.6924 3.05271 24.7861 3.14654L28.5011 6.86338C28.5948 6.95714 28.6475 7.08428 28.6475 7.21684V9.06239C28.6475 9.33853 28.4236 9.56239 28.1475 9.56239H11.4439V31.9596C11.4439 32.2358 11.2201 32.4596 10.9439 32.4596H5C4.72386 32.4596 4.5 32.2358 4.5 31.9596V3.5ZM5.5 4V31.4596H10.4439V9.06239C10.4439 8.78624 10.6678 8.56239 10.9439 8.56239H27.6475V7.42388L24.2253 4H5.5Z" fill="#2B3436"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.4438 9.0625C10.4438 8.78636 10.6677 8.5625 10.9438 8.5625H30.7653C30.9017 8.5625 31.0322 8.61824 31.1265 8.71679L34.4525 12.192C34.5416 12.2851 34.5913 12.4089 34.5913 12.5377V37.5222C34.5913 37.7983 34.3675 38.0222 34.0913 38.0222H10.9438C10.6677 38.0222 10.4438 37.7983 10.4438 37.5222V9.0625ZM11.4438 9.5625V37.0222H33.5913V12.7384L30.5517 9.5625H11.4438Z"
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1349
            Entropy (8bit):4.611063642380927
            Encrypted:false
            SSDEEP:24:tKT8FuXMMpTAjbFToY1I66QWbCrkXrS7iBMWMLbmTjA9MM8ZWTkkXtITTF4L/m4D:a8OQbJoYv6Q6W4mWBXyIzZWTk5WLes5J
            MD5:7A27F811862FD2A7136EA84CD4B7CCA9
            SHA1:A0FA3A3B90E62FFFA7FAC8D4CA90AC47D399CE8E
            SHA-256:206B06122D85797ECD207BF28B508DF02EE64295F37F234168ED403B1ABD15AB
            SHA-512:48A5FAFB61E03F5478EAD4C34684B10839D2CEF0B0752D789FCB35E05F7CCEFDB07B3FA1ACAE518B5EB155E63A3AE73D77BC146EBD04D773F81A8D1A9DF1F2B1
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.5 3C4.5 2.72386 4.72386 2.5 5 2.5H24.4325C24.5652 2.5 24.6924 2.55271 24.7861 2.64654L28.5011 6.36338C28.5948 6.45714 28.6475 6.58428 28.6475 6.71684V8.56239C28.6475 8.83853 28.4236 9.06239 28.1475 9.06239H11.4439V31.4596C11.4439 31.7358 11.2201 31.9596 10.9439 31.9596H5C4.72386 31.9596 4.5 31.7358 4.5 31.4596V3ZM5.5 3.5V30.9596H10.4439V8.56239C10.4439 8.28624 10.6678 8.06239 10.9439 8.06239H27.6475V6.92388L24.2253 3.5H5.5Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.4438 8.5625C10.4438 8.28636 10.6677 8.0625 10.9438 8.0625H30.7653C30.9017 8.0625 31.0322 8.11824 31.1265 8.21679L34.4525 11.692C34.5416 11.7851 34.5913 11.9089 34.5913 12.0377V37.0222C34.5913 37.2983 34.3675 37.5222 34.0913 37.5222H10.9438C10.6677 37.5222 10.4438 37.2983 10.4438 37.0222V8.5625ZM11.4438 9.0625V36.5222H33.5913V12.2384L30.5517 9.0625H11.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1356
            Entropy (8bit):4.72648997674461
            Encrypted:false
            SSDEEP:24:tKnguXMMm35AWkRU4Na6CDbRru0A2RDIzmcGxq9MMqJsERXtIEqlnjYWSie9MMad:gi35AWkRBNtCH5s2RDKGLJsypqljYo+c
            MD5:8D6C0771F0C563C5A8E246C68FAE30B1
            SHA1:7F7EB04680C03CD276C547ECC2FF083F8032C432
            SHA-256:8A63A6A76821D830850756666501979075A9310660020E31A8C126E00C6BA6BA
            SHA-512:1EF7AE9C71B803E4383DB826F23C9DF1554896574F6F5E94BB1860999ABF2803A2D17A423E6EDBC4BA3CB2C40247C9635546632DDC8FFB8880386354929A635A
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.5 3.5C4.5 3.22386 4.72386 3 5 3H24.4325C24.5652 3 24.6924 3.05271 24.7861 3.14654L28.5011 6.86338C28.5948 6.95714 28.6475 7.08428 28.6475 7.21684V9.06239C28.6475 9.33853 28.4236 9.56239 28.1475 9.56239H11.4439V31.9596C11.4439 32.2358 11.2201 32.4596 10.9439 32.4596H5C4.72386 32.4596 4.5 32.2358 4.5 31.9596V3.5ZM5.5 4V31.4596H10.4439V9.06239C10.4439 8.78624 10.6678 8.56239 10.9439 8.56239H27.6475V7.42388L24.2253 4H5.5Z" fill="#2B3436"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.4438 9.0625C10.4438 8.78636 10.6677 8.5625 10.9438 8.5625H30.7653C30.9017 8.5625 31.0322 8.61824 31.1265 8.71679L34.4525 12.192C34.5416 12.2851 34.5913 12.4089 34.5913 12.5377V37.5222C34.5913 37.7983 34.3675 38.0222 34.0913 38.0222H10.9438C10.6677 38.0222 10.4438 37.7983 10.4438 37.5222V9.0625ZM11.4438 9.5625V37.0222H33.5913V12.7384L30.5517 9.5625H11.4438Z"
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1340
            Entropy (8bit):4.733611299421871
            Encrypted:false
            SSDEEP:24:tKT8FuXMMpTAjbFToY1I66QWbCrkXrS7iBMWMLbmTjA9MM8ZWTkkXtITTF4L/m4n:a8OQbJoYv6Q6W4mWBXyIzZWTk5WLe7Pc
            MD5:5F6EB53C96A04430382F5194DC9391D7
            SHA1:C423E536AF4CBE3573B7CA1A2FE82F57D44A996C
            SHA-256:4D0B801F1B313359245AA28860B3F638682A73AC15D7BB4C39124640D7E15A56
            SHA-512:1BDB5F1214DE4B03BD094DAB03505870126C9C7B466A52B7AE386BA565650F7B37EAF1DD2E3A623526B36A90EBF6D49B213971D7B4A8DB3BB0635E204F376D96
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.5 3C4.5 2.72386 4.72386 2.5 5 2.5H24.4325C24.5652 2.5 24.6924 2.55271 24.7861 2.64654L28.5011 6.36338C28.5948 6.45714 28.6475 6.58428 28.6475 6.71684V8.56239C28.6475 8.83853 28.4236 9.06239 28.1475 9.06239H11.4439V31.4596C11.4439 31.7358 11.2201 31.9596 10.9439 31.9596H5C4.72386 31.9596 4.5 31.7358 4.5 31.4596V3ZM5.5 3.5V30.9596H10.4439V8.56239C10.4439 8.28624 10.6678 8.06239 10.9439 8.06239H27.6475V6.92388L24.2253 3.5H5.5Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.4438 8.5625C10.4438 8.28636 10.6677 8.0625 10.9438 8.0625H30.7653C30.9017 8.0625 31.0322 8.11824 31.1265 8.21679L34.4525 11.692C34.5416 11.7851 34.5913 11.9089 34.5913 12.0377V37.0222C34.5913 37.2983 34.3675 37.5222 34.0913 37.5222H10.9438C10.6677 37.5222 10.4438 37.2983 10.4438 37.0222V8.5625ZM11.4438 9.0625V36.5222H33.5913V12.2384L30.5517 9.0625H11.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):168
            Entropy (8bit):4.866061003858592
            Encrypted:false
            SSDEEP:3:tRBRNq6FNpO+aFTMacvUj6FDMJA7SLvDmJS4RKb58ZQGuMnc6FNpO+aFDMJAGVPU:tnrLJUGFcAumc4sl7anZ7ASlckm
            MD5:DC2DA01A6C6933275EAA24F1FF93DF08
            SHA1:036800D0F44CAB12D96B5F868F6425A7D21BC994
            SHA-256:6F5802D5A89AEEC46B1A57E6AE73E33E18AEFC5557B9BCA9FACA6A66BDDDFCEC
            SHA-512:98272FA90C24D8FD0527E17C09793E6CD9CCC0E2F09C2A56B36CF2A3308DA0CE42B584316DE7E0D2006D06B66C2D621EA85A3DFCE566C975A9547F2F49897D17
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="14" height="14" fill="#00AE42" fill-opacity="0.5"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):242
            Entropy (8bit):5.069170074787946
            Encrypted:false
            SSDEEP:6:tnr0Qol8kAumc4sllXdSieXI0ouEFgyGQK9AHKb2:tr0dmkAuTtSie4DRVKiHA2
            MD5:DB97515503FFCA161C68D77C7600F302
            SHA1:5AF93EB71431019232820C201A4D890B501D2741
            SHA-256:244181015F5EC15317F995A190BCE15F35BA70D6C51D2F4AA0ABFA8184B15264
            SHA-512:B5FFD2EFF4C43886BAD0C11271B98BE7F0DB693F3A4B095C22F7DA1A4B38099FD576F708344C3BACDE7CCAAEFAF3E8E09ED874B27A16BE2AFED8600BEAB7AE5C
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<circle cx="10" cy="10" r="10" fill="#00AE42"/>.<path d="M7.386 7.762V6.474L10.368 4.738H11.32V15H10.06V6.236L7.386 7.762Z" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):793
            Entropy (8bit):4.467077794101617
            Encrypted:false
            SSDEEP:24:twdmluTtSieVhgqjlEWffCS+zTflaXvRdYdS5HsyjH2:68/RBn6RTflaXvZsP
            MD5:BE266CDAB54ECE32A537F559B402F574
            SHA1:66CF50BE04FBE35CDE239C567176D12EFDBAFA7A
            SHA-256:D36E10D2825A31C1B033717568C317272291B19C02F3895B33C4A9B5DFFB33A3
            SHA-512:0882C91DC1733907ECCE65B84C210723E59E6614B80623CCE834FF3E8C6F3DB177218E78CB548F0860E0B67C6FF53E55EED466F8D7C7FB3D1CE88C1B9299698F
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<circle cx="10" cy="10" r="10" fill="#00AE42"/>.<path d="M8.604 13.894H13.238V15H6.7V14.202L10.018 10.506C10.6433 9.81533 11.0727 9.274 11.306 8.882C11.5393 8.48067 11.656 8.04667 11.656 7.58C11.656 6.98267 11.4927 6.52067 11.166 6.194C10.8393 5.86733 10.4287 5.704 9.934 5.704C9.43 5.704 8.98667 5.87667 8.604 6.222C8.22133 6.558 7.946 7.006 7.778 7.566L6.77 6.992C6.97533 6.22667 7.38133 5.634 7.988 5.214C8.59467 4.78467 9.27133 4.57 10.018 4.57C10.5593 4.57 11.054 4.68667 11.502 4.92C11.95 5.144 12.3047 5.48 12.566 5.928C12.8367 6.36667 12.972 6.89867 12.972 7.524C12.972 8.13067 12.8227 8.70467 12.524 9.246C12.2253 9.78733 11.7027 10.4687 10.956 11.29L8.604 13.894Z" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):795
            Entropy (8bit):4.466857760908474
            Encrypted:false
            SSDEEP:24:twdmluTtAVhgqjlEWffCS+zTflaXvRdYdS5Hsyjs:68/RBn6RTflaXvZsd
            MD5:A4825A62910E0248FF25921C752613FE
            SHA1:29E4095E975CAA62AA2B217CD554CA795F56DD2D
            SHA-256:1AAB3A77D45E7122F60906DA52043282DA9A5356AE3F98331718E81081EB4393
            SHA-512:934D3F3D21845A55B1ADC075EE428ECE1BF8B5E84A8558C104C74C6E81067983D37B2F8C242623CB928BC05C15A47F004AD3062A5ED698811362550D91CF9486
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<circle cx="10" cy="10" r="10" fill="#CECECE"/>.<path d="M8.604 13.894H13.238V15H6.7V14.202L10.018 10.506C10.6433 9.81533 11.0727 9.274 11.306 8.882C11.5393 8.48067 11.656 8.04667 11.656 7.58C11.656 6.98267 11.4927 6.52067 11.166 6.194C10.8393 5.86733 10.4287 5.704 9.934 5.704C9.43 5.704 8.98667 5.87667 8.604 6.222C8.22133 6.558 7.946 7.006 7.778 7.566L6.77 6.992C6.97533 6.22667 7.38133 5.634 7.988 5.214C8.59467 4.78467 9.27133 4.57 10.018 4.57C10.5593 4.57 11.054 4.68667 11.502 4.92C11.95 5.144 12.3047 5.48 12.566 5.928C12.8367 6.36667 12.972 6.89867 12.972 7.524C12.972 8.13067 12.8227 8.70467 12.524 9.246C12.2253 9.78733 11.7027 10.4687 10.956 11.29L8.604 13.894Z" fill="#262E30"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):491
            Entropy (8bit):4.777487447896642
            Encrypted:false
            SSDEEP:12:tr0dmkAuTtUN477q+07r95JrHK+KffTflf0mLO3aA0:twdmluTtMP+sr97rq9ffTfl79A0
            MD5:465CC968218FA0BC3C82180B36E4237F
            SHA1:6E8962007DF612C18BB21D71F9F18215DE6B517B
            SHA-256:1268E4C8D66745964B1672C9F5BBD13C228DA4C3088E6C01A43CBD7EC9F8B6CE
            SHA-512:367B7116A2262A4FE4EA89D9956CE795E9137AC522F9FEBE2E69F55E6FACB9F6B438DF63C95260C5C9840697AD927BE5FD8D3D0A3EA684BC3E86683623606ABA
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<circle cx="10" cy="10" r="10" fill="#DBFDE7"/>.<path d="M15.874 6.75361C16.0401 6.92314 16.0401 7.20205 15.874 7.37158L8.58827 14.8091C8.4222 14.9786 8.14899 14.9786 7.98292 14.8091L4.12577 10.8716C3.9597 10.7021 3.9597 10.4231 4.12577 10.2536C4.29185 10.0841 4.56506 10.0841 4.73113 10.2536L8.2856 13.8821L15.2686 6.75361C15.4347 6.58408 15.7079 6.58408 15.874 6.75361Z" fill="black"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):320
            Entropy (8bit):4.956700384622663
            Encrypted:false
            SSDEEP:6:tnrZvUYltumc4slGnLzjqRIPQQ+pMFR0FkcqdkLkAHw6YmqZuV2F:trZvnltu8LvDoQPF5cAkLkAHFYhuIF
            MD5:B18F0B17D0C3E56F70B3A67C4E807CB9
            SHA1:751E61909E8679279CCF1C937150781504F4639D
            SHA-256:838C028CE4216C03230C3237DC31B11A756656482245610A434990DC3C12534B
            SHA-512:005E501B658953EC0E0AF103CB2402D37E3C37E1391CC3EA2271EFF95D977579BB0D1774AC442DB7FC96ED22A7D77768300A6E5DC850A097F5CA376347D86218
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">. <rect width="16" height="16" rx="1"/>. <path d="M3.35537 7.5374L7.30284 10.9361C7.71855 11.294 8.34501 11.2502 8.70687 10.838L13.8175 5.01521" stroke="white" stroke-width="1.2" stroke-linecap="round"/>. </svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1682
            Entropy (8bit):5.226110396396356
            Encrypted:false
            SSDEEP:24:tfFTuGgpCfApKFeNfa2I23hjh+MhjhNhjhleYzjhpTzjhWeFzjhkpgpCIQrFKrH0:TdAp7la2I21eU4eTQCHOzDYbkMYDKHA
            MD5:C49B73D196677B7662879849EB4E0829
            SHA1:88872609056F22E336E70F91E71A4CB303D04900
            SHA-256:B191F3EB53E670C0FB70D6B794E53A931296E7DBDEA64673A848310554C3C498
            SHA-512:CEAD895615672D4939FF271BD3BD05AD036576BBB546B55F3DBF6C4CFAB77A86CFA2C6A8DE3030E29996ACABDB9546F842F6FDCA2A04A18739291F20A78B6FF7
            Malicious:false
            Reputation:low
            Preview:<svg width="47" height="47" viewBox="0 0 47 47" fill="none" xmlns="http://www.w3.org/2000/svg">.<g filter="url(#filter0_d_3018_22744)">.<circle cx="23.3301" cy="23.3301" r="17.3301" fill="#747671"/>.<circle cx="23.3301" cy="23.3301" r="16.8301" stroke="#828280"/>.</g>.<line x1="17.1948" y1="17.1445" x2="29.9764" y2="17.1445" stroke="#AEAEAE" stroke-width="2" stroke-linecap="round"/>.<line x1="17.1948" y1="23.0508" x2="29.9764" y2="23.0508" stroke="#AEAEAE" stroke-width="2" stroke-linecap="round"/>.<line x1="17.1948" y1="28.9551" x2="29.9764" y2="28.9551" stroke="#AEAEAE" stroke-width="2" stroke-linecap="round"/>.<line x1="17.1948" y1="16.7227" x2="29.9764" y2="16.7227" stroke="#3B3B3A" stroke-width="2" stroke-linecap="round"/>.<line x1="17.1948" y1="22.6289" x2="29.9764" y2="22.6289" stroke="#3B3B3A" stroke-width="2" stroke-linecap="round"/>.<line x1="17.1948" y1="28.5332" x2="29.9764" y2="28.5332" stroke="#3B3B3A" stroke-width="2" stroke-linecap="round"/>.<defs>.<filter id="filter0_d_
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Mac OS X icon, 68486 bytes, "ic08" type
            Category:dropped
            Size (bytes):68486
            Entropy (8bit):6.675992930131724
            Encrypted:false
            SSDEEP:768:dQ1hWw6UqY81CV+EovyFkWyZOviw/ByeD75uNt4g7T5s03T5WT5FvWTX2I:dQuwTqngkyFJV5yQKlx3lWlBWTf
            MD5:32B65A5C97FB0129620E5F13B90C9284
            SHA1:699C2680BD2C1B2C5CEF924E356D287AFC949C3E
            SHA-256:0E8D118FC326A795F991EF3422A3FAB8829C0BCD0D69AF7A217B1F974F779AC5
            SHA-512:BC4D80E5FC7FB25C69A39BAF1BFB56CA6CA35F6E4AEA463A61191A5C173AC35F1D511CF483294EBCF94497BC946DF911DB04E336A87F8EF645B80DA70C129ED4
            Malicious:false
            Reputation:low
            Preview:icns....ic08..rb....jP ........ftypjp2 ....jp2 ...Ojp2h....ihdr..................colr.........."cdef............................q.jp2c.O.Q.2.................................................R.............\..@@HHPHHPHHPHHPHHP........q....S..........]...@@HHPHHPHHPHHPHHP.S..........]...@@HHPHHPHHPHHPHHP.S..........]...@@HHPHHPHHPHHPHHP...z8...^.&...t.o........15.j(.tl.2.... <)3....N...1...pPW....Q..b........z@...^.&...t.vp.|.e..m...........]..J...Z..._.A..9.a."Q.C.k.~....<.G.zH...j0..y..7.BO..<!..[Qq..[.....l.0y?.c....CW.W..v.+.?..Z\.O....$yR.k.....z.._...Wt8..yL..X)8.3...EM.b..d..Zp3......^l.`...h..R!bnc.j.v...%...}............K.f.U...Rx....k.5..p..7...k........$..B3.U...P..AS...^.....Eb.U..m<.Me.0.k..R+..xNr...n|.....aN.C...K.+.:yPM.....L.1(.*.*..Rt.6..'.U.-*IhW~....."{..H..Txq?..}............JT?.......S|...K..s....&k)E..t.P..h.i.P\.*~...F...?...^.....j.y&.....u..J.l.A.;..[....M.c#.8IH....-v.;M.w+.:yPM....."l.'z.....x.......L.J.l..5"\.m..u".U.~@...}.Q.....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):973
            Entropy (8bit):5.283655035912691
            Encrypted:false
            SSDEEP:24:t3JfDuQ8022rWJhPKHjP4hPKHAhPKHjZhPKHjgnA0hPKHjIhPKHLRc0Rv:3miAuMuQuvuaAsusu3v
            MD5:DC01D87041812BC1A08D2E9F34C6519D
            SHA1:3BDFE67B992C793127D214B684B9F180EA5E282A
            SHA-256:501C12B094F64C2192EBEE2117619175CFB68B89C6EE409F2E6EFC6C2F69B211
            SHA-512:8CC8A868BAA4BCA1690775CD6A297A78159BA575840C002E510371EDD4F610522DE15467D747A476DFB64EC07A28942AB8B1AACEEBBD26C74F3150CEF90056A2
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">..<g clip-path="url(#clip0_1018_9510)">..<path d="M12.7924 12.7886H7.96937V5.61065H1V1H12.7924V12.7886Z" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10"/>..<path d="M5.752 5.61133H1.89062V12.8391H5.752V5.61133Z" fill="#ACACAC" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10"/>..<path d="M3.27295 5.61133L1.93945 6.9444" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10"/>..<path d="M5.75226 5.61133L1.97314 9.38924" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10"/>..<path d="M5.75186 8.08984L1.97363 11.8669" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10"/>..<path d="M5.75185 10.5703L3.52148 12.8" stroke="#262E30" stroke-width="0.5" stroke-miterlimit="10"/>..</g>..<defs>..<clipPath id="clip0_1018_9510">..<rect width="14" height="14" fill="white" transform="translate(0 14) rotate(-90)"/>..</clipPath>..</defs>..</svg>..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):882
            Entropy (8bit):4.53643384503926
            Encrypted:false
            SSDEEP:24:tT1zuNkDN8E9JlGZ0a7Th9JHcAx5K7BC5ekaPPhR:vegN8cJlBa7T/gw2X
            MD5:63BB1213B38389E8F2CF1C8A492E459E
            SHA1:077313DBCFB0F6102D458F32562C310958BAB468
            SHA-256:655DCB8A0DDF30BA309D17BD5FEC8E868A1B3CE207DA20E42E2E3661966C6ABF
            SHA-512:D46C3FD8C8D3337BBB53EBC79F479ED0276647534866EFBBF51F1AFF17648496BD9FC760DA24D22FA07BF0AAFE78B0FEB2B98AF2B020786AF8158B8B42DEEE32
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M2.23222 6.30567L8.75806 10.0014C8.82343 10.0296 8.89292 10.0432 8.96414 10.0442C9.0326 10.0442 9.11499 10.016 9.16935 10.0025L15.7755 6.30549C15.9257 6.2298 16.0146 6.06487 15.9978 5.89225C16.0033 5.7225 15.9112 5.56559 15.7635 5.49259L9.23867 2.05355C9.11482 1.98215 8.96431 1.98215 8.84063 2.05355L2.24736 5.49276C2.0965 5.56399 1.99966 5.72036 2 5.89243C2 6.07825 2.08136 6.21998 2.23222 6.30567ZM9.0326 2.96659L14.6091 5.92046L8.96414 9.07496L3.3866 5.92064L9.0326 2.96659Z" fill="white"/>.<path d="M2.50708 6.26074V12.1727C2.50708 12.2808 2.56524 12.3805 2.65932 12.4338L8.81225 15.9161C8.90393 15.968 9.0161 15.968 9.10778 15.9161L15.2607 12.4338C15.3548 12.3805 15.4129 12.2808 15.4129 12.1727V6.26074" stroke="white" stroke-width="0.8" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):749
            Entropy (8bit):5.088097749469684
            Encrypted:false
            SSDEEP:12:trf1zuC/mGfD4ArMsFXPO5kAHAc4oCDgPFkAHFht4oCkeFkAHFht4oCDFkAHFhtQ:tT1zu8mAMArMEXPQk1cuEPFkahtufFkY
            MD5:A2D30ABC0C6A96F425D40950FFAFA2AB
            SHA1:B4C010B494CB95EB5026F23A4E2957E868C274E3
            SHA-256:AA8385EA6B3AD5CEDBF80B7CF53F6098290D9146929BE5F9E7874A9741499456
            SHA-512:3A5872CFA77B988B3E577B587AAA05FD7EA3C194CB0D5D05FFF0F1CAAE7DA80156A1B22C060FEAF7F59DC1F8356BE660A97471A8F7884827FF7E9310E74B1573
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M15.9333 2.5H3C2.72386 2.5 2.5 2.72386 2.5 3V15C2.5 15.2761 2.72386 15.5 3 15.5H15.9333C16.2094 15.5 16.4333 15.2761 16.4333 15V3C16.4333 2.72386 16.2094 2.5 15.9333 2.5Z" stroke="white"/>.<path d="M5.30078 5.23242H6.16745" stroke="white" stroke-linecap="round"/>.<path d="M5.30078 8.9668H6.16745" stroke="white" stroke-linecap="round"/>.<path d="M5.30078 12.6992H6.16745" stroke="white" stroke-linecap="round"/>.<path d="M8.09961 5.23242H13.6329" stroke="white" stroke-linecap="round"/>.<path d="M8.09961 8.9668H13.6329" stroke="white" stroke-linecap="round"/>.<path d="M8.09961 12.6992H13.6329" stroke="white" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):734
            Entropy (8bit):4.381860401591368
            Encrypted:false
            SSDEEP:12:trZHq4RuCSeDhWoMWJ9WXUP5vjzaM0Demb2pSL8jO+QegVPSQgz5K3deEKiHA2:tVHqIuGhWHWlP0M0qmLgpgVvgzEdTKH2
            MD5:100C87555D2C1FB364CAC4B1CEF48EF6
            SHA1:AD98CE79BE796221F21DEB832C9C64C001ECD83F
            SHA-256:BF40D1413593286F29E5F4F6EBB112FA9496B3E85424E21C1FDA114B562764C1
            SHA-512:FAB62F9B18DA2362AF5C71E9D67B519B266DE8F65DE98D2B11A57E47C0A4D9CCC38988660CA7E3865A38CC65E27EC005E54C15C8816821AE2B133218363BFAAE
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="15" viewBox="0 0 16 15" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M1.88298 7.32558H1.30663C0.847929 7.32558 0.631321 6.75953 0.972844 6.45331L7.82924 0.305723C8.0222 0.13271 8.31538 0.135818 8.50463 0.312882L15.0753 6.46047C15.4065 6.77031 15.1873 7.32558 14.7337 7.32558H14.117C13.8409 7.32558 13.617 7.54944 13.617 7.82558V14.5C13.617 14.7761 13.3932 15 13.117 15H9.69149C9.41535 15 9.19149 14.7761 9.19149 14.5V10.2674C9.19149 9.9913 8.96763 9.76744 8.69149 9.76744H7.30851C7.03237 9.76744 6.80851 9.9913 6.80851 10.2674V14.5C6.80851 14.7761 6.58465 15 6.30851 15H2.88298C2.60684 15 2.38298 14.7761 2.38298 14.5V7.82558C2.38298 7.54944 2.15912 7.32558 1.88298 7.32558Z" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2247
            Entropy (8bit):4.3154049068087055
            Encrypted:false
            SSDEEP:48:vULEyBZLAgP9AvuPt8dgcC+hs5QZ8rUUAHW8wT/NKZPK7n:sLEY2vqtxshsyZW6Hxc/NyCr
            MD5:C9B856988B44BB1374ABBDAD75EF2E3C
            SHA1:F286A9AFEDA826126344E62C22574C2F2D3CA32B
            SHA-256:420F9D96B2359D149086F3DDE4E714FC7B35A6EB5CC90C4FC9900003802907D1
            SHA-512:C284D8F7E1FE8C1F169AF8C00B807CEFB2ED4191C9A6133C6FA9EF01DB747265D2A45E3FAC2631691A36CF8079708C5423DD8CF8ECAF0C4AD9D9BBFE9D116669
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M1.72266 1.87109C1.44651 1.87109 1.22266 2.09495 1.22266 2.37109V6.61085C1.22266 6.88699 1.44651 7.11085 1.72266 7.11085H4.7726C4.77186 7.12198 4.77148 7.13321 4.77148 7.14453V8.00956C4.77148 8.03825 4.7739 8.06638 4.77854 8.09375H3.62305C3.3469 8.09375 3.12305 8.31761 3.12305 8.59375C3.12305 8.86989 3.3469 9.09375 3.62305 9.09375H7.25294C7.52908 9.09375 7.75294 8.86989 7.75294 8.59375C7.75294 8.31761 7.52908 8.09375 7.25294 8.09375H5.76443C5.76907 8.06638 5.77148 8.03825 5.77148 8.00956V7.14453C5.77148 7.13321 5.77111 7.12198 5.77037 7.11085H8.755C9.03114 7.11085 9.255 6.88699 9.255 6.61085V2.37109C9.255 2.09495 9.03114 1.87109 8.755 1.87109H1.72266ZM2.22266 2.87109V6.11085H8.255V2.87109H2.22266Z" fill="#F8F8F8"/>.<path d="M16.7705 2.51172C16.7705 2.23558 16.5466 2.01172 16.2705 2.01172L12.8463 2.01172C12.5702 2.01172 12.3463 2.23558 12.3463
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2304
            Entropy (8bit):3.888116368199277
            Encrypted:false
            SSDEEP:48:v5r321Gs2h/9NBhYT7qRLyvfNlcNr8wE9Ir23oIrQYo2OTxd:BG1GBh/9NBAFvFEdE99+
            MD5:91841B56A64818CDD1501CA3B533970C
            SHA1:125C0AC44DFA5151171E50204E1AB258E9C36602
            SHA-256:3AF900B6C3F8E49467671A7F802F128D28C06D5D9B2696453DF0AD3DB6E7DA39
            SHA-512:E55C731729D4D9A0A5017F5B3937168042F3042FC7C8C03B1224645403B7A1F6B567F37CB43B5FFCDB0FA1562E5E4AC2C9BFC62F76D9DB2FBAB4B07741A773E6
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M8.91667 7.96053V3.42763C8.91667 3.17105 8.75 3 8.5 3C8.25 3 8.08333 3.17105 8.08333 3.42763V7.96053C7.41667 8.13158 6.91667 8.73026 6.91667 9.5C6.91667 10.2697 7.41667 10.8684 8.08333 11.0395V15.5724C8.08333 15.8289 8.25 16 8.5 16C8.75 16 8.91667 15.8289 8.91667 15.5724V11.0395C9.58333 10.8684 10.0833 10.2697 10.0833 9.5C10.0833 8.73026 9.58333 8.13158 8.91667 7.96053ZM8.91667 10.1842C8.75 10.2697 8.66667 10.2697 8.5 10.2697C8.33333 10.2697 8.25 10.1842 8.08333 10.1842C7.83333 10.0987 7.66667 9.75658 7.66667 9.5C7.66667 9.15789 7.83333 8.90132 8.08333 8.81579C8.25 8.73026 8.33333 8.64474 8.5 8.64474C8.66667 8.64474 8.75 8.73026 8.91667 8.73026C9.16667 8.90132 9.33333 9.15789 9.33333 9.5C9.33333 9.75658 9.16667 10.0987 8.91667 10.1842ZM4 10.6974V3.42763C4 3.17105 3.83333 3 3.58333 3C3.33333 3 3.16667 3.17105 3.16667 3.42763V10.6974C2.5 10.8684 2 11.4671 2 12.2368C2 13.0066 2.5 13.60
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2306
            Entropy (8bit):3.8926988074685718
            Encrypted:false
            SSDEEP:48:v5r321Gs2h/9NBhYT7qRLyvfNlcNr8wE9Ir23oIrQYo2OTxh:BG1GBh/9NBAFvFEdE99u
            MD5:E99784C905B45FAE5EB13021025031B8
            SHA1:42CE3BFED37F9E284C3D713F82722CC8F5696C15
            SHA-256:8A58E7513A8A3EA98D2A210BCDBA8BF33D195AF0BDC3980A121414E8DF8F3A96
            SHA-512:7ADEF85061473FE3A8B68798FC82DF5E0DB3C46251BFB46DBC0B69BCAE1885FA5C33A5C4A53833E85C6B925073DF21427AE8D1A3A68631D2E71157C2FF13BE6D
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M8.91667 7.96053V3.42763C8.91667 3.17105 8.75 3 8.5 3C8.25 3 8.08333 3.17105 8.08333 3.42763V7.96053C7.41667 8.13158 6.91667 8.73026 6.91667 9.5C6.91667 10.2697 7.41667 10.8684 8.08333 11.0395V15.5724C8.08333 15.8289 8.25 16 8.5 16C8.75 16 8.91667 15.8289 8.91667 15.5724V11.0395C9.58333 10.8684 10.0833 10.2697 10.0833 9.5C10.0833 8.73026 9.58333 8.13158 8.91667 7.96053ZM8.91667 10.1842C8.75 10.2697 8.66667 10.2697 8.5 10.2697C8.33333 10.2697 8.25 10.1842 8.08333 10.1842C7.83333 10.0987 7.66667 9.75658 7.66667 9.5C7.66667 9.15789 7.83333 8.90132 8.08333 8.81579C8.25 8.73026 8.33333 8.64474 8.5 8.64474C8.66667 8.64474 8.75 8.73026 8.91667 8.73026C9.16667 8.90132 9.33333 9.15789 9.33333 9.5C9.33333 9.75658 9.16667 10.0987 8.91667 10.1842ZM4 10.6974V3.42763C4 3.17105 3.83333 3 3.58333 3C3.33333 3 3.16667 3.17105 3.16667 3.42763V10.6974C2.5 10.8684 2 11.4671 2 12.2368C2 13.0066 2.5 13.60
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1488
            Entropy (8bit):4.112515381725983
            Encrypted:false
            SSDEEP:24:tT1zuCEF644rT0q1poHAtt+eyc4V80W3h2sunBd9Cldp+2NPbo4lcu1GqdAH2:vJrT/UAtt+eycA8EX9CPp+2RNKqz
            MD5:9593A6C04755B4EE6E6991EDF0A07717
            SHA1:4CB70945CEE89FB306265231CEBD1D5FF15507EB
            SHA-256:D2180170F45B5646D5E1E42CD4A739AD955BB3451D63718EE896F48CF7562CB1
            SHA-512:6FD7F2A5B0DE01F3D4E93F8F02B415DDCC545194A8E0BD6FA1C36453C1E0A70511A75616CE690FE5D0B48ECD70FED90EA6204BA2153F2D57267E8036DE29C8E2
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M2.30974 6.12634L8.79893 9.66813C8.86393 9.69516 8.93303 9.70816 9.00385 9.70919C9.07193 9.70919 9.15386 9.68216 9.20791 9.66916L15.777 6.12617C15.9263 6.05363 16.0147 5.89557 15.998 5.73014C16.0034 5.56746 15.9119 5.41709 15.765 5.34712L9.27684 2.05132C9.15369 1.98289 9.00402 1.98289 8.88104 2.05132L2.32479 5.34729C2.17478 5.41555 2.07848 5.5654 2.07883 5.73031C2.07883 5.9084 2.16076 6.04422 2.31077 6.12634H2.30974ZM9.07192 2.92633L14.6171 5.75717L9.00385 8.78029L3.45764 5.75734L9.07192 2.92736V2.92633ZM15.6819 8.56132L14.3852 7.90425L13.4554 8.41027L14.5492 8.97018L8.93492 11.9931L3.38973 8.9712L4.55063 8.38324L3.62184 7.87722L2.242 8.56115C1.92813 8.72521 1.91513 9.17614 2.22901 9.3402L8.71683 12.8822C8.78491 12.9222 8.86684 12.9372 8.93492 12.9372C9.00693 12.9384 9.07808 12.9195 9.13983 12.8822L15.6959 9.3402C15.8423 9.26373 15.933 9.11114 15.9301 8.94588C15.9272 8.78063 15.831
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):687
            Entropy (8bit):4.864434871073583
            Encrypted:false
            SSDEEP:12:trZHq4Ru+Qb6Zfw3ww6ZfLhqClZfLho6ZfLhz7HTw6ZfLh/7HXlZfLh6Hv6ZfLhR:tVHqIu+Qedst6dLh5ldLhddLhzD86dLJ
            MD5:10F504F10938E4876781C6589616DF55
            SHA1:CE79CBAE674E65D3A348DEC8A2CCB0DAD0378AD7
            SHA-256:428AB7FFC7862483433DC5D6387E20DE4C00147BBE2E4BA3A6D6A3DFB2688A65
            SHA-512:6DF9EB77D16E45FFD0C992F6373E75FE33414679D137C8A4EE54E5342041D1DEB2CC9B1814274CF74EC88B23FAFE18B1E323536C91F0A3F6F62D56B1A1396916
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="15" viewBox="0 0 16 15" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect x="0.5" y="0.5" width="15" height="14" rx="1.5" stroke="#323A3D"/>.<line x1="3.5" y1="3.5" x2="4.5" y2="3.5" stroke="#323A3D" stroke-linecap="round"/>.<line x1="3.5" y1="7.5" x2="4.5" y2="7.5" stroke="#323A3D" stroke-linecap="round"/>.<line x1="3.5" y1="11.5" x2="4.5" y2="11.5" stroke="#323A3D" stroke-linecap="round"/>.<line x1="6.5" y1="3.5" x2="12.5" y2="3.5" stroke="#323A3D" stroke-linecap="round"/>.<line x1="6.5" y1="7.5" x2="12.5" y2="7.5" stroke="#323A3D" stroke-linecap="round"/>.<line x1="6.5" y1="11.5" x2="12.5" y2="11.5" stroke="#323A3D" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 259 x 353, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):199194
            Entropy (8bit):7.975824874597925
            Encrypted:false
            SSDEEP:3072:uMn7aVeBIzckZEt3m8kzWDTxh7Dx83W4LpOU6yTsj48F77iEc7iFh:uMneVeB+qt3mZWDH3x83W4LQU6YIVff
            MD5:614EECF3EA9B81B7CE8929F48123CA43
            SHA1:7E80A1098F02E204E694711B106879D27AB3EAED
            SHA-256:16D3255EC65E0AF8E5E4A0116DE32946B36C50BAAA6E6F78C927AB6408F20D4D
            SHA-512:B61B7055579FFD33FD4BB35BEF6AEF8A62D8F5E5AFD55A5C3B95034CB1FC5BB96F58F86DC28A54599459DE7D033C54B52BDA4BD4C86897880CBEB84014E683DF
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.......a.....t......sRGB.........gAMA......a.....pHYs...M...M.......IDATx^....X....DT.9t.s.9.:..VK.nI....`...c.N....8alc...crNB(.H.}......<.].......}g..Z..^uN.:..S...j...'.>.d...|NB...2.6y.... ... .....k2.,_......s|A.O...7.....#........G.g...O.?W...Xo.%.(.?H,..s...G.G...o...GF.9...?...=...............U;v..;r.-...o....J.........v..{J..S'v.#...N.{.N....u.W............v..>?~..>.......v..^;}..;wf..=..N....y..~W.{...............a=..Co.q.9vX.N.O..Y]..I...~.......o..c..C.}t.d.?..rR).<.g8qT.....x.wB..S*.{....3..o.T.p..D..Z..W...>)..s..;..9.oyV..xf....=[H.%....".{..*...(.......yN.....x.....<.rB....MIy..t.3<..M~<.zqL...w.......5.......<....$un.Zz...J....T.x...5.?t..d.]...........6r..^Oc../....Co..k.............+...P~......y.._......_.)..k...G.\G.Jx>.K/..y...........;..:w....9...........{.9.?...=..YO....}..3..;..........*.w......|...0...{.0.|...!.#.DE..d;...sc.8...../ .#......#I>...xB..'\....%>._....O............{z.......*.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 424 x 632, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):548541
            Entropy (8bit):7.9829924585313154
            Encrypted:false
            SSDEEP:12288:BiE2jB6V9HmDqZkSPaen2nigwRKYyJOIcn7AI8fMn+RXSR:BiT2miPaeSigwRK7Fcn7lAMn+tSR
            MD5:90C231FB296968C30E49BF67E5CB19AF
            SHA1:E5BAA70C33B030764899CCA50B0B14E0CA0B1971
            SHA-256:2240D55546CA1D5D91A609453653B4ACFB5B5DC32B96D49FD8A30E96851FFD50
            SHA-512:4EC3E9CF8162820CF5F9593FEE9280F129DA7762DB03A8378C3D6550CD8B9BE1B0E1752E9C4DFC7A0B5F514373A5012C71732347E8CB822F875B01217BBCC592
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.......x.....0dwr....sRGB.........gAMA......a.....pHYs...M...M.......IDATx^........@NB9K..H.49ir.h.4...h.r@.9.ml......mc.c6.8...L...3...}...X.{..g..s~...b.X..P].w..u.w..s^}...................s.....|...{...y...{...x....v..vH..~..{v...d..7..g..{.k.s.+.s..w...w......}{.t.r9...v.w...|...g?e.....h..=.vn..o{............rv...(...*{..m.....2v.:v.;..m;vx..8....n..-:.2wl}.ny.v.....Ayo.....C....mvp..s.;v.......n')K...>r.=.wX......._..N...N...o}.o.}.....t.....c........|[.O......l]..i....]o....3....=v........X>.m'..;.........)....q..u...vZ.......t~~?.B....!......?y|..>..S..~.6?.4..........'t/..r.._,.;.....o.s.........~...GU..=.c..Y.x..;.....8.g...{{..{.>=.'..?8..N..b......+.1.;.|G........r;*..D.....-:....W...rlX.Z.......;.N...o.}...Hy.0.!....c...d9..../...K...'.<......\G..._..].(/..^vb\S,'..5...k.L....2.....by...:h.n.':.......9.r.qN...;...k.q...|].c.^../...9m.I.......}.7.-.U]'.j}7..u.....Q../.B.c..'..m/j=.../.X.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):168
            Entropy (8bit):4.8907140362995225
            Encrypted:false
            SSDEEP:3:tRBRNqcwR+8XcvUJUTlt7SLvDmJS4RKb58ZQGuMnccwR+8DGVPRXlcJ3CrVZ8v:tnrZvUYltumc4sl7anLqSlckm
            MD5:27BF75AB7A92D199AC473C1FCA8830DB
            SHA1:E179820CF9EE47B32BDFC2EC7675AFD9512B35C3
            SHA-256:6C5EE2333EC8E6DB37BD238E7E9531305D988F2BA2C902A1C54E6A29F3132EB6
            SHA-512:B171113B60DBD773B55941A002B940E9691F24B0651527A75823942EE6E445325C4B571C0C5F8C97A1E99EA2E9C86D0F8698DF7D5B481C9483CE4B2A2247C6D5
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="16" height="16" fill="#00AE42" fill-opacity="0.5"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):755
            Entropy (8bit):4.288964348465872
            Encrypted:false
            SSDEEP:12:tr0dmkAuC2TC1n5/k7xw/P0pLY+F/dpOBa+vFm1pLQFAkW8cgJHE5+:twdmluBTCfkysiedpO4Gm1dyjcgJks
            MD5:B58A52721E27676C1D941A8FC9BB82F8
            SHA1:8F85BEE58C6C412CEC9F94958C96AB139A730EFD
            SHA-256:FE70D9C824A1F85145EF93CD2C32BFE9B33845D466155984CE343F2485ABCDBD
            SHA-512:E651A2522905C7B59C41BA70F8075417222D290FB65C3F592A2A656B442C6FF139D1DE62F745D23417306A694E2D64C85A232921EBA2497695FEF19F308136F0
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M11.676 10.236C12.588 10.604 13.044 11.268 13.044 12.228C13.044 13.028 12.744 13.656 12.144 14.112C11.544 14.56 10.72 14.784 9.672 14.784H6V6H9.372C10.316 6 11.092 6.212 11.7 6.636C12.308 7.06 12.612 7.676 12.612 8.484C12.612 9.268 12.3 9.852 11.676 10.236ZM8.004 7.764V9.492H9.204C9.596 9.492 9.908 9.408 10.14 9.24C10.372 9.072 10.488 8.848 10.488 8.568C10.488 8.304 10.376 8.104 10.152 7.968C9.928 7.832 9.612 7.764 9.204 7.764H8.004ZM9.552 13.008C9.984 13.008 10.32 12.932 10.56 12.78C10.8 12.62 10.92 12.396 10.92 12.108C10.92 11.82 10.796 11.596 10.548 11.436C10.308 11.268 9.972 11.184 9.54 11.184H8.004V13.008H9.552Z" fill="#262E30"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):882
            Entropy (8bit):4.219127183857094
            Encrypted:false
            SSDEEP:24:twdmlufORFXuAuvuShu5Y2QwXYcP3Dy6WMqFqwa:687R/iuY8YDwX3m6WbFqx
            MD5:01FC1155E22532F9FA2E5D007FD23D2C
            SHA1:44F8D1D88621A85503BEF3A5C117A224E80573D3
            SHA-256:EA576DC8B8C060332885395E8CF27A71F6D47874FC53240E7E43857397E5B4E6
            SHA-512:8D8B4C85A119AF664430D05D055606D6D8BD77EB4DC0A752C738BB282F34EDE261C410789253D635A3734FB433A617F69C4500425CA8785962E77E58EB2279A3
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M12.219 10.0622C13.131 10.4302 13.587 11.0942 13.587 12.0542C13.587 12.8542 13.287 13.4822 12.687 13.9382C12.087 14.3862 11.263 14.6102 10.215 14.6102H6.54297V5.82617H9.91497C10.859 5.82617 11.635 6.03817 12.243 6.46217C12.851 6.88617 13.155 7.50217 13.155 8.31017C13.155 9.09417 12.843 9.67817 12.219 10.0622ZM8.54697 7.59017V9.31817H9.74697C10.139 9.31817 10.451 9.23417 10.683 9.06617C10.915 8.89817 11.031 8.67417 11.031 8.39417C11.031 8.13017 10.919 7.93017 10.695 7.79417C10.471 7.65817 10.155 7.59017 9.74697 7.59017H8.54697ZM10.095 12.8342C10.527 12.8342 10.863 12.7582 11.103 12.6062C11.343 12.4462 11.463 12.2222 11.463 11.9342C11.463 11.6462 11.339 11.4222 11.091 11.2622C10.851 11.0942 10.515 11.0102 10.083 11.0102H8.54697V12.8342H10.095Z" fill="#B6B6B6"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):253
            Entropy (8bit):5.08719639287643
            Encrypted:false
            SSDEEP:6:tnr0Qol8kAumc4slvIFccazw1lVWoEXIfV+LqLnMqVWo+:tr0dmkAuCFcle5E4qwnMq5+
            MD5:E3348D97D3DE03481617E4E692AC98EA
            SHA1:440A9D5EAC2053652491F634159747C8D7A84687
            SHA-256:D7FE99134FF0E4B14970242EB22A10B7943FCCB525F71A0B1736BE6BC1725A27
            SHA-512:4D86D1580A86E30CA3B9FE2F50BF1790C4ED94E6C696753272FA68ACAEF6C0FAFCE1D0411F4B5D2848018AD95CE7528BFCAC133F8F397D2B45978AE7D2E452FF
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M9.29796 6H10.298L7.86755 14.5945H6.86755L9.29796 6Z" fill="#262E30"/>.<path d="M6.38243 6H13.3824L13 6.91839H6L6.38243 6Z" fill="#262E30"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):324
            Entropy (8bit):5.073866805412608
            Encrypted:false
            SSDEEP:6:tnr0Qol8kAumc4sl7aniQolz04XIE2WnSjFM82WftwpXIw8U2WTXjsU2WftwN:tr0dmkAucidt044NJjFg4wp4W2M24wN
            MD5:B77FF758D71FB5F9F39B5C7966A3B8B9
            SHA1:D736CC2883034B5F874B51F1FE70F27E3BF14548
            SHA-256:FCC5F59604CF37BFF72BAF354BA24E29864AB24744273CE3900010B743A12273
            SHA-512:C1DCBBB5C44AD52D758E13068D009D0EC1EEF5E880118CE4485C7199AD053C6535E3AACCC46EF06C76B56903A65CBC739940C2722A8468109BC1374943A898FD
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="20" height="20" rx="1" fill="none"/>.<path d="M10.2981 6.10938H12.0005L9.57008 14.7039H7.86768L10.2981 6.10938Z" fill="#B6B6B6"/>.<path d="M7.38243 6.10938H14.3824L14 7.5H7L7.38243 6.10938Z" fill="#B6B6B6"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):25707
            Entropy (8bit):4.06511711264803
            Encrypted:false
            SSDEEP:192:Qp2WQxlZSQIstffjuAGZ7LJUuXJEQ4jUU+9CrJig19yHB2AqJ0IxmWOSbesxIKN/:Qp2riLOjUURJd88e4QuAhCigZ
            MD5:0F8ED5702E4D3408628512C86D0F1055
            SHA1:3C59AA85B478E381708AA7476D92E7B00201ED17
            SHA-256:2E5FFF404F5471A60B8BA1888F479B6117993FE351688E1376C9EE488A603263
            SHA-512:A751C7184D4A955CB0B8B2873942DCB1CE0F594678E364C1CF16114837040376E60A6E574C0B428ECBC6E6B27166191018B100D5113AE8EFE9FEF67970B055BC
            Malicious:false
            Reputation:low
            Preview:<svg width="256" height="256" viewBox="0 0 256 256" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M0 0H256V256H0V0Z" fill="white"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M14.2222 0H7.11111V7.11111H0V14.2222H7.11111V21.3333H0V28.4444H7.11111V35.5556H0V42.6667H7.11111V35.5556H14.2222V42.6667H21.3333V35.5556H28.4444V42.6667H35.5556V35.5556H42.6667V42.6667H49.7778V35.5556H56.8889V42.6667H64V35.5556H71.1111V42.6667H78.2222V35.5556H85.3333V28.4444H78.2222L78.2222 21.3333H85.3333V14.2222H78.2222V7.11111H85.3333V0H78.2222L78.2222 7.11111H71.1111V0H64V7.11111H56.8889V0H49.7778V7.11111H42.6667V0H35.5556V7.11111H28.4444V0H21.3333V7.11111H14.2222V0ZM14.2222 14.2222V7.11111H7.11111V14.2222H14.2222ZM21.3333 14.2222H14.2222V21.3333H7.11111V28.4444H14.2222V35.5556H21.3333V28.4444H28.4444V35.5556H35.5556V28.4444H42.6667V35.5556H49.7778V28.4444H56.8889V35.5556H64V28.4444H71.1111V35.5556H78.2222V28.4444H71.1111V21.3333H78.2222L78.2222 14.2222H71.1111V7.11111H64V14.2222H56.8889V7.111
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):513
            Entropy (8bit):4.526432318538391
            Encrypted:false
            SSDEEP:12:trwdU/gKuCFQ5iNQSEk/Uh8akNlZf7kXnLhvQXQB2IASiM:tYU/duLiNQFavlZf7k3s8ASiM
            MD5:516D197C1324815E114DBC2ECE24DB76
            SHA1:2F50E9AF72FBC64A3130629C4FC6678F79E093B2
            SHA-256:6F119EA0F6980C242325DB3ACA7AC5A18AF9A688326019C985499001F3CB7170
            SHA-512:95833DA0186FD4EBBAEB5154E227883061160D1F49F7991D91DED6C954D7B4FDE712FD69250412B3FD357D2169E03517D858D81F7A5F0FDDDADC1129D1E4092C
            Malicious:false
            Reputation:low
            Preview:<svg width="24" height="24" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M2.28619 11.4674C1.8995 11.8617 1.90568 12.4949 2.29999 12.8816L8.72575 19.1831C9.12006 19.5698 9.7532 19.5636 10.1399 19.1693C10.5266 18.775 10.5204 18.1419 10.1261 17.7552L4.41431 12.1538L10.0157 6.44201C10.4024 6.04769 10.3962 5.41456 10.0019 5.02786C9.60758 4.64117 8.97445 4.64735 8.58775 5.04166L2.28619 11.4674ZM20.165 11L2.99041 11.1676L3.00992 13.1675L20.1846 13L20.165 11Z" fill="#00AE42"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):230
            Entropy (8bit):4.819526157697445
            Encrypted:false
            SSDEEP:6:tnrwdJ4wAumc4sl7anmdQqSus20tff9AHKb2:trwdJ4JucmdQB5XiHA2
            MD5:469AEE821B8520ADECE93BD691C2A2D5
            SHA1:8013712EDA6D48D80860E7E747726BAE5144553B
            SHA-256:2EC69E51EAB115C832DAB71D96B6A772F552FF9CF041ACC7DEE143EB2EA42730
            SHA-512:0D7272267DD4A9C14E7850EF27098463325E99B011F2EA319B230BD416D21E27F4F0F9A9E18594D6411C0F23FA9AF74B5F833D5F5F48BA6E97E8DB7D2E11AD3D
            Malicious:false
            Reputation:low
            Preview:<svg width="24" height="14" viewBox="0 0 24 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="24" height="14" rx="7" fill="#ACACAC"/>.<rect x="1" y="1.00293" width="12.0384" height="12" rx="6" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):231
            Entropy (8bit):4.783667881121118
            Encrypted:false
            SSDEEP:6:tnrwdJ4wAumc4sl7anmdQqSSi9M+0tff9AHKb2:trwdJ4JucmdQBSiaXiHA2
            MD5:90AE95C03A0B52BFDC07ED6CD5E192CD
            SHA1:23044831CFB491A006D2ED3B77A2906A3E927178
            SHA-256:FFFAA7FCEEA7CB52B362D282E25DD01201C5F8136343094A4FA7685099F6D3FC
            SHA-512:6A73A8A6C80F321B8355AFC4D0855D4DCB66D4042DB9AC7BC8526BCA6887831E125A14F5EF1F06AE620590F3DE652C42E210F6380254146026AFA92C84F1B89D
            Malicious:false
            Reputation:low
            Preview:<svg width="24" height="14" viewBox="0 0 24 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="24" height="14" rx="7" fill="#00AE42"/>.<rect x="11" y="1.00293" width="12.0384" height="12" rx="6" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2459
            Entropy (8bit):4.849015415636103
            Encrypted:false
            SSDEEP:24:tKnguXMMfKl+9MMDj+9MMz+9MMlwFx+9MMJDG+9MMlBFU+9MM4p/+9MMQWQ8SW+R:glkEBF+p3iSkvnpY64GqIRv4TGhnxEb
            MD5:7B07F40D84EC882C67A2A38ED01B18EE
            SHA1:08630ADCFEBC370E534A761BE5C56511AF78F1D3
            SHA-256:66344EC13BB60365DC684C74B22C2306430700026ED1D85F39B02BBDD50341CF
            SHA-512:13F30E158531DFE44B22354797DBA98657353DE1395ABDEB9F84F5DD9E40F856ECCCEBD4B7CE7275F2DABC94F8946A858B9694BE3C99576106A1286EF2CC044D
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M32 10.5488H3V9.54883H32V10.5488Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M32 16.6914H3V15.6914H32V16.6914Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M25.7426 23.0332H3V22.0332H25.7426V23.0332Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M21.1312 29.1777L3.00001 29.1785L2.99997 28.1785L21.1312 28.1777L21.1312 29.1777Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M27.0447 21.7156L27.0447 4.5L28.0447 4.5L28.0447 21.7156L27.0447 21.7156Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M21.1063 33.5L21.1063 4.5L22.1063 4.5L22.1063 33.5L21.1063 33.5Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M14.9678 33.5L14.9678 4.5L15.9678 4.5L15.9678 33.5L14.9678 33.5Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2444
            Entropy (8bit):4.871083858752833
            Encrypted:false
            SSDEEP:48:a8jqSHxUJtI80MVqYBJNoS42ZpV2/PdNRhpQhxnwJlGbiGrv0VBQufKS:WiUJtbVqG7t3o3dNbCwJlG+Gr5cKS
            MD5:E3402FD1936EC3EDB880519566F12873
            SHA1:D6CE5E056A4098E26EB2EE337B07E7F797A64667
            SHA-256:4B0EAB1D9206ED47C49E85D355788D98D68761FF70A2AC8936176947F04761C9
            SHA-512:6DA26E2060AED02E17C865D24F4548D5868EE3B12A8F29B5B8C165102F929A7B02ECAE7AD7EC22DB926E26CB64710F4FF974CDFB5CBC8B0AAC19D845BE6D9D4A
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M32 10.0488H3V9.04883H32V10.0488Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M32 16.1914H3V15.1914H32V16.1914Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M25.7426 22.5342H3V21.5342H25.7426V22.5342Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M21.1312 28.6768L3.00004 28.6775L3 27.6775L21.1312 27.6768L21.1312 28.6768Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M27.0449 21.2156L27.0449 4L28.0449 4L28.0449 21.2156L27.0449 21.2156Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M21.1064 33L21.1064 4L22.1064 4L22.1064 33L21.1064 33Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M14.9678 33L14.9678 4L15.9678 4L15.9678 33L14.9678 33Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M8.8291 33L8.8291
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1421
            Entropy (8bit):4.790495627847774
            Encrypted:false
            SSDEEP:24:tKnguXMMaVeKUMOc0zKq9MM3ijGFBHSmPtdbSie9MMY/yRi7/dVVEFGrAq9MM4jC:gW2zmjGFByUYRiLdXxqk3PWVy
            MD5:BE5F233C18D8DF27BCC0B507B94A327B
            SHA1:52CEBB89DFC9537D58C10DB01D834EBB4E144F5E
            SHA-256:A8292D2109C007AEA14AF71B41476B1A028E1B77ADEA46BBFFEA6AA31275C44A
            SHA-512:1A159CDB5C08D4BF89C019B8E1D5043101901CDC0F5EFAC88A3B9D853B6C4FFECDAF722F380D5F504C759D17259101646FBAE6C5E79D492D8E56F9EAAED50A2E
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.5 4.5C3.5 4.22386 3.72386 4 4 4H35.5919C35.868 4 36.0919 4.22386 36.0919 4.5V36.0919C36.0919 36.368 35.868 36.5919 35.5919 36.5919H4C3.72386 36.5919 3.5 36.368 3.5 36.0919V4.5ZM4.5 5V35.5919H35.0919V5H4.5Z" fill="#2B3436"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M7.08533 7.48633C7.08533 7.21019 7.30918 6.98633 7.58533 6.98633H32.6563C32.9324 6.98633 33.1563 7.21019 33.1563 7.48633V16.569C33.1563 16.8452 32.9324 17.069 32.6563 17.069H7.58533C7.30918 17.069 7.08533 16.8452 7.08533 16.569V7.48633ZM8.08533 7.98633V16.069H32.1563V7.98633H8.08533Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M7.10181 19.1719C7.10181 18.8957 7.32566 18.6719 7.60181 18.6719H15.0543C15.3304 18.6719 15.5543 18.8957 15.5543 19.1719V32.6741C15.5543 32.9503 15.3304 33.1741 15.0543 33.1741H7.60181C7.32566 33.1741 7.10181 32.9503 7.10181 32
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1419
            Entropy (8bit):4.797625785693247
            Encrypted:false
            SSDEEP:24:tKT8FuXMMaAGIwcDHw00lerVA9MM7WpeqM2V0iNm49MMVPgVL5M4SET0LcA9MM4K:a81F030AHxMu0l5PMFLQhrJpeeTS
            MD5:47EE70C97D6284EEC1675D46586CEF53
            SHA1:2DC0A4C40EF8A251F34FD7195359CA41A5B48174
            SHA-256:B36E25A940B77B388B8ACFFE8919A7EED47E6AF41B8B7B364CECFD00531010A8
            SHA-512:8B8D30B032F78D77D4FB2E074AFCADFC335C89E484413D397015CC4269132BC5D90D2A375B1F42482B7E42ABB0AE8811AE483E24AAD90AD593BB8B146DA45565
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.5 4C3.5 3.72386 3.72386 3.5 4 3.5H35.5919C35.868 3.5 36.0919 3.72386 36.0919 4V35.5919C36.0919 35.868 35.868 36.0919 35.5919 36.0919H4C3.72386 36.0919 3.5 35.868 3.5 35.5919V4ZM4.5 4.5V35.0919H35.0919V4.5H4.5Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M7.08545 6.98633C7.08545 6.71019 7.30931 6.48633 7.58545 6.48633H32.6564C32.9325 6.48633 33.1564 6.71019 33.1564 6.98633V16.069C33.1564 16.3452 32.9325 16.569 32.6564 16.569H7.58545C7.30931 16.569 7.08545 16.3452 7.08545 16.069V6.98633ZM8.08545 7.48633V15.569H32.1564V7.48633H8.08545Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M7.10156 18.6719C7.10156 18.3957 7.32542 18.1719 7.60156 18.1719H15.054C15.3302 18.1719 15.554 18.3957 15.554 18.6719V32.1741C15.554 32.4503 15.3302 32.6741 15.054 32.6741H7.60156C7.32542 32.6741 7.10156 32.4503 7.10156 32.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1085
            Entropy (8bit):5.350602706567717
            Encrypted:false
            SSDEEP:24:2dKATLfY/iMKaNE7d6rrOXBd5/jOoQqc0pE0p0CeAy5:cKAvfY/iMTE7d6vwBdpjl06E6ZeA2
            MD5:804E57DDC9569465D7C063A44BFB6D08
            SHA1:FD965695D5BA7AD974472910333D73D5EB1D5381
            SHA-256:C58FFA53D1A431502C26B5C73B95E5D52A5AA166612DEE0EB78BDAD559C5DD3D
            SHA-512:C9DF09827A4AA970D26B8D4527A6DCDCB87D2168EF591476F9BCD87141389FB903AF5944DEEC192796A28BBCFA83AAF6C1B8EF27761A9E453B1C7EE68D0C38F0
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="utf-8"?>. Generator: Adobe Illustrator 25.2.1, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->.<svg version="1.1" id="Layer_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px". viewBox="0 0 330 330" style="enable-background:new 0 0 330 330;" xml:space="preserve">.<style type="text/css">. .st0{display:none;}. .st1{fill:none;stroke:#ED6B21;stroke-width:17.0079;stroke-linecap:round;stroke-miterlimit:10;}.</style>.<path id="XMLID_28_" class="st0" d="M180,315V51.2l49.4,49.4c5.9,5.9,15.4,5.9,21.2,0c5.9-5.9,5.9-15.4,0-21.2l-75-75. c-5.9-5.9-15.4-5.9-21.2,0l-75,75C76.5,82.3,75,86.2,75,90s1.5,7.7,4.4,10.6c5.9,5.9,15.4,5.9,21.2,0L150,51.2V315. c0,8.3,6.7,15,15,15S180,323.3,180,315z". style="fill:#ed6b21;"/>.<g id="XMLID_1_">. <g>. </g>. <g>. <polyline class="st1" points="113.6,84.5 164.3,18.3 164.3,18.3 "/>. <polyline class="st1" points="216.4,84.5 164.3,18.3 164.3,18.3 "
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3709
            Entropy (8bit):4.188950542259717
            Encrypted:false
            SSDEEP:96:7jYgAN3eQ/fHEkOV1ZRih+IcZ4aspMl9Ze:QDbHExbRuMlXe
            MD5:DFB2324B73CF7ED38F2071452328E889
            SHA1:5F6D3FF4CA95665EA67C135EFD6F38E8A6FC5653
            SHA-256:D5802F9AC455ED9753459D965A4AA5C70852C594625C68CF8686DC36E55B152A
            SHA-512:B2D9119CF48738964B33AF876AA9B8176BB37714D23EF28767F39DE4A767C8AF1925C88E8170CB5653B82D4C25D086715859ED6AF60B6C5EE0BBEC38B3E0B0BA
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.50012 10.623C3.50012 10.3469 3.72398 10.123 4.00012 10.123H16.7671C17.0432 10.123 17.2671 10.3469 17.2671 10.623V14.3822C17.2671 14.6583 17.0432 14.8822 16.7671 14.8822C15.5997 14.8822 14.6558 15.8253 14.6558 16.9843C14.6558 18.1433 15.5997 19.0864 16.7671 19.0864C17.0432 19.0864 17.2671 19.3103 17.2671 19.5864V23.3455C17.2671 23.6217 17.0432 23.8455 16.7671 23.8455H13.4546C13.2147 25.322 11.9295 26.4477 10.3836 26.4477C8.83768 26.4477 7.55253 25.322 7.31257 23.8455H4.00012C3.72398 23.8455 3.50012 23.6217 3.50012 23.3455V10.623ZM4.50012 11.123V22.8455H7.77237C8.04851 22.8455 8.27237 23.0694 8.27237 23.3455C8.27237 24.5046 9.21626 25.4477 10.3836 25.4477C11.5509 25.4477 12.4948 24.5046 12.4948 23.3455C12.4948 23.0694 12.7187 22.8455 12.9948 22.8455H16.2671V20.0465C14.7878 19.8081 13.6558 18.5289 13.6558 16.9843C13.6558 15.4397 14.7878 14.160
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3605
            Entropy (8bit):4.1960028450107325
            Encrypted:false
            SSDEEP:96:33BS+F5US2jutyOYr9uJUBEL/cUPismtspu7zMS:33Ae5US2jutyOYWUCL0U92IS
            MD5:A5F53F1D6D82A380F431D540170CF8F9
            SHA1:6FE3BC4EBC9BD844A9F517357723F443CC5F822F
            SHA-256:43896C0FC9D34D138E29BC4DB15FC847452E734B0388E521F11E60D03875AA80
            SHA-512:D7DF5E5AB8B68E9A0D507F5AF652EC8D9975CBFEC6A4BFC9F87C10334A21D745A698F5E3D816CF9F531EA22FED94B24F501145CA7701592C5EF2B96F8E241111
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.5 10.123C3.5 9.8469 3.72386 9.62305 4 9.62305H16.767C17.0431 9.62305 17.267 9.8469 17.267 10.123V13.8822C17.267 14.1583 17.0431 14.3822 16.767 14.3822C15.5996 14.3822 14.6557 15.3253 14.6557 16.4843C14.6557 17.6433 15.5996 18.5864 16.767 18.5864C17.0431 18.5864 17.267 18.8103 17.267 19.0864V22.8455C17.267 23.1217 17.0431 23.3455 16.767 23.3455H13.4545C13.2146 24.822 11.9294 25.9477 10.3835 25.9477C8.83755 25.9477 7.5524 24.822 7.31245 23.3455H4C3.72386 23.3455 3.5 23.1217 3.5 22.8455V10.123ZM4.5 10.623V22.3455H7.77225C8.04839 22.3455 8.27225 22.5694 8.27225 22.8455C8.27225 24.0046 9.21614 24.9477 10.3835 24.9477C11.5508 24.9477 12.4947 24.0046 12.4947 22.8455C12.4947 22.5694 12.7186 22.3455 12.9947 22.3455H16.267V19.5465C14.7877 19.3081 13.6557 18.0289 13.6557 16.4843C13.6557 14.9397 14.7877 13.6605 16.267 13.422V10.623H4.5Z" fill="#21A452"
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):422
            Entropy (8bit):4.5898013780998514
            Encrypted:false
            SSDEEP:6:6v/lhP6x2/6TsR/BGsJfKl9WWWWWWWWWWWWWWWWWWWWWWWWWWWWWWrYp:6v/7SY/6Ts/Yvzy
            MD5:448E54ADF43419737206EDCC9AAEB374
            SHA1:817A49ED4777FB04334AF460FD32FEB76F9E4123
            SHA-256:DA8F4CC0BCD968FEFAA5300892D33AB1329C1902BBF90B422501746182EBDDAE
            SHA-512:E9F6BA5C49883555A2C8A18ADB8E05C771E71955ABC70AA88885EF570CE0791603975BD0B902703699DC5E738AC6756E8DE9D35542E97B038F74760B6238BE70
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR..............>a.....pHYs.................sRGB.........gAMA......a....;IDATx...... ...k.hv.A..8....;...'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..\J..:......IEND.B`.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):423
            Entropy (8bit):4.559637836137445
            Encrypted:false
            SSDEEP:6:6v/lhP6x2/6TsR/3cnKBcJWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWjVp:6v/7SY/6Ts/8Auj7
            MD5:8E6CB67468A8B02021ABE04D55017FB0
            SHA1:5C959EEA11F143EC2C664D0873A9857597F6565E
            SHA-256:2B36A7E3C8951AB3D564EBEE55EB75F841B1CFC3529C6A212BDD188E4526CA6A
            SHA-512:AE6FBE0ACD6BB7F752A03296D6A3A1C6C4BC292067D2F251CC283A1DEA99364EA0EA3EF7066797A6EF61E2D4DA219944E5863573E8315EC189AD0B1141FE486C
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR..............>a.....pHYs.................sRGB.........gAMA......a....<IDATx...1.. ..!5./...A.2.g.[d.E..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q....'@..q..}8s....k,....IEND.B`.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3085
            Entropy (8bit):4.1969024600993645
            Encrypted:false
            SSDEEP:96:hlhCs4rmwP1BgRpAUtYqC77vd6dUO8DFO4NMD0tvUF0ilCnzO464flWn:hl4snwdBg2UU5hPxtiACn
            MD5:61E3A890D2A3574CACDFE4540C83C5D9
            SHA1:FFBDF6F2EDF1B7A50CAC00A596F1C40EB41005B4
            SHA-256:C6E8097F30314CCFF38142F19F064F23087E60937D2D72AF095B29D66265863B
            SHA-512:A9CF55DA6E17A4DF8CF2DF79F6C93A0FBD3E3867C4DDAD691C277CEDABFC2E5A83935C44BE05801067CD800D7B1FD2F7B22E539138A7248C2BEBC342178A441F
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.93604 4.5C4.93604 4.22386 5.15989 4 5.43604 4H34.4942C34.7703 4 34.9942 4.22386 34.9942 4.5V18.16C34.9942 18.4361 34.7703 18.66 34.4942 18.66H5.43604C5.15989 18.66 4.93604 18.4361 4.93604 18.16V4.5ZM5.93604 5V17.66H33.9942V5H5.93604Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.93604 22.2695C4.93604 21.9934 5.15989 21.7695 5.43604 21.7695H34.4942C34.7703 21.7695 34.9942 21.9934 34.9942 22.2695V35.9295C34.9942 36.2057 34.7703 36.4295 34.4942 36.4295H5.43604C5.15989 36.4295 4.93604 36.2057 4.93604 35.9295V22.2695ZM5.93604 22.7695V35.4295H33.9942V22.7695H5.93604Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M5.48832 20.7578H5V19.7578H5.48832C5.76446 19.7578 5.98832 19.9817 5.98832 20.2578C5.98832 20.534 5.76446 20.7578 5.48832 20.7578ZM6.9416 20.2578C6.9416 19.9817 7.16546 19.7578 7.4416 19.7578H8
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3089
            Entropy (8bit):4.191498746226774
            Encrypted:false
            SSDEEP:96:dXTBWrhKXmSbSJAKtNncsHkafQ1C7PxQZ/R74xdIt4UrFfT1O9OGxayhMnM7:dXTYrhKX/bSAKtNncsHkaI1IPyZp74d5
            MD5:15D952C90BB393D038254AC741727835
            SHA1:B609A9DE0F2B9F4FAFD40C14969C849FDB34E9BD
            SHA-256:153B756B965210EA9237CEB330371795D0FB4F65F4E3EA95EDCB67BE33165494
            SHA-512:74064B6AE2A7607563F74D68DCC771AF78E3076219EC4155B48FB4033D21583FBB2003988A3A2FBFE99FBC243C44537B67B0A20C5C65EE6F179339C5DFDFF30A
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.93604 4C4.93604 3.72386 5.15989 3.5 5.43604 3.5H34.4942C34.7703 3.5 34.9942 3.72386 34.9942 4V17.66C34.9942 17.9361 34.7703 18.16 34.4942 18.16H5.43604C5.15989 18.16 4.93604 17.9361 4.93604 17.66V4ZM5.93604 4.5V17.16H33.9942V4.5H5.93604Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.93604 21.7695C4.93604 21.4934 5.15989 21.2695 5.43604 21.2695H34.4942C34.7703 21.2695 34.9942 21.4934 34.9942 21.7695V35.4295C34.9942 35.7057 34.7703 35.9295 34.4942 35.9295H5.43604C5.15989 35.9295 4.93604 35.7057 4.93604 35.4295V21.7695ZM5.93604 22.2695V34.9295H33.9942V22.2695H5.93604Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M5.48832 20.2578H5V19.2578H5.48832C5.76446 19.2578 5.98832 19.4817 5.98832 19.7578C5.98832 20.034 5.76446 20.2578 5.48832 20.2578ZM6.9416 19.7578C6.9416 19.4817 7.16546 19.2578 7.4416 19.25
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1853
            Entropy (8bit):4.494711233191695
            Encrypted:false
            SSDEEP:24:tKnguXMMHbDhsKcwZDQD0QjSie9MMfUlqcYoS1W+UAq6IcSWHBmrMiFIAd9Sie9g:gLbFXEDhecYojHAq6XOMV4F1vzvlaE
            MD5:CB9C0E1332FB24C16067754B1E26F8D8
            SHA1:3C3D9EC69C15991246A01344D2AA637D27079429
            SHA-256:B1DBA5318A6B804C9F96BC013C344F3F44192B8AAD4E3BC77B02D99377A6179C
            SHA-512:7D62B21D44805D4C8277AEA160008EDA820DD659F59219E2DD43C6B9C6B61F54EE57B785AE5909F69AA9FACF2FD72204C046AA3C06A83D42D1D37A38B162E9DD
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.4345 24.336C12.5433 24.2271 12.4935 24.0412 12.3448 24.0014L3.33063 21.586C3.18192 21.5462 3.04583 21.6823 3.08568 21.831L5.50103 30.8452C5.54087 30.9939 5.72677 31.0437 5.83563 30.9348L12.4345 24.336ZM6.10832 29.2479L10.7476 24.6087L4.41024 22.9106L6.10832 29.2479Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M7.89786 22.7056C8.40732 21.7816 9.08704 20.9596 9.90325 20.2842C10.7195 19.6087 11.6541 19.0948 12.6571 18.7672C12.7425 18.7393 12.8284 18.7128 12.9148 18.6876C12.9289 18.6835 12.9427 18.6788 12.9562 18.6735C13.1713 18.5893 13.302 18.3618 13.2485 18.1334C13.1916 17.8906 12.9483 17.7388 12.7086 17.8073C12.6931 17.8118 12.6776 17.8163 12.6621 17.8208C12.5638 17.8494 12.4661 17.8796 12.369 17.9115C11.2614 18.2743 10.2292 18.8424 9.32761 19.5885C8.42598 20.3346 7.67479 21.2422 7.11113 22.2624C7.0617 22.3519 7.01371
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1809
            Entropy (8bit):4.498090614963723
            Encrypted:false
            SSDEEP:24:tKT8FuXMMq/Q/yxmPKmQem49MMB8H7Uw4ma4eaumUtqPN0yj5SufVXnDm49MMotB:a8bYqjB17d4maCu8PN0GMuMDYYaxEl8S
            MD5:F6E258229E26CC498E539F41D5F201A8
            SHA1:F1CA58CD6203CFD721D59BDE0E5E7A2A8CEC182E
            SHA-256:8810BF8655B99E432D7E7173539FC22694FBCBD8185E78DCEB6368296F1AE126
            SHA-512:6CC0640281C1E464779F1AF1AD510A7117B79E5DAC5C05720E67BD6696214219E643CBF0D782C5AF84660B3E8668453F745B2B1A79DBD0B427E07B14457C7BFE
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.4347 23.836C12.5436 23.7271 12.4938 23.5412 12.3451 23.5014L3.33087 21.086C3.18216 21.0462 3.04608 21.1823 3.08592 21.331L5.50127 30.3452C5.54112 30.4939 5.72701 30.5437 5.83588 30.4348L12.4347 23.836ZM6.10857 28.7479L10.7478 24.1087L4.41048 22.4106L6.10857 28.7479Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M7.89761 22.2056C8.40708 21.2816 9.0868 20.4596 9.90301 19.7842C10.7192 19.1087 11.6539 18.5948 12.6569 18.2672C12.7423 18.2393 12.8282 18.2128 12.9145 18.1876C12.9287 18.1835 12.9425 18.1788 12.956 18.1735C13.171 18.0893 13.3017 17.8618 13.2482 17.6334C13.1914 17.3906 12.9481 17.2388 12.7084 17.3073C12.6929 17.3118 12.6774 17.3163 12.6619 17.3208C12.5636 17.3494 12.4659 17.3796 12.3688 17.4115C11.2611 17.7743 10.229 18.3424 9.32737 19.0885C8.42574 19.8346 7.67454 20.7422 7.11088 21.7624C7.06145 21.8519 7.01346
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):643
            Entropy (8bit):5.189850637261886
            Encrypted:false
            SSDEEP:12:trsdCtuticzwHkUdLOsdLOE48CBUUCmv133JlPKhllFkynzJiKcmSdJiHAie:tAdCtutrwHk4LPLB5Kd1nJlPKhllFkyy
            MD5:2982590260A53BBA74456D434DA8404A
            SHA1:C5EC3717962DE92907C3451874809415C219DE1E
            SHA-256:1A6CB151985062A3E493B314B43C3A9F9663FCE701EC3C6C24A751A9222DCCF0
            SHA-512:00B83827449B7C3F16C89C01706D95373AAC7F12839D6BE3CCFF3BFE782C58E898901825D4100F09C039B5F89D61E52EF8AD14826BC55C0EA79681D7C9860569
            Malicious:false
            Reputation:low
            Preview:<svg width="42" height="42" viewBox="0 0 42 42" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_11764_39986)">.<rect x="3.5" y="13.5" width="24" height="24" stroke="#262E30"/>.<rect x="14.5" y="4.5" width="24" height="24" stroke="#262E30"/>.<path d="M17.25 14L15 16.1M21 14L15 20.3M24.75 14L15 24.5M27 15.4L15.75 28M27 18.9L19.5 28M27 23.8L23.25 28" stroke="#00AE42" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<rect x="14.5" y="13.5" width="13" height="15" stroke="#00AE42"/>.</g>.<defs>.<clipPath id="clip0_11764_39986">.<rect width="42" height="42" fill="white"/>.</clipPath>.</defs>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):643
            Entropy (8bit):5.210756215670351
            Encrypted:false
            SSDEEP:12:trsdCtuticzwHkUdLFHNdLFHp48CBUUCmv133JlPKhllFkynzJiKcmSdJiHAie:tAdCtutrwHk4LFXLFJ5Kd1nJlPKhllFg
            MD5:CD20905C47A75A6A82D09E11F844B65C
            SHA1:8FE7CA3B47D377CD0A81A4ECD05D54710D02DDF0
            SHA-256:7B150CDAC4BDEDB2E0E21178F2F5239AB79E06B32B408B4EB05B308D704DD4BF
            SHA-512:6B67599140B8D3E0EB7C61DFED75688F2E112D146D9CC6B77E1CD53CECB7BE559F65E808D39E599E439D4C237A7EF43A4013BDB12F9522396FA3172A313775C7
            Malicious:false
            Reputation:low
            Preview:<svg width="42" height="42" viewBox="0 0 42 42" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_11764_39986)">.<rect x="3.5" y="13.5" width="24" height="24" stroke="#B6B6B6"/>.<rect x="14.5" y="4.5" width="24" height="24" stroke="#B6B6B6"/>.<path d="M17.25 14L15 16.1M21 14L15 20.3M24.75 14L15 24.5M27 15.4L15.75 28M27 18.9L19.5 28M27 23.8L23.25 28" stroke="#00AE42" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/>.<rect x="14.5" y="13.5" width="13" height="15" stroke="#00AE42"/>.</g>.<defs>.<clipPath id="clip0_11764_39986">.<rect width="42" height="42" fill="white"/>.</clipPath>.</defs>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):347
            Entropy (8bit):4.92475700848918
            Encrypted:false
            SSDEEP:6:tnr1tRC/oQJAumc4sl7uOBPfHHcW0nX4piQaRmM/nhMWxq9DwWovIvHDTxmM/nhm:tr1tCotu5BPvwIpBVMf2W4OuHDFmMf21
            MD5:C57A013C9536AA617E9DB6AA3285D567
            SHA1:26CA6918C12A66BE4010B8E4A6202CCBC3627FF7
            SHA-256:1ACC0B952B1CBD0D2EF4EDCE74ADBCAD5388DD988D77D300D59DA23B5DC8403E
            SHA-512:6B1D52112E2881FF78176BC80F905A3A502251A3336E2793C4558DE774C522EA46A99526860C6D952E0FB580E09E107087A1F3F086261C9B3FB3FA7FEFE22CA7
            Malicious:false
            Reputation:low
            Preview:<svg width="43" height="42" viewBox="0 0 43 42" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect x="13.9966" y="13.6648" width="13.7939" height="14.4547" fill="#B9C7CE"/>.<rect x="4.00488" y="4.46069" width="24.1147" height="24.1147" stroke="#262E30"/>.<rect x="14.4966" y="13.4246" width="24.1147" height="24.1147" stroke="#262E30"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):4388
            Entropy (8bit):3.92153798715895
            Encrypted:false
            SSDEEP:96:jImjIgtTnliKTtA7yNNComOAtIHW2SNrFf6+/EKvx8r1hZK/Sxw39k:0mjIeDliKyqmD2HW24Ff1sZRhqHk
            MD5:3B6C6ACBA8D16E53F98883AF343A2EEE
            SHA1:13366A2FABF5BE89324FDD44E35E372C5E61D08F
            SHA-256:67179E02FDFAA05CC218D755217A3069EED92098527055BEE80484318BF5CB98
            SHA-512:9A38290811C10B0BBAE079F1CE2403621DC98C05C36828AB96CD2F4E460BE51B487098B72054931E67576055C539A03244EA27278FC19B2AEBD58A4DA998FFFD
            Malicious:false
            Reputation:low
            Preview:<svg width="35" height="35" viewBox="0 0 35 35" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M18.2319 2.92265C18.4019 2.9249 18.5591 3.01341 18.6493 3.15761L33.8522 27.4823C33.9874 27.6986 33.9381 27.982 33.7378 28.1399C33.5947 28.2528 33.4443 28.3758 33.2841 28.5066C32.3626 29.2596 31.1207 30.2744 29.1189 31.1328C26.7685 32.1408 23.3924 32.9289 18.2253 32.9289C13.0577 32.9289 9.41503 32.1407 6.82329 31.1397C4.22658 30.1369 2.70661 28.9286 1.78223 28.1246C1.59289 27.9599 1.55495 27.6804 1.69354 27.4712L17.8084 3.14646C17.9023 3.00471 18.0619 2.9204 18.2319 2.92265ZM2.77192 27.6541C3.65977 28.3925 5.02043 29.3715 7.18356 30.2069C9.64262 31.1566 13.1603 31.9289 18.2253 31.9289C23.2906 31.9289 26.5266 31.1565 28.7248 30.2138C30.5887 29.4145 31.7223 28.4897 32.6409 27.7402C32.684 27.7051 32.7267 27.6703 32.7689 27.6359L18.213 4.34642L2.77192 27.6541Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M2.66192 26.9101C2.822
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2620
            Entropy (8bit):4.214972414580219
            Encrypted:false
            SSDEEP:48:jBmozlASv2GWitpV+XsxbhJU0qQANFeahi22+b5wAcehOCmNe7g/7JkI76:wwy4b7U7QUFeahi22+6BCoh1a
            MD5:82FFA6143DAAE567EE700702E9945E63
            SHA1:C008179B72F968E1D8527B9D2769C4CFF37928CB
            SHA-256:0DF597D88EFEB17236FD85ED9E12018DD3E988DE7904ADCF9E85B1B7D0612FFF
            SHA-512:46B85C6AF48AC5A28561679CD06D0DDDFDBF8A59C5A8CB4E13607F3FE26ABF3F2E424769CE88E25851DC1C83BECA8407568124837DD16F1319F105BF8642DB22
            Malicious:false
            Reputation:low
            Preview:<svg width="35" height="35" viewBox="0 0 35 35" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M17.0007 3.15607C17.0007 3.15609 17.0008 3.15605 17.0007 3.15607L5.26748 9.97446C5.0759 10.0857 4.8723 10.2988 4.71546 10.5713C4.55862 10.8438 4.47656 11.127 4.47656 11.349V24.4715C4.47656 24.6929 4.55879 24.9752 4.71606 25.2472C4.87328 25.5192 5.07737 25.7322 5.26956 25.8438L17.1143 32.6992C17.3061 32.8102 17.5904 32.8795 17.902 32.8782C18.2136 32.8768 18.4968 32.8049 18.6868 32.6927L30.2729 25.8523C30.2729 25.8522 30.2729 25.8523 30.2729 25.8523C30.4645 25.739 30.6677 25.524 30.8242 25.2501C30.9806 24.9761 31.0625 24.6919 31.0625 24.4693V11.2435C31.0625 11.0216 30.9805 10.7392 30.8238 10.4679C30.667 10.1966 30.4635 9.98491 30.2715 9.87455L18.582 3.15275C18.3912 3.04273 18.1054 2.97271 17.7915 2.97339C17.4777 2.97408 17.192 3.045 17.0007 3.15607ZM19.0809 2.28613C18.7002 2.0665 18.2304 1.97243 17.7893 1.9734C17.3481 1.97436 16.8787 2.07053 16.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1554
            Entropy (8bit):4.31589698839427
            Encrypted:false
            SSDEEP:24:t2sZuXMM1SkOd1J7M6nnpLtXBqCZwOwHQ4IG+9MMLl+nunWOL/lkTlHg8THYTWRr:jnDDnnpLtxqCZdvl+RObqTq8DYTeNl3
            MD5:E2C13FACA875FBFFCBDFA0E6E65DFD06
            SHA1:4D5EB61B85CA2C5C507ADB5DA296D217B0D43FD3
            SHA-256:A3E878D0FBCE41E970EBC356D77E982CF161616D1A0209DD204B65FDED135396
            SHA-512:4900DE94E29CE3F0557F618FA759EF9C55765455F5DFD68AD0BD6E1408A5034FE1FD8B4E3593288E08C59E6C89C5E9D3474B7A8907F89D020FB79C220BF0CC16
            Malicious:false
            Reputation:low
            Preview:<svg width="35" height="35" viewBox="0 0 35 35" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M28.9668 7.89524C29.5156 7.50686 29.5487 7.26489 29.5487 7.2226C29.5487 7.18031 29.5156 6.93834 28.9668 6.54996C28.4444 6.18023 27.6234 5.8064 26.519 5.47582C24.323 4.81849 21.2293 4.39746 17.7695 4.39746C14.3097 4.39746 11.216 4.81849 9.01994 5.47582C7.91552 5.8064 7.09461 6.18023 6.57215 6.54996C6.02334 6.93834 5.99023 7.18031 5.99023 7.2226C5.99023 7.26489 6.02334 7.50686 6.57215 7.89524C7.09461 8.26497 7.91552 8.6388 9.01994 8.96938C11.216 9.62672 14.3097 10.0477 17.7695 10.0477C21.2293 10.0477 24.323 9.62672 26.519 8.96938C27.6234 8.6388 28.4444 8.26497 28.9668 7.89524ZM17.7695 11.0477C24.8273 11.0477 30.5487 9.33517 30.5487 7.2226C30.5487 5.11003 24.8273 3.39746 17.7695 3.39746C10.7117 3.39746 4.99023 5.11003 4.99023 7.2226C4.99023 9.33517 10.7117 11.0477 17.7695 11.0477Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d=
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3800
            Entropy (8bit):4.054346990818828
            Encrypted:false
            SSDEEP:96:wMQwsf8G8RNNZkKHWrsX98xutE4TeBDB2A:weSRiBH+g8WFav2A
            MD5:8990E271A220E13B1C7C0859E6FEF742
            SHA1:F722274F8A57C764F3A89421028DC6A1007CB013
            SHA-256:B90E51E7EEC7A777ED00A0D77108048582B76FC317CA41301A38385638C3BDF7
            SHA-512:5C968C5CDDF8EB77BB5075B62DC85BD58D7A9183D740539AB5E8B888934F3CCD531C0AC12B0FFE6B9B3F329E0E85F55DB19562E54CF82A6B0EB41584238204F6
            Malicious:false
            Reputation:low
            Preview:<svg width="35" height="35" viewBox="0 0 35 35" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M17.4801 3C9.48294 3 3 9.48294 3 17.4801C3 25.4772 9.48294 31.9601 17.4801 31.9601C25.4772 31.9601 31.9601 25.4772 31.9601 17.4801C31.9601 9.48294 25.4772 3 17.4801 3ZM1 17.4801C1 8.37837 8.37837 1 17.4801 1C26.5817 1 33.9601 8.37837 33.9601 17.4801C33.9601 26.5817 26.5817 33.9601 17.4801 33.9601C8.37837 33.9601 1 26.5817 1 17.4801Z" fill="black"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M2.99897 17.4328C2.97507 16.9017 2.53696 16.4785 2 16.4785C1.44772 16.4785 1 16.9262 1 17.4785C1 18.0435 1.26141 18.5072 1.58135 18.8534C1.89569 19.1934 2.31077 19.4719 2.75976 19.7053C3.65972 20.1731 4.89555 20.5611 6.33679 20.8745C9.23581 21.5047 13.1905 21.8794 17.5192 21.8794C21.8496 21.8794 25.795 21.4946 28.6843 20.8593C30.1208 20.5434 31.3506 20.1541 32.2456 19.6888C32.6919 19.4567 33.1045 19.1807 33.4172 18.8446C33.7346 18.5036 33.9992 18.0427
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2786
            Entropy (8bit):4.18303242536012
            Encrypted:false
            SSDEEP:48:68qZ9kzYxLIEXOhFLjegB3bm7ZGjUuTEUmw7zOjyv5+yKdLIwyT49ctMoFzrudVM:oQxEXOhFPenVgTrOjHPLIw9utMoFzruo
            MD5:209F238F93DC7CF285E93D6D38282AA3
            SHA1:217893B18409F375B596039D63947744FB538871
            SHA-256:C581B7AE672077FB1AB908EC41BB9497104AD7C7484AC835AC886B5B6E79253D
            SHA-512:5B1248F4472DB20E644B63EB7EE75A7D2B3A03CFECAE892F2250586A86D7A8186188059A3AA044A12971B74CDBB6F6B1BDD6D7C48E9FE4CCA249D27594E7EE7B
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M10 17.3707C14.0707 17.3707 17.3707 14.0707 17.3707 10C17.3707 5.92935 14.0707 2.62939 10 2.62939C5.92935 2.62939 2.62939 5.92935 2.62939 10C2.62939 14.0707 5.92935 17.3707 10 17.3707ZM10 18.3707C14.623 18.3707 18.3707 14.623 18.3707 10C18.3707 5.37706 14.623 1.62939 10 1.62939C5.37706 1.62939 1.62939 5.37706 1.62939 10C1.62939 14.623 5.37706 18.3707 10 18.3707Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M8.93664 7.212C9.28438 7.19745 9.6393 7.18994 9.99983 7.18994C10.3604 7.18994 10.7153 7.19745 11.063 7.212L11.0212 8.21113C10.6875 8.19716 10.3465 8.18994 9.99983 8.18994C9.65316 8.18994 9.31218 8.19716 8.97845 8.21113L8.93664 7.212ZM13.1859 7.39813C13.9585 7.50435 14.6701 7.64869 15.2947 7.8252L15.0227 8.78751C14.4502 8.62572 13.7849 8.48989 13.0497 8.38881L13.1859 7.39813ZM4.705 7.8252C5.3296 7.64869 6.04112 7.50435 6
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):4462
            Entropy (8bit):4.209504709731756
            Encrypted:false
            SSDEEP:48:gSy0xp4CyfzTV1XiHpFmEFLV50i2PszK3s2zEkZb/aXpRhEEaD2KqD9Z4dDZBA6:bNxS5dVYUEfK7LhE+byZIlD2KqxmZx
            MD5:4396CE1F91564998DF5850E40255A421
            SHA1:788BBC91982835D700854FEA5B591B532F4C6727
            SHA-256:4D5147665EFA0BD8BCD9A642A9B020AE4C739C38888BA9C2095B61C6A236DD5B
            SHA-512:7B45D44EB23CE72BDF0518B282BA20F9913CBE412714049E6F2031684FA99F2BF1ADBBBEFDF8200DA659F3FF5854ED443D08FCCAECEE14319468BB6CEE6B0630
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M8.84595 14.3015C9.24443 14.4643 9.30707 14.8898 9.30707 15.1236V18.3529C9.30707 18.4739 9.40721 18.574 9.52806 18.574H12.156C12.8293 18.574 13.377 19.1219 13.377 19.7951V21.2268C13.377 21.9 12.8293 22.4479 12.156 22.4479H9.52806C9.40721 22.4479 9.30707 22.548 9.30707 22.669V25.9035C9.30707 26.1374 9.24443 26.5628 8.84595 26.7256C8.45003 26.8874 8.10697 26.6316 7.94149 26.466L2.85937 21.3779C2.37779 20.9031 2.38315 20.1257 2.85783 19.6508L7.94131 14.5613C8.10679 14.3958 8.45003 14.1398 8.84595 14.3015ZM8.30707 15.6101L3.56536 20.3574C3.47661 20.4462 3.48123 20.5871 3.56186 20.6662L3.56537 20.6697L8.30707 25.417V22.669C8.30707 21.9958 8.85478 21.4479 9.52806 21.4479H12.156C12.2768 21.4479 12.377 21.3479 12.377 21.2268V19.7951C12.377 19.674 12.2768 19.574 12.156 19.574H9.52806C8.85478 19.574 8.30707 19.0261 8.30707 18.3529V15.6101Z" fill="#00AE4
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):4475
            Entropy (8bit):4.2049265185221865
            Encrypted:false
            SSDEEP:96:jB/h8CLK/HGXY/QfOvwL7bmIYOLlitD0hDHe1TyPqhc:1/YPGXY/oO4L7bmElit49HeRyPqy
            MD5:6CEBF2666080A883796D49E090448D46
            SHA1:FD4A1F0421B8A663101BD49B9499E8E013935EA8
            SHA-256:B594D40307937E08B74334280A820C0EE4624D674F3C765E5EE167E4B246E349
            SHA-512:4F9DDA867956858ECA6ABF1FF36DB33CF306F0FC6E13258829D146558BC715FD94CB0755CE9781DEBD984C9AFFC4A477E4CCCFA7395EC5793E6441FBF2C2CB3E
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M8.84595 13.8015C9.24443 13.9643 9.30707 14.3898 9.30707 14.6236V17.8529C9.30707 17.9739 9.40721 18.074 9.52806 18.074H12.156C12.8293 18.074 13.377 18.6219 13.377 19.2951V20.7268C13.377 21.4 12.8293 21.9479 12.156 21.9479H9.52806C9.40721 21.9479 9.30707 22.048 9.30707 22.169V25.4035C9.30707 25.6374 9.24443 26.0628 8.84595 26.2256C8.45003 26.3874 8.10697 26.1316 7.94149 25.966L2.85937 20.8779C2.37779 20.4031 2.38315 19.6257 2.85783 19.1508L7.94131 14.0613C8.10679 13.8958 8.45003 13.6398 8.84595 13.8015ZM8.30707 15.1101L3.56536 19.8574C3.47661 19.9462 3.48123 20.0871 3.56186 20.1662L3.56537 20.1697L8.30707 24.917V22.169C8.30707 21.4958 8.85478 20.9479 9.52806 20.9479H12.156C12.2768 20.9479 12.377 20.8479 12.377 20.7268V19.2951C12.377 19.174 12.2768 19.074 12.156 19.074H9.52806C8.85478 19.074 8.30707 18.5261 8.30707 17.8529V15.1101Z" fill="#21A45
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2971
            Entropy (8bit):4.464760284826174
            Encrypted:false
            SSDEEP:48:gd9VsF1HV8cg4tHAnvSWzhxEKLsU9F1HV8cg4tHm9RBMyuPbNfaLSEe:MszxjgvrEwsqzxjGHBXuPbNiLY
            MD5:5DC889AE41DF7AF46C1D87273FE36086
            SHA1:ACBD52721315FD5334F0EDF67EAAF3E0285169B7
            SHA-256:B58C8ABD6A4ED0A71C30AB2617F38496B99555396DD5521024EB92318C98D5D5
            SHA-512:44E3DF5FA63B9EB51855F7D670AC21F599E61C8D882ED41096D9FC0DF5CE5299A67B918E65840CD093F79C36A6BF3BD9BA9CC6C40099C7CF5E518AB27D8FB1B7
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M0.5 13.5137C0.5 13.2375 0.723858 13.0137 1 13.0137H21.8591C22.1352 13.0137 22.3591 13.2375 22.3591 13.5137V34.5813C22.3591 34.8574 22.1352 35.0813 21.8591 35.0813H1C0.723858 35.0813 0.5 34.8574 0.5 34.5813V13.5137ZM1.5 14.0137V34.0813H21.3591V14.0137H1.5Z" fill="#2B3436"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.5539 3.1483C10.6478 3.0534 10.7758 3 10.9093 3H31.7736C31.9754 3 32.1574 3.12128 32.2351 3.30751C32.3127 3.49374 32.2709 3.7084 32.1289 3.85179L22.2156 13.8642C22.1217 13.9591 21.9938 14.0125 21.8603 14.0125H1.00123C0.79948 14.0125 0.617494 13.8912 0.539798 13.705C0.462102 13.5188 0.503921 13.3042 0.645833 13.1608L10.5539 3.1483ZM11.1179 4L2.19945 13.0125H21.6517L30.5749 4H11.1179Z" fill="#2B3436"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M31.963 3.0376C32.1505 3.1147 32.2728 3.29733 32.2728 3.50002V19.3287C32.27
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3006
            Entropy (8bit):4.466150881097051
            Encrypted:false
            SSDEEP:48:a8dxwzOiwJcdwAvEUxGXzH9Xyw/6wJcdwAvEUxmhF1++yS6klt83T9OrEPKf0nS:lxyOreoXzD/DeK7yS6Qt8jpPK8S
            MD5:B28A033A760D8AD97355D886E1282DC1
            SHA1:7C676D6269F3AF51D97D45D8C9187B3C5BA683E3
            SHA-256:408C662A3EA009A78E81ED158EB5C21277970FE82B504CDFD3680CE1B73609D3
            SHA-512:B6F1FA18BFBAE15BD0CEFD7D7CEB9C76E6A085FF3D13B2C84DCE865C0623A7F472E7406F9572709619575405769A5618680530EB078ECF04AE3E2D4E2DBD1767
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M0.5 13.0137C0.5 12.7375 0.723858 12.5137 1 12.5137H21.8591C22.1352 12.5137 22.3591 12.7375 22.3591 13.0137V34.0813C22.3591 34.3574 22.1352 34.5813 21.8591 34.5813H1C0.723858 34.5813 0.5 34.3574 0.5 34.0813V13.0137ZM1.5 13.5137V33.5813H21.3591V13.5137H1.5Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.5536 2.6483C10.6476 2.5534 10.7755 2.5 10.909 2.5H31.7734C31.9751 2.5 32.1571 2.62128 32.2348 2.80751C32.3125 2.99374 32.2706 3.2084 32.1287 3.35179L22.2153 13.3642C22.1214 13.4591 21.9935 13.5125 21.86 13.5125H1.00099C0.799236 13.5125 0.61725 13.3912 0.539554 13.205C0.461858 13.0188 0.503677 12.8042 0.645589 12.6608L10.5536 2.6483ZM11.1177 3.5L2.19921 12.5125H21.6515L30.5747 3.5H11.1177Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M31.9629 2.5376C32.1504 2.6147 32.2727 2.79733 32.2727 3.00002V18.82
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):4544
            Entropy (8bit):4.208743010499331
            Encrypted:false
            SSDEEP:96:GXMWcYoSMpYkMyKRo735gWNp6xp163p4O:5WcwpkMyL5gWLG763p4O
            MD5:FC498F4A5245391700CC4DE16333DC63
            SHA1:1A451F27BD0EFF737101C8DCE51713CD84D5F02B
            SHA-256:162935A1A520ECA2192BE2B630F12CEDE53B64F7E9A1D6CCF184BBA707B779F2
            SHA-512:76EB68BD18085A757BA5E7FDE52E811ACF900B504390B726E4000C2DC79B7037AD117E1E12F0C293BFF6AFD4B5BFCE4199BE2F1FC2B6339F991CFD2EC055DB81
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.4345 24.334C12.5434 24.2252 12.4936 24.0393 12.3449 23.9994L3.33066 21.5841C3.18195 21.5442 3.04586 21.6803 3.08571 21.829L5.50106 30.8432C5.54091 30.9919 5.7268 31.0417 5.83566 30.9329L12.4345 24.334ZM6.10835 29.246L10.7476 24.6067L4.41027 22.9086L6.10835 29.246Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M7.89783 22.7056C8.40729 21.7816 9.08701 20.9596 9.90322 20.2842C10.7194 19.6087 11.6541 19.0948 12.6571 18.7672C12.7425 18.7393 12.8284 18.7128 12.9148 18.6876C12.9289 18.6835 12.9427 18.6788 12.9562 18.6735C13.1713 18.5893 13.3019 18.3618 13.2484 18.1334C13.1916 17.8906 12.9483 17.7388 12.7086 17.8073C12.6931 17.8118 12.6776 17.8163 12.6621 17.8208C12.5638 17.8494 12.4661 17.8796 12.369 17.9115C11.2613 18.2743 10.2292 18.8424 9.32758 19.5885C8.42595 20.3346 7.67475 21.2422 7.1111 22.2624C7.06167 22.3519 7.01368
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):4443
            Entropy (8bit):4.208640400938917
            Encrypted:false
            SSDEEP:96:h1R4mU8PbMlDWnssuMvVHyypG0WDG7WDOzv/ewtS:hTnoDWnoMvVHyoxQ2/eqS
            MD5:DC0541EBEBA641DE85D98FC049B146E8
            SHA1:428B3F1C08675CA33E56BA4E5E35E718C63A3062
            SHA-256:1BF9A5EA87BA16EDDB6ADBB786E8EC30073A2C8F891D6969C7FF3C907D3342DF
            SHA-512:66CD00148DB559CDC01BC7E3F4047EBE97DB2C9D63605E32705E3730085F6DC9D601589607EB51AEA363AB57715DED83F430A38A31DB94F1D65FB0BF082E6B12
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.4347 23.836C12.5436 23.7271 12.4938 23.5412 12.3451 23.5014L3.33087 21.086C3.18216 21.0462 3.04608 21.1823 3.08592 21.331L5.50127 30.3452C5.54112 30.4939 5.72701 30.5437 5.83588 30.4348L12.4347 23.836ZM6.10857 28.7479L10.7478 24.1087L4.41048 22.4106L6.10857 28.7479Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M7.89761 22.2056C8.40708 21.2816 9.0868 20.4596 9.90301 19.7842C10.7192 19.1087 11.6539 18.5948 12.6569 18.2672C12.7423 18.2393 12.8282 18.2128 12.9145 18.1876C12.9287 18.1835 12.9425 18.1788 12.956 18.1735C13.171 18.0893 13.3017 17.8618 13.2482 17.6334C13.1914 17.3906 12.9481 17.2388 12.7084 17.3073C12.6929 17.3118 12.6774 17.3163 12.6619 17.3208C12.5636 17.3494 12.4659 17.3796 12.3688 17.4115C11.2611 17.7743 10.229 18.3424 9.32737 19.0885C8.42574 19.8346 7.67454 20.7422 7.11088 21.7624C7.06145 21.8519 7.01346
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):802
            Entropy (8bit):4.584015954620641
            Encrypted:false
            SSDEEP:24:t3JfDuXMMJYOuZNRpCEsZVmyBGydWfvYJXVJ2NrxedAy:3UYOuZNVsZxguarg
            MD5:F0BE0AFFCEB723DB06D81A98EC35BFD5
            SHA1:2AA4CBD0ED5114D88F2DE4E1F72190B2FBC0172C
            SHA-256:0907C7914104E45087E61C9B6A5BE07D10A038C2761EC16BF30D310282008DEF
            SHA-512:C441EFB459FA38FADF423059C7A414926E49087919BF46CDD06D0777C3DD3A04BD5B6AC6773114F6140071968F8277E23C9CA92BB113DC3247836768FEA22F61
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.6457 7C10.5448 7 10.4602 6.9247 10.4433 6.82524C10.1226 4.93741 8.47917 3.5 6.5 3.5C4.29086 3.5 2.5 5.29086 2.5 7.5C2.5 9.47929 3.93759 11.1228 5.82559 11.4434C5.92506 11.4603 6.00037 11.5448 6.00037 11.6457V12.7588C6.00037 12.8763 5.89925 12.9688 5.7827 12.9536C3.08405 12.6022 1 10.2945 1 7.5C1 4.46243 3.46243 2 6.5 2C9.29433 2 11.6019 4.08386 11.9536 6.78232C11.9688 6.89888 11.8763 7 11.7587 7H10.6457Z" fill="#FF6F00"/>.<path d="M11.1644 9.76271C11.0849 9.87751 10.9151 9.87751 10.8356 9.76271L8.6194 6.5639C8.5275 6.43126 8.62243 6.25 8.7838 6.25L13.2162 6.25C13.3776 6.25 13.4725 6.43126 13.3806 6.5639L11.1644 9.76271Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):705
            Entropy (8bit):4.566267229870671
            Encrypted:false
            SSDEEP:12:trLJfDuXM65pJv5FivbfnsmW1tKIEkY+MXA6bg4XO8IZQfDy:t3JfDuXMMp/FivDsmQtKIEkYY67XUZqG
            MD5:FC2FD56F58C6FA8D5DB693D74873852F
            SHA1:59B313876D2BE35B13918DB7890DD98826E75F00
            SHA-256:D0ABBB89CF205D949C425825867C842799E469ACE56B7572970A2B017C874A4E
            SHA-512:9430850851C6420B874125057D9C47BB700AFD65D5ECDE76927ACDC17F3185FE7AD4FE48F52A347F79C9F564534911D2E38998640D290993A401299365FC6832
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.2937 5.63794C9.71589 3.81838 8.01293 2.5 6.00204 2.5C3.51563 2.5 1.5 4.51563 1.5 7.00204C1.5 9.24293 3.13722 11.1014 5.28073 11.4466C5.38062 11.4627 5.4564 11.5475 5.4564 11.6486V12.7608C5.4564 12.8783 5.35522 12.9708 5.23861 12.956C2.28425 12.581 0 10.0583 0 7.00204C0 3.68721 2.68721 1 6.00204 1C8.84765 1 11.2307 2.98029 11.8484 5.63794H13.3662C13.5275 5.63794 13.6225 5.8192 13.5306 5.95184L11.0772 9.49295C10.9977 9.60775 10.8279 9.60775 10.7484 9.49295L8.29505 5.95184C8.20315 5.8192 8.29808 5.63794 8.45945 5.63794H10.2937Z" fill="#FF6F00"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1861
            Entropy (8bit):4.647536144569904
            Encrypted:false
            SSDEEP:48:gCsUDVaH2zQjhWg81yKmMiJ6/scgKdp1LY1aDS8eMaQ:QUUJwd1lH06Fgqp1UaDteMj
            MD5:26AFA3433E8DD9734A73DB2BF1A07C97
            SHA1:F40D29F98BFFD5E3BF332AE2875B34839E611E61
            SHA-256:E7BFEF73D3936AB90C90AE313D5A067C2B0FB5F45D932B1DE7298D8BA002E3C0
            SHA-512:5D40DE7C9541553A8D637222CE6CAA2F1DEA2F1A56E6E868616B885FBBD9290B19CD7E792DCBC047F40F92E1A0B94F43667140C626D5C9E1C8F5F40DD3F5F474
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_7034_29433)">.<path fill-rule="evenodd" clip-rule="evenodd" d="M31.0417 25.2279L19.728 13.9142L8.41432 25.2279L19.728 36.5416L31.0417 25.2279ZM19.728 12.5L7.00011 25.2279L19.728 37.9558L32.4559 25.2279L19.728 12.5Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M5.16318 25.3288C3.80438 22.3365 3.53064 18.9548 4.40407 15.7706C5.34279 12.3484 7.53755 9.4061 10.5503 7.53094C13.563 5.65578 17.172 4.98572 20.6571 5.65452C23.8997 6.2768 26.813 8.01557 28.8978 10.556C28.9586 10.63 29.0187 10.7048 29.078 10.7802C29.0837 10.7873 29.0894 10.7942 29.0954 10.801C29.2525 10.9788 29.5211 11.0138 29.7143 10.8715C29.9148 10.7238 29.9581 10.441 29.8045 10.2451C29.7986 10.2375 29.7926 10.2299 29.7867 10.2224C29.7225 10.1409 29.6576 10.0601 29.5919 9.98012C27.3739 7.27925 24.2755 5.43063 20.827 4.76885C17.1191 4.05727 13.2791 4.77019 10.0737 6.7653C6.86829 8.76041 4
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1844
            Entropy (8bit):4.612904520626604
            Encrypted:false
            SSDEEP:48:a87dtPGowxtfjul5fXiJYTNR+h/pcfkriKKH0P:jYKlZX0YhROpcMOKKHY
            MD5:6360BEE01FB5E691ED58821D16BE61E3
            SHA1:17BE4804EB7CA26923C448665E7B39D31CC828E7
            SHA-256:85840306FBF6C07C14466B5B2CEDC3DDCB77CCA8C046E72B732216E2FA49D148
            SHA-512:370499D12536D72AD3114E8520E622CF63AAA907E0DEED9DEA05EF55141666D27A55B946414835BAFFF8C31D4D3381BC2DFAB7E0FB12AF9698EAD0C9C9D39EDD
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_8432_56489)">.<path fill-rule="evenodd" clip-rule="evenodd" d="M31.0422 24.7269L19.7285 13.4132L8.41481 24.7269L19.7285 36.0407L31.0422 24.7269ZM19.7285 11.999L7.00059 24.7269L19.7285 37.4549L32.4564 24.7269L19.7285 11.999Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M5.16318 24.8288C3.80438 21.8365 3.53064 18.4548 4.40407 15.2706C5.34279 11.8484 7.53755 8.9061 10.5503 7.03094C13.563 5.15578 17.172 4.48572 20.6571 5.15452C23.8997 5.7768 26.813 7.51557 28.8978 10.056C28.9586 10.13 29.0187 10.2048 29.078 10.2802C29.0837 10.2873 29.0894 10.2942 29.0954 10.301C29.2525 10.4788 29.5211 10.5138 29.7143 10.3715C29.9148 10.2238 29.9581 9.94105 29.8045 9.74506C29.7986 9.7375 29.7926 9.72994 29.7867 9.72239C29.7225 9.64089 29.6576 9.56013 29.5919 9.48012C27.3739 6.77925 24.2755 4.93063 20.827 4.26885C17.1191 3.55727 13.2791 4.27019 10.0737 6.2653C6.86829
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2876
            Entropy (8bit):4.775637119149455
            Encrypted:false
            SSDEEP:48:gWsyXm/ANhIsn0b9xWt3GV4gOERqTaAw9llWiXdS8zfzRtGjZQPt1doplxHnHv0c:Jpsg0b9x0oUMlwy/G/39nHv0uKq
            MD5:3BF42A6F491897222D03C89E63AD1C18
            SHA1:0F03AAD3AD5BE9BBFB342A64E4677B5C3AF94FF1
            SHA-256:2BAA79301D21476FB63F00B1814FBD5CB0BD5D30EAB296A8FCBFDFE6CE3D9E86
            SHA-512:4A95D7CFF36FD028A13FFA3B94E27ABD4ED0579147421A20BB592E39A289C97E8480453998DA715A658DB5EDF49E78EAAA130C10205302044C132C44C5023CC0
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M35.0918 35.5914V34.6875H36.0918V36.5914H34.1879V35.5914H35.0918Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M8.26439 36.5918H6.71082V35.5918H8.26439V36.5918ZM14.4787 36.5918H11.3715V35.5918H14.4787V36.5918ZM20.693 36.5918H17.5858V35.5918H20.693V36.5918ZM26.9073 36.5918H23.8001V35.5918H26.9073V36.5918ZM31.568 36.5918H30.0144V35.5918H31.568V36.5918Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.5 35.5914V34.6875H3.5V36.5914H5.40393V35.5914H4.5Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.5 8.76484V7.21094H4.5V8.76484H3.5ZM3.5 14.9804V11.8726H4.5V14.9804H3.5ZM3.5 21.196V18.0882H4.5V21.196H3.5ZM3.5 27.4116V24.3038H4.5V27.4116H3.5ZM3.5 32.0733V30.5194H4.5V32.0733H3.5Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.50012 4.00195H5.40413V5.00195H4.50012V
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2901
            Entropy (8bit):4.784840737756296
            Encrypted:false
            SSDEEP:48:a8rL1M/gYxJQEAIbkp7QoxdYoxigfYwllA5wRWAh8yAc9vTPta4OyNqHNRybOS:j5M/gYxJQExbDofYoEgL6K8yAc9vTPtx
            MD5:7B3346137EBB94116E3DFF328EAAC9E8
            SHA1:D41FC4DB86212959C0244A702B38ADAB40C9BE2B
            SHA-256:AEC94325A93B3613949B2655C23611864E4FF5C3492787F47ECE3ECBE57E549B
            SHA-512:F37D80B924BA9D6A1C5D130A7F11F1D82B9D284D6D4BB28F5139C81B0CA50AE9D86767455DC1FBC1E33FC4C1B2A3B18AD5EB6970DE5DDCF1544E0DA2D70B7458
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M35.0919 35.0914V34.1875H36.0919V36.0914H34.188V35.0914H35.0919Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M8.26451 36.0918H6.71094V35.0918H8.26451V36.0918ZM14.4788 36.0918H11.3717V35.0918H14.4788V36.0918ZM20.6931 36.0918H17.586V35.0918H20.6931V36.0918ZM26.9074 36.0918H23.8003V35.0918H26.9074V36.0918ZM31.5681 36.0918H30.0146V35.0918H31.5681V36.0918Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.5 35.0914V34.1875H3.5V36.0914H5.40393V35.0914H4.5Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.5 8.26484V6.71094H4.5V8.26484H3.5ZM3.5 14.4804V11.3726H4.5V14.4804H3.5ZM3.5 20.696V17.5882H4.5V20.696H3.5ZM3.5 26.9116V23.8038H4.5V26.9116H3.5ZM3.5 31.5733V30.0194H4.5V31.5733H3.5Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.5 3.50195H5.40401V4.50195H4.5V5.4059
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3166
            Entropy (8bit):4.398139586302197
            Encrypted:false
            SSDEEP:96:wkeD/c+bDvJkeDQFe1OoZdtXe3ycf1P8ZXqz6:STbDTkYleCcdP8ZaW
            MD5:89C01A5D1661A20B99E4BFDAF96011C8
            SHA1:E1C798E23B2078639F6EBDBD0465EF8714420D7B
            SHA-256:D82FEFEB7FAC43D2BAF9CDF9944F9E887A2B2C188FE07E4E3A70EF94E58CC815
            SHA-512:098CC55484A669603D6E259E0FFDF328CDF3D2CB24CF403DA50259A6D7086B4AFE280B6716F9788D6B84015DA733A7146B8C714BB6C6AE9CF934AAD1BA801F03
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M14.5713 4.14955C14.6653 4.05389 14.7938 4 14.9279 4H35.8208C36.0223 4 36.204 4.12088 36.2819 4.30664C36.3598 4.49241 36.3186 4.70677 36.1775 4.85045L26.2495 14.9534C26.1555 15.0491 26.027 15.103 25.8929 15.103H5.00001C4.79858 15.103 4.61681 14.9821 4.53891 14.7963C4.46102 14.6106 4.5022 14.3962 4.64338 14.2525L14.5713 4.14955ZM15.1376 5L6.19236 14.103H25.6832L34.6285 5H15.1376Z" fill="#262E30"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M36.0101 4.03724C36.198 4.11412 36.3208 4.29699 36.3208 4.50002V25.7984C36.3208 25.9295 36.2693 26.0553 36.1774 26.1488L26.2495 36.2518C26.1071 36.3966 25.8914 36.441 25.7035 36.3641C25.5156 36.2873 25.3928 36.1044 25.3928 35.9014V14.603C25.3928 14.4719 25.4443 14.346 25.5362 14.2525L35.4641 4.14956C35.6064 4.00475 35.8222 3.96037 36.0101 4.03724ZM26.3928 14.8075V34.6792L35.3208 25.5938V5.7222L26.3928 1
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3183
            Entropy (8bit):4.394624934227451
            Encrypted:false
            SSDEEP:96:pecnXRUfB+ecnjNZT86IjfC+cZsQsbiUS:XXRUGjk6Ij1QseUS
            MD5:49679AA70099CD5D8736B0EAB94EFF15
            SHA1:5F7A9DB7628EDA254B09DCADB4BD0A8EBAE556B7
            SHA-256:13D03499C14574CA731EFC6C95C4115CF293645AA817D2979DFFDDC8704ADAD3
            SHA-512:AC458D7A905C19060E409D8DF5A2F11F3E180DE3511BE7CFA304700FE85E0BDC594A884C14681184149145BB7631834B65E3BA3851D1733DFA2C40C71C5B3340
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M14.5713 3.64955C14.6653 3.55389 14.7938 3.5 14.9279 3.5H35.8208C36.0223 3.5 36.204 3.62088 36.2819 3.80664C36.3598 3.99241 36.3186 4.20677 36.1775 4.35045L26.2495 14.4534C26.1555 14.5491 26.027 14.603 25.8929 14.603H5.00001C4.79858 14.603 4.61681 14.4821 4.53891 14.2963C4.46102 14.1106 4.5022 13.8962 4.64338 13.7525L14.5713 3.64955ZM15.1376 4.5L6.19236 13.603H25.6832L34.6285 4.5H15.1376Z" fill="#B6B6B6"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M36.0103 3.53724C36.1982 3.61412 36.321 3.79699 36.321 4.00002V25.2984C36.321 25.4295 36.2695 25.5553 36.1776 25.6488L26.2497 35.7518C26.1074 35.8966 25.8917 35.941 25.7037 35.8641C25.5158 35.7873 25.3931 35.6044 25.3931 35.4014V14.103C25.3931 13.9719 25.4446 13.846 25.5364 13.7525L35.4644 3.64956C35.6067 3.50475 35.8224 3.46037 36.0103 3.53724ZM26.3931 14.3075V34.1792L35.321 25.0938V5.2222L26
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1502
            Entropy (8bit):4.597511409783738
            Encrypted:false
            SSDEEP:24:tKT8FuXMMpTAjbFToY1I66QWbCrkXrS7iBMWMLbmTjq9MM8ZWTkkXtITTF4L/q8a:a8OQbJoYv6Q6W4mWBXyIlZWTk5WLhFWv
            MD5:A7FE3CBB828E1ABA8E8C7DAA4A492115
            SHA1:99CE07BBBDE9C68CED325253213EEC0DEDE057D1
            SHA-256:0C7C8CFE429CDB7D46EED7BF8B955402CB3252DF9FA597E8032016381D9093ED
            SHA-512:76F4A79D83B9198CBCB6E844A8CEA4A40E5720CD9028336A10E4FEAC5EA450FE194325BF0F525A5C3C8B2939F65EAFFA378F9A7ACE9553F97F7C2D6341591D81
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M4.5 3C4.5 2.72386 4.72386 2.5 5 2.5H24.4325C24.5652 2.5 24.6924 2.55271 24.7861 2.64654L28.5011 6.36338C28.5948 6.45714 28.6475 6.58428 28.6475 6.71684V8.56239C28.6475 8.83853 28.4236 9.06239 28.1475 9.06239H11.4439V31.4596C11.4439 31.7358 11.2201 31.9596 10.9439 31.9596H5C4.72386 31.9596 4.5 31.7358 4.5 31.4596V3ZM5.5 3.5V30.9596H10.4439V8.56239C10.4439 8.28624 10.6678 8.06239 10.9439 8.06239H27.6475V6.92388L24.2253 3.5H5.5Z" fill="#2B3436"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.4438 8.5625C10.4438 8.28636 10.6677 8.0625 10.9438 8.0625H30.7653C30.9017 8.0625 31.0322 8.11824 31.1265 8.21679L34.4525 11.692C34.5416 11.7851 34.5913 11.9089 34.5913 12.0377V37.0222C34.5913 37.2983 34.3675 37.5222 34.0913 37.5222H10.9438C10.6677 37.5222 10.4438 37.2983 10.4438 37.0222V8.5625ZM11.4438 9.0625V36.5222H33.5913V12.2384L30.5517 9.0625H11.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2047
            Entropy (8bit):4.896183118299394
            Encrypted:false
            SSDEEP:24:tKnguXMMvIcZbsn3xADn2bRgSie9MMLzSie9MMtySie9MMTEASie9MMTK3Sie9Ml:gkcVsn3DRaFX9+MM1xsIM
            MD5:6E0EF56BE37F2CFBDDFDC9A8690A6B53
            SHA1:A494BB29D2800483264A94C7D13C3F5330543A7E
            SHA-256:1E01B11B34C97684187ED240F31ED25507156A3EE7C5CDB541D7E7BBC354E3EB
            SHA-512:37D1D15A3BB6EE4A73B97E2E46A48FEB44E9BCEDA5149B2BCC796EA30E5B7B584D96E97D58F5B0504093B1B1DF11105BC324042FE042BC32BD507FCA334409C1
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.3252 18.1621C6.3252 17.886 6.54905 17.6621 6.8252 17.6621H17.7751C18.0513 17.6621 18.2751 17.886 18.2751 18.1621V35.9297C18.2751 36.2058 18.0513 36.4297 17.7751 36.4297H6.8252C6.54905 36.4297 6.3252 36.2058 6.3252 35.9297V18.1621ZM7.3252 18.6621V35.4297H17.2751V18.6621H7.3252Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.46857 20.0913L8.70794 17.8125L9.42119 18.5134L7.18183 20.7922L6.46857 20.0913Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.53058 23.4714L12.0914 17.8125L12.8047 18.5134L7.24384 24.1723L6.53058 23.4714Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.46863 26.9781L15.4776 17.8125L16.1908 18.5135L7.1818 27.6791L6.46863 26.9781Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.46851 30.4239L17.4678 19.2285L18.1811 19.9293L7.18183 31.1
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2054
            Entropy (8bit):4.875669456875355
            Encrypted:false
            SSDEEP:24:tKT8FuXMMWIOgeyOyDlZ40cm49MMx3i2JOSm49MMsWom49MM3uRm49MMBNg63Obz:a8vvy7QNyUr9YSK8OKGsX1LMoAZPdLL
            MD5:37446DD3E86B8E75D706957C77132CB5
            SHA1:389A04800D3967013AF8BF8854EAF5009A048192
            SHA-256:07399544EAFF3A5F5EF36BD3FF8B1274D1F2C9BBC0174BD30C48D0CE7E042FB6
            SHA-512:94216BA95128484034EE6F5B419A164FB09F4932D3DCA2F85FC9CB84BD58A3006E1AF9C6CCA7725384DF87B921E76D2BCB261D7CCDCCE821CFAA5F217762359B
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.3252 17.6621C6.3252 17.386 6.54905 17.1621 6.8252 17.1621H17.7751C18.0513 17.1621 18.2751 17.386 18.2751 17.6621V35.4297C18.2751 35.7058 18.0513 35.9297 17.7751 35.9297H6.8252C6.54905 35.9297 6.3252 35.7058 6.3252 35.4297V17.6621ZM7.3252 18.1621V34.9297H17.2751V18.1621H7.3252Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.46875 19.5904L8.70812 17.3115L9.42138 18.0124L7.18201 20.2913L6.46875 19.5904Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.53076 22.9704L12.0916 17.3115L12.8049 18.0124L7.24402 23.6713L6.53076 22.9704Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.46875 26.4772L15.4778 17.3115L16.1909 18.0125L7.18192 27.1782L6.46875 26.4772Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.46875 29.9229L17.4681 18.7275L18.1814 19.4284L7.18208 30.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3113
            Entropy (8bit):4.079522565619838
            Encrypted:false
            SSDEEP:48:gxgLqd7BpnYsWg4sNhM2VQAuE7rb/9z/Od63V0apLmaNVIQRynaJi7KOiXl:+wLsWg7VQ+7rbflHBNByaE7ri1
            MD5:12DF0840515D03CDEFB4D75927157E09
            SHA1:AA9911DFC9AB26778E55D6B37E57C339F69AE299
            SHA-256:AA4605F47197633D54502C066585BB4AC268515127C553F3DF4B1CB4333648C5
            SHA-512:69B301EE02C0516C90153B9C1D24101BC3C25B9B98CE2F300603F59B44FFCF3D8EBF98266DD35983BD8DDAB97DEC8243A315FC979ABCE16A2C1F521907C39B73
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="41" viewBox="0 0 40 41" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M5.5 5V9.44653H13.3165C13.8704 9.44653 14.3091 9.89686 14.3091 10.4441V35.2513H19.9173V10.4441C19.9173 9.89686 20.3561 9.44653 20.91 9.44653H28.7479V5H5.5ZM4.5 4.9976C4.5 4.45033 4.93873 4 5.49267 4H28.7552C29.3092 4 29.7479 4.45033 29.7479 4.9976V9.44894C29.7479 9.99623 29.3092 10.4465 28.7552 10.4465H20.9173V35.2537C20.9173 35.8009 20.4786 36.2513 19.9247 36.2513H14.3018C13.7478 36.2513 13.3091 35.8009 13.3091 35.2537V10.4465H5.49267C4.93875 10.4465 4.5 9.99623 4.5 9.44894V4.9976Z" fill="#00AE42"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M30.6779 23.6992C30.0689 23.6992 29.3177 23.7852 28.4197 23.9751L28.4182 23.9754C27.6749 24.1302 27.073 24.3232 26.6099 24.5434V26.109C27.7461 25.4864 28.9492 25.171 30.2173 25.171C30.9889 25.171 31.6598 25.349 32.1511 25.782C32.6487 26.2205 32.8833 26.8506 32.9229 27.5858L32.9231 27.5891C32.9414 27
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3117
            Entropy (8bit):4.076897184229268
            Encrypted:false
            SSDEEP:48:a8g2dWIYXD+MNP/ktbf6zdW4qBH/Ae0NzhOAbcqRALQW0TgIA73+RZc6fYFX:YXTNN3mbiJeH/JoOAAqRAqTgIAL+Yb
            MD5:B4C77AD24AC877433FBD4BF56B1E9A72
            SHA1:903B7DC206BF06E94E083C09F47B3DBF8FF901BA
            SHA-256:58632A6503C66532FEFEB68F6447589F3AB89136EADA1D28E9FFD8B00084468B
            SHA-512:CF4C8F2BA3E9B2189F1640E19A089098AF6AD9716CE9D2447BC01655A3F93CD4861A5370CC4BAEF00196D473AF8F7D5D6AF29ECDDC7C9A1C19C96264E2906AA1
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M5.5 4.5V8.94653H13.3165C13.8704 8.94653 14.3091 9.39686 14.3091 9.94413V34.7513H19.9173V9.94413C19.9173 9.39686 20.3561 8.94653 20.91 8.94653H28.7479V4.5H5.5ZM4.5 4.4976C4.5 3.95033 4.93873 3.5 5.49267 3.5H28.7552C29.3092 3.5 29.7479 3.95033 29.7479 4.4976V8.94894C29.7479 9.49623 29.3092 9.94653 28.7552 9.94653H20.9173V34.7537C20.9173 35.3009 20.4786 35.7513 19.9247 35.7513H14.3018C13.7478 35.7513 13.3091 35.3009 13.3091 34.7537V9.94653H5.49267C4.93875 9.94653 4.5 9.49623 4.5 8.94894V4.4976Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M30.6776 23.1992C30.0687 23.1992 29.3174 23.2852 28.4194 23.4751L28.418 23.4754C27.6747 23.6302 27.0728 23.8232 26.6097 24.0434V25.609C27.7458 24.9864 28.949 24.671 30.2171 24.671C30.9887 24.671 31.6595 24.849 32.1508 25.282C32.6485 25.7205 32.8831 26.3506 32.9227 27.0858L32.9228 27.0891C3
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1469
            Entropy (8bit):4.78492454114836
            Encrypted:false
            SSDEEP:24:tB8CuXMMfDQzVm0xlCAI8LSyB/Xg5IASiedjSieDSieuEySiekWXzNtASieJIz1F:s5UzVmd58LSyBfg5gzNVEnblTA+0UDWK
            MD5:26D21BCC9BB65FA17F05C2E2E1FA4AB8
            SHA1:A317AA4D56236459577A95E705074F7976EF824A
            SHA-256:D7138FAD073B65D00F323A7A618262B51625D979DE4F6AFC7CAE96E4655FF030
            SHA-512:54FD594B6531C0791549705329F415199E2287F299D9A5F31906CB6BA6F5CD8009020C1982D7AAAE2870BEAC66AB7ACF6AE3F4DB9F80B8660616EA7F0C23DA76
            Malicious:false
            Reputation:low
            Preview:<svg width="30" height="22" viewBox="0 0 30 22" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M6.51452 4.99991C5.66891 4.99991 4.99995 5.66991 4.99995 6.47171V15.6783C4.99995 16.4801 5.66891 17.1501 6.51452 17.1501H23.0855C23.9311 17.1501 24.6001 16.4801 24.6001 15.6783V6.47171C24.6001 5.66991 23.9311 4.99991 23.0855 4.99991H6.51452ZM4 6.47171C4 5.09757 5.13697 4 6.51452 4H23.0855C24.463 4 25.6 5.09757 25.6 6.47171V15.6783C25.6 17.0524 24.463 18.15 23.0855 18.15H6.51452C5.13697 18.15 4 17.0524 4 15.6783V6.47171Z" fill="#00AE42"/>.<path d="M10.3222 10.1983H6.73835V11.9506H10.3222V10.1983Z" fill="#00AE42"/>.<path d="M13.9034 10.1983H12.113V11.9506H13.9034V10.1983Z" fill="#00AE42"/>.<path d="M17.4869 10.1983H15.6966V11.9506H17.4869V10.1983Z" fill="#00AE42"/>.<path d="M15.6971 7.13181H13.9067V8.88414H15.6971V7.13181Z" fill="#00AE42"/>.<path d="M12.1128 7.13181H10.3225V8.88414H12.1128V7.13181Z" fill="#00AE42"/>.<path d="M8.52929 7.13181H6.7
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1446
            Entropy (8bit):4.8229544985368635
            Encrypted:false
            SSDEEP:24:tB8CuXMMy1IJyEgeB6tQDFv8oWuSieQMbSieDvjrYbSieTcCbSie1Sien6Siep4p:sk1Io2o2tMUvjrYIcCJm/gZu
            MD5:EC04435C7D587B791F1CF33ECD5851B5
            SHA1:1A3070B709F6DB08609133A9492E39C909DB9A84
            SHA-256:F2A06A6FFB07384029D786B185F5CAACD14A51387286834C27A2DEEFB0F04821
            SHA-512:E4CE50F31CFCA224BF59076715CF31CA0973FF4D7460A877221289C71D60C6C3BF758BADE614126EF0A5FC64B88BD3F4C5F6562E0F006BA05311D820F9F00ED3
            Malicious:false
            Reputation:low
            Preview:<svg width="30" height="22" viewBox="0 0 30 22" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M5.02092 4.20131C4.00501 4.20131 3.20133 5.00625 3.20133 5.96954V17.0305C3.20133 17.9938 4.00501 18.7987 5.02092 18.7987H24.9291C25.945 18.7987 26.7487 17.9938 26.7487 17.0305V5.96954C26.7487 5.00625 25.945 4.20131 24.9291 4.20131H5.02092ZM2 5.96954C2 4.31864 3.36594 3 5.02092 3H24.9291C26.5841 3 27.95 4.31864 27.95 5.96954V17.0305C27.95 18.6814 26.5841 20 24.9291 20H5.02092C3.36594 20 2 18.6814 2 17.0305V5.96954Z" fill="#00AE42"/>.<path d="M9.59541 10.4467H5.28983V12.552H9.59541V10.4467Z" fill="#00AE42"/>.<path d="M13.8978 10.4467H11.7469V12.552H13.8978V10.4467Z" fill="#00AE42"/>.<path d="M18.203 10.4467H16.0521V12.552H18.203V10.4467Z" fill="#00AE42"/>.<path d="M16.0527 6.7626H13.9018V8.86787H16.0527V6.7626Z" fill="#00AE42"/>.<path d="M11.7467 6.7626H9.59576V8.86787H11.7467V6.7626Z" fill="#00AE42"/>.<path d="M7.44144 6.7626H5.29052V8.86787H7.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):683
            Entropy (8bit):5.158737370184265
            Encrypted:false
            SSDEEP:12:trsdhouCCQmmfjAJlHclt4CQRghtjGdJlHclt4CQOyL61NJlHclt4CQdHW63hHcS:tAdhouwVAJlHcltmqtjiJlHcltmOzJlZ
            MD5:9D21524B2670FC5E5984389D12DD88CB
            SHA1:B69EAFE93BB69493F82DBFC1BE7EB8B95B2182EA
            SHA-256:D71474C1E82CE1BA6B678B49EF47EFAA3BC616AF118B0ACC18741F62D4CB30CF
            SHA-512:47102C8E54727F2B9251526E46A1F4D4DA73109FF51BA7E830B610D00FAF0F192A2C638077F4DD55606546263A7A7216B3DB2C61270864BAB66E4ACAE7B483FF
            Malicious:false
            Reputation:low
            Preview:<svg width="42" height="43" viewBox="0 0 42 43" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M35.5 23.2715H6.5V27.6602H35.5V23.2715Z" stroke="#00AE42" stroke-miterlimit="10" stroke-linejoin="round"/>.<path d="M35.5 17.3281H6.5V20.4512H35.5V17.3281Z" stroke="#00AE42" stroke-miterlimit="10" stroke-linejoin="round"/>.<path d="M35.5 12.3008H6.5V14.5078H35.5V12.3008Z" stroke="#00AE42" stroke-miterlimit="10" stroke-linejoin="round"/>.<path d="M35.5 8.48047H6.5V9.48047H35.5V8.48047Z" stroke="#262E30" stroke-miterlimit="10" stroke-linejoin="round"/>.<path d="M35.5 30.4805H6.5V35.4805H35.5V30.4805Z" stroke="#262E30" stroke-miterlimit="10" stroke-linejoin="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1509
            Entropy (8bit):4.750008065332757
            Encrypted:false
            SSDEEP:24:tKT8FuXMMYYGSxcMXXLIpKm49MMCgSEkKVyKm49MMCQPSTwJVVLAKm49MMNnScPb:a8//scgXLIptpgZkYytpmXV+tQnVPgxY
            MD5:D4EAB6A10B5C6D1B07F578624510E957
            SHA1:F901E36B3F764B3B78A949C7B04F0B190452EF31
            SHA-256:C485A4EB80013F9EE87FD6AAB8B6F4C33932D22FF55D29B14696FEBADEAE6BA1
            SHA-512:45425AB94578E16BC991FC5ED0B6E2915F9F9C93DFC4A21385BAA9C714031D3D967B600029AA8E2EA1C4285C0836906BCAAB91181D7B68F5EA32AA4A57735052
            Malicious:false
            Reputation:low
            Preview:<svg width="40" height="40" viewBox="0 0 40 40" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M5 21.2715C5 20.9953 5.22386 20.7715 5.5 20.7715H34.5C34.7761 20.7715 35 20.9953 35 21.2715V25.6602C35 25.9363 34.7761 26.1602 34.5 26.1602H5.5C5.22386 26.1602 5 25.9363 5 25.6602V21.2715ZM6 21.7715V25.1602H34V21.7715H6Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M5 15.3281C5 15.052 5.22386 14.8281 5.5 14.8281H34.5C34.7761 14.8281 35 15.052 35 15.3281V18.4512C35 18.7274 34.7761 18.9512 34.5 18.9512H5.5C5.22386 18.9512 5 18.7274 5 18.4512V15.3281ZM6 15.8281V17.9512H34V15.8281H6Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M5 10.3008C5 10.0246 5.22386 9.80078 5.5 9.80078H34.5C34.7761 9.80078 35 10.0246 35 10.3008V12.5078C35 12.7839 34.7761 13.0078 34.5 13.0078H5.5C5.22386 13.0078 5 12.7839 5 12.5078V10.3008ZM6 10.8008V12.0078H34V10.8008H6Z" fill="#21A452"/>.<path fill-rule="evenodd" clip-rule="eveno
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 18 x 18, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):199
            Entropy (8bit):6.464601759150598
            Encrypted:false
            SSDEEP:6:6v/lhPW/GjGXjIuVaNpGN5CJ6VcKnXnuEp:6v/7uaesuSpGrKnKnXnuG
            MD5:3407E2891A1CA23ED1DC1A3C36BF99F8
            SHA1:C84C7C64C29179A4BDA640A042DA489AD3A0E6BC
            SHA-256:01D417F1BB0DB77D917DFCF8DFFA163A635AAE954972487714833C59CDAABABC
            SHA-512:40D23DA56784B4691728B34028279507BA1A90352DBFCBA7A911BDF649F77C2297B5412101535279AFFA2AA09F2208460A60D9AB273752400425C21EAD9929CC
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............V.W....IDAT8.....!.E.\.@....4....K%.D.^.AA..r.L...?/..Os...9.......3.p.7.s......^..l`..z""...Z+b..$....@c..<.......W;7.).)%6.Z.....Z.....B@).....A.L......IEND.B`.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1510
            Entropy (8bit):4.072653936100841
            Encrypted:false
            SSDEEP:24:twdmluKJtJrChCSIy8v6MX0UFOmSJHJ/953ayPBXWPsf3NyShkAhXwoNfSE07rl:68TxChCvZPEJbz5Kop3NTdwuv6Z
            MD5:3CB61ECDFA8DF10218D86201C2B4C8FD
            SHA1:C42C18BCF1324F407A2E2C249189DF8C4EAB1DA1
            SHA-256:F9311B15879AC652927151EF7ED4F87BFE5B64D63B73F9408EF413E7F974BDE0
            SHA-512:802B609F81666C8B9155BA4F6EA4C225C7233EE24F2701B816D520133B42CE237B9167B815789B05274F975663FB0CCD94872D1767302E27252DA7A540E5F7C5
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M16.992 17.4421C16.8521 15.3781 15.8193 13.4579 14.1584 12.1736L14.0586 12.1054L14.0577 12.1066C13.9632 12.0495 13.8555 12.019 13.7448 12.019C13.3641 12.019 13.1367 12.2003 13.1367 12.504C13.1367 12.6808 13.2196 12.8471 13.3585 12.96L13.3568 12.9626L13.445 13.0249C14.8378 14.0081 15.622 15.4995 15.7756 17.4583L15.7773 17.4798C15.7759 17.4962 15.7751 17.5127 15.7751 17.5297C15.7751 17.8606 16.0469 18.129 16.382 18.129C16.706 18.129 16.9705 17.8785 16.9879 17.5628H17L16.992 17.4421ZM15.0378 7.404C15.0378 4.42429 12.5535 2 9.50005 2C6.44635 2 3.96207 4.42429 3.96207 7.404C3.96207 9.00946 4.6808 10.5068 5.9407 11.5394C3.67916 12.7314 2.17816 15.0052 2.00832 17.5158L2.00132 17.6203C2.00132 17.6225 2.00107 17.6246 2.00083 17.6268L2.00011 17.6365C1.99987 17.6415 2.00011 17.6468 2.00011 17.6518C2.00011 17.9324 2.23034 18.16 2.5147 18.16C2.79881 18.16 3.02928 17.9324 3.02928 17.6518C3.02928
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):282
            Entropy (8bit):4.964680628542868
            Encrypted:false
            SSDEEP:6:tnr0Qol8kAumc4slr+SvctIpF9smqZFImSvUN4vcy9smqZR:tr0dmkAuUSvctUihPSvo4vcyihR
            MD5:C276A19C01BBED40F1490279A9D8EA75
            SHA1:449AC5953B5750EA15E56A4E6B8FA23A2AF6B2CF
            SHA-256:955ECAF9E3F7DE0E09C537E7571226A20A57F85190ACA18DA482B041DDA205A3
            SHA-512:B3BBE860735593D5627F821894BAEC595648C695C97D59E10B4BADD56201A1998B39A2B5CE81BB41E9B09E37F2D270B9B1538914291FC084B7390064BAB232E8
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<line x1="5.70711" y1="6" x2="15" y2="15.2929" stroke="#EBEBEB" stroke-linecap="round"/>.<line x1="15" y1="5.70711" x2="5.70711" y2="15" stroke="#EBEBEB" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):197
            Entropy (8bit):5.101279977196751
            Encrypted:false
            SSDEEP:6:tnrLJUGFcAumc4slvIDzCcM6B6kAHw6mqZR:trLJfDuCNIkAHFhR
            MD5:743ACABC51351A461B491DDA06A5368D
            SHA1:75A007074BB3248B278D21C69FF1009DBC16AA39
            SHA-256:92553C35410AE8844874B7FE3356472931A1F9930FB2910CFBB345B8CA23E341
            SHA-512:3046E908FBBEB773610C661E17867F49C18D19A6EC68651F79290D734448A27601E248EB063B53CA800E2AE481C397807FA71A27E813B63F19149C72FA69CC0C
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M3 6L7 9C8.5621 7.82843 9.4379 7.17157 11 6" stroke="white" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):298
            Entropy (8bit):4.588996091222993
            Encrypted:false
            SSDEEP:6:tnrLJUGFcAumc4sl7uFvHP9AHKbnnwNR3HP9AHKbna1UHP9AHKb2:trLJfDukvHPiHAniR3HPiHAfHPiHA2
            MD5:89A24FE9F681C0EACD97E0AB3CC2939D
            SHA1:2585B26D0918205828C2ED29C7005F7CB6C6F992
            SHA-256:A6AA34E6578E71FE7C51FBE3F2BB292E81EB7349FBBE4C9053A9F27FB0CCBF1B
            SHA-512:EBBF0F186CA280BDD537BBBA4201705DB1F356A3E602F28CC051E5ADF5BD671F161A0B2265125BF172B92563F39EE04A3ED062C941BA9F7F0ECCE6D5329D6835
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect x="1" y="2" width="12" height="1.11111" fill="white"/>.<rect x="1" y="6.44434" width="12" height="1.11111" fill="white"/>.<rect x="1" y="10.8887" width="12" height="1.11111" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):354
            Entropy (8bit):5.121730668470263
            Encrypted:false
            SSDEEP:6:tnrf1Uqtumc4slvtM65tOvTF9YjRxt74JkjeUR/P8qXcvEXIZ3zTaKXcv+:trf1zuXM65ovT7YjTN4qqUR/kquE4Z3R
            MD5:6ED308163A77EA1F4AA454D785226F12
            SHA1:EB035B1244E120C19E6C95B7395D029750C6DB3D
            SHA-256:AA4F1916B0E2A85823358076B31484B1FC309FA2EEEA27A8CA8C7E4F38FFC772
            SHA-512:31FABD71F0F1C36B7789A5E0D53013F5F8F3900B4DDB42FA1A84714DCB87422006A55AA5007A657AFE57B3D82711421DA6D8AE9D0B9F99A2C2A874CB3F683228
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M15 4H3V14H15V4ZM3 3C2.44772 3 2 3.44772 2 4V14C2 14.5523 2.44772 15 3 15H15C15.5523 15 16 14.5523 16 14V4C16 3.44772 15.5523 3 15 3H3Z" fill="#EBEBEB"/>.<path d="M2 6H16V7.09091H2V6Z" fill="#EBEBEB"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):188
            Entropy (8bit):4.948322547345897
            Encrypted:false
            SSDEEP:3:tRBRNqFH3AMO+lHpkKcvXvcJq7SLvDmJS4RKb58ZWwSjL2ypqceFmA9gigAAmYHH:tnr0Qol8kAumc4slrwsbqceF9smqZR
            MD5:907F84B11D9E8416BDADD79CB77E693E
            SHA1:3DCD0D8CC8335E7AB3EEF86FDAF6E5C46C7F042B
            SHA-256:CF4A2D49F28DF31CF737657B4AD9765CBEFC393736FFE33FBFE74900486E1440
            SHA-512:3B6E10E0A84EC80FAF92DCED849291DF0493A1ED913EEA02216437BED10B4847904FCB90C119F3452986EB0A6EF4498078E18CA35F119A5D4D4F1AB5547B8B2D
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<line x1="4.5" y1="9.5" x2="15.5" y2="9.5" stroke="#EBEBEB" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2208
            Entropy (8bit):4.09310302518252
            Encrypted:false
            SSDEEP:48:3nhQh4oRKm8S/NuwZhg6/vjSEcPUqDxrd:3he4oU7SRhg4bRwz
            MD5:B025567CBA5B9C365D048A91CDDD08E5
            SHA1:ACF177CD8ECD6C30CCE79E7584E4E9D24B58448C
            SHA-256:B58F310ED44DA31DF7DBDB2AEF8A2A2DC6B27B5B00D076C4A3EB3059B18A7B1B
            SHA-512:79A530C9FD5B66A763C1CAD14E93D5D92224743C7C828766E74E40A06536047A4B4C01E614B6C412C1A639E55FDB5146BA01E433424F90A0B5517B7974C104D1
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M6.87817 12.4991C6.87817 12.7718 7.10885 12.9933 7.39124 12.9933C7.67504 12.9933 7.90431 12.7718 7.90431 12.4991C7.90431 12.2263 7.67364 12.0049 7.39124 12.0049C7.10885 12.0049 6.87817 12.2263 6.87817 12.4991Z" fill="#F7F7F7"/>.<path d="M12.4507 4.89963V4.83346C12.4507 3.77079 11.5587 2.90931 10.4585 2.90931H6.96907L5.6843 1.2417C5.56966 1.04726 5.4047 0.99865 5.2593 1.00135L5.25791 1H1.99216C0.891929 1 0 1.86148 0 2.92416V11.0745C0 12.1372 0.891929 12.9986 1.99216 12.9986H5.33759V12.9932C5.62139 12.9932 5.85066 12.7718 5.85066 12.499C5.85066 12.2249 5.61999 12.0048 5.33759 12.0048C5.32221 12.0048 5.30544 12.0062 5.28866 12.0062H2.47168C1.92226 12.0062 1.4749 11.5741 1.4749 11.0434C1.4749 10.9611 1.48608 10.88 1.50565 10.8031L2.64363 6.55778L2.64643 6.55643C2.75128 6.13379 3.14272 5.81917 3.61245 5.81782L3.61525 5.81647H11.8984C11.918 5.81512 11.9376 5.81512 11.9572 5.81512C12.5066
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):805
            Entropy (8bit):4.573135098954127
            Encrypted:false
            SSDEEP:24:tT1zugGhqkahtkSrQ3ZjpZ6xDYPW/OIH2:vQH3SrQ3FpZ6xsO/Oh
            MD5:860ECF2A39875396E4E87FEBB9C62356
            SHA1:C93CC4ECCD44A19A6B0F906210438FA062E1779F
            SHA-256:96FB4B1272B8E16FC974737F2FCB05CF10131555CFBA13F603D5565927D8C0F3
            SHA-512:CB4EF00C03E1C8CBD15DDF85266B0BF493FE27C45B4122997A963012B4E8007B76C191D2488A22E27E53DDA417EC91F0F20FD926C6BE6532A798E858A75B174F
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M5.97222 3H4C2.89543 3 2 3.89543 2 5V14C2 15.1046 2.89543 16 4 16H14.4444C15.549 16 16.4444 15.1046 16.4444 14V5C16.4444 3.89543 15.549 3 14.4444 3H12.8333" stroke="white" stroke-linecap="round"/>.<path d="M9.93711 2.64645C9.74185 2.45118 9.42527 2.45118 9.23 2.64645L6.04802 5.82843C5.85276 6.02369 5.85276 6.34027 6.04802 6.53553C6.24329 6.7308 6.55987 6.7308 6.75513 6.53553L9.58356 3.70711L12.412 6.53553C12.6072 6.7308 12.9238 6.7308 13.1191 6.53553C13.3144 6.34027 13.3144 6.02369 13.1191 5.82843L9.93711 2.64645ZM9.08356 11.3056C9.08356 11.5817 9.30741 11.8056 9.58356 11.8056C9.8597 11.8056 10.0836 11.5817 10.0836 11.3056H9.08356ZM9.08356 3V11.3056H10.0836V3H9.08356Z" fill="white"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):283
            Entropy (8bit):5.0617901353949595
            Encrypted:false
            SSDEEP:6:tnrf1Uqtumc4slcrQSc7jgIb4dqgAVlhGMKan9I9AHKbiAqzC:trf1zut5NEdCfAK9IiHAie
            MD5:4F6A7763D8053F2825CB87CB98F93DEB
            SHA1:7217BFDE727905EBF73DFF2DE5EF7FAFEBCB01D9
            SHA-256:7EDA632150186A63D9AC0E9D7278632904D5031CB3B07F7F34C0B55AE5FC26FC
            SHA-512:3D4F840B7A5014CED08761BBF7A5ECC4BBA64DC27DB8CF33CE96B5D1784E034A0D63660D07DE34BA0287C7619E2786A99B3FCE3348F1F168F474930B15E1C405
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_1_12)">.<path d="M18 0H0V18H18V0Z" fill="#262E2F"/>.</g>.<defs>.<clipPath id="clip0_1_12">.<rect width="18" height="18" fill="white"/>.</clipPath>.</defs>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):483
            Entropy (8bit):4.5760425608670685
            Encrypted:false
            SSDEEP:12:trLJfDuCMUi4SjmMteFOeSSwmusM021Lmnk1sbj3x:t3JfDuzFc6eFP1wmusM02FmnoSjh
            MD5:5DE7F3E250A53A5A599AACF1AB17517E
            SHA1:DE3DD91C48D1DD8941F9B2B3B14E84FE44E357EE
            SHA-256:F2F7CAA8C887278963DB996128C4A063B8F2718C1152533AA939B07E611993AF
            SHA-512:7BD1255D3D170A9D9FAFAC78911A63702B913ADCB2872FDC3B389D9729EBD6BCC2344777A620F37DE0F74D42A177A5A4050D2DCD0E035E23C4231E2D8FF3EF9E
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M6.72784 4.69172C3.68852 4.69172 1.0418 8.08581 1 11.1021C1 11.3429 1.20302 11.4092 1.39559 11.1021C2.37785 9.40797 3.9826 8.52989 6.08744 8.52989H6.81592V10.5398C6.81592 11.1411 7.27421 11.5505 7.79669 11.1468L12.608 7.41824C13.1304 7.01452 13.1304 6.35272 12.6094 5.949L7.76236 2.18291C7.24137 1.77776 6.81742 2.07478 6.81742 2.78705V4.69172H6.72784Z" fill="#F7F7F7"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):506
            Entropy (8bit):4.664473415221785
            Encrypted:false
            SSDEEP:12:trLJfDu5OMUi4SjmMteFOeSSwmusM021Lmnk1sbj3v:t3JfDu5nFc6eFP1wmusM02FmnoSj/
            MD5:2B55E260E55991A44C8358A09E46C703
            SHA1:D3188C4505EF1130CC0B6FB530FC6D2594B5C44E
            SHA-256:CEE55A7242B410EC0B7F1B526F3E6EE8D075762747A0E5E81F63062258E38037
            SHA-512:5B6B197E6AD88FEC6F0A88DDF89E08FEF90643828F92DF87497FFFCF6095F688B0FCCC58F1AC035AF5984D8545531CFCC2419E4CDE40541C3C05513FD8855A54
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<g opacity="0.5">.<path d="M6.72784 4.69172C3.68852 4.69172 1.0418 8.08581 1 11.1021C1 11.3429 1.20302 11.4092 1.39559 11.1021C2.37785 9.40797 3.9826 8.52989 6.08744 8.52989H6.81592V10.5398C6.81592 11.1411 7.27421 11.5505 7.79669 11.1468L12.608 7.41824C13.1304 7.01452 13.1304 6.35272 12.6094 5.949L7.76236 2.18291C7.24137 1.77776 6.81742 2.07478 6.81742 2.78705V4.69172H6.72784Z" fill="#F7F7F7"/>.</g>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):933
            Entropy (8bit):4.509686828100799
            Encrypted:false
            SSDEEP:24:t3JfDuzW1RKvdZGfWWlpNcGbQlL8tF5Sw5yOT9T909lh:3/9G8oOu
            MD5:2D045EB2A6C65093E4ADFDE2518A861D
            SHA1:D04A67D90C5E6B9447405CE69CC632FAB31DBD2F
            SHA-256:76B62AE2B7BD99246DED95AFE19751D2507A8110C635C07639A95987EB6571C4
            SHA-512:DC890D9132CC6582B0D75FB06495EC08F5B5775616A94CC3A9C90872F627CB159451E41ADFE68A8C6F9C8B3D8173F154815DCE67E809F0705A57D7C578EA69EA
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M12.7398 4.84619L9.15381 1.26016C8.98676 1.09311 8.76084 1 8.52533 1H1.88864C1.39708 1 1 1.39845 1 1.88864V12.1114C1 12.6029 1.39845 13 1.88864 13H12.1114C12.6029 13 13 12.6016 13 12.1114V5.47467C13 5.23916 12.9055 5.01324 12.7398 4.84619ZM3.88909 1.88864H6.55637V3.44409H3.88909V1.88864ZM10.1109 12.1114H3.88909V10.1109H10.1109V12.1114ZM12.1114 12.1114H11.0009V9.66727C11.0009 9.42218 10.8024 9.22227 10.5559 9.22227H3.44409C3.19899 9.22227 2.99909 9.42081 2.99909 9.66727V12.1114H1.88864V1.88864H2.99909V3.88909C2.99909 4.13419 3.19763 4.33409 3.44409 4.33409H7C7.24509 4.33409 7.445 4.13555 7.445 3.88909V1.88864H8.52533L12.1114 5.47467V12.1114Z" fill="#F7F7F7"/>.<path d="M7.00038 1.36523H3.48145V3.90243H7.00038V1.36523Z" fill="#F7F7F7"/>.<path d="M10.5686 9.77148H3.48145V12.5565H10.5686V9.77148Z" fill="#F7F7F7"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3270
            Entropy (8bit):3.9409989193261317
            Encrypted:false
            SSDEEP:96:ya0gNr6uvragVDpmrDUVn5rcOWXvf8rhBgc6mmVjxIB8c:JN6mVRQXvEroHzVjxI6c
            MD5:ACDEED0CA51CBFD1DD5ED9B5A08624C9
            SHA1:B906850132EEA728CFDE248EB036EF9E59999450
            SHA-256:F178623E2BBB278728934C0750962E7DAF78F36F00A3B96B6989823E2905EAFB
            SHA-512:8B99E937DE9707259213A5F3B3FAB6F3D2094A357507D05E212C8916200803E4E0FBF7667B612AA608172828F2C6CC7F12BBA9B14B7F145CB2ECBFDE50034EBB
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M3.68026 17.909C3.29346 17.909 2.92644 17.7615 2.64715 17.4931C2.36787 17.2234 2.2134 16.8679 2.2134 16.4907V13.0023C2.2134 12.8886 2.25047 12.7919 2.33203 12.6903C2.40618 12.619 2.51987 12.5778 2.64592 12.5778C2.87577 12.5778 3.07844 12.7665 3.07844 12.9805V16.4471C3.07844 16.7676 3.35402 17.0384 3.68026 17.0384H16.0949C16.4211 17.0384 16.6967 16.7676 16.6967 16.4471V12.914C16.6967 12.6879 16.887 12.5113 17.1292 12.5113C17.3603 12.5113 17.5617 12.7 17.5617 12.914V16.4242C17.5617 17.2101 16.9166 17.8437 16.0924 17.8643L3.68026 17.909ZM9.99878 11.5283C9.00398 11.5283 8.06232 11.1015 7.41601 10.3578L7.23435 10.1487L7.05269 10.3578C6.43727 11.0918 5.47955 11.5283 4.49093 11.5283C3.93977 11.5283 3.46029 11.4279 3.02406 11.22L2.86588 11.1305C1.78211 10.5392 1.11108 9.43042 1.11108 8.23336C1.11108 7.90689 1.16917 7.5659 1.2878 7.19228L1.29027 7.18381V7.17414C1.29027 7.15479 1.29027 7.1547
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):487
            Entropy (8bit):4.561639766367932
            Encrypted:false
            SSDEEP:12:trLJfDuCzY4zdFU7V0PO7WIdQH8YEuFZMs8UXIA3x:t3JfDujyU7ViO8A0MsFXIAh
            MD5:1D20AC0DAF91108F20D29B9195775712
            SHA1:B1B795A6173D4D1808C827080F39658594DC8354
            SHA-256:E32A7271E32A0826801107F55383951897366C4A07A27EF7444DF0BF259765F2
            SHA-512:3B7ED446505C82C78755583F6CA0CE58B26775026D2A1AD874701F3247D16BD0025CA9B12B2DA037BD21C15765AC87C5717A56EBA86B9FA2D5840B50A1A51917
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M7.27066 4.69171H7.18258V2.78704C7.18258 2.07478 6.76012 1.77776 6.23765 2.18291L1.39055 5.949C0.869567 6.35271 0.869568 7.01451 1.39205 7.41823L6.20331 11.1468C6.7243 11.5505 7.18408 11.1411 7.18408 10.5398V8.53133H7.91256C10.0159 8.53133 11.6221 9.40941 12.6044 11.1036C12.797 11.4107 13 11.3444 13 11.1036C12.9567 8.0858 10.3115 4.69171 7.27066 4.69171Z" fill="#F7F7F7"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):510
            Entropy (8bit):4.64919645536224
            Encrypted:false
            SSDEEP:12:trLJfDu5OzY4zdFU7V0PO7WIdQH8YEuFZMs8UXIA3v:t3JfDu53yU7ViO8A0MsFXIA/
            MD5:78A6724BE19D1CDF92F839DC4ADB3641
            SHA1:5A44526C18640148484F28E6CA87E77F826AB2C4
            SHA-256:6B63673144FAD749707CCEF4232368FBA7319317A2B9327E1747BF98824AD554
            SHA-512:D6BC4308D78CFDFA48E62322D182C1A65719FCA089DF205997E27D3EC9CDA1BB6EEFF2D15B3D36F8F763C923103FE887C9884203519B396C37456C0EEBC385FD
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<g opacity="0.5">.<path d="M7.27066 4.69171H7.18258V2.78704C7.18258 2.07478 6.76012 1.77776 6.23765 2.18291L1.39055 5.949C0.869567 6.35271 0.869568 7.01451 1.39205 7.41823L6.20331 11.1468C6.7243 11.5505 7.18408 11.1411 7.18408 10.5398V8.53133H7.91256C10.0159 8.53133 11.6221 9.40941 12.6044 11.1036C12.797 11.4107 13 11.3444 13 11.1036C12.9567 8.0858 10.3115 4.69171 7.27066 4.69171Z" fill="#F7F7F7"/>.</g>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):277
            Entropy (8bit):4.925379661372918
            Encrypted:false
            SSDEEP:6:tnr0Qol8kAumc4sl7udSn3Rl9rvvO6pH/n3Rl9rv+:tr0dmkAunn3bdmY/3bd+
            MD5:C144F48926963E4FBE479ADB75E9D851
            SHA1:F1837CD18C10D39C11B790CC6B6619297C0C1C9D
            SHA-256:F949A02ED3DFD53246063DFF7252F2F9623ABBB44597CC5EF4087A82AC688543
            SHA-512:A777C197DACB5C64186E494171DE5ABD7A83673A904CB31670071A08DADCE52238169465D7E56B1D9F7D52A2481DA8F93F35EED010E55CA553993093208369BF
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect x="2.5" y="4.5" width="9.83333" height="7.66667" rx="0.5" stroke="#EBEBEB"/>.<rect x="6.83325" y="8.83301" width="10.9167" height="7.66667" rx="0.5" stroke="#EBEBEB"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1575
            Entropy (8bit):4.805080946660328
            Encrypted:false
            SSDEEP:24:tCb8EAuvbuOakZoZ+ZUZhZCwZpZbZFZe5RZ9jZ3ZDZdDZbZ1YZ1lZ131:/puzZ4ZF
            MD5:D104B33D53EBBF6EE7826D1B91AF4B87
            SHA1:AF006D17AE64D2F0F54C4ACC92DC7115A0B15F27
            SHA-256:9A612BA1FE492B84F58132E1DA2755FDB1CAE73F7A529DC668EE6423D8BE2417
            SHA-512:0697152517931BA23F51A7ACA70D44697E48B057CF7C9B0265A68D7EE7BEEB9196A4502087AD1160735C96964369D943902FDBC81DFA67400AD9451A6C14689F
            Malicious:false
            Reputation:low
            Preview:<svg width="48" height="48" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="48" height="48" transform="matrix(1 0 0 -1 0 48)" fill="#FEFFFE"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 0 8)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 0 24)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 0 40)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 8 0)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 8 16)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 8 32)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 16 8)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 16 24)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 16 40)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 24 0)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 2
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1574
            Entropy (8bit):4.804154524721629
            Encrypted:false
            SSDEEP:24:tCb8EAuvbuOakZoZ+ZUZhZCwZpZbZFZe5RZ9jZ3ZDZdDZbZ1YZ1lZ13l:/puzZ4ZV
            MD5:64C7B838F93FBFA7F0A2B5630AAB3D5B
            SHA1:F32E326548DD5B0D1203159E316CEC89B3892701
            SHA-256:ABCFA381E845628D82857111978735F2EA543EE5D94ABFC837A6343B52B6FA69
            SHA-512:C48C2883B19DA82F2B783E0899520450CBBDDF8024689DDE186881288EE14E707BE43740D4E1A3F90AA6E992E2988BB5DAC5668BC97001FBAD8E8ABEEA9A1144
            Malicious:false
            Reputation:low
            Preview:<svg width="48" height="48" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="48" height="48" transform="matrix(1 0 0 -1 0 48)" fill="#FEFFFE"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 0 8)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 0 24)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 0 40)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 8 0)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 8 16)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 8 32)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 16 8)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 16 24)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 16 40)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 24 0)" fill="#D9D9D9"/>.<rect width="8" height="8" transform="matrix(0 1 1 0 2
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3362
            Entropy (8bit):4.22846283038256
            Encrypted:false
            SSDEEP:96:5RnOjElNTLbpgFgWv6WScOHNHi/EBj5Ek8SzvyPVA8KPDlA:zngEnTJ+vyWScOekP8SzqPVAt6
            MD5:F91FF7E6338E782918283021997B28D6
            SHA1:2CFCB349CD6E12B84FC9D4FE9CE07EC46100D3DD
            SHA-256:EF2E3EB7F4C609D1CA489F8847E10BFED9D1B75F053AE6EA2CAD3567317A3B13
            SHA-512:25C3251048CFA135C85CA437E7697148C361016066DE54440ADE22E43DE1C53951D5282FAEE7589300D5D869DE4229102BD798DF84725FDF56097D798D631111
            Malicious:false
            Reputation:low
            Preview:<svg width="50" height="68" viewBox="0 0 50 68" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M50 64C50 66.2091 48.2091 68 46 68H4C1.79086 68 0 66.2091 0 64V4C0 1.79086 1.79086 0 4 0H46C48.2091 0 50 1.79086 50 4V64Z" fill="#FEFFFE"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M3.84619 4V0H7.69234V4H3.84619ZM0 4V8H3.84615V4H0ZM23.0767 4V8H19.231V4H23.0767ZM19.231 64V68H23.0771V64H26.9229V60H23.0771V56H26.9229V52H23.0771V48H26.9229V44H23.0771V40H26.9229V36H23.0771V32H26.9229V28H23.0771V24H26.9229V20H23.0771V16H26.9229V12H23.0771V8H26.9229V4H23.0771V0H19.231L19.231 4H15.3848V8H19.231V12H15.3848V16H19.231V20H15.3848V24H19.231L19.231 28H15.3848V32H19.231V36H15.3848V40H19.231V44H15.3848V48H19.231V52H15.3848V56H19.231L19.231 60H15.3848V64H19.231ZM19.231 64V60H23.0767V64H19.231ZM19.231 56V52H23.0767V56H19.231ZM19.231 48V44H23.0767V48H19.231ZM19.231 40V36H23.0767V40H19.231ZM19.231 32L19.231 28H23.0767V32H19.231ZM19.231 24V20H23.0767V24H19.231ZM19.231 16H23.0767V12H19.231V16ZM0
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1055
            Entropy (8bit):4.5494069880267345
            Encrypted:false
            SSDEEP:24:tPnRGKucNCE9MM1PlvfXln3Y27Og8qmxXsMv9VOhdPdvu:hRGU1lIoCqmBsOA8
            MD5:3CF447FA21EA8B96AF2CE2621E99ADB7
            SHA1:A9A1069B7FE01A31ECAD43D0EC4717413C7BA3F8
            SHA-256:63097D8D13EDE5713F69EBAAE5DE4B7C945DC9B89E150F71F96F4CE4B01C5161
            SHA-512:C10FD033FC7DED794048588D6277EEB2FB5DF532A2D5F63A73F5F04F56C52BBA31A2FB27195FB5B5774A7FA9941ACF95F7601E296CD1E25AE7EAAF270C2F73B1
            Malicious:false
            Reputation:low
            Preview:<svg width="25" height="25" viewBox="0 0 25 25" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M25 12.5C25 5.59644 19.4036 0 12.5 0V0C5.59644 0 0 5.59644 0 12.5V12.5C0 19.4036 5.59644 25 12.5 25V25C19.4036 25 25 19.4036 25 12.5V12.5Z" fill="#FEFFFE"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M0.250045 15C0.0860757 14.1922 0 13.3562 0 12.5C0 11.6438 0.0860756 10.8078 0.250045 10H5V15H0.250045ZM5 22.5009C4.05303 21.7896 3.21038 20.947 2.49908 20H5V22.5009ZM15 24.75C14.1922 24.9139 13.3562 25 12.5 25C11.6438 25 10.8078 24.9139 10 24.75V20H15V24.75ZM22.5009 20C21.7896 20.947 20.947 21.7896 20 22.5009V20H22.5009ZM25 12.5C25 13.3562 24.9139 14.1922 24.75 15H20V10H24.75C24.9139 10.8078 25 11.6438 25 12.5ZM20 2.49908C20.947 3.21038 21.7896 4.05303 22.5009 5H20V2.49908ZM10 0.250045C10.8078 0.0860756 11.6438 0 12.5 0C13.3562 0 14.1922 0.0860757 15 0.250045V5H10V0.250045ZM5 2.49908C4.05303 3.21038 3.21038 4.05303 2.49908 5H5V10H10V15H5V20H10V15H15V20H20V15H15V10H20V5H15V10H10V5H
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):3315
            Entropy (8bit):4.846536716900397
            Encrypted:false
            SSDEEP:24:tFfMiutrELxPxKxaxAxzSxPxTxfxQNxzxZxDx2xGx5xzxOxZDxRglxYxvxmxsRxC:PESXgqi1p9tXGRippr1k/hE5CmH
            MD5:1100331C3F4DAACEFCE0C5C3D2C72C37
            SHA1:51C284BCC4C70F2024800652CCE43BD334058416
            SHA-256:A7AD1F15635A0F4AA47647C8E36842752332D15072BF5CA2545DEBB8189398C1
            SHA-512:638953450B97526723E024974DC6B87E12A03930FB5F6F4D5F6484A24F1D3F3CC53C3754CCBE00CFD01BD1FE1610EE05FCF25606DC5827E2E695F2D79E5D4854
            Malicious:false
            Reputation:low
            Preview:<svg width="45" height="44" viewBox="0 0 45 44" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_10957_38888)">.<path d="M45 44H0V0H45V44Z" fill="#FEFFFE"/>.<path d="M0 8V4H4V8H0Z" fill="#D9D9D9"/>.<path d="M24 8V4H28V8H24Z" fill="#D9D9D9"/>.<path d="M0 40V36H4V40H0Z" fill="#D9D9D9"/>.<path d="M24 40V36H28V40H24Z" fill="#D9D9D9"/>.<path d="M0 16V12H4V16H0Z" fill="#D9D9D9"/>.<path d="M24 16V12H28V16H24Z" fill="#D9D9D9"/>.<path d="M0 24V20H4V24H0Z" fill="#D9D9D9"/>.<path d="M24 24V20H28V24H24Z" fill="#D9D9D9"/>.<path d="M4 28V24H8V28H4Z" fill="#D9D9D9"/>.<path d="M28 28V24H32V28H28Z" fill="#D9D9D9"/>.<path d="M0 32V28H4V32H0Z" fill="#D9D9D9"/>.<path d="M24 32V28H28V32H24Z" fill="#D9D9D9"/>.<path d="M4 4V0H8V4H4Z" fill="#D9D9D9"/>.<path d="M28 4V0H32V4H28Z" fill="#D9D9D9"/>.<path d="M4 36V32H8V36H4Z" fill="#D9D9D9"/>.<path d="M4 44V40H8V44H4Z" fill="#D9D9D9"/>.<path d="M28 36V32H32V36H28Z" fill="#D9D9D9"/>.<path d="M28 44V40H32V44H28Z" fill="#D9D9D9"/>.<path d="M4
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1179
            Entropy (8bit):4.714983892103017
            Encrypted:false
            SSDEEP:24:t+Byutd0HJbE9MM10KRnXZzV8gMJLO3mbOZZfRRdkzIo2MghHacSHb:OV0HJzKnXZBKC2bOZZfRv9oZk6p
            MD5:6CCA5895FE080813AD37A43F62DB73D3
            SHA1:1BD2308A9F23788057CF0FF97ED35D13FABAE709
            SHA-256:7094432098ACFAE82C8CBBDD0253D7BE921326D3A524A2B6DB000AFCAB662486
            SHA-512:1A49F9D352B40D0A661A14B54729CC3EF6F3A344AC74CCD7C9BECB66303DBA73DA6ABC702637F8266196566CCDB7B3B6BBCA952AC78879FF1C0BD426B72EBA2D
            Malicious:false
            Reputation:low
            Preview:<svg width="62" height="32" viewBox="0 0 62 32" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_10955_38884)">.<path d="M0 0H62V32H0V0Z" fill="#FEFFFE"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M0 0V4H3V8H0V12H3V16H0V20H3V24H0V28H3V32H7V28H11V32H15V28H19V32H23V28H27V32H31V28H35V32H39V28H43V32H47V28H51V32H55V28H59V32H62V28H59V24H62V20H59V16H62V12H59V8H62V4H59V0H55V4H51V0H47V4H43V0H39V4H35V0H31V4H27V0H23V4H19V0H15V4H11V0H7V4H3V0H0ZM7 8V4H11V8H7ZM7 12V8H3V12H7ZM11 12V8H15V12H11ZM11 16V12H7V16H3V20H7V24H3V28H7V24H11V28H15V24H19V28H23V24H27V28H31V24H35V28H39V24H43V28H47V24H51V28H55V24H59V20H55V16H59V12H55V8H59V4H55V8H51V4H47V8H43V4H39V8H35V4H31V8H27V4H23V8H19V4H15V8H19V12H15V16H11ZM11 20V24H15V20H19V24H23V20H27V24H31V20H35V24H39V20H43V24H47V20H51V24H55V20H51V16H55V12H51V8H47V12H43V8H39V12H35V8H31V12H27V8H23V12H19V16H15V20H11ZM23 16V12H27V16H23ZM31 16V12H35V16H31ZM39 16V12H43V16H39ZM47 16V20H43V16H47ZM39 16V20H35V16H39ZM31 16V20H27V16H31ZM23 16V20H19V16H23ZM
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):706
            Entropy (8bit):5.054486124649339
            Encrypted:false
            SSDEEP:12:TMbeIMu5E4Bz38qWGRRHLcYpPPHMaJ5NfZBfUxfcRAWsITclkN0:qexisqW8rppPPnDU5cpncCN0
            MD5:909AF0DE9F49C7093CADCAA704B8B278
            SHA1:C6EA40E9565BA4706661E69B20C22C6F8DE25F4B
            SHA-256:874B4F3162E66DDE9D2F4BB30D0DF475624D403F53391BE14E9B01DD68198832
            SHA-512:11B4890EFD7CBF92A59F641FC2D5B571B0A8EFB2618B8AD2FAAAC806ED3F8FC53C6F5B206CEF646A1176A40D3FB146AC13AD7E617C1A4414F3ABE07ADC984D0D
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" standalone="no"?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"><svg t="1644672648032" class="icon" viewBox="0 0 1024 1024" version="1.1" xmlns="http://www.w3.org/2000/svg" p-id="4744" xmlns:xlink="http://www.w3.org/1999/xlink" width="200" height="200"><defs><style type="text/css"></style></defs><path d="M933.12 823.04l-384-664.746667a42.666667 42.666667 0 0 0-74.24 0l-384 664.746667a42.666667 42.666667 0 0 0 0 42.666667 42.666667 42.666667 0 0 0 37.12 21.333333h768a42.666667 42.666667 0 0 0 37.12-21.333333 42.666667 42.666667 0 0 0 0-42.666667z m-731.306667-21.333333L512 264.96l310.186667 536.746667z" p-id="4745"></path></svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):429
            Entropy (8bit):4.876515401117376
            Encrypted:false
            SSDEEP:12:tr0dmkAuXM65z7C4Vfeo2FnVDbBxcpdD0vRwN:twdmluXMMNknrx0Aa
            MD5:6D92DFA1B881853FCAC2AB466D0F5633
            SHA1:AB3BF6FB98B67F4C1E3031567311A511629D0A41
            SHA-256:5617EFADE6DA624A4594857035EF98CA05A451785D24D077596A1D10784083A3
            SHA-512:2533D196A669D5317655238EF20F8AF1945E0E39D34C779E9E6316C533E76F6A9902DC98716218544245E07EF476638B3087A10481C8FEDACE1A3F07158E0121
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M10.0002 3.21338L2.69245 15.8707H17.3079L10.0002 3.21338ZM10.4332 1.96338C10.2407 1.63005 9.75961 1.63005 9.56716 1.96338L1.39342 16.1207C1.20097 16.4541 1.44153 16.8707 1.82643 16.8707H18.1739C18.5588 16.8707 18.7994 16.4541 18.6069 16.1207L10.4332 1.96338Z" fill="#B6B6B6"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):919
            Entropy (8bit):4.623177479311564
            Encrypted:false
            SSDEEP:24:t3JfDuSt8djjaE9MMPg7qjke8inqLPFCQdBcSdJ1Mjh1:3bEXJg+AevnKPFNXK
            MD5:D1BB188C2E7828864D3F9FE51BBAF561
            SHA1:8CDBE6D37E2E95F84AADC956DD9B41A7FB745A3E
            SHA-256:06A0FF1631C5F23F27AA28E6BF31F9BF4FF0CAAE448DBD28981D50B1A31C4F80
            SHA-512:7B9EB596E8C0A2B18E2770F5C8BE6359E6E4E40C97F86E6CFF71AA48E76943364E00D974E4D791FD2128A347FA0A916A7B2E7F7FF233D6712823060E1B0D3CE9
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M14 2C14 0.89543 13.1046 0 12 0H2C0.89543 0 0 0.895431 0 2V12C0 13.1046 0.895431 14 2 14H12C13.1046 14 14 13.1046 14 12V2Z" fill="#FEFFFE"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M13.9992 12.0564V11.2002H11.1992V14H12C13.0857 14 13.9693 13.1349 13.9992 12.0564ZM8.40156 14V11.2002H5.60156V14H8.40156ZM2.8 14V11.2002H0V12C0 13.1046 0.895431 14 2 14H2.8ZM0 8.4001H2.8V5.6001H0V8.4001ZM0 2.8H2.8V0H2C0.89543 0 0 0.895431 0 2V2.8ZM5.60156 0V2.8H8.39844V5.5998H11.1984V2.7998H8.40156V0H5.60156ZM11.1992 0V2.8H13.9992V1.94356C13.9693 0.865088 13.0857 0 12 0H11.1992ZM2.80078 5.5998V2.7998H5.60078V5.5998H2.80078ZM11.1992 8.4001V5.6001H13.9992V8.4001H11.1992ZM2.80078 11.1999V8.3999H5.60078V11.1999H2.80078ZM5.60156 5.6001V8.4001H8.39844V11.1999H11.1984V8.3999H8.40156V5.6001H5.60156Z" fill="#D9D9D9"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):939
            Entropy (8bit):4.538136502264874
            Encrypted:false
            SSDEEP:24:tQRJKugpANSxHc9MMJ/0dyUCzmP3z0pJpZk5gmAAEmK1:QJVShd2zsQDkgmAAEmg
            MD5:C23D06FC9AFD9C71DCFD21BEF6888A4E
            SHA1:50C0E449CB8C58B1B3DE6A5F31A53249A77F03F4
            SHA-256:F19C4CE7FF18EBFD6E55673515BE720B925E33C9A9EF8F1BCEFE1EB2ACEC259A
            SHA-512:39942A9490D122CBE2BBDC80822A97AA77B29B72A8DE7CB608829A5D6CB2A4718A4EE89247AF98547FB738919D026C4F40FF6255C0619E7D97B67B3DE0FFA6EF
            Malicious:false
            Reputation:low
            Preview:<svg width="60" height="25" viewBox="0 0 60 25" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M0 8C0 3.58172 3.58172 0 8 0H52C56.4183 0 60 3.58172 60 8V17C60 21.4183 56.4183 25 52 25H8C3.58172 25 0 21.4183 0 17V8Z" fill="white"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M0.581517 5C0.206507 5.92643 0 6.9391 0 8V10H5V15H0V17C0 18.0609 0.206507 19.0736 0.581517 20H5V24.4185C5.92643 24.7935 6.9391 25 8 25H10V20H15V25H20V20H25V25H30V20H35V25H40V20H45V25H50V20H55V24.4185C57.0054 23.6067 58.6067 22.0054 59.4185 20H55V15H60V10H55V5H59.4185C58.6067 2.9946 57.0054 1.39328 55 0.581517V5H50V0H45V5H40V0H35V5H30V0H25V5H20V0H15V5H10V0H8C6.9391 0 5.92643 0.206507 5 0.581517V5H0.581517ZM10 10V5H5V10H10ZM15 10H10V15H5V20H10V15H15V20H20V15H25V20H30V15H35V20H40V15H45V20H50V15H55V10H50V5H45V10H40V5H35V10H30V5H25V10H20V5H15V10ZM15 10V15H20V10H15ZM25 10H30V15H25V10ZM35 10H40V15H35V10ZM45 10H50V15H45V10Z" fill="#D9D9D9"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):766
            Entropy (8bit):4.81659963535133
            Encrypted:false
            SSDEEP:12:trfFIoqOz1QCdhlRWKEIdZgB/5RuQCnA0WcsVhvVgtxhnVghY4Er8pVghISVKY9r:tTFINwdhlRWKtW9PWA0WcsVhN6xhnChc
            MD5:8BCD7F6DF312FAD079F1AD72BF5DE393
            SHA1:7B1F7634E979384A4829A0A4B20E0CEAABCF821F
            SHA-256:41EDE49ECA7392E33A26A52CC082D2D3F37A8586B5241347D438B8ADB8968360
            SHA-512:24BBF42A40B079D8AF8EB452A124F3D8AD9DF59077383CFDA37A8FEA92E97B2CDA5D73FC109718B49FC39843D906EE8D53FC2AA50DCBFAA89F4EB7D4EE02BE89
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" xmlns="http://www.w3.org/2000/svg" fill="none">.. <g>. <title>Layer 1</title>. <path id="svg_1" stroke-linecap="round" stroke="#6B6B6B" d="m10,5.03774l0,-2.03774c0,-0.55228 -0.44772,-1 -1,-1l-7,0c-0.55228,0 -1,0.44772 -1,1l0,12c0,0.5523 0.44772,1 1,1l7,0c0.55228,0 1,-0.4477 1,-1l0,-1.5094"/>. <path id="svg_2" fill="#6B6B6B" d="m7,8.5c-0.27614,0 -0.5,0.22386 -0.5,0.5c0,0.27614 0.22386,0.5 0.5,0.5l0,-1zm9.3536,0.85355c0.1952,-0.19526 0.1952,-0.51184 0,-0.7071l-3.182,-3.18198c-0.1953,-0.19527 -0.5119,-0.19527 -0.7071,0c-0.1953,0.19526 -0.1953,0.51184 0,0.7071l2.8284,2.82843l-2.8284,2.8284c-0.1953,0.1953 -0.1953,0.5119 0,0.7071c0.1952,0.1953 0.5118,0.1953 0.7071,0l3.182,-3.18195zm-9.3536,0.14645l9,0l0,-1l-9,0l0,1z"/>. </g>.</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):681
            Entropy (8bit):5.082304315173034
            Encrypted:false
            SSDEEP:12:trzPKIoqOz1QCbK5PJnUmpTqs4oU3hJmnKMxCtC+hljBB1W:t/PKINwbK5P6m9baunKMxCw+hlj8
            MD5:7823D4AE868D0C19A5BA5F4D9EC48CFF
            SHA1:78168534ECEA11B3141BBBF3D445679E154558DC
            SHA-256:195D07242F09502B94DB027F60BC98860D1DB2AA67046BC3DC8148F5A6D42B6E
            SHA-512:957BFB0E73F7F339586ABB3A90F78FC21293713D787EE6DC17635A39F6D31798490B754BCC97F18EC89F259781A63A3F99F7526A78E901BBCAB123D2DE7C711B
            Malicious:false
            Reputation:low
            Preview:<svg width="36" height="28" xmlns="http://www.w3.org/2000/svg" fill="none">.. <g>. <title>Layer 1</title>. <path id="svg_1" fill="#FF6F00" d="m15.4493,18.498l-7.44846,0c-2.76142,0 -5,-2.2385 -5,-5c0,-2.7614 2.23858,-4.99995 5,-4.99995l7.44846,0l0,-2l-7.44846,0c-3.86599,0 -7,3.134 -7,6.99995c0,3.866 3.13401,7 7,7l7.44846,0l0,-2zm5.0253,0l0,2l7.4473,0c3.866,0 7,-3.134 7,-7c0,-3.86595 -3.134,-6.99995 -7,-6.99995l-7.4473,0l0,2l7.4473,0c2.7614,0 5,2.23855 5,4.99995c0,2.7615 -2.2386,5 -5,5l-7.4473,0z" clip-rule="evenodd" fill-rule="evenodd"/>. <line id="svg_2" stroke-linecap="round" stroke-width="2" stroke="#FF6F00" y2="3" x2="17.9043" y1="24.2422" x1="17.9043"/>. </g>.</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):766
            Entropy (8bit):4.804896344316304
            Encrypted:false
            SSDEEP:12:trfFIYqOz1qKEIdZgB/GZfLhMCSRuqcsVhvVgtxhnVghY4Er8pVghISVKY9T8vYX:tTFIdItW9GdLhDSREsVhN6xhnCh1Er8S
            MD5:803AA5DDB79FC9C5EC0BC2D7F03D4901
            SHA1:7F0E6F7BD2DDE87DB01A6A8DEDE228185CC3083F
            SHA-256:4459AE4404611F05BD58DFBEB03E21D20B9807CF654BB5AEEE3822D1D9E931EC
            SHA-512:CAC3426E72D5341AC423B5B1876B49DAF66D7D9059D479B1F09D0CC106EE9573C5B8EC73117FCE12487DEA93759F6D68F11996B57EE1CADB730C0E19B4D856FA
            Malicious:false
            Reputation:low
            Preview:<svg width="18" height="18" xmlns="http://www.w3.org/2000/svg" fill="none">. <g>. <title>Layer 1</title>. <path d="m10,5.03774l0,-2.03774c0,-0.55228 -0.44772,-1 -1,-1l-7,0c-0.55228,0 -1,0.44772 -1,1l0,12c0,0.5523 0.44772,1 1,1l7,0c0.55228,0 1,-0.4477 1,-1l0,-1.5094" stroke="#323A3D" stroke-linecap="round" id="svg_1"/>. <path d="m7,8.5c-0.27614,0 -0.5,0.22386 -0.5,0.5c0,0.27614 0.22386,0.5 0.5,0.5l0,-1zm9.3536,0.85355c0.1952,-0.19526 0.1952,-0.51184 0,-0.7071l-3.182,-3.18198c-0.1953,-0.19527 -0.5119,-0.19527 -0.7071,0c-0.1953,0.19526 -0.1953,0.51184 0,0.7071l2.8284,2.82843l-2.8284,2.8284c-0.1953,0.1953 -0.1953,0.5119 0,0.7071c0.1952,0.1953 0.5118,0.1953 0.7071,0l3.182,-3.18195zm-9.3536,0.14645l9,0l0,-1l-9,0l0,1z" fill="#323A3D" id="svg_2"/>. </g>..</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):446
            Entropy (8bit):5.318272927204852
            Encrypted:false
            SSDEEP:12:tvbA91nRqaAx7BdCBtsrBdQu9pXdvougtJLU:tE91nRqlvitwBtZItJLU
            MD5:5AEBFD32C0F352B3901DD794B0439DA9
            SHA1:199680B1304B610CE62586803806C9C887635712
            SHA-256:D5F3C1C8CE8A3C6973FDCFA8EC3441BC4C43112B070ACD801DC6ACECE4C5A4CA
            SHA-512:2EA0DB7A98EB29849AD1B6D8C2C52AD059970711E0143A476A1218F41A2D17C1B8CD76D36D318EAF01B42C004C87DA7F32EC756B3E64E73314785D536D0F405F
            Malicious:false
            Reputation:low
            Preview:<svg id=".._1" data-name=".. 1" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 16 16">. <defs><style>.cls-1{fill:none;}.cls-2,.cls-3{fill:#2b3436;}.cls-2{fill-rule:evenodd;}</style></defs>. <title>Slice 41</title>. <path fill="#F1754E" d="M12.33,7.47A5,5,0,0,0,7.43,3,5,5,0,0,0,2.51,8a5,5,0,0,0,4.38,5v1A6,6,0,0,1,1.51,8,6,6,0,0,1,7.43,2a6,6,0,0,1,5.9,5.47Z"/>. <path fill="#F1754E" d="M12.82,10.75,10.48,7.47h4.67Z"/>.</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):952
            Entropy (8bit):5.25079936718003
            Encrypted:false
            SSDEEP:24:2dauNAOLf3TlEd0YKkK9o8Y1g9s+/p8M/:cDAqf3o7K9o833x8M/
            MD5:E14332B29CEC446DF50B071C5DB3B484
            SHA1:180BC37BD26AD7F7A9E498FEE3E4777F8823EB8E
            SHA-256:460EAD35B010019A037286536A0E7A24566D4E814505CBE46459898E8D6E7106
            SHA-512:226E6491020AB2F6406BE0F78C1075B52CB13CE1CF481468CB5720F17F84B71500877651BE337CEF00D23B00917A8B37904E8DDCCFD811A6BAB5ADBC1B715C2A
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="utf-8"?>. Generator: Adobe Illustrator 24.3.0, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->.<svg version="1.0" id="Layer_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px".. viewBox="0 0 128 128" enable-background="new 0 0 128 128" xml:space="preserve">.<g id="redo">..<g>...<path fill="#ED6B21" d="M36.57,72.21c0.73,0,1.46-0.32,1.95-0.94c0.86-1.08,0.69-2.65-0.39-3.51L12,46.86l26.13-20.9....c1.08-0.86,1.25-2.44,0.39-3.51c-0.86-1.08-2.43-1.25-3.51-0.39L6.44,44.9C5.85,45.38,5.5,46.1,5.5,46.86s0.35,1.48,0.94,1.95....l28.57,22.86C35.47,72.04,36.02,72.21,36.57,72.21z"/>..</g>..<g>...<path fill="#ED6B21" d="M48,106.5h43.43c17.13,0,31.07-13.94,31.07-31.07s-13.94-31.07-31.07-31.07H8c-1.38,0-2.5,1.12-2.5,2.5....s1.12,2.5,2.5,2.5h83.43c14.38,0,26.07,11.7,26.07,26.07s-11.7,26.07-26.07,26.07H48c-1.38,0-2.5,1.12-2.5,2.5....S46.62,106.5,48,106.5z"/>..</g>.</g>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):168
            Entropy (8bit):4.8907140362995225
            Encrypted:false
            SSDEEP:3:tRBRNqcwR+8XcvUJUTlt7SLvDmJS4RKb58ZQGuMnccwR+8DGVPRXlcJ3CrVZ8v:tnrZvUYltumc4sl7anLqSlckm
            MD5:27BF75AB7A92D199AC473C1FCA8830DB
            SHA1:E179820CF9EE47B32BDFC2EC7675AFD9512B35C3
            SHA-256:6C5EE2333EC8E6DB37BD238E7E9531305D988F2BA2C902A1C54E6A29F3132EB6
            SHA-512:B171113B60DBD773B55941A002B940E9691F24B0651527A75823942EE6E445325C4B571C0C5F8C97A1E99EA2E9C86D0F8698DF7D5B481C9483CE4B2A2247C6D5
            Malicious:false
            Reputation:low
            Preview:<svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">.<rect width="16" height="16" fill="#00AE42" fill-opacity="0.5"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):102
            Entropy (8bit):5.0024381220927
            Encrypted:false
            SSDEEP:3:tvQ8/oJDDmJS4RKb5ykKcvUJUT7Bin:tvQ8A9mc4sl3UY7Bi
            MD5:06E89AA1307B3F65F0DE3AA914F71793
            SHA1:8F5D537C2DF580CC2C5E064A06CF75BFC3749D1F
            SHA-256:FCA45940F7F7A1B1BC80EFCF3C692B781C8837198C1D84301E76B0809D88058A
            SHA-512:FAF54DBC112B490D4609EEEC3DDC53951ED36531714E1009076C44AB5C900B2F4C75420FCDA2D073295F60B63DC0EE9A93A49BCAF57CC79CC11A7D1F1EB62F92
            Malicious:false
            Reputation:low
            Preview:<svg id=".._1" data-name=".. 1" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 16 16">.</svg>
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1126
            Entropy (8bit):4.870970781813964
            Encrypted:false
            SSDEEP:24:twdpINwb0W1/t2tZMyty9ssdJlhJSnKMxWA0WrOVIvZlMxPjUnKMxWft0WrEFScb:6u+1/oT4tL5ctiflj2Qzr2Sbytm7S
            MD5:A3F0BD13281A0A98DC426F60384B48B8
            SHA1:5B4A97DED2E55700E0F810F357D5673CD6C523E5
            SHA-256:DDA0EB674F066B393D922FBF658493CAC16CDB5B4350FB3B73D34BB2E0FBC819
            SHA-512:1A35F43934E27833286E0FEAD2057DBDBBB8C85855FC13E4126B7D0CC7F96AC3FC0D220DC3FFD72F6DDE0BC2A2FB3368F4E7EE656C867548116F55E2DEE34B9B
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="14" xmlns="http://www.w3.org/2000/svg" fill="none">.. <g>. <title>Layer 1</title>. <path id="svg_1" fill="#6B6B6B" d="m18.4872,11.724l0,-8.69898l-3.5639,4.3491l3.5639,4.34988zm1,-8.69898c0,-0.93941 -1.1781,-1.36044 -1.7735,-0.63383l-3.5639,4.34911c-0.302,0.36855 -0.302,0.899 0,1.26758l3.5638,4.34992c0.5954,0.7267 1.7736,0.3057 1.7736,-0.6338l0,-8.69898z" clip-rule="evenodd" fill-rule="evenodd"/>. <path id="svg_2" fill="#6B6B6B" d="m12.9751,1.55273l-11.9751,0l0,10.90007l11.9751,0l0,-10.90007zm-11.9751,-1c-0.55229,0 -1,0.44772 -1,1.00001l0,10.90006c0,0.5523 0.44772,1 1,1l11.9751,0c0.5523,0 1,-0.4477 1,-1l0,-10.90007c0,-0.55228 -0.4477,-1 -1,-1l-11.9751,0z" clip-rule="evenodd" fill-rule="evenodd"/>. <path id="svg_3" fill="#6B6B6B" d="m4.5,10.4777c0.82843,0 1.5,-0.67155 1.5,-1.49998c0,-0.82843 -0.67157,-1.5 -1.5,-1.5c-0.82843,0 -1.5,0.67157 -1.5,1.5c0,0.82843 0.67157,1.49998 1.5,1.49998zm0,1c1.38071,0 2.5,-1.1193 2.5,-2.49998c0,-1.38071 -1.11929,-2.5 -2.5,-2.5c-
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1126
            Entropy (8bit):4.858921493806359
            Encrypted:false
            SSDEEP:24:twdpINwbSm/t2tZMyty9ssdJlhJSnKMxWASwOVIvZlMxPjUnKMxWftSKEFScKDIp:6u6/oT4tL5ccflj2Qf2Sbytm7S
            MD5:447A2E0DFD915AE52915FD989BFA9FBC
            SHA1:6228F0F4DF68660F94C203F1D506798E54EFF9A8
            SHA-256:AD3564B4AD3D266F5A46A1DA133497E6596B572F39A1B50F7063DF6AA863C664
            SHA-512:84708054ED77B11C3EAC2037A815CD9135739D5E1A56CFAF4837A714CFC81725988D38E273D1A9D92C6432A0FC5BC5190A88CA9BECEAAE26C9EE919377C4221A
            Malicious:false
            Reputation:low
            Preview:<svg width="20" height="14" xmlns="http://www.w3.org/2000/svg" fill="none">.. <g>. <title>Layer 1</title>. <path id="svg_1" fill="#00AE42" d="m18.4872,11.724l0,-8.69898l-3.5639,4.3491l3.5639,4.34988zm1,-8.69898c0,-0.93941 -1.1781,-1.36044 -1.7735,-0.63383l-3.5639,4.34911c-0.302,0.36855 -0.302,0.899 0,1.26758l3.5638,4.34992c0.5954,0.7267 1.7736,0.3057 1.7736,-0.6338l0,-8.69898z" clip-rule="evenodd" fill-rule="evenodd"/>. <path id="svg_2" fill="#00AE42" d="m12.9751,1.55273l-11.9751,0l0,10.90007l11.9751,0l0,-10.90007zm-11.9751,-1c-0.55229,0 -1,0.44772 -1,1.00001l0,10.90006c0,0.5523 0.44772,1 1,1l11.9751,0c0.5523,0 1,-0.4477 1,-1l0,-10.90007c0,-0.55228 -0.4477,-1 -1,-1l-11.9751,0z" clip-rule="evenodd" fill-rule="evenodd"/>. <path id="svg_3" fill="#00AE42" d="m4.5,10.4777c0.82843,0 1.5,-0.67155 1.5,-1.49998c0,-0.82843 -0.67157,-1.5 -1.5,-1.5c-0.82843,0 -1.5,0.67157 -1.5,1.5c0,0.82843 0.67157,1.49998 1.5,1.49998zm0,1c1.38071,0 2.5,-1.1193 2.5,-2.49998c0,-1.38071 -1.11929,-2.5 -2.5,-2.5c-
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):433
            Entropy (8bit):3.773706717596857
            Encrypted:false
            SSDEEP:6:lS18hbDvvkn2CtHkooIEoqOmjTBdqCy6vqhcBUksHQIdaO1dkFCA:Y18d0Z+ITyQCkcBUkVcmCA
            MD5:B5669A09FE9DCF58B3BAD42AB8422FEF
            SHA1:C329F897EBAC56B1AEBCD07FE7994EFB77EA84B2
            SHA-256:657FB44B68F135A2E903E2104845540E7EB4453AE45EC03E1C0C43D7F1405EEC
            SHA-512:7FC36A6291F9C32E4EABF5559D5CF0EC99FF63BAE657D816C76005A8836DFEE9F4A749AA1CE9623A9E42EFB2031210AF2F080ED0C3659BBE55DAB9110AC346EB
            Malicious:false
            Reputation:low
            Preview:{. "version": "1.0.0.1",. "high_temp_filament": [. "ABS",. "ASA",. "PC",. "PA",. "PA-CF",. "PA6-CF",. "PET-CF",. "PPS",. "PPS-CF",. "PPA-CF",. "PPA-GF". ],. "low_temp_filament": [. "PLA",. "TPU",. "PLA-CF",. "PLA-AERO",. "PVA". ],. "high_low_compatible_filament":[. "HIPS",. "PETG". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):158
            Entropy (8bit):3.9550566897961676
            Encrypted:false
            SSDEEP:3:A2S18hWdNHLCFGHsv/F/ERuk6gJicvV8Rl9z03JHlVJdFNtmXJvFX6YK8FVHFZn:lS18hdFBHe8zgPvWRl10bcJYY3n
            MD5:0974850AB6BC8BBFA796FA63411CAD54
            SHA1:C474ADBB654CFCFB792AAD68A86C41D33D5D69E4
            SHA-256:137A27C54AC04CE407BB2B09DF22BEA029C0B759ED2D0688AB928D1D94339F7A
            SHA-512:4BAB11BF4A8FB00CAA17802166712A783F9FEDBECB14DA3DDCC97C4650D7E3EF146C49B326584FFB80BE669375070AD70265662F363679BFFEC1947FE94BB60D
            Malicious:false
            Reputation:low
            Preview:{. "version": "1.0.0.1",. "nozzle_hrc": {. "hardened_steel": 55,. "stainless_steel": 20,. "brass": 2,. "undefine": 0. }.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):11257784
            Entropy (8bit):7.098488113396249
            Encrypted:false
            SSDEEP:196608:7WFShWOubvc36ZGeWXYG05/tmbotPojKVMrhHwWllr6PZDp0Hyc2EGg:7WEh0bvc36ZGr5odPojKVMiPZDp0Hy6
            MD5:691E13A546042622C55D0237F8CA5759
            SHA1:197C686601F5065378B1BCD033A4089CC464A715
            SHA-256:BDA2C80F10195078CBCA11753584087341EC13D530AC9282482BCEBF6DE9C59B
            SHA-512:DB1FFF9AF4EC738EBBB7EF9C862E1C4199FEA211B5076DF6498722439702DFE7CC89355D6EB569D7B6D94AE4BE542C4BA75A740812051DA0A09E2EB73BA4FEC2
            Malicious:false
            Reputation:low
            Preview:.................................................................................o...).?.....j.=..BH'.B...B..BB&.BP./B..BH..B...B..y/.?....q>.=..BH'.B...B..BH..B...B..BH'.B..B..C#.?..:..=...B...B.z-B...B...B5.-B..BH..B...B...Y.?thn....=...B...B5.-B...B5$.B.B.B..BH..B...B...*.?U..7...=..BH..B...B...B5$.B.B.B..BH'.B..B...5.?..b..=...B..BHa,Ba..B...Bj.,B..BH..B...B.....?XX?;.(.=a..B...Bj.,BH..B...B..-B..BH..B...B...I.?'.|....=..BH..B...BH..B...B..-B...B...B.z-B...4.?8..7/@.=...B.Byi+B...B)..BL.+B..BH..B...B.....?\Cp;..=...B)..BL.+B...B..B>.,B..BH..B...B...S.?.7b...=..BH..B...B...B..B>.,B...B..BHa,B...+.?T.H;...=_..B...B.*B...B.7.B5.*B..BH..B...B..M;.?..-..=...B.7.B5.*B@..B.^.B. +B..BH..B...B...J.?X...`..=..BH..B...B@..B.^.B. +B...B.Byi+B...5.?4..8h..=...B...B..*Bw..B...Bp=*B..BH..B...B...,.?.Q];~*.=w..B...Bp=*Bk..B..B.l*B..BH..B...B../9.?Ow?.te.=..BH..B...Bk..B..B.l*B_..B...B.*B..k8.?.e...=...B..B..)B...B.%.B5.)B..BH..B...B...5.?u,.:..=...B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):43484
            Entropy (8bit):5.275956862385738
            Encrypted:false
            SSDEEP:384:k64ZCmEc1De27WgCnEW0hDNOdbV5CEdnqsBa51kQ+wg4WmCTTIjGGNdQBQRG9Hzi:+G0hPseg4CTTIjGGNdQBQRG9HzM9iHG
            MD5:2AB8D1F7179FFB70B0AC19DFEF226F56
            SHA1:5F1207B536320ACD473E3E83C96C76FEB68EFE5C
            SHA-256:7E006BC455D455D47DE505E5255CB5C98E14B3B191AF89439CAD0B1CEE86B9F5
            SHA-512:07D4D1DCBE85399A835AD2F5CD08BE1A59A8A710C0046C8DB0AEF8F66204E15A023F437A0B4116315068DF107D83C7ACA6DCC988057E7D417846FF996D4013C0
            Malicious:false
            Reputation:low
            Preview:STLB ATF 11.7.0.108 COLOR=n.B. d.........5?..5?ff&A...@...A..A...@...Aff&A..@...AM"zh.$..5?..5?ff&A..@...A..A...@...A..A..@...AM"..4....<..4?...Aff.A...A..Aff.A...A..A.U.A...AM"9.4....<.+5?..A.U.A...A..Aff.A...A..A.o.A...AM"3.4..[.=..4?..A.U.A...A..A.o.A...A:..A...@...AM".M3.B.=.X5?:..A...@...A..A.o.A...A.y.A...@...AM"w<2.|..>..4?:..A...@...A.y.A...@...AkQ.A...@...AM".0."7.>.z5?kQ.A...@...A.y.A...@...A...A.;.@...AM",O/.Z.;>>.4?kQ.A...@...A...A.;.@...A..A...@...AM"..,...M>=.5?..A...@...A...A.;.@...A...A...@...AM".[+...o>.}4?..A...@...A...A...@...A...A...@...AM"..(."/.>O.5?...A...@...A...A...@...AP.A.<.@...AM"zh&..4.>.z4?...A...@...AP.A.<.@...AmN.A..@...AM"7.".e..>I.5?mN.A..@...AP.A.<.@...AI.A...@...AM";} .[..>..4?mN.A..@...AI.A...@...A.[.Aff.@...AM"......>).5?.[.Aff.@...AI.A...@...AZ.A.K.@...AM"....j..>..4?.[.Aff.@...AZ.A.K.@...A.F.A..@...AM"_......>.j5?.F.A..@...AZ.A.K.@...AG..A...@...AM"....w\.>.4?.F.A
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):665984
            Entropy (8bit):6.858323264941966
            Encrypted:false
            SSDEEP:12288:VbwHk3SdDxRMWpNwObJ87flC1k1Aks1dljqCj3N+PX5Rb:4k3Sdl8PAkKdljQPX5h
            MD5:FFBD7974A2715D642C6C414999EF6D4A
            SHA1:563121EE664C80A2C656108CE4A9D590B24BFAE2
            SHA-256:992F3EAF46C6891BB47201B3383A4ED663EDA8062E72502AF1ABE67CF154DF16
            SHA-512:ED117DF8268F1215065999E6A5CBA9CA9D8E440B95D87DC7803FA14FE753BF97021386E0615B21252B736BCEFD04E3CDBF5F81B434987C734E9EC4F95DBFA159
            Malicious:false
            Reputation:low
            Preview:.................................................................................4.............?C".B.<.C...@'..BK..C...@...B...C...@.............?...B...C...@'..BK..C...@...B...C...@.............?...B...C...@...B...C...@'..B...C...@.............?.E.B...C...@9..B...C...@C".B.<.C...@.............?C".B.<.C...@9..B...C...@l..B...C...@.............?C".B.<.C...@l..B...C...@'..BK..C...@.............?...B...C...@34.B...C...@.E.B...C...@.............?.E.B...C...@34.B...C...@[..B. .C...@.............?.E.B...C...@[..B. .C...@.W.B...C...@.............?..BVw.C...@`..B...C...@...B...C...@.............?...B...C...@`..B...C...@s_.B...C...@.............?...B...C...@s_.B...C...@...BLI.C...@.............?.8.BJ8.C...@(H.B.U.C...@..BVw.C...@.............?..BVw.C...@(H.B.U.C...@.[.B...C...@.............?..BVw.C...@.[.B...C...@.v.B...C...@.............?.BP..C...@04#C...C...@.8.BJ8.C...@.............?.8.BJ8.C...@04#C...C...@.m#C...C...@.............?.8.BJ8.C...@.m#C...C...@..C...C...@.............?..C
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):72084
            Entropy (8bit):4.919787129251563
            Encrypted:false
            SSDEEP:768:jUzKRj+afBZdaH+B3aT1wZKfjgFnqDKNeANAleQo/Ej5qXqkSuxh/rWLCypQSLRj:vdaH+gT1wNash/rGxAX50sLdcerQbvT
            MD5:E25D1009849A9A0E8EAE531B9B9BBA22
            SHA1:F1680EB6A015545A921DA7CA8F169DEF956738A4
            SHA-256:1A94E3D30E71C1684288D1144EC9049C7279F507D24AA3BA4ADFCF392C7C8F7D
            SHA-512:0806359BB4F018416B45C40819C4D2998A586B7163432A38B107E9C3EA02A3CCFF7BACD53B5160D8CE2140C4F630DE8D3431FC2F0B5293F0F5717888C9464004
            Malicious:false
            Reputation:low
            Preview:...................................................................................................C...C.......C...C.......C...C.................?...C...C...>...C...C...>...C...C...>...<.....?.......C...C...>...C...C...>...C...C.......<.....?.......C...C...>...C...C.......C...C.....................C...C....T..C8..C.......C...C.................?T..C8..C...>...C...C...>...C...C...>..,..u..?....T..C8..C...>...C...C...>...C...C......,..u..?....T..C8..C...>...C...C....T..C8..C.....................C...C.......C?..C....T..C8..C.................?...C?..C...>...C...C...>T..C8..C...>...Z2....?.......C?..C...>T..C8..C...>T..C8..C.......Z2....?.......C?..C...>T..C8..C.......C?..C.....................C...C.......C...C.......C?..C.................?...C...C...>...C...C...>...C?..C...>....y...?.......C...C...>...C?..C...>...C?..C........y...?.......C...C...>...C?..C.......C...C.....................C...C....q..C!..C.......C...C.................?q..C!..C...>...C...C...>...C...C...>..w...5.?....q..C
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):611784
            Entropy (8bit):6.200384771384886
            Encrypted:false
            SSDEEP:12288:L0U5wafpqZ8PUziX7AcrA7JlBw0B0R7bq1:nPYJlBZ1
            MD5:D6AB2A6A021A18C7ABCD19F3C9E463DC
            SHA1:19AD1A20F65340D69FC4411F5779A793291E59BE
            SHA-256:6FA494DDA2A892F5044CD11E5CC657BC9C1BC713A8EA2AC4AB398BB0793D1DE2
            SHA-512:3F542D467816982009436AFA78320E64BD232199D3CC6BB8577BC190319D79AB477873D51A401C80EC7DD9BFD01847DB937175C92AF5C815DF160FBEA867A36B
            Malicious:false
            Reputation:low
            Preview:................................................................................./..H..>..t?.*.>D..B).WC...BDQ.B.WC".BD..B+.WC_}.B..G..>..t?.*.>D..B+.WC_}.BDQ.B.WC".BDQ.B..WC}c.B..W.;...(?$.4>DQ.B.WC".B.y.B.WC^..BDQ.B..WC}c.B..Y.;...(?#.4>DQ.B..WC}c.B.y.B.WC^..B.y.B..WC.n.B..Cg0..23?..@>.y.B..WC.n.B.y.B.WC^..B...Bz.WC...B...b0."73?..@>.y.B..WC.n.B...Bz.WC...B...B{.WC@y.B..0.....D?..R>...B{.WC@y.B...Bz.WC...B...B..WC!..B........D?..R>...B{.WC@y.B...B..WC!..B...B..XC|..B...*..j.O?.t^>...B..XC|..B...B..WC!..BD..BF.WCy..B...*..j.O?.t^>...B..XC|..BD..BF.WCy..BD..BH.XC..B..6\...b?.Tr>D..BF.WCy..B.;.B..WC...BD..BH.XC..B..[N...b?.Rr>D..BH.XC..B.;.B..WC...B.;.B..XC...B..._..#0j?..z>.;.B..XC...B.;.B..WC...B.s.B..WC.!.B..._..#0j?..z>.;.B..XC...B.s.B..WC.!.B.s.B.(XC...B..../...s?...>.s.B.(XC...B.s.B..WC.!.B..B..WC@$.B..../...s?...>.s.B.(XC...B..B..WC@$.B..B.,XC...B......|v?...>..B.,XC...B..B..WC@$.BD..BI.WC|%.B.......|v?...>..B.,XC...BD..BI.WC|%.BD..BK/XC..B.....=..v?..>D..B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):153684
            Entropy (8bit):7.152701334594184
            Encrypted:false
            SSDEEP:3072:lE1zxPS2mOZTEuqlRgb/+4/HJR3AEFaTIrjjnHS5NX3LhuI:tOZTEblRgbt/prHS5NX3r
            MD5:0A8D33EAD85B90ED1A844E3FDA0E3428
            SHA1:F37CF4591F79C93932F72C53A97934EC7A41E334
            SHA-256:B867943480AF442053BA3FD92E4538E2B071CF41B8805F85910FC326A5F31CC0
            SHA-512:3BC00D4CEF031BD16ABD109426E5B67596AEAFFCAD611B0F2303965E3FB549715EB30C12EA5E7F24C5AEE3F35A2196AB7B76587452BB79EC26188770254A324F
            Malicious:false
            Reputation:low
            Preview:.................................................................................... :~?.M.=.O.=.QdA......5@.]bA.i.?..5@..aA`..?ktX@.. :~?.M.="P.=.QdA......5@..aA`..?ktX@0scA....ktX@....t?j3.=~U.>0scA....ktX@..aA`..?ktX@..^A...?~nz@....t?S3.=.U.>0scA....ktX@..^A...?~nz@..`A....~nz@..Cea?.^l=...>..`A....~nz@..^A...?~nz@..ZA.r.?X.@..Cea?.^l=...>..`A....~nz@..ZA.r.?X.@^.\A....X.@....E?.BO=\2"?^.\A....X.@..ZA.r.?X.@.7UA...?x..@....E?.BO=Z2"?^.\A....X.@.7UA...?x..@..WA....x..@...C"?a**=E.E?..WA....x..@.7UA...?x..@BjNA.f.?..@...C"?j**=D.E?..WA....x..@BjNA.f.?..@;2PA......@...=.>...<..a?;2PA......@BjNA.f.?..@[.FA.9.?.9.@...=.>...<..a?;2PA......@[.FA.9.?.9.@/^HA.....9.@..Q..>..<..t?/^HA.....9.@[.FA.9.?.9.@q;>A7[.?Ba.@..H..>s.<..t?/^HA.....9.@q;>A7[.?Ba.@..?A....Ba.@.....=...;..~?..?A....Ba.@q;>A7[.?Ba.@\y5A.!.?...@.....=k..;..~?..?A....Ba.@\y5A.!.?...@=.7A.......@.....q....~?=.7A.......@\y5A.!.?...@H.,Ai.?Ba.@.....N....~?=.7A.......@H.,Ai.?Ba.@.4.A....Ba.@..R........t?.4.A
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2909
            Entropy (8bit):4.119817712483234
            Encrypted:false
            SSDEEP:48:rYmPReA9f08EmOHIUNkIDEphdqndVhdddPGYd++d2dHIydweVr+dy/hv+UBnqvIV:8mpewf085OoKkIDEJqdVX7PG230HI4pv
            MD5:62D01A49D5076A7E7FDCF0C773054FDA
            SHA1:598ABD266AF6A512C63098E663348F2C757A452B
            SHA-256:08A411D31E7C9E91013C73142FE502802642C7DED12819D94A7B834423939DDE
            SHA-512:008A10081D0300C667DE04AD555939F4070E254DDF5B67883DB6FCC5F246CCE136021BE1F809FD4E925214B7AC3BE173D17444792D3B555F2B5872F1F3A57249
            Malicious:false
            Reputation:low
            Preview:{. "00.00.00.00": {. "display_name": "Bambu Lab X1 Carbon",. "print": {. "ipcam": {. "resolution_supported": [ "720p", "1080p" ],. "virtual_camera": "enabled",. "liveview": {. "remote": "enabled". },. "file": {. "remote": "enabled",. "model_download": "enabled". }. },. "support_motor_noise_cali":false,. "support_tunnel_mqtt":false,. "support_mqtt_alive":false,. "support_command_ams_switch":false,. "support_cloud_print_only":false,. "support_1080dpi":false,. "support_prompt_sound":false,. "support_ams_humidity":false,. "support_auto_recovery_step_loss":false,. "support_auto_leveling":true,. "support_update_remain":false,. "support_timelapse":true,. "support_filame
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2898
            Entropy (8bit):4.107626631935887
            Encrypted:false
            SSDEEP:48:r3mPReA9f08EmOHIUNkIDEphdqndVhdddPGYd++d2dHIydweVr+dy/hv+trIq5xo:Dmpewf085OoKkIDEJqdVX7PG230HI4pZ
            MD5:C431D7AD306553FE794ACD49C0C92B89
            SHA1:1D45ABB2A03D85A6DB4D7391FA4A14E157C2B8C6
            SHA-256:45743EECBDEEDBAE7F4CD939841E8E69C0801C99D3B1A707E682FD0391B38CAC
            SHA-512:0B16D0258B18F8A1DCD965E3DFFD1DDF779D1894460109DE7DDDB32A70D1FE463A0BC7F75E5BCCC03420CC6D3FBFA10911B981629216C2094B2449E87D87867B
            Malicious:false
            Reputation:low
            Preview:{. "00.00.00.00": {. "display_name": "Bambu Lab X1",. "print": {. "ipcam": {. "resolution_supported": [ "720p", "1080p" ],. "virtual_camera": "enabled",. "liveview": {. "remote": "enabled". },. "file": {. "remote": "enabled",. "model_download": "enabled". }. },. "support_motor_noise_cali":false,. "support_tunnel_mqtt":false,. "support_mqtt_alive":false,. "support_command_ams_switch":false,. "support_cloud_print_only":false,. "support_1080dpi":false,. "support_prompt_sound":false,. "support_ams_humidity":false,. "support_auto_recovery_step_loss":false,. "support_auto_leveling":true,. "support_update_remain":false,. "support_timelapse":true,. "support_filament_back
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2721
            Entropy (8bit):4.037983428960696
            Encrypted:false
            SSDEEP:48:rD8Mq08EmOHIU+dkI0dpdphdXdndmdhdddPGHclHIRweVpy/hAd+1VlrIBCP4j9U:n8Mq085OoNkIK/JtdEX7PGHclHIRpPi5
            MD5:4D86CBF45639AC5B254AE7AE8CC0A960
            SHA1:E9D76B47781EB386F7B580A02FC7829DC2056DEC
            SHA-256:D0B83C50149B23413595F13F1F98EE4FC9C0FB98C23C64DE2F8DFEF5FEC296D3
            SHA-512:B0A9D2C53A5C4F3655353226C823B7F0F7FCED627F405DC1E866B333D9B00D9900BDAAAD96EB864C6931EF97C36D0BC3EEEE9F533B7A9DDDAA94DD26208222E7
            Malicious:false
            Reputation:low
            Preview:{. "00.00.00.00": {. "display_name": "Bambu Lab P1P",. "print": {. "ipcam": {. "resolution_supported": [ "720p" ],. "liveview": {. "local": "local". }. },. "support_motor_noise_cali":false,. "support_tunnel_mqtt":false,. "support_mqtt_alive":false,. "support_command_ams_switch":false,. "support_cloud_print_only":true,. "support_1080dpi":false,. "support_prompt_sound":false,. "support_ams_humidity":true,. "support_auto_recovery_step_loss":true,. "support_auto_leveling":true,. "support_update_remain":true,. "support_timelapse":true,. "support_filament_backup":true,. "support_chamber_fan":true,. "support_aux_fan":true,. "support_send_to_sd":false,. "support_print_all":false,. "support_print_w
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2612
            Entropy (8bit):4.052945489758651
            Encrypted:false
            SSDEEP:48:rc8Mq08EmOHIU+dkI0dpdphdXdndmdhdddP4+dHclHIRweVpy/hAd+sAFrIBZQHw:w8Mq085OoNkIK/JtdEX7PBHclHIRpPi6
            MD5:8B910B687670E130FEC0ABB095553498
            SHA1:9F17563B2C1EC96F1DCC4B85D158D1029AD12658
            SHA-256:2215974794FDAC2E10A51931B329152A4E25767D1A08B0915621E4614695A12C
            SHA-512:ED74E65446EDCA614C465040DCE9A7E780CC39A88FF9032F77E9C0159838483CFDDE41ADD1936FF4E5915A36B4A97ED16C59FBEB188D29DCE20610FD624A74D3
            Malicious:false
            Reputation:low
            Preview:{. "00.00.00.00": {. "display_name": "Bambu Lab P1S",. "print": {. "ipcam": {. "resolution_supported": [ "720p" ],. "liveview": {. "local": "local". }. },. "support_motor_noise_cali":false,. "support_tunnel_mqtt":false,. "support_mqtt_alive":false,. "support_command_ams_switch":false,. "support_cloud_print_only":true,. "support_1080dpi":false,. "support_prompt_sound":false,. "support_ams_humidity":true,. "support_auto_recovery_step_loss":true,. "support_auto_leveling":true,. "support_update_remain":true,. "support_timelapse":true,. "support_filament_backup":true,. "support_chamber_fan":true,. "support_aux_fan":true,. "support_send_to_sd":true,. "support_print_all":false,. "support_print_wi
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2232
            Entropy (8bit):4.11602786192638
            Encrypted:false
            SSDEEP:48:rpFWmPReA9f08EjdLdH9d4dUNxbdI0dpdphdXdndmdhdddP4+dYd++d2dy+dydwX:N8mpewf08gp7WKfIK/JtdEX7PB230y8Z
            MD5:92EEE974B9F7A19ECD0022A9D9C63586
            SHA1:C0226AB573FF359382004CD194833CCD629040FC
            SHA-256:E6D42E524C4D023E2A7CA20E150667C1421D4E8EDB140F86764DBAA1B589112E
            SHA-512:D6DDE7ADA7ED83985EABC259CC20E9894989C941D8BB3A681254F5DE2A6C7B7190FF36994126F37F781C3B78E00305E0D2CE128BE462F95EE5FC2BB83270A606
            Malicious:false
            Reputation:low
            Preview:{. "00.00.00.00": {. "display_name": "Bambu Lab X1E",. "print": {. "ipcam": {. "resolution_supported": [ "720p", "1080p" ],. "virtual_camera": "enabled",. "liveview": {. "remote": "enabled". },. "file": {. "remote": "enabled",. "model_download": "enabled". }. },. "support_motor_noise_cali":false,. "support_tunnel_mqtt":true,. "support_mqtt_alive":true,. "support_command_ams_switch":true,. "support_ssl_for_mqtt":true,. "support_cloud_print_only":false,. "support_1080dpi":true,. "support_prompt_sound":false,. "support_ams_humidity":true,. "support_auto_recovery_step_loss":true,. "support_auto_leveling":true,. "support_update_remain":true,. "support_timelapse":true,
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2109
            Entropy (8bit):3.993832086573198
            Encrypted:false
            SSDEEP:48:r/8MbF0hdEjdLdH9dU+dxbd1bdDpdphdqndmd8oP4+dHc2dRweVpy/hAd+MdqmJy:T8MbF0Xgp7Nf1ZD/JqdE8oPBHc0RpPix
            MD5:B41EF73F1C97F5FAED9BD5FA7023AB9C
            SHA1:FF27C1437E1ABED5DDE0A79D93AB14FDB8B7F6C7
            SHA-256:251F23526153056657F55AC6FF6EFD8B7CBE9F1720DA16457C48D41A7DD174D6
            SHA-512:7CBA79C6DB1BD39B92851ED6687003CDDF866ED9EE2EAB004771C3DD2ABD22BD5F1270044C7826B552F920440AF6752C653A55227CC408DF518960107870325F
            Malicious:false
            Reputation:low
            Preview:{. "00.00.00.00": {. "display_name": "Bambu Lab A1 mini",. "print": {. "ipcam": {. "resolution_supported": [ "720p" ],. "liveview": {. "local": "local",. "remote": "enabled". }. },. "support_motor_noise_cali":true,. "support_tunnel_mqtt":true,. "support_mqtt_alive":true,. "support_command_ams_switch":true,. "support_cloud_print_only":true,. "support_1080dpi":true,. "support_prompt_sound":true,. "support_ams_humidity":false,. "support_auto_recovery_step_loss":true,. "support_auto_leveling":true,. "support_update_remain":false,. "support_timelapse":true,. "support_filament_backup":true,. "support_chamber_fan":false,. "support_aux_fan":false,. "support_send_to_sd":true,. "support_prin
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2066
            Entropy (8bit):4.0061476829028315
            Encrypted:false
            SSDEEP:48:rY8MbF0hdEjdLdH9dU+dxbd1bdDpdphdqndmd8oP4+dHc2dRweVpy/hAd+JVty6d:08MbF0Xgp7Nf1ZD/JqdE8oPBHc0RpPiR
            MD5:7FE48C163189E34258BF858B77C57351
            SHA1:912B5731E7679F70D9CB28ED28296FB2771FE2A6
            SHA-256:8DEC8BC2293AE4B1C6C15B932C22AEA1ED4E25F1949A85CFBAD4B88A57A27592
            SHA-512:4FB0A5D618986C2F2C923936920E0AFC9C17C34B8E582EC4AF0E858D45358E2C27C8CCC21BC5DF24016B48F3EAD77CB0B44369E78DE2EBCAF12C3D1474B999C7
            Malicious:false
            Reputation:low
            Preview:{. "00.00.00.00": {. "display_name": "Bambu Lab A1",. "print": {. "ipcam": {. "resolution_supported": [ "720p" ],. "liveview": {. "local": "local",. "remote": "enabled". }. },. "support_motor_noise_cali":true,. "support_tunnel_mqtt":true,. "support_mqtt_alive":true,. "support_command_ams_switch":true,. "support_cloud_print_only":true,. "support_1080dpi":true,. "support_prompt_sound":true,. "support_ams_humidity":false,. "support_auto_recovery_step_loss":true,. "support_auto_leveling":true,. "support_update_remain":false,. "support_timelapse":true,. "support_filament_backup":true,. "support_chamber_fan":false,. "support_aux_fan":false,. "support_send_to_sd":true,. "support_print_all
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):509
            Entropy (8bit):4.345379767708786
            Encrypted:false
            SSDEEP:12:sDcmo3ovxooQaC2rW6c1SXyT+EaBqiqLtQa083:sQmo3joQt2S6c1SXyT+EaBqiqRQ+3
            MD5:9AB75BD27845D0FB2B5256035B211808
            SHA1:BC79677EA30DCCA1A1C9EB7C02DCA5061D5984FF
            SHA-256:1FDD9E3CBBDF43D2EE1FF3192AA3668BF7472C0D2D105B5452A49246D342A0C1
            SHA-512:58867DAFB988AF110177D48576DE00CC77D8F8DC9AEE332D7268EFE92E2B496FBD3B9F830BB21E2010B87C6043D26B4F76727606D900F444905E0AF25DBC2BE1
            Malicious:false
            Reputation:low
            Preview:M620 S[next_extruder].M106 S255.M104 S250.M17 S.M17 X0.5 Y0.5.G91.G1 Y-5 F1200.G1 Z3.G90.G28 X.M17 R.G1 X70 F21000.G1 Y245.G1 Y265 F3000.G4.M106 S0.M109 S250.G1 X90.G1 Y255.G1 X120.G1 X20 Y50 F21000.G1 Y-3.T[next_extruder].G1 X54.G1 Y265.G92 E0.G1 E40 F180.G4.M104 S[new_filament_temp].G1 X70 F15000.G1 X76.G1 X65.G1 X76.G1 X65.G1 X90 F3000.G1 Y255.G1 X100.G1 Y265.G1 X70 F10000.G1 X100 F5000.G1 X70 F10000.G1 X100 F5000.G1 X165 F12000.G1 Y245.G1 X70.G1 Y265 F3000.G91.G1 Z-3 F1200.G90.M621 S[next_extruder]..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):294
            Entropy (8bit):3.883270491490095
            Encrypted:false
            SSDEEP:6:OoQ6PjJ09V23q/Vi6Cow3QjmV0/SvPWnZh3y5Qgde69E:DQAjmo3X6CooQaC/Q4ZGre8E
            MD5:CE61DB1A3F441CAEACD3A397E6C7DEE2
            SHA1:F87BC46FA5F77AEF0A5E960F2A2AA5622AFB5BB2
            SHA-256:AB2EFEE18FFB311777AD5E06C0D0471290CA43ABD56ED2AD9F6D2DBBB15211D6
            SHA-512:D430598527A8B92B1A16271BBAAEC44D4C9F128E637CF8F9E51CFA71277B229837AD8D122D2D1FFD2FFEE59C57AA3397F23856DF5C33FBE28D435000CF784598
            Malicious:false
            Reputation:low
            Preview:M620 S255.M106 P1 S255.M104 S250.M17 S.M17 X0.5 Y0.5.G91.G1 Y-5 F3000.G1 Z3 F1200.G90.G28 X.M17 R.G1 X70 F21000.G1 Y245.G1 Y265 F3000.G4.M106 P1 S0.M109 S250.G1 X90 F3000.G1 Y255 F4000.G1 X100 F5000.G1 X120 F21000.G1 X20 Y50.G1 Y-3.T255.G4.M104 S0.G1 X70 F3000..G91.G1 Z-3 F1200.G90.M621 S255..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1325
            Entropy (8bit):4.267400200004619
            Encrypted:false
            SSDEEP:24:fhupafI8upafIxnzupFaxnqaupFm6xnWupFm6xnJupFm6xn1upFm6gZupa/JgMsd:fAa4aC+F8OF19F1YF10F5aVad
            MD5:01BAD7755140E999B0766970F667660F
            SHA1:32BAF122699E73648804462EBDE9B1D7049B9E1A
            SHA-256:4E2D6829BCE882F5ACB5D868A21CA32C0A3C20AFA86EB52A5DF3C950F0462CD1
            SHA-512:964070C679EE5C4D8AE5BB5BDBBE6418E9F2F4088A400CBC064F2AA01DFA322457C7A27AAE0C44D08B31FA26C88EF66BC3263294E1F3BE90A141374094F68A00
            Malicious:false
            Reputation:low
            Preview:{. "whitelist": [. ],. "blacklist": [. {. "vendor": "Third Party",. "type": "TPU",. "action": "prohibition",. "description": "TPU: not supported". },. {. "vendor": "Bambulab",. "type": "TPU",. "action": "prohibition",. "description": "TPU: not supported". },. {. "vendor": "Third Party",. "type": "PVA",. "action": "warning",. "description": "PVA: flexible". },. {. "vendor": "Third Party",. "type": "PLA-CF",. "action": "warning",. "description": "CF/GF: hard and brittle". },. {. "vendor": "Third Party",. "type": "PETG-CF",. "action": "warning",. "description": "CF/GF: hard and brittle". },. {. "vendor": "Third Party",. "type": "PA-CF",. "action": "warning",. "description": "CF/GF: hard and brittle". },. {. "vendor": "Third Party",. "type": "PAHT-CF",. "action": "warning",. "description": "CF/GF: hard and brit
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with no line terminators
            Category:dropped
            Size (bytes):11
            Entropy (8bit):2.1180782093497093
            Encrypted:false
            SSDEEP:3:0VbM+:0RM+
            MD5:44BCD92A541E3A0A5820524576284271
            SHA1:44A93BCFF7A7DE6A9356F9C6F9ADCB9084A2EF16
            SHA-256:0BA82D6546FE954F09C5B458172637673C58ADF9F1F85EA49814D41FE291919B
            SHA-512:B6C7BE8651892273063975173531E4D9D00CD9580F6B53A81B3F67FE9A8BFAE2237C9D5AD4C40F60C767A786ED4B33133190614BBD74D83DF30A0DEE5244083E
            Malicious:false
            Reputation:low
            Preview:01.08.03.01
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):4362
            Entropy (8bit):4.103379191299849
            Encrypted:false
            SSDEEP:48:Qt7aSyM1AsjqWVOvyw3drjLp5hREIFbL8Ld1r:IlPVehEr
            MD5:BBEC009029F2F2274AC64E1B09361603
            SHA1:118F59D6AB3FB27F448DB626614E90341979E482
            SHA-256:182EBF7E3A5D99B94662B81E5E04BB913B7C217BD731C1D586BF32A4F9A2FB69
            SHA-512:6F51D854E2D4AACE5DAD585BB8E79A200994A5FFA6C58BA84783E3001199BBB48C9EF370FCD4A8515285612F5B1FDF33DE376220E8D2FBF7D33BED526A39A273
            Malicious:false
            Reputation:low
            Preview:{. "name": "Anker",. "version": "01.08.00.03",. "force_update": "0",. "description": "Anker configurations",. "machine_model_list": [. {. "name": "Anker M5",. "sub_path": "machine/Anker M5.json". },. {. "name": "Anker M5C",. "sub_path": "machine/Anker M5C.json". }. ],. "process_list": [. {. "name": "fdm_process_common",. "sub_path": "process/fdm_process_common.json". },. {. "name": "0.05mm Ultradetail @Anker",. "sub_path": "process/0.05mm Ultradetail @Anker.json". },. {. "name": "0.10mm Detail @Anker",. "sub_path": "process/0.10mm Detail @Anker.json". },. {. "name": "0.15mm Optimal @Anker",. "sub_path": "process/0.15mm Optimal @Anker.json". },. {. "name": "0.20mm Standard @Anker",. "sub_path": "process/0.20mm Standard @Anker
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):12532
            Entropy (8bit):7.905201277563467
            Encrypted:false
            SSDEEP:384:/0jn0r7qOsDdj/QGBNyk9Ig2atR8uN02lbexwTV:/0j0i3p0aIk9Ig23u3lP
            MD5:A1DA724F50DD371E7F1B9147940648D7
            SHA1:6EE2B3591ADC6D983CE7C5CC4007D27CFA3CE2AC
            SHA-256:B283E0E9FA08C8E24ADAF79E61E0309698E8DBB8C10013241BB6DF4A2366D5E7
            SHA-512:E0A967CE21F7E86E30EA6E61EE311EFB7CE013B99F53DE310B129814FDA6A4EF2A35175AEDF3C6CDFD613E452C34244B0F769D5225ED06795FD3514076D645CF
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................e....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". tiff:ImageLength="180". tiff:ImageWidth="180". tiff:ResolutionUnit="2". tiff:XResolution="96/1". tiff:YResolution="96/1". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="1". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". xmp:ModifyDate="2023-07-14T15:12:26-04:00". xmp:MetadataDate="2023-07-14T15:12:26-04:00">. <xmpMM:History>. <rdf:
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):15390
            Entropy (8bit):7.959199600900811
            Encrypted:false
            SSDEEP:384:lvP++X8c+UtSmYOe7dTwp3+N1KvKuJXDN77q5yEBHd:lvP++X8c8mYvUpa1oJTN77Ydd
            MD5:BE00BB97F408A3B0C454B1CD664981F6
            SHA1:3EB2FC02330429E5D0F01A9EFF101E7BDC79DC2E
            SHA-256:F3387DE6C5C200D88ED87094871414BDE1B4FC7AC903CDA4A7913DEF0ADC1121
            SHA-512:5BEEF1ABE3D625B78CCFD6DEBC24C0A712FAAF6FFB48AF627B4644628A43ACE397EBDD78732E6E251F465E5B092A296D94365120CFC1EEE0A03EA0B2B4149B5D
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................e....pHYs..........+.... .IDATx..i.d.U&x....{dDdVVU....TH.R..hmIH%..0=..G....4.i..l..k..h..M.f.......!...4.*$.%.T..=....w..............<<.=.......`..N...`......8.k.....c......8.k.....c......8.k......8.k.....c......8.k.....c......8.k......8.k.....c......8.k.....c......8.k......8.k.....c.....k....\.%..".y..-3. ...Zk..8...|.+....Zf.a...2[c.$.. .. ..?8z.....uu....?....>......[m.`f......... ....?...~.]..&W.7...>.....?2...h..".H....._Y]>q....D..~....|..s..........f......L.!.....hLLL"......o....$..$.S.....$..ic.0.....6.xhbb.....?..._W......9J.HDJ!.y.g..?..i..e!.s..Y.GQ8.....j..###.....1. `..y.+..R...v]]|..} ...7.# 3#.[...8...K.t...".. ..c.e...uY........Q..:.l@f'.ED.C.,Dk-..e.&kY..Y.....y.Xk...o...."..)"...DX.......iLt... =........:u.( ......i..Y...a.M..K_z.....H)B"..5_.r..........A..._..#...d...(...^... ...###.. ....p.B..8....p&. .."... ..lnnZk..0..~.4.R..i E..RDD....>..o:...4]y.|.9....y1..VY.=.....H..,Li...+.P.....hS......7.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):36084
            Entropy (8bit):5.60965219200579
            Encrypted:false
            SSDEEP:768:cVxQ48tmZm/RkUk5l2s/PcAHZIx2PpOhBt:cVJ8tmZmJkUk5/PccZIx2PpOhBt
            MD5:2897C7066330BC867844871E25AED33B
            SHA1:F3A39814873FD9C35410756CF443A467099E833D
            SHA-256:EFD5D7E3B6E525D33DF9E298F64BE761DA2049F7041033E60F3EE922B335B4A4
            SHA-512:7EBABD460F229ED7C3B54A3DFFAC2CEC712866F7BBC258CE41AFEB3F54020E217EAF6F3A78A02546C42ED2B2C4F8CAF2AB3C12701214694F6260AFFA1C2AD74F
            Malicious:false
            Reputation:low
            Preview:................................................................................................................@.B.........@.B.......................@.B....J......B.............................J......B....J.......................................c..................J................C)......J..............c...........c.........y.u..x.........c...........c.....................y.u..x.........c..................................b./.k..............................7..E..........b./.k..................7..E........7..E.............................................7..E.................................7..E............u....................................u......X...................................X..........d..............................................d.............IZ....................d..........d.............IZ....................d.......................?Al..-.........az..............................?Al..-.........az.....................az........6.x..q.....T...
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):7462
            Entropy (8bit):4.225964914374582
            Encrypted:false
            SSDEEP:96:1kurboctkzNJIvQ5YntBBZ/MnjHSeaaDRqBOCa1ADscBIyKrzJ0Tcpw4rwfmAf63:1k+b4blOnjhe7RpAGUOAis3goZbPPQ
            MD5:699741ECDEAFA1F05AAE1FEB0B9633B7
            SHA1:8A136030D0C6F676F79062482D03EF45FF4D89A7
            SHA-256:1BCB3DE590731610EA6EE9A816F7F2A32C11CD6098CAA663B698BC6B3C821975
            SHA-512:696207495B9624B8F08445E638110A04FC10433786738DCEDF9CE502F3E5D2AEE2C2D7DB46DC362F942E3BCE1952A9BB8C0D9361FD9324AACFD5425B4CA913E3
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="UTF-8" standalone="no"?>.<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">.<svg width="100%" height="100%" viewBox="0 0 2776 2776" version="1.1". xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink". xml:space="preserve" xmlns:serif="http://www.serif.com/". style="fill-rule:evenodd;clip-rule:evenodd;stroke-linejoin:round;stroke-miterlimit:2;">. <g transform="matrix(1,0,0,1,-825.477,1083.19)">. <g id="Layer-1" serif:id="Layer 1">. <g>. <path id="path1042" d="M893.14,1449.47C893.553,1448.37 924.014,1364.64 933.494,1338.55C937.632,1327.16 941.335,1317.03 941.723,1316.04L942.431,1314.23L975.67,1314.23L976.649,1317.02C977.857,1320.47 1024.15,1447.55 1024.78,1449.14C1025.2,1450.22 1024.17,1450.29 1008.46,1450.29L991.679,1450.29L982.915,1424L935.26,1424L930.802,1437.14L926.343,1450.29L909.589,1450.29C896.459,1450.29 892.901,1450.11 893.142,1449.4
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):22084
            Entropy (8bit):5.174079549364883
            Encrypted:false
            SSDEEP:192:hc015Tsz1syfxfrMyiRVkPieolS/fsr0Iz2oL6OYPlIgmdZ7T9F:oieol7UHPlI
            MD5:519CB2599919404B8AACD47107823E06
            SHA1:22B38D71D937A9521DD85DCC8EDA619C08426A8B
            SHA-256:088009F13A6A35CC09CD4DEF6A163EC0A54DF545AAB421D0A15D9F0DDD1E41AF
            SHA-512:63864906B68B3AAD7C29D20C975634E512E718B359C2BD07DCD6D0A4132787F2612847107A6CBEC12311551F6571D371577731E4A0BB4894DB700CAB14D874C2
            Malicious:false
            Reputation:low
            Preview:....................................................................................................-..........3J.B........3J.B......................3J.B....7....s.B........-....................7....s.B....7...V..........-........................%...........-......7...V............g.......7...V..........%...........%.........o.s...x.........%...........%........>..?w........o.s...x.........%........>..?w.......>..?w........xR...l......>..?w.......>..?w..........m........xR...l......>..?w..........m..........m........................-.......>..?w..........m........................-..........m....................................-......................R........................-..........R..........S...................................-..........S........Y.Y.a......................S..........S........Y.Y.a......................S.....................k.J;...... ..6.................................k.J;...... ..6................... ..6...........x..^t.....f...
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):422
            Entropy (8bit):4.4894957490498015
            Encrypted:false
            SSDEEP:6:fS5TDY80htzEHm4bD0dlz9JvFmu+oE99mqbDf6zwhnww/KyqrbLRFC0MrMCkCK:KY3hJYR0dlpTmu5umqvzGTrbLRMrM8K
            MD5:438836E0C6189D45B4EC1D2336A292E0
            SHA1:C3DB79154AE9E10837750E1ABB5DA28FAAFBC883
            SHA-256:961FCFB22792DB80DD01340792B56713953C26C3DA4CA15F527D68F23C449F54
            SHA-512:586FD4513BECBA31D8F474922AD917E9DDF0B564E34F9A8FEF04A8061D7FE179A5F65630CD69C0D3B2BCBA23E66331550D80A970311532ED89E1FA0D53FAA644
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFB99",. "setting_id": "GFSB99_Anker_00",. "name": "Generic ABS @Anker",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_abs",. "filament_flow_ratio": [. "0.926". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Anker M5 0.4 nozzle",. "Anker M5C 0.4 nozzle". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):421
            Entropy (8bit):4.482252879318061
            Encrypted:false
            SSDEEP:6:fS5TDVz80htzsjSm4FrY0dlz9JvFmu+oP99ObDf6zwhnww/KyqrbLRFC0MrMCkCK:KVz3hJsm40dlpTmu5jOvzGTrbLRMrM8K
            MD5:B0450F429209C38EC0B060F7D013F772
            SHA1:FAF508B6DBC6E57BDC02F334C1E2905E743AA279
            SHA-256:CD0FDD93FA2207683AB8C07C5EFB9E1A91D157E0469992176CDDCCA640A2C840
            SHA-512:49B53E653DFE17DB1D2E3BEC3A6E893DBEF1D3032911B161F55CD495534B35BA8B0ECC3BB788B984669E9185980AC7C1095B78607C9BE5E92897DEFEA423C4E2
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFB98",. "setting_id": "GFSB98_Anker_00",. "name": "Generic ASA @Anker",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_asa",. "filament_flow_ratio": [. "0.93". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Anker M5 0.4 nozzle",. "Anker M5C 0.4 nozzle". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):449
            Entropy (8bit):4.434518165714195
            Encrypted:false
            SSDEEP:6:fS5TDs80htzIHm4HY0dlz9JvFmu+o/eTQXALQ1NQQoTQXAPbDf6zwhnww/KyqrMv:Ks3hJE20dlpTmu5/XSQlxIvzGTrM8K
            MD5:BDC14F284EE39D1775CE7662AB63D8A4
            SHA1:C1B30A38FDEA4B56531811F524BC3430BEA7B73D
            SHA-256:8C133E8674AE4327DC8CB74945EC37A2C59B15A1583981D25E7518071B231B89
            SHA-512:089D3A953CB525456081678159B4D1CD673F41B10AF986516AE4E3125F6AD939FDE57C3126777B5F173E5DC1D83CFB4DC22C8E57C10202708429A2D172BB25B3
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFN99",. "setting_id": "GFSN99_Anker_00",. "name": "Generic PA @Anker",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pa",. "nozzle_temperature_initial_layer": [. "280". ],. "nozzle_temperature": [. "280". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Anker M5C 0.4 nozzle". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):439
            Entropy (8bit):4.422145513357976
            Encrypted:false
            SSDEEP:6:fS5TDRz80htzgjSm4a0dlz9JvFmu+o/9i5HwoTQXALQ1NQQoTQXAPw/KyqrMCkCK:KRz3hJgmE0dlpTmu5/cqxSQlxITrM8K
            MD5:1E9B6E7FC9E234101D1D650460F6521F
            SHA1:EA9A556CB2C14671B18BC1F10C8048C97CDBAD9D
            SHA-256:DC82784A6FA62EA5021D5F0D3E0C045A49FF516A9FB5E88B9509769ECCFD0ABA
            SHA-512:324409C96CDDCBAE35057DE992B2ED1C86E4397E80D682261708AA1D004D3730C89AB1E8550BA34B5E9CE370FB286A0AF2F35FF5C92B1DA5687D54DA5C245522
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFN98",. "setting_id": "GFSN98_Anker_00",. "name": "Generic PA-CF @Anker",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pa",. "filament_type": [. "PA-CF". ],. "nozzle_temperature_initial_layer": [. "280". ],. "nozzle_temperature": [. "280". ],. "compatible_printers": [. "Anker M5C 0.4 nozzle". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):7462
            Entropy (8bit):4.264061300719105
            Encrypted:false
            SSDEEP:48:r7akONpIHe4bzQSo2UNI6f21AM6CHnfZ1C1AZfa1smAVOvyw3drjLp5hY+M2rEIv:X7j+YJHVKh7r
            MD5:B363378970AAA89573A870B3BDD06D1A
            SHA1:C93CF15A839F8A1CD1DF902031ADBDD8FA227C52
            SHA-256:40480E4C02CEF4A9BB67E010BABA190EBE10B0A5DEAC1E4C541025251FC0C4E6
            SHA-512:ECFAD234881985487D60BC5E1699F93183E15993F1D504AAF5BD4ACDFBC187DD7FA956850032CA59F57D7E61984B5B0CE135B928D9D3535A7323A9EDC44E75B7
            Malicious:false
            Reputation:low
            Preview:{. "name": "Anycubic",. "version": "01.08.00.03",. "force_update": "0",. "description": "Anycubic configurations",. "machine_model_list": [. {. "name": "Anycubic i3 Mega S",. "sub_path": "machine/Anycubic i3 Mega S.json". },. {. "name": "Anycubic Chiron",. "sub_path": "machine/Anycubic Chiron.json". },. {. "name": "Anycubic Vyper",. "sub_path": "machine/Anycubic Vyper.json". },. {. "name": "Anycubic Kobra Max",. "sub_path": "machine/Anycubic Kobra Max.json". },. {. "name": "Anycubic 4Max Pro",. "sub_path": "machine/Anycubic 4Max Pro.json". },. {. "name": "Anycubic 4Max Pro 2",. "sub_path": "machine/Anycubic 4Max Pro 2.json". },. {. "name": "Anycubic Kobra 2",. "sub_path": "machine/Anycubic Kobra 2.json". }. ],. "proce
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):82393
            Entropy (8bit):4.3099053809277015
            Encrypted:false
            SSDEEP:192:d6GFwRhuhu65klSvifN+OL8NklDzVC20Nf9tuVCdhst0dHnTlkDWxD9NSnkthr7:dr3
            MD5:BCCF59FD271EFFAE203DED425F0F74A8
            SHA1:8BF5FCD42660831053D08ACD3010E337E22AA008
            SHA-256:F70F930504C8860C37CAF9EE5088372F24EC0E9B30D73EF6D8126311D272C94B
            SHA-512:AE87B2CBB3DEEE031E9A439CB978351FE8E40D8BB07E2A2B4DFE07AA7B4AD3798EC36058FE818B46F31632941F711B30ABDE7505BDD46B3DDC7FAE6E1FA367CC
            Malicious:false
            Reputation:low
            Preview:{. "name": "Bambulab",. "url": "http://www.bambulab.com/Parameters/vendor/BBL.json",. "version": "01.08.00.18",. "force_update": "0",. "description": "the initial version of BBL configurations",. "machine_model_list": [. {. "name": "Bambu Lab X1 Carbon",. "sub_path": "machine/Bambu Lab X1 Carbon.json". },. {. "name": "Bambu Lab X1",. "sub_path": "machine/Bambu Lab X1.json". },. {. "name": "Bambu Lab X1E",. "sub_path": "machine/Bambu Lab X1E.json". },. {. "name": "Bambu Lab P1P",. "sub_path": "machine/Bambu Lab P1P.json". },. {. "name": "Bambu Lab P1S",. "sub_path": "machine/Bambu Lab P1S.json". },. {. "name": "Bambu Lab A1 mini",. "sub_path": "machine/Bambu Lab A1 mini.json". },. {. "name": "Bambu Lab A1",. "sub_path": "machine
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):688
            Entropy (8bit):4.33685533405214
            Encrypted:false
            SSDEEP:12:M2QKEgU0UhJV7lpTSdvwOdGFOXXcGF0kW1s1NA:TJqPRpTSJwUQsXcQ0/qzA
            MD5:FD7A8CB8E453CF7AF9DD2D03AAB0CC20
            SHA1:7ECCCB820C6C21FE79F794F3A531731A5CE8C2C3
            SHA-256:23C93ABCE995C779093BA30118D3A59C8F5DD18B51B7708B074385F84A6580F2
            SHA-512:6D71A2B87B57AFCC36F2E1FAC66DDD57819121C43868A24AF87A46EDC1C1BB237FEF04CE1CCD52F2EFDAE712297EE0BFFFD815B0C8F4C5AE4AD5252FA21A0950
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Glow @BBL P1P",. "inherits": "Bambu PLA Glow @base",. "from": "system",. "setting_id": "GFSA12_02",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_min_speed": [. "50". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab P1P 0.6 nozzle",. "Bambu Lab P1P 0.4 nozzle",. "Bambu Lab P1P 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):327
            Entropy (8bit):4.5660027858763685
            Encrypted:false
            SSDEEP:6:fS583FYF0h+W0KRFYF0pG0H0htzVmlz9JvF/Df6zwxdqw/Kyr3sV+2CA:MeIW0KEepG0UhJVmlpTbzrqkscbA
            MD5:688A2814BC21DB75788FB2A718CC2E09
            SHA1:60181E7CFFE3B82D158E9D56E6ADCFA19CAEC5CD
            SHA-256:1C859BFB3BFE8E5DA4D942F360FA8DF47B99DF0F122D5CD5D6149E8824A96277
            SHA-512:F3E97F3E599586FE18448F00C60E8B7735C38D99089DE598094BC554528281688A18CA338102DC84BBF76E5DAEE946925A57566FAE5B88A5890D0594092CA2E7
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Glow @BBL X1 0.2 nozzle",. "inherits": "Bambu PLA Glow @BBL X1",. "from": "system",. "setting_id": "GFSA12_09",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1". ],. "compatible_printers": [. "Bambu Lab X1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):375
            Entropy (8bit):4.469938835826282
            Encrypted:false
            SSDEEP:6:fS583FYF0p0KRFYjqdU0H0htzVKclz9JvF8Jcw/Kyr3sjC053sJgh053sH+2CA:Mep0KEgU0UhJVKclpTLksjl1sT1sH8A
            MD5:E85A24E993DDBB64D55A9B2104F86A4E
            SHA1:A60DDEADA15418962ED7C073FE5ABD7D0C0747A7
            SHA-256:A8D8F2CAF6F4BA7C2D95D1457A5AAD14731FDD1FA16B3BB72ACA686E74CADDF7
            SHA-512:E86F30EFCB02BBDB81E26405B2CFF9656CC4CC9793318062986CCE0B896417B98C771C715658C2BA38CC9B9ABCA8900DCBE28AD1B8EE9C01DEC28193592D3D7D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Glow @BBL X1",. "inherits": "Bambu PLA Glow @base",. "from": "system",. "setting_id": "GFSA12_08",. "instantiation": "true",. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):372
            Entropy (8bit):4.573397671866983
            Encrypted:false
            SSDEEP:6:fS583FYF0yVgW0KRFYF0wJm0H0htzVOlz9JvF/Df6zwxdqw/Kyr3+XwBMW53pFzn:MeyVgW0KEen0UhJVOlpTbzrqk+XwKW1v
            MD5:529826CA2DD6925B88B9AE02C881CBA0
            SHA1:D54075E3C19037A0AC7A38CC75311228267DDA97
            SHA-256:33C871344090CD2DEC32480C7A86F9BCBA18DC39791AC743F0A3B2B13B4185FB
            SHA-512:22CEB1451681BCA040C6B078412A2C63651E5FAA2B1F15F7624FD0EEC273A9D45A62FBBC51BFB6B4CE95BA7FEBFF74078A761BE6504CF05BCDF87A5EDBAC54FE
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Glow @BBL X1C 0.2 nozzle",. "inherits": "Bambu PLA Glow @BBL X1C",. "from": "system",. "setting_id": "GFSA12_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):456
            Entropy (8bit):4.466428539302966
            Encrypted:false
            SSDEEP:12:MehKEgU0UhJVFlpTg+XwHP1+Xw91+XwLP1rxl1r91rl8A:0JqPPpTnXwHPEXw9EXwbDlX8A
            MD5:45E2E7D8D07C92BB33801009285F288B
            SHA1:550C8AA094F853018E557A1AD340D98BB0069B43
            SHA-256:1B1A4F13E334D095C955E5B55DFD9A61F52B342DD6B47F4F531FD244FEF1B2EA
            SHA-512:9E410E7E2789C62B99D38E4C22C4395ADE9D8B3D952321172960378F8DE815E3FFECE8533962D0DC4079E88BA481169A64869865029614DA126E516F03982740
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Glow @BBL X1C",. "inherits": "Bambu PLA Glow @base",. "from": "system",. "setting_id": "GFSA12_00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):330
            Entropy (8bit):4.599198006795928
            Encrypted:false
            SSDEEP:6:fS583FYF0AKW0KRFYF0ChFU0H0htzVh0lz9JvF/Df6zwxdqw/Kyr3Pg2CA:Me9W0KEeChFU0UhJVh0lpTbzrqkPgbA
            MD5:0A1AEF9D6EF7E8808D0549F9DFC7BDB4
            SHA1:CEF6A8475D20224C4BC63BAB5D37B64B284484A9
            SHA-256:22CE6BD402E563B4B0E603863B25CFF8C09F291604A5EF4DBE1A2325CB32D15E
            SHA-512:2FEFAEE02D69CCD682947A8840632BA837087A53F711118D6946579C5629C4A138E0A18D3526D815671CE993DAA0C9530B1B9D438397D07E18B039A13E5063C1
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Glow @BBL X1E 0.2 nozzle",. "inherits": "Bambu PLA Glow @BBL X1E",. "from": "system",. "setting_id": "GFSA12_05",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1". ],. "compatible_printers": [. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):330
            Entropy (8bit):4.540238512480522
            Encrypted:false
            SSDEEP:6:fS583FYF0ChFmKRFYjqdU0H0htzVJlz9JvFs/Kyr3P6053Peh053Pi2CA:MeChFmKEgU0UhJVJlpTgPd1PP1PAA
            MD5:1E20D65BA79BB4F55F0904BFBC899880
            SHA1:9A38A9541880B281F9822E838DF33ABAFDB95947
            SHA-256:C6F56AF4AD179817889E6CA4D5129A5E05C8450029785B0494C04DEDE15CC903
            SHA-512:E760A561B79AC53F590B0E5529C05040A2B37073E53438F0B2F30FF719B0643E7DB0621175B620B13A31676D4A106955B6EBDABFE3703E9527441BF40F2D4B03
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Glow @BBL X1E",. "inherits": "Bambu PLA Glow @base",. "from": "system",. "setting_id": "GFSA12_04",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1062
            Entropy (8bit):4.8390406148922445
            Encrypted:false
            SSDEEP:24:tr5TiU6psqlRvg4mlJnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:N5TiU6pswQhr+EW+Yn1B/P
            MD5:DB3CC5BE80C021E3E67AD933F6B8B16E
            SHA1:82379705716A20CD2231E2045C8CA5A634F8B533
            SHA-256:1E1F211ACB244BC87493368F4A070C9224692AE00FB589BE75C931C367D6BBFE
            SHA-512:AE08BE190811B8618210F3CD5DAA5EDC71A4D02ABC14EB970559EC1191666157D1CCE0694E72FB5F11A4094377D236EA71213D912F5DDDA5D09A35E80B7EE046
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Glow @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFA12",. "instantiation": "false",. "filament_cost": [. "29.99". ],. "filament_density": [. "1.26". ],. "filament_flow_ratio": [. "0.98". ],. "filament_max_volumetric_speed": [. "18". ],. "filament_vendor": [. "Bambu Lab". ],. "temperature_vitrification": [. "45". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_pri
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):392
            Entropy (8bit):4.580839481669392
            Encrypted:false
            SSDEEP:12:8hJv3n0dlpTmK6hbzmE+XwHPtsjltrl8K:yVkHpTShb6jXwHP6REK
            MD5:81A9A12544D712ADFD07FAA0F753DB14
            SHA1:44D0FDBA311DCB1CE2E1AF3A4F3925D1D4D36A4E
            SHA-256:F3BAC980B1028E770482D9B8D6FB28B59DC6EF50286401F9660F163F459DD883
            SHA-512:7B91EF180C85E078EA467EE59C12DB96DC427CBF1B9C80AA7ACF8B08095D6F385796408DAEDDC452EED0A27E4C8DBBDE5211B5244CFD91E9777A0376A44BFA80
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "setting_id": "GFSA03",. "name": "Bambu PLA Impact @BBL X1C",. "from": "system",. "instantiation": "true",. "inherits": "Bambu PLA Impact @base",. "filament_max_volumetric_speed": [. "23.2". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab P1S 0.4 nozzle". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):328
            Entropy (8bit):4.295196270557748
            Encrypted:false
            SSDEEP:6:fS583FWoEWCdmu+o8h0yDhvlz9slKeR1QbgWLQu2b93FqA:Shmu58h0illphcpu2h3oA
            MD5:8B46660AB5FF33D2D9133D8CFFB550A2
            SHA1:F7E5E99F8FAA40FD8B0859C7805F183EE6878A97
            SHA-256:66BFBDB012628378A86B9CE82F349B1829E691CE2BE6AAE08443AF6BF91D6BE6
            SHA-512:3122CE7F53CE5A38569060AA7B725F63D8F0067B50D89C1AF7DD8B7517D20014C58116D122EEB0C5CA01D7B0D3E7558E76DB8E682845E0765FD558CADA919C73
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Impact @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFA03",. "instantiation": "false",. "filament_vendor": [. "Bambu Lab". ],. "filament_cost": [. "25.4". ],. "filament_flow_ratio": [. "0.95". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):731
            Entropy (8bit):4.298250001207491
            Encrypted:false
            SSDEEP:12:fKNTU0UhJwlpTSPwwxdPOdGFOXNcGF0kBR1BT1BcA:aJq2pTSPwcpUQsNcQ0QDsA
            MD5:8B6ECBF9EFDE1FF5544FD8DBF8320AC9
            SHA1:B89487C1A4B018F88336EEB5244B8DB1FA8B884C
            SHA-256:DAA569FACE141D4CE49586ADD87C67130D67097F3B6EB44562A7B97E24DA32D7
            SHA-512:082DCBE3AD84A6D8C1F1AA6B519E3FA127F5B3AA36CA3B1AEA6F6B3CA182028A52CDDFA1137759B8421644886A545BC0D50384FB89CED7DAD48FA4C403C811FB
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Marble @BBL A1",. "inherits": "Bambu PLA Marble @base",. "from": "system",. "setting_id": "GFSA07_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):747
            Entropy (8bit):4.3019921001056565
            Encrypted:false
            SSDEEP:12:UKNTU0UhJHlpTSPwwxdPOdGOO4NcGF0ko1i1RA:XJqfpTSPwcpUPjNcQ0x4LA
            MD5:78EDCF61A00C19D736C0956A815DB8FF
            SHA1:06E8CBDE731FEF0CDD03BCF47107849873691088
            SHA-256:75D55F7311751057DDF5E6EF46F0563B801A314A423DCE1DD0AC0EF538D5E9D6
            SHA-512:2044AD32681DD3A51BF24139A856CF4EFA964635C3575D9FC26259A5976C97D51D377DA4855290E26740FC1330B7C94DBBA354DFAE213939F00BCED18F1E4977
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Marble @BBL A1M",. "inherits": "Bambu PLA Marble @base",. "from": "system",. "setting_id": "GFSA07_02",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):379
            Entropy (8bit):4.467792617604318
            Encrypted:false
            SSDEEP:6:fS583FSv0p0KRFSyWqdU0H0htzG+alz9JvF8Jcw/Kyr3sjC053sJgh053sH+2CA:zp0KNTU0UhJXalpTLksjl1sT1sH8A
            MD5:2628E1E40CD72358FE8CD02F2F26FB7F
            SHA1:1DFB9EFD33381713FEA3E8A2E86827E67FDCB500
            SHA-256:4C74D8F8F0EE6676428FBE00342812E6574C21EA6EBD6D1485C07F19A5678009
            SHA-512:6C0DBC7C4229148C95507BEA67B5C304B1379E0C0D1A24A24FC50FA66B31D14F8AFC9DF914A2CCD320DC48E03803618DA7F9937404D73CCF3481C11C3B0F3765
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Marble @BBL X1",. "inherits": "Bambu PLA Marble @base",. "from": "system",. "setting_id": "GFSA07_01",. "instantiation": "true",. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):568
            Entropy (8bit):4.402461099141884
            Encrypted:false
            SSDEEP:12:zhKNTU0UhJAJUlpTg+XwHP1+Xw91+XwLP1rll1r91rxl1Pd1PP1PAA:EJqhpTnXwHPEXw9EXwblXDlBdBPBAA
            MD5:84D6A97458586E1979126109690D1311
            SHA1:6A2BB206C3E584244AED5A788256C1819494AFE1
            SHA-256:9449550950760BC76DD750B4C001E570F928DA94F9617A6182205B2A49A5C90D
            SHA-512:7B6A2F487DBDF86C761CCE41EF79473A02E94180700AD96395C1EDB4579602CBBEF1FE37311E1B4632194557B0D95076F2C72CD576D9E48B3F7F6C6DB0B61821
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Marble @BBL X1C",. "inherits": "Bambu PLA Marble @base",. "from": "system",. "setting_id": "GFSA07_00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):950
            Entropy (8bit):4.883562995159512
            Encrypted:false
            SSDEEP:24:Vr5Ti7psqBR4JnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:15Ti7ps9hr+EW+Yn1B/P
            MD5:C68B96314B77C13C832342EB983DC284
            SHA1:14634ABEEAC06293E136BEA2A0A31D38B4C41E73
            SHA-256:CC6A04C579543D6F3681431E57815D2FBF4734BD89FF88FB139B5E3B831C2FC8
            SHA-512:5B8A6CC1243B3A68CF433234D764781EE8A9BE1E1E3FC22A05925FE980FDB7E99925D25015D1CAA9D20CA8FF65FEF850209B4C1FF7982536F085A2EB2334C45B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Marble @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFA07",. "instantiation": "false",. "filament_cost": [. "29.99". ],. "filament_density": [. "1.22". ],. "filament_flow_ratio": [. "0.98". ],. "filament_vendor": [. "Bambu Lab". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):728
            Entropy (8bit):4.278607214900651
            Encrypted:false
            SSDEEP:12:iKW0KbTU0UhJBlpTSPwwxdPvzPOdGFOXNcGF0kBcbA:iBNTJqxpTSPwcpvjUQsNcQ0bA
            MD5:2904DD7E350895B78BAEAEBD1BE80228
            SHA1:9DC1C7CA5C4CEE8CFAE69AE6D4BC032676C72D95
            SHA-256:039114AD04ED6934FC221B13126A10EC23125B7115AD75BABAB0AA3CD0FD656F
            SHA-512:EE66C060A6221FEB45DA878BC8FE9D6014B5E59B71ED0ED85B6868219ECA9EC93EB6D74D97B81B7725D4F368477A92733A717CDF34A06AE0FF0A3A21EA414282
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Matte @BBL A1 0.2 nozzle",. "inherits": "Bambu PLA Matte @base",. "from": "system",. "setting_id": "GFSA01_06",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):788
            Entropy (8bit):4.294173512449997
            Encrypted:false
            SSDEEP:12:RKbTU0UhJXlpTSPwwxdPvzNOdGFOXNcGF0kBR1BT1BcA:sTJqvpTSPwcpvpUQsNcQ0QDsA
            MD5:DDC9D88699703FAAC703FA437CD523A6
            SHA1:2518884316A83BF0DBF980A52650CF1B4FD52E17
            SHA-256:660D3D68050E3BF2ABF9C886BF265DE90B78FC961E4BD629A3B3BAB7FC3C2378
            SHA-512:FAFA4D76B3ED782BFB6B8A34C742959586524B633503EAD7F427DA02C89454ACBA2B8C35B871202333CFC54A0F21A7C83A481A5F23078E2AD1BD2276F2ECAE80
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Matte @BBL A1",. "inherits": "Bambu PLA Matte @base",. "from": "system",. "setting_id": "GFSA01_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "22". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):734
            Entropy (8bit):4.286791930089385
            Encrypted:false
            SSDEEP:12:J+W0KbTU0UhJtUlpTSPwwxdPvzPOdGOO4NcGF0kfbA:TNTJqkpTSPwcpvjUPjNcQ02A
            MD5:79487944B800025E35C9A89004DB7F54
            SHA1:9EB6718650AC9000930DC0253B36E0BD7D36B23C
            SHA-256:FC1C960CEFA087D205A7FA6478A256B06EFCE2850E7C182644C71E76EE39FF46
            SHA-512:F2E5451A9BA44CFB23F0F2D3932E0C2D87FCC5837265619792605337FE805E201A68CAB1EB4ECC17A0EF1B71A93F7744F2EF9F6D995AC66C0517921D88AD39BC
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Matte @BBL A1M 0.2 nozzle",. "inherits": "Bambu PLA Matte @base",. "from": "system",. "setting_id": "GFSA01_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):804
            Entropy (8bit):4.296593299963939
            Encrypted:false
            SSDEEP:12:iKbTU0UhJ9lpTSPwwxdPvzNOdGOO4NcGF0ko1i1RA:/TJqdpTSPwcpvpUPjNcQ0x4LA
            MD5:BC279DD1054A88B896F818C2D3AB8B7F
            SHA1:4074E4C18F1D927B765C674BA306882697844E33
            SHA-256:70EA4C0C3580570909F0A8E518E1D734BD4C8C01C6B1B76607670EDC4DCA18B9
            SHA-512:57539714F8EB9ECA4E8E28ECB501F3D3C3A9E3CD4D31FD41BF102A203729641208DFB2D369CA0A6B6B7BB8EBB01D88ACC3C2D81CB9914BD5F971D93CE2CAF80B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Matte @BBL A1M",. "inherits": "Bambu PLA Matte @base",. "from": "system",. "setting_id": "GFSA01_02",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "22". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):433
            Entropy (8bit):4.4615720367530125
            Encrypted:false
            SSDEEP:6:fS583FSkp0KRFS6JdU0H0htzP0lz9JvF/Df6zwNgJcw/Kyr3sjC053sJgh053sHn:dp0KbTU0UhJP0lpTbzNXksjl1sT1sH8A
            MD5:297369CCA9EF1E782CB03F9DBD32B879
            SHA1:00986BF0A7E8FD8CBDD4335FB929E9E40CA28E03
            SHA-256:2221936EE703D0AC04A770DA5A86C43CF51ACEE230B39BED4E4BE0D9A0963E27
            SHA-512:7E8A75DC8B6EE4D477EC894BF38E901CDD65716534A0C5B07F5C52AA138609523D2F0466378BA2AAFFBD42176C719443D51FBA2D06E809506DF91B3ADC4A3F7D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Matte @BBL X1",. "inherits": "Bambu PLA Matte @base",. "from": "system",. "setting_id": "GFSA05",. "instantiation": "true",. "filament_max_volumetric_speed": [. "22". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):442
            Entropy (8bit):4.491902451115311
            Encrypted:false
            SSDEEP:12:dyVgW0KbTU0UhJTlpTbzPk+XwKW1scW1rKW1PgbA:UjNTJq7pTbjDXwBS/LBKA
            MD5:999F2E3CA85F8B502284B5D63BC88A1E
            SHA1:182D0A1F442E063E2DBBED347AB94156D4D65328
            SHA-256:274A06203E07FC01F8F0FFDF20C0857395685050F5FF6121883818186F1FD806
            SHA-512:1AAE923833E96973BCA4EB785519CB0E1195A3B173C20C11E341D92776938B889DED5C7F88046AD1869498EC4248ABB1B11568FD0A6C20A1DE03936623DB6D46
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Matte @BBL X1C 0.2 nozzle",. "inherits": "Bambu PLA Matte @base",. "from": "system",. "setting_id": "GFSA01_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):408
            Entropy (8bit):4.537450795354542
            Encrypted:false
            SSDEEP:12:dyVZ0KbTU0UhJMlpTbzNk+XwLP1rxl1PAA:UZNTJqCpTbpDXwbDlBAA
            MD5:21A2760390BC24641C02DD5F545AAC6D
            SHA1:7368D5183627069F3923739F5CB9DE5B47AE4AD6
            SHA-256:5A28023503FCB80BBF408B7C05BC796EA0E3DC1D9AE91B10258AD1AF95733DC6
            SHA-512:92EE87C47925EE2437FC25C8AF21E5C9D9626E49A808801C66891D58BDBAA46F04E40B132A1DDAB2818E258FB96D5885D6E5F16834736C742EB61466181E78A3
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Matte @BBL X1C 0.8 nozzle",. "inherits": "Bambu PLA Matte @base",. "from": "system",. "setting_id": "GFSA01_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "22". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):508
            Entropy (8bit):4.470840775162066
            Encrypted:false
            SSDEEP:12:dhKbTU0UhJglpTbzNk+XwHP1+Xw91rll1r91Pd1PGA:mTJqWpTbpDXwHPEXw9lXBdBGA
            MD5:10E0F3A47C1384FE7030F165CF55EF8C
            SHA1:9EB9A2FCA2149161DF40E9EBFED371206B8CC5DC
            SHA-256:DC8FB5A68FFD7492842110399E6954228009D44B1925B2F1FC6EE2BFE4ED3C3B
            SHA-512:BE95BDBB1B14660CE2CD77B2209CCC431ED9419282993D7DAC999D02225591C2A3564D8D81200365430B0E4187988551D34E62E6897BF24E1862BE12519C4571
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Matte @BBL X1C",. "inherits": "Bambu PLA Matte @base",. "from": "system",. "setting_id": "GFSA01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "22". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):949
            Entropy (8bit):4.876001815743319
            Encrypted:false
            SSDEEP:24:TTr5TixpnQIR4JnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:Tf5TixpYhr+EW+Yn1B/P
            MD5:C568031C9A4AC1B86560E64B689B8205
            SHA1:EF507F65D04E5B7CC90E692D32FF392BD53EBA26
            SHA-256:19A228BEE116C0C45BC4BB0C7E7CAE88E722463076FF3C42F1CB70A3ABC8F362
            SHA-512:7CD311A43A72796FC124A8EC91DAC2811065A8C7886978994F4B809B1EB033BF911200E58D50757182F9FF2BD32A6AFF33AF8F5CF95DA65360631AEB6EC54442
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Matte @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFA01",. "instantiation": "false",. "filament_cost": [. "24.99". ],. "filament_density": [. "1.32". ],. "filament_flow_ratio": [. "0.98". ],. "filament_vendor": [. "Bambu Lab". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):728
            Entropy (8bit):4.281087291216025
            Encrypted:false
            SSDEEP:12:UKW0K9U0UhJE0lpTSPwwxdPvzPOdGFOXNcGF0kBcbA:UB7JqSopTSPwcpvjUQsNcQ0bA
            MD5:A11EA7895B42201A70F592871494C491
            SHA1:AF5DC900648B266787084A5BFF5196749510DB26
            SHA-256:04ED9B3904A203AD3FC8A7755CCF28C3DAD810061AF684768D7BDD24E1E5060A
            SHA-512:99499BE66BB5957D0E248FD88CDA127DE004C58EEDF6CF7ECF3A846A0973A90E1E5188358FEF39A1CDAAABC2DCDB501F0C1E5EA876B495AA418E3305D171871D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Metal @BBL A1 0.2 nozzle",. "inherits": "Bambu PLA Metal @base",. "from": "system",. "setting_id": "GFSA02_05",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):788
            Entropy (8bit):4.296223665148584
            Encrypted:false
            SSDEEP:12:vK9U0UhJclpTSPwwxdPvzXQOdGFOXNcGF0kBR1BT1BcA:0JqmpTSPwcpvrQUQsNcQ0QDsA
            MD5:DCECACA187D4535FBEC79116D4284110
            SHA1:9D4B6CB5A644889EA5BB07B9DE542545491DCD4A
            SHA-256:13B3D7D38853E6231422ADFDFB3892AA391DA35475C0264990A0BCA1D93C2AEA
            SHA-512:9946154042FB3081807B4ADFF652402824BBAFE2C22282E5EC28A9B657792D6DABC938F24CA027A3FF5BB70C0F60D4763F2927DE7B7D7B49A238A3D41ECDCE0F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Metal @BBL A1",. "inherits": "Bambu PLA Metal @base",. "from": "system",. "setting_id": "GFSA02_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "21". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):734
            Entropy (8bit):4.288526843688777
            Encrypted:false
            SSDEEP:12:/+W0K9U0UhJRlpTSPwwxdPvzPOdGOO4NcGF0kfbA:97Jq9pTSPwcpvjUPjNcQ02A
            MD5:A268491713C31DF6E9E7F584A8246C9E
            SHA1:1C76624B329744C5D020728AB660FC8156D9CC65
            SHA-256:6C79959EC6BB7E48E230AA9FFE779234792363508982A88F8C24DF33602733ED
            SHA-512:564D9CB53A68C8FCFB7A7400643237CEB55FF41A838B984B0500A23BD701800CA8AF371F71F1E03C34F8D971F2831CCD8FA7FE27BC5174A6C41305B2A21BC778
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Metal @BBL A1M 0.2 nozzle",. "inherits": "Bambu PLA Metal @base",. "from": "system",. "setting_id": "GFSA02_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):804
            Entropy (8bit):4.296016112118805
            Encrypted:false
            SSDEEP:12:EK9U0UhJQlpTSPwwxdPvzXQOdGOO4NcGF0ko1i1RA:LJqipTSPwcpvrQUPjNcQ0x4LA
            MD5:8A2D2747B068281FC95FBF616B3C5964
            SHA1:B687E1A955A8D6B8CEBD888D5271C26E724A133C
            SHA-256:4882CD757BE6CF9B69F6C955F1624AEC3356692D7FA2D3AF7A86530A52F129D7
            SHA-512:7824DB7059FF3F0F78F9B84267724E196FD4ED3F9038054D4961AA7C73F16465009DD0C64BB03ACE0978605FD67C2277976DEC84C9B0D5474A85798ABA0117A0
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Metal @BBL A1M",. "inherits": "Bambu PLA Metal @base",. "from": "system",. "setting_id": "GFSA02_00",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "21". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):436
            Entropy (8bit):4.471729916830841
            Encrypted:false
            SSDEEP:6:fS583FSOp0KRFSedU0H0htzxclz9JvF/Df6zwXdqgJcw/Kyr3sjC053sJgh053sH:Dp0K9U0UhJKlpTbzXQXksjl1sT1sH8A
            MD5:4C98ED69672F9438FAA15D8A76FE293A
            SHA1:21A9212C0E292A5D17AD3286BB7E0B06704C3436
            SHA-256:E853DEE71E54BD6DA3A1226244FD2B5F74B5A2C7F8E027BFDF7817465D6DFC21
            SHA-512:38F9ADF4FD795E8F2E8A0AD323E16FE47E8087CA4D529FC3D241F07885457E04567D57ACEFBC9835766316824AA8FA7A34C3102F05456175A0E981880C638BE0
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Metal @BBL X1",. "inherits": "Bambu PLA Metal @base",. "from": "system",. "setting_id": "GFSA02_02",. "instantiation": "true",. "filament_max_volumetric_speed": [. "21". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):442
            Entropy (8bit):4.495841440548461
            Encrypted:false
            SSDEEP:12:DyVgW0K9U0UhJnlpTbzPk+XwKW1scW1rKW1PgbA:aj7JqbpTbjDXwBS/LBKA
            MD5:CAA4DCAB057C1FBD9A84F36131D6FCA1
            SHA1:5776834197CFBF3D22D1D237DFDDF1A932C099D7
            SHA-256:19232D050C18ADE4DC7855F1C3CE08154C50D3C5A8531ED1FE8C43BD91947043
            SHA-512:1F96876D559EF5B2DC3BC442739AADBC17EE9E887A06E36DDCD7D5457A6A7BEA13E2854682B1EBAEA0895806BC4A052C03FA61DADC9C1D4A11F371302E9EA63A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Metal @BBL X1C 0.2 nozzle",. "inherits": "Bambu PLA Metal @base",. "from": "system",. "setting_id": "GFSA02_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):622
            Entropy (8bit):4.429896480691225
            Encrypted:false
            SSDEEP:12:DhK9U0UhJhlpTbzXQk+XwHP1+Xw91+XwLP1rll1r91rxl1Pd1PP1PAA:6JqBpTbrQDXwHPEXw9EXwblXDlBdBPBD
            MD5:E203DA3A5C83F1A3EE4CF4070BE1053E
            SHA1:1A4C4C171CE7AD2557C97B6F59DC23C9C1B45B00
            SHA-256:72B3BADA5DC3952E318C2DE2694BE22508B39F0E5D488950E89A35F2124B4C13
            SHA-512:0A43B348E627966E4A1EEACACDA6C303304D8665323E9B3867223B17C82AF867D7E02B1C260261E4480475F8D13D905C3F7370C33101010003E4BEE0510FA0C1
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Metal @BBL X1C",. "inherits": "Bambu PLA Metal @base",. "from": "system",. "setting_id": "GFSA02",. "instantiation": "true",. "filament_max_volumetric_speed": [. "21". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):949
            Entropy (8bit):4.876716758857207
            Encrypted:false
            SSDEEP:24:Fr5TiGpsqYR4JnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:F5TiGpsuhr+EW+Yn1B/P
            MD5:046BB6666DB4F7CCF88281A61896DDFA
            SHA1:6CBCF0CE2BAC5073F44B9800A16409E6E230C1E0
            SHA-256:B3C2FC458E2A5A862396A80350CB8618518224A90F0D4CFEA90AFE3E73087747
            SHA-512:C84F800AA50D8156531C1CE5FA44091CDF27CEED1283042B9C87C127162CA62F23B2C50ACDE8850A99AE2F38142F5123B17A95CE2543F29501396643EF750E89
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Metal @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFA02",. "instantiation": "false",. "filament_cost": [. "29.99". ],. "filament_density": [. "1.25". ],. "filament_flow_ratio": [. "0.98". ],. "filament_vendor": [. "Bambu Lab". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):726
            Entropy (8bit):4.293887587940559
            Encrypted:false
            SSDEEP:12:Y9xKW0KQLcU0UhJFlpTSPwwxdPvzPOdGFOXXcGF0kBcbA:Y9xBaLcJqVpTSPwcpvjUQsXcQ0bA
            MD5:4E8E671E331682ADFA42A707E5498AB7
            SHA1:E89EC3888C66CB965B4C3AA62985F2E4F72798B6
            SHA-256:B43B75DA676F47E2C8527BFB0C1B76A1276508B2206B80C0840DD69D4D843E95
            SHA-512:44602E3C734EB943FD7A14E576A3DDDF5631D3E8CDFCC70E4FD75E59EF9B2D15E6F43CFFA86E5964FCE616C75CB1F5A5A3307590B1CBD13C419ACA38D0E8B148
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Silk @BBL A1 0.2 nozzle",. "inherits": "Bambu PLA Silk @base",. "from": "system",. "setting_id": "GFSA05_06",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):727
            Entropy (8bit):4.292780970083782
            Encrypted:false
            SSDEEP:12:Y9uKQLcU0UhJH0lpTSPwwxdPOdGFOXXcGF0kBR1BT1BcA:Y9gLcJqpopTSPwcpUQsXcQ0QDsA
            MD5:D2757157427F2AE52D5CDCB09748E5C1
            SHA1:83058CD3BC30CCA63C932317A4DD389E417B33C0
            SHA-256:78B430DA9BC8DB37E07EC76EA01328979A4DB6205E1831DD411D28A471150AC6
            SHA-512:F1589DF5AB2A683CB68C3842AB6ADD760DC9B98B53D60F0DC03EFE4283759DD0BBB0CBBBE20BEE45686DDD88A98BC33BAB75B29C1A1D2C0CFEA095E457069153
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Silk @BBL A1",. "inherits": "Bambu PLA Silk @base",. "from": "system",. "setting_id": "GFSA05_05",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):732
            Entropy (8bit):4.299693578438292
            Encrypted:false
            SSDEEP:12:Y9k+W0KQLcU0UhJa6lpTSPwwxdPvzPOdGOO4XcGOrkfbA:Y9kaLcJqwapTSPwcpvjUPjXcPr2A
            MD5:B74C005308755FAFF3B8EEF1BA0CF8FF
            SHA1:437EECE48F45D57C38A83313030D0389A6FFC93F
            SHA-256:D6B54536E33CAA7B5697AC2B7E53F97850566360D9F54AD2AC75F123C7BB6943
            SHA-512:71E5F71D17805E2DD79D74F5381C95F80F10909F6E1F298D186FE8FDC1D00B8EEA4A2F2D1FE60161CEE63AF25F7A0FA7FB4001C9E040FF287D5E213F5ACF9B70
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Silk @BBL A1M 0.2 nozzle",. "inherits": "Bambu PLA Silk @base",. "from": "system",. "setting_id": "GFSA05_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "60". ],. "textured_plate_temp_initial_layer": [. "60". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):743
            Entropy (8bit):4.298832635812249
            Encrypted:false
            SSDEEP:12:Y9PKQLcU0UhJvalpTSPwwxdPOdGOO4XcGOrko1i1RA:Y9dLcJqh6pTSPwcpUPjXcPrx4LA
            MD5:F14D5C912EB5C6F7F344DEA299E2541F
            SHA1:45C9DF6EC0086B281150E04A417532A2E6F8A030
            SHA-256:438C8159ADA37A9899050A62E26D2C17AE794ED3CC5A7EC92FDC0D6E6560196F
            SHA-512:0D74B79ABDD0E1C62744D901EBA4B3600511D16B184A1388FAD889C460AD837412930D7F7BF9429115E6E3763049D1D1542BC5E643AC5261355F0D0C2C10C00D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Silk @BBL A1M",. "inherits": "Bambu PLA Silk @base",. "from": "system",. "setting_id": "GFSA05_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "60". ],. "textured_plate_temp_initial_layer": [. "60". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):375
            Entropy (8bit):4.48573136894685
            Encrypted:false
            SSDEEP:6:fS583FMIS0p0KRFMIpWqdU0H0htzIJvclz9JvF8Jcw/Kyr3sjC053sJgh053sH+s:Y90p0KQLcU0UhJWclpTLksjl1sT1sH8A
            MD5:6469FCFA6CE35FD80469CE2D520B82C7
            SHA1:A37E629B3587096ECD8F32845E8ACCEC856FC89B
            SHA-256:0E55B769CF37FF5940F0BA68E57191F4C5DED3AE7671C4DE2DFFC0DA514A6B83
            SHA-512:082E5012D811213901B1A7CCB1ED16C53B1DA16DA807A9F5E9C6F12C6279FC14F3E6BB4581E9C7E7D117ECA863571E182536CB3179E5B3C8650F96708F133F79
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Silk @BBL X1",. "inherits": "Bambu PLA Silk @base",. "from": "system",. "setting_id": "GFSA05_02",. "instantiation": "true",. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):440
            Entropy (8bit):4.517887014303456
            Encrypted:false
            SSDEEP:12:Y90yVgW0KQLcU0UhJm6lpTbzPk+XwKW1scW1rKW1PgbA:Y9njaLcJqHpTbjDXwBS/LBKA
            MD5:6CF9B34CEEB6AAF61321877E16806547
            SHA1:31DC80AC1E2773B46D158D1653B7E6D7D2C9F5FA
            SHA-256:520EA953089E7B262288E83EBE08A0D82AD4AE47730AA88C0D0284B6F4B12079
            SHA-512:B2EF1AA5C06CF68E2633B99B364B2D900A4CA91B596CC7DF178EBC6B7611F25ADD3CB367D0C4010D59A825B0C79BB1A8538B162F73943794D31D89699249842D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Silk @BBL X1C 0.2 nozzle",. "inherits": "Bambu PLA Silk @base",. "from": "system",. "setting_id": "GFSA05_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):564
            Entropy (8bit):4.409222186381898
            Encrypted:false
            SSDEEP:12:Y90hKQLcU0UhJDUlpTg+XwHP1+Xw91+XwLP1rll1r91rxl1Pd1PP1PAA:Y9kLcJqepTnXwHPEXw9EXwblXDlBdBP9
            MD5:B10B516C3482DF544BED56EF474B2198
            SHA1:AD90327A6CAF931BD8E2595325B54A20B03F38B9
            SHA-256:CE888AC2E47E634FB1F646C8B0C6756C6A13FBFFA503BCD30938399C20213152
            SHA-512:58A2C602D0BE29A8DF76855CF9374AD3DBD53F13B7552A100A82217598EE2F49AFD2E6503A9380AA95DF4428F16819EFDA58720A29400929DF76E39AA43A5721
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Silk @BBL X1C",. "inherits": "Bambu PLA Silk @base",. "from": "system",. "setting_id": "GFSA05_01",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1060
            Entropy (8bit):4.840961222664544
            Encrypted:false
            SSDEEP:24:YLcr5TiwopsqIR4x3xSrJnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:p5TiwopsLphr+EW+Yn1B/P
            MD5:35186F211742B68C79F3AD8A0D4E915B
            SHA1:1AB087B8BD558F419AEA7DD229DA5BA0291E49A6
            SHA-256:49393EDA17B872E27452D7583F282F7505CDF5E109248B32722A3DB6D7CD96B4
            SHA-512:6A2530DB198F02B3148146696A7FB61738F038E596D137193DB6FE559BB410CEA8789AB91532450BD250C31CC6254295F6ED4D0D1D40E0FA37F758B9BC68CDFD
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Silk @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFA05",. "instantiation": "false",. "filament_cost": [. "29.99". ],. "filament_density": [. "1.32". ],. "filament_flow_ratio": [. "0.98". ],. "filament_vendor": [. "Bambu Lab". ],. "nozzle_temperature": [. "230". ],. "nozzle_temperature_initial_layer": [. "230". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):733
            Entropy (8bit):4.304556843390196
            Encrypted:false
            SSDEEP:12:YYkKQYMU0UhJDlpTSPwwxdPOdGFOXNcGF0kBR1BT1BcA:YNVJqXpTSPwcpUQsNcQ0QDsA
            MD5:90F417AC2575F025FD9AAD6DCD655306
            SHA1:3E108C24461F2004B6EAA4AFA756AB6BAF35F12B
            SHA-256:DB2264CC18B8BB18AE28DF38032F641CDC56140F07FDC72C4580621CD5B978C6
            SHA-512:A379111526FF79E92E24C6451CC935D9498CC44E16E08CC40F0F50167C642B7DD5EC0F9DD6686F048FBA62982DCC2BDA276EAD6012D98AEBEF6E318E371A9803
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Sparkle @BBL A1",. "inherits": "Bambu PLA Sparkle @base",. "from": "system",. "setting_id": "GFSA08_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):749
            Entropy (8bit):4.311915608657704
            Encrypted:false
            SSDEEP:12:YYxKQYMU0UhJ8lpTSPwwxdPOdGOO4NcGF0ko1i1RA:Y6VJqupTSPwcpUPjNcQ0x4LA
            MD5:FE09153D4EBD2E4126B9B5268FC0085D
            SHA1:6F5214D09D445997BBFC7F745D758F62AD94E8EA
            SHA-256:5B6E0E69E298207F63F0C90AD41961DF7E5F8F2B81F24CF6A2CA01194A7650EC
            SHA-512:01514DA7C990B5F4F3813CAC7251BC5740B3727D2C782DC65F238619F2804B0462F14097418EF1245744F8497A1D41C48B666459498CFCB0660737B598C77655
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Sparkle @BBL A1M",. "inherits": "Bambu PLA Sparkle @base",. "from": "system",. "setting_id": "GFSA08_02",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):381
            Entropy (8bit):4.484919268040234
            Encrypted:false
            SSDEEP:6:fS583FMYx0p0KRFMY3qdU0H0htztlz9JvF8Jcw/Kyr3sjC053sJgh053sH+2CA:YYCp0KQYMU0UhJtlpTLksjl1sT1sH8A
            MD5:79E2A16F2869630388A506A51D1F22B2
            SHA1:975A334FFA0D0AE350EDDD06FB127654B3C1DFB5
            SHA-256:7202DF1DA08EE373564766B28A9554B027BA2A3B11C506EBCD1F6FF1FA8978FC
            SHA-512:44A771E71259648882531732CE9BFDBAD2D98F3736D29D7A1016709889AECBEF510E4E2E06E298F94663DBE58E9CD54715DDF9A84D6695BE512E5CD365D7778A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Sparkle @BBL X1",. "inherits": "Bambu PLA Sparkle @base",. "from": "system",. "setting_id": "GFSA08_01",. "instantiation": "true",. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):570
            Entropy (8bit):4.414848736724982
            Encrypted:false
            SSDEEP:12:YYChKQYMU0UhJTHhclpTg+XwHP1+Xw91+XwLP1rll1r91rxl1Pd1PP1PAA:YnVJqBhwpTnXwHPEXw9EXwblXDlBdBP9
            MD5:787122C2D5E81E73861ADD3A0787B56D
            SHA1:A6608866E8EEBCA37C2150E63DF28E66318B5A16
            SHA-256:077CD790090D07E0C44F48142ADBF820AB26510C692B22B845A27876201BE00D
            SHA-512:04CE93F8DD9598C0D377EBD63A9D93450081DA9D53F42D5A1FA970D59BC1422431FCB91E65A5DCC5355470BB9CAB0FD583D3DBB67BC2A1CA90FA317609BE3C83
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Sparkle @BBL X1C",. "inherits": "Bambu PLA Sparkle @base",. "from": "system",. "setting_id": "GFSA08_00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):951
            Entropy (8bit):4.8875960628232304
            Encrypted:false
            SSDEEP:24:YVr5TiApsqlR4JnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:o5TiAps5hr+EW+Yn1B/P
            MD5:5847D6ACEE253240A86D0D93925B0CA8
            SHA1:F92E6CBD028088F1A2A2B4FD2E8E5FEEF3FD2E14
            SHA-256:3001B9BC7BE586FB4E4F4DA051C63AE056C9F983F60C50A12FFB4F56FF022CDB
            SHA-512:43A132333D61CDB88B1B2766D5C5CDD0BDCDC8A79C38C41DB2B1425F94CEABE91315FC58825378940B5C94C21A383761C7A01BEFB80B7CBE4EC4C4810E4A5EE2
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Sparkle @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFA08",. "instantiation": "false",. "filament_cost": [. "29.99". ],. "filament_density": [. "1.26". ],. "filament_flow_ratio": [. "0.98". ],. "filament_vendor": [. "Bambu Lab". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):728
            Entropy (8bit):4.31548670391678
            Encrypted:false
            SSDEEP:12:utTKW0KmNEU0UhJilpTSPwwxdPvzPOdGFOXNcGF0kBcbA:8BLJqApTSPwcpvjUQsNcQ0bA
            MD5:B9C2903AB8AD177617567601B2F1E13A
            SHA1:1820B5061BADF3C21078D520ACC624E0D5043761
            SHA-256:5EF2D4C0D9A6E970901EE3DF1785EA515B44239AF0C1F8F21DBEEE1AADEAFB6E
            SHA-512:B2F0650761621F3A74CDB9D7DD81FE001811D1D83B72805817A0D17FB2E1836EF43FBF8F1176D4409464811AB9665A0FD6DC20D6C098A818F8FD794F43DCE520
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Tough @BBL A1 0.2 nozzle",. "inherits": "Bambu PLA Tough @base",. "from": "system",. "setting_id": "GFSA09_07",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):788
            Entropy (8bit):4.319494666003738
            Encrypted:false
            SSDEEP:12:utsKmNEU0UhJjH0lpTSPwwxdPvzXQOdGFOXNcGF0kBR1BT1BcA:0JqtHopTSPwcpvrQUQsNcQ0QDsA
            MD5:1F691C02E7CF1435B93014762E6148F0
            SHA1:FABBEDAEF13F92FE39CE7FF2615CCDCC622B09D5
            SHA-256:E407962009640A5495C3B97BFBFEA686D1ADEAB447B60A42C4C9E6036527CDF6
            SHA-512:273C079B1B8725C57EF1EB15BE618814F1888AE2B8AD65C2CB24160DE16A4B0B90D1B5BD79DCF1CCCDC5C66ECAB1EE3AC65FE54DE5F8E6D29812C33EF584AD75
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Tough @BBL A1",. "inherits": "Bambu PLA Tough @base",. "from": "system",. "setting_id": "GFSA09_05",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "21". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):734
            Entropy (8bit):4.3214805486940575
            Encrypted:false
            SSDEEP:12:utK+W0KmNEU0UhJflpTSPwwxdPvzPOdGOO4NcGF0kfbA:1LJqnpTSPwcpvjUPjNcQ02A
            MD5:AA637A6349C21B81C3E0EFF63EEF418E
            SHA1:0564C2B314DD2E593EB2305F2EEA4834BA9D851D
            SHA-256:F7CB6ABBD222847E4388248F4C57DB83ADF6F43A4A37C2989F2538F9E88395AC
            SHA-512:FFED42907ED34C004457F1AE04C7442C63955B97FDA5F517CFF7C986CF9A8083F401C643643F6624FB7555A35D8DA91D00E8F822808E45E092E866F3E85A88E7
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Tough @BBL A1M 0.2 nozzle",. "inherits": "Bambu PLA Tough @base",. "from": "system",. "setting_id": "GFSA09_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):804
            Entropy (8bit):4.330265544340943
            Encrypted:false
            SSDEEP:12:ut5KmNEU0UhJulpTSPwwxdPvzXQOdGOO4NcGF0ko1i1RA:zJq8pTSPwcpvrQUPjNcQ0x4LA
            MD5:7FC21F8B08DD5B6637A1DD879F00C3CD
            SHA1:2827192CBD09145A0F1C6457A917F84F2C11089E
            SHA-256:51452D1B10B1199F1E3C8805491516B38CB839085A2C9DE47CB20B6AC6D66D1C
            SHA-512:9B53CE2E0FA9F929E87ED1F030B04A0D93F4CD47A198189D27F3E11554A3A441A97E3A1B7A6D5F2D8BE1056660667FE597F45789A00CC57828B924B1A202C444
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Tough @BBL A1M",. "inherits": "Bambu PLA Tough @base",. "from": "system",. "setting_id": "GFSA09_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "21". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):436
            Entropy (8bit):4.508662128651014
            Encrypted:false
            SSDEEP:12:ut6p0KmNEU0UhJ0lpTbzXQXksjl1sT1sH8A:1JqapTbrQXRRSTSH8A
            MD5:01063BF7EE5D5B50255E21F5366AB2B6
            SHA1:E84B6595899F52402A7E905440D34EE370547B48
            SHA-256:EB9C44E6466FF37BB564C4367E46428E4033A3A4465A13B285A456E14661FDB7
            SHA-512:DCC7BFD2196AC4DD4FD2DD2AB3CFCE762B16D6B9A1B2B2A5E5AACCF6C8CD9F57A354D10C81C12A689F70A9DC133E689F6C2A868F16F03290C6B1C5AE1D492949
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Tough @BBL X1",. "inherits": "Bambu PLA Tough @base",. "from": "system",. "setting_id": "GFSA09_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "21". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):442
            Entropy (8bit):4.537564389757655
            Encrypted:false
            SSDEEP:12:ut6yVgW0KmNEU0UhJblpTbzPk+XwKW1scW1rKW1PgbA:yjLJqTpTbjDXwBS/LBKA
            MD5:274BC6F8932966F205BEDD503858F0BC
            SHA1:61D690180271BFD0862DB88AA2014A04E7740FF4
            SHA-256:43B122B22DC98C752350B7D406FFA9F9D3B8DB032808988B2323E7071B2B3343
            SHA-512:DF28FA209D5FC32A2E493317FBB07BAF19D932F42B97142F51563E87C6205EB3FB56172DB0C8F5C3B9B6722E3031C58C93195D8AA9A322E3B3FD61AE444FEB83
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Tough @BBL X1C 0.2 nozzle",. "inherits": "Bambu PLA Tough @base",. "from": "system",. "setting_id": "GFSA09_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):625
            Entropy (8bit):4.470255734294214
            Encrypted:false
            SSDEEP:12:ut6hKmNEU0UhJllpTbzXQk+XwHP1+Xw91+XwLP1rll1r91rxl1Pd1PP1PAA:6Jq1pTbrQDXwHPEXw9EXwblXDlBdBPBD
            MD5:89083E6F48C0D7400AE98EA689FBE11D
            SHA1:A86E9B4960199D148A83C57F120D685B0FB7341A
            SHA-256:5A47D7F470F3CC7F44D946243E7693B53419F796254A50ABAF3CB2AF208DB269
            SHA-512:0D1C6ACADE0D169BD92A494BAB8A13A8DCAE018374507E7B6262397D7E047DF6F92E3B9CCD82A75A01BA43077E5503FCF4CA53FF72DB4D5B059A1CBF03988BB9
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Tough @BBL X1C",. "inherits": "Bambu PLA Tough @base",. "from": "system",. "setting_id": "GFSA09_02",. "instantiation": "true",. "filament_max_volumetric_speed": [. "21". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):949
            Entropy (8bit):4.894352338443239
            Encrypted:false
            SSDEEP:24:Nr5TippklR4JnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:t5Tipp/hr+EW+Yn1B/P
            MD5:2D0065348A681F8288C4A57B12217AB8
            SHA1:E518A9C9775F4ADE465C7495D83D258B777C155B
            SHA-256:45E4083DE2293C0C3EC2977A579988746C3430CEFC1BEDC1F81163252A16A339
            SHA-512:E20E4BC3DC0C0C15E86AEE802DC997D06C9378D0D198836F2D0889A13B6A234F9111AA162A112C3BBEEF8762805C5099FFD2791BF6874A76925D04ACA6E50EE4
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA Tough @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFA09",. "instantiation": "false",. "filament_cost": [. "28.99". ],. "filament_density": [. "1.26". ],. "filament_flow_ratio": [. "0.98". ],. "filament_vendor": [. "Bambu Lab". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):870
            Entropy (8bit):4.31031253716184
            Encrypted:false
            SSDEEP:12:Pb0K4U0UhJt0lpTSPwwxdPvzrwOdGFOXx6wxSQtwNcGF0kBT1BcA:PbqJqnopTSPwcpvgUQsx3xSrNcQ0KsA
            MD5:996A76E2E04F58583DD30206EFC2354D
            SHA1:A47FED3F67E40D567D00275663746BD0A888F3AA
            SHA-256:C2686C6E2CB25881B66B0563214623CC7ECE196F654B2242CC17CE3167B21CD3
            SHA-512:8D88F9761C5F5743722BDE101B06A5BCB6650B8A973D1D4D58E928EE39C0BCCF5C9B20259479495E42BB7D494AD2E40921906764DE14C94834C098713E9D1381
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA-CF @BBL A1 0.8 nozzle",. "inherits": "Bambu PLA-CF @base",. "from": "system",. "setting_id": "GFSA50_05",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "18". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "nozzle_temperature": [. "230". ],. "nozzle_temperature_initial_layer": [. "230". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):824
            Entropy (8bit):4.288445771874488
            Encrypted:false
            SSDEEP:12:QK4U0UhJaBclpTSPwwxdPvzTOdGFOXx6wxSQtwNcGF0kBYA:eJqxpTSPwcpvXUQsx3xSrNcQ0VA
            MD5:2383C12095C6C83BBA9F5A61A37C99C2
            SHA1:B88804B25795BFB518DE062C5C1FD2C459DCB54F
            SHA-256:E053C2E12AE6434D84DA16267B7CDC0443F54EAB9A614CE3F148B624834D5184
            SHA-512:B1D173AEDFA80F79AC845D4A310BB981F7FB8BF63D842BA7F69EB6DC80F798D6B35F8E373F5970CB0965117A74AF5E3A3C7C7A826E2F7880EBDCCD297937941D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA-CF @BBL A1",. "inherits": "Bambu PLA-CF @base",. "from": "system",. "setting_id": "GFSA50_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "15". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "nozzle_temperature": [. "230". ],. "nozzle_temperature_initial_layer": [. "230". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):881
            Entropy (8bit):4.317679694375527
            Encrypted:false
            SSDEEP:12:w0K4U0UhJYlpTSPwwxdPvzrwOdGOO4x6wxSQtwNcGF0ki1RA:wqJqCpTSPwcpvgUPjx3xSrNcQ0zLA
            MD5:50BD5DD922A32F7DF1624B820A8D4452
            SHA1:885FD97D8E2049F29B0F56954642C8CC2D442308
            SHA-256:2486407768B4EB75ECA38F603C7D9F69C0B09C5F3E78B4DF9F4DCCC6235B137F
            SHA-512:541EEE6CDBA5B491DAA69965EACBAE3AB398468E207DB953E7990E00ED67E310A35FFD187B3F74ACD4A3A9F3DC0B20727F05AE49400B3742B7D2AF302C9065FE
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA-CF @BBL A1M 0.8 nozzle",. "inherits": "Bambu PLA-CF @base",. "from": "system",. "setting_id": "GFSA50_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "18". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "nozzle_temperature": [. "230". ],. "nozzle_temperature_initial_layer": [. "230". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):830
            Entropy (8bit):4.292226826907062
            Encrypted:false
            SSDEEP:12:dK4U0UhJealpTSPwwxdPvzTOdGOO4x6wxSQtwNcGF0kNA:5JqM6pTSPwcpvXUPjx3xSrNcQ04A
            MD5:DF9791BA7115279A8D105F33FB72545D
            SHA1:16841DF9E3BAEC4D25AD246EF83E40F00FB48F3C
            SHA-256:8D12920A1EFC280FA6041F8012C9BB6089EE3DD487AD30B5E6A9C26311BA3711
            SHA-512:04DEECACE8503A33F26BCE443DF698B539DD658C5F64B0F610B323B0DB9669A6E544AA4C610B82366F8B621935C7A828BA2682B9957F137BF10ABE6069F50D83
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA-CF @BBL A1M",. "inherits": "Bambu PLA-CF @base",. "from": "system",. "setting_id": "GFSA50_00",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "15". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "nozzle_temperature": [. "230". ],. "nozzle_temperature_initial_layer": [. "230". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):698
            Entropy (8bit):4.457150801319893
            Encrypted:false
            SSDEEP:12:eyVZ0K4U0UhJPlpTbzrwx6wxSQtwk+Xw91+XwLP1sT1sHl1r91rxl1PP1PAA:xZqJq7pTbgx3xSrDXw9EXwbSTSHlXDl3
            MD5:E09ACCF1519062AEA6872B4939A965C0
            SHA1:B574D8CA0AD545118710D8DEA34474AB73A5C5A6
            SHA-256:2D77449BD00AB7820E0657DFA6A28AD487F05F6A36E4E8A2E941B372782D3AA1
            SHA-512:84CD733D5A5CD2D49D6229222C5762E40E617443BF7EC42EF5BCEA77CFA853B769937B1858F1FC3A1AD8EA4912300551B990DD4281D3C9106CDBF15DD2CA5EC4
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA-CF @BBL X1C 0.8 nozzle",. "inherits": "Bambu PLA-CF @base",. "from": "system",. "setting_id": "GFSA50_02",. "instantiation": "true",. "filament_max_volumetric_speed": [. "18". ],. "nozzle_temperature": [. "230". ],. "nozzle_temperature_initial_layer": [. "230". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):538
            Entropy (8bit):4.494570221699925
            Encrypted:false
            SSDEEP:12:ehK4U0UhJSlpTbzTx6wxSQtwk+XwHP1sjl1rll1P0A:6JqkpTbXx3xSrDXwHPSRlB0A
            MD5:DC78BB82485804B2974B74151363CFEC
            SHA1:4FAC2BF031D922685178E2669E473BC977BB5B57
            SHA-256:87F59EC4415EEDD87178BF9382E7F10D5C8BB5EB79C54FC376696AB9B834D68F
            SHA-512:4A0DC3C09797D4B6CDD436D3F58BDD0BD2D23413CDC76DF40A643E4B67ED78AB05CE311552ECFA2BA84232956718B595255436564C56C48AF8CE2A8D35686F19
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA-CF @BBL X1C",. "inherits": "Bambu PLA-CF @base",. "from": "system",. "setting_id": "GFSA50_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "15". ],. "nozzle_temperature": [. "230". ],. "nozzle_temperature_initial_layer": [. "230". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab X1E 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1371
            Entropy (8bit):4.772334345510724
            Encrypted:false
            SSDEEP:24:gr5TiGMpNXouGuBRmQ4x08oxQAujXJnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:25Tinp40uxhr+EW+Yn1B/P
            MD5:6311DD96CB2F5C2FC2CEC5AA0D09CD6C
            SHA1:61AAE9F7D37AA21B5A1C2A1780F893B4DC8A2953
            SHA-256:3158C3FA52B342A6154A7EC4DEA05F79A54B1D9E247D535093424E60CA02E96C
            SHA-512:9C4850425B57692BBADFCFFAB07965D4EAFD2DC9CC4DFF9749BB9870B57ED3E0AEB9BCB8700A7566E711E6855D6118A02DE82C0B46FE6BE31ACE4002418E5134
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu PLA-CF @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFA50",. "instantiation": "false",. "additional_cooling_fan_speed": [. "0". ],. "cool_plate_temp": [. "45". ],. "cool_plate_temp_initial_layer": [. "45". ],. "filament_cost": [. "34.99". ],. "filament_density": [. "1.22". ],. "filament_flow_ratio": [. "0.98". ],. "filament_type": [. "PLA-CF". ],. "filament_vendor": [. "Bambu Lab". ],. "nozzle_temperature_range_high": [. "250". ],. "nozzle_temperature_range_low": [. "210". ],. "required_nozzle_HRC": [. "40". ],. "slow_down_layer_time": [. "8". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[cu
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):346
            Entropy (8bit):4.581288645062639
            Encrypted:false
            SSDEEP:6:fS583XXR6KRXSdU0H0htzAlJvclz9JvFs/Kyr3B+053Bqh053Be2CA:FsKyU0UhJATvclpTgBR1BT1BcA
            MD5:E9FECFB54812214FF9408DB77983B211
            SHA1:503100ADA49D6652382F2FCBD083E9041B315142
            SHA-256:2356E32CB179ED0017E289872FC361E92D78D95B5821D717AF218270B65EC8AD
            SHA-512:91FE031FDA30A66FF02AC4DDD065FB96B482004085F8C64D97F2CDE7981CDB58159BC28F9AF84FBA928F35EC1CE32B7521A81C8DD953F2B62CA4E4BC35D49EF8
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PA/PET @BBL A1",. "inherits": "Bambu Support For PA/PET @base",. "from": "system",. "setting_id": "GFSS03_02",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):739
            Entropy (8bit):4.40158093976288
            Encrypted:false
            SSDEEP:12:F6hKyU0UhJAP6lpTomrk+XwHP1+Xw91+XwLP1sjl1sT1sHl1rll1r91rxl1Pd1Pl:FEJq+PapT1rDXwHPEXw9EXwbSRSTSHlf
            MD5:EA7D04EE6A0A2DB88DC4C06E2987D7C6
            SHA1:4226B7FD04512047434B93E0AAF8D7F0E4F6C2D4
            SHA-256:5300F35DE4DDBD10A0366379A6FFC51CFA88C06C9B7BD63039C80F05BA79E38B
            SHA-512:A76C0C3773C2ADFDB09650CF11EF0CA8507BC535B2181BA43EC5061063C05E50CD7D68C59C9C761CC0DBE0E9C4C2B4789A7D4AE85FE020EA66E687689F13EFC4
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PA/PET @BBL X1C",. "inherits": "Bambu Support For PA/PET @base",. "from": "system",. "setting_id": "GFSS03_00",. "instantiation": "true",. "chamber_temperatures": [. "60". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):642
            Entropy (8bit):4.295683641537838
            Encrypted:false
            SSDEEP:12:Kmu5/G0izvlpF6F+YlC49zkzqxSQlxIGwcpbNA:Kr5fixpFuPC4BkzqxS8xIzuNA
            MD5:3A60E86553E0AE98F72685252A873CF9
            SHA1:35416DE50D71719206D0D8C950801094AE3F7E65
            SHA-256:A4067ADE7D6363EFF034B33002826EE2CC849A774CEEBDA89CF6E4B9EDB90A13
            SHA-512:7C92626399BBC15CC0E621A317853E5A5C2A88F7E2847BD55F0A4C17C6E330A0B0E2C8B13F6624B59A3952194BC492EDD1266F54D9C7D7AD8BAFA1782A838C1D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PA/PET @base",. "inherits": "fdm_filament_pa",. "from": "system",. "filament_id": "GFS03",. "instantiation": "false",. "required_nozzle_HRC": [. "3". ],. "filament_vendor": [. "Bambu Lab". ],. "filament_density": [. "1.22". ],. "filament_is_support": [. "1". ],. "nozzle_temperature_initial_layer": [. "280". ],. "nozzle_temperature": [. "280". ],. "fan_cooling_layer_time": [. "10". ],. "filament_cost": [. "34.99". ],. "slow_down_layer_time": [. "6". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):805
            Entropy (8bit):4.306621676123111
            Encrypted:false
            SSDEEP:12:/KW0KIU0UhJG0lpTSPwwxdPvz1qOdGFOXxkxSQxcGF0kBcbA:/B2JqAopTSPwcpvxqUQsxkxSwcQ0bA
            MD5:4137B683B968820C9361152142EB8244
            SHA1:5828F82EB6252D9ED82D13EC9E84C8ED4E7E93BE
            SHA-256:25E947FCFE95F0A7A1E5FCF8FDF20A85E0BA97ED1E0B0A4C1774AC16246C0C08
            SHA-512:444AB117233EEC497DDCAA9EE4BA471104FA9C9CDFD231071B953BB501D678A2B8CB80EC31262CEAF8DDD6BA31EBED53493F66458A6D618660B96CFA929D7C80
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PLA @BBL A1 0.2 nozzle",. "inherits": "Bambu Support For PLA @base",. "from": "system",. "setting_id": "GFSS02_05",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "0.5". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "nozzle_temperature": [. "240". ],. "nozzle_temperature_initial_layer": [. "240". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):692
            Entropy (8bit):4.323939431555323
            Encrypted:false
            SSDEEP:12:AKIU0UhJClpTSPwwxdPOdGFOXcGF0kBR1BT1BcA:aJqUpTSPwcpUQscQ0QDsA
            MD5:E8DC4BFB4DE75C659D5DCCD971E5CD80
            SHA1:A6A4EB5C22D412620C1030EC7FE131A269F76203
            SHA-256:5C1F27EE03BAEDC9B957DE4D8CC71AB86CBB08DDFD579582ED10F4B7EE08A980
            SHA-512:D412B82707EB11F2EFC87293C98FB6015D36083C4B4EDD364471398D33A3E89F2C875768782C1CB3D75DEFA2247EC49555E09160C229913B120E1CCBDBC68044
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PLA @BBL A1",. "inherits": "Bambu Support For PLA @base",. "from": "system",. "setting_id": "GFSS02_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):811
            Entropy (8bit):4.310378432029134
            Encrypted:false
            SSDEEP:12:u+W0KIU0UhJ7lpTSPwwxdPvz1qOdGOO4xkxSQxcGOrkfbA:y2JqfpTSPwcpvxqUPjxkxSwcPr2A
            MD5:D9C8DB982950EFB0061FF6818DC3A995
            SHA1:8CE046BD490481949138391D6DD7B89750BDB2C8
            SHA-256:0D1F63F1BCB9B409826A43DA8C6DD7F203C5E41D90C1623BECE01D0BF03BF96C
            SHA-512:F2FE03601080B6DF55C30BB028B87AF723A26F2D8393AA89D6260E1DAECD64FAAAA85D413485587429D0F513C49853728A470A2229BB058E91DB975DEAACCD6D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PLA @BBL A1M 0.2 nozzle",. "inherits": "Bambu Support For PLA @base",. "from": "system",. "setting_id": "GFSS02_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "0.5". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "nozzle_temperature": [. "240". ],. "nozzle_temperature_initial_layer": [. "240". ],. "textured_plate_temp": [. "60". ],. "textured_plate_temp_initial_layer": [. "60". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):708
            Entropy (8bit):4.315662369188732
            Encrypted:false
            SSDEEP:12:tKIU0UhJOlpTSPwwxdPOdGOO4cGOrko1i1RA:3JqYpTSPwcpUPjcPrx4LA
            MD5:65F16D27A1642DE69F34FBEDD6BAA360
            SHA1:9A53879EA7DB6805A2EB1262603A2DD4A00538FD
            SHA-256:8A9C2AC742056C1F425FF233E21B36023192F47C192F14CB37FB8F2F42B11F7A
            SHA-512:F581862B2ACD3DC732A6351D6EAE2FAF02C615EE890ECD26F46DB763FC0048D78D6B4582A848A888174E6D612DC2F0AAB0F79E054480CA60999F7345C3ACAD49
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PLA @BBL A1M",. "inherits": "Bambu Support For PLA @base",. "from": "system",. "setting_id": "GFSS02_00",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "textured_plate_temp": [. "60". ],. "textured_plate_temp_initial_layer": [. "60". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):568
            Entropy (8bit):4.482857089314861
            Encrypted:false
            SSDEEP:12:OyVgW0KIU0UhJFlpTbz1qxkxSQxk+XwKW1scW1rKW1PgbA:hj2JqhpTbxqxkxSwDXwBS/LBKA
            MD5:7743C33F34FD305A8BE3F2068CA67594
            SHA1:42CEB323395C474F91888FD5D289BCCBB56CA726
            SHA-256:CBBB212EF6411DA27164BB9FBCEEE1898573D771FFCE6F1F5BBA26F5C5954E66
            SHA-512:0E06E7ACCD53AB1991FD925BCA09075972AE825403005C83E6015EA2DCBC457805325D0129EDA7B4E970B6EDE3FE514EBBC7951127620F608F101B4CAA8E1DFA
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PLA @BBL X1C 0.2 nozzle",. "inherits": "Bambu Support For PLA @base",. "from": "system",. "setting_id": "GFSS02_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "0.5". ],. "nozzle_temperature": [. "240". ],. "nozzle_temperature_initial_layer": [. "240". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):683
            Entropy (8bit):4.363732781382465
            Encrypted:false
            SSDEEP:12:OhKIU0UhJUlpTg+XwHP1+Xw91+XwLP1sjl1sT1sHl1rll1r91rxl1Pd1PP1PAA:2Jq2pTnXwHPEXw9EXwbSRSTSHllXDlB9
            MD5:C3CBE16DD8F3FA1189DA4504A523C235
            SHA1:D3C6F47ABC6BA3D09F0C2243E5927B09920EE0EE
            SHA-256:3401F50CF30D6C4A5FC1603525702498A292A81AD55C4E496A81395F12E91C3B
            SHA-512:F079DCFACDD9DC52EC44CB7AEF5F5EAF5E0A34887E1341A7B27D6203B440811B3826DD91B9E031CF38CF8FDBBE73F5046D9864F2DA9A332405CF9335697543E0
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PLA @BBL X1C",. "inherits": "Bambu Support For PLA @base",. "from": "system",. "setting_id": "GFSS02_02",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1105
            Entropy (8bit):4.803240590760015
            Encrypted:false
            SSDEEP:24:wr5Tiopxldyiykzq4XJnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:m5Tiop8Izzhr+EW+Yn1B/P
            MD5:4AF7B9763C0A2AB4C2051E6E19DB1981
            SHA1:F3A9DF8443FD9C8C566C7AD1E24EB60936F20824
            SHA-256:1C31EF3E8125AA6AB7819B9F161CB41E09F410F8F3B516DEBAE9261BDD67D9BA
            SHA-512:D4FF99724A8D53917E8BFEC1D1CAF2FC03FD4D410465C92EDDB978BA6B278D4E1A8FBFB79DD051064DA0D8B67ABC8ED2CB78D93A3DE90A1C223D616FB033DF86
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support For PLA @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFS02",. "instantiation": "false",. "cool_plate_temp": [. "40". ],. "cool_plate_temp_initial_layer": [. "40". ],. "filament_cost": [. "69.98". ],. "filament_density": [. "1.30". ],. "filament_is_support": [. "1". ],. "filament_vendor": [. "Bambu Lab". ],. "slow_down_layer_time": [. "8". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && su
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):328
            Entropy (8bit):4.438274642031349
            Encrypted:false
            SSDEEP:6:fS583Xe6KRX9JdU0H0htzulz9JvFs/Kyr3B+053Bqh053Be2CA:NKvTU0UhJulpTgBR1BT1BcA
            MD5:14790D307B1BEFBA1C46F26E7801B0F3
            SHA1:FAAAD7A5AFAD3EC941D1ECC10620BC1BE71A45E5
            SHA-256:DBDE20F9D69CBE5A30E4A0B7A550ED9DB992CF69A35D8140B0269A434C5B3012
            SHA-512:E1B4CC34A15C3F8CD558B94EF3C8DAFFDCDF1E2745BC675263E8FFB8631311AACF97DB46569A8B05979EFF186180FA0856853ACA353C6FBAA7D52B37D3D73C26
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support G @BBL A1",. "inherits": "Bambu Support G @base",. "from": "system",. "setting_id": "GFSS01_01",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):560
            Entropy (8bit):4.349350726464551
            Encrypted:false
            SSDEEP:12:phKvTU0UhJ6lpTg+XwHP1+Xw91+XwLP1sjl1sT1sHl1rll1r91rx8A:OJqYpTnXwHPEXw9EXwbSRSTSHllXD8A
            MD5:4B2204C849330452C059A84102E0336A
            SHA1:2975DE80CF124FC21E85895430CD01EE28FE804E
            SHA-256:8E8B67F2CAB5F16706ECC4BFD0C7E433E6BF2C79D8C3E70D02801C42CE0B03DC
            SHA-512:34ADA14F2B07A809826505CA69E3C90A7E01D07BEC0D80AF05ACD15612857A5743C8306A7CE4766ACCB480626592FFC0ECEDB93B7938D141BA6A0377D12B60B0
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support G @BBL X1C",. "inherits": "Bambu Support G @base",. "from": "system",. "setting_id": "GFSS01",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):385
            Entropy (8bit):4.462247186382324
            Encrypted:false
            SSDEEP:6:fS583XrChFmKRXrwJm0H0htzc6lz9JvFsNEmAeQXAgw/Kyr3P6053Peh053Pi2CA:pChFmKhn0UhJc6lpTomrkPd1PP1PAA
            MD5:E8040A865211C143275BDAD309EB70D4
            SHA1:BDE0C1FE7E1D673F72C36295A2E7AA91AD2ED487
            SHA-256:104A14C886F43C0BB65B61C61D8F87C1AD61A7FFD458847D26574EC6ACAFFB45
            SHA-512:906702F1A05A0ED881F23325F05BB79DFA045B4D98EE9257CA185F27D3506067C57DDDBDA2665EFC80D9C224E95988316BEC690C6ABE254E075F32E3F3099DD1
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support G @BBL X1E",. "inherits": "Bambu Support G @BBL X1C",. "from": "system",. "setting_id": "GFSS01_00",. "instantiation": "true",. "chamber_temperatures": [. "60". ],. "compatible_printers": [. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):633
            Entropy (8bit):4.236965362183166
            Encrypted:false
            SSDEEP:12:XTmu5/G0iz5lpF6F+YlC49zkzqxSQlxIGwcpbNA:jr5fivpFuPC4BkzqxS8xIzuNA
            MD5:4EBD4D4251E080AA2151688C45BA6AFF
            SHA1:EF11CBB0C234C746B56A32E70711EB96411A7ADD
            SHA-256:F0DAF0D06E5EE721AB4EE93AC6EBDD15B47846B1B1C473BCD9B21842DEE2B1E2
            SHA-512:114EE41F9F8BDA6E9CE3AEEFE97265722345B0D90B194FA990A9B1CC2DC9ACCFA427C06AC1D8F3C8575A0A97494186E7F0C8F7A0549E7D129142A7155D136227
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support G @base",. "inherits": "fdm_filament_pa",. "from": "system",. "filament_id": "GFS01",. "instantiation": "false",. "required_nozzle_HRC": [. "3". ],. "filament_vendor": [. "Bambu Lab". ],. "filament_density": [. "1.22". ],. "filament_is_support": [. "1". ],. "nozzle_temperature_initial_layer": [. "280". ],. "nozzle_temperature": [. "280". ],. "fan_cooling_layer_time": [. "10". ],. "filament_cost": [. "34.99". ],. "slow_down_layer_time": [. "6". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):793
            Entropy (8bit):4.276361641171914
            Encrypted:false
            SSDEEP:12:AxKW0KecU0UhJHclpTSPwwxdPvz1qOdGFOXxkxSQxcGF0kBcbA:GBxJqGpTSPwcpvxqUQsxkxSwcQ0bA
            MD5:D79F623258E4A8C5317C925CC4405660
            SHA1:19757E6B2383C84DDD61AB154060A91830A12841
            SHA-256:B848E10911B3703316802B5F475D1E673BF0FD9BBB641BB58DC44B03CE7A50E9
            SHA-512:7D7447ECC3B335BA7AA37E88BC2C9675D6C98DC96AD0B438DF27E1E2B5EF74E56F45DD346F8EAF8C4F10934A2479582F0C1F0C77E27F8090DD4E67E4CFB7E37C
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support W @BBL A1 0.2 nozzle",. "inherits": "Bambu Support W @base",. "from": "system",. "setting_id": "GFSS00_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "0.5". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "nozzle_temperature": [. "240". ],. "nozzle_temperature_initial_layer": [. "240". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):680
            Entropy (8bit):4.2908866783015815
            Encrypted:false
            SSDEEP:12:AuKecU0UhJxlpTSPwwxdPOdGFOXcGF0kBR1BT1BcA:gJqdpTSPwcpUQscQ0QDsA
            MD5:3424F20A42BCCAEC325DC774DA0F5CA9
            SHA1:98E3B3D7400849FE2321745F7D864559DF119A27
            SHA-256:8080F0801D6D4896F93BAE503FC8B9BA86E2D3C53D8442331A52E63571CD8667
            SHA-512:1911F5B15B9DC63944A52F8350D6DC806CA618F423D5AD4C80301A228883B6CDC59B32DF0AA5F8603671CD2217FBCE3E0A7850F30EA9B38F97C09FED1A642D0E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support W @BBL A1",. "inherits": "Bambu Support W @base",. "from": "system",. "setting_id": "GFSS00_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):799
            Entropy (8bit):4.2737213668110545
            Encrypted:false
            SSDEEP:12:Ak+W0KecU0UhJqlpTSPwwxdPvz1qOdGOO4xkxSQxcGOrkfbA:/xJqkpTSPwcpvxqUPjxkxSwcPr2A
            MD5:0EBB99F5EB104D6B7F96670995BC9C01
            SHA1:5641CACA477E11FF70D8324B5E892F4F8C7F86E5
            SHA-256:EB890DE8D84E67CEF266615B62A9E4A5C4E118EE03CC628289188AAA7902A23F
            SHA-512:01FE737CB28C1DFD29AF63FA9D170DF723DB78508DEA804A5F88E5570D5058CB7A5949CAF8F27EBDAF656DFFA09A9B108E421702ED83100A4C3C4F3DCFBA19CB
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support W @BBL A1M 0.2 nozzle",. "inherits": "Bambu Support W @base",. "from": "system",. "setting_id": "GFSS00_02",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "0.5". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "nozzle_temperature": [. "240". ],. "nozzle_temperature_initial_layer": [. "240". ],. "textured_plate_temp": [. "60". ],. "textured_plate_temp_initial_layer": [. "60". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):696
            Entropy (8bit):4.281162176310083
            Encrypted:false
            SSDEEP:12:APKecU0UhJHlpTSPwwxdPOdGOO4cGOrko1i1RA:7Jq7pTSPwcpUPjcPrx4LA
            MD5:7C8AD98C99D1A17E0D87D29A7728DA7C
            SHA1:9968B4A2428800BC076288E26BF399F7556A609E
            SHA-256:53597E336D0C95AD4B943D7EC14064B0C4901DC0428A709792729C642F8D8072
            SHA-512:3F8954CE2EC7DD5772C03708ECE15296AFD4630B7DF9447B6172773D5BDEF48E5DC9BB1E7FD9ECEC4C2EF4C255AA672D22ED5484167FCB0064307E08D4A1358A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support W @BBL A1M",. "inherits": "Bambu Support W @base",. "from": "system",. "setting_id": "GFSS00_01",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "textured_plate_temp": [. "60". ],. "textured_plate_temp_initial_layer": [. "60". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):325
            Entropy (8bit):4.440007340391637
            Encrypted:false
            SSDEEP:6:fS583XG0p0KRXEqdU0H0htzXlz9JvFs/Kyr3sjC053sJgh053sH+2CA:A0p0KecU0UhJXlpTgsjl1sT1sH8A
            MD5:ECD7D793EAB9458EAF31A51972F8AF63
            SHA1:0E547D71DCDDB288279FBCC7CEC63F9094157499
            SHA-256:CEDB5A96F7BA60C8C60173985B815CBC4E98071DF26076DFDDF2E930DE0DACBF
            SHA-512:6B469CE398B927C1B4ED9F7E5CF0BA801AD78568CC8A134B95A7BF3533154B520279234EEA44BDA9178921E34414E135CCAE3CD62DE1A516C8A2B253AB605EC3
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support W @BBL X1",. "inherits": "Bambu Support W @base",. "from": "system",. "setting_id": "GFSS02",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):556
            Entropy (8bit):4.449740048435497
            Encrypted:false
            SSDEEP:12:A0yVgW0KecU0UhJwlpTbz1qxkxSQxk+XwKW1scW1rKW1PgbA:IjxJqCpTbxqxkxSwDXwBS/LBKA
            MD5:66488F9252ACE751B1955B23527B013C
            SHA1:8E68405E922473340C2CD463C770144468DA8FFE
            SHA-256:8DCE9B083D013FF526F73DFF78DB28A4D4DC8A03E6B56F3DA4CE0169936443A8
            SHA-512:CE1DF64BF30C6B6A9E5A5B5A2F801F04A6680FB0E656A933EE3279FA3A2A7B36C71C391A269E656EA233E7D0691FB91C270E9382439A676E0FB490D9A641AE54
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support W @BBL X1C 0.2 nozzle",. "inherits": "Bambu Support W @base",. "from": "system",. "setting_id": "GFSS00_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "0.5". ],. "nozzle_temperature": [. "240". ],. "nozzle_temperature_initial_layer": [. "240". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):563
            Entropy (8bit):4.378976755652108
            Encrypted:false
            SSDEEP:12:A0hKecU0UhJBlpTg+XwHP1+Xw91+XwLP1rll1r91rxl1Pd1PP1PAA:OJqhpTnXwHPEXw9EXwblXDlBdBPBAA
            MD5:0FCAD4AFD36F3D50842E1A53A5F8F87B
            SHA1:F9FBAC0A2E5BA4112242CD5C3257B9B7DD9E0DDD
            SHA-256:14569DBBCE9113F6FD5E12C9C9CCB7165BA2BB39D1EC306E782E52E7B30EE255
            SHA-512:17F5E425443CC147135B3239062860EE485A0656E77C15CAFF072F062204897586E4DE22BD189D49960323E73A48C04681E51A3C9055F68C08A8776D59924D64
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support W @BBL X1C",. "inherits": "Bambu Support W @base",. "from": "system",. "setting_id": "GFSS00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1099
            Entropy (8bit):4.790391740099949
            Encrypted:false
            SSDEEP:24:zr5TiGpxldyiykzq4XJnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:/5TiGp8Izzhr+EW+Yn1B/P
            MD5:101EA6480A78E115327246E66E0984F5
            SHA1:86238FB5BAC2B247AD7480521300FD1184A3416C
            SHA-256:39588B0844CD69B12268F7D87313710777DD9F0B4578E6341EF4E086E06CF84E
            SHA-512:0EC882AF8027E3E84672E92518FA18484DD68CE81E6EEDBCEBC6575F826E5B65466F37B1FEEF432087F3FBB71D7CDB7EAC98752A245159CE3E31B954EB2C0903
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu Support W @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFS00",. "instantiation": "false",. "cool_plate_temp": [. "40". ],. "cool_plate_temp_initial_layer": [. "40". ],. "filament_cost": [. "69.98". ],. "filament_density": [. "1.30". ],. "filament_is_support": [. "1". ],. "filament_vendor": [. "Bambu Lab". ],. "slow_down_layer_time": [. "8". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && support_
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):598
            Entropy (8bit):4.406592245831331
            Encrypted:false
            SSDEEP:12:xKHU0UhJROlpTbzXMOdGjOZcGjSkBR1BT1BcA:MJqvmpTb7MUuKcuSQDsA
            MD5:420AC81BF23B46A5C30133FAC8C68427
            SHA1:DC3D75B8BB20BC607C3F4EE0EACF7B9276463429
            SHA-256:C7A4C69BFE00C3EADD333D039CE34E01D053194D3BAD44444028C0F20A0786F5
            SHA-512:054E07E23DEE6A99C0CACCCE2AC9D303894CC405129F15BEC44FC8E483267D0B9979A72909F826584BF0106D8DB7786B49678838F2E9368A6285AD057C16EC09
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A @BBL A1",. "inherits": "Bambu TPU 95A @base",. "from": "system",. "setting_id": "GFSU01_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "3.6". ],. "hot_plate_temp": [. "45". ],. "hot_plate_temp_initial_layer": [. "45". ],. "textured_plate_temp": [. "45". ],. "textured_plate_temp_initial_layer": [. "45". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):614
            Entropy (8bit):4.409253714451483
            Encrypted:false
            SSDEEP:12:CKHU0UhJRFlpTbzXMOdGGwOMwcGGwNwko1i1RA:bJqvPpTb7MU+Kc+Sx4LA
            MD5:9038862F0EAF24350BF4154D36BAD6D8
            SHA1:E282880C406DAD338706C035F1453968E18122DC
            SHA-256:4F9A0569866B144B3C821FB5CE240936E14E70FF4F634DD8856390150A09C6EE
            SHA-512:C99C3D422845E8FA04F620B625C1ECF1AE4D833B5671A47019C61645F04D3151A142E731C44470C628B655261B57496CABDFD91A2D9A04B4BF688FB60A4EA3D9
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A @BBL A1M",. "inherits": "Bambu TPU 95A @base",. "from": "system",. "setting_id": "GFSU01_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "3.6". ],. "hot_plate_temp": [. "30". ],. "hot_plate_temp_initial_layer": [. "30". ],. "textured_plate_temp": [. "30". ],. "textured_plate_temp_initial_layer": [. "30". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):381
            Entropy (8bit):4.536731786762462
            Encrypted:false
            SSDEEP:6:fS583u6p0KRuCdU0H0htzRalz9JvF/Df6zwXMw/Kyr3sjC053sJgh053sH+2CA:9p0KHU0UhJRalpTbzXMksjl1sT1sH8A
            MD5:C632308777287A7E7A174327A706068B
            SHA1:359E1111D0D40765D369EC1935DB112C1A16EDD7
            SHA-256:6AFC4C52E8471E89442E27C29DED670601AF0D3F362A9B187E13213008136A4D
            SHA-512:CAD5443FAA1CA82A2E83461FF45CF73C894CAA29C2C29B57A1637C795D1DA8B966A0E3A522E1A5C9A5D59F08A90458CA8D5506B152BE05698A285C9FA07FEE83
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A @BBL X1",. "inherits": "Bambu TPU 95A @base",. "from": "system",. "setting_id": "GFSU01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "3.6". ],. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):619
            Entropy (8bit):4.4704926369463145
            Encrypted:false
            SSDEEP:12:9hKHU0UhJ6vclpTbzXMk+XwHP1+Xw91+XwLP1rll1r91rxl1Pd1PP1PAA:aJqWwpTb7MDXwHPEXw9EXwblXDlBdBP9
            MD5:625250A3B103154EE8DBDF6409ACEFD1
            SHA1:AE3F409A4546335B10C1B30CF93D69C75A12A15E
            SHA-256:301E2714E2F0FDCF791E06B7FDE5C450B2DB4B5F3AE0AB17C33AB1DC1DDD02EE
            SHA-512:930A149B1D7E4A1F63E8414F8A64C89952D861A60A7ADF00507BA7767EF99FAC3CFA678A16E484885DA7AD656E491A231043956C57519A747CCA94904ADABA7F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A @BBL X1C",. "inherits": "Bambu TPU 95A @base",. "from": "system",. "setting_id": "GFSU00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "3.6". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):435
            Entropy (8bit):4.29285630811446
            Encrypted:false
            SSDEEP:6:fS583uCdmu+os6m0yD1+H6lz9slKeR1QblD6HPooTQXALQ1NQCwbgWLQawoTQXAz:vmu5sN0i8H6lph9zxSQtwcpawx6wA
            MD5:37C05F4A087413CA6B2CAB838B92011F
            SHA1:59DC7045672A2F488B520B4858B556D6CB5D5DA4
            SHA-256:796FFD3CB382851E253CCF1491AE15DF734A9297FFB661182DC837B5D0FBD660
            SHA-512:D0D579A0CA69E6350B4D899287C457F88FB44A16DCF33BD8DA80327CD33B4EDBC25BAD61EDF976D5659F1A51B9A2741758723789663797FC881A8140F556BC4B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A @base",. "inherits": "fdm_filament_tpu",. "from": "system",. "filament_id": "GFU01",. "instantiation": "false",. "filament_vendor": [. "Bambu Lab". ],. "filament_density": [. "1.22". ],. "nozzle_temperature_initial_layer": [. "230". ],. "filament_cost": [. "41.99". ],. "nozzle_temperature": [. "230". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):544
            Entropy (8bit):4.414969241918045
            Encrypted:false
            SSDEEP:6:fS583m16KRmGdU0H0htzx6lz9JvFKc4RflGjOc4RfBwNQjAflGjAfBwNQjw/KyrD:/KNU0UhJMlpTKdGjOZcGjSkBR1BT1BcA
            MD5:142E4AB749FDBD3A2A43F963F4389796
            SHA1:40C8EF473571C7D46F275E230D1B5472EFBC5FEE
            SHA-256:6F89E7E11D760E4BCB6AF33D4F4132406760D0415E15B0964998645D187DED20
            SHA-512:6BBD59560567D12F9A882AC6EE0D568D5A54FA08520E8396B27089460957EDFF13F79F223DC3990D8BE12F43B791ECF139D02E9A1B802C2E58D0D7872AAB8D45
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A HF @BBL A1",. "inherits": "Bambu TPU 95A HF @base",. "from": "system",. "setting_id": "GFSU00_06",. "instantiation": "true",. "hot_plate_temp": [. "45". ],. "hot_plate_temp_initial_layer": [. "45". ],. "textured_plate_temp": [. "45". ],. "textured_plate_temp_initial_layer": [. "45". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):560
            Entropy (8bit):4.423066096506692
            Encrypted:false
            SSDEEP:12:0KNU0UhJ60lpTKdGGwOMwcGGwNwko1i1RA:DJq8opTo+Kc+Sx4LA
            MD5:C5C3E747DA230D43261A0761C49AF6B6
            SHA1:85DD3060BAFD9E0FB5CD76B64B7AAFDC7056F6EA
            SHA-256:4F921C90485C69771D8A145D3E449EA0862EFE119BBA13FADB512E54FB55D625
            SHA-512:A475338541E531DF090DFB2BCC7C8BD5B82D74D11179F25FB68A39DEBD99DEEA1DDDE3A941293DF07E5F2AC3CF6642877010FDB1842AE5A2F26B192BC4CFCD76
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A HF @BBL A1M",. "inherits": "Bambu TPU 95A HF @base",. "from": "system",. "setting_id": "GFSU00_05",. "instantiation": "true",. "hot_plate_temp": [. "30". ],. "hot_plate_temp_initial_layer": [. "30". ],. "textured_plate_temp": [. "30". ],. "textured_plate_temp_initial_layer": [. "30". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):548
            Entropy (8bit):4.430977294673453
            Encrypted:false
            SSDEEP:6:fS583mO1aKRmGdU0H0htz96lz9JvFKc4RflGjOc4RfBwNQjAflGjAfBwNQjw/Kyw:LQKNU0UhJAlpTKdGjOZcGjSks1W1NA
            MD5:627EF330D00FB1270B0370FC81890439
            SHA1:7EC04C5256776E1B15222015A8DC35AEA43A81F6
            SHA-256:0D3C82BCB711427682214D06D1CC512C42E4A72677AB9286D695531FA5546232
            SHA-512:95F0F502C78AE06592BE2A03E0FA46C299326B0B8877079BAB71D018ED9D8067BC7510524A4205401E0F5A15E674A3AF207464933323BD8CB7356AC8D7F2E0CB
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A HF @BBL P1P",. "inherits": "Bambu TPU 95A HF @base",. "from": "system",. "setting_id": "GFSU00_02",. "instantiation": "true",. "hot_plate_temp": [. "45". ],. "hot_plate_temp_initial_layer": [. "45". ],. "textured_plate_temp": [. "45". ],. "textured_plate_temp_initial_layer": [. "45". ],. "compatible_printers": [. "Bambu Lab P1P 0.4 nozzle",. "Bambu Lab P1P 0.6 nozzle",. "Bambu Lab P1P 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):334
            Entropy (8bit):4.571666188444207
            Encrypted:false
            SSDEEP:6:fS583mOMdF0KRmGdU0H0htzXlz9JvFs/Kyr3pFlC053pF/gh053pFx+2CA:LKF0KNU0UhJXlpTgrll1r91rx8A
            MD5:F53D34CF9118F1E057DF6E5D72E5761A
            SHA1:6045045A91A92E3C0FFB467141BD9B655FAF8D5E
            SHA-256:E168B375EA221FD25559101779B9D5EBAAD8D785010DA75A667FE21C09B7B75A
            SHA-512:E87C3B9E463285C3D33748AB55F6B20588E7F3115738230009272BF3FF70FE6B44FB36D72809DFE58747A30F3EC8278D011D64C37EA41297B492047A0528B307
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A HF @BBL P1S",. "inherits": "Bambu TPU 95A HF @base",. "from": "system",. "setting_id": "GFSU00_03",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):330
            Entropy (8bit):4.5490162998772075
            Encrypted:false
            SSDEEP:6:fS583mmp0KRmGdU0H0htzBlz9JvFs/Kyr3sjC053sJgh053sH+2CA:Tp0KNU0UhJBlpTgsjl1sT1sH8A
            MD5:5F1DFB48EB7D3E2772363A6D8F60EA0F
            SHA1:D7692645C8481571199E7F563796C70FA702DA19
            SHA-256:61026108AB155FE78541CFED33112DAEB0A496E0F205EF712D7C4EC181ECA905
            SHA-512:B399891FF61E12DF8D59C1527AFD47398D5DD6EE7BD8D11E58527057347FBCF2634A3CC8D18E40AF6BA92BDA75961009C03CB4A006B52F6A5790C174CF00699E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A HF @BBL X1",. "inherits": "Bambu TPU 95A HF @base",. "from": "system",. "setting_id": "GFSU00_01",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):352
            Entropy (8bit):4.585698928977847
            Encrypted:false
            SSDEEP:6:fS583mmwJUKRmGdU0H0htzn6lz9JvFs/Kyr3+XwFeh053+XwHs053+XwLM2CA:ThKNU0UhJn6lpTg+Xw91+XwHP1+XwLGA
            MD5:B4EE7B86071DD688EC263A9C8F5AD567
            SHA1:2F4A732F1D720BECA739C62930469FF949795770
            SHA-256:81984B8EA98B99DC9D059FC023F69536008FD4CEC085EEFA5763A64E5E230F85
            SHA-512:1C0ADB02F26DFF8C2A651C0B974308E77BB837570CB25227F1B68418FEA18A822DBEE26374223C003EB7D371AFF0DFE39C6B6D003285D42193520B97758B6C8F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A HF @BBL X1C",. "inherits": "Bambu TPU 95A HF @base",. "from": "system",. "setting_id": "GFSU00_00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):334
            Entropy (8bit):4.592981803650087
            Encrypted:false
            SSDEEP:6:fS583mmChFmKRmGdU0H0htzbhclz9JvFs/Kyr3P6053Peh053Pi2CA:TChFmKNU0UhJbhclpTgPd1PP1PAA
            MD5:45A6B4423C77D4160B0484BF71BCBE44
            SHA1:C0F6CDCCD78D8814B18EE655863C7ACA7C9ECD5F
            SHA-256:88EA10130832959539D6CA901719304784812167F01E25A60DDAFA89363B5FF1
            SHA-512:F62155866C0783EE2DEBC66AA56229051718B96525F69A338B31D6937FFCDF588D4D8B0F5692BF0E116F6E07436012D994734926BB3796C287797D09B49D5C92
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A HF @BBL X1E",. "inherits": "Bambu TPU 95A HF @base",. "from": "system",. "setting_id": "GFSU00_04",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):554
            Entropy (8bit):4.314437091943331
            Encrypted:false
            SSDEEP:12:1mu5sN0i4lpBpaw9zvzG0lP14x6wxSQtwA:1r5fiUp+wBvi84x3xSrA
            MD5:CD8B23AF0DA6B237185540BF14225A0F
            SHA1:919CABF7E2A9C89B59664D0D924BD429E1D781C5
            SHA-256:4D1061132A7A81932E41909AE24BCF14F7C51D7FE9BA841294C942C7303DAC0D
            SHA-512:0E346D121BCAF50E5D2ED9BAF6E78A5E6FCB567237944FB2382B47C812C4655EDCD1F7DD1A7609C08FC0EC0CA4553790A256129A0AB96FDAFBA4FD1D8AAC91DC
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Bambu TPU 95A HF @base",. "inherits": "fdm_filament_tpu",. "from": "system",. "filament_id": "GFU00",. "instantiation": "false",. "filament_cost": [. "41.99". ],. "filament_density": [. "1.22". ],. "filament_max_volumetric_speed": [. "12". ],. "filament_retraction_length": [. "0.8". ],. "filament_vendor": [. "Bambu Lab". ],. "nozzle_temperature": [. "230". ],. "nozzle_temperature_initial_layer": [. "230". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):390
            Entropy (8bit):4.491386160163602
            Encrypted:false
            SSDEEP:6:fS584bL0FbMdU0H0htzMclz9JvF/Df6zwPw/Kyr3+XwBMW53sV+W53pFz+2CA:S0gU0UhJblpTbzPk+XwKW1scW1rKbA
            MD5:434D3B408CDC1586785B12773756D8E5
            SHA1:B5B0E3CECCF02B22A96B315F88A2B54C46372D7B
            SHA-256:7F8962B5C440C2D0B6ABAF5BD1967FD32903979D47F1419DF2327DCA871ADB1B
            SHA-512:B8AD387E6406651BF457D5C6B8F3F451E289929CA163B9ABDB91BB8BE69A5EF2A70C06231D11EF780990606A548CE1E653FC1BF8EA6C448BE8C430D2AF56E8EC
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ABS @0.2 nozzle",. "inherits": "Generic ABS @base",. "from": "system",. "setting_id": "GFSB99_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):635
            Entropy (8bit):4.303906041526814
            Encrypted:false
            SSDEEP:12:QKW0gU0UhJ2clpTbwwDvzPOdGMKOGKIh5cGMKnKkBcbA:QBPJqowpTbwGvjUeyIh5ceKbA
            MD5:76D8F93A3632FEE746282C6F65C2C8A4
            SHA1:6EEFF489B2AF563F076BFE8986286FD31D890F25
            SHA-256:193589312A94022B6ADEB340A30E1955FAC876DB707C02192107B36564623186
            SHA-512:DCEC484AAFC2DAC59BA6291CAFEBD70052D0090D794085CF51C6F46E9AF71ACCF962A7B409F708B442BF21AA74B318C51569626A3F5CEA0A90C5FB1DD4380EA6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ABS @BBL A1 0.2 nozzle",. "inherits": "Generic ABS @base",. "from": "system",. "setting_id": "GFSB99_06",. "instantiation": "true",. "fan_max_speed": [. "20". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "100". ],. "hot_plate_temp_initial_layer": [. "100". ],. "reduce_fan_stop_start_freq": [. "0". ],. "textured_plate_temp": [. "100". ],. "textured_plate_temp_initial_layer": [. "100". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):695
            Entropy (8bit):4.3245436376733135
            Encrypted:false
            SSDEEP:12:DgU0UhJL0lpTbwwDvzTOdGMKOGKIh5cGMKnKkBR1BT1BcA:UJq5opTbwGvXUeyIh5ceKQDsA
            MD5:8B8FBC5A2C2BF045C6BC9087F1CEEF7A
            SHA1:CE2F78C90D6112DE54E7BAE1BA9F5E8661F09AA0
            SHA-256:ED79B5B3DD2526329C2ACFB7320BB50C822EC3B3762509BB346B8C57536C89FE
            SHA-512:867D052B28A7E19341F6D0FCF50D6FF763E970544A6DEBCD7085358FC4D86C149AA7D4E3A331922889E72B62F85D52FDB4D858B4E14C9A7523D9B958BF0AC23A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ABS @BBL A1",. "inherits": "Generic ABS @base",. "from": "system",. "setting_id": "GFSB99_05",. "instantiation": "true",. "fan_max_speed": [. "20". ],. "filament_max_volumetric_speed": [. "15". ],. "hot_plate_temp": [. "100". ],. "hot_plate_temp_initial_layer": [. "100". ],. "reduce_fan_stop_start_freq": [. "0". ],. "textured_plate_temp": [. "100". ],. "textured_plate_temp_initial_layer": [. "100". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):269
            Entropy (8bit):4.5669723294231925
            Encrypted:false
            SSDEEP:6:fS584b4AKW0FbLG0H0htzeUlz9JvFs/Kyr3Pg2CA:39W0FG0UhJeUlpTgPgbA
            MD5:9BCCB34166326EEB905B66C6DA290D5C
            SHA1:CE8F23079942EAAEADBB4C126257BB1B2296EBCE
            SHA-256:A04B6090E5C1241BFBF8B5561B9E78AE22E987A404B7C33028605E77DF65345A
            SHA-512:FED969703E3DEB971785ED1530D8ED879E0BC45126C913117564B7D96516E6CE7A323B7435CCD8026B4D5141BC6A2C3988F0C6DBF6A3BD9B8F62BA5E9E3A4201
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ABS @BBL X1E 0.2 nozzle",. "inherits": "Generic ABS @0.2 nozzle",. "from": "system",. "setting_id": "GFSB99_04",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):318
            Entropy (8bit):4.5052114548554085
            Encrypted:false
            SSDEEP:6:fS584b4ChFmFZI0H0htzlUlz9JvFs/Kyr3P6053Peh053Pi2CA:3ChFmDI0UhJulpTgPd1PP1PAA
            MD5:956FF90FAB9E0CCAAE2CAC9D35BDEA2E
            SHA1:6DEAE87004F169140ECCEFD81B6E388843BE1D65
            SHA-256:27019A09351DB4D13F38A5E7A18D1AB43023CF3DB169C8853B5BCD4A1CDB2783
            SHA-512:2B99A73BBC4963C1EC1E06EA4021443138CB362208CA16E15AD25EF8282A0D14AD1014CEA096F7B57306646195DF2018596B620AF50C973FEA7C79E93666FF7A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ABS @BBL X1E",. "inherits": "Generic ABS",. "from": "system",. "setting_id": "GFSB99_03",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):285
            Entropy (8bit):4.331774281597466
            Encrypted:false
            SSDEEP:6:fS584bMdmu+oEG0yDYmlz9sl93FqbDf6zwlwA:hmu5t0iYmlpG3ovzaA
            MD5:320CF7291A09FD5AF01A45BE795F8809
            SHA1:424601FFC33FD7B08190220886C004D8A9A8752E
            SHA-256:93F22D6B82A6FD99961FBE3ABB440732697659266126EB1D6F088DD0898154AB
            SHA-512:B96C380A4787980729F177748FD1D320D8A1102E2BEAB167FF3DFE95A45DBBFD60E3FC2D61A86941DF3E60A2285B3E16E58BFDBF1645BFB9BE9DF7C8DF23FF0F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ABS @base",. "inherits": "fdm_filament_abs",. "from": "system",. "filament_id": "GFB99",. "instantiation": "false",. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "16". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):602
            Entropy (8bit):4.401445553052672
            Encrypted:false
            SSDEEP:12:Q6gU0UhJpmlpTbzTk+XwHP1sjl1+Xw91+XwLP1sT1sHl1rll1r91rx8A:KJqCpTbXDXwHPSREXw9EXwbSTSHllXDn
            MD5:23E76048C3F72FA780BCFAAB6E27B521
            SHA1:7E2F7EAEB4F88ACD21C50CCE948EBD0F74782008
            SHA-256:9603AFE4CE92AD701683226237BC1092712277D8F01A225A862AB7691AFB7522
            SHA-512:0F4620715795A995326A87D137E81228E12E8A2CDA39F6B2A55D751B336F0E1FE2CFCC5EDA4164BBDBE60CA42F30B1579108A826CE43F472AC5FFD39E63951C0
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ABS",. "inherits": "Generic ABS @base",. "from": "system",. "setting_id": "GFSB99",. "instantiation": "true",. "filament_max_volumetric_speed": [. "15". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):390
            Entropy (8bit):4.500385583251619
            Encrypted:false
            SSDEEP:12:t0McU0UhJs+rclpTbzPk+XwKW1scW1rKbA:tBcJqDwpTbjDXwBS/SA
            MD5:91001E58C3B77E19C9F2EB8591F3C5AA
            SHA1:22826B6D4FEBB6580C38B4BC6D967546E7A7D0BE
            SHA-256:CC96419D7884A90A942E4CED9E250897B5B72277C481173C548FF3660E3C221C
            SHA-512:628DA6F088149A3911183D63074E497E33B506A2D51E3DD528F936C5C4D8173683CA34F170A1B19F3E9558BB24F8F57FBC3ECCA389EEE1D1F67CEB72BDCA683B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ASA @0.2 nozzle",. "inherits": "Generic ASA @base",. "from": "system",. "setting_id": "GFSB98_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):537
            Entropy (8bit):4.34973027486026
            Encrypted:false
            SSDEEP:12:dxKW0McU0UhJs+xlpTbzPOdGMKOGKcGMKnKkBcbA:dxBBcJqLpTbjUeyceKbA
            MD5:CBBABA0ABADD61D38074143BACB3F4CA
            SHA1:49B6569D16036D6235C37E3F0AA4C0F45C268D3F
            SHA-256:FE7EDCED6D25E39948125E4D4AA2A9E6DAAEB2147CAE32FD379F9B10AE675C70
            SHA-512:CB535D77917F617ECCF8C7984A5C8CFE63DD01E9EEBDC87D45C49F9637C252017450E4D2142884DFF103CF7833871255C64DF3A7140C12253FC4B3B3F5A62393
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ASA @BBL A1 0.2 nozzle",. "inherits": "Generic ASA @base",. "from": "system",. "setting_id": "GFSB98_03",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "100". ],. "hot_plate_temp_initial_layer": [. "100". ],. "textured_plate_temp": [. "100". ],. "textured_plate_temp_initial_layer": [. "100". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):538
            Entropy (8bit):4.344210733183681
            Encrypted:false
            SSDEEP:12:duMcU0UhJs+8lpTKdGMKOGKcGMKnKkBR1BT1BcA:dDcJq4pToeyceKQDsA
            MD5:C4AE79B7099188C0B94019BAA96A98CA
            SHA1:52B11B02198ABC348387AAC9FA29EB4A4131E85A
            SHA-256:A2F2F0D49E0DEE0B3C0292515D1C219F5E3E23DDBBD85B546A9E7A0B44DABB8F
            SHA-512:7D1CCFDAFE2E6E53ED21C335F19C778FDA65B9261BFF7AA835C1D67FCB835300FBC14798389A9904F92B1A81140EBB01F3954ADCBC33D7C4D8C28965952461C7
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ASA @BBL A1",. "inherits": "Generic ASA @base",. "from": "system",. "setting_id": "GFSB98_04",. "instantiation": "true",. "hot_plate_temp": [. "100". ],. "hot_plate_temp_initial_layer": [. "100". ],. "textured_plate_temp": [. "100". ],. "textured_plate_temp_initial_layer": [. "100". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):269
            Entropy (8bit):4.569778602665435
            Encrypted:false
            SSDEEP:6:fS584c0AKW0FEPG0H0htzs+e6lz9JvFs/Kyr3Pg2CA:d09W0uG0UhJs+e6lpTgPgbA
            MD5:80A852A8979A8BF814D951E87B7CEB1D
            SHA1:1C47B0F16A40FDA4208F4BA1D028D1132E1EECF2
            SHA-256:725177BA23D879910258A40EC987F56433848D3D0003259DF2E025FE9EBE0246
            SHA-512:99B3137AFCC7FDEC766315C240FA1B40CD7F41374DE0FE8D33E5EBACE25A539A7C2463BCB365FB80CECE9D463D3CAC10C4E3D46ED7380FB000CD801DB483A867
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ASA @BBL X1E 0.2 nozzle",. "inherits": "Generic ASA @0.2 nozzle",. "from": "system",. "setting_id": "GFSB98_01",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):318
            Entropy (8bit):4.513042351068217
            Encrypted:false
            SSDEEP:6:fS584c0ChFmFQG0H0htzs+qlz9JvFs/Kyr3P6053Peh053Pi2CA:d0ChFmr0UhJs+qlpTgPd1PP1PAA
            MD5:1B0CA7485F173E844176127B4BD6713C
            SHA1:052FD86A973F8E80C595431D29B6FD627AC15F1F
            SHA-256:1C2F0C4862F995686D6051C11130FBCCAF4244361639DDAC2D7A537D5155276E
            SHA-512:F09B121CB18B66F2D92830788F8FAED77BCACFD87BC0F4115A71646AE80618D7047375D8F1347CD8D9A1BC64A2623E9EB88CDB113E51386F27454A1C35F72AD6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ASA @BBL X1E",. "inherits": "Generic ASA",. "from": "system",. "setting_id": "GFSB98_02",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):285
            Entropy (8bit):4.330222123454277
            Encrypted:false
            SSDEEP:6:fS5846qdmu+oPG0yDVzmlz9sl93FqbDf6zwhnwA:rcmu5e0iVzmlpG3ovzGA
            MD5:DD5043A8AB675F7F416BCB992A1C3552
            SHA1:E225602E6BE23F3F392A664973E890B3512879CA
            SHA-256:E7EC6BF07D64D1E33E3C6F8F34782357F7323722B6D3A6CCE9B03E0B250F1240
            SHA-512:E1D5D45089720F624F1D2D6AC0952CFFDEB61E5A65FDB70CA1522EEF3E95A31D364DA497F350022DF0DC40C34268DA9C96ACFD0D9B3FC96B558F63B6F408D831
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ASA @base",. "inherits": "fdm_filament_asa",. "from": "system",. "filament_id": "GFB98",. "instantiation": "false",. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "12". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):543
            Entropy (8bit):4.362948427848184
            Encrypted:false
            SSDEEP:12:2McU0UhJszmlpTg+XwHP1sjl1+Xw91+XwLP1sT1sHl1rll1r91rx8A:7cJqiepTnXwHPSREXw9EXwbSTSHllXDn
            MD5:041E82B7CED629E90366A22B3B9B53BA
            SHA1:B0358FEFDA39D4D4B2656FD5CE1A91D554A77A77
            SHA-256:3A2573E8CB5F363B985B772F61CABB70292D4BFD7DA0A588D2F58D55B31401E8
            SHA-512:221F74D08BBE73853593E1C4146C75E959A0D50D223292B1D1B18C58E6ACA9C305F01FAC03B01FC6668ED8695D85B23753A665AA4A6EC8B421C0E0DBE378BBE5
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ASA",. "inherits": "Generic ASA @base",. "from": "system",. "setting_id": "GFSB98",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):639
            Entropy (8bit):4.322177892457622
            Encrypted:false
            SSDEEP:12:OKW0UU0UhJv0lpTqsGT22vz1qOdGTOVcGTmkBcbA:OB5JqdopTqsq22vxqUqecqmbA
            MD5:B6061F69014588C343899DBDBFBFE16B
            SHA1:FC30D8B708A8D757E0FA6437C451AC050112725D
            SHA-256:FFDCE17DD8E0A850BAE08EE002E017571897AB7193F4F10C3FBB1148FF55B69D
            SHA-512:CD859A954513F70F0185A2C09ECB63CE858CF2CFB965613031B343ECED910EBEE7566D809F430A807FB8AA2B615093EFCCB6E2E34566E0C1BC534B78D11C9494
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic HIPS @BBL A1 0.2 nozzle",. "inherits": "Generic HIPS @base",. "from": "system",. "setting_id": "GFSS98_05",. "instantiation": "true",. "eng_plate_temp": [. "70". ],. "eng_plate_temp_initial_layer": [. "70". ],. "filament_max_volumetric_speed": [. "0.5". ],. "hot_plate_temp": [. "70". ],. "hot_plate_temp_initial_layer": [. "70". ],. "textured_plate_temp": [. "70". ],. "textured_plate_temp_initial_layer": [. "70". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):638
            Entropy (8bit):4.322786206313915
            Encrypted:false
            SSDEEP:12:VUU0UhJTlpTqsGT22OdGTOVcGTmkBR1BT1BcA:KJqPpTqsq22UqecqmQDsA
            MD5:AE408DE3A72805B0727E474EBBB54406
            SHA1:F6869A33CD3FFC1DF0512AB9AFAA18C0F848D0F3
            SHA-256:34BD11EE31AA3474DCB1BB6E385E9D8CC0ED5D0784FB029CE6D4B6A07E8E1327
            SHA-512:AE2DE7BED2E7751E82A4582EBBBDBF2B3B01EDDD8F2587614AFC66475730CC5DD18818F202CD2CAD494852B7AD10C93B7F66EB7F62EB0A742005439BA0239996
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic HIPS @BBL A1",. "inherits": "Generic HIPS @base",. "from": "system",. "setting_id": "GFSS98_04",. "instantiation": "true",. "eng_plate_temp": [. "70". ],. "eng_plate_temp_initial_layer": [. "70". ],. "hot_plate_temp": [. "70". ],. "hot_plate_temp_initial_layer": [. "70". ],. "textured_plate_temp": [. "70". ],. "textured_plate_temp_initial_layer": [. "70". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):645
            Entropy (8bit):4.335610739609171
            Encrypted:false
            SSDEEP:12:t+W0UU0UhJn6lpTqsGT22vz1qOdGTOVcGTmkfbA:35JqEpTqsq22vxqUqecqm2A
            MD5:560BDC9B23A346DA5D0EE40B7538BB76
            SHA1:0EDDCF4E0E4206B656B1672007415C5E61B5FDD6
            SHA-256:DE83171ECBC1C86D3DF78BD58AA554D83ADCE307BBC901072E3DEC6EE0C57DB1
            SHA-512:92ABDCA656B31E08AF767F33EFB0F4A48FD806357D5A88F81A1D8583B05A8C94724CB733EC9691379DCF5ACE0EECFD68C3F77AF34B0913DC4F7D0C19953F2F83
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic HIPS @BBL A1M 0.2 nozzle",. "inherits": "Generic HIPS @base",. "from": "system",. "setting_id": "GFSS98_03",. "instantiation": "true",. "eng_plate_temp": [. "70". ],. "eng_plate_temp_initial_layer": [. "70". ],. "filament_max_volumetric_speed": [. "0.5". ],. "hot_plate_temp": [. "70". ],. "hot_plate_temp_initial_layer": [. "70". ],. "textured_plate_temp": [. "70". ],. "textured_plate_temp_initial_layer": [. "70". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):654
            Entropy (8bit):4.336379538712203
            Encrypted:false
            SSDEEP:12:mUU0UhJBlpTqsGT22OdGTOVcGTmko1i1RA:7Jq9pTqsq22Uqecqmx4LA
            MD5:CB7757B19A2DD8A2695BE89B77E544A6
            SHA1:29A679DFDC039BAF551C8A3AE23882C1383CC55D
            SHA-256:D4682905D416F91BD9CA95BDDA7F71EF7035CB140E75D1BF4AAB37E0F076B719
            SHA-512:BFF767E9B6AB4DB19027947F425D48C4F2CF887912099A1C011BFF08AFEC024A047A855E6EC9B7EEAAFB3E689AA7A7D2116A440AFF28CBAED5E94B4A1738D7D8
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic HIPS @BBL A1M",. "inherits": "Generic HIPS @base",. "from": "system",. "setting_id": "GFSS98_02",. "instantiation": "true",. "eng_plate_temp": [. "70". ],. "eng_plate_temp_initial_layer": [. "70". ],. "hot_plate_temp": [. "70". ],. "hot_plate_temp_initial_layer": [. "70". ],. "textured_plate_temp": [. "70". ],. "textured_plate_temp_initial_layer": [. "70". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):474
            Entropy (8bit):4.5342072821534805
            Encrypted:false
            SSDEEP:12:ByVgW0UU0UhJAlpTbz1qk+XwKW1scW1bW1rKW1PgbA:Aj5JqipTbxqDXwBS/MLBKA
            MD5:1578BE165F0C4DABA5C1125C5A1BB125
            SHA1:FC8C03803B3DBE26A366936EC9B9E436F7998C77
            SHA-256:CD13E387CBCC18FB32C507A58DD4586B377AEE4554B3014914C09DF28D2C4097
            SHA-512:D8420630817B8E7F8CE5FF404D5BC213DEB00015627D79B5B8B4458ECFDB1C5AD236D6F5A391A9A85C7A93F3B2F59B82131112F47F2CAB13A74CF92BE8494497
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic HIPS @BBL X1C 0.2 nozzle",. "inherits": "Generic HIPS @base",. "from": "system",. "setting_id": "GFSS98_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "0.5". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1P 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):773
            Entropy (8bit):4.323436778569249
            Encrypted:false
            SSDEEP:24:AJqWwpTnXwHPSREXw9EXwbSTSHlqwOlXDlBdBPBAA:aapTOk2
            MD5:FBCABB4916F3DB6DC803F8CEB784F763
            SHA1:73FBAE95A79601196227C1401539DFE669EF88ED
            SHA-256:C9305BA827C9A2B3973228CD6ADC729B23C916C5066111F80F6CDA028429274C
            SHA-512:97A6D6915C636D17D483C42CF52510803258CE33715864139F87C76004C5495804391974E9C41111082B65A4BFEDE51FAAE4D49EB46CF6DC9BFEC72A137F4B09
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic HIPS @BBL X1C",. "inherits": "Generic HIPS @base",. "from": "system",. "setting_id": "GFSS98_00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1P 0.4 nozzle",. "Bambu Lab P1P 0.6 nozzle",. "Bambu Lab P1P 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):225
            Entropy (8bit):4.279604041809766
            Encrypted:false
            SSDEEP:6:fS5848dmu+osJG0yDzcdzmlz9sleHpdqA:7mu5b0iz/lpTzqA
            MD5:F440B3D0EC54A8A2C6ED252491774ED0
            SHA1:877E7359535F2134C8C88A3ED7BE5D035F44F157
            SHA-256:B029ACD12AD6E5F4963C29858506D86EDC36B7DD434DE5FAD4ADA2AB1E38C10D
            SHA-512:BAFC9F747A1F3AD8466C816047BF8AEAD4B7551006D13AC0B8A6ECBBF6CCB986204C6D055487CDCD6E47626779F77FEF648AADDFD4502C0A90A1541971C6F5DD
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic HIPS @base",. "inherits": "fdm_filament_hips",. "from": "system",. "filament_id": "GFS98",. "instantiation": "false",. "filament_is_support": [. "1". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):361
            Entropy (8bit):4.399326660260481
            Encrypted:false
            SSDEEP:6:fS584a6FWu0H0htzQclz9JvFsNEmAeQXAkw/Kyr3B+053Bqh053Be2CA:YZ0UhJ/lpTomVkBR1BT1BcA
            MD5:D326441A83AABB7FD3B13933F85DB2BD
            SHA1:138EBA1DA27F1E69DB601922FC3AC52D7A0BEB3E
            SHA-256:FA425DCF9C8BA69DE40A90152B994E490D63482F7199B1AD242BE19B5AC69BC1
            SHA-512:B1200022DBF20B6A1E008C021BBF7CA4454D15C04504710FD1DE86F933AD0539229D11436AF20A842E39790A5314282FF662539D18DF65B0194560ED59A97221
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PA @BBL A1",. "inherits": "Generic PA",. "from": "system",. "setting_id": "GFSN99_00",. "instantiation": "true",. "chamber_temperatures": [. "0". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):374
            Entropy (8bit):4.4912009669334525
            Encrypted:false
            SSDEEP:6:fS584o6FR0H0htzg+e6lz9JvFEeQXAyHejvqw/Kyr3B+053Bqh053Be2CA:Qv0UhJg+e6lpTyyikBR1BT1BcA
            MD5:9D51542C6818F532EF50330075C23A95
            SHA1:B04E2764C7EAAB82E2E144AF435298D285B9905E
            SHA-256:073194E74C5C5A8FD161B26AF7852D6361894FEF1474D23F9E7F205350B9674E
            SHA-512:EED14999B88813FBC8C3490629328C65F080AD5271700D1F2AD2B8167960C91355F84CED4ECE897D5782CF65602A0B480938A54D69D5B2E948E9E28AE6EB0E11
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PA-CF @BBL A1",. "inherits": "Generic PA-CF",. "from": "system",. "setting_id": "GFSN98_01",. "instantiation": "true",. "temperature_vitrification": [. "108". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):372
            Entropy (8bit):4.528159206672356
            Encrypted:false
            SSDEEP:6:fS584FChFmFR0H0htzg+rclz9JvFsNEmAeQXAgw/Kyr3P6053Peh053Pi2CA:eChFmv0UhJg+rclpTomrkPd1PP1PAA
            MD5:B7EA6D3A8E7434A5C2EF956B841EA6B2
            SHA1:71BF595C0AB6466D24F373827B2CEFE702B98BBF
            SHA-256:B41766DC85809C174A21C70AE6B958A5EC66E34ACEB085A68820BC7A75EE006A
            SHA-512:9D0DFD364BE9563349A0D1597750292F92355204C908520663130FF32070E87991CB8E45012010D1048F71D13F02BFB4F9CA332C25DC0B716C75734D72104549
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PA-CF @BBL X1E",. "inherits": "Generic PA-CF",. "from": "system",. "setting_id": "GFSN98_00",. "instantiation": "true",. "chamber_temperatures": [. "60". ],. "compatible_printers": [. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):959
            Entropy (8bit):4.379290632502378
            Encrypted:false
            SSDEEP:24:D5filxGpTvPwLqnojoiHoBm4DXwHPEXw9EXwbSRSTSHllXD8A:D5filApT3Bnqkv
            MD5:D72A65725936A4D8FD38833CCC27C014
            SHA1:0519C4D181CF80159ADF04E0E7A93D2796CE7E57
            SHA-256:B3362A93645081A1317761F3E4DBFA24B6769E0C37CD048F5A006B1213F97AD2
            SHA-512:DFA8EEC1694334BCA4FA9A407C85D20727813B45C9A47331BD860737C69EAF09D0139B0165E69A50257855135301394D210D8FD94378ACA29E01BEA1C1A8F972
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PA-CF",. "inherits": "fdm_filament_pa",. "from": "system",. "filament_id": "GFN98",. "setting_id": "GFSN99",. "instantiation": "true",. "fan_cooling_layer_time": [. "5". ],. "fan_max_speed": [. "30". ],. "fan_min_speed": [. "10". ],. "filament_type": [. "PA-CF". ],. "full_fan_speed_layer": [. "2". ],. "overhang_fan_speed": [. "40". ],. "overhang_fan_threshold": [. "0%". ],. "temperature_vitrification": [. "170". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1401
            Entropy (8bit):4.367682696218726
            Encrypted:false
            SSDEEP:24:b5fi0mepT1rXPwwQDvixGxSSx0QxxoiFo0AuPCXNDXwHPEXw9EXwbSRSTSHllXDN:b5fiLepTZxawxp3unkV
            MD5:929D735958D608706F2C22EF5F9FB0B9
            SHA1:816EB29357B24BDCCF09FB4FCE573EB3A4B1E7F5
            SHA-256:33B02DF75B50FAE7EEA95A4D19C274671B6B8BE0AEDD7A910CB543A7E7571EE5
            SHA-512:E7F596226C028633D7DDBDBF9B09061499AB60905A733308624A77002C0FCB444E806C288240B730BE71C20A1BBA6F831DF889FB330999173B660E4EAEA86F5A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PA",. "inherits": "fdm_filament_pa",. "from": "system",. "filament_id": "GFN99",. "setting_id": "GFSN98",. "instantiation": "true",. "chamber_temperatures": [. "60". ],. "fan_cooling_layer_time": [. "65". ],. "fan_max_speed": [. "85". ],. "fan_min_speed": [. "40". ],. "filament_max_volumetric_speed": [. "12". ],. "nozzle_temperature": [. "260". ],. "nozzle_temperature_initial_layer": [. "260". ],. "nozzle_temperature_range_high": [. "280". ],. "nozzle_temperature_range_low": [. "240". ],. "overhang_fan_speed": [. "95". ],. "overhang_fan_threshold": [. "10%". ],. "required_nozzle_HRC": [. "3". ],. "slow_down_layer_time": [. "8". ],. "slow_down_min_speed": [. "10". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):352
            Entropy (8bit):4.482316970210604
            Encrypted:false
            SSDEEP:6:fS5840j0FmidU0H0htzJclz9JvF/Df6zwxdqw/Kyr3+XwBMW53sV+2CA:30IEU0UhJSlpTbzrqk+XwKW1scbA
            MD5:75DDE39AF1F5947AA18D1026F2D2771B
            SHA1:027A66A4C01BEB908D04C6445C5463FB7A086CAD
            SHA-256:648108FF1D8834D78E1310BFAC514BC484CBDE2918AEC338C70F2D6B38B6A694
            SHA-512:B92E07E708DDF24EE7A8C35A4C28412E69DC0FBA7FCB02BAE3CDF7A54E13D7206F878BCCD8B480E87B5F803DAF152EFC38337177055E65EC973C16D128492657
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC @0.2 nozzle",. "inherits": "Generic PC @base",. "from": "system",. "setting_id": "GFSC99_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):737
            Entropy (8bit):4.253686542809031
            Encrypted:false
            SSDEEP:12:5TKW0IEU0UhJqlpTqsGMK23KPwwDvzrqOdGMKOGKIh5cGMKnKkBcbA:5TBPEJqgpTqse2aPwGvnqUeyIh5ceKbA
            MD5:99171B89DEBF236DE57A26F56856C53F
            SHA1:8CE1153358A0E8FA09C8D1424534EED75C14360A
            SHA-256:72C9D4C0479B4492BDFFA543478528E8DD5B3AC5F4D443AB8D8E643A34954A72
            SHA-512:D4C7060A981E798478C545065131DBD15A00EB700DA30B487212FC1FED4F118EB2264ECA4295161F9B17F6CCDEC709DF4842CC4179B54495A08D7A82AEF2AE94
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC @BBL A1 0.2 nozzle",. "inherits": "Generic PC @base",. "from": "system",. "setting_id": "GFSC99_08",. "instantiation": "true",. "eng_plate_temp": [. "100". ],. "eng_plate_temp_initial_layer": [. "100". ],. "fan_max_speed": [. "20". ],. "filament_max_volumetric_speed": [. "1". ],. "hot_plate_temp": [. "100". ],. "hot_plate_temp_initial_layer": [. "100". ],. "reduce_fan_stop_start_freq": [. "0". ],. "textured_plate_temp": [. "100". ],. "textured_plate_temp_initial_layer": [. "100". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):738
            Entropy (8bit):4.27506107121964
            Encrypted:false
            SSDEEP:12:5sIEU0UhJq6lpTqsGMK23KPwwDOdGMKOGKIh5cGMKnKkBR1BT1BcA:5HEJqbpTqse2aPwGUeyIh5ceKQDsA
            MD5:5482AB66531D83D4CA8503CB85247B91
            SHA1:BFA388C3BC92CA7F00793789D2CD17173F1DDB0C
            SHA-256:C0EF5273523980E8C29E72D927C467B0A5CD2BFD4B99A3F066CD8CA5C73F2802
            SHA-512:A941C9829E390ABC458C8DE8BD9B3F0949CF58300385B6FAAD54B8E00E8FDCD434DC26089B957D2B2B9035F32A8E64C8785D061D25F15FC571A4694A0ECA490B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC @BBL A1",. "inherits": "Generic PC @base",. "from": "system",. "setting_id": "GFSC99_07",. "instantiation": "true",. "eng_plate_temp": [. "100". ],. "eng_plate_temp_initial_layer": [. "100". ],. "fan_max_speed": [. "20". ],. "hot_plate_temp": [. "100". ],. "hot_plate_temp_initial_layer": [. "100". ],. "reduce_fan_stop_start_freq": [. "0". ],. "textured_plate_temp": [. "100". ],. "textured_plate_temp_initial_layer": [. "100". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):589
            Entropy (8bit):4.298459441732879
            Encrypted:false
            SSDEEP:12:5C2gW0aG0UhJ26lpTqsGMK23KOdGMKOGKcGMKnKkrKbA:5tjJHq8apTqse2aUeyceKZA
            MD5:D03C3D355DBFE7CB2077CEE7F190214E
            SHA1:D6156EC20D265B6794399855B1096AB77DE40A93
            SHA-256:FE30A47666FD1C78D4D23A60213F0DEDF7C824CEC3AA687F25A73F92230A29B0
            SHA-512:8F2FA27F8031EC436B1EBD31716A7E67966AE40A04F96609BE7A3E7926B5742250FD66D966F03D830590E9A879C06840BF799544FDF53413CA73C9C2DF80E390
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC @BBL P1S 0.2 nozzle",. "inherits": "Generic PC @0.2 nozzle",. "from": "system",. "setting_id": "GFSC99_03",. "instantiation": "true",. "eng_plate_temp": [. "100". ],. "eng_plate_temp_initial_layer": [. "100". ],. "hot_plate_temp": [. "100". ],. "hot_plate_temp_initial_layer": [. "100". ],. "textured_plate_temp": [. "100". ],. "textured_plate_temp_initial_layer": [. "100". ],. "compatible_printers": [. "Bambu Lab P1S 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):638
            Entropy (8bit):4.294166867730461
            Encrypted:false
            SSDEEP:12:5CKF0f0UhJ1UlpTqsGMK23KOdGMKOGKcGMKnKkrll1r91rx8A:5xfqEpTqse2aUeyceKSXD8A
            MD5:58BD5AD450E1F2D7B0E1F549A1CBC7CE
            SHA1:F868B4765BC52E9A8EC11642B1A13204D081CBFA
            SHA-256:941E38825D76D9C4A3B7EE5FA993A56F4F84A285D14A77E3F28E341F3C5AC9EE
            SHA-512:2264D7CBB58434D99094855B41C86180AF516466CBB34F3F9425768F4E51BC0D6B8C443D491CE3BF64D5428F253B892763756A0F62155A6942BE7EF689072BC2
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC @BBL P1S",. "inherits": "Generic PC",. "from": "system",. "setting_id": "GFSC99_04",. "instantiation": "true",. "eng_plate_temp": [. "100". ],. "eng_plate_temp_initial_layer": [. "100". ],. "hot_plate_temp": [. "100". ],. "hot_plate_temp_initial_layer": [. "100". ],. "textured_plate_temp": [. "100". ],. "textured_plate_temp_initial_layer": [. "100". ],. "compatible_printers": [. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):317
            Entropy (8bit):4.517693177301055
            Encrypted:false
            SSDEEP:6:fS584G6AKW0F0jG0H0htzaHJ0lz9JvFsNEmAeQXAgw/Kyr3Pg2CA:569W0aG0UhJap0lpTomrkPgbA
            MD5:E2B42646B1183E69D29E55975EB473EF
            SHA1:521ECA09173698F033D1099A566B6F7FDC35B633
            SHA-256:03A72782562679741198C314C4BF2EA16C15DE83CF8377691FAC654161741A6C
            SHA-512:59043021C3C3ADB39FFD3E66CA2BD7A01E3C6C7F17BE625AE8732C85F7494EED0779A2ACBD6E35960FF2D9CB186AF4D3AB70458B40AD36CC167342656C49114F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC @BBL X1E 0.2 nozzle",. "inherits": "Generic PC @0.2 nozzle",. "from": "system",. "setting_id": "GFSC99_05",. "instantiation": "true",. "chamber_temperatures": [. "60". ],. "compatible_printers": [. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):366
            Entropy (8bit):4.458468674835013
            Encrypted:false
            SSDEEP:6:fS584G6ChFmFp0H0htz/clz9JvFsNEmAeQXAgw/Kyr3P6053Peh053Pi2CA:56ChFmf0UhJ/clpTomrkPd1PP1PAA
            MD5:FF75FD2D1478353FA451F889F8B3CEF5
            SHA1:8F20E846EDD235C7F2C953A9BCC246091319FE9F
            SHA-256:EF57FB7F15D7BE2F398CA5425825EE3F4631C26B4602F15D5260A1EE94FE11D3
            SHA-512:21290198FD1700755C29C05BFCFDC93F19DEE126F64D8255D8F49446FEDEEB18FFF699A6236D8E70705C4E60EADAFEF6DDA8893BCC7B14E079DE3BA3A5D81475
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC @BBL X1E",. "inherits": "Generic PC",. "from": "system",. "setting_id": "GFSC99_06",. "instantiation": "true",. "chamber_temperatures": [. "60". ],. "compatible_printers": [. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):283
            Entropy (8bit):4.315532504471026
            Encrypted:false
            SSDEEP:6:fS584midmu+ok0yDjcPlz9slDf6zwlwb9bA:ZEmu5k0ijIlpCzahbA
            MD5:21FAA97716435A1BC474AE86F4B582AD
            SHA1:88416A8EC29D36A515DEC1659407DEF38AD6095A
            SHA-256:943C1B8F666C348BE88592CE5554EC888B335E4AC8F8DB9800F77302D98A9A0E
            SHA-512:E04352FC90EDB5DBAA4E5B1339D4BD35048379353E9E45B7E863F08D1EC9842CD9BAEB8DBC858155771621162EE2363BFE197DDEB007F517B388835FB8229028
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC @base",. "inherits": "fdm_filament_pc",. "from": "system",. "filament_id": "GFC99",. "instantiation": "false",. "filament_max_volumetric_speed": [. "16". ],. "filament_flow_ratio": [. "0.94". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):433
            Entropy (8bit):4.384263600494565
            Encrypted:false
            SSDEEP:12:cIEU0UhJblpTg+XwHP1+Xw91+XwLP1sjl1sT1sH8A:3EJqPpTnXwHPEXw9EXwbSRSTSH8A
            MD5:35E127D4E594B033745EFF8E6FFE9517
            SHA1:40AFBABA17EBB71E613D310F33ACEE81101E4808
            SHA-256:76EF30478F8F28233736ABA7131A383829B6763EAAF0AD618CBC1C2D2BFF86B7
            SHA-512:5B25168B51F05A16CF7E405C47645C6B771179524916620E64FB5A8AA29A197333EB88D6E125A5703B27066024EFF832A4F7AAC19870EF879D2C4BE66C75509A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC",. "inherits": "Generic PC @base",. "from": "system",. "setting_id": "GFSC99",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):428
            Entropy (8bit):4.506490560995974
            Encrypted:false
            SSDEEP:12:E0rcU0UhJj5lpTbzrqk+XwKW1scW1rKW1PgbA:ENJqdpTbnqDXwBS/LBKA
            MD5:190AF76F06B1D4AD8FBBF7D3EF51F5D0
            SHA1:29775BEDEEF87AD796AD3AD1CF65FD3351D6F57B
            SHA-256:4DD11AB816254464219B9B4F54829F449C58BAAB4D2808E0B6F163DA64427AB7
            SHA-512:5BC548C92E0871F0BC8EE4D91D3CB2FB801B1F8D038D678547E348435199AA5D45B062050FBD5EC21A610B71E6A2D5B3DC7E079CEAD43A246AFFD516C98A9F80
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG @0.2 nozzle",. "inherits": "Generic PETG @base",. "from": "system",. "setting_id": "GFSG99_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):535
            Entropy (8bit):4.376550498445313
            Encrypted:false
            SSDEEP:12:ExKW0rcU0UhJjVUlpTbzrqOdGgO2cGgFkBcbA:KBNJqopTbnqUxtcxFbA
            MD5:A7AADA821F1DA5E18A45D25B79689DE3
            SHA1:967CACDAAB70511B3E1A7B2E86D83ECA8A16652C
            SHA-256:63E5372E95B1AF46DBFCA67357B79A8F4881EC83DB075745109D941B80773CA7
            SHA-512:AEAF947FA28FC880ED6231B5072CE6DD3A9994649181C30DAC60DBBA45A8CE849970FD4FF2325618C738502CB299B4C91363C186716EB4C6890839E7525BD3E6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG @BBL A1 0.2 nozzle",. "inherits": "Generic PETG @base",. "from": "system",. "setting_id": "GFSG99_04",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1". ],. "hot_plate_temp": [. "80". ],. "hot_plate_temp_initial_layer": [. "80". ],. "textured_plate_temp": [. "80". ],. "textured_plate_temp_initial_layer": [. "80". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):536
            Entropy (8bit):4.3833441670649815
            Encrypted:false
            SSDEEP:12:EurcU0UhJjvlpTKdGgO2cGgFkBR1BT1BcA:yJq7pToxtcxFQDsA
            MD5:F800DC36A081F342880E475C1E5D0A0D
            SHA1:37B3CDD6AF7001B431C69F2F3BAB4BE0AEAE4A7C
            SHA-256:119002F686BDD07CBC9CD3A13085522D5727E5E26A416D5A391FA877313BE2B9
            SHA-512:D908320579D2A6F79C8FFE5B0A6BA568B5D1BAEE966A5FD74AB54A8AD4C710D936DF2928A98C46823F0E4D65CBB40BA01C09B49DBBFFADAD5A19E494AB4E173B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG @BBL A1",. "inherits": "Generic PETG @base",. "from": "system",. "setting_id": "GFSG99_03",. "instantiation": "true",. "hot_plate_temp": [. "80". ],. "hot_plate_temp_initial_layer": [. "80". ],. "textured_plate_temp": [. "80". ],. "textured_plate_temp_initial_layer": [. "80". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):327
            Entropy (8bit):4.5468741085092566
            Encrypted:false
            SSDEEP:6:fS584fk+W0FVqdU0H0htzjVqlz9JvF/Df6zwxdqw/Kyr3f2CA:Ek+W0rcU0UhJj4lpTbzrqkfbA
            MD5:7DE8F19A43772E01D2CE85E5D1912C76
            SHA1:D9D5728EBF7B874D469392DA811685CB9946E5CC
            SHA-256:6DFCBED1DF7FC643A1C4C266D599306D39119CA46362ADD8C86E68AF136E659D
            SHA-512:FE3BDE1A9CCFD507FF22BA3296F1B10AB8139254948A66D0D34AB2887E773A9E5FCBB9E669E9CE6F0BDE382F503A51151615AD90C8130AE2B90671F9A284F8D5
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG @BBL A1M 0.2 nozzle",. "inherits": "Generic PETG @base",. "from": "system",. "setting_id": "GFSG99_02",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):396
            Entropy (8bit):4.508448549045002
            Encrypted:false
            SSDEEP:6:fS584fg0FVqdU0H0htzjVrclz9JvF/Df6zwRw/Kyr3r053zh053R2CA:EPrcU0UhJjylpTbzRko1i1RA
            MD5:3E57C82159C38CAE4C58DAC16D5E3C69
            SHA1:4A861771AFF39E015252DC6537B36B940B5DF0AA
            SHA-256:6190F0D0085A94C521692389D5961FA082C414EF9C07ACB44D54805A34E3C636
            SHA-512:7155228DE9A2D6C2D52938681C65DCC658BF157090371FA739082BA8CCAF4191266C8E2ACC0E6606708701FFD3349B2C00D3E9FF779670E09FB52338A3E31CF2
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG @BBL A1M",. "inherits": "Generic PETG @base",. "from": "system",. "setting_id": "GFSG99_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "8". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1561
            Entropy (8bit):4.543678547879724
            Encrypted:false
            SSDEEP:24:Xr5RinEpx5h2sq22ZPwpDNoviUqex0WwoiOo0kycqmJvTcL3SfjcLcgSf4fTl/ui:75RinEpIaQsItwvH/SB/P
            MD5:5BEBE589A01448E0A5B1B395B8822EBF
            SHA1:02AB1B67729D1F2A2DDCE9C86B6C1EAC0E30EA24
            SHA-256:6F6C6F213537CF75AB87F5EAE7454A876CA268208D70F6B241C5396224A95B1A
            SHA-512:B99E8904C1092DA6FFD626A6C193E7A6ED902942C5E6A65C032AA92C3D0D4A3AAF2FB085E5D760F66D24164C24FECAAA1E8E5BD161C41D9C893A60B358668933
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG @base",. "inherits": "fdm_filament_pet",. "from": "system",. "filament_id": "GFG99",. "instantiation": "false",. "cool_plate_temp": [. "0". ],. "cool_plate_temp_initial_layer": [. "0". ],. "eng_plate_temp": [. "70". ],. "eng_plate_temp_initial_layer": [. "70". ],. "fan_cooling_layer_time": [. "30". ],. "fan_max_speed": [. "90". ],. "fan_min_speed": [. "40". ],. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "12". ],. "hot_plate_temp": [. "70". ],. "hot_plate_temp_initial_layer": [. "70". ],. "nozzle_temperature_range_high": [. "270". ],. "overhang_fan_speed": [. "90". ],. "overhang_fan_threshold": [. "10%". ],. "slow_down_layer_time": [. "12". ],. "slow_down_min_speed": [. "20". ],. "textu
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):575
            Entropy (8bit):4.440251550447094
            Encrypted:false
            SSDEEP:12:DAU0UhJclpTIwPwwld6vzSCFiZjKkBR1BT1BcA:MJq+pTFPwQ8v+oiMQDsA
            MD5:882BBCBBDED1750E48A26FFD0E24ADD2
            SHA1:C2528EF284C8492538D047382F380140E6A7B26B
            SHA-256:4B95D6A3C4ABDC717B4FDE0BFF5DD86BBC8D37655D5311438B7F1B82A34987BA
            SHA-512:3AFE540E45F3B9722A3C565C314EBDFA605AEB03D98C7713A44495DF70D4B54E69A87BDA3B138EF6F87D01F82BC33CFB39832C379B8D3459851E8FD35E87ADF9
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG-CF @BBL A1",. "inherits": "Generic PETG-CF @base",. "from": "system",. "setting_id": "GFSG98_01",. "instantiation": "true",. "fan_cooling_layer_time": [. "30". ],. "fan_max_speed": [. "40". ],. "fan_min_speed": [. "5". ],. "filament_max_volumetric_speed": [. "11.5". ],. "overhang_fan_speed": [. "100". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):915
            Entropy (8bit):4.402726783454049
            Encrypted:false
            SSDEEP:24:OJqOpTFPwQ8v+oiMDXwHPSREXw9EXwbSTSHllXDlBdBPBAA:wxpTRaf+kV
            MD5:456B1C38A9FBD6B6586D1AABBD1E4F17
            SHA1:8F0BC7190364F59BDAAFBCB90E67B064B6CE2167
            SHA-256:697DA31A9BF45A0A98288B4100BE2E5178EC85424C66CAAE33D2EC507926D927
            SHA-512:22E70C913EBFB84A48506D7D8F5E363171EC41B59EA0546CF46E756BBB5A6493F6BFA3208F3E7BF68405AD91403BED4019D2D4CA7A3044ADE20151AA7D8D9623
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG-CF @BBL X1C",. "inherits": "Generic PETG-CF @base",. "from": "system",. "setting_id": "GFSG50",. "instantiation": "true",. "fan_cooling_layer_time": [. "30". ],. "fan_max_speed": [. "40". ],. "fan_min_speed": [. "5". ],. "filament_max_volumetric_speed": [. "11.5". ],. "overhang_fan_speed": [. "100". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1816
            Entropy (8bit):4.530289092927429
            Encrypted:false
            SSDEEP:24:hr5Rin9px5h2sq22PwLzuYNoviYoQUqex0WwxxoiOo0AujNmZcqmJvTcL3SfjcLX:J5Rin9pIai+I+Rw3uhH/SB/P
            MD5:B1097B0CBED77ABB965A5C6DA2445552
            SHA1:912CC9549C737039F2FBE7EA1E79511EAF255DAC
            SHA-256:D29E600EACAFAFE5ACE2E4CE3DD1D23D33B7F1C64641CE13753509CA6333B9D0
            SHA-512:6B051FECE47ED6001326125679DCB3C105C89031DDFD1123855C48C9BB41464B4620D10382C45C8767FE137B17AC441E1E1E96D274A52F60AD31588B9868203B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG-CF @base",. "inherits": "fdm_filament_pet",. "from": "system",. "filament_id": "GFG98",. "instantiation": "false",. "cool_plate_temp": [. "0". ],. "cool_plate_temp_initial_layer": [. "0". ],. "eng_plate_temp": [. "70". ],. "eng_plate_temp_initial_layer": [. "70". ],. "fan_max_speed": [. "30". ],. "fan_min_speed": [. "0". ],. "filament_cost": [. "34.99". ],. "filament_density": [. "1.25". ],. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "12". ],. "filament_type": [. "PETG-CF". ],. "filament_vendor": [. "Generic". ],. "hot_plate_temp": [. "70". ],. "hot_plate_temp_initial_layer": [. "70". ],. "nozzle_temperature_range_high": [. "270". ],. "nozzle_temperature_range_low": [. "240". ],. "over
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):653
            Entropy (8bit):4.340201201393617
            Encrypted:false
            SSDEEP:12:HrcU0UhJHlpTg+XwHP1sjl1+Xw91+XwLP1sT1sHl1rll1r91rxl1Pd1PP1PAA:4JqrpTnXwHPSREXw9EXwbSTSHllXDlB9
            MD5:2B5D7D5A011386AD71319FDE0CA62B03
            SHA1:990D7DF2D5CEC2E3A621C2DD36E3A458C02B7569
            SHA-256:BD00A0A084F9CBFA7287EB1715505847EDC4A5C816B82CAB2679F6A56EDEA9B7
            SHA-512:60A66E720FC24BBA4EDF26EBE332FEADD027FD5AF786CD9C1D3BBB6CA38235E41DA17ACB50A0E86BF5E27C37C82647377465A7C01DF80F54B73A7C78F9479E1E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG",. "inherits": "Generic PETG @base",. "from": "system",. "setting_id": "GFSG99",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1001
            Entropy (8bit):4.964678834489314
            Encrypted:false
            SSDEEP:24:lmJqxpTb3qDXwBS/LBKJnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:6cpTb31hr+EW+Yn1B/P
            MD5:E3580E40481F89390E07B6E17A2D39BC
            SHA1:08D6E53F6DD418D2A460308026E22E7095C6EFAA
            SHA-256:29E5A8E678A4A2C21591EF7FE94BC8BD0C9BDDF58393668F1BF6434281C28733
            SHA-512:EA69FCE4D33AC54B5B47DAF9D30AD9AD55490BB4F5EEA335BE3642ECDEC73663843283454722EF525F6CCD9A88B65FFF2E6251080BFAF16B8CC662B63960EC85
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA @0.2 nozzle",. "inherits": "Generic PLA @base",. "from": "system",. "setting_id": "GFSL99_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1.6". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ].
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1132
            Entropy (8bit):4.730298344145795
            Encrypted:false
            SSDEEP:24:vBmJqLopTSPwcpv3qUQscQ0bJnNE7L8ASfyLsSfvfTl/u1/COA:mUopT2D3QrCvB/P
            MD5:065349CD8D2D1FB57CD00F00262DE958
            SHA1:AC8C2C117247679D3CBE933EF2E56FD97EB4C099
            SHA-256:BE93A31E9E4535924A55233D2CBC6A345558C13DDD849D5C6F4E828455B69BA4
            SHA-512:2CF56B4E3E2FCA3D27F633E5BCD96E1391201DC65260C56C33C7A23DB4FFCD9C45378DB8694BEA3F1215D89F78A813F980E76446C54A3FBF7FD6B67635B89BAA
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA @BBL A1 0.2 nozzle",. "inherits": "Generic PLA @base",. "from": "system",. "setting_id": "GFSL99_05",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "1.6". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >35)||(bed_temperature_initial_layer[current_extruder] >35)}M106 P3 S255\n{elsif(bed_temperature[current_extruder] >30)||(bed_temperature_initial_layer[current_extruder] >30)}M106 P3 S180\n{endif}\n\n{if activate_air_filtrat
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):672
            Entropy (8bit):4.293178912312692
            Encrypted:false
            SSDEEP:12:wNU0UhJsUlpTSPwwxdPOdGFOXcGF0kBR1BT1BcA:CJqdpTSPwcpUQscQ0QDsA
            MD5:FBD681DC32C05655F24435E01C2579BC
            SHA1:EEB52528A191F0B70110FFAFE48E9A405DD3FE6B
            SHA-256:23C1AA2EBB152191EBC45B73FF997E0D91D8A2D4408F133E2DBB65560E014A6D
            SHA-512:7A03C36278756634B191505A44A7C16852D03CEF9C481E4E6EAB0C3812926146735DC409A200CEEBFC07C8092D6E6BF1EE137FC86BB0B516BF6CC588EE280F9C
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA @BBL A1",. "inherits": "Generic PLA @base",. "from": "system",. "setting_id": "GFSL99_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1138
            Entropy (8bit):4.730418285660464
            Encrypted:false
            SSDEEP:24:imJqGpTSPwcpv3qUPjcQ02JnNE7L8ASfyLsSfvfTl/u1/COA:lzpT2D3/rCvB/P
            MD5:EDE8A6AFEC9E785DD44E897AB74ADD04
            SHA1:E10C31FB562D90FD9C4EBD7DA044020C154BFABC
            SHA-256:D8782632BC820BA471F99F19680CABF1CF7BF1F38B91F242D8B6B55B88AE50B9
            SHA-512:B8D5DD324AE48663E8263FD158F389AED791C09D4F2FE03AB9E18CBB302CE6273924BC7AB33EF077606730DAFC0390E0DFDB4EBCC8C1BA67FADEEE9910B47081
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA @BBL A1M 0.2 nozzle",. "inherits": "Generic PLA @base",. "from": "system",. "setting_id": "GFSL99_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "1.6". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >35)||(bed_temperature_initial_layer[current_extruder] >35)}M106 P3 S255\n{elsif(bed_temperature[current_extruder] >30)||(bed_temperature_initial_layer[current_extruder] >30)}M106 P3 S180\n{endif}\n\n{if activate_air_f
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):688
            Entropy (8bit):4.302759972023449
            Encrypted:false
            SSDEEP:12:9NU0UhJDlpTSPwwxdPOdGOO4cGF0ko1i1RA:zJqvpTSPwcpUPjcQ0x4LA
            MD5:2DE01919198ACF93A2E6DD7FB0C62A2D
            SHA1:58624350B0E3C57A151D64B3FD304D375981541D
            SHA-256:24286E1C65A757BFC400CEC200AA66AF99C61B099B271BC399CC176417E627F1
            SHA-512:1D9790050D6D100B3D00ABD8B50CDDB897B3664C5E44FAD413FCB308F2689A180F373CD6DBFFEECD136218065CDDFE85F4517FAE4AE212BAF19AAF5CDD8515F3
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA @BBL A1M",. "inherits": "Generic PLA @base",. "from": "system",. "setting_id": "GFSL99_02",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):761
            Entropy (8bit):4.9098301818925485
            Encrypted:false
            SSDEEP:12:Amu58h0iSmlpGfXXZnNE7sWsSQLWzsW8ASQLWP2FcI1Wl/I2UV6soWCOA:Ar5TiSep6XJnNE7LsSfzL8ASf+6Tl/ui
            MD5:6B9987CE92D50D4CC7AEDE44BD9FB78B
            SHA1:EB25DA408FD7A92A2C0B6B0B6D520C72EE43EDD6
            SHA-256:4D3B78772F4D05B004B66DCC729E989CD52185655544BF3593BAE6666B15BD30
            SHA-512:972E099F188098833F8DA78B6CB74C0339ECA49877DFEBD5B979DF3DE3BD214302E5EC5CED6C6DEA1AA375BAD014830902BFB247F8BC717A27EDC6361AB41340
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFL99",. "instantiation": "false",. "filament_flow_ratio": [. "0.98". ],. "slow_down_layer_time": [. "8". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S255\n{elsif(bed_temperature[current_extruder] >35)||(bed_temperature_initial_layer[current_extruder] >35)}M106 P3 S180\n{endif};Prevent PLA from jamming\n\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):742
            Entropy (8bit):4.315207665871274
            Encrypted:false
            SSDEEP:12:uKW0gU0UhJrJ0lpTSPwwxdPvzPOdGFOXNcGF0kBcbA:uBlJqpJopTSPwcpvjUQsNcQ0bA
            MD5:7367833D21DF551665B381671D81BD73
            SHA1:41CCBD05FB3DF7E5037F6B61D635D3E96663C774
            SHA-256:A9485464F94142C12283E24236E419990C9BAD6F2267673C957D7EBB19F69720
            SHA-512:A5B36FEAB1743A44A9DEC070985E26907D2D14F27650E334764CC6E4AD96213AA1A630330CA68160C9DA90BFABA706A03BD47C22D7B033C8D0EF10F03FFFAE9F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA High Speed @BBL A1 0.2 nozzle",. "inherits": "Generic PLA High Speed @base",. "from": "system",. "setting_id": "GFSL95_05",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "2". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):743
            Entropy (8bit):4.325318698065636
            Encrypted:false
            SSDEEP:12:1gU0UhJNlpTSPwwxdPOdGFOXNcGF0kBR1BT1BcA:qJqRpTSPwcpUQsNcQ0QDsA
            MD5:E9D8F58088BD116DED3B19C5D1E7DCC8
            SHA1:16E373369879395A4767180DB3B560CF28CC2CD5
            SHA-256:2E790C607460495AA5115E9E6C724388270C2DA919FB3C4FA501A461119FB9CC
            SHA-512:863F7A4CA52981431B7B41E78E0266DA97EA36D85946E6D0F9386769CEC603F10C97F2E00302034F8A17D44906D3B207D86D5EC5D7692322C408D22CFC12479E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA High Speed @BBL A1",. "inherits": "Generic PLA High Speed @base",. "from": "system",. "setting_id": "GFSL95_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):350
            Entropy (8bit):4.6091862967889625
            Encrypted:false
            SSDEEP:6:fS584Y+W0FUG0H0htzB6lz9JvF/Df6zwPw/Kyr3f2CA:N+W0D0UhJclpTbzPkfbA
            MD5:4E980BD7FC05FAA8330CCCD51FC70CEF
            SHA1:0C2BF15EA2AC92F318904DBC5C82BCFF48E792D1
            SHA-256:76E511F7F9D89CD361ECCE6DE6D8FEFB49880808EC269BD6390BC241FF803BEB
            SHA-512:3B9FD396053C971069E8AE60133868FB6DFEED1651A6AE68F4FC92D15A138F8D23EFEF7D218B9DDC77E740A7290732938076EF0FD9A3635B48828A9EE745B59A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA High Speed @BBL A1M 0.2 nozzle",. "inherits": "Generic PLA High Speed @BBL A1M",. "from": "system",. "setting_id": "GFSL95_07",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):759
            Entropy (8bit):4.3292297282198895
            Encrypted:false
            SSDEEP:12:GgU0UhJwpUlpTSPwwxdPOdGOO4NcGF0ki1s1NA:7Jqq6pTSPwcpUPjNcQ0zmHA
            MD5:5FCEFF00C166EBB54CBFD059010F7862
            SHA1:C944CADFE6E35A8B482488546E1BD39E64335174
            SHA-256:A3A1E349168A63BC43330EC14DBC9E919AB8824E2191DE7496FDB82CA725814C
            SHA-512:D6D41240EC303BC5990E6D682CF7CF699B4B6104F5E99767C6860B1236FEE9CC5BD2D6C3308AFC395646E0973D5A012267E8950B00C190E4C30A4C19CB440267
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA High Speed @BBL A1M",. "inherits": "Generic PLA High Speed @base",. "from": "system",. "setting_id": "GFSL95_06",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "6". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle",. "Bambu Lab A1 mini 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):346
            Entropy (8bit):4.601161222974154
            Encrypted:false
            SSDEEP:6:fS584A1IW0FA1o0H0htzN6lz9JvF/Df6zwPw/Kyr3qg2CA:ZCW02C0UhJQlpTbzPkbbA
            MD5:6EED6C8003EBA5DB40692EBB111B9FAA
            SHA1:1B92D7EFD97E7270EF809F2530E423E04CE23474
            SHA-256:39C09FA514A74AB2FA14167BA8369003CE4C299B99779DF7D5FDBFCEB5007AC7
            SHA-512:71A83EE59AFFECEE1C9165D5CF16285271CFA9DEB374E8FBA6DA7F3B12706FF787F9CA63835ABB72C87984869FE60825A68DCED61BCFC09BF2AE6276E7F13CA0
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA High Speed @BBL P1P 0.2 nozzle",. "inherits": "Generic PLA High Speed @BBL P1P",. "from": "system",. "setting_id": "GFSL95_03",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "compatible_printers": [. "Bambu Lab P1P 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):655
            Entropy (8bit):4.377900792474333
            Encrypted:false
            SSDEEP:12:ZQgU0UhJ0BclpTSdvwOdGFOXcGF0ks1W1NA:zJqbpTSJwUQscQ0NwzA
            MD5:8AABD34F390DD32F96F9A94D2812A923
            SHA1:C0582D8AE622AD5DE0FA3C2C2257F19009DDDAE2
            SHA-256:DF86AE82538383F80F1592DE687A1F50B4F969D8797D12F582ACB93F15271316
            SHA-512:BBACF6FD5358B5D302DC0EA4AAEE4EB050AEC71267EA01854FACEC4FE0ACDA3EEB68ADD36F0E665844DD5EA69CC4B60DD01B20F3BCAD396B53FE486B4E6508AC
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA High Speed @BBL P1P",. "inherits": "Generic PLA High Speed @base",. "from": "system",. "setting_id": "GFSL95_02",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_min_speed": [. "50". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab P1P 0.4 nozzle",. "Bambu Lab P1P 0.6 nozzle",. "Bambu Lab P1P 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):459
            Entropy (8bit):4.584528368862106
            Encrypted:false
            SSDEEP:12:hyVgW0en0UhJ36lpTbzPk+XwKW1scW1rKW1PgbA:gjIqEpTbjDXwBS/LBKA
            MD5:3370933D669D1789B34FB9CB815F6935
            SHA1:34D8F839C62D62D0808A655725FB599919E78E95
            SHA-256:654B396E8E8A373DCBA71ADB25A79B1A02D6A4719A7D10D60075DC73DECDAC1B
            SHA-512:360C604CF985151A688C9B6B774E15FDE30779901D0BA39EF844810DD400480DFA6FA186D9EFCDFC99FE3787E9F1737FBFE13BD0DBBE5F40D1C85DEAEA8DDC16
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA High Speed @BBL X1C 0.2 nozzle",. "inherits": "Generic PLA High Speed @BBL X1C",. "from": "system",. "setting_id": "GFSL95_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "2". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):734
            Entropy (8bit):4.421570091306269
            Encrypted:false
            SSDEEP:12:hhgU0UhJMUlpTPk+XwHP1sjl1rll1Pd1+Xw91+XwLP1sHl1sT1r91rxl1PP1PAA:UJq+IpTPDXwHPSRlBdEXw9EXwbSHlSTB
            MD5:E9EE73CB8BCCE359805AD4ED69FE2C86
            SHA1:3FB0BA1DAF0E6DF0DE2FE0DFBCD9698DA7D4067E
            SHA-256:65E925ACC0CD55BB291C97BA445ADC8823AEB8292CBE596798B8BE5D2EB692E7
            SHA-512:5CF64168DCB632CD492EAE478160CF0B8BA362656C55D342848A4CFDDDB765EE0BFE5237A82F6ADF5B049305FB1955C3821CFA91746BA2E00CC30091DA6200BC
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA High Speed @BBL X1C",. "inherits": "Generic PLA High Speed @base",. "from": "system",. "setting_id": "GFSL95_00",. "instantiation": "true",. "slow_down_layer_time": [. "4". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):345
            Entropy (8bit):4.35013193590825
            Encrypted:false
            SSDEEP:6:fS584cdmu+o8h0yD6clz9sl9fbDf6zwrnwgJcA:bmu58h0i6clpGfvzrwXA
            MD5:CE559E8505E1A97A5A4605C91CEF5FD0
            SHA1:0776B1FC6B75F8A9AE5F692078F4A2F89FF89133
            SHA-256:EDD1C3BF34842F92F8F900DF14D9608A975CEBE81453ED0A00A57FF02CDA2677
            SHA-512:408F81059A0C37353D54082853B6BC6D7F67E53BE76ADED3C3A9314B32C25BA5804C600C61EFB18F6FE5957F940DF96A3E4A0FE79D1510BF989862B51A263CF7
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA High Speed @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFL95",. "instantiation": "false",. "filament_flow_ratio": [. "0.98". ],. "filament_max_volumetric_speed": [. "18". ],. "slow_down_layer_time": [. "8". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):585
            Entropy (8bit):4.3980276369798945
            Encrypted:false
            SSDEEP:12:yuRcU0UhJRlpTSPwwxdPvzrJ0lPrqkBR1BT1BcA:yAcJqppTSPwcpvJWqQDsA
            MD5:EEB52DC5FCB2C97BC0C5889667D2A063
            SHA1:C12085520CCEA328D96B51AEC7FF13B75D862B43
            SHA-256:11FAFD6C4A77AD9EB6EC6BF66DFB01976DA3B68CB30F0B2AA10A8FCBE56BAEB6
            SHA-512:474214019770758A67929DE5B581C88076BAF1F040D154F633607217B5282C6AF474CD34C3F56347B4A61A58BCE899DC84B26EC0727EA0DD4FB41DF2D143A3A2
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA Silk @BBL A1",. "inherits": "Generic PLA Silk @base",. "from": "system",. "setting_id": "GFSL96_01",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "7.5". ],. "filament_retraction_length": [. "0.5". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):815
            Entropy (8bit):4.321072150681669
            Encrypted:false
            SSDEEP:12:yPRcU0UhJxclpTSPwwxdPvzrJ0lPrqOdGOO4cGOrko1i1RA:yZcJqApTSPwcpvJWqUPjcPrx4LA
            MD5:A5C5C8FF583E6ACE2A7DF2BA29EFFC30
            SHA1:C13F31098BE94BAEB8943D98CDDF1EEB37FD6A31
            SHA-256:FF78A7F2DEF22AF1F3320C677BB66BCB43F01CF05D8DE2110361AD04E347EB53
            SHA-512:48D585500F65E1944103BC8B7047C27E5AAFBEF110DB5CDE3B6A9D1B5BF580AAFCC2D9D9C217CF1EF87C3D2EFB2A1EDA531E7A797BB62ADA84DF802AE29B6188
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA Silk @BBL A1M",. "inherits": "Generic PLA Silk @base",. "from": "system",. "setting_id": "GFSL96_00",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "7.5". ],. "filament_retraction_length": [. "0.5". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "textured_plate_temp": [. "60". ],. "textured_plate_temp_initial_layer": [. "60". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):764
            Entropy (8bit):4.916632217769154
            Encrypted:false
            SSDEEP:12:Ycmu58h0iB6lpGfXXZnNE7sWsSQLWzsW8ASQLWP2bcI1Wl/I2UV6soWCOA:Ycr5TiBap6XJnNE7LsSfzL8ASf+ITl/P
            MD5:F93A91A9F1DA836499A5C28769C94047
            SHA1:DE37AF9D77A4A2217E4D5DC1238F88910C264E8D
            SHA-256:E592066ECEECA244C9A56D69A4F8CA609E5A043652E0EECF3B6769C873BA70AC
            SHA-512:EEEFD6C1FE386DF59D280CA7AB0DE6E551F496ABFA93A23A8E8DD1CA1F62DDCE386793530BE71BDA359238D483927DFDC3C621D35E87B8870078AC71527EEC28
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA Silk @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFL96",. "instantiation": "false",. "filament_flow_ratio": [. "0.98". ],. "slow_down_layer_time": [. "8". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S255\n{elsif(bed_temperature[current_extruder] >35)||(bed_temperature_initial_layer[current_extruder] >35)}M106 P3 S180\n{endif};Prevent PLA from jamming\n\n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):781
            Entropy (8bit):4.417742744782821
            Encrypted:false
            SSDEEP:24:TcJqopTbJWqDXwHPSREXw9EXwbSTSHllXDlBdBPBAA:KVpTb8kV
            MD5:6FC468C2E70AA37EEE3346B64F951942
            SHA1:1C28057311FA5CDF83A623F58B6393A63A6C3A6A
            SHA-256:4839232E35084D005AAEB156CC8328F7E80356A708D6CDFEC48055D67C9301CD
            SHA-512:112A7333FAE3D8D074249FA1382E64B2E71E4A15B73F60886403957B6C5828B4CDCF1BAB9481A8F28D37764CE57C8889B078654AD0DFDC5A15DF4F3C2CA73240
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA Silk",. "inherits": "Generic PLA Silk @base",. "from": "system",. "setting_id": "GFSL99_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "7.5". ],. "filament_retraction_length": [. "0.5". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):727
            Entropy (8bit):4.323778317246417
            Encrypted:false
            SSDEEP:12:ojU0UhJ26lpTSPwwxdPOdGFOXXcGF0kBR1BT1BcA:uJq0apTSPwcpUQsXcQ0QDsA
            MD5:A04366CD36BDE25FA86B7CFC9D69BFAB
            SHA1:2822373A87B3D7F2920C679D56586F9CBB2A1576
            SHA-256:D826D3955FB811CD168261C3AEAB8DC9E39A461F15B55557B3351A2055CC2B2E
            SHA-512:40BB64C1DC2054821C78A41485DCA8132DB69E10BFC64C5A9D2BD9AE43F9A79E822B9050FA059100AC64E9769EDE93CBAEECB68F0ACA1163FB9D38E6B3164C4C
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA-CF @BBL A1",. "inherits": "Generic PLA-CF @base",. "from": "system",. "setting_id": "GFSL98_01",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):743
            Entropy (8bit):4.328700925748883
            Encrypted:false
            SSDEEP:12:1jU0UhJDclpTSPwwxdPOdGOO4XcGF0ko1i1RA:tJqNwpTSPwcpUPjXcQ0x4LA
            MD5:1FD985913C25B859042907210A57B31E
            SHA1:42A701C4FE8F98980338AD8529658E9DE5B2536A
            SHA-256:91A71C288B559CDD0B37B1A32F03AE4CB01B048E268D304DCC4B9EB413095944
            SHA-512:FE9C987878C54A24AD0630D694010E9ED3DF30BC8265BE5DF74E8B3D8818D92DED0899CC2334AACA7ECC953EB358AF280EBE7B453E9C3338BF0A06AA24592C7D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA-CF @BBL A1M",. "inherits": "Generic PLA-CF @base",. "from": "system",. "setting_id": "GFSL98_00",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1108
            Entropy (8bit):4.841724719459114
            Encrypted:false
            SSDEEP:24:or5TiypNXouGNomQAujtQJnNE7LGMSfG1LGbSfGwLsSfv1fTl/u1/COA:+5TiypC/upmhr+EW+Yn1B/P
            MD5:7D6E7137FB0656E83AAD7DDA9803D1E5
            SHA1:F3DED02B0FBF88A47E60F7EC58ED92B7CAB289B7
            SHA-256:CEFF2FCAD7C7AE3F6C1B47E170DD1F9F3108D4CC82BD7F839DB0819C36E1E6FB
            SHA-512:46C24E790D9D7EE432CCE2E1426F24A4AE2935156F03684D28478A46EE57BE5023099A38E59E941EF153817A13861A23EA6DC15A5A7E5B4F2518BED788FD8D50
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA-CF @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFL98",. "instantiation": "false",. "additional_cooling_fan_speed": [. "0". ],. "cool_plate_temp": [. "45". ],. "cool_plate_temp_initial_layer": [. "45". ],. "filament_flow_ratio": [. "0.95". ],. "filament_type": [. "PLA-CF". ],. "required_nozzle_HRC": [. "40". ],. "slow_down_layer_time": [. "7". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_temperature_initial_layer[current_extruder] >45)}M106 P3 S50\n{endif}\n\n{if activate_air_filtration[current_extruder] &&
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):657
            Entropy (8bit):4.359437002575452
            Encrypted:false
            SSDEEP:12:b6jU0UhJimlpTg+XwHP1+Xw91+XwLP1sjl1sT1sHl1rll1r91rxl1Pd1PP1PAA:bUJq9pTnXwHPEXw9EXwbSRSTSHllXDlj
            MD5:F24A1C0CD42ECE51197DD57ECFDCFED5
            SHA1:56C3862E4B78E89D48623E1CE59AE9177E1905A2
            SHA-256:4FDA35A0BD257B37CBEC80E32D23B3E72FE419EC4A0025387A97F22232AC672A
            SHA-512:422D287FD8A658E72D7A7F498AFADBACA006CCD96BB1D0560648AD8E941D546139B0B7CB39D84981ECA060521B8952FD75D0049884FB1402FE5B5E26E34CFC10
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA-CF",. "inherits": "Generic PLA-CF @base",. "from": "system",. "setting_id": "GFSL98",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1224
            Entropy (8bit):4.9148071461596485
            Encrypted:false
            SSDEEP:24:oJqpepTnXwHPSREXw9EXwbSTSHllXDlBdBPBAJnNE7LGMSfG1LGbSfGwLsSfv1fp:SqepTOk4hr+EW+Yn1B/P
            MD5:0C30E557987CCEBB67C082CBED0FD6AB
            SHA1:5F96A95DA0379EED490215088793112D418311F2
            SHA-256:C8C71A010B8E24FC99467849E31844DB7D7BF5544969C865C22EAAE73E47120C
            SHA-512:EA54BB07F21DD0702FB2C625E77AE7E3C015810257221F122D018AEA471089636FF15F15FD0389F93752F53D94E23B6CA5024964C0EB860035BF19EC1ADAAB53
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA",. "inherits": "Generic PLA @base",. "from": "system",. "setting_id": "GFSL99",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >55)||(bed_temperature_initial_layer[current_extruder] >55)}M106 P3 S200\n{elsif(bed_temperature[current_extruder] >50)||(bed_temperature_initial_layer[current_extruder] >50)}M106 P3 S150\n{elsif(bed_temperature[current_extruder] >45)||(bed_tempe
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):716
            Entropy (8bit):4.389342045665239
            Encrypted:false
            SSDEEP:12:olhvXU0UhJNlpTKqk+XwHP1sjl1sHl1sT1+Xw91+XwLP1W1s1o1rll1r91rx8A:oXXJqJpTNDXwHPSRSHlSTEXw9EXwbwqQ
            MD5:6FB853AA160D5901C658C3719704C672
            SHA1:6C23C0A4652AD43AEA53E6D1F25E7257895EC0C9
            SHA-256:EE8F7AD9A92E5757E58CC8E67A7E098A74600F779CE899A3092D897D83CEFCB5
            SHA-512:BA92672352018D349BDEDD37FA790E87E424168995EE0975FE353FBE7C7907E11FDC1AE0AA962122C7A0791A4EBD5128C2F53884969BC0C333D27BADD6DED25B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPA-CF @BBL X1C",. "inherits": "Generic PPA-CF @base",. "from": "system",. "setting_id": "GFSN97_00",. "instantiation": "true",. "filament_type": [. "PPA-CF". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1P 0.6 nozzle",. "Bambu Lab P1P 0.4 nozzle",. "Bambu Lab P1P 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):427
            Entropy (8bit):4.520337939441485
            Encrypted:false
            SSDEEP:12:olChFmvXU0UhJr6lpTomrmqkPd1PP1PAA:oyFoXJqRapT1r5ydBPBAA
            MD5:ED7F77A4DEFFB7055D0D3B461010CF67
            SHA1:EDBD1D59FB81D0A9AAFB86977B05B0A6A9C5E48E
            SHA-256:A023668AFB23BCE33C47FCF9C4856D96190AD024472E7F70E0E741AFCAD0C43E
            SHA-512:D54FC20D1F7AC6D650B7ABCC656BB21B0343A2A0C61E9448D44E0D5B89253D31AD18A50200AA7085BC5E325547E01E573D26A9A707926A4D8E3FA38F2C06FBCB
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPA-CF @BBL X1E",. "inherits": "Generic PPA-CF @base",. "from": "system",. "setting_id": "GFSN97_01",. "instantiation": "true",. "chamber_temperatures": [. "60". ],. "filament_type": [. "PPA-CF". ],. "compatible_printers": [. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):333
            Entropy (8bit):4.282748707009971
            Encrypted:false
            SSDEEP:6:fS584p9dmu+oguJG0yDm/0lz9slDf6zwzbiFwbKeivdqA:oXmu5g4G0im/0lpCzzmqoQA
            MD5:2571B064C0B05F1C66BD040442786EB8
            SHA1:CCACCF4EAE53F04EA423F9A85E7F4B447398391F
            SHA-256:0589B9D9739C7B8B2BA64FC6207B4D03E76F1A331B833C88DB3E483B3756F768
            SHA-512:91B3DA56478D10E3CA6ADDC86DBA31535B1C2C089B99D6285EB4D8376A23319799F99615290A9B6933F80A9B7DE34E4031BDE75665ADCDE6A570C63D6266541B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPA-CF @base",. "inherits": "fdm_filament_ppa",. "from": "system",. "filament_id": "GFN97",. "instantiation": "false",. "filament_max_volumetric_speed": [. "6". ],. "filament_type": [. "PPA-CF". ],. "filament_vendor": [. "Generic". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):669
            Entropy (8bit):4.379510909241472
            Encrypted:false
            SSDEEP:12:oZhvzU0UhJfrclpTg+XwHP1sjl1sHl1sT1+Xw91+XwLP1s1W1o1r91rll1rx8A:oLzJqZMpTnXwHPSRSHlSTEXw9EXwbqwk
            MD5:962E177B95CF071DBA58CDCC52DD5190
            SHA1:355AE9B170113A184935F845880AA6BF80D285B8
            SHA-256:7BCE1664A8198ED1B27728BD12C4B0693F3C53C92C67799843CCFC236010D30B
            SHA-512:1B9D4B0B029E1A6FB7348D7DE47A8305586A2B51D54E1ABEA3886EF42A7B8D3CF56D54D7CC5BD144A7F3C106301035BE229BB018FCED6FE7DC6928F686C79B2B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPA-GF @BBL X1C",. "inherits": "Generic PPA-GF @base",. "from": "system",. "setting_id": "GFSN96_00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1P 0.4 nozzle",. "Bambu Lab P1P 0.6 nozzle",. "Bambu Lab P1P 0.8 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):380
            Entropy (8bit):4.534799445162181
            Encrypted:false
            SSDEEP:6:fS584pg4ChFmFpgMdU0H0htzu6VUalz9JvFsNEmAeQXAgw/Kyr3Peh053PiW53Pf:oZChFmvzU0UhJfHlpTomrkPP1PZ1P0A
            MD5:A915A8B56CAB5949CC54FBC680C1ADD5
            SHA1:B9029E6A93A97BD519F0CF8C6165ACA45C2504A0
            SHA-256:8AC9EB198F3C47DF384D8EA2ABB86049DA045511D46202818F0B7B5C1CB87ADE
            SHA-512:6D6A1B795E4862B7BF0F213A531366A234ADEEC0AEC7CF27452674B1F24C43E2D9D0C9A97F23B8073C551F5DE7036D3A4D0ACC55849AE79BC113809B6380FEE6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPA-GF @BBL X1E",. "inherits": "Generic PPA-GF @base",. "from": "system",. "setting_id": "GFSN96_01",. "instantiation": "true",. "chamber_temperatures": [. "60". ],. "compatible_printers": [. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):333
            Entropy (8bit):4.26216386324939
            Encrypted:false
            SSDEEP:6:fS584pgMdmu+oguJG0yDfpUlz9slDf6zwzbiZdqbKeivdqA:ozmu5g4G0iRUlpCzzmZQoQA
            MD5:BD4DB446A31CBE119BFEE63057E3062A
            SHA1:1ECC90902B2F6CFDEE3364F4AFD2EF6E170B8DCD
            SHA-256:79D3C4834C65139213BF8F88DBDF5DD2766F8AF2B63F74F1A26363E14CB16632
            SHA-512:9CBAE6B99657F281AE1DFA0A265A10F53B76A7F56929B7060177E3CE6C4D466FFA7A6B939450754AA4EE4DF9CFDCE265B26215862333A6D03A27AF1F3276F4EB
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPA-GF @base",. "inherits": "fdm_filament_ppa",. "from": "system",. "filament_id": "GFN96",. "instantiation": "false",. "filament_max_volumetric_speed": [. "6". ],. "filament_type": [. "PPA-GF". ],. "filament_vendor": [. "Generic". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):324
            Entropy (8bit):4.528870737233856
            Encrypted:false
            SSDEEP:6:fS584PChFmFZJdU0H0htz4clz9JvFs/Kyr3Peh053PiW53P6kCA:wChFmrTU0UhJXlpTgPP1PZ1P0A
            MD5:63731272AFB8B34BACBDFAA0954752BD
            SHA1:8F740560B922C8A25CAEE2A063808A2270C5749C
            SHA-256:6F4A8BC330AAFB3EE381084B397F34F4D0F710E092E2D8C426E37857A66D5779
            SHA-512:AF8F1904D8A6E80B5515B9CB046CD58933F4BE3E78B2ACF3F437925F1D2BBF35E084DC3C1F972E0A4C6766BE460DF352F0BAF9A6E459C440998AF09E26C5A502
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPS @BBL X1E",. "inherits": "Generic PPS @base",. "from": "system",. "setting_id": "GFST97_00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):175
            Entropy (8bit):4.272816339546934
            Encrypted:false
            SSDEEP:3:Cc8fh5R/HLhifF6+FlkJdNHMxEHD+6DIHAJ/HDa0qHD5D0jBFF/HM1YKz9R:fS584ZJdmu+ogAJG0yDMFF0lz9R
            MD5:C84DC2875317818BDD60DCDEF16412D2
            SHA1:CD8C08CA44BDA42BB3D6725191AEAB8D8D31F802
            SHA-256:21B94CA0C513E023A610B4EDA54F9C642CA1FDCDACD9C9BF935BA868123C8086
            SHA-512:3E08DDCAE686F7575D28CB41D00A7C7FAD9B8465D24AE444F0B5F1750D77F531DF08702D34459926049AE55E2610D8A0445C40906C974B7057C16F0D0F57ABA1
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPS @base",. "inherits": "fdm_filament_pps",. "from": "system",. "filament_id": "GFT97",. "instantiation": "false".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):330
            Entropy (8bit):4.592042912509414
            Encrypted:false
            SSDEEP:6:fS5843lChFmF39dU0H0htzW+rclz9JvFs/Kyr3PiW53P6053PehkCA:MChFmxU0UhJW+rclpTgPZ1Pd1PGA
            MD5:561C04559AD8BCE52CF069A7497D80D0
            SHA1:952A590A17777829ED5DB27173FA320D15F1966F
            SHA-256:39C19E82E0EFF59596E123472AEA46B279551168A4D806C985487642C6372749
            SHA-512:553827516929DF138400A546D7E75A3E716B15882011BF580F2B402AC537FD061BB72772A3E874C51E299718CC9A8BFBCC2DB6D7C8F47B4C9ADBB98611691F37
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPS-CF @BBL X1E",. "inherits": "Generic PPS-CF @base",. "from": "system",. "setting_id": "GFST98_00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1E 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):538
            Entropy (8bit):4.322010495411999
            Encrypted:false
            SSDEEP:12:mmu5gAI0iHalp+wwJw9nCvzblCmsx0NoA6F+0mgA:mr5gkiH6p+wLNCv1C3x06AujmgA
            MD5:3FC0963AAB808F21B0F37654C606741F
            SHA1:8B4BF4B0449B96708E5593C397C13493E0650E3E
            SHA-256:F9219EFE113BC70640DE04B5F20841966D24295844BF7AB74A3E1DFDF1E84B11
            SHA-512:810738D94129EDCCD3E3C58EFAE2A6D7F1EC057F3D47ACC1CA5A6FF1161BE95AF87239CBCFA30DC70F68F1A1241379B89F68A5F47C674E2EBE81A76F1C7EB773
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPS-CF @base",. "inherits": "fdm_filament_pps",. "from": "system",. "filament_id": "GFT98",. "instantiation": "false",. "fan_max_speed": [. "30". ],. "filament_density": [. "1.3". ],. "filament_max_volumetric_speed": [. "3". ],. "filament_type": [. "PPS-CF". ],. "nozzle_temperature_range_high": [. "350". ],. "required_nozzle_HRC": [. "40". ],. "temperature_vitrification": [. "220". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):428
            Entropy (8bit):4.520215567960756
            Encrypted:false
            SSDEEP:12:b0yEU0UhJXylpTbz1qk+XwKW1scW1rKW1PgbA:b/EJqRypTbxqDXwBS/LBKA
            MD5:A1454B9F9FFE6EF50D11888E8D965B31
            SHA1:3D33E4EEE932D3048442D210D36EA6E18EDB57F5
            SHA-256:9A0752B68A068C4C10BC0DE2BCA23416652D8FFC25E16917E0B1D4BD13099D5C
            SHA-512:D4399D14B38DC0159B8AE7F2673CBD4E9F6C73584EB4C1EC0A248F52AC58A3969C0DF2DCF3B13FDE1343F3DA095A9DC2342F635DD16AE3E34EAABE456A8EF723
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PVA @0.2 nozzle",. "inherits": "Generic PVA @base",. "from": "system",. "setting_id": "GFSS99_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "0.5". ],. "compatible_printers": [. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):722
            Entropy (8bit):4.297649996486657
            Encrypted:false
            SSDEEP:12:NTKW0yEU0UhJXVUlpTSPwwxdPvz1qOdGFOXXcGF0kBcbA:NTB/EJqR2pTSPwcpvxqUQsXcQ0bA
            MD5:B3873BA3D3A539EDF40DA977DF971F97
            SHA1:C719E257E265B9521179C9B8B31A80266890D1FE
            SHA-256:00AE3F3275E90728C116CAFF499E3DBF52F09CF35733537325CC4DED2CB69064
            SHA-512:9837874A621CDBD14642849CFC3151E8F23C2B370B907C9A529C85A01C376AF85A441AAFD64C49D4958A01A9AB98F6F59FC2858841CC2EBDA289FDAF30CF58CD
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PVA @BBL A1 0.2 nozzle",. "inherits": "Generic PVA @base",. "from": "system",. "setting_id": "GFSS99_04",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "0.5". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):721
            Entropy (8bit):4.298692467055024
            Encrypted:false
            SSDEEP:12:NsyEU0UhJXvlpTSPwwxdPOdGFOXXcGF0kBR1BT1BcA:NnEJqRNpTSPwcpUQsXcQ0QDsA
            MD5:FE183F0622238DB672492632C81C5CDF
            SHA1:29A63D3E2013198386BBA24CA7C673B87C3D95CD
            SHA-256:C47407310CB34E8D21705FF90190E413714999F4755E175203043A7BBB400671
            SHA-512:AEAB11410E08CB2984CDB83F1A03446ECF4882627A385D0589AD4950F1ADA8DC4EA823E56D281BC9F33042E67BF88E8CA464078D34EC0F9758EDA90B5750010F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PVA @BBL A1",. "inherits": "Generic PVA @base",. "from": "system",. "setting_id": "GFSS99_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):728
            Entropy (8bit):4.303620091967582
            Encrypted:false
            SSDEEP:12:NK+W0yEU0UhJX4lpTSPwwxdPvz1qOdGFOXXcGF0kfbA:Nu/EJqRUpTSPwcpvxqUQsXcQ02A
            MD5:473D76F4D506933C3BBDFB38767F496E
            SHA1:466EBC9290FB4FB917CEAA46142ECA721D11FDF5
            SHA-256:1278A0930E53FE3BFFC97096AEE15CEC95225D27FD5F9804E1CC5F9481003BE7
            SHA-512:AD5654A04145512D9F54231E7E6D768A58FA195B23B821A4E48895E86D503723DDBFA4C7EB3768BB4C4188E2F1130BC89FBF7EF39DDB0797F9FA4D521E36045F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PVA @BBL A1M 0.2 nozzle",. "inherits": "Generic PVA @base",. "from": "system",. "setting_id": "GFSS99_02",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "0.5". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):737
            Entropy (8bit):4.304415903643617
            Encrypted:false
            SSDEEP:12:N5yEU0UhJX5lpTSPwwxdPOdGFOXXcGF0ki1s1NA:N4EJqRrpTSPwcpUQsXcQ0zmHA
            MD5:09C639BD0D51E826B64A9FB24F159370
            SHA1:ED378D3862E147156284EF5D64DD068ACA141252
            SHA-256:93FF8177763709C7AA3BA2A60809F83C740935CD3E75CCA59CD025A289261BF8
            SHA-512:E965A14375EB113FF96FEEAA3907FB6107B2FE286D1BAC3E91146F6B0E333CCE5279AEE39849822594A2B373797EB861C12E99DA9524DF278A7716307968AF44
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PVA @BBL A1M",. "inherits": "Generic PVA @base",. "from": "system",. "setting_id": "GFSS99_01",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle",. "Bambu Lab A1 mini 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):383
            Entropy (8bit):4.2889061442583225
            Encrypted:false
            SSDEEP:6:fS5848idmu+omGvu0yDzcudmlz9sl93FqbDf6zwlwgJmdqgJJDA:tEmu5dm0izIlpG3ovzatQMDA
            MD5:1B171B8248770C30793B350666077C69
            SHA1:535DE38ACB9578056947BB3439B549FB557C92FD
            SHA-256:CDC6DEC07BD854FC0AA33676170F2572EEE58660BE156B0A3276425A224D7D06
            SHA-512:64A5D64016D46AB7E5800EFDB2DE4BB1C15EAA3F83A838A393FC572993491B67B81DE93E24FD0CF3BF08D2BC883694CD3B223796C087C88028876EBF29A4E472
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PVA @base",. "inherits": "fdm_filament_pva",. "from": "system",. "filament_id": "GFS99",. "instantiation": "false",. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "16". ],. "slow_down_layer_time": [. "7". ],. "slow_down_min_speed": [. "20". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):651
            Entropy (8bit):4.338814960447064
            Encrypted:false
            SSDEEP:12:IyEU0UhJLlpTg+XwHP1sjl1+Xw91+XwLP1sT1sHl1rll1r91rxl1Pd1PP1PAA:bEJqfpTnXwHPSREXw9EXwbSTSHllXDlj
            MD5:2023E7DDB912FDBE8436842BEDED2CBC
            SHA1:C52D90BC87F237578153A2270882739C7526B879
            SHA-256:2136F70A06F1ACB5E52164F75A138493D2D630F104B7AB494FA01D84B123E56C
            SHA-512:81EC8416C81E1075009038023590DEF7545EEAF7433CCB435CAE98EA090B777ED681DEB8A270BE3EE118CBF5F49DAAEE78A2417CFE016FFD2CB82F92FE026513
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PVA",. "inherits": "Generic PVA @base",. "from": "system",. "setting_id": "GFSS99",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):986
            Entropy (8bit):4.825403569709317
            Encrypted:false
            SSDEEP:24:rqjpTouKcuSQDsJvTcL8ASfvcLsSfv3Tl/u1/COA:rKpTvYHB/P
            MD5:600EEFEC20E76F5A45AE6411647B0D87
            SHA1:A72F224CA8EF1E8D4B88331246A71A1AA2CB89DA
            SHA-256:18FDDFA1A3658DDE7E6D04190CE1832E3A59EC5E372B3CF49C42BDF32605794D
            SHA-512:5CE1F3CAB57E8434DDE1A897BBD78DC442441D78BB3FE6D752500D9A983FC8858A4CD8EC7082A48C6CFCFC0AE5E28A6EFD0E375C642D6E0E1C2873C3A3905342
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic TPU @BBL A1",. "inherits": "Generic TPU",. "from": "system",. "setting_id": "GFSU99_01",. "instantiation": "true",. "hot_plate_temp": [. "45". ],. "hot_plate_temp_initial_layer": [. "45". ],. "textured_plate_temp": [. "45". ],. "textured_plate_temp_initial_layer": [. "45". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >35)||(bed_temperature_initial_layer[current_extruder] >35)}M106 P3 S255\n{elsif (bed_temperature[current_extruder] >30)||(bed_temperature_initial_layer[current_extruder] >30)}M106 P3 S180\n{endif} \n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1002
            Entropy (8bit):4.809848130894995
            Encrypted:false
            SSDEEP:24:eqqpTo+Kc+Sx4LJvTcL8ASfvcLsSfv3Tl/u1/COA:eDpTsYHB/P
            MD5:8D47CBB5C96CCE52F6617190451D4BC0
            SHA1:6D2592C6926FC4D16276B135EB284FBAD228E3A3
            SHA-256:555C11D89F8CBEA37E7CDC08FAD437B493779551B068FEC4BD05E4EA8B351438
            SHA-512:F3E6483E5C69985110BBC795FCF5BD220D4351FD4506F355850AA7E1F691982AC84BB94F28DD4537AB9BCBA9B258CAB612CA8E7D76A8407045351FDF5D9D8253
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic TPU @BBL A1M",. "inherits": "Generic TPU",. "from": "system",. "setting_id": "GFSU99_00",. "instantiation": "true",. "hot_plate_temp": [. "30". ],. "hot_plate_temp_initial_layer": [. "30". ],. "textured_plate_temp": [. "30". ],. "textured_plate_temp_initial_layer": [. "30". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >35)||(bed_temperature_initial_layer[current_extruder] >35)}M106 P3 S255\n{elsif (bed_temperature[current_extruder] >30)||(bed_temperature_initial_layer[current_extruder] >30)}M106 P3 S180\n{endif} \n{if activate_air_filtration[current_extruder] && support_air_filtration}\nM106 P3 S{during_print_exhaust_fan_speed_num[current_extruder]} \n{endif}". ]
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1198
            Entropy (8bit):4.868999352938792
            Encrypted:false
            SSDEEP:24:P5fiW4SpTb7gRRSTSHlEXwHPEXw9EXwblXDlBdBPBAJvTcL8ASfvcLsSfvVTl/ui:P5ficpTb7cfkYFB/P
            MD5:C73F3FDBF78442DF9818970F69198F74
            SHA1:3FE3B686EDB13D38C38F9FC7499F88702A75F4AA
            SHA-256:E8CD684CDA80B0FD018CACF608C46DB7E402C09FD792227FB5AD89012327CE7E
            SHA-512:E113220D4CBC150D8C88DA0F1EFF6EA1549F65DCD4985A4FEFBE96A8686E6BACBE8D70498471126595259A12BB294C929859FC22B2F42A18942883739932EC09
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic TPU",. "inherits": "fdm_filament_tpu",. "from": "system",. "filament_id": "GFU99",. "setting_id": "GFSR99",. "instantiation": "true",. "filament_max_volumetric_speed": [. "3.2". ],. "compatible_printers": [. "Bambu Lab X1 0.4 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ],. "filament_start_gcode": [. "; filament start gcode\n{if (bed_temperature[current_extruder] >35)||(bed_temperature_initial_layer[current_extruder] >35)}M106 P3 S255\n{elsif (bed_temperature[current_extruder] >30)||(bed_temperature_initial_layer[current
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):736
            Entropy (8bit):4.302882274825823
            Encrypted:false
            SSDEEP:12:FKW0NU0UhJWlpTSPwwxdPvzPQOdGFOXXcGF0kBcbA:FBMJqwpTSPwcpv0UQsXcQ0bA
            MD5:A02248BE98E007B1C1358AC2406D4483
            SHA1:6DA8C6BAE3CEB3CBE8455B836DD85A07A2426907
            SHA-256:4555EBA79997A68915097C4E66C6E61BB1CCADE58BA571589F088BC8312BB05D
            SHA-512:BF459C5A344A47157DABB125E26D0F693B3994BB759533EBD7637E922AAF49FB7109337B6FEC22F83767198A3BDB7DE31196856E8923A9A353A3973A3D5732BA
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @BBL A1 0.2 nozzle",. "inherits": "Overture Matte PLA @base",. "from": "system",. "setting_id": "GFSL05_08",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "1.8". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):735
            Entropy (8bit):4.305817216316397
            Encrypted:false
            SSDEEP:12:aNU0UhJOUlpTSPwwxdPOdGFOXXcGF0kBR1BT1BcA:OJqEIpTSPwcpUQsXcQ0QDsA
            MD5:01CAE3D3BAFA2A0530B8F32BD39995A2
            SHA1:364692F7F7C7FE9EA70F5722E0CFFD4F41507F20
            SHA-256:3A03CDA0213D13303595A50E6699163C3DE6B79FB1868077790D9C4BF7FAFE3C
            SHA-512:A6514B4E14BB4A7D6BA8C23987DE06CB05554A1C9093885F44606327EB8121DE998CD50DDAEE7B1DEDDE0268CDCA96424D2354573933B1EB5743AC64F6B31029
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @BBL A1",. "inherits": "Overture Matte PLA @base",. "from": "system",. "setting_id": "GFSL05_07",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):340
            Entropy (8bit):4.593211910704286
            Encrypted:false
            SSDEEP:6:fS58P7S+W0s7OG0H0htz4lz9JvF/Df6zw9FQw/Kyr3qg2CA:g+W0O0UhJ4lpTbzPQkbbA
            MD5:3C06999FC2F5FA98D259504B3148738B
            SHA1:65104092C89277FB5FE57F98B197F40264759526
            SHA-256:D69FA1314C4964BB068BB8970700D2155689C818E217E7837F59E1C3A5DA1878
            SHA-512:F064C3BDDDF1C7D37A0CDFAE741ADB08EAF5E426B431D04B154286D5B6ED35F02DF2127FCD90D424DAE2261AA9C86527EC0D27AFBAE53085DD1DD2C8DA0DC747
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @BBL A1M 0.2 nozzle",. "inherits": "Overture Matte PLA @BBL A1M",. "from": "system",. "setting_id": "GFSL05_06",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1.8". ],. "compatible_printers": [. "Bambu Lab P1P 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):751
            Entropy (8bit):4.306986212841748
            Encrypted:false
            SSDEEP:12:7NU0UhJ20lpTSPwwxdPOdGOO4XcGF0ko1s1XA:5JqAopTSPwcpUPjXcQ0xm9A
            MD5:BE6D5EE717166887CEEF6D215173FFC3
            SHA1:2A864822B5E62A5DF21CE50CEBE143A99D0B44FA
            SHA-256:BFEAE5D77684E7D797104C33FF8FB6475A5B292C4183AF76A7335E43550884A8
            SHA-512:D4BF4DEF2CA06F9973EF766B3D06C11732C474FB885040C54774E432046F00A024ED61C84768C6491C9EAF0148131867C8CC04A9D3845F9DC1EF2CCE53A9BACB
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @BBL A1M",. "inherits": "Overture Matte PLA @base",. "from": "system",. "setting_id": "GFSL05_05",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.8 nozzle",. "Bambu Lab A1 mini 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):340
            Entropy (8bit):4.581447204821933
            Encrypted:false
            SSDEEP:6:fS58P7q1IW0s7q1o0H0htzylz9JvF/Df6zw9FQw/Kyr3qg2CA:ICW0TC0UhJylpTbzPQkbbA
            MD5:5ABAE25DA88FA0957F638949D023042A
            SHA1:B3A95EC02EC501D2DF10460FB8BC42D336F9FB41
            SHA-256:12D4D95B5C6664360208151E71845A48A8105E600E0EE697FF45066958A33586
            SHA-512:E52ADCC82898F944BAE8219F6D54F151354946188ABED60716D5EB73888CC1937AC4FC13D4389F60FEDB1FD6F72C61ECCCFC55E6ABD2E8A8CCE0A990DF3920A1
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @BBL P1P 0.2 nozzle",. "inherits": "Overture Matte PLA @BBL P1P",. "from": "system",. "setting_id": "GFSL05_04",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1.8". ],. "compatible_printers": [. "Bambu Lab P1P 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):697
            Entropy (8bit):4.344218354999542
            Encrypted:false
            SSDEEP:12:IQNU0UhJrlpTSdvwOdGFOXZwcGF0ks1W1NA:ZJqfpTSJwUQsOcQ0NwzA
            MD5:BE8C1136343496C1DA0170193FE90651
            SHA1:B35E9C364F61A91ACDEAFE8BD3D7053C61F4C2AD
            SHA-256:7D0F71D88B30240D048AF9A2ACB14BA1516E4453A03312FBBDDA4A0AB6B7D144
            SHA-512:D9EE468E04090E6705BADF809D24742A75215BA85339640331B4C680AAE6FF687368EE321ED4A2B3FD8504D5ED430F893CF2EE41F4C7A7FCD30F20369A55D46A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @BBL P1P",. "inherits": "Overture Matte PLA @base",. "from": "system",. "setting_id": "GFSL05_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_min_speed": [. "50". ],. "hot_plate_temp": [. "65". ],. "hot_plate_temp_initial_layer": [. "65". ],. "slow_down_layer_time": [. "10". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab P1P 0.4 nozzle",. "Bambu Lab P1P 0.6 nozzle",. "Bambu Lab P1P 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):384
            Entropy (8bit):4.49965819574246
            Encrypted:false
            SSDEEP:6:fS58P7yp0s7qdU0H0htz3vclz9JvF8Juww/Kyr3sJgh053sH+W53sjCkCA:gp0NU0UhJfclpT1wksT1sHl1sj8A
            MD5:D638AEFC68B3EBD0348EC67058A386D9
            SHA1:8BE2EFC21F328772B14DD4FBD99A30D9537EDAAF
            SHA-256:42AD1781AE9342AFC6D9F31D309415F393F48DD8137132E4F3A36C0998BFA14F
            SHA-512:666AA909F1A1CCFDCDA1CDE57FB22FE74081576A9F819235B479D85AD68955DAD1F0EC6535C4095C65B5711CC36E611F0E4B91F7B937EA844C0E4E99DF60D03E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @BBL X1",. "inherits": "Overture Matte PLA @base",. "from": "system",. "setting_id": "GFSL05_02",. "instantiation": "true",. "slow_down_layer_time": [. "10". ],. "compatible_printers": [. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab X1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):453
            Entropy (8bit):4.559830278096201
            Encrypted:false
            SSDEEP:12:gyVgW0Ln0UhJoUlpTbzPQkscW1+XwKW1rKW1PgbA:LjjqhpTb0R/EXwBLBKA
            MD5:CED10C340C7940A191FA1BA9C55899FA
            SHA1:2ACCB9D7566FC50DF158763B6CDBFE76B28628A6
            SHA-256:7FD1DF5651DF566AC3B928CBD675B98D5E80557B332F624782F89015D210E5CD
            SHA-512:C75BB29013F9EE70B80EBB8A0B60F8768F63F64DA8F9BA1D9A301745685F9B1403C5AC9CD025BE8E8F2739551DAC03CA2B18D4F232B8B0C22E248DED8FE4D9FA
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @BBL X1C 0.2 nozzle",. "inherits": "Overture Matte PLA @BBL X1C",. "from": "system",. "setting_id": "GFSL05_01",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1.8". ],. "compatible_printers": [. "Bambu Lab X1 0.2 nozzle",. "Bambu Lab X1 Carbon 0.2 nozzle",. "Bambu Lab P1S 0.2 nozzle",. "Bambu Lab X1E 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):572
            Entropy (8bit):4.438460141238269
            Encrypted:false
            SSDEEP:12:ghNU0UhJ+lpTg+XwHP1+Xw91+XwLP1rll1r91rxl1Pd1PP1PAA:yJqYpTnXwHPEXw9EXwblXDlBdBPBAA
            MD5:E3FC1011C527A137DE4465D4AFC5E241
            SHA1:CD9D21C6238885F78FB8B7B28BAC2ACFB22463B3
            SHA-256:62A2C330DF232579242CED8B618EB0023A397B9A40FCBE8FEE3DEE862466FA85
            SHA-512:023781DDFBD9D7E094B19232F896BC4E51B4EE54D6B412811A3995338E61730ED5B1859736A8408AF118607E032CF5D72ED29F7947EBF037ABA8CC6CD81C5F2F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @BBL X1C",. "inherits": "Overture Matte PLA @base",. "from": "system",. "setting_id": "GFSL05_00",. "instantiation": "true",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.4 nozzle",. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.4 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.4 nozzle",. "Bambu Lab X1E 0.6 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):486
            Entropy (8bit):4.25869259702107
            Encrypted:false
            SSDEEP:6:fS58P7qdmu+o8h0yDH0lz9slgWLQEwblD6HPob9fbDf6zwlwbKeqTdgJyA:ymu58h0iH0lpBpEw9zhfvza4dNA
            MD5:B2F842E9C9B45949AD0BBAA89C488AF7
            SHA1:3BFD9514EE709CEBA7E22C727F96612BDE4AE00F
            SHA-256:32B776833D820DF30BBAAD78696DCBD872382034C3E5C8DF0E96DD7AA8CF3BA0
            SHA-512:9B8BF383AE5A18E029274DC9A80AE7599066AB7A133068A5F6DFEFD360FB75180E5CA8E4F9BCB25A05AF1A7853DB2C11C2EBDA0578BB802D9B8794AE9A2D2D46
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture Matte PLA @base",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFL05",. "instantiation": "false",. "filament_cost": [. "24.52". ],. "filament_density": [. "1.22". ],. "filament_flow_ratio": [. "0.98". ],. "filament_max_volumetric_speed": [. "16". ],. "filament_vendor": [. "Overture". ],. "slow_down_layer_time": [. "6". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):510
            Entropy (8bit):4.382250536172833
            Encrypted:false
            SSDEEP:6:fS58PWKW0sZdU0H0htzKhclz9JvFSPwwxxzPbDf6zw9LdqgJcw/Kyr3Bc2CA:MKW0iU0UhJcclpTSPwwxdPvz7qXkBcbA
            MD5:6A644F14190D1573C5F67225D9CA7035
            SHA1:9EB38C8D6891F93D1B690F78A92D22FB674FBEB8
            SHA-256:F4BFCA6664B54721A21C01018432EE276C57161B808EEA683C6B3F280A3FFB0D
            SHA-512:F933F23E40F38F9DBB9B3194CFFEA20AB4A7B65114B7D45A6C736DE4DB621F4E9D2D6E38A4B25FB16922942F15413139B5F237D2AA1FCD9C53D69AFD408C801D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture PLA @BBL A1 0.2 nozzle",. "inherits": "Overture PLA @base",. "from": "system",. "setting_id": "GFSL04_08",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "filament_max_volumetric_speed": [. "1.6". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Bambu Lab A1 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):509
            Entropy (8bit):4.364281397429289
            Encrypted:false
            SSDEEP:6:fS58PU6sZdU0H0htzKlz9JvFSPwwxxzPgJcw/Kyr3B+053Bqh053Be2CA:3iU0UhJKlpTSPwwxdPXkBR1BT1BcA
            MD5:56DF36526B0400B18221B282559341B2
            SHA1:B8EC05E1260D0DA2D2C1C4ADD44BCEF4FD502773
            SHA-256:82FEF243D7B201FD522CA880976C65581C7B166EB51581BEE43DA446FC3ACA9B
            SHA-512:CFA0C3BD94D57645A82C65C88F5946C121E2D0AA4BB8D124E3B22D2ECD5DAF939E8BC230690F6B33D5B7F00F3A37D5074C47326FBB85D4AF3408953C5AFE692C
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture PLA @BBL A1",. "inherits": "Overture PLA @base",. "from": "system",. "setting_id": "GFSL04_07",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Bambu Lab A1 0.4 nozzle",. "Bambu Lab A1 0.6 nozzle",. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):332
            Entropy (8bit):4.58034109125344
            Encrypted:false
            SSDEEP:6:fS58PF+W0sNG0H0htzg6lz9JvF/Df6zw9Ldqw/Kyr3f2CA:H+W0V0UhJg6lpTbz7qkfbA
            MD5:F8CA29B83C822EA7AE120C6104D745C3
            SHA1:1490BBA3EB89F5E95DD2FA47F1A6998A6D7F7D0F
            SHA-256:187F02F2FA51AABC5216BB6627EFDB2812CE2423CA8AD36138D2FB2A7C35966B
            SHA-512:CD13E2240957C376D64DA65821E4D2E9832FCB76B08F3E8F4D04CD124A4E4E7994D2FD74899FFEA3663A0CC70D7F1F7A0A0C5F2122CF59A3F4B16D8AE22D2380
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture PLA @BBL A1M 0.2 nozzle",. "inherits": "Overture PLA @BBL A1M",. "from": "system",. "setting_id": "GFSL04_06",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1.6". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):739
            Entropy (8bit):4.299256568599995
            Encrypted:false
            SSDEEP:12:siU0UhJjlpTSPwwxdPOdGOO4XcGF0ko1i1RA:3JqbpTSPwcpUPjXcQ0x4LA
            MD5:04686E5FAA84A605D165099A853FDE11
            SHA1:D674841B206D3E05A897CAD7BB7B3D454992F924
            SHA-256:134E641A05245A1EEAD32280DC9C4D30219866D77720E88496E1ECCFBAACEEB2
            SHA-512:FD806FF44D5EB2CBAA2735BF08A05A558703D805042367E9C48469C0BC9DD186152F41522D9EE63CA758CA1DF329EE6533280E29389C97E90F741719D21E1E37
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture PLA @BBL A1M",. "inherits": "Overture PLA @base",. "from": "system",. "setting_id": "GFSL04_00",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "60". ],. "hot_plate_temp": [. "60". ],. "hot_plate_temp_initial_layer": [. "60". ],. "slow_down_layer_time": [. "8". ],. "textured_plate_temp": [. "65". ],. "textured_plate_temp_initial_layer": [. "65". ],. "compatible_printers": [. "Bambu Lab A1 mini 0.4 nozzle",. "Bambu Lab A1 mini 0.6 nozzle",. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):328
            Entropy (8bit):4.569164935151267
            Encrypted:false
            SSDEEP:6:fS58Px1IW0sx1o0H0htz+6lz9JvF/Df6zw9Ldqw/Kyr3qg2CA:jCW0YC0UhJnlpTbz7qkbbA
            MD5:0C82A3D0E41789C412D06A927CF31A4F
            SHA1:A6912C1643F558EDB190B3811380018E14AFDA5B
            SHA-256:5D68B424DFB647AC884C41E369CD0B2A516D7F2029969B56BB21B9DCBDB77729
            SHA-512:CF40A3D6CC10D46A0F4AE473B8421C5FD0773EB716C02908F94AA3B8B9AF52A9EEEC60ADE0D988679D6DC56E5FC50BB0A5DC32A53C37537238EFAED69AE8779D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture PLA @BBL P1P 0.2 nozzle",. "inherits": "Overture PLA @BBL P1P",. "from": "system",. "setting_id": "GFSL04_04",. "instantiation": "true",. "filament_max_volumetric_speed": [. "1.6". ],. "compatible_printers": [. "Bambu Lab P1P 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):471
            Entropy (8bit):4.417781681233166
            Encrypted:false
            SSDEEP:6:fS58Px1asZdU0H0htzWlz9JvFSxzvPogJuww/Kyr3q6053qeh053qi2CA:jQiU0UhJWlpTSdvwZwks1W1NA
            MD5:23CD455C82A768ED37A7162A67E3F274
            SHA1:446612BE610FDEFF3FC26938428F28C7424FC636
            SHA-256:EE15E18AAA00E86AA271D16C5ECEC6AD8EF526271944A632BBD442FB40DA5DD8
            SHA-512:B4EA932106131BE391EFA92C8D32DC6B3895620F58527A2124E708232BE0F8A79E47D6B9442963587AF15C2AC60921DE1B7A7E5F5A692FB75A50DA6CA08476F5
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Overture PLA @BBL P1P",. "inherits": "Overture PLA @base",. "from": "system",. "setting_id": "GFSL04_03",. "instantiation": "true",. "fan_cooling_layer_time": [. "80". ],. "fan_min_speed": [. "50". ],. "slow_down_layer_time": [. "10". ],. "compatible_printers": [. "Bambu Lab P1P 0.4 nozzle",. "Bambu Lab P1P 0.6 nozzle",. "Bambu Lab P1P 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):376
            Entropy (8bit):4.644159058976663
            Encrypted:false
            SSDEEP:6:fEaxTFOSi7xAL1Gh00u++N7S0H0htAa/0lz9JvFqOm0R4/MKz9CSgVfHNBihCaQk:8GTFg7xAL10uVe0UhYlpTqK6jpCSihbA
            MD5:0843AB5A002BB7DF673B1B7ADFD12618
            SHA1:E9426862A0CAFD7335EF2113B225627E9AF362ED
            SHA-256:5EF28379241E37696B02744457355F3E7A93A34F36DB72746E92C1A1836A8439
            SHA-512:F3CBB51A0B179DFA44060FF7D82E693E4032F73E9AA6C8AA58A4BDE6ABCA29982E7ECE2E03929407B4FC2BC2A86BEC224E82491731AA419511C963E6D9E2979F
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.30mm Strength @BBL P1P 0.6 nozzle",. "inherits": "fdm_process_bbl_0.30_nozzle_0.6",. "from": "system",. "setting_id": "GP067",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "sparse_infill_density": "25%",. "wall_loops": "4",. "compatible_printers": [. "Bambu Lab P1P 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):489
            Entropy (8bit):4.6166109128606285
            Encrypted:false
            SSDEEP:12:8GTFg7xATyVP0uVe0Uh6lpTqK6jpCSih+Xw91sT1r91PGA:8GTFmFP9ZqapTqfFCSi4Xw9STXBGA
            MD5:8ACB24994122D3E56A9E3E1EDCB3B4E1
            SHA1:0FD3CAE9D0DF3D9DA9BD027E5AD6B4D49332F61C
            SHA-256:B476AE340A1A91280C835B9DB5F4BDB732E07EF1FF18AA9B42A37D017684509A
            SHA-512:D375ED686DBD0B8A1A87E081DC814765582F7783E35D637C583B09F4B2DB116C1C8A3CFBA99E88FAB52E3146464958892600AC007B82E74A421B55B17DDA6D06
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.30mm Strength @BBL X1C 0.6 nozzle",. "inherits": "fdm_process_bbl_0.30_nozzle_0.6",. "from": "system",. "setting_id": "GP036",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "sparse_infill_density": "25%",. "wall_loops": "4",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab X1E 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):378
            Entropy (8bit):4.641663996089166
            Encrypted:false
            SSDEEP:6:fEaxTFOSlQIfTYW0u++N9lm0H0htWclz9JvFUDEQ3mOIMs9AOm0R4/MKz9O6HayD:8GTFTQATb0uVXm0UhTlpTa5vxOAK6jpN
            MD5:741BA007622C4F8FC89EA3DC5F216332
            SHA1:D23B7E97BF53E24C65ED9FABAD50C4F9CECEB6ED
            SHA-256:4D2162BE126AC4201F178A5A5A1842AA048B25B7372865DFAF24902F7C8DBE91
            SHA-512:2AE64D526FC13E779280E100D366754EE89DFED9723DE632D0EE9C2F36B0321CD5B53ED405B24C156C942377D0E4956A67DAEF376387625891CD9A444B238E35
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.32mm Optimal @BBL A1 0.8 nozzle",. "inherits": "fdm_process_bbl_0.32_nozzle_0.8",. "from": "system",. "setting_id": "GP093",. "instantiation": "true",. "default_acceleration": "6000",. "elefant_foot_compensation": "0.075",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):342
            Entropy (8bit):4.639238284848965
            Encrypted:false
            SSDEEP:6:fEaxTFOSlQIfM+W0u++N9lm0H0htBalz9JvFUDEQ3mOIMs9CylZg6/Kyr3R2CA:8GTFTQAs0uVXm0UhClpTa5vxOjjgiRA
            MD5:F093DA400DFE6293A97FBA873E38179C
            SHA1:0AE9B015F81856B70CA055D03F4FE7C5768DDF6B
            SHA-256:22EE84E817A921BBB416A15CEBCF1E00C7F79F59CD898A951A1C0DF9E84197BD
            SHA-512:ED1BE9CFE1F934F7CC6A8694A21BFE091F3744050A59B3738A33FE51A3158DA90A5E693F871B290A73DCEA8B3C15DD6D3300F1032E493176A5D0AE06E553B53B
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.32mm Optimal @BBL A1M 0.8 nozzle",. "inherits": "fdm_process_bbl_0.32_nozzle_0.8",. "from": "system",. "setting_id": "GP058",. "instantiation": "true",. "default_acceleration": "6000",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):316
            Entropy (8bit):4.630667795658583
            Encrypted:false
            SSDEEP:6:fEaxTFOSlQIfC16W0u++N9lm0H0htu0lz9JvFqOm0R4/MKz9CSw/Kyr3qi2CA:8GTFTQACD0uVXm0UhblpTqK6jpCSkNA
            MD5:A07228BD99D8C266DBFE50B772F3A265
            SHA1:D6FB1C76CD1F21EB5E85EA1FDE527A95AC5B7D6E
            SHA-256:663FA263A63238FDCC9998EBBC4CDA3B3BAF1D4D79286439F147E37338F447DE
            SHA-512:E1F7703F0A1C7F704C6CA4A6E38FD12A07A6871E461EC07080853292DDA05A79968192E964541147244130DCA163A3EC053F6AE4D7BBF4292CFE1CCBF9F4F4FB
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.32mm Optimal @BBL P1P 0.8 nozzle",. "inherits": "fdm_process_bbl_0.32_nozzle_0.8",. "from": "system",. "setting_id": "GP075",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab P1P 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):430
            Entropy (8bit):4.5877947080652195
            Encrypted:false
            SSDEEP:12:8GTFTMGyVZ0uVXm0Uh60lpTqK6jpCSk+XwLP1sHl1rxl1PAA:8GTFTMJZ9Nnq6opTqfFCSDXwbSHlDlBD
            MD5:681B0FFCD368A332B6C1C021A342F094
            SHA1:9D84910D4C04314BCA4B35A7C9BDFAC0C2B61B0D
            SHA-256:4D58CD97C0E65168C652D84659515A97475690BDB74E37E46565969A79D8AA83
            SHA-512:1C1452851F5411860D9DAE91B5C132913E7146B236ACB4675932BB36921D9277F593FAE1ADC5D553A969DA282A827567D6168F83806E1D490122DDDD770907DB
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.32mm Standard @BBL X1C 0.8 nozzle",. "inherits": "fdm_process_bbl_0.32_nozzle_0.8",. "from": "system",. "setting_id": "GP033",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):376
            Entropy (8bit):4.610249066434045
            Encrypted:false
            SSDEEP:6:fEaxTFOSTOTYh00u++Nb9S0H0httzmlz9JvFUDEQ3mOIMs9AOm0R4/MKz9O6HayV:8GTFg90uVbY0UhHmlpTa5vxOAK6jpOgV
            MD5:77350E6CF082AD1147FB145E4D8D6F22
            SHA1:010C9D930D6B47CDC916E4E1DEC023534AD090D4
            SHA-256:E5E10DFCFD9D3A54C795FC972F62A6947F81E914541162877E870EAAAF68C8A3
            SHA-512:87487DFF488E917BD0A3B5EB3DA18CF6CB3B2B06D416E03714DF43B0CE67741E574F8C22D4963E392A6FB79D3F7C5C08FF7F9163A5F1CB81B51BAC8ED891BA56
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.36mm Draft @BBL A1 0.6 nozzle",. "inherits": "fdm_process_bbl_0.36_nozzle_0.6",. "from": "system",. "setting_id": "GP090",. "instantiation": "true",. "default_acceleration": "6000",. "elefant_foot_compensation": "0.075",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):340
            Entropy (8bit):4.617379896771356
            Encrypted:false
            SSDEEP:6:fEaxTFOSTO+gh00u++Nb9S0H0htevFF0lz9JvFUDEQ3mOIMs9CylZg6/Kyr3zhk5:8GTFvl0uVbY0UhAvFmlpTa5vxOjjgiXA
            MD5:0CFF5E9553E9A54B87C700C25ACEC04F
            SHA1:6F4DDCC5071D0A77B91C2AA14C28A5686126C16F
            SHA-256:F0A07F10B3C5329280665AE69B2C0014117817398F40F0902692C3E929888CC3
            SHA-512:4EF3804ED521A5D1F45E36041F235EA526D0D10168C84F9624AACFFE09DEEE6268C2D2C164324443C1A91887F15A330EF24DF214D69642C4DC0A119CC9A2C0EA
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.36mm Draft @BBL A1M 0.6 nozzle",. "inherits": "fdm_process_bbl_0.36_nozzle_0.6",. "from": "system",. "setting_id": "GP055",. "instantiation": "true",. "default_acceleration": "6000",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 mini 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):314
            Entropy (8bit):4.606540252580885
            Encrypted:false
            SSDEEP:6:fEaxTFOSTOC1Gh00u++Nb9S0H0htjH6lz9JvFqOm0R4/MKz9CSw/Kyr3qehkCA:8GTF/10uVbY0UhNalpTqK6jpCSkbA
            MD5:BC05DDE4BBE7DA7B9D50AF722DF15B64
            SHA1:E3803F49D21293E081C1C3A687AB6A91734A6456
            SHA-256:4688AC2CA3F648695F664E1BEF24CCFD50770A8A05E01E17A92AB87548AB1A0F
            SHA-512:B25B69A876C8265A1F2388591EE9D31578B2165CCAD27572E0B4820F2EA69308F0B01586184341916F59372095D5E3DB39AB2FC598E9B194355E0D1F7DADCFAE
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.36mm Draft @BBL P1P 0.6 nozzle",. "inherits": "fdm_process_bbl_0.36_nozzle_0.6",. "from": "system",. "setting_id": "GP070",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab P1P 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):430
            Entropy (8bit):4.569004988637375
            Encrypted:false
            SSDEEP:12:8GTFryVP0uVbY0UhBalpTqK6jpCSk+Xw91sT1r91PGA:8GTFSP99dqB6pTqfFCSDXw9STXBGA
            MD5:A5B240A012874B5C4FCCD1D729000571
            SHA1:BD3799F806F6F55BDFF689E2B0FEDECE8FF1504D
            SHA-256:DC7377CFF45F6178CC2656B135CC3F04113CBEF61A298E1582E847BBEF52A1FA
            SHA-512:C8B4049B44B41620CE2E64CD35649B999AE4C8392CB3737E9D06273427DAA347B06D733E4ADC47265B5F101A6EC060AE97DCFCA8FD2B1B4C9C3437A3FA6905D3
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.36mm Standard @BBL X1C 0.6 nozzle",. "inherits": "fdm_process_bbl_0.36_nozzle_0.6",. "from": "system",. "setting_id": "GP030",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab X1E 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):379
            Entropy (8bit):4.621543068922238
            Encrypted:false
            SSDEEP:6:fEaxTFOA4UpTYW0u++NweClm0H0htlpUlz9JvFUDEQ3mOIMs9AOm0R4/MKz9O6HP:8GTFAeb0uVwxm0UhulpTa5vxOAK6jpO6
            MD5:41A61A8C6EFD57A796C791F2C8DE88BF
            SHA1:A9B21845DA94A10C8BD7B36C07A7B76A9C25D460
            SHA-256:05E38AB2310E5ED1DA4C9D2E4E8F74AE1E5525C40DBB9676548C71C5B4FFFC3F
            SHA-512:5085C1F2F9DFBFB479DE041CA2B50C4C6142C3A0BAD9E8C69DEFAA19A0834F5F0E3E44156D09CA4C8FF8A83405F9C857666376CEDE15656B11FFF916A9350919
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.40mm Standard @BBL A1 0.8 nozzle",. "inherits": "fdm_process_bbl_0.40_nozzle_0.8",. "from": "system",. "setting_id": "GP098",. "instantiation": "true",. "default_acceleration": "6000",. "elefant_foot_compensation": "0.075",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):385
            Entropy (8bit):4.603858096565496
            Encrypted:false
            SSDEEP:12:8GTFAd0UJDG0UhBlpTa5vxOAK6jpvjgiRA:8GTFEZHqTpTopOAfFvA
            MD5:922854E05ABE3E5501C2B732BAEEA444
            SHA1:BD6D2CF217333DA029FA20941AF82EFCD874DEC4
            SHA-256:61284BACE8A2116F616334EE50E559DB03AA933AACCE50F8B6BA9916A55D9355
            SHA-512:E130F21D3C83130089F6D4445427553CB45CB815DC80E8A0A3337453D9C6A7FBBB0263C75C46ABB77B9225E2D6F8994CB01FCD0D4EF9C492181F278B8D9467B0
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.40mm Standard @BBL A1M 0.8 nozzle",. "inherits": "0.40mm Standard @BBL P1P 0.8 nozzle",. "from": "system",. "setting_id": "GP037",. "instantiation": "true",. "default_acceleration": "6000",. "elefant_foot_compensation": "0",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):317
            Entropy (8bit):4.613529792238632
            Encrypted:false
            SSDEEP:6:fEaxTFOA4UpC16W0u++NweClm0H0ht6clz9JvFqOm0R4/MKz9CSw/Kyr3qi2CA:8GTFAJD0uVwxm0UhvlpTqK6jpCSkNA
            MD5:AC71112F4BD5B4D1CD0D50AC2B49E687
            SHA1:6F1119FCB298053B9223C0D599A3C8EA9BF93BFB
            SHA-256:443EE9080A70A190D518841E9807D9B7D9C2AC1A05E097514AD12215832D037F
            SHA-512:0EC941C49286F543E7C5EB184A396B1D2F102997A69AD98BEA048FC78C3EB2E91C13C20B9295271871FC30C4C03B4C01C143A361DF140DE7805423D66DF2A169
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.40mm Standard @BBL P1P 0.8 nozzle",. "inherits": "fdm_process_bbl_0.40_nozzle_0.8",. "from": "system",. "setting_id": "GP017",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab P1P 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):315
            Entropy (8bit):4.611446469371059
            Encrypted:false
            SSDEEP:6:fEaxTFOA4Up6j+W0u++NweClm0H0ht3HTmlz9JvFqOm0R4/MKz9CSw/Kyr3sH+25:8GTFARjl0uVwxm0Uh5HTmlpTqK6jpCSp
            MD5:755154851B1972AA8FC51501B40794D8
            SHA1:1CF682CFAF420039EBE245081C2FFB29717C43DC
            SHA-256:F0576844BEBA0A100C3C776719C4441B2AB73A349B01CEBE01E6E1E41EE75250
            SHA-512:A3A53913BA87A26347675F4B87D9780AAEDD1893B93BD2E240F2760FCE2C1C263D422CC8B4C55CE1B10FEDC6F133BF1AD75F0FAADBEBB175ECB28A4A6EFC3E62
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.40mm Standard @BBL X1 0.8 nozzle",. "inherits": "fdm_process_bbl_0.40_nozzle_0.8",. "from": "system",. "setting_id": "GP012",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab X1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):395
            Entropy (8bit):4.60367383583465
            Encrypted:false
            SSDEEP:12:8GTFARyVZ0uVwxm0UhoPlpTqK6jpCSk+XwLP1rxl1PAA:8GTFtZ94nqotpTqfFCSDXwbDlBAA
            MD5:E1A6720B664EDF179C73BFF512EBE878
            SHA1:FF9C4C4D246E32CB13736A3524A1AEBA38A656DC
            SHA-256:84958DD9BF1430F30DE2729BA1D9A6A1E1011F99B9A7FC5D3F2820963F1EEB1F
            SHA-512:30094CB6BA4E05B950C0CFA410DF143EFA1DADBDB172F476D74CDDE712D2A6AB06C5D86D6F5753A94346A4A8326F77A85DA2BD00E81391F49A1D3B17F07E25CB
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.40mm Standard @BBL X1C 0.8 nozzle",. "inherits": "fdm_process_bbl_0.40_nozzle_0.8",. "from": "system",. "setting_id": "GP009",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):382
            Entropy (8bit):4.654900383129876
            Encrypted:false
            SSDEEP:6:fEaxTFOpPsTYh00u++NwtS0H0ht+dF0lz9JvFUDEQ3mOIMs9AOm0R4/MKz9O6HaS:8GTFqk90uVwo0UhgdmlpTa5vxOAK6jpL
            MD5:77EB6E27A27DC085D5B51C0A0E199D24
            SHA1:5CDCBEBC58BDED8D3B5E520A076F2FCBC1E63B0B
            SHA-256:50E54AD8D9B8D220B1F9A1B7E6FA466EFBADFECFA7C080747216809D2F701A23
            SHA-512:DBBA4BAC121E1B82DAC9DBF5F543D352C01D35F288B4407182C622F9D1D33CAC8344ECEDE2B4644AA3C3B0FDF4C98D85AF904916E695631D84E7C14A5AE9F2CA
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.42mm Extra Draft @BBL A1 0.6 nozzle",. "inherits": "fdm_process_bbl_0.42_nozzle_0.6",. "from": "system",. "setting_id": "GP091",. "instantiation": "true",. "default_acceleration": "6000",. "elefant_foot_compensation": "0.075",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):346
            Entropy (8bit):4.65399231311455
            Encrypted:false
            SSDEEP:6:fEaxTFOpPs+gh00u++NwtS0H0htPpUlz9JvFUDEQ3mOIMs9CylZg6/Kyr3zhkCA:8GTFqjl0uVwo0UhhalpTa5vxOjjgiXA
            MD5:0E8F2E50E5EB3794E53E78135AAD10FE
            SHA1:56B444B371297BBC0E9EFB3DEBE52FB6652B6F29
            SHA-256:2C2F5E6A6D40325960B37798AE7400CC04CB6D3061C43BE56C9CC09467EDDA3C
            SHA-512:BDB7BDC2845EF6456B0630F323210F9C239D00F5F3D045399463933BC33C1DCAE9746CE46FD164FFEB9323C4AD4908619EF979C9B5D21A189910CC8CC22010E2
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.42mm Extra Draft @BBL A1M 0.6 nozzle",. "inherits": "fdm_process_bbl_0.42_nozzle_0.6",. "from": "system",. "setting_id": "GP056",. "instantiation": "true",. "default_acceleration": "6000",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 mini 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):320
            Entropy (8bit):4.663005835540176
            Encrypted:false
            SSDEEP:6:fEaxTFOpPsC1Gh00u++NwtS0H0htKdmlz9JvFqOm0R4/MKz9CSw/Kyr3qehkCA:8GTFqL10uVwo0UhplpTqK6jpCSkbA
            MD5:453BAAC3AEB6E22D202B8E640E9FE043
            SHA1:2869D961AB8274D8FA9E9AB01A419005453CC775
            SHA-256:8815283CE3D0A698E5164861CF46F7F752DCB3DF87F4402DB11B2CE81AF09D57
            SHA-512:A03A5F817CDB77E0727404C6266CD9BC9BEE935D677469DF12EEE5491F96B6F3F1EECBADE8D4534657C9A6F89B4E85D968CE46BAD10890C3710A34600CB78F58
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.42mm Extra Draft @BBL P1P 0.6 nozzle",. "inherits": "fdm_process_bbl_0.42_nozzle_0.6",. "from": "system",. "setting_id": "GP073",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab P1P 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):430
            Entropy (8bit):4.592116313995275
            Encrypted:false
            SSDEEP:12:8GTFAyVP0uVwo0UhTlpTqK6jpCSk+Xw91sT1r91PGA:8GTFrP9cqppTqfFCSDXw9STXBGA
            MD5:29897C7E3DFEA98328E5DFD0C3A0E1ED
            SHA1:E9337D726F16C5DE34B018728484FB44AEA9A11C
            SHA-256:85EEF1389A30DE6787798327B8A301A809E89944574AEA6BA2888D5B9007FB67
            SHA-512:32694990D7FE2B9EBC8BBD16401EA1C59BC1CDD816C476D496D98BF94EFA69CEFACFDC1799D98E75773232F58A35320AB5D90A89B1201648A2C88D7613100927
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.42mm Standard @BBL X1C 0.6 nozzle",. "inherits": "fdm_process_bbl_0.42_nozzle_0.6",. "from": "system",. "setting_id": "GP031",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.6 nozzle",. "Bambu Lab X1 0.6 nozzle",. "Bambu Lab P1S 0.6 nozzle",. "Bambu Lab X1E 0.6 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):376
            Entropy (8bit):4.627117416435905
            Encrypted:false
            SSDEEP:6:fEaxTFO42sTYW0u++NwDlm0H0htpalz9JvFUDEQ3mOIMs9AOm0R4/MKz9O6HaylV:8GTF2kb0uVwpm0Uh6lpTa5vxOAK6jpO6
            MD5:485DF0AAB7DAAE13ABB364BB9C5C73B1
            SHA1:D0208BE108EA4A902854DABCFF0D48DCFDCDCBF0
            SHA-256:B72CE3BB810125EE4669D57326489D53783109A9FA6548D6DDBF15EE91890351
            SHA-512:5862F11AB42A7050F8B4EA21103015EA810B90721448989D6DE50FEDE088CC7E4D8F489A4AF8740BA95AFE5C30BF53829D9147D23F9D401E13EB9BA8F890A764
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.48mm Draft @BBL A1 0.8 nozzle",. "inherits": "fdm_process_bbl_0.48_nozzle_0.8",. "from": "system",. "setting_id": "GP094",. "instantiation": "true",. "default_acceleration": "6000",. "elefant_foot_compensation": "0.075",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):340
            Entropy (8bit):4.634733233623974
            Encrypted:false
            SSDEEP:6:fEaxTFO42sM+W0u++NwDlm0H0htTlz9JvFUDEQ3mOIMs9CylZg6/Kyr3R2CA:8GTF230uVwpm0UhJlpTa5vxOjjgiRA
            MD5:B0DFB1347A08009A226D223D2F7B13F5
            SHA1:A7F680521A6AD328F301459500444CDA879CC0A4
            SHA-256:3C1EF7D56BA816B53D4677B6A31C3F61830B2B5FF6808B0216FCBA4C49C8C121
            SHA-512:D9A5C2318A92F9EDDB3D22B74D74BD8B5D1C53DB0C3D6C824624DE195C9C47CAAE65B8337CD70D4AE1A217730C9B17F9363C2B498A50A41347663742075F89D0
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.48mm Draft @BBL A1M 0.8 nozzle",. "inherits": "fdm_process_bbl_0.48_nozzle_0.8",. "from": "system",. "setting_id": "GP059",. "instantiation": "true",. "default_acceleration": "6000",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):314
            Entropy (8bit):4.611615501126851
            Encrypted:false
            SSDEEP:6:fEaxTFO42sC16W0u++NwDlm0H0htnHJUlz9JvFqOm0R4/MKz9CSw/Kyr3qi2CA:8GTF2LD0uVwpm0UhJpUlpTqK6jpCSkNA
            MD5:DF638DE04755C5B4B3FB7C94540964F9
            SHA1:7CB421E8E6AB2FD69A28EDA24D510245C59948A9
            SHA-256:2DE585852563568B83065C68C14D0E5ABCC4524DA69CE65C661A1F64C2356177
            SHA-512:C5353F1057E21D2B70D2EA6F219EC7290B7ADE9F790B6FFFEE31A90B26235750D282A6C7EB4EC7A3C9BCE262EB19A52E33DE2AE9992157A85FC05FEAD4DF4C7D
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.48mm Draft @BBL P1P 0.8 nozzle",. "inherits": "fdm_process_bbl_0.48_nozzle_0.8",. "from": "system",. "setting_id": "GP074",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab P1P 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):430
            Entropy (8bit):4.580247934814437
            Encrypted:false
            SSDEEP:12:8GTF6yVZ0uVwpm0UhFalpTqK6jpCSk+XwLP1sHl1rxl1PAA:8GTFFZ9gnq8pTqfFCSDXwbSHlDlBAA
            MD5:6F6D43855620613DE0D48721ED636AD6
            SHA1:261BB6E24B0DB7B51C95EC54778DC5F8F82D9997
            SHA-256:838065F3E1F39F43C16B637D67D856FC062BF2ABB31DE8F0676AAD6B039EA827
            SHA-512:E66383BB2282413BFCBCEB556785B69BA8AC46A777BF41B30D1B620E13B50FB2DD18A6A2D95E733C6B21B3D808E1551CF1C7FF4016506BEF3F85B680792FACE6
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.48mm Standard @BBL X1C 0.8 nozzle",. "inherits": "fdm_process_bbl_0.48_nozzle_0.8",. "from": "system",. "setting_id": "GP034",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):382
            Entropy (8bit):4.647688635742013
            Encrypted:false
            SSDEEP:6:fEaxTFOUEIaTCsTYW0u++NVllm0H0ht7lz9JvFUDEQ3mOIMs9AOm0R4/MKz9O6HP:8GTFzs+kb0uVV/m0UhBlpTa5vxOAK6jb
            MD5:AD629B6AA736D767F71BDD034F9F60D7
            SHA1:10FC1551FDCFCEA187C6076365F9021C85F37695
            SHA-256:055B3D4CECD29E1FAA0C4C0DF417DF064BFD9C51B624E9C723ED0973074B0EF3
            SHA-512:28671813ACD7291FF30EE448249C05D07A8882634B64C747A4A6829A76CDF4B90EAF31CB74253F0A26EC4082C6874C36B2593D9B31F23336C76C238694726EE1
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.56mm Extra Draft @BBL A1 0.8 nozzle",. "inherits": "fdm_process_bbl_0.56_nozzle_0.8",. "from": "system",. "setting_id": "GP095",. "instantiation": "true",. "default_acceleration": "6000",. "elefant_foot_compensation": "0.075",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):346
            Entropy (8bit):4.642110667937179
            Encrypted:false
            SSDEEP:6:fEaxTFOUEIaTCsM+W0u++NVllm0H0htAwlz9JvFUDEQ3mOIMs9CylZg6/Kyr3R25:8GTFzs+30uVV/m0UhVlpTa5vxOjjgiRA
            MD5:94E0BA8A8306C4793C765202A95E8679
            SHA1:97C41D84ABCC1EBF5A464DED761D1FAD3562BC65
            SHA-256:04C05779A06AA16029CAD24826F241EE36CCE1F7E2F3423FD9D0F9249AD7E71B
            SHA-512:AA42F2F8282E2DAA2EAD43C3FA44F70D617C53D74209CBD03772138B105F2BCDCD5658E8A8F96DAAF276D9985CE72C5B10E3681350392613DAE581533BE1C2A7
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.56mm Extra Draft @BBL A1M 0.8 nozzle",. "inherits": "fdm_process_bbl_0.56_nozzle_0.8",. "from": "system",. "setting_id": "GP060",. "instantiation": "true",. "default_acceleration": "6000",. "travel_speed": "700",. "compatible_printers": [. "Bambu Lab A1 mini 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):320
            Entropy (8bit):4.644255835540176
            Encrypted:false
            SSDEEP:6:fEaxTFOUEIaTCsC16W0u++NVllm0H0htKclz9JvFqOm0R4/MKz9CSw/Kyr3qi2CA:8GTFzs+LD0uVV/m0UhwclpTqK6jpCSk6
            MD5:A60082392155ECE93C94C9672DEDCE0C
            SHA1:0176D559CBF1290E1E5D381057AE25215C9E7055
            SHA-256:88C28C8EB847EFBCD729BB47BBB498373C1537B8887EDEF40FC4587C0767C25D
            SHA-512:D50224447E730F895DC14AC40478D55A23C65BE90E7E26400A7E68A956BFD7FEA56C4F843E2817AD6766070B34EAAEB303B062508395217BB3449CB5C9895553
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.56mm Extra Draft @BBL P1P 0.8 nozzle",. "inherits": "fdm_process_bbl_0.56_nozzle_0.8",. "from": "system",. "setting_id": "GP071",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab P1P 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):430
            Entropy (8bit):4.5877947080652195
            Encrypted:false
            SSDEEP:12:8GTFzlyVZ0uVV/m0UhXlpTqK6jpCSk+XwLP1sHl1rxl1PAA:8GTFAZ9D/nq1pTqfFCSDXwbSHlDlBAA
            MD5:CD725FF21D17360F94B10B6CB87C4E15
            SHA1:4BA76858DBD05D2BB6ED73129991D061EA27A681
            SHA-256:CEB5CF5C818ADDFCEE4AC5A1D987EBBA7F27D4365415E311C1D9FD13D602FD0C
            SHA-512:10C5479627781CC7AB24F3CE25A81AD7A2ED3B0AD10E5BAF96F6C05E819A51B37C874BD707DC550E7DC647BA95DC3F6E0A8114CC83BA26BAF4B3F5787CF2FB6B
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "0.56mm Standard @BBL X1C 0.8 nozzle",. "inherits": "fdm_process_bbl_0.56_nozzle_0.8",. "from": "system",. "setting_id": "GP035",. "instantiation": "true",. "elefant_foot_compensation": "0.15",. "compatible_printers": [. "Bambu Lab X1 Carbon 0.8 nozzle",. "Bambu Lab X1 0.8 nozzle",. "Bambu Lab P1S 0.8 nozzle",. "Bambu Lab X1E 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):782
            Entropy (8bit):4.494604522279984
            Encrypted:false
            SSDEEP:12:8GTFy0RUuVpU0dlpG3Lv0JHdJSJJG1XpfqJGLWXEEjZgyZ7WIq:8GTFz3nJHpCvsm7JGLWxPdWx
            MD5:0C61DBA209414524CD020B15728BB622
            SHA1:68E780018BDEE154371AFF51027088F9674EEF22
            SHA-256:5F63E9DB9CE5AE1B6D8C36B6C399404712F5852A7AC5ADCB82E4BE942E4AF20D
            SHA-512:611A0D836425425C3393A0BCEAC050B350C144B18B8C2A7D353A2DEACC6D7A6AE5F3A8D7471E8CC6C8844029290E90A1B9BB0DA209554A6F570A597EFE0E6336
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.06_nozzle_0.2",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.06",. "initial_layer_print_height": "0.1",. "wall_loops": "4",. "bottom_shell_layers": "5",. "top_shell_layers": "7",. "bridge_flow": "1",. "line_width": "0.22",. "outer_wall_line_width": "0.22",. "initial_layer_line_width": "0.25",. "sparse_infill_line_width": "0.22",. "inner_wall_line_width": "0.22",. "internal_solid_infill_line_width": "0.22",. "support_line_width": "0.22",. "top_surface_line_width": "0.22",. "initial_layer_speed": "40",. "initial_layer_infill_speed": "70",. "sparse_infill_speed": "100",. "top_surface_speed": "150".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):711
            Entropy (8bit):4.514563486090086
            Encrypted:false
            SSDEEP:12:8GTFy0YuVpU0dlpkK6jpCSp0JddJOjJJGc3TEcUjZlJ7Z4r7ZmZEzmJIZTIZeScU:8GTFzhnJHpkfFCSpu6j7RELJ787IWzS3
            MD5:E1757AB16B4C9E536D6414B5543A1F1D
            SHA1:A499498C43FA5ABD84709B48FD8FC98776AC55DF
            SHA-256:E75D35CD78B3FD4881AE59FB12BA68CC194E6DD3F92594695CB55565053C909A
            SHA-512:552C20AA2C06A268F6F99369A7A6DD61EB940F3F0A2263E4956861D8D5EF64251FA4F9FE9CC61883C2489A4B665C9D69668E86E82FD180D725859C8C379CF15F
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.08",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.08",. "elefant_foot_compensation": "0.15",. "bottom_shell_layers": "7",. "top_shell_layers": "9",. "bridge_flow": "1",. "ironing_flow": "8%",. "initial_layer_speed": "50",. "initial_layer_infill_speed": "105",. "outer_wall_speed": "200",. "inner_wall_speed": "350",. "sparse_infill_speed": "450",. "internal_solid_infill_speed": "350",. "gap_infill_speed": "350",. "overhang_1_4_speed": "60",. "overhang_2_4_speed": "30",. "overhang_3_4_speed": "10",. "support_threshold_angle": "15".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):782
            Entropy (8bit):4.494604522279984
            Encrypted:false
            SSDEEP:12:8GTFy0DUuVpU0dlpo3Lv0JHdJSJJG1XpfqJGLWXEEjZgyZ7WIq:8GTFzRnJHpsvsm7JGLWxPdWx
            MD5:AB1BAF419F44E11E0FC7C549575BFCD5
            SHA1:BAC5B92B715AA47F46A29942287798D185F3049A
            SHA-256:A4941523EAAEE51E7664AA2B61856120A99E5FBCD6AE39DDF0F24C500739EB5B
            SHA-512:138F554EFB87AE9F95943CD534C9EADBBD2BAAFEE43816146974C9A412419F12E5EB9F64490A414AD872A11700D8A13E24E8802EB2631ED46152BA945C6967DD
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.08_nozzle_0.2",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.08",. "initial_layer_print_height": "0.1",. "wall_loops": "4",. "bottom_shell_layers": "5",. "top_shell_layers": "7",. "bridge_flow": "1",. "line_width": "0.22",. "outer_wall_line_width": "0.22",. "initial_layer_line_width": "0.25",. "sparse_infill_line_width": "0.22",. "inner_wall_line_width": "0.22",. "internal_solid_infill_line_width": "0.22",. "support_line_width": "0.22",. "top_surface_line_width": "0.22",. "initial_layer_speed": "40",. "initial_layer_infill_speed": "70",. "sparse_infill_speed": "100",. "top_surface_speed": "150".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):781
            Entropy (8bit):4.486389420157008
            Encrypted:false
            SSDEEP:12:8GTFy1UuVpU0dlpWa3Lv0JHdJSJJG1XpfqJGLWXEEjZgyZ7WIq:8GTF2nJHpWGvsm7JGLWxPdWx
            MD5:5E1EE46690544ED6D9CF13B8064600AF
            SHA1:2D8FF0350AEEF03294D94D44B470DD09276D0B91
            SHA-256:86CF59136BABDE5358B8C853B96B9E99C0050ED5255F4CCC02E23F7050D6E1CF
            SHA-512:458F6366C2117B43B845012CF78A7DB3DA226F03501AF1393698C1CE44A168B6CC9768127FAA58908EF11E795C6F0B6FEED48AE89222C4DB9A395209D724882A
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.10_nozzle_0.2",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.1",. "initial_layer_print_height": "0.1",. "wall_loops": "4",. "bottom_shell_layers": "5",. "top_shell_layers": "7",. "bridge_flow": "1",. "line_width": "0.22",. "outer_wall_line_width": "0.22",. "initial_layer_line_width": "0.25",. "sparse_infill_line_width": "0.22",. "inner_wall_line_width": "0.22",. "internal_solid_infill_line_width": "0.22",. "support_line_width": "0.22",. "top_surface_line_width": "0.22",. "initial_layer_speed": "40",. "initial_layer_infill_speed": "70",. "sparse_infill_speed": "100",. "top_surface_speed": "150".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):719
            Entropy (8bit):4.5031119241921065
            Encrypted:false
            SSDEEP:12:8GTFyYuVpU0dlpWZn0JpK6jpCSKdJHdRwApJJGcEcUjZlJ7Z4r7ZmZ5JIZTIZeS7:8GTFenJHpWZnAfFCSKzFp7RELJ787Ixf
            MD5:296167E387802C499965CFA6AD61911B
            SHA1:538900C20E84628618F158BAAE7C3B68C6D4E6DE
            SHA-256:4641C7C827689A8F284583B5C5CDB74DE22E79F04B16EFCE780C942E7A9B4855
            SHA-512:5FCF908E4DDE0F7A60C83B1A471F785BBBAF786B245D2079B2B4D8B9D8081234773FFF77F013401812E64BADFD133F6B71A74589CFCCFEFA321B9EF1148B9433
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.12",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.12",. "bottom_shell_layers": "5",. "elefant_foot_compensation": "0.15",. "top_shell_layers": "5",. "top_shell_thickness": "0.6",. "bridge_flow": "1",. "initial_layer_speed": "50",. "initial_layer_infill_speed": "105",. "outer_wall_speed": "200",. "inner_wall_speed": "350",. "sparse_infill_speed": "430",. "internal_solid_infill_speed": "350",. "gap_infill_speed": "350",. "overhang_1_4_speed": "60",. "overhang_2_4_speed": "30",. "overhang_3_4_speed": "10",. "support_threshold_angle": "20".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):782
            Entropy (8bit):4.487769905174976
            Encrypted:false
            SSDEEP:12:8GTFydVUuVpU0dlpWZU3Lv0JHdJSJJG1XpfqJGLWXEEjZgyZ7WIq:8GTFcnJHpWZ4vsm7JGLWxPdWx
            MD5:A9941A155FF963307A7B6397401D807D
            SHA1:F52E5A719CE3350DEC44C56820CB734FBD3606DC
            SHA-256:1108F80357AF4A1F5EAAEC51BEAA702F8C4DF9C75E9C33B5AB9E9FB941C2CB5B
            SHA-512:2B8EB26E9B6BBBD3D73FFF42D2DA610D8730CD411F019CEB46D1DD5B2261D670053520BB7F3F6D242EFB20EE845D188D3CA26768DA65D2D977BBEB5D010629AC
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.12_nozzle_0.2",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.12",. "initial_layer_print_height": "0.1",. "wall_loops": "4",. "bottom_shell_layers": "5",. "top_shell_layers": "7",. "bridge_flow": "1",. "line_width": "0.22",. "outer_wall_line_width": "0.22",. "initial_layer_line_width": "0.25",. "sparse_infill_line_width": "0.22",. "inner_wall_line_width": "0.22",. "internal_solid_infill_line_width": "0.22",. "support_line_width": "0.22",. "top_surface_line_width": "0.22",. "initial_layer_speed": "40",. "initial_layer_infill_speed": "70",. "sparse_infill_speed": "100",. "top_surface_speed": "150".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):782
            Entropy (8bit):4.494238767100758
            Encrypted:false
            SSDEEP:12:8GTFyZUuVpU0dlpW83Lv0JHdJSJJG1XpfqJGLWXEEjZgyZ7WIq:8GTFCnJHpWgvsm7JGLWxPdWx
            MD5:DECAE1187F111E7722AF5DA872117BED
            SHA1:FEEDC1587A6C47041CDDFE454AFD3AF4A7B783ED
            SHA-256:49FAE6C45174EC7FDBF57071F0EE256175DB0F354ED3969FED35AD957B258265
            SHA-512:977E9FF4D01E0A1415B3648467EFB633B806D2E6BDEB45F1E9DDEBAC629D43216CF30D245616586CABDCDEE0E97B92F87783BF2950D25FD49B94F91C15DA8516
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.14_nozzle_0.2",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.14",. "initial_layer_print_height": "0.1",. "wall_loops": "4",. "bottom_shell_layers": "5",. "top_shell_layers": "7",. "bridge_flow": "1",. "line_width": "0.22",. "outer_wall_line_width": "0.22",. "initial_layer_line_width": "0.25",. "sparse_infill_line_width": "0.22",. "inner_wall_line_width": "0.22",. "internal_solid_infill_line_width": "0.22",. "support_line_width": "0.22",. "top_surface_line_width": "0.22",. "initial_layer_speed": "40",. "initial_layer_infill_speed": "70",. "sparse_infill_speed": "100",. "top_surface_speed": "150".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):719
            Entropy (8bit):4.4993648837896565
            Encrypted:false
            SSDEEP:12:8GTFyNmuVpU0dlpWXqK6jpCSp0JmdJkdRw3JJJGcEcUjZlJ7Z4r7Zs8ZNBcJIZsC:8GTFcrnJHpWXqfFCSplAgJ7RELJ787OU
            MD5:EDFF0F8C9218926A1B170EF036771142
            SHA1:79483D91E9022F55D3D5BAFE9A13AA95349677F3
            SHA-256:4384E55FF42495432C4876F0CAB1A7479DDF26FDB0EFC97B58ED9E383F062687
            SHA-512:370B13A61229900ABBFF65C0ADDA72F2575C74DBE8C27963E80E1EABE1C310B0EF99CD7C4094FAC885CB2FD42FA3E24986CF417B155C63D53F2D2D9B1FD5F380
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.16",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.16",. "elefant_foot_compensation": "0.15",. "bottom_shell_layers": "4",. "top_shell_layers": "6",. "top_shell_thickness": "1.0",. "bridge_flow": "1",. "initial_layer_speed": "50",. "initial_layer_infill_speed": "105",. "outer_wall_speed": "200",. "inner_wall_speed": "300",. "sparse_infill_speed": "330",. "internal_solid_infill_speed": "300",. "gap_infill_speed": "300",. "overhang_1_4_speed": "60",. "overhang_2_4_speed": "30",. "overhang_3_4_speed": "10",. "support_threshold_angle": "25".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):756
            Entropy (8bit):4.550979220520898
            Encrypted:false
            SSDEEP:12:8GTFyauVpU0dlpWzU3jJJGlkOJqHWjEp6jZeZ7WI/wsiVw:8GTF6nJHpWY7sqHW54dWSJ
            MD5:5CBAA752B876A3AE191635BD67B92505
            SHA1:330AB9596733D1023A13BF527873671D3FACB9D4
            SHA-256:95E4B2C256D70F4F6FCABDCBA2CF317A6CD6A8C72FC98A51AB502A5486DC98A4
            SHA-512:1F58F94B609BBD2D25899124336C8D90F47822381574E7B98C5812778DEC9FF681FDBE027F1E250FCD07C6F8EA4336C542F84CE7F7DBF485FE11DB9859651526
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.18_nozzle_0.6",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.18",. "initial_layer_print_height": "0.3",. "bridge_flow": "1",. "line_width": "0.62",. "outer_wall_line_width": "0.62",. "initial_layer_line_width": "0.62",. "sparse_infill_line_width": "0.62",. "inner_wall_line_width": "0.62",. "internal_solid_infill_line_width": "0.62",. "support_line_width": "0.62",. "top_surface_line_width": "0.62",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "15".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):526
            Entropy (8bit):4.438076279267363
            Encrypted:false
            SSDEEP:12:8GTFyNuVpU0dlp3K6jpCSKdRw3JJJGcEcUjZlJ7Z4r7Zs8ZrJIZMIZjdJH:8GTF7nJHp3fFCSKgJ7RELJ787O8zIV5L
            MD5:4B21972ECFB5A6ED73A3C15E4426B5DA
            SHA1:EEB4AC2EA6CA4F6F8D6F252125E60C1DAC404C78
            SHA-256:628C4665FA12603BDD1A11150B45354997F9116BC9B16AE6418525E989A30F24
            SHA-512:E3EE723F714C8F15AFC4309A4015197F18F51D51991368A11F3CA430496781872D5AFF64459F58517617C792C0A79B62FB689C623FE8026AEA8096284A207C2F
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.20",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "elefant_foot_compensation": "0.15",. "top_shell_thickness": "1.0",. "bridge_flow": "1",. "initial_layer_speed": "50",. "initial_layer_infill_speed": "105",. "outer_wall_speed": "200",. "inner_wall_speed": "300",. "sparse_infill_speed": "270",. "internal_solid_infill_speed": "250",. "gap_infill_speed": "250",. "top_shell_layers": "5".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):629
            Entropy (8bit):4.494479163015694
            Encrypted:false
            SSDEEP:12:8GTFyRuVpU0dlpyK6jpCSKWEdRw3JJJGcEcUjZlJ7Z4r7ZNZ3JIZeIZ2VQ/KdJE:8GTFPnJHpyfFCSKWEgJ7RELJ787L3IXh
            MD5:F197A61B5CA4580558E94125AE5EC3CE
            SHA1:3D5090BA5173D2E019FFBA4F7A577E6002F11759
            SHA-256:C3F60DE100E58FDCB4BDD84FFA8F91DFADF3C7755F6CD1018980300CC125407E
            SHA-512:6BCE9C43CFA64FB4576C7B26486B8D3A9F6BF505B27F3E652EAC5BC2D7A0440EFF9953216D7574E47B305262B26501B48D948238351B17D9841C016E327D96DA
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.24",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.24",. "elefant_foot_compensation": "0.15",. "top_surface_line_width": "0.45",. "top_shell_thickness": "1.0",. "bridge_flow": "1",. "initial_layer_speed": "50",. "initial_layer_infill_speed": "105",. "outer_wall_speed": "200",. "inner_wall_speed": "230",. "sparse_infill_speed": "230",. "internal_solid_infill_speed": "230",. "gap_infill_speed": "230",. "support_threshold_angle": "35",. "top_shell_layers": "4".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):756
            Entropy (8bit):4.545073938183981
            Encrypted:false
            SSDEEP:12:8GTFybuVpU0dlp+3jJJGlkOJqHWjEp6jZeZ7WI/wsiVw:8GTF/nJHpi7sqHW54dWSJ
            MD5:31DDE9253A349644BDBFD48F716EBABF
            SHA1:26279BEBF7EB2ABCF60805967463CE693EAA6B6A
            SHA-256:8104E53A2E94EB3A18B49F8B82AFC5F8AD7D35EFD07DB0C942D90082B0A8DD44
            SHA-512:AEDC9B6D05AEF1E1530E2E3FB85E4CC945C4DAB60647C36CFA58D72EDC4FB673D7B3A504CC47E2EC3269F4C2325BB7944D87B99D0FDD5B7B268323DE01F189A1
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.24_nozzle_0.6",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.24",. "initial_layer_print_height": "0.3",. "bridge_flow": "1",. "line_width": "0.62",. "outer_wall_line_width": "0.62",. "initial_layer_line_width": "0.62",. "sparse_infill_line_width": "0.62",. "inner_wall_line_width": "0.62",. "internal_solid_infill_line_width": "0.62",. "support_line_width": "0.62",. "top_surface_line_width": "0.62",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "15".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):827
            Entropy (8bit):4.5551795001729385
            Encrypted:false
            SSDEEP:12:8GTFycUuVpU0dlp+3oJJGRkgJ4FW3WqfimEp6jZeZ7WI/wsiViA+UA:8GTFndnJHph7e4FW3Wqj4dWSSA
            MD5:294CBB7BE0C85040C7CFECEBA935FCA4
            SHA1:03D69DEEB987DB6479ABA637F7300580F563B4D9
            SHA-256:C6BF28401E3B62AB5C52B6F95549AC8A172459DBF8F10501CA79DA2A2561FF6A
            SHA-512:47314C1AC2F0CB863E01D80285AA161C529BAF6B25FBB2A5782C3830874C5AFF5DD7882F4D6FE23A97D57324D8CD3F65283DA0AB338C14EFDF222864E6FA7F05
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.24_nozzle_0.8",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.24",. "initial_layer_print_height": "0.4",. "bridge_flow": "1",. "line_width": "0.82",. "outer_wall_line_width": "0.82",. "initial_layer_line_width": "0.82",. "sparse_infill_line_width": "0.82",. "inner_wall_line_width": "0.82",. "internal_solid_infill_line_width": "0.82",. "support_line_width": "0.82",. "top_surface_line_width": "0.82",. "top_surface_pattern": "monotonic",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "25",. "overhang_4_4_speed": "5".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):629
            Entropy (8bit):4.477804218272583
            Encrypted:false
            SSDEEP:12:8GTFy1uVpU0dlpGK6jpCSKWEdRw3JJJGcEcUjZlJ7Z4r7Z0Z4JIZpIZ5VQZ4dJE:8GTFjnJHpGfFCSKWEgJ7RELJ787eyIMO
            MD5:291ECADF07B3063706D6778CEC92CFF8
            SHA1:AEAE2A09474953A0609A3D79C1EF627675F8B8FB
            SHA-256:2A7240B3FEDFC3C885F84DAF88AA7A6CE197F48195DF4F87AC2C6E35E7AF1E0C
            SHA-512:05C1BB0151FD71D61D65596C60472293666A62DB898887AA9B9CD5442851BDDA349F20269DA0A03815C3FEA137C214C4BC876A98CF5761E5B42A955E19EFBE04
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.28",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.28",. "elefant_foot_compensation": "0.15",. "top_surface_line_width": "0.45",. "top_shell_thickness": "1.0",. "bridge_flow": "1",. "initial_layer_speed": "50",. "initial_layer_infill_speed": "105",. "outer_wall_speed": "200",. "inner_wall_speed": "200",. "sparse_infill_speed": "200",. "internal_solid_infill_speed": "200",. "gap_infill_speed": "200",. "support_threshold_angle": "40",. "top_shell_layers": "4".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):755
            Entropy (8bit):4.537813827194444
            Encrypted:false
            SSDEEP:12:8GTFysuVpU0dlpH3jJJGlkOJqHWjEp6jZeZ7WI/wsiVw:8GTF8nJHpT7sqHW54dWSJ
            MD5:35C16E186944A9929D37C747652A36C0
            SHA1:59D674206656961E2655DD00AFA194A6DD5A0C73
            SHA-256:B76910927C9C254D331C970BC607CE4FB4D7A32A0199425774C8C39D19836FC7
            SHA-512:A6994A4F6ACA344F8BC93C3E05E0B1356AED12609CF16369EE575FD2209AE0013B613DF6B01686AAEAB4C0EED52497CA9A3534FF20A4917972FD8361031621B9
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.30_nozzle_0.6",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.3",. "initial_layer_print_height": "0.3",. "bridge_flow": "1",. "line_width": "0.62",. "outer_wall_line_width": "0.62",. "initial_layer_line_width": "0.62",. "sparse_infill_line_width": "0.62",. "inner_wall_line_width": "0.62",. "internal_solid_infill_line_width": "0.62",. "support_line_width": "0.62",. "top_surface_line_width": "0.62",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "15".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):827
            Entropy (8bit):4.555971546160911
            Encrypted:false
            SSDEEP:12:8GTFyXUuVpU0dlpp3oJJGRkgJ4FW3WqfimEp6jZeZ7WI/wsiViA+UA:8GTFQdnJHpi7e4FW3Wqj4dWSSA
            MD5:8584E3A5F6D56206C2FFBCAD7520DC91
            SHA1:A32054FFF55B4EE9429F3ACEB1693823E90CEE78
            SHA-256:A0111753DDE48B01FCEFE8A86A39E9225566E5F00F8C694B856127C580A3C8D0
            SHA-512:49D9DA90759C59B9EA03411011A8B37E0F0E7EECDA319BE6F89139EDBC113A0A208F36F659F1700DC348F52488FD70BF561A28B9EA61C17BFFAF902FFE84F362
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.32_nozzle_0.8",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.32",. "initial_layer_print_height": "0.4",. "bridge_flow": "1",. "line_width": "0.82",. "outer_wall_line_width": "0.82",. "initial_layer_line_width": "0.82",. "sparse_infill_line_width": "0.82",. "inner_wall_line_width": "0.82",. "internal_solid_infill_line_width": "0.82",. "support_line_width": "0.82",. "top_surface_line_width": "0.82",. "top_surface_pattern": "monotonic",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "25",. "overhang_4_4_speed": "5".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):756
            Entropy (8bit):4.541026280319802
            Encrypted:false
            SSDEEP:12:8GTFybquVpU0dlpl3jJJGlkOJqHWjEp6jZeZ7WI/wsiVw:8GTFmPnJHp97sqHW54dWSJ
            MD5:CAAE2BC44B41B1D8162730247DBABA4B
            SHA1:8A5AB1E812AD9F82C6BFD03086699D2CB753451A
            SHA-256:380201A155CEECA01F15A22644D92C8E519E7FE3BBF9278FF3BC8BEDF0A21DFE
            SHA-512:61A9414825629AA896C316751F4E49F8F7F640440952D81B02486B0D81ACAE93EEEB63F32B6CC1BFE388D56B770EA17E7D45B59E564D36F47F8F94F5EFE1F1E6
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.36_nozzle_0.6",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.36",. "initial_layer_print_height": "0.3",. "bridge_flow": "1",. "line_width": "0.62",. "outer_wall_line_width": "0.62",. "initial_layer_line_width": "0.62",. "sparse_infill_line_width": "0.62",. "inner_wall_line_width": "0.62",. "internal_solid_infill_line_width": "0.62",. "support_line_width": "0.62",. "top_surface_line_width": "0.62",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "15".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):826
            Entropy (8bit):4.552103432411153
            Encrypted:false
            SSDEEP:12:8GTFywxUuVpU0dlp23oJJGRkgJ4FW3WqfimEp6jZeZ7WI/wsiViA+UA:8GTFhdnJHpZ7e4FW3Wqj4dWSSA
            MD5:7445E5D6E994D58FA86A2DB89C3FE3E2
            SHA1:7814E56F236FDDE831F5A079B0669948EC01BF45
            SHA-256:6CBAC34C9CF2BEF204F463CCFBD683B9DF5B3EDC3C4E229050AC3CC9CE26D8A8
            SHA-512:95BC12C5C3BD3D12E9A64A784D870684445FA65103EF4F9B33C1C41D0E163992A357D43C123887AEA672DAF19C7F1C72FF54E44364B55FE7E3BDBF6EA1E94E70
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.40_nozzle_0.8",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.4",. "initial_layer_print_height": "0.4",. "bridge_flow": "1",. "line_width": "0.82",. "outer_wall_line_width": "0.82",. "initial_layer_line_width": "0.82",. "sparse_infill_line_width": "0.82",. "inner_wall_line_width": "0.82",. "internal_solid_infill_line_width": "0.82",. "support_line_width": "0.82",. "top_surface_line_width": "0.82",. "top_surface_pattern": "monotonic",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "25",. "overhang_4_4_speed": "5".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):756
            Entropy (8bit):4.545073938183981
            Encrypted:false
            SSDEEP:12:8GTFywauVpU0dlpe3jJJGlkOJqHWjEp6jZeZ7WI/wsiVw:8GTFPnJHpC7sqHW54dWSJ
            MD5:1D0BE9556ED15EEB2ADA2D4E46F3B9A9
            SHA1:F42A014CA555D27CB23AB086423AE7A6DBA264F1
            SHA-256:21A0FB739E1B7DB0294EC13B730B8E002EEEA32E7AB18AE26E0508CC9225D57D
            SHA-512:AC97A663887D6DF0FF644967CE116930ED4C38E3C6D2B7427E332CDA0AAA2411692215815E5803A373D0F01F6655152AB09D83E1DC9594DD8ED01D83485CECBC
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.42_nozzle_0.6",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.42",. "initial_layer_print_height": "0.3",. "bridge_flow": "1",. "line_width": "0.62",. "outer_wall_line_width": "0.62",. "initial_layer_line_width": "0.62",. "sparse_infill_line_width": "0.62",. "inner_wall_line_width": "0.62",. "internal_solid_infill_line_width": "0.62",. "support_line_width": "0.62",. "top_surface_line_width": "0.62",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "15".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):827
            Entropy (8bit):4.5551795001729385
            Encrypted:false
            SSDEEP:12:8GTFywpUuVpU0dlp83oJJGRkgJ4FW3WqfimEp6jZeZ7WI/wsiViA+UA:8GTFZdnJHpv7e4FW3Wqj4dWSSA
            MD5:3E61CE7ECD2C5B8054FE4CBC68510289
            SHA1:A0A202488DA63803A446387DF9C2807EA871EC3C
            SHA-256:3202B5F17D1157E7EA82FAEE08F77A9047B24148A7462F9456DB7AFF8C093140
            SHA-512:30501FC850510343A11519A68453D57092DDD41FE1203A7C1E2C865512735A7464CE5C97E24358032B1C4AB8C64DC924D257DF18419F77D40006EF6CAE186463
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.48_nozzle_0.8",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.48",. "initial_layer_print_height": "0.4",. "bridge_flow": "1",. "line_width": "0.82",. "outer_wall_line_width": "0.82",. "initial_layer_line_width": "0.82",. "sparse_infill_line_width": "0.82",. "inner_wall_line_width": "0.82",. "internal_solid_infill_line_width": "0.82",. "support_line_width": "0.82",. "top_surface_line_width": "0.82",. "top_surface_pattern": "monotonic",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "25",. "overhang_4_4_speed": "5".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):827
            Entropy (8bit):4.5630924056151185
            Encrypted:false
            SSDEEP:12:8GTFyV/UuVpU0dlpS23oJJGRkgJ4FW3WqfimEp6jZeZ7WI/wsiViA+UA:8GTFa/dnJHp87e4FW3Wqj4dWSSA
            MD5:3DD611783C52AE6AC5310FCD11D75EAB
            SHA1:D5B7F4F150316EEFFDDAC1E77035341808CF73EF
            SHA-256:8AA3FC265A4D19E834DE8E9135071BEE834965203F3F89A9919BC0BF475C51A7
            SHA-512:4C156BEF76DC7B5E625C9FED8DEDB051EF991675732E54E5E6877EDCA1807E8E7C34A01E9E01B310B8C4C947E55DA4BD09EA379236030B671F1F450E08103016
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_0.56_nozzle_0.8",. "inherits": "fdm_process_bbl_common",. "from": "system",. "instantiation": "false",. "layer_height": "0.56",. "initial_layer_print_height": "0.4",. "bridge_flow": "1",. "line_width": "0.82",. "outer_wall_line_width": "0.82",. "initial_layer_line_width": "0.82",. "sparse_infill_line_width": "0.82",. "inner_wall_line_width": "0.82",. "internal_solid_infill_line_width": "0.82",. "support_line_width": "0.82",. "top_surface_line_width": "0.82",. "top_surface_pattern": "monotonic",. "initial_layer_speed": "35",. "initial_layer_infill_speed": "55",. "sparse_infill_speed": "100",. "top_surface_speed": "150",. "bridge_speed": "30",. "overhang_3_4_speed": "25",. "overhang_4_4_speed": "5".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2512
            Entropy (8bit):4.571016482205942
            Encrypted:false
            SSDEEP:48:jJGeHpQkpWnmgOqfF85O6Z+b4OjoZCKQODMTN1YUtf9p33lx1yBMsN5MsT3OAKdS:jJdRpWmDD53YrODfUp9p33lsMsN5MsTl
            MD5:91F9297530E7207A486DBA2F5518BDE4
            SHA1:F4B9FCE11090D5914F77B0C3AE37B6E655E1B6CB
            SHA-256:54EAF2A6945B5DA07F7D191AF50CC0FE2B7003F2FD7C3F394919F84AA887FDE9
            SHA-512:DA9A02002B207FCD6A94957A3F93D00ACDDEA6AC8FA38B33FCDF2C249337BB2F760CB2E261AD9162EE2048A99C71AD5A5C492108E88DAEB927D89C4AE75D8313
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_bbl_common",. "inherits": "fdm_process_common",. "from": "system",. "instantiation": "false",. "max_travel_detour_distance": "0",. "bottom_surface_pattern": "monotonic",. "bottom_shell_layers": "3",. "bottom_shell_thickness": "0",. "bridge_speed": "50",. "brim_object_gap": "0.1",. "compatible_printers_condition": "",. "draft_shield": "disabled",. "elefant_foot_compensation": "0",. "enable_arc_fitting": "1",. "outer_wall_acceleration": "5000",. "wall_infill_order": "inner wall/outer wall/infill",. "line_width": "0.42",. "internal_bridge_support_thickness": "0.8",. "initial_layer_acceleration": "500",. "initial_layer_line_width": "0.5",. "initial_layer_speed": "30",. "gap_infill_speed": "50",. "sparse_infill_speed": "250",. "ironing_flow": "10%",. "ironing_spacing": "0.15",. "ironing_speed": "30",. "ironing_type": "no ironing",. "layer_height": "0.2",. "re
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2324
            Entropy (8bit):4.5049589201586135
            Encrypted:false
            SSDEEP:48:jJhHprQUsONefFWi9ND6TS1W12LnrOHjnMRliSkjUhyur6Lx4N4g2:jJ5dQUsLHrrOHjnMRsSQUhyu+d4Y
            MD5:79BB16869485F2F7A1AEF68D9DFA5E41
            SHA1:1C8B2BA5D9178B79B2F5DFF8EEA6A2FCAE27A63A
            SHA-256:4DB6F68DB3EEAA065C45DE686AA14A97C307352B1E2901FAB282278F161D5894
            SHA-512:1CD5A6B3817233DA664A133682919D7B9E24ED8AC71471A134D983C0D8D96324DE42DAC5250D16B99CB80B8F04E9CF0C43980E67606AA00C359F3054ADD2585B
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_common",. "from": "system",. "instantiation": "false",. "adaptive_layer_height": "0",. "reduce_crossing_wall": "0",. "bridge_flow": "0.95",. "bridge_speed": "25",. "brim_width": "5",. "print_sequence": "by layer",. "default_acceleration": "10000",. "bridge_no_support": "0",. "elefant_foot_compensation": "0.1",. "outer_wall_line_width": "0.42",. "outer_wall_speed": "120",. "line_width": "0.45",. "infill_direction": "45",. "sparse_infill_density": "15%",. "sparse_infill_pattern": "grid",. "initial_layer_line_width": "0.42",. "initial_layer_print_height": "0.2",. "initial_layer_speed": "20",. "gap_infill_speed": "30",. "infill_combination": "0",. "sparse_infill_line_width": "0.45",. "infill_wall_overlap": "15%",. "sparse_infill_speed": "50",. "interface_shells": "0",. "detect_overhang_wall": "0",. "reduce_infill_retraction": "0",. "filename_format": "{in
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):14796
            Entropy (8bit):4.422001440465886
            Encrypted:false
            SSDEEP:192:GEstSwhSrO9sX9x36TL38P1kahW9VEuPd5Liv6WB3uNaVy5WOkKXS9Slkp+ZoMP5:GfsQl
            MD5:4566511698B02B9918A5FF8460BF48C9
            SHA1:ECDD8BA7685A6CB0B724B808F2B647C57E7B8916
            SHA-256:23D606A754B82FF86D1B16616422E06565D52CFAAAD3CF51F5A61170AD7C609C
            SHA-512:193131E2B30DE54A56D30D014C12C2E3670211340BA5AA57A87057AEF3B150B5F8C23628766697B507ECCCDDEA6B9E94F0F65F6CD65375A5EAA4821D11B53FA7
            Malicious:false
            Reputation:low
            Preview:{. "name": "Creality",. "version": "01.08.00.03",. "force_update": "0",. "description": "Creality configurations",. "machine_model_list": [. {. "name": "Creality CR-10 V2",. "sub_path": "machine/Creality CR-10 V2.json". },. {. "name": "Creality CR-10 Max",. "sub_path": "machine/Creality CR-10 Max.json". },. {. "name": "Creality Ender-3 V2",. "sub_path": "machine/Creality Ender-3 V2.json". },. {. "name": "Creality Ender-3 S1",. "sub_path": "machine/Creality Ender-3 S1.json". },. {. "name": "Creality Ender-3 S1 Pro",. "sub_path": "machine/Creality Ender-3 S1 Pro.json". },. {. "name": "Creality Ender-5",. "sub_path": "machine/Creality Ender-5.json". },. {. "name": "Creality Ender-5 Plus",. "sub_path": "machine/Creality Ender-5 Plus.j
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):28743
            Entropy (8bit):7.964598462587341
            Encrypted:false
            SSDEEP:384:3w/Aee00flRZ1+fWAxc/i2x7dIpREgqZRzQHEo2nOy+A+cf0fk+8SRIM6qfg8tEC:3ySfrGadUpOgqwEjnOVwuk+rLgSEbG
            MD5:2F9740F64C3B160960D0D923A7EEC71A
            SHA1:80F08D68007640986498D3FEFCA8DA91685CCECB
            SHA-256:D78B2C06959341CCAE63DA70D800CC537577BF7989809C960D34787A66383BA8
            SHA-512:45E773BB9C394557B1DF0B1FF21F85B8736D912F671FAADA9DB3549091E9114BC089C3723E8A9D5D6E9C47B9D2BEB3535E2EBA774E2C3C78C596B9C5501EC9C8
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-05T20:59:57+0200". xmp:ModifyDate="2023-05-05T21:02:03+02:00". xmp:MetadataDate="2023-05-05T21:02:03+02:00". photoshop:DateCreated="2023-05-05T20:59:57+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):25298
            Entropy (8bit):7.949145079344626
            Encrypted:false
            SSDEEP:768:3tnL47dwnZFGcE19SZ1oE7hDPt5CiC9g1dMB/3kv8:9nL4hwnZ1s36NC9gfMB0k
            MD5:AE1867BFC687BF477645C75DC21FA401
            SHA1:7CFFF03EDDA1110CC545C73D379DE098AE7BF6C4
            SHA-256:DA54F970D41878D1DA8261C0BBABDAD566896D1A21266EA9681A9E79447CBC44
            SHA-512:7A308726C3CFFBBE2E5923F19802A9EB1FAAEA426135C078F89FE69485966A0BBBE5E6C71215C49E525A86E551931986573C4497D6705DFFBFE9316B9BFA836A
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-05T21:30:27+0200". xmp:ModifyDate="2023-05-05T21:31:39+02:00". xmp:MetadataDate="2023-05-05T21:31:39+02:00". photoshop:DateCreated="2023-05-05T21:30:27+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 171, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):35718
            Entropy (8bit):7.957314097055014
            Encrypted:false
            SSDEEP:384:/nwNSCFCi1MlaIbW6aMZp1Pr1KC3M6VEMHovtn3KrR4FKVwlWcqNiyKVfygmSaXa:/cj1v6fZp1ECxIV3KruFK/NAywPpSo2K
            MD5:AF2FDB429084D88ACFAB5672BB98AB01
            SHA1:840BD1682AE65AB0AC95FF7D1F19A445345B1342
            SHA-256:282385A380B29ED352F4AC2345E7A0DD0A86A078D1BFC58C2AA1502B563C1D92
            SHA-512:11EE58521322D3402C59B0172A695A82E2136972E92FFB3620A4BAC7076B76B5F0D1FC0D8D3CCF74BD6BDA36EEDBE4D351AF864C933E89A3ABAF321A5F760FB8
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR..............M.|....pHYs...t...t..f.x....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.0-c001 79.c0204b2, 2023/02/09-06:26:14 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmp:CreatorTool="Adobe Photoshop 24.4 (Windows)" xmp:CreateDate="2023-07-20T13:21:21-05:00" xmp:ModifyDate="2023-07-20T14:27:04-05:00" xmp:MetadataDate="2023-07-20T14:27:04-05:00" dc:format="image/png" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:7dd8e368-32d0-b945-a050-57df01077a50" xmpMM:DocumentID="xmp.did:7dd8e368-32d0-b945-a050-57df01077a50" xmpMM:OriginalDocumentID="xmp.did:7dd8e368-32d0-b945-a
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 236, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):50137
            Entropy (8bit):7.967293812956008
            Encrypted:false
            SSDEEP:1536:tDTqkBQfjbsCUyG0aFvviKm09UXIbR8cHJ8flgPrTwRZ2AaQhgYT9o:RTHBQf0VyGdUHXyR8cpOlgTTwu039o
            MD5:24E37ECA8BBCF91837A73A5253E8F9E5
            SHA1:A78368F5CD58ADDA648C040BA8176A7CE350611A
            SHA-256:23E20EE5A9836267695514DA5FD85503C3D57B7CEF9C6D15B4A211628441C406
            SHA-512:DE997EE84DBDC70D977E23E251D2F6B3569AC3AD6C480FA5E420079F4176E2916E6FB612D5FE7421E555EA8B49047054890A8D0CA1AC31E48118DA728E000E48
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.....................pHYs.................iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.0-c001 79.c0204b2, 2023/02/09-06:26:14 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:GIMP="http://www.gimp.org/xmp/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:Iptc4xmpExt="http://iptc.org/std/Iptc4xmpExt/2008-02-29/" xmlns:plus="http://ns.useplus.org/ldf/xmp/1.0/" xmlns:tiff="http://ns.adobe.com/tiff/1.0/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmpMM:DocumentID="gimp:docid:gimp:639a8412-2d59-4386-b94c-555ef0c693d5" xmpMM:InstanceID="xmp.iid:05884bc1-358d-e241-b779-8de29e8e2cad" xmpMM:OriginalDocumentID="xmp.did:2416efd4-6d5a-46c5-9fb0-8684e5e0662f" GIMP:AP
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):21612
            Entropy (8bit):7.9458437099570265
            Encrypted:false
            SSDEEP:384:3kp/ee0OyxtveT6Fp6no+oRMezNdaeAnOt3sTXPG91MmYsYbf3jAQ6f0eTWqi2m:3ImKolRMe5se+Ot3W/O1SsO3QfrWv
            MD5:8B88C67751D6B130F386EE5665EAC337
            SHA1:E52F2FC422BC7D83F847064C52F2DB9526EE205B
            SHA-256:95CC19D49E96A29A384E9BBF20A741B761607F5FF2EF37D59167BFC7A48D1954
            SHA-512:D318822B7296E7C8A4BA60BCAFF1F1D84DADF4CD9D227CCA7A9273CE622113274B9757C2E7C1DE1256695FC39D845964E21E6452A30205B476AD2F3FB27DEE0E
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-07T15:23:50+0200". xmp:ModifyDate="2023-05-07T15:25:41+02:00". xmp:MetadataDate="2023-05-07T15:25:41+02:00". photoshop:DateCreated="2023-05-07T15:23:50+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):21687
            Entropy (8bit):7.9368810808879156
            Encrypted:false
            SSDEEP:384:3orTGee0NejEcwzNhp3woCZ70x3Thv7etBP79R8iSTwObgOb593AcpjcwXo6goVi:32peDwzNhpdg70xjqBj9R8iSvMO9HpoX
            MD5:76D2BB688BB0CB9FED159D3429EDFDD2
            SHA1:0BA4DB9FB9C7FA807E9F5EE57581589E3D8DA755
            SHA-256:C21AF0037F08BEFE6620F618BE64747F4B2733930CA8A23E13984F6991211BF8
            SHA-512:C666A8EED891445324CC6A440A9838C58EE0ACEF4348195DA1FE5DF4A567848A2645F35E9E23614BA79DC9518D6A9FD5CA45205740ADE2A340E9FB930E9C1F71
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-05T20:59:57+0200". xmp:ModifyDate="2023-05-05T21:09:33+02:00". xmp:MetadataDate="2023-05-05T21:09:33+02:00". photoshop:DateCreated="2023-05-05T20:59:57+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):28362
            Entropy (8bit):7.96793957895072
            Encrypted:false
            SSDEEP:768:3+UdFNszRWjFSvWc8yZM2x64fJgzldem55+3aYXDmDr:OXzYb+7LfJgBdew5+rXDmDr
            MD5:51878EEA50D856D366889413BE5351C6
            SHA1:816F04A8AF689FC57C34468EEAC607AD62461D71
            SHA-256:6ACA57E14A7F448984D1D90B5F7086A4B2E7A249ED84C11477DA8F49EDC2326B
            SHA-512:BE09AA6007AD66C37EB1113DCEDF6A85D6C17730D6FDDCA6AB27BBF208F5AB25E0056B01FF2C5354D8EEE6F27C9094547FE94DFCDE07A4A7A36B7C7EAACFA19D
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-05T20:59:57+0200". xmp:ModifyDate="2023-05-05T21:03:31+02:00". xmp:MetadataDate="2023-05-05T21:03:31+02:00". photoshop:DateCreated="2023-05-05T20:59:57+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):34307
            Entropy (8bit):7.969900770425781
            Encrypted:false
            SSDEEP:768:3FWAtY6tH3WQiivYkpd4j6kU0PxCVwhD44DduN7nb:VptPtH3WbK19kRaEDaNbb
            MD5:754D4AFF66CBE881695EA6C97495EBD2
            SHA1:AD08D7225A81188B279DDDE625E5D6AFEBB49EAF
            SHA-256:9246BBA30F7CE02D063CCECC61B5593B6F0F4F64CEB6851E72BBB34818AEA780
            SHA-512:C02F96A89D363919716000C43DBFBF2C259CAFC44DBCB833601E4159A0B6E438FE2BBE13AB0B380530E4F570A13990A5F25E110C16FC71EA457972FDC82555C4
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-05T20:59:57+0200". xmp:ModifyDate="2023-05-05T21:06:42+02:00". xmp:MetadataDate="2023-05-05T21:06:42+02:00". photoshop:DateCreated="2023-05-05T20:59:57+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):30703
            Entropy (8bit):7.9687215091806545
            Encrypted:false
            SSDEEP:768:3vtPuQvCuAcKd4f8A1x9SDVJnCXNOQQXIaru9tPBJMzAW/:/tPuR5TdaDmPC0QQXIMQJ/O
            MD5:7A6ED700D7B5C7A4402CFB31D64A971F
            SHA1:C5C06E11A6C7A06AF20A9255D3BCE998EE91085C
            SHA-256:4F0879644EC41CA2F75BE09A6E8F230C2AFF5EECA54377E350EF94B45F97656E
            SHA-512:C3A9B30B83092E6B67D302498DA3862D034EA2B2A70FCA1A839C8EDF3E533143FD4ADAE288417A93B05CD3CE3E9E74A751F21EF6A2A6CAE53D7D24B6103F81FE
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T01:29:14+0200". xmp:ModifyDate="2023-05-06T01:33:10+02:00". xmp:MetadataDate="2023-05-06T01:33:10+02:00". photoshop:DateCreated="2023-05-06T01:29:14+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):31331
            Entropy (8bit):7.965395437519607
            Encrypted:false
            SSDEEP:768:3+v9Hmm81m+RXHGPzT+vmkXy+JKcOdtuKddkz8y:Ov9B81RVcYtKnMV
            MD5:0D722023DD1DB19EC2F7716E15BD701F
            SHA1:80A88F4FE174C94925B3D35602F1AE7A17599907
            SHA-256:6180DDAB1133E52444A7B1C7AE12EB67A9B4D8C4953528CE1DE574DF9329AD29
            SHA-512:9CE777B8B0387D15870DAAAC8CF13A0B5DF0ED5E1B0F502820ADFE326785AEC0F5CBEC497E074ED2C1FCF0C0A45B02535C114758685F6868A85724CB308C21C5
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T01:29:14+0200". xmp:ModifyDate="2023-05-06T01:30:52+02:00". xmp:MetadataDate="2023-05-06T01:30:52+02:00". photoshop:DateCreated="2023-05-06T01:29:14+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):30756
            Entropy (8bit):7.97192252371449
            Encrypted:false
            SSDEEP:384:3wrqee0xjX3VJ69zxPaERo9r5A3PCWoYnmMXfQkv3hULfWZTcWSycwWtqQhqMkah:36N3KzE5e1oCRifWBcDvq1L+QTGj
            MD5:E9760636CF5E9E714B8515741CF8A3E6
            SHA1:54016A1C0432300376F0CCE2EB3DDAB7D21C7564
            SHA-256:0C742D01BB9EE938237ACF881814FDFC4DE28363F5C9028A60C6B42C3A0D6FDD
            SHA-512:D23325E67611C2DDFBA2B57405C768CBD164DB8E6234FFE6D2C9515EFDD2D96E99420E92EEB3C2D17448B8E957EAB5F61F623D6B5E3E2AED5B740231D5306216
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T01:29:14+0200". xmp:ModifyDate="2023-05-06T01:30:01+02:00". xmp:MetadataDate="2023-05-06T01:30:01+02:00". photoshop:DateCreated="2023-05-06T01:29:14+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):34768
            Entropy (8bit):7.979132246307319
            Encrypted:false
            SSDEEP:768:3CLKazpLquI0P8lektm5zn9CGBy9pYlsYuQ0KtSeE+wx92W0:SLK27/we4mZcGBy9fStSf+w/t0
            MD5:2FD05A8F631CA5512227CA308C3AEC1E
            SHA1:CD48D79D77A28497E551527F3FF88672DC77B377
            SHA-256:64B2091F5152678B3EC4361EE8C4D201B2E22E50E665A8E00BD93C11446FBA00
            SHA-512:D7F427BA54225547CF30FFF6F2FF38629F94A571BB6923F84688C5944F31D2CD79219994B4D66CCDBA3E181BEA3ED57464BE1CDAE81C44FC0504C115D66D11C2
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-05T20:59:57+0200". xmp:ModifyDate="2023-05-05T21:08:12+02:00". xmp:MetadataDate="2023-05-05T21:08:12+02:00". photoshop:DateCreated="2023-05-05T20:59:57+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):30760
            Entropy (8bit):7.9753090086861285
            Encrypted:false
            SSDEEP:768:WVsA8wFAod7Ws4+2CZLZLOKxAt291HGl1U9zsSEcVkRbdA:0sXbHe3Tkk1q1UZsSEcVkTA
            MD5:26CD6D7E68B0623738CEDC4C47E7BA54
            SHA1:A7AFA14BBBB608D3D11F5352CB6968221B9A7231
            SHA-256:5552301C9C4ABF79DDA411C9036F53CEE03B8AE49317788F1A1CB2F95E3C2069
            SHA-512:6B46C8617CE0ED882FBA1B9C698E5B9978AEA495B7824F5B56D046EF1ED1F45E142E564E9B8FFB2B53AF31AA08692DE87E7D3FDBDB5163828682176677E7674D
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-06-12T22:22:25+0200". xmp:ModifyDate="2023-06-12T22:24:56+02:00". xmp:MetadataDate="2023-06-12T22:24:56+02:00". photoshop:DateCreated="2023-06-12T22:22:25+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SD 170M-A". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180". tiff:Resolutio
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):25009
            Entropy (8bit):7.967518032813092
            Encrypted:false
            SSDEEP:384:WQXAUQWMRuVZ70bAydLH7ZzlKRXELrMtXrEWOrm9DIHxaHZxEwvsx38QmVXgUars:WQOzRuj70bASMhEiOAIHGcx1mVQLI
            MD5:4794D8A4962851C2D8C0E0035169B307
            SHA1:10DBC005AEE07168D7FC87EAE8F1B1DBA0D28F16
            SHA-256:5D03D4A3090446FFCB485D21D26E481BE93C6CDADDA3BA30877CDE1210799B91
            SHA-512:7097B7C1911F57CCD974A210752885931958F0FEB2DAE98E7B3AF521B974467FA3BC126FC40C80954B82692EE9AD8DFE66F482AA270BD913E5F952218DE64624
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-06-12T22:22:25+0200". xmp:ModifyDate="2023-06-12T22:24:11+02:00". xmp:MetadataDate="2023-06-12T22:24:11+02:00". photoshop:DateCreated="2023-06-12T22:22:25+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SD 170M-A". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180". tiff:Resolutio
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.314551717417327
            Encrypted:false
            SSDEEP:384:5Z/8cR8DxNn9ejPmEgd5cgzccYYcn8kRjx2vIdTGRkERYYAvYpEhc0o:5Z/8cgnQjuEgd5cgz7YaIdTGCERzAw
            MD5:89E5DA2196ADE946A0534C2D92722A47
            SHA1:97C019F1BFBF0BBA740B08BFA03F5D06270BACAA
            SHA-256:A1EA33EACDC3C10E959E5B26722D5AC214B674B40C8A417C8904410A64D3C864
            SHA-512:B7262BF9B989BBEE1CDECB8AB14CFD3B46AF6EC7FB668BC52C74FAE5C271FDCB2C20346CE6FA447329BD86DE3D1949773D765CE425369602C57DCB2C4EAABA44
            Malicious:false
            Reputation:low
            Preview:Uranium STLWriter Sun 23 Jul 2023 11:42:11......................................t................*YB>........*YB>......3d.SBl.....................d.SBl........*YB>......3d.SBl......3..............d.SBl.......d.SBl......3.NB.......................NB........d.SBl......3.NB.......3...............NB.........NB.......3MkJB......................MkJB.........NB.......3MkJB.......3..............MkJB.......3..,B&d.....3MkJB......................MkJB..........,B&d.....3..,B&d...................../.B.s.....3./.B.s........#B.......3................#B.......3./.B.s........#B........................#B.......3..#B........;.(Bb......3..............;.(Bb......3..#B........;.(Bb.....................;.(Bb......3;.(Bb.........,B&d.....3................,B&d.....3;.(Bb.........,B&d...................../.B.s.....3./...s.....3./.B.s...................../.B.s......./...s.....3./...s...............................3.)/........3MkJ........3..............MkJ........3.)/........3...........3..............MkJ.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.5379112731343865
            Encrypted:false
            SSDEEP:384:G9pqUsoSRsZHPMybclQZ3fszLEUhG7luMY8KaA:G9pqUsoSRKxcl+cEUB
            MD5:B493D5F0A5302735857CE0307761D932
            SHA1:8B5107650FC2B447456DE7FB4A97A503EA809BA5
            SHA-256:8CEBD75419F5C54BB50D7BD7554DCD6D38EB835657D525297C5ECFCE59FF171E
            SHA-512:1E40FD104F0FD366352535DD7AA194F6A97A7283505F0D5AF30C65AA01E33D34F509100BC21BEE2ACDAAE6F8D65650316597C25A2DE5E0D987556DAA3C41B2C2
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB..b......HRB..b.......MB..b.....sN...>U.}.......MB..b......HRB..b.......MB..b.....sN...>^.l.......MB..b.......MB..b......HHB}+c.....sN...>^.l......HHB}+c.......MB..b......HHB}+c.....sN...?4.K......HHB}+c......HHB}+c.....c$DB..c.....sN...?4.K.....c$DB..c......HHB}+c.....c$DB..c.....sN..5?..5.....c$DB..c.......'B..k.....c$DB..c.....sN..5?..5.....c$DB..c.......'B..k.......'B..k.....sN...>U.}.....:..B..l.....:..B..l.....a..BcTl.....sN...>U.}.....a..BcTl.....:..B..l.....a..BcTl.....sN...>^.l.....a..BcTl.....a..BcTl.....:.#B..k.....sN...>^.l.....:.#B..k.....a..BcTl.....:.#B..k.....sN...?4.K.....:.#B..k.....:.#B..k.......'B..k.....sN...?4.K.......'B..k.....:.#B..k.......'B..k.....sN...'........:..B..l.....:.....l.....:..B..l.....sN...'........:..B..l.....:.....l.....:.....l.....sN...........?7.%..h.......&...g.....c$@...c.....sN...........?c$@...c.......&...g.....7.%.|.f.....sN...........?c$@.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1304 x 1333, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):12109
            Entropy (8bit):4.372022895092242
            Encrypted:false
            SSDEEP:96:uWPk0o2+7EM1tuLX6Fl0njb8iRrtES+ri7cersvZhZrNmDUQVSD8r3QgAPsxAgKe:Zk05+SWiAeovZhZrJQV+87YzF7PMt
            MD5:CCEDC832F925531682F573A0C1623924
            SHA1:2E18BD728248159A18429F5875F48A14263BB08F
            SHA-256:1522835C5E9A8FD7E5024AD3AAA774B7B7EB9AEA9FB449621687F8F1C75F589C
            SHA-512:295410C8E375A66D602A097AFE7E3541804E94F2E9B4A6F4BD8DEA641D26A20D2370303BE894189008A64923F5D4EB60B5370ED592AB838B02917F40590BA41A
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.......5.....x*......iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:40:32+0200". xmp:ModifyDate="2023-05-06T18:01:41+02:00". xmp:MetadataDate="2023-05-06T18:01:41+02:00". photoshop:DateCreated="2023-05-06T17:40:32+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="1304". exif:PixelYDimension="1333". exif:ColorSpace="1". tiff:ImageW
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.5129438945701414
            Encrypted:false
            SSDEEP:384:XEgAbBJaDiXko1GMXeW6f+dittFr3YU5yriXPvjgP4B69gLC2Uwkz9EaH8qIhIpi:XEgAbaf+cWUvjgP4B69gm2UwkxpmZ
            MD5:0F5B390E2510B6CF3265A3B326773F98
            SHA1:95E7A0C5FDAB6CF37BE21D0E2F2780369AE82393
            SHA-256:7EF975DFBE4913A98A448ECA12B1700B643B51926BC6D967F559E7E0424FE20F
            SHA-512:328864F20E078E8FF8F8DBE799F57A4FF133DC563BBAEF29904A7CC32D97D52819F0CA28D0765C2780C75CD111B671B4F145904B200E3CE92D2BC5279D23B366
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB........sN...>U.}.......MB.........HRB..........MB........sN...>^.l.......MB..........MB.........HHB}+......sN...>^.l......HHB}+........MB.........HHB}+......sN...?4.K......HHB}+.......HHB}+......c$DB........sN...?4.K.....c$DB.........HHB}+......c$DB........sN..5?..5.....c$DB..........'B.. .....c$DB........sN..5?..5.....c$DB..........'B.. .......'B.. .....sN...>U.}.....:..B..!.....:..B..!.....a..BcT!.....sN...>U.}.....a..BcT!.....:..B..!.....a..BcT!.....sN...>^.l.....a..BcT!.....a..BcT!.....:.#B.. .....sN...>^.l.....:.#B.. .....a..BcT!.....:.#B.. .....sN...?4.K.....:.#B.. .....:.#B.. .......'B.. .....sN...?4.K.......'B.. .....:.#B.. .......'B.. .....sN.{.'........:..B..!.....:.....!.....:..B..!.....sN.{.'........:..B..!.....:.....!.....:.....!.....sN...........?.E.B|........E..|..........B........sN...........?...B.........E..|...................sN...........?...B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 879 x 908, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):8390
            Entropy (8bit):5.771452250683318
            Encrypted:false
            SSDEEP:96:wWPk0o22kJU1fCuGYXxFl0n8b7giRrtESwA2fD120r03Lk9sMKhdEdMA4yjL0zai:fk0k+Sv2Rt4bk65dEdZdjGDEK1
            MD5:EAB576BD4B176B3A4963F3E7745E7A99
            SHA1:42716B1FBEA5D8D3A7419CFF4EB1993A20B312F3
            SHA-256:4507DF52DFAC25F59B7B517691D6BD62DFC5B13331591D88F43AAEA775A1FD65
            SHA-512:7FA338498C36639B8F824345A4191F7B718EE2EF8C6EAE9EE8A0D905C427721E93F3ECC8892CF6FD5D046785527F19502FCADBB12B0182CCD4A6D69E23D8A467
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR...o.................iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:43:55+0200". xmp:ModifyDate="2023-05-06T18:03:02+02:00". xmp:MetadataDate="2023-05-06T18:03:02+02:00". photoshop:DateCreated="2023-05-06T17:43:55+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="879". exif:PixelYDimension="908". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 652 x 681, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6914
            Entropy (8bit):6.555126581410005
            Encrypted:false
            SSDEEP:96:MWPk0o2aa3w1hZuWXjFl0nfbWiRrtESwnizHEDN9lIckSG49nyX0specWVyWFtQ/:rk0gk0Swniz2NxkSG49n10Wy/
            MD5:6FD3470CF95AFB5143AAD2E206E119B8
            SHA1:394E645EAA5A2AB9FD49D7FCD63505A3AC1ABDE2
            SHA-256:03897A59B456EB6C3B833A78D0DF5DA9A0EF14210247FBB49CBDF84F44D6B053
            SHA-512:0C73DD8728C0D906DD52EFAD51B8BCD47A3AF2451C13461DB02EA027AEDDE2A928985C91A0E4A0D3865A87F7AFCF91403445B82C9BF610D583E1A2B3F4C566DD
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............6R}S....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:46:41+0200". xmp:ModifyDate="2023-05-06T18:05:59+02:00". xmp:MetadataDate="2023-05-06T18:05:59+02:00". photoshop:DateCreated="2023-05-06T17:46:41+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="652". exif:PixelYDimension="681". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.415821244591656
            Encrypted:false
            SSDEEP:384:Z5rm6nQVTfMrYgQOahE4fIUQYZLV/anIT:Z5rm6nQVTfMrYgQOahE4fIUQYZLV/ani
            MD5:AAFC3327D093F013C4CD769176665EAA
            SHA1:1FC90CB8A6E5D030D084CC8C32D4CA0CE1048AE8
            SHA-256:96C06F5391F1F00DFBAE623A78E641175F3B27C809F0FBBD14CC7359F3C2E893
            SHA-512:CFBBCBB74CBA4C6332797BEE5B1232D2D421B4609298641C302F8EB16515871D68EAB1D9FB7460E8AA94EB9B8CB7C473F34B3B3A6EA2D055E06FDE258597D970
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB;W......sN...>U.}.......MB;W.......HRB..........MB;W......sN...>^.l.......MB;W........MB;W.......HHB.V......sN...>^.l......HHB.V........MB;W.......HHB.V......sN...?4.K......HHB.V.......HHB.V......c$DB........sN...?4.K.....c$DB.........HHB.V......c$DB........sN..5?..5.....c$DB..........'B2.......c$DB........sN..5?..5.....c$DB..........'B2.........'B2.......sN...>U.}.....:..B........:..B........a..B.......sN...>U.}.....a..B.......:..B........a..B.......sN...>^.l.....a..B.......a..B.......:.#B........sN...>^.l.....:.#B........a..B.......:.#B........sN...?4.K.....:.#B........:.#B..........'B2.......sN...?4.K.......'B2.......:.#B..........'B2.......sN.{.'........:..B........:...........:..B........sN.{.'........:..B........:...........:...........sN...........?7.%...........&.........c$@.........sN...........?c$@...........&.........7.%.........sN...........?c$@.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 652 x 681, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6914
            Entropy (8bit):6.55404340756016
            Encrypted:false
            SSDEEP:96:MWPk0o2aWXw1hZuWXjFl0nTbIiRrtESwnizHEDN9lIckSG49nyX0specWVyWFtQ/:rk0g0ySwniz2NxkSG49n10Wy/
            MD5:E86F933AB2C12C85F7DBFCBE67BDD464
            SHA1:56135ED13F25A435377571D32BB6D6574A1D2ED7
            SHA-256:0AEFC273DD34A23D7BFF09A5626F286ECDF0E69188E9F185D5DB993BFAA3CC84
            SHA-512:BAF9529670C29EB688F441E17B54141D65E8516FA64954B2D39A7D06C84C7FE087EB97F1AE53CF0B8232CC12034231E3653C49BADB2283EE8737B4753B47A6E6
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............6R}S....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:46:41+0200". xmp:ModifyDate="2023-05-06T18:05:28+02:00". xmp:MetadataDate="2023-05-06T18:05:28+02:00". photoshop:DateCreated="2023-05-06T17:46:41+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="652". exif:PixelYDimension="681". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.415821244591656
            Encrypted:false
            SSDEEP:384:Z5rm6nQVTfMrYgQOahE4fIUQYZLV/anIT:Z5rm6nQVTfMrYgQOahE4fIUQYZLV/ani
            MD5:AAFC3327D093F013C4CD769176665EAA
            SHA1:1FC90CB8A6E5D030D084CC8C32D4CA0CE1048AE8
            SHA-256:96C06F5391F1F00DFBAE623A78E641175F3B27C809F0FBBD14CC7359F3C2E893
            SHA-512:CFBBCBB74CBA4C6332797BEE5B1232D2D421B4609298641C302F8EB16515871D68EAB1D9FB7460E8AA94EB9B8CB7C473F34B3B3A6EA2D055E06FDE258597D970
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB;W......sN...>U.}.......MB;W.......HRB..........MB;W......sN...>^.l.......MB;W........MB;W.......HHB.V......sN...>^.l......HHB.V........MB;W.......HHB.V......sN...?4.K......HHB.V.......HHB.V......c$DB........sN...?4.K.....c$DB.........HHB.V......c$DB........sN..5?..5.....c$DB..........'B2.......c$DB........sN..5?..5.....c$DB..........'B2.........'B2.......sN...>U.}.....:..B........:..B........a..B.......sN...>U.}.....a..B.......:..B........a..B.......sN...>^.l.....a..B.......a..B.......:.#B........sN...>^.l.....:.#B........a..B.......:.#B........sN...?4.K.....:.#B........:.#B..........'B2.......sN...?4.K.......'B2.......:.#B..........'B2.......sN.{.'........:..B........:...........:..B........sN.{.'........:..B........:...........:...........sN...........?7.%...........&.........c$@.........sN...........?c$@...........&.........7.%.........sN...........?c$@.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 652 x 681, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6914
            Entropy (8bit):6.55404340756016
            Encrypted:false
            SSDEEP:96:MWPk0o2aWXw1hZuWXjFl0nTbIiRrtESwnizHEDN9lIckSG49nyX0specWVyWFtQ/:rk0g0ySwniz2NxkSG49n10Wy/
            MD5:E86F933AB2C12C85F7DBFCBE67BDD464
            SHA1:56135ED13F25A435377571D32BB6D6574A1D2ED7
            SHA-256:0AEFC273DD34A23D7BFF09A5626F286ECDF0E69188E9F185D5DB993BFAA3CC84
            SHA-512:BAF9529670C29EB688F441E17B54141D65E8516FA64954B2D39A7D06C84C7FE087EB97F1AE53CF0B8232CC12034231E3653C49BADB2283EE8737B4753B47A6E6
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............6R}S....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:46:41+0200". xmp:ModifyDate="2023-05-06T18:05:28+02:00". xmp:MetadataDate="2023-05-06T18:05:28+02:00". photoshop:DateCreated="2023-05-06T17:46:41+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="652". exif:PixelYDimension="681". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.415821244591656
            Encrypted:false
            SSDEEP:384:Z5rm6nQVTfMrYgQOahE4fIUQYZLV/anIT:Z5rm6nQVTfMrYgQOahE4fIUQYZLV/ani
            MD5:AAFC3327D093F013C4CD769176665EAA
            SHA1:1FC90CB8A6E5D030D084CC8C32D4CA0CE1048AE8
            SHA-256:96C06F5391F1F00DFBAE623A78E641175F3B27C809F0FBBD14CC7359F3C2E893
            SHA-512:CFBBCBB74CBA4C6332797BEE5B1232D2D421B4609298641C302F8EB16515871D68EAB1D9FB7460E8AA94EB9B8CB7C473F34B3B3A6EA2D055E06FDE258597D970
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB;W......sN...>U.}.......MB;W.......HRB..........MB;W......sN...>^.l.......MB;W........MB;W.......HHB.V......sN...>^.l......HHB.V........MB;W.......HHB.V......sN...?4.K......HHB.V.......HHB.V......c$DB........sN...?4.K.....c$DB.........HHB.V......c$DB........sN..5?..5.....c$DB..........'B2.......c$DB........sN..5?..5.....c$DB..........'B2.........'B2.......sN...>U.}.....:..B........:..B........a..B.......sN...>U.}.....a..B.......:..B........a..B.......sN...>^.l.....a..B.......a..B.......:.#B........sN...>^.l.....:.#B........a..B.......:.#B........sN...?4.K.....:.#B........:.#B..........'B2.......sN...?4.K.......'B2.......:.#B..........'B2.......sN.{.'........:..B........:...........:..B........sN.{.'........:..B........:...........:...........sN...........?7.%...........&.........c$@.........sN...........?c$@...........&.........7.%.........sN...........?c$@.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 652 x 681, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6914
            Entropy (8bit):6.555126581410005
            Encrypted:false
            SSDEEP:96:MWPk0o2aa3w1hZuWXjFl0nfbWiRrtESwnizHEDN9lIckSG49nyX0specWVyWFtQ/:rk0gk0Swniz2NxkSG49n10Wy/
            MD5:6FD3470CF95AFB5143AAD2E206E119B8
            SHA1:394E645EAA5A2AB9FD49D7FCD63505A3AC1ABDE2
            SHA-256:03897A59B456EB6C3B833A78D0DF5DA9A0EF14210247FBB49CBDF84F44D6B053
            SHA-512:0C73DD8728C0D906DD52EFAD51B8BCD47A3AF2451C13461DB02EA027AEDDE2A928985C91A0E4A0D3865A87F7AFCF91403445B82C9BF610D583E1A2B3F4C566DD
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............6R}S....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:46:41+0200". xmp:ModifyDate="2023-05-06T18:05:59+02:00". xmp:MetadataDate="2023-05-06T18:05:59+02:00". photoshop:DateCreated="2023-05-06T17:46:41+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="652". exif:PixelYDimension="681". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.415821244591656
            Encrypted:false
            SSDEEP:384:Z5rm6nQVTfMrYgQOahE4fIUQYZLV/anIT:Z5rm6nQVTfMrYgQOahE4fIUQYZLV/ani
            MD5:AAFC3327D093F013C4CD769176665EAA
            SHA1:1FC90CB8A6E5D030D084CC8C32D4CA0CE1048AE8
            SHA-256:96C06F5391F1F00DFBAE623A78E641175F3B27C809F0FBBD14CC7359F3C2E893
            SHA-512:CFBBCBB74CBA4C6332797BEE5B1232D2D421B4609298641C302F8EB16515871D68EAB1D9FB7460E8AA94EB9B8CB7C473F34B3B3A6EA2D055E06FDE258597D970
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB;W......sN...>U.}.......MB;W.......HRB..........MB;W......sN...>^.l.......MB;W........MB;W.......HHB.V......sN...>^.l......HHB.V........MB;W.......HHB.V......sN...?4.K......HHB.V.......HHB.V......c$DB........sN...?4.K.....c$DB.........HHB.V......c$DB........sN..5?..5.....c$DB..........'B2.......c$DB........sN..5?..5.....c$DB..........'B2.........'B2.......sN...>U.}.....:..B........:..B........a..B.......sN...>U.}.....a..B.......:..B........a..B.......sN...>^.l.....a..B.......a..B.......:.#B........sN...>^.l.....:.#B........a..B.......:.#B........sN...?4.K.....:.#B........:.#B..........'B2.......sN...?4.K.......'B2.......:.#B..........'B2.......sN.{.'........:..B........:...........:..B........sN.{.'........:..B........:...........:...........sN...........?7.%...........&.........c$@.........sN...........?c$@...........&.........7.%.........sN...........?c$@.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 652 x 681, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6911
            Entropy (8bit):6.554798310924467
            Encrypted:false
            SSDEEP:96:JWPk0o2a6nw1hZuWXjFl0nhbEiRrtESwnizHEDN9lIckSG49nyX0specWVyWFtQ/:Uk0gQuSwniz2NxkSG49n10Wy/
            MD5:D159E0CEE3228D17E000C5DFF579CBDD
            SHA1:F53B81A87C257624BFF01991D9739427C06BC7C6
            SHA-256:878327268792A6CC79F0577539D4B3F6011F355DDED04199AA530803FC7055D2
            SHA-512:BB129139C56578479D816ACA6FD79E314C567060DC295E94E81E44F9628C48570CB55B3B356DBE55EABD7EE514AA44BAFE9A46F7F2529F47109611E339A553EB
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............6R}S....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:46:41+0200". xmp:ModifyDate="2023-05-06T18:06:36+02:00". xmp:MetadataDate="2023-05-06T18:06:36+02:00". photoshop:DateCreated="2023-05-06T17:46:41+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="652". exif:PixelYDimension="681". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.550433898826635
            Encrypted:false
            SSDEEP:192:6NqKTfU6yUo+SmkyAQuMjLoyMaq48zXe4ok2jVZ5R3aong:ATImkyAQubyc48e4okL
            MD5:6408D1EA5499DA0AD0911CB06C47DE69
            SHA1:0EFB1B26933F6331BC15F1E3368DCB77BC339E37
            SHA-256:6AF2FE410213E5DE1BE3EE1313B6215FF7063425E44A2E75B174898F25E1B184
            SHA-512:4972361FAEBFCE02C409CE67211E992CD800990B711F8D73B4FDAA3494B2073E2CC0E9B7F7F649CC19A440410422070BB3FDDEC1F1C4A6A937840CAA309ED4D4
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB..0......HRB..0.......MB..0.....sN...>U.}.......MB..0......HRB..0.......MB..0.....sN...>^.l.......MB..0.......MB..0......HHB}+1.....sN...>^.l......HHB}+1.......MB..0......HHB}+1.....sN...?4.K......HHB}+1......HHB}+1.....c$DB..1.....sN...?4.K.....c$DB..1......HHB}+1.....c$DB..1.....sN..5?..5.....c$DB..1.......'B..9.....c$DB..1.....sN..5?..5.....c$DB..1.......'B..9.......'B..9.....sN...>U.}.....:..B..:.....:..B..:.....a..BcT:.....sN...>U.}.....a..BcT:.....:..B..:.....a..BcT:.....sN...>^.l.....a..BcT:.....a..BcT:.....:.#B..9.....sN...>^.l.....:.#B..9.....a..BcT:.....:.#B..9.....sN...?4.K.....:.#B..9.....:.#B..9.......'B..9.....sN...?4.K.......'B..9.....:.#B..9.......'B..9.....sNC..(........:..B..:.....:.....:.....:..B..:.....sNC..(........:..B..:.....:.....:.....:.....:.....sN...........?.E.B|.4......E..|.4........B..5.....sN...........?...B..5......E..|.4...........5.....sN...........?...B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1021 x 1049, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):9512
            Entropy (8bit):5.440740624377038
            Encrypted:false
            SSDEEP:96:5WPk0o2Sqro1JuXXiFl0nJbHiRrtESjbHIEKRhappU6fKdtNwoILo9rfDIk:Ek0b1SnHIEKR4p+6C3Nwc9b0k
            MD5:681B30D724C5BC5A1584EC1C217094A3
            SHA1:2F804354874010AC829FD8467CA10F8100311CFC
            SHA-256:E8E2CE1DD25AC534695D18E65A3D4FC586C6E11A860F1084F2C1F39F1EE71917
            SHA-512:AC21D80725EE1B675EAAAFC3E5A28C9B321EE43F9EBF3BD5B2DBDFD871D2FD3BDF240B5F319956E018C0E3D5E4F07D6878581D947056A672F711AEDFAEF2CE58
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR..............Mjz....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:51:09+0200". xmp:ModifyDate="2023-05-06T18:04:38+02:00". xmp:MetadataDate="2023-05-06T18:04:38+02:00". photoshop:DateCreated="2023-05-06T17:51:09+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="1021". exif:PixelYDimension="1049". exif:ColorSpace="1". tiff:ImageW
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.420874264870821
            Encrypted:false
            SSDEEP:384:Z5Cm6KQVXTMlRhE4fIUQfKYgQHLV/anIX:Z5Cm6KQVXTMlRhE4fIUQfKYgQHLV/anO
            MD5:F1B7B560E44792BC08DE7FC7AFC2468E
            SHA1:0B00CC53AD96702138F1300594A34624825C54CB
            SHA-256:64E867B222D0E3DCEE3B485044D3C8D568B65E46F7CF4F91AF18B23BFE80E4C7
            SHA-512:17D9F59951AEFAD3CD09587CB94928C4555F94DF7046BAAD895B816033104BB035276150E8FFCCCB3F915DDF3FEE4A90D5ECBC2E6733900BAC29C4D760A3039A
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB;W......sN...>U.}.......MB;W.......HRB..........MB;W......sN...>^.l.......MB;W........MB;W.......HHB.V......sN...>^.l......HHB.V........MB;W.......HHB.V......sN...?4.K......HHB.V.......HHB.V......c$DB........sN...?4.K.....c$DB.........HHB.V......c$DB........sN..5?..5.....c$DB..........'B2.......c$DB........sN..5?..5.....c$DB..........'B2.........'B2.......sN...>U.}.....:..B........:..B........a..B.......sN...>U.}.....a..B.......:..B........a..B.......sN...>^.l.....a..B.......a..B.......:.#B........sN...>^.l.....:.#B........a..B.......:.#B........sN...?4.K.....:.#B........:.#B..........'B2.......sN...?4.K.......'B2.......:.#B..........'B2.......sN..'........:..B........:...........:..B........sN..'........:..B........:...........:...........sN...........?.E.B.........E.............B........sN...........?...B.........E......................sN...........?...B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 652 x 681, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6915
            Entropy (8bit):6.553950042049767
            Encrypted:false
            SSDEEP:96:FWPk0o2aUdw1hZuWXjFl0nAbmiRrtESwnizHEDN9lIckSG49nyX0specWVyWFtQ/:wk0490Swniz2NxkSG49n10Wy/
            MD5:D766BE39DB510175764FD808E5F350A1
            SHA1:DE8B80DCDCAE94B041E9B580E6CCABF4C678E5E4
            SHA-256:40AD76634671675EDE73ABE26EF8BC256F724D9F6FE4282F416CD524D08C8137
            SHA-512:D996D3312D3AD73C2489FE9328312EE35DF23E2059DCBD7BC1114F116C14DB230A2C504ABAAD2B755AF385E999AE06F8177F7904903CA761330629DECC39BD54
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............6R}S....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:46:41+0200". xmp:ModifyDate="2023-05-06T18:07:20+02:00". xmp:MetadataDate="2023-05-06T18:07:20+02:00". photoshop:DateCreated="2023-05-06T17:46:41+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="652". exif:PixelYDimension="681". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.420874264870821
            Encrypted:false
            SSDEEP:384:Z5Cm6KQVXTMlRhE4fIUQfKYgQHLV/anIX:Z5Cm6KQVXTMlRhE4fIUQfKYgQHLV/anO
            MD5:F1B7B560E44792BC08DE7FC7AFC2468E
            SHA1:0B00CC53AD96702138F1300594A34624825C54CB
            SHA-256:64E867B222D0E3DCEE3B485044D3C8D568B65E46F7CF4F91AF18B23BFE80E4C7
            SHA-512:17D9F59951AEFAD3CD09587CB94928C4555F94DF7046BAAD895B816033104BB035276150E8FFCCCB3F915DDF3FEE4A90D5ECBC2E6733900BAC29C4D760A3039A
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB;W......sN...>U.}.......MB;W.......HRB..........MB;W......sN...>^.l.......MB;W........MB;W.......HHB.V......sN...>^.l......HHB.V........MB;W.......HHB.V......sN...?4.K......HHB.V.......HHB.V......c$DB........sN...?4.K.....c$DB.........HHB.V......c$DB........sN..5?..5.....c$DB..........'B2.......c$DB........sN..5?..5.....c$DB..........'B2.........'B2.......sN...>U.}.....:..B........:..B........a..B.......sN...>U.}.....a..B.......:..B........a..B.......sN...>^.l.....a..B.......a..B.......:.#B........sN...>^.l.....:.#B........a..B.......:.#B........sN...?4.K.....:.#B........:.#B..........'B2.......sN...?4.K.......'B2.......:.#B..........'B2.......sN..'........:..B........:...........:..B........sN..'........:..B........:...........:...........sN...........?.E.B.........E.............B........sN...........?...B.........E......................sN...........?...B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 652 x 681, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6914
            Entropy (8bit):6.554893447040955
            Encrypted:false
            SSDEEP:96:MWPk0o2a+jw1hZuWXjFl0nRb9iRrtESwnizHEDN9lIckSG49nyX0specWVyWFtQ/:rk0AGHSwniz2NxkSG49n10Wy/
            MD5:10D83042B266BAEA4A38C3A6C7379ED3
            SHA1:4BDC6AAA478744D8AF2068076412E064B8E6DE9E
            SHA-256:AA3FD292BB71B17EEC2FB6CBEF494F486E8C68BD86D004DC32059728250173F3
            SHA-512:89692BCD84728E339A33C2F25581D78EFF058EFD177C70ED62039479D4315194B7B6812E4E0407F378834C799748475FC1860757984CEC3DEBA99ADC53E81312
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............6R}S....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:46:41+0200". xmp:ModifyDate="2023-05-06T18:08:09+02:00". xmp:MetadataDate="2023-05-06T18:08:09+02:00". photoshop:DateCreated="2023-05-06T17:46:41+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="652". exif:PixelYDimension="681". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.420874264870821
            Encrypted:false
            SSDEEP:384:Z5Cm6KQVXTMlRhE4fIUQfKYgQHLV/anIX:Z5Cm6KQVXTMlRhE4fIUQfKYgQHLV/anO
            MD5:F1B7B560E44792BC08DE7FC7AFC2468E
            SHA1:0B00CC53AD96702138F1300594A34624825C54CB
            SHA-256:64E867B222D0E3DCEE3B485044D3C8D568B65E46F7CF4F91AF18B23BFE80E4C7
            SHA-512:17D9F59951AEFAD3CD09587CB94928C4555F94DF7046BAAD895B816033104BB035276150E8FFCCCB3F915DDF3FEE4A90D5ECBC2E6733900BAC29C4D760A3039A
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB;W......sN...>U.}.......MB;W.......HRB..........MB;W......sN...>^.l.......MB;W........MB;W.......HHB.V......sN...>^.l......HHB.V........MB;W.......HHB.V......sN...?4.K......HHB.V.......HHB.V......c$DB........sN...?4.K.....c$DB.........HHB.V......c$DB........sN..5?..5.....c$DB..........'B2.......c$DB........sN..5?..5.....c$DB..........'B2.........'B2.......sN...>U.}.....:..B........:..B........a..B.......sN...>U.}.....a..B.......:..B........a..B.......sN...>^.l.....a..B.......a..B.......:.#B........sN...>^.l.....:.#B........a..B.......:.#B........sN...?4.K.....:.#B........:.#B..........'B2.......sN...?4.K.......'B2.......:.#B..........'B2.......sN..'........:..B........:...........:..B........sN..'........:..B........:...........:...........sN...........?.E.B.........E.............B........sN...........?...B.........E......................sN...........?...B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 652 x 681, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6912
            Entropy (8bit):6.5546259149074215
            Encrypted:false
            SSDEEP:96:2WPk0o2ajIw1hZuWXjFl0nJbOiRrtESwnizHEDN9lIckSG49nyX0specWVyWFtQ/:hk08OsSwniz2NxkSG49n10Wy/
            MD5:74BC1E4351B50EE473BE46A727905465
            SHA1:B9895C488199FA902D96E182645D423A17045601
            SHA-256:CA36E22718B6D7304EFE67F481C0552AA450AB1F25ED0FA500DF59D6F6C317D3
            SHA-512:D0BFB40832893FD754E557B204A07B1894341BA157BA34F24787B234D6CCEABEB3C94279FD76D4CBC17E8E1AEB5127C43B66F0EE42A87737958B1976BDFFB56A
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............6R}S....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:46:41+0200". xmp:ModifyDate="2023-05-06T18:08:37+02:00". xmp:MetadataDate="2023-05-06T18:08:37+02:00". photoshop:DateCreated="2023-05-06T17:46:41+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="652". exif:PixelYDimension="681". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.526144648605933
            Encrypted:false
            SSDEEP:384:Ls0UnIuTvHzHaW5LLWv8sEIsINCDP/nREM8BXGV+vY+wMTH3C:Ls0UnQW5LLaEIsINCDP/nREM8ZH3C
            MD5:20FD552D428B9A4447D4F480CF209B1F
            SHA1:6BD0C9597C95FAB29BE168B08D6AE01E6936C486
            SHA-256:6698E00852EB6482F8F346DE392FD4248F2A363613CE0BCE9763FF280A0CDFEE
            SHA-512:52D7AAF01B789DD6E59D7624AC1BE5DEAC2F291D99CA10480F801AD851F4796766C4F313D10E00FB81EC5F346343A03423F99C11DDCBD35EF3906897B6E02068
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB;W......sN...>U.}.......MB;W.......HRB..........MB;W......sN...>^.l.......MB;W........MB;W.......HHB.V......sN...>^.l......HHB.V........MB;W.......HHB.V......sN...?4.K......HHB.V.......HHB.V......c$DB........sN...?4.K.....c$DB.........HHB.V......c$DB........sN..5?..5.....c$DB..........'B........c$DB........sN..5?..5.....c$DB..........'B..........'B........sN...>U.}.....:..B........:..B........a..BcT......sN...>U.}.....a..BcT......:..B........a..BcT......sN...>^.l.....a..BcT......a..BcT......:.#B........sN...>^.l.....:.#B........a..BcT......:.#B........sN...?4.K.....:.#B........:.#B..........'B........sN...?4.K.......'B........:.#B..........'B........sNC..(........:..B........:...........:..B........sNC..(........:..B........:...........:...........sN...........?7.%..........&.........c$@.........sN...........?c$@...........&.........7.%.|.......sN...........?c$@.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 738 x 766, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):7459
            Entropy (8bit):6.285777312776848
            Encrypted:false
            SSDEEP:96:FWPk0o2052C1eudX3Fl0nHbzuiRrtESBBozHSQw4/9zLhDZW68wQiyulGo:wk0TPYSYRw4F/J1Go
            MD5:B4A19EC5BD92FF34FAB5A1B24ABDE41A
            SHA1:6C2A9E546C82E8376DCDC307F92868E0C4C65E12
            SHA-256:5E81FEA7951400A8598C6B2AACB1623C9EBEB254693580C8E28A714910F1C003
            SHA-512:D5FEE7C773A0DA20F4E80445E5A96E50A6207F24341AF01F719673F25136CAC7A3BEB4D3BC38BE10882B2E191E76DD844901DDCDAA1157CB969C2E22B90D4ED9
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR...............q.....iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-06T17:55:54+0200". xmp:ModifyDate="2023-05-06T18:00:04+02:00". xmp:MetadataDate="2023-05-06T18:00:04+02:00". photoshop:DateCreated="2023-05-06T17:55:54+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="738". exif:PixelYDimension="766". exif:ColorSpace="1". tiff:ImageWid
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.420874264870821
            Encrypted:false
            SSDEEP:384:Z5Cm6KQVXTMlRhE4fIUQfKYgQHLV/anIX:Z5Cm6KQVXTMlRhE4fIUQfKYgQHLV/anO
            MD5:F1B7B560E44792BC08DE7FC7AFC2468E
            SHA1:0B00CC53AD96702138F1300594A34624825C54CB
            SHA-256:64E867B222D0E3DCEE3B485044D3C8D568B65E46F7CF4F91AF18B23BFE80E4C7
            SHA-512:17D9F59951AEFAD3CD09587CB94928C4555F94DF7046BAAD895B816033104BB035276150E8FFCCCB3F915DDF3FEE4A90D5ECBC2E6733900BAC29C4D760A3039A
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB;W......sN...>U.}.......MB;W.......HRB..........MB;W......sN...>^.l.......MB;W........MB;W.......HHB.V......sN...>^.l......HHB.V........MB;W.......HHB.V......sN...?4.K......HHB.V.......HHB.V......c$DB........sN...?4.K.....c$DB.........HHB.V......c$DB........sN..5?..5.....c$DB..........'B2.......c$DB........sN..5?..5.....c$DB..........'B2.........'B2.......sN...>U.}.....:..B........:..B........a..B.......sN...>U.}.....a..B.......:..B........a..B.......sN...>^.l.....a..B.......a..B.......:.#B........sN...>^.l.....:.#B........a..B.......:.#B........sN...?4.K.....:.#B........:.#B..........'B2.......sN...?4.K.......'B2.......:.#B..........'B2.......sN..'........:..B........:...........:..B........sN..'........:..B........:...........:...........sN...........?.E.B.........E.............B........sN...........?...B.........E......................sN...........?...B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 2717 x 2835, 8-bit colormap, non-interlaced
            Category:dropped
            Size (bytes):18711
            Entropy (8bit):5.93963856201406
            Encrypted:false
            SSDEEP:384:30wzSEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEU:3BSEEEEEEEEEEEEEEEEEEEEEEEEEEEE6
            MD5:D6306709291952AFA2E1A45A51D444E6
            SHA1:D6EFFEA79AB9763E199751E4A3DA47B2DAE42EAA
            SHA-256:E4B593F203446DA14353CE56BCF5E46D8FF9A9098DB3D5FEE331556C90303F57
            SHA-512:DF5796324E91F3B728F73C46F008E0640D1A5CF10C0625D89BD851C15CDD358339C6EA2E7A49D9C52B82EDF0F180118B1DE959CE1FB9A40DA4CDC096112DE708
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............]..2....gAMA......a....IiCCPsRGB IEC61966-2.1..H..SwX...>..e.VB..l.."#....Y....a...@...V....HU...H...(.gA..Z.U\8....}z...........y.....&..j.9R.<:...OH.....H.. ....g......yx~t.?...o...p..$......P&W. ...".....R...T.......S.d.....ly|B"......I>................(G$.@..`U.R,......@"......Y.2G.....v.X..@`...B,.. 8..C.... L..0.._p..H.....K.3.....w....!..l.Ba.).f.."...#.H..L.........8?......f.l....k.o">!.........N..._....p...u.k.[..V.h..]3...Z..z..y8.@...P.<......%b..0.>.3.o..~..@...z..q.@......qanv.R....B1n..#.....)..4.\,...X..P"M.y.R.D!.....2......w....O.N....l.~.....X.v.@~.-......g42y.......@+..........\...L....D..*.A..............a.D@.$.<.B.......A.T.:.............18....\..p..`........A...a!:..b.."......"aH4... ..Q"..r...Bj.]H#.-r.9.\@.... 2....G1...Q...u@......s.t4.]...k....=.....K.ut.}..c..1.f..a\..E`.X.&..c.X5V.5c.X7v....a..$......^...l...GXLXC.%.#....W...1.'"..O.%z...xb:..XF.&.!.!.%^'.._.H$...N.!%.2I.IkH.H-.S.>..i.L&.m....... ......O.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):18684
            Entropy (8bit):4.5129438945701414
            Encrypted:false
            SSDEEP:384:XEgAbBJaDiXko1GMXeW6f+dittFr3YU5yriXPvjgP4B69gLC2Uwkz9EaH8qIhIpi:XEgAbaf+cWUvjgP4B69gm2UwkxpmZ
            MD5:0F5B390E2510B6CF3265A3B326773F98
            SHA1:95E7A0C5FDAB6CF37BE21D0E2F2780369AE82393
            SHA-256:7EF975DFBE4913A98A448ECA12B1700B643B51926BC6D967F559E7E0424FE20F
            SHA-512:328864F20E078E8FF8F8DBE799F57A4FF133DC563BBAEF29904A7CC32D97D52819F0CA28D0765C2780C75CD111B671B4F145904B200E3CE92D2BC5279D23B366
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... t......>U.}......HRB.........HRB..........MB........sN...>U.}.......MB.........HRB..........MB........sN...>^.l.......MB..........MB.........HHB}+......sN...>^.l......HHB}+........MB.........HHB}+......sN...?4.K......HHB}+.......HHB}+......c$DB........sN...?4.K.....c$DB.........HHB}+......c$DB........sN..5?..5.....c$DB..........'B.. .....c$DB........sN..5?..5.....c$DB..........'B.. .......'B.. .....sN...>U.}.....:..B..!.....:..B..!.....a..BcT!.....sN...>U.}.....a..BcT!.....:..B..!.....a..BcT!.....sN...>^.l.....a..BcT!.....a..BcT!.....:.#B.. .....sN...>^.l.....:.#B.. .....a..BcT!.....:.#B.. .....sN...?4.K.....:.#B.. .....:.#B.. .......'B.. .....sN...?4.K.......'B.. .....:.#B.. .......'B.. .....sN.{.'........:..B..!.....:.....!.....:..B..!.....sN.{.'........:..B..!.....:.....!.....:.....!.....sN...........?.E.B|........E..|..........B........sN...........?...B.........E..|...................sN...........?...B
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 3662 x 3780, 8-bit colormap, non-interlaced
            Category:dropped
            Size (bytes):25995
            Entropy (8bit):4.771498803752463
            Encrypted:false
            SSDEEP:192:XIIHUCD4waYeCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCr:J0w1BEMwE4YSSlp
            MD5:BF81CFCD964F949415C4CDB37644966D
            SHA1:9B3BA749AB4267632E35DA1DE02CDF4541729513
            SHA-256:11A91523FDBDD375CCCA57202234D7CF5B7555569CA968A32F88D4A3B31F3ACB
            SHA-512:959D74E3554D4358BE48E8CC8FDDDDE0C41563ED0C63F97186818B20F2517C15B2BED53227963861462A0BD0E20710A26116D918F3BC3CF1D849CCB63DB88CC4
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR...N.................gAMA......a....IiCCPsRGB IEC61966-2.1..H..SwX...>..e.VB..l.."#....Y....a...@...V....HU...H...(.gA..Z.U\8....}z...........y.....&..j.9R.<:...OH.....H.. ....g......yx~t.?...o...p..$......P&W. ...".....R...T.......S.d.....ly|B"......I>................(G$.@..`U.R,......@"......Y.2G.....v.X..@`...B,.. 8..C.... L..0.._p..H.....K.3.....w....!..l.Ba.).f.."...#.H..L.........8?......f.l....k.o">!.........N..._....p...u.k.[..V.h..]3...Z..z..y8.@...P.<......%b..0.>.3.o..~..@...z..q.@......qanv.R....B1n..#.....)..4.\,...X..P"M.y.R.D!.....2......w....O.N....l.~.....X.v.@~.-......g42y.......@+..........\...L....D..*.A..............a.D@.$.<.B.......A.T.:.............18....\..p..`........A...a!:..b.."......"aH4... ..Q"..r...Bj.]H#.-r.9.\@.... 2....G1...Q...u@......s.t4.]...k....=.....K.ut.}..c..1.f..a\..E`.X.&..c.X5V.5c.X7v....a..$......^...l...GXLXC.%.#....W...1.'"..O.%z...xb:..XF.&.!.!.%^'.._.H$...N.!%.2I.IkH.H-.S.>..i.L&.m....... ......O.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):251
            Entropy (8bit):4.930206193965322
            Encrypted:false
            SSDEEP:6:TMVBd/hrVtnqD4OFYmc4slafpckdGj9fhWR6e:TMHdVVtny4OKOpcoGjze
            MD5:310D881CF07F060D447E116F35464417
            SHA1:FC17887AD3BE7FE0ACC2935B1E66CFB364047E58
            SHA-256:9C254928751644543D4402F503969800D73861FD6A8187346B2C6D4A967CC171
            SHA-512:22CBE95B739534AC5703BA5638586142169F6D63A626176AA63D972713A05F97690EC32E02D6FBBA8BC696743ECB2BB17D1D59017F2388CB280857F1FEAC9F49
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" encoding="UTF-8"?>.<svg width="210mm" height="220mm" version="1.1" viewBox="0 0 210 220" xmlns="http://www.w3.org/2000/svg">. <rect x=".25" y=".25" width="209.5" height="219.5" fill="none" stroke="#fff" stroke-width=".5"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):685
            Entropy (8bit):4.538004134461036
            Encrypted:false
            SSDEEP:12:KY3haD+fhTo0dlpTmu5umqvzGxh3TeW4h3Tr4h3TJ4h3T/4h3TSBW4h3TSa4h3TA:Kg8IhTtHpTr5RqviT3TFW3TrW3TJW3Td
            MD5:0CE8794043955FE7D5DCEC507A9885DE
            SHA1:D74B902515991F5C7CF725534BB8EF2E392B0910
            SHA-256:4897D9722A5573F13DA943A520E44DD551FA679813B458A10DCC49EF1591D19D
            SHA-512:37CB04E47A6E8A884B4041A75681FD8DAD662C82D490E4A54FB7600D703A728C0180E5CCC00E90937431014B1C500D4C0AA160C8470FA3CC5BD57A2F00590803
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "CRB99",. "setting_id": "CRSB99_CREALITY_00",. "name": "Generic ABS @Creality CR-6",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_abs",. "filament_flow_ratio": [. "0.926". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Creality CR-6 SE 0.2 nozzle",. "Creality CR-6 SE 0.4 nozzle",. "Creality CR-6 SE 0.6 nozzle",. "Creality CR-6 SE 0.8 nozzle",. "Creality CR-6 Max 0.2 nozzle",. "Creality CR-6 Max 0.4 nozzle",. "Creality CR-6 Max 0.6 nozzle",. "Creality CR-6 Max 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):851
            Entropy (8bit):4.554111791089125
            Encrypted:false
            SSDEEP:24:KgkIHHpTr5RqviT3iW34WnFWlWUWdWzWIWvWiWnWIA:KLKHpTr5RSepPn0UL8Cvu5Wr
            MD5:6ADB825BB87FFEDFFDC9D48FD55CC345
            SHA1:D1E4CD90A9BE1DAEF879D25869B09058753C4F87
            SHA-256:DC694D5BCF9EA17699038D06824F5F3CDC8DFC1374135D2B85F7350EBA9DC232
            SHA-512:06C4946440CADCA32E530B0D6B7AAE8BBFFC11D2393C4CF7294E2115241382F4B75EEA70434E56C9A2336C7448AE0C32799D4ADF4F90306FA916E77058F2E3E3
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFB99",. "setting_id": "GFSB99_CREALITY_00",. "name": "Generic ABS @Creality",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_abs",. "filament_flow_ratio": [. "0.926". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Creality CR-10 V2 0.4 nozzle",. "Creality CR-10 Max 0.4 nozzle",. "Creality Ender-3 V2 0.4 nozzle",. "Creality Ender-3 S1 0.4 nozzle",. "Creality Ender-3 S1 Pro 0.4 nozzle",. "Creality Ender-5 0.4 nozzle",. "Creality Ender-5 Plus 0.4 nozzle",. "Creality Ender-5S 0.4 nozzle",. "Creality Ender-5 S1 0.4 nozzle",. "Creality Ender-6 0.4 nozzle",. "Creality K1 0.4 nozzle",. "Creality K1 Max 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):851
            Entropy (8bit):4.546453277182562
            Encrypted:false
            SSDEEP:24:KRxz7vHHpTr5aqviT3iW34WnFWlWUWdWzWIWvWiWnWIA:KL7PHpTr5aSepPn0UL8Cvu5Wr
            MD5:7AFF37F4552C7B9DD7FE9D502CEDB1B4
            SHA1:87CC274A7B52D79DC71AB40B7AD466D5956F94FB
            SHA-256:DB99098612AA2449590F94FC0632DE2434D2752E6DFB97448D2AA66779DB989A
            SHA-512:382968115CFA5578D41F6E20108E9CA2AFD1DCEF0CFF467446B6281155478DB61F38BA7A48E1DE607646A0B8D9CD446A740CDC2666C557A73566289C5241C105
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFB98",. "setting_id": "GFSA04_CREALITY_00",. "name": "Generic ASA @Creality",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_asa",. "filament_flow_ratio": [. "0.926". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Creality CR-10 V2 0.4 nozzle",. "Creality CR-10 Max 0.4 nozzle",. "Creality Ender-3 V2 0.4 nozzle",. "Creality Ender-3 S1 0.4 nozzle",. "Creality Ender-3 S1 Pro 0.4 nozzle",. "Creality Ender-5 0.4 nozzle",. "Creality Ender-5 Plus 0.4 nozzle",. "Creality Ender-5S 0.4 nozzle",. "Creality Ender-5 S1 0.4 nozzle",. "Creality Ender-6 0.4 nozzle",. "Creality K1 0.4 nozzle",. "Creality K1 Max 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):924
            Entropy (8bit):4.470488177194585
            Encrypted:false
            SSDEEP:24:K1drohTtHpTr5NoiOo8PwpDNov4T3TFW3TrW3TJW3T/W3TxW3TfW3TtW3TSA:K1VGtHpTr5Ww8sIAj0jKjoj+jAjejMjp
            MD5:A73A4ADFF493D681FCDDDB366AEAD469
            SHA1:4733405CCC37D0477B24D422ABA1299DB29ED314
            SHA-256:9DA7FF2498DFAEC57E5398471D4555AA5FCCDF74A0D4EBF1627F861D60DB366F
            SHA-512:FBA4C49FE8F27EBEE365E350FD08DF39EC5B1EEF4DA3BF2DA8B5DE96CEDFAAAA38CFABFE26DBE46D16B872736A2DBB06C2A30FE701E2084DD880947D9297815A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "CRG99",. "setting_id": "CRSG99_CREALITY_00",. "name": "Generic PETG @Creality CR-6",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pet",. "fan_cooling_layer_time": [. "30". ],. "overhang_fan_speed": [. "90". ],. "overhang_fan_threshold": [. "25%". ],. "fan_max_speed": [. "90". ],. "fan_min_speed": [. "40". ],. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "10". ],. "compatible_printers": [. "Creality CR-6 SE 0.2 nozzle",. "Creality CR-6 SE 0.4 nozzle",. "Creality CR-6 SE 0.6 nozzle",. "Creality CR-6 SE 0.8 nozzle",. "Creality CR-6 Max 0.2 nozzle",. "Creality CR-6 Max 0.4 nozzle",. "Creality CR-6 Max 0.6 nozzle",. "Creality CR-6 Max 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1084
            Entropy (8bit):4.5128008108392015
            Encrypted:false
            SSDEEP:24:KnnToHHpTr5NoiOo8PwpDNov4T3iW34WnFWlWUWdWzWIWvWiW1bA:KnTqHpTr5Ww8sIApPn0UL8Cvu5i
            MD5:94094CD2A09FB56DB55AE2E1359FB690
            SHA1:D2A8191B0FC47EF0DFF8ACB5FB8B75E592CCCD46
            SHA-256:1A0BEF942C0BD8DFF7EC7D1F291BA05B18781C8397F00B4DE165907661805E48
            SHA-512:861EB5C6858758BC965055D0AEEB5371757AF351EF8ABB8C15F49624F438FC64D776B5BFC95E7F3428DA2DEE53645351B23565CCB839D896CBC5C78910B0550F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFG99",. "setting_id": "GFSG99_CREALITY_00",. "name": "Generic PETG @Creality",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pet",. "fan_cooling_layer_time": [. "30". ],. "overhang_fan_speed": [. "90". ],. "overhang_fan_threshold": [. "25%". ],. "fan_max_speed": [. "90". ],. "fan_min_speed": [. "40". ],. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "10". ],. "compatible_printers": [. "Creality CR-10 V2 0.4 nozzle",. "Creality CR-10 Max 0.4 nozzle",. "Creality Ender-3 V2 0.4 nozzle",. "Creality Ender-3 S1 0.4 nozzle",. "Creality Ender-3 S1 Pro 0.4 nozzle",. "Creality Ender-5 0.4 nozzle",. "Creality Ender-5 Plus 0.4 nozzle",. "Creality Ender-5S 0.4 nozzle",. "Creality Ender-5 S1 0.4 nozzle",. "Creality Ender-6 0
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):674
            Entropy (8bit):4.501448874860853
            Encrypted:false
            SSDEEP:12:KS3hEJDnfhTo0dlpTmu58afXxh3TeW4h3Tr4h3TJ4h3T/4h3TSBW4h3TSa4h3TSV:KSxkDnfhTtHpTr5XXT3TFW3TrW3TJW3h
            MD5:D9BA1BE7FD66A684C4983EB8A5FD7F39
            SHA1:9B61EAA66BFDECFF57BB80B84BCB062D1C7A0B77
            SHA-256:1966E33FE8C571303FD0D2B49D79A10F5BB8916117C263FA0C148C0F5D45247D
            SHA-512:6EA2F51E5C7A10238C986B6BDA60396767F5E84065786AE84929940526FE9E8379CEA5F079119254A37DA71E63669AF34C9D6AE75596FB1903174DB7C4D46A6C
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "CRL99",. "setting_id": "CRSL99_CREALITY_00",. "name": "Generic PLA @Creality CR-6",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pla",. "filament_flow_ratio": [. "0.98". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Creality CR-6 SE 0.2 nozzle",. "Creality CR-6 SE 0.4 nozzle",. "Creality CR-6 SE 0.6 nozzle",. "Creality CR-6 SE 0.8 nozzle",. "Creality CR-6 Max 0.2 nozzle",. "Creality CR-6 Max 0.4 nozzle",. "Creality CR-6 Max 0.6 nozzle",. "Creality CR-6 Max 0.8 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):834
            Entropy (8bit):4.562701382739668
            Encrypted:false
            SSDEEP:24:KSxsDnfHHpTr5XXT3iW34WnFWlWUWdWzWIWvWiW1bA:KSyDnfHpTr5zpPn0UL8Cvu5i
            MD5:A442B1BE2E34F8ABACF63A75667AFB16
            SHA1:B62F130FC40DAE5E7971D19D1A38EB83E610E175
            SHA-256:5EB2D4989A0A68AED89D08A6A67F24344E7A06A4C1F8A1F7340E968959033E96
            SHA-512:4AE4C63793234F0F7C2D31607EEC100FFC69F3652162A1AED02CCC71BA08EE938034C0AA13334FE84A9B6754E0C952EB46E111AA2571907299599034E2DD410E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFL99",. "setting_id": "GFSL99_CREALITY_00",. "name": "Generic PLA @Creality",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pla",. "filament_flow_ratio": [. "0.98". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Creality CR-10 V2 0.4 nozzle",. "Creality CR-10 Max 0.4 nozzle",. "Creality Ender-3 V2 0.4 nozzle",. "Creality Ender-3 S1 0.4 nozzle",. "Creality Ender-3 S1 Pro 0.4 nozzle",. "Creality Ender-5 0.4 nozzle",. "Creality Ender-5 Plus 0.4 nozzle",. "Creality Ender-5S 0.4 nozzle",. "Creality Ender-5 S1 0.4 nozzle",. "Creality Ender-6 0.4 nozzle",. "Creality K1 0.4 nozzle",..."Creality K1 Max 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):800
            Entropy (8bit):4.557679360048173
            Encrypted:false
            SSDEEP:24:KW4kRjHHpTr557gT3iW34WnFWlWUWdWzWIWvWiWnWIK:KUTHpTr557IpPn0UL8Cvu5W7
            MD5:F37BB35A7332BF807F03945B0EA2CA16
            SHA1:B92CED4AF1B6765ECD27DF0683FCB152E8BE9165
            SHA-256:A34B0292EEF33EBF817FDAF4D6EA2A142280559E2826F7FBDDCDFFDD492F9E00
            SHA-512:750803135C7290B0974ED50B917DABB6F8ED0989F6433ABA7D03BFEEFBC5F34715D8F8E79363C9DCE78F9BE3AA16399144E3E05B5D4D07278384B3498C506F35
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFU99",. "setting_id": "GFU99_CREALITY_00",. "name": "Generic TPU @Creality",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_tpu",. "filament_max_volumetric_speed": [. "3.2". ],. "compatible_printers": [. "Creality CR-10 V2 0.4 nozzle",. "Creality CR-10 Max 0.4 nozzle",. "Creality Ender-3 V2 0.4 nozzle",. "Creality Ender-3 S1 0.4 nozzle",. "Creality Ender-3 S1 Pro 0.4 nozzle",. "Creality Ender-5 0.4 nozzle",. "Creality Ender-5 Plus 0.4 nozzle",. "Creality Ender-5S 0.4 nozzle",. "Creality Ender-5 S1 0.4 nozzle",. "Creality Ender-6 0.4 nozzle",. "Creality K1 0.4 nozzle",. "Creality K1 Max 0.4 nozzle". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1403
            Entropy (8bit):4.12581517488523
            Encrypted:false
            SSDEEP:24:9+Hpy5v/MV2sVUVcV92ZxJZvDajcoRxSSIhrqPwcqo8oiTxGm5wxxx0WwTCA:9+Hpy5vTHHxXZrOh9k
            MD5:1EC1C7ABD4C66B39A69E754D857DE100
            SHA1:41A08C3CD0F55A404675FEE3C4E106C3221FAD40
            SHA-256:8F0350180179CADD39D2BE5AE865B117A03083A9E9FE63609ABC667104C6F5D3
            SHA-512:12DBFCD611292623EE1ABBD3EF76B910AF2F73641321A4CEFEDA0DB8213657538553CA9F8DA300E7C0907FD91D83A4E4B3CB7D3876695954F7BB9254CC8D1E74
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_abs",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp": [. "105". ],. "eng_plate_temp": [. "105". ],. "hot_plate_temp": [. "105". ],. "textured_plate_temp": [. "105". ],. "cool_plate_temp_initial_layer": [. "105". ],. "eng_plate_temp_initial_layer": [. "105". ],. "hot_plate_temp_initial_layer": [. "105". ],. "textured_plate_temp_initial_layer": [. "105". ],. "fan_cooling_layer_time": [. "30". ],. "filament_max_volumetric_speed": [. "28.6". ],. "filament_type": [. "ABS". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "260". ],. "reduce_fan_stop_start_freq": [. "1". ],. "fan_max_speed": [. "80". ],. "fan_min_s
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1458
            Entropy (8bit):4.118418260991309
            Encrypted:false
            SSDEEP:24:9PHpy5v/T22z2b2mO26OyOOgzqbvGCavDaLocoRxSSIhrqPwcqo8oiTxGm5wxxxM:9PHpy5vbDzMtjzJ8XZrOh9e
            MD5:F733D418EC659BE981E94BE53C3EF6BA
            SHA1:12E34BB5EEF592794108AB549E916E485332746C
            SHA-256:EEFB5356DE7FBD1CAB20EE90034EA506C102BD8764379CD8178A1327E38A44E2
            SHA-512:3B365FE6D130F9AD6CB416F8C6B2F46C15E1D2BC3834DD2D422053DFEDB15A5D7509346FEA60A250B30935BA6D3CF765AFEC45BB6FDC098B0ACA2DF94D31B606
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_asa",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "105". ],. "eng_plate_temp" : [. "105". ],. "hot_plate_temp" : [. "105". ],. "cool_plate_temp_initial_layer" : [. "105". ],. "eng_plate_temp_initial_layer" : [. "105". ],. "hot_plate_temp_initial_layer" : [. "105". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "35". ],. "filament_max_volumetric_speed": [. "28.6". ],. "filament_type": [. "ASA". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "260". ],. "reduce_fan_stop_start_freq": [. "1". ],. "fan_max_speed": [. "80". ],. "fan_
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2599
            Entropy (8bit):4.052726770282634
            Encrypted:false
            SSDEEP:24:9v/JHpyvGCoPH2sP274PwRnn4LZA2VlC2qkxvtrmFkWZ1C9gBDiToQIFGNzotUPI:9vxHpWz882V1DpY0gzq10YauozpR/
            MD5:CB662801FFE561A41DFF1801CE2B7F43
            SHA1:38265709AFFD390E557F5D3838148F4827E93F3D
            SHA-256:26F3BFD79F0BBD57E45AEBE094F28BBDFD6EE148F04C31173076CE5483708BD3
            SHA-512:96D6BEF74579FB48D3BCC19B798F24D6F98656D19467D6F99ADA30DDB096D9F2B680E64402BEBA63E49EE3608ADEDD11A6E048D5AD7E10AB2B3A5A943092A589
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_common",. "from": "system",. "instantiation": "false",. "close_fan_the_first_x_layers": [. "3". ],. "cool_plate_temp": [. "60". ],. "cool_plate_temp_initial_layer": [. "60". ],. "eng_plate_temp": [. "60". ],. "eng_plate_temp_initial_layer": [. "60". ],. "fan_cooling_layer_time": [. "60". ],. "fan_max_speed": [. "100". ],. "fan_min_speed": [. "35". ],. "filament_cost": [. "0". ],. "filament_density": [. "0". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "0". ],. "filament_minimal_purge_on_wipe_tower": [. "15". ],. "filament_retract_before_wipe": [. "nil". ],. "filamen
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1166
            Entropy (8bit):4.11520809078545
            Encrypted:false
            SSDEEP:24:9RHpy5v/qs5Uxcx2ltFMvAdClQExSWIhrqlxymix3x0+JwA:9RHpy5vyLybedrD
            MD5:C47C50B4507D24DE2AFA8DE1C631E064
            SHA1:03DCFBF351823515C056B79E803184D869CE09C0
            SHA-256:8D9351A961FA0D7F48ACB11958D472BEB0E4DCF270F9C6CD5A16A22EB90EE164
            SHA-512:E0D1E6505776BB351C97788DD738A494167718DFF27D2A7FA3440A4F9F1913E287C2F52E0E3F1660FA9EF86D0D077796F9DDEC6FB6A093AA7D028388B3ADA622
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pet",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "eng_plate_temp": [. "0". ],. "hot_plate_temp": [. "80". ],. "textured_plate_temp": [. "80". ],. "eng_plate_temp_initial_layer": [. "0". ],. "hot_plate_temp_initial_layer": [. "80". ],. "textured_plate_temp_initial_layer": [. "80". ],. "fan_cooling_layer_time": [. "20". ],. "filament_max_volumetric_speed": [. "25". ],. "filament_type": [. "PETG". ],. "filament_density": [. "1.27". ],. "filament_cost": [. "30". ],. "nozzle_temperature_initial_layer": [. "255". ],. "reduce_fan_stop_start_freq": [. "1". ],. "fan_min_speed": [. "20". ],. "nozzle_temperature": [. "255". ],. "temperature_vitrification": [. "80". ],. "nozzle_temperature_r
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1026
            Entropy (8bit):4.184557112426614
            Encrypted:false
            SSDEEP:24:9THpy5v/jvi7RxSmIhrq4oO5bvIqxymMxUPox0PDAgJwA:9THpy5v7ZNrGOKqP1
            MD5:36E205311A3109D1455F156174B60E11
            SHA1:D37BD06F8243B66DEEB432C297743167C4EC2139
            SHA-256:F178B58C47EC5E318ED7C6B76EB39E4789204C4D92CBE0C77A95AE9D41014D9B
            SHA-512:1FA934C93A146FC7D156483CE4005D7EEDC5B229C066737E5412F1522167825E78B399DD21D8A7715CCBED1F5F7689AB9E791239B2624174D44566B438F12ECF
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pla",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "12". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "220". ],. "reduce_fan_stop_start_freq": [. "1". ],. "fan_min_speed": [. "100". ],. "overhang_fan_threshold": [. "50%". ],. "close_fan_the_first_x_layers": [. "1". ],. "nozzle_temperature": [. "220". ],. "temperature_vitrification": [. "60". ],. "nozzle_temperature_range_low": [. "190". ],. "nozzle_temperature_range_high": [. "230". ],. "slow_down_layer_time": [. "4". ],. "additional_cooling_fan_speed": [. "70". ],. "filament_start_gcode": [. "; filam
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1489
            Entropy (8bit):4.114287899570241
            Encrypted:false
            SSDEEP:24:9fHpy5v/Tf2zfbgmH26HyoPvXiw7RoxSwIhrqOgzqPwR4oiMAgbvIqxkmMxNx08g:9fHpy5vbOzTewyGrrYzOeg/g
            MD5:C75ED1FC612C97CCA859FA1F1B7CAE75
            SHA1:F09569904777BC8CFA52AC15FB18C763A2AFAF19
            SHA-256:B0AD3153AA13419889A347671387757B2324C2B30230EE4EA1F825BA3CD0E20D
            SHA-512:B0B36593D6E4D52780569AECB119407C06C98E058F15A5F83024407DDE33BF4BC27F0ED7C2238B9FD465BDD6A838F26E5BD1537694A34EAC4A1A0DDD24004196
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_tpu",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "30". ],. "eng_plate_temp" : [. "30". ],. "hot_plate_temp" : [. "35". ],. "cool_plate_temp_initial_layer" : [. "30". ],. "eng_plate_temp_initial_layer" : [. "30". ],. "hot_plate_temp_initial_layer" : [. "35". ],. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "15". ],. "filament_type": [. "TPU". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "filament_retraction_length": [. "0.4". ],. "nozzle_temperature_initial_layer": [. "240". ],. "reduce_fan_stop_start_freq": [. "1". ],. "slow_down_for_layer_cooling": [. "1". ],. "fan_max_speed": [. "100". ],. "fan_min_sp
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):638084
            Entropy (8bit):7.1347022172682015
            Encrypted:false
            SSDEEP:12288:L43WBcX2okskzaBm3ampMz1fSY66P6JR8fX:E3WBcUsu3awMz1fSY665
            MD5:13221E8EFAFFF7FBEC70CCCAA50AD65A
            SHA1:BD53E5BE1A0B34AC50EC3952AEFF2FEC4BA121E2
            SHA-256:3EBEBD84B8315B33D48B8E3FF29B91A4BA985A3A2F4C8ADD330CF4A49F6D834B
            SHA-512:796AA5C69E34766B093905856CE786DE8E25CE3EC5531A00CF9E4892FE9674A4EC5A98B5E8B2DE8262AF9D47573F60FE542BC34FF4B10F6730A6E7E8D0EB977E
            Malicious:false
            Reputation:low
            Preview:.................................................................................1...o.BF??5.)?.0R>{.....,A..>..|.G.+A..L=.p}.G.+A..J. ....?......L=.p}....A..L=.p}.G.+A..>..|.G.+A.."KY...4?..4?..L=......,A.0R>{.....,A..L=.p}.G.+A...u.<1.4?..4?....|.G.+A..L=......,A..L=.p}.G.+A..!. =K..?&6$;vA..Nz....A....|.G.+A..L=.p}.G.+A.....=.5.?....vA..Nz....A..L=.p}.G.+A..L=.p}....A.....q_3?.i5?.0R>{.....,A..Q>%Rz.G.+A..>..|.G.+A..}..9~?0,#;..L=.p}....A..>..|.G.+A..Q>%Rz.G.+A... ..|3:?.+?n..>.g~...,A..>.pv.G.+A..Q>%Rz.G.+A..U.G.*.{?...+.R>.Nz....A..Q>%Rz.G.+A..>.pv.G.+A...b"..1?..3?.0R>{.....,An..>.g~...,A..Q>%Rz.G.+A.......5.?..?7..L=.p}....A..Q>%Rz.G.+A+.R>.Nz....A...C...-?..5?n..>.g~...,A.7.>..q.G.+A..>.pv.G.+A..6....cv?$.";+.R>.Nz....A..>.pv.G.+A.7.>..q.G.+A...^...0?.`-?'G.?..o...,A...>.&j.G.+A.7.>..q.G.+A..;1..<.p?. >7]B.>..q....A.7.>..q.G.+A...>.&j.G.+A..%....*?..2?n..>.g~...,A'G.?..o...,A.7.>..q.G.+A..u[o.z.x?..7+.R>.Nz....A.7.>..q.G.+A]B.>..q....A.......l#?..6?'G.?
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):576
            Entropy (8bit):4.501918319387547
            Encrypted:false
            SSDEEP:12:q+hR34G0dlpTmuM62jj9k3o25d/Z90TdQjldPx9A:ZJ4HHpTrM62jj9IXd/ZaT2lD9A
            MD5:C2AB33EAD371CC5C64BFC90884D701E3
            SHA1:A788892047A78C198EA3A5C2D7F7E96E93C34324
            SHA-256:61744163741E5D0E7E3C5218199456FA7A4032E752D534E12A98B95BE83E375E
            SHA-512:5D3A87211403A207B6FDBD3605C7C391DC0FBE8FE42C9C6FB7EEB29924396D7201CDC55CF8C5F2399DEF514148E0346F8910DDF36E307F3A3C9B9A0D4B51A677
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_001",. "name": "Creality CR-10 Max 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "nozzle_diameter": [. "0.4". ],. "printer_model": "Creality CR-10 Max",. "default_print_profile": "0.20mm Standard @Creality CR10Max",. "extruder_type": [. "Bowden". ],. "printable_area": [. "0x0",. "450x0",. "450x450",. "0x450". ],. "printable_height": "470",. "retract_lift_below":[. "469". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):426
            Entropy (8bit):4.731646020118261
            Encrypted:false
            SSDEEP:6:fiqQ/E3ohYXWAEF0Iv2s8ZV/Euma4Xkv24Xu4XnQXpAm6DEQ7164DhJ/Xlk/Xlbt:qqn3o+XkFx2s8nMUVX2umo53f/i/8fOv
            MD5:4520C60F0CDF0763BF1ACBFB2CA97CD6
            SHA1:F9245E3E47060898AC7EEFCCEECA9E5A909A2922
            SHA-256:E079F588ED8F8278CF7FF2EB055B0377F108592FF4BF36005D3E98FC8E9D6CB9
            SHA-512:2B20B6686A229FC06EAFB9390B5C991DC7F8A9204ADC52FC8B44FC2E926624CB1FC59573D9B1C8DC7A65F6C8A22DDFDE00B899E270F10434CCDC3C8AE194FF5E
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality CR-10 Max",. "model_id": "Creality_CR-10_Max",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_cr10max_buildplate_model.stl",. "bed_texture": "creality_cr10max_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1901
            Entropy (8bit):4.939986292618786
            Encrypted:false
            SSDEEP:48:xHpTrEfEUUkqcZbUWB/zxvwpjtOJ7z3wwg:J2fwkaq/NvwTczg
            MD5:6DDC853B634E8AADC95BD087F1C294EF
            SHA1:D598C8B0B36553B6414A340BE3CE7A888AFA1CB2
            SHA-256:838FB65F3026AE69054F1C7F6C5EA2C3D794B2FB9EB7931FC6A834B58FFE1FBE
            SHA-512:7A84693727AC15573DF651252FC632FA7FB982A6B6A923642955D9DF94DE3938756813EE8705504369698B161691DE24FC3BBF59F0EB7CF79E55A826CDDF7226
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_000",. "name": "Creality CR-10 V2 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "nozzle_diameter": [. "0.4". ],. "printer_model": "Creality CR-10 V2",. "default_print_profile": "0.20mm Standard @Creality CR10V2",. "extruder_type": [. "Bowden". ],. "printable_area": [. "0x0",. "300x0",. "300x300",. "0x300". ],. "printable_height": "400",. "retract_lift_below":[. "399". ],. "machine_max_acceleration_travel": [. "1500",. "1250". ],. "max_layer_height": [. "0.36". ],. "printer_settings_id": "Creality",. "retraction_length": [. "1". ],. "retract_length_toolchange": [. "1". ],. "single_extruder_multi_material": "0",. "machine_start_gcode": "G90 ; use absolute coordinates\nM83 ; extruder relative mode\nM104 S[nozzle_temperature_in
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):420
            Entropy (8bit):4.771896568299587
            Encrypted:false
            SSDEEP:6:fiqQ/E3ceXWAEmv2s8ZV/Euma0Uv24Xu03QXpAm6DEQ7164DhJ/Xlk/XlbGfOn:qqn3ceXkQ2s8nMiVXAumo53f/i/8fOn
            MD5:32C581CF85D09494D4A1125212875665
            SHA1:E9D73F6626744BAAB45936B37C5D0263D897A4A5
            SHA-256:321DFF8DD6F5BFB7A638C317E73AE0611A3786BE9201008058432736F8297534
            SHA-512:AD9457E7C010AA095464DD4463A82761FF6B64921B5A1556184219F9EF2B044DF175A143A88261B52DEFB5D8F82BA2E3AC006180A9D8918A6305BB6715ED1D07
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality CR-10 V2",. "model_id": "Creality-CR10-V2",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_cr10v2_buildplate_model.stl",. "bed_texture": "creality_cr10v2_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):625
            Entropy (8bit):4.818099546897526
            Encrypted:false
            SSDEEP:12:qehTb3TSBWe0ZJpTEKMP9k3TS2k5SNfhTD5d/gFNEJhTb+2HQhk/xKDgMk:3hTzTxe0ZJpTEKMP9ITDk5SNfhTD5d/R
            MD5:E4C81874F9C4CEE17F74DE7841D95F8A
            SHA1:BADA900F228582354BB1156527DE848AE80157AE
            SHA-256:0A4B7AD78E48B9F4CADB55D0718CD0931FDA48416BE931FD64DABC5380326851
            SHA-512:DC2A436EE555E1023113E9F2FA16D922ED6F1D4EC5FA23F4939E70ECE553C6D7DB070003B4057AD12A365104F0A27B4CDCD67E504A58BF20D0E9C9634CB76615
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_010",. "name": "Creality CR-6 Max 0.2 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality CR-6 Max",. "default_filament_profile": [. "Generic PLA @Creality CR-6". ],. "printer_variant": "0.2",. "default_print_profile": "0.16mm Opitmal @Creality CR-6 0.2",. "nozzle_diameter": [. "0.2". ],. "printable_area": [. "5x5",. "395x5",. "395x395",. "5x395". ],. "printable_height": "400",. "retract_lift_below":[. "399". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):591
            Entropy (8bit):4.832249781003375
            Encrypted:false
            SSDEEP:12:qehW3TSae0ZJpTEKMP9k3TS2k5SNfhTt5d/0EJhT+2zVQhk/xKDgWSk:3hiTfe0ZJpTEKMP9ITDk5SNfhTt5d/9+
            MD5:A346E45D176CD32A4E9712FFDFBEF8BE
            SHA1:265F75169CD75EFEF399C717482B33453ACB67C7
            SHA-256:664C1E14DBE2F44307B9C116F5FACCE97DE6A618B9A7BEC12A973BB7E16730A4
            SHA-512:E8C45418AA40C88C89E40E58DECB61F37217F3C86C4318D2AB586C178F7BEC4EC122CBDFBE00A96C338B37D6C4C779631BBB5121A133F117569EEAD0CBCD6FB0
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_011",. "name": "Creality CR-6 Max 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality CR-6 Max",. "default_filament_profile": [. "Generic PLA @Creality CR-6". ],. "default_print_profile": "0.20mm Normal @Creality CR-6",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "5x5",. "395x5",. "395x395",. "5x395". ],. "printable_height": "400",. "retract_lift_below":[. "399"..],. "nozzle_type": "undefine",. "auxiliary_fan": "0".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):623
            Entropy (8bit):4.812293037024601
            Encrypted:false
            SSDEEP:12:qehd/3TSge0ZJpTEKMP9k3TS2k5SNfhTv5d/0EJhTf+2jQhk/xKDgMa:3hhTte0ZJpTEKMP9ITDk5SNfhTv5d/9f
            MD5:84D4CD9BE3A587E46A50FD4FAF3B8353
            SHA1:E7408F417741E1F51144F7CEFF7482B8478D948F
            SHA-256:BB23C077F02C81144127B703C06D1E8DC2D229B7D29F68EB5219B01448EB173F
            SHA-512:8EDFD994C3FE50C0FFEBFFC085494AA7E22E49CF35A352C7BACD37984D02182AEFA3F4FA0C1D9F1532A7A27FE390452EAC65730277BDACFADA6B203B605A1C06
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_012",. "name": "Creality CR-6 Max 0.6 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality CR-6 Max",. "default_filament_profile": [. "Generic PLA @Creality CR-6". ],. "printer_variant": "0.6",. "default_print_profile": "0.20mm Normal @Creality CR-6 0.6",. "nozzle_diameter": [. "0.6". ],. "printable_area": [. "5x5",. "395x5",. "395x395",. "5x395". ],. "printable_height": "400",. "retract_lift_below":[. "399". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):629
            Entropy (8bit):4.805253503156734
            Encrypted:false
            SSDEEP:12:qehsFFJ3TS+e0ZJpTEKMP9k3TS2k5SNfhTZ5d/O8EJhTA2VQhk/xKDgMk:3hkPTLe0ZJpTEKMP9ITDk5SNfhT7d/Oz
            MD5:10ECE9C830C3F909500168DA3E6C56CA
            SHA1:4D9E867D9F130E3D6BC25D364326422D1D1730C6
            SHA-256:2F07575750A4DFE5FEFB6A4DBE05F4C85E7DE2BCB2A6E6C9FF5C6DF2864A8C94
            SHA-512:8FB0F2645E51505E5D1CB2B2082D6AC381EE954C8CDAEA8641B7BE457345C3B23D5D1FA1E61CFDCA0437CA6E8903CE0D3C75FF85A7B3AC05BB61A5A19176D387
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_013",. "name": "Creality CR-6 Max 0.8 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality CR-6 Max",. "default_filament_profile": [. "Generic PLA @Creality CR-6". ],. "printer_variant": "0.8",. "default_print_profile": "0.32mm Normal @Creality CR-6 0.8",. "nozzle_diameter": [. "0.8". ],. "printable_area": [. "5x5",. "395x5",. "395x395",. "5x395". ],. "printable_height": "400",. "retract_lift_below":[. "399". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):372
            Entropy (8bit):4.751017233659537
            Encrypted:false
            SSDEEP:6:fiqQ/E3TS2vWv2qVEFic4XuTPQXpD/EWmM8ZyXWAEKDEQ716/EYTAnZA:qqn3TS2o2GXcKZMWmM8MXkY5T7ZA
            MD5:9BBB84C044938BAE8512ED56768CE5AC
            SHA1:2A701F828D4D1F42E7FAC8C7C836D9748A047268
            SHA-256:7CFB79E73AA9AEA2B96313ED4C1423F382D6BD78DB1AADD3F57C0C01E47E070A
            SHA-512:D53F76E4053ED7ABB413DCD60CEA72A607B870FB80D07D533FF7FA53C1B110D320A19A95B41145F528F802BC663B650A1A9F25B711609033C5EDFAFBC365FCC6
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality CR-6 Max",. "nozzle_diameter": "0.2;0.4;0.6;0.8",. "bed_texture": "creality_cr6se_buildplate_texture.png",. "family": "Creality",. "hotend_model": "",. "machine_tech": "FFF",. "model_id": "Creality_CR_6_Max",. "default_materials": "Creality Generic PLA;Creality Generic PETG;Creality Generic ABS".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):623
            Entropy (8bit):4.819519141503213
            Encrypted:false
            SSDEEP:12:qehfb3TeWe0ZJpTEKMP9k3Ts5SNfhTD5d/gFNEJhTb+2HQhtwZaIcJqk:3hLTFe0ZJpTEKMP9ITs5SNfhTD5d/gFF
            MD5:B186DBCB68E37AB62DCAA0A4A4D1F2E2
            SHA1:BCA884654CC5B27CEA047F00DEABD4395F1662FB
            SHA-256:88A1A923D1FD87D2A291CEA2FCA291001112AF47272CAD5B9BB7EDD6A062F9C3
            SHA-512:32447F74111A518169D28E92D52C771EF82D4D8FED7253AF68367B93C79BBC2C596AA6B0158274CE398F3417874A73E05C9FEE17887E795F2633C2ABD5A19AB7
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_014",. "name": "Creality CR-6 SE 0.2 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality CR-6 SE",. "default_filament_profile": [. "Generic PLA @Creality CR-6". ],. "printer_variant": "0.2",. "default_print_profile": "0.16mm Opitmal @Creality CR-6 0.2",. "nozzle_diameter": [. "0.2". ],. "printable_area": [. "5x0",. "230x0",. "230x235",. "5x235". ],. "printable_height": "250",. "retract_lift_below":[. "249". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):590
            Entropy (8bit):4.818962826728486
            Encrypted:false
            SSDEEP:12:qehC3Tre0ZJpTEKMP9k3Ts5SNfhTt5d/0EJhT+2zVQhtwZaIcJqk:3hGTre0ZJpTEKMP9ITs5SNfhTt5d/9JS
            MD5:DFFE6454F00776F9672FC5440899EB68
            SHA1:5FC2F8EE9FA5D6BEA81190E7B940957129730A44
            SHA-256:5489FB6AFC13123B7C13783FF38C7ECAA3A4C6E213EF1862F51525A2E4CEC232
            SHA-512:C4552CB4371B7C111714894966440047542EDBAD73DB0346520DE8F875E8D097802767CCE068B2D110123E3C271FE37CFDE4B7181C7B2C9BFA147D2BB6D75DBA
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_015",. "name": "Creality CR-6 SE 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality CR-6 SE",. "default_filament_profile": [. "Generic PLA @Creality CR-6". ],. "default_print_profile": "0.20mm Normal @Creality CR-6",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "5x0",. "230x0",. "230x235",. "5x235". ],. "printable_height": "250",. "retract_lift_below":[. "249". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):621
            Entropy (8bit):4.816445965713855
            Encrypted:false
            SSDEEP:12:qehF3TJe0ZJpTEKMP9k3Ts5SNfhTv5d/0EJhTf+2jQhtwZaIcJqk:3hFTJe0ZJpTEKMP9ITs5SNfhTv5d/9JO
            MD5:78BE30AE67FC4BDDFC8BEDB440260CC2
            SHA1:6B0D19E0D676C85C23350088E15CDCF07D7FA214
            SHA-256:CF7A91684F82042E4B36893A85A3810C73AC3F887C18C3F5761CBA294FDE9358
            SHA-512:E0CD2CEC017606667BD02A50BDA0B57EC2871D1B0DD47577D1F1AD3B1CABF590EA7AC81041CD0698AC47CE4955A08C2CCC7D34B2FAB08A0875C881E69C86F7CA
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_016",. "name": "Creality CR-6 SE 0.6 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality CR-6 SE",. "default_filament_profile": [. "Generic PLA @Creality CR-6". ],. "printer_variant": "0.6",. "default_print_profile": "0.20mm Normal @Creality CR-6 0.6",. "nozzle_diameter": [. "0.6". ],. "printable_area": [. "5x0",. "230x0",. "230x235",. "5x235". ],. "printable_height": "250",. "retract_lift_below":[. "249". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):621
            Entropy (8bit):4.83899967081164
            Encrypted:false
            SSDEEP:12:qehU3T/e0ZJpTEKMP9k3Ts5SNfhT55d/O8EJhTo2VQhtwZaIcJqk:3hYT/e0ZJpTEKMP9ITs5SNfhT55d/OVY
            MD5:02B4C9AA87D5F611A8004873ED36B9E9
            SHA1:8B67A3B4AFFCB21E6BFB75C213B2C577B166496D
            SHA-256:D1FB6C1FCBC79606358E1999D9ADD967C93EA3DFC36A4AF7C76CFA255BDFA347
            SHA-512:E32ECF860AE8D448476E5D1B2BCC1DC8AACA1890FCD8B2519AFA3FF15E40010F78BC8A97921314DBD0851F8E602CB9E30655AC5B19FA55F09C860D5E248138DA
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_017",. "name": "Creality CR-6 SE 0.8 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality CR-6 SE",. "default_filament_profile": [. "Generic PLA @Creality CR-6". ],. "printer_variant": "0.8",. "default_print_profile": "0.32mm Normal @Creality CR-6 0.8",. "nozzle_diameter": [. "0.8". ],. "printable_area": [. "5x0",. "230x0",. "230x235",. "5x235". ],. "printable_height": "250",. "retract_lift_below":[. "249". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):446
            Entropy (8bit):4.81654312467979
            Encrypted:false
            SSDEEP:12:qqn3Tw2uVXcKZMWmM8MXkh253fhTe/hTeZfhTg:J3Tw2uVMKVrXL3fhTQhTghTg
            MD5:35CA5930770CEFECF206DD7183685656
            SHA1:BBD608692D59540EE41C72CF86FE0AACA3ECB48A
            SHA-256:38E6DB67BF5A2B9F466D8B2DAD98491962CAC3A816BEBC1897A8B831D8E36581
            SHA-512:3A092C3709750D6451B731EC545F8C170887184A6B1603FAFD3E1BB49594A5D149281DD91C97A72BF4F58698BE90548A77C508394378F078E95B898C2E5535EE
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality CR-6 SE",. "nozzle_diameter": "0.2;0.4;0.6;0.8",. "bed_model": "creality_CR_6_SE_buildplate_model.stl",. "bed_texture": "creality_cr6se_buildplate_texture.png",. "family": "Creality",. "hotend_model": "",. "machine_tech": "FFF",. "model_id": "Creality_CR_6_SE",. "default_materials": "Generic PLA @Creality CR-6;Generic PETG @Creality CR-6;Generic ABS @Creality CR-6".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2148
            Entropy (8bit):4.98076238670501
            Encrypted:false
            SSDEEP:48:rHpTrEfzpukqcZbUWmYeesVnM/lXEn7vGrws:L2fYkaXYeemnM/lavGL
            MD5:AD843C60ED51ECDA703734E6EA5221F6
            SHA1:1502D19F352ABB4679C796B491C9855854AE1ED5
            SHA-256:98ADCB37A4F59DD2F44F9B9435D60D9D10C8599957A3D906DB766D297A37196E
            SHA-512:258CF827491535FF8EAB7B919CE50636A2C1BFC223CE5E0A37118364B7BCB86D1A8D3CF7F6B3A9A18A2D77F655016A42652941F7DA8AD974C0FE5BB946DA8C20
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_003",. "name": "Creality Ender-3 S1 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "nozzle_diameter": [. "0.4". ],. "printer_model": "Creality Ender-3 S1",. "default_print_profile": "0.20mm Standard @Creality Ender3S1",. "printable_area": [. "0x0",. "220x0",. "220x220",. "0x220". ],. "printable_height": "270",. "retract_lift_below":[. "269". ],. "machine_max_acceleration_travel": [. "1500",. "1250". ],. "max_layer_height": [. "0.36". ],. "printer_settings_id": "Creality",. "retraction_length": [. "1". ],. "retract_length_toolchange": [. "1". ],. "single_extruder_multi_material": "0",. "machine_start_gcode": "G90 ; use absolute coordinates\nM83 ; extruder relative mode\nM140 S[bed_temperature_initial_layer_single] ; set final bed temp\nM10
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2397
            Entropy (8bit):4.935843770477532
            Encrypted:false
            SSDEEP:48:HHpTrEfGw8kq1wwG+bjWgecmPfLnMBIXEn7vGrws:n2f6kYReNHLnMBIavGL
            MD5:485B005C469DEF643560E27E55280D8A
            SHA1:829743BF3C9B704A5D6C202951BEEA516A04EEEA
            SHA-256:0DAA420682C05F8275D8A49B11CC10A5B599F30E29780186A248A3B421E319B3
            SHA-512:FA18E2079713466053742CCD3F18A65203B92769801E267E6587DDE003A6B11A5F793EEB4371281322A12468D8B587459B6AC5FEE7823322EF5E3C5B963F82C7
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_004",. "name": "Creality Ender-3 S1 Pro 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "nozzle_diameter": [. "0.4". ],. "printer_model": "Creality Ender-3 S1 Pro",. "default_print_profile": "0.20mm Standard @Creality Ender3S1Pro",. "printable_area": [. "0x0",. "220x0",. "220x220",. "0x220". ],. "printable_height": "270",. "retract_lift_below":[. "269". ],. "machine_max_acceleration_travel": [. "1000",. "1000". ],. "max_layer_height": [. "0.36". ],. "printer_settings_id": "Creality",. "retraction_minimum_travel": [. "1". ],. "retract_before_wipe": [. "0%". ],. "retraction_length": [. "0.8". ],. "retract_length_toolchange": [. "1". ],. "retraction_speed": [. "30". ],. "deretraction_speed": [. "30"
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):442
            Entropy (8bit):4.727373767417396
            Encrypted:false
            SSDEEP:12:qqnJXkBB92s8nMXFh0VX7FhSumo53f/i/8fOn:JJXcB92sKg0VDn3f/i/qOn
            MD5:2B5C1B6FEB33AAA949A3E73E17E3074E
            SHA1:B65EF9866511C4D22D5582EFD9B72653FF4F1B11
            SHA-256:6BBBC9EC7DF6DA83D576BF288996246C10765715CEF4FFF6988A816F9AD1131B
            SHA-512:B1FA5849D27CBBD59BF4D83CEBC031E300FA7102A26CE3A92439165B0260838FD04EFE8EF9E5B3AD395ADE5026693BEF11175524485737708AD8878EC882E518
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality Ender-3 S1 Pro",. "model_id": "Creality-Ender3-S1-Pro",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_ender3s1pro_buildplate_model.stl",. "bed_texture": "creality_ender3s1pro_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):428
            Entropy (8bit):4.70185897058124
            Encrypted:false
            SSDEEP:12:qqn+XkBBD2s8nMX5VX7pumo53f/i/8fOn:J+XcBD2sKAVQ3f/i/qOn
            MD5:AA0F9ABC037CE25961BF161C76D20593
            SHA1:DB54178465DA5134099F4904CCF35F721D4A3820
            SHA-256:BE1465F3B55F9CD1CB75AEAC750FC7FE5D6CE15E45CDB3BB51FC9AF04149D003
            SHA-512:8019D6B0537AEC84E18DED9B97F6CB2EBED696E5BC9A58D02738D776439B3EE2C0CEDE1BBEC4AC930D9989A2184AF180EB6992674402ABE57C644EF5BF3042A8
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality Ender-3 S1",. "model_id": "Creality-Ender3-S1",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_ender3s1_buildplate_model.stl",. "bed_texture": "creality_ender3s1_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):433
            Entropy (8bit):4.3687004273655745
            Encrypted:false
            SSDEEP:6:fiJ0htgU/Eni0G0dlz9JvFmu+rF8v2OQmgj9HEnWAR/wmkJQtA:q+h6DnFG0dlpTmuM62jj9knWTdQtA
            MD5:6848060B8FABD468EF0E1C62785CC6A6
            SHA1:3502367B3400792278965009036F191361477156
            SHA-256:E8D2C5E19A6DD3B7ECD17732F0C8B928E0CC22405645C6461D74AA161BCE23E4
            SHA-512:8FEDFFBE778CC70AD88BB052EACD9096B4F4B1AA40C9435AF952B73DB51F0F5F11395DE030A1175264CBCB2F22DCA96643020C54E6BEE096C4A49D24204654F6
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_002",. "name": "Creality Ender-3 V2 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "nozzle_diameter": [. "0.4". ],. "printer_model": "Creality Ender-3 V2",. "extruder_type": [. "Bowden". ],. "printable_area": [. "0x0",. "220x0",. "220x220",. "0x220". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):430
            Entropy (8bit):4.704955274327398
            Encrypted:false
            SSDEEP:12:qqnneXkpRg2s8nMXZVX7Jumo53f/i/8fOv:JneXIg2sKgVY3f/i/qOv
            MD5:421EDE174FCAB7618F2CCEF870C29E16
            SHA1:C507DFE6F7BAE0E59F4892F2311967E33E4B1195
            SHA-256:4C8E8C2F06F00DB53EB28BD970FFA00053E107B18253FF570EEA6C0E3749C2D6
            SHA-512:C704D086708B4B3AC72E296A6B5D6D6A191FA67DD58048DC437F7F49C90010F19C7FAF6F4444E6FA7F5FC2810293B35B0D7ADD8BCDD4C12CBBE9E92C0C30D3DD
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality Ender-3 V2",. "model_id": "Creality_Ender_3_V2",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_ender3v2_buildplate_model.stl",. "bed_texture": "creality_ender3v2_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3376
            Entropy (8bit):4.721175778895484
            Encrypted:false
            SSDEEP:48:VTHpTrexCssk/EtkzHkqVkpEtk0EtkgE6ETFY5b6wt6WmYeesVnM/lXEn7vGrJ:VzI0sskMk7kGkSk7ko6XYeemnM/lavGN
            MD5:DF485D6E95994756D44792A5C1A4F267
            SHA1:D905905AE2253C66D724D53882F03AB1B3BE828E
            SHA-256:7BFA835788AD0D77402FFE2F1C0FD7E1D267A5574C6D0A0A5A82C3A7C4B88FEC
            SHA-512:9B437B15FA104CFCCB3CAB38F0ED5ECB6C4DD377D1AA6010D9469DD9F16887032740D9DE883CB9EC4595F6D72E2AF7D64B405869B51811CF9F8A34DDC969168F
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_005",. "name": "Creality Ender-5 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality Ender-5",. "default_print_profile": "0.20mm Standard @Creality Ender5",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "220x0",. "220x220",. "0x220". ],. "printable_height": "300",. "retract_lift_below":[. "299". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0",. "machine_max_acceleration_extruding": [. "500",. "500". ],. "machine_max_acceleration_retracting": [. "1000",. "1000". ],. "machine_max_acceleration_travel": [. "1500",. "1250". ],. "machine_max_acceleration_x": [. "500",. "500". ],. "machine_max_acceleration_y": [. "500",. "500". ],. "machine_max_acceleration_z":
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3270
            Entropy (8bit):4.676781197632837
            Encrypted:false
            SSDEEP:48:IHpTrEfxqakMVHk/EtkzHkqVkpEtk0EtkdFYCZb6wt6WmYeesVnM/lXuayJ:82fEakMVkMk7kGkSk7k76XYeemnM/ls
            MD5:A1770297459DC8B96654CF876FF0811F
            SHA1:585BC209D591057BC76E648C63B966D4EC3D18C2
            SHA-256:012217A7E729748E60FF1BAD27F578D438497F60D10EDB716110B9CB24674D21
            SHA-512:2237041DDC486D8FC064A49A1D50F541259F479EAD9DB155125D25B1A51F3A1C06C41C264474B70ED53A9C9A00BAA948130369D72B8D74E2CCE232E7B1EA19BD
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_006",. "name": "Creality Ender-5 Plus 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "nozzle_diameter": [. "0.4". ],. "printer_model": "Creality Ender-5 Plus",. "default_print_profile": "0.20mm Standard @Creality Ender5Plus",. "printable_area": [. "0x0",. "350x0",. "350x350",. "0x350". ],. "printable_height": "400",. "retract_lift_below":[. "399". ],. "machine_max_acceleration_e": [. "1000". ],. "machine_max_acceleration_extruding": [. "500",. "500". ],. "machine_max_acceleration_retracting": [. "1000",. "1000". ],. "machine_max_acceleration_travel": [. "1500",. "1250". ],. "machine_max_acceleration_x": [. "500",. "500". ],. "machine_max_acceleration_y": [. "500",. "500". ],. "machine_max_a
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):436
            Entropy (8bit):4.689651033773251
            Encrypted:false
            SSDEEP:12:qqnpTFwXkBBIFI2s8nMXvVX7bumo53f/i/8fOn:JQXcBh2sKWVW3f/i/qOn
            MD5:C93E1A1D6529BAFB95650A5A253F382B
            SHA1:E6EBC049ABC8BE176F15AA4BA5B140F8A89F60E9
            SHA-256:B3F26360C4CF02AE30EF387F38362C90291A71081DA929DE5F641B479BCE78A5
            SHA-512:1D695B75EFAE869460DD27790E9815FDBA285BDE00A401DE62EF99BCA90493F703C8AC4206E923B1E1E86AA76DF791D53138FE6E6D7B10917579826D2B2F8DDB
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality Ender-5 Plus",. "model_id": "Creality-Ender5-Plus",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_ender5plus_buildplate_model.stl",. "bed_texture": "creality_ender5plus_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3423
            Entropy (8bit):4.735777858077493
            Encrypted:false
            SSDEEP:48:iHpTreB+Nssk/EtkzHkqVkpEtk0EtkgE6ETFYNbFx6WgecmPfLnMBIXEn7vGrJ:GIkNsskMk7kGkSk7ka6ReNHLnMBIavGN
            MD5:56651E9FB59E8A9440F8FFDAA0B381C7
            SHA1:B9A5D2CDA4AF39CA912D15B99C333AF4D5279770
            SHA-256:132CB1E2A020FCA6AA995026579236AF6CD0A4B68057C642774DFD23E68E2C31
            SHA-512:B1B7C19764150247718DBEB1CBF430ECDC36D7B40737407BA22759AF4B8A6591C1381EC121EF4A70E457583696CCE5DD537CABD56D9ECC364EDE160623B449EA
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_008",. "name": "Creality Ender-5 S1 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality Ender-5 S1",. "default_print_profile": "0.20mm Standard @Creality Ender5S1",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "220x0",. "220x220",. "0x220". ],. "printable_height": "300",. "retract_lift_below":[. "299". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0",. "machine_max_acceleration_extruding": [. "500",. "500". ],. "machine_max_acceleration_retracting": [. "1000",. "1000". ],. "machine_max_acceleration_travel": [. "1500",. "1250". ],. "machine_max_acceleration_x": [. "500",. "500". ],. "machine_max_acceleration_y": [. "500",. "500". ],. "machine_max_accelera
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):428
            Entropy (8bit):4.70185897058124
            Encrypted:false
            SSDEEP:12:qqn8XkBBZ2s8nMXLVX7vumo53f/i/8fOn:J8XcBZ2sKWVC3f/i/qOn
            MD5:2ECFA4ECAE14AC8B9C9D2DE573A30F37
            SHA1:1DCA3750A10CFC8D1F8F0A02A118C9EAED08F0B0
            SHA-256:7728B0B79AF2BBF2E768468E30E77BB006377BEC16D22ABD755D4BEE521B3E2B
            SHA-512:3AE3EA84600AB61A14EC653076E1F4A67BFFA6D76EFCCD43E1812236141B583A218052BBE0517E2413FD5821E3C0A3B0D546C88B6C7A6E2137F558A8999BEA50
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality Ender-5 S1",. "model_id": "Creality-Ender5-S1",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_ender5s1_buildplate_model.stl",. "bed_texture": "creality_ender5s1_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):418
            Entropy (8bit):4.640004374050776
            Encrypted:false
            SSDEEP:12:qqnWXkBBa2s8nMXgHUVX7gHyumo53f/i/8fOn:JWXcBa2sKpUV2H3f/i/qOn
            MD5:BF822EF864653C76D358F6A34176A586
            SHA1:C4401D748CE0B1B46511D5B17A538CB1A6AAFB46
            SHA-256:4D246FD1BDC1AE6BD562F7F31055383B93AC1FAB5A734B44D7C9E38E4FE25CE5
            SHA-512:35E7CAE80431D90DA7EFAEA6F184C069A2F0070514EB598EB7A1333B0621FDC3F6BD83901AB23C84468A383C8FA903F5347E5C2C17B8FA4B501520782A600E0A
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality Ender-5",. "model_id": "Creality-Ender5",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_ender5_buildplate_model.stl",. "bed_texture": "creality_ender5_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3379
            Entropy (8bit):4.724811291250834
            Encrypted:false
            SSDEEP:48:UHpTreGbssk/EtkzHkqVkpEtk0EtkgE6ETFYNb6wt6WmYeesVnM/lXEn7vGrJ:oI8sskMk7kGkSk7kk6XYeemnM/lavGN
            MD5:D330D0514082EBA3F6C8C15E4CCDECBC
            SHA1:28CD90BE9FA2EE2A5C2A0A80590778BB3C3314E1
            SHA-256:5FD9EBA24CDF8B8E022BC0419BB6B0CFC7EB619743F4BED433C909AD3B68D2FC
            SHA-512:D47F711EEC137ED478791D9E48C20CABBE932907F0103BACF9B7CD0A018C9A72715196F578547D8C6589486DB9117A2D33FD3FDDA930FB8C3D91AF49696B17E0
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_007",. "name": "Creality Ender-5S 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality Ender-5S",. "default_print_profile": "0.20mm Standard @Creality Ender5S",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "220x0",. "220x220",. "0x220". ],. "printable_height": "300",. "retract_lift_below":[. "299". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0",. "machine_max_acceleration_extruding": [. "500",. "500". ],. "machine_max_acceleration_retracting": [. "1000",. "1000". ],. "machine_max_acceleration_travel": [. "1500",. "1250". ],. "machine_max_acceleration_x": [. "500",. "500". ],. "machine_max_acceleration_y": [. "500",. "500". ],. "machine_max_acceleration_
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):422
            Entropy (8bit):4.666812040937642
            Encrypted:false
            SSDEEP:12:qqndXkBBG62s8nMXAVX7Gumo53f/i/8fOn:JdXcBG62sK7VP3f/i/qOn
            MD5:01BDE2380B3CBEB3FFD8900D40C3E6D6
            SHA1:629D9A5208D841D0D777D9D3B056E84C9CC76558
            SHA-256:647F94EA01AC57BE72F7563DB14704174944C876FA7A76DBC13955E89DD5A084
            SHA-512:33C0B881CBBB6F29D5773B9FDFA02616450DB4A05CF7EF510F126D7119B77157EF5AB202D3521C2B6CF3C62B6E0BB81514758A384945430F8B71FAF283090E13
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality Ender-5S",. "model_id": "Creality-Ender5S",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_ender5s_buildplate_model.stl",. "bed_texture": "creality_ender5s_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3304
            Entropy (8bit):4.669778246240571
            Encrypted:false
            SSDEEP:48:0HpTre6PSu9sk/EtkzHkqVkpEtk0EtkgE6ERjFYQb6wt6WmYeesVnM/lXuayJ:II6BskMk7kGkSk7kJ6XYeemnM/ls
            MD5:ED032A0135BD0A32B0BC13E70BB440D9
            SHA1:CAD2A6D5CA4D0FDAA675DBA43EDDEA485550FCE9
            SHA-256:D5759FFF80177C7139D516A44A742ADE92BF7EBBA9C08763AC8D0575AEBF3ACB
            SHA-512:ABF79AA0137C3E9629595AF566A7E6D88B3E21B2C892E8D4BCB4FBD56985D3218FEF517C0281138DB3549D6912A5389E28E637956C863B9C18665509907D521E
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_CREALITY_009",. "name": "Creality Ender-6 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_creality_common",. "printer_model": "Creality Ender-6",. "default_print_profile": "0.20mm Standard @Creality Ender6",. "nozzle_diameter": [. "0.4". ],. "extruder_type": [. "Bowden". ],. "printable_area": [. "0x0",. "250x0",. "250x250",. "0x250". ],. "printable_height": "400",. "retract_lift_below":[. "399". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0",. "machine_max_acceleration_extruding": [. "500",. "500". ],. "machine_max_acceleration_retracting": [. "1000",. "1000". ],. "machine_max_acceleration_travel": [. "1500",. "1250". ],. "machine_max_acceleration_x": [. "500",. "500". ],. "machine_max_acceleration_y": [. "500",.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):418
            Entropy (8bit):4.640004374050776
            Encrypted:false
            SSDEEP:12:qqnLXkBBF2s8nMXmhVX7mhumo53f/i/8fOn:JLXcBF2sKPVN3f/i/qOn
            MD5:E3FDF128C68B6352486F093D0C2F00EB
            SHA1:67097564643547BCCE5738DF6B5A1CE8A9E11339
            SHA-256:37532D6D9C43F9C9B44A6102B4331D6AA26F23CFFEFCE6B9936CB4DE47FA4382
            SHA-512:85BCD33EF495C46C3B4B0B2623B1D9E03B0BC2313FD2FA4E89C5109DA619E26EB297B7A6C806B2C0CEC30EF2A16E42059B0ABA4B6E28170B83F0ED8DC812D499
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality Ender-6",. "model_id": "Creality-Ender6",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_ender6_buildplate_model.stl",. "bed_texture": "creality_ender6_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2105
            Entropy (8bit):4.970493336704192
            Encrypted:false
            SSDEEP:48:7lQpYvLEyLApcqakMak0kFkqHkKkTkL3xZKNU6z0ZK6FLqF:7CSwyLQakMak0kFkIkKkTkE+K6FLA
            MD5:AB4C747E3502E0D87C3281AC0A3D089A
            SHA1:2AFA3D8A578F51666F967268C60FC3F2E2D8DD37
            SHA-256:3CAAB98D9525851C6EFAB6B8DD7520AC551BE1412A33B12AE6AF6C8B59B31C58
            SHA-512:741BFD85B1B10116176AA0B4D128AFC7F0B190E86F9B86BE13BDFF6781BE232595E4EDF1B9411E0849C763182406566EC0B5894D384A5DDF27F453F913CA3137
            Malicious:false
            Reputation:low
            Preview:{.."type": "machine",.."setting_id": "GM_CREALITY_018",.."name": "Creality K1 0.4 nozzle",.."from": "system",.."instantiation": "true",.."inherits": "fdm_creality_common",.."printer_model": "Creality K1",.."gcode_flavor": "klipper",.."default_print_profile": "0.20mm Standard @Creality K1 0.4 nozzle",.."nozzle_diameter": [..."0.4"..],.."nozzle_type": "stainless_steel",.."printer_structure": "corexy",.."thumbnail_size": [..."96x96",..."300x300"..],.."version": "1.8.0.2",.."printer_variant": "0.4",.."printable_area": [..."0x0",..."220x0",..."220x220",..."0x220"..],.."printable_height": "250",.."auxiliary_fan": "1",.."machine_max_acceleration_e": [..."5000",..."5000"..],.."machine_max_acceleration_extruding": [..."20000",..."20000"..],.."machine_max_acceleration_retracting": [..."5000",..."5000"..],.."machine_max_acceleration_travel": [..."9000",..."9000"..],.."machine_max_acceleration_x": [..."20000",..."20000"..],.."machine_max_acceleration_y": [..."20000",..."20000"..],.."machine_max_ac
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2116
            Entropy (8bit):4.969081136291158
            Encrypted:false
            SSDEEP:48:qQpYvpMyLApcAZkMak0kFkqHkKkTkL3xZKNU6z0ZK6FLqF:TSSyLeZkMak0kFkIkKkTkE+K6FLA
            MD5:E75315E66BB176B114F1A3E1192E4D94
            SHA1:C74E216ADC589754E97602E2D33D5DF4E428FFEE
            SHA-256:AF220A961B708719FE6DC5FAF8D4019C5F507865FCAA36A71374AC723EF2DE18
            SHA-512:DAF2AC1CCFCF7761F008C10F9D0949F0DA602C96AB902C70EDD2E25926B990EBC7A9C14415989566C5E293663E498901CABBD480D22D25E644653053B721E438
            Malicious:false
            Reputation:low
            Preview:{.."type": "machine",.."setting_id": "GM_CREALITY_020",.."name": "Creality K1 Max 0.4 nozzle",.."from": "system",.."instantiation": "true",.."inherits": "fdm_creality_common",.."printer_model": "Creality K1 Max",.."gcode_flavor": "klipper",.."default_print_profile": "0.20mm Standard @Creality K1Max 0.4 nozzle",.."nozzle_diameter": [..."0.4"..],.."nozzle_type": "stainless_steel",.."printer_structure": "corexy",.."thumbnail_size": [..."96x96",..."300x300"..],.."version": "1.8.0.2",.."printer_variant": "0.4",.."printable_area": [..."0x0",..."300x0",..."300x300",..."0x300"..],.."printable_height": "300",.."auxiliary_fan": "0",.."machine_max_acceleration_e": [..."5000",..."5000"..],.."machine_max_acceleration_extruding": [..."20000",..."20000"..],.."machine_max_acceleration_retracting": [..."5000",..."5000"..],.."machine_max_acceleration_travel": [..."9000",..."9000"..],.."machine_max_acceleration_x": [..."20000",..."20000"..],.."machine_max_acceleration_y": [..."20000",..."20000"..],.."mac
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):415
            Entropy (8bit):4.717594985114095
            Encrypted:false
            SSDEEP:6:fiqQ/EP9YXWAEVBWv2s8ZV/EumaYkv24XuYnQXpAm6DEQ7164DhJ/Xlk/XlbGfOn:qqnPiXkrg2s8nMwVXqumo53f/i/8fOn
            MD5:0A4C42D41AD036551BFFB30E6C84FF28
            SHA1:895B42AF4E58E7D03ACF8125151921158077DF01
            SHA-256:9710A9643A4018DDF1908DAA7FC6B0E4E58301AEBCE1C7711302591C3CDCE5AD
            SHA-512:42E05498A41F92901237845BF6E85B482CE9A390B9C583AAD8AFC7F2BCDBEAAED964F13B470D25F38034E5C65490FAFDF04C27E8374B7C882C44D2476A9EE09C
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality K1 Max",. "model_id": "Creality-K1-Max",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_k1max_buildplate_model.stl",. "bed_texture": "creality_k1max_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):401
            Entropy (8bit):4.673541098435816
            Encrypted:false
            SSDEEP:6:fiqQ/EN+XWAEhv2s8ZV/Eumafv24XuaQXpAm6DEQ7164DhJ/Xlk/XlbGfOn:qqnUXk12s8nMeVXMumo53f/i/8fOn
            MD5:97D8D91FE3214395ADD6EE64740DDB0C
            SHA1:2A6E756C42D5DD47F4FED5ED249756782C6863C4
            SHA-256:898725925DCE9F48C8AF6A39E18655EE5669BCD91F94B6372ED3809D1CC3B667
            SHA-512:88788AA6F2F406845A5201E489FF8EE59D251BA37ACB14A42715CA9BE4638309DDA0B1AA54DCC37BF5A3B36744E7A6D04DB6A380F11EF056539D2E633A9A70D0
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Creality K1",. "model_id": "Creality-K1",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Creality",. "bed_model": "creality_k1_buildplate_model.stl",. "bed_texture": "creality_k1_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic PLA @Creality;Generic PETG @Creality;Generic ABS @Creality".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3210
            Entropy (8bit):4.706098677306018
            Encrypted:false
            SSDEEP:48:FHpytkMpK3k/EtkzHkqAEtkpEtk0EtkgE6ERjV3h46wTt/WmpeesVn//lXtnuvnX:N0kMwkMk7kIkSk7kux/Xpeemn//lQvnX
            MD5:1BDCCD05F1A8EE8B579482C4F37821C1
            SHA1:879E14C43F5D0A0CBA7552DCBC96F4E48754A78C
            SHA-256:B4AAE12B2EDCA84F8A427B7601ABCAA7845E12E1D35AA37D79C1F0BE1570AF8F
            SHA-512:FB9AB4200DFC8E223DA41F55580E34FD29F6FD6913F9B94834FC757E39B0D638CDACA559553F4EDED9ABD96926E9412DE8086875C4E2C2AE8CCD18A83B047B0A
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "name": "fdm_creality_common",. "from": "system",. "instantiation": "false",. "inherits": "fdm_machine_common",. "printer_variant": "0.4",. "machine_max_acceleration_e": [. "5000",. "5000". ],. "machine_max_acceleration_extruding": [. "500",. "500". ],. "machine_max_acceleration_retracting": [. "1000",. "1000". ],. "machine_max_acceleration_travel": [. "500",. "500". ],. "machine_max_acceleration_x": [. "500",. "500". ],. "machine_max_acceleration_y": [. "500",. "500". ],. "machine_max_acceleration_z": [. "100",. "100". ],. "machine_max_speed_e": [. "60",. "60". ],. "machine_max_speed_x": [. "500",. "500". ],. "machine_max_speed_y": [. "500",. "500". ],. "machine_max_speed_z": [. "10",. "10". ],. "machine_max_jerk_e": [.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3112
            Entropy (8bit):4.695365604572646
            Encrypted:false
            SSDEEP:48:/HpMCqVrBkMp3khkiHkvkYkp67NZiRYWab04agS2HcXMXIP+ELzZsxcLMxHoM:/qLBkMRkhk2kvkYkN8mPW6zZfuX
            MD5:898424D20790A43CCE1FF4FCCE125081
            SHA1:B2C4767B23CDD5FE8F2B63AC5DE2DD8B48417388
            SHA-256:540EEBC55E362CDA207AEF4B438838960226AC7B960C60477A1942BCCF6714CC
            SHA-512:2955C4BA9C3CF92D570959C763DB2E12180630C2812B65F492981690B292B1F417B64961C594EB864534F01226B3754B42B7100E707F9038B97866357A935EDB
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "name": "fdm_machine_common",. "from": "system",. "instantiation": "false",. "nozzle_diameter": [. "0.4". ],. "printer_variant": "0.4",. "printer_technology": "FFF",. "deretraction_speed": [. "40". ],. "extruder_colour": [. "#FCE94F". ],. "extruder_offset": [. "0x0". ],. "gcode_flavor": "marlin",. "silent_mode": "0",. "machine_max_acceleration_e": [. "5000". ],. "machine_max_acceleration_extruding": [. "10000". ],. "machine_max_acceleration_retracting": [. "1000". ],. "machine_max_acceleration_x": [. "10000". ],. "machine_max_acceleration_y": [. "10000". ],. "machine_max_acceleration_z": [. "100". ],. "machine_max_speed_e": [. "60". ],. "machine_max_speed_x": [. "500". ],. "machine_max_speed_y": [. "500". ],. "machine_max_speed_z": [. "10". ],. "machine_max_
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):717
            Entropy (8bit):4.657038784591469
            Encrypted:false
            SSDEEP:12:8GTFphAsVRqJhTbo0dlpTmuVwV0Jlx3LZUaJAdJkWGh3TeW4h3TSBbA:8GTFrdqJhTbtHpTrqVQZ7AAWU3TFW3T7
            MD5:F48FF1167828DDFD31AB627D4CDAF99D
            SHA1:9F3F1E276CE37BB1E09D17E588890BA2C9114562
            SHA-256:61E904ADB2A5B7F8EA70326F5E4140987281EE7307809DEB518BCE12A0B269BC
            SHA-512:48B4A74F6197A80AB4EF465ECDC01CD0A0F366645AD5ED570E19A2CB6D96872E5C62BB47453F6ECCED2D9E3A9D1582D7ADFF58921BEB4A41327C2DCFF0856402
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_CREALITY_034",. "name": "0.08mm SuperDetail @Creality CR-6 0.2",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_creality_common",. "bottom_shell_layers": "5",. "initial_layer_line_width": "0.2",. "initial_layer_print_height": "0.12",. "inner_wall_line_width": "0.2",. "internal_solid_infill_line_width": "0.2",. "layer_height": "0.08",. "line_width": "0.2",. "outer_wall_line_width": "0.2",. "sparse_infill_line_width": "0.2",. "top_shell_layers": "6",. "top_surface_line_width": "0.2",. "compatible_printers": [. "Creality CR-6 SE 0.2 nozzle",. "Creality CR-6 Max 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):637
            Entropy (8bit):4.650605379861928
            Encrypted:false
            SSDEEP:12:8GTFphAg/JhTo0dlpTmuVwmqhJLRdJmWlh3Tr4h3TSvA:8GTFrB/JhTtHpTrqVLRCWP3TrW3T2A
            MD5:ED6AB7B2B04020E213C25EF03C3B4FE4
            SHA1:F758F50276CB857F926246ABC3D915B0A15E8E60
            SHA-256:68712429F531CF4CB78B1345E5CCFE49EA95A494CE328D20BD62000903120BC5
            SHA-512:B3F776D1BFC46105B7996B12BCCD31505D6DB3FC9D07A94FAFDED4A8A6ACED576A1B217254FE03304DECB14A1006AEFDF860C48662EAFBC85C45A28EEB4435A7
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_CREALITY_000",. "name": "0.10mm HighDetail @Creality CR-6",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_creality_common",. "initial_layer_line_width": "0.3",. "inner_wall_line_width": "0.3",. "internal_solid_infill_line_width": "0.3",. "layer_height": "0.1",. "line_width": "0.3",. "outer_wall_line_width": "0.3",. "sparse_infill_line_width": "0.3",. "top_shell_layers": "4",. "top_surface_line_width": "0.3",. "compatible_printers": [. "Creality CR-6 SE 0.4 nozzle",. "Creality CR-6 Max 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):685
            Entropy (8bit):4.644618590994595
            Encrypted:false
            SSDEEP:12:8GTFphAMIIJ+4E0dlpTmDIIJhTJ0Jlx3LZUaJNdJkWGh3TeW4h3TSBbA:8GTFrt5J+45HpT65JhTJQZ7NAWU3TFWH
            MD5:ECEDEE29A28C1008E42DD217ABE8D1C6
            SHA1:B268E9C0228152E19ADB450916B2E1B8535C1310
            SHA-256:E74FCB84F1CEFE838092252B42F1B94174E48F99F8594551F6E107F18BF5DA38
            SHA-512:C78237E3B8E63DE84FEE448D8DD58F9513D18CDB3695894D53F1AFC9B8F3E4ADECDF9AF8C91E1F7D4A650EF50D828F546CA16F4E112CBE56B05812BB01B6B371
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_CREALITY_048",. "name": "0.12mm Detail @Creality 0.2 CR-6",. "from": "system",. "instantiation": "true",. "inherits": "0.12mm Detail @Creality CR-6",. "bottom_shell_layers": "5",. "initial_layer_line_width": "0.2",. "initial_layer_print_height": "0.12",. "inner_wall_line_width": "0.2",. "internal_solid_infill_line_width": "0.2",. "line_width": "0.2",. "outer_wall_line_width": "0.2",. "sparse_infill_line_width": "0.2",. "top_shell_layers": "6",. "top_surface_line_width": "0.2",. "compatible_printers": [. "Creality CR-6 SE 0.2 nozzle",. "Creality CR-6 Max 0.2 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):209
            Entropy (8bit):4.664364774406283
            Encrypted:false
            SSDEEP:6:fEaxTFu0ht+oQIIJA0dlz9JvFmDIIJhTg:8GTFphA9IIJA0dlpTmDIIJhTg
            MD5:F5FBC41AFEDF419A4AFA3275BA311D9E
            SHA1:0420A688A3B6B5544FBF5B3EB288D91B2E928986
            SHA-256:76E8C530C5CFF9733546060C36AD39469A043FF5798B8F20E4CF7E79CC8A0716
            SHA-512:01296E334B6AD0AC604BD7B705713669F293CF2F785898E1BED5EA81A9F8BDE6D5D063077B2A74978318B14AFF1D15164348A69A7860FA11902864FA74A2B3F1
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_CREALITY_050",. "name": "0.12mm Detail @Creality 0.4 CR-6",. "from": "system",. "instantiation": "true",. "inherits": "0.12mm Detail @Creality CR-6".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):12071
            Entropy (8bit):4.251346528179768
            Encrypted:false
            SSDEEP:96:qG49kpAXiSF72AHNUsT42U5Q1+fvciz1OEJh6N4Gzifghxeklfw2DLsHdVQhgr:qGvGzifghxeklfw2DLsHdahgr
            MD5:1C8F53563199CF0C6D439B3087D88A14
            SHA1:44497E12AFE2EEB02C68D1CBCC8D95075755AF8D
            SHA-256:CC4C13ABE82B31805C6AF2F3FB1CA344C38DE205A4CA6A716B37B75FC8728D82
            SHA-512:F25BE41F50503672009000AC81C14D4A392B48A8194984020DB7DCF02C2EAE5F8A6FC6D7A3CC8F2F1CB7E476DE34C97602634129251D9F5D1865A71792F7E921
            Malicious:false
            Reputation:low
            Preview:{. "name": "Elegoo",. "version": "01.08.00.03",. "force_update": "0",. "description": "Elegoo configurations",. "machine_model_list": [. {. "name": "Elegoo Neptune",. "sub_path": "machine/Elegoo Neptune.json". },. {. "name": "Elegoo Neptune X",. "sub_path": "machine/Elegoo Neptune X.json". },. {. "name": "Elegoo Neptune 2",. "sub_path": "machine/Elegoo Neptune 2.json". },. {. "name": "Elegoo Neptune 2S",. "sub_path": "machine/Elegoo Neptune 2S.json". },. {. "name": "Elegoo Neptune 2D",. "sub_path": "machine/Elegoo Neptune 2D.json". },. {. "name": "Elegoo Neptune 3",. "sub_path": "machine/Elegoo Neptune 3.json". },. {. "name": "Elegoo Neptune 3 Pro",. "sub_path": "machine/Elegoo Neptune 3 Pro.json". },. {.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3493
            Entropy (8bit):4.110237658980711
            Encrypted:false
            SSDEEP:24:01OEaO1QXVOv/aw3xjrjLp5hB9ErHIvJpwr:U7ayyVOvyw3drjLp5hBEIMr
            MD5:B8A09573CAA7B0C7715B4776EC07B7F2
            SHA1:426D84DC98D44B89766F1B921AAD7E0C28C747BC
            SHA-256:ACE9DA318BE550AEF04F91F6C30A0EAEAA8CD9D3650A28D033DBCCA24FA23317
            SHA-512:67D3ADDC3A745F0E65D29FED4353C1BF31C970CDC06FC94161BA6261ED8A86F088F1B9C0E9D3D06F80AD7990417261B178E01867BA14B7524192B09B20D203AE
            Malicious:false
            Reputation:low
            Preview:{. "name": "Prusa",. "version": "01.08.00.03",. "force_update": "0",. "description": "Prusa configurations",. "machine_model_list": [. {. "name": "Prusa MK3S",. "sub_path": "machine/Prusa MK3S.json". },. {. "name": "Prusa MINI",. "sub_path": "machine/Prusa MINI.json". }. ],. "process_list": [. {. "name": "fdm_process_common",. "sub_path": "process/fdm_process_common.json". },. {. "name": "0.20mm Standard @MK3S",. "sub_path": "process/0.20mm Standard @MK3S.json". },. {. "name": "0.20mm Standard @MINI",. "sub_path": "process/0.20mm Standard @MINI.json". }. ],. "filament_list": [. {. "name": "fdm_filament_common",. "sub_path": "filament/fdm_filament_common.json". },. {. "name": "fdm_filament_abs",. "sub_path": "filament/f
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):9100
            Entropy (8bit):4.227795002952182
            Encrypted:false
            SSDEEP:96:0kOFYFcFoFbFSF40bThdmVchHFKFqFeF7FKF0r:0kOCy6N8q0bThdm+hHcA4lk+r
            MD5:484C78A9F04B5627782DC21635F771FF
            SHA1:B3594BCBDA47F8C73721E2151E37907E9CF6DEE0
            SHA-256:584BF95CF714FC8DE501CDC7ACF8387569B48784B87E01EFF9F70CD80C3638DC
            SHA-512:3767C19F192732976C468453496EFA052EA8F93A0F1D523E33071AF6091D841514E511ED1252AC93E1E2094F0A56974273929052B40A948DA04B990980666E9F
            Malicious:false
            Reputation:low
            Preview:{. "name": "Qidi",. "version": "01.08.00.04",. "force_update": "0",. "description": "Qidi configurations",. "machine_model_list": [. {. "name": "Qidi X-Plus",. "sub_path": "machine/Qidi X-Plus.json". },. {. "name": "Qidi X-Max",. "sub_path": "machine/Qidi X-Max.json". },. {. "name": "Qidi X-CF Pro",. "sub_path": "machine/Qidi X-CF Pro.json". },. {. "name": "Qidi X-Smart 3",. "sub_path": "machine/Qidi X-Smart 3.json". },. {. "name": "Qidi X-Plus 3",. "sub_path": "machine/Qidi X-Plus 3.json". },. {. "name": "Qidi X-Max 3",. "sub_path": "machine/Qidi X-Max 3.json". }. ],. "process_list": [. {. "name": "fdm_process_common",. "sub_path": "process/fdm_process_common.json". },. {. "name": "fdm_process_qidi_
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3861
            Entropy (8bit):4.194077888314755
            Encrypted:false
            SSDEEP:24:J1OEa/+I8QN0KQ5jWYTYo6/6qVOv/aw5xp3LxjhrX9ErHIvPDr:77aQ0Q5WIMVOvyw5xp3LdhrXEITr
            MD5:2F39AAE6A21E25EF61BB57FD703531FF
            SHA1:6899C5152B546E80D516B04910A90C825C5A0352
            SHA-256:4E127B470DD3C25AC6015528C2AD62B0B4E96AF364BE52D09DF1D9C2BA6F5055
            SHA-512:7A4C27956C010C7F815540CC2C4910B14D581BD9AC28FA6B4EDFC95C607AE3FC0D0916EC3709DA7F0E90D9BA2490580705D75A30BE01CE8D27EFD05637125242
            Malicious:false
            Reputation:low
            Preview:{. "name": "Tronxy",. "version": "01.08.00.03",. "force_update": "0",. "description": "Tronxy configurations",. "machine_model_list": [. {. "name": "Tronxy X5SA 400 Marlin Firmware",. "sub_path": "machine/Tronxy X5SA 400 Marlin Firmware.json". }. ],. "process_list": [. {. "name": "fdm_process_common",. "sub_path": "process/fdm_process_common.json". },. {. "name": "0.08mm Extra Fine @Tronxy",. "sub_path": "process/0.08mm Extra Fine @Tronxy.json". },. {. "name": "0.12mm Fine @Tronxy",. "sub_path": "process/0.12mm Fine @Tronxy.json". },. {. "name": "0.15mm Optimal @Tronxy",. "sub_path": "process/0.15mm Optimal @Tronxy.json". },. {. "name": "0.20mm Standard @Tronxy",. "sub_path": "process/0.20mm Standard @Tronxy.json". },. {. "name": "0.24
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1568
            Entropy (8bit):4.094531360924966
            Encrypted:false
            SSDEEP:24:9ZHpy5v/TK2zHwbHwDHwmi26PwyPwKPwOgzqbvGCZv6SwcoRxSawIhrqPwyqo8oN:9ZHpy5vbnzmQnFzatXSrOX9N
            MD5:EBC718D41A605C12F9377589805B0295
            SHA1:CB17B9FA4F962D442D9B9F69FE0270E6C30EFB54
            SHA-256:FC7FF0B2283FA534359EF90F9AE0406193BE8EF37FB4DDBA9F71C6CB0A9C8642
            SHA-512:5E0F71FC53342C6D2249B3FE2852F994F4343C92AC5DAF42744CDEBBFD41170DB434F6692FB1EE4D7CFA9288C0DB0BBFF40EEDB8DCDC14F2D78539016D10C757
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pc",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "0". ],. "eng_plate_temp" : [. "110". ],. "hot_plate_temp" : [. "110". ],. "textured_plate_temp" : [. "110". ],. "cool_plate_temp_initial_layer" : [. "0". ],. "eng_plate_temp_initial_layer" : [. "110". ],. "hot_plate_temp_initial_layer" : [. "110". ],. "textured_plate_temp_initial_layer" : [. "110". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "30". ],. "filament_max_volumetric_speed": [. "23.2". ],. "filament_type": [. "PC". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "270".
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1485
            Entropy (8bit):4.09844788979624
            Encrypted:false
            SSDEEP:24:9RHpy5v/TO2zKbgDgmW26iyYKYOgzqbvGCMvAdClQExSWIhrqPwRloiMxymix3xt:9RHpy5vb7zAALbzfbedrObG
            MD5:DFD5D0BFC8AF0158F1C45DB2EA3F9083
            SHA1:67AD8B450CA296BEEC8DEB8A6866E9ECAE3DBACC
            SHA-256:F753AD2C2066C32C9ACE0959724B408A21B5AA32985966F825DE519AA224AA4B
            SHA-512:F81ACE708C31EB3C30A65F3D073F381E88A001EC017C95977AB548C0D6157BDFC54E5520F4840E01191794E1556E6CC0F1C4A6E740C88C05C031C52AD37E5121
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pet",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "0". ],. "hot_plate_temp" : [. "80". ],. "textured_plate_temp" : [. "80". ],. "cool_plate_temp_initial_layer" : [. "60". ],. "eng_plate_temp_initial_layer" : [. "0". ],. "hot_plate_temp_initial_layer" : [. "80". ],. "textured_plate_temp_initial_layer" : [. "80". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "20". ],. "filament_max_volumetric_speed": [. "25". ],. "filament_type": [. "PETG". ],. "filament_density": [. "1.27". ],. "filament_cost": [. "30". ],. "nozzle_temperature_initial_layer": [. "255". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1697
            Entropy (8bit):4.104138497261157
            Encrypted:false
            SSDEEP:24:9THpy5v/jviT7R/O2zObODOmW26WyWKWxSmIhrqOgzqPwR4oiMoO5bvIqxymMxUX:9THpy5v767zEqd6NrYzOe0OKqPP
            MD5:EF709238E6BA0FFFB1E50C355854D78B
            SHA1:5D3C4872C5308E5A7775AC8E7D9157F9AB1F9007
            SHA-256:65DE50F6DAB0C9F550C0C3D465549F5E7389A2332C7E6B949C66402DD9CF7735
            SHA-512:F9F7E72F77FAAC9B422BF77182B396F705553556B83F70D5D9C3D8F63789EFD0E2BED39F7D2AEA327F7D8DA3179B76152E697CB990BE4DF9AD2DABAC5F128FAA
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pla",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "12". ],. "filament_type": [. "PLA". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "60". ],. "hot_plate_temp" : [. "60". ],. "textured_plate_temp" : [. "60". ],. "cool_plate_temp_initial_layer" : [. "60". ],. "eng_plate_temp_initial_layer" : [. "60". ],. "hot_plate_temp_initial_layer" : [. "60". ],. "textured_plate_temp_initial_layer" : [. "60". ],. "nozzle_temperature_initial_layer": [. "220". ],. "reduce_fan_stop_start_freq": [. "1". ],. "slow_down_for_layer_cooling": [. "1". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1788
            Entropy (8bit):4.097754760791249
            Encrypted:false
            SSDEEP:24:9ZHpy5v/Tg2zKbjDjmo26iyrKrPvXD4qkzq97RxSmIhrqOgzqPwR4oiMoO5bvIq2:9ZHpy5vbdzAHy/UDzXNrYzOe0OKzVPAi
            MD5:93AFB2AD0669F88A22BD26E4E6D1361A
            SHA1:3085299A770B58C76A7FEB7A5697A7507D64B937
            SHA-256:0686BAE3D5221CEEA41CAA469610D10DD352A6089E2FFBECCAAEE51AF0531D39
            SHA-512:67D92006411C8BAEDF667F77219B058FC9A6D84DD81637026600CD7112041BEABB7CDAC3B8FC8407A09E28EF1338B4B5B601DB1C5465A2248D76814C8443600B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pva",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "35". ],. "eng_plate_temp" : [. "0". ],. "hot_plate_temp" : [. "45". ],. "textured_plate_temp" : [. "45". ],. "cool_plate_temp_initial_layer" : [. "35". ],. "eng_plate_temp_initial_layer" : [. "0". ],. "hot_plate_temp_initial_layer" : [. "45". ],. "textured_plate_temp_initial_layer" : [. "45". ],. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "15". ],. "filament_soluble": [. "1". ],. "filament_is_support": [. "1". ],. "filament_type": [. "PVA". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "220". ],. "reduce_fan_stop_s
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1603
            Entropy (8bit):4.109406244255383
            Encrypted:false
            SSDEEP:24:9fHpy5v/Tf2zfbgDgmH26HyoKoPvXiw7RoxSwIhrqOgzqPwR4oiMAgbvIqxkmMxk:9fHpy5vbOzTAegyGrrYzOeg/g
            MD5:F4153047E773DE3AAE04B4AB679BA086
            SHA1:6855A107AD93D340AE633AED43E87048346B9205
            SHA-256:772368404EE59E786C875861EE943754EF5781331660E6BAB5BC66A0006EE8AF
            SHA-512:BA08BACC3D1DF681D43111D871121E300341CF7557C6A90BCD0516CFB1373A966DEFFEDCADDA87B33AA3639FCA486F473941B2ACAC532157754E2323697374F6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_tpu",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "30". ],. "eng_plate_temp" : [. "30". ],. "hot_plate_temp" : [. "35". ],. "textured_plate_temp" : [. "35". ],. "cool_plate_temp_initial_layer" : [. "30". ],. "eng_plate_temp_initial_layer" : [. "30". ],. "hot_plate_temp_initial_layer" : [. "35". ],. "textured_plate_temp_initial_layer" : [. "35". ],. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "15". ],. "filament_type": [. "TPU". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "filament_retraction_length": [. "0.4". ],. "nozzle_temperature_initial_layer": [. "240". ],. "reduce_fan_stop_start_freq": [. "1". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):496
            Entropy (8bit):4.6994386911729285
            Encrypted:false
            SSDEEP:12:qehGV1e0ZJpTEKWrP98sS+l2zVQlVH5Stk5d/S4:3hGfe0ZJpTEKWrP9MG2zsZ5Stk5d/b
            MD5:DC5097B20D34D5F1455435A952530506
            SHA1:70EF25C1C482815BBBDAB560E65F0E96AC771531
            SHA-256:5A3DB694562722D1458E1E993A42685C08A1B0FA86A3196FBA1DB3B04CEA3E48
            SHA-512:39B75C1B00499E0814DD6134C6BCB90D4E288605E5F214DBDB1EB6727B29EC801EA2DA425A83E9641AB0B004C22C06CCB5A4AF6BB65FDC71DCEC45E1A0F0E28D
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_Tronxy_003",. "name": "Tronxy X5SA 400 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_machine_common",. "printer_model": "Tronxy X5SA 400 Marlin Firmware",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "400x0",. "400x400",. "0x400". ],. "printable_height": "400",. "default_filament_profile": [. "Generic PLA @Tronxy". ],. "default_print_profile": "0.20mm Standard @Tronxy".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):521
            Entropy (8bit):4.809169740267119
            Encrypted:false
            SSDEEP:12:qqHsS+XX80nF2s8nEoCX6mo5TEAqjA/AWdCAClALA3ATApAJzAb:JT2XBF2sKLCygD
            MD5:D712BBDDB7A941C7D16A0841D8E782A2
            SHA1:39373448ADDA9DDDD8440B77A1824BE0885BDE78
            SHA-256:59D1E98D6E4BC3B999EB6614117E6D76CF852F398C4D93D913573CF482E75AC2
            SHA-512:9431EA58E9A30387AD99F7DE71801275EE2F4C0DF5AB0A74628429D7F7C1540E284CB61CE81797B78A7999692850E08A06839C8EDEC3B414648AC1BA86616B07
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Tronxy X5SA 400 Marlin Firmware",. "model_id": "Tronxy_X5SA_400_Marlin_Firmware",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "TronxyDesign",. "bed_model": "",. "bed_texture": "tronxy_logo.png",. "hotend_model": "",. "default_materials": "Tronxy Generic ABS;Tronxy Generic PLA;Tronxy Generic PLA-CF;Tronxy Generic PETG;Tronxy Generic TPU;Tronxy Generic ASA;Tronxy Generic PC;Tronxy Generic PVA;Tronxy Generic PA;Tronxy Generic PA-CF".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3158
            Entropy (8bit):4.724307744480378
            Encrypted:false
            SSDEEP:48:/HpTqVrBkMp3khkiHkvkYkp67aZiL/YWab7j4HSmXHcXMXIP+ELzZsxcLMxHGCn:/wBkMRkhk2kvkYkGeymPW6zZfuGC
            MD5:44DA61B5EC3C2F1D70589EBD46BA5579
            SHA1:6C2B35038C5197A515C88D53ADB05852C172360A
            SHA-256:33D2BADC1D862958FC1E7440CE8EA2DB51FE00612A33BC29BB9DBED5EEC8A887
            SHA-512:07A61F620B3437CF83BF016FD814EC817C06630E94D3C9CDC67503DDF91D5E0F46737E08ECD17FBA488B04F136DFC5FE075A1473CD8795C1FCB4B7BDC2833BE2
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "name": "fdm_machine_common",. "from": "system",. "instantiation": "false",. "printer_technology": "FFF",. "deretraction_speed": [. "40". ],. "extruder_colour": [. "#FCE94F". ],. "extruder_offset": [. "0x0". ],. "gcode_flavor": "marlin",. "silent_mode": "0",. "machine_max_acceleration_e": [. "5000". ],. "machine_max_acceleration_extruding": [. "10000". ],. "machine_max_acceleration_retracting": [. "1000". ],. "machine_max_acceleration_x": [. "10000". ],. "machine_max_acceleration_y": [. "10000". ],. "machine_max_acceleration_z": [. "100". ],. "machine_max_speed_e": [. "60". ],. "machine_max_speed_x": [. "500". ],. "machine_max_speed_y": [. "500". ],. "machine_max_speed_z": [. "10". ],. "machine_max_jerk_e": [. "5". ],. "machine_max_jerk_x": [. "8". ],
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):352
            Entropy (8bit):4.5608306988445735
            Encrypted:false
            SSDEEP:6:fEaxTFu0htUiuL81f0dlz9JvFmu++NOF4TJF1tJ6JM58Q+JMP+/KyoVMkCA:8GTFphmicu0dlpTmuVqC0JddJOlsA
            MD5:7A6CB10B3F61231EC15DE7BB11AB660B
            SHA1:E9CA15A05642800B331A3415FC8CC49AB99CB6E2
            SHA-256:7E00CBAC3ED4C593CC96DBBE1BA7622BA85CE6AB08AFD4364F84A1FDEA9B275D
            SHA-512:3E2FC20E92B02138BFF7C4ADC3DA98C44FA313AC7EAB59BEF2119B4D22B4F8BF207B771FED7B9D8FCAD80CA816882250EF4814442CC6FE0701DFF37CFE635370
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Tronxy_001",. "name": "0.08mm Extra Fine @Tronxy",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_common",. "layer_height": "0.08",. "bottom_shell_layers": "7",. "top_shell_layers": "9",. "compatible_printers": [. "Tronxy X5SA 400 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):346
            Entropy (8bit):4.548916277591418
            Encrypted:false
            SSDEEP:6:fEaxTFu0htULpuQyf0dlz9JvFmu++NOF4TJFiZttJ6JMgQ+JMD/KyoVMkCA:8GTFphm9k0dlpTmuVqLZn0JHdJlsA
            MD5:715EAD31989F4F776298013DBC026BC8
            SHA1:4D6676640A54C13499A908791BE3FE813850BAF3
            SHA-256:F40FB1B18C57C939C452DD1591E45DE15430517181897F518FF13FDBF5DD91D9
            SHA-512:49435CC2AEBF51B6E791E40F5EDF72A2469F70C1725A07F18AED00516F1A9C6D1E004776CCCC7E09178DE49F6FB42B9EF6C472A8CC61532D0C490F37C57F45E2
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Tronxy_002",. "name": "0.12mm Fine @Tronxy",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_common",. "layer_height": "0.12",. "bottom_shell_layers": "5",. "top_shell_layers": "6",. "compatible_printers": [. "Tronxy X5SA 400 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):349
            Entropy (8bit):4.546768969712906
            Encrypted:false
            SSDEEP:6:fEaxTFu0htUimQK1JXQf0dlz9JvFmu++NOFPtJ6JMpQ+JMWTJFiSw/KyoVMkCA:8GTFphmiPKnQf0dlpTmuVqV0JmdJMST3
            MD5:E3252207828B730997A67395B17AC5AA
            SHA1:57F5288322055E7B526FC2E93681D310C648564B
            SHA-256:AB8861ADF285D755F66ADA762660A6DCE6839B7C11DF1E439D126C29AF8F6220
            SHA-512:A8F968ACA56003F1B4B7A2A1748BF7F71AABB9492F834488A482EEBE1188197B1B59BC66F6657DE461598C280DE57BD5E288127183D417DA6EBF29844DDE6A9C
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Tronxy_003",. "name": "0.15mm Optimal @Tronxy",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_common",. "bottom_shell_layers": "4",. "top_shell_layers": "5",. "layer_height": "0.15",. "compatible_printers": [. "Tronxy X5SA 400 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):349
            Entropy (8bit):4.535577643471288
            Encrypted:false
            SSDEEP:6:fEaxTFu0htUNUi/O0du++NOFmlz9JvF4TJF1tJ6JMdkQ+JM1/KyoVMkCA:8GTFphmNhO0duVqmlpT40JJdJ3sA
            MD5:C6C07221E45665DF90A00F456953B66F
            SHA1:05753644C2D7C67AE34232AB8450D074E137003C
            SHA-256:C1C4F1997BA85704CE4F6E9A60C8F5D21B74C94A68B596CCCD6CB22CB0B1BF49
            SHA-512:9C6486AD44AC553C63F438443F4C8125D932E9AEFEFDAF871614A16EA3B40FB3221F1C4B4A8F095EE144DBB9492311936F91EA2664C3BF8A66160C5D85EEFD5B
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Tronxy_004",. "name": "0.20mm Standard @Tronxy",. "from": "system",. "inherits": "fdm_process_common",. "instantiation": "true",. "layer_height": "0.2",. "bottom_shell_layers": "3",. "top_shell_layers": "4",. "compatible_printers": [. "Tronxy X5SA 400 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):385
            Entropy (8bit):4.58112014629677
            Encrypted:false
            SSDEEP:6:fEaxTFu0htUwOJYaT0dlz9JvFmu++NOF4TJFKQHj9jtJ6JMdkQ+JM1/KyoVMkCA:8GTFphmwmYO0dlpTmuVqpWn0JJdJ3sA
            MD5:265DF80E0EF130996D701B309484D2E3
            SHA1:252B8FFCD7B767BC6B044D3872C91AA2230B6FE6
            SHA-256:7492EEC2DC6FACC7704060BB58F977B7E01478EE5A9680718372C82632FA0EEB
            SHA-512:66CAAA444E7EF52C6C6B21A5B256A0AE42C6FFD0CF6A3E7FD4E916DCBDCFDEDB59B49846C29DA3A6FBBED3E3CD24B0BA1CF34028A7A23F2763032A0C4309DB8A
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Tronxy_005",. "name": "0.24mm Draft @Tronxy",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_common",. "layer_height": "0.24",. "top_surface_line_width": "0.45",. "bottom_shell_layers": "3",. "top_shell_layers": "4",. "compatible_printers": [. "Tronxy X5SA 400 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):391
            Entropy (8bit):4.617967880796369
            Encrypted:false
            SSDEEP:6:fEaxTFu0htUPU2C6aT0dlz9JvFmu++NOF4TJFmQHj9jtJ6JMdkQ+JM1/KyoVMkCA:8GTFphm46O0dlpTmuVqFWn0JJdJ3sA
            MD5:7A5B17CD4FC92E76010EF87BC81C7BC0
            SHA1:B25DBCBB6C22A8611F911A146173C1A5227DE7E1
            SHA-256:BA700A87FE3099CAB85BB3BA85D2F704A516A752DA098822E6C3470EE70F6046
            SHA-512:CF4E6E30B4CC7EC29C81DC8391EF4034F2F96468F9E860A5DD59DAE1C3A661EDC9EC860423795EAD635E95FCCF5F54A073E0F12561A25DB58526CC3A20ADC2CF
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Tronxy_006",. "name": "0.28mm Extra Draft @Tronxy",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_common",. "layer_height": "0.28",. "top_surface_line_width": "0.45",. "bottom_shell_layers": "3",. "top_shell_layers": "4",. "compatible_printers": [. "Tronxy X5SA 400 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2892
            Entropy (8bit):4.557467882976717
            Encrypted:false
            SSDEEP:48:jJhHprCkp+USpvOL3OjOgOqfF8wZ+C9BOjZvCKQlDMefWw2LpYpStLxVwdamJZkv:jJ5dZp+USxC3TiHvrlDdFpStdVwdamMv
            MD5:6FF5AB3E0C3550628824EE2A4C3DA020
            SHA1:020BF477A31EFCECEBF89C9ADC2D7C03A6F72908
            SHA-256:680B524C23F3474960DBB432D9FDD5B80BB793D213BB3123BAA97D8E0CF7B87A
            SHA-512:E4BD9128C4085D4DEF494F219E81635A28B0189E9C4631185461EE75C374ABDDF8EF94A86A2E06240E7289126AD3FF23C52771E7D5A4E2F02487E48FC04AB5FE
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_common",. "from": "system",. "instantiation": "false",. "adaptive_layer_height": "0",. "reduce_crossing_wall": "0",. "max_travel_detour_distance": "0",. "bottom_surface_pattern": "monotonic",. "bottom_shell_layers": "3",. "bottom_shell_thickness": "0",. "bridge_flow": "0.95",. "bridge_speed": "50",. "brim_width": "5",. "brim_object_gap": "0.1",. "compatible_printers_condition": "",. "print_sequence": "by layer",. "default_acceleration": "7000",. "top_surface_acceleration": "3000",. "bridge_no_support": "0",. "draft_shield": "disabled",. "elefant_foot_compensation": "0",. "enable_arc_fitting": "0",. "outer_wall_line_width": "0.4",. "wall_infill_order": "inner wall/outer wall/infill",. "line_width": "0.4",. "infill_direction": "45",. "sparse_infill_density": "15%",. "sparse_infill_pattern": "grid",. "initial_layer_acceleration": "500",. "initial_layer_line
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3517
            Entropy (8bit):4.573081570103841
            Encrypted:false
            SSDEEP:96:jJGYZp+USxC3TiHvrlDdFUpjprYMHR3lSxMsNBKdVwdamMY:FZppSxuQRDdFejprYMHR3lSxMsNBKg
            MD5:57EA6496B1E3EB32FD3A011B4EA0432D
            SHA1:1204B28462F4769C8CE4D0BAFD8E9C33252B2480
            SHA-256:CC9C7F052B45A2D5AF02F866F6CF8A8F0CA873F2F6F171FFFF4B34047EC0F004
            SHA-512:1E2D960AF286BDB34AAEBDC99CCFB1E370F76A5FD40847E12627B1785DB99141B130A63A58E6C4A9BE200376D5AF73FBB36D06777074078B4C7713DDC7D3AB83
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_tronxy_common",. "from": "system",. "instantiation": "false",. "inherits": "fdm_process_common",. "adaptive_layer_height": "0",. "reduce_crossing_wall": "0",. "max_travel_detour_distance": "0",. "bottom_surface_pattern": "monotonic",. "bottom_shell_layers": "3",. "bottom_shell_thickness": "0",. "bridge_flow": "0.95",. "bridge_speed": "50",. "brim_width": "5",. "brim_object_gap": "0.1",. "compatible_printers_condition": "",. "print_sequence": "by layer",. "default_acceleration": "7000",. "top_surface_acceleration": "3000",. "bridge_no_support": "0",. "draft_shield": "disabled",. "elefant_foot_compensation": "0",. "enable_arc_fitting": "0",. "outer_wall_line_width": "0.4",. "wall_infill_order": "inner wall/outer wall/infill",. "line_width": "0.4",. "infill_direction": "45",. "sparse_infill_density": "15%",. "sparse_infill_pattern": "grid",. "initial_layer_
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):4511
            Entropy (8bit):4.154901651054124
            Encrypted:false
            SSDEEP:48:L7a4N/OMUSWIjiCO+BeLxLW/EVOvyw5xp3LdhrWxVutS/JDZaEIr72bh7:3hNGMUSWIjLO+BeLxLW/EVChebh7
            MD5:FC084B0B085AB137F6FE9E3ADC9C9FF1
            SHA1:D52ED0F7E47E082AEC4D68DECB76AC1AA716515A
            SHA-256:470313A654A771B5C2855A2E937AC0D8F2F1C0246022C29E23623875F52206A8
            SHA-512:92F3313F5F2A80B5B4DE9C2D3ED59FE0CAEB5ADB712EDE6DBC5BA0081AA451E0F1D149F6D937592730C58CE64DFEBC1798A28D7ADA5FA7C0D7D07C8E8DF02D19
            Malicious:false
            Reputation:low
            Preview:{. "name": "Vivedino",. "version": "01.08.00.03",. "force_update": "0",. "description": "Vivedino configurations",. "machine_model_list": [. {. "name": "Troodon 2.0 - RRF",. "sub_path": "machine/Troodon2RRF.json". },. {. "name": "Troodon 2.0 - Klipper",. "sub_path": "machine/Troodon2Klipper.json". }. ],. "process_list": [. {. "name": "fdm_process_common",. "sub_path": "process/fdm_process_common.json". },. {. "name": "fdm_process_klipper_common",. "sub_path": "process/fdm_process_klipper_common.json". },. {. "name": "0.08mm Extra Fine @Troodon2",. "sub_path": "process/0.08mm Extra Fine @Troodon2.json". },. {. "name": "0.12mm Fine @Troodon2",. "sub_path": "process/0.12mm Fine @Troodon2.json". },. {. "name": "0.15mm Optimal @Troodon2",.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):52778
            Entropy (8bit):7.975140764588401
            Encrypted:false
            SSDEEP:1536:1GLFx9DKqg4bMF7yij68LocRGxh9rost1:MKOgF7yij6iRIh1oy1
            MD5:30B2D761A772C653882BC39457F9CA27
            SHA1:9E6C21A014CC6F817A5E141EF848B73D2D8F0E89
            SHA-256:F430D1554074F6D3873545527F909DF6613730FBCBFA4703671BA0B270D24A6E
            SHA-512:A25C86A8742D41E033AAA9903C6A37F5863E6A09A9DED97C60A83FD7DDBB16535D76646A912DD29901F9BEEB1BB3E72B2C29FB3B65F7DAD2DCED1BAB9BA1DDBB
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2....pHYs..\F..\F...CA...)iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.0-c000 79.171c27fab, 2022/08/16-22:35:41 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:tiff="http://ns.adobe.com/tiff/1.0/" xmlns:exif="http://ns.adobe.com/exif/1.0/" xmp:CreatorTool="Adobe Photoshop 24.0 (Macintosh)" xmp:CreateDate="2023-05-04T09:18:52-04:00" xmp:ModifyDate="2023-05-05T00:08:46-04:00" xmp:MetadataDate="2023-05-05T00:08:46-04:00" dc:format="image/png" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:4c743
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):53378
            Entropy (8bit):7.974124223286638
            Encrypted:false
            SSDEEP:1536:1qofAfulp9RsqYy329SdhlXO8iiffbzf/UXt:YmlWVQ29uOGby
            MD5:D43221DAE91ECB7744304FD49AFE288C
            SHA1:DFC4EF5F3552B5BAC587076C2F506262E4A62690
            SHA-256:B299FA2A949FE6BB3820337D3D46DDF7843D5A7FB231DE3892E9DD1762161560
            SHA-512:D49D25BA9B914F9558B143FC45281D7EF224D9B391CD4C6E7A11891C716845CEFD7ACBAF3290CC421C86497DD5A710F0AC416CE4A4C6D2AF712CFD780ADD6A1A
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2....pHYs..\F..\F...CA...)iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.0-c000 79.171c27fab, 2022/08/16-22:35:41 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:tiff="http://ns.adobe.com/tiff/1.0/" xmlns:exif="http://ns.adobe.com/exif/1.0/" xmp:CreatorTool="Adobe Photoshop 24.0 (Macintosh)" xmp:CreateDate="2023-05-04T09:18:52-04:00" xmp:ModifyDate="2023-05-05T00:14:47-04:00" xmp:MetadataDate="2023-05-05T00:14:47-04:00" dc:format="image/png" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:702c0
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 2048 x 2048, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):36503
            Entropy (8bit):5.085885778111331
            Encrypted:false
            SSDEEP:192:5SDknkWjPP6zu/iV3XJT7OfRiwgNetbl247ChOWEQIFK/8owXWs4/q2r9S3R5qnU:gonkwPP6zuCJfqblOEQIMfXRxAPqU
            MD5:9E9767E49FC3BEE31B493BFAB29192BD
            SHA1:E2B9D06D44A01A0AB3D1F5C457CB359E3BC35EC4
            SHA-256:B729AD15650CBF7818BA869FE8EF12F8D5F3387898FE76FE2A6D6DCF8F580FEF
            SHA-512:2FCDF993F20D7268A6F2EB75753E2CD2F0E9C3B030E3BFFAA7BDF34F3BB77A4EBCACABBE71E4685D2D98FBC24720E65B728DADD5C5316C4E9B81DBE9782B5072
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................0....pHYs.................iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.0-c000 79.171c27fab, 2022/08/16-22:35:41 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:GIMP="http://www.gimp.org/xmp/" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:tiff="http://ns.adobe.com/tiff/1.0/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmpMM:DocumentID="adobe:docid:photoshop:0c41cf3b-a594-a84b-bca7-32f0f4abf951" xmpMM:InstanceID="xmp.iid:dd847d0d-c9e8-4e40-af0c-cec49f06336d" xmpMM:OriginalDocumentID="xmp.did:1d766764-8c93-42f7-be6f-4143490373ea" dc:Format="image/png" dc:format="image/png" GIMP:API="2.0" GIMP:Platform="Windows" GIMP:TimeStamp="167750288360
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):442
            Entropy (8bit):4.511646049736679
            Encrypted:false
            SSDEEP:6:fS584b26u+oEG0yDY80htzMXK4wlz9JvF/9mqbDf6zwhnww/KyvQKFM0dQ6kCA:96u5t0iY3hJN4wlpTVmqvzGyXFvdZA
            MD5:7DA2E2CD72C07A253307C2B13373B937
            SHA1:130A65A054E7BABD4522750D305AB09E89436D3E
            SHA-256:3321750955EEB0D6975F3FFA6CC185D4721DC099F8A95782489F203D9D980C97
            SHA-512:348ED5D07BADA576B4B4C5F72CFD566CA60F1F64808F7BC6D78BAA83B43F033A77F3512F379F977A8B9B0FAC2A985EADAE5989B48BB86477C8627B0DED2E5C64
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ABS @Troodon",. "inherits": "fdm_filament_abs",. "from": "system",. "filament_id": "GFB99",. "setting_id": "GFSB99_Troodon_00",. "instantiation": "true",. "filament_flow_ratio": [. "0.926". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):441
            Entropy (8bit):4.511762304463855
            Encrypted:false
            SSDEEP:6:fS584j6u+oPG0yDVz80htzsEwlz9JvF/9ObDf6zwhnww/KyvQKFM0dQ6kCA:M6u5e0iVz3hJsEwlpTVOvzGyXFvdZA
            MD5:69A059CB717F0E352D222FD7F1D40571
            SHA1:68A1B6227A029FFAAB9918877AB391D9FD227A40
            SHA-256:C65522C2EE4FBC7DBDCDC41C13BC2B789341B8DFBBA2D25B97A6C8126016A4D4
            SHA-512:32B168D2BB0DE7B548008B59AE4090782E1DEC0943899D2D3C1C8206F40F816A8AE3D747BF27655ADF38C6C421337F6DD267EFEAA9E2ACDCF9617B82B7617119
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ASA @Troodon",. "inherits": "fdm_filament_asa",. "from": "system",. "filament_id": "GFB98",. "setting_id": "GFSB98_Troodon_00",. "instantiation": "true",. "filament_flow_ratio": [. "0.93". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):500
            Entropy (8bit):4.46083952199516
            Encrypted:false
            SSDEEP:12:s6u5/G0is3hJJ4wlpTbzGxIxSQlyXFvdZA:sf5fi0RpTbixIxS8yVvdZA
            MD5:20E0874F9119B6F44E10154396786044
            SHA1:E4624B57FFCB6233DC4A30E01C007C08F12E4BB1
            SHA-256:025DD20A09CBE8CD47C9FA08D9FF88EE62998D136D8F2FC3F9C4EF01A432ED9C
            SHA-512:27B343E5A21627352E5AC59C6547B3FD1E47FB9BAEC221707E41E7D751E78C0ACE5B64BF4A7EE32BD80A1FBF55342526793F793149CE9E7BADBAFACB1FAF418B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PA @Troodon",. "inherits": "fdm_filament_pa",. "from": "system",. "filament_id": "GFN99",. "setting_id": "GFSN99_Troodon_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "12". ],. "nozzle_temperature": [. "280". ],. "nozzle_temperature_initial_layer": [. "280". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):490
            Entropy (8bit):4.46232907754103
            Encrypted:false
            SSDEEP:12:U6u5/G0iRz3hJgEwlpTKqxIxSQlyXFvdZA:Uf5filxqpTDxIxS8yVvdZA
            MD5:9CC8DEB9237CABB5034F1FA88A730E45
            SHA1:576B2E6E2A614793A757C12E61BD682AEBE5AA9E
            SHA-256:50DC764568E9A4E35CC484BBE2D62E2395DABB89E2FCA05CFE82143C2EB2ECD9
            SHA-512:1FE3AF6F07D44AF3C9667BB12D5434913CE865A12AA77901451CEEFC7252DAAC7414D97070B8AFED20A5DF15AF7B4395EB4BB79269005EDF1664B7AF02A010A0
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PA-CF @Troodon",. "inherits": "fdm_filament_pa",. "from": "system",. "filament_id": "GFN98",. "setting_id": "GFSN98_Troodon_00",. "instantiation": "true",. "filament_type": [. "PA-CF". ],. "nozzle_temperature": [. "280". ],. "nozzle_temperature_initial_layer": [. "280". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):439
            Entropy (8bit):4.487216864226929
            Encrypted:false
            SSDEEP:6:fS584QC6u+ok0yDjcV0htzRdwlz9JvF/9bbDf6zwhnww/KyvQKFM0dQ6kCA:66u5k0ij9hJfwlpTVbvzGyXFvdZA
            MD5:0CA50483F51F1B2965FDA1FD524DE124
            SHA1:0A741225E3247FC4CC478136E305E4B89120C09A
            SHA-256:07D9510CCE2BC7191C8FE2D4EEF5FD10E8FF233E4B66CFD445D036A72B5415AD
            SHA-512:03D5A618BA5CF2E9835E81DEC4309E7F78DB4FC42B9A1B6A19E8882C0A5769D4A15FB65463698A4B7EA65904B19A7E0AC2FFE09B4110138408ACE613D4EA5296
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC @Troodon",. "inherits": "fdm_filament_pc",. "from": "system",. "filament_id": "GFC99",. "setting_id": "GFSC99_Troodon_00",. "instantiation": "true",. "filament_flow_ratio": [. "0.94". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):681
            Entropy (8bit):4.3591389325801035
            Encrypted:false
            SSDEEP:12:r6u5M0in9hJj/wlpTIwPwwbwdlh3ovzjwCFiZbwCF8yXFvdZA:rf5RinnepTFPwpDNov4oiOo8yVvdZA
            MD5:FCBE2E9B16CF54B2F94CCB4758292A1E
            SHA1:8E01B0C8CA4EDCF1612B17E69D761149C743394A
            SHA-256:B8F19E77CBD6F0595CD1312D9438ADEA3AAC1940079F3E4261B12A8DC03EA8DE
            SHA-512:87A7879A9CF85E1704E158D2626599021CB5AC4904D517F8B45D6F64217AD825CE7568B48F0D83C816A0CE5081EA6F0C456D810A43591A5EAC4D3C1154B62582
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PETG @Troodon",. "inherits": "fdm_filament_pet",. "from": "system",. "filament_id": "GFG99",. "setting_id": "GFSG99_Troodon_00",. "instantiation": "true",. "fan_cooling_layer_time": [. "30". ],. "fan_max_speed": [. "90". ],. "fan_min_speed": [. "40". ],. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "10". ],. "overhang_fan_speed": [. "90". ],. "overhang_fan_threshold": [. "25%". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):431
            Entropy (8bit):4.460566632123672
            Encrypted:false
            SSDEEP:6:fS584f6u+o8h0yDEd80htzj4wlz9JvF/9fgJcw/KyvQKFM0dQ6kCA:06u58h0iS3hJj4wlpTVfXyXFvdZA
            MD5:855818839608921A19173B0E07A1F092
            SHA1:900467E4855A04286AA4740BD499608373A135F4
            SHA-256:53B44DB781F90B7F0AC49776804D1C22173FFA7EB99BCB5140CC5A04B678A312
            SHA-512:FE6A3B9ADBB251365A222EAF7F06616A4568E01198753B04B3DF965C4D667AD40313BEFEEFA1BD165F22E3D22655323B87C44C668212CBAC7DB462EF86D378F4
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA @Troodon",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFL99",. "setting_id": "GFSL99_Troodon_00",. "instantiation": "true",. "filament_flow_ratio": [. "0.98". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):481
            Entropy (8bit):4.48623727091708
            Encrypted:false
            SSDEEP:6:fS584W26u+o8h0yDPT80htzV/wlz9JvF/93FqbixHwgJmdqw/KyvQKFM0dQ6kCA:86u58h0ir3hJxwlpTV3omxQtQyXFvdZA
            MD5:04314D9DB0A6ACD8CB8CE4B81BC5AFD0
            SHA1:97BBB1CBD88F8E906D3863F07CD22B8467C8B6A8
            SHA-256:F209F70DF040FA04F976627BCD152E82BEA8E7AB00E7C3B99BF4C99629C80EEC
            SHA-512:2FA3F5CBFE66D5E64752766AEB7454F441072FCF017590A1A009AF7C92FF15965758AC0FA596A1B1DEC382800A93F451991916D539F7F601185E982F842E7A0F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA-CF @Troodon",. "inherits": "fdm_filament_pla",. "from": "system",. "filament_id": "GFL98",. "setting_id": "GFSL98_Troodon_00",. "instantiation": "true",. "filament_flow_ratio": [. "0.95". ],. "filament_type": [. "PLA-CF". ],. "slow_down_layer_time": [. "7". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):490
            Entropy (8bit):4.4812215980606185
            Encrypted:false
            SSDEEP:6:fS584KC6u+omGvu0yDzcud80htzd/wlz9JvF/93FqbDf6zwhnwgJmdqw/KyvQKFI:m6u5dm0iz9hJZwlpTV3ovzGtQyXFvdZA
            MD5:99AE89056E03029AF5A2CEB29F5C13C6
            SHA1:6047832BA8EF7FD6E5EE4D8FD29B2F331B3FA754
            SHA-256:A818FD131E38187015160D0F1463D0E2D57FBB0B2D0AE061EF87906D311BC515
            SHA-512:BACE1702796B8934FDB94B5F7D018EBD1B6452D09E3D2605AF5E73F715337AC85CF59A9187CB53BED9BBCDD0BB75ADEA5BF6049EE1C19D874944117DADA9725B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PVA @Troodon",. "inherits": "fdm_filament_pva",. "from": "system",. "filament_id": "GFS99",. "setting_id": "GFSA99_Troodon_00",. "instantiation": "true",. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "12". ],. "slow_down_layer_time": [. "7". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):391
            Entropy (8bit):4.532837352729908
            Encrypted:false
            SSDEEP:6:fS584T6u+os6m0yD1cV0htzfdwlz9JvF/Df6zwXNqw/KyvQKFM0dQ6kCA:Q6u5sN0iWqhJFwlpTbzXgyXFvdZA
            MD5:76F15F6BD92AB9A1E9724D58D3D4F696
            SHA1:05EFB300BB75F5434F2B1BC907E92DAB9B9E4B45
            SHA-256:9CD9E3EA78778ACCFA2FE9C03AC738FFFBBD08BABA58DC8174F65EC83BA09B0E
            SHA-512:EB61BA667BF69ADE26C0BB592A8D1DD8325CF2557B98D1A3C9471ED569E5974EAF83CC7201579F4277B0BF1480A362AEE36EE6D21F02681B9099C092C378D71A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic TPU @Troodon",. "inherits": "fdm_filament_tpu",. "from": "system",. "filament_id": "GFU99",. "setting_id": "GFSU99_Troodon_00",. "instantiation": "true",. "filament_max_volumetric_speed": [. "3.2". ],. "compatible_printers": [. "Troodon 2.0 Klipper 0.4 nozzle",. "Troodon 2.0 RRF 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1574
            Entropy (8bit):4.11991221597891
            Encrypted:false
            SSDEEP:24:9+Hpy5v/T22z2b2D2mO26OyOKOOgzqbvGCZvDajcoRxSSIhrqPwcqo8oiTxGm5wy:9+Hpy5vbDzMStvzaxXZrOh9e
            MD5:8B97B9CE5AAC0E306E0F31FF28669502
            SHA1:CC4A22E822E5B4CA945845FAA556B5AE25E90E7A
            SHA-256:7CC59EA3561C57F2D952692833081C53ADAFC77554FD0D22028229458CE500B6
            SHA-512:A226A3AA66D45D141DEBD06566274E0DBA2598DC386894A69571D4346A489826B4D3F812F6F0236B9E71E90DB6D6A876BB397114723410D0C6D9748BF6C67F6A
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_abs",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "105". ],. "eng_plate_temp" : [. "105". ],. "hot_plate_temp" : [. "105". ],. "textured_plate_temp" : [. "105". ],. "cool_plate_temp_initial_layer" : [. "105". ],. "eng_plate_temp_initial_layer" : [. "105". ],. "hot_plate_temp_initial_layer" : [. "105". ],. "textured_plate_temp_initial_layer" : [. "105". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "30". ],. "filament_max_volumetric_speed": [. "28.6". ],. "filament_type": [. "ABS". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "260
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1574
            Entropy (8bit):4.11471979163291
            Encrypted:false
            SSDEEP:24:9PHpy5v/T22z2b2D2mO26OyOKOOgzqbvGCavDaLocoRxSSIhrqPwcqo8oiTxGm5h:9PHpy5vbDzMStvzJ8XZrOh9e
            MD5:2939ADF1322E95D7A4CD5097AC8A6C63
            SHA1:B47570B979528CC8A79507F6D4A614B8FBB42F92
            SHA-256:3E2DBA2179CC00223BA0A68EBBF7158BBE6A8C62E4183F1B6BE1AB2778CF53DF
            SHA-512:7052B49F96CFC50DC00D5EE4123FE558AF85FAEE224104EA722208E23BE5B0BAF9C8C395B0BA31CC1E5AC7C10F15E76B1094483DD289D139A2E45FFD9C3A3B03
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_asa",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "105". ],. "eng_plate_temp" : [. "105". ],. "hot_plate_temp" : [. "105". ],. "textured_plate_temp" : [. "105". ],. "cool_plate_temp_initial_layer" : [. "105". ],. "eng_plate_temp_initial_layer" : [. "105". ],. "hot_plate_temp_initial_layer" : [. "105". ],. "textured_plate_temp_initial_layer" : [. "105". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "35". ],. "filament_max_volumetric_speed": [. "28.6". ],. "filament_type": [. "ASA". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "260
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2654
            Entropy (8bit):4.0444088056554826
            Encrypted:false
            SSDEEP:48:9vxHpi7zEqdyanziBxK2VZp0oCziNzunU:vsPEqwan12VmOWU
            MD5:6ADA5B042440175D276A510F1F991555
            SHA1:F23497AAEA901B187AC0A2AEDC3A2CB24EDFE576
            SHA-256:E88E444F8C651E8F82DC022B25D6406E3C29A40E3EAC26101E32241A62008910
            SHA-512:385BD32F7081EC3FF809799A80F6E7FD0CDB2693F8DABC19BCF02BB6730A2745E21518A17FEF35FE9BE7BF9E5C6A654EEEB6D3E9E910BC00C56896517E57D102
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_common",. "from": "system",. "instantiation": "false",. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "60". ],. "hot_plate_temp" : [. "60". ],. "textured_plate_temp" : [. "60". ],. "cool_plate_temp_initial_layer" : [. "60". ],. "eng_plate_temp_initial_layer" : [. "60". ],. "hot_plate_temp_initial_layer" : [. "60". ],. "textured_plate_temp_initial_layer" : [. "60". ],. "overhang_fan_threshold": [. "95%". ],. "overhang_fan_speed": [. "100". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "filament_end_gcode": [. "; filament end gcode \n". ],. "filament_flow_ratio": [. "1". ],. "reduce_fan_stop_start_freq": [. "0". ],. "fan_cooling_layer_time": [. "60". ],. "filament_cost":
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1510
            Entropy (8bit):4.064943678091041
            Encrypted:false
            SSDEEP:24:9fHpy5v/TK2zNbNDNmi26FyFKFOgzqbvGCAvlJcoRxSJIh5Pwyzoi0xlmLxhwx0C:9fHpy5vbnzh1cazpYXotIV
            MD5:DB3C15F3C501D0F7B37315598EBCC757
            SHA1:6681B3262418D88DA8A0DE916A22C4842AC54F44
            SHA-256:58E318F39B98679DC3C97E518E41EA1B8A0102EBBA839AAB7236CA5FCA9B0824
            SHA-512:C38CC72EFD51435A72B9C2C3DED84B967624172BF8E53F80456B653E944F734FCB90B593CB6C41A6BC540D94A50686025C129348A4AE0EA98695A1814BBB09EC
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pa",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "0". ],. "eng_plate_temp" : [. "100". ],. "hot_plate_temp" : [. "100". ],. "textured_plate_temp" : [. "100". ],. "cool_plate_temp_initial_layer" : [. "0". ],. "eng_plate_temp_initial_layer" : [. "100". ],. "hot_plate_temp_initial_layer" : [. "100". ],. "textured_plate_temp_initial_layer" : [. "100". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "4". ],. "filament_max_volumetric_speed": [. "8". ],. "filament_type": [. "PA". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "290". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1568
            Entropy (8bit):4.094531360924966
            Encrypted:false
            SSDEEP:24:9ZHpy5v/TK2zHwbHwDHwmi26PwyPwKPwOgzqbvGCZv6SwcoRxSawIhrqPwyqo8oN:9ZHpy5vbnzmQnFzatXSrOX9N
            MD5:EBC718D41A605C12F9377589805B0295
            SHA1:CB17B9FA4F962D442D9B9F69FE0270E6C30EFB54
            SHA-256:FC7FF0B2283FA534359EF90F9AE0406193BE8EF37FB4DDBA9F71C6CB0A9C8642
            SHA-512:5E0F71FC53342C6D2249B3FE2852F994F4343C92AC5DAF42744CDEBBFD41170DB434F6692FB1EE4D7CFA9288C0DB0BBFF40EEDB8DCDC14F2D78539016D10C757
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pc",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "0". ],. "eng_plate_temp" : [. "110". ],. "hot_plate_temp" : [. "110". ],. "textured_plate_temp" : [. "110". ],. "cool_plate_temp_initial_layer" : [. "0". ],. "eng_plate_temp_initial_layer" : [. "110". ],. "hot_plate_temp_initial_layer" : [. "110". ],. "textured_plate_temp_initial_layer" : [. "110". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "30". ],. "filament_max_volumetric_speed": [. "23.2". ],. "filament_type": [. "PC". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "270".
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1485
            Entropy (8bit):4.09844788979624
            Encrypted:false
            SSDEEP:24:9RHpy5v/TO2zKbgDgmW26iyYKYOgzqbvGCMvAdClQExSWIhrqPwRloiMxymix3xt:9RHpy5vb7zAALbzfbedrObG
            MD5:DFD5D0BFC8AF0158F1C45DB2EA3F9083
            SHA1:67AD8B450CA296BEEC8DEB8A6866E9ECAE3DBACC
            SHA-256:F753AD2C2066C32C9ACE0959724B408A21B5AA32985966F825DE519AA224AA4B
            SHA-512:F81ACE708C31EB3C30A65F3D073F381E88A001EC017C95977AB548C0D6157BDFC54E5520F4840E01191794E1556E6CC0F1C4A6E740C88C05C031C52AD37E5121
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pet",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "0". ],. "hot_plate_temp" : [. "80". ],. "textured_plate_temp" : [. "80". ],. "cool_plate_temp_initial_layer" : [. "60". ],. "eng_plate_temp_initial_layer" : [. "0". ],. "hot_plate_temp_initial_layer" : [. "80". ],. "textured_plate_temp_initial_layer" : [. "80". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "20". ],. "filament_max_volumetric_speed": [. "25". ],. "filament_type": [. "PETG". ],. "filament_density": [. "1.27". ],. "filament_cost": [. "30". ],. "nozzle_temperature_initial_layer": [. "255". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1697
            Entropy (8bit):4.104138497261157
            Encrypted:false
            SSDEEP:24:9THpy5v/jviT7R/O2zObODOmW26WyWKWxSmIhrqOgzqPwR4oiMoO5bvIqxymMxUX:9THpy5v767zEqd6NrYzOe0OKqPP
            MD5:EF709238E6BA0FFFB1E50C355854D78B
            SHA1:5D3C4872C5308E5A7775AC8E7D9157F9AB1F9007
            SHA-256:65DE50F6DAB0C9F550C0C3D465549F5E7389A2332C7E6B949C66402DD9CF7735
            SHA-512:F9F7E72F77FAAC9B422BF77182B396F705553556B83F70D5D9C3D8F63789EFD0E2BED39F7D2AEA327F7D8DA3179B76152E697CB990BE4DF9AD2DABAC5F128FAA
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pla",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "12". ],. "filament_type": [. "PLA". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "60". ],. "hot_plate_temp" : [. "60". ],. "textured_plate_temp" : [. "60". ],. "cool_plate_temp_initial_layer" : [. "60". ],. "eng_plate_temp_initial_layer" : [. "60". ],. "hot_plate_temp_initial_layer" : [. "60". ],. "textured_plate_temp_initial_layer" : [. "60". ],. "nozzle_temperature_initial_layer": [. "220". ],. "reduce_fan_stop_start_freq": [. "1". ],. "slow_down_for_layer_cooling": [. "1". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1788
            Entropy (8bit):4.097754760791249
            Encrypted:false
            SSDEEP:24:9ZHpy5v/Tg2zKbjDjmo26iyrKrPvXD4qkzq97RxSmIhrqOgzqPwR4oiMoO5bvIq2:9ZHpy5vbdzAHy/UDzXNrYzOe0OKzVPAi
            MD5:93AFB2AD0669F88A22BD26E4E6D1361A
            SHA1:3085299A770B58C76A7FEB7A5697A7507D64B937
            SHA-256:0686BAE3D5221CEEA41CAA469610D10DD352A6089E2FFBECCAAEE51AF0531D39
            SHA-512:67D92006411C8BAEDF667F77219B058FC9A6D84DD81637026600CD7112041BEABB7CDAC3B8FC8407A09E28EF1338B4B5B601DB1C5465A2248D76814C8443600B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pva",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "35". ],. "eng_plate_temp" : [. "0". ],. "hot_plate_temp" : [. "45". ],. "textured_plate_temp" : [. "45". ],. "cool_plate_temp_initial_layer" : [. "35". ],. "eng_plate_temp_initial_layer" : [. "0". ],. "hot_plate_temp_initial_layer" : [. "45". ],. "textured_plate_temp_initial_layer" : [. "45". ],. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "15". ],. "filament_soluble": [. "1". ],. "filament_is_support": [. "1". ],. "filament_type": [. "PVA". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "220". ],. "reduce_fan_stop_s
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1603
            Entropy (8bit):4.109406244255383
            Encrypted:false
            SSDEEP:24:9fHpy5v/Tf2zfbgDgmH26HyoKoPvXiw7RoxSwIhrqOgzqPwR4oiMAgbvIqxkmMxk:9fHpy5vbOzTAegyGrrYzOeg/g
            MD5:F4153047E773DE3AAE04B4AB679BA086
            SHA1:6855A107AD93D340AE633AED43E87048346B9205
            SHA-256:772368404EE59E786C875861EE943754EF5781331660E6BAB5BC66A0006EE8AF
            SHA-512:BA08BACC3D1DF681D43111D871121E300341CF7557C6A90BCD0516CFB1373A966DEFFEDCADDA87B33AA3639FCA486F473941B2ACAC532157754E2323697374F6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_tpu",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "30". ],. "eng_plate_temp" : [. "30". ],. "hot_plate_temp" : [. "35". ],. "textured_plate_temp" : [. "35". ],. "cool_plate_temp_initial_layer" : [. "30". ],. "eng_plate_temp_initial_layer" : [. "30". ],. "hot_plate_temp_initial_layer" : [. "35". ],. "textured_plate_temp_initial_layer" : [. "35". ],. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "15". ],. "filament_type": [. "TPU". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "filament_retraction_length": [. "0.4". ],. "nozzle_temperature_initial_layer": [. "240". ],. "reduce_fan_stop_start_freq": [. "1". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):374
            Entropy (8bit):4.600130894698145
            Encrypted:false
            SSDEEP:6:fiehtop7QKFM0e0ZJz9JvFEK+FbFKgj9jQcu7HT0v2OoOkJQMH7JvNFCOkJyFTq:qehuZXFve0ZJpTEKYP9jG7zy2zVQMHN0
            MD5:8846B793DFB018E6DDFAA2B806C7D5B3
            SHA1:E75442FBAD72AD6350690963DB9A82EFA2E74FD2
            SHA-256:6CC566220C59D8BC4B228F1E5C1E653D06ED24A586DB6340F4758AFA3155A54A
            SHA-512:2C2B74F7B5DC4CF4EF5CB76EFFD971DF0669B94915B8B7773E11374084F1624C98BD106F82FFC4088D8253C249C10A93A1FA393BF1D4C377ACD6276DE6523B4B
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_Troodon_001",. "name": "Troodon 2.0 Klipper 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_klipper_common",. "printer_model": "Troodon 2.0 - Klipper",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "350x0",. "350x350",. "0x350". ],. "printable_height": "330".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):362
            Entropy (8bit):4.594201299721931
            Encrypted:false
            SSDEEP:6:fiehtoK7Q60e0ZJz9JvFEK+8WEFKgj9jQcUv2OoOkJQMH7JvNFCOkJyFTq:qehucUe0ZJpTEKtWsP9jq2zVQMHNvXur
            MD5:7C4D1827E24F09F8F373B9ADE00987B9
            SHA1:B1CEBAEE0A8B2B1A3888604DEECF8ACC497141C9
            SHA-256:377B1CBC610D171DF7E4BBD8116402F26D12AE927EBE1CA484F80C02AB37A38D
            SHA-512:4533E8B6D8B2CC5F93031E61A88CE1661031C4A3E35E11D144B453239A601555EADF18071D4BCBFFBBBAD887C2D727C4D57B251994D02D05FEE50C72BC416932
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_Troodon_002",. "name": "Troodon 2.0 RRF 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_rrf_common",. "printer_model": "Troodon 2.0 - RRF",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "350x0",. "350x350",. "0x350". ],. "printable_height": "330".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):521
            Entropy (8bit):4.702745304654603
            Encrypted:false
            SSDEEP:12:qqWG7ziXjCuzXz62s8nqM6rXaCCGdLmo53K:JWG/iXjCMj62sKqM2qCCGdx3K
            MD5:B556EDEBA72AD1EC2BD25A02D03194FD
            SHA1:C0C73BBBA08E66E687C529D7833DC15A00127DCC
            SHA-256:9E1FAB12552029E020DC577368C91C619A88BD457DE22B0D97C5185FC65E1B7D
            SHA-512:500754FAD58EDFE5A471665845DDF827745E6F0173CBB944B32C4F4CAAD8C09198F464D3606E9B73FDB66D4C163268404A158F825FFE3D4D746D96F5D94135CE
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Troodon 2.0 - Klipper",. "model_id": "Troodon2Klipper",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Vivedino",. "bed_model": "",. "bed_texture": "Troodon2-Bed-Texture.png",. "hotend_model": "",. "default_materials": "Generic ABS @Troodon;Generic PLA @Troodon;Generic PLA-CF @Troodon;Generic PETG @Troodon;Generic TPU @Troodon;Generic ASA @Troodon;Generic PC @Troodon;Generic PVA @Troodon;Generic PA @Troodon;Generic PA-CF @Troodon".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):513
            Entropy (8bit):4.703406062012308
            Encrypted:false
            SSDEEP:6:fiqQ7QcCXjCcv2s8ZVqM6NmZ4XaCCGdKAm6DEQ7164bCLWC+fvQeKeZLK:qqWqXjCa2s8nqM6rXaCCGdLmo53K
            MD5:1CCB6E0D9785C108258AFE786DDDD51A
            SHA1:FFD03D47DAB47622E5A7BB37A6FE4001970CCAE5
            SHA-256:BADFCD544C2AFEAABB55C9199127C827E361B9A24BEC89F5200272ACF1B2C4B5
            SHA-512:DCC660381AFC3EDAB9E812E68521D4A255ADA4C336239AF8B3FBE412B92B853BE1029488EB5F259DC83DB353FA59AF687F3EDA627E036517B7858C007071815F
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Troodon 2.0 - RRF",. "model_id": "Troodon2RRF",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Vivedino",. "bed_model": "",. "bed_texture": "Troodon2-Bed-Texture.png",. "hotend_model": "",. "default_materials": "Generic ABS @Troodon;Generic PLA @Troodon;Generic PLA-CF @Troodon;Generic PETG @Troodon;Generic TPU @Troodon;Generic ASA @Troodon;Generic PC @Troodon;Generic PVA @Troodon;Generic PA @Troodon;Generic PA-CF @Troodon".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2706
            Entropy (8bit):4.750190725489378
            Encrypted:false
            SSDEEP:48:/ZJpvKK+kMpagCkzCkKagCkq+CkVCkSCkHEGE3ELWphjAec/HVzbIrjbZJ743Q1Y:xJFmkM4kmk7kikcklk2J743QODik
            MD5:A337B8416E9817FFCA0FB1D5ED367545
            SHA1:D00AFFEDA6F2599086EBEA39BF9889F8C89C2F31
            SHA-256:FC579C63F9A936F371D318018AE55546F8C04EBB99574A9A0574AD26AA9A2950
            SHA-512:AF41535B87C7212DC05817F5E0A1292F6AC24AD621B7BB55AEE1F2DB910FC1F8DE7B749B2126E4CD4A5D1DAD77339FD24255313B0455BDEFA2AFA0EECC8D243C
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "name": "fdm_klipper_common",. "from": "system",. "instantiation": "false",. "inherits": "fdm_machine_common",. "gcode_flavor": "klipper",. "machine_max_acceleration_e": [. "5000",. "5000". ],. "machine_max_acceleration_extruding": [. "20000",. "20000". ],. "machine_max_acceleration_retracting": [. "5000",. "5000". ],. "machine_max_acceleration_travel": [. "20000",. "20000". ],. "machine_max_acceleration_x": [. "20000",. "20000". ],. "machine_max_acceleration_y": [. "20000",. "20000". ],. "machine_max_acceleration_z": [. "500",. "200". ],. "machine_max_speed_e": [. "25",. "25". ],. "machine_max_speed_x": [. "500",. "200". ],. "machine_max_speed_y": [. "500",. "200". ],. "machine_max_speed_z": [. "12",. "12". ],. "machine_max_jerk_e": [. "2.5",. "2.5". ],. "machine_max_jerk_x": [. "9",. "9". ],. "machine_max_jerk_y": [. "9",. "9". ],. "machine_max
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3208
            Entropy (8bit):4.734665314324068
            Encrypted:false
            SSDEEP:48:/HpTqVrBkMp3khkiHkvkYkp67NZiL/YWab7j4SHcXMXIP+ELzZsxcLMxHHW:/wBkMRkhk2kvkYkB0mPW6zZfu2
            MD5:7A8E4F159F99812B8A5884E012989F29
            SHA1:CDF848843684B126BAD5BB20CEF190EF2336D5F4
            SHA-256:3121570E86E880BE172764E42515A1A93D67A1DF3DF7A22585F689BD376B212D
            SHA-512:B998E448B0C41039A16EC3329EB9E9EB4484D4A1F3122D5B91C7226C4A350495AB80FE44ED3DD4A49131F40567F9834B3C233824B1486A0DDF736389648A517A
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "name": "fdm_machine_common",. "from": "system",. "instantiation": "false",. "printer_technology": "FFF",. "deretraction_speed": [. "40". ],. "extruder_colour": [. "#FCE94F". ],. "extruder_offset": [. "0x0". ],. "gcode_flavor": "marlin",. "silent_mode": "0",. "machine_max_acceleration_e": [. "5000". ],. "machine_max_acceleration_extruding": [. "10000". ],. "machine_max_acceleration_retracting": [. "1000". ],. "machine_max_acceleration_x": [. "10000". ],. "machine_max_acceleration_y": [. "10000". ],. "machine_max_acceleration_z": [. "100". ],. "machine_max_speed_e": [. "60". ],. "machine_max_speed_x": [. "500". ],. "machine_max_speed_y": [. "500". ],. "machine_max_speed_z": [. "10". ],. "machine_max_jerk_e": [. "5". ],. "machine_max_jerk_x": [. "8". ],
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2766
            Entropy (8bit):4.74751577139639
            Encrypted:false
            SSDEEP:48:4ZJpvKkSkMpagCkzCkKagCkq+CkVCkSCkHEGE3ELWpajAec/HVzsPIrjbZJ/8ZdU:WJFkkM4kmk7kikcklk9mJ0Zlk
            MD5:891646AD8E72A9E2AF8D01D531F91761
            SHA1:257822C46E1F0E7984E0B8DBEA172F8F0D876E3E
            SHA-256:7465FFF6F9B24FC2D710321538E863D669FB099F091446880CF64B3FEEC33E2B
            SHA-512:F563939787495B2EA3D999FD9847617F6D521794522293137EFE0832AA269659C1696BEE7758D9A7B8F2A6E4EF24895A4821F34AE51E1338E10CB5D5DFABDBDA
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "name": "fdm_rrf_common",. "from": "system",. "instantiation": "false",. "inherits": "fdm_machine_common",. "gcode_flavor": "reprapfirmware",. "machine_max_acceleration_e": [. "5000",. "5000". ],. "machine_max_acceleration_extruding": [. "20000",. "20000". ],. "machine_max_acceleration_retracting": [. "5000",. "5000". ],. "machine_max_acceleration_travel": [. "20000",. "20000". ],. "machine_max_acceleration_x": [. "20000",. "20000". ],. "machine_max_acceleration_y": [. "20000",. "20000". ],. "machine_max_acceleration_z": [. "500",. "200". ],. "machine_max_speed_e": [. "25",. "25". ],. "machine_max_speed_x": [. "500",. "200". ],. "machine_max_speed_y": [. "500",. "200". ],. "machine_max_speed_z": [. "12",. "12". ],. "machine_max_jerk_e": [. "2.5",. "2.5". ],. "machine_max_jerk_x": [. "9",. "9". ],. "machine_max_jerk_y": [. "9",. "9". ],. "machine_
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):291
            Entropy (8bit):4.509209658468899
            Encrypted:false
            SSDEEP:6:fEaxTFu0htZxuL8Do0dlz9JvFmu++NCbF4TJF1tJ6JM58Q+JMon:8GTFph/xcyo0dlpTmuVcC0JddJD
            MD5:089BB165EFEA024597087B0EF79796B1
            SHA1:2343D345A82EAC0CD9CB4D6023348999FEEB9D9D
            SHA-256:0296F399DD9BE3F640C2140661182D4084DE6004F1A0ECD8E6539F31A210721B
            SHA-512:F2D6AA71544CEE7EBC24AD8CCCA08C67DC688F920739E3F40A5837F9E0D7922A52DC5C46AEDF1AA40990117C89A42483D7CE4EA6F6D85FDEBF3805541928073B
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Troodon_000",. "name": "0.08mm Extra Fine @Troodon2",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_klipper_common",. "layer_height": "0.08",. "bottom_shell_layers": "7",. "top_shell_layers": "9".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):285
            Entropy (8bit):4.491099805580785
            Encrypted:false
            SSDEEP:6:fEaxTFu0htZZQAo0dlz9JvFmu++NCbF4TJFiZttJ6JMgQ+JM7:8GTFph/uAo0dlpTmuVcLZn0JHdJA
            MD5:F9E9542AC3A7349CBF91723B74779AE1
            SHA1:26EC2CF53D809CB284B9F9BC9A0B61C867469061
            SHA-256:C26DAFCF579FCD596C6CC65F28CDA1421F176F91E787F86F8381E32E40AE3B22
            SHA-512:B02E94A2A9E97B17F2283D41BD808E40E4CC0CFF84DBDEA33408D1D75F1A98B86C88441B62D3FE093412D988023C715EC8B83006CBD343BFFC2BBA1380FB301E
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Troodon_001",. "name": "0.12mm Fine @Troodon2",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_klipper_common",. "layer_height": "0.12",. "bottom_shell_layers": "5",. "top_shell_layers": "6".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):288
            Entropy (8bit):4.503195194472186
            Encrypted:false
            SSDEEP:6:fEaxTFu0htZ4QK1JXCo0dlz9JvFmu++NCbFPtJ6JMpQ+JMWTJFiSK:8GTFph/tKnCo0dlpTmuVcV0JmdJMSK
            MD5:C472DCBDCA422F544BB6D22E581DACB4
            SHA1:25A4562F8A611BC3CFB484EA8603DFAB53BBCDA8
            SHA-256:792361490EC6BFDEC37FF4F4D633DC4EE8D4ACFC3D9405511153D1424E7EA906
            SHA-512:C2B25B6D3BE9EBB03BC20C74D53F50078B5AD10A4EC0B7FD619D4E86917E865C1D966101F15E0EAEDA10BB2ED35ED6D6A3BDA5D4BC4C95DDC4192C9406203F8F
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Troodon_004",. "name": "0.15mm Optimal @Troodon2",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_klipper_common",. "bottom_shell_layers": "4",. "top_shell_layers": "5",. "layer_height": "0.15".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):288
            Entropy (8bit):4.481258196809371
            Encrypted:false
            SSDEEP:6:fEaxTFu0htZCi/So0du++NCbFmlz9JvF4TJF1tJ6JMdkQ+JMl:8GTFph/fSo0duVcmlpT40JJdJG
            MD5:04C004570B06C0635F58253D7474C1B4
            SHA1:3D27B791EA8BEB8E8475C5F8B9296FE98F8B33B9
            SHA-256:6B3D867ACE96CE50B33EA81D46E3938104271EFF5C72F02CDB2EE1DFDA4642FB
            SHA-512:86D85115EB868F409D5E3A987CA13CDEBE198471CF18F40B4511AA24DF20D9CDADE4E8FECC6CC58D30BC6FD67B9B93FCD6794A5DC6378B4DB3F7319141E9DF81
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Troodon_002",. "name": "0.20mm Standard @Troodon2",. "from": "system",. "inherits": "fdm_process_klipper_common",. "instantiation": "true",. "layer_height": "0.2",. "bottom_shell_layers": "3",. "top_shell_layers": "4".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):324
            Entropy (8bit):4.543250304643094
            Encrypted:false
            SSDEEP:6:fEaxTFu0htZAmJYa1o0dlz9JvFmu++NCbF4TJFKQHj9jtJ6JMdkQ+JMl:8GTFph/AeYSo0dlpTmuVcpWn0JJdJG
            MD5:AE1355F4C23C8FD245709F62D38AB54F
            SHA1:60DB8EDA7F135A8B4A8236807EEF28CDE0FD0FA3
            SHA-256:091940D7A6CC84DCA6B23D32A2C3539E0FD4EDE08DEEDBFDAA0AED631098B38F
            SHA-512:E15015B0D4734AFA5C714513BBA4B2456ECD4173C2A3AFAB49D0CF0AEC5893A36097D6058048E9340ECC2E05F8F4901C228DEDB6179509131BC4193D36994C9F
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Troodon_003",. "name": "0.24mm Draft @Troodon2",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_klipper_common",. "layer_height": "0.24",. "top_surface_line_width": "0.45",. "bottom_shell_layers": "3",. "top_shell_layers": "4".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):330
            Entropy (8bit):4.583083829803463
            Encrypted:false
            SSDEEP:6:fEaxTFu0htZoHO2C6a1o0dlz9JvFmu++NCbF4TJFmQHj9jtJ6JMdkQ+JMl:8GTFph/CK6So0dlpTmuVcFWn0JJdJG
            MD5:C34427AB65FADA7AF6771300A69ED38B
            SHA1:9F406016A71D065763751CAB2755D96C367F93FD
            SHA-256:6F3627A57CB9E54E0913A52AFC75AE081D63E1FCC69C5DC11359DB1430891E8A
            SHA-512:E73ECC5EB7CFC747BC317A8E5975D2DC8CE70E00657C35D34EFBDBBE29FCAE03883FD9868DAD69C4FF71A2F301C584632C9959AB391E7E15B8B9896F2807AD5F
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Troodon_005",. "name": "0.28mm Extra Draft @Troodon2",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_klipper_common",. "layer_height": "0.28",. "top_surface_line_width": "0.45",. "bottom_shell_layers": "3",. "top_shell_layers": "4".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2232
            Entropy (8bit):4.493834259982489
            Encrypted:false
            SSDEEP:48:jJhHprQUiONefFYi9Ny65S1W12LnrOHjnMRliSxhyur6LxwN4gk:jJ5dQUigtrrOHjnMRsSxhyu+dwe
            MD5:9DAF904A4655ED5DD14E62E07FFE89BF
            SHA1:FB4667B08D375D20DAF360F64FA18396227C27EA
            SHA-256:BDA68CA486D5F3725229E66397BA0D6D9C4BE15CA4CEE66071DAD3570225217C
            SHA-512:6076C7EFAD0DEE139F946774A3131C7D4887CCBE006BAE52984F2A9B55584A8A94F5E5635F118DEDF8A3A1F5F07122DBE7D84552E8161DEA041764EAC094E3E5
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_common",. "from": "system",. "instantiation": "false",. "adaptive_layer_height": "0",. "reduce_crossing_wall": "0",. "bridge_flow": "0.95",. "bridge_speed": "25",. "brim_width": "5",. "compatible_printers": [],. "print_sequence": "by layer",. "default_acceleration": "10000",. "bridge_no_support": "0",. "elefant_foot_compensation": "0.1",. "outer_wall_line_width": "0.4",. "outer_wall_speed": "120",. "line_width": "0.45",. "infill_direction": "45",. "sparse_infill_density": "15%",. "sparse_infill_pattern": "grid",. "initial_layer_line_width": "0.42",. "initial_layer_print_height": "0.2",. "initial_layer_speed": "20",. "gap_infill_speed": "30",. "infill_combination": "0",. "sparse_infill_line_width": "0.45",. "infill_wall_overlap": "25%",. "sparse_infill_speed": "50",. "interface_shells": "0",. "detect_overhang_wall": "0",. "reduce_infill_retraction": "0
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3411
            Entropy (8bit):4.638453769507467
            Encrypted:false
            SSDEEP:96:jJNJFa5B+UyKpQnQHxr+W7QYublAMpTX+CdkSDHKpYqNS:jPa5BpyKpQnQHxH7QYublAsTX+CmUHKq
            MD5:E9D130454328882D41D8090C789FFE14
            SHA1:8C61C8B6DBD9EB043A75D4E5D877229A274EFF61
            SHA-256:B7244D7F54A79E7D43E585B593E60BE1830E435BC355612603F2042BBF22C488
            SHA-512:7A4EAEF3A39EAB12D6AACD212E34C9113DC209CAAF44D9CA33A919FC9612C3BB0B4DB9DE17B2C26DBF955D4464F8F8CC1BA44A86C9A8AB64B90B77C220F7AA72
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_klipper_common",. "from": "system",. "instantiation": "false",. "inherits": "fdm_process_common",. "adaptive_layer_height": "0",. "reduce_crossing_wall": "0",. "max_travel_detour_distance": "0",. "bottom_surface_pattern": "monotonic",. "bottom_shell_layers": "3",. "bottom_shell_thickness": "0",. "bridge_flow": "0.95",. "bridge_speed": "50",. "ineternal_bridge_speed": "70",. "brim_width": "5",. "brim_object_gap": "0.1",. "compatible_printers_condition": "",. "print_sequence": "by layer",. "default_acceleration": "5000",. "top_surface_acceleration": "3000",. "travel_acceleration": "7000",. "inner_wall_acceleration": "5000",. "outer_wall_acceleration": "3000",. "bridge_no_support": "0",. "draft_shield": "disabled",. "elefant_foot_compensation": "0",. "outer_wall_line_width": "0.4",. "wall_infill_order": "inner wall/outer wall/infill",. "line_width": "0.4",. "infill_direction": "45",. "sparse_infill_density": "15%",
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):5537
            Entropy (8bit):4.105765640793725
            Encrypted:false
            SSDEEP:48:/7aWSwe9Ss2Lp1p3G0VOvyw3drjLp5hFEIrcr:DFSwe9Ss2L7p3G0VShgr
            MD5:7F390AD710D0B97E1BB00961E6A9E354
            SHA1:A129F1F6C916745B316980D0BB339D95BB314CD3
            SHA-256:6EED8376F36C9EE639736CF74B87124BF8A01C27A695F4263AA7E23C3CC7CDBF
            SHA-512:872B011EA85527DF1AD1FBCE0F5F2D8EE719D5F485D6078CACDCD2BA55E4D652925FD2563B20B87C61105FC5D7E2746F2A5046E23779350951BC5F56C4A47D7C
            Malicious:false
            Reputation:low
            Preview:{. "name": "Voron",. "version": "01.08.00.03",. "force_update": "0",. "description": "Voron configurations",. "machine_model_list": [. {. "name": "Voron 2.4 250",. "sub_path": "machine/Voron 2.4 250.json". },. {. "name": "Voron 2.4 300",. "sub_path": "machine/Voron 2.4 300.json". },. {. "name": "Voron 2.4 350",. "sub_path": "machine/Voron 2.4 350.json". },. {. "name": "Voron Trident 250",. "sub_path": "machine/Voron Trident 250.json". },. {. "name": "Voron Trident 300",. "sub_path": "machine/Voron Trident 300.json". },. {. "name": "Voron Trident 350",. "sub_path": "machine/Voron Trident 350.json". },. {. "name": "Voron 0.1",. "sub_path": "machine/Voron 0.1.json". }. ],. "process_list": [. {. "name":
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):53506
            Entropy (8bit):7.978103061576475
            Encrypted:false
            SSDEEP:768:G+C4oVBZo57OgjfOHxyFc9ZnTkFqxzj0XaU4GAXi8oLLJfAo5syaRnoMh0VQrXY:tCFBZcjfaac9ZoWHjXoxj5svRnoMeVII
            MD5:8E410765A0345B245085D26B3973C25E
            SHA1:52BE1F6D614FCB6BEECB7E0492461C40CD2B2CEB
            SHA-256:540FD1CDC782112492ED5797FA8ECAAB96DB88450C5DE2831D840907B7AC1A1A
            SHA-512:B707728892687713E5A40196E670E2ABF45F8C81D2E830562DC718CBB3D425EF936146BFBECDD186A1303DB4C07F63189694E10923C54BAA162CEF1051417CD4
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................e....pHYs...#...#.x.?v.. .IDATx..w.m.Q.XU{.t....:'e.. .......b..X23...3..f.......g..=`...a..B.I.b'..u|.r...n>a.?....^7,.k...n8g..kW..W......~...@T.DDB.%D....SP.&@.....U....TA.T..TATA..............$.*..7<.=...D.xq..[.;.y.....j...^E..jx!"z...>.O-./...|O....PU.xi........}....{.q...?.^.DHi.@.4..YsqqQ.=.$.E.{....v..,]Zh7..c.u....'..{cg..m.o.v...=O={. I.nw...%.....* .1..#]...J....O.......3............>..~k....X..w~W..s...<..c..72{.V....~.s...w....."..`Y..N...8{...p<..9s.......@.....o..o...]..D@"....j].z.#....u'...._uZ.....].Tv.*_......"!.!c......g.D."........@PD $D..'....=........X*......0|!...(...h..D.....T.."......ld.........U..2.T$/&EY...FEQ.i....P.UE.F.mI4B.....|..,.}._......;7lT.e........0.........*..q...*. ..........@.s...3...N. ".V.'c.89d....j....!..(......h.G.cL.....q...6..n....H......1.{...}.......N..;...{....LTO...$@D....E.U..p..p..Q....ol4Rc.F.AL.8.z.%........B....[....TDTh...a........Q.y.....V...U.4/..Un..7..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):34533
            Entropy (8bit):7.986440882495313
            Encrypted:false
            SSDEEP:768:uvx90p0HD/itDrsmT0Erdqfnj1H5ZdHaSnDeXf:IrSWD/w302qfnznDeXf
            MD5:E19D487F6486087CC4A029371696056A
            SHA1:80132773651AC6CBF8314C377804A0DADF06C53C
            SHA-256:3F2E0DD6E122B2F75C6E933360ECD4E0A223E85F9C76B61BB2E179D1E52FE1A8
            SHA-512:F557F6B80D704F944D51CA7064F4CD81A09E77C718E55DA5A1E8A0FA8217A44418EBA1B15D999A80C9C156DBA419CB23CB44DD217772772397F6F3A98032C3D2
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................e....pHYs............... .IDATx..k.e.u&....<...f7I.M.IQ.d..E..I<v`G6.?l8@2@~$....cL........f.$.ag<3..c.a."K.-..#.,.")R$..f.....<..U.....9....h.{...S{.z|.[_1....3.G........=.~.{.. ...1...{H?.{..fwy.N........4......^`Z...._..%g..W.ay..AH_.G.;H?..~...p2................n8..L}....;Z_~....t.p.M.m..w|?~...]Q.........n..8[.`...ok....s..-:...)dW.=..;......i.<...M.z...k|7#.[...}..,..l..Z.e..u.}...!k.3...2W..lz.j.d.K.}..-..K^.g.]..=..^.........o|..g.|..;..............k...]..&...o......p...;..j............p....2Sz..oj.28.....j.}.....`e...g...k...|.;.....p..t.]...;..L.............Fx..9......m.....-3r. ]K.o0...X..~b.]|...o....D...0G.H.....M;..7..E...`.z.y:.)..>.....Xs....r......U..YC./.j0..;g.s.m..oC....9......g.;..........L.K......s.f.|...]S..}-.`%Z....2.%.1..5O.Z.....=^.+..4...{...1#....`.y[.H[.....O..$#....v.C............f.3...I...m..... '.~zA+.t.o.N..s.Sl.F.,..La...2......<G./.B.)I.Z...gS:..N.}..<..A.....o.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):34533
            Entropy (8bit):7.986440882495313
            Encrypted:false
            SSDEEP:768:uvx90p0HD/itDrsmT0Erdqfnj1H5ZdHaSnDeXf:IrSWD/w302qfnznDeXf
            MD5:E19D487F6486087CC4A029371696056A
            SHA1:80132773651AC6CBF8314C377804A0DADF06C53C
            SHA-256:3F2E0DD6E122B2F75C6E933360ECD4E0A223E85F9C76B61BB2E179D1E52FE1A8
            SHA-512:F557F6B80D704F944D51CA7064F4CD81A09E77C718E55DA5A1E8A0FA8217A44418EBA1B15D999A80C9C156DBA419CB23CB44DD217772772397F6F3A98032C3D2
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................e....pHYs............... .IDATx..k.e.u&....<...f7I.M.IQ.d..E..I<v`G6.?l8@2@~$....cL........f.$.ag<3..c.a."K.-..#.,.")R$..f.....<..U.....9....h.{...S{.z|.[_1....3.G........=.~.{.. ...1...{H?.{..fwy.N........4......^`Z...._..%g..W.ay..AH_.G.;H?..~...p2................n8..L}....;Z_~....t.p.M.m..w|?~...]Q.........n..8[.`...ok....s..-:...)dW.=..;......i.<...M.z...k|7#.[...}..,..l..Z.e..u.}...!k.3...2W..lz.j.d.K.}..-..K^.g.]..=..^.........o|..g.|..;..............k...]..&...o......p...;..j............p....2Sz..oj.28.....j.}.....`e...g...k...|.;.....p..t.]...;..L.............Fx..9......m.....-3r. ]K.o0...X..~b.]|...o....D...0G.H.....M;..7..E...`.z.y:.)..>.....Xs....r......U..YC./.j0..;g.s.m..oC....9......g.;..........L.K......s.f.|...]S..}-.`%Z....2.%.1..5O.Z.....=^.+..4...{...1#....`.y[.H[.....O..$#....v.C............f.3...I...m..... '.~zA+.t.o.N..s.Sl.F.,..La...2......<G./.B.)I.Z...gS:..N.}..<..A.....o.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):34533
            Entropy (8bit):7.986440882495313
            Encrypted:false
            SSDEEP:768:uvx90p0HD/itDrsmT0Erdqfnj1H5ZdHaSnDeXf:IrSWD/w302qfnznDeXf
            MD5:E19D487F6486087CC4A029371696056A
            SHA1:80132773651AC6CBF8314C377804A0DADF06C53C
            SHA-256:3F2E0DD6E122B2F75C6E933360ECD4E0A223E85F9C76B61BB2E179D1E52FE1A8
            SHA-512:F557F6B80D704F944D51CA7064F4CD81A09E77C718E55DA5A1E8A0FA8217A44418EBA1B15D999A80C9C156DBA419CB23CB44DD217772772397F6F3A98032C3D2
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................e....pHYs............... .IDATx..k.e.u&....<...f7I.M.IQ.d..E..I<v`G6.?l8@2@~$....cL........f.$.ag<3..c.a."K.-..#.,.")R$..f.....<..U.....9....h.{...S{.z|.[_1....3.G........=.~.{.. ...1...{H?.{..fwy.N........4......^`Z...._..%g..W.ay..AH_.G.;H?..~...p2................n8..L}....;Z_~....t.p.M.m..w|?~...]Q.........n..8[.`...ok....s..-:...)dW.=..;......i.<...M.z...k|7#.[...}..,..l..Z.e..u.}...!k.3...2W..lz.j.d.K.}..-..K^.g.]..=..^.........o|..g.|..;..............k...]..&...o......p...;..j............p....2Sz..oj.28.....j.}.....`e...g...k...|.;.....p..t.]...;..L.............Fx..9......m.....-3r. ]K.o0...X..~b.]|...o....D...0G.H.....M;..7..E...`.z.y:.)..>.....Xs....r......U..YC./.j0..;g.s.m..oC....9......g.;..........L.K......s.f.|...]S..}-.`%Z....2.%.1..5O.Z.....=^.+..4...{...1#....`.y[.H[.....O..$#....v.C............f.3...I...m..... '.~zA+.t.o.N..s.Sl.F.,..La...2......<G./.B.)I.Z...gS:..N.}..<..A.....o.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):40221
            Entropy (8bit):7.977241955216268
            Encrypted:false
            SSDEEP:768:sRgXwnhJSoHMvS1AzuLNJe/Q9R6sQO8A7pKLYcS9b4OLdDePPCi0bu09B45:sWGJMs7qMQOtcGzLu6Z+
            MD5:46DE92A5AD6D903F0EBA4E90BE01FF1B
            SHA1:141871E23FE09454C7B19E93F3B1E6E6FCEE7A8E
            SHA-256:BFA2AF1D11DF357CDE3AC060859E15531CCEC4D6FEE71BBDA30FBACF0646CFB8
            SHA-512:B359946275E77412684C6357466D00EAB891ECDA5F1CB6DD6AD1C68A39B290C25140D12DA88FA433F5E42B5DF79747A38AC366BF872EC8509274041CE0BA1C72
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................e....pHYs...#...#.x.?v.. .IDATx..W.eYr&..kmw...o.,.].]M.dw.....#q8.8... a$....y..Ga..4.H.@.4`7...........zs.....Z{.........y.9{.V./....X..b]..u....X..b]..u....X..b]..u....X..b]..u....X..b]..u....X..b]..u.....g...U...PT....."..SoE...+....>..>...@....@U.....!... .../........O...Rhn.........5....D..E...G.Q.\.......Z..pc|js......yZ..>..'..l.b.x............P.+D.P..H.?\........@.9TD...........H...BDQ%x.p............OZ...T..!.......u.mU@...^...TPm.}.|(....DD.UQA.......,..O+|i.U}...GGA...RQ.@......<%.J.{.i.RT. ..p.E..A...9.p.O=....H..).A}O.?.5.....Q.B..nD.U..m..(..j-E...e....`t....~..R.#..{T...j..s.(....F......{.i.._....e.. ....sI.B....3#.%.Z..(H.....0..+....+G;..*.Z...;#...H......yn..8.@. Z[.fK...Q...B..E....@.+#""..M.((j...."..........s...{r H....A..JD..(....PU..N?eI.?....a..........z...w..;Z_.K..+...IU...7.._...].Yj.!...NG...4..5B....6Dl.H.T....9.3.C......>.6......6.**^O..#..._Qu.PU..<o..y1......VD..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):40221
            Entropy (8bit):7.977241955216268
            Encrypted:false
            SSDEEP:768:sRgXwnhJSoHMvS1AzuLNJe/Q9R6sQO8A7pKLYcS9b4OLdDePPCi0bu09B45:sWGJMs7qMQOtcGzLu6Z+
            MD5:46DE92A5AD6D903F0EBA4E90BE01FF1B
            SHA1:141871E23FE09454C7B19E93F3B1E6E6FCEE7A8E
            SHA-256:BFA2AF1D11DF357CDE3AC060859E15531CCEC4D6FEE71BBDA30FBACF0646CFB8
            SHA-512:B359946275E77412684C6357466D00EAB891ECDA5F1CB6DD6AD1C68A39B290C25140D12DA88FA433F5E42B5DF79747A38AC366BF872EC8509274041CE0BA1C72
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................e....pHYs...#...#.x.?v.. .IDATx..W.eYr&..kmw...o.,.].]M.dw.....#q8.8... a$....y..Ga..4.H.@.4`7...........zs.....Z{.........y.9{.V./....X..b]..u....X..b]..u....X..b]..u....X..b]..u....X..b]..u....X..b]..u.....g...U...PT....."..SoE...+....>..>...@....@U.....!... .../........O...Rhn.........5....D..E...G.Q.\.......Z..pc|js......yZ..>..'..l.b.x............P.+D.P..H.?\........@.9TD...........H...BDQ%x.p............OZ...T..!.......u.mU@...^...TPm.}.|(....DD.UQA.......,..O+|i.U}...GGA...RQ.@......<%.J.{.i.RT. ..p.E..A...9.p.O=....H..).A}O.?.5.....Q.B..nD.U..m..(..j-E...e....`t....~..R.#..{T...j..s.(....F......{.i.._....e.. ....sI.B....3#.%.Z..(H.....0..+....+G;..*.Z...;#...H......yn..8.@. Z[.fK...Q...B..E....@.+#""..M.((j...."..........s...{r H....A..JD..(....PU..N?eI.?....a..........z...w..;Z_.K..+...IU...7.._...].Yj.!...NG...4..5B....6Dl.H.T....9.3.C......>.6......6.**^O..#..._Qu.PU..<o..y1......VD..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):40221
            Entropy (8bit):7.977241955216268
            Encrypted:false
            SSDEEP:768:sRgXwnhJSoHMvS1AzuLNJe/Q9R6sQO8A7pKLYcS9b4OLdDePPCi0bu09B45:sWGJMs7qMQOtcGzLu6Z+
            MD5:46DE92A5AD6D903F0EBA4E90BE01FF1B
            SHA1:141871E23FE09454C7B19E93F3B1E6E6FCEE7A8E
            SHA-256:BFA2AF1D11DF357CDE3AC060859E15531CCEC4D6FEE71BBDA30FBACF0646CFB8
            SHA-512:B359946275E77412684C6357466D00EAB891ECDA5F1CB6DD6AD1C68A39B290C25140D12DA88FA433F5E42B5DF79747A38AC366BF872EC8509274041CE0BA1C72
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................e....pHYs...#...#.x.?v.. .IDATx..W.eYr&..kmw...o.,.].]M.dw.....#q8.8... a$....y..Ga..4.H.@.4`7...........zs.....Z{.........y.9{.V./....X..b]..u....X..b]..u....X..b]..u....X..b]..u....X..b]..u....X..b]..u.....g...U...PT....."..SoE...+....>..>...@....@U.....!... .../........O...Rhn.........5....D..E...G.Q.\.......Z..pc|js......yZ..>..'..l.b.x............P.+D.P..H.?\........@.9TD...........H...BDQ%x.p............OZ...T..!.......u.mU@...^...TPm.}.|(....DD.UQA.......,..O+|i.U}...GGA...RQ.@......<%.J.{.i.RT. ..p.E..A...9.p.O=....H..).A}O.?.5.....Q.B..nD.U..m..(..j-E...e....`t....~..R.#..{T...j..s.(....F......{.i.._....e.. ....sI.B....3#.%.Z..(H.....0..+....+G;..*.Z...;#...H......yn..8.@. Z[.fK...Q...B..E....@.+#""..M.((j...."..........s...{r H....A..JD..(....PU..N?eI.?....a..........z...w..;Z_.K..+...IU...7.._...].Yj.!...NG...4..5B....6Dl.H.T....9.3.C......>.6......6.**^O..#..._Qu.PU..<o..y1......VD..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):618
            Entropy (8bit):4.4554901522460995
            Encrypted:false
            SSDEEP:12:KY3hJOqU0dlpTmu5umqvzGzmRFQcrRcO8hYA:KgwqHpTr5RqvizmRFQqRpvA
            MD5:9E4E50DA57D22729C84D5FBC9383BBE6
            SHA1:D7E2779F37FB68814AA3CA61799BF30734242581
            SHA-256:13261E438ABECBB7FDD66F9890C74865764AFB6E8A0E6E9CB3870D2B2DA963B1
            SHA-512:193383601E731274A7960E3BD4A82B6EB5AAF2FD9C6C70DBEBD2EF3D788CB315432475F76EBA6DB07A0BCC49AC88FC0DAC030A584E614416D95B056BBBBF870D
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFB99",. "setting_id": "GFSB99_VORON_00",. "name": "Generic ABS @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_abs",. "filament_flow_ratio": [. "0.926". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):617
            Entropy (8bit):4.450300594815677
            Encrypted:false
            SSDEEP:12:KVz3hJsHRp0dlpTmu5jOvzGzmRFQcrRcO8hYA:KRxLHpTr5KvizmRFQqRpvA
            MD5:CC501E5A0D59E7B55A9DB857DBEDE909
            SHA1:6676C6449D22939A9561526D683FC2DEBED61CA5
            SHA-256:32B2D751DD02499B14897D7ECD53E7061B9F37FDF415E8A76D0C139F555B59BD
            SHA-512:ABB62C55CBB1EF5FD81D7FB3755738655F19FAA8EEC8B318B75D5F6ACD2A0AF0037DD021D9CC8BCF01CE33DBCC5DE676DF766842C6A060C5F0BCC9599637A052
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFB98",. "setting_id": "GFSB98_VORON_00",. "name": "Generic ASA @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_asa",. "filament_flow_ratio": [. "0.93". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):676
            Entropy (8bit):4.419519017730459
            Encrypted:false
            SSDEEP:12:Ks3hJSqn0dlpTmu5/XSQlxIvzGzmRFQcrRcO8hYA:K0cdHpTr5vS8xIvizmRFQqRpvA
            MD5:0563C0EAE4729C4D0413A90B50B65462
            SHA1:B549F6CA5981B039F35A201BFF221FEEA1DA1FFC
            SHA-256:A999E71A448C9A55D28BFE4F5E1DAAF6D53D1DE52929D7C9A98EC79D8DADC8D0
            SHA-512:1E838DFCF189CAEE0553913FD8855A800EB1D6EA58C362EB05903FA0372267E68C69694FAD2389C9656D147A68551EB9DF3B82BDA802B6042F5541FA86FBE499
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFN99",. "setting_id": "GFSN99_VORON_00",. "name": "Generic PA @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pa",. "nozzle_temperature_initial_layer": [. "280". ],. "nozzle_temperature": [. "280". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):666
            Entropy (8bit):4.421764284358958
            Encrypted:false
            SSDEEP:12:KRz3hJgHR10dlpTmu5/cqxSQlxIzmRFQcrRcO8hYA:KlxwcHpTr5RxS8xIzmRFQqRpvA
            MD5:BA20E7558845A57080559722189B9AAC
            SHA1:E01DDF54A6E394EECC2C44A351631E2D8DDA298F
            SHA-256:865DE2FA0B6F44A75096928625C15AFC2408CBAF17DE1CAE8ADEC3C02A47118F
            SHA-512:F003345A013439834718989C8E4EB6DB59EC81AA83756152D9DE6A1342C4524F71590EFD485F1ECFAF13C15C76E602322777754E75E0C9080F479279B79317E7
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFN98",. "setting_id": "GFSN98_VORON_00",. "name": "Generic PA-CF @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pa",. "filament_type": [. "PA-CF". ],. "nozzle_temperature_initial_layer": [. "280". ],. "nozzle_temperature": [. "280". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):615
            Entropy (8bit):4.434354096509682
            Encrypted:false
            SSDEEP:12:Kj9hJTq4A0dlpTmu5LzGhbzmRFQcrRcO8hYA:KbhHpTr5Li9zmRFQqRpvA
            MD5:1141A70EDC847055813AD79EC7D67BDE
            SHA1:0CE7DF9CB974DD9BCEC8729A4D092BCACDE7EE33
            SHA-256:513898E4B5DE16AA63CEFFCC9E7EF09BB80CA7E753BBFA9A1B4724ECC52E594F
            SHA-512:5F2A65843305AE0C5F7CCD0F862FDEEFF0D96A6ECDF44FD623CF0CD305D936F5252A69CD795DDF98478A63DC78219A7576C10A8498FFB6989C59C7A3C1FBE920
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFC99",. "setting_id": "GFSC99_VORON_00",. "name": "Generic PC @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pc",. "filament_max_volumetric_speed": [. "12". ],. "filament_flow_ratio": [. "0.94". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):857
            Entropy (8bit):4.3634584820864815
            Encrypted:false
            SSDEEP:24:KnnSHpTr5NoiOo8PwpDNov4zmRFQqRpvA:KnSHpTr5Ww8sIW
            MD5:3F9B5507A203C6F6AB17C8660FFD9F24
            SHA1:8054E9E55DA8B59C54E43764718FC2746E199736
            SHA-256:009A33F675B79EC24B7057A8766B66854B3AE429B9E506DD412AF699BA5A3274
            SHA-512:14FAE3C6054A88001F888A43804F85DEDC9C1E5199C882045D775D91602C1FB490BBCF259E13E309BA41E344FF3D54E075532E530287F5D67605AB43768DDABD
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFG99",. "setting_id": "GFSG99_VORON_00",. "name": "Generic PETG @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pet",. "fan_cooling_layer_time": [. "30". ],. "overhang_fan_speed": [. "90". ],. "overhang_fan_threshold": [. "25%". ],. "fan_max_speed": [. "90". ],. "fan_min_speed": [. "40". ],. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "10". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):607
            Entropy (8bit):4.416477952890504
            Encrypted:false
            SSDEEP:12:KS3hJpZ0dlpTmu58afXzmRFQcrRcO8hYA:KSx2HpTr5XXzmRFQqRpvA
            MD5:29CE04DB4B1022FF0A53C1D75AAAC336
            SHA1:A635A15D5A2AE9AADA364F4D58C8B207520F9E1D
            SHA-256:5DFE95697F9E9C8E7657B55A16C00F69CC887B13B0659D5154F471F1157E1532
            SHA-512:2369035FC7383D709A848BD6C06C81120C845DFDC518B7C4B703D1FB85E150FA7DF34BBCDE00BF66C390FCD3BCB29AC170B29A60C4EBA3C0BB45BCD17268E6EA
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFL99",. "setting_id": "GFSL99_VORON_00",. "name": "Generic PLA @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pla",. "filament_flow_ratio": [. "0.98". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):657
            Entropy (8bit):4.447300361224638
            Encrypted:false
            SSDEEP:12:Kr3hJA70dlpTmu58a3omxQtQzmRFQcrRcO8hYA:Kl9HpTr5/omQtQzmRFQqRpvA
            MD5:A41C328D5037BD0CA2FCE24CCB141944
            SHA1:DA1F8BE85135C086E8DC13FD8868FAC1C71C9EB6
            SHA-256:EF1EEA2AEF408E81E85B964F8DC7D6F3AA7AC049387E378E16C42E5D2FCBBB4F
            SHA-512:BC71E9E42E3C2CC2FF9DECB18D256F740B70A7C94FC7B33CD6C2E6E37F12AB5CA087FDC80524F11F9A0628D50DF733C8547B4AE020316BCA42053277C1C6C5FF
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFL98",. "setting_id": "GFSL98_VORON_00",. "name": "Generic PLA-CF @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pla",. "filament_flow_ratio": [. "0.95". ],. "filament_type": [. "PLA-CF". ],. "slow_down_layer_time": [. "7". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):666
            Entropy (8bit):4.433293749987797
            Encrypted:false
            SSDEEP:12:Kz9hJX+SA0dlpTmu5dr3ovzGtQzmRFQcrRcO8hYA:KLRjHpTr5ZovitQzmRFQqRpvA
            MD5:A9302E908DFE2195C682756C382678E6
            SHA1:1CBA684A235A19E90B6A7339DBB7AD9789DBC149
            SHA-256:47264838ABC8A15FD17DC87CEA3765037A73E3037202B78CA39C196F41E7F0C4
            SHA-512:FB69694F6F0D3030A6616C655ADF34D8DC72ECB178825ED8249DF32DE14620BD9E3FA1F20A34FAF93DD6C811399D4181BFACC96D95455707F2CFB83F382CED98
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFS99",. "setting_id": "GFSS99_VORON_00",. "name": "Generic PVA @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pva",. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "12". ],. "slow_down_layer_time": [. "7". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):567
            Entropy (8bit):4.456127122476946
            Encrypted:false
            SSDEEP:12:KWqhJdMh680dlpTmu5sazXgzmRFQcrRcO8hYA:KW4LBHpTr557gzmRFQqRpvA
            MD5:A6D780EB5EDD9AA36A22E0F1C7511A81
            SHA1:B43591249A1241675BB9FB2E55FDC97219A7F75E
            SHA-256:C8B100636B7C8FDB5F68C30F4EC43C4E71F577B3F224CA1C68CC94EA51A92960
            SHA-512:F99F61E4BDC18C6CA83080F15D8F758FFC787CFD143B9545413EDA037D809D7AB2C60E1F7D501A26D5FB9F622D58820E1025D4538BBF2AE68E8B36A8ECC5A2A6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFU99",. "setting_id": "GFSU99_VORON_00",. "name": "Generic TPU @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_tpu",. "filament_max_volumetric_speed": [. "3.2". ],. "compatible_printers": [. "Voron 2.4 250 0.4 nozzle",. "Voron 2.4 300 0.4 nozzle",. "Voron 2.4 350 0.4 nozzle",. "Voron Trident 250 0.4 nozzle",. "Voron Trident 300 0.4 nozzle",. "Voron Trident 350 0.4 nozzle",. "Voron 0.1 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1574
            Entropy (8bit):4.121853774832129
            Encrypted:false
            SSDEEP:24:9+Hpy5v/T22z2b2D2mO26OyOKOOgzqbvGCZvDajcoRxSSIhrqPwUno8oiTxGm5wy:9+Hpy5vbDzMStvzaxXZrOm9e
            MD5:E0C44507EFE6484D671590C7EB51A104
            SHA1:97538D13AA926C420E4A45247718588449BCE58A
            SHA-256:D43AFC81EDC409230CF91F106DDBB5B766813C44FC423906C484428617E6720F
            SHA-512:513E8F8A10086F913BC165D2BC2504D10917615A2FE5F911DF1E39ECA7E8A9C6E0CB31B269CA418B582FACFD8D0EB60348BE9B2054426F80AFD45B33A4A7B28E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_abs",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "105". ],. "eng_plate_temp" : [. "105". ],. "hot_plate_temp" : [. "105". ],. "textured_plate_temp" : [. "105". ],. "cool_plate_temp_initial_layer" : [. "105". ],. "eng_plate_temp_initial_layer" : [. "105". ],. "hot_plate_temp_initial_layer" : [. "105". ],. "textured_plate_temp_initial_layer" : [. "105". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "30". ],. "filament_max_volumetric_speed": [. "28.6". ],. "filament_type": [. "ABS". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "260
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1574
            Entropy (8bit):4.116386888170143
            Encrypted:false
            SSDEEP:24:9PHpy5v/T22z2b2D2mO26OyOKOOgzqbvGCavDaLocoRxSSIhrqPwUno8oiTxGm5h:9PHpy5vbDzMStvzJ8XZrOm9e
            MD5:EA4F9D824861A26984A2FA47B6AE37FD
            SHA1:4DB8C776CF70A7374728B11A8871B57A907BE021
            SHA-256:01CAC22172DD56FAAA748AB41803620E78858AA065F06660B265E0FFE890B653
            SHA-512:1D154FB5CC8539FD186CDC6F5CF45639BD42269792784305407B0FE0453753AAC38B7E9CD8D8C5503B1338176DE94E54A0912A41E1B88EE4826E2DA11B33C6DD
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_asa",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "105". ],. "eng_plate_temp" : [. "105". ],. "hot_plate_temp" : [. "105". ],. "textured_plate_temp" : [. "105". ],. "cool_plate_temp_initial_layer" : [. "105". ],. "eng_plate_temp_initial_layer" : [. "105". ],. "hot_plate_temp_initial_layer" : [. "105". ],. "textured_plate_temp_initial_layer" : [. "105". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "35". ],. "filament_max_volumetric_speed": [. "28.6". ],. "filament_type": [. "ASA". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "260
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2608
            Entropy (8bit):4.045397417224265
            Encrypted:false
            SSDEEP:48:9vxHpi7zEqdyanziBxK2VZp0oCz/NzunU:vsPEqwan12VmTWU
            MD5:1775ACEFB9277B88D7511EF4FE227930
            SHA1:6B55ED4FCE4DD9FD3096F8AB2CB0E26980FAD8B1
            SHA-256:68F4D4E346B08ACAD7A04E264D9DED9A9833CBD385FDAA6D2C6AAB3B56C27175
            SHA-512:4D5B80E139545B0D43FA6AED5591C084159CC75A5AB43652BC9123A20CF96418ADAEE606EB6871BE793E8A2A0F10143ABA709E6E9F85FE5DE8CF3D436DA24FE8
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_common",. "from": "system",. "instantiation": "false",. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "60". ],. "hot_plate_temp" : [. "60". ],. "textured_plate_temp" : [. "60". ],. "cool_plate_temp_initial_layer" : [. "60". ],. "eng_plate_temp_initial_layer" : [. "60". ],. "hot_plate_temp_initial_layer" : [. "60". ],. "textured_plate_temp_initial_layer" : [. "60". ],. "overhang_fan_threshold": [. "95%". ],. "overhang_fan_speed": [. "100". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "filament_end_gcode": [. "; filament end gcode \n". ],. "filament_flow_ratio": [. "1". ],. "reduce_fan_stop_start_freq": [. "0". ],. "fan_cooling_layer_time": [. "60". ],. "filament_cost":
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1510
            Entropy (8bit):4.064943678091041
            Encrypted:false
            SSDEEP:24:9fHpy5v/TK2zNbNDNmi26FyFKFOgzqbvGCAvlJcoRxSJIh5Pwyzoi0xlmLxhwx0C:9fHpy5vbnzh1cazpYXotIV
            MD5:DB3C15F3C501D0F7B37315598EBCC757
            SHA1:6681B3262418D88DA8A0DE916A22C4842AC54F44
            SHA-256:58E318F39B98679DC3C97E518E41EA1B8A0102EBBA839AAB7236CA5FCA9B0824
            SHA-512:C38CC72EFD51435A72B9C2C3DED84B967624172BF8E53F80456B653E944F734FCB90B593CB6C41A6BC540D94A50686025C129348A4AE0EA98695A1814BBB09EC
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pa",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "0". ],. "eng_plate_temp" : [. "100". ],. "hot_plate_temp" : [. "100". ],. "textured_plate_temp" : [. "100". ],. "cool_plate_temp_initial_layer" : [. "0". ],. "eng_plate_temp_initial_layer" : [. "100". ],. "hot_plate_temp_initial_layer" : [. "100". ],. "textured_plate_temp_initial_layer" : [. "100". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "4". ],. "filament_max_volumetric_speed": [. "8". ],. "filament_type": [. "PA". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "290". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1568
            Entropy (8bit):4.094531360924966
            Encrypted:false
            SSDEEP:24:9ZHpy5v/TK2zHwbHwDHwmi26PwyPwKPwOgzqbvGCZv6SwcoRxSawIhrqPwyqo8oN:9ZHpy5vbnzmQnFzatXSrOX9N
            MD5:EBC718D41A605C12F9377589805B0295
            SHA1:CB17B9FA4F962D442D9B9F69FE0270E6C30EFB54
            SHA-256:FC7FF0B2283FA534359EF90F9AE0406193BE8EF37FB4DDBA9F71C6CB0A9C8642
            SHA-512:5E0F71FC53342C6D2249B3FE2852F994F4343C92AC5DAF42744CDEBBFD41170DB434F6692FB1EE4D7CFA9288C0DB0BBFF40EEDB8DCDC14F2D78539016D10C757
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pc",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "0". ],. "eng_plate_temp" : [. "110". ],. "hot_plate_temp" : [. "110". ],. "textured_plate_temp" : [. "110". ],. "cool_plate_temp_initial_layer" : [. "0". ],. "eng_plate_temp_initial_layer" : [. "110". ],. "hot_plate_temp_initial_layer" : [. "110". ],. "textured_plate_temp_initial_layer" : [. "110". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "30". ],. "filament_max_volumetric_speed": [. "23.2". ],. "filament_type": [. "PC". ],. "filament_density": [. "1.04". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "270".
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1485
            Entropy (8bit):4.09844788979624
            Encrypted:false
            SSDEEP:24:9RHpy5v/TO2zKbgDgmW26iyYKYOgzqbvGCMvAdClQExSWIhrqPwRloiMxymix3xt:9RHpy5vb7zAALbzfbedrObG
            MD5:DFD5D0BFC8AF0158F1C45DB2EA3F9083
            SHA1:67AD8B450CA296BEEC8DEB8A6866E9ECAE3DBACC
            SHA-256:F753AD2C2066C32C9ACE0959724B408A21B5AA32985966F825DE519AA224AA4B
            SHA-512:F81ACE708C31EB3C30A65F3D073F381E88A001EC017C95977AB548C0D6157BDFC54E5520F4840E01191794E1556E6CC0F1C4A6E740C88C05C031C52AD37E5121
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pet",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "0". ],. "hot_plate_temp" : [. "80". ],. "textured_plate_temp" : [. "80". ],. "cool_plate_temp_initial_layer" : [. "60". ],. "eng_plate_temp_initial_layer" : [. "0". ],. "hot_plate_temp_initial_layer" : [. "80". ],. "textured_plate_temp_initial_layer" : [. "80". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "20". ],. "filament_max_volumetric_speed": [. "25". ],. "filament_type": [. "PETG". ],. "filament_density": [. "1.27". ],. "filament_cost": [. "30". ],. "nozzle_temperature_initial_layer": [. "255". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1697
            Entropy (8bit):4.104138497261157
            Encrypted:false
            SSDEEP:24:9THpy5v/jviT7R/O2zObODOmW26WyWKWxSmIhrqOgzqPwR4oiMoO5bvIqxymMxUX:9THpy5v767zEqd6NrYzOe0OKqPP
            MD5:EF709238E6BA0FFFB1E50C355854D78B
            SHA1:5D3C4872C5308E5A7775AC8E7D9157F9AB1F9007
            SHA-256:65DE50F6DAB0C9F550C0C3D465549F5E7389A2332C7E6B949C66402DD9CF7735
            SHA-512:F9F7E72F77FAAC9B422BF77182B396F705553556B83F70D5D9C3D8F63789EFD0E2BED39F7D2AEA327F7D8DA3179B76152E697CB990BE4DF9AD2DABAC5F128FAA
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pla",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "12". ],. "filament_type": [. "PLA". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "60". ],. "hot_plate_temp" : [. "60". ],. "textured_plate_temp" : [. "60". ],. "cool_plate_temp_initial_layer" : [. "60". ],. "eng_plate_temp_initial_layer" : [. "60". ],. "hot_plate_temp_initial_layer" : [. "60". ],. "textured_plate_temp_initial_layer" : [. "60". ],. "nozzle_temperature_initial_layer": [. "220". ],. "reduce_fan_stop_start_freq": [. "1". ],. "slow_down_for_layer_cooling": [. "1". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1788
            Entropy (8bit):4.097754760791249
            Encrypted:false
            SSDEEP:24:9ZHpy5v/Tg2zKbjDjmo26iyrKrPvXD4qkzq97RxSmIhrqOgzqPwR4oiMoO5bvIq2:9ZHpy5vbdzAHy/UDzXNrYzOe0OKzVPAi
            MD5:93AFB2AD0669F88A22BD26E4E6D1361A
            SHA1:3085299A770B58C76A7FEB7A5697A7507D64B937
            SHA-256:0686BAE3D5221CEEA41CAA469610D10DD352A6089E2FFBECCAAEE51AF0531D39
            SHA-512:67D92006411C8BAEDF667F77219B058FC9A6D84DD81637026600CD7112041BEABB7CDAC3B8FC8407A09E28EF1338B4B5B601DB1C5465A2248D76814C8443600B
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pva",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "35". ],. "eng_plate_temp" : [. "0". ],. "hot_plate_temp" : [. "45". ],. "textured_plate_temp" : [. "45". ],. "cool_plate_temp_initial_layer" : [. "35". ],. "eng_plate_temp_initial_layer" : [. "0". ],. "hot_plate_temp_initial_layer" : [. "45". ],. "textured_plate_temp_initial_layer" : [. "45". ],. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "15". ],. "filament_soluble": [. "1". ],. "filament_is_support": [. "1". ],. "filament_type": [. "PVA". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "220". ],. "reduce_fan_stop_s
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1603
            Entropy (8bit):4.109406244255383
            Encrypted:false
            SSDEEP:24:9fHpy5v/Tf2zfbgDgmH26HyoKoPvXiw7RoxSwIhrqOgzqPwR4oiMAgbvIqxkmMxk:9fHpy5vbOzTAegyGrrYzOeg/g
            MD5:F4153047E773DE3AAE04B4AB679BA086
            SHA1:6855A107AD93D340AE633AED43E87048346B9205
            SHA-256:772368404EE59E786C875861EE943754EF5781331660E6BAB5BC66A0006EE8AF
            SHA-512:BA08BACC3D1DF681D43111D871121E300341CF7557C6A90BCD0516CFB1373A966DEFFEDCADDA87B33AA3639FCA486F473941B2ACAC532157754E2323697374F6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_tpu",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "30". ],. "eng_plate_temp" : [. "30". ],. "hot_plate_temp" : [. "35". ],. "textured_plate_temp" : [. "35". ],. "cool_plate_temp_initial_layer" : [. "30". ],. "eng_plate_temp_initial_layer" : [. "30". ],. "hot_plate_temp_initial_layer" : [. "35". ],. "textured_plate_temp_initial_layer" : [. "35". ],. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "15". ],. "filament_type": [. "TPU". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "filament_retraction_length": [. "0.4". ],. "nozzle_temperature_initial_layer": [. "240". ],. "reduce_fan_stop_start_freq": [. "1". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):496
            Entropy (8bit):4.648123112857606
            Encrypted:false
            SSDEEP:12:qehVShRe0ZJpTEKYP995d/d2zVQ71VTc9k:3hVwe0ZJpTEKYP995d/d2zU/c9k
            MD5:959A6FB614915D628B1702AEBD623207
            SHA1:24336A16FD605AEAE7161F3FF4EF1454E167F2EB
            SHA-256:70205EA5CE99AB4AF6AB2314D1AD55A2F58D873EBE475368DCA6CBF82E63F292
            SHA-512:08FF61EC797ACD229A1256E0E03B3EFB0F956BCFBEAB33E9CF24FFF6DCF7CC2E4A60E341E7A2A59D1463A2C640FE0011C5C253C72771D7943FBE4FE9EDC92763
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_VORON_001",. "name": "Voron 0.1 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_klipper_common",. "printer_model": "Voron 0.1",. "default_print_profile": "0.20mm Standard @Voron",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "120x0",. "120x120",. "0x120". ],. "printable_height": "120",. "retract_lift_below":[. "119". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):476
            Entropy (8bit):4.701554789711413
            Encrypted:false
            SSDEEP:6:fiqQQ+Xsv2s8ZVspQSmZ4Xb6LAm6DEQ7164bIa5aWVqaEaJaqa9aSWaIWaL7aMEv:qqSXK2s8nXCXb6kmo5QGuNPqOlWhWeC
            MD5:84EB053AEA3CC5B24DD97D103FBE68EA
            SHA1:7F3EC07049E4330A6F9E70B9E341F9196674921A
            SHA-256:0D2E073564F5E87165C46D8D5A808244FB83DEC00A446FDA313F7F2D43003FCD
            SHA-512:9C2ADA0CC448E4696E31B306DA15E67A980EB42F95B0584B9D1159769E9175C2695EC37A9F64BBD47F1FD0A9C153ABBE70EFA1F28C0752DA52FDF10BE2514DBD
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Voron 0.1",. "model_id": "Voron0",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "VoronDesign",. "bed_model": "",. "bed_texture": "voron_v0_logo.png",. "hotend_model": "",. "default_materials": "Generic ABS @Voron;Generic PLA @Voron;Generic PLA-CF @Voron;Generic PETG @Voron;Generic TPU @Voron;Generic ASA @Voron;Generic PC @Voron;Generic PVA @Voron;Generic PA @Voron;Generic PA-CF @Voron".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):398
            Entropy (8bit):4.596466796771205
            Encrypted:false
            SSDEEP:6:fiehtzcMls0e0ZJz9JvFEK+FbFKgj9mmv2OoOkJQpXiVqk/4OkJyFE/JPNt:qehV7e0ZJpTEKYP9mQ2zVQ5Jv3JH
            MD5:14A9464886F7DD0FE2C1F407D6A708A0
            SHA1:646CC6B3E6828FFB8612E29D5DEE4E0F94CE2A03
            SHA-256:CDD5858ADF6E76CE2DEC6C191CDC0F7D664887765C6BAB555FCB91D2554C71D4
            SHA-512:72E8345A3A1AFF2AE4E0D5BFD6826DE882D540730358DB5333B1C4C8C125AD447E25B5EB4A2ED6A666075F11A3C8D553995FEB06D9D47B2B5060124E37552810
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_VORON_002",. "name": "Voron 2.4 250 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_klipper_common",. "printer_model": "Voron 2.4 250",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "250x0",. "250x250",. "0x250". ],. "printable_height": "225",. "retract_lift_below":[. "224". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):481
            Entropy (8bit):4.730369970353977
            Encrypted:false
            SSDEEP:6:fiqQOQXyv2s8ZVspQSmZ4XbXAm6DEQ7164bIa5aWVqaEaJaqa9aSWaIWaL7aMEv:qqLQXM2s8nXCXbQmo5QGuNPqOlWhWeC
            MD5:BB0DB16313952625DF61916E1F2183DD
            SHA1:0827AC64126A95AC40A68D32812D2D5CB7F226C6
            SHA-256:B0BD1E748958901797F79BD0BE6B6A6D710795ECD1A2AE21BD6CE7AFF3629D14
            SHA-512:6BD1CC5ECF6F7A80E813980C40E95B4D7A5BE6993EF1D594CB943E94900C594A31733FA83CFE38F1C8B294D1EA908191CCA668D9B51D20FBFF0375AEB43DF07E
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Voron 2.4 250",. "model_id": "Voron2_250",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "VoronDesign",. "bed_model": "",. "bed_texture": "voron_logo.png",. "hotend_model": "",. "default_materials": "Generic ABS @Voron;Generic PLA @Voron;Generic PLA-CF @Voron;Generic PETG @Voron;Generic TPU @Voron;Generic ASA @Voron;Generic PC @Voron;Generic PVA @Voron;Generic PA @Voron;Generic PA-CF @Voron".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):398
            Entropy (8bit):4.608954543873953
            Encrypted:false
            SSDEEP:6:fiehtzMvOg+0e0ZJz9JvFEK+FbFKgj9Hv2OoOkJQZ+g5OkJyFikJPNyP/r:qehVu5Re0ZJpTEKYP9P2zVQ5VBE8nr
            MD5:61FDA1116D7255AEA4F88972E0C07E7A
            SHA1:6172D95B25DE74F236F0A5EEFA6839973C844C90
            SHA-256:CC9CED2F04BBB3353818C5E8F608826CAD301157560F78F5742E96C1297DA3B2
            SHA-512:E2E2DDCDA93BB15F6F20D573902D86FE7696FCC00325413A944C82C5AC83DB69B5A76D3155D2C2DF399CF6685507802FB2B9DC21F609C6C249B2F46229CDF96D
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_VORON_003",. "name": "Voron 2.4 300 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_klipper_common",. "printer_model": "Voron 2.4 300",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "300x0",. "300x300",. "0x300". ],. "printable_height": "275",. "retract_lift_below":[. "274". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):481
            Entropy (8bit):4.728592937147588
            Encrypted:false
            SSDEEP:6:fiqQRXpWv2s8ZVspQSmZ4XbXAm6DEQ7164bIa5aWVqaEaJaqa9aSWaIWaL7aMEv:qqmXO2s8nXCXbQmo5QGuNPqOlWhWeC
            MD5:28B89452A36BF36119AC5DB67A207776
            SHA1:1649DA5E1CE9218B82AEA59A291F6C2C0795D01F
            SHA-256:ED3DC5C33E261B411CE8FBF2556DCB4E72E718216F4C146A9C0E97F3A2519C64
            SHA-512:8479C165D21B5025D0F22753F0718E0453D86F00BAB6384D23B6AED897D7E4428B3CC6357A1661E122B8F22BDF87EFBAD115C6CB06889C1F684E21F0C4A8F5D8
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Voron 2.4 300",. "model_id": "Voron2_300",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "VoronDesign",. "bed_model": "",. "bed_texture": "voron_logo.png",. "hotend_model": "",. "default_materials": "Generic ABS @Voron;Generic PLA @Voron;Generic PLA-CF @Voron;Generic PETG @Voron;Generic TPU @Voron;Generic ASA @Voron;Generic PC @Voron;Generic PVA @Voron;Generic PA @Voron;Generic PA-CF @Voron".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):398
            Entropy (8bit):4.627134087740914
            Encrypted:false
            SSDEEP:12:qehV/Ye0ZJpTEKYP9nQ2zVQMHNvXuoJut:3hVAe0ZJpTEKYP9nQ2zVvXn+
            MD5:53F9202B81F4B2CE80C90F63FAE17A8E
            SHA1:FBE566B4DC03086C40BC698054F913992115D152
            SHA-256:1FD90ACEA33CB015AE4B0E9CFC9066A68DCAFCFD295CF27A0607C71DBD7E9841
            SHA-512:021F583019B940045F66586919938749C09739B610F8C639DF1E0170B5D749CFB0B29D758FE12698416416126D0F8C7FC076AAC2A18B5C25652AD370E0669514
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_VORON_004",. "name": "Voron 2.4 350 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_klipper_common",. "printer_model": "Voron 2.4 350",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "350x0",. "350x350",. "0x350". ],. "printable_height": "325",. "retract_lift_below":[. "324". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):481
            Entropy (8bit):4.738685978669985
            Encrypted:false
            SSDEEP:6:fiqQPQXRv2s8ZVspQSmZ4XbXAm6DEQ7164bIa5aWVqaEaJaqa9aSWaIWaL7aMEv:qq6QXF2s8nXCXbQmo5QGuNPqOlWhWeC
            MD5:038CE6FEB487B3A1C5E41C34EC10A2B1
            SHA1:35D95380510B36D6DFABF5A4D69BCD598E25C712
            SHA-256:DF695591F1B046BFB2A4634398F5E68CA074F8DD65236AEB565DF06E41820224
            SHA-512:B2CBE45F68A3A82F21DCFBD529DFC374A55B0FE008D7CADE38F10891509DAE6BC801F0696E8088C0CEFB1F98ADBF4178F89E3D30E6C8E80340416F9348583BF2
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Voron 2.4 350",. "model_id": "Voron2_350",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "VoronDesign",. "bed_model": "",. "bed_texture": "voron_logo.png",. "hotend_model": "",. "default_materials": "Generic ABS @Voron;Generic PLA @Voron;Generic PLA-CF @Voron;Generic PETG @Voron;Generic TPU @Voron;Generic ASA @Voron;Generic PC @Voron;Generic PVA @Voron;Generic PA @Voron;Generic PA-CF @Voron".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):406
            Entropy (8bit):4.612287239548561
            Encrypted:false
            SSDEEP:6:fiehtzE2es0e0ZJz9JvFEK+FbFKgj9Jv2OoOkJQpXiVqk/4OkJyFg7pPN6:qehVEJe0ZJpTEKYP992zVQ5JvJ4
            MD5:BCA35A1DE40F0AC53022B9F021E688BE
            SHA1:2A2664AF23E03EA9912034AC2357882B0A518457
            SHA-256:14017E47B4A62FE7CB694534783ED189E8D7C1ACED9BFA2C6B9D6794ED80D47F
            SHA-512:892A7E1B897759547DF00DA4B0A748830694ECC1FB9B8A088F73F2C30AE1B8AD6E3A2F8FE8343455C28151E0653B8B70C96960E3774197F0F8520D0AE65673FC
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_VORON_005",. "name": "Voron Trident 250 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_klipper_common",. "printer_model": "Voron Trident 250",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "250x0",. "250x250",. "0x250". ],. "printable_height": "250",. "retract_lift_below":[. "249". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):493
            Entropy (8bit):4.721482368932831
            Encrypted:false
            SSDEEP:6:fiqQHXA8v2s8ZVspQSmZ4XbXAm6DEQ7164bIa5aWVqaEaJaqa9aSWaIWaL7aMEv:qqEXA62s8nXCXbQmo5QGuNPqOlWhWeC
            MD5:F83078FC6F4B6C046F55F45AD1F105A6
            SHA1:1377BBA1662707810B560071D81AD92A82FBE5BC
            SHA-256:2F4386C5A1341D6613DECC92EB1262D296DAC2A6EBB796359C1763F118ACA80F
            SHA-512:CC95C2E9944DA34D92F7AEAF23DCD2BB299C63E703C8E34EA9ADC5211AEBB59E8EDBC6C05320709FB880AB2A9C799EADDA4821AAF5220D7495FB56D8D27B2FA8
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Voron Trident 250",. "model_id": "Voron2_Trident_250",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "VoronDesign",. "bed_model": "",. "bed_texture": "voron_logo.png",. "hotend_model": "",. "default_materials": "Generic ABS @Voron;Generic PLA @Voron;Generic PLA-CF @Voron;Generic PETG @Voron;Generic TPU @Voron;Generic ASA @Voron;Generic PC @Voron;Generic PVA @Voron;Generic PA @Voron;Generic PA-CF @Voron".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):406
            Entropy (8bit):4.6045407322861145
            Encrypted:false
            SSDEEP:6:fiehtzY2r+0e0ZJz9JvFEK+FbFKgj9uIv2OoOkJQZ+g5OkJyFg7pPN6:qehV/rRe0ZJpTEKYP9uG2zVQ5VJ4
            MD5:CCF3CB9DDDFB7A58336F836A53A7DC52
            SHA1:4EFFE293B8C94396FBDA111C62DD8DD82F8CFEDB
            SHA-256:B309AD43388399AC0CC825C9013AC57BE997D850037A18A404893EBCFD3C1C0C
            SHA-512:A370C46A2F7662A3157A0CC3A3230E4DF84677FF4BFDD98A609B148EC46B096E77BFF1140B6854781BD5DBC58C292AB7E2A0F86777A79E7EB5E74966EF2B7A4F
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_VORON_006",. "name": "Voron Trident 300 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_klipper_common",. "printer_model": "Voron Trident 300",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "300x0",. "300x300",. "0x300". ],. "printable_height": "250",. "retract_lift_below":[. "249". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):493
            Entropy (8bit):4.7172230069244945
            Encrypted:false
            SSDEEP:12:qqX2XALo2s8nXCXbQmo5QGuNPqOlWhWeC:JGXA82sKXCr0QGuNPqOkweC
            MD5:2A8D68464F46CEE802B20B4F657A0084
            SHA1:E9B205F99225E0AD49D5345A734E107B872A93BA
            SHA-256:75E062A8EC1D3840ACEBB21C91C323A51B70E43A9C22D99E36839B22A019902C
            SHA-512:AB896D8558E8FD84A463958D9A48AD6ABE48A153387A3423D864E2579852D823D5789ED21BF84C7857C4E9EEC421287657AD3D29B82B7DB3CAF9525F91861B4A
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Voron Trident 300",. "model_id": "Voron2_Trident_300",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "VoronDesign",. "bed_model": "",. "bed_texture": "voron_logo.png",. "hotend_model": "",. "default_materials": "Generic ABS @Voron;Generic PLA @Voron;Generic PLA-CF @Voron;Generic PETG @Voron;Generic TPU @Voron;Generic ASA @Voron;Generic PC @Voron;Generic PVA @Voron;Generic PA @Voron;Generic PA-CF @Voron".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):406
            Entropy (8bit):4.638983644822624
            Encrypted:false
            SSDEEP:6:fiehtzt2QVi0e0ZJz9JvFEK+FbFKgj9uQVAv2OoOkJQMH7JvNFCOkJyFg7pPN6:qehVUOe0ZJpTEKYP9ul2zVQMHNvXuJ4
            MD5:59A798F7AF61E0F9F3FD39BEDE2DEE71
            SHA1:06A1704554524F10949700E604E9CE64A7AD05A4
            SHA-256:B837BE3FCDD172E2C0BE6E12A2AFAF58F0535FF67BC9D452C27DCDAAA8736E7F
            SHA-512:23AEB1BD1F2827C9FF4338E4FDEDC49118E1725794548ED5DAF39A8BC3C30EBDB0A9F88BA245BE7442FF67E819EA2EB2252631CA47343F553E55155DBD8CD51C
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_VORON_007",. "name": "Voron Trident 350 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_klipper_common",. "printer_model": "Voron Trident 350",. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "350x0",. "350x350",. "0x350". ],. "printable_height": "250",. "retract_lift_below":[. "249". ].}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):493
            Entropy (8bit):4.727070376036611
            Encrypted:false
            SSDEEP:6:fiqQ2QVeXADv2s8ZVspQSmZ4XbXAm6DEQ7164bIa5aWVqaEaJaqa9aSWaIWaL7aP:qqXXXAr2s8nXCXbQmo5QGuNPqOlWhWeC
            MD5:611BD026C75FB4885B483276228D669F
            SHA1:32AFA9125D43302CFF872A054FB5E4B8170C6097
            SHA-256:DD8CA20F1FC6A30F4A720CF08FA53E7E2D5D07404A5C3ECA39481897EF7DA2F8
            SHA-512:66DC75D5D6157258647BEFB3E6091531D57817AB3129836B6BAAC0A13999EE395FA6C568FC24A847A6F62271444374236ABF25B8D38A2586271E7333DEB88E66
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Voron Trident 350",. "model_id": "Voron2_Trident_350",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "VoronDesign",. "bed_model": "",. "bed_texture": "voron_logo.png",. "hotend_model": "",. "default_materials": "Generic ABS @Voron;Generic PLA @Voron;Generic PLA-CF @Voron;Generic PETG @Voron;Generic TPU @Voron;Generic ASA @Voron;Generic PC @Voron;Generic PVA @Voron;Generic PA @Voron;Generic PA-CF @Voron".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3064
            Entropy (8bit):4.87165099927688
            Encrypted:false
            SSDEEP:48:/ZJpvKK+kMpagCkzCkKagCkqqCkVCkSCkHEGE3EQhjAec/HVzspIrMbi743QAQ1V:xJFmkM4kmk7kWkcklkke743QAQOlk
            MD5:E0D294961F6B9F2517F732C12E3F7568
            SHA1:37BBE1E6649BF74DD65426981638DB0249DA9C58
            SHA-256:B49E642EBE97532AB2D3EE261918AC4731DADB306CD9E26479AFC69C7D76A854
            SHA-512:A9DA110DF5C23971C5FA55305B21C3659974D6A076192CBE2915C7022F450CDD43747AE5C519D2F2B88778E93D58BD988E7A5F111FE37E50CA617DA9AEAFD3A4
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "name": "fdm_klipper_common",. "from": "system",. "instantiation": "false",. "inherits": "fdm_machine_common",. "gcode_flavor": "klipper",. "machine_max_acceleration_e": [. "5000",. "5000". ],. "machine_max_acceleration_extruding": [. "20000",. "20000". ],. "machine_max_acceleration_retracting": [. "5000",. "5000". ],. "machine_max_acceleration_travel": [. "9000",. "9000". ],. "machine_max_acceleration_x": [. "20000",. "20000". ],. "machine_max_acceleration_y": [. "20000",. "20000". ],. "machine_max_acceleration_z": [. "500",. "200". ],. "machine_max_speed_e": [. "25",. "25". ],. "machine_max_speed_x": [. "500",. "200". ],. "machine_max_speed_y": [. "500",. "200". ],. "machine_max_speed_z": [. "12",. "12". ],. "machine_max_jerk_e": [. "2.5",. "2.5". ],. "machine_max_jerk_x": [. "12",. "12". ],. "machine_max_jerk_y": [. "12",. "12". ],. "machine_m
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3079
            Entropy (8bit):4.688293921551152
            Encrypted:false
            SSDEEP:48:/HpTqVrBkMp3khkiHkvkYkp67NZiL/YWabSj4HS2HcXMXIP+ELzZsxcLMxHGCn:/wBkMRkhk2kvkYkB38mPW6zZfuGC
            MD5:EE83E04A416E2556D8986D84350FA784
            SHA1:9A465C36F4B9340A0CCEF182FBFEBF259A74F84E
            SHA-256:CB59731F8C00634C7538CC90330F110BADE1F0004A2CD9E85210BB62A3E2F633
            SHA-512:110BA39C5737DC69D56A004369565E37C6DC761D0D95F9AA877476B77EA6A164568FEB728814248DF91BC3FC76598A309176399571C83675C2813E09FB27B52F
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "name": "fdm_machine_common",. "from": "system",. "instantiation": "false",. "printer_technology": "FFF",. "deretraction_speed": [. "40". ],. "extruder_colour": [. "#FCE94F". ],. "extruder_offset": [. "0x0". ],. "gcode_flavor": "marlin",. "silent_mode": "0",. "machine_max_acceleration_e": [. "5000". ],. "machine_max_acceleration_extruding": [. "10000". ],. "machine_max_acceleration_retracting": [. "1000". ],. "machine_max_acceleration_x": [. "10000". ],. "machine_max_acceleration_y": [. "10000". ],. "machine_max_acceleration_z": [. "100". ],. "machine_max_speed_e": [. "60". ],. "machine_max_speed_x": [. "500". ],. "machine_max_speed_y": [. "500". ],. "machine_max_speed_z": [. "10". ],. "machine_max_jerk_e": [. "5". ],. "machine_max_jerk_x": [. "8". ],
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):283
            Entropy (8bit):4.543123947736398
            Encrypted:false
            SSDEEP:6:fEaxTFu0hts3qoL8uU0dlz9JvFmu++NyQyEF4TJF1tJ6JM58Q+JMW:8GTFphgqSy0dlpTmuVXC0JddJz
            MD5:DB6FF72A641A9FE665E786ACB7D11202
            SHA1:2D139E5E767BE08D9BC9A84F6F1A43CD7956A869
            SHA-256:4E16AEAA7E77959666B7885775AA640D4787A2517F95307E177CFE3A66AEA46D
            SHA-512:4B40B0EEE869B0A76A9F85DC1C04F585AA90D9274367573CE8D42D89595AB9CBFDF9FA95C12D0674CA81EB894CB88304C0A4A29DD92FE529251D562C70ED989A
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_VORON_001",. "name": "0.08mm Extra Fine @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_voron_common",. "layer_height": "0.08",. "bottom_shell_layers": "7",. "top_shell_layers": "9".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):277
            Entropy (8bit):4.520625324443028
            Encrypted:false
            SSDEEP:6:fEaxTFu0hts3q7QfU0dlz9JvFmu++NyQyEF4TJFiZttJ6JMgQ+JMr:8GTFphgq0M0dlpTmuVXLZn0JHdJO
            MD5:D7599702AFBCF46BEDCBFEDC8B20BEBC
            SHA1:1CF0A2C400D64704C6EE5F4D19C6D601A684D049
            SHA-256:3CE22FF961F81112FF0FA0BE16E0C6363293A259901BD187E37BE8B308D9B1A7
            SHA-512:DB9F13FE8640F3BDC8A36DD15FD546D32A3C62230009F1305E61CB1B4CE3B780E8AB2C038ECE1790A040795F1515686A4E7EDD9D621A8992201C213EBB806F62
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_VORON_002",. "name": "0.12mm Fine @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_voron_common",. "layer_height": "0.12",. "bottom_shell_layers": "5",. "top_shell_layers": "6".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):280
            Entropy (8bit):4.521979514641999
            Encrypted:false
            SSDEEP:6:fEaxTFu0hts3qHvmQK1LrU0dlz9JvFmu++NyQyEFPtJ6JMpQ+JMWTJFiSA:8GTFphgqPPK1A0dlpTmuVXV0JmdJMSA
            MD5:CEC8FA6800009423787CF3ECC30946AE
            SHA1:332503E3C4C2C7178B1529E2D11DDB047077C546
            SHA-256:248EFABE09F3262C0493DF00DB4CA89FEA09A192CA40F2143E7C4783B2875B7D
            SHA-512:359EF710463458F789BCD07B971555655808F5EA92E03C450D68EDA689F59400EC61DA9F475859F0069605B282DFA3AA11C78B9D1A342546CB8338B3B425DDF3
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_VORON_003",. "name": "0.15mm Optimal @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_voron_common",. "bottom_shell_layers": "4",. "top_shell_layers": "5",. "layer_height": "0.15".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):280
            Entropy (8bit):4.519138918789038
            Encrypted:false
            SSDEEP:6:fEaxTFu0hts3qUui9KcU0du++NyQyEFmlz9JvF4TJF1tJ6JMdkQ+JM1:8GTFphgqUu0duVXmlpT40JJdJE
            MD5:9158022CC205A27BF27EF147581D009F
            SHA1:C781209A6945A9F7CB4440AA4A47B6B4E96AFEC0
            SHA-256:7D1C8B99BFA046D12D2854579A925CD218998EB9E5CD087A03A8E9712A312CE9
            SHA-512:AB16D6FD191A88C5D2DBAD0E8734265920CA0E092CE9C50206DB2F5F2E493A8A05EA71B07A8E0670A9FC399AB2038F951F63B8BF3F8743859787B58683E48781
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_VORON_004",. "name": "0.20mm Standard @Voron",. "from": "system",. "inherits": "fdm_process_voron_common",. "instantiation": "true",. "layer_height": "0.2",. "bottom_shell_layers": "3",. "top_shell_layers": "4".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):316
            Entropy (8bit):4.573251767216782
            Encrypted:false
            SSDEEP:6:fEaxTFu0hts3qBOJaMKPU0dlz9JvFmu++NyQyEF4TJFKQHj9jtJ6JMdkQ+JM1:8GTFphgqBmhN0dlpTmuVXpWn0JJdJE
            MD5:D370B600521D921A84F40B8235A8C0EA
            SHA1:CFEBAA90554FE22CE6132B44F0072D61B069FFF1
            SHA-256:BC38E8CCED0CDD84EEB1645BB6C30EE380CE4E9C4CB08BC17BE876E4CDE92D10
            SHA-512:720CF426F15F27FAD3320092763DDDFB2A3F06D15410A6F0E353A08E4D6D0DE2E3A47FBEBFD41DAE16F280383D4E3B5717979F5770ADE8C05249F15415F1FEAD
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_VORON_005",. "name": "0.24mm Draft @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_voron_common",. "layer_height": "0.24",. "top_surface_line_width": "0.45",. "bottom_shell_layers": "3",. "top_shell_layers": "4".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):322
            Entropy (8bit):4.619406206147565
            Encrypted:false
            SSDEEP:6:fEaxTFu0hts3qv2C4MKPU0dlz9JvFmu++NyQyEF4TJFmQHj9jtJ6JMdkQ+JM1:8GTFphgq93N0dlpTmuVXFWn0JJdJE
            MD5:6397668A93228DB54D29D935A82E6331
            SHA1:A56580FC83AA39706FFEF5667FFAAF458269C37A
            SHA-256:43940768987B8D65A8517D0F2B75769F659DF45AAE9ACD7315C658CAAB18F6F4
            SHA-512:DB334C6BB50858C3DDEC6F7406D559C3CC95FB62A4EFCD102C7D59E4936FF90811C8058ED227E2F152E2031062B59BB84A7C3AFEF29B67413651F4BCB6619BCB
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_VORON_006",. "name": "0.28mm Extra Draft @Voron",. "from": "system",. "instantiation": "true",. "inherits": "fdm_process_voron_common",. "layer_height": "0.28",. "top_surface_line_width": "0.45",. "bottom_shell_layers": "3",. "top_shell_layers": "4".}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1859
            Entropy (8bit):4.495398584371799
            Encrypted:false
            SSDEEP:48:jJhHprQUiONefFYi9Ny6ES1W12LnnSbLxwN4ga:jJ5dQUigGrnSbdwc
            MD5:C8969EB4E5EADCD5E823C4298B3F15BE
            SHA1:3BBCF8D931F5C3AD36015F03E1F48266387A7C54
            SHA-256:7F14F635DB07127B5C9CD84A8962BA8729DEE5814F5A5F260161C66D00FF0AC3
            SHA-512:269DA7AF9030D87AA1F1D550828B3F968A2AD5DA0A5B293877C805562506A08418EFB11F5B54F11950B74306E6570A65C2E750D1D79EED85F4EA27F5ACF96DAB
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_common",. "from": "system",. "instantiation": "false",. "adaptive_layer_height": "0",. "reduce_crossing_wall": "0",. "bridge_flow": "0.95",. "bridge_speed": "25",. "brim_width": "5",. "compatible_printers": [],. "print_sequence": "by layer",. "default_acceleration": "10000",. "bridge_no_support": "0",. "elefant_foot_compensation": "0.1",. "outer_wall_line_width": "0.4",. "outer_wall_speed": "120",. "line_width": "0.45",. "infill_direction": "45",. "sparse_infill_density": "15%",. "sparse_infill_pattern": "grid",. "initial_layer_line_width": "0.42",. "initial_layer_print_height": "0.2",. "initial_layer_speed": "20",. "gap_infill_speed": "30",. "infill_combination": "0",. "sparse_infill_line_width": "0.45",. "infill_wall_overlap": "25%",. "sparse_infill_speed": "50",. "interface_shells": "0",. "detect_overhang_wall": "0",. "reduce_infill_retraction": "0
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3439
            Entropy (8bit):4.567002507178138
            Encrypted:false
            SSDEEP:96:jJM6p+UEI3vi5TmHvrOnVFpS7VwdamMlN:bppEovi5USnVFpShn
            MD5:0C73F9A12ECB45189A28F2538434EDC3
            SHA1:0B65AC95159805BF52EBC123285AC45AC269F4C1
            SHA-256:CDB6F90C1B4B307E630E4FE5BDD1E0FE02318F30075F2199C23F781BFDDD1B27
            SHA-512:DBA7F647686595A3BCD6BA39464F1E8E61821A0BF53291664C9F9D0A59B596DDCDDA0E1DDA91C64E8DA1E0F785D0269D1D5BFE899F311FA101E2F3BB79B24518
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_voron_common",. "from": "system",. "instantiation": "false",. "inherits": "fdm_process_common",. "reduce_crossing_wall": "0",. "max_travel_detour_distance": "0",. "bottom_surface_pattern": "monotonic",. "bottom_shell_layers": "3",. "bottom_shell_thickness": "0",. "bridge_flow": "0.95",. "bridge_speed": "25",. "brim_width": "5",. "brim_object_gap": "0.1",. "compatible_printers_condition": "",. "print_sequence": "by layer",. "default_acceleration": "5000",. "top_surface_acceleration": "3000",. "travel_acceleration": "7000",. "inner_wall_acceleration": "5000",. "outer_wall_acceleration": "3000",. "bridge_no_support": "0",. "draft_shield": "disabled",. "elefant_foot_compensation": "0",. "outer_wall_line_width": "0.4",. "wall_infill_order": "inner wall/outer wall/infill",. "line_width": "0.4",. "infill_direction": "45",. "sparse_infill_density": "15%",. "spar
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 2048 x 2048, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):39743
            Entropy (8bit):5.878738603124816
            Encrypted:false
            SSDEEP:384:+oD1xhnGhZhjAozq3zDe5TydEqkToAZW9V4AK73rGypv3l8JuiUZe+ZH:5bnGLhj1IO5OIjZ53rzd3ouv0+ZH
            MD5:A86B01EA1673209D022DDC33AF9BB23C
            SHA1:C06897461C32487BD000E03B8C26BFCE812FFFA9
            SHA-256:DC4D018B39DEC5BE4E6A8AD37EE26E78FA271208A354B1D88718F1380060EDBB
            SHA-512:89E4F7376E4E3B9312C7BD08EADBF23DA92393E03DCCFCE8B8B2A65430BF1686D13719C96602CEF7820DD8EF8C77E0E589A10BC4DCB0864ADD666F7AE9040E54
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR................0....zTXtRaw profile type exif..x..Q..&.E...,...I........<\.JwO...#?mW.......Q....u.....(U.yk'...9pb.c..Hg......w.....JP.m..%=...g..#.......G.......'y;................(.mGmw.........E......)$'."w...rH\'..nC....j.]BB>..ksD.v..S....3Z..#...|Hr{....T?.r..M...3~_....8z...]+m]}F/.4...zv.:.]G..i;.Z..1d(.....z.Z.....91p-*...h^........p.J.;.qq+{..*.)....^._.....Z3...S&8#.......k.G..W....N6.....f B.Nj....?n...`.Y..#...W..M .h.aE.x\H.v....`H@..H*5:.Y..H..@.,.;.P.....H....4nQ.L.2....e..U.(..`.R1~...PT....V.^.I+....b.h9.jSUS.0.b.......^.....G.........]z...k..=...(..6t....)..G...I.Ci.Yg.:m......Xe...[..E......jtS..6..5.>].~.....0....F....iT.or...x.Ie.Y7..M...$.....~......C.;n.....~........=...S.....`.=..P.?.......oG...};...A..*...*.c....!>.F..3.So.9w......;j.........)Z..%.k.....S{W..2..e>e.v.$....kXe.<.g..R.m....1m<...R..._..5.Y.......lPN..c.0....X......|&C...<.-t"..N]..r.Z....3;.t.rm.....:r.n.....E[.>t.w.j.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 1024 x 1024, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):17990
            Entropy (8bit):6.460675986240661
            Encrypted:false
            SSDEEP:192:oveNkyu/jDSPDd0vf9irwJ9ehMdOiTOAIilWTjPcapzcgD2/D:8euyY2PJ03Arw37g+OVilW/PcaCgD2/D
            MD5:BB887D62BC7DBD2F973E2D0D7585A35E
            SHA1:11EDDD69C0553CB6B329098EA036C086FA5B2FB9
            SHA-256:044F46A9069C398C2D72CF688E6082B854919DF200BBB19C770A514C18CE79DB
            SHA-512:468E48A9C7AEFE5F927D43F8EAD6869E9E72B0A5D4DD423828847966566C4A49838787035B2CA8311C4A2F54F842F968FF1E340882313758E43A283F1A5557C0
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR...............+....`zTXtRaw profile type exif..x..Ar,'...."GhI....... ..Ow....U.I..q7......i...J..a.%e.Z...O...P.....KG>..'.....Q%..j....Q.Pt..P...........\_.....Q.[........kZG.j.....c..z......J^....R.........~%I;...mA.=jT......O..ri..._.^i.w....J+.-"/N.....D.=....F.....z..=..'..w...3f.r...=..T...:..C....t....{'G.X.....GG.....(SP.E......y&.+f...++.9.p#.;.b...........9..#..U...Q&(#ty;.w;....DG}..v1og.Mn.!.".n....Gz}6W.A.^.?..c...+.....Z ......V..ah.1$ .j$J..c6"8..P..,.;..*...,R.....].NQVFuB=63.P)b`...+g...\....fU-jZ..).h).......dj....*5W..Z..ksv...^..{k..AsC....:w.k.[..{.X>#..e..G.....Q..G.4..f.:.Y.........l..=..X..7..M.OR[..Pk.PA{;....8e.q....y3;*...fv8.?Q.....mb .'..z.K|......d..7....F.&........'..W..z.~}h..qm....._5...(.Q...G...E.."...Q....).U[.......uN....@[x....4[L.......!%Im1..G...d!...4..9f...k8.q`7.M:..>ey..B.ZJZ.....+pc..W..!. ..1gv.#.|;...... ....<Z..( ..Ns *(.h.....<X.p...h......}.8.....H....(u.ul.q/2.U.U.7..n.G......\F.#u
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1905
            Entropy (8bit):4.216080543631329
            Encrypted:false
            SSDEEP:24:e1OEaIJQwUQqDk19VOv/aw3ph9ErHIve/d6w/Qr:C7aAQwURk19VOvyw3phEIG/Ew/Qr
            MD5:8514E01C1C382E53F252BBB4AF940ACF
            SHA1:AD12D1E16D5A21B4A81928301F3FE0B0ACF876A5
            SHA-256:B9C040D33049F75572DA06F467DD5DB3041AA7117FA8C3EA9FE49CABA957DD5D
            SHA-512:B4E1B6D25F2402D20059F4AEDC07895D342241691D5A86DBBC17449F974F497C2655A51BAF595E659065B50FD95F0EF358488964B285481A7409CB7F67D595E0
            Malicious:false
            Reputation:low
            Preview:{. "name": "Voxelab",. "version": "01.08.00.03",. "force_update": "0",. "description": "Voxelab configurations",. "machine_model_list": [. {. "name": "Voxelab Aquila X2",. "sub_path": "machine/Voxelab Aquila X2.json". }. ],. "process_list": [. {. "name": "fdm_process_common",. "sub_path": "process/fdm_process_common.json". },. {. "name": "0.16mm Optimal @Voxelab AquilaX2",. "sub_path": "process/0.16mm Optimal @Voxelab AquilaX2.json". },. {. "name": "0.20mm Standard @Voxelab AquilaX2",. "sub_path": "process/0.20mm Standard @Voxelab AquilaX2.json". }. ],. "filament_list": [. {. "name": "fdm_filament_common",. "sub_path": "filament/fdm_filament_common.json". },. {. "name": "fdm_filament_abs",. "sub_path": "filament/fdm_filament_abs.json". },.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 180 x 180, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):23254
            Entropy (8bit):7.948034625621652
            Encrypted:false
            SSDEEP:384:3oolee0eSX1yn+6aOPP22R0a2En6Vb6EMqwvp3qXinO9oq2upr5jnbWjghD:3RdP+Y7ibDna11bsjbWj8
            MD5:04E676982DECE0AB719BB13B528FC536
            SHA1:6170D9DB6CFE760E92BF05EDE59ADD841668A187
            SHA-256:ECC39B1068FE47736CBC0EAACF55F8612D9FC84C27F475E9553A5D0DDEF16845
            SHA-512:3E31CD3CF865CF8767B2E4B9C074FCB85885341CF48C2E369C4E01AACA0AB812941AF3F4B936608A2D166BBADE4BEECD2951A2EEBBCBFA88B88C7C50F3FF3CF5
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............=..2...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-03T21:00:49+0200". xmp:ModifyDate="2023-05-03T21:01:45+02:00". xmp:MetadataDate="2023-05-03T21:01:45+02:00". photoshop:DateCreated="2023-05-03T21:00:49+0200". photoshop:ColorMode="3". photoshop:ICCProfile="SMPTE RP 431-2-2007 DCI (P3)". exif:PixelXDimension="180". exif:PixelYDimension="180". exif:ColorSpace="65535". tiff:ImageWidth="180". tiff:ImageLength="180
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):402
            Entropy (8bit):4.521493199675786
            Encrypted:false
            SSDEEP:6:fS5TDY80htzOGsEH684bZczU0dlz9JvFmu+oE99mqbDf6zwhnww/KyIHet9/6kCA:KY3hJOGlH2czU0dlpTmu5umqvzGTQ/0A
            MD5:4229B8397E31CA2F409310DEC4D43E07
            SHA1:0C00E3FC1A02E67294702536B193BB01FBBB21B8
            SHA-256:2E323D1C39671C2271EAD36FADB172908495C6597CEE79520255C31C049D523F
            SHA-512:1D2B47A2FD042D1C74CB729F7940747D2A4355C5DDE732DD6C0DE44EDAC2B86025182D0EC3215DA9F334A6FC88966CCDF903BB2C12429039CA1DDFFEA7DB6C57
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFB99",. "setting_id": "GFSB99_Voxelab_00",. "name": "Generic ABS @Voxelab",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_abs",. "filament_flow_ratio": [. "0.926". ],. "filament_max_volumetric_speed": [. "12". ],. "compatible_printers": [. "Voxelab Aquila X2 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):502
            Entropy (8bit):4.453593504493092
            Encrypted:false
            SSDEEP:12:Kn9hJjWHUczU0dlpTmu5wwCFiZbwh3ovzTTQ/0A:KnnUvHpTr5NoiONovXk/0A
            MD5:56BDA9CE44060422907E2D19B672BDE3
            SHA1:51E030E467803D469EF5E7EC5D5B4DD31D1121C7
            SHA-256:375BCA46FECC8C7FB1104AFB5BDBC5224E00E5385F0323C4DF70FDEDCC3ABB5C
            SHA-512:5D1FA32808280ACEF8428DEC08B3F368A7F46C4C8A1D3474A74BF9DE0AF6C820FB0E71D75002AC1D07933552C2475863F35A8CD50C2E16004074CB6B5B10C413
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFG99",. "setting_id": "GFSG99_Voxelab_00",. "name": "Generic PETG @Voxelab",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pet",. "fan_cooling_layer_time": [. "30". ],. "overhang_fan_speed": [. "90". ],. "filament_flow_ratio": [. "0.95". ],. "filament_max_volumetric_speed": [. "15". ],. "compatible_printers": [. "Voxelab Aquila X2 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):450
            Entropy (8bit):4.481985036976424
            Encrypted:false
            SSDEEP:6:fS5TDEd80htzVsEH684NzU0dlz9JvFmu+o8s9fbDf6zwwdqgJcw/KyIHet9/6kCA:KS3hJVlHkzU0dlpTmu58afvzTXTQ/0A
            MD5:50677CF88B31971949470C9B24746D57
            SHA1:AE935520D016C88E7D1975CE67CBBC26CA45C251
            SHA-256:14800FD3B28FCA6C3AA89E88AA7BBB2C602C3E8B096CC3149198D9A3CA478B73
            SHA-512:5E10654B08B54E79ABC6DEEE02392FA7622AB3D513B27ECC62E9D405EC14CE3EE8036D4048E297E9872EF3F6270D7665A3EFFFE9457AA04B1A1F8F871BDF6BC6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "filament_id": "GFL99",. "setting_id": "GFSL99_Voxelab_00",. "name": "Generic PLA @Voxelab",. "from": "system",. "instantiation": "true",. "inherits": "fdm_filament_pla",. "filament_flow_ratio": [. "0.98". ],. "filament_max_volumetric_speed": [. "15". ],. "slow_down_layer_time": [. "8". ],. "compatible_printers": [. "Voxelab Aquila X2 0.4 nozzle". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1562
            Entropy (8bit):4.089951767645742
            Encrypted:false
            SSDEEP:24:9+Hpy5v/Tg2zgbgDgmY26YyYKYOgzqbvGCZvtajQRxSwIhrqPw18o8oiTxYm5wxs:9+Hpy5vbdz2AtPzaYrrO+9c
            MD5:0A557FF26EC438F27888C55C2EFCC752
            SHA1:9EFC9823F5E7F925BEA08F3D1C9A23BE90A9F78E
            SHA-256:05B718CE4DB6CD7F6B1EEF039B87B96B3BF865AF8A58FD2AD9BAD26ECFAF2291
            SHA-512:61668BF098611BB2AF8D4A7232F8FE24CFE215A4A039DFD9829B8D0AAE610F41235337AF1CB19E61B9BB9E0873903BE554E95C3482949DDF3FA637A60245DD62
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_abs",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "80". ],. "eng_plate_temp" : [. "80". ],. "hot_plate_temp" : [. "80". ],. "textured_plate_temp" : [. "80". ],. "cool_plate_temp_initial_layer" : [. "80". ],. "eng_plate_temp_initial_layer" : [. "80". ],. "hot_plate_temp_initial_layer" : [. "80". ],. "textured_plate_temp_initial_layer" : [. "80". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "30". ],. "filament_max_volumetric_speed": [. "0". ],. "filament_type": [. "ABS". ],. "filament_density": [. "1.10". ],. "filament_cost": [. "20". ],. "nozzle_temperature_initial_layer": [. "240". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2608
            Entropy (8bit):4.045241599756256
            Encrypted:false
            SSDEEP:24:9v/JHpiO2zObODOmW26WyWKWoZoiMOgzqbvGC3U2qIh54n4LZA2ykxvtrC9mFZ1u:9vxHpi7zEqdyanziBxK27p0oCz/NzunU
            MD5:64244927E71E237B71F5BD7932E7CA7B
            SHA1:5B8B9BA26DC3E76DD5460E5535B81193A3E559CE
            SHA-256:E03BD51724FFD3474A45A98C8087150B7D4C98A8AC5313140A9F92C410E05E6C
            SHA-512:DE74BFCDACBB791DFA5D136B6B55CBAD7C0E8F24ECB850AF38ADEE239DA6A3B3C4E2CC441F7E708A34AC68A2B3906187F7F605C56BCD67ED9C9727CEEE10042C
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_common",. "from": "system",. "instantiation": "false",. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "60". ],. "hot_plate_temp" : [. "60". ],. "textured_plate_temp" : [. "60". ],. "cool_plate_temp_initial_layer" : [. "60". ],. "eng_plate_temp_initial_layer" : [. "60". ],. "hot_plate_temp_initial_layer" : [. "60". ],. "textured_plate_temp_initial_layer" : [. "60". ],. "overhang_fan_threshold": [. "95%". ],. "overhang_fan_speed": [. "100". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "filament_end_gcode": [. "; filament end gcode \n". ],. "filament_flow_ratio": [. "1". ],. "reduce_fan_stop_start_freq": [. "0". ],. "fan_cooling_layer_time": [. "60". ],. "filament_cost":
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1484
            Entropy (8bit):4.102139424792527
            Encrypted:false
            SSDEEP:24:9RHpy5v/T0Q2z0Qb0QD0QmsQ26sQysQKsQOgzqbvGC8vtdClQExSwIhrqPwQloiR:9RHpy5vb0Nz0m0Q00N7mgKz3MerrO0eT
            MD5:8647785A89D20D981A3B8D75D9C2EDBC
            SHA1:02F173C5547CAC3DF6A41E074696B3E321699B97
            SHA-256:A84E6F901993F88D7B947B3D784E7F6EFD6D9859F75C55E35CB91F0AC2238FCD
            SHA-512:47E35631E0C3FB6A7D6F44F905350DE57836CCEFC3C15AB44B20FF121BAC9CEF6EFB6E1FBFA78A17E0A88CB6FD286D51AE368BEE0DB17B3E5B6F069FE8F7BF44
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pet",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "cool_plate_temp" : [. "85". ],. "eng_plate_temp" : [. "85". ],. "hot_plate_temp" : [. "85". ],. "textured_plate_temp" : [. "85". ],. "cool_plate_temp_initial_layer" : [. "85". ],. "eng_plate_temp_initial_layer" : [. "85". ],. "hot_plate_temp_initial_layer" : [. "85". ],. "textured_plate_temp_initial_layer" : [. "85". ],. "slow_down_for_layer_cooling": [. "1". ],. "close_fan_the_first_x_layers": [. "3". ],. "fan_cooling_layer_time": [. "15". ],. "filament_max_volumetric_speed": [. "0". ],. "filament_type": [. "PETG". ],. "filament_density": [. "1.27". ],. "filament_cost": [. "30". ],. "nozzle_temperature_initial_layer": [. "240". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1638
            Entropy (8bit):4.099313920315345
            Encrypted:false
            SSDEEP:24:9THpy5v/jvtT7R/O2zObODOm1o261oy1oK1oxS4QIhrqOgzqPwR4oiMoO5bvIqx+:9THpy5v7D7zEqlimrYzOe0OKTP9
            MD5:BA0FA7EF82E08137500E3199A9207096
            SHA1:D71CDD318339FF9E894813080BABD95D35B33AAB
            SHA-256:3B7808016274CCA397497E078723FF222257271BB16A0C127778476437D287D9
            SHA-512:501F8CF470AE685F59AE2A826C42762435FAF7B780EA3D0BD580228AD3FCC6D939803136B431BB2D7B8529CFB9B34A07B75B663EE764E83170E5FD36F81B319F
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "fdm_filament_pla",. "from": "system",. "instantiation": "false",. "inherits": "fdm_filament_common",. "fan_cooling_layer_time": [. "100". ],. "filament_max_volumetric_speed": [. "0". ],. "filament_type": [. "PLA". ],. "filament_density": [. "1.24". ],. "filament_cost": [. "20". ],. "cool_plate_temp" : [. "60". ],. "eng_plate_temp" : [. "60". ],. "hot_plate_temp" : [. "60". ],. "textured_plate_temp" : [. "60". ],. "cool_plate_temp_initial_layer" : [. "55". ],. "eng_plate_temp_initial_layer" : [. "55". ],. "hot_plate_temp_initial_layer" : [. "55". ],. "textured_plate_temp_initial_layer" : [. "55". ],. "nozzle_temperature_initial_layer": [. "205". ],. "reduce_fan_stop_start_freq": [. "1". ],. "slow_down_for_layer_cooling": [. "1". ],.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3424
            Entropy (8bit):4.714009028954813
            Encrypted:false
            SSDEEP:48:3s/hHpTr+dAxF5sk/EtkzHkqVkpEtk0EtkgE6ERjdYQb6w4WmYeesVnM/lXEn7vC:cxMdQ5skMk7kGkSk7kUXYeemnM/lavGN
            MD5:1EDE6D78280AF6B7AEE1FD1C1C4A04F2
            SHA1:76C1FD91463788A9ED8C7E9B35FD3398BC1BD2B2
            SHA-256:12B5AE5D81655CAE7F1513573C65F6DA8CEB18544AE5F5C2A265F4F41E45C77D
            SHA-512:A72289067F36336960D75F97AED39D086BB3356B42E34C57CB677132870059A5E404E86F4B08024A8258D92B5F2A6BD270B806F5D44D67DE5C00D3641E3D51E9
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "setting_id": "GM_Voxelab_001",. "name": "Voxelab Aquila X2 0.4 nozzle",. "from": "system",. "instantiation": "true",. "inherits": "fdm_machine_common",. "printer_model": "Voxelab Aquila X2",. "default_print_profile": "0.20mm Standard @Voxelab AquilaX2",. "extruder_type": [. "Bowden". ],. "nozzle_diameter": [. "0.4". ],. "printable_area": [. "0x0",. "220x0",. "220x220",. "0x220". ],. "printable_height": "250",. "retract_lift_below":[. "249". ],. "nozzle_type": "undefine",. "auxiliary_fan": "0",. "machine_max_acceleration_extruding": [. "500",. "500". ],. "machine_max_acceleration_retracting": [. "1000",. "1000". ],. "machine_max_acceleration_travel": [. "1500",. "1250". ],. "machine_max_acceleration_x": [. "500",. "500". ],. "machine_max_acceleration_y": [. "500",.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):420
            Entropy (8bit):4.743082970166617
            Encrypted:false
            SSDEEP:6:fiqQcHet9ZQXkHY2v2s8ZVsfHzSmSLY6Uv24XuLY63QXpAm6DEQ7164bZcDdcDNq:qqHQuXOYA2s8n2zM0VX0Sumo5BcZchq
            MD5:7A61CCEAA738464BF0C872BB8919CB9D
            SHA1:A01E19CB87F1FD7F90DD31B2A987EF6E2B1F0428
            SHA-256:7D28B1FA54CA9726AF643E42923CD0012204461A6FE1107BD1E0BB8452ACB600
            SHA-512:2DB1D2854ADE3988E3B3CD0DE1AB31BB7E56718B85D97F1A7464A5B31A7DA285E0BE5063947BABF0960498DC94532046B678E11A647464B52AB7F8CA54C8B4D5
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine_model",. "name": "Voxelab Aquila X2",. "model_id": "Voxelab-Aquila-X2",. "nozzle_diameter": "0.4",. "machine_tech": "FFF",. "family": "Voxelab",. "bed_model": "voxelab_aquilax2_buildplate_model.stl",. "bed_texture": "voxelab_aquilax2_buildplate_texture.png",. "hotend_model": "",. "default_materials": "Generic ABS @Voxelab;Generic PETG @Voxelab;Generic PLA @Voxelab".}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2251
            Entropy (8bit):4.199871574196417
            Encrypted:false
            SSDEEP:48:/HpTqVrBkMp3k/tkiHkptk0tkp67NZiL/YWabSj47C5:/wBkMRkVk2k7kEkBN
            MD5:6B1F82956393F7C8094F611AE2EE784D
            SHA1:4A41BA3157E6BBDA44AD8D7023786C7C6CA42450
            SHA-256:1F208F95AFC96BCE7B04BD9D6AA757DED78D537C4732764C12C659E9BC0EBA3D
            SHA-512:1F343E5267CD7CD7C7E4551A6F67C7A9DA240DC7E0D1CB7331FF4529DA9795431093BB7C298B339D3CDC739EB23AD1AAA937B365DB3E099C73D2D3223401EE82
            Malicious:false
            Reputation:low
            Preview:{. "type": "machine",. "name": "fdm_machine_common",. "from": "system",. "instantiation": "false",. "printer_technology": "FFF",. "deretraction_speed": [. "40". ],. "extruder_colour": [. "#FCE94F". ],. "extruder_offset": [. "0x0". ],. "gcode_flavor": "marlin",. "silent_mode": "0",. "machine_max_acceleration_e": [. "5000". ],. "machine_max_acceleration_extruding": [. "500". ],. "machine_max_acceleration_retracting": [. "1000". ],. "machine_max_acceleration_x": [. "500". ],. "machine_max_acceleration_y": [. "500". ],. "machine_max_acceleration_z": [. "100". ],. "machine_max_speed_e": [. "60". ],. "machine_max_speed_x": [. "500". ],. "machine_max_speed_y": [. "500". ],. "machine_max_speed_z": [. "10". ],. "machine_max_jerk_e": [. "5". ],. "machine_max_jerk_x": [. "8". ],. "
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2949
            Entropy (8bit):4.55239033244297
            Encrypted:false
            SSDEEP:48:jJpE6hI5pTp5kP+cvOpO43OsOgOqfFxwZ+l9BOJOMOG/3TqefJp2LpYntNVrzost:jJptuLCP+YYX3C/O01DjTrntNVrzs03
            MD5:5597B862FCADDAA7D6D71F282216BC0B
            SHA1:5C62A771A0371348E1610E5E561D1CD3C8487392
            SHA-256:4E38A749B5FDA7E007BE0D0FEB63A879CDEEAAC3BDA646066105F0DF0EA808C4
            SHA-512:BAC1E3A7706C98BCF12F205EC071B8B5AA045AE3C5ACE9C9A2703A2B15BD59E218C1F8EA500A36966DFCAC0F921A9061B3697EBC83CE6F4C414EE2C2E2B9A9F6
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Voxelab_004",. "name": "0.16mm Optimal @Voxelab AquilaX2",. "from": "system",. "inherits": "fdm_process_common",. "instantiation": "true",. "reduce_crossing_wall": "0",. "layer_height": "0.16",. "max_travel_detour_distance": "0",. "bottom_surface_pattern": "monotonic",. "bottom_shell_layers": "5",. "bottom_shell_thickness": "0",. "bridge_flow": "0.85",. "bridge_speed": "25",. "brim_width": "0",. "brim_object_gap": "0",. "compatible_printers_condition": "",. "print_sequence": "by layer",. "default_acceleration": "0",. "outer_wall_acceleration": "0",. "top_surface_acceleration": "0",. "bridge_no_support": "0",. "draft_shield": "disabled",. "elefant_foot_compensation": "0.1",. "enable_arc_fitting": "0",. "outer_wall_line_width": "0.4",. "wall_infill_order": "inner wall/outer wall/infill",. "line_width": "0.45",. "infill_direction": "45",. "sparse_infill_densit
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2949
            Entropy (8bit):4.5514936972746325
            Encrypted:false
            SSDEEP:48:jJpE9TI5pT+kP+cvOpO43OsOgOqfFxwZ+l9BOJOMOG/3TqefJp2LpYTtNVrzos8q:jJpKcrP+YYX3C/O01DjTrTtNVrzs03
            MD5:ACD8E8596D6688F5268FA871C0D00949
            SHA1:0415468B2E89CEF270D3ACC678F84FFC8B0AB7C9
            SHA-256:C7A718C028EEB6CFF7DB968954CD20CA721B6D427D6130F5748871D16DAEC756
            SHA-512:CD055A3B5D6E838E2FAE239BA5A8A6629AC3CD7C984B741623785CB83AB236D11AF93D93E37E16F16D8DCCAF5507FDE9CCD7780736A9D4B81277BA57BA2FC5D3
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "setting_id": "GP_Voxelab_005",. "name": "0.20mm Standard @Voxelab AquilaX2",. "from": "system",. "inherits": "fdm_process_common",. "instantiation": "true",. "reduce_crossing_wall": "0",. "layer_height": "0.2",. "max_travel_detour_distance": "0",. "bottom_surface_pattern": "monotonic",. "bottom_shell_layers": "5",. "bottom_shell_thickness": "0",. "bridge_flow": "0.85",. "bridge_speed": "25",. "brim_width": "0",. "brim_object_gap": "0",. "compatible_printers_condition": "",. "print_sequence": "by layer",. "default_acceleration": "0",. "outer_wall_acceleration": "0",. "top_surface_acceleration": "0",. "bridge_no_support": "0",. "draft_shield": "disabled",. "elefant_foot_compensation": "0.1",. "enable_arc_fitting": "0",. "outer_wall_line_width": "0.4",. "wall_infill_order": "inner wall/outer wall/infill",. "line_width": "0.45",. "infill_direction": "45",. "sparse_infill_densit
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1855
            Entropy (8bit):4.491480562045838
            Encrypted:false
            SSDEEP:48:jJhHprQUiOsefFYi9Ny6ES1W12LnnSbLxwN4ga:jJ5dQUi5GrnSbdwc
            MD5:288D4CE8DC1458BDB3749CA4E311E732
            SHA1:65C3DB1490927421DB5E5685EC97EAD0B0B67A7B
            SHA-256:43AAD42907D57569CA311B1CC309A443C131F6F1432DF656FB20D5912334166B
            SHA-512:51AF5C1E950DE224E8E2A3C5589788672297B6BC27AB43A15A3213F7CF52AC6825753A866D1CBCDF1DBE649E28C472B9C420796FC61C8C898738F48FB58133AD
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "fdm_process_common",. "from": "system",. "instantiation": "false",. "adaptive_layer_height": "0",. "reduce_crossing_wall": "0",. "bridge_flow": "0.95",. "bridge_speed": "25",. "brim_width": "5",. "compatible_printers": [],. "print_sequence": "by layer",. "default_acceleration": "0",. "bridge_no_support": "0",. "elefant_foot_compensation": "0.1",. "outer_wall_line_width": "0.4",. "outer_wall_speed": "120",. "line_width": "0.45",. "infill_direction": "45",. "sparse_infill_density": "15%",. "sparse_infill_pattern": "grid",. "initial_layer_line_width": "0.42",. "initial_layer_print_height": "0.2",. "initial_layer_speed": "20",. "gap_infill_speed": "30",. "infill_combination": "0",. "sparse_infill_line_width": "0.45",. "infill_wall_overlap": "25%",. "sparse_infill_speed": "50",. "interface_shells": "0",. "detect_overhang_wall": "0",. "reduce_infill_retraction": "0",.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:data
            Category:dropped
            Size (bytes):5484
            Entropy (8bit):3.7784359983545057
            Encrypted:false
            SSDEEP:96:RMiW/bg99egMjGE1zCC3Wy9qqFsaSIAn99vtarlRBM3WHsaYw2Hw+eK:Rcg99egMjGC3JqqFsaSIA991arjBM3Wa
            MD5:7369DA21840FF14AE9F7479A970212DC
            SHA1:32F880FC2B48661C96B357041D350CB0D595D750
            SHA-256:05313FBCADE16D3B8646088086771C09B34BEC950A73552B10A6B7A4824B7746
            SHA-512:57139A40565BC13292D63E655E2BFADE27C1BDECB7B56346AF14DD84405B2B83C0F83296E43480DD3EC94CBAEB0C8691BE71778D0F3D19C860A854C50D9BCB46
            Malicious:false
            Reputation:low
            Preview:STLB ATF 12.4.0.73 COLOR=.... l.......U.}?...........B...........B........n.B....sN....U.}?........n.B...........B........n.B....sN...^.l?........n.B........n.B........h;.B....sN...^.l?........h;.B........n.B........h;.B....sN....4.K?........h;.B........h;.B...........B....sN....4.K?...........B........h;.B...........B....sN4.K....?...........B...........B....h;.....B....sN4.K....?....h;.....B...........B....h;.....B....sN^.l....>....h;.....B....h;.....B.....n....B....sN^.l....>.....n....B....h;.....B.....n....B....sNU.}....>.....n....B.....n....B...........B....sNU.}....>...........B.....n....B...........B....sN.......?...........B.......B...B...........B....sN.......?...........B.......B...B.......B...B....sN...........?....n.B........h;.B...........B....sN...........?.......B........h;.B...........B....sN...........?.......B...........B....h;.....B....sN...........?h;.....B.....n....B...........B....sN...........?....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 661 x 661, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6214
            Entropy (8bit):6.385386945781998
            Encrypted:false
            SSDEEP:96:9Wgo22unU1TuAXZFl0nibCFnCSuuWKMc+vOV9Bokdl0HpEfHsSSZ:9ulSVQC9WS0Hp6XSZ
            MD5:6018087BD47C1FC68B16FF7E68C96F93
            SHA1:E8B07D8A603674A901881CE436D3BDC8917145B5
            SHA-256:BAD0290BE816E5D6291EE774C8D80AA404EEF394D393543AAF02892308FFACBD
            SHA-512:15BDFF60CDE6502ECFF4F66BA6890F289442A266F9607E24AC07AD86FAB9920DB332CFD880E475CB36FD1E81C4A37C5A6181DF9953246E8968E5D6A160CC56D6
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR..............Q......iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmp:CreateDate="2023-05-04T12:27:36+0200". xmp:ModifyDate="2023-05-04T12:30:51+02:00". xmp:MetadataDate="2023-05-04T12:30:51+02:00". photoshop:DateCreated="2023-05-04T12:27:36+0200". photoshop:ColorMode="3". photoshop:ICCProfile="sRGB IEC61966-2.1". exif:PixelXDimension="661". exif:PixelYDimension="661". exif:ColorSpace="1". tiff:ImageWidth="661". tiff:ImageLength="661". tiff:Resol
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):84
            Entropy (8bit):3.6139827970754483
            Encrypted:false
            SSDEEP:3:Q5EvFYwoBVXWfGi9iA:0EviwoKf9iA
            MD5:7D0B5FE880F2F6BA8328877067631D19
            SHA1:9B49DFABB3EE3A06BD92ABC18029EB2C63B0FE71
            SHA-256:99967E57FAF1A44D26B9E0BBC738FEF595782BB008D3110407FC6D17DBDAB7A5
            SHA-512:6C5FAC2DDC4DB09D65BCC16B1556E8D00DD07FEEFCDB21990FC04AB6B73696746BEEB80D456292AB306CBC6B6B7BD403EBC9B9A1909BC56A2EF53C4A66525D5B
            Malicious:false
            Reputation:low
            Preview:{. "filament": [. "GFSA03". ],. "process": [. "GP008". ].}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Python script, Unicode text, UTF-8 text executable
            Category:dropped
            Size (bytes):1488
            Entropy (8bit):4.960058660343264
            Encrypted:false
            SSDEEP:24:ohqNDn6rzORrt35zgDzVhObPVrdEthjuPd+7eZNUBAWyax:AqtMzORtJAzVho1IjuPd++UBA/ax
            MD5:99E8D8FB3C88BA958135C7D28663B558
            SHA1:F23666145E435F5446F2D8FE0B4DC0340F4E3B7D
            SHA-256:369F8536DCE24A246AA9768B40DBC19010A77CA38AB631C19C297BF6F938CB75
            SHA-512:69585DD66E3EFB541C9AA0E2C6CEA12AD64F797E55D70291A8B14DAF5FDDA4586B775DAB25D947106164DEE9542EDC7CB1E3150D537FEBD075F6A9EC8BD327F5
            Malicious:false
            Reputation:low
            Preview:#by chatGPT.import os.import json..# ............... setting_id.setting_id_values = []..# .......def traverse_files(path):. for file in os.listdir(path):. file_path = os.path.join(path, file). if os.path.isdir(file_path):. traverse_files(file_path) # ......... elif file_path.endswith('.json'):. # .. JSON ..... setting_id ... with open(file_path) as f:. try:. data = json.load(f). if 'setting_id' in data:. setting_id = data['setting_id']. if isinstance(setting_id, str):. setting_id_values.append(setting_id). #print(f"Found setting_id value: {setting_id}"). except (KeyError, json.JSONDecodeError):. pass..# ..........traverse_files('.')..from collections im
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Python script, Unicode text, UTF-8 text executable
            Category:dropped
            Size (bytes):1521
            Entropy (8bit):4.707682013438248
            Encrypted:false
            SSDEEP:24:KU9dMTEgIrzORrt35zllwRHkpzJensmORrDxxyX:/9zzORtJB5h87OR1xW
            MD5:BB62FD29AE5566A8928F308A2EE07C52
            SHA1:3EA8366144F4AB05188EF9DEA3A70983884E0270
            SHA-256:18E9D89A69242DFAAD3480DDF33085FD2BA7EFC6C4C8264714A9A904C2C441A0
            SHA-512:97608F911D45AA6D4146F51F76B881EA6EF535D4752839C5031459B6AB94969DDFDAC309DADDC17CA411DB78127DF24831154085783D7A51E4ECE1DA0E02BD78
            Malicious:false
            Reputation:low
            Preview:import os.import json..setting_id_used=set().setting_id_all=set().root_dir=os.path.dirname(os.path.abspath(__file__))...def loadBlackList():. with open(root_dir+'/blacklist.json') as file:. data=json.load(file).. for key,val in data.items():. for item in val:. setting_id_used.add(item). setting_id_all.add(item)..def traverse_files(path):. for file in os.listdir(path):. file_path = os.path.join(path, file). if os.path.isdir(file_path):. traverse_files(file_path) # ......... elif file_path.endswith('.json'):. # .. JSON ..... setting_id ... with open(file_path) as f:. data = json.load(f). if 'setting_id' in data:. setting_id_all.add(data['setting_id'])..def getUsedId(brand):. with open(root_dir+'/'+brand+'.json')as file:. data=json.load(file).. key_list=["machine_model_list","machine_list","filam
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1417
            Entropy (8bit):4.239904628878988
            Encrypted:false
            SSDEEP:12:n1VGEaHd8ApywwFOlLBD/4XkkLkkpXpwz4rwd8CL:n1VGEa9iwwFILBD/rkLkkpXpwzrdH
            MD5:C4A8C3ED005ED2AE6CC4B31E83A3225F
            SHA1:E38FCE8ED5CBEBEAB53C16A223DCFE286098CF3C
            SHA-256:FC85A14BB292BE761A745422C2BBF996930D2CAFF26FDB6073EAD0C3C7935B0A
            SHA-512:6071577BE2029B2BF928D2F33F8DF25C04FA44D55FEDCD857EE314F6B074C2DEEEBCF4071F2D813EB12AE611491E32DF663895FF0B882EBBA5A110B6C75F5C28
            Malicious:false
            Reputation:low
            Preview:{. "name": "Template",. "version": "01.07.00.02",. "force_update": "0",. "description": "Template configurations",. "machine_model_list": [. ],. "process_list": [. {. "name": "process template",. "sub_path": "process/process template.json". }. ],. "filament_list": [. {. "name": "filament_abs_template",. "sub_path": "filament/filament_abs_template.json". },. {. "name": "filament_asa_template",. "sub_path": "filament/filament_asa_template.json". },. {. "name": "filament_hips_template",. "sub_path": "filament/filament_hips_template.json". },. {. "name": "filament_pa_template",. "sub_path": "filament/filament_pa_template.json". },. {. "name": "filament_pet_template",. "sub_path": "filament/filament_pet_template.json". },. {. "name": "filament_pla_template",. "sub_path": "filament/filament_pla_template.json". },. {. "name": "filament_ppa_template",.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):4.536789307269339
            Encrypted:false
            SSDEEP:48:vJpkQsVL21tLRu0rLRJ7QwL9uwTNvUB/aoY:vJaL21PVJ7nJqQ
            MD5:27A0D248EF61CC3FD7EA40E815609D55
            SHA1:BC9873C22E3EB40C6E59D1BB32C5107AD0BABCBE
            SHA-256:6378380CBD3207D91444F500E81B7BBD6F5E4CF9856E7D15257F076B83110765
            SHA-512:44A6FE6603D2F0C46CA3127611B3F53F7F18CF9BD55A1E5E48EF8B0FBCE2FC79BE8B65057F0AE265195228711C22091DC0760837D2C26E61A8B6166703F699BB
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ABS template",. "instantiation": "false",. "activate_air_filtration": [. "1". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "3". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "0". ],. "cool_plate_temp_initial_layer": [. "0". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "90". ],. "eng_plate_temp_initial_layer": [. "90". ],. "fan_cooling_layer_time": [. "30". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "10". ],. "filament_cost": [. "20". ],. "filament_density": [. "1.04". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "28.6". ],. "filament_minimal_purge_on_wipe_tower": [. "15". ],. "filament_retract_before_wipe
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):4.5363102429407745
            Encrypted:false
            SSDEEP:48:0JpkQTVL21tLRu0wLgJ7QwL9uwTNvUB/aoY:0JNL21EEJ7nJqQ
            MD5:654916580E816653772B74D4E3FDE4B7
            SHA1:DA45B7B2C3E00FBED3973F3EA2C3FBDC697CD144
            SHA-256:D95FC1F4C96F8852686A26E87CA2FCA5D86620599B71FE95307189186A66E12D
            SHA-512:BC4B7BB2D07D4466CE8FD4CBCB48D9C2587310201697D9429EFA23B2B9E1A19173163F31FC68B5789FFE01366F6DD04F8574D7A56F5E32651E7A92AE3B442C8E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic ASA template",. "instantiation": "false",. "activate_air_filtration": [. "1". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "3". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "0". ],. "cool_plate_temp_initial_layer": [. "0". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "90". ],. "eng_plate_temp_initial_layer": [. "90". ],. "fan_cooling_layer_time": [. "35". ],. "fan_max_speed": [. "80". ],. "fan_min_speed": [. "10". ],. "filament_cost": [. "20". ],. "filament_density": [. "1.04". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "28.6". ],. "filament_minimal_purge_on_wipe_tower": [. "15". ],. "filament_retract_before_wipe
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2731
            Entropy (8bit):4.535202983243752
            Encrypted:false
            SSDEEP:24:dJpk15Zp1T/1uGw1iK21tK+RAOXIULla50S4p0GBikQehyuXgTKjz0iEjTl/u1/R:dJpkBW21tLRA0HL6M7QwyuwTsvUB/aoY
            MD5:F139B098D252E0F7C8FE240281DA8D25
            SHA1:565999DD46519E34E6A58A6D128AB5F0CE65D880
            SHA-256:BF6A4DB229E6F10EB518E81EDE33883F8699A0479A02F996986D264616B99B08
            SHA-512:9FC6FE15907A0C5EF2FB5546CF11EB983D74B78CBB7B1576C626FEFC3A543A6743B581CE6D8F39876BB53E9EFA7078FB4096D275BA3C60EFD4B676207042F1DA
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic HIPS template",. "instantiation": "false",. "activate_air_filtration": [. "0". ],. "additional_cooling_fan_speed": [. "0". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "3". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "0". ],. "cool_plate_temp_initial_layer": [. "0". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "90". ],. "eng_plate_temp_initial_layer": [. "90". ],. "fan_cooling_layer_time": [. "10". ],. "fan_max_speed": [. "60". ],. "fan_min_speed": [. "0". ],. "filament_cost": [. "22.99". ],. "filament_density": [. "1.06". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "8". ],. "filament_minimal_purge_on_wipe_tower"
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2681
            Entropy (8bit):4.5249645000095216
            Encrypted:false
            SSDEEP:48:0JpkQC5AneL21tLRA0aLRyI2CunwyunTWKgUB/aoY:0J3eL210l/u+IqQ
            MD5:9EA3B44499EAA7435F244B38C3898600
            SHA1:857869B2438E5585D53B4F72A178C02DBA371A6E
            SHA-256:8E92131B732C3EFA7F92D720695E23CD20B0D2E02179054B6B96EE9CB3E9E30F
            SHA-512:26BB25CCCD20729799EA49C7327C715D3D5FC04B0D50097C19AB2CD33FDC72E2EDF675454C199DAF016E2A39ADD146FB10FAE8458F8EC02944B647A19BB217C9
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PA template",. "instantiation": "false",. "activate_air_filtration": [. "1". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "3". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "0". ],. "cool_plate_temp_initial_layer": [. "0". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "100". ],. "eng_plate_temp_initial_layer": [. "100". ],. "fan_cooling_layer_time": [. "4". ],. "fan_max_speed": [. "60". ],. "fan_min_speed": [. "0". ],. "filament_cost": [. "20". ],. "filament_density": [. "1.04". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "8". ],. "filament_minimal_purge_on_wipe_tower": [. "15". ],. "filament_retract_before_wipe": [
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2685
            Entropy (8bit):4.529422416831642
            Encrypted:false
            SSDEEP:48:WJpkmnL21tLRh0MLSNdQwL9uwT+UB/aoY:WJFL21nONdnKqQ
            MD5:3BE4ECB27221B0DF2A67DE73426F2128
            SHA1:59B15C5021A5679F0D2A8E0E14F486C316100D15
            SHA-256:4150BEC21CF99AA36B6EADEDE32186AE9C704B057BDE944ACA2445CFD6EE09BE
            SHA-512:DF876990C35CA08E266D6A8595A83A6C95C445D2AB0992CCABF630561D616D71C43A51BF3183F72CDC7358820A4AC456B728F022070E3978BA247792B6AAC6B2
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PC template",. "instantiation": "false",. "activate_air_filtration": [. "0". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "3". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "0". ],. "cool_plate_temp_initial_layer": [. "0". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "110". ],. "eng_plate_temp_initial_layer": [. "110". ],. "fan_cooling_layer_time": [. "30". ],. "fan_max_speed": [. "60". ],. "fan_min_speed": [. "10". ],. "filament_cost": [. "20". ],. "filament_density": [. "1.04". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "23.2". ],. "filament_minimal_purge_on_wipe_tower": [. "15". ],. "filament_retract_before_wip
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2952
            Entropy (8bit):4.653032708546615
            Encrypted:false
            SSDEEP:48:mJpkv6kz21tLR30zLoNLwnwL9uwT9bW+wB/aoY:mJY212EN8GxbW+mQ
            MD5:0C4057D75D58D8AF395235FCDC4E001B
            SHA1:4B47684F39606C406FF3E0601F7041702C13889C
            SHA-256:20237B79A363E68730F3EA3D0F52EAE7757EC9779133780D42C4C6C333C5587A
            SHA-512:E1256E72603C7391C5B37908E0E1B9158B9E7797B624C4C965657274C3F5C576CD8D2C369BE21F1A7B16BA0E790F2E6C10330FA32AC63C6524DF5624E9FD4AE6
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PET template",. "instantiation": "false",. "activate_air_filtration": [. "0". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "3". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "60". ],. "cool_plate_temp_initial_layer": [. "60". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "0". ],. "eng_plate_temp_initial_layer": [. "0". ],. "fan_cooling_layer_time": [. "20". ],. "fan_max_speed": [. "100". ],. "fan_min_speed": [. "20". ],. "filament_cost": [. "30". ],. "filament_density": [. "1.27". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "25". ],. "filament_minimal_purge_on_wipe_tower": [. "15". ],. "filament_retract_before_wipe"
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2978
            Entropy (8bit):4.6358140433638155
            Encrypted:false
            SSDEEP:48:MJpkhWn6Ic21tLRJ0YL4vPJLwe3wL9uwTAhWOoB/aoY:MJA21ZUp8rMhWOeQ
            MD5:82D3AE1442870DBF255CC5092E350638
            SHA1:65AEC2910D8008BD865B444EDA1422EF00290849
            SHA-256:757E318C831EEA14F2F819011DA4204594F884740033C7D0A642F325DBF1CD85
            SHA-512:AB653D27A772972177F0B4F7EB558212605534EB565D8F05BC3EBB055C9FBF9ED1E1F65C0F5DDE5BF093E7072404CF789A3EE38362C888E8BD4EA6CAFF83396E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PLA template",. "instantiation": "false",. "activate_air_filtration": [. "0". ],. "additional_cooling_fan_speed": [. "70". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "1". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "35". ],. "cool_plate_temp_initial_layer": [. "35". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "0". ],. "eng_plate_temp_initial_layer": [. "0". ],. "fan_cooling_layer_time": [. "100". ],. "fan_max_speed": [. "100". ],. "fan_min_speed": [. "100". ],. "filament_cost": [. "20". ],. "filament_density": [. "1.24". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "12". ],. "filament_minimal_purge_on_wipe_towe
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2689
            Entropy (8bit):4.540238151915419
            Encrypted:false
            SSDEEP:48:AJpkQC5j821fRA06LRyIb/vwyunTGKgUB/aoY:AJz21Wlb/mIqQ
            MD5:0D3214CCD7C9C16F58CF1F3EB24DDBC9
            SHA1:AADD6FEE2209316BAC9847FD88754130A5A4175C
            SHA-256:0476E0EB5DD6C5000FC71A1081C443796F1AD1C3BB39CB3C3DB217AB7E9B910E
            SHA-512:D4D48A05A1A52C178D042ED846A0639034929102417E17ED36873DBB62D1676039F7A9CDB81CBBC58138D757675C889137AE351C8EC28A155252AD99B7A88831
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPA template",. "instantiation": "false",. "activate_air_filtration": [. "1". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "3". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "0". ],. "cool_plate_temp_initial_layer": [. "0". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "100". ],. "eng_plate_temp_initial_layer": [. "100". ],. "fan_cooling_layer_time": [. "5". ],. "fan_max_speed": [. "30". ],. "fan_min_speed": [. "10". ],. "filament_cost": [. "20". ],. "filament_density": [. "1.17". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "0.96". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "8". ],. "filament_minimal_purge_on_wipe_tower": [. "15". ],. "filament_retract_before_wip
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2684
            Entropy (8bit):4.527548933052628
            Encrypted:false
            SSDEEP:48:CJpkezO21fRpK0SLr7wuvwyuwT2UB/aoY:CJE21XC3suv6qQ
            MD5:2EAEA4ED32D199B7AF43A71CC6DB7B77
            SHA1:8D414EE42B5FAA034D56EC2E0819B29377F03999
            SHA-256:65B68B5FD3D5FBB524EFD13C5460F4BF884E29F11DD3A1438FB9A49E8C512D5E
            SHA-512:97712EEDC852D8C959DB516E6143A8FCF0FBE2CFDB8092CDCC23916E861AEFEB3349F499DBD49056B1984106F3317D8D7C845AC26FEEE07B52FF002BCCFD144E
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PPS template",. "instantiation": "false",. "activate_air_filtration": [. "0". ],. "chamber_temperatures": [. "60". ],. "close_fan_the_first_x_layers": [. "3". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "0". ],. "cool_plate_temp_initial_layer": [. "0". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "110". ],. "eng_plate_temp_initial_layer": [. "110". ],. "fan_cooling_layer_time": [. "5". ],. "fan_max_speed": [. "50". ],. "fan_min_speed": [. "0". ],. "filament_cost": [. "0". ],. "filament_density": [. "1.36". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "0.96". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "4". ],. "filament_minimal_purge_on_wipe_tower": [. "15". ],. "filament_retract_before_wipe
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2978
            Entropy (8bit):4.6356699007540225
            Encrypted:false
            SSDEEP:48:KJpkhkn6Ic21tLTqq0VvL4rPJLwe3wL9uwTAAHWOoB/aoY:KJu21IUN8rMuWOeQ
            MD5:174894E5EA131B322212C7CDC1CF8492
            SHA1:2014AA9BDB14A362BFD9E047CDE5AFD1F8F63316
            SHA-256:3CE164F27E9BC1A33C5D0CE7CE78EFA9ED5505D0D38A2AB4B68C0745C204087F
            SHA-512:18F1B6047D0472411381246DE8BA1643F6DCCF1AD81F9BD812B45ED1E4B108CB3F66B7399DC7F3FC08AFCC4C00090873ACE63D1200E75C22A94854692D766067
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic PVA template",. "instantiation": "false",. "activate_air_filtration": [. "0". ],. "additional_cooling_fan_speed": [. "70". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "1". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "45". ],. "cool_plate_temp_initial_layer": [. "45". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "0". ],. "eng_plate_temp_initial_layer": [. "0". ],. "fan_cooling_layer_time": [. "100". ],. "fan_max_speed": [. "100". ],. "fan_min_speed": [. "100". ],. "filament_cost": [. "20". ],. "filament_density": [. "1.24". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "1". ],. "filament_max_volumetric_speed": [. "15". ],. "filament_minimal_purge_on_wipe_towe
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2980
            Entropy (8bit):4.640476496535464
            Encrypted:false
            SSDEEP:48:wJpkhSn6Ic21tLRqJ2EmLuAOwLwnwL9uwTprCvB/aoY:wJI21xyAv8GVrCJQ
            MD5:1AFA090A06CA4B7A74F21A3A99B18A6C
            SHA1:6C32240446870F1D8BC2E6AE804457FE62966BCD
            SHA-256:C596D7B1A9194EA963BD6B4B527BEF153EF03C91853EF5F80B959D36611C0ED1
            SHA-512:944C49994D47900ABD4D76089DFEB33332C7F24B5B6852C97329951B7EC5101B724722F4572D735DA277CA1BBEAD6EAD3B1463B5965092AB84ED10FF687D7354
            Malicious:false
            Reputation:low
            Preview:{. "type": "filament",. "name": "Generic TPU template",. "instantiation": "false",. "activate_air_filtration": [. "0". ],. "additional_cooling_fan_speed": [. "70". ],. "chamber_temperatures": [. "0". ],. "close_fan_the_first_x_layers": [. "1". ],. "complete_print_exhaust_fan_speed": [. "70". ],. "cool_plate_temp": [. "30". ],. "cool_plate_temp_initial_layer": [. "30". ],. "during_print_exhaust_fan_speed": [. "70". ],. "eng_plate_temp": [. "30". ],. "eng_plate_temp_initial_layer": [. "30". ],. "fan_cooling_layer_time": [. "100". ],. "fan_max_speed": [. "100". ],. "fan_min_speed": [. "100". ],. "filament_cost": [. "20". ],. "filament_density": [. "1.24". ],. "filament_deretraction_speed": [. "nil". ],. "filament_diameter": [. "1.75". ],. "filament_flow_ratio": [. "1". ],. "filament_is_support": [. "0". ],. "filament_max_volumetric_speed": [. "15". ],. "filament_minimal_purge_on_wipe_to
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):3721
            Entropy (8bit):4.547383219667639
            Encrypted:false
            SSDEEP:96:jJVwdAUMpPolYzt8tq/D/8rOHjpMRlSQUMsNTUp93374pMsT3NdvEB:bUTMpPftZ/D/8rOHjpMRlSQUMsNTe935
            MD5:9A85B75E30C3E55BBC1853DED70BB74A
            SHA1:225C0D584BC4B676EF50319228C18A8A8653DA4D
            SHA-256:8945228433889E0B8EB7E605070FFA8F06F0E80E9A0D42EAE00385CEF1528209
            SHA-512:FFAABC1758A27830552A172671CE5EF598C6FF4EE282B9EEE7FA3339D67F915711EC3AD8E588BE75EEAC69CD683146D623097A47CE04C2F057D06F0149365E08
            Malicious:false
            Reputation:low
            Preview:{. "type": "process",. "name": "process template",. "instantiation": "false",. "adaptive_layer_height": "0",. "bridge_flow": "1",. "bridge_speed": "50",. "brim_width": "5",. "bridge_no_support": "0",. "bottom_surface_pattern": "monotonic",. "bottom_shell_layers": "3",. "bottom_shell_thickness": "0",. "brim_object_gap": "0.1",. "compatible_printers_condition": "",. "default_acceleration": "10000",. "detect_overhang_wall": "1",. "detect_thin_wall": "0",. "draft_shield": "disabled",. "elefant_foot_compensation": "0.15",. "enable_support": "0",. "enable_prime_tower": "1",. "enable_arc_fitting": "1",. "filename_format": "{input_filename_base}_{filament_type[0]}_{print_time}.gcode",. "gap_infill_speed": "250",. "infill_direction": "45",. "initial_layer_line_width": "0.5",. "initial_layer_print_height": "0.2",. "initial_layer_speed": "50",. "infill_combination": "0",. "infill_wall_overlap": "15%",. "inte
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):93
            Entropy (8bit):4.429837502038517
            Encrypted:false
            SSDEEP:3:xQuCjjT4GSPlKdFFvb9zwCKXGSin:efK6zdKGn
            MD5:1DF93654BDA177BA9F5E833DA6436233
            SHA1:79B3E1C63C78164225081D1921FCBEC890385A36
            SHA-256:E2A327F4F2E28B00C52E97804D4BB34FD6D9E75A0AC815B96E43A7D23D34FC3A
            SHA-512:4F26DA3AB5D04A72ECB06460344D736200DC6414110E6718D48CBF9709E5B5859D6CCF645ACDAC4CD15A5858ECB952E88DE4E3FEACD4D2625E4C6694D10B8406
            Malicious:false
            Reputation:low
            Preview:#version 110..uniform vec4 uniform_color;..void main().{. gl_FragColor = uniform_color;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):62
            Entropy (8bit):4.401957101394496
            Encrypted:false
            SSDEEP:3:xQLkdFF5KWXXJMKYv:el6uKYv
            MD5:84879544045892C2ED916A874BE23624
            SHA1:E3960405450CEA6A59688027A1E08FEE8F8460D9
            SHA-256:35D1A78EDF0B8E6E35C7BB623B49EBD7B3D40D58CA384183B8C2B95746B6397D
            SHA-512:B749E4D231C29422CAC30B1D07605BA3D90899B4A3FDCD5A51131A7145CFB3EAC254FDFEF65C374D237F6B66920F87E76B155B78151DAD84B9860C046312519C
            Malicious:false
            Reputation:low
            Preview:#version 110..void main().{. gl_Position = ftransform();.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):93
            Entropy (8bit):4.429837502038517
            Encrypted:false
            SSDEEP:3:xQuCjjT4GSPlKdFFvb9zwCKXGSin:efK6zdKGn
            MD5:1DF93654BDA177BA9F5E833DA6436233
            SHA1:79B3E1C63C78164225081D1921FCBEC890385A36
            SHA-256:E2A327F4F2E28B00C52E97804D4BB34FD6D9E75A0AC815B96E43A7D23D34FC3A
            SHA-512:4F26DA3AB5D04A72ECB06460344D736200DC6414110E6718D48CBF9709E5B5859D6CCF645ACDAC4CD15A5858ECB952E88DE4E3FEACD4D2625E4C6694D10B8406
            Malicious:false
            Reputation:low
            Preview:#version 110..uniform vec4 uniform_color;..void main().{. gl_FragColor = uniform_color;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):204
            Entropy (8bit):4.683056231155179
            Encrypted:false
            SSDEEP:3:xQuCVpBdHRselvalUXce3DRKWXBKdFF5KWalUXcF9TBdHRsF9TjeNZTKn:ez1lalUXRBXtlUX0x1kxw4
            MD5:6161EC0ABE7F1959409690E755FADF35
            SHA1:4E932D36B3BE778420B9C885E7AFF97884DD79D7
            SHA-256:0E9576541D6136219E0733C3924669BB3ED51F1991A53988CAB3E000459C2F2D
            SHA-512:96C058951A469694DE1BB39721A1827F42E645FC99703551F773F782228B93A6AD5E84A375818E4D5FA2F297E4659A49315297BB37D2BF54D4DE9E9915496078
            Malicious:false
            Reputation:low
            Preview:#version 110..uniform mat4 view_model_matrix;.uniform mat4 projection_matrix;..attribute vec3 v_position;..void main().{. gl_Position = projection_matrix * view_model_matrix * vec4(v_position, 1.0);.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):3481
            Entropy (8bit):5.052227242838322
            Encrypted:false
            SSDEEP:48:On0eJ1pBocNObxB8qYL8RMN/Vl6VNctb5DSdoXNzA/1ZoOoYAguSRZPRutLGvVn0:hWlb4bnm8RMNdl6VN2dIo+PR6LCV3XUT
            MD5:2151CD2AF143BC7FAEC5681B624229E4
            SHA1:C042A403267494CF7298B55D7D01EC756ABA77CC
            SHA-256:150F47F672F1ABC166DD0DDFF4A87A414CA924C868C208CE9868106B13E44110
            SHA-512:AE2BAA8F5CDF0825BA7618FE50CED32A5E47BEFD7DB5EBD9F461725C6053DB2094B811C0B234C1F565DE583AEC83954FF18DB8C52E34290703310BAE3FF35E02
            Malicious:false
            Reputation:low
            Preview:#version 110..const vec3 ZERO = vec3(0.0, 0.0, 0.0);.//BBS: add grey and orange.//const vec3 GREY = vec3(0.9, 0.9, 0.9);.const vec3 ORANGE = vec3(0.8, 0.4, 0.0);.const vec3 LightRed = vec3(0.78, 0.0, 0.0);.const vec3 LightBlue = vec3(0.73, 1.0, 1.0);.const float EPSILON = 0.0001;..struct PrintVolumeDetection.{..// 0 = rectangle, 1 = circle, 2 = custom, 3 = invalid..int type;. // type = 0 (rectangle):. // x = min.x, y = min.y, z = max.x, w = max.y. // type = 1 (circle):. // x = center.x, y = center.y, z = radius..vec4 xy_data;. // x = min z, y = max z..vec2 z_data;.};..struct SlopeDetection.{. bool actived;..float normal_z;. mat3 volume_world_normal_matrix;.};..uniform vec4 uniform_color;.uniform SlopeDetection slope;..//BBS: add outline_color.uniform bool is_outline;..uniform bool offset_depth_buffer;..#ifdef ENABLE_ENVIRONMENT_MAP. uniform sampler2D environment_tex;. uniform bool use_environment_tex;.#endif // ENABLE_ENVIRONMENT_MAP..varying vec3 clipping_pl
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):3020
            Entropy (8bit):5.4400441894943565
            Encrypted:false
            SSDEEP:48:sVMOoo+IawPo6Gch7nRMNrUYjW+XACNsZplipbNMNSWoLMw8MLlOIfb:s6OonIawPo6LnRMNrUYjXQCNsZpIZNM6
            MD5:4D15733C3DE70BCC81282F0687627911
            SHA1:69AB5B969B897B372EC6E6C598899C45370A3782
            SHA-256:54EB1787E08F5853F88DDFA782DB4EB1B34AAFD11FF713D80FFCFB7B43EDC7A7
            SHA-512:52BFB851913214A4F89F44D25E60530B6CAE3CD80FDB30F106CD1359721FAB69124ED7C68C27E4B49D3380613586AA87C43999029C839AB08D008909C1B07581
            Malicious:false
            Reputation:low
            Preview:#version 110..#define INTENSITY_CORRECTION 0.6..// normalized values for (-0.6/1.31, 0.6/1.31, 1./1.31).const vec3 LIGHT_TOP_DIR = vec3(-0.4574957, 0.4574957, 0.7624929);.#define LIGHT_TOP_DIFFUSE (0.8 * INTENSITY_CORRECTION).#define LIGHT_TOP_SPECULAR (0.125 * INTENSITY_CORRECTION).#define LIGHT_TOP_SHININESS 20.0..// normalized values for (1./1.43, 0.2/1.43, 1./1.43).const vec3 LIGHT_FRONT_DIR = vec3(0.6985074, 0.1397015, 0.6985074);.#define LIGHT_FRONT_DIFFUSE (0.3 * INTENSITY_CORRECTION).//#define LIGHT_FRONT_SPECULAR (0.0 * INTENSITY_CORRECTION).//#define LIGHT_FRONT_SHININESS 5.0..const vec3 LIGHT_BACK_DIR = vec3(0.1397015, 0.6985074,0.6985074);.#define LIGHT_BACK_DIFFUSE (0.3 * INTENSITY_CORRECTION)..#define INTENSITY_AMBIENT 0.3..const vec3 ZERO = vec3(0.0, 0.0, 0.0);..struct SlopeDetection.{. bool actived;..float normal_z;. mat3 volume_world_normal_matrix;.};..uniform mat4 volume_world_matrix;.uniform SlopeDetection slope;..// Clipping plane, x = min z, y = ma
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):4172
            Entropy (8bit):5.146361233882689
            Encrypted:false
            SSDEEP:96:2b4bnOUyuqK2I8RMN96DIo+PJ6L9BxbHGK3XUT:24KUyuqK2DReo+23XUT
            MD5:84B06514C3DAD0DCB39D96027BFDB959
            SHA1:BC9315C63CC5ACD5088D1AB587A635494DB1414B
            SHA-256:BBD8E0585A37AEC7EE2AE73AF7DC4010ADE2E097240D6FA96970443EE4D55A3C
            SHA-512:E11412338962CC7503B2C689DF8C4D8C17CBD99EA73E47531D83CF50032E760157C04B7597636C3503A72B6622B691B8EE5A0AFECEFC9AB4E7323D66B24B98FA
            Malicious:false
            Reputation:low
            Preview:#version 130..const vec3 ZERO = vec3(0.0, 0.0, 0.0);.//BBS: add grey and orange.//const vec3 GREY = vec3(0.9, 0.9, 0.9);.const vec3 ORANGE = vec3(0.8, 0.4, 0.0);.const float EPSILON = 0.0001;..struct PrintVolumeDetection.{..// 0 = rectangle, 1 = circle, 2 = custom, 3 = invalid..int type;. // type = 0 (rectangle):. // x = min.x, y = min.y, z = max.x, w = max.y. // type = 1 (circle):. // x = center.x, y = center.y, z = radius..vec4 xy_data;. // x = min z, y = max z..vec2 z_data;.};..struct SlopeDetection.{. bool actived;..float normal_z;. mat3 volume_world_normal_matrix;.};..//BBS: add wireframe logic.varying vec3 barycentric_coordinates;.float edgeFactor(float lineWidth) {. vec3 d = fwidth(barycentric_coordinates);. vec3 a3 = smoothstep(vec3(0.0), d * lineWidth, barycentric_coordinates);. return min(min(a3.x, a3.y), a3.z);.}..vec3 wireframe(vec3 fill, vec3 stroke, float lineWidth) {. return mix(stroke, fill, edgeFactor(lineWidth));.}..vec3 getWireframeCo
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):2975
            Entropy (8bit):5.361332735634411
            Encrypted:false
            SSDEEP:48:6VMOoo+IuGch74RMNICUYjW+XACNsZplipbN/FLMw8MLlOIfEbF:66OonIuL4RMN3UYjXQCNsZpIZN9wwxlg
            MD5:10DFF0E9AEA2A2522553D8B3C52DA328
            SHA1:02FDFDDA603CAD7D1E5959C8AA3C4CDE43F6CC37
            SHA-256:D1CD786F2BDC04AEEC4AEC61AC2FDE12DB7F76A839438E9B9181BCB90ADE0E0D
            SHA-512:9428771126890674AEFB91B9557A28A214314C4F9EFA18432A4E17489EAC5A22988D1EE3A35E52FE8FEA24BDA963A9057B0F43A3E02EE1E26D774D28E078AB74
            Malicious:false
            Reputation:low
            Preview:#version 130..#define INTENSITY_CORRECTION 0.6..// normalized values for (-0.6/1.31, 0.6/1.31, 1./1.31).const vec3 LIGHT_TOP_DIR = vec3(-0.4574957, 0.4574957, 0.7624929);.#define LIGHT_TOP_DIFFUSE (0.8 * INTENSITY_CORRECTION).#define LIGHT_TOP_SPECULAR (0.125 * INTENSITY_CORRECTION).#define LIGHT_TOP_SHININESS 20.0..// normalized values for (1./1.43, 0.2/1.43, 1./1.43).const vec3 LIGHT_FRONT_DIR = vec3(0.6985074, 0.1397015, 0.6985074);.#define LIGHT_FRONT_DIFFUSE (0.3 * INTENSITY_CORRECTION).//#define LIGHT_FRONT_SPECULAR (0.0 * INTENSITY_CORRECTION).//#define LIGHT_FRONT_SHININESS 5.0..#define INTENSITY_AMBIENT 0.3..const vec3 ZERO = vec3(0.0, 0.0, 0.0);..struct SlopeDetection.{. bool actived;..float normal_z;. mat3 volume_world_normal_matrix;.};..uniform mat4 volume_world_matrix;.uniform SlopeDetection slope;..// Clipping plane, x = min z, y = max z. Used by the FFF and SLA previews to clip with a top / bottom plane..uniform vec2 z_range;.// Clipping plane - general o
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):260
            Entropy (8bit):4.771161830910359
            Encrypted:false
            SSDEEP:6:ef0AmWTAbwAmDAp5KCpj96zlqLlJDKlt6I85JOn:NAmWTRAfICJ96z2JDKlt6I8mn
            MD5:6690B3450AC89E1729C325DA6F858806
            SHA1:A3FFEDC97F85CE1BC40502CEDE388ACED47E1217
            SHA-256:52C45CAD84FE4C7C0EE7E6287BDD10FB813214440DDB00ABF77C8E9BDB67F1BE
            SHA-512:FCD9677B4C1616FFBD7E33D5593512E34F4A3565D1D400316A32BDAE405B1AA9CEBD4032975571D3F657852248F544F57228A6781571A44F10156BB10008D2B2
            Malicious:false
            Reputation:low
            Preview:#version 110..uniform vec4 uniform_color;.uniform float emission_factor;..// x = tainted, y = specular;.varying vec2 intensity;..void main().{. gl_FragColor = vec4(vec3(intensity.y) + uniform_color.rgb * (intensity.x + emission_factor), uniform_color.a);.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):1564
            Entropy (8bit):5.3983414909764305
            Encrypted:false
            SSDEEP:24:TAVMSODiHIo+kEQQ9bU9VlW0MJHdZ8gGJbWn6fxUEdPp4benVF4:sVMOoo+dM9jWVAfySlP4qV6
            MD5:1F7B18226D1653AE17FBF7A8BEC72AEC
            SHA1:DD38628708EEAB0659BB0427FAFE40DE2A91B82B
            SHA-256:D1DABBD8CA53B3739D31C5205CEA098DA9253AC3B57E8EC4DA230B0D671481F8
            SHA-512:EA9B51F220ABD2CB32C926DEA458697244135C7CD8F7D5AE585A99C0B2BD1B839467759F02E115F4FCFDB98511DB04E6C0C65DB91721075FB450D8D6D09C2093
            Malicious:false
            Reputation:low
            Preview:#version 110..#define INTENSITY_CORRECTION 0.6..// normalized values for (-0.6/1.31, 0.6/1.31, 1./1.31).const vec3 LIGHT_TOP_DIR = vec3(-0.4574957, 0.4574957, 0.7624929);.#define LIGHT_TOP_DIFFUSE (0.8 * INTENSITY_CORRECTION).#define LIGHT_TOP_SPECULAR (0.125 * INTENSITY_CORRECTION).#define LIGHT_TOP_SHININESS 20.0..// normalized values for (1./1.43, 0.2/1.43, 1./1.43).const vec3 LIGHT_FRONT_DIR = vec3(0.6985074, 0.1397015, 0.6985074);.#define LIGHT_FRONT_DIFFUSE (0.3 * INTENSITY_CORRECTION)..#define INTENSITY_AMBIENT 0.3..// x = tainted, y = specular;.varying vec2 intensity;..void main().{. // First transform the normal into camera space and normalize the result.. vec3 normal = normalize(gl_NormalMatrix * gl_Normal);. . // Compute the cos of the angle between the normal and lights direction. The light is directional so the direction is constant for every vertex.. // Since these two are normalized the cosine is the dot product. We also need to clamp the result
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):260
            Entropy (8bit):4.771161830910359
            Encrypted:false
            SSDEEP:6:ef0AmWTAbwAmDAp5KCpj96zlqLlJDKlt6I85JOn:NAmWTRAfICJ96z2JDKlt6I8mn
            MD5:6690B3450AC89E1729C325DA6F858806
            SHA1:A3FFEDC97F85CE1BC40502CEDE388ACED47E1217
            SHA-256:52C45CAD84FE4C7C0EE7E6287BDD10FB813214440DDB00ABF77C8E9BDB67F1BE
            SHA-512:FCD9677B4C1616FFBD7E33D5593512E34F4A3565D1D400316A32BDAE405B1AA9CEBD4032975571D3F657852248F544F57228A6781571A44F10156BB10008D2B2
            Malicious:false
            Reputation:low
            Preview:#version 110..uniform vec4 uniform_color;.uniform float emission_factor;..// x = tainted, y = specular;.varying vec2 intensity;..void main().{. gl_FragColor = vec4(vec3(intensity.y) + uniform_color.rgb * (intensity.x + emission_factor), uniform_color.a);.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):1916
            Entropy (8bit):5.372036678821447
            Encrypted:false
            SSDEEP:48:sVMOoo+17LGRfH+p9NjWVAfNAqDWSiW4N2VLE:s6Oon1WfH+p9NjtfN7DGRN2VE
            MD5:78CE235F8AE65F9278BBC1FF2ED95E9A
            SHA1:852B545298C7F2A924B61A6563A0D3A83A69D4CA
            SHA-256:00D5659C45B51BF21220086CF4076C190E82C5572AD9DFF9EC4B09A445F618DD
            SHA-512:4169397EB88CF083FB7533D26798A83C3BA5A4AFA49EA627437608E612A3CB146F2EF0666ADE276F10399025B63CEBF3818781239EB2163DB9F0D04AA1708BD7
            Malicious:false
            Reputation:low
            Preview:#version 110..#define INTENSITY_CORRECTION 0.6..// normalized values for (-0.6/1.31, 0.6/1.31, 1./1.31).const vec3 LIGHT_TOP_DIR = vec3(-0.4574957, 0.4574957, 0.7624929);.#define LIGHT_TOP_DIFFUSE (0.8 * INTENSITY_CORRECTION).#define LIGHT_TOP_SPECULAR (0.125 * INTENSITY_CORRECTION).#define LIGHT_TOP_SHININESS 20.0..// normalized values for (1./1.43, 0.2/1.43, 1./1.43).const vec3 LIGHT_FRONT_DIR = vec3(0.6985074, 0.1397015, 0.6985074);.#define LIGHT_FRONT_DIFFUSE (0.3 * INTENSITY_CORRECTION)..#define INTENSITY_AMBIENT 0.3..// vertex attributes.attribute vec3 v_position;.attribute vec3 v_normal;.// instance attributes.attribute vec3 i_offset;.attribute vec2 i_scales;..// x = tainted, y = specular;.varying vec2 intensity;..void main().{. // First transform the normal into camera space and normalize the result.. vec3 eye_normal = normalize(gl_NormalMatrix * v_normal);. . // Compute the cos of the angle between the normal and lights direction. The light is directional
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):333
            Entropy (8bit):4.840708528134221
            Encrypted:false
            SSDEEP:6:eZ57l6zlixz1A8r9QNah2+jGCT8xfuDNTMjR8K5bW2dP0jJQK:il6zExzhttjWARgV8KEfF
            MD5:6D4420F0EB743C63A9F3BA9D7E1875B3
            SHA1:91324DB55E67853EFA712468334F4DAD834F9B8E
            SHA-256:6D8FDDBCA86534F600ACFA848F559591908ACE7174FEBF26B6B39F51D52E7E65
            SHA-512:9D5114DD996EDE4576104F49E8A7C2EE0601BF1478980B9151966B6C3A1A8FF7691B00560CC24FAF572AEAC1B98742AC9C52F2D23B22134233FB13AA6B85FD16
            Malicious:false
            Reputation:low
            Preview:#version 110..const float EPSILON = 0.0001;..void main().{. gl_FragColor = vec4(1.0, 1.0, 1.0, 1.0);. // Values inside depth buffer for fragments of the contour of a selected area are offset. // by small epsilon to solve z-fighting between painted triangles and contour lines.. gl_FragDepth = gl_FragCoord.z - EPSILON;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):62
            Entropy (8bit):4.401957101394496
            Encrypted:false
            SSDEEP:3:xQLkdFF5KWXXJMKYv:el6uKYv
            MD5:84879544045892C2ED916A874BE23624
            SHA1:E3960405450CEA6A59688027A1E08FEE8F8460D9
            SHA-256:35D1A78EDF0B8E6E35C7BB623B49EBD7B3D40D58CA384183B8C2B95746B6397D
            SHA-512:B749E4D231C29422CAC30B1D07605BA3D90899B4A3FDCD5A51131A7145CFB3EAC254FDFEF65C374D237F6B66920F87E76B155B78151DAD84B9860C046312519C
            Malicious:false
            Reputation:low
            Preview:#version 110..void main().{. gl_Position = ftransform();.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):2913
            Entropy (8bit):5.24215743363155
            Encrypted:false
            SSDEEP:48:sVMOoo+1jn0eJJXcuciGtxjXhGYYQBxjV5i4jhdjWVAfNtnUliW4N2V/r:s6OonaWJXcuciGtxjxiQBxjV5i4ldjti
            MD5:5142A0ECE8F9D52823BBB148599E6C55
            SHA1:E003BDA6D6E7812BACCD4DF8063A3AA11F261C25
            SHA-256:197FA7B4D41150CEC5476C06650F26064272C5969D4F066F9E4555E7A6D29423
            SHA-512:0AF44A4D9C8210C817DD408E414240D79FCB1FD5BA99C1DD15FB099823850418E0A96B11839857D42C678C77773109893936BBC3E5F54DD6FDA95EC790530BD6
            Malicious:false
            Reputation:low
            Preview:#version 110..#define INTENSITY_CORRECTION 0.6..// normalized values for (-0.6/1.31, 0.6/1.31, 1./1.31).const vec3 LIGHT_TOP_DIR = vec3(-0.4574957, 0.4574957, 0.7624929);.#define LIGHT_TOP_DIFFUSE (0.8 * INTENSITY_CORRECTION).#define LIGHT_TOP_SPECULAR (0.125 * INTENSITY_CORRECTION).#define LIGHT_TOP_SHININESS 20.0..// normalized values for (1./1.43, 0.2/1.43, 1./1.43).const vec3 LIGHT_FRONT_DIR = vec3(0.6985074, 0.1397015, 0.6985074);.#define LIGHT_FRONT_DIFFUSE (0.3 * INTENSITY_CORRECTION)..#define INTENSITY_AMBIENT 0.3..const vec3 ZERO = vec3(0.0, 0.0, 0.0);.const float EPSILON = 0.0001;.//BBS: add grey and orange.//const vec3 GREY = vec3(0.9, 0.9, 0.9);.const vec3 ORANGE = vec3(0.8, 0.4, 0.0);.const vec3 LightRed = vec3(0.78, 0.0, 0.0);.const vec3 LightBlue = vec3(0.73, 1.0, 1.0);.uniform vec4 uniform_color;..varying vec3 clipping_planes_dots;.varying vec4 model_pos;.varying vec4 world_pos;.uniform bool volume_mirrored;..struct SlopeDetection.{. bool actived;.. flo
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):932
            Entropy (8bit):4.867798862944211
            Encrypted:false
            SSDEEP:12:mFS11h76C86jhdXiiCtZ5HCzZCLSDn5ObD71DoH8GEMP+CDsDbLlgi5Xmg/Ihufb:mFch7nZs/cZamamTMLlgFIfVF
            MD5:B7CBEA1F512C2C8B76DAB4E73711341B
            SHA1:75A054D79FFE3F2E804161049F539173C0A801CF
            SHA-256:F3EC0EB8E841966000CBB0404F186E301E1EC554FE320CB94C876F7BD63CCDE6
            SHA-512:B1B278E6CA16A4A02980177E6CCA42708B9F045AA55C97BF820CCD6B8F947CCE2ECE6D8477B2A8734B7FC9CD62F058F9C6B078CE64FFE6E02815EE6E9C1AC432
            Malicious:false
            Reputation:low
            Preview:#version 110..const vec3 ZERO = vec3(0.0, 0.0, 0.0);..uniform mat4 volume_world_matrix;.// Clipping plane, x = min z, y = max z. Used by the FFF and SLA previews to clip with a top / bottom plane..uniform vec2 z_range;.// Clipping plane - general orientation. Used by the SLA gizmo..uniform vec4 clipping_plane;..varying vec3 clipping_planes_dots;.varying vec4 model_pos;.varying vec4 world_pos;.struct SlopeDetection.{. bool actived;..float normal_z;. mat3 volume_world_normal_matrix;.};.uniform SlopeDetection slope;.void main().{. model_pos = gl_Vertex;. // Point in homogenous coordinates.. world_pos = volume_world_matrix * gl_Vertex;.. gl_Position = ftransform();. // Fill in the scalars for fragment shader clipping. Fragments with any of these components lower than zero are discarded.. clipping_planes_dots = vec3(dot(world_pos, clipping_plane), world_pos.z - z_range.x, z_range.y - world_pos.z);.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):3938
            Entropy (8bit):5.24110726146665
            Encrypted:false
            SSDEEP:96:s6OonaWJXOUyuqXY2ouciGtxjx0QBxjV59ldjtfNtnUIRN2t8crTO:6o/+UyuqXY2eUY5pXU7BS
            MD5:9B23385B336880E24A3F2D0072363703
            SHA1:7D8EED682845E252B1B44490DC8E868684E6205B
            SHA-256:A3A98561B72983990994CF0271293492072414A91A7CC9AB4D68F6A3A9BF3586
            SHA-512:0AB6DA4C8411806E94F783B417119CD258B11E6611E230A5AE00A6665A8D2DDC12EBB83A8A767BE4B165B662A048564556AC1F764DA6C8CC2B21FC102AAACAFD
            Malicious:false
            Reputation:low
            Preview:#version 110..#define INTENSITY_CORRECTION 0.6..// normalized values for (-0.6/1.31, 0.6/1.31, 1./1.31).const vec3 LIGHT_TOP_DIR = vec3(-0.4574957, 0.4574957, 0.7624929);.#define LIGHT_TOP_DIFFUSE (0.8 * INTENSITY_CORRECTION).#define LIGHT_TOP_SPECULAR (0.125 * INTENSITY_CORRECTION).#define LIGHT_TOP_SHININESS 20.0..// normalized values for (1./1.43, 0.2/1.43, 1./1.43).const vec3 LIGHT_FRONT_DIR = vec3(0.6985074, 0.1397015, 0.6985074);.#define LIGHT_FRONT_DIFFUSE (0.3 * INTENSITY_CORRECTION)..#define INTENSITY_AMBIENT 0.3..const vec3 ZERO = vec3(0.0, 0.0, 0.0);.const float EPSILON = 0.0001;.//BBS: add grey and orange.//const vec3 GREY = vec3(0.9, 0.9, 0.9);.const vec3 ORANGE = vec3(0.8, 0.4, 0.0);.const vec3 LightRed = vec3(0.78, 0.0, 0.0);.const vec3 LightBlue = vec3(0.73, 1.0, 1.0);.uniform vec4 uniform_color;..varying vec3 clipping_planes_dots;.varying vec4 model_pos;.varying vec4 world_pos;.uniform bool volume_mirrored;..struct SlopeDetection.{. bool actived;.. flo
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):1397
            Entropy (8bit):4.928838722112783
            Encrypted:false
            SSDEEP:24:RFch7nZs/cZnZVamakgujsATMLlgFIfVgbdOINwl:jch7RRf5lMLlOIfqbC
            MD5:F9704A131374013CB2F9081F99F18F4C
            SHA1:A596341FFDC5C8FFD3363067C049D25FE040B2BA
            SHA-256:3AFCE28D640AB36A546DC32B3A1884276DEEEB6744F67608EC84193B977BCD19
            SHA-512:F26268B2D3D717363B977D502E790927F6347967D23D9C14E71356505788EC4D6ECDB7AB3A7E53468DBEBC293C9C01C6385318B493F6D63AEFF524A2D9ABD72B
            Malicious:false
            Reputation:low
            Preview:#version 110..const vec3 ZERO = vec3(0.0, 0.0, 0.0);..//attribute vec3 v_position;.//attribute vec3 v_barycentric;..uniform mat4 volume_world_matrix;.// Clipping plane, x = min z, y = max z. Used by the FFF and SLA previews to clip with a top / bottom plane..uniform vec2 z_range;.// Clipping plane - general orientation. Used by the SLA gizmo..uniform vec4 clipping_plane;..varying vec3 clipping_planes_dots;.varying vec4 model_pos;.varying vec4 world_pos;.varying vec3 barycentric_coordinates;..struct SlopeDetection.{. bool actived;..float normal_z;. mat3 volume_world_normal_matrix;.};.uniform SlopeDetection slope;.void main().{. model_pos = gl_Vertex;. //model_pos = vec4(v_position, 1.0);. // Point in homogenous coordinates...world_pos = volume_world_matrix * model_pos;.. gl_Position = ftransform();. //gl_Position = gl_ModelViewProjectionMatrix * vec4(v_position, 1.0);. // Fill in the scalars for fragment shader clipping. Fragments with any of these components low
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):93
            Entropy (8bit):4.429837502038517
            Encrypted:false
            SSDEEP:3:xQuCjjT4GSPlKdFFvb9zwCKXGSin:efK6zdKGn
            MD5:1DF93654BDA177BA9F5E833DA6436233
            SHA1:79B3E1C63C78164225081D1921FCBEC890385A36
            SHA-256:E2A327F4F2E28B00C52E97804D4BB34FD6D9E75A0AC815B96E43A7D23D34FC3A
            SHA-512:4F26DA3AB5D04A72ECB06460344D736200DC6414110E6718D48CBF9709E5B5859D6CCF645ACDAC4CD15A5858ECB952E88DE4E3FEACD4D2625E4C6694D10B8406
            Malicious:false
            Reputation:low
            Preview:#version 110..uniform vec4 uniform_color;..void main().{. gl_FragColor = uniform_color;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):471
            Entropy (8bit):4.6879292373272055
            Encrypted:false
            SSDEEP:12:UOeEXDXcTtX+2LDIPQexg9l3P9m1BoLDxLcLDxLygM/eAez:GEX7WXRODx4f93apFzz
            MD5:1B48BFACD23DFAF795C61B42D4F23027
            SHA1:00ED1E91A26A44A36FBFFA59E36AC5A42AF80BF5
            SHA-256:19D366578DA94A6ABEB4DD1DACCD3737D3E45C657EAB17E3EABB7D6BDF0F2C92
            SHA-512:9F42F99D1A50DC1A55F5A6599F8D1964001F1DDA405F7572AFB4C1D7F6DA491FF758D5539C1EAF4D9C2EA942F8990440AD476608AED26DBA1BD92B85F5FA21CF
            Malicious:false
            Reputation:low
            Preview:#version 110..uniform bool use_fixed_screen_size;.uniform float zoom;.uniform float point_size;.uniform float near_plane_height;..float fixed_screen_size().{. return point_size;.}..float fixed_world_size().{. return (gl_Position.w == 1.0) ? zoom * near_plane_height * point_size : near_plane_height * point_size / gl_Position.w;.}..void main().{. gl_Position = ftransform();. gl_PointSize = use_fixed_screen_size ? fixed_screen_size() : fixed_world_size();.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):537
            Entropy (8bit):4.6775296199624234
            Encrypted:false
            SSDEEP:12:jufYO1XAtJXheTlxr9e4BRe2v8aPEpuieOuYutixz6qR:GYO1QtJQTlxgn2v8a3ieOQSFR
            MD5:5E87538EA250F1F712FFA10B8C3D3C53
            SHA1:278E8DF2BC1EB022A09E864FFE7B7CDEFF659B8C
            SHA-256:BC57EB3AD21B146F1ABF8A3A13DD3DB54B77B0788646E06DCE95C64F299B5781
            SHA-512:915972D0E264462F106B40B4B1E1B2C9B3A33EFB6CBD1125A8205F9E8EA38B5DE2C671B9FC2C78509C36278F21F87A836B838EC914A46A951678847A532595BF
            Malicious:false
            Reputation:low
            Preview:// version 120 is needed for gl_PointCoord.#version 120..uniform vec4 uniform_color;.uniform float percent_outline_radius;.uniform float percent_center_radius;..vec4 calc_color(float radius, vec4 color).{. return ((radius < percent_center_radius) || (radius > 1.0 - percent_outline_radius)) ?. vec4(0.5 * color.rgb, color.a) : color;.}..void main().{. vec2 pos = (gl_PointCoord - 0.5) * 2.0;. float radius = length(pos);. if (radius > 1.0). discard;.. gl_FragColor = calc_color(radius, uniform_color);.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):471
            Entropy (8bit):4.693778255378508
            Encrypted:false
            SSDEEP:12:EqOeEXDXcTtX+2LDIPQexg9l3P9m1BoLDxLcLDxLygM/eAez:EIEX7WXRODx4f93apFzz
            MD5:A88C6A19EC90A3208E498B63A172445A
            SHA1:A341F5967E0FA0B87636DDEEB83BBFBEA6491F7C
            SHA-256:A6CD00B5269C6D0C5C75BFB6FE6BD0E526AC43BC9D5A7E1183376CB00BB0C8FC
            SHA-512:CA1ED3D87E9506D5CC9FBD47C850E5478DF5338558F0635A5BD110A0E8012D35B0650FAC68A2D47DD3E6DC7D54DB6585F9C4ED2B2D7FE8C686A2D9D9297B988F
            Malicious:false
            Reputation:low
            Preview:#version 120..uniform bool use_fixed_screen_size;.uniform float zoom;.uniform float point_size;.uniform float near_plane_height;..float fixed_screen_size().{. return point_size;.}..float fixed_world_size().{. return (gl_Position.w == 1.0) ? zoom * near_plane_height * point_size : near_plane_height * point_size / gl_Position.w;.}..void main().{. gl_Position = ftransform();. gl_PointSize = use_fixed_screen_size ? fixed_screen_size() : fixed_world_size();.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):170
            Entropy (8bit):5.001354553219848
            Encrypted:false
            SSDEEP:3:xQZWYWTMldmernjT4GSPlKdFFvb9zwCKXGSMKKhjb9zlpneA:eZGTBKK6zdKwfjJzlH
            MD5:4FDF6604D04FA3B4EF4B7B5E02ADAE7F
            SHA1:F0D45C9DB1DEC878C628B543C8959A201FC3E05E
            SHA-256:B3C348F956DCEDA39950B155253720907D60ADE248C99319410E844DBF4363D3
            SHA-512:1BBC0445B5922AC5BA003613E108072A08F89AFF726DDB26A4EB3BFED5746464843AAC4741B8AB1CDB50C4C9960EB7DF811D4ACD5BBB2FE5D9D8DDC671C92C12
            Malicious:false
            Reputation:low
            Preview:#version 110..const vec3 ORANGE = vec3(0.8, 0.4, 0.0);.uniform vec4 uniform_color;..void main().{. gl_FragColor = uniform_color;..//gl_FragColor = vec4(ORANGE, 1.0);.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):176
            Entropy (8bit):4.559746755466812
            Encrypted:false
            SSDEEP:3:xQIxGmgWgGE4xRvKCpjXU46RvbBKdFF5KWXXJMK/Z36bZRCn:e26WKCpnQbBX6uK/Zr
            MD5:39A4C66E8EDB3B750F14990752EE0D79
            SHA1:E6E498FEAD4F689EBE0690868773ADE245C9D995
            SHA-256:7B5692D34D377155164BA9A7C0CCD4C90F7F62BC4147D87D0D379E97E3FEA67B
            SHA-512:AE27ACAF51381CCE9A4F55CD27C981E883D0B7B05B4C77FBA4611B01FA90AA9C080B8CB515B0ADC686C20AC8E6DF92B734122A4986D9E7209A488113D7ED367D
            Malicious:false
            Reputation:low
            Preview:#version 110..attribute vec4 v_position;.attribute vec2 v_tex_coords;..varying vec2 tex_coords;..void main().{. gl_Position = ftransform();. tex_coords = v_tex_coords;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):942
            Entropy (8bit):4.872185394661227
            Encrypted:false
            SSDEEP:12:WD1hpFhfSgr9CiG+MSc21Y2NwbvP+9slTLr2uMukQSPRmuXve0G+MSh2JeXnz8zG:WD17mszLwjG9equMuuX2zs8JVDDej
            MD5:FF53A14B4ED98E1D83F8BAC29497A2CF
            SHA1:A9CC6D04B076436C30FA35B66178D450A8C35140
            SHA-256:06D21D69736B3B4BECC6451074A1557E3018D21DF2D3D312D4887724C344E089
            SHA-512:B383A4EF711AEA017AE162B2142B3038194DFDA61FEDA3B4372493CF66CC26015ADBD60A6112534167228889B74F3F503AC4CEF2ACB0C98FFFF7374D968F5181
            Malicious:false
            Reputation:low
            Preview:#version 110..const vec3 back_color_dark = vec3(0.235, 0.235, 0.235);.const vec3 back_color_light = vec3(0.365, 0.365, 0.365);..uniform sampler2D texture;.uniform bool transparent_background;.uniform bool svg_source;..varying vec2 tex_coords;..vec4 svg_color().{. // takes foreground from texture. vec4 fore_color = texture2D(texture, tex_coords);.. // calculates radial gradient. vec3 back_color = vec3(mix(back_color_light, back_color_dark, smoothstep(0.0, 0.5, length(abs(tex_coords.xy) - vec2(0.5)))));.. // blends foreground with background. return vec4(mix(back_color, fore_color.rgb, fore_color.a), transparent_background ? fore_color.a : 1.0);.}..vec4 non_svg_color().{. // takes foreground from texture. vec4 color = texture2D(texture, tex_coords);. return vec4(color.rgb, transparent_background ? color.a * 0.25 : color.a);.}..void main().{. gl_FragColor = svg_source ? svg_color() : non_svg_color();.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):386
            Entropy (8bit):4.809294805182675
            Encrypted:false
            SSDEEP:6:e2qKCpnQbBXId4vKw8F2IumKrVaLBaGVAQs2xd4vKwfr:pC0B64vhIu99Ge24vz
            MD5:F79C4ADB240FBC95C1E81B0F7BC31206
            SHA1:4444DF6E20B4CA019B789D82FD4E8E3703992DBA
            SHA-256:2A1BD61AD341F137CBE0D092CBE9E5ACC16A98FAFEA90CCAA74E83C423002EB3
            SHA-512:F383D86D1530225FFF16650663B249BC393DFF0A4816D76B3E98E738555051C96A53FCC81BE6AA1BF8E179362621913BEA78FE30433AAC954FB7AAD15DF59BA2
            Malicious:false
            Reputation:low
            Preview:#version 110..attribute vec3 v_position;.attribute vec2 v_tex_coords;..varying vec2 tex_coords;..void main().{. gl_Position = gl_ModelViewProjectionMatrix * vec4(v_position.x, v_position.y, v_position.z, 1.0);..// the following line leads to crash on some Intel graphics card. //gl_Position = gl_ModelViewProjectionMatrix * vec4(v_position, 1.0);. tex_coords = v_tex_coords;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):350
            Entropy (8bit):4.794796313260767
            Encrypted:false
            SSDEEP:6:ef0AmWTAbwAmDAp5KCpjhI85EERdiCpFbB5SIF/DuzlqLlJDKlt6I85JOn:NAmWTRAfICJ+8a4diCfbB1F/Duz2JDKN
            MD5:204B176C8A60250DDA8E3811E7DD37C5
            SHA1:4FE710A24DFC5A9D18C967B88952567B909B91F3
            SHA-256:8A28D13BE69C35E1A28E55F81DC9BA23F303E241E8DB5BC18DD6152B17145677
            SHA-512:CDE337FFF0583A9CA1523530B59FFAF7215F5F9CF031F00D768CAAA9C953AB802470FD27CA2AB51E111927C6585B8EB576831F3014DE57BC6CF8024F8075CE41
            Malicious:false
            Reputation:low
            Preview:#version 110..uniform vec4 uniform_color;.uniform float emission_factor;..// x = tainted, y = specular;.varying vec2 intensity;.//varying float drop;.varying vec4 world_pos;..void main().{. if (world_pos.z < 0.0). discard;. gl_FragColor = vec4(vec3(intensity.y) + uniform_color.rgb * (intensity.x + emission_factor), uniform_color.a);.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):1712
            Entropy (8bit):5.383704912849795
            Encrypted:false
            SSDEEP:24:TAVMSODiHIo+kEQQ64BbU9VlW0MJHdZ8gGJbWn6fxUEdPp4benVb4:sVMOoo+5/m9jWVAfySlP4qVk
            MD5:B554DAA6B3B9162D0CAB4D778B2365D4
            SHA1:B1266B6A8C1CF4AD5B60CE64BD7592396645C4BF
            SHA-256:256AB3468E1DA7F290D8CEBC58E500BD9397BFFF466E54A27F54A2C2F483CFE4
            SHA-512:3A3168F8CB3D834A2763ADAB8AE8DB57D3EFB9DF8B27DD053D0D0E7B9722F67D154C1FCCE670EF4AFAB8A8A2E9B08B1F774A68530C4A89172079527C92C28B70
            Malicious:false
            Reputation:low
            Preview:#version 110..#define INTENSITY_CORRECTION 0.6..// normalized values for (-0.6/1.31, 0.6/1.31, 1./1.31).const vec3 LIGHT_TOP_DIR = vec3(-0.4574957, 0.4574957, 0.7624929);.#define LIGHT_TOP_DIFFUSE (0.8 * INTENSITY_CORRECTION).#define LIGHT_TOP_SPECULAR (0.125 * INTENSITY_CORRECTION).#define LIGHT_TOP_SHININESS 20.0..// normalized values for (1./1.43, 0.2/1.43, 1./1.43).const vec3 LIGHT_FRONT_DIR = vec3(0.6985074, 0.1397015, 0.6985074);.#define LIGHT_FRONT_DIFFUSE (0.3 * INTENSITY_CORRECTION)..#define INTENSITY_AMBIENT 0.3..uniform mat4 volume_world_matrix;.// x = tainted, y = specular;.varying vec2 intensity;.varying vec4 world_pos;..void main().{. // First transform the normal into camera space and normalize the result.. vec3 normal = normalize(gl_NormalMatrix * gl_Normal);. . // Compute the cos of the angle between the normal and lights direction. The light is directional so the direction is constant for every vertex.. // Since these two are normalized the co
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):1080
            Entropy (8bit):5.01414311109514
            Encrypted:false
            SSDEEP:24:qMS4WIupCA/tdVlW0MJHdhyQ1ulWmaztPY/L+o/nf7Flm:qM88StdjWVaW4z/Pnfu
            MD5:D71FED4DE49CB1497A54F714F69F115A
            SHA1:55CB00F8B4D0CC0F450E8608ABE9974076D052FB
            SHA-256:4205606CB8FA7D711BDBD56CC839BF798F2CCE45F1FDAD4293DDC75E129CB130
            SHA-512:AC28C35599A8A97F57867B3CF41ECF14CEE3365CD71FB72A6608D0FEDDC7B9133E12F481DD870A91DC22051AB5360881408A5DC90D071D455FAD2C003FE4780D
            Malicious:false
            Reputation:low
            Preview:#version 110..// normalized values for (-0.6/1.31, 0.6/1.31, 1./1.31).const vec3 LIGHT_TOP_DIR = vec3(-0.4574957, 0.4574957, 0.7624929);.const vec3 LIGHT_FRONT_DIR = vec3(0.0, 0.0, 1.0);..// x = ambient, y = top diffuse, z = front diffuse, w = global.uniform vec4 light_intensity;.uniform vec4 uniform_color;..varying vec3 eye_normal;..void main().{. vec3 normal = normalize(eye_normal);.. // Compute the cos of the angle between the normal and lights direction. The light is directional so the direction is constant for every vertex.. // Since these two are normalized the cosine is the dot product. Take the abs value to light the lines no matter in which direction the normal points.. float NdotL = abs(dot(normal, LIGHT_TOP_DIR));.. float intensity = light_intensity.x + NdotL * light_intensity.y;.. // Perform the same lighting calculation for the 2nd light source.. NdotL = abs(dot(normal, LIGHT_FRONT_DIR));. intensity += NdotL * light_intensity.z; .. gl_FragColo
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):162
            Entropy (8bit):4.637474692773325
            Encrypted:false
            SSDEEP:3:xQ3KCpjWgXMBKdFF5KW8WdZGvRXcPCJ0/hXcM5maiCJP5QAv:e3KCpqgXMBXId4vt0/hXcM4MPOK
            MD5:397C8A78530F68CA992A9FD206863BA9
            SHA1:B14F02F85E525AD516401609206FDE450C5EE033
            SHA-256:79B8676972A47B3C220630A30753F9A945AECAF7249CC1F8FF5BAA23AE78530C
            SHA-512:5D8F0FF4ECC264AD74D735118D8B8818E566F52A4055D28FDB49C8D176198E32943F72165BECEAD0539514080AD14FC9DFEA8B2B3D35898C342BBA8B3C066F4B
            Malicious:false
            Reputation:low
            Preview:#version 110..varying vec3 eye_normal;..void main().{. gl_Position = gl_ModelViewProjectionMatrix * gl_Vertex;. eye_normal = gl_NormalMatrix * gl_Normal;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):1883
            Entropy (8bit):4.894798934625289
            Encrypted:false
            SSDEEP:48:hm8istp7S7HoQYlbQ60L6X5LaadQi3p3/8g:hmqtpm7HoFQ6zQxitB
            MD5:5D07EFB20D04B61BB45D8220D489C2D1
            SHA1:5EE402556C5EE9FC824F148CD2E17634AF75B7EA
            SHA-256:407993B55298FB9C51F4EA4D69E2C8FF809CB67652F7BB3BDD12C5CBE442D058
            SHA-512:C0A72B75B677B8BAF3C2CB5025851957A117DAE6CBB2AC3183E9FFA635740139C073ED11377618EF61E2D4EDA868D9E57FDEAA29AEE3D3699703A3675CC4085A
            Malicious:false
            Reputation:low
            Preview:#version 110..#define M_PI 3.1415926535897932384626433832795..// 2D texture (1D texture split by the rows) of color along the object Z axis..uniform sampler2D z_texture;.// Scaling from the Z texture rows coordinate to the normalized texture row coordinate..uniform float z_to_texture_row;.uniform float z_texture_row_to_normalized;.uniform float z_cursor;.uniform float z_cursor_band_width;..// x = tainted, y = specular;.varying vec2 intensity;..varying float object_z;..void main().{. float object_z_row = z_to_texture_row * object_z;. // Index of the row in the texture.. float z_texture_row = floor(object_z_row);. // Normalized coordinate from 0. to 1.. float z_texture_col = object_z_row - z_texture_row;. float z_blend = 0.25 * cos(min(M_PI, abs(M_PI * (object_z - z_cursor) * 1.8 / z_cursor_band_width))) + 0.25;. // Calculate level of detail from the object Z coordinate.. // This makes the slowly sloping surfaces to be shown with high detail (with stripes),. //
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C source, ASCII text
            Category:dropped
            Size (bytes):1909
            Entropy (8bit):5.328246142677428
            Encrypted:false
            SSDEEP:24:TAXSODiHITFkSCooQQyf4bAbU9VlW0MJHdZ8gGJbWn6fxUEdPJnbeeUVXts/8e4:sXOoTFIRR9jWVAfySljnqe49s/89
            MD5:62B4253D790BB5ED291D48F1D5D3A249
            SHA1:B722CEFE6B1F74B860B49236DF7880D28FFA12E7
            SHA-256:57A449C4331FCAC0F08A9465FB8320037E4C0FAA8F35BF73B30502A7652D4261
            SHA-512:46E48A2D52CE2C85E4BA155826FAFA7732288D517FB2D749CCD330ACCB475184133E08D2B2C3BED5CDACBD8000B1556774DD312D34A6089E8511D8ACDDFFD33A
            Malicious:false
            Reputation:low
            Preview:#version 110..#define INTENSITY_CORRECTION 0.6..const vec3 LIGHT_TOP_DIR = vec3(-0.4574957, 0.4574957, 0.7624929);.#define LIGHT_TOP_DIFFUSE (0.8 * INTENSITY_CORRECTION).#define LIGHT_TOP_SPECULAR (0.125 * INTENSITY_CORRECTION).#define LIGHT_TOP_SHININESS 20.0..const vec3 LIGHT_FRONT_DIR = vec3(0.6985074, 0.1397015, 0.6985074);.#define LIGHT_FRONT_DIFFUSE (0.3 * INTENSITY_CORRECTION).//#define LIGHT_FRONT_SPECULAR (0.0 * INTENSITY_CORRECTION).//#define LIGHT_FRONT_SHININESS 5.0..#define INTENSITY_AMBIENT 0.3..uniform mat4 volume_world_matrix;.uniform float object_max_z;..// x = tainted, y = specular;.varying vec2 intensity;..varying float object_z;..void main().{. // First transform the normal into camera space and normalize the result.. vec3 normal = normalize(gl_NormalMatrix * gl_Normal);. . // Compute the cos of the angle between the normal and lights direction. The light is directional so the direction is constant for every vertex.. // Since these two are n
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):58
            Entropy (8bit):4.1704930126977935
            Encrypted:false
            SSDEEP:3:RGSBNGJrNAcpLwLVrSP:BGQ3VWP
            MD5:C69648238C10BADB05E07E08C83995CC
            SHA1:DF602DC820BA93617AC13A03B7EBDB176AF70FD0
            SHA-256:FCEA382A8E290A653B0CE571D95BD5A22F67C97FECA9C3F4BC27CDBF8D482C4C
            SHA-512:9AA44B837207B70A068C3F1352FABFA9B8276CA28FBF33E4D9FDCC57AE6FA53748980A89A68AAD0B7EE29FE07EC5C90982374F5180EB01C3B037768939AB26DB
            Malicious:false
            Reputation:low
            Preview:#### TODO:.We are creating these contents, please wait ...
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (20709), with no line terminators
            Category:dropped
            Size (bytes):20709
            Entropy (8bit):5.02864298853138
            Encrypted:false
            SSDEEP:192:rU0AFk6l31OQtvdtnN3HkAtNetZmoi/ki4C4/HKDhhR8EDJtZM8Yy5T3LlJtpUWf:di315HHc/i/kiTYKWETcE
            MD5:E83BED244C3577297131435D2B0B5FA5
            SHA1:110605FE814CEEDD52E14D625B2625739EB88557
            SHA-256:5A35838EC138A4EBD0AA160957EDFCDB5E746C9EF8C34A6617E2FC6DF0530BF0
            SHA-512:C8CE2526317574AEBC08386D7F74E2379F0E9234667A9DFE1CC1354D5956AAC5EE86361B7A13488667126054B48E38DA35C06C7F5F29A505B89684D255B53872
            Malicious:false
            Reputation:low
            Preview:html{font-family:sans-serif;-ms-text-size-adjust:100%;-webkit-text-size-adjust:100%}body{margin:0}article,aside,details,figcaption,figure,footer,header,hgroup,main,menu,nav,section,summary{display:block}audio,canvas,progress,video{display:inline-block;vertical-align:baseline}audio:not([controls]){display:none;height:0}[hidden],template{display:none}a{background-color:transparent}a:active,a:hover{outline:0}abbr[title]{border-bottom:1px dotted}b,strong{font-weight:700}dfn{font-style:italic}h1{font-size:2em;margin:.67em 0}mark{background:#ff0;color:#000}small{font-size:80%}sub,sup{font-size:75%;line-height:0;position:relative;vertical-align:baseline}sup{top:-.5em}sub{bottom:-.25em}img{border:0}svg:not(:root){overflow:hidden}figure{margin:1em 40px}hr{-webkit-box-sizing:content-box;-moz-box-sizing:content-box;box-sizing:content-box;height:0}pre{overflow:auto}code,kbd,pre,samp{font-family:monospace,monospace;font-size:1em}button,input,optgroup,select,textarea{color:inherit;font:inherit;margi
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:HTML document, ASCII text
            Category:dropped
            Size (bytes):881
            Entropy (8bit):4.698067908174358
            Encrypted:false
            SSDEEP:24:0pcIOuptNBGNVOAdbMp/u+F89KGKskuSd4Nu:0wupCdI8HbwCNu
            MD5:B2BABBC43CB6BF7B735612A23C8CCFE5
            SHA1:03EE565B171DE864A9B6B9DA8C0B6F707B2C1B2F
            SHA-256:4F91AF1D404E28D06CA545A7B68D271ACF1D05C0F39B46889E42837A92763F96
            SHA-512:EE39ACF4AC8A5616BD83925CF8A4555F9C9BEFE0F80A142977D6179FCFD56B05BC12DB8771316C75902A3AE9A6FD7AFD2F9503B4CE94878E489033FD9B8D2D72
            Malicious:false
            Reputation:low
            Preview:<!doctype html>.<html>. <head>. <meta charset="UTF-8" />. <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no" />. <link rel="stylesheet" href="./main.css" />. <script src="./main.js"></script>. </head>. <body style="background-color: #F8F8F8;">. <div class="container markdown-body" id="contents"></div>. </body>. <script>. const resizeOberver = new ResizeObserver((entities) => {. const height = entities[0].contentRect.height. document.title = height.toFixed(). }). resizeOberver.observe(document.querySelector('#contents')). window.showMarkdownFile = function (file) {. $.get(file, function( data ) {. window.showMarkdown(encodeURIComponent(data));. });. }. </script>.</html>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Unicode text, UTF-8 text, with very long lines (630)
            Category:dropped
            Size (bytes):60062
            Entropy (8bit):5.738634641243996
            Encrypted:false
            SSDEEP:1536:PWz5ePzE5Y4AlN3CgNT7mcwAXdC6yhsI5MHWR:ezQzE5MggNT7zdvy6IKHWR
            MD5:A0B7BEC48AD0B3B460CF152FAABBE279
            SHA1:AC06876F8B6105CD1EE7755E66383E5F9176A2FC
            SHA-256:6E76A841B75CBFD220196B9C46AB45713F9BDBC133DCC6512F1ABF4A147BA095
            SHA-512:FD2246183116A0D627E86C72FC38F038FDA11CA90E8357AF873B01E305E379544297BEBEF1847079E74BE01287F0843100BC99DD5E770CE2C5A35F6BA098F852
            Malicious:false
            Reputation:low
            Preview:var LangText={. "en": {. "t1": "Welcome to Bambu Studio",. "t2": "Bambu Studio will be setup in several steps. Let's start!",. "t3": "User Agreement",. "t4": "Disagree",. "t5": "Agree",. "t6": "We kindly request your help to improve everyone's printing.<br/>Come and Join our Customer Experience Improvement Program",. "t7": "Join our Customer Experience Improvement Program",. "t8": "Back",. "t9": "Next",. "t10": "Printer Selection",. "t11": "All",. "t12": "Clear all",. "t13": "mm nozzle",. "t14": "Filament Selection",. "t15": "Printer",. "t16": "Filament type",. "t17": "Vendor",. "t18": "error",. "t19": "At least one filament must be selected.",. "t20": "Do you want to use default filament ?",. "t21": "yes",. "t22": "no",. "t23": "Release note",. "t24": "Get Started",. "t25": "Finish",. "t26": "Login",.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):400
            Entropy (8bit):4.757177390806721
            Encrypted:false
            SSDEEP:12:Uc8Ok9vM2SMGRDqQ1gXOEdwj+388aN5VdhsXbhsY:U9vMuGRJSe15VdWXbWY
            MD5:578F63FA678FF78DE43D32A59D664C9C
            SHA1:34D02DAAF6FB8299ED1BA1E877B2972037FE7D64
            SHA-256:29AC1D56D7BBC387E46FA0641FA31BCAA02115DFC58CE85C185C597ED8490BCB
            SHA-512:1C3E820A565D6EF240C094FAF328FEADA4DD0A6E25DD93B0555EE902C83D6E76ED733840E22C41202F9ACCD4DB0DDC14C732F3A69C8E77F6F6528FB29D5CD6C1
            Malicious:false
            Reputation:low
            Preview:body {. background-color:#4c4c54;. font-family: Arial, sans-serif;. display: flex;. justify-content: center;. align-items: center;. height: 100vh;. margin: 0;.}...container {. text-align: center;. padding: 30px;. border-radius: 10px;. background-color: #272727;. box-shadow: 0 4px 6px rgba(39, 39, 39, 0.1);.}..h1 {. color: #ffffff;.}..p {. color: #ffffff;.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):345
            Entropy (8bit):4.696069711948808
            Encrypted:false
            SSDEEP:6:2vU8hRQlzo0LhvM2jWB8VA7RXIiqQRr/gXOE/dwy++388hRKs/ysrd9Vf:v889vM2SMGRDqQ1gXOEdwj+388isPVf
            MD5:E93EF9CA9B99A93821F107660849FF8B
            SHA1:DA5DD77A0EE818D07C0C24075C7C7DCCF819891E
            SHA-256:B9D71776039A4259F6B1D9C5A1C065B9BBCCAC7DFEBF78283B6BB8F2204D7509
            SHA-512:090EF2ECC59ECE54CF6D31062579AE346A17FBA1B48BF32891A4A35FA69E908D7189B69DE5FEBA23147FA65747183564CD9A5EDE056DC6A79FEF80E366C7AB6F
            Malicious:false
            Reputation:low
            Preview:body.{. background-color:#eeeeee;. font-family: Arial, sans-serif;. display: flex;. justify-content: center;. align-items: center;. height: 100vh;. margin: 0;.}...container {. text-align: center;. padding: 30px;. border-radius: 10px;. background-color: #ffffff;. box-shadow: 0 4px 6px rgba(39, 39, 39, 0.1);.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:HTML document, ASCII text
            Category:dropped
            Size (bytes):1020
            Entropy (8bit):4.857431810417764
            Encrypted:false
            SSDEEP:24:0phAC3Z13EC6vV25qXNVvP5uNVvP5TLVvP5HV4NwvsguMKMnD1:0HHE3w3BVYNEKk
            MD5:3004EDA8D3016711EC60D4C2EA455254
            SHA1:4514CF42300BFF010057527AEB4CE4C85A70F2F7
            SHA-256:11DE8C66DC81D16495D5C365C8656CBF231F2606039FE82BF5C87A0A50904489
            SHA-512:4232A827495C564D61AECBB0182E8415B2A1967FE5BB4D73799493113056FA64F3439155F29BD5CA5E7CE89AE5C647485998AA8ED85C6761C75A8276F7BAFD52
            Malicious:false
            Reputation:low
            Preview:<!doctype html>.<html>.<head>.<meta charset="utf-8">.<meta name="viewport" content="width=device-width, initial-scale=1.0">.<title>Printer Connection Required</title>.<link rel="stylesheet" type="text/css" href="css/home.css" />.<link rel="stylesheet" type="text/css" href="css/dark.css" />.<script type="text/javascript" src="../data/text.js"></script>..<script type="text/javascript" src="../homepage/js/jquery-3.6.0.min.js"></script>.<script type="text/javascript" src="../homepage/js/json2.js"></script>.<script type="text/javascript" src="../homepage/js/globalapi.js"></script>.<script type="text/javascript" src="../homepage/js/home.js"></script>.</head>.<body onLoad="OnInit()">. <div class="container">. <h1 class="trans">Printer Connection</h1>. <p class="trans">Please set up your printer connection to view the device.</p>. <img src="setup_connection.gif" alt="Printer connection setup demonstration" style="max-width: 100%; height: auto; display: block;"/>. </d
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:GIF image data, version 89a, 1280 x 720
            Category:dropped
            Size (bytes):948959
            Entropy (8bit):7.9683077256209
            Encrypted:false
            SSDEEP:24576:1CPwx1J1o9BoNoLuoeAipzGWssMSspEjH0l0Aka:1CPwpuoNoLuoKzGWsHrTD
            MD5:CEFFF97A9246F1E78C7EA8F08D0DBEA0
            SHA1:BD75F7A85F771149C100BB56097E2B6B0C95608C
            SHA-256:01D158B686EE71D7EA0D00AB6031DA7C448273278AC477D57CB8E856F9191A61
            SHA-512:5F1A90E601D5A719F8574A41434E61646FC5855D19B0F9A19B2BB4C9869E9FF3E5149430B034283B55C4ADE2FCCA281D2B708CF07ABD65D49A95220FC914F220
            Malicious:false
            Reputation:low
            Preview:GIF89a....x..!..NETSCAPE2.0.....!.......,...............$*,&-/%-/&.6&.;(/6216M0=f4;b=@_GGWONRSSSUURUURUURVVUWWPY_L_lGn{A.x&.j..d..I..B..A..A..6..4..:._y*L./C|9AR;CE<BD;FE;DFIPQdedcgeeofimknptpsrqtrtus~~|}.}}.~|..............~..c..L..p..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................t.e.g..[..P.{@.k6.X1.?"............H......*\.aC.-.J.H....3j.... C..I...(S.\...0c.IS%..8.B....@...J...H.*]...NG.J...X.j....`.B.;q*..A..9....!9..K...x......X.+j..L....f/.........P....*)......
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (349), with no line terminators
            Category:dropped
            Size (bytes):349
            Entropy (8bit):4.505703524726495
            Encrypted:false
            SSDEEP:6:PuMRr9P8MsvAF7vXSTJjWpuMRrziywlJ8MsC6XK/9MlevsuMRrziyuA6TLP8MsVn:Pui9P8LA7/vuimyq8RK1Uosuimyu7z8J
            MD5:4C7753C3C1B16C658BF2188507FADD94
            SHA1:58282D269808402B3052EEA0041116AAF05D4F53
            SHA-256:3983AAD5C59259C713B48C123FCD8672342BAE168C6A0B1A85FC419905F72708
            SHA-512:0825575BBB508FA71B52AC92B7E6AEB13363869233FD489EF32FC04899F8F74E541FBFE891BB70169A1B4CF52035B9FDA49D6CB164EF56EB68273A028DED883A
            Malicious:false
            Reputation:low
            Preview:.swiper-virtual.swiper-css-mode .swiper-wrapper::after{content:'';position:absolute;left:0;top:0;pointer-events:none}.swiper-virtual.swiper-css-mode.swiper-horizontal .swiper-wrapper::after{height:1px;width:var(--swiper-virtual-size)}.swiper-virtual.swiper-css-mode.swiper-vertical .swiper-wrapper::after{width:1px;height:var(--swiper-virtual-size)}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):371
            Entropy (8bit):4.478382400624059
            Encrypted:false
            SSDEEP:6:PuMRr9C8MsMwR6YAFFMveHhITJyerwlJ8MsMwAShXK/9MleamruA6TLP8MsMwkzy:Pui9C8AwQYAEvwherq8AwASY1U/mru7O
            MD5:D9C6F9C09634B0067405FE8EF5D7A3D8
            SHA1:3B70863F8B603B99E98B46484D49AB478B0A3DA2
            SHA-256:EF038A7797AC75EED63CF4A2479C764CB9F56FD9360D8346F0E18B494C689CF5
            SHA-512:5E6C2E8858497C4AEB7EF0EDBF5415EC9F3FE99C7B60573C1F51D5E8CC41D852C8E88B4C6A90D53D13D59EACE0EEAD627E2F8E6B0020179820011B67D83483A3
            Malicious:false
            Reputation:low
            Preview:.swiper-virtual.swiper-css-mode {. .swiper-wrapper::after {. content: '';. position: absolute;. left: 0;. top: 0;. pointer-events: none;. }. &.swiper-horizontal .swiper-wrapper::after {. height: 1px;. width: var(--swiper-virtual-size);. }. &.swiper-vertical .swiper-wrapper::after {. width: 1px;. height: var(--swiper-virtual-size);. }.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):20519
            Entropy (8bit):4.86339195872396
            Encrypted:false
            SSDEEP:384:ds5yTUrmDarPD6VuM5ISQlx0OlxoPlq6llqYbihLs3G/JzLWcw39B78Lj:O5SMOarL6VLInzn3PLs380cG9Z8Lj
            MD5:2F5662CA8D1A2BD016AFD701E6AFF630
            SHA1:6095DAC6443D6C87C8287908208F7595353D5887
            SHA-256:BBC08BE23DC2C13B9A6C5A65CF7DF13844CB3CF34DEBEEA8219A9A3477C8DA38
            SHA-512:2F46731E8C8E286591F22158C8EFD3AC55E42951EFA9AAEB56F1B1804E71ECBF456FDF67C1561A56F9ADEBCF18495A4CFB94EFED8F2E4838CDEFB429F31CE4E2
            Malicious:false
            Reputation:low
            Preview:import { getWindow } from 'ssr-window';.import $ from '../../shared/dom.js';.import { getTranslate } from '../../shared/utils.js';.export default function Zoom({. swiper,. extendParams,. on,. emit.}) {. const window = getWindow();. extendParams({. zoom: {. enabled: false,. maxRatio: 3,. minRatio: 1,. toggle: true,. containerClass: 'swiper-zoom-container',. zoomedSlideClass: 'swiper-slide-zoomed'. }. });. swiper.zoom = {. enabled: false. };. let currentScale = 1;. let isScaling = false;. let gesturesEnabled;. let fakeGestureTouched;. let fakeGestureMoved;. const gesture = {. $slideEl: undefined,. slideWidth: undefined,. slideHeight: undefined,. $imageEl: undefined,. $imageWrapEl: undefined,. maxRatio: 3. };. const image = {. isTouched: undefined,. isMoved: undefined,. currentX: undefined,. currentY: undefined,. minX: undefined,. minY: undefined,. maxX: undefined,. maxY: undefined,. width
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):293
            Entropy (8bit):4.649592514111089
            Encrypted:false
            SSDEEP:6:PiKvQt/c5+qFvxjrC8VA3Xr2m28IRExFIwRtuFKplgOadFS:PiKv0cEivx/CMqXqDREDrbKK3gOa6
            MD5:B39FAE158DF03BD34AEFF587635AF840
            SHA1:4DB6FEACBDCB58DD4A38AA4597096735EACC82C2
            SHA-256:023916787907241C299DC33707E4D84B48D82EF990BDFB1F0AFE0C22D9D34437
            SHA-512:2E22A713FD919C955A57077EEBE15D33954687A07CEB717305FFDB650E0F1D8CDCC80FC63091C248E14097A27F858EF8DE03713A6E9E51627BB3404AFB8CE9A6
            Malicious:false
            Reputation:low
            Preview:.swiper-zoom-container {. width: 100%;. height: 100%;. display: flex;. justify-content: center;. align-items: center;. text-align: center;.. > img,. > svg,. > canvas {. max-width: 100%;. max-height: 100%;. object-fit: contain;. }.}...swiper-slide-zoomed {. cursor: move;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with no line terminators
            Category:dropped
            Size (bytes):286
            Entropy (8bit):4.72890207385394
            Encrypted:false
            SSDEEP:6:PiKvQzLf2G6Gej1V/mziKvQ3uiKvQ9/zpiKvQn2BR0xRfFyOg35Z:PiKvg7oGexV/mziKvsuiKvwiKv8mRgLI
            MD5:3C580C85316E61D3615B719492476599
            SHA1:19CB2DFF1E80B23B2BAE39F38C43D2340CA27AE4
            SHA-256:63FB69A307DACCC86C8553577AECAEF98CF9DF6373614B4D361546919B29DA84
            SHA-512:86D10AB002264493DDF15AB12051CC14BC44BBBB688563565C4C9FBEAA98785F6EEAF4E22C1A43F58829C8514266EE7E050142C56240F35894A095BE5DA872E6
            Malicious:false
            Reputation:low
            Preview:.swiper-zoom-container{width:100%;height:100%;display:flex;justify-content:center;align-items:center;text-align:center}.swiper-zoom-container>canvas,.swiper-zoom-container>img,.swiper-zoom-container>svg{max-width:100%;max-height:100%;object-fit:contain}.swiper-slide-zoomed{cursor:move}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):293
            Entropy (8bit):4.649592514111089
            Encrypted:false
            SSDEEP:6:PiKvQt/c5+qFvxjrC8VA3Xr2m28IRExFIwRtuFKplgOadFS:PiKv0cEivx/CMqXqDREDrbKK3gOa6
            MD5:B39FAE158DF03BD34AEFF587635AF840
            SHA1:4DB6FEACBDCB58DD4A38AA4597096735EACC82C2
            SHA-256:023916787907241C299DC33707E4D84B48D82EF990BDFB1F0AFE0C22D9D34437
            SHA-512:2E22A713FD919C955A57077EEBE15D33954687A07CEB717305FFDB650E0F1D8CDCC80FC63091C248E14097A27F858EF8DE03713A6E9E51627BB3404AFB8CE9A6
            Malicious:false
            Reputation:low
            Preview:.swiper-zoom-container {. width: 100%;. height: 100%;. display: flex;. justify-content: center;. align-items: center;. text-align: center;.. > img,. > svg,. > canvas {. max-width: 100%;. max-height: 100%;. object-fit: contain;. }.}...swiper-slide-zoomed {. cursor: move;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1077
            Entropy (8bit):5.107556568523812
            Encrypted:false
            SSDEEP:24:zGrmJHHH0yN3gtsHw1hC09QHOsUv4eOk4/+/m3oqLFh:6aJHlxE3dQHOs5exm3ogFh
            MD5:A734CABB77D0418895B3B2BACCB8379A
            SHA1:05CC6348BA043EA14FFD3C83D732D89AA47C4FCA
            SHA-256:D3A872D7E699D3C4409583ABC70C5BDFC3D9332837A33334879B0175FE858752
            SHA-512:172067B6529049C61FB82D8DAF61F3BCCA3CAF91213A064D6159CFEDE09A13B0B38FA3BFB66F6B9EE1565EB85892852840CC3AE39EDA2D09E912890557E2A735
            Malicious:false
            Reputation:low
            Preview:MIT License..Copyright (c) 2017 Vladimir Kharlampidi..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR I
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, Unicode text, UTF-8 text, with very long lines (372)
            Category:dropped
            Size (bytes):1406
            Entropy (8bit):5.101618096701846
            Encrypted:false
            SSDEEP:24:L2E31+km6qX7qSPPLCoXnSvOo3tFsUPt0gJBUVd2V/bYa6I31U1sG4Ra79aHTg:L0k22SPPRmOMFsEJGd2+g1U1sGB9Qc
            MD5:EF88E6C36229069A4291E1438A55FB4E
            SHA1:19E271EA326BFBCE10E7E580A7FC13AD447CD492
            SHA-256:E67B6FFEF95C525DC75ED56D4F56EFABB4F233E32A767BE3C4C93BEE764528C8
            SHA-512:FC08C4D4A4A6C1CDA30ED46C936A1B66DAE3AFE1D0E1C44250A2B3EC3D6F3A6206C82CE071152DD867181AA875EB857E716EBC7F10F15A47A8B489F64B0DE93C
            Malicious:false
            Reputation:low
            Preview:# Dom7..### Minimalistic JavaScript library for DOM manipulation, with a jQuery-compatible API..Dom7 - is the default DOM manipulation library built-in [Framework7](https://framework7.io). It utilizes most edge and high-performance methods for DOM manipulation. You don.t need to learn something new, its usage is very simple because it has the same syntax as well known jQuery library with support of the most popular and widely used methods and jQuery-like chaining...See [Framework7 Dom7](https://framework7.io/docs/dom7.html) documentation for usage examples and available methods...## Installation..Dom7 can be installed with NPM:..```.npm install dom7 --save.```..## Usage..```js.// import Dom7 and methods you need.import { $, addClass, removeClass, toggleClass, on } from 'dom7';..// install methods.$.fn.addClass = addClass;.$.fn.removeClass = removeClass;.$.fn.toggleClass = toggleClass;.$.fn.on = on;..// use.$('p').addClass('custom-paragraph');..$('p').on('click', function() {. $(this
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):25554
            Entropy (8bit):4.734131429067365
            Encrypted:false
            SSDEEP:768:YKjRz+LzpaxIJpaxImJkaX/VZwUm3u+RvtuLn43R/Ajmz0Bm+Xi86DeL+k0Kwf5P:YKjRz+LzpaxIJpaxImJkaqRvtuLn43RT
            MD5:372FE91610F368F0299B0576FD427455
            SHA1:F47DEAC55F28A384890BBD790DBC52483D5B2ECA
            SHA-256:AD117B97B2EB65DAEEABF0ADB13573A8F1D12D5CE21C312EB7EB588106B92560
            SHA-512:390B2C2D656ED32D73B0D5C7E6AEB991FFF379CE966762DE402A3B2DD16DA183622DEDDC7F1B2527402543F9301D5B7A9F82B0A6E686A553DBE14FD12F9830E7
            Malicious:false
            Reputation:low
            Preview:export interface Dom7Array {. /* ====== DEFAULT ARRAY METHODS ====== */. /**. * Gets or sets the length of the array. This is a number one higher than the highest element defined in an array.. */. length: number;.. /**. * Removes the last element from an array and returns it.. */. pop(): Element | undefined;. /**. * Appends new elements to an array, and returns the new length of the array.. * @param items New elements of the Array.. */. push(...items: Element[]): number;. /**. * Combines two or more arrays.. * @param items Additional items to add to the end of array1.. */. concat(...items: ConcatArray<Element>[]): Element[];. /**. * Combines two or more arrays.. * @param items Additional items to add to the end of array1.. */. concat(...items: (Element | ConcatArray<Element>)[]): Element[];. /**. * Adds all the elements of an array separated by the specified separator string.. * @param separator A string used to separate one element of an array
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text, with very long lines (741)
            Category:dropped
            Size (bytes):35134
            Entropy (8bit):4.715964198408208
            Encrypted:false
            SSDEEP:768:hyYK0LEKPgxMy30fG3+qRNo8oQg5cGTRg6mOTOGfmyt2eo:ZK0LEKPkT30g+qReFQg5cGFjmOTOGfmZ
            MD5:6A52B41365648D727E5B9069CF245210
            SHA1:E3BA444C222EC2F49850455F1F0E6FB3C2A29ED4
            SHA-256:9603C1CF57CEF5865C3BA563F3E1CAF9E3755DB43CFB69ECAC8AFF505D31CCF3
            SHA-512:1E431F9AF5A4954689C65EDD69577C23074EE13272B99352DC8137C0D3DE1F33BF57E7AFCA62B933B3321C7051C1F7FC5579796AE5C37B9F7F755C70975887D4
            Malicious:false
            Reputation:low
            Preview:/**. * Dom7 4.0.1. * Minimalistic JavaScript library for DOM manipulation, with a jQuery-compatible API. * https://framework7.io/docs/dom7.html. *. * Copyright 2021, Vladimir Kharlampidi. *. * Licensed under MIT. *. * Released on: October 27, 2021. */.import { getWindow, getDocument } from 'ssr-window';../* eslint-disable no-proto */.function makeReactive(obj) {. const proto = obj.__proto__;. Object.defineProperty(obj, '__proto__', {. get() {. return proto;. },.. set(value) {. proto.__proto__ = value;. }.. });.}..class Dom7 extends Array {. constructor(items) {. super(...(items || []));. makeReactive(this);. }..}..function arrayFlat(arr = []) {. const res = [];. arr.forEach(el => {. if (Array.isArray(el)) {. res.push(...arrayFlat(el));. } else {. res.push(el);. }. });. return res;.}.function arrayFilter(arr, callback) {. return Array.prototype.filter.call(arr, callback);.}.function arrayUnique(arr) {. const uniqueArray = [];..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):45189
            Entropy (8bit):4.391878810976434
            Encrypted:false
            SSDEEP:768:lNgo60L0a/wxMCH0PWveKBNIsIwAZMWDhgqG+TO2fWyNm+c:lH60L0a/UjH0ueKBelwAZMWFzG+TO2f+
            MD5:CED5B0FFC53BB86B7FA3F6D6B8F1770F
            SHA1:F3F966FAA13957B0E7722604A60F533181896C27
            SHA-256:7FB103905BEA2C8EC3084DECB4A57B4682D40C4406BAF76404D2929D5A2F079D
            SHA-512:591058F5A83C17187B211C81F4D145AF56839FD43B6D097CA1342601BC4FEC1A22023AA431C9A8C5B7C39B9130F89636F097E7E44A90500C180441A98AE95405
            Malicious:false
            Reputation:low
            Preview:/**. * Dom7 4.0.1. * Minimalistic JavaScript library for DOM manipulation, with a jQuery-compatible API. * https://framework7.io/docs/dom7.html. *. * Copyright 2021, Vladimir Kharlampidi. *. * Licensed under MIT. *. * Released on: October 27, 2021. */.(function (global, factory) {. typeof exports === 'object' && typeof module !== 'undefined' ? module.exports = factory() :. typeof define === 'function' && define.amd ? define(factory) :. (global = typeof globalThis !== 'undefined' ? globalThis : global || self, global.Dom7 = factory());.}(this, (function () { 'use strict';.. /**. * SSR Window 4.0.0. * Better handling for window object in SSR environment. * https://github.com/nolimits4web/ssr-window. *. * Copyright 2021, Vladimir Kharlampidi. *. * Licensed under MIT. *. * Released on: August 25, 2021. */.. /* eslint-disable no-param-reassign */. function isObject(obj) {. return obj !== null && typeof obj === 'object' && 'const
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):93313
            Entropy (8bit):5.061007244042799
            Encrypted:false
            SSDEEP:1536:mJYnuUpRvUXaGS30+DUvE3V9OqTEWjsGt3kziTcxi3+0P2xqyPYiiqmQh/3cyi3/:eYnuUpueD4iPMtc
            MD5:FB10837F7B300284C924B97B450E2D94
            SHA1:2A39C40985D39CEC5B401947CD8C8CA836EF7EDF
            SHA-256:08F2537666BA79176980B4A5A22A273886DDA28AE50B8B677F31DC92C840FE7B
            SHA-512:716C8FD9622EF1C6B746FAA9518ABBAAE31622FCC2239A16C66CB24CE24915A560234BA6356070601A18FD8C2500C57DB432DC1C6AE564D6968C881D511F073F
            Malicious:false
            Reputation:low
            Preview:{"version":3,"file":"dom7.js","sources":["../node_modules/ssr-window/ssr-window.esm.js","../src/dom7-class.js","../src/utils.js","../src/$.js","../src/methods.js","../src/scroll.js","../src/animate.js","../src/shortcuts.js","../src/dom7.bundle.js"],"sourcesContent":["/**\n * SSR Window 4.0.0\n * Better handling for window object in SSR environment\n * https://github.com/nolimits4web/ssr-window\n *\n * Copyright 2021, Vladimir Kharlampidi\n *\n * Licensed under MIT\n *\n * Released on: August 25, 2021\n */\n/* eslint-disable no-param-reassign */\nfunction isObject(obj) {\n return (obj !== null &&\n typeof obj === 'object' &&\n 'constructor' in obj &&\n obj.constructor === Object);\n}\nfunction extend(target = {}, src = {}) {\n Object.keys(src).forEach((key) => {\n if (typeof target[key] === 'undefined')\n target[key] = src[key];\n else if (isObject(src[key]) &&\n isObject(target[key]) &&\n Object.keys(src[key]).le
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (18664)
            Category:dropped
            Size (bytes):18953
            Entropy (8bit):5.157377623741089
            Encrypted:false
            SSDEEP:384:HP/TiDCwqRhgJDN4L2OX4W4KapyCIUYMD/BCWqWZIYfrwHl/npNxP/w3uu5HMORd:vLiaRGJjOX4W4JwD8/BCWqzyM/Cuu5Hb
            MD5:181FCA7557DD427A577D431309DCB50D
            SHA1:E2B98927259374065AA0B361F6DF7C1C47599222
            SHA-256:26A6102D47E52F9AE2CCAF726BBBD4B6AC18009DAFEBA0E2E8D879A9B3542571
            SHA-512:80253AD3BE3432BED654D908154BD32FFB816F7E09EB33E8E1371ED843C00001368A4344F6BA7A2BA2B8912B195331776BDBD6E9F0B33B00DC0A3262CA2AE01C
            Malicious:false
            Reputation:low
            Preview:/**. * Dom7 4.0.1. * Minimalistic JavaScript library for DOM manipulation, with a jQuery-compatible API. * https://framework7.io/docs/dom7.html. *. * Copyright 2021, Vladimir Kharlampidi. *. * Licensed under MIT. *. * Released on: October 27, 2021. */.!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?module.exports=e():"function"==typeof define&&define.amd?define(e):(t="undefined"!=typeof globalThis?globalThis:t||self).Dom7=e()}(this,(function(){"use strict";function t(t){return null!==t&&"object"==typeof t&&"constructor"in t&&t.constructor===Object}function e(n={},i={}){Object.keys(i).forEach((o=>{void 0===n[o]?n[o]=i[o]:t(i[o])&&t(n[o])&&Object.keys(i[o]).length>0&&e(n[o],i[o])}))}const n={body:{},addEventListener(){},removeEventListener(){},activeElement:{blur(){},nodeName:""},querySelector:()=>null,querySelectorAll:()=>[],getElementById:()=>null,createEvent:()=>({initEvent(){}}),createElement:()=>({children:[],childNodes:[],style:{},setAttribute(){},getElementsByT
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):67695
            Entropy (8bit):5.232749837215292
            Encrypted:false
            SSDEEP:1536:CeJdxvR99CViIV+nzBmhuhFKJYnuUpRvUXaGS30+DUvE3V9OqTEWjsGR:doVWnzBms2YnuUpum
            MD5:CC0C929F388305EAAA63CAE0C01AC9AA
            SHA1:8779FC8028F9B15AF12F50D1C778D8E4A92C3852
            SHA-256:FACFE7AAB2D644A62B6B3A9F0527ADF6C6556C807BCDEB1540AAADC9BFEC8C04
            SHA-512:39115AE7C575994E8029500C8F89EFF520E657C39879DA65DA1E8FEAEE981681CD64F0113ECAF0A7610581415D5AA3AC62DB69016B031D03EBBDC3A5ABEF09CC
            Malicious:false
            Reputation:low
            Preview:{"version":3,"sources":["../node_modules/ssr-window/ssr-window.esm.js","../src/dom7-class.js","../src/utils.js","../src/$.js","../src/methods.js","../src/scroll.js","../src/animate.js","../src/shortcuts.js","../src/dom7.bundle.js"],"names":["isObject","obj","constructor","Object","extend","target","src","keys","forEach","key","length","ssrDocument","body","addEventListener","removeEventListener","activeElement","blur","nodeName","querySelector","querySelectorAll","getElementById","createEvent","initEvent","createElement","children","childNodes","style","setAttribute","getElementsByTagName","createElementNS","importNode","location","hash","host","hostname","href","origin","pathname","protocol","search","getDocument","doc","document","ssrWindow","navigator","userAgent","history","replaceState","pushState","go","back","CustomEvent","this","getComputedStyle","getPropertyValue","Image","Date","screen","setTimeout","clearTimeout","matchMedia","requestAnimationFrame","callback","cancelAnimati
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1517
            Entropy (8bit):5.113068021241666
            Encrypted:false
            SSDEEP:24:tWK17UDMBDz2NvtxGk1e2DODCfBtqgStJC2E31OZ4dNN6o2H2Ck+/61x:tWK17UDMBX2NvtxGce2y62r3ChOZYNsE
            MD5:F15AE1F4E3EE571E216F36ACF6F7E38F
            SHA1:436456160B84C5CF5D7A380E9B490F4F747F91F0
            SHA-256:AD29CFFE3A755F531F59F86D65FB9624D2E111203793291B29A8E252EAC9BD0E
            SHA-512:41A5965325310A2A6EFEC54D0E334A4CCB0E3FDEF460BE1C25AFB2C9447B49262E5B7B400412DEAF1007134552DAC66729DB6D762643C88303EE8930574419D7
            Malicious:false
            Reputation:low
            Preview:{. "_from": "dom7@^4.0.1",. "_id": "dom7@4.0.1",. "_inBundle": false,. "_integrity": "sha512-y/RWjw3gK3qQnZz6IqDaIoqH6+xBhcB3Wsh5HFwl0abwuO/NAgbSB31ZbxtBDcuDe8jAX5NYUNDLTx4Ul48sIw==",. "_location": "/swiper/dom7",. "_phantomChildren": {},. "_requested": {. "type": "range",. "registry": true,. "raw": "dom7@^4.0.1",. "name": "dom7",. "escapedName": "dom7",. "rawSpec": "^4.0.1",. "saveSpec": null,. "fetchSpec": "^4.0.1". },. "_requiredBy": [. "/swiper". ],. "_resolved": "https://registry.npmjs.org/dom7/-/dom7-4.0.1.tgz",. "_shasum": "821209df1bfdf97dd82b5156e50f7cb66b3f166c",. "_spec": "dom7@^4.0.1",. "_where": "C:\\Users\\Administrator\\node_modules\\swiper",. "author": {. "name": "Vladimir Kharlampidi". },. "bugs": {. "url": "https://github.com/nolimits4web/dom7/issues". },. "bundleDependencies": false,. "dependencies": {. "ssr-window": "^4.0.0". },. "deprecated": false,. "description": "Minimalistic JavaScript library for DOM m
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1077
            Entropy (8bit):5.107556568523812
            Encrypted:false
            SSDEEP:24:QGrmJHHH0yN3gtsHw1hC09QHOsUv4eOk4/+/m3oqLFh:XaJHlxE3dQHOs5exm3ogFh
            MD5:250E9BC8E4F186E19B57D26561B593B7
            SHA1:68DD3228D8109686CA02D39728D1A163237BD191
            SHA-256:584C59575E2A05F4F525EF584C89A6D41CA0E454EEEED4EF4CE04BECD5DFF1C1
            SHA-512:91EA1CA71D76137ACE0F543DCFBCF77B8817EB415CDD28593A009BD3C4E3A33DD3683A4AE524B6C424D319AA7F7579FED2DCBA492A559C9467D9A2F998A1D359
            Malicious:false
            Reputation:low
            Preview:MIT License..Copyright (c) 2018 Vladimir Kharlampidi..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR I
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1337
            Entropy (8bit):5.096364306840587
            Encrypted:false
            SSDEEP:24:QXFYz5Oq51svtNkeWW/UqNt3gQRPsKlkmRo79aHT2:Qex1svjWZItwQJsKO9QC
            MD5:9926BF58439285C5F18990D782379D5F
            SHA1:C0FFE76F5FCE2B9A832156C698DE2EBC765C65AC
            SHA-256:C1CECAEB7B3DEFA93A51DDE3DB146CC94A8AE73D57DD6C189A75D672BB5D0A6A
            SHA-512:E61CB264559ED353906BF4D8EEDB72E167263A04954CD271AA38D5A3C4B02BCFB5E9DF4079221A5D2545A7C8EDC20F37495141263B17C67AE0FAE9705BA50441
            Malicious:false
            Reputation:low
            Preview:# SSR Window..Better handling for `window` and `document` object in SSR environment...This library doesn't implement the DOM (like JSDOM), it just patches (or creates `window` and `document` objects) to avoid them to fail (throw errors) during server-side rendering...Was created for use in:..- [Dom7](https://github.com/nolimits4web/dom7).- [Swiper](https://github.com/nolimits4web/swiper).- [Framework7](https://github.com/framework7io/framework7)..## Installation..Library available on NPM:..```.npm i ssr-window.```..## Usage..```js.import { window, document } from 'ssr-window';..window.addEventListener('resize', () => {});..const div = document.querySelectorAll('div');.```..## Extending..If you rely on some window/document properties which are not included here, you can use `extend` helper to add them:..```js.import { window, document, extend } from 'ssr-window';..// add window.navigator.language.extend(window, {. navigator: {. language: 'en',. },.});..// add document.body.extend(d
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):1513
            Entropy (8bit):5.079894900682013
            Encrypted:false
            SSDEEP:24:tDh9RIMHDzyptxGkwWNODCfBXq2SZXFKONVyAU5yCL/nf1x:tDh9CMHXyptxGvWA68BZUON0b5yKNx
            MD5:5DF4A53CD13DF75A9F8386C9DF1CB016
            SHA1:5957B01DDAF330C1C59E6252D8E5908CA95D7A79
            SHA-256:E12F04DA4165BC8BA9B30307B66A8AE4647E53E5EF77611621613525A0AEE29B
            SHA-512:BA2974A63385A698764A9196F5DAD2C818EB50D422DF8FEA74A79C588CA21B2E1A85680A97D26168AF6CB0B152F83CB4B6254AA89AC67DB65B86384B76EC93E1
            Malicious:false
            Reputation:low
            Preview:{. "_from": "ssr-window@^4.0.1",. "_id": "ssr-window@4.0.1",. "_inBundle": false,. "_integrity": "sha512-5q936lkCk5Lg5hM6tG8Nutdym4vNiuFSWorslTzOn71PWb3Wnx44q/k2Ryn1LWA1G4FtxMzjywUFOiOxPkVGrA==",. "_location": "/swiper/ssr-window",. "_phantomChildren": {},. "_requested": {. "type": "range",. "registry": true,. "raw": "ssr-window@^4.0.1",. "name": "ssr-window",. "escapedName": "ssr-window",. "rawSpec": "^4.0.1",. "saveSpec": null,. "fetchSpec": "^4.0.1". },. "_requiredBy": [. "/swiper",. "/swiper/dom7". ],. "_resolved": "https://registry.npmjs.org/ssr-window/-/ssr-window-4.0.1.tgz",. "_shasum": "514bf2ca81952f63fe88e8b0c623a23f90f7feb3",. "_spec": "ssr-window@^4.0.1",. "_where": "C:\\Users\\Administrator\\node_modules\\swiper",. "author": {. "name": "Vladimir Kharlampidi". },. "bugs": {. "url": "https://github.com/nolimits4web/ssr-window/issues". },. "bundleDependencies": false,. "deprecated": false,. "description": "Better handli
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):3184
            Entropy (8bit):4.371106285384701
            Encrypted:false
            SSDEEP:96:cQ+4zJbav+pG3Wv21kwr1SZoYUv0QVDr++CWC66m:cQ+4Nbav+04AkZoYqTVDr+fL6B
            MD5:A0E50E62DE6BA229609BCCB63F768542
            SHA1:F29C7E7C2AFDCFBDB2AE3289542EE37AC14C4BA9
            SHA-256:C320054BB947175175D1604FA7DF4D83253A184BA1E9F8D55AC021EC999EB75C
            SHA-512:2AC7680C71DEEE928891E4E1E3ACE94832472A75DA6BDC44542CDB0D2F84EA5D468C2D8253BACDE8B493DD57BB7F80F132BCD3D26E663AF3076C39A09199DFCA
            Malicious:false
            Reputation:low
            Preview:/**. * SSR Window 4.0.1. * Better handling for window object in SSR environment. * https://github.com/nolimits4web/ssr-window. *. * Copyright 2021, Vladimir Kharlampidi. *. * Licensed under MIT. *. * Released on: October 27, 2021. */./* eslint-disable no-param-reassign */.function isObject(obj) {. return (obj !== null &&. typeof obj === 'object' &&. 'constructor' in obj &&. obj.constructor === Object);.}.function extend(target = {}, src = {}) {. Object.keys(src).forEach((key) => {. if (typeof target[key] === 'undefined'). target[key] = src[key];. else if (isObject(src[key]) &&. isObject(target[key]) &&. Object.keys(src[key]).length > 0) {. extend(target[key], src[key]);. }. });.}..const ssrDocument = {. body: {},. addEventListener() { },. removeEventListener() { },. activeElement: {. blur() { },. nodeName: '',. },. querySelector() {. return null;. },.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):4297
            Entropy (8bit):4.141862987986008
            Encrypted:false
            SSDEEP:96:cQcpTAimJLaP+JWnbEQbFyZAgoTL+OS2CwjKaH:cQcpTXeLaP+k30ZAlTL+vrwOaH
            MD5:CA633D322FD2800FA6F96C1BD2BC60BA
            SHA1:D293F9E7F6BD74A015DC2ADA469A8E02194DE5C4
            SHA-256:6582D308A75C6A308FB0B9B8ACF616011F5BEFAE80A6F00EC97C29E5C2A9076F
            SHA-512:DA689BA08D91DD7FF6B9879FEF6274F589FF65149335AFD20CE91B457F9D4FC1B5F8917D0F2F122FA75AA9073F3833446E88887F2BD6F9DE6F12D242F8639B47
            Malicious:false
            Reputation:low
            Preview:/**. * SSR Window 4.0.1. * Better handling for window object in SSR environment. * https://github.com/nolimits4web/ssr-window. *. * Copyright 2021, Vladimir Kharlampidi. *. * Licensed under MIT. *. * Released on: October 27, 2021. */.(function (global, factory) {. typeof exports === 'object' && typeof module !== 'undefined' ? factory(exports) :. typeof define === 'function' && define.amd ? define(['exports'], factory) :. (global = typeof globalThis !== 'undefined' ? globalThis : global || self, factory(global.ssrWindow = {}));.}(this, (function (exports) { 'use strict';.. /* eslint-disable no-param-reassign */. function isObject(obj) {. return (obj !== null &&. typeof obj === 'object' &&. 'constructor' in obj &&. obj.constructor === Object);. }. function extend(target = {}, src = {}) {. Object.keys(src).forEach((key) => {. if (typeof target[key] === 'undefined'). target[key] = src[key];.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2712
            Entropy (8bit):3.94905315134676
            Encrypted:false
            SSDEEP:48:YWLCK5gYf73viaEWxfvH+nJvR6qXNR/11ScLSASjXiFVscUcxttndJbqnnFVscUF:fjK+O/DZ1j84CG
            MD5:F9F2F7843C9D315C88FA032A6818BB8B
            SHA1:8BAFE7CF8AF5FBA5B04C5541F89A2A1479F49441
            SHA-256:1824A591C1311E2B4E8555B1911E1F26A78A0881EC66A91301893A6BEAB4F395
            SHA-512:EE9A98794B282F6E1D6A1E12C286B29B7667D0B12924E29EF6C8FFB6446761E8F4FF0903A26AE3D8910C8EE5FCB6531142E2EA33127B7628BEB0B4538C9CE203
            Malicious:false
            Reputation:low
            Preview:{"version":3,"file":"ssr-window.umd.js.map","sources":["../src/extend.ts","../src/document.ts","../src/window.ts"],"sourcesContent":[null,null,null],"names":[],"mappings":";;;;;;;;;;;;;;;;;IAAA;IACA,SAAS,QAAQ,CAAC,GAAG;QACnB,QACE,GAAG,KAAK,IAAI;YACZ,OAAO,GAAG,KAAK,QAAQ;YACvB,aAAa,IAAI,GAAG;YACpB,GAAG,CAAC,WAAW,KAAK,MAAM,EAC1B;IACJ,CAAC;IAED,SAAS,MAAM,CAAC,SAAc,EAAE,EAAE,MAAW,EAAE;QAC7C,MAAM,CAAC,IAAI,CAAC,GAAG,CAAC,CAAC,OAAO,CAAC,CAAC,GAAG;YAC3B,IAAI,OAAO,MAAM,CAAC,GAAG,CAAC,KAAK,WAAW;gBAAE,MAAM,CAAC,GAAG,CAAC,GAAG,GAAG,CAAC,GAAG,CAAC,CAAC;iBAC1D,IACH,QAAQ,CAAC,GAAG,CAAC,GAAG,CAAC,CAAC;gBAClB,QAAQ,CAAC,MAAM,CAAC,GAAG,CAAC,CAAC;gBACrB,MAAM,CAAC,IAAI,CAAC,GAAG,CAAC,GAAG,CAAC,CAAC,CAAC,MAAM,GAAG,CAAC,EAChC;gBACA,MAAM,CAAC,MAAM,CAAC,GAAG,CAAC,EAAE,GAAG,CAAC,GAAG,CAAC,CAAC,CAAC;aAC/B;SACF,CAAC,CAAC;IACL;;UCnBM,WAAW,GAAG;QAClB,IAAI,EAAE,EAAE;QACR,gBAAgB,MAAK;QACrB,mBAAmB,MAAK;QACxB,aAAa,EAAE;YACb,IAAI,MAAK;YACT,QAAQ,EAAE,EAAE;SACb;QACD,aAAa;YACX,OAAO,IAAI,CAAC;SACb;QACD,gBAAgB;YACd,OAAO,EAAE
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (1743)
            Category:dropped
            Size (bytes):2024
            Entropy (8bit):5.24054229339775
            Encrypted:false
            SSDEEP:48:lSQH6MSHh43VZQ3/dSTgjsDwRYjQvFMoYjQwSCSJLqsebFIWm:cQbPzQ3/nj5MMLubtm
            MD5:E5B82089E59CBBAEB5AB38B7CABE4DF2
            SHA1:D9CE6295AE064E35186FC4BAA50BB3BB3D6D8C34
            SHA-256:585B4167B3B38288CAA5E172C4D601766F93D0B7310546A8BCE03FC0138C481B
            SHA-512:5F0FBF2F93F0B36F7D45DAB99765DC054F82B21F788EE248589064D4301DE7010457445F707E0E9221AED07E0ECE0333655B392450CA41983915CD9269EAEEBF
            Malicious:false
            Reputation:low
            Preview:/**. * SSR Window 4.0.1. * Better handling for window object in SSR environment. * https://github.com/nolimits4web/ssr-window. *. * Copyright 2021, Vladimir Kharlampidi. *. * Licensed under MIT. *. * Released on: October 27, 2021. */.!function(e,t){"object"==typeof exports&&"undefined"!=typeof module?t(exports):"function"==typeof define&&define.amd?define(["exports"],t):t((e="undefined"!=typeof globalThis?globalThis:e||self).ssrWindow={})}(this,(function(e){"use strict";function t(e){return null!==e&&"object"==typeof e&&"constructor"in e&&e.constructor===Object}function n(e={},o={}){Object.keys(o).forEach((i=>{void 0===e[i]?e[i]=o[i]:t(o[i])&&t(e[i])&&Object.keys(o[i]).length>0&&n(e[i],o[i])}))}const o={body:{},addEventListener(){},removeEventListener(){},activeElement:{blur(){},nodeName:""},querySelector:()=>null,querySelectorAll:()=>[],getElementById:()=>null,createEvent:()=>({initEvent(){}}),createElement:()=>({children:[],childNodes:[],style:{},setAttribute(){},getElementsByTagName
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):2117
            Entropy (8bit):4.8552298417316795
            Encrypted:false
            SSDEEP:48:YWLowzy2mKwpLKH7KbOKYUrCflm6mikgW57m5LdgEV:fEZEebbYUrCOWMOdBV
            MD5:D9896B25F2968670B771996EB4C319CA
            SHA1:AAE48870A84575BA80CDC9CC6ECE00D0FD37464C
            SHA-256:01EA1EA9DC7B1EB060AAA6D5E6442ED96A4847FF34802BC25936C3DE6544887D
            SHA-512:C84D9DF70CC8FC78CC7EEFC35B5EDBBC443FC52E4C101EC7985F544C93C3D71E744253A62FA2B3165E4EE36E364258A3474F4DFD4F0AFB94BE32B3DC501ECD2C
            Malicious:false
            Reputation:low
            Preview:{"version":3,"sources":["../src/extend.ts","../src/document.ts","../src/window.ts"],"names":["isObject","obj","constructor","Object","extend","target","src","keys","forEach","key","length","ssrDocument","body","addEventListener","removeEventListener","activeElement","blur","nodeName","querySelector","querySelectorAll","getElementById","createEvent","initEvent","createElement","children","childNodes","style","setAttribute","getElementsByTagName","createElementNS","importNode","location","hash","host","hostname","href","origin","pathname","protocol","search","ssrWindow","document","navigator","userAgent","history","replaceState","pushState","go","back","CustomEvent","this","getComputedStyle","getPropertyValue","Image","Date","screen","setTimeout","clearTimeout","matchMedia","requestAnimationFrame","callback","cancelAnimationFrame","id","doc","win","window"],"mappings":";;;;;;;;;;;iPACA,SAASA,EAASC,GAChB,OACU,OAARA,GACe,iBAARA,GACP,gBAAiBA,GACjBA,EAAIC,cAAgBC,OAIxB,SAASC,EAAOC,EAAc,GAAIC,
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):838
            Entropy (8bit):4.284607559342966
            Encrypted:false
            SSDEEP:12:8QA28VZfdzn8/oRRznG3934zRHMkRWnC34ckhUQfPbZWb6WCL6MBlQV:BA28VZFz3RRS3934NMkRWC344ZkFBKV
            MD5:34AA9EEC74DCC42CCD5EE37246C5FABE
            SHA1:683DF22CED3731CF5844A10CFBF64628BCCDA03D
            SHA-256:DC13BE7B4280009BDABEAFE9F848D964919C7E47D0BCC37151AADB362401D752
            SHA-512:4FA9FEFF51CAD218C5F9E3181C60931310BB8F1B1775B96FB8A8395E0F4B7DD68B1E523F314BB477D9CB8338DEFF8A8BEFAD1925367E147C263E7225CBF160BD
            Malicious:false
            Reputation:low
            Preview:declare const ssrDocument: {. body: {};. addEventListener(): void;. removeEventListener(): void;. activeElement: {. blur(): void;. nodeName: string;. };. querySelector(): any;. querySelectorAll(): any[];. getElementById(): any;. createEvent(): {. initEvent(): void;. };. createElement(): {. children: any[];. childNodes: any[];. style: {};. setAttribute(): void;. getElementsByTagName(): any[];. };. createElementNS(): {};. importNode(): any;. location: {. hash: string;. host: string;. hostname: string;. href: string;. origin: string;. pathname: string;. protocol: string;. search: string;. };.};.declare function getDocument(): Document;.export { getDocument, ssrDocument };.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):79
            Entropy (8bit):4.3553071351487675
            Encrypted:false
            SSDEEP:3:nPXcijtXafFiTXTdgB7AYg6Tuy:0ijtKfOXRgB/cy
            MD5:427623CC389272DFDB4EE63274E8A323
            SHA1:04579FF17FEFD74575E17D56C9B8015A962C4056
            SHA-256:A0766F3F058445AECE8844C95FD6141B46AEE3C69592FD86FC16F700100E762B
            SHA-512:73E28152D83EB5B0E3BDAC0D893B88C955C65FA476FEA535E95BAFF0335EB275A8556437E1A827ED6AF84242F4FCCFE89B91A0364B85CF9315284E3C258B69FE
            Malicious:false
            Reputation:low
            Preview:declare function extend(target?: any, src?: any): void;.export default extend;.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):202
            Entropy (8bit):4.460885025609302
            Encrypted:false
            SSDEEP:6:Y0g9LQ9wTDihW0yaq1BfQPJoCk40g9LQ9NRv:iQqsK1BsJrlQF
            MD5:25B18E520FA4E9A8E8507A717CFA6B60
            SHA1:0BEF6E6680F5FEADAE3FC695243EEEA8DE1B2263
            SHA-256:851A1D55F054EF92E68F0F1157D84389784B8C0ECCE4DF1F95CCFD3DAA3B94EA
            SHA-512:961724E7850FD79A460F582A81761D91B88935281DBD618841AF424F18F67D09F8D352EBC1EA46864AC55B76467BFD20E2DC6F5B493CA90D2FF337681996739F
            Malicious:false
            Reputation:low
            Preview:import { getDocument, ssrDocument } from './document';.import { getWindow, ssrWindow } from './window';.import extend from './extend';.export { getDocument, ssrDocument, getWindow, ssrWindow, extend };.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1781
            Entropy (8bit):4.146814367368126
            Encrypted:false
            SSDEEP:48:tLeT9OZCZw63NbuQ328Ot1YEH9OOF9oMhvJiW:3Z763NbCf1Yjc30W
            MD5:A1ECC63239A855E0D9A43CA259652E93
            SHA1:893193AC5BAA0D88BB2DF77AA3D2FAA332569971
            SHA-256:F631909DB95BF7967D02BFE8D4AB808040269ECEA29F53D5151B4CFEFD1BABD4
            SHA-512:4209E62581C531722B0F1728E6528A159F5CF6E73C88A3C169F5A6C15BCC3868B0DA1BD452D36F8ECDE7A7A28B768DD63FD74DB103478EB73739732B7C60ACC5
            Malicious:false
            Reputation:low
            Preview:/// <reference types="node" />.declare const ssrWindow: {. document: {. body: {};. addEventListener(): void;. removeEventListener(): void;. activeElement: {. blur(): void;. nodeName: string;. };. querySelector(): any;. querySelectorAll(): any[];. getElementById(): any;. createEvent(): {. initEvent(): void;. };. createElement(): {. children: any[];. childNodes: any[];. style: {};. setAttribute(): void;. getElementsByTagName(): any[];. };. createElementNS(): {};. importNode(): any;. location: {. hash: string;. host: string;. hostname: string;. href: string;. origin: string;. pathname: string;. protocol: string;. search: string;. };. };. navigator: {. userAgent: string;. };. location:
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1458
            Entropy (8bit):4.734626895010498
            Encrypted:false
            SSDEEP:24:hkT8mur86OrUb5NZe1dqVPdBuJ0lRutY3+v6p++6khWrkH1YcHg0aIi2t6wQzQHP:hkTduI6O6NZSesJdxypeNrWC+g0aVLwh
            MD5:FA9E8A3CD8C5A55DA33A7F52493E1978
            SHA1:5A2C3B6A403B01559BB2A67CE6190A50B0B6BA43
            SHA-256:9EA320D9A740385D6E35AD2CF18E63B3F915E297C20EF30627BDB020387B5120
            SHA-512:C39164A99B2AB40C0FBD723A06BCA0F02508344C434B679CE09864EC73FE77578BECBF96116DCDC540CE079070DF3BB496EFF4E303182FB65F09E41B3F35CC6D
            Malicious:false
            Reputation:low
            Preview:import { paramsList } from './params-list.js';.import { isObject } from './utils.js';..function getChangedParams(swiperParams, oldParams, children, oldChildren) {. const keys = [];. if (!oldParams) return keys;.. const addKey = key => {. if (keys.indexOf(key) < 0) keys.push(key);. };.. const oldChildrenKeys = oldChildren.map(child => child.key);. const childrenKeys = children.map(child => child.key);. if (oldChildrenKeys.join('') !== childrenKeys.join('')) addKey('children');. if (oldChildren.length !== children.length) addKey('children');. const watchParams = paramsList.filter(key => key[0] === '_').map(key => key.replace(/_/, ''));. watchParams.forEach(key => {. if (key in swiperParams && key in oldParams) {. if (isObject(swiperParams[key]) && isObject(oldParams[key])) {. const newKeys = Object.keys(swiperParams[key]);. const oldKeys = Object.keys(oldParams[key]);.. if (newKeys.length !== oldKeys.length) {. addKey(key);. } els
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1226
            Entropy (8bit):4.617370038426258
            Encrypted:false
            SSDEEP:24:whMxhu9jQboZe77eTiQZxhu9jZ24odeAHgquSY:whMxw90bCE7AiMxw9V24aeAAjr
            MD5:E9AA825B7E5033113D1E14F1B2F68A47
            SHA1:87DA4029FC6DC2E46F9EA1DDF44F276516E3159E
            SHA-256:FFAD03AB59E7B1469F46D0873CCBD4F203ABB1AE6A268B17ADCEEE2E99876558
            SHA-512:00781F24BE184C27CD172EE20DBAF36C07A7FD0408EE50E61EE4A9C35A14EE80B7192331CE74AB223E526AAA7AF462171685A76F690A3C2FD509C6B003DB8F92
            Malicious:false
            Reputation:low
            Preview:import React from 'react';..function processChildren(c) {. const slides = [];. React.Children.toArray(c).forEach(child => {. if (child.type && child.type.displayName === 'SwiperSlide') {. slides.push(child);. } else if (child.props && child.props.children) {. processChildren(child.props.children).forEach(slide => slides.push(slide));. }. });. return slides;.}..function getChildren(c) {. const slides = [];. const slots = {. 'container-start': [],. 'container-end': [],. 'wrapper-start': [],. 'wrapper-end': []. };. React.Children.toArray(c).forEach(child => {. if (child.type && child.type.displayName === 'SwiperSlide') {. slides.push(child);. } else if (child.props && child.props.slot && slots[child.props.slot]) {. slots[child.props.slot].push(child);. } else if (child.props && child.props.children) {. const foundSlides = processChildren(child.props.children);.. if (foundSlides.length > 0) {. foundSlides.forEach(sl
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1261
            Entropy (8bit):4.78115100756888
            Encrypted:false
            SSDEEP:24:8z+/kT+ROfM1dk+Lzkm6BWNu2RnIYLiViboho4LTeTrpvN9yUOFVVKWLtGYIsiIt:J/kT+RwMQnm6BP+IsiVibcDLSvpN9yUi
            MD5:D783F65868CF71D732FC2B44F1C147AE
            SHA1:56BA9ED6D92D445341848B8C89C4009048E0B670
            SHA-256:5F1487FFAFA900B351ABF59F9E2B0FB99872EA0F060EA3B9FC76002E994521A1
            SHA-512:932810DFE5BA3B9D541E1AF0065E9BB7FB322A3433736B80E3E424B07E3D92FD5EC98F3F504CF659197A18CD4070367A93A516F1973ED832F110FCE887998720
            Malicious:false
            Reputation:low
            Preview:import Swiper from 'swiper';.import { isObject, extend } from './utils.js';.import { paramsList } from './params-list.js';..function getParams(obj = {}) {. const params = {. on: {}. };. const events = {};. const passedParams = {};. extend(params, Swiper.defaults);. extend(params, Swiper.extendedDefaults);. params._emitClasses = true;. params.init = false;. const rest = {};. const allowedParams = paramsList.map(key => key.replace(/_/, ''));. Object.keys(obj).forEach(key => {. if (allowedParams.indexOf(key) >= 0) {. if (isObject(obj[key])) {. params[key] = {};. passedParams[key] = {};. extend(params[key], obj[key]);. extend(passedParams[key], obj[key]);. } else {. params[key] = obj[key];. passedParams[key] = obj[key];. }. } else if (key.search(/on[A-Z]/) === 0 && typeof obj[key] === 'function') {. events[`${key[2].toLowerCase()}${key.substr(3)}`] = obj[key];. } else {. rest[key] = obj[key];. }.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):934
            Entropy (8bit):4.616139718387101
            Encrypted:false
            SSDEEP:24:8w1uPysIsKbOUXz9BCPRCPICbiqRCbixxdn8dQ1BSrBN9y1U9:h1uPyBjhBCPRCPICjRCin2q+BDym9
            MD5:473C4FEBB4542C8A4064F6BD51B84DDD
            SHA1:EE8D03277CB9AB30AEF418F2119E33E8901F57BC
            SHA-256:77BBEA04B408B78373106A62B25D6E2588A74420B7B55965F2743B98133408B6
            SHA-512:334A1371B06B03EDB12AFF916263BC2587A4289A882E35EF9E31AC639F5B7F3A48D39EEDCA25E70164EA360F38790B31E83A89302BF417694B7A44779A991FC2
            Malicious:false
            Reputation:low
            Preview:import Swiper from 'swiper';.import { needsNavigation, needsPagination, needsScrollbar } from './utils.js';..function initSwiper(swiperParams) {. return new Swiper(swiperParams);.}..function mountSwiper({. el,. nextEl,. prevEl,. paginationEl,. scrollbarEl,. swiper.}, swiperParams) {. if (needsNavigation(swiperParams) && nextEl && prevEl) {. swiper.params.navigation.nextEl = nextEl;. swiper.originalParams.navigation.nextEl = nextEl;. swiper.params.navigation.prevEl = prevEl;. swiper.originalParams.navigation.prevEl = prevEl;. }.. if (needsPagination(swiperParams) && paginationEl) {. swiper.params.pagination.el = paginationEl;. swiper.originalParams.pagination.el = paginationEl;. }.. if (needsScrollbar(swiperParams) && scrollbarEl) {. swiper.params.scrollbar.el = scrollbarEl;. swiper.originalParams.scrollbar.el = scrollbarEl;. }.. swiper.init(el);.}..export { initSwiper, mountSwiper };
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):2533
            Entropy (8bit):4.86600432102841
            Encrypted:false
            SSDEEP:48:aIsjJl8B1BwNHhAlXmUhAevbautdFj7AKRYSw9kHjylrwuSKwIpk9S:uwBQHixJHpUKTw9Qjyd1IS
            MD5:20BBB849E19E3E0EB8949EA5172641EC
            SHA1:59C86A1A38EFAF47EF53DF79CB516329934D22A8
            SHA-256:5FBF5306753E72551D19AB755F6872599A48FD02500500B9326C2620C48546E5
            SHA-512:A6A276D4C72B826DD0B5DDB5AA1C58A231294B8E9FF7BAB9339736D1D763D81EABF6A2A40E780F20F757E90D81F716FDF7F3CDC5CEAED59F0612058CF5542785
            Malicious:false
            Reputation:low
            Preview:import React from 'react';.import Swiper from 'swiper';..function calcLoopedSlides(slides, swiperParams) {. let slidesPerViewParams = swiperParams.slidesPerView;.. if (swiperParams.breakpoints) {. const breakpoint = Swiper.prototype.getBreakpoint(swiperParams.breakpoints);. const breakpointOnlyParams = breakpoint in swiperParams.breakpoints ? swiperParams.breakpoints[breakpoint] : undefined;.. if (breakpointOnlyParams && breakpointOnlyParams.slidesPerView) {. slidesPerViewParams = breakpointOnlyParams.slidesPerView;. }. }.. let loopedSlides = Math.ceil(parseFloat(swiperParams.loopedSlides || slidesPerViewParams, 10));. loopedSlides += swiperParams.loopAdditionalSlides;.. if (loopedSlides > slides.length) {. loopedSlides = slides.length;. }.. return loopedSlides;.}..function renderLoop(swiper, slides, swiperParams) {. const modifiedSlides = slides.map((child, index) => {. return /*#__PURE__*/React.cloneElement(child, {. swiper,. 'data-swiper-sli
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (1741)
            Category:dropped
            Size (bytes):2089
            Entropy (8bit):4.744182989771888
            Encrypted:false
            SSDEEP:48:kFl9aBONs8INhyw2cofcezZOl2dAaJDcL0fVsTOn:kFlO/8TUll7aJDcwfuTe
            MD5:196A01069A99BCA82B4F4DFD44469713
            SHA1:602A17476C445F8AE44787FE5D70CE9F6530BE7A
            SHA-256:EF417A0742166485A02A667F5726F5C20FB2F872236C1344CF58980CF76EEF52
            SHA-512:756C0FBDFB3203483B20E90893484648A9F6C9220111ABED32240B03B286B1D3050767B3280EC79C61938CCFC726750A8AEEA4C16FDC884949D21E2469FBEF88
            Malicious:false
            Reputation:low
            Preview:/* underscore in name -> watch for changes */.const paramsList = ['modules', 'init', '_direction', 'touchEventsTarget', 'initialSlide', '_speed', 'cssMode', 'updateOnWindowResize', 'resizeObserver', 'nested', 'focusableElements', '_enabled', '_width', '_height', 'preventInteractionOnTransition', 'userAgent', 'url', '_edgeSwipeDetection', '_edgeSwipeThreshold', '_freeMode', '_autoHeight', 'setWrapperSize', 'virtualTranslate', '_effect', 'breakpoints', '_spaceBetween', '_slidesPerView', '_grid', '_slidesPerGroup', '_slidesPerGroupSkip', '_slidesPerGroupAuto', '_centeredSlides', '_centeredSlidesBounds', '_slidesOffsetBefore', '_slidesOffsetAfter', 'normalizeSlideIndex', '_centerInsufficientSlides', '_watchOverflow', 'roundLengths', 'touchRatio', 'touchAngle', 'simulateTouch', '_shortSwipes', '_longSwipes', 'longSwipesRatio', 'longSwipesMs', '_followFinger', 'allowTouchMove', '_threshold', 'touchMoveStopPropagation', 'touchStartPreventDefault', 'touchStartForcePreventDefault', 'touchReleas
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):13628
            Entropy (8bit):4.761312297015221
            Encrypted:false
            SSDEEP:384:CbDUH0ot1GP6d6jvs/pNZr0XmxNzaQa725MLNgSOMofg9dvt5tkfXFypKp8cFoS9:46/KKpf9
            MD5:63C636277CC46AC0CB0FA83ADFF6E057
            SHA1:13719014320B5035266128F83D8165FC6E198A69
            SHA-256:B205A0ADD8AE8C6AF043D7E1E2AECBF03020FCD9E4F7DE8910FED69F1682AC2A
            SHA-512:C0963FB3E50475E6064A14184ABA812D8EA3B7D519FD1AF4288EBF97A88D0D1BFA63AA4BD15EFFFC1D3A7C3919B33EC222C0D30C5A3C566FC6EBFE1C9D06F923
            Malicious:false
            Reputation:low
            Preview:import * as React from 'react';..import { SwiperOptions, Swiper as SwiperClass } from '../types/';..interface Swiper extends SwiperOptions {. /**. * Swiper container tag. *. * @default 'div'. */. tag?: string;.. /**. * Swiper wrapper tag. *. * @default 'div'. */. wrapperTag?: string;.. /**. * Get Swiper instance. */. onSwiper?: (swiper: SwiperClass) => void;.. /**. * Event will be fired in when autoplay started. */. onAutoplayStart?: (swiper: SwiperClass) => void;. /**. * Event will be fired when autoplay stopped. */. onAutoplayStop?: (swiper: SwiperClass) => void;. /**. * Event will be fired when slide changed with autoplay. */. onAutoplay?: (swiper: SwiperClass) => void;/**. * Event will be fired on window hash change. */. onHashChange?: (swiper: SwiperClass) => void;. /**. * Event will be fired when swiper updates the hash. */. onHashSet?: (swiper: SwiperClass) => void;/**. * Event will be fired on mousewheel scroll. */. on
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):380
            Entropy (8bit):4.8365068766736
            Encrypted:false
            SSDEEP:6:UzxitAASX+PxKXawIAfMRLidMfZCSleO5ugiw1944qR9lLUuTRtUuAeIAoQkMUCh:UzhASXSPmkxtfESR5ugiww4+9myUu/Iq
            MD5:33A958B02C53BAF446E5AB6594299938
            SHA1:BE721B0DFDE942CC7727E86029ACD90A1608C7F0
            SHA-256:08CB7395B028ED754D29389BB8941379174DDE8775688C62EED974113B2F3FCC
            SHA-512:342D536CF3BD0560800A467FB8D6EC8CBC8B65D9F1D7AEA701E15CBA4CA54294F60699F0A358DB2732EE1D25AABB68DA0E2878A5B7F4B84F851DEE0914F066F5
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper React 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..import { Swiper } from './swiper.js';.import { SwiperSlide } from './swiper-slide.js';.export { Swiper, SwiperSlide };
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text, with very long lines (317)
            Category:dropped
            Size (bytes):2773
            Entropy (8bit):4.958563417344549
            Encrypted:false
            SSDEEP:48:IXXtw1OC6L0NoDbB4L1JvkrM0rg1HPhHfgbw1r7yjf2GlPE1CtA2kZM/oYuUGBJ9:I+OC6L0NubB4zkGWw1UDXyB+kzLVBr
            MD5:63996F533E1157B2092EC4FFCDE5A82B
            SHA1:53F084B3024965CECD4A167A88CEEC5337521FFA
            SHA-256:69E9DB7010234E4CF7F8A5FC27F5EC77A37CA6815E2EF1FACA5EE044C65EDEA9
            SHA-512:032743CE249EA2F39B55FE58628BE0A34FF6200137AC68B0A7C15C36CB581C506E06E52FE2CC352D470173FE7FC4ABEDD481D06D7CBABB05131312B9CF085E48
            Malicious:false
            Reputation:low
            Preview:function _extends() { _extends = Object.assign || function (target) { for (var i = 1; i < arguments.length; i++) { var source = arguments[i]; for (var key in source) { if (Object.prototype.hasOwnProperty.call(source, key)) { target[key] = source[key]; } } } return target; }; return _extends.apply(this, arguments); }..import React, { useRef, useState, forwardRef } from 'react';.import { uniqueClasses } from './utils.js';.import { useIsomorphicLayoutEffect } from './use-isomorphic-layout-effect.js';.const SwiperSlide = /*#__PURE__*/forwardRef(({. tag: Tag = 'div',. children,. className = '',. swiper,. zoom,. virtualIndex,. ...rest.} = {}, externalRef) => {. const slideElRef = useRef(null);. const [slideClasses, setSlideClasses] = useState('swiper-slide');.. function updateClasses(_s, el, classNames) {. if (el === slideElRef.current) {. setSlideClasses(classNames);. }. }.. useIsomorphicLayoutEffect(() => {. if (externalRef) {. externalRef.current = slideElRe
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text, with very long lines (317)
            Category:dropped
            Size (bytes):6757
            Entropy (8bit):4.903817502387012
            Encrypted:false
            SSDEEP:192:Iq6Ld+/oulGlDrxD9C3IZBIrZV+xY2UjVY:n6LdmoBlDne2
            MD5:0A39A317C2B135C639332A381A31B03F
            SHA1:11761BAA50F0A24238615F36F24D5F31EEB0450D
            SHA-256:D19A32E44A6CADECD1901EAFB067BA4FEF7EF200780D60D4E6C2E78DD5EF6CE3
            SHA-512:030CAB6416CE40DE31FF0488660D7DCE9939C9F7CBF9D1EED036CA5F86AAC5CE74F2156A36CF7E059DC4CFE391B01E877901AB61DC8277D1138D5E20A1F2451C
            Malicious:false
            Reputation:low
            Preview:function _extends() { _extends = Object.assign || function (target) { for (var i = 1; i < arguments.length; i++) { var source = arguments[i]; for (var key in source) { if (Object.prototype.hasOwnProperty.call(source, key)) { target[key] = source[key]; } } } return target; }; return _extends.apply(this, arguments); }..import React, { useRef, useState, useEffect, forwardRef } from 'react';.import { getParams } from './get-params.js';.import { initSwiper, mountSwiper } from './init-swiper.js';.import { needsScrollbar, needsNavigation, needsPagination, uniqueClasses, extend } from './utils.js';.import { renderLoop, calcLoopedSlides } from './loop.js';.import { getChangedParams } from './get-changed-params.js';.import { getChildren } from './get-children.js';.import { updateSwiper } from './update-swiper.js';.import { renderVirtual, updateOnVirtualData } from './virtual.js';.import { useIsomorphicLayoutEffect } from './use-isomorphic-layout-effect.js';.const Swiper = /*#__PURE__*/forwardRef
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):4034
            Entropy (8bit):4.789040506907139
            Encrypted:false
            SSDEEP:96:zTbU67uuIALIkYMBMxEGmw4ToUk2/I3Baj3x3LLyB:f37uuTLIkRBMxsoUkEIsNL4
            MD5:3D812567C95447F740508E7329BF43A3
            SHA1:361BC4A06A146BE949102000940EECF5B235C3A0
            SHA-256:F00815FA460FA0D55FDCEE55C8C58390A5E70ADFAFFE878D66BDDCB17EBF0485
            SHA-512:099A70D1779517BD4BF900A8339DF98B3E9E1712DF8BA9C3E2FD83DCE3DDDFEE44BE170CB3B94779393BF9067E17618D0153AD848FEEB0389761749BEC3EBBA9
            Malicious:false
            Reputation:low
            Preview:import { isObject, extend } from './utils.js';..function updateSwiper({. swiper,. slides,. passedParams,. changedParams,. nextEl,. prevEl,. scrollbarEl,. paginationEl.}) {. const updateParams = changedParams.filter(key => key !== 'children' && key !== 'direction');. const {. params: currentParams,. pagination,. navigation,. scrollbar,. virtual,. thumbs. } = swiper;. let needThumbsInit;. let needControllerInit;. let needPaginationInit;. let needScrollbarInit;. let needNavigationInit;.. if (changedParams.includes('thumbs') && passedParams.thumbs && passedParams.thumbs.swiper && currentParams.thumbs && !currentParams.thumbs.swiper) {. needThumbsInit = true;. }.. if (changedParams.includes('controller') && passedParams.controller && passedParams.controller.control && currentParams.controller && !currentParams.controller.control) {. needControllerInit = true;. }.. if (changedParams.includes('pagination') && passedParams.pagination && (passedParam
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):289
            Entropy (8bit):4.751124398723337
            Encrypted:false
            SSDEEP:6:KKclU69nocmKFMZlIDz+nSlDWpKFMwSW/cmKFMt4VQkqXwnocK:KK0U6poHKFMZleqnuKpKFMwl/HKFM6QB
            MD5:75786F57843F3B585844ED7B1FE8B991
            SHA1:03104F280408E3BBCC76BA00AD843EF8CF537EFE
            SHA-256:20FC17BD248213CD1E808EC4F5FF0BF58EBD75D0DB80795F7E72A9882DF69168
            SHA-512:036AB441502612BE600B2F4664B844B859D53FA39BB0047668858AAA8F63BBE1D885F88474F6412490FE2AB289505689B7F77914057E29EA9B4EFC33DEC3B438
            Malicious:false
            Reputation:low
            Preview:import { useEffect, useLayoutEffect } from 'react';..function useIsomorphicLayoutEffect(callback, deps) {. // eslint-disable-next-line. if (typeof window === 'undefined') return useEffect(callback, deps);. return useLayoutEffect(callback, deps);.}..export { useIsomorphicLayoutEffect };
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1376
            Entropy (8bit):4.962647861301955
            Encrypted:false
            SSDEEP:24:gYQnwNWvp4kHuxYNa0nr5sKUmIQLA+GsCs0C32CTKtQ/daK28yaKszv3qsu6puTN:JQnwNEXHuxSa0nr5sKUmj0+GsCNC32CS
            MD5:86FFEEC7F078B46A888281A06D6826EE
            SHA1:D461C0182245F488130EFDE92D1CEDDD3E3D4203
            SHA-256:0ACA58D3F5ADFC74F16C4CA9A03866DE922471FB6B83E20127F3C743348CF0AE
            SHA-512:7D5E519CBBBAE511C3DE205EACDFF0F0E9D32A57E523FAA59766922F0D1D00CBC8A1CEA44E208000CE23A0D954E551B604F4E4F3A77C5EF9F70FA3734F430660
            Malicious:false
            Reputation:low
            Preview:function isObject(o) {. return typeof o === 'object' && o !== null && o.constructor && Object.prototype.toString.call(o).slice(8, -1) === 'Object';.}..function extend(target, src) {. const noExtend = ['__proto__', 'constructor', 'prototype'];. Object.keys(src).filter(key => noExtend.indexOf(key) < 0).forEach(key => {. if (typeof target[key] === 'undefined') target[key] = src[key];else if (isObject(src[key]) && isObject(target[key]) && Object.keys(src[key]).length > 0) {. if (src[key].__swiper__) target[key] = src[key];else extend(target[key], src[key]);. } else {. target[key] = src[key];. }. });.}..function needsNavigation(params = {}) {. return params.navigation && typeof params.navigation.nextEl === 'undefined' && typeof params.navigation.prevEl === 'undefined';.}..function needsPagination(params = {}) {. return params.pagination && typeof params.pagination.el === 'undefined';.}..function needsScrollbar(params = {}) {. return params.scrollbar && typeof param
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):988
            Entropy (8bit):4.862140359763871
            Encrypted:false
            SSDEEP:24:wLPYrEdojAB6BbBqgMuwsZAo06KP35fF1UlUidLHz6hxytHiiLmse:wLAkqlqq2o06KPpfF1UlUILHGhAlP6/
            MD5:7923F3AA4A8DC66A7AA89B585DD8B2E7
            SHA1:8CBA6C058D043F7BA8942B76D291E3495120363E
            SHA-256:F06617482CFCEEF532294D5A65701FA089A8191CE238E3B03CBA9B306B359D74
            SHA-512:AF42E1027ED209226CAB165DED1B4CA9768F45D727387214DB83F5B20516DCD79157937AD354A6B6D77AB4E6A8B47E90DF0CED8F9FD372BCEA85915FE8B1C9AE
            Malicious:false
            Reputation:low
            Preview:import React from 'react';..function updateOnVirtualData(swiper) {. if (!swiper || swiper.destroyed || !swiper.params.virtual || swiper.params.virtual && !swiper.params.virtual.enabled) return;. swiper.updateSlides();. swiper.updateProgress();. swiper.updateSlidesClasses();.. if (swiper.lazy && swiper.params.lazy.enabled) {. swiper.lazy.load();. }.. if (swiper.parallax && swiper.params.parallax && swiper.params.parallax.enabled) {. swiper.parallax.setTranslate();. }.}..function renderVirtual(swiper, slides, virtualData) {. if (!virtualData) return null;. const style = swiper.isHorizontal() ? {. [swiper.rtlTranslate ? 'right' : 'left']: `${virtualData.offset}px`. } : {. top: `${virtualData.offset}px`. };. return slides.filter((child, index) => index >= virtualData.from && index <= virtualData.to).map(child => {. return /*#__PURE__*/React.cloneElement(child, {. swiper,. style. });. });.}..export { renderVirtual, updateOnVirtualData };
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):166
            Entropy (8bit):4.8578310917510255
            Encrypted:false
            SSDEEP:3:4i7AYg5QyXbm2yJAGRKdeEU8ew+/fKRTNMwCYNGLfE5K4MKeCBUPFHJMLRI6tMLl:4i/mZDyJ4dez8tTNMwCgGQU4ZBUtClI9
            MD5:C3E770E9F3CBF351E72AA837FFF0CA5C
            SHA1:9C9E76AF6463CC9DA981E30564901B2F2A9EB063
            SHA-256:2E69B95FB2B57B1B668BD48CDF75863C8F8C41A3983C8BF5886B9C84B1193FAE
            SHA-512:ACA6C573A26475DF1A1323799E158E7F789A8E0AC72854A18A8B9BB0F5173D3A0F2BB712C0E7F066F00F7AC32390F4E7661F3535A53EE585B4923E9F66AE8CEF
            Malicious:false
            Reputation:low
            Preview:export default function classesToSelector(classes = '') {. return `.${classes.trim().replace(/([\.:!\/])/g, '\\$1') // eslint-disable-line. .replace(/ /g, '.')}`;.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):656
            Entropy (8bit):4.631531860874772
            Encrypted:false
            SSDEEP:12:XKkk3mlEQwphLnIWbpY1u6L0/r8dn9AyAucHNbtXz0r3IOiOSEon:Xhk2ljwpVIWlY5Qz8liyAuctbtXCIOid
            MD5:85A759BE1025937447861D825BC65DB7
            SHA1:A0830D7DBFD40D8ADD166595E97BF93C8CEB470D
            SHA-256:5912B2CB5A5D2511B18C406F03B4B0F459A1C386F34A3129F96E0AB6F22B38C9
            SHA-512:5A71C7441B69C753EE4EA103E4524909D0853ED36FDB2E6EA93E2E52BFD9CAD0876A0C2678A9C61FF0AAC7073B8A2ED2D693C9E596EC5B1F4A7DA2EFFE189836
            Malicious:false
            Reputation:low
            Preview:import { getDocument } from 'ssr-window';.export default function createElementIfNotDefined(swiper, originalParams, params, checkProps) {. const document = getDocument();.. if (swiper.params.createElements) {. Object.keys(checkProps).forEach(key => {. if (!params[key] && params.auto === true) {. let element = swiper.$el.children(`.${checkProps[key]}`)[0];.. if (!element) {. element = document.createElement('div');. element.className = checkProps[key];. swiper.$el.append(element);. }.. params[key] = element;. originalParams[key] = element;. }. });. }.. return params;.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):498
            Entropy (8bit):4.866389906011228
            Encrypted:false
            SSDEEP:12:8Q3qvBTQOW7HthdgV3GWi36GfF58bBOW7gpebgX:8QaKOCtDgVWN/fhb
            MD5:46D468DEBC4750BDFDC651389040ECBF
            SHA1:03C217F07F4D1DA3191E6B83E6D01662DA3EB338
            SHA-256:FF8316619BF74EF0459B86CC57EDEFA54118CC98E75118F6B67E3D35A6D17C02
            SHA-512:E5A598E65D88AB6B859BDA4F529347FBFEC97DC86355748E967D4045E8680FC520A5EB91258386BF6D0A6941FC90552DA12723F9430A21AF00BFB6CA2A5DE51D
            Malicious:false
            Reputation:low
            Preview:import $ from './dom.js';.export default function createShadow(params, $slideEl, side) {. const shadowClass = `swiper-slide-shadow${side ? `-${side}` : ''}`;. const $shadowContainer = params.transformEl ? $slideEl.find(params.transformEl) : $slideEl;. let $shadowEl = $shadowContainer.children(`.${shadowClass}`);.. if (!$shadowEl.length) {. $shadowEl = $(`<div class="swiper-slide-shadow${side ? `-${side}` : ''}"></div>`);. $shadowContainer.append($shadowEl);. }.. return $shadowEl;.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text, with very long lines (329)
            Category:dropped
            Size (bytes):893
            Entropy (8bit):4.550998867469539
            Encrypted:false
            SSDEEP:24:NUB+LRbZFuC+4bhIxWmQRVpsJagIen9KPsPu9TLAFv:WctF7+36RSiQKUPu9Ev
            MD5:9802E8893B3A77FB326B74DBAB6E5269
            SHA1:25DF9BE324BC8AA073A87DD09CDF236C5F0980A9
            SHA-256:32724B17D20263089E35D8820DAA9FD576D10511F7C5B53588E2037F9722DA7D
            SHA-512:12DDCD1180502D45A1018629C40264A7EE363C36D6E139B3E5BA45EB631FC8D48E90BC341380D12ECAEC02106EEE5DE73F7BB32D2587089E31E73990686948BE
            Malicious:false
            Reputation:low
            Preview:import { $, addClass, removeClass, hasClass, toggleClass, attr, removeAttr, transform, transition, on, off, trigger, transitionEnd, outerWidth, outerHeight, styles, offset, css, each, html, text, is, index, eq, append, prepend, next, nextAll, prev, prevAll, parent, parents, closest, find, children, filter, remove } from 'dom7';.const Methods = {. addClass,. removeClass,. hasClass,. toggleClass,. attr,. removeAttr,. transform,. transition,. on,. off,. trigger,. transitionEnd,. outerWidth,. outerHeight,. styles,. offset,. css,. each,. html,. text,. is,. index,. eq,. append,. prepend,. next,. nextAll,. prev,. prevAll,. parent,. parents,. closest,. find,. children,. filter,. remove.};.Object.keys(Methods).forEach(methodName => {. Object.defineProperty($.fn, methodName, {. value: Methods[methodName],. writable: true. });.});.export default $;
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):889
            Entropy (8bit):4.668329715534651
            Encrypted:false
            SSDEEP:24:PuHxcveQJLGY82yccydaiPFXzHXy51sLG3wnLGz:Pg2NRGYKccyzPFXzHXy5GGqGz
            MD5:1513C1A92B7DEC2E547C44AE0CACABF3
            SHA1:D75E83123A89B08B8E292B61027ADDD1A7C7FAB0
            SHA-256:54A0577146A2F6580DFCB72D7E209C5520E4FAEDF2B56CC48592F6D8DA8F538C
            SHA-512:D9C057EEAA95CCCBCD66A9D9A1E81907BEDBC19AC96AB31424B35A07D154FC73DAE9143D2522C171EDF6D77FE01897BA9031DC960A0B3FE1C5FFDE5FED58A159
            Malicious:false
            Reputation:low
            Preview:export default function effectInit(params) {. const {. effect,. swiper,. on,. setTranslate,. setTransition,. overwriteParams,. perspective. } = params;. on('beforeInit', () => {. if (swiper.params.effect !== effect) return;. swiper.classNames.push(`${swiper.params.containerModifierClass}${effect}`);.. if (perspective && perspective()) {. swiper.classNames.push(`${swiper.params.containerModifierClass}3d`);. }.. const overwriteParamsResult = overwriteParams ? overwriteParams() : {};. Object.assign(swiper.params, overwriteParamsResult);. Object.assign(swiper.originalParams, overwriteParamsResult);. });. on('setTranslate', () => {. if (swiper.params.effect !== effect) return;. setTranslate();. });. on('setTransition', (_s, duration) => {. if (swiper.params.effect !== effect) return;. setTransition(duration);. });.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):272
            Entropy (8bit):4.701539070580277
            Encrypted:false
            SSDEEP:6:4i/mZf25pqAzRlQ4mge3G8RlQ4X8DzXyBDzXypet:4iM25p7te3GSUpet
            MD5:5D7479D68EEB0AF37A01B41F6122C997
            SHA1:C3195AC22F3F1A5B5F4E018471989192DDB02F92
            SHA-256:00651BACF0A1CFF912812B63FE45105B51A565F1CE9BE9FE8CA811863B3A0320
            SHA-512:6C6B016F38159192BB1E3CD8B1F48CD92D434B7EF293ECA2865C9590C8B8B04334D334970085A2BCF756CED0ABFEC80D6858F3C1BAC847E6961D4ACF8A3D7BE8
            Malicious:false
            Reputation:low
            Preview:export default function effectTarget(effectParams, $slideEl) {. if (effectParams.transformEl) {. return $slideEl.find(effectParams.transformEl).css({. 'backface-visibility': 'hidden',. '-webkit-backface-visibility': 'hidden'. });. }.. return $slideEl;.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):911
            Entropy (8bit):4.570616608568733
            Encrypted:false
            SSDEEP:24:qZkHZoRSgW1s8QkIbEIPXFjCp8xeOKix9BaQVnYLWIUvNbM:qYZg5W1s8x4d+SxHBaQVn0n4M
            MD5:DE44F1E1329DEADE85381A611D0CFCB9
            SHA1:B69BC771549C460FDA7442E77AEE5BA51FA825A4
            SHA-256:13D97ED19A80782C37B9B77815AED48321B387A9ECA408C46022BD7F51B6DE38
            SHA-512:8E63D3712EE0271646D94813708A9046782646F71A90B5EB7CFBBD6FAC5E80CBF1B9EF9D509FF6468DA9F199E6902CF3B605B0FC30649A3530DACDE6F255D58E
            Malicious:false
            Reputation:low
            Preview:export default function effectVirtualTransitionEnd({. swiper,. duration,. transformEl,. allSlides.}) {. const {. slides,. activeIndex,. $wrapperEl. } = swiper;.. if (swiper.params.virtualTranslate && duration !== 0) {. let eventTriggered = false;. let $transitionEndTarget;.. if (allSlides) {. $transitionEndTarget = transformEl ? slides.find(transformEl) : slides;. } else {. $transitionEndTarget = transformEl ? slides.eq(activeIndex).find(transformEl) : slides.eq(activeIndex);. }.. $transitionEndTarget.transitionEnd(() => {. if (eventTriggered) return;. if (!swiper || swiper.destroyed) return;. eventTriggered = true;. swiper.animating = false;. const triggerEvents = ['webkitTransitionEnd', 'transitionend'];.. for (let i = 0; i < triggerEvents.length; i += 1) {. $wrapperEl.trigger(triggerEvents[i]);. }. });. }.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):550
            Entropy (8bit):4.875595388049905
            Encrypted:false
            SSDEEP:12:2KfltjS846dOyKRBPY1zbP2AU77WrvZSq2IA3fnbQ0r:2Gzt469KWP42rZfQP8k
            MD5:72488A9746CC468A6DBF8C4625C98343
            SHA1:7333D7E7DA0DE30F53831FAEB612AE09789911C3
            SHA-256:25CEB9AE041E10B7494CE3F6D032174B7C01B239C398203B6DEA15628C28D7C5
            SHA-512:6D4051649C41B95444712C0EF7E1E4F5DE4E5B08E3F6D9050284768ADFE778A509DB26D68235A938138940219A646BFFE14FD6BAA02A4530A35B8DF122C34957
            Malicious:false
            Reputation:low
            Preview:import { getWindow } from 'ssr-window';.let browser;..function calcBrowser() {. const window = getWindow();.. function isSafari() {. const ua = window.navigator.userAgent.toLowerCase();. return ua.indexOf('safari') >= 0 && ua.indexOf('chrome') < 0 && ua.indexOf('android') < 0;. }.. return {. isSafari: isSafari(),. isWebView: /(iPhone|iPod|iPad).*AppleWebKit(?!.*Safari)/i.test(window.navigator.userAgent). };.}..function getBrowser() {. if (!browser) {. browser = calcBrowser();. }.. return browser;.}..export { getBrowser };
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1561
            Entropy (8bit):5.186476159389475
            Encrypted:false
            SSDEEP:48:2jXkMG9XlboJpDeCW/Z2Tc6qbefbTDgJrk5C:2j0PlKoR/Zac6Bz/Ow5C
            MD5:A3B30CBADAC21C3849BE4C0B691D69AA
            SHA1:D04A151D361D087B49BDB23FC666833D236AEDBB
            SHA-256:998B0D6020B34B7289C74E07D13AA55C829EB04C39A02974A336FF10D394FD84
            SHA-512:B2D390C07CA3650AA5B45C74F317E5B0D1722FF913D6B6295F3A1E23DEAD9E4679FD8618BD7BDAFDC100A786D48C8E38C346C0DBA154A86715B368AFB482DCB2
            Malicious:false
            Reputation:low
            Preview:import { getWindow } from 'ssr-window';.import { getSupport } from './get-support.js';.let deviceCached;..function calcDevice({. userAgent.} = {}) {. const support = getSupport();. const window = getWindow();. const platform = window.navigator.platform;. const ua = userAgent || window.navigator.userAgent;. const device = {. ios: false,. android: false. };. const screenWidth = window.screen.width;. const screenHeight = window.screen.height;. const android = ua.match(/(Android);?[\s\/]+([\d.]+)?/); // eslint-disable-line.. let ipad = ua.match(/(iPad).*OS\s([\d_]+)/);. const ipod = ua.match(/(iPod)(.*OS\s([\d_]+))?/);. const iphone = !ipad && ua.match(/(iPhone\sOS|iOS)\s([\d_]+)/);. const windows = platform === 'Win32';. let macos = platform === 'MacIntel'; // iPadOs 13 fix.. const iPadScreens = ['1024x1366', '1366x1024', '834x1194', '1194x834', '834x1112', '1112x834', '768x1024', '1024x768', '820x1180', '1180x820', '810x1080', '1080x810'];.. if (!ipad && macos && s
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1020
            Entropy (8bit):4.583416649185365
            Encrypted:false
            SSDEEP:24:dFYFGJmRqxsYmRsGbzpKpuMDTFXeXUMNtnYPvz:dF67AUOGbzprcB6ZYXz
            MD5:B02ABA3407E140C235E3B88E09677854
            SHA1:DAE2CCAD0EE336BDACA26600872F88EB7025D51D
            SHA-256:2A3D17EDCA59159B3E64926196B88D1150798A7DCBA79777E8E5204DC98BC84F
            SHA-512:5B9833384EB14817755F6C85EBA633EC9F9B23731B891FC894876709F76AA023F1979DBFC6B9A3594EC1962440ACA053A01C9024728216685AD4E9DB9F7A8EC9
            Malicious:false
            Reputation:low
            Preview:import { getWindow, getDocument } from 'ssr-window';.let support;..function calcSupport() {. const window = getWindow();. const document = getDocument();. return {. smoothScroll: document.documentElement && 'scrollBehavior' in document.documentElement.style,. touch: !!('ontouchstart' in window || window.DocumentTouch && document instanceof window.DocumentTouch),. passiveListener: function checkPassiveListener() {. let supportsPassive = false;.. try {. const opts = Object.defineProperty({}, 'passive', {. // eslint-disable-next-line. get() {. supportsPassive = true;. }.. });. window.addEventListener('testPassiveListener', null, opts);. } catch (e) {// No support. }.. return supportsPassive;. }(),. gestures: function checkGestures() {. return 'ongesturestart' in window;. }(). };.}..function getSupport() {. if (!support) {. support = calcSupport();. }.. return support;.}..ex
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):5747
            Entropy (8bit):4.886435340829515
            Encrypted:false
            SSDEEP:96:26vikFbK72h6M+vACKFY0m+FpTDtyqSDmDhCyqSD6q6yaEK7ESCGGMDjG:Hik+vM+pkY0mw/IqSDEhVqSD6q6yaz7s
            MD5:4E55054DC264D60DB050FDF27B8A3980
            SHA1:86A30CEEDDAC5E42E647B0DA3FBA543A26B8C3AF
            SHA-256:7CBA7D6C91FD6C6B1E2C0B9FEC6BDCB0848AD99297874BEECEAACD858A710A2F
            SHA-512:6CC61BCE03C2989E9361CF8025927326AAD5C235C15F24946A01E624F4D90473722B52955B556A4BF87975B22F6BC928CF23C656982E63F17D624C8FFA542579
            Malicious:false
            Reputation:low
            Preview:import { getWindow } from 'ssr-window';..function deleteProps(obj) {. const object = obj;. Object.keys(object).forEach(key => {. try {. object[key] = null;. } catch (e) {// no getter for object. }.. try {. delete object[key];. } catch (e) {// something got wrong. }. });.}..function nextTick(callback, delay = 0) {. return setTimeout(callback, delay);.}..function now() {. return Date.now();.}..function getComputedStyle(el) {. const window = getWindow();. let style;.. if (window.getComputedStyle) {. style = window.getComputedStyle(el, null);. }.. if (!style && el.currentStyle) {. style = el.currentStyle;. }.. if (!style) {. style = el.style;. }.. return style;.}..function getTranslate(el, axis = 'x') {. const window = getWindow();. let matrix;. let curTransform;. let transformMatrix;. const curStyle = getComputedStyle(el, null);.. if (window.WebKitCSSMatrix) {. curTransform = curStyle.transform || curStyle.webkitTransform;.. i
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1171
            Entropy (8bit):4.6387345432992415
            Encrypted:false
            SSDEEP:24:Wm/kT+r8uUb5NuJ0lRutY3+v6p++6khWrkH1YcHg0aIi2t6wQzQHSn/Jt6HlQzHi:f/kT+IHAJdxypeNrWC+g0aVLwQzqSnWb
            MD5:5E3B5CB99E3AA7D49BB3AC7231D22898
            SHA1:E2704887B05F6B12BDA0AA1F9503542FFA401267
            SHA-256:54049409193DB9ED5B2384E8EB4123626D5582005AB552B30DD402D1A376331E
            SHA-512:E9034EB91F94515E886507FD8BDB1B2DF97E627CBD326319F44D39E82BC2F8939273974C7DEB383CDDFB7171109DC7F6160A61C647197C2DE9D5F47FBFE6BDCD
            Malicious:false
            Reputation:low
            Preview:import { isObject } from './utils.js';.import { paramsList } from './params-list.js';..function getChangedParams(swiperParams, oldParams) {. const keys = [];. if (!oldParams) return keys;.. const addKey = key => {. if (keys.indexOf(key) < 0) keys.push(key);. };.. const watchParams = paramsList.filter(key => key[0] === '_').map(key => key.replace(/_/, ''));. watchParams.forEach(key => {. if (key in swiperParams && key in oldParams) {. if (isObject(swiperParams[key]) && isObject(oldParams[key])) {. const newKeys = Object.keys(swiperParams[key]);. const oldKeys = Object.keys(oldParams[key]);.. if (newKeys.length !== oldKeys.length) {. addKey(key);. } else {. newKeys.forEach(newKey => {. if (swiperParams[key][newKey] !== oldParams[key][newKey]) {. addKey(key);. }. });. oldKeys.forEach(oldKey => {. if (swiperParams[key][oldKey] !== oldParams[key][oldKey]) addKey(key
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1231
            Entropy (8bit):4.787278669784192
            Encrypted:false
            SSDEEP:24:8z+/kT+ROG1dk+Lzkm6BWNu2RnIYLiViboho4LTeTrpv99yUOFVVKWLtGYIsiIEj:J/kT+R5Qnm6BP+IsiVibcDLSvp99yUOG
            MD5:FF9B0A466D3903C9CEB6882748696425
            SHA1:DDE025AF98E59727AD8D2184CFB3647167E9DEBF
            SHA-256:DE6D0F635D6B7A15B6AD7630BC78C5DED65C539041293FF4C72A715D11D1D7B0
            SHA-512:615BD8AFCBB3763C7F2743A4C734D92AA4CD851715288145D732F48AD6604FE026C283DBFDD4080EE471B9769BF08BFAC604B4F1B98A54DB85832EC552738FA2
            Malicious:false
            Reputation:low
            Preview:import Swiper from 'swiper';.import { isObject, extend } from './utils.js';.import { paramsList } from './params-list.js';..function getParams(obj = {}) {. const params = {. on: {}. };. const passedParams = {};. extend(params, Swiper.defaults);. extend(params, Swiper.extendedDefaults);. params._emitClasses = true;. params.init = false;. const rest = {};. const allowedParams = paramsList.map(key => key.replace(/_/, ''));. Object.keys(obj).forEach(key => {. if (allowedParams.indexOf(key) >= 0) {. if (isObject(obj[key])) {. params[key] = {};. passedParams[key] = {};. extend(params[key], obj[key]);. extend(passedParams[key], obj[key]);. } else {. params[key] = obj[key];. passedParams[key] = obj[key];. }. } else if (key.search(/on[A-Z]/) === 0 && typeof obj[key] === 'function') {. params.on[`${key[2].toLowerCase()}${key.substr(3)}`] = obj[key];. } else {. rest[key] = obj[key];. }. });. ['navigation
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):934
            Entropy (8bit):4.616139718387101
            Encrypted:false
            SSDEEP:24:8w1uPysIsKbOUXz9BCPRCPICbiqRCbixxdn8dQ1BSrBN9y1U9:h1uPyBjhBCPRCPICjRCin2q+BDym9
            MD5:473C4FEBB4542C8A4064F6BD51B84DDD
            SHA1:EE8D03277CB9AB30AEF418F2119E33E8901F57BC
            SHA-256:77BBEA04B408B78373106A62B25D6E2588A74420B7B55965F2743B98133408B6
            SHA-512:334A1371B06B03EDB12AFF916263BC2587A4289A882E35EF9E31AC639F5B7F3A48D39EEDCA25E70164EA360F38790B31E83A89302BF417694B7A44779A991FC2
            Malicious:false
            Reputation:low
            Preview:import Swiper from 'swiper';.import { needsNavigation, needsPagination, needsScrollbar } from './utils.js';..function initSwiper(swiperParams) {. return new Swiper(swiperParams);.}..function mountSwiper({. el,. nextEl,. prevEl,. paginationEl,. scrollbarEl,. swiper.}, swiperParams) {. if (needsNavigation(swiperParams) && nextEl && prevEl) {. swiper.params.navigation.nextEl = nextEl;. swiper.originalParams.navigation.nextEl = nextEl;. swiper.params.navigation.prevEl = prevEl;. swiper.originalParams.navigation.prevEl = prevEl;. }.. if (needsPagination(swiperParams) && paginationEl) {. swiper.params.pagination.el = paginationEl;. swiper.originalParams.pagination.el = paginationEl;. }.. if (needsScrollbar(swiperParams) && scrollbarEl) {. swiper.params.scrollbar.el = scrollbarEl;. swiper.originalParams.scrollbar.el = scrollbarEl;. }.. swiper.init(el);.}..export { initSwiper, mountSwiper };
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (1741)
            Category:dropped
            Size (bytes):2090
            Entropy (8bit):4.744554756966573
            Encrypted:false
            SSDEEP:48:kFl9aBONs8INhyw2cofcezZOl2dAaJDcL0fVsaOn:kFlO/8TUll7aJDcwfuae
            MD5:C8F7C73BB5B9D0F9F675DEA5355BB562
            SHA1:2271F378C5D72D63E0F584CA8B6CBE95C1879EAC
            SHA-256:0685EC7D4569AC583A6C5A3ABFE06B5B91AB606A1D7E69A0EDE1A3C40A9CEC3B
            SHA-512:8BC93ACEE01E7992C0071A2BBE34C4B943408F035B5FBBD67C3E7F78275267B80A89B2753CE9E9F8CAD98C8F7F06DCED173265FE4580F4F326B02ED306F7FEBB
            Malicious:false
            Reputation:low
            Preview:/* underscore in name -> watch for changes */.const paramsList = ['modules', 'init', '_direction', 'touchEventsTarget', 'initialSlide', '_speed', 'cssMode', 'updateOnWindowResize', 'resizeObserver', 'nested', 'focusableElements', '_enabled', '_width', '_height', 'preventInteractionOnTransition', 'userAgent', 'url', '_edgeSwipeDetection', '_edgeSwipeThreshold', '_freeMode', '_autoHeight', 'setWrapperSize', 'virtualTranslate', '_effect', 'breakpoints', '_spaceBetween', '_slidesPerView', '_grid', '_slidesPerGroup', '_slidesPerGroupSkip', '_slidesPerGroupAuto', '_centeredSlides', '_centeredSlidesBounds', '_slidesOffsetBefore', '_slidesOffsetAfter', 'normalizeSlideIndex', '_centerInsufficientSlides', '_watchOverflow', 'roundLengths', 'touchRatio', 'touchAngle', 'simulateTouch', '_shortSwipes', '_longSwipes', 'longSwipesRatio', 'longSwipesMs', '_followFinger', 'allowTouchMove', '_threshold', 'touchMoveStopPropagation', 'touchStartPreventDefault', 'touchStartForcePreventDefault', 'touchReleas
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:HTML document, ASCII text
            Category:dropped
            Size (bytes):2281
            Entropy (8bit):4.754271557958187
            Encrypted:false
            SSDEEP:48:frUslMaaOgp5GwNGMAGtviTE7AnBGYyauo33uy+m+X9yAb4BFBy:fr5mXGmGSIBG/9guy+Uy
            MD5:41AED283BD7AFDAEF96A0CF46846C450
            SHA1:05C39B040837E3A7D208C4B2711FE5787C04DED9
            SHA-256:3EF135FA6AEFE58A921432F25F4296446ACBD9E00B421CAE9DF9B71CB77A8913
            SHA-512:81D21AA72B8BBA9A16DB8B8AEB7CBECF9B7D2CD48A26FCC187DF07E0B3FFCE0EB00505E122C32C7F3CDEEF5173BA3AEA18ADDC54C40C9899318BA52CDF9B220B
            Malicious:false
            Reputation:low
            Preview:<script>. import { onMount, onDestroy, beforeUpdate, afterUpdate } from 'svelte';. import { uniqueClasses } from './utils.js';.. export let zoom = undefined;. export let virtualIndex = undefined;.. let className = undefined;. export { className as class };.. let slideEl = null;. let slideClasses = 'swiper-slide';.. let swiper = null;. let eventAttached = false;.. const updateClasses = (_, el, classNames) => {. if (el === slideEl) {. slideClasses = classNames;. }. };.. const attachEvent = () => {. if (!swiper || eventAttached) return;. swiper.on('_slideClass', updateClasses);. eventAttached = true;. };.. const detachEvent = () => {. if (!swiper) return;. swiper.off('_slideClass', updateClasses);. eventAttached = false;. };.. $: slideData = {. isActive:. slideClasses.indexOf('swiper-slide-active') >= 0 ||. slideClasses.indexOf('swiper-slide-duplicate-active') >= 0,. isVisible: slideClasses.indexOf('swiper-slide-visible') >= 0,
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):13298
            Entropy (8bit):4.787779863203995
            Encrypted:false
            SSDEEP:384:d7hZ8Dx6aV0+RikEUATQXg6galaKr6leU57OXbmp2isl5LYZnJrDmY:+6AvY
            MD5:82BBBC0E2C7E6EDA52CEB23B0697B081
            SHA1:C82BF9BE391F7DF6B065325AF20074223ED4E482
            SHA-256:FCB891109EAC14BD37A52C5CF0E5FC99D20B0952FF9881408134F93B52A59BF2
            SHA-512:07CF57501AD5608F8BE309989EE741F07DCEEDDE7CB4BA201CF843C3FBF508D178900CB3B9F2B5CF9C58B70F28CE1DE45B8A93C59C4EC546BE9FB6CF7A17E1C6
            Malicious:false
            Reputation:low
            Preview:import { SvelteComponentTyped } from 'svelte';.import { SwiperOptions, Swiper as SwiperClass } from '../types/';..// @ts-ignore.interface SwiperProps extends svelte.JSX.HTMLAttributes<HTMLElementTagNameMap['div']> {}.interface SwiperProps extends SwiperOptions {}..// @ts-ignore.interface SwiperSlideProps extends svelte.JSX.HTMLAttributes<HTMLElementTagNameMap['div']> {. /**. * Enables additional wrapper required for zoom mode. *. * @default false. */. zoom?: boolean;.. /**. * Slide's index in slides array/collection. *. * @default false. */. virtualIndex?: number;.}..declare class Swiper extends SvelteComponentTyped<. SwiperProps,. {. swiper: CustomEvent<void>;. /**. * Event will be fired in when autoplay started. */. autoplayStart: CustomEvent<[swiper: SwiperClass]>;. /**. * Event will be fired when autoplay stopped. */. autoplayStop: CustomEvent<[swiper: SwiperClass]>;. /**. * Event will be fired when slide changed with autoplay. */. autop
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):381
            Entropy (8bit):4.816195185278631
            Encrypted:false
            SSDEEP:6:UzSFtAASX+PxKXawIAfMRLidMfZCSleO5ugiw1944qR9lHpTP9puAv/3TkQkMUCh:UzSgASXSPmkxtfESR5ugiww4+9TTbuWH
            MD5:091B5F5DD55C91F31E870890D328BD37
            SHA1:325BE06F47C50106F4A3A892F1E533725C618337
            SHA-256:8E839E6058658E962E4BBAB7BDE69F9F4789112F5686C18C69DAF062BD95DD4F
            SHA-512:B3AC1B2169F24888AE99315EFBE10357ACC49D40E571983F545415AF4875846785D7EB988AEF3A9D24926F161D4562641B7A316C105B6B87AEC9855F17F8990A
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper Svelte 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..import Swiper from './swiper.svelte';.import SwiperSlide from './swiper-slide.svelte';.export { Swiper, SwiperSlide };
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:HTML document, ASCII text
            Category:dropped
            Size (bytes):4514
            Entropy (8bit):4.740629581391987
            Encrypted:false
            SSDEEP:96:8Uf0+0nw3sMOWUxq7OBbhYG67ee7QG8OzQd4Yc1y3fSPGpiRjOCcVlI1a5u8:JhC9kSBbhYG67eQQG8YQdpc1gSYsjDc7
            MD5:155BD13717629B79468B5661D79F1DAA
            SHA1:F5A247C99778E34145A7715ABAB54746171FD161
            SHA-256:B97B27B1C0A64AD23464CD131BD56B0C1E6DA21287254FE618DA525CCD5FB83D
            SHA-512:F12EA7D86DB16ECB207E98E53B855F06DD26CB466378CCA6D0289F4774FAC6C2E985D02698649A9CB27F972B0DF3F29FE72611DBF1D0BCA798F94E3CBBBD3C39
            Malicious:false
            Reputation:low
            Preview:<script>. import {. onMount,. onDestroy,. afterUpdate,. createEventDispatcher,. tick,. beforeUpdate,. } from 'svelte';. import { getParams } from './get-params.js';. import { initSwiper, mountSwiper } from './init-swiper.js';. import {. needsScrollbar,. needsNavigation,. needsPagination,. uniqueClasses,. extend,. } from './utils.js';. import { getChangedParams } from './get-changed-params.js';. import { updateSwiper } from './update-swiper.js';.. const dispatch = createEventDispatcher();.. let className = undefined;. export { className as class };.. let containerClasses = 'swiper';. let breakpointChanged = false;. let swiperInstance = null;. let oldPassedParams = null;.. let paramsData;. let swiperParams;. let passedParams;. let restProps;.. let swiperEl = null;. let prevEl = null;. let nextEl = null;. let scrollbarEl = null;. let paginationEl = null;. let virtualData = { slides: [] };.. export function swiper() {. return sw
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):3983
            Entropy (8bit):4.777597745315783
            Encrypted:false
            SSDEEP:96:z3U6huIALIkYMBMxSGmw4ToUkgaj3x3LLyB:nhuTLIkRBMxOoUk5NL4
            MD5:069B7532287E1120CDA578EB21C22576
            SHA1:852007B6EE221093F70A2BECB2655B0E8E26EB5B
            SHA-256:07BE35D1F6CE6689FC56535DC2FD094B33E27EA009BA44FD763624FA300B8077
            SHA-512:ED80C26EC5C917F7C915DD740D74C6218056C2469A70A5228194EED02EF2FC2BDF8A45069F2DA0C9DE56B21C0EF1AFFDEE443CDAA76005BE357154612D4E90EC
            Malicious:false
            Reputation:low
            Preview:import { isObject, extend } from './utils.js';..function updateSwiper({. swiper,. passedParams,. changedParams,. nextEl,. prevEl,. scrollbarEl,. paginationEl.}) {. const updateParams = changedParams.filter(key => key !== 'children' && key !== 'direction');. const {. params: currentParams,. pagination,. navigation,. scrollbar,. thumbs. } = swiper;. let needThumbsInit;. let needControllerInit;. let needPaginationInit;. let needScrollbarInit;. let needNavigationInit;.. if (changedParams.includes('thumbs') && passedParams.thumbs && passedParams.thumbs.swiper && currentParams.thumbs && !currentParams.thumbs.swiper) {. needThumbsInit = true;. }.. if (changedParams.includes('controller') && passedParams.controller && passedParams.controller.control && currentParams.controller && !currentParams.controller.control) {. needControllerInit = true;. }.. if (changedParams.includes('pagination') && passedParams.pagination && (passedParams.pagination.el || pagi
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1376
            Entropy (8bit):4.962647861301955
            Encrypted:false
            SSDEEP:24:gYQnwNWvp4kHuxYNa0nr5sKUmIQLA+GsCs0C32CTKtQ/daK28yaKszv3qsu6puTN:JQnwNEXHuxSa0nr5sKUmj0+GsCNC32CS
            MD5:86FFEEC7F078B46A888281A06D6826EE
            SHA1:D461C0182245F488130EFDE92D1CEDDD3E3D4203
            SHA-256:0ACA58D3F5ADFC74F16C4CA9A03866DE922471FB6B83E20127F3C743348CF0AE
            SHA-512:7D5E519CBBBAE511C3DE205EACDFF0F0E9D32A57E523FAA59766922F0D1D00CBC8A1CEA44E208000CE23A0D954E551B604F4E4F3A77C5EF9F70FA3734F430660
            Malicious:false
            Reputation:low
            Preview:function isObject(o) {. return typeof o === 'object' && o !== null && o.constructor && Object.prototype.toString.call(o).slice(8, -1) === 'Object';.}..function extend(target, src) {. const noExtend = ['__proto__', 'constructor', 'prototype'];. Object.keys(src).filter(key => noExtend.indexOf(key) < 0).forEach(key => {. if (typeof target[key] === 'undefined') target[key] = src[key];else if (isObject(src[key]) && isObject(target[key]) && Object.keys(src[key]).length > 0) {. if (src[key].__swiper__) target[key] = src[key];else extend(target[key], src[key]);. } else {. target[key] = src[key];. }. });.}..function needsNavigation(params = {}) {. return params.navigation && typeof params.navigation.nextEl === 'undefined' && typeof params.navigation.prevEl === 'undefined';.}..function needsPagination(params = {}) {. return params.pagination && typeof params.pagination.el === 'undefined';.}..function needsScrollbar(params = {}) {. return params.scrollbar && typeof param
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):183
            Entropy (8bit):4.543461774434355
            Encrypted:false
            SSDEEP:3:4i1F3FmWUdYgk7mB+cXuTU/pGreYdVQ1F3Fm/pAMMyXQ1F3Fm/pKIiVQ1F3F4K+C:4iP1vUygkqpuTYYdVQP1aM6QP1VVQP1r
            MD5:EB5915D4F32D9C78EF6136E41DD53FEC
            SHA1:5D3498E81F96BDAAD599BA10D6ABCEAF34EBE31E
            SHA-256:F38DE91C0F358EF33080BCCBDD537DF6343B44DF245D76FE1519AD2F6216F231
            SHA-512:EE3FB7B785563993401395CC1515B7390563E3A8ABFBD94C315B759130CD909AD22B3BCA1EECE884B9018D41CF5C39E5DB660F66450DAAA179D8FC125E45FE10
            Malicious:false
            Reputation:low
            Preview:export * from './shared';.export { default as Swiper } from './swiper-class';.export * from './swiper-events';.export * from './swiper-options';.export * from './modules/public-api';.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1755
            Entropy (8bit):4.428146866032324
            Encrypted:false
            SSDEEP:48:g12c20IzJlKB3VSNzV9giZVD5uKT0bxMVyxGVtbwVquHs+K:g12c20UJsBIx5pQbK08QZsP
            MD5:21CE44BA23B3691FB95A6E65D9E017BA
            SHA1:D590DDD0E152ED2188A329DB24C99CE35DEBCFB9
            SHA-256:84E0F838B9A5D0587A6F72B415A46E94885F0F6BC1789C957312E7D1E72F1E64
            SHA-512:FDD623C2024F1338DEA4E59FAD8AC7332781A8ECF51D1D2DE398E04667B25423D1E48610C75FA72F115BFB829ED0B6D79FA3E8B08D2BF6F566EC10BDD9B63BD5
            Malicious:false
            Reputation:low
            Preview:export interface A11yMethods {}..export interface A11yEvents {}..export interface A11yOptions {. /**. * Enables A11y. *. * @default true. */. enabled?: boolean;.. /**. * Message for screen readers for previous button. *. * @default 'Previous slide'. */. prevSlideMessage?: string;.. /**. * Message for screen readers for next button. *. * @default 'Next slide'. */. nextSlideMessage?: string;.. /**. * Message for screen readers for previous button when swiper is on first slide. *. * @default 'This is the first slide'. */. firstSlideMessage?: string;.. /**. * Message for screen readers for next button when swiper is on last slide. *. * @default 'This is the last slide'. */. lastSlideMessage?: string;.. /**. * Message for screen readers for single pagination bullet. *. * @default 'Go to slide {{index}}'. */. paginationBulletMessage?: string;.. /**. * CSS class name of A11y notification. *. * @default 'swiper-notification'.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):2290
            Entropy (8bit):4.584629921613706
            Encrypted:false
            SSDEEP:48:Vv2ZOjOfK1O2xxd0Cn2zqh5m52txxhy1Qe1U9K4p740xm3Lp8/eprni9Yik769hE:Vv2Z1SY2xxd/2OhE52rRe/4S0QLRpTik
            MD5:7F45ECFE4E9BECAA5569C98348CB1CD7
            SHA1:BD65F61B127DDDF9CCD1EAC4A702E303ED8AE143
            SHA-256:5E49FFB9D4B58B3DBF210FA82892A52BEEBC061ABC5EE671352B0CF9733C9AE9
            SHA-512:AE9214448E56434AD43E1F99EECAE8E23B904AC46AE13C7E2F0A728F90333EB49B722A47DCC73966AB53EB5E517E48DF8B2A51EFE5172534C202DBC53C8D81E5
            Malicious:false
            Reputation:low
            Preview:import Swiper from '../swiper-class';..export interface AutoplayMethods {. /**. * Whether autoplay enabled and running. */. running: boolean;.. /**. * Start autoplay. */. start(): boolean;.. /**. * Stop autoplay. */. stop(): boolean;.}..export interface AutoplayEvents {. /**. * Event will be fired in when autoplay started. */. autoplayStart: (swiper: Swiper) => void;. /**. * Event will be fired when autoplay stopped. */. autoplayStop: (swiper: Swiper) => void;. /**. * Event will be fired when slide changed with autoplay. */. autoplay: (swiper: Swiper) => void;.}../**. * Object with autoplay parameters or boolean `true` to enable with default settings.. *. * @example. * ```js. * const swiper = new Swiper('.swiper', {. * autoplay: {. * delay: 5000,. * },. * });. * ```. */.export interface AutoplayOptions {. /**. * Delay between transitions (in ms). If this parameter is not specified, auto play will be disabled. *. * If you need to specif
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):857
            Entropy (8bit):4.478962716732535
            Encrypted:false
            SSDEEP:24:8Ev2PR/4GP04Ghbp6GQBH2J2294GP04Ghbp6GQBpJgvKh4Z3SiS7gn:Vv2PRwGZG6R2J22mGZG6nJ8Kh40Vgn
            MD5:71C539974BD7A0FF6D4F9104026938E4
            SHA1:646C15DC009666B3424B5B1D6FFD5D67461E86B9
            SHA-256:D9C59CCB78167EB9D90112B19B05EEE52A7F268E229DF2569B556594F406A572
            SHA-512:6ECA6EFA8DDE62FE231B0F2DB32571C2B45431B31F3EF8BF1B08279D7D6E521D071C43AE8E4F82DA4281C12D6CAEDE64FA642FA08ED39C47FA875934CEF8ACC1
            Malicious:false
            Reputation:low
            Preview:import Swiper from '../swiper-class';..export interface ControllerMethods {. /**. * Pass here another Swiper instance or array with Swiper instances that should be controlled. * by this Swiper. */. control?: Swiper | Swiper[];.}..export interface ControllerEvents {}..export interface ControllerOptions {. /**. * Pass here another Swiper instance or array with Swiper instances that should be controlled. * by this Swiper. */. control?: Swiper | Swiper[];.. /**. * Set to `true` and controlling will be in inverse direction. *. * @default false. */. inverse?: boolean;.. /**. * Defines a way how to control another slider: slide by slide. * (with respect to other slider's grid) or depending on all slides/container. * (depending on total slider percentage).. *. * @default 'slide'. */. by?: 'slide' | 'container';.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):438
            Entropy (8bit):4.486031987818897
            Encrypted:false
            SSDEEP:12:n1Vo3AX2t22PJ2vft8/WD/Beo4cpzKBKiiK/9tm8N:nH4AX2t2E2uWD/H4imBRN
            MD5:45A6E3F3A619459EB841E78CE0796DAE
            SHA1:F8FC35DA1D59989DBCDE3A561292A83523636D01
            SHA-256:9E0BF1F4A614DC7AE4AA5B2EA1D856F78A5D11B7BE9EA17DE873A0C4ABCCEEE3
            SHA-512:C2402D57BAEB8612F533F7A91B1B11627549D1A4B2E1E870ABCD6CBD8DF790FD2A569F2AB367AD137008C155ED685FEF154074D5E71458B513E70B6F333F7D1B
            Malicious:false
            Reputation:low
            Preview:import { CSSSelector } from '../shared';..export interface CardsEffectMethods {}..export interface CardsEffectEvents {}..export interface CardsEffectOptions {. /**. * Enables slides shadows. *. * @default true. */. slideShadows?: boolean;. /**. * CSS selector of the element inside of the slide to transform instead of the slide itself. Useful to use with cssMode. *. * @default null. */. transformEl?: CSSSelector;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):885
            Entropy (8bit):4.453722578998718
            Encrypted:false
            SSDEEP:24:nH4AX2Ld2L02L+WD/fqW16WfCF91xWXx64imBRN:H4AX2J2Y2aEyWMD9bw4QBRN
            MD5:00416944C1968B195217C76FEE42E2FE
            SHA1:D73770709D572BCF10A222495988BB682E901517
            SHA-256:A241FF00D23A28523174FC5BC8ED0D51144E6699E66A016042BC72A6B7A60F91
            SHA-512:34B9BEA32979CB266E67327556D1D80E412BBC15FA7768E5CA232B62B4FF19A12A6F3216D72085E418DBA6B1C9FF384228733266F45652F1793FCDA45FC9F40B
            Malicious:false
            Reputation:low
            Preview:import { CSSSelector } from '../shared';..export interface CoverflowEffectMethods {}..export interface CoverflowEffectEvents {}..export interface CoverflowEffectOptions {. /**. * Enables slides shadows. *. * @default true. */. slideShadows?: boolean;. /**. * Slide rotate in degrees. *. * @default 50. */. rotate?: number;. /**. * Stretch space between slides (in px). *. * @default 0. */. stretch?: number;. /**. * Depth offset in px (slides translate in Z axis). *. * @default 100. */. depth?: number;. /**. * Slide scale effect. *. * @default 1. */. scale?: number;. /**. * Effect multiplier. *. * @default 1. */. modifier?: number;. /**. * CSS selector of the element inside of the slide to transform instead of the slide itself. Useful to use with cssMode. *. * @default null. */. transformEl?: CSSSelector;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text, with very long lines (331)
            Category:dropped
            Size (bytes):2589
            Entropy (8bit):4.636901352801288
            Encrypted:false
            SSDEEP:48:H4A4z02t2E2ZbXXpt5ld3KbXXpt5dvrQBRCz0Hk/at8GlTYhjFtyrl6V1O:YFz02t2E2ZnLVKn3vjitMjFI6VU
            MD5:DC31134FF8018FFE66167FBBF4F2ADCE
            SHA1:315388D7C5A5C3389DAFC007917D5C7FAE10A00F
            SHA-256:1B166033E9EC75F4C47B9756703EE53032F6AD9C105BA4952D0A325A7B1B9A56
            SHA-512:B38334122452096ABEC24DCE251FB8182E63A21BC479BEDAE0F0DC279DB6C20F404E6120B96B3039710C02F11794D78A1D69FE41DDDB4571695D9BE1FBA74274
            Malicious:false
            Reputation:low
            Preview:import { CSSSelector } from '../shared';..interface CreativeEffectTransform {. translate?: (string | number)[];. rotate?: number[];. opacity?: number;. scale?: number;. shadow?: boolean;. origin?: string;.}..export interface CreativeEffectMethods {}..export interface CreativeEffectEvents {}..export interface CreativeEffectOptions {. /**. * Previous slide transformations. Accepts object of the following type:. *. * @example. * ```js. * {. * // Array with translate X, Y and Z values. * translate: (string | number)[];. * // Array with rotate X, Y and Z values (in deg). * rotate?: number[];. * // Slide opacity. * opacity?: number;. * // Slide scale. * scale?: number;. * // Enables slide shadow. * shadow?: boolean;. * // Transform origin, e.g. `left bottom`. * origin?: string;. * }. * ```. *. */. prev?: CreativeEffectTransform;. /**. * Next slide transformations.. *. * @example. * ```js. * {. * // Array
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):472
            Entropy (8bit):4.460252940546162
            Encrypted:false
            SSDEEP:12:4i2p2KPJ2Lft8/WD/BRe0spt8/W3j/I/WLDBjk+ipMq/W8v:gp2426WD/negWzwWLD9k+SLW+
            MD5:55CA141B8F933F775DB42FBA45B34CB6
            SHA1:8F5BDFACF903D1C5D959546AC00D9AC70DAAC785
            SHA-256:D2A32B1C9E3CFBCEB0107710704602EA3003D2B27CD337FD22009DC838E02413
            SHA-512:B74A022AF3C1B825AE6E4B7B7425ECD872447665CEC58E0A110916308F44AE0A0C9A6B4C696747134157325798DE4404D9BB954677325374B7C17C7C654BB482
            Malicious:false
            Reputation:low
            Preview:export interface CubeEffectMethods {}..export interface CubeEffectEvents {}..export interface CubeEffectOptions {. /**. * Enables slides shadows. *. * @default true. */. slideShadows?: boolean;. /**. * Enables main slider shadow. *. * @default true. */. shadow?: boolean;. /**. * Main shadow offset in px. *. * @default 20. */. shadowOffset?: number;. /**. * Main shadow scale ratio. *. * @default 0.94. */. shadowScale?: number;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):436
            Entropy (8bit):4.466130136609745
            Encrypted:false
            SSDEEP:12:n1Vo3AX282pPJ2ScrX/Gdxleo4cpzKBKiiK/9tm8N:nH4AX282n2lvGb4imBRN
            MD5:171B893A6464384B7E2897A59316450C
            SHA1:B2E03CB0F8028D3C3351FCDBAD031219E6D3A459
            SHA-256:B0EE0D1936AA567BC5C5753062E993E8734DF2DFF1ECC148CD2113D68BDDE981
            SHA-512:72A90EE91D9DE77CB0D20C0F9E0C61D5646DED65DD1CFC938B1B1C32043CC3B509E020D3693D19D273DADF9F0ADBC511113A76D1079D6A247B7DBD8674E0E4A8
            Malicious:false
            Reputation:low
            Preview:import { CSSSelector } from '../shared';..export interface FadeEffectMethods {}..export interface FadeEffectEvents {}..export interface FadeEffectOptions {. /**. * Enables slides cross fade. *. * @default false. */. crossFade?: boolean;. /**. * CSS selector of the element inside of the slide to transform instead of the slide itself. Useful to use with cssMode. *. * @default null. */. transformEl?: CSSSelector;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):530
            Entropy (8bit):4.491645216287411
            Encrypted:false
            SSDEEP:12:n1Vo3AX2n20PJ2Vft8/WD/BqVGst8/NPeo4cpzKBKiiK/9tm8N:nH4AX2n2m2sWD/803z4imBRN
            MD5:C13B420FFF3A7E6F9230571D6786EC02
            SHA1:E3C920551DBC67E5044C577E7849C279E7A93A9B
            SHA-256:C08B3D1B112718A54CD98B121C3C2A3DDA95DA50EEE6E85267FE00DA59D373A4
            SHA-512:0742D790EED7C3CEA4DB25B6EE56E41F5A66E43F5E5585FE725FD6AE86A50D68784CDB9A36E18390710528289F14706D7CCC2A895CE6A7DA05D73368E9D26D8D
            Malicious:false
            Reputation:low
            Preview:import { CSSSelector } from '../shared';..export interface FlipEffectMethods {}..export interface FlipEffectEvents {}..export interface FlipEffectOptions {. /**. * Enables slides shadows. *. * @default true. */. slideShadows?: boolean;. /**. * Limit edge slides rotation. *. * @default true. */. limitRotation?: boolean;. /**. * CSS selector of the element inside of the slide to transform instead of the slide itself. Useful to use with cssMode. *. * @default null. */. transformEl?: CSSSelector;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1118
            Entropy (8bit):4.49217779346733
            Encrypted:false
            SSDEEP:24:gaN252DzrF3SN0FofNSFAfNJ7INqBFsANqjwQUenICsYvW4:go252DzJSOCfgyf77IIBSAIjwDdCVf
            MD5:FC931EC3E9E9E9BE63630079E2751AF1
            SHA1:9C04233FC09871E009029DDDC61FB8F8DF99B371
            SHA-256:CD0109FD2693A88449D77ABC75D3849285FDCB5E1345928BA9A75F0EB7F6538C
            SHA-512:58940ED09F66ADEB35592908847B7323BE26CCC5E0BAA8B1CB94B5CED3E63915C47F9B7C083B2A6F5A034EBC13DEC47365E20358F75BEC06492A61D872AAC7AA
            Malicious:false
            Reputation:low
            Preview:export interface FreeModeMethods {. onTouchMove(): void;. onTouchEnd(): void;.}..export interface FreeModeEvents {}..export interface FreeModeOptions {. enabled?: boolean;.. /**. * If enabled, then slide will keep moving for a while after you release it. *. * @default true. */. momentum?: boolean;.. /**. * Higher value produces larger momentum distance after you release slider. *. * @default 1. */. momentumRatio?: number;.. /**. * Higher value produces larger momentum velocity after you release slider. *. * @default 1. */. momentumVelocityRatio?: number;.. /**. * Set to `false` if you want to disable momentum bounce in free mode. *. * @default true. */. momentumBounce?: boolean;.. /**. * Higher value produces larger momentum bounce effect. *. * @default 1. */. momentumBounceRatio?: number;.. /**. * Minimum touchmove-velocity required to trigger free mode momentum. *. * @default 0.02. */. minimumVelocity?: number;.. /**.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):441
            Entropy (8bit):4.59188336139251
            Encrypted:false
            SSDEEP:12:4i2aE2ahPJ2aKUK9QxLEz9eDlv/Kve8SGLKt60i/ZR4K:gaE2af2aPv1EzQpKkt6X0K
            MD5:BDB8D067FB4194AFBF703B0FA00020DF
            SHA1:ADD286F25CAF7EFC3875D99A2512672E6A096950
            SHA-256:2784AE11E899F4D74B423D97796D75EC96719A3FC75575DDD90AE9EE48734865
            SHA-512:D7439EF66F4ABBA3DCD49265DD023DE837C4D33CC1DCD545C8A2C681412B2ADE9B7B3D4B877273DA55565296ABD0AF812E3543409AD2F6B3FBED630C430273BD
            Malicious:false
            Reputation:low
            Preview:export interface GridMethods {}..export interface GridEvents {}..export interface GridOptions {. /**. * Number of slides rows, for multirow layout. *. * @note `rows` > 1 is currently not compatible with loop mode (`loop: true`). *. * @default 1. */. rows?: number;.. /**. * Can be `'column'` or `'row'`. Defines how slides should fill rows, by column or by row. *. * @default 'column'. */. fill?: 'row' | 'column';.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):775
            Entropy (8bit):4.544225076030252
            Encrypted:false
            SSDEEP:24:8Ev23Rh23RI/FHNc9367z523Rtil6cvAiuOgbxUlx2in:Vv23j23qNHiJcd234AiuOGEwC
            MD5:5408A1EE15E7CCC1BEBA4BD5DC4509AB
            SHA1:8509A561D3B608BD30397C4B5A3523110F7450C0
            SHA-256:47ECE250AE0A7255E9679ED259E50CC63252B1C95252FC6CA14FA60C5347F747
            SHA-512:58F9857C1B88FB5BB9B0B679DD59DB326F1352027D31FCBF8CD6918D2545C25266224165DC161DE8339FED7675F2FA9E6A7713481B57EA9D32546FF2EE8F4275
            Malicious:false
            Reputation:low
            Preview:import Swiper from '../swiper-class';..export interface HashNavigationMethods {}..export interface HashNavigationEvents {. /**. * Event will be fired on window hash change. */. hashChange: (swiper: Swiper) => void;. /**. * Event will be fired when swiper updates the hash. */. hashSet: (swiper: Swiper) => void;.}..export interface HashNavigationOptions {. /**. * Set to `true` to enable also navigation through slides (when hashnav. * is enabled) by browser history or by setting directly hash on document location. *. * @default false. */. watchState?: boolean;.. /**. * Works in addition to hashnav to replace current url state with the. * new one instead of adding it to history. *. * @default false. */. replaceState?: boolean;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):638
            Entropy (8bit):4.538360111035057
            Encrypted:false
            SSDEEP:12:4i23Iy23oPJ23KAOUmPzFLrCrTDLA+IWk/5vKuT6/bBbZ2rX/x2i/vdm/OzT:g3T23a23KCmZerU1D5iuO/bxIvx2i/Is
            MD5:7222BBDFA19C323F52B60B5C6347EDB7
            SHA1:6D6B0B9FA14BAC3A686731250C3ED9BBAECDEFB7
            SHA-256:2914F7EB45E9D77CAB9623DCECCB395037C2E3B1A6000B83452AA60425E3540E
            SHA-512:6A8FC2E601C4E4371021B340A791408FFB12FBE99EE85973E55AD67A2775BD01D19157FEA4C4A2CB9F0D369A990FF72C96026BAD64D7C514209B2BA24D0E7C7D
            Malicious:false
            Reputation:low
            Preview:export interface HistoryMethods {}..export interface HistoryEvents {}..export interface HistoryOptions {. /**. * Swiper page root, useful to specify when you use Swiper history mode not on root website page.. * For example can be `https://my-website.com/` or `https://my-website.com/subpage/` or `/subpage/`. *. *. * @default ''. */. root?: string;.. /**. * Works in addition to hashnav or history to replace current url state with the. * new one instead of adding it to history. *. * @default false. */. replaceState?: boolean;.. /**. * Url key for slides. *. * @default 'slides'. */. key?: string;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):839
            Entropy (8bit):4.557469919150582
            Encrypted:false
            SSDEEP:24:8Ev2Rz/0sPH3VBKPV8d2J/F0tOqul2eDvs9ZmGB69eqSCD+93:Vv2Rz/0sPH3VBKPV8d2JNwORl2e7s97F
            MD5:CF551D85400A1647BE63D0743AEB0414
            SHA1:7758592705A907622765F031F109AE4EB43DA83C
            SHA-256:A47F07B2FE6688C8D33E91D744CFA113D32385700FEBB24402ECDC2D83202B2C
            SHA-512:FF37BE0ABF754C74C038094761131D1ED2E810D484989588B111D50DF3E16DA84E32C724885626226E3C169CB76F1585040C7BCD12685A94C6EA68D50878BCAA
            Malicious:false
            Reputation:low
            Preview:import Swiper from '../swiper-class';..export interface KeyboardMethods {. /**. * Whether the keyboard control is enabled. */. enabled: boolean;.. /**. * Enable keyboard control. */. enable(): void;.. /**. * Disable keyboard control. */. disable(): void;.}..export interface KeyboardEvents {. /**. * Event will be fired on key press. */. keyPress: (swiper: Swiper, keyCode: string) => void;.}..export interface KeyboardOptions {. /**. * Set to `true` to enable keyboard control. *. * @default false. */. enabled?: boolean;. /**. * When enabled it will control sliders that are currently in viewport. *. * @default true. */. onlyInViewport?: boolean;. /**. * When enabled it will enable keyboard navigation by Page Up and Page Down keys. *. * @default true. */. pageUpDown?: boolean;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):2191
            Entropy (8bit):4.710647446855385
            Encrypted:false
            SSDEEP:48:A14A+0v2xL16D38c22WZY2Mpo/2Mz2EV7joacopZPJdcpJk/Wv05b46/AxK4:Ai50v2xM02WK22i2229ULjcpK+UJAxK4
            MD5:0187C29E198A8D06443BAC831B7E5BFF
            SHA1:26DEDBA07210AF61DDC322FBC6A4DD907EE99973
            SHA-256:18AFADB2092928B54A4F8500A375D7033A0BE9E6353BB0A3779F9408A87BC0A5
            SHA-512:D6D169FAD22F60FA28379F1CDABA3AFC7FE217DA3A3B8F107BC396D6F68F6ED35C17717344B0A7AC0C482CE049032190670CC16646C77D4790115471B26A173B
            Malicious:false
            Reputation:low
            Preview:import { Dom7Array } from 'dom7';.import { CSSSelector } from '../shared';.import Swiper from '../swiper-class';..export interface LazyMethods {. /**. * Load/update lazy images based on current slider state (position). */. load(): void;.. /**. * Force to load lazy images in slide by specified index. * @param number index number of slide to load lazy images in. */. loadInSlide(index: number): void;.}..export interface LazyEvents {. /**. * Event will be fired in the beginning of lazy loading of image. */. lazyImageLoad: (swiper: Swiper, slideEl: HTMLElement, imageEl: HTMLElement) => void;. /**. * Event will be fired when lazy loading image will be loaded. */. lazyImageReady: (swiper: Swiper, slideEl: HTMLElement, imageEl: HTMLElement) => void;.}..export interface LazyOptions {. /**. * Enables to check is the Swiper in view before lazy loading images on initial slides. *. * @default false. */. checkInView?: boolean;. /**. * Element to check scrolling
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1959
            Entropy (8bit):4.810933665018539
            Encrypted:false
            SSDEEP:48:goPtbiGbEX7DtbMbzqp7wYtbAUYzWbEZR7Sbj8+eXH2oA2oL:gi07ZF7FmR7SY32Z2y
            MD5:C27C5AA5EC3E654B61A7E18FC85943A7
            SHA1:21D9F55EB8D5630604DF628A67954F161434F754
            SHA-256:C9D433D2BD63F22107D3D5F70D255A9240CDE0D25C7DF5096685126930D560F6
            SHA-512:50498B3F4DAA41A04BE23665463846DB781F19A277A73D421E9A57F68678E984D9A9B30E7324DC5A1018D7C519F9C3F81C61695427A9ECFECD8D1A8C86390DA9
            Malicious:false
            Reputation:low
            Preview:export interface ManipulationMethods {. /**. * Add new slides to the end. slides could be. * HTMLElement or HTML string with new slide or. * array with such slides, for example:. *. * @example. * ```js. * appendSlide('<div class="swiper-slide">Slide 10"</div>'). *. * appendSlide([. * '<div class="swiper-slide">Slide 10"</div>',. * '<div class="swiper-slide">Slide 11"</div>'. * ]);. * ```. */. appendSlide(slides: HTMLElement | string | string[] | HTMLElement[]): void;.. /**. * Add new slides to the beginning. slides could be. * HTMLElement or HTML string with new slide or array with such slides, for example:. *. * @example. * ```js. * prependSlide('<div class="swiper-slide">Slide 0"</div>'). *. * prependSlide([. * '<div class="swiper-slide">Slide 1"</div>',. * '<div class="swiper-slide">Slide 2"</div>'. * ]);. * ```. */. prependSlide(slides: HTMLElement | string | string[] | HTMLElement[]): void;.. /**. * Add new slides to
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1744
            Entropy (8bit):4.563799263374634
            Encrypted:false
            SSDEEP:48:V54AX2oM0sPHyBK68d2aNltX2qJtdPSwQ1+iBmO2MwcYp4pwcBp4o:Vmc2oyPmK32aNf2aS5+/ewBewGr
            MD5:DBA2CF8644960CE9E4239D014688CAFB
            SHA1:16905FFB20AE2875450114474B6BA82A5ECF2CC0
            SHA-256:CA532D3AD3AA65D36BFB94A03BF982B918F30DDA0DA3D4760AA0297F29901BE9
            SHA-512:4E97980E8FFF4B684F0A09E65EBB4A66950FF72693F8AAB8F85C4BE3698F45B137D589603F9F044B368BAED55F34BB0F188F8E7D3A3D278357EAFB59556A71C1
            Malicious:false
            Reputation:low
            Preview:import Swiper from '../swiper-class';.import { CSSSelector } from '../shared';..export interface MousewheelMethods {. /**. * Whether the mousewheel control is enabled. */. enabled: boolean;.. /**. * Enable mousewheel control. */. enable(): void;.. /**. * Disable mousewheel control. */. disable(): void;.}..export interface MousewheelEvents {. /**. * Event will be fired on mousewheel scroll. */. scroll: (swiper: Swiper, event: WheelEvent) => void;.}..export interface MousewheelOptions {. /**. * Set to `true` to force mousewheel swipes to axis. So in horizontal mode mousewheel will work only with horizontal mousewheel scrolling, and only with vertical scrolling in vertical mode... *. * @default false. */. forceToAxis?: boolean;. /**. * Set to `true` and swiper will release mousewheel event and allow page scrolling when swiper is on edge positions (in the beginning or in the end).. *. * @default false. */. releaseOnEdges?: boolean;. /**. * Set
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1746
            Entropy (8bit):4.666054008434794
            Encrypted:false
            SSDEEP:48:H4A+0v2ycqIcynoP88uk2KN7v6fN7E6aJ2akuYecMmYeVsRQyAU8aVfMyObm:Y50v2yRIlnqJJ2KN76N7U2FePeVm2yVJ
            MD5:F2E5CA085B6848D69580012876683FFD
            SHA1:35458134CFAF5808EC17022841C851D50D5429D7
            SHA-256:C8ED23A0C74ADB2D571C3ED74767645942B8D76F88567BB452366F10B75FE6F3
            SHA-512:BBDEADD3671FEF0E6EFC1B5E3820540AD82EB669BA986450FAAC37BFC4CAB43451599DC7E63A52D8765C2F4F388FDEA6F9E96125413F80BAE9768C01A9B7211F
            Malicious:false
            Reputation:low
            Preview:import { CSSSelector } from '../shared';.import Swiper from '../swiper-class';..export interface NavigationMethods {. /**. * HTMLElement of "next" navigation button. */. nextEl: HTMLElement;.. /**. * HTMLElement of "previous" navigation button. */. prevEl: HTMLElement;.. /**. * Update navigation buttons state (enabled/disabled). */. update(): void;.. /**. * Initialize navigation. */. init(): void;.. /**. * Destroy navigation. */. destroy(): void;.}..export interface NavigationEvents {. /**. * Event will be fired on navigation hide. */. navigationHide: (swiper: Swiper) => void;. /**. * Event will be fired on navigation show. */. navigationShow: (swiper: Swiper) => void;.}..export interface NavigationOptions {. /**. * String with CSS selector or HTML element of the element that will work. * like "next" button after click on it. *. * @default null. */. nextEl?: CSSSelector | HTMLElement | null;.. /**. * String with CSS selector or H
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):6969
            Entropy (8bit):4.687238337588603
            Encrypted:false
            SSDEEP:192:r0OVx9DM3yseLtBtNstNhZeFoLhJgFkF3RRnW5thXo8shrvIiKeldUL6r4AVDh:r7Vx9DM3yL7AdIFoLhJgFIhRW5thXo1b
            MD5:5C355EC6D0B7FBB423144567B4150E9F
            SHA1:A5EF3E6AD29A799E09B5EB3D66835F9E57C1F617
            SHA-256:18E4258C6BE2FB7AB5488094D3A3D055A295C841DB7A9F4EED6CFDF83137715F
            SHA-512:5920263602195489E020774442681387BE23FAFB9E3D3C8AAB9649F8B1A5AA764295E895264E310B87ABB52008FA812DF869316FE0F7AE7A2D21646EB1351961
            Malicious:false
            Reputation:low
            Preview:import { Dom7Array } from 'dom7';.import { CSSSelector } from '../shared';.import Swiper from '../swiper-class';..export interface PaginationMethods {. /**. * HTMLElement of pagination container element. */. el: HTMLElement;.. /**. * Dom7 array-like collection of pagination bullets. * HTML elements. To get specific slide HTMLElement. * use `swiper.pagination.bullets[1]`.. */. bullets: Dom7Array[];.. /**. * Render pagination layout. */. render(): void;.. /**. * Update pagination state (enabled/disabled/active). */. update(): void;.. /**. * Initialize pagination. */. init(): void;.. /**. * Destroy pagination. */. destroy(): void;.}..export interface PaginationEvents {. /**. * Event will be fired after pagination rendered. */. paginationRender: (swiper: Swiper, paginationEl: HTMLElement) => void;.. /**. * Event will be fired when pagination updated. */. paginationUpdate: (swiper: Swiper, paginationEl: HTMLElement) => void;.. /**. * Ev
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):239
            Entropy (8bit):4.4200076503503
            Encrypted:false
            SSDEEP:6:4i2vEDUhQ2vE3LwFHvgQ2vE1Y5KhnJQApl0r/TX/ALkZ:4i2vM2vjFPJ2vigMnJ3arX/j
            MD5:AEFA17F56367FC525D93EA7AE5B9AF9F
            SHA1:F23EB829ED5930618E32AD3E2BA17F0A994CA0F5
            SHA-256:AF51CDC4AAC8D3D3EF578D092EDB86FF7A240A50AE4DD0B843667FB7A23363E6
            SHA-512:72DAA67E76D5552CE906B5AC1074BF13FFA1B7A212CB5B51DAD6F8E5941B0AFBCD3D12B140886FAD96C3CC650185D1090EE3C374970146EECD570D3D4A75440F
            Malicious:false
            Reputation:low
            Preview:export interface ParallaxMethods {}..export interface ParallaxEvents {}..export interface ParallaxOptions {. /**. * Enable, if you want to use "parallaxed" elements inside of slider. *. * @default false. */. enabled?: boolean;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):701
            Entropy (8bit):4.465619385165455
            Encrypted:false
            SSDEEP:12:4iP1rnP1OlP1POgP12Z1DzP12ZSegQP1206QP124UnP12Z2QP12Z+gdwVQP1bvgV:5RnPAlPggPQZ1DzPQZ7PQePQ4+PQZLP/
            MD5:F1A87C7FFBF08B16DC16EFBCC44C3052
            SHA1:F0FC3ABEE534A9204174C07FFA1DC736B5C1B67D
            SHA-256:4DB92E9E62F825C93784445417F3023E1882D1171125141872F6214225C11D17
            SHA-512:A21F15B8D001A06F8FB6863C393CFA54C01A1F627092585AE5C0920B0FCB05A8CF38421DC4C06CB230C8A9836B8BBEF2284A5414C6F180373F3F607491A44FA2
            Malicious:false
            Reputation:low
            Preview:export * from './a11y';.export * from './autoplay';.export * from './controller';.export * from './effect-coverflow';.export * from './effect-cube';.export * from './effect-fade';.export * from './effect-flip';.export * from './effect-creative';.export * from './effect-cards';.export * from './hash-navigation';.export * from './history';.export * from './keyboard';.export * from './lazy';.export * from './mousewheel';.export * from './navigation';.export * from './pagination';.export * from './parallax';.export * from './scrollbar';.export * from './thumbs';.export * from './virtual';.export * from './zoom';.export * from './free-mode';.export * from './grid';.export * from './manipulation';.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):2279
            Entropy (8bit):4.666465617690204
            Encrypted:false
            SSDEEP:48:H4A+0v2TpbXpaeaMa8Uk2YNbmtNKbtNCrdej52grbYezyJo9JmoIqfWmCuykwbVd:Y50v2tjbPvP2YNytNMtNicj52le+J6Jk
            MD5:4314B7244D1636E7C69DFEBA23B6D412
            SHA1:E2117C6F610E2D8AC1181F3BB3BE8E3968D4E26C
            SHA-256:DAA9A5F61DC1BF3E04F8C75CFE09068F50D836D4F398F18DC2E8E51DE39C5237
            SHA-512:815A20E19E5DE8773CAA267021BE586718D0BB15FE5B91E7559D615635282489B9E31796C69C1FC7C1006C012F0C41F79B377A4E153227AE151B4E97DE3C3487
            Malicious:false
            Reputation:low
            Preview:import { CSSSelector } from '../shared';.import Swiper from '../swiper-class';..export interface ScrollbarMethods {. /**. * HTMLElement of Scrollbar container element. */. el: HTMLElement;.. /**. * HTMLElement of Scrollbar draggable handler element. */. dragEl: HTMLElement;.. /**. * Updates scrollbar track and handler sizes. */. updateSize(): void;.. /**. * Updates scrollbar translate. */. setTranslate(): void;.. /**. * Initialize scrollbar. */. init(): void;.. /**. * Destroy scrollbar. */. destroy(): void;.}..export interface ScrollbarEvents {. /**. * Event will be fired on draggable scrollbar drag start. */. scrollbarDragStart: (swiper: Swiper, event: MouseEvent | TouchEvent | PointerEvent) => void;.. /**. * Event will be fired on draggable scrollbar drag move. */. scrollbarDragMove: (swiper: Swiper, event: MouseEvent | TouchEvent | PointerEvent) => void;.. /**. * Event will be fired on draggable scrollbar drag end. */. scrollbarD
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1211
            Entropy (8bit):4.585060487950581
            Encrypted:false
            SSDEEP:24:8Ev2Yr74GPNW2J1E5r02h2C4GPgdAdMWhhGEe7aWD6Gbw29vQsFPbFYHh64:Vv2ccGlz1E5r02h2PGYAeoGEemVGk29i
            MD5:EE9ABCDA1F062A01230682CB1F826170
            SHA1:64465FD112CD32A5212CCBAFE62C3A697B3498DC
            SHA-256:48C4222F8192885D0CC8DE9FF6CCAC4E97EAB50F239DFCEB4A0BB3F3AFDC1861
            SHA-512:A4721D90608BF7E35FA8174C14579BE7697987019CD2960158AD019DF30A4CEF5EA906A3B31E9ACEB4A107A2D55B24C8917E955AED23EEAEB97C62ACCB5F8FA9
            Malicious:false
            Reputation:low
            Preview:import Swiper from '../swiper-class';..export interface ThumbsMethods {. /**. * Swiper instance of thumbs swiper. */. swiper: Swiper;.. /**. * Update thumbs. */. update(initial: boolean): void;.. /**. * Initialize thumbs. */. init(): boolean;.}..export interface ThumbsEvents {}..export interface ThumbsOptions {. /**. * Swiper instance of swiper used as thumbs or object with Swiper parameters to initialize thumbs swiper. *. * @default null. */. swiper?: Swiper | null;. /**. * Additional class that will be added to activated thumbs swiper slide. *. * @default 'swiper-slide-thumb-active'. */. slideThumbActiveClass?: string;. /**. * Additional class that will be added to thumbs swiper. *. * @default 'swiper-thumbs'. */. thumbsContainerClass?: string;. /**. * When enabled multiple thumbnail slides may get activated. *. * @default true. */. multipleActiveThumbs?: boolean;. /**. * Allows to set on which thumbs active slide from edge
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):3017
            Entropy (8bit):4.560670808034504
            Encrypted:false
            SSDEEP:48:gpVrHaEpagij55a14DVQ1CDVeBXpn1s252OHF9qPuqT326MQR6mahjw9iLEQ12Fd:gpVrHJYgkbHJtJo5nG252OHsF20Y2FEU
            MD5:F88C2E18B2CFA22592762A0E1AD4798F
            SHA1:FF6B861BCCAC817F992372BD03ADD966149FC0FA
            SHA-256:AFDF342BAD1CE22B1FB70E626972B45C7CB7D9B911F5FB2F33E422F7EECD35F2
            SHA-512:826F85AEBC0903B671B170F4C9BA7FA7BF021BD8825499AE81B65B6C4EBFB4210392BC92A9F6F431BB6CD592AEEE11D7464A4E59CE949429C9BD696BEB040266
            Malicious:false
            Reputation:low
            Preview:export interface VirtualMethods {. /**. * Object with cached slides HTML elements. */. cache: object;.. /**. * Index of first rendered slide. */. from: number;.. /**. * Index of last rendered slide. */. to: number;.. /**. * Array with slide items passed by `virtual.slides` parameter. */. slides: any[];.. /*. * Methods. */.. /**. * Append slide. `slides` can be a single slide item or array with such slides.. */. appendSlide(slide: HTMLElement | string | HTMLElement[] | string[]): void;.. /**. * Prepend slide. `slides` can be a single slide item or array with such slides.. */. prependSlide(slide: HTMLElement | string | HTMLElement[] | string[]): void;.. /**. * Remove specific slide or slides. `slideIndexes` can be a number with slide index to remove or array with indexes.. */. removeSlide(slideIndexes: number[]): void;.. /**. * Remove all slides. */. removeAllSlides(): void;.. /**. * Update virtual slides state. */. update(force:
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1303
            Entropy (8bit):4.577202743462438
            Encrypted:false
            SSDEEP:24:8Ev2gcm0sPH1+iW0C8BKE8L1GM+RvJYGM+IVzKtGM+k2ge/FfKFNc+/hLiM252gp:Vv2gcm0sPH1brC8BKE8L1GTxyGTIVzIC
            MD5:5755481EA978C23DD537D1D931B58A21
            SHA1:8B0F9A1E6BC39E66951DF6C7ED34A1092376842A
            SHA-256:2C1AC410DC6B2BA10E5EFAC432034433249052564022CDF4B124935D3AB7BFE6
            SHA-512:E20A6BE6C23E08207D72B95F5DA81C709C7D5DB768D7587057235DD13B89459E0CB99F197034665E1CBB03297524A3AECF2CD7111682633A974C3AAF794DB010
            Malicious:false
            Reputation:low
            Preview:import Swiper from '../swiper-class';..export interface ZoomMethods {. /**. * Whether the zoom module is enabled. */. enabled: boolean;.. /**. * Current image scale ratio. */. scale: number;.. /**. * Enable zoom module. */. enable(): void;.. /**. * Disable zoom module. */. disable(): void;.. /**. * Zoom in image of the currently active slide. */. in(): void;.. /**. * Zoom out image of the currently active slide. */. out(): void;.. /**. * Toggle image zoom of the currently active slide. */. toggle(): void;.}..export interface ZoomEvents {. /**. * Event will be fired on zoom change. */. zoomChange: (swiper: Swiper, scale: number, imageEl: HTMLElement, slideEl: HTMLElement) => void;.}..export interface ZoomOptions {. /**. * Maximum image zoom multiplier. *. * @default 3. */. maxRatio?: number;. /**. * Minimal image zoom multiplier. *. * @default 1. */. minRatio?: number;. /**. * Enable/disable zoom-in by slide's double
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):81
            Entropy (8bit):4.2046437139889346
            Encrypted:false
            SSDEEP:3:4i2lmQsAdV4m5KJYwdVQ2l2SZXobs:4i2+AdV4fJhQ292s
            MD5:B0674DB2D867194E817E4104898C88B6
            SHA1:661ED4993160979090F21E71E8C923FD59CC9D32
            SHA-256:3D178394ACDDFF6D8604DC5222B9292C566B8C3C0CAE2BE283C3205F1695E99C
            SHA-512:C3BCF4041BF797827D6CD4FD077CA8F84B5C9A3F0325AADC6E3C4D44FEC39CC0D46BE402B3CD158F6995D547530CD45CFC07EF3D2338985D17D96A65213575E1
            Malicious:false
            Reputation:low
            Preview:export interface CSSSelector extends String {}..export interface SwiperModule {}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):12634
            Entropy (8bit):4.789130132183968
            Encrypted:false
            SSDEEP:384:LA5/hmnSoP1Y8vZ7sM5sD3lVooeZJkx4ZJV6E8AiKGR9iK1fPg2rRsV0ksqebh8g:HgA6x4ofa0ZRh9rR
            MD5:EEAAD64DE3E881D839136E2BF29E59C2
            SHA1:C7E3777E941411172F344BCF04DA1E2A24FB23B7
            SHA-256:A73F7E56886E51FA412BE1068194CBADBF3332F0FC682EF7E7812C7E0859379E
            SHA-512:21DF51A5704D61EF530CB976F14DA412687BFEB600D14347CB19A3C9B571455EA1CC9B7DC38FC23C8E712BC56CB0254EB7325EEE27B8C76FC210D154D5262BE3
            Malicious:false
            Reputation:low
            Preview:import { Dom7Array } from 'dom7';.import { SwiperOptions } from './swiper-options';.import { CSSSelector, SwiperModule } from './shared';.import { SwiperEvents } from './swiper-events';..import { A11yMethods } from './modules/a11y';.import { AutoplayMethods } from './modules/autoplay';.import { ControllerMethods } from './modules/controller';.import { CoverflowEffectMethods } from './modules/effect-coverflow';.import { CubeEffectMethods } from './modules/effect-cube';.import { FadeEffectMethods } from './modules/effect-fade';.import { FlipEffectMethods } from './modules/effect-flip';.import { CreativeEffectMethods } from './modules/effect-creative';.import { CardsEffectMethods } from './modules/effect-cards';.import { HashNavigationMethods } from './modules/hash-navigation';.import { HistoryMethods } from './modules/history';.import { KeyboardMethods } from './modules/keyboard';.import { LazyMethods } from './modules/lazy';.import { MousewheelMethods } from './modules/mousewheel';.impo
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):11652
            Entropy (8bit):4.771514819499092
            Encrypted:false
            SSDEEP:192:IC8tbofFAWYhgikRx5Rc4jwFFDZjK5o6rtqZtdt3tM5X3HtptWtXt8t3tBtPto8v:ICybofFAWYhgikRx5Rc48FFDZjn6rene
            MD5:4C384F060AB63FB3FF4832A44A0FAB9C
            SHA1:AA0B4D5E6DF4FE579587D38FCD24658AB90076E2
            SHA-256:922C25448A3614875629E18480AF748C497218B1818068820D756DBF9BBE245D
            SHA-512:1E5E1B4C367948FDACAEDF91EE459C3926E28538B76553AD06CF8F1B719609D1D143A911A74F70184AF4FCE414A7975629C3BC517D2F51B6EB7AFA578D5F3FB3
            Malicious:false
            Reputation:low
            Preview:import { SwiperOptions } from './swiper-options';.import Swiper from './swiper-class';..import { A11yEvents } from './modules/a11y';.import { AutoplayEvents } from './modules/autoplay';.import { ControllerEvents } from './modules/controller';.import { CoverflowEffectEvents } from './modules/effect-coverflow';.import { CubeEffectEvents } from './modules/effect-cube';.import { FadeEffectEvents } from './modules/effect-fade';.import { FlipEffectEvents } from './modules/effect-flip';.import { CreativeEffectEvents } from './modules/effect-creative';.import { CardsEffectEvents } from './modules/effect-cards';.import { HashNavigationEvents } from './modules/hash-navigation';.import { HistoryEvents } from './modules/history';.import { KeyboardEvents } from './modules/keyboard';.import { LazyEvents } from './modules/lazy';.import { MousewheelEvents } from './modules/mousewheel';.import { NavigationEvents } from './modules/navigation';.import { PaginationEvents } from './modules/pagination';.imp
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text, with very long lines (324)
            Category:dropped
            Size (bytes):31600
            Entropy (8bit):4.651195296384794
            Encrypted:false
            SSDEEP:768:85FFIHgSAZkmVFAo3K/kLm8c47hh8Jl3aJ4GQcMoD9EbqwJBw5G5BewMnmYILwb+:8v6HgSAZkmVFAoa/ktc47hhYlqJ4GQcs
            MD5:792AB4794175A6412DF188CC2B11D563
            SHA1:9594FB164B1DC3E74F16F1A634460D1C4BB6F678
            SHA-256:A11EA789BDD0CE72A003C65C17814941AFB82058EB3BEFC393BB9C29794421A8
            SHA-512:6579D0DD2CC9551E5569C5B8B8D8EE67B8640B4148A6984FE65D40715C3B21ABB076956FF9D2835386DB7F0A988848C6488AFA1652A93DDF983C19534963B135
            Malicious:false
            Reputation:low
            Preview:import { A11yOptions } from './modules/a11y';.import { AutoplayOptions } from './modules/autoplay';.import { ControllerOptions } from './modules/controller';.import { CoverflowEffectOptions } from './modules/effect-coverflow';.import { CubeEffectOptions } from './modules/effect-cube';.import { FadeEffectOptions } from './modules/effect-fade';.import { FlipEffectOptions } from './modules/effect-flip';.import { CreativeEffectOptions } from './modules/effect-creative';.import { CardsEffectOptions } from './modules/effect-cards';.import { HashNavigationOptions } from './modules/hash-navigation';.import { HistoryOptions } from './modules/history';.import { KeyboardOptions } from './modules/keyboard';.import { LazyOptions } from './modules/lazy';.import { MousewheelOptions } from './modules/mousewheel';.import { NavigationOptions } from './modules/navigation';.import { PaginationOptions } from './modules/pagination';.import { ParallaxOptions } from './modules/parallax';.import { ScrollbarOpt
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1506
            Entropy (8bit):4.75651626761606
            Encrypted:false
            SSDEEP:24:hkT8mur86OrUb5iRdqV7dBuJ0lRutY3+v6p++6khWrkH1YcHg0aIi2t6wQzQHSnQ:hkTduI6O6IosJdxypeNrWC+g0aVLwQzE
            MD5:0838A47878557E27F88C58F5D42AD8D7
            SHA1:C9DE291EAD781ECFC50EFC25D2DE23B53E2089C7
            SHA-256:CEE8159ED65F21739E294590B0104F896D8DE05AEBE7A93F9682EBD851CA35A6
            SHA-512:06BFD68F8568435C5AFCE649AF616CBA7F0ED353E943DA39BEE02F48D3A89462316A69D556FDF685EC4731A9F906ED9FB9BD5A6198F6C1A658A0DD67A019D7A0
            Malicious:false
            Reputation:low
            Preview:import { paramsList } from './params-list.js';.import { isObject } from './utils.js';..function getChangedParams(swiperParams, oldParams, children, oldChildren) {. const keys = [];. if (!oldParams) return keys;.. const addKey = key => {. if (keys.indexOf(key) < 0) keys.push(key);. };.. const oldChildrenKeys = oldChildren.map(child => child.props && child.props.key);. const childrenKeys = children.map(child => child.props && child.props.key);. if (oldChildrenKeys.join('') !== childrenKeys.join('')) keys.push('children');. if (oldChildren.length !== children.length) keys.push('children');. const watchParams = paramsList.filter(key => key[0] === '_').map(key => key.replace(/_/, ''));. watchParams.forEach(key => {. if (key in swiperParams && key in oldParams) {. if (isObject(swiperParams[key]) && isObject(oldParams[key])) {. const newKeys = Object.keys(swiperParams[key]);. const oldKeys = Object.keys(oldParams[key]);.. if (newKeys.length !== oldKey
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1078
            Entropy (8bit):4.710331299441967
            Encrypted:false
            SSDEEP:24:Jcmezww7eTiQeWruRxUfdTy1rSceWrEa4iMiqAoQSRxeWbvwXgquSY:Smm97AiUUxUfBfoYDPiqAoQ8PBjr
            MD5:B311500F0F1D72A7850CA1F4E8D7B3B5
            SHA1:68A491E157D33BDFE02839FE6B412D651466472C
            SHA-256:B7651FE1DC95986A02C41F8C15F1A41D508B9F6699E9A6273390F3EFCF339C41
            SHA-512:F30CB3217A2D1AC3F9D3E508B10387A2C65F1022B8D6E3A24DADE5704F0EA59A27812E2031873ADFCD1D1A997E259E07A68AC2FF83D372761C8CFA7CA9EF08AE
            Malicious:false
            Reputation:low
            Preview:function getChildren(originalSlots = {}, slidesRef, oldSlidesRef) {. const slides = [];. const slots = {. 'container-start': [],. 'container-end': [],. 'wrapper-start': [],. 'wrapper-end': []. };.. const getSlidesFromElements = (els, slotName) => {. if (!Array.isArray(els)) {. return;. }.. els.forEach(vnode => {. const isFragment = typeof vnode.type === 'symbol';. if (slotName === 'default') slotName = 'container-end';.. if (isFragment && vnode.children) {. getSlidesFromElements(vnode.children, 'default');. } else if (vnode.type && (vnode.type.name === 'SwiperSlide' || vnode.type.name === 'AsyncComponentWrapper')) {. slides.push(vnode);. } else if (slots[slotName]) {. slots[slotName].push(vnode);. }. });. };.. Object.keys(originalSlots).forEach(slotName => {. const els = originalSlots[slotName]();. getSlidesFromElements(els, slotName);. });. oldSlidesRef.value = slidesRef.value;. slidesRef.va
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1378
            Entropy (8bit):4.812777494686066
            Encrypted:false
            SSDEEP:24:8z+/kT+ROG1dk+Lzkm6BWNu2RPQcZk01X1YuBRiViboho4LTeTrpv99yUOFVVKWw:J/kT+R5Qnm6BPGQcWCX11BRiVibcDLSh
            MD5:666FC38F660B5463F83727B0B2F9FC17
            SHA1:78960EC9C4EA4FB526B3F7197189B7839C62EE14
            SHA-256:DDC91FA05F6A8D10BA9281BAA9842573FBDE9535978867FB32EA649384983BAD
            SHA-512:B22A8C17CDD1A2095CA512C70FEB17266FB357E706210D7FD3CF7DC07C4921E86832FE1076E88E265FA95892786B097F94721D6D90724BDFB89E6FA803A0F448
            Malicious:false
            Reputation:low
            Preview:import Swiper from 'swiper';.import { isObject, extend } from './utils.js';.import { paramsList } from './params-list.js';..function getParams(obj = {}) {. const params = {. on: {}. };. const passedParams = {};. extend(params, Swiper.defaults);. extend(params, Swiper.extendedDefaults);. params._emitClasses = true;. params.init = false;. const rest = {};. const allowedParams = paramsList.map(key => key.replace(/_/, '')); // Prevent empty Object.keys(obj) array on ios... const plainObj = Object.assign({}, obj);. Object.keys(plainObj).forEach(key => {. if (typeof obj[key] === 'undefined') return;.. if (allowedParams.indexOf(key) >= 0) {. if (isObject(obj[key])) {. params[key] = {};. passedParams[key] = {};. extend(params[key], obj[key]);. extend(passedParams[key], obj[key]);. } else {. params[key] = obj[key];. passedParams[key] = obj[key];. }. } else if (key.search(/on[A-Z]/) === 0 && typeof obj[key] === 'func
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):934
            Entropy (8bit):4.616139718387101
            Encrypted:false
            SSDEEP:24:8w1uPysIsKbOUXz9BCPRCPICbiqRCbixxdn8dQ1BSrBN9y1U9:h1uPyBjhBCPRCPICjRCin2q+BDym9
            MD5:473C4FEBB4542C8A4064F6BD51B84DDD
            SHA1:EE8D03277CB9AB30AEF418F2119E33E8901F57BC
            SHA-256:77BBEA04B408B78373106A62B25D6E2588A74420B7B55965F2743B98133408B6
            SHA-512:334A1371B06B03EDB12AFF916263BC2587A4289A882E35EF9E31AC639F5B7F3A48D39EEDCA25E70164EA360F38790B31E83A89302BF417694B7A44779A991FC2
            Malicious:false
            Reputation:low
            Preview:import Swiper from 'swiper';.import { needsNavigation, needsPagination, needsScrollbar } from './utils.js';..function initSwiper(swiperParams) {. return new Swiper(swiperParams);.}..function mountSwiper({. el,. nextEl,. prevEl,. paginationEl,. scrollbarEl,. swiper.}, swiperParams) {. if (needsNavigation(swiperParams) && nextEl && prevEl) {. swiper.params.navigation.nextEl = nextEl;. swiper.originalParams.navigation.nextEl = nextEl;. swiper.params.navigation.prevEl = prevEl;. swiper.originalParams.navigation.prevEl = prevEl;. }.. if (needsPagination(swiperParams) && paginationEl) {. swiper.params.pagination.el = paginationEl;. swiper.originalParams.pagination.el = paginationEl;. }.. if (needsScrollbar(swiperParams) && scrollbarEl) {. swiper.params.scrollbar.el = scrollbarEl;. swiper.originalParams.scrollbar.el = scrollbarEl;. }.. swiper.init(el);.}..export { initSwiper, mountSwiper };
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):2623
            Entropy (8bit):4.804984143413247
            Encrypted:false
            SSDEEP:48:CtIsjJl8B1BwID3TUjpcscT6DovUauaFj7AKRYDw9kHjylrwuSKwIp49S:CzwBbDjuk6s+apUKew9Qjyd18S
            MD5:E7BFFF5CED2B92DCDDC52E88B89DE8CF
            SHA1:9A2D55A451DC731B46FC542AEF329F95FD0B3AF6
            SHA-256:0753888B0E4D1754C5388DDA40BB45ED2549147701B8CAAFEFA2E47B31714D6A
            SHA-512:19C271D2941F2AA161B45F72507D8C86D3D7E0923FE785DF1853773E0EEC116E85B0F17219EBA1131C88F733EB66DB615443EB7C2EED9E1F2D683B216C37FB6A
            Malicious:false
            Reputation:low
            Preview:import { h } from 'vue';.import Swiper from 'swiper';..function calcLoopedSlides(slides, swiperParams) {. let slidesPerViewParams = swiperParams.slidesPerView;.. if (swiperParams.breakpoints) {. const breakpoint = Swiper.prototype.getBreakpoint(swiperParams.breakpoints);. const breakpointOnlyParams = breakpoint in swiperParams.breakpoints ? swiperParams.breakpoints[breakpoint] : undefined;.. if (breakpointOnlyParams && breakpointOnlyParams.slidesPerView) {. slidesPerViewParams = breakpointOnlyParams.slidesPerView;. }. }.. let loopedSlides = Math.ceil(parseFloat(swiperParams.loopedSlides || slidesPerViewParams, 10));. loopedSlides += swiperParams.loopAdditionalSlides;.. if (loopedSlides > slides.length) {. loopedSlides = slides.length;. }.. return loopedSlides;.}..function renderLoop(swiperRef, slides, swiperParams) {. const modifiedSlides = slides.map((child, index) => {. if (!child.props) child.props = {};. child.props.swiperRef = swiperRef;. chil
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (1741)
            Category:dropped
            Size (bytes):2089
            Entropy (8bit):4.744182989771888
            Encrypted:false
            SSDEEP:48:kFl9aBONs8INhyw2cofcezZOl2dAaJDcL0fVsTOn:kFlO/8TUll7aJDcwfuTe
            MD5:196A01069A99BCA82B4F4DFD44469713
            SHA1:602A17476C445F8AE44787FE5D70CE9F6530BE7A
            SHA-256:EF417A0742166485A02A667F5726F5C20FB2F872236C1344CF58980CF76EEF52
            SHA-512:756C0FBDFB3203483B20E90893484648A9F6C9220111ABED32240B03B286B1D3050767B3280EC79C61938CCFC726750A8AEEA4C16FDC884949D21E2469FBEF88
            Malicious:false
            Reputation:low
            Preview:/* underscore in name -> watch for changes */.const paramsList = ['modules', 'init', '_direction', 'touchEventsTarget', 'initialSlide', '_speed', 'cssMode', 'updateOnWindowResize', 'resizeObserver', 'nested', 'focusableElements', '_enabled', '_width', '_height', 'preventInteractionOnTransition', 'userAgent', 'url', '_edgeSwipeDetection', '_edgeSwipeThreshold', '_freeMode', '_autoHeight', 'setWrapperSize', 'virtualTranslate', '_effect', 'breakpoints', '_spaceBetween', '_slidesPerView', '_grid', '_slidesPerGroup', '_slidesPerGroupSkip', '_slidesPerGroupAuto', '_centeredSlides', '_centeredSlidesBounds', '_slidesOffsetBefore', '_slidesOffsetAfter', 'normalizeSlideIndex', '_centerInsufficientSlides', '_watchOverflow', 'roundLengths', 'touchRatio', 'touchAngle', 'simulateTouch', '_shortSwipes', '_longSwipes', 'longSwipesRatio', 'longSwipesMs', '_followFinger', 'allowTouchMove', '_threshold', 'touchMoveStopPropagation', 'touchStartPreventDefault', 'touchStartForcePreventDefault', 'touchReleas
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):2639
            Entropy (8bit):4.704526156065144
            Encrypted:false
            SSDEEP:48:G0sOb7OYgfiAYSMCS7l14wwPQPVov6Ha2kbStrGkG50/sA7qBNYSmRgdXBr:QOb7OL2nwom4a7p6leBr
            MD5:A8EC528202AA3EBE375D3DD69DE3F05E
            SHA1:D6ADFEE66AD3C1AC9AF8E4940BCF755AF2CFD408
            SHA-256:F9B0DA3E93570EDE6EB001444CD21CF5F5D61CFA09BB795359468D00B7523260
            SHA-512:F74216C06A499C28E78E9502E49EED02CC1FA61FADFBEF21B84636EA08772836301D8C0EAD900A699FA48F04F2DC827F6F9222C7CADD12462BAFCDF25643AB2E
            Malicious:false
            Reputation:low
            Preview:import { h, ref, onMounted, onUpdated, onBeforeUpdate, computed, onBeforeUnmount } from 'vue';.import { uniqueClasses } from './utils.js';.const SwiperSlide = {. name: 'SwiperSlide',. props: {. tag: {. type: String,. default: 'div'. },. swiperRef: {. type: Object,. required: false. },. zoom: {. type: Boolean,. default: undefined. },. virtualIndex: {. type: [String, Number],. default: undefined. }. },.. setup(props, {. slots. }) {. let eventAttached = false;. const {. swiperRef. } = props;. const slideElRef = ref(null);. const slideClasses = ref('swiper-slide');.. function updateClasses(swiper, el, classNames) {. if (el === slideElRef.value) {. slideClasses.value = classNames;. }. }.. onMounted(() => {. if (!swiperRef.value) return;. swiperRef.value.on('_slideClass', updateClasses);. eventAttached = true;. });. onBeforeUpdate(() => {. if (eventA
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):23081
            Entropy (8bit):4.666606703765468
            Encrypted:false
            SSDEEP:384:VpgPRaWsFYuDWeSsGNPjVooQFy5NYd6h+9jKXNtdZIBExnxaGaXovODdyQO0grCW:pQBNbVc6Dj
            MD5:EA015A2169CECAE44CD51A84A22C9CFD
            SHA1:11242306B4FA36BC93FEF99780579F4146F23A39
            SHA-256:F90961F2DCBBCF27E36D88FA0C560E280A0E8049D528017889670C6351653EC7
            SHA-512:B7AA2F2CD9A8D08D17BB593C0EBC35B734FD7D7310DAAE94650F664C9D0B5D628D817433D9DB6FFE488DF6820B2B2A9B5E415FBB13E4D287CB7DFEFBF876974F
            Malicious:false
            Reputation:low
            Preview:import {. A11yOptions,. AutoplayOptions,. ControllerOptions,. CoverflowEffectOptions,. CubeEffectOptions,. FadeEffectOptions,. FlipEffectOptions,. CreativeEffectOptions,. CardsEffectOptions,. HashNavigationOptions,. HistoryOptions,. KeyboardOptions,. LazyOptions,. MousewheelOptions,. NavigationOptions,. PaginationOptions,. ParallaxOptions,. ScrollbarOptions,. ThumbsOptions,. VirtualOptions,. ZoomOptions,. FreeModeOptions,. GridOptions,.} from '../types';.import { ComponentOptionsMixin, DefineComponent, PropType } from 'vue';.import { SwiperOptions, Swiper as SwiperClass } from '../types';..declare const Swiper: DefineComponent<. {. tag: {. type: StringConstructor;. default: string;. };. wrapperTag: {. type: StringConstructor;. default: string;. };. modules: {. type: ArrayConstructor;. default: undefined;. };. init: {. type: BooleanConstructor;. default: undefined;. };. direction: {. type: Pr
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):378
            Entropy (8bit):4.842284084995639
            Encrypted:false
            SSDEEP:6:UzbtAASX+PxKXawIAfMRLidMfZCSleO5ugiw1944qR9lLUuTRtUuAeIAoQkMUCUm:UzSASXSPmkxtfESR5ugiww4+9myUu/Iq
            MD5:E441843C1DB1687A1E083578543CF03D
            SHA1:B2923FC54D4DFCE34D56186E647C57B28E26B2D5
            SHA-256:024D0F784898AF007F13BB1129938C79E2CB96ECC83C12DA87CD92E1301BEE44
            SHA-512:DD6FF5BC946BF3FBF3828C9B24E520D9507BF99C3FA4FAF7DD0083B2BEC57248F097211E2704BC87C9579E37EBE548E766857142B44DB974FECC6CCBDDD022ED
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper Vue 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..import { Swiper } from './swiper.js';.import { SwiperSlide } from './swiper-slide.js';.export { Swiper, SwiperSlide };
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text, with very long lines (1381)
            Category:dropped
            Size (bytes):15560
            Entropy (8bit):4.512265164032862
            Encrypted:false
            SSDEEP:192:2nbm3AI8u3zlHJR0pOTveVGgENNu8fkpzEcoxX:2ny3AINRp6pOSEDNuITX
            MD5:7A79708B5F04696874AF181FB788D69C
            SHA1:D5B181FE454180E0F322A79C421BE63FC72A87CA
            SHA-256:86DCD40E39D0BC81ADDD8ECCB8E80330808ACB81F0590C75E6C7C8498B19C10A
            SHA-512:C24E53A4C8C7D6B9A260ED7130618D6AF292B6E55EC9ABE9809FFF2E34E13FE431CC90586B002351E9D84BA8ABD1A20BF8CF8D5BA2367E1E7300C6638318F6FB
            Malicious:false
            Reputation:low
            Preview:import { h, ref, onMounted, onUpdated, onBeforeUnmount, watch, nextTick } from 'vue';.import { getParams } from './get-params.js';.import { initSwiper, mountSwiper } from './init-swiper.js';.import { needsScrollbar, needsNavigation, needsPagination, uniqueClasses, extend } from './utils.js';.import { renderLoop, calcLoopedSlides } from './loop.js';.import { getChangedParams } from './get-changed-params.js';.import { getChildren } from './get-children.js';.import { updateSwiper } from './update-swiper.js';.import { renderVirtual, updateOnVirtualData } from './virtual.js';.const Swiper = {. name: 'Swiper',. props: {. tag: {. type: String,. default: 'div'. },. wrapperTag: {. type: String,. default: 'div'. },. modules: {. type: Array,. default: undefined. },. init: {. type: Boolean,. default: undefined. },. direction: {. type: String,. default: undefined. },. touchEventsTarget: {. type: String,.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):4034
            Entropy (8bit):4.789040506907139
            Encrypted:false
            SSDEEP:96:zTFU67uuIALIkYMBMxEGmw4ToUk2/I3Baj3x3LLyB:fV7uuTLIkRBMxsoUkEIsNL4
            MD5:AD06286F33221DA002AB716623A24459
            SHA1:4D0B8F35B6D988A1641893E348AB49620E584F6A
            SHA-256:B25C137ED5D25E87A6EC431CA27A3A5227F81B21CABE38ECEB73572A47620B64
            SHA-512:39D92DC11E46EFE5A8710AC62977C33D7C427F885DD2B0B8DC01011135C6EE1BC949E3BEBE9782CC50B11473667DCCC816B642B89579035EF7654ED8501CC65E
            Malicious:false
            Reputation:low
            Preview:import { isObject, extend } from './utils.js';..function updateSwiper({. swiper,. slides,. passedParams,. changedParams,. nextEl,. prevEl,. paginationEl,. scrollbarEl.}) {. const updateParams = changedParams.filter(key => key !== 'children' && key !== 'direction');. const {. params: currentParams,. pagination,. navigation,. scrollbar,. virtual,. thumbs. } = swiper;. let needThumbsInit;. let needControllerInit;. let needPaginationInit;. let needScrollbarInit;. let needNavigationInit;.. if (changedParams.includes('thumbs') && passedParams.thumbs && passedParams.thumbs.swiper && currentParams.thumbs && !currentParams.thumbs.swiper) {. needThumbsInit = true;. }.. if (changedParams.includes('controller') && passedParams.controller && passedParams.controller.control && currentParams.controller && !currentParams.controller.control) {. needControllerInit = true;. }.. if (changedParams.includes('pagination') && passedParams.pagination && (passedParam
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1366
            Entropy (8bit):4.948502343813141
            Encrypted:false
            SSDEEP:24:gYQnwNWvp4kHuxYNa0nr5sKUmIQLA+GjsB3LTKItaK2SEaKszv3qsu6puTB6sNd3:JQnwNEXHuxSa0nr5sKUmj0+Gj63LTKEQ
            MD5:F5940966EA5415C78E29994B1E9DB3CF
            SHA1:695A5A8969F614609795292F0A0BD63D0F02EF7E
            SHA-256:F67DEA266D21F8DCA660492F83432C6AE3B8C2292D5CAE8B53D7DFE0BF326897
            SHA-512:32E6669FFFC33AA14728958163875A21C0F5037B4AE963B25EC4A5CCFD86D64B7BBC30CD7A29FAEF89DDC97E726E6F239FBEA6BC65B8AE6311D274300CA7C2CA
            Malicious:false
            Reputation:low
            Preview:function isObject(o) {. return typeof o === 'object' && o !== null && o.constructor && Object.prototype.toString.call(o).slice(8, -1) === 'Object';.}..function extend(target, src) {. const noExtend = ['__proto__', 'constructor', 'prototype'];. Object.keys(src).filter(key => noExtend.indexOf(key) < 0).forEach(key => {. if (typeof target[key] === 'undefined') target[key] = src[key];else if (isObject(src[key]) && isObject(target[key]) && Object.keys(src[key]).length > 0) {. if (src[key].__swiper__) target[key] = src[key];else extend(target[key], src[key]);. } else {. target[key] = src[key];. }. });.}..function needsNavigation(props = {}) {. return props.navigation && typeof props.navigation.nextEl === 'undefined' && typeof props.navigation.prevEl === 'undefined';.}..function needsPagination(props = {}) {. return props.pagination && typeof props.pagination.el === 'undefined';.}..function needsScrollbar(props = {}) {. return props.scrollbar && typeof props.scrollba
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1149
            Entropy (8bit):4.760591329978127
            Encrypted:false
            SSDEEP:24:CFLPYrEdojAB6BbBqgMuws9Do06KPlp5fF1UlUidMHmdUH85oT6EDLQ5DLToQ/cd:CFLAkqlqq9Do06KPlXfF1UlUIMHm+H8s
            MD5:3736F2E191557BB3F9FB65F704D634B9
            SHA1:839DB617CA456205A3622720A507B4D619F0F31D
            SHA-256:D83ACBD53DC99BBEFE8254DEEC88F763599A0F4391D6B0597373E85C73974E32
            SHA-512:331CC9221E16781173A4E622F500B87D94A240327FCCCDB4476721CF3A26F96044BB3A5C6A370DA4C66494838ECD1E481ABE1916CB3F5371226E9CB9AF7C9A79
            Malicious:false
            Reputation:low
            Preview:import { h } from 'vue';..function updateOnVirtualData(swiper) {. if (!swiper || swiper.destroyed || !swiper.params.virtual || swiper.params.virtual && !swiper.params.virtual.enabled) return;. swiper.updateSlides();. swiper.updateProgress();. swiper.updateSlidesClasses();.. if (swiper.lazy && swiper.params.lazy.enabled) {. swiper.lazy.load();. }.. if (swiper.parallax && swiper.params.parallax && swiper.params.parallax.enabled) {. swiper.parallax.setTranslate();. }.}..function renderVirtual(swiperRef, slides, virtualData) {. if (!virtualData) return null;. const style = swiperRef.value.isHorizontal() ? {. [swiperRef.value.rtlTranslate ? 'right' : 'left']: `${virtualData.offset}px`. } : {. top: `${virtualData.offset}px`. };. return slides.filter((slide, index) => index >= virtualData.from && index <= virtualData.to).map(slide => {. if (!slide.props) slide.props = {};. if (!slide.props.style) slide.props.style = {};. slide.props.swiperRef = swiperRef;.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Unicode text, UTF-8 text, with CRLF line terminators
            Category:dropped
            Size (bytes):1695
            Entropy (8bit):5.604462860598622
            Encrypted:false
            SSDEEP:24:ryf0ZPfXR2/C2kBvXLNo6FtT//ZkwTS3sUqYoQZ5oxddEwbrR/PK+AhK+J:ryfQnZLLDV/JTSDZ/iss1c
            MD5:E62441F828DB1519F5174C3560ED22CD
            SHA1:200CEAA6F0E0E25E597C003D61A57C1EB3BA8EB6
            SHA-256:B484903C34578FE2D85C2343D30B393220BF268BCABFF97337C710ACB3C51390
            SHA-512:3685CE79794FB6AEA87C2D645FAE5F9A07CF826B39A6B3862DAD5E0203835D0C2764BBC00BECCF87F4AA5A4892271EE6567E1268CB1632F26ECA0642E2146E6F
            Malicious:false
            Reputation:low
            Preview:body..{...background-color:#242428;..}....*..{...border-color: #3E3E45;..}.......TextS1..{...color:#efeff0;..}.....TextS2..{...color:#B3B3B5;..}.....ZScrol::-webkit-scrollbar-thumb {/*........*/.. background-color: #939594;..}.....ZScrol::-webkit-scrollbar-track {/*.......*/.. background: #161817;..}........../*----Left Menu Button----*/..#LogoutBtn:hover..{...background: #243E30;...color: #efeff0;..}.....BtnItem..{...color:#B3B3B5;..}.....BtnItem:hover..{...color: #efeff0;...background-color: #243E30;..}.....BtnItem:hover .LeftIcon..{...filter: brightness(300%);..}.....BtnItemSelected..{...color: #efeff0;...background-color: #243E30;..}.....BtnItemSelected .LeftIcon..{...filter: brightness(300%);..}..../*-----Right Top MenuBtn-----*/...MenuItem:hover..{...border-color: #4CAA50;...background-color: #243E30;..}....#RecentClearAllBtn:hover..{...color: #000;..}....#recnet_context_menu..{...color: #efeff0;...background-color:#242428;...border: 0px;..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Unicode text, UTF-8 text, with CRLF line terminators
            Category:dropped
            Size (bytes):10754
            Entropy (8bit):5.381318374184903
            Encrypted:false
            SSDEEP:192:b7qoS4zblCfQzbVsWaR6G3f7lulKprxn0mazci9rkRC9rhD9rF9ry9D3e464Lz:/NSduRaR6AhAK4zciNkRCNhDNFNyh3ei
            MD5:0F268FD83971E4E6FC3F93E908816C29
            SHA1:21C0F965B9E18B7E5C6756F36301577D53BDC573
            SHA-256:BDF937AF78078BBA672F6B986296F051777244F57349BB07F92EC42659611298
            SHA-512:B822C75350F9A83F5E34AA15C31A3DA8C03368173D2EA0EED1595DFEE43DCB92D91E8D68E9999D4FA1C501911FEBF113765F72D1AE84FE40317251DF9CE385E5
            Malicious:false
            Reputation:low
            Preview:*..{...padding:0px;...border: 0px;...margin: 0px;.. font-family: "system-ui", "Segoe UI", Roboto, Oxygen, Ubuntu, "Fira Sans", "Droid Sans", "Helvetica Neue", sans-sans;...border-color: #D7D7D7;...user-select: none;..}....html, body {...height: 100%;...width: 100%;.. margin: 0px;.. padding: 0px;...line-height: 20px;.. font-size: 16px;...}.....ZScrol::-webkit-scrollbar {/*.......*/.. width: 12px; /*..............*/.. height: 1px;...padding: 2px;..}.....ZScrol::-webkit-scrollbar-thumb {/*........*/.. border-radius: 6px;.. -webkit-box-shadow: inset 0 0 5px rgba(0,0,0,0.2);...box-shadow: inset 0 0 5px rgba(0,0,0,0.2);.. background-color: #AAAAAA;..}.....ZScrol::-webkit-scrollbar-track {/*.......*/.. -webkit-box-shadow: inset 0 0 5px rgba(0,0,0,0.2);... box-shadow: inset 0 0 5px rgba(0,0,0,0.2);.. border-radius: 10px;.. background: #EDEDED;..}.......RedFont..{...fon
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 480 x 300, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):129565
            Entropy (8bit):7.995789746440967
            Encrypted:true
            SSDEEP:3072:c4HE4QiHRORlEAGs663Sq9c2ongrnKhBRcKd3haqm5NN:c47/0RGspSbLgeCKpFGN
            MD5:4F9E952AA77CA40E13300662B70F5F2A
            SHA1:814461B079859E105869A272DF89571ED7C778D9
            SHA-256:0EFE6306C2C36B0AFF00DB9BBDEC1B8FC0BFC62E2A16AF4CEA5EEDA6C15C82CA
            SHA-512:A5F219258B0CE050D2A80980B16EC35FD18D89F2638B79353136BE5ADAE2422408BE083A7D8EFD2A2C8F841B9D6AE0E2899C7C765FBCB0FD5DEC915C12CE3CB8
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.......,.......`Z....pHYs.........&.:4....sRGB.........gAMA......a.....IDATx.....m.q&.}y.V.[..5.(T.@...`.l....T.V..!...l...&....;....z..v.mw...l..4.&...P....y.oU.Rg._.k..5......s.^Cf.............o...._9.f..=...-....^...r.......G#..m...D..ymg.....~.z.M;..ua.r..7_K;L.9.....u.is...S.N......=........K...|..........?:.._..|.*.J=....t:.w.............ox.8..z..........~)....~.3..5..Q.......`.d.B8!....{...A..3(....ggg.A.j..8.b..t.j.......0.j..^.c.N...o.8&.......$.....b...o.....~A.HTd[.p....x/1....X...*e>....>.....>._..W.......?......l!.wq...K|F.....,..1....U..j.~J..........u.C.....h.z...Z.d.Z.M....?....>...X....vfE".f.4.. ...Y...Z.zx..p.....hc.u.%.......e....>7...bi.;.>".4k.8..?>.....X.G.. ..r".....A..1.Z:]..V.s.Y..N]..M;......(.@.....@iW.e.nO.s8.|..,...lZ..^.hV..P...B/..m.....C.....@j..o...,...d.#v.1.S.....o.*..;..r.n.whos].em,/c.2.)..6.R.X1ut.76B...Z.`.T0.....Y9..G...n8L'c.W..m.....I..._....W?._...?."j....\....~..|....O.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, baseline, precision 8, 360x360, components 3
            Category:dropped
            Size (bytes):56697
            Entropy (8bit):7.926141223464922
            Encrypted:false
            SSDEEP:1536:n+NF1M9xUV2hGwoWBMzJIKy1ua+OE9N8IkEHJuguNe:+NF1M9S2chWBIIKpaqzv99uNe
            MD5:4C2524FD040BB9573DE1E5C841B52012
            SHA1:B191E49CCFAD2A5877EE58FE454219B584C08F3D
            SHA-256:DEB65C21179292C4E8AA2C5600FA49F619C63AE389482B941F154518FFFBC093
            SHA-512:02EDB49DEE53CFA9CE707C937BA0BFBE55751765DE718AEDC6124E7231A21380784B2E322C370E10E7177B77037860FE593FD067F405401346283CA71116D56D
            Malicious:false
            Reputation:low
            Preview:......JFIF.....,.,.....C....................................................................C.......................................................................h.h.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?......?.~(g........T..y....9..B..O.-...'.J'.q......W..;......|O.5z...V...u....{.=4.I;.....p.....sQ.' ........a...Pp~...URm........~...8I.(..~?-60F3....9'?....:P.....j...?S..).A....R.....%..3 d..A.FFx..<...y..!.p..#...y.zX.,G^...q.u..RM.P9.N.....=...[......yf..'.3.^... .x.B..$.........}?S.5.b.v....}.Se.H...8......}3.AQ%g...@H<rs..g...F@......*@2G^O..Y.(..6....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, baseline, precision 8, 769x580, components 3
            Category:dropped
            Size (bytes):173011
            Entropy (8bit):7.946863127548712
            Encrypted:false
            SSDEEP:3072:XX8BJy07w+vzD4etsiQ2aIMgkQR9A7eilvo8rOU86ohxVspVEpN:XMzrnsekQjAKixkVxx6pGf
            MD5:40CE3C4825C13222A96F9D42E8FD98B3
            SHA1:0B53905717536B51F82ED7520237E44CB9177A4E
            SHA-256:6BD947062D5CC71537E2EC0C2CA2A8441612799998C8CECCFDDA42A16472C405
            SHA-512:22F2BBA7782D58E7169BFA6F3506BDADF9E36F99C7BD6D441068F9517357EC7C9042588CD8BC89173573FABE34FCCEDA4F7BED32ABE7EE6325208D29495D4758
            Malicious:false
            Reputation:low
            Preview:......JFIF.....,.,.....C....................................................................C.......................................................................D...."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..o. .......KV(....".....m........>.....6.Q........?...............).`...PD.r....NV...._&5.v9.)._.........8.g''.....Z..77..........O..._.............9e.{....J..b9 ..=y..I.....T..u......;d{r./..Pn.`...(..k.h...mm{>.b>.=.o.. .rry.......(.>.._...o.h2....W\..Db08.........$1'q.=.bz{.zv'...8.>.>........85....6.}<..D".x'.{z.CF..=O.....n.s...[........:q..)<.....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, baseline, precision 8, 583x577, components 3
            Category:dropped
            Size (bytes):38788
            Entropy (8bit):7.803924321416531
            Encrypted:false
            SSDEEP:768:Na+u4D6/Hmm3sUnjMwHOA3M2YPgsZarRRwXJ6pwtJjY:N1Ymm8AwwuA3MDrcrRSXC8jY
            MD5:72C799C4F00366AE6607B9A7EFD1133D
            SHA1:B99C028D0059C8C934076DD2BEEB132E1556CBF9
            SHA-256:13A3CEAE0CCA59B3235ED80DCFA9C3AF1E372AC886F09B4D98BFA9AFF57A188C
            SHA-512:6193742EAB3E0CF2D284A7B8411DA776187C45D73B75D8EB4853A90485657410C8892E8DBA45D02B1E209888BDED8BD9760A1901D1524F12BDADEC67D6E7CB9E
            Malicious:false
            Reputation:low
            Preview:......JFIF.....,.,.....C....................................................................C.......................................................................A.G.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?.............f....!...c..."...(...(...(...(...(...(...(...(...(...(...(...)......-@[$...U....+%...h`..2q.-+.w.B..+..H..\..M.n%W._.2..8...6?.3..../|k.I.#...>3.D.o....iv.7w.#..,<5ba..[...}4z..{q.R.=7D..-j.`.k..1Eo........~...=C._.O.....%.......Z.T.W....k...t.......A+[..S..{m..j.......h.u}.}...z......8.[.x!..7w..q.0....wam. F.d.L`.(E;....?.......z~..s..L...
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 185 x 184, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):5454
            Entropy (8bit):7.926217505564751
            Encrypted:false
            SSDEEP:96:5eRT2o9CeZL+hV0CUiITlLTVkRhkolWPs2hosSMa2Ev/nsU/jZzoiP2X8jEMPJv:5eocCBhFULTlLTVWplWP1osSMEnsU7Zz
            MD5:751B7979DA9D3D45C60401805863432C
            SHA1:AEDC50D6C16E351A66CB57F923923E3B64B9FBE1
            SHA-256:4519449202207C818538972304F651F681C0DBF865DB169230DE4246CE754613
            SHA-512:26E1BC1177C6D102C1874F2CAD66E4FA1DBDFDABC4D106A011FC2ED0234620E9E7B96916C98B38DE1547674001B41EA82E13AA4105DF656D230C0C513ACB6BDC
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR...............M.....pHYs...........~.....IDATx..k...u...........% T.... +6(RdE& .]..].U........U..v*.'....8..\e...!aT..;.@U..;68@A...lI...<w.{.uS..{...............3.{.s..!2........!...C"'..DN.......9!<$rBxH.....!...C"'..DN.......9!<$rBxH.....!...C"'..DN........|.??.~..v..........W]5...!bY.]9........u.....O\.n...6..!.N...^.4..........n..9..E..e#..'.5.r.k.......kH..d.t<.c.f.m`...6....\...Bk./].B.}..+Z.....^.....C,#B.].......E........y...%.|y.]..>....+WP.%B..OO.L0...8...H..".....}..^.....#..L.H(,9c...O.*...t>.%}}ll.FK...>y..[.....>...g2....@.-9clu.o#..../B...K. .^7a!n-......+.l...$....=.|....'c.....A.....S..\iv............!.9.*........)........Q....*w.\.cG..W.z...?....s..h.....)........$...is.....z....O.... ..DN.......9!<$rBxH.....!...C"'..DN.......9!<.z...(..(......r..%.g.....t.bY.....B...x...4.H|S..2...m.....X;8..4{....$.]..'.p.P".0..&...-...F.0@S50....x<.}}}.....'jB......T*`.F.Z..h....0....J$.Q.n.Zt.,..E..e9R...#.8..L.L.Zd.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 481 x 300, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):152345
            Entropy (8bit):7.993617361905378
            Encrypted:true
            SSDEEP:3072:Md4LN1dVwshlIXfIM9YF8OaUJyjamIGeQnhgVGsy27KdP2jzM39Gl:Md4p1dOcyfIM9YSUCXPCVBn2Uo30l
            MD5:4CEDACCF2C63A8FA2B110F928944E6CB
            SHA1:D6A30882A20F2A54B1B66955BCBDC743E06A89B2
            SHA-256:81E32947F3A7A34CB3387D61311D15BDADCB96A8B6AB53CEE4CD15432E150202
            SHA-512:9CA65BB661D0FBB5A9B53BB7A2280B9A1A081735F41D8DCC0EE5A6F5997EAF41E94DEE31B4AAF9568E9941FA6EFF66A36C9EE32B66FCA67E8E96A97CD515BF05
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.......,......<.d....pHYs.........&.:4....sRGB.........gAMA......a...R.IDATx...{...Q..u...]...c...A...x@@.A.....I.$...........=L..`#f*$.'U....#1)...XH8....d..gj.L....%a.8...o.]...~z..!.9....V.^.O_..U...O...6..1...^t........#......P9.^^.|o...YN.Yd.]%4.Q......By....s......~...^....u+....^O...E.I...Z.Q...0.'..$c.{6.}<_.o.E.*.....}[......./njc.:5.....8..-Y......!z9|..M.2...Z.w......p.%..W..4..#.O...1..>.Wr.-.......8.;M..f}d....]5$.3.R#...WH.R......mR..E......}.*.K..|.S.."d.=.O.L.~........,..<..#ne..i~Qe.N.v.+D..n..<.N..t.~...........=SO..7..1P...>...Y..s..2.-...k...|..g.j.eH.tZ...`.MV.|.B....Lm..p..D(<du..11x..l..........J...9*kz.$.c..Q.?...$@g...v.....)...w......[Fq].{.....mg._^.k)jS.n`....#.).>.n..8...P...n....6.B......?.....w...L7.je...@ ...}..W....[.Q....t^.?.5FgKu.+.+E.....4|be.&.f].6.H...k.l..._.w....#(D.v.M"..#. I.8...c..P.%.zd.o....U.......`.eh..pJ...rX...x.4..u.0V......=S8...U..q\.X.-....-.Ss..).So.uI.h..##
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):2509
            Entropy (8bit):7.342666923288678
            Encrypted:false
            SSDEEP:48:1/61sxx+Qqt+7CqFM/xePmMsAS3e0tNcVk:1Saj+QqtJVxeTsG0tNc6
            MD5:CD2F24209532E1BDC934E4EE5797BD03
            SHA1:B143B8076D520A41542CB301EE5CBC7F0D2B3203
            SHA-256:E45CE3374E59E404E91A5A94FAD405A8F9FE0A1F49C2756876D24617B35B3642
            SHA-512:43963D2813E7F8FA74A69AFC66B9B9BD5775D3E65ED25E38E7895C5D1FFEB0AA3E922ECDAC23BC38AEB27A2EFA7FD824718CC8E0BD81421954274B5ED350016D
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............\r.f....pHYs.................sRGB.........gAMA......a....bIDATx...R.......&%.........^...tqe........ h......T..TB].*..t^..i.X..y.h.#..}....o.Y...h.....-...............o.eF666..fmaa...N...e.{.7'...?^\\......-2..lmmu...a|....<w.I|._^^>..1.J....I|.-.D......y..D.....9??.V.|r.[^^....;-sfb..Y..(`......c.......X,....'..7..... wgii.:1.9.TZ6..O..[.......{.W.^.X.@....?.'V........Xk.......`..q.......r.....o...1.o....8.W....M...y.......|^....8).........6.}..;w;M.{}.v.c.i..9...N...s...|.V...+c...i<voee..$..............?....5..]s|xx...`p.[........v...X...AO.4.<...<^.......~.......)..q/n.E.v#.u.:...z..Og1..:....Y....N...~......._. .....e..=..mr....1C.d...P'........q16fr.....,.;...p-...W#...F.....2.......'.s..,.F....\..eX.c..*S6r..;.4..........i...).9..m.....U....{......_....zc..]@*.3]....=.h.)?.C...0......HL. 1........HL. 1........HL. 1........HL. 1........HL. 1........HL. 1........HL. 1.......W`F...W/......>.......['.............c
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):6133
            Entropy (8bit):7.80164222074627
            Encrypted:false
            SSDEEP:96:1So5ADPyC9shtQxBL9nxH//btFOhXZCQV1QLpvrh1fjghy2gNId5DIvo83pxVNC:1SoKWCGqx9nZ//bP8XZwfjyy2YIHI1xG
            MD5:2BD4A6D119FC7970E5CCD9492C537CA6
            SHA1:2B0B7F5C53BD4A0DCF680F1E63562F4D9EF41042
            SHA-256:A303219E7868C90E13D0648A42A223A4F56721FBD3201AE30D66A2F5791307E5
            SHA-512:19978774FE6A0981B15124B2A2545D823D019E043D86CDB5E6BA04328BD3DBAFC2E1B7104D3B7BA59EFC00FCB9F24BBF69BE6857E32FC1D5368C064AA15BB728
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............\r.f....pHYs.................sRGB.........gAMA......a.....IDATx...?lT.....3XJ..v...m.#.E"......v+."..#a..0.V....Q`.-..(U.;.#.[e...."...9..~..xf......~.....y..s..G.....................................;CPJ...I.V.....Q2.....~../........:...... ..J......7.sg.I......_../my........~......Q=...[^^...X..y...7.......}y.....s{ccc.....rfR...~c..qP..a[..'O.d...........7..k....g...L...."C......Vk.{...../S...%d..x.. <....w/....T.....*.p0.&(....S.[FO?=d.a@.P......F..............m.. .Lh...Oq....?.-.^|.@....1..'.nW.}.....kk}}.9.7..# ..C.x.@....'...@......_...nE...._.~..m.;.5N..{. ...m.(QU_....%......~....\..[ZZ:'[...)?.yO....p..&...{..Y..(.@..j.C...k..3:.\.....7!l.....v.l^Z..........!.L'..`..g..8?..>.`.4.I..p...........&.p.o.......v...8..`v<.T ,&.\.....K._.X63i.N,[c%.:88H...& ..#A`sss.`.J...{}..o../+..R...!..BvI....k.w...W..`../(.^_.yI=....%....$+X... Q...r......^?......h4.ph..f .5.."HV...|N.R..`..W.~.2..W....{!..l..cHp....<D.P>i%......
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):5326
            Entropy (8bit):7.751142118027679
            Encrypted:false
            SSDEEP:96:1SMvgy7J3zhGIMZoEzekRazSi6s2Mg+Bc2Tb/h0BjNHIrU4DhZS0nndN:1SMvjh6oE70S/hAcOh07MUu3dN
            MD5:6DEB80FD56DE1F8BE78179D8C37E1C82
            SHA1:93B89CB5E75B1E80D9D9D52F4139033748F03DFA
            SHA-256:6B514FDF295C2A7C1BDEADCDA6C9E9328F7E6FA7BC7A43C8547D05C7DD5124A4
            SHA-512:5BE977892E7D83DB4BA5C7FC102227C240DC18B7E3A4E8F8BA9E26BF2B710FFF7F17D9E449C17C2201F29247FA7653C7C6FF27D6A1D3F7D6753D26FFF6E77341
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............\r.f....pHYs.................sRGB.........gAMA......a....cIDATx...=sSI...c.e&.?.f..6...`.....L..h.Q5..`>...d2<..;.....Uc..Fd..'....c.xdY.o..."..W%d..V...v......................z[....vW...ZGGG........*@.>..<.A....ur...vd..>.<x..}K?........u........./^...j..\O....E?...L......_.={...U...cN.uDp..#....7..)..1.lD....u........p..0.,q.A.f]...T...l../.$.f.4/......|...[.X...5...H...._.vm..w}.Pe.@....._...U.H.......?.h.fUS......k....!..vu...*...).6...`.....K.@.#....u.......[.,//.....+@I4q..N.5..]..~.%..Tq).$%...:...B_...x#@..?..Q....j.v......b})Qi#.WH..'-.n..{*@...+9.S5H...r......Y.....!|....*{v........g......Ls.O..+.4....r[......Z....h..e:.x.OA..h{)mi|).@..^..M.=.`.i.....sA#.........i..,..\.%...o.n......4....)..X\\\..e%.............z....s..h.z...^.v.....4..........k..4.(#.XX.p....G,..X.9....4.-#.XX.pS...~i$.0.l...4.XX..... .....4.-:.X.J@..,......`.u:......\.X...w.O..M.9W.d`..`w..S......Z.^d20z..../@..0./..K.F..L...[20j.8<<.....Cj....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):5413
            Entropy (8bit):7.772943399548984
            Encrypted:false
            SSDEEP:96:1SZL6XqO5/OX4FCyotPwVhAhUuyW90BBIsXNF9stho/tKl3MbUQyxiWo4BL75:1ScyX+XCPwVhAhtyBBBJfathoV+8LyxX
            MD5:1F51F82814E13D3CA29C054438B13C58
            SHA1:A59C75E21443CDFA6FDC9795E3F25DCF35D61F50
            SHA-256:D33A8C8E937B7F9329385BD1F1760BE45E478D9939BC24311231A66DC7EF2B88
            SHA-512:B1FA8BF9725042895BFD7DADE917F0D3003D8E4B600CDB3A46FD22A68C58B68651580D7829D1179B26010B8D8EAA35FBF98434C959F60201869EAF3EFD86E143
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............\r.f....pHYs.................sRGB.........gAMA......a.....IDATx...Ol..}....Rq`...u..b. ..C#.9..F....A..M.... *.|..s..C{....cj..AK....]........z.C.4..4l....~3.s..........DI.a+|..{...EP~u.*...}..m..k.H....XU.^...`.N.CDK..:.....{-.h_.3Z$..c...IPz.A9...T...$.t.x`.1y8..T.....aX4...Q....k....@EuG.t....U.....KE..e7...{..jh..E.......9r......?/lF..... a.2..P)...P..w...M.......A ..Y.]......~..A.I~....~..Bp.....u.2.....z....Kz......q.l ....H......^..A...AF..i..=..|4..2z..@..._.W.(h.9...h.UA2..a.k.E.7w.0....`4......%..J.z.. ..A...._N.<@......._...H..n..zB....a...Ap.....#{.p.....wMn.......l.A.}...l.........F.{..2. .1qY`V...~e..|.-{..-.....).....>Dk. X0.x....Y.Fa.*.dE...5fz..f}HF.j@.....i.7._....:a.t5.N...v.l.....r....?..F.~._VjD...K~a.Y.$..q.p....@...%?.C.%A...\...b.`.~.8Tb......Z%.#...x..Be.....,.y.P.m9..E.h.T2....os._#...+.>...tz.<.Pw&..?....R5.....t.1..$.*.?..>.+.....F..R.J@..`sj...J*89.....4u+....O...Y...J.%.A.R3.0.A/..z....z
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):5963
            Entropy (8bit):7.820231951410501
            Encrypted:false
            SSDEEP:96:1SUTABH/wi11aLXpdtWXrQW8gbUURWoYyJCVK1Vjbqh8qqsPlhAZW//F/oU:1SUTqmLpdtWXrIgbUUFTJmK3qjSMoU
            MD5:592A01182F1A9397773D35A37B6B716E
            SHA1:910482C39F2BE7A7538A75C11DAEFEFFD5D726BD
            SHA-256:CC07343E05B4B7039DFA3146BB0E9A67FFD4F8FCF5B6377221876A266A87E188
            SHA-512:B14795C30701D0AF0D938A25E6C5573A65B7E9E83BC336D8E11A692A9DDFF288478E57FA6453629FC2041063546C3759B861B379F62299855CBCB983E2DB1375
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............\r.f....pHYs.................sRGB.........gAMA......a.....IDATx...KlTW.....*.....i`....H...."a6Db.8RZ.b.@F.b61..4..d3...f3...C.H-5R.,Fj6..Ha....U".i$..@a.;~.=}.{...z...s.......L0...w....F....m"..B=.{.s..JR}9x..7...r.~....>V.3.........|.qN...K.ho...z. .q...v...H..!.A.Q..#r.G.9..L.=..........$.....u.u%h....*.XQ..9d.zA.HY.w.WO....(e.....2.[*SP.a.C........$...?nl...? .....h...!Y..........;...>.q........X... ~..1....}.,.r..w^0(...W...@......>R..b....{...p..}2...\3pN.%...@..._...4..8B..........Zo..J.....g..kX......6.|..V..8..~..+......R.9......dM".t.....~f .t.....?...Z@....?7....>....j.^L....r..=...........TSz..U.><..@...`O.eB..9,......r....C....#y..,..{......?t`KY.....I..g.....(.'.@.r..d:..z}B..."..d.`O?.../......l s..W.E...%.P....eLf2...C.......Y9.4......$..ddfH`....zx........Hp..d8...W...+X..)(Ir..>K`...v......Z.rVXK'M.....0..M.Y.0j...C..-y..wPd.c....!.@...............J...b...$-.).......~.sHaM.0C.u..o.....J......$Mi....!+t.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 200 x 200, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):5926
            Entropy (8bit):7.934148691552724
            Encrypted:false
            SSDEEP:96:Y0vsDTp7UQbNOyzXSfREIFEdWWhQ4cY4xt0tLuhp7Q/Ty1Jd7ZXB0Jy/VrTwk1qd:uZpNHzcREIFEYQM/0tLypYTy1nNx/Fw5
            MD5:4FA9634878F654B333337BE896AB8A74
            SHA1:10785799D3EC09500EC7BD986F90DB45FC8382DF
            SHA-256:CBC79EB1B7EC6BA55B962B5A8085DAA8B403ED530A3AD8CE96BED5F3EFACB04E
            SHA-512:FEEDBBB3ECB01D9B9C9795184730E78FDFA6F1F18E6573D5CF6D10190AF95CA25E55E9865D0D0FEB71A9E330247F6233BE868EB236F4DDC865165A65BD7E0118
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR..............X......pHYs..,K..,K..=......sRGB.........gAMA......a.....IDATx..ol.g~.......$.T..k.z!j ..Q...I.."%...J..".T.Hzi....^.-.M".{.{.b.....J.]..M.r.....&`.....<..fg...gvvwfv.g~.a...=;...}...".....`.......U%.;.0V....G...L<r..j..&..&....G...y0F.`...MN..#....."r..M.B0.....-!....qR...>.\1.9."p...0D.i..H.\=...`..2.n...Q.t.......9..f.! BC......t...u..N..-C..f..8e.pa.#@H!...V.b|......[.f)..!..1...!..x.0.xYu+..E ., .......n.>p.7.....d...."d.L....g.O|..D...`G..}..d.....E$..../.f/d.h/..F,...U*..](......Gu..v.!a..-...@H.....;.....&h!.+.;D..8....T...u.z)-...|.`...tm*..N..7Tv..P....b_.o...#.0./.....^..(gA.".Z.....a.*...fM.. .NtP..<.8.A...D.....'.. .P...I.-......k.8t.bM>...{!...u.>...@h.....2f..uip*.B.U.H..:...T.Re...u..{H.........V.L.)..si.r.F xb,....e..9..$... ../...G.....``.w.wA.i.@\q`.....i........X.."q.5.*..s.{%...X.7.K-#D8Z..N\ $..!Z$.D.B. ..."I,....... ..RP..^K......r""..=).$"....\.D. .b.r;./........AD...$*.....p...A...9{c...(.&.w
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 480 x 300, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):329163
            Entropy (8bit):7.995111900780554
            Encrypted:true
            SSDEEP:6144:2JOww/ug8itz2HuUvmG0lNYWo+vkwUUfAGTCa6+TqJssNNIC/eaGECz2:2cw3gVt8uUvmG0lNmmkwnfA1m+sAI7SN
            MD5:3EFBA3B589BBBE88840E6D43A46A24F8
            SHA1:1AFBA597DE3A0AD3D364D99FEA10B26A0F06EE7B
            SHA-256:9E2AA8145343BAAF6FD722521CBE66A7BC6AECC30AE5B6A7AFCAE97825E55357
            SHA-512:25B4882DB163D74ECD861CA2B33FE53A7189186BFA740ABE4BA788ED2F0E9A05DB6C7853EF69AA6E368740F47F34521F331CD9C14879819E440DE7BBD7BC68AA
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.......,.......`Z....pHYs.........&.:4....sRGB.........gAMA......a....`IDATx.\.G..k.%.=......u.N.D..H.......$.J@...B..# @ ...p#..+...H...p.f..tMwUW.5yo......w<._d5X......{.s.c|.?....|.....;..2..gC.....fk..............v...vk.....K...o....z:.?nm...f6..l._......+......z........t......t.6....+..":.eod..................1..L........>;.c..O.7...w.&c..z2....pL.PP......<...._....@$.N.....x..3.......+...:..f..[..ns.,p......t.....^.X.k...6?./.M.;#.......w.L.|.....0.y....m=..-.:.|......a..q..d... ......o1..fn...|.|?.3...t.,.{...,.....-......+.O.6.-m..ZXoy.......Dp...Q....i.X....=....a?~pm.NR....8.5^;...k./.x?>#....)..X..,.u..q.pOy.".&.`......|..}^....O..~...?..&,..X<..X...J....M.}.......}...^{.}.......NW.......v.X.!.G...jf..n8..wS..p.X..|W:..d8m.....{......B.......rj.E....p.BX.)~O8..J....@....'t<.q.F....P.5..Z1...$....[S{..a..=..n.?..h.E..w.N8.{.{...s..J...~...8...../.Y<..h,.5..4l0.........3...`......g.-..k......[..x.q^.t..'..<...&.|
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):980
            Entropy (8bit):4.639308502816959
            Encrypted:false
            SSDEEP:24:t3JfDuIph1gNCX5OP02IJRlHchtNlEGxNwkH8BI8O/g7v+kPJuRlHchR:3PgsX5Y02csNCM8ICvRMM
            MD5:7D1288A648992E6B6F7F85043A50E965
            SHA1:52B471D58CF74B679ADC773D03852002E0898E74
            SHA-256:DDEFCFE93D58A888352274E8F02DC2C18F2B1974F6BFA87BC3D0230EFB28B0C0
            SHA-512:AB63B9C67378D8AC7091BB314DF981168DB1DE2A86F24DB01570C4956EA4CB2D556378CF5A658AAB6BDA69CD94E1157C3123C3AACDE4AC0C9CB7017751FA7102
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M8.34801 3.82127C8.71179 4.19206 9.20969 4.40069 9.7295 4.40069H11.3196C11.4502 4.40069 11.5773 4.41559 11.7 4.44276V3.14981C11.7 2.62475 11.274 2.19873 10.749 2.19873H7.00335C6.92533 2.19873 6.8517 2.211 6.77895 2.22853C6.79385 2.24256 6.80875 2.25483 6.82277 2.26886L8.34801 3.82127Z" stroke="#6B6B6B" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M11.7 4.44284C11.5773 4.41566 11.4502 4.40076 11.3196 4.40076H9.72951C9.2097 4.40076 8.71268 4.19214 8.34803 3.82135L6.82279 2.26893C6.80876 2.25491 6.79298 2.24176 6.77896 2.22861C6.45726 1.92269 6.03036 1.75 5.58419 1.75H2.34787C1.374 1.75 0.583328 2.53979 0.583328 3.51455V10.6402C0.583328 11.615 1.37312 12.4048 2.34787 12.4048H11.3196C12.2944 12.4048 13.0842 11.615 13.0842 10.6402V6.16531C13.0842 5.32117 12.4916 4.61728 11.7 4.44284Z" stroke="#6B6B6B" stroke-miterlimit="10" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):976
            Entropy (8bit):4.627420312501156
            Encrypted:false
            SSDEEP:24:t3JfDuIph1gNCX5OP02IJkaHchtNlEGxNwkH8BI8O/g7v+kPJukaHchR:3PgsX5Y02d+sNCM8ICvRt+M
            MD5:1E55AFC96EA602089F2BEAB1D03B63B1
            SHA1:1923CB353E9620AD0490EA459DB83F968F8DEE86
            SHA-256:B813EE15914CF3FDC98CED187CCAD89FDA9BFF6203ACE9D11CEB08360B000AD1
            SHA-512:B7C077D9048954356B4106E15B80B19F63B47CA7AF1AB358F934B125AB83742AD2D884EE152D54BF7923E289CB2E0E1C3C1EB02CF01BD0A4957483AE50F49764
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="14" viewBox="0 0 14 14" fill="none" xmlns="http://www.w3.org/2000/svg">.<path d="M8.34801 3.82127C8.71179 4.19206 9.20969 4.40069 9.7295 4.40069H11.3196C11.4502 4.40069 11.5773 4.41559 11.7 4.44276V3.14981C11.7 2.62475 11.274 2.19873 10.749 2.19873H7.00335C6.92533 2.19873 6.8517 2.211 6.77895 2.22853C6.79385 2.24256 6.80875 2.25483 6.82277 2.26886L8.34801 3.82127Z" stroke="white" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M11.7 4.44284C11.5773 4.41566 11.4502 4.40076 11.3196 4.40076H9.72951C9.2097 4.40076 8.71268 4.19214 8.34803 3.82135L6.82279 2.26893C6.80876 2.25491 6.79298 2.24176 6.77896 2.22861C6.45726 1.92269 6.03036 1.75 5.58419 1.75H2.34787C1.374 1.75 0.583328 2.53979 0.583328 3.51455V10.6402C0.583328 11.615 1.37312 12.4048 2.34787 12.4048H11.3196C12.2944 12.4048 13.0842 11.615 13.0842 10.6402V6.16531C13.0842 5.32117 12.4916 4.61728 11.7 4.44284Z" stroke="white" stroke-miterlimit="10" stroke-linecap="round"/>.</svg>.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 481 x 301, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):58365
            Entropy (8bit):7.982034479404888
            Encrypted:false
            SSDEEP:1536:qYftW3aD6STR+xjn+IVqg/nvuHUJftXZ3Tu8XfW47NDIelO:BftZbR8+I4mJtZXOoDb8
            MD5:4C23F54D09E41D899D7150FEC49FA7EE
            SHA1:137F3D6599591B3345AB5C4C7C15806879531B3A
            SHA-256:C21DA932E908B9AC0420A4F2C1B03DCB71566CB3AF7FB5A6656868CA8DB33200
            SHA-512:54FC05DF04669B6352F56AAD6F183C3082D7C6FD294A2EA718787093700C61CF4FBF9795832322FCB357CE0891896EDD62891F2E310B29F86CC4255B0A4816AB
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.......-.....?`......pHYs.................sRGB.........gAMA......a....IDATx..]...E.>....J.)..~...{......Q.....U@D.b..T.&H..B.%. -4IB@ .....{..wv......./\.[fggg.S.B1.r.-.,.X<..C}./...S...'uttP}.A.=.u.b..5.^..n.mP.G..2..L..v$V<.D.g1u.5z.\@{G.a.....bFK*.".I....f..{K.y'..w..........t..v.9.7+TY.2.q.Z.p!..../H..hoo...6j5...u7<./.......QiSoZ.~...r.....W..>dzuC...q.v.....|p-.1\...#fH..o*...C..=..J...C.FI.8..p.6U..p.....=....iP[....R...R......;.q..............~.U.T...~x0 ...... `..D..V..\LD_0"ni.F_k....IP.|..l<)...X..\[.F....K3.fj..Mc...v..".z.W................/.8y..m...Gk.............|.M."..+*.x0xQcg.....!.,hu"N.P.$.,.W<I..1...J..L$...lC..P.|Mu^f........y..$.d'.R.Pf!(\.D....RA@+..17.f[o.a...C%.7.h."...FI.&,UM77Z....l...B.\.Y[.........N.'d..:.:.... .t....m5.)U.e..`..kCQM..B..X...:;*...n.hw~C%...[.nVd...9......?ko.P..6CG+....7...@-...*.$.J6..SC*.J...j.l%............U..)....ah..3...7.6....J.3.....wv.Du....H.*..={P3b.D.\X*....~..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 481 x 300, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):13096
            Entropy (8bit):7.896587827607765
            Encrypted:false
            SSDEEP:192:bTcs0VuY0fVeNiRkE5Io6R5A2SCiNLSMUebCnwvaTDRhiP134TaUdWADIyqHcDlo:/mVa9ylCJNeMvlS5QPyawWADIyvfvti
            MD5:011FFEC3560361B194EC3FA4615F1612
            SHA1:E6E17B429D2E5278FE7B9A610C146176941458E5
            SHA-256:BC39705D5B36AE3806D19A02D91EEA388C8EF33AC4544AEDB6D04B8F08D1CE3A
            SHA-512:6C5C6EE590A0D51F10E132CB2D7B839D23DB912807ACB7AD62478047EE85817FD1CE6636C7061BAF9002AA2E7E6CDC0D2163CF25F828C5F99DFC44E0321C9051
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.......,......<.d....pHYs.........&.:4....sRGB.........gAMA......a...2.IDATx.....\U...].`.n.G...I...8.y\....>.Q..5....(.Ge!8........A\0ry..k....%".$<.$.8$D.........I.{.oW....ujWu.?ku...N.........}../..sr&c...5....P.(.....':2.g?.e..c~..1.{...;...h..@CE.we.1..........x.1.D5....HE<.w...0...S..V.\.......Nc.>...'.....e..@.../.......h..l..`....M......... .....A...@.....B... ..0......... ..@ .a...!.....A...@.....B... ..0......... ..@ .a...!.....A...@.....B... ..0...............|].7.l..@.....@ .a...!.....A...@.....B... ..0......... ..@ .a...!.....A...@......e.....g..v2....lz.M.....x2....3.._6Con2....H...2.O|n...G.f.~.>c~....4...W...4k_z..k..........?.k...)...wN.~.w.._j.k.<.|{.g....W.3.../z......m...`...K.W..0..1......z.Y'.P..z.f....{..[..\...B.._?-........w._.~..D.......~l..E.\....A..Sf.L>........_....87....=V.3..;..W...;.T.{.xm....sVT.xw.c......8..g+w^......1.s..\[U.....9g..nJ....9.........N...)9M. ....N.8.K.s..vh....`....g..A.0*...I_;.d..).
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 481 x 300, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):110028
            Entropy (8bit):7.99142271813207
            Encrypted:true
            SSDEEP:3072:a39MS6deB+ABBWBGO2a2hAc+LyHiRgHfU:kydk4BGO2aeA8H00fU
            MD5:D96BC389AC88C9BF5501DEB24C83C0AF
            SHA1:1B95F949B5D2481ECBC18AA670BAE747536C8306
            SHA-256:D8CE47E4205742AF74F46BD343A8FBCDDCB5DB155A2E93EEE8CE6E748B842DF2
            SHA-512:F771F02659165B0B4E8CB76EA8E50C6E5D137834AB820B753AA9875BAC0E0B5B1692BB64FB22C86FBF6A419A4ABE92085FCD586E1DDBC027B8E01FD36805B837
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.......,......<.d....pHYs.........&.:4....sRGB.........gAMA......a....aIDATx.....d.y....E.Y....jA..J. @.;).....,.c..e..=s....t...}..g.....m..X.....LR...$.b.....=#....w.....Y.......x.......:.._.....'....}..&..@.2...d ....K.......................>..@.2...d WT... ..g~.3.&...;D_..x?.d ...@.2.."U n....d ...@.*......}.'Q..ko.......k[.:.........2...d ......r....\F..}xw....2.]W.q.i^O..h....=......M(..v......>.!...2...d .1Q....F.^.e.....f$,.%.W>.`1../.}\..cp'.o.r..a.7........(..d .....Dp5.Jj*6.q.....j.7..e...G0."..b=[f...s..|-...2|..7...K.ts..4...d .b...X.W.$...DK.x..+zEbc.>.../|....)h{O.=..9g%...c<.....'....d .....D...U...0..g.S.K.i....Z..l...K.`%........k.....;...je....F...2...d ...-.J}.l.U.M......[0_.@g@......|..+|.>2......IE.0........TF.c...d ...\..jtr.;..R.Le.4U..........}...)[......$.../r.....o.l..e<.....0.x.....@..&.f.H.R.5.Z..S.....D.w>.....wf.ve.6.M"...[3b..d]...ey..+.bS*|<.E.p.y3#...o|.....2.....&..r....x.;.su..Gvk...
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1152
            Entropy (8bit):5.172829660694891
            Encrypted:false
            SSDEEP:24:t3HqORutoFqub0Nj0/PPHchtp0/PPHchtn/PPHchtKiq/PPHchtESiq/PPHchfT1:FqzO0t2/v/k/PJ/0J/+l
            MD5:A11EBF33BB2DD08E31A5A5C647FFEBAC
            SHA1:6DD791E2A1CF81DE12BECC0BBCF0E07E53EF2E49
            SHA-256:8EB129E74E5F4A3408812EE73A0741CFB81819F4706CDDDAF313945A9C94B10A
            SHA-512:F5827F657E702EB5A611C158BBE2CD58BC0A8F7A32947219200DB53EBC4B9D61A34554C3F59B6A02D950D7550151C603CA053F67A57CC9A454D8D995C0957CF5
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="15" viewBox="0 0 14 15" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_7828_34220)">.<path d="M11.8245 5.10425V13.1577C11.8245 13.431 11.5708 13.6544 11.2604 13.6544H2.73973C2.42934 13.6544 2.17566 13.431 2.17566 13.1577V5.10425" stroke="#D01B1B" stroke-width="0.8" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M0.965012 3.55176H13.0353" stroke="#D01B1B" stroke-width="0.8" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M4.31033 1.55829C4.31033 1.55829 4.31033 1.38921 4.31033 1.18246C4.31033 0.975717 4.56401 0.806641 4.8744 0.806641H9.1263C9.43668 0.806641 9.69036 0.975717 9.69036 1.18246C9.69036 1.38921 9.69036 1.55829 9.69036 1.55829" stroke="#D01B1B" stroke-width="0.8" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M5.23859 5.29443V12.0461" stroke="#D01B1B" stroke-width="0.8" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M8.76242 5.29443V12.0461" stroke="#D01B1B" stroke-width="0.8" stroke-miter
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1142
            Entropy (8bit):5.128741834304259
            Encrypted:false
            SSDEEP:24:t3HqORutfWqub0Nj0kaPPHchtp0kaPPHchtnkaPPHchtKiqkaPPHchtESiqkaPPM:FqNO0tb2/82/V2/Py2/0y2/6nl
            MD5:0193D7311AA052579E894FF0283B028A
            SHA1:5D8A72021E245EB3D951C687778F0B517B870BB5
            SHA-256:7D535FD31B3FA6754B61F3CBDB8C78206D52BDF1BC4D1512D1BA01B4A1A70D99
            SHA-512:5378ABD43006DBBC0C2DE0F69591A552C819E9A02767657FB8FCE1AB5641AD50BB68EE799227D64062F0E60BBAB8C500EE7FE031E5C634AC7FE0B979451ACEA3
            Malicious:false
            Reputation:low
            Preview:<svg width="14" height="15" viewBox="0 0 14 15" fill="none" xmlns="http://www.w3.org/2000/svg">.<g clip-path="url(#clip0_7844_34237)">.<path d="M11.8245 5.10425V13.1577C11.8245 13.431 11.5708 13.6544 11.2604 13.6544H2.73973C2.42934 13.6544 2.17566 13.431 2.17566 13.1577V5.10425" stroke="white" stroke-width="0.8" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M0.965012 3.55176H13.0353" stroke="white" stroke-width="0.8" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M4.31033 1.55829C4.31033 1.55829 4.31033 1.38921 4.31033 1.18246C4.31033 0.975717 4.56401 0.806641 4.8744 0.806641H9.1263C9.43668 0.806641 9.69036 0.975717 9.69036 1.18246C9.69036 1.38921 9.69036 1.55829 9.69036 1.55829" stroke="white" stroke-width="0.8" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M5.23859 5.29443V12.0461" stroke="white" stroke-width="0.8" stroke-miterlimit="10" stroke-linecap="round"/>.<path d="M8.76242 5.29443V12.0461" stroke="white" stroke-width="0.8" stroke-miterlimit="10"
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 480 x 300, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):69971
            Entropy (8bit):7.9912216766107
            Encrypted:true
            SSDEEP:1536:CuqlX/HAHTvOEg6snIezgrZXEoNgjLlBBBJd3rdZYRn:YBHAaS1rRZelBBBJPZ4
            MD5:E87E7D518F0524A951B1EB5729830B3C
            SHA1:D857D47562C72A64DB29188C2AAA2376456A6B77
            SHA-256:DEECEA06E5DE2A11A7535DC0E7136C9B6D3351F8F92DB7544BDCDDC7A8072860
            SHA-512:523992B28091B47E1F267C1DB9C7EA61D819FFFBF95620EA068D868BA1015C6E449457F1B1F3DB94BB369058DEA7E1ED314A78BCCC99C5AF78AFD375CDD158D9
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.......,.......`Z....pHYs.........&.:4....sRGB.........gAMA......a.....IDATx...`Tgv6|f..BB]BB...L.c.1.k...z.g.M.&..~.f.$....zm....1..M.EB....]....<..;..$. 1..c...w..>........z.M..A..n.!.6l.a.......s.a...y..~.L.....2...&...l.a...#.&.SAD...[...|.....I6l.a..K.+.;.M.6l.a.......f....>M6l.a......?.D...a...6..\n&`..te...6l\^.i..N5.a...6.3...$.6l.a..e.M.6l.a....M.6l.a....M.6l.a....M.6l.a....M.6l.a...@0..X..g}C6l....;..a."`.p..m0oZr*...Y......q+.*......fb.6..6.........<Asrf.......o......A..$l...a.p...^~.....=:.^}....Z....k8.....A.t.p:....F..jh.....{...#...6......n..j..,q+2...s..#m.@..g../.~M.....w.>...p.......{...t.......X..........!...wz{.}..^....:k..x..pZ7i..E$....W..k7...y.gTT........... r.....Z.w6l...l....y_.....oii....Sd..$.........p.~.....3g.[n.I.&..JF}.}.X..`W..d...M.N%.....G...e............jJ.D.|..........?.E.....C...B..;n.8.....;.f...E......M.r]...t...Z.t.|...O;w.k......{..m...u...:..}.C{......./.3...H....
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 481 x 300, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):27163
            Entropy (8bit):7.94357850314399
            Encrypted:false
            SSDEEP:768:MSmXwn5WYQkY8y9GEkVO6JrTC4Y2/Q6jnxR:MSLHQT8y9qdFTtYIH
            MD5:AC3BBD51FE98E8D9CCA04804CB3EF449
            SHA1:691AD024A54A30FA5A82AF34ACD6E7B4D4C1859B
            SHA-256:F2E2BB1C71113996A5CC450DAED008397B85D3887C4A7C99E49B0E7BD2093386
            SHA-512:87C258D3D28E79741C767A83B8FFB7FEA9D03A505BE0A5449E129C5C77239B477EE5C4C9A505E1A80655C82AEFEDAD373A1B8B9EF4FD8A202A69355193E3F3B7
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.......,......<.d....pHYs.........&.:4....sRGB.........gAMA......a...i.IDATx....mIu.........;J.a(+03Qy`d.....D.......F8U.RR....,...T*.......q.../.\....i~.0 ......(.3L...y...7..{....s...?Vw..uN.......{...^.W.^(M............5*B...S..J........T..b.P'''.7A.....c..d.....Mp.J.i..j.|6'.w....u.....r...$x...}o...].B.\..u...\.J].O1...^S.k.....e...o_..%.R..o..o......|...._..1%.T...0.n..siQP.k..%..S..K...bu..b|Vm...fx6}...\..!'.c.............Y_....m.Y@/^..z.o.....5....Z~..|..T,.k...+..."......Z.(.A..0z.8..=..)_...w.$..r...{....`.!............. ..BaV.. .$$......>=..b4.......T{..@.,.?..I<W..s.>.....xII...L.....0..w.-~..8Y.....L.....u..W...^....kt.......@..m"...^.....8W....1...9`N.!.K.."s...'..x.e.|.w?../..W... ...X.pL+.F.j.C..."..N..n..Q.tH.....^........6.7.i...J..]..Z..F..G.........,`].\\\..t. .i.8M&..-h...C...l...-t....es5#tq B?OU........f.<k1.....eH12..e.........0@.s.\....=hHwA.Z.z.-..V.L.....=...qM...b./.6Df........w.}....3...}.k.x.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):2480
            Entropy (8bit):4.71768326966651
            Encrypted:false
            SSDEEP:48:n/vZ45i8sSLa9AhCuVWHGz8FAK9Tb6AoNymhL415HtKGjHthh:n5FHtlulxKcAoNymqP7t
            MD5:0400538AE1CB8530993D04B2581A21F1
            SHA1:CF5E86DA4A0C3D756F0555F616412C79A34AD00F
            SHA-256:7A01A43C33BA65B3F51C0CCFC216E9EE2A44CF013D62903B593EB0547249B7D3
            SHA-512:995221B9ED1CA9E5B9122CB31833F07481B15CCC792A3A05C6AC8E6D2DE83D19F442CA05666B301C2270517F038B07583E347C318BD45189E9FCA7E031460E99
            Malicious:false
            Reputation:low
            Preview:<svg width="24" height="24" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M7.5 16.646V21.2895C7.5 21.3382 7.5071 21.3866 7.52109 21.4332C7.60044 21.6977 7.87918 21.8478 8.14367 21.7684L12 20.6115L15.8563 21.7684C15.9029 21.7824 15.9513 21.7895 16 21.7895C16.2761 21.7895 16.5 21.5656 16.5 21.2895V16.6462L15.7247 16.7081C15.0954 16.7583 14.498 17.0058 14.0175 17.4152L13.379 17.9594C12.5851 18.6359 11.4175 18.6359 10.6237 17.9594L9.98515 17.4152C9.50466 17.0058 8.90724 16.7583 8.27795 16.7081L7.5 16.646Z" fill="url(#paint0_linear_10080_34787)"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M11.2125 2.79872C11.7202 2.44222 12.4121 2.46866 12.8925 2.87803L13.531 3.42217C14.1316 3.93401 14.8784 4.24333 15.665 4.3061L16.5013 4.37284C17.1739 4.42651 17.708 4.9606 17.7616 5.63318L17.8284 6.46944C17.8912 7.25606 18.2005 8.00284 18.7123 8.60345L19.2565 9.24197C19.6941 9.75551 19.6941 10.5108 19.2565 11.0244L18.7123 11.6629
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1293
            Entropy (8bit):4.894705772050092
            Encrypted:false
            SSDEEP:24:tYU/duXMMgcbeNjLOPSHdWBv9IKltdkAq7BLM49MMS9Md7i26SYSjQHxNNcGXiHG:n/bOYi9Btd1qlLk9MdmjHthh
            MD5:57C32613550F59BE4CE93BD810117FF2
            SHA1:EC6BA105E3BA031C8F2344BE9CCBFAF379579B6F
            SHA-256:7DFF2AFA30C4DC233B8CF04506E4494806266C27C8D8CB1E696A186B4FF8BB6D
            SHA-512:AB72789F8AD64AF4E177F81E26273E5F4D88EC059F78204C5E27170D7A3248E604541A14D5B563D81064B3B5FEFBC72780015ACB0A9226B43D3A81314388E485
            Malicious:false
            Reputation:low
            Preview:<svg width="24" height="24" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">.<path fill-rule="evenodd" clip-rule="evenodd" d="M12.4145 8.28147C12.4145 7.82507 12.0445 7.45508 11.5881 7.45508C11.1317 7.45508 10.7617 7.82507 10.7617 8.28147V12.3419C10.7597 12.3655 10.7587 12.3893 10.7587 12.4133C10.7587 12.8604 11.1138 13.2246 11.5573 13.2392C11.5675 13.2396 11.5778 13.2398 11.5881 13.2398L11.6017 13.2397H14.0642C14.5206 13.2397 14.8906 12.8697 14.8906 12.4133C14.8906 11.9569 14.5206 11.5869 14.0642 11.5869H12.4145V8.28147ZM19 12C19 15.866 15.866 19 12 19C8.13401 19 5 15.866 5 12C5 8.13401 8.13401 5 12 5C15.866 5 19 8.13401 19 12Z" fill="url(#paint0_linear_10269_34622)"/>.<path fill-rule="evenodd" clip-rule="evenodd" d="M12 19C15.866 19 19 15.866 19 12C19 8.13401 15.866 5 12 5C8.13401 5 5 8.13401 5 12C5 15.866 8.13401 19 12 19ZM12 20.5C16.6944 20.5 20.5 16.6944 20.5 12C20.5 7.30558 16.6944 3.5 12 3.5C7.30558 3.5 3.5 7.30558 3.5 12C3.5 16.6944 7.30558 20.5 12 20.5Z" fil
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 772 x 487, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):471159
            Entropy (8bit):7.99597146015849
            Encrypted:true
            SSDEEP:12288:TZMbd3ewqHDnctqAmTmYcDop7u9zfl7jZl:1adhqHwtqAmVcspEzfln
            MD5:5A02BD2E78C59824CF9924D72ACB129B
            SHA1:C2C388082447AB5C0DDD8A4149BF78D7C8FBA867
            SHA-256:ECF8A0D1C8569F754E12002097222F569D3557D5D1A4D7616606BC1F32B93A4B
            SHA-512:6DB31F0846916C662643829576712BECE014FF346A7D3E1EC256FCAE9B33DD95060C39DACFB5A4B9F4B9BEFECFB237ECB2A5127DBB3AF3CDB6E0A871BF63609B
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR.....................IDATx..g{.V.......$..T#i...y........t..Lw....J%.L*...dx..@......d..n..T.Pb.#..{/.8?.{.(G...;..../..(@$!..?>..../.....$..Qd....Xd.}Ax...........,.aYV$...EZ~;.7{.i..:.....h,.N.2.i.v..h4[-....~..E#.(..<.o.AIBC"^,.M.."..b....].D...2.)K....g;.^......X4........Z..5..yvq...$.(.....Q......E.[... ...^./..%.PB.Y.(G..w...,[.q..-Pb7........`H.p...&!..........X.=x..AdB .9..).r.J.P(.o..(>....x1........&+.._?.0B.y....%..i.o...O......|'....FD..!......5].Sc.......J.\..$q2........%9...C......~r.m...%.PBy'D.....e[B.;z.ne.Cx.c.z)X..|..7B...E....-[...;/.....@.|c$..ff...,.O..r.R...t..w.......x.F.........G.....).....m...(.L+...b.X4...b.8=..d.R./.....x.c.......?3f3sf.- .H.@.}..U.V..J%...a.?.\._..ul.N..@./p.n.^.x..o3...C.%.P~.".zq{{gnY.'...nr.=....[...)/x...>....~....`.n...e?x.....x:........x.H&bZD.%......,@.......v A.[.](.+.r.V....$rB.[s..L.d&r...H.&y...S..w....,..6]..h...\..i___..=cj...H..H.ww...L6.A[_>.......O......D..n...$,,.Ax..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 664 x 426, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):348993
            Entropy (8bit):7.994091134822872
            Encrypted:true
            SSDEEP:6144:abfK06+1ENRW4MgCrPv8QCWPWdj5aTrVoBz1DqFxXL5fc7muCA1BWbxYm6AyqflM:abi0PIwx7rXyzrmF9L5FuCAjWnJyEl+V
            MD5:46BEEFF97CF9AABB69695E8842B5587B
            SHA1:FDC25A9CEC62F37FBDCDD7DB7E971E062BAD1C9D
            SHA-256:98F4D5442C10BE82A26FE80928A2BE5E6E392D172D791A7A4892ED2DF2859337
            SHA-512:E07C5565CA32628AEB4AEF34E8B900072272585EB3AD815BDD9C92C5DCA05B24246C18EE5F7EA771E3630F2749FFE9E5B9AC131B9B157FF91354F95585130345
            Malicious:true
            Reputation:low
            Preview:.PNG........IHDR............. .......IDATx...-Iv..U..{........t.X...%@.m ..M.. .....`0...O%.....`.X.Dk...M..9g.Lr...Z....s.}j......../............%..B.5......~....Fj.Y....'e..Y.?..H.?*~#..B.2}i.T........o....E.#M.MY>-..=..4|Qi...U.G}.....g>.B..^.4W..(.......G../%....s.....]..U...H..e.gcQ.j.hsV....T.2....../.=F..1pa..m.mE./..w9.i....)..../..:.n.......i......z...h.-A[.#H.j.(>..ri9}.}.}../....V.?(..~..;AM.P....+...$.]n%.Qj%&)......K...Gj......e...;>...U..e[.6.{.r...b..z..lYz..P ..^n...'mk....z.)$.tLr-.*m.t.l-.P...6,y... 1.A.a....-.4...r.@.k.....n...\./.....b.......7*.^[...Ww.W.....Q.#....-.0iqi4.&vfL.0.....,Je.X.CM,.%.... 7..fQ...Io...*.O...]a.Ol.......7...N=.l..f..r....r.`J..F.Y.,..J[m....-..A..}....J...... W...3 .....@......6..............Py.DW.4......L......r...N... .@.....!@..ds.'.|m.gMql#0x_....K .5aYO_.yA..;..B..yka.M....Y....yz<W..fB).r\...E..m`>.>mkJ..o.HA~.v.Y._?..F.. w........P.....Wj..\.I^....o...R.#.....G....Q. .?.=E...
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 873 x 535, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):526505
            Entropy (8bit):7.986726578807242
            Encrypted:false
            SSDEEP:12288:IMzY9JGrlQD4zrZun5jcUjTX23NDaQYObltbFhmOjRhxA0S:IgcJGScZ85jHP23laQJ5tBlPKH
            MD5:F3062192C0698B26CFFE65DE51ADCEF9
            SHA1:5C9529D53F1288333B3C8696D556C62E39D348AA
            SHA-256:54C595A6CBD7D6CCB907FB1FCD84FAA986F2E4BE33098A924CB1665EF364524A
            SHA-512:0C8DBD4133627BE43AFD03AEC12E7A9EE51E0A596C294A163ABDE4ED5E448B0C5058F9231E8EC34358EFC5730FECE8E3E340BF10A56716C298C8B58412A2A132
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR...i.................IDATx..Y.-Iv..C...p....Q.J..I%45..2u.Z..1ZM7`.....G..|..y..^1k...*+3..cpw....!bG........:...c..p....K.@i....KO...^../....7ayCS....W.==......o.e....]......Y..{..J#.......k9._.^.....(.........(Z..^..........P+.......e.....[...x..@....._E..k_.~~+R........n..>$>..V..`.d.k..~..j.?7U;{.3.K.!......W6.......x..l..g.}}.....\.?...yC...S.t....Z..p...C....g. ...m......|t.O.V.V..7..jm..g....E.....#....t.&P..>...xlbKR..X.n....p...u.Sp.KzW5..........e.._..u./..?76...y..T&~...'..JW......t>.V....7......{.Rz_...k.e...C....q..=.....L.H...M...rn2.....w......n=.R.].6....X...n...vc7.....f.M.0n.....F7.-.?W...:c0...A..-...om...v.a..u.....x#q0g.x.>..'..}.........7685x.]>o....O.?:g.oU.X..Q.cl......6...nt..clY..........{..i7...n.3...{.FG_...'8<(.sC....A.g.....!.q.#........?.w...........l|Hw..a!......x#.s...y\......e.1:....k..-vL?*....).|=.8g.E..?;......U....v....O.wQ..~p..3<Z|....;.....C&.Uv4...V.1.....;..E.o?.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:HTML document, Unicode text, UTF-8 text, with very long lines (382), with CRLF line terminators
            Category:dropped
            Size (bytes):18254
            Entropy (8bit):5.406616810583083
            Encrypted:false
            SSDEEP:192:HNQ2tL3X1Ky6/VAX9Ir9IqbMpm4YhBK0rCdBMPf:HvKy6/FMund3
            MD5:FDA2E23D72F99FB0DB95B8C6E126A6B2
            SHA1:5EBF5EE415E5C93F9E0B05F4B89676E4D98FB724
            SHA-256:2CBFF3422F20CE2CB07280EDB8502A166D115355CD01635E8F82D02DC4056C2C
            SHA-512:E385E69AEFEC8D723F16CD85E0C4604625D3DB0BB231B8005BB211289FD4E53EDBDC5B3C43B18C5408EF0EAB653C43D18B0EBFC555F32A883510B8AF87CD1242
            Malicious:false
            Reputation:low
            Preview:<!doctype html>..<html>..<head>..<meta charset="utf-8">..<meta http-equiv="Cache-Control" content="max-age=7200" />..<meta content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" name="viewport" />...<title>homepage</title>..<link rel="stylesheet" type="text/css" href="./css/home.css" />..<link rel="stylesheet" type="text/css" href="./css/dark.css" />.....<script type="text/javascript" src="../include/jquery-2.1.1.min.js"></script>..<script type="text/javascript" src="../include/json2.js"></script>...<script type="text/javascript" src="../include/globalapi.js"></script>.....<link rel="stylesheet" type="text/css" href="../include/swiper/swiper-bundle.min.css" />..<script type="text/javascript" src="../include/swiper/swiper-bundle.min.js"></script>..<script type="text/javascript" src="../data/text.js"></script>.......<script type="text/javascript" src="js/home.js"></script>..</head>..<body class="ZScrol" onLoad="OnInit()">..<div id="LeftBoard">...<div id="Logi
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Unicode text, UTF-8 text, with very long lines (864), with CRLF line terminators
            Category:dropped
            Size (bytes):13079
            Entropy (8bit):5.64571794866111
            Encrypted:false
            SSDEEP:384:QvDLOIw+b67X8V9P8lPEzSHtXQ74dLVCWr:W2+O7X8V9P8RpHtXQ74dLVCWr
            MD5:CBA4A8A19E84EA9E9BFD924E9D960C53
            SHA1:D387CF6AE4E9C125C70444D48F5E6DC851333B5D
            SHA-256:E5DE68E212C8721F29C8878E275549AFA3FC56931C7DB05F8A5F38A8D4519C54
            SHA-512:CB413DB53DE01B24927108E8F5CE36AD391C3DE0AF34875BAEEE61EFADCB7AADE785F73BDCE26B1AA40194325F64410748DCCE04AAD70DE5BE90100D87469600
            Malicious:false
            Reputation:low
            Preview:/*var TestData={"sequence_id":"0","command":"studio_send_recentfile","data":[{"path":"D:\\work\\Models\\Toy\\3d-puzzle-cube-model_files\\3d-puzzle-cube.3mf","time":"2022\/3\/24 20:33:10"},{"path":"D:\\work\\Models\\Art\\Carved Stone Vase - remeshed+drainage\\Carved Stone Vase.3mf","time":"2022\/3\/24 17:11:51"},{"path":"D:\\work\\Models\\Art\\Kity & Cat\\Cat.3mf","time":"2022\/3\/24 17:07:55"},{"path":"D:\\work\\Models\\Toy\\....3mf","time":"2022\/3\/24 17:06:02"},{"path":"D:\\work\\Models\\Toy\\minimalistic-dual-tone-whistle-model_files\\minimalistic-dual-tone-whistle.3mf","time":"2022\/3\/22 21:12:22"},{"path":"D:\\work\\Models\\Toy\\spiral-city-model_files\\spiral-city.3mf","time":"2022\/3\/22 18:58:37"},{"path":"D:\\work\\Models\\Toy\\impossible-dovetail-puzzle-box-model_files\\impossible-dovetail-puzzle-box.3mf","time":"2022\/3\/22 20:08:40"}]};*/....var m_HotModelList=null;....function OnInit()..{....//-----Test-----...//Set_RecentFile_MouseRightBtn_Event();......//-----Off
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:HTML document, ASCII text, with CRLF line terminators
            Category:dropped
            Size (bytes):572
            Entropy (8bit):4.869033401212329
            Encrypted:false
            SSDEEP:12:qTWgymnGlA+2qJmW7mNVMcqJmWvLVI1qJmWbuNVMcqJmW/LVIdL8fziPG3:0W1IGjheNVMDvVReNVMDjLVAwfGQ
            MD5:9AAD805CA19672F7E9170AB5E8C62AD5
            SHA1:36AF3689F4FE4B39CA073144186C85518D018107
            SHA-256:A79E6B8F47E49FCE4D1AF55A0D2A0C1D3469691FAC3F0EB484BF2ECF79A41659
            SHA-512:DDABCB10542C7FB0822013E928E53DDBE5A8A5D7BEDC7469215E5D56117397DD17B4E04736D384F1A7DA70BB3EAE65C5D01FA4F12CD65AEF899BEBDDB66F2BC3
            Malicious:false
            Reputation:low
            Preview:<!doctype html>..<html>..<head>..<meta charset="utf-8">..<meta http-equiv="Cache-Control" content="max-age=7200" />..<title>homepage</title>..<link rel="stylesheet" type="text/css" href="css/home.css" />..<script type="text/javascript" src="js/jquery-3.6.0.min.js"></script>..<script type="text/javascript" src="../data/text.js"></script>...<script type="text/javascript" src="js/json2.js"></script>..<script type="text/javascript" src="js/globalapi.js"></script>...</head>..<body>..<div id="d1">...<div id="d2"></div>..</div>..</body>..</html>............................
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:SVG Scalable Vector Graphics image
            Category:dropped
            Size (bytes):1572
            Entropy (8bit):4.622340838599913
            Encrypted:false
            SSDEEP:24:qex1qW88pPEPRkeqqvvqJzajH9qxBJPwRCaka17pCxKgJtKTpRgciy7btSIz:LLqCpMJkavvqZqU4Vkuwv/Ol3b
            MD5:DA38EAC44FE95BE9DEFDB5F512B39D67
            SHA1:224AB30ED8552DE63536154FD7ED1116B91E16D9
            SHA-256:64B225ECA6461359BDE645F163004B001A685740CE8EBA54F661B6A34856AE61
            SHA-512:D461CA1A0EF3FCEFF35D32D9345584C26AF426BACB432DD7720FFBB7CEBA81E4C6DCA3468FE9153CF57A67F9DB60A9CE03835BB0D43E41CE9B2B9F8FC9774D7F
            Malicious:false
            Reputation:low
            Preview:<?xml version="1.0" standalone="no"?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"><svg t="1695385857383" class="icon" viewBox="0 0 1024 1024" version="1.1" xmlns="http://www.w3.org/2000/svg" p-id="1746" xmlns:xlink="http://www.w3.org/1999/xlink" width="200" height="200"><path d="M943.104 216.064q-8.192 9.216-15.36 16.384l-12.288 12.288q-6.144 6.144-11.264 10.24l-138.24-139.264q8.192-8.192 20.48-19.456t20.48-17.408q20.48-16.384 44.032-14.336t37.888 9.216q15.36 8.192 34.304 28.672t29.184 43.008q5.12 14.336 6.656 33.792t-15.872 36.864zM551.936 329.728l158.72-158.72 138.24 138.24q-87.04 87.04-158.72 157.696-30.72 29.696-59.904 58.88t-53.248 52.224-39.424 38.4l-18.432 18.432q-7.168 7.168-16.384 14.336t-20.48 12.288-31.232 12.288-41.472 13.824-40.96 12.288-29.696 6.656q-19.456 2.048-20.992-3.584t1.536-25.088q1.024-10.24 5.12-30.208t8.192-40.448 8.704-38.4 7.68-25.088q5.12-11.264 10.752-19.456t15.872-18.432zM899.072 478.208q21.504 0 40.96 1
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 154 x 154, 8-bit/color RGBA, non-interlaced
            Category:dropped
            Size (bytes):2343
            Entropy (8bit):7.8563754357549795
            Encrypted:false
            SSDEEP:48:d/6jMFLzm2/dR9l62BiKJJWJmSuUJzVToJfTaXPrkYms63+JeZBaK:dSjMhP9l6gi94GJzVTYaw3s6uJeZBaK
            MD5:C4852B1CE5E124F9348E928249FB5C10
            SHA1:4BCD97973F1DCBC21CF2E46DE11D85183ED02D15
            SHA-256:E89E7261360E7A5DD8FFE1A56219AC2C37C811CF9600ADD59E668B1C7B9BFAAC
            SHA-512:C0E5C0077BA4E2D01E12A78A82932762720320EA2C7EA312AC51F36D845BD80CA1D829F214A9E9C55A17ACE1294B1B651025D14DB95E060F4E9E2F37F587CC67
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR.............Q.Q.....pHYs.................sRGB.........gAMA......a.....IDATx...Ml......3.....}%=.5...*..P.Q..{.~A.JU.8.J94..8.qN-....K..j......{#@pI........@.F..B......o....gwv...._..|.g^v....?..7.Xy..0....<.uyT`M..^......b.......$.qx8..q.H..$>.a...".U...C+.>.f\..S`\.c. .oQ.+"A...6+.......\R...Z..2.g`=.5.....6..M.`.fe.~...".mu.1.....a.5p...a.#q...V..S...0.~4(...q~...@K_].......-P..'..Q.n.._.b.o...Ffq.D..H+.E....n-..<4FF.E.m...oN..y.....iL...}A...C..w..H.....y.C...o.....E..4..s~.f..2.'..."......Mg..,.(...e......vO..9.................f..\6....<3....T....6C.4.$.j...s.D..f.6.Qz...6@....>..b%.h.l%......s.D.3R...04]...!|N....b.O......v/.M.Q..1/...Qj....5....d...@-.9...`.14J.}.....?=...At....b...}...."..#..+.....?S........w.r...0.......eI.D ........`h..C#'..9.....FN04r.......`h..C#'..9.....FN04r.......`h..C#'..9.....FN04r.......s./b..@.1.6,..............Z...^......M.w....%H..9.*w>...G....G..0..0N=>......8......_..M......L:.r.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PNG image data, 399 x 517, 8-bit/color RGB, non-interlaced
            Category:dropped
            Size (bytes):4562
            Entropy (8bit):6.950462008373588
            Encrypted:false
            SSDEEP:96:3nBljjjjjjjjjjjjjjjjjjjcY7DJeNPKFTPhHgVgG192ZJC+xjjjjjjjjjjjjjj0:3zjjjjjjjjjjjjjjjjjjjT5YgG1gJC+W
            MD5:D230FFF6D58DAD3259CC93B463EEBA69
            SHA1:04CBAE9FA964E160B4443D0CDD6D99452315784C
            SHA-256:6CDC1373AAA6DCF3BFD903104BB13C578E3899E2E2AAEE981B8164EF2EB0A2A0
            SHA-512:9B2B2BF69F91E8824583723B5325A1ED26B7A29B5AC298640A1E5BC3D4E7DF06DB382343205E85D1C14DF32776A25BC2F1E5B5BFB62330F784DC86BEFA034250
            Malicious:false
            Reputation:low
            Preview:.PNG........IHDR..............;.....IDATx...?.....q(hH$S$"..Vv.*.7.e.i..........mS.H.=DJ..).&..6........E.0RBC.>..l...|<3..<.....#..=..=..W_}../...<...~.w..../..'.~........Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R+...Z.V....".Vt..)..K.H..]jEJ..R+RjE.Z.R
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Unicode text, UTF-8 text, with CRLF line terminators
            Category:dropped
            Size (bytes):8984
            Entropy (8bit):5.571807077427902
            Encrypted:false
            SSDEEP:192:7EjWh933jvQ4bJQA/Tvh831GhYR0VhgjaS1/1F86FXq3PXrJPkaf:4o3j4yg2GD1qv1jf
            MD5:A9E00A2A4B91113525E4DD8C5168E75A
            SHA1:3B37BD8A063289918B48DB1B5D70EC697A3AFB7E
            SHA-256:F4BE439114938631C0CB3E6024C6FDE1100CEA9F7345E5AB4F854C31436F4CB1
            SHA-512:3B722D842ECB55B5452481DD384E7F1345103EDF90E86D50EAA03EA2CB36BCB219F79BEEF76E3419B34FCB4945716008739A09459D23E0D0B7EB07F777F23B26
            Malicious:false
            Reputation:low
            Preview:../*------------------ Date Function ------------------------*/..function GetFullToday( )..{...var d=new Date();......var nday=d.getDate();...var nmonth=d.getMonth()+1;...var nyear=d.getFullYear();......var strM=nmonth+'';...if( nmonth<10 )....strM='0'+nmonth;.... var strD=nday+'';.. if( nday<10 )... strD='0'+nday;.......return nyear+'-'+strM+'-'+strD;..}....function GetFullDate()..{...var d=new Date();......var tDate={};......tDate.nyear=d.getFullYear();...tDate.nmonth=d.getMonth()+1;...tDate.nday=d.getDate();......tDate.nhour=d.getHours();...tDate.nminute=d.getMinutes();...tDate.nsecond=d.getSeconds();.......tDate.nweek=d.getDay();...tDate.ndate=d.getDate();......var strM=tDate.nmonth+'';...if( tDate.nmonth<10 )....strM='0'+tDate.nmonth;.... var strD=tDate.nday+'';.. if( tDate.nday<10 )... strD='0'+tDate.nday;......var strH=tDate.nhour+'';...if( tDate.nhour<10 )....strH='0'+tDate.nhour;.....var strMin=tDate.nminute+'';...if( tDate.nminute<10 )....strMin='0'+tDate.nm
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (32061), with CRLF line terminators
            Category:dropped
            Size (bytes):84252
            Entropy (8bit):5.370434151667816
            Encrypted:false
            SSDEEP:1536:uPEkjP+iADIOr/NEe876nmBu3HvF38NdTuJO1z6/A4TqAub0R4ULvguEhjzXpa9r:FNM2Jiz6oAFKP5a98HrY
            MD5:26625F3019AF11369EEF2B11024BAC6F
            SHA1:70C314AF63829B136F307A3E8AEE6669AFF9D968
            SHA-256:91A2571E098CE816E9EC0E4169CF4399872DC124F2D6F416EA87F975CDF5EA8D
            SHA-512:D7934B564A8C4410462844F2F616B98B5625A861FD2636CD9143B75877E5E2BD3EEF68CAA1F6E413B0BC50FF27F1F1CEEBADDD71059989D290420B2186B4136F
            Malicious:false
            Reputation:low
            Preview:./*! jQuery v2.1.1 | (c) 2005, 2014 jQuery Foundation, Inc. | jquery.org/license */..!function(a,b){"object"==typeof module&&"object"==typeof module.exports?module.exports=a.document?b(a,!0):function(a){if(!a.document)throw new Error("jQuery requires a window with a document");return b(a)}:b(a)}("undefined"!=typeof window?window:this,function(a,b){var c=[],d=c.slice,e=c.concat,f=c.push,g=c.indexOf,h={},i=h.toString,j=h.hasOwnProperty,k={},l=a.document,m="2.1.1",n=function(a,b){return new n.fn.init(a,b)},o=/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,p=/^-ms-/,q=/-([\da-z])/gi,r=function(a,b){return b.toUpperCase()};n.fn=n.prototype={jquery:m,constructor:n,selector:"",length:0,toArray:function(){return d.call(this)},get:function(a){return null!=a?0>a?this[a+this.length]:this[a]:d.call(this)},pushStack:function(a){var b=n.merge(this.constructor(),a);return b.prevObject=this,b.context=this.context,b},each:function(a,b){return n.each(this,a,b)},map:function(a){return this.pushStack(n.map(this,fu
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (65447)
            Category:dropped
            Size (bytes):89501
            Entropy (8bit):5.289893677458563
            Encrypted:false
            SSDEEP:1536:DjExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1v9:DIh8GgP3hujzwbhd3XvSiDQ47GKn
            MD5:8FB8FEE4FCC3CC86FF6C724154C49C42
            SHA1:B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4
            SHA-256:FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E
            SHA-512:F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31
            Malicious:false
            Reputation:low
            Preview:/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],r=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},x=function(e){return null!=e&&e===e.window},E=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function b(e,t,n){var r,i,o=(n=n||E).createElement("script");if(o.text=e,t)for(r in c)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.removeChild(o)}funct
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with CRLF line terminators
            Category:dropped
            Size (bytes):6854
            Entropy (8bit):4.027783590939373
            Encrypted:false
            SSDEEP:96:WTCsELQ5NuSWaAmEXA4FPjq2Bj+jO55CSNCYgLNC+TddySD4YYHCrFgLYqJYcj2:N24lmEZw4j+jO5BILHESD4YYHLbYE2
            MD5:3F2793FB286D25C22ED155510DF5681E
            SHA1:02F1A1EDE2733AE5D9A45A963F9F6D089FC9A951
            SHA-256:FB9EA02E2B3E1D2329B3F4CA349376F5A2F70BD9DEA244B3D4CFCADAE891660C
            SHA-512:5A30424C6B08F9E957EB42EA1742E102D7079735D4664C32E3CB6DEF0761C9FE75928DD0431860FAC920596C00B52939605622C46C630DBC68A38425AA7411C5
            Malicious:false
            Reputation:low
            Preview:var JSON;..if (!JSON) {.. JSON = {};..}..(function () {.. 'use strict';.. function f(n) {.. // Format integers to have at least two digits... return n < 10 ? '0' + n : n;.. }.. if (typeof Date.prototype.toJSON !== 'function') {.. Date.prototype.toJSON = function (key) {.... return isFinite(this.valueOf()).. ? this.getUTCFullYear() + '-' +.. f(this.getUTCMonth() + 1) + '-' +.. f(this.getUTCDate()) + 'T' +.. f(this.getUTCHours()) + ':' +.. f(this.getUTCMinutes()) + ':' +.. f(this.getUTCSeconds()) + 'Z'.. : null;.. };.... String.prototype.toJSON =.. Number.prototype.toJSON =.. Boolean.prototype.toJSON = function (key) {.. return this.valueOf();.. };.. }.. var cx = /[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1087
            Entropy (8bit):5.108093082103088
            Encrypted:false
            SSDEEP:24:b3GrOJH7H0yxgtAHw1hC09QHOsUv4tk4/+dpoaq/FD:b2SJrlxEDdQHOs52TSaYFD
            MD5:1410420805BE3C6F5781AE8A73C904C3
            SHA1:899FC9E161C2B9FC6C4596ACF21402FC2E6C6B5E
            SHA-256:99F08E3E3EE0799FE1488FCBCB41DC933B14873E9556693209DAF9E1007601D6
            SHA-512:44F3705097AC99BF9EA81B622D28D93D9FF5250E1A0891947158E13CD438EDDC833D3EA8C3CCCF2DD50A27DFE261753A271BA639D05FAB47E5DBAAA5714A3321
            Malicious:false
            Reputation:low
            Preview:The MIT License (MIT)..Copyright (c) 2019 Vladimir Kharlampidi..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of.the Software, and to permit persons to whom the Software is furnished to do so,.subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS.FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR.COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER.IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, O
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):570
            Entropy (8bit):4.653008624382028
            Encrypted:false
            SSDEEP:12:gSmhhASXo/kxjggvhOww2isXouYK5u+xR8RE27XVRE26Bd3/nBAV3B:XKhf47gvhO32B4un5uSRAEoLElBVZANB
            MD5:DB9E55308D3F0010668711DA7AE7972C
            SHA1:456C654924870281CA9305DDC871BC6C59D9464B
            SHA-256:8F588351422A5016ED5B310BEFAA9DFCE0A856B0F9C377326FB1730FC0AE6BFF
            SHA-512:DEB3596B67ABD133EFD45C07E59DD5EB3A540ED18FC1E161DF15DD6C557880A4CF48E22DDC64450F5DDE4524E170DF73FBBDE3DB9706F020C304E941BB102487
            Malicious:false
            Reputation:low
            Preview:Swiper.==========..Swiper - is the free and most modern mobile touch slider with hardware accelerated transitions and amazing native behavior. It is intended to be used in mobile websites, mobile web apps, and mobile native/hybrid apps...Swiper is not compatible with all platforms, it is a modern touch slider which is focused only on modern apps/platforms to bring the best experience and simplicity...# Getting Started. * [Getting Started Guide](https://swiperjs.com/get-started/). * [API](https://swiperjs.com/swiper-api/). * [Demos](https://swiperjs.com/demos/).
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):111
            Entropy (8bit):4.3640476752382975
            Encrypted:false
            SSDEEP:3:4i1F3Fm/q3+ewVQ1F3Fm/qmzvAdi1F3Fm/pWCgMXjdCw:4iP1P2VQP1PyP1yJXjr
            MD5:73F4026A2EE0141E0365822A1C711C13
            SHA1:9FC3882514CCF6BB79265DB904B9BA3EEBDFC6D5
            SHA-256:BD8B05A9FF51D6D00F3F92BF563E7758A48E0C44D655A089213089F91CB44F89
            SHA-512:07B62918F013282A452940D0EB1EFE2E80DD151C8AD42448C6242EA8FC6110FF562DCFB4588095A1920C5B3C2FF2BA1201F9F269852B3CCCC5B5721FDB39652E
            Malicious:false
            Reputation:low
            Preview:export * from './swiper.module';.export * from './swiper.component';.export * from './swiper-slide.directive';.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, Unicode text, UTF-8 text
            Category:dropped
            Size (bytes):951
            Entropy (8bit):4.764079126916585
            Encrypted:false
            SSDEEP:24:9DX7jvuM6kf8KUUuBFLDGkz7F8DfKbkFIS7lL4hZezUZkKsyoVsRUN:9DX3Gcf8KnWjOrKLS5SeIkwq
            MD5:074E29FE802D44C652AEC7A7AC624C75
            SHA1:CDF414D1FE4DA010BEA78340E6BF752AB9CF082C
            SHA-256:05AD76F2B3EC4D94C882BAC662BEE1161DA06F58194142E27F50CE1E63990DF0
            SHA-512:07717F3A673A9E24752521B3F5208930B9F5DB85E4CD385CE051E0B0788D4DF08F26748FE6A2A050DE75FC5FB1358942A61B199FF3B17D5099EDA7E8E7B36F0E
            Malicious:false
            Reputation:low
            Preview:import { TemplateRef } from '@angular/core';.import * as i0 from "@angular/core";.export declare class SwiperSlideDirective {. template: TemplateRef<any>;. virtualIndex: number;. class: string;. autoplayDelay: string | null;. set zoom(val: boolean);. get zoom(): boolean;. private _zoom;. slideIndex: number;. get classNames(): string;. set classNames(val: string);. private _hasClass;. slideData: {. isActive: boolean;. isPrev: boolean;. isNext: boolean;. isVisible: boolean;. isDuplicate: boolean;. };. private _classNames;. constructor(template: TemplateRef<any>);. static .fac: i0...FactoryDeclaration<SwiperSlideDirective, never>;. static .dir: i0...DirectiveDeclaration<SwiperSlideDirective, "ng-template[swiperSlide]", never, { "virtualIndex": "virtualIndex"; "class": "class"; "autoplayDelay": "data-swiper-autoplay"; "zoom": "zoom"; }, {}, never>;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, Unicode text, UTF-8 text, with very long lines (6871)
            Category:dropped
            Size (bytes):20201
            Entropy (8bit):4.975275214786833
            Encrypted:false
            SSDEEP:384:XFyO4jyDgKEI6lZEcywMT61LNAFkW6aYKCpa+NcS7kS71GZnBY8k174iEZn:8byp6lZEcyv61JALY7pa+NcS7kS71GZF
            MD5:A19DEE5A88A2B96D1A03C2D2E0EA413B
            SHA1:6DC005743196BE63CE4A193A7256CA2497D2C9BF
            SHA-256:75561A78365260F047CFA0879BFEFC462E20E047D85DB4FF278DAD06E2ACBFF0
            SHA-512:39235379AB7E56EB6C81E7EFCDCFDD51F96DADE8B9721BEFB0CE76C21AB1ECB0D099A9C05F156C2C9FFC7A3A44E34EC4B4A3C70DF8D7BC922676D73768CD7672
            Malicious:false
            Reputation:low
            Preview:import { ChangeDetectorRef, ElementRef, EventEmitter, NgZone, OnInit, QueryList, SimpleChanges } from '@angular/core';.import Swiper from 'swiper';.import { Observable, Subject } from 'rxjs';.import { SwiperSlideDirective } from './swiper-slide.directive';.import { SwiperOptions, SwiperEvents, NavigationOptions, PaginationOptions, ScrollbarOptions, VirtualOptions } from 'swiper/types';.import * as i0 from "@angular/core";.export declare class SwiperComponent implements OnInit {. private _ngZone;. private elementRef;. private _changeDetectorRef;. private _platformId;. enabled: SwiperOptions['enabled'];. direction: SwiperOptions['direction'];. touchEventsTarget: SwiperOptions['touchEventsTarget'];. initialSlide: SwiperOptions['initialSlide'];. speed: SwiperOptions['speed'];. cssMode: SwiperOptions['cssMode'];. updateOnWindowResize: SwiperOptions['updateOnWindowResize'];. resizeObserver: SwiperOptions['resizeObserver'];. nested: SwiperOptions['nested
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, Unicode text, UTF-8 text
            Category:dropped
            Size (bytes):538
            Entropy (8bit):4.939167563431772
            Encrypted:false
            SSDEEP:12:CN55ONzjNCV57oONR+pv2cTjEhNIf0mNjJaSj0aaSCjf93NK:C75Ota+O6pvp4hecmV89pBk
            MD5:135B9E1D174E93DAD57F6C815470575E
            SHA1:00482C0D438445AF7914D452B72FE78A9C6C3E07
            SHA-256:5648AA2CCCBBFAB3649000F3ACB426B1F896047A2AA1BCCDB8EAF5CD9E8F8119
            SHA-512:AAF0E18CF056C5CD10650DA473AFEC98C221D11C9F0C7A86FBBECEB6F3A2A0D03CDD806D6811D42A6E8207317B87C0173B4FD2909754EE2B771A5DAD8C965D65
            Malicious:false
            Reputation:low
            Preview:import * as i0 from "@angular/core";.import * as i1 from "./swiper.component";.import * as i2 from "./swiper-slide.directive";.import * as i3 from "@angular/common";.export declare class SwiperModule {. static .fac: i0...FactoryDeclaration<SwiperModule, never>;. static .mod: i0...NgModuleDeclaration<SwiperModule, [typeof i1.SwiperComponent, typeof i2.SwiperSlideDirective], [typeof i3.CommonModule], [typeof i1.SwiperComponent, typeof i2.SwiperSlideDirective]>;. static .inj: i0...InjectorDeclaration<SwiperModule>;.}.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):152
            Entropy (8bit):4.421925379417138
            Encrypted:false
            SSDEEP:3:4i7AbQ+FmAB1+ErfwOAaB7AbQPXN4EZlfoevF/mhWeV/H6AfmXA1ow:4iQ3DP+aB3lfpehhdDmQ+w
            MD5:DF0B73D27DE7A349700A9FDF92D16C37
            SHA1:9BA003C5A152DE83B82D8CCFF574B0A6DB5ED4FA
            SHA-256:833C3F91DC3242215BD48F440D8E07C250458CF9C7025C90DD828E5459E40CE6
            SHA-512:160F5AD433AAA81209D20F5B80940332D76F8A7E1B734821BB26A8C4B72DABB2D839F47157AE1B1180F43AA4524360431DB1B910CDC347732A9609D1AAB53E07
            Malicious:false
            Reputation:low
            Preview:export declare const allowedParams: string[];.export declare function getParams(obj?: any): {. params: any;. passedParams: any;. rest: any;.};.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):43
            Entropy (8bit):4.228363010415425
            Encrypted:false
            SSDEEP:3:4i7AbQ+FuUIWpMWYXMhn:4iQuUIuz
            MD5:6C002719C5548EE91E7604B6A7A623BF
            SHA1:497775F26BBC1E512B59B452CBCE71DA361714CC
            SHA-256:B24AA5F6910FDFEFC5FCF4351A6358FA7E5A3FEDB84282AEBC0A38C194F483DC
            SHA-512:5B60FE2038F1479C12FF8A16C090F94BF18A85BCCFC50D7AA820BB2B10F8DF77F976EF816052B0039770093946610EBC18FBF350E4C206D5538F03BFFD59ABD2
            Malicious:false
            Reputation:low
            Preview:export declare const paramsList: string[];.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):371
            Entropy (8bit):4.642343327319834
            Encrypted:false
            SSDEEP:6:4iqpOoy7jpOWi4u3XRgBEqKrJ0g1apOQwTMCzFIaBWgflhfY5ow:4iqwoyvw74eXRiEqoagcwMCz+aBWg9bw
            MD5:CE3CD60691C1903E82AD584EAD72AA54
            SHA1:22CC6CC43FF081C7804894EE3D40EBC36E3B4AEE
            SHA-256:D811B2A7D1FA926BAD510C0669FFC8CBB553D3AF2C746F1AB92A81F4D66E06EC
            SHA-512:C8C62E507E1F230725CCAAEFA326B99DF821D25EFD40116CFB2429E0C01CC688FD3527C1A60033B3FD49D5AF0915FD9995CAFD92299CA0B49592BE3E7BCAC9BF
            Malicious:false
            Reputation:low
            Preview:export declare function isObject(o: any): boolean;.export declare function isShowEl(val: any, obj: any, el: any): boolean;.export declare function extend(target: any, src: any): void;.export declare function coerceBooleanProperty(value: any): boolean;.export declare const ignoreNgOnChanges: string[];.export declare function setProperty(val: any, obj?: {}): {} | false;.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Unicode text, UTF-8 text, with very long lines (9303)
            Category:dropped
            Size (bytes):87464
            Entropy (8bit):4.331051421501726
            Encrypted:false
            SSDEEP:1536:epwLkjpi7yTcFukXSXLz6X9XjX5XuXUXPXXXbXHXJXGXbQvXUcNLfx/gy4G/kOYg:LLn0zhQsUTT/cLU9ILD0D6guc/99Ix+R
            MD5:3030CAFD4702854131CE5F85286ED567
            SHA1:C273B0A4C7EE3D795C67C77FACFF1B403469DA28
            SHA-256:B6888318FC76B321ADF7E23FDE293BA349BCA74A503CA2218911462235F498B4
            SHA-512:59816B4767AA8466439C9CA5B1E03FCC4DBA268AAC23BFAF35BF1D7110AB2A3A50E4A43F3011EFFC17EF70FED365834490744E8ADC3D634B1FC7A2F524E2BC6B
            Malicious:false
            Reputation:low
            Preview:(function (global, factory) {. typeof exports === 'object' && typeof module !== 'undefined' ? factory(exports, require('@angular/core'), require('@angular/common'), require('swiper'), require('rxjs')) :. typeof define === 'function' && define.amd ? define('swiper_angular', ['exports', '@angular/core', '@angular/common', 'swiper', 'rxjs'], factory) :. (global = typeof globalThis !== 'undefined' ? globalThis : global || self, factory(global.swiper_angular = {}, global.ng.core, global.ng.common, global.Swiper, global.rxjs));.}(this, (function (exports, i0, i1, Swiper, rxjs) { 'use strict';.. function _interopDefaultLegacy (e) { return e && typeof e === 'object' && 'default' in e ? e : { 'default': e }; }.. function _interopNamespace(e) {. if (e && e.__esModule) return e;. var n = Object.create(null);. if (e) {. Object.keys(e).forEach(function (k) {. if (k !== 'default') {. var d = Object.getOwnPropertyDescrip
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):104355
            Entropy (8bit):5.102406241297126
            Encrypted:false
            SSDEEP:1536:HhUvbxxIySBsu1ym6WZncagXRmbe23noZYwWgqEDFt:HhXRZ9gXRmbfHYD
            MD5:AC811A2BB40FA4236B11209FF19BC3B0
            SHA1:5CBC7709DFFC07F9E66F33B78A8F2814DAE650D5
            SHA-256:DF8B808C1B1FC50222403828E56B10910DA05D2ACEC1F13CEC3F35AD1AAD8E57
            SHA-512:717638D1DEC7BD8A1E1A04D9D00742A9CC43857079F210E07AB5E7E45217577D46223CE7759CB6AE13472039EB6701C48E4BAA4A0722C7D4C4104F3D0574587B
            Malicious:false
            Reputation:low
            Preview:{"version":3,"file":"swiper_angular.umd.js","sources":["../../../node_modules/tslib/tslib.es6.js","../../../src/angular/src/utils/utils.ts","../../../src/angular/src/utils/params-list.ts","../../../src/angular/src/utils/get-params.ts","../../../src/angular/src/swiper-slide.directive.ts","../../../src/angular/src/swiper.component.ts","../../../src/angular/src/swiper.component.html","../../../src/angular/src/swiper.module.ts","../../../src/angular/src/public-api.ts","../../../src/swiper_angular.ts"],"sourcesContent":["/*! *****************************************************************************\r\nCopyright (c) Microsoft Corporation.\r\n\r\nPermission to use, copy, modify, and/or distribute this software for any\r\npurpose with or without fee is hereby granted.\r\n\r\nTHE SOFTWARE IS PROVIDED \"AS IS\" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH\r\nREGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY\r\nAND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR A
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (574)
            Category:dropped
            Size (bytes):725
            Entropy (8bit):5.868189755357018
            Encrypted:false
            SSDEEP:12:UAU2FGjBP1aQP1qP1y5XstnKpSMGRM6g8g8g8q63DOdG0HrcOLFGhTL0s/sh7/xf:t0jBPVPcPwKKpEwDDQC5LVS0iBr49dn
            MD5:58696E457C2A2C24ADAA9A3C778F00D0
            SHA1:18776A5056E5BE38FCF16CD26DE9DE4E783E8B1F
            SHA-256:549A543889F2012613879D6DA8727418E66314C2682221439699D43358FB473F
            SHA-512:B3284967BDA8C1CFF0BAC719905D883269DB776C6270A313CB89C6B926E35CA19ED46EDAA186141004FD409E6EB69F450C26192715AC95A842BF0E0E61FDE12E
            Malicious:false
            Reputation:low
            Preview:/*. * Public API Surface of angular. */.export * from './swiper.module';.export * from './swiper.component';.export * from './swiper-slide.directive';.//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoicHVibGljLWFwaS5qcyIsInNvdXJjZVJvb3QiOiIiLCJzb3VyY2VzIjpbIi4uLy4uLy4uLy4uLy4uL3NyYy9hbmd1bGFyL3NyYy9wdWJsaWMtYXBpLnRzIl0sIm5hbWVzIjpbXSwibWFwcGluZ3MiOiJBQUFBOztHQUVHO0FBQ0gsY0FBYyxpQkFBaUIsQ0FBQztBQUNoQyxjQUFjLG9CQUFvQixDQUFDO0FBQ25DLGNBQWMsMEJBQTBCLENBQUMiLCJzb3VyY2VzQ29udGVudCI6WyIvKlxuICogUHVibGljIEFQSSBTdXJmYWNlIG9mIGFuZ3VsYXJcbiAqL1xuZXhwb3J0ICogZnJvbSAnLi9zd2lwZXIubW9kdWxlJztcbmV4cG9ydCAqIGZyb20gJy4vc3dpcGVyLmNvbXBvbmVudCc7XG5leHBvcnQgKiBmcm9tICcuL3N3aXBlci1zbGlkZS5kaXJlY3RpdmUnO1xuIl19
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, Unicode text, UTF-8 text, with very long lines (4138)
            Category:dropped
            Size (bytes):6686
            Entropy (8bit):5.781975512369315
            Encrypted:false
            SSDEEP:192:XEG0uqQZfNUF13+ERIu+q/Fe/s5aOveda:XY+j00M
            MD5:202A710A84FBE72EA097B6D8D035EE08
            SHA1:5B7C4F4D343AEE177722A0F50F9EF94EA096B5ED
            SHA-256:66A0722D06BF446C69D8C1FAB6BA7089E322FF982B77C033DD26823FF329BC49
            SHA-512:098E42ED02CC98526534D73A07DED62AC343FC629CEDC4E25B69D61763C6D489A4BFE235A502349A4317739F623AFF9E7BF97C23183EC262061B37347A0578AD
            Malicious:false
            Reputation:low
            Preview:import { Directive, Input } from '@angular/core';.import { coerceBooleanProperty } from './utils/utils';.import * as i0 from "@angular/core";.export class SwiperSlideDirective {. constructor(template) {. this.template = template;. this.class = '';. this.autoplayDelay = null;. this.slideData = {. isActive: false,. isPrev: false,. isNext: false,. isVisible: false,. isDuplicate: false,. };. }. set zoom(val) {. this._zoom = coerceBooleanProperty(val);. }. get zoom() {. return this._zoom;. }. get classNames() {. return this._classNames;. }. set classNames(val) {. if (this._classNames === val) {. return;. }. this._classNames = val;. this.slideData = {. isActive: this._hasClass(['swiper-slide-active', 'swiper-slide-duplicate-active']),. isVisible: this._hasClass(['swiper-slide-visible']),.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, Unicode text, UTF-8 text, with very long lines (13533)
            Category:dropped
            Size (bytes):137061
            Entropy (8bit):5.73313546980264
            Encrypted:false
            SSDEEP:3072:RaBC2dV0/cN6a4CluGv+5/8SmKZsKChOp:RaBC2dV0/qU8SmKZqO
            MD5:1D76934F4F247C977AE731F6E4850B54
            SHA1:E1031794673A37F6143D3373D9C267E04639B8EA
            SHA-256:87C401F2984D12977BB392824619EDD13F53E498DEBFAB6412746EE2CEAAA54F
            SHA-512:F54C11CB45338251F42D3BECBF79A2AE08E426C966D467B5DEBE14D3209B1CA31A8382C78A4061EBE9613294E71404CF5846E63D6C93046E8350D0F9F4632967
            Malicious:false
            Reputation:low
            Preview:import { ChangeDetectionStrategy, Component, ContentChildren, EventEmitter, HostBinding, Inject, Input, Output, PLATFORM_ID, ViewChild, ViewEncapsulation, } from '@angular/core';.// @ts-ignore.import Swiper from 'swiper';.import { of, Subject } from 'rxjs';.import { getParams } from './utils/get-params';.import { SwiperSlideDirective } from './swiper-slide.directive';.import { extend, isObject, setProperty, ignoreNgOnChanges, coerceBooleanProperty, isShowEl, } from './utils/utils';.import { isPlatformBrowser } from '@angular/common';.import * as i0 from "@angular/core";.import * as i1 from "@angular/common";.export class SwiperComponent {. constructor(_ngZone, elementRef, _changeDetectorRef, _platformId) {. this._ngZone = _ngZone;. this.elementRef = elementRef;. this._changeDetectorRef = _changeDetectorRef;. this._platformId = _platformId;. this.slideClass = 'swiper-slide';. this.wrapperClass = 'swiper-wrapper';. this.showNavigation =
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, Unicode text, UTF-8 text, with very long lines (1414)
            Category:dropped
            Size (bytes):2668
            Entropy (8bit):5.823871236745468
            Encrypted:false
            SSDEEP:48:ryG7jAc3pcNczHsTnczXcphjDOdKmAzq3zE+eUV4r1c/S6enNBI:ryG7jL3pcNczHEncDcjDHwVg1caTTI
            MD5:9E83EFA5320256FF492F73638AD88644
            SHA1:9BDAFF824EA285657FFEA0BC52FD9F1C3DF32AEC
            SHA-256:259B08E434C037C5F1514957895050DA4A4E5B519987FDB12016503F7F0263F1
            SHA-512:DEC98964BCE374ED8FC25C52FC3ADA36AA4FC6D825991EE57D1CFD4BD2920C7360F280A6CA1BA3E3DE2D37B1AFD0242B77E034E164F221129D554CD0C952A792
            Malicious:false
            Reputation:low
            Preview:import { NgModule } from '@angular/core';.import { CommonModule } from '@angular/common';.import { SwiperComponent } from './swiper.component';.import { SwiperSlideDirective } from './swiper-slide.directive';.import * as i0 from "@angular/core";.export class SwiperModule {.}.SwiperModule..fac = i0...ngDeclareFactory({ minVersion: "12.0.0", version: "12.2.2", ngImport: i0, type: SwiperModule, deps: [], target: i0...FactoryTarget.NgModule });.SwiperModule..mod = i0...ngDeclareNgModule({ minVersion: "12.0.0", version: "12.2.2", ngImport: i0, type: SwiperModule, declarations: [SwiperComponent, SwiperSlideDirective], imports: [CommonModule], exports: [SwiperComponent, SwiperSlideDirective] });.SwiperModule..inj = i0...ngDeclareInjector({ minVersion: "12.0.0", version: "12.2.2", ngImport: i0, type: SwiperModule, imports: [[CommonModule]] });.i0...ngDeclareClassMetadata({ minVersion: "12.0.0", version: "12.2.2", ngImport: i0, type: SwiperModule, decorators: [{. type: N
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text, with very long lines (3538)
            Category:dropped
            Size (bytes):4697
            Entropy (8bit):5.750021517807863
            Encrypted:false
            SSDEEP:96:EhT8fqmsQ6BBIHHzzySyFpSifW9XvAsEhiDuHj0fyibJH0Gzh2DxFzHbc:ytNtBBIHTzySyFpSi2XIo6IfyibJUGSQ
            MD5:236728C6A3F0BE367D2A5C5A298AD27E
            SHA1:8127BEB68AA485F5789C7C31EFA5B1B646CC9BE1
            SHA-256:653F3B307C26989B4AF6638CAE05F5C71B39C024B16666D498B3501FF2EA7E19
            SHA-512:7C058F9CD2E75A0B2D798DCDEBA9B69E90EEE147CC0B3E00885B168DC6B04546381E8998DDFF00E739DBCD0A9CF8D38BBAFDB034502B88AC84B132F81024B0DE
            Malicious:false
            Reputation:low
            Preview:// eslint-disable-next-line.import { isObject, extend } from './utils';.import { paramsList } from './params-list';.// @ts-ignore.import Swiper from 'swiper';.export const allowedParams = paramsList.map((key) => key.replace(/_/, ''));.export function getParams(obj = {}) {. const params = {. on: {},. };. const passedParams = {};. extend(params, Swiper.defaults);. extend(params, Swiper.extendedDefaults);. params._emitClasses = true;. const rest = {};. Object.keys(obj).forEach((key) => {. const _key = key.replace(/^_/, '');. if (typeof obj[_key] === 'undefined'). return;. if (allowedParams.indexOf(_key) >= 0) {. if (isObject(obj[_key])) {. params[_key] = {};. passedParams[_key] = {};. extend(params[_key], obj[_key]);. extend(passedParams[_key], obj[_key]);. }. else {. params[_key] = obj[_key];. passedParam
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (5226)
            Category:dropped
            Size (bytes):7712
            Entropy (8bit):5.7523700713772365
            Encrypted:false
            SSDEEP:192:ktBmtlALJ9A13swXJJWb8+cayHkirQe2/crr9paGKjSXcDZ+:ktBmtlAFG3XJJHkirQe2Err9paGKjSXz
            MD5:F73D912DF47C64A7A841179AFC04575B
            SHA1:F283337D9BFE4C96FB5AD89CEEF8B8D01CB56692
            SHA-256:9AF34BF3A3629C29058A534DEB34892D7CD96B5E298B7FBA9EF3A9C68DFD0F60
            SHA-512:AF6B3ED6C8CF200276DC11E63FE6D57F7C7F53E2E8B767AB57329F7FB832791A9DE34DD2367561776AA7B97CAE590C54DD8113733EA95802E9D1993B8A094961
            Malicious:false
            Reputation:low
            Preview:/* underscore in name -> watch for changes */.export const paramsList = [. 'init',. 'enabled',. '_direction',. 'touchEventsTarget',. 'initialSlide',. '_speed',. 'cssMode',. 'updateOnWindowResize',. 'resizeObserver',. 'nested',. 'focusableElements',. '_width',. '_height',. 'preventInteractionOnTransition',. 'userAgent',. 'url',. '_edgeSwipeDetection',. '_edgeSwipeThreshold',. '_freeMode',. '_autoHeight',. 'setWrapperSize',. 'virtualTranslate',. '_effect',. 'breakpoints',. '_spaceBetween',. '_slidesPerView',. '_grid',. '_slidesPerGroup',. '_slidesPerGroupSkip',. '_centeredSlides',. '_centeredSlidesBounds',. '_slidesOffsetBefore',. '_slidesOffsetAfter',. 'normalizeSlideIndex',. '_centerInsufficientSlides',. '_watchOverflow',. 'roundLengths',. 'touchRatio',. 'touchAngle',. 'simulateTouch',. '_shortSwipes',. '_longSwipes',. 'longSwipesRatio',. 'longSwipesMs',.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (4858)
            Category:dropped
            Size (bytes):6438
            Entropy (8bit):5.787891444033149
            Encrypted:false
            SSDEEP:192:oZnaRbac+QCNa+fb4+pgWDVQQrOrN6vj/zN9kECP:VX+1Y+U+WxQ/TkEy
            MD5:E0FEC801B9C6987FE18232ED8B659678
            SHA1:FA604DE98F5600FDA60A7047933EBE5F1D383F16
            SHA-256:BC135BF1E0367978587033EDB4A6DA6737D804B6510330EE3C6D832834B2AA26
            SHA-512:7F2A2ACC611DC0D617397130EC6CE8FC334ED86600FEE7209FA51C6E6BE81C7A750EC3EBA3FABB1F728408F1DF9458F340F89434DFC9754DE2BA0A034C76F27B
            Malicious:false
            Reputation:low
            Preview:export function isObject(o) {. return (typeof o === 'object' &&. o !== null &&. o.constructor &&. Object.prototype.toString.call(o).slice(8, -1) === 'Object');.}.export function isShowEl(val, obj, el) {. return ((coerceBooleanProperty(val) === true && obj && !obj.el) ||. !(typeof obj !== 'boolean' &&. obj.el !== (el === null || el === void 0 ? void 0 : el.nativeElement) &&. (typeof obj.el === 'string' || typeof obj.el === 'object')));.}.export function extend(target, src) {. const noExtend = ['__proto__', 'constructor', 'prototype'];. Object.keys(src). .filter((key) => noExtend.indexOf(key) < 0). .forEach((key) => {. if (typeof target[key] === 'undefined') {. target[key] = src[key];. return;. }. if (target[key] && !src[key]) {. return;. }. if (isObject(src[key]) && isObject(target[key]) && Object.keys(src[key]).length > 0) {. if (src
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (334)
            Category:dropped
            Size (bytes):376
            Entropy (8bit):5.731718358988259
            Encrypted:false
            SSDEEP:6:4iP1yT/ug5msthFzKEsWHrwGWkFt3ffQQvYsWSGO2RWQ8pze96cYjDY4Gno3o:4iP1yT2ggstnKKcGx/ROPwzVcr4oo4
            MD5:13F33AFBDD17124E8DC367CC17A864C2
            SHA1:34D675E9003C16EC22BBE59633EF428ED3CBF513
            SHA-256:E65F1E7D3E8364D523E3ABB55A0C6B99FDFE9766D290015529A3EB5074FAB8E9
            SHA-512:84F5432C7E8C2AD38ED76C7243B4299BF55CD5C454F0253AE0FA851C125372098C2B6383C6DF0FB39E5436DCF71FDC24BBC3995C9959F5F4831B3C1E0E853AE2
            Malicious:false
            Reputation:low
            Preview:export * from './angular/src/public-api';.//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoic3dpcGVyLWFuZ3VsYXIuanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi8uLi8uLi9zcmMvc3dpcGVyLWFuZ3VsYXIudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IkFBQUEsY0FBYywwQkFBMEIsQ0FBQyIsInNvdXJjZXNDb250ZW50IjpbImV4cG9ydCAqIGZyb20gJy4vYW5ndWxhci9zcmMvcHVibGljLWFwaSc7XG4iXX0=
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (410)
            Category:dropped
            Size (bytes):492
            Entropy (8bit):5.799869577858748
            Encrypted:false
            SSDEEP:12:UvmJe1P15KNstnKRHcGx/RFPP2ZTqVoDmHTv:wmJMP7KxbeoVoD8
            MD5:B54C1862F9DBCA4C61124DAA66C79722
            SHA1:47C42AF83A4265D720249D8DCCE76089C62F9F6C
            SHA-256:76121E2A278E7740944EAD046DF81056F3FAB202365B6DEE1A1B61D1F829D44D
            SHA-512:256C65BF9578F3350D8A55F252028B9D284E137D6104CC64674849E356FEBE768987AF1B21AB1209D673D8A4A7CA6B2CFAC2446906EFE91905800FB1848CA545
            Malicious:false
            Reputation:low
            Preview:/**. * Generated bundle index. Do not edit.. */.export * from './swiper-angular';.//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoic3dpcGVyX2FuZ3VsYXIuanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi8uLi8uLi9zcmMvc3dpcGVyX2FuZ3VsYXIudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IkFBQUE7O0dBRUc7QUFFSCxjQUFjLGtCQUFrQixDQUFDIiwic291cmNlc0NvbnRlbnQiOlsiLyoqXG4gKiBHZW5lcmF0ZWQgYnVuZGxlIGluZGV4LiBEbyBub3QgZWRpdC5cbiAqL1xuXG5leHBvcnQgKiBmcm9tICcuL3N3aXBlci1hbmd1bGFyJztcbiJdfQ==
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C++ source, Unicode text, UTF-8 text, with very long lines (10063)
            Category:dropped
            Size (bytes):60422
            Entropy (8bit):4.499684780069089
            Encrypted:false
            SSDEEP:768:b7bNJslAFWaTRPwP2jHpVJugIl40X/kOOP/rvvbnRJew/uw:rsleWaBC2dVJugy4G/kOYPWw/uw
            MD5:C6A08A6A4E24CEC29A31C7CD6C01AD3E
            SHA1:216BF6A6F9A70C9E06F06EEB5B5333B470AA2045
            SHA-256:C1114D0199387CD5C239AED96137DB9BD1A95C3E157DB7905240CACFDC006475
            SHA-512:1574612E196817F5A1094A05AB83A519BC13E21BD2B95FB295A62F6731820924D4CEE469B06C6F744C653A89B20DA50ACF5B00749C897C834EAB4D4478A3907A
            Malicious:false
            Reputation:low
            Preview:import * as i0 from '@angular/core';.import { Directive, Input, EventEmitter, PLATFORM_ID, Component, ChangeDetectionStrategy, ViewEncapsulation, Inject, Output, ViewChild, ContentChildren, HostBinding, NgModule } from '@angular/core';.import * as i1 from '@angular/common';.import { isPlatformBrowser, CommonModule } from '@angular/common';.import Swiper from 'swiper';.import { Subject, of } from 'rxjs';..function isObject(o) {. return (typeof o === 'object' &&. o !== null &&. o.constructor &&. Object.prototype.toString.call(o).slice(8, -1) === 'Object');.}.function isShowEl(val, obj, el) {. return ((coerceBooleanProperty(val) === true && obj && !obj.el) ||. !(typeof obj !== 'boolean' &&. obj.el !== (el === null || el === void 0 ? void 0 : el.nativeElement) &&. (typeof obj.el === 'string' || typeof obj.el === 'object')));.}.function extend(target, src) {. const noExtend = ['__proto__', 'constructor', 'prototype'];. Object.key
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):74959
            Entropy (8bit):5.186809876541305
            Encrypted:false
            SSDEEP:1536:ISBsu1ym6WZncagXRmbeAAurBCbzpX0f/9K:PRZ9gXRmbzczpXEU
            MD5:8FBC7DC3B71FEAEECFCB383CFD90F8EC
            SHA1:780114EF3CE7A52129397AC203B454D732B63A27
            SHA-256:64CCC477FFAAD9471EE3CBA080462A62A777BC8259CEDB14781EDF8CE353DD0D
            SHA-512:7EAF517A920E5CCD5935B12D234BC3A67C41832E091CAF7BD82FE9D84C0937F195369975692C580C21FE1F682239D254D605364C7DFAD0945E6D2D540CA9F76B
            Malicious:false
            Reputation:low
            Preview:{"version":3,"file":"swiper_angular.js","sources":["../../../src/angular/src/utils/utils.ts","../../../src/angular/src/utils/params-list.ts","../../../src/angular/src/utils/get-params.ts","../../../src/angular/src/swiper-slide.directive.ts","../../../src/angular/src/swiper.component.ts","../../../src/angular/src/swiper.component.html","../../../src/angular/src/swiper.module.ts","../../../src/angular/src/public-api.ts","../../../src/swiper_angular.ts"],"sourcesContent":["export function isObject(o: any): boolean {\n return (\n typeof o === 'object' &&\n o !== null &&\n o.constructor &&\n Object.prototype.toString.call(o).slice(8, -1) === 'Object'\n );\n}\n\nexport function isShowEl(val: any, obj: any, el: any): boolean {\n return (\n (coerceBooleanProperty(val) === true && obj && !obj.el) ||\n !(\n typeof obj !== 'boolean' &&\n obj.el !== el?.nativeElement &&\n (typeof obj.el === 'string' || typeof obj.el === 'object')\n )\n );\n}\n\nexport functi
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):487
            Entropy (8bit):4.7377891062738335
            Encrypted:false
            SSDEEP:12:9Tc1vFjyFD0FYsa4Sse+0nG7H6GWFHGGKFH6GpTgc4:lc1vFjyFwFDB0nGD6GEGGY6GJgb
            MD5:0A99E8192639F8A8F034478DCA441868
            SHA1:92847E3488B2E3C2343C5DEC0F461BABE816D73E
            SHA-256:4B1F3A1F93653F97663B020ED7E96E51BEA2ACD101852FFCD1F25259956C287C
            SHA-512:C8CC5883D4541910B42CFED74EA54A60C2E71816EA0ABE257B76F2FFF8B44D9FAF5768D00BF696864FAD77CF27888E5296EB28042568EE1106CC1A889E402BCF
            Malicious:false
            Reputation:low
            Preview:{. "name": "swiper_angular",. "version": "0.0.1",. "private": "true",. "peerDependencies": {. "@angular/common": "^12.2.0",. "@angular/core": "^12.2.0". },. "dependencies": {. "tslib": "^2.3.0". },. "main": "bundles/swiper_angular.umd.js",. "module": "fesm2015/swiper_angular.js",. "es2015": "fesm2015/swiper_angular.js",. "esm2015": "esm2015/swiper_angular.js",. "fesm2015": "fesm2015/swiper_angular.js",. "typings": "swiper_angular.d.ts",. "sideEffects": false.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):42
            Entropy (8bit):4.463280517810811
            Encrypted:false
            SSDEEP:3:4i1F3F0LTJx9Dwn:4iP1yT/un
            MD5:F37CC4A3B568BCFD69BCF475765DFA97
            SHA1:8729D74200028C4668CF91329856BEFAF9174207
            SHA-256:C5983E8BE79DBDA976AA76177717DB919F15C0B72662E1842CE347A8E2281FAB
            SHA-512:FAA3AB65E86A4751078F747F7CB352D3283410DFB54678AD3511CF36F94C188DE263FFE4D881E7879E0CEDDBE6860ECA03027695FEBD6B867B6CC799077DBEAE
            Malicious:false
            Reputation:low
            Preview:export * from './angular/src/public-api';.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):123
            Entropy (8bit):4.635106977181566
            Encrypted:false
            SSDEEP:3:UV93AXE29QLBOg4KF+ZSUFj+3BxC9YHrvLF74gB1F3Fm/pE3Kd:UvmycneTcj6BU9YLTiiP15Kd
            MD5:8973293A14E916DDF51DF9C357735E69
            SHA1:CF1A5D6D98806F241123CB33637E244FF824E6A2
            SHA-256:8C59802B6663F54E56F60E50B0400DD8ECB352069BAD4C20062445B3C89C86DE
            SHA-512:9C9AE66B005AB935455053F9E4B4FEF65BCBFBE22F523788C18DD27C5804AF15CBC54C3A3000C7501DC1A7C3021067CDF757C1CE01B8C8EDDF968DFFEC66F405
            Malicious:false
            Reputation:low
            Preview:/**. * Generated bundle index. Do not edit.. */./// <amd-module name="swiper_angular" />.export * from './swiper-angular';.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1113
            Entropy (8bit):4.651842928136367
            Encrypted:false
            SSDEEP:24:2hm7WAKveGPMbJzBeNdkNruX2BYSSzYyaUB:2hmSXMb9BuMSX2BYvYyaUB
            MD5:7D43F48158DED140E0530FBBF64FCE94
            SHA1:D86C72AB1ED51E09EE733A976AE68AC245131D6F
            SHA-256:93D66C6C336AD550321A08518B362BAA910693025FC340A7328754FA350C1577
            SHA-512:C81F86068C1F84EB027D28A74B5BD67926F58D2316C0FC2A08F33F550CB02D69E66D1FA022185DB7DA6AA61944D2FE0E2CEAB46270F5CB1F4C0235763CA3C536
            Malicious:false
            Reputation:low
            Preview:import { getWindow } from 'ssr-window';.export default function getBreakpoint(breakpoints, base = 'window', containerEl) {. if (!breakpoints || base === 'container' && !containerEl) return undefined;. let breakpoint = false;. const window = getWindow();. const currentHeight = base === 'window' ? window.innerHeight : containerEl.clientHeight;. const points = Object.keys(breakpoints).map(point => {. if (typeof point === 'string' && point.indexOf('@') === 0) {. const minRatio = parseFloat(point.substr(1));. const value = currentHeight * minRatio;. return {. value,. point. };. }.. return {. value: point,. point. };. });. points.sort((a, b) => parseInt(a.value, 10) - parseInt(b.value, 10));.. for (let i = 0; i < points.length; i += 1) {. const {. point,. value. } = points[i];.. if (base === 'window') {. if (window.matchMedia(`(min-width: ${value}px)`).matches) {. breakpoint = point;. }. }
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):148
            Entropy (8bit):4.367398686823478
            Encrypted:false
            SSDEEP:3:JS7hhA/geXhA0+oQhhA/0eXhA0yXQ7AYgkds0XhA3/DhhAZ:4hhSzRahhSfR6Q/q0Xhalh2
            MD5:1B804CA2865F846D0EE0C42FAB856132
            SHA1:B699E51D4E217169AFE19F31357F8B634312337C
            SHA-256:5047B7B0B373C98F99A8DDD602E9E80E3109A41FFE49BBA6A2BB5864A2F454A3
            SHA-512:2D3DDAAD10F4D56C1C9B94407080F06DCD330280BBCC4EEDAF99FD5CDF1D481EB8FB641182D5C2E1A6D3A7233C8C4CB5E206E6953B366207F2E9FF2FD92F8628
            Malicious:false
            Reputation:low
            Preview:import setBreakpoint from './setBreakpoint.js';.import getBreakpoint from './getBreakpoint.js';.export default {. setBreakpoint,. getBreakpoint.};
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):2568
            Entropy (8bit):4.866081331855102
            Encrypted:false
            SSDEEP:48:QtzMMs/k0OfT5LHEzTgYXdNowkXQNv0hbm:Qx95T5LHEzTBtNo/ANcY
            MD5:472E47E2555AE0DC287CF3A89A7DA029
            SHA1:4601EB455E088F71FD1A6296B0A94D3EC7C636DC
            SHA-256:111FE2A237F28EA49BCC68E94EC04995CD18D4349C2B81A3F6C4325F91C12F7A
            SHA-512:C78EF899D22F2343B97F58D8BC9DE4816A009E40ED4BE379A6E068D261A3A99B7C0F66E7B6018A2DAA49278298C1A8432A2FDE621AA9D5CCDA1DBAC948262121
            Malicious:false
            Reputation:low
            Preview:import { extend } from '../../shared/utils.js';..const isGridEnabled = (swiper, params) => {. return swiper.grid && params.grid && params.grid.rows > 1;.};..export default function setBreakpoint() {. const swiper = this;. const {. activeIndex,. initialized,. loopedSlides = 0,. params,. $el. } = swiper;. const breakpoints = params.breakpoints;. if (!breakpoints || breakpoints && Object.keys(breakpoints).length === 0) return; // Get breakpoint for window width and update parameters.. const breakpoint = swiper.getBreakpoint(breakpoints, swiper.params.breakpointsBase, swiper.el);. if (!breakpoint || swiper.currentBreakpoint === breakpoint) return;. const breakpointOnlyParams = breakpoint in breakpoints ? breakpoints[breakpoint] : undefined;. const breakpointParams = breakpointOnlyParams || swiper.originalParams;. const wasMultiRow = isGridEnabled(swiper, params);. const isMultiRow = isGridEnabled(swiper, breakpointParams);. const wasEnabled = params.enabled;..
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):895
            Entropy (8bit):4.734964753470903
            Encrypted:false
            SSDEEP:12:AWfstl7lShWQRmMoffGoRA0xCQxCJLWxUgRWCUj4xY49uYAzYA5bOvQ/3:7f87lSUQRifun4vKCO7tcxt9IP
            MD5:B8BE34074692D4155A3FFEC65FC76687
            SHA1:417155ECD37890E657595917F4263C8009FA1FB8
            SHA-256:A9176ECE4582B0AEF620CBC8A9734E7A8C38A64677589FC37A2C88364D23DFBE
            SHA-512:40CB8C7BCCD7AE38F35FF613A2BAB2038D359315FF8DCA96B5DED1011F0B9CC8067692AF474CE16EB9BCE23FE5BD1BBBE8555F1FDE7490D5BCF0FCAE3FA8E44E
            Malicious:false
            Reputation:low
            Preview:function checkOverflow() {. const swiper = this;. const {. isLocked: wasLocked,. params. } = swiper;. const {. slidesOffsetBefore. } = params;.. if (slidesOffsetBefore) {. const lastSlideIndex = swiper.slides.length - 1;. const lastSlideRightEdge = swiper.slidesGrid[lastSlideIndex] + swiper.slidesSizesGrid[lastSlideIndex] + slidesOffsetBefore * 2;. swiper.isLocked = swiper.size > lastSlideRightEdge;. } else {. swiper.isLocked = swiper.snapGrid.length === 1;. }.. if (params.allowSlideNext === true) {. swiper.allowSlideNext = !swiper.isLocked;. }.. if (params.allowSlidePrev === true) {. swiper.allowSlidePrev = !swiper.isLocked;. }.. if (wasLocked && wasLocked !== swiper.isLocked) {. swiper.isEnd = false;. }.. if (wasLocked !== swiper.isLocked) {. swiper.emit(swiper.isLocked ? 'lock' : 'unlock');. }.}..export default {. checkOverflow.};
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1295
            Entropy (8bit):4.685233297839435
            Encrypted:false
            SSDEEP:24:rT1jlRsMK2dXyCFt6pY6MTr1yJJM8X+tBJAJ95bFHkFUUUHYCUx5IDHjUyk:9bsMDXSRyrAJJ3g3k9yqK
            MD5:0B6F6BB20A721F12BD9659E4CF450BF7
            SHA1:9787172FF886F9401261D330FA09ABEA150C0400
            SHA-256:8AD5152DFD2726E233A59CADEEDA87DDF1AAB6CCB40427F23846B7629376C187
            SHA-512:58EDB9658AD37B888AFD8C9F3E56E9C12B64F405C86974D7A1F6F81D01A9A61212BA20C4822C3C3BD380DB6F9A08E8DBB2B5230179D556227394BDF5F90ADDF7
            Malicious:false
            Reputation:low
            Preview:function prepareClasses(entries, prefix) {. const resultClasses = [];. entries.forEach(item => {. if (typeof item === 'object') {. Object.keys(item).forEach(classNames => {. if (item[classNames]) {. resultClasses.push(prefix + classNames);. }. });. } else if (typeof item === 'string') {. resultClasses.push(prefix + item);. }. });. return resultClasses;.}..export default function addClasses() {. const swiper = this;. const {. classNames,. params,. rtl,. $el,. device,. support. } = swiper; // prettier-ignore.. const suffixes = prepareClasses(['initialized', params.direction, {. 'pointer-events': !support.touch. }, {. 'free-mode': swiper.params.freeMode && params.freeMode.enabled. }, {. 'autoheight': params.autoHeight. }, {. 'rtl': rtl. }, {. 'grid': params.grid && params.grid.rows > 1. }, {. 'grid-column': params.grid && params.grid.rows > 1 && params.grid.fill === 'column'. }, {. 'android
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):139
            Entropy (8bit):4.247906679811936
            Encrypted:false
            SSDEEP:3:JSZWAADGBQNWAvvMoU9+ERAADVt9+ERAvvAXQ7AYgkd+CWAAFFXA8+ERAFe:AWWcPqRdVzRMgQ/4CgXAaREe
            MD5:C5485C1D475D5B7A1F68108D9299BE3E
            SHA1:E10565334FCF3E6DE6D13C4495714C40C9FDD047
            SHA-256:58B733D4312FE825F5802F78842FB36757455B1B2A3C95EB4150471C9D638324
            SHA-512:8122C292397601B04883F61BBA9CB5D1CAE29459675556F773F063AA2F8EEE08141D58A07FD66C461F78B630D0311792366F790583F4F2AE33A44653FBCB0079
            Malicious:false
            Reputation:low
            Preview:import addClasses from './addClasses.js';.import removeClasses from './removeClasses.js';.export default {. addClasses,. removeClasses.};
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):188
            Entropy (8bit):4.494119548844177
            Encrypted:false
            SSDEEP:3:4i7AYg5QyXQ3M+ERAXaCVMk3d6w/FKUKWl0vXWdNdFuqVERUH0OWVMMwQYtzQTAQ:4i/mZTRaaCmkt6w/TKWXdg/RYWmHHot
            MD5:C340456F89651C5E2E630EF28172C227
            SHA1:6E78170899B8CA8BB3BEF77CA44588C91B4AB7F7
            SHA-256:16509A7586DB78621D0AD1F519F98204374EC90902681CFC769E35CF748224ED
            SHA-512:D67FE3151A816CAE3B716BCF7732D822DEE3A8133BE21A8E8BFFD98522F988C81D58319715724950432CF8E4A65304BFF8F035C0B0209A30CA0197E4B4169494
            Malicious:false
            Reputation:low
            Preview:export default function removeClasses() {. const swiper = this;. const {. $el,. classNames. } = swiper;. $el.removeClass(classNames.join(' '));. swiper.emitContainerClasses();.}
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:C++ source, ASCII text
            Category:dropped
            Size (bytes):16412
            Entropy (8bit):4.726469379398965
            Encrypted:false
            SSDEEP:192:0qnZuKKa7Dw0Wciip7V1vYSxLlF55f/Bb3lfnofaGyKByanIG0qkONZE85iJ6wcd:0q0la3WciCBYS/dyGT85/wJk
            MD5:2FD63894EAD2831E4820B9DA1E72A7E4
            SHA1:629B6B2B2AACF8540A46930F7080B8D10D6EBEDA
            SHA-256:991C427F3D29379D176A726CC91420240EEFB41C826C8E4E9C9BF90E136A278D
            SHA-512:A0CE7A66F5467CD3C0AFDBB64DD09A4D4792D424E19BBA06C462F77A91BAA3E4462A690AB79E2B206F89F9206804DFDD71B13E813DC328D24A0BC35484F80C06
            Malicious:false
            Reputation:low
            Preview:/* eslint no-param-reassign: "off" */.import { getDocument } from 'ssr-window';.import $ from '../shared/dom.js';.import { extend, now, deleteProps } from '../shared/utils.js';.import { getSupport } from '../shared/get-support.js';.import { getDevice } from '../shared/get-device.js';.import { getBrowser } from '../shared/get-browser.js';.import Resize from './modules/resize/resize.js';.import Observer from './modules/observer/observer.js';.import eventsEmitter from './events-emitter.js';.import update from './update/index.js';.import translate from './translate/index.js';.import transition from './transition/index.js';.import slide from './slide/index.js';.import loop from './loop/index.js';.import grabCursor from './grab-cursor/index.js';.import events from './events/index.js';.import breakpoints from './breakpoints/index.js';.import classes from './classes/index.js';.import images from './images/index.js';.import checkOverflow from './check-overflow/index.js';.import defaults from '.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):3091
            Entropy (8bit):4.762775992742305
            Encrypted:false
            SSDEEP:96:uNKfblM/VQMBUIbotA8Hq9EpfKs9bHJDZ0h6:uNy6/eMBUIbuXKqpCWDJmh6
            MD5:9B7ABEC279FACA399A051DD3E7306D09
            SHA1:563F5E351418B6EC91CFBB206210AFB2D7CA9E9F
            SHA-256:BFBFBEC89590C328370B1F16821E7979C95D38E45C7D082429B254EE56915679
            SHA-512:ED4BE2F8FE569872C8F3DE80FEE8E55760F069A24F922937AC76BCBF977C23DC832B5FDF8D542A8C117054A1ED841466E5A0FF784D2E39FC77D4E933FC256E41
            Malicious:false
            Reputation:low
            Preview:export default {. init: true,. direction: 'horizontal',. touchEventsTarget: 'wrapper',. initialSlide: 0,. speed: 300,. cssMode: false,. updateOnWindowResize: true,. resizeObserver: true,. nested: false,. createElements: false,. enabled: true,. focusableElements: 'input, select, option, textarea, button, video, label',. // Overrides. width: null,. height: null,. //. preventInteractionOnTransition: false,. // ssr. userAgent: null,. url: null,. // To support iOS's swipe-to-go-back gesture (when being used in-app).. edgeSwipeDetection: false,. edgeSwipeThreshold: 20,. // Autoheight. autoHeight: false,. // Set wrapper width. setWrapperSize: false,. // Virtual Translate. virtualTranslate: false,. // Effects. effect: 'slide',. // 'slide' or 'fade' or 'cube' or 'coverflow' or 'flip'. // Breakpoints. breakpoints: undefined,. breakpointsBase: 'window',. // Slides grid. spaceBetween: 0,. slidesPerView: 1,. slidesPerGroup: 1,. slidesPerGroupSkip: 0,. slides
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):2921
            Entropy (8bit):4.511614684283214
            Encrypted:false
            SSDEEP:48:5YvpZ9uocXl9vpZomSmRSYmc8DvpZ9m+uQuipioE6iDLGecmqmvIlLpv3i1tsPAf:5Yv0P9vpjRSRc8DvQ+wip7EhGeF7wlLg
            MD5:16602E7E17A2C0AE9FA68B0CDF342EC5
            SHA1:1DC04B0191EA987289DDCE10EA222914E3B727CD
            SHA-256:6D1E57BD953D21665A506EE66508763BD133A02D4B1F8331B48745738A11FD33
            SHA-512:51460FC3ECFDEFC8049F5C6E050DFE7A1FD6202F1EB30841F75A3F0385EFD06BDC53A6232EE06568864F728F12604AD344DE58865EECC269F7AC369A8C19698C
            Malicious:false
            Reputation:low
            Preview:/* eslint-disable no-underscore-dangle */.export default {. on(events, handler, priority) {. const self = this;. if (typeof handler !== 'function') return self;. const method = priority ? 'unshift' : 'push';. events.split(' ').forEach(event => {. if (!self.eventsListeners[event]) self.eventsListeners[event] = [];. self.eventsListeners[event][method](handler);. });. return self;. },.. once(events, handler, priority) {. const self = this;. if (typeof handler !== 'function') return self;.. function onceHandler(...args) {. self.off(events, onceHandler);.. if (onceHandler.__emitterProxy) {. delete onceHandler.__emitterProxy;. }.. handler.apply(self, args);. }.. onceHandler.__emitterProxy = handler;. return self.on(events, onceHandler, priority);. },.. onAny(handler, priority) {. const self = this;. if (typeof handler !== 'function') return self;. const method = priority ? 'unshift' : 'push';.. if (self
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1096
            Entropy (8bit):4.579182277912634
            Encrypted:false
            SSDEEP:24:QAhQBK0BRGxDzlH/cZAkUrqrlAGXaH0rqrfxXrX4WFFUrvS9:QAhQBK0BRIDzlH/cZjUrqrlAkaH0rqrx
            MD5:8F3F8A7E88F39ABD41CFC020D50FA99C
            SHA1:103FF1B904D7F21457B498B540AC93820A9DF1BC
            SHA-256:3B21C8DA18C7ADA9E6AB51F95EDF7F2B22ABE8A1F3D75A9B6C515B949DE79991
            SHA-512:C152B868B911D5AE6540D653F386F0D76224A2036AC70CBD2C759C277222EFF4E5A36001FFADD43E60CF0362895C9187853339885D18DDCAF7002827930DC098
            Malicious:false
            Reputation:low
            Preview:import { extend } from '../shared/utils.js';.export default function moduleExtendParams(params, allModulesParams) {. return function extendParams(obj = {}) {. const moduleParamName = Object.keys(obj)[0];. const moduleParams = obj[moduleParamName];.. if (typeof moduleParams !== 'object' || moduleParams === null) {. extend(allModulesParams, obj);. return;. }.. if (['navigation', 'pagination', 'scrollbar'].indexOf(moduleParamName) >= 0 && params[moduleParamName] === true) {. params[moduleParamName] = {. auto: true. };. }.. if (!(moduleParamName in params && 'enabled' in moduleParams)) {. extend(allModulesParams, obj);. return;. }.. if (params[moduleParamName] === true) {. params[moduleParamName] = {. enabled: true. };. }.. if (typeof params[moduleParamName] === 'object' && !('enabled' in params[moduleParamName])) {. params[moduleParamName].enabled = true;. }.. if (!params[moduleParamName]) p
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):7336
            Entropy (8bit):4.752890375638503
            Encrypted:false
            SSDEEP:192:PR/eUOy8+MeZwGf6YxVMZwm8D29LZBO1Zt5D5hC58keJE88EV8raAF6YxHMZwEGd:JWHylMeZwGf6YxVMZwm8D29TObt5Fw5V
            MD5:B791D9DA866522452F0564125FE3D4EC
            SHA1:E2CAFCB8A1924BB066C33C2830663406F8D007A9
            SHA-256:2CEEF03D8679220E977C43D4E62B5CF9814C01255BB35FC2776E014AF544B7BC
            SHA-512:D655E5299D7FCCACD3C8FF837904381F7A06F032DCFF8AE7DFF0D290C02C2933DE6C4F70C3DE97A2A9B7D5F3E9530B9DBE8C0374EA735EE0631A49A7F1FA4EA6
            Malicious:false
            Reputation:low
            Preview:{. "_from": "swiper",. "_id": "swiper@7.2.0",. "_inBundle": false,. "_integrity": "sha512-CUL6Nvzcf3fU0b8dHaraYphgBT7l44PY1B6T8b+E12pim4DEcwFZDy/KZoIKrAnn+rfbayCmcksYmSDIP5nDHg==",. "_location": "/swiper",. "_phantomChildren": {},. "_requested": {. "type": "tag",. "registry": true,. "raw": "swiper",. "name": "swiper",. "escapedName": "swiper",. "rawSpec": "",. "saveSpec": null,. "fetchSpec": "latest". },. "_requiredBy": [. "#USER",. "/". ],. "_resolved": "https://registry.npmjs.org/swiper/-/swiper-7.2.0.tgz",. "_shasum": "aae2bb7632798467abd5c1ab3e2441598a70dbd7",. "_spec": "swiper",. "_where": "C:\\Users\\Administrator",. "author": {. "name": "Vladimir Kharlampidi". },. "bugs": {. "url": "https://github.com/nolimits4web/swiper/issues". },. "bundleDependencies": false,. "dependencies": {. "dom7": "^4.0.1",. "ssr-window": "^4.0.1". },. "deprecated": false,. "description": "Most modern mobile touch slider and framework with
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):1235
            Entropy (8bit):5.585083061413934
            Encrypted:false
            SSDEEP:24:h3YolWspIZK5ThLAOIIVdhCFwNIVIHHzvzcev6oGHyGo7gUz/gxU52MLGoH:h3PYspIUKIVdhC8IV+vzcev1GSGOLzI4
            MD5:D6A5F40CA0666D218B6EE44E53244EFA
            SHA1:5FAB7729C79F46EC5633A290282A74581D4B4C17
            SHA-256:2E476111F4B535C8FC643624386F4D4009D5E09B69C3033E2B3F00FEB37DB207
            SHA-512:94ABA39C7C73E3D2BF1544FEEA152E41327D964ABDCDC2DADC05E2024D41F505F798BDAA5DF4567C87765AA776F67C0CA9F616DD45AF40B0C39F21D029976FA5
            Malicious:false
            Reputation:low
            Preview:/* eslint-disable max-len -- for better formatting */.var env = process.env;..var ADBLOCK = is(env.ADBLOCK);.var COLOR = is(env.npm_config_color);.var DISABLE_OPENCOLLECTIVE = is(env.DISABLE_OPENCOLLECTIVE);.var SILENT = ['silent', 'error', 'warn'].indexOf(env.npm_config_loglevel) !== -1;.var OPEN_SOURCE_CONTRIBUTOR = is(env.OPEN_SOURCE_CONTRIBUTOR);..// you could add a PR with an env variable for your CI detection.var CI = [. 'BUILD_NUMBER',. 'CI',. 'CONTINUOUS_INTEGRATION',. 'DRONE',. 'RUN_ID'.].some(function (it) { return is(env[it]); });..var BANNER = '\u001b[35m\u001b[1mLove Swiper? Support Vladimir\'s work by donating or pledging: \u001B[0m\n' +.'\u001b[22m\u001b[39m\u001b[32m> On Patreon https://patreon.com/swiperjs \u001B[0m\n' +.'\u001b[22m\u001b[39m\u001b[32m> On Open Collective https://opencollective.com/swiper';..function is(it) {. return !!it && it !== '0' && it !== 'false';.}..function isBannerRequired() {. return !(ADBLOCK || CI || DISABLE_OPENCOLLECTIVE || SILENT
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (2240)
            Category:dropped
            Size (bytes):18289
            Entropy (8bit):5.231938166064
            Encrypted:false
            SSDEEP:192:stCmUJbiKnectyOJ4PQAUpqWaCxYGsOdbG68FWPgFmFFDEAr5wwvlce7se6toXc2:sBUbecNOPXUpTcGZGAYFmFFEunxlh
            MD5:115DFCA8D0A70CC0FAC0879AE13CC7ED
            SHA1:81998A8B03189FFE4E8F90954008C6A22755EA53
            SHA-256:841B1A16CC360C1ADF26A82F6BF6D02F22BCEC190AFB1876D1B2AB39E82EF6B8
            SHA-512:6E5352B6E4D7007F594065E77D4069D750F66AA45F88AFFCA66014A5B3604EC8CA82EEAE85AD12F19A7E685964FAEB156778CDCF01E091FE72C6F3DEDF205DCA
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..@font-face {. font-family: 'swiper-icons';. src: url('data:application/font-woff;charset=utf-8;base64, d09GRgABAAAAAAZgABAAAAAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAAGRAAAABoAAAAci6qHkUdERUYAAAWgAAAAIwAAACQAYABXR1BPUwAABhQAAAAuAAAANuAY7+xHU1VCAAAFxAAAAFAAAABm2fPczU9TLzIAAAHcAAAASgAAAGBP9V5RY21hcAAAAkQAAACIAAABYt6F0cBjdnQgAAACzAAAAAQAAAAEABEBRGdhc3AAAAWYAAAACAAAAAj//wADZ2x5ZgAAAywAAADMAAAD2MHtryVoZWFkAAABbAAAADAAAAA2E2+eoWhoZWEAAAGcAAAAHwAAACQC9gDzaG10eAAAAigAAAAZAAAArgJkABFsb2NhAAAC0AAAAFoAAABaFQAUGG1heHAAAAG8AAAAHwAAACAAcABAbmFtZQAAA/gAAAE5AAACXvFdBwlwb3N0AAAFNAAAAGIAAACE5s74hXjaY2BkYGAAYpf5Hu/j+W2+MnAzMYDAzaX6QjD6/4//Bxj5GA8AuRwMYGkAPywL13jaY2BkYGA88P8Agx4j+/8fQDYfA1AEBWgDAIB2BOoAeNpjYGRgYNBh4GdgYgABEMnIABJzYNADCQAACWgAsQB42mN
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):286224
            Entropy (8bit):4.847181585804322
            Encrypted:false
            SSDEEP:6144:c0LEKPjBhbtgNLkc7Oo503dbeUzHegjGN+pYLs3/cG9MfLYeearlIEJw0/eZOEI3:Zc
            MD5:C9B5AF8A22C522BB7C9DE9D12FDBBE73
            SHA1:6409034CEE6F48786E06A1E0B2582F5ECCB17A1F
            SHA-256:6F1294BB88EAA8F84F4BF96BE23693B4A25A009493ED6C33166165E608CDBEA3
            SHA-512:4171C96D4AE0A2F695C583D3B7A4178DCC04BDA9F3B8A0DE2F22AEA5B5333EEC411E47B5B00E888A4E50ACB54CC2BB0DE39F32613E09F5C5A89E86BB7B4DC3DF
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */../**. * SSR Window 4.0.1. * Better handling for window object in SSR environment. * https://github.com/nolimits4web/ssr-window. *. * Copyright 2021, Vladimir Kharlampidi. *. * Licensed under MIT. *. * Released on: October 27, 2021. */../* eslint-disable no-param-reassign */.function isObject$1(obj) {. return obj !== null && typeof obj === 'object' && 'constructor' in obj && obj.constructor === Object;.}..function extend$1(target = {}, src = {}) {. Object.keys(src).forEach(key => {. if (typeof target[key] === 'undefined') target[key] = src[key];else if (isObject$1(src[key]) && isObject$1(target[key]) && Object.keys(src[key]).length > 0) {. extend$1(target[key], src[key]);. }. });.}..const ssrDocument = {. body: {},.. add
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):692241
            Entropy (8bit):5.122192455810527
            Encrypted:false
            SSDEEP:6144:EYneUpm0Wpn4AuNQiFeLRZcIhJUsgYXBIkzYcx6RrExSB1/kunLwJkjApmCsB5MS:iTHO
            MD5:EA13C1DE5E455A75E1C60E1CBA0B1C2C
            SHA1:65682DD728132D2609F1B55F2FDC55A40F39E07D
            SHA-256:DBC350FD7B1F1F99FC02833BB1E9CA27848BB1725EDC62112BCAFE59A594C477
            SHA-512:41963F8B03C7EC2EBA3AF08F3785DA00967B5A5B0F12D70F3C838D6FEF040A69728DE9AB1B3331A9F070D87C227891C7D982D7C387520228BF411655DBCE7934
            Malicious:false
            Reputation:low
            Preview:{"version":3,"file":"swiper-bundle.esm.browser.js.map","sources":["../node_modules/ssr-window/ssr-window.esm.js","../node_modules/dom7/dom7.esm.js","../src/shared/dom.js","../src/shared/utils.js","../src/shared/get-support.js","../src/shared/get-device.js","../src/shared/get-browser.js","../src/core/modules/resize/resize.js","../src/core/modules/observer/observer.js","../src/core/events-emitter.js","../src/core/update/updateSize.js","../src/core/update/updateSlides.js","../src/core/update/updateAutoHeight.js","../src/core/update/updateSlidesOffset.js","../src/core/update/updateSlidesProgress.js","../src/core/update/updateProgress.js","../src/core/update/updateSlidesClasses.js","../src/core/update/updateActiveIndex.js","../src/core/update/updateClickedSlide.js","../src/core/update/index.js","../src/core/translate/getTranslate.js","../src/core/translate/setTranslate.js","../src/core/translate/minTranslate.js","../src/core/translate/maxTranslate.js","../src/core/translate/translateTo.js",
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (65280)
            Category:dropped
            Size (bytes):140308
            Entropy (8bit):5.244784800626768
            Encrypted:false
            SSDEEP:3072:9OSNA9QxBW7jjCC2/ONL206fKFrnK4ZKXZd41CFsY2H3e:MSNA9QxB2j12/cL206fKNnK4ZKXZbsYN
            MD5:298E0A10DB18B67621245EE1241B2D5E
            SHA1:A12B82AC2A867A0588E068714B4E8DB0C95ED683
            SHA-256:B8AE3B3E9BB3DC3EA541127F2D030D046DC3C9DC0C48FEA892CDE0E893798C27
            SHA-512:B49B9145D527CCCAF4F066FE46602E5ED8ABE6D864E1EBB8F9E2EBA72CB2D162006ED1A633837B720E769182AB2C185AD44E996AB32123A6B368DA65CEFF498F
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..function isObject$1(e){return null!==e&&"object"==typeof e&&"constructor"in e&&e.constructor===Object}function extend$1(e={},t={}){Object.keys(t).forEach((s=>{void 0===e[s]?e[s]=t[s]:isObject$1(t[s])&&isObject$1(e[s])&&Object.keys(t[s]).length>0&&extend$1(e[s],t[s])}))}const ssrDocument={body:{},addEventListener(){},removeEventListener(){},activeElement:{blur(){},nodeName:""},querySelector:()=>null,querySelectorAll:()=>[],getElementById:()=>null,createEvent:()=>({initEvent(){}}),createElement:()=>({children:[],childNodes:[],style:{},setAttribute(){},getElementsByTagName:()=>[]}),createElementNS:()=>({}),importNode:()=>null,location:{hash:"",host:"",hostname:"",href:"",origin:"",pathname:"",protocol:"",search:""}};function getDocument(
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):516247
            Entropy (8bit):5.3175323387519065
            Encrypted:false
            SSDEEP:6144:JmoLE0+zzNtIo46AkYneUpm0Wpn4AuNQiFeLRZcIhJUsgYXBIkzYcx6RrExSB1/X:Jdwz6
            MD5:ACFDD23C9942C359994992043AB1AEE1
            SHA1:354C377441181241F16C7A3E23D61411FD32C7BC
            SHA-256:95E12B3E08EC2C64BCC3E0699E95FA6D00F4B922A10C3B3DC05B5FCAC02766B0
            SHA-512:9B24EFFAE345FF2D85A1CC3257D576C0AEEC030C2A2B8984B7D38D74A8595B564308E4066F4DB3E67D8D1F1BB19660FDC7C5C935A4F8004EB3898DC41DD333D3
            Malicious:false
            Reputation:low
            Preview:{"version":3,"sources":["../node_modules/ssr-window/ssr-window.esm.js","../node_modules/dom7/dom7.esm.js","../src/shared/dom.js","../src/shared/utils.js","../src/shared/get-support.js","../src/shared/get-device.js","../src/shared/get-browser.js","../src/core/modules/resize/resize.js","../src/core/modules/observer/observer.js","../src/core/events-emitter.js","../src/core/update/updateSize.js","../src/core/update/updateSlides.js","../src/core/update/updateAutoHeight.js","../src/core/update/updateSlidesOffset.js","../src/core/update/updateSlidesProgress.js","../src/core/update/updateProgress.js","../src/core/update/updateSlidesClasses.js","../src/core/update/updateActiveIndex.js","../src/core/update/updateClickedSlide.js","../src/core/update/index.js","../src/core/translate/getTranslate.js","../src/core/translate/setTranslate.js","../src/core/translate/minTranslate.js","../src/core/translate/maxTranslate.js","../src/core/translate/translateTo.js","../src/core/translate/index.js","../src/c
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):2070
            Entropy (8bit):4.96131056396799
            Encrypted:false
            SSDEEP:48:sPsIvpQBKr0eLgK5ugHTvkp+ke0V8wZ3VZwceLMiZ6VVEcvisV1Dt1D2VlAV+Q+W:sVOBKrBLgK5ugzvkp+ke0V8aVZwZLMis
            MD5:2C792AEE966D8E97CE5C211DCF10AC9A
            SHA1:B51A7B469AEDAF3D9253B0CB43BD7A4A2504B080
            SHA-256:98B2A70E33C44A8643A553CBE8178A1A1AF197E3141E59461D6BD9D7002A3B19
            SHA-512:07240A21775D670537BD990A4FFC025DFC9F0D4FF551996AFB20D97D0D9C509CF3A5F8F47812F8AA4328750059CD0E8145FEBAAC3C043D29EE084D56E02BAB54
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..import Swiper from './core/core.js';.export { default as Swiper, default } from './core/core.js';.import Virtual from './modules/virtual/virtual.js';.import Keyboard from './modules/keyboard/keyboard.js';.import Mousewheel from './modules/mousewheel/mousewheel.js';.import Navigation from './modules/navigation/navigation.js';.import Pagination from './modules/pagination/pagination.js';.import Scrollbar from './modules/scrollbar/scrollbar.js';.import Parallax from './modules/parallax/parallax.js';.import Zoom from './modules/zoom/zoom.js';.import Lazy from './modules/lazy/lazy.js';.import Controller from './modules/controller/controller.js';.import A11y from './modules/a11y/a11y.js';.import History from './modules/history/history.js';.i
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):320130
            Entropy (8bit):4.5548262807595865
            Encrypted:false
            SSDEEP:6144:L0L0a/jhBrNQtLk8be4Z03dbuEjX+wTGd+pILMHvM29s/ro+e67FoEJg0PupuU4A:En
            MD5:2A9CBB6323C60FE8851CC3B331E8BD7D
            SHA1:1B596D05ACED3E184B951D9F599919E772DCB43C
            SHA-256:DF9DF432E2C8A5F52C02D72C7E30F9D9653F6C97263B0631E245B849DF575B42
            SHA-512:96E6F5F8E18FA9C28D6741914D621945A2720E194B68796118FB3F0661A58CDD3D873F684D24BF731C3E49C483FF6C5168FAC2AB9C21D76BC5C9648ECBC78E80
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..(function (global, factory) {. typeof exports === 'object' && typeof module !== 'undefined' ? module.exports = factory() :. typeof define === 'function' && define.amd ? define(factory) :. (global = typeof globalThis !== 'undefined' ? globalThis : global || self, global.Swiper = factory());.}(this, (function () { 'use strict';.. /**. * SSR Window 4.0.1. * Better handling for window object in SSR environment. * https://github.com/nolimits4web/ssr-window. *. * Copyright 2021, Vladimir Kharlampidi. *. * Licensed under MIT. *. * Released on: October 27, 2021. */.. /* eslint-disable no-param-reassign */. function isObject$1(obj) {. return obj !== null && typeof obj === 'object'
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):692245
            Entropy (8bit):5.160490661956608
            Encrypted:false
            SSDEEP:6144:vYneUpm0Wpn4AuNQiFeLRZcIhJUsgYXBIkzYcx6RrExSB1/kunLwJkjApmCsB5Mr:RbP
            MD5:9F3FBCC40410D15384620467077FB594
            SHA1:CA6D62E812F04BB07337ECFCC6181A39AE862665
            SHA-256:06E74CC16D4E25276F1649C7D748062C3E5A0E3529A49C46A8D040BFD03BA9A4
            SHA-512:96E220CDE85D54F4FFCC956D28F48CB4E5A41A869D557B458568D6AEAF904570F8C4FE7099CADC8570AC2DF53F2DF4B41E0DFD6F908542AB2C17044A809E6147
            Malicious:false
            Reputation:low
            Preview:{"version":3,"file":"swiper-bundle.js.map","sources":["../node_modules/ssr-window/ssr-window.esm.js","../node_modules/dom7/dom7.esm.js","../src/shared/dom.js","../src/shared/utils.js","../src/shared/get-support.js","../src/shared/get-device.js","../src/shared/get-browser.js","../src/core/modules/resize/resize.js","../src/core/modules/observer/observer.js","../src/core/events-emitter.js","../src/core/update/updateSize.js","../src/core/update/updateSlides.js","../src/core/update/updateAutoHeight.js","../src/core/update/updateSlidesOffset.js","../src/core/update/updateSlidesProgress.js","../src/core/update/updateProgress.js","../src/core/update/updateSlidesClasses.js","../src/core/update/updateActiveIndex.js","../src/core/update/updateClickedSlide.js","../src/core/update/index.js","../src/core/translate/getTranslate.js","../src/core/translate/setTranslate.js","../src/core/translate/minTranslate.js","../src/core/translate/maxTranslate.js","../src/core/translate/translateTo.js","../src/core
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (15306)
            Category:dropped
            Size (bytes):15562
            Entropy (8bit):5.2376965472585155
            Encrypted:false
            SSDEEP:192:s4mUJbiKneTTzbHZ+SKUP3p/a/AMQfHffxVeesedOJ9A5Pz+c3At2/6:sJUbeTXbHZ+GA/AVfHfS4XYz
            MD5:8188534E7DF1EC7FECE646687F2D7D77
            SHA1:42D5E077E634D4EE917072138BBA1FE52896E3B4
            SHA-256:5297BA46897D0955BF211BD3D4239FC52A7ADD3A8830E7DEC65523C022A75A9C
            SHA-512:0589F5519729CE4822E1C168AF353353F16AB1EC0871F5C3600534B538457DE8629AB52BA7984EB5C58F2355A9962F2B2A8A5422168309BC573EDB410D321280
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..@font-face{font-family:swiper-icons;src:url('data:application/font-woff;charset=utf-8;base64, d09GRgABAAAAAAZgABAAAAAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAAGRAAAABoAAAAci6qHkUdERUYAAAWgAAAAIwAAACQAYABXR1BPUwAABhQAAAAuAAAANuAY7+xHU1VCAAAFxAAAAFAAAABm2fPczU9TLzIAAAHcAAAASgAAAGBP9V5RY21hcAAAAkQAAACIAAABYt6F0cBjdnQgAAACzAAAAAQAAAAEABEBRGdhc3AAAAWYAAAACAAAAAj//wADZ2x5ZgAAAywAAADMAAAD2MHtryVoZWFkAAABbAAAADAAAAA2E2+eoWhoZWEAAAGcAAAAHwAAACQC9gDzaG10eAAAAigAAAAZAAAArgJkABFsb2NhAAAC0AAAAFoAAABaFQAUGG1heHAAAAG8AAAAHwAAACAAcABAbmFtZQAAA/gAAAE5AAACXvFdBwlwb3N0AAAFNAAAAGIAAACE5s74hXjaY2BkYGAAYpf5Hu/j+W2+MnAzMYDAzaX6QjD6/4//Bxj5GA8AuRwMYGkAPywL13jaY2BkYGA88P8Agx4j+/8fQDYfA1AEBWgDAIB2BOoAeNpjYGRgYNBh4GdgYgABEMnIABJzYNADCQAACWgAsQB42mNgYfzCOIGBlY
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (65280)
            Category:dropped
            Size (bytes):135574
            Entropy (8bit):5.251119348462882
            Encrypted:false
            SSDEEP:3072:IJkYe9swz2jkTbkC74OrynImO/TYW9D/EL74ami0lLHb:IJte9rz2jkTbkC8OrynImQTYW9D/iP0x
            MD5:8B357CC5E8365726E8663674DE5D6593
            SHA1:583BC844B5D43DB5F316940A18647BF2E1351918
            SHA-256:330FE5965859F5757348BE82340B21F1D473CC9B3FB8C3B1FCD4E082AAF4C0A9
            SHA-512:5C79D6656BF2E539029CF80B53B5EC5A118092CD49437B85BAD5714521F4678F9D8EC1A40A4C55B18BBE2607EB0E272F6C29A37D47F51DE316614BD460A823CD
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..!function(e,t){"object"==typeof exports&&"undefined"!=typeof module?module.exports=t():"function"==typeof define&&define.amd?define(t):(e="undefined"!=typeof globalThis?globalThis:e||self).Swiper=t()}(this,(function(){"use strict";function e(e){return null!==e&&"object"==typeof e&&"constructor"in e&&e.constructor===Object}function t(s={},a={}){Object.keys(a).forEach((i=>{void 0===s[i]?s[i]=a[i]:e(a[i])&&e(s[i])&&Object.keys(a[i]).length>0&&t(s[i],a[i])}))}const s={body:{},addEventListener(){},removeEventListener(){},activeElement:{blur(){},nodeName:""},querySelector:()=>null,querySelectorAll:()=>[],getElementById:()=>null,createEvent:()=>({initEvent(){}}),createElement:()=>({children:[],childNodes:[],style:{},setAttribute(){},getEleme
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:JSON data
            Category:dropped
            Size (bytes):514594
            Entropy (8bit):5.323873087640151
            Encrypted:false
            SSDEEP:6144:RLL3KeQ4z8cYov0pYneUpD7KJzEAuNQiFeLRZcIhJUsgYXBIkzYcx6RrEeSB1/kF:RjNP
            MD5:9B3C29EC8B1754C64B4F09518420DE7F
            SHA1:3310FE183208F3388D335A1F296FB6A9B227D0B8
            SHA-256:7BD2EAA4C66CF216AF889ECA76585C061DBE479D4427D3BE228DEAB59154CA1C
            SHA-512:1693BF8B09FA5634BCFD660F2ADE38AFA092E8184CA2CD1177617C59CE3C45D0682CC985DB8CBEC5D90BC0296730A104304A1D02EE6561FA6F1D469F306341A1
            Malicious:false
            Reputation:low
            Preview:{"version":3,"sources":["../node_modules/ssr-window/ssr-window.esm.js","../node_modules/dom7/dom7.esm.js","../src/shared/dom.js","../src/shared/utils.js","../src/shared/get-support.js","../src/shared/get-device.js","../src/shared/get-browser.js","../src/core/events-emitter.js","../src/core/transition/transitionEmit.js","../src/core/events/onTouchStart.js","../src/core/events/onTouchMove.js","../src/core/events/onTouchEnd.js","../src/core/events/onResize.js","../src/core/events/onClick.js","../src/core/events/onScroll.js","../src/core/events/index.js","../src/core/breakpoints/setBreakpoint.js","../src/core/check-overflow/index.js","../src/core/defaults.js","../src/core/moduleExtendParams.js","../src/core/core.js","../src/core/update/index.js","../src/core/update/updateSize.js","../src/core/update/updateSlides.js","../src/core/update/updateAutoHeight.js","../src/core/update/updateSlidesOffset.js","../src/core/update/updateSlidesProgress.js","../src/core/update/updateProgress.js","../src/
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):22
            Entropy (8bit):4.095795255000933
            Encrypted:false
            SSDEEP:3:XXCi:N
            MD5:6EEA8C168E5EF0121375CCE340BE3E0C
            SHA1:59490C69CA42E9D511B5CE6234AE8A127380BCB5
            SHA-256:E2CD7E70E13BC32CD8A29F210F7B6D9D3829DE802298F2B3190A9CE994AFB154
            SHA-512:261E6536A78070F3FA70F24D9F2740BE54FF1DD1C32ED362A9FD1FC81E73ABA73A84E29CE2705173946410A3B431E91405A2D92F6FC03501A6171201DBAF7893
            Malicious:false
            Reputation:low
            Preview:@themeColor: #007aff;.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):31
            Entropy (8bit):4.260332600569877
            Encrypted:false
            SSDEEP:3:S9mjCBrRwn:SEOri
            MD5:A373824370E77D4729BE9C7118092AC2
            SHA1:0670690F6ED3C1238A48E78125C290190CA150DC
            SHA-256:00323E584F3C71872635BF77209C1AFB3FD320E13F0B7254F9A74BBD1634075D
            SHA-512:9D79DB5586402553ACB10E4B35683ACCFEF1FCBD2A6BEE16D385EB120E335DA913DF84C042A5AEA39C43F4F545B84CC93ED5395CAAA0A7EAF8816623751F51F0
            Malicious:false
            Reputation:low
            Preview:$themeColor: #007aff !default;.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Java source, ASCII text
            Category:dropped
            Size (bytes):1452
            Entropy (8bit):4.755692392775698
            Encrypted:false
            SSDEEP:24:86VuDAzNIAt5upAbDpysxU9TN1LVgpKW1LfLWvMkuETsLkAyqJLuWvXjRsdbAhL0:tcAOAt5uREU9cZXjRsd0ED
            MD5:EA4B1C7BADB5B2415F511EEEBDEAA346
            SHA1:3B02871A40F29D6D23A121DB98279A76610093D4
            SHA-256:4D49B5EA22C4CBD30D6B5E117CD355DB55CE791A7D05F120BC024AF92E9911ED
            SHA-512:60CCA02CBE727DAE534F752A66D8C25C7E14CB4EBBE4C1748028417D399F4C8D98DF56B9490B4F0B9D41F43B76F0C62C766D1833E0DEFD80CAF87B59D0227918
            Malicious:false
            Reputation:low
            Preview:import Swiper from './types/swiper-class';.import { SwiperOptions } from './types/swiper-options';.import { SwiperModule } from './types/shared';..declare const A11y: SwiperModule;.declare const Autoplay: SwiperModule;.declare const Controller: SwiperModule;.declare const EffectCoverflow: SwiperModule;.declare const EffectCube: SwiperModule;.declare const EffectFade: SwiperModule;.declare const EffectFlip: SwiperModule;.declare const EffectCreative: SwiperModule;.declare const EffectCards: SwiperModule;.declare const HashNavigation: SwiperModule;.declare const History: SwiperModule;.declare const Keyboard: SwiperModule;.declare const Lazy: SwiperModule;.declare const Mousewheel: SwiperModule;.declare const Navigation: SwiperModule;.declare const Pagination: SwiperModule;.declare const Parallax: SwiperModule;.declare const Scrollbar: SwiperModule;.declare const Thumbs: SwiperModule;.declare const Virtual: SwiperModule;.declare const Zoom: SwiperModule;.declare const FreeMode: SwiperModu
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text
            Category:dropped
            Size (bytes):2075
            Entropy (8bit):4.843967795084604
            Encrypted:false
            SSDEEP:48:sPsIHBKpQzcPQbcLPQccpQkc5vQWcpQGcHzQFcXQlcvQQcdQ+cZQ+clQgc/Qwc/2:sNBKOzc4bcL4ccOkc5YWcOGc0FcglcYU
            MD5:BEC01D284AC843892BA03F5069CB5B23
            SHA1:7D22AECFAD801F99E87D1577CEC5E991E70672AE
            SHA-256:5DA32E95F36E594A8EAE7DC54CB570C7716A7D8EDE71D040568B6DE9480F76F3
            SHA-512:06D663B8DAE45990795829ECCDB3EDD7839B103A558CBD1268A0CA327F8B09042EB66613F0DF37F442B67107FF685CD151D3A45F633A4E73E2DAC162ACDB272D
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..export { default as Swiper, default } from './core/core.js';.export { default as Virtual } from './modules/virtual/virtual.js';.export { default as Keyboard } from './modules/keyboard/keyboard.js';.export { default as Mousewheel } from './modules/mousewheel/mousewheel.js';.export { default as Navigation } from './modules/navigation/navigation.js';.export { default as Pagination } from './modules/pagination/pagination.js';.export { default as Scrollbar } from './modules/scrollbar/scrollbar.js';.export { default as Parallax } from './modules/parallax/parallax.js';.export { default as Zoom } from './modules/zoom/zoom.js';.export { default as Lazy } from './modules/lazy/lazy.js';.export { default as Controller } from './modules/controller
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (2240)
            Category:dropped
            Size (bytes):5823
            Entropy (8bit):5.649780684420396
            Encrypted:false
            SSDEEP:96:DQB5mSJ+MbpDAKneQYX7EKf7blL4W0EVfKQQPoqg2:DCmUJbiKneRnd4hQgoqg2
            MD5:8C9FEC78752B2487957D7D1B949F6CB1
            SHA1:98DF6C3211832314EA9C8E6D1C7AFAA888E4829A
            SHA-256:50C52CBBDC6C2D3E4ED39BE662E03B82E760535F96692D75E46734B6173E2392
            SHA-512:F717A5ECB53373855CFE2B7EA163142F8C552B9A54E32B805AA3162CCC328A5D3E02FFB69C9BC8C12CD1217B549DE38629B653F32814CEFE2567D74F187333B9
            Malicious:false
            Reputation:low
            Preview:@themeColor: #007aff;..@font-face {. font-family: 'swiper-icons';. src: url('data:application/font-woff;charset=utf-8;base64, d09GRgABAAAAAAZgABAAAAAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAAGRAAAABoAAAAci6qHkUdERUYAAAWgAAAAIwAAACQAYABXR1BPUwAABhQAAAAuAAAANuAY7+xHU1VCAAAFxAAAAFAAAABm2fPczU9TLzIAAAHcAAAASgAAAGBP9V5RY21hcAAAAkQAAACIAAABYt6F0cBjdnQgAAACzAAAAAQAAAAEABEBRGdhc3AAAAWYAAAACAAAAAj//wADZ2x5ZgAAAywAAADMAAAD2MHtryVoZWFkAAABbAAAADAAAAA2E2+eoWhoZWEAAAGcAAAAHwAAACQC9gDzaG10eAAAAigAAAAZAAAArgJkABFsb2NhAAAC0AAAAFoAAABaFQAUGG1heHAAAAG8AAAAHwAAACAAcABAbmFtZQAAA/gAAAE5AAACXvFdBwlwb3N0AAAFNAAAAGIAAACE5s74hXjaY2BkYGAAYpf5Hu/j+W2+MnAzMYDAzaX6QjD6/4//Bxj5GA8AuRwMYGkAPywL13jaY2BkYGA88P8Agx4j+/8fQDYfA1AEBWgDAIB2BOoAeNpjYGRgYNBh4GdgYgABEMnIABJzYNADCQAACWgAsQB42mNgYfzCOIGBlYGB0YcxjYGBwR1Kf2WQZGhhYGBiYGVmgAFGBiQQkOaawtDAoMBQxXjg/wEGPcYDDA4wNUA2CCgwsAAAO4EL6gAAeNpj2M0gyAACqxgGNWBkZ2D4/wMA+xkDdgAAAHjaY2BgYGaAYBkGRgYQiAHyGMF8FgYHIM3DwMHABGQrMOgyWDLEM1T9/w8UBfEMgLzE////P/5//f/V/xv+r4eaAAeMbAxwIUYm
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (5320)
            Category:dropped
            Size (bytes):5576
            Entropy (8bit):5.678348791142288
            Encrypted:false
            SSDEEP:96:seB5mSJ+MbpDAKneQYXzTqiRbaZDar5Z+SK8:s4mUJbiKneTTzbHZ+SK8
            MD5:3955B3A391CC7E4E4EF2DE9D9A25BDE5
            SHA1:53D7D6E74FC8570EA722769379764AE4195E1C1A
            SHA-256:2ACF8F58A341001BEF20873D6822B08DA3D6DF5D680BA016EDD78CA15A1EE5A0
            SHA-512:54F1F67AB1AE0D3FB42561EDF5DADB681396B62EFFFB3B42FEB7B07844AF7ED33F678ECC4CDF0B17E597DA5FBC6CAA9AB8CABB6712792F2CFDF58212113CF150
            Malicious:false
            Reputation:low
            Preview:/**. * Swiper 7.2.0. * Most modern mobile touch slider and framework with hardware accelerated transitions. * https://swiperjs.com. *. * Copyright 2014-2021 Vladimir Kharlampidi. *. * Released under the MIT License. *. * Released on: October 27, 2021. */..@font-face{font-family:swiper-icons;src:url('data:application/font-woff;charset=utf-8;base64, d09GRgABAAAAAAZgABAAAAAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAAGRAAAABoAAAAci6qHkUdERUYAAAWgAAAAIwAAACQAYABXR1BPUwAABhQAAAAuAAAANuAY7+xHU1VCAAAFxAAAAFAAAABm2fPczU9TLzIAAAHcAAAASgAAAGBP9V5RY21hcAAAAkQAAACIAAABYt6F0cBjdnQgAAACzAAAAAQAAAAEABEBRGdhc3AAAAWYAAAACAAAAAj//wADZ2x5ZgAAAywAAADMAAAD2MHtryVoZWFkAAABbAAAADAAAAA2E2+eoWhoZWEAAAGcAAAAHwAAACQC9gDzaG10eAAAAigAAAAZAAAArgJkABFsb2NhAAAC0AAAAFoAAABaFQAUGG1heHAAAAG8AAAAHwAAACAAcABAbmFtZQAAA/gAAAE5AAACXvFdBwlwb3N0AAAFNAAAAGIAAACE5s74hXjaY2BkYGAAYpf5Hu/j+W2+MnAzMYDAzaX6QjD6/4//Bxj5GA8AuRwMYGkAPywL13jaY2BkYGA88P8Agx4j+/8fQDYfA1AEBWgDAIB2BOoAeNpjYGRgYNBh4GdgYgABEMnIABJzYNADCQAACWgAsQB42mNgYfzCOIGBlY
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:ASCII text, with very long lines (2239)
            Category:dropped
            Size (bytes):5790
            Entropy (8bit):5.6530520175205865
            Encrypted:false
            SSDEEP:96:EQB5mSJ+MbpDAKneQYXTEVGw/4W0EVfKQQPoYa:ECmUJbiKnegt/4hQgoYa
            MD5:710A8281EB073264A2F60F389C895AF5
            SHA1:9B3F7F6E1110B12258D3A9C8E8854837695EB3E5
            SHA-256:ECE4F121A5534B2F535680AC566380B26632D766B40F987CF313D8B655214480
            SHA-512:BCC1880870CB507C53E8A7D54FF9556A1DAF78D5ADF74D13836BC6390B3B9CDFD6553F6DAA6FF9BB8850BA8BBEBD02D81581837E2C4E91842DE94F88E2D434CF
            Malicious:false
            Reputation:low
            Preview:@import 'swiper-vars.scss';..@font-face {. font-family: 'swiper-icons';. src: url('data:application/font-woff;charset=utf-8;base64, d09GRgABAAAAAAZgABAAAAAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAAGRAAAABoAAAAci6qHkUdERUYAAAWgAAAAIwAAACQAYABXR1BPUwAABhQAAAAuAAAANuAY7+xHU1VCAAAFxAAAAFAAAABm2fPczU9TLzIAAAHcAAAASgAAAGBP9V5RY21hcAAAAkQAAACIAAABYt6F0cBjdnQgAAACzAAAAAQAAAAEABEBRGdhc3AAAAWYAAAACAAAAAj//wADZ2x5ZgAAAywAAADMAAAD2MHtryVoZWFkAAABbAAAADAAAAA2E2+eoWhoZWEAAAGcAAAAHwAAACQC9gDzaG10eAAAAigAAAAZAAAArgJkABFsb2NhAAAC0AAAAFoAAABaFQAUGG1heHAAAAG8AAAAHwAAACAAcABAbmFtZQAAA/gAAAE5AAACXvFdBwlwb3N0AAAFNAAAAGIAAACE5s74hXjaY2BkYGAAYpf5Hu/j+W2+MnAzMYDAzaX6QjD6/4//Bxj5GA8AuRwMYGkAPywL13jaY2BkYGA88P8Agx4j+/8fQDYfA1AEBWgDAIB2BOoAeNpjYGRgYNBh4GdgYgABEMnIABJzYNADCQAACWgAsQB42mNgYfzCOIGBlYGB0YcxjYGBwR1Kf2WQZGhhYGBiYGVmgAFGBiQQkOaawtDAoMBQxXjg/wEGPcYDDA4wNUA2CCgwsAAAO4EL6gAAeNpj2M0gyAACqxgGNWBkZ2D4/wMA+xkDdgAAAHjaY2BgYGaAYBkGRgYQiAHyGMF8FgYHIM3DwMHABGQrMOgyWDLEM1T9/w8UBfEMgLzE////P/5//f/V/xv+r4eaAAeMbA
            Process:C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
            File Type:data
            Category:modified
            Size (bytes):435642
            Entropy (8bit):3.8270305395311657
            Encrypted:false
            SSDEEP:6144:25hbSkMV0ywFzSTyPeul5ZhqYp0Fw0ETmvvEyFPwBu7Y1BMwogJjDYyFFPowBWbb:FJ
            MD5:CEDCA349C151C78394778ED4929AFE94
            SHA1:103D99CC45AFD3F2657BE302F9D47A0E3CF6BB68
            SHA-256:CF542AC8B4153ACC16FCB670AA42D2A70F1513B83E221AE7BFDF0F22BEDA7772
            SHA-512:DAC8BE47D94A5EC631D8BE1F180051ADAC9DAD82EE01CDC7E6341E3CF3026938FC4926E494C3A7C80D0C5F2644AB824D22A9BBBBCEE49E3303BE6ABB1D3A875D
            Malicious:false
            Reputation:low
            Preview:..[.1.0./.0.3./.2.3. .0.8.:.5.5.:.5.7...7.2.5.].[.M.i.c.r.o.s.o.f.t.E.d.g.e.U.p.d.a.t.e.:.m.s.e.d.g.e.u.p.d.a.t.e.].[.2.4.0.0.:.2.4.0.4.].[.D.l.l.E.n.t.r.y.].[.".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t.\.E.d.g.e.U.p.d.a.t.e.\.M.i.c.r.o.s.o.f.t.E.d.g.e.U.p.d.a.t.e...e.x.e.". ./.s.v.c.].....[.1.0./.0.3./.2.3. .0.8.:.5.5.:.5.7...7.2.5.].[.M.i.c.r.o.s.o.f.t.E.d.g.e.U.p.d.a.t.e.:.m.s.e.d.g.e.u.p.d.a.t.e.].[.2.4.0.0.:.2.4.0.4.].[.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t.\.E.d.g.e.U.p.d.a.t.e.\.1...3...1.4.7...3.7.\.m.s.e.d.g.e.u.p.d.a.t.e...d.l.l.].[.v.e.r.s.i.o.n. .1...3...1.4.7...3.7.].[.o.p.t.].[.o.f.f.i.c.i.a.l.].....[.1.0./.0.3./.2.3. .0.8.:.5.5.:.5.7...7.4.0.].[.M.i.c.r.o.s.o.f.t.E.d.g.e.U.p.d.a.t.e.:.m.s.e.d.g.e.u.p.d.a.t.e.].[.2.4.0.0.:.2.4.0.4.].[.i.s. .m.a.c.h.i.n.e.:. .1.].[.C.u.r.r.e.n.t. .d.i.r.].[.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t.\.E.d.g.e.U.p.d.a.t.e.\.1...3...1.4.7...3.7.].....[.1.0./.0.3./.2.3. .0.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):15872
            Entropy (8bit):5.471852540236525
            Encrypted:false
            SSDEEP:384:EXsC43tPegZ3eBaRwCPOYY7nNYXC06/Yosa:EXJTgZ3eBTCmrnNA5p
            MD5:ECE25721125D55AA26CDFE019C871476
            SHA1:B87685AE482553823BF95E73E790DE48DC0C11BA
            SHA-256:C7FEF6457989D97FECC0616A69947927DA9D8C493F7905DC8475C748F044F3CF
            SHA-512:4E384735D03C943F5EB3396BB3A9CB42C9D8A5479FE2871DE5B8BC18DB4BBD6E2C5F8FD71B6840512A7249E12A1C63E0E760417E4BAA3DC30F51375588410480
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......N.px.q.+.q.+.q.+.q.+[q.+.~C+.q.+^R.+.q.+^R/+.q.+.w.+.q.+.Q.+.q.+Rich.q.+........PE..L....Oa...........!.........`.......+.......0............................................@..........................8......X1..................................X....................................................0..X............................text............................... ..`.rdata..G....0......."..............@..@.data...DL...@.......,..............@....rsrc................6..............@..@.reloc..x............8..............@..B........................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
            Category:dropped
            Size (bytes):1492
            Entropy (8bit):3.6562047966625673
            Encrypted:false
            SSDEEP:24:Q+sxv5SADyqWCs7y6PaPC9nsp8B6tCxGsp8oC96jK7SjLPEUg/kvECvyMsp8i:rsxwA+qQtaPpO/+7SjLPEUg2OJf
            MD5:D9F58D8434ED79AADB58860C1F4F4949
            SHA1:F7392FBD5F4887693EF309640912370181FF8250
            SHA-256:494EECFBCC03054F1A76FECBC2287F3FFC7C26142C4C4ECE3E47DC93A9887ABC
            SHA-512:6D85B90926FCD08D8000589B5C4DE6FDE943D45B93FE46259E7B65CC964682FDE8382004DCCDE463D90C94ED1D7AE8032CBBCDFB092D0A4C4693B2C2F3607B47
            Malicious:false
            Reputation:low
            Preview:..[.S.e.t.t.i.n.g.s.].....R.e.c.t.=.1.0.4.4.....N.u.m.F.i.e.l.d.s.=.3.....R.T.L.=.0.....N.e.x.t.B.u.t.t.o.n.T.e.x.t.=.....C.a.n.c.e.l.E.n.a.b.l.e.d.=.....S.t.a.t.e.=.0.....[.F.i.e.l.d. .1.].....T.y.p.e.=.b.i.t.m.a.p.....L.e.f.t.=.0.....R.i.g.h.t.=.1.0.9.....T.o.p.=.0.....B.o.t.t.o.m.=.1.9.3.....F.l.a.g.s.=.R.E.S.I.Z.E.T.O.F.I.T.....T.e.x.t.=.C.:.\.U.s.e.r.s.\.a.l.f.o.n.s.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.n.s.j.6.7.3.0...t.m.p.\.m.o.d.e.r.n.-.w.i.z.a.r.d...b.m.p.....H.W.N.D.=.6.6.6.7.2.....[.F.i.e.l.d. .2.].....T.y.p.e.=.l.a.b.e.l.....L.e.f.t.=.1.2.0.....R.i.g.h.t.=.3.1.5.....T.o.p.=.1.0.....T.e.x.t.=.W.e.l.c.o.m.e. .t.o. .B.a.m.b.u. .S.t.u.d.i.o. .0.1...0.8...0.4...5.1. .S.e.t.u.p.....B.o.t.t.o.m.=.3.8.....H.W.N.D.=.6.6.6.7.4.....[.F.i.e.l.d. .3.].....T.y.p.e.=.l.a.b.e.l.....L.e.f.t.=.1.2.0.....R.i.g.h.t.=.3.1.5.....T.o.p.=.4.5.....B.o.t.t.o.m.=.1.8.5.....T.e.x.t.=.S.e.t.u.p. .w.i.l.l. .g.u.i.d.e. .y.o.u. .t.h.r.o.u.g.h. .t.h.e. .i.n.s.t.a.l.l.a.t.i.o.n. .o.f. .B.a.m.b.u. .S.t.u.
            Process:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
            Category:dropped
            Size (bytes):4608
            Entropy (8bit):4.703695912299512
            Encrypted:false
            SSDEEP:48:Sz4joMeH+Iwdf8Rom/L+rOnnk5/OCnXeAdbdOAa4GPI+CJ87eILzlq7gthwIsEQW:64c/eFdfS/SSnkxNa4G+ueqPuCtGsj
            MD5:F0438A894F3A7E01A4AAE8D1B5DD0289
            SHA1:B058E3FCFB7B550041DA16BF10D8837024C38BF6
            SHA-256:30C6C3DD3CC7FCEA6E6081CE821ADC7B2888542DAE30BF00E881C0A105EB4D11
            SHA-512:F91FCEA19CBDDF8086AFFCB63FE599DC2B36351FC81AC144F58A80A524043DDEAA3943F36C86EBAE45DD82E8FAF622EA7B7C9B776E74C54B93DF2963CFE66CC7
            Malicious:false
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........s.I...I...I...n}f.L...I...P...@..K...@..H...@..H...RichI...........................PE..L...\..N...........!......................... ...............................`.......................................#....... ..<....@.......................P..|.................................................... ..d............................text............................... ..`.rdata....... ......................@..@.data... ....0......................@....rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\SysWOW64\cmd.exe
            File Type:ASCII text, with very long lines (613), with CRLF line terminators
            Category:modified
            Size (bytes):346196
            Entropy (8bit):2.2001933525891535
            Encrypted:false
            SSDEEP:1536:ikfnS3bGhVr9BNrIJMfTOZsGFgsHGy4gJNw4:nfSElOZF
            MD5:1431CF826C49924722F34895ADD45CC3
            SHA1:E9C8DD5A1982F7F8552FC3E3FE893C2F1C7E1655
            SHA-256:D2AE759CAB4EF87C09121237D06B622F94A7AB791029226AA683748447F641F8
            SHA-512:04C2A57F1283E6A4D188A66F5CD3C58E5F911110C91D74F0170CB04261D26AEE46F9F21EEA6D92A221B085F5A62B6B8D8E538BDD808DF9E68ABE98FE31329634
            Malicious:false
            Reputation:low
            Preview:--2024-04-26 13:11:13-- https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe..Resolving github.com (github.com)... 140.82.112.3..Connecting to github.com (github.com)|140.82.112.3|:443... connected...HTTP request sent, awaiting response... 302 Found..Location: https://objects.githubusercontent.com/github-production-release-asset-2e65be/511797274/42e664ca-d493-4c52-abd9-b5dc06d128f3?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAVCODYLSA53PQK4ZA%2F20240426%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20240426T111114Z&X-Amz-Expires=300&X-Amz-Signature=ad09487a8c07252000b0bfb9391e69811cd140dc62cb0f81d05115c8a6c66183&X-Amz-SignedHeaders=host&actor_id=0&key_id=0&repo_id=511797274&response-content-disposition=attachment%3B%20filename%3DBambu_Studio_win_public-v01.08.04.51-20240117164301.exe&response-content-type=application%2Foctet-stream [following]..--2024-04-26 13:11:14-- https://objects.githubusercontent.com
            Process:C:\Windows\SysWOW64\wget.exe
            File Type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
            Category:dropped
            Size (bytes):227156280
            Entropy (8bit):7.9999392641178675
            Encrypted:true
            SSDEEP:3145728:Fz/Hlx62MMm5DdD8q8fbHSb27hjm/n51hqX0ckUDfet0+kfJ4mNoFYeS3A+skw4x:dtxpMMmJ59G+MM5LqX0chD8ayYeF+
            MD5:DFD4A19DE50A68477EDAC8DBB25FAF9A
            SHA1:F5D117A3550ADEE70F3FF2EDBF65B375334C79F6
            SHA-256:F911E04176476439BF4F10B4A476627BB3E401025B225EEFCB529D8A7D25F5E6
            SHA-512:45A1DA9A8182A9E78E8B688E4123EA83AD5FFDD1A17D8A9E86D298B4B01DAA5B993D873491859F77C082AEDFAB67BEB72DEE64527AFF436D0E3198A39F1630E6
            Malicious:true
            Reputation:low
            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf.sV..Pf..V`..Pf.Rich.Pf.........................PE..L....Oa.................f...*.......4............@..................................6....@.......................................... ...u..............6...........................................................................................text....e.......f.................. ..`.rdata...............j..............@..@.data...8............~..............@....ndata...p...............................rsrc....u... ...v..................@..@................................................................................................................................................................................................................................................................................................................................................
            No static file info
            Skipped network analysis since the amount of network traffic is too extensive. Please download the PCAP and check manually.

            Click to jump to process

            Click to jump to process

            Click to dive into process behavior distribution

            Click to jump to process

            Target ID:0
            Start time:13:11:13
            Start date:26/04/2024
            Path:C:\Windows\SysWOW64\cmd.exe
            Wow64 process (32bit):true
            Commandline:C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe" > cmdline.out 2>&1
            Imagebase:0x790000
            File size:236'544 bytes
            MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:1
            Start time:13:11:13
            Start date:26/04/2024
            Path:C:\Windows\System32\conhost.exe
            Wow64 process (32bit):false
            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Imagebase:0x7ff6d64d0000
            File size:862'208 bytes
            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:2
            Start time:13:11:13
            Start date:26/04/2024
            Path:C:\Windows\SysWOW64\wget.exe
            Wow64 process (32bit):true
            Commandline:wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://github.com/bambulab/BambuStudio/releases/download/v01.08.04.51/Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe"
            Imagebase:0x400000
            File size:3'895'184 bytes
            MD5 hash:3DADB6E2ECE9C4B3E1E322E617658B60
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:6
            Start time:13:11:43
            Start date:26/04/2024
            Path:C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe
            Wow64 process (32bit):true
            Commandline:"C:\Users\user\Desktop\download\Bambu_Studio_win_public-v01.08.04.51-20240117164301.exe"
            Imagebase:0x400000
            File size:227'156'280 bytes
            MD5 hash:DFD4A19DE50A68477EDAC8DBB25FAF9A
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:8
            Start time:13:13:20
            Start date:26/04/2024
            Path:C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
            Wow64 process (32bit):true
            Commandline:"C:\Program Files\Bambu Studio\plugin\MicrosoftEdgeWebView2RuntimeInstallerX64.exe" /silent /install
            Imagebase:0x60000
            File size:115'254'560 bytes
            MD5 hash:8D32A91401F3C062EE93502BD79D28D8
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:9
            Start time:13:13:41
            Start date:26/04/2024
            Path:C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe
            Wow64 process (32bit):true
            Commandline:"C:\Program Files (x86)\Microsoft\Temp\EUE0BF.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=True"
            Imagebase:0x530000
            File size:214'928 bytes
            MD5 hash:0F11E6717C1FE6DD20AE2D12F63AF3F7
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:10
            Start time:13:13:41
            Start date:26/04/2024
            Path:C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
            Wow64 process (32bit):true
            Commandline:"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvc
            Imagebase:0x840000
            File size:214'928 bytes
            MD5 hash:0F11E6717C1FE6DD20AE2D12F63AF3F7
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:11
            Start time:13:13:42
            Start date:26/04/2024
            Path:C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
            Wow64 process (32bit):true
            Commandline:"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserver
            Imagebase:0x840000
            File size:214'928 bytes
            MD5 hash:0F11E6717C1FE6DD20AE2D12F63AF3F7
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:12
            Start time:13:13:42
            Start date:26/04/2024
            Path:C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe"
            Imagebase:0x7ff76d6f0000
            File size:208'784 bytes
            MD5 hash:3DACF7CC11DE65C60616DC29C41397BE
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:13
            Start time:13:13:42
            Start date:26/04/2024
            Path:C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe"
            Imagebase:0x7ff76d6f0000
            File size:208'784 bytes
            MD5 hash:3DACF7CC11DE65C60616DC29C41397BE
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:14
            Start time:13:13:42
            Start date:26/04/2024
            Path:C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.153.47\MicrosoftEdgeUpdateComRegisterShell64.exe"
            Imagebase:0x7ff76d6f0000
            File size:208'784 bytes
            MD5 hash:3DACF7CC11DE65C60616DC29C41397BE
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:15
            Start time:13:13:43
            Start date:26/04/2024
            Path:C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
            Wow64 process (32bit):true
            Commandline:"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNTMuNDciIHNoZWxsX3ZlcnNpb249IjEuMy4xNTMuNDciIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7MEFFNDg4MjEtNDIxRC00MEYwLTlCOTMtOUZEMjhFQzhBRTREfSIgdXNlcmlkPSJ7MEVBMkNGRkQtMUMyRS00NEUyLTgzMjAtNTI5NzQ5QkU3NDE1fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins0RjU1MDU0RC04NzAwLTREMjAtQUZDMS1DODVEQTU4MzFDRjd9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iOCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjIwMDYiIHNwPSIiIGFyY2g9Ing2NCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9Imp3dGFpaywgSW5jLiIgcHJvZHVjdF9uYW1lPSJqd3RhaWsyMCwxIi8-PGV4cCBldGFnPSImcXVvdDtxV0pTeld3UGZkY0xSK1hHSXY2eHJaZmlZT3hoUFUyczFOV21qV2NhRlBnPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGM0M0RkUwMC1FRkQ1LTQwM0ItOTU2OS0zOThBMjBGMUJBNEF9IiB2ZXJzaW9uPSIxLjMuMTc3LjExIiBuZXh0dmVyc2lvbj0iMS4zLjE1My40NyIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSIxOTY5Ii8-PC9hcHA-PC9yZXF1ZXN0Pg
            Imagebase:0x840000
            File size:214'928 bytes
            MD5 hash:0F11E6717C1FE6DD20AE2D12F63AF3F7
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            Target ID:16
            Start time:13:13:45
            Start date:26/04/2024
            Path:C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
            Wow64 process (32bit):true
            Commandline:"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20WebView2%20Runtime&needsadmin=True" /installsource offline /sessionid "{0AE48821-421D-40F0-9B93-9FD28EC8AE4D}" /silent /offlinedir "{FAF4F54B-74F8-4FCD-81CD-4DFC19E93F21}"
            Imagebase:0x840000
            File size:214'928 bytes
            MD5 hash:0F11E6717C1FE6DD20AE2D12F63AF3F7
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:17
            Start time:13:13:45
            Start date:26/04/2024
            Path:C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
            Wow64 process (32bit):true
            Commandline:"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
            Imagebase:0x840000
            File size:214'928 bytes
            MD5 hash:0F11E6717C1FE6DD20AE2D12F63AF3F7
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Reset < >
              Memory Dump Source
              • Source File: 00000002.00000002.2243268639.0000000000DCD000.00000004.00000020.00020000.00000000.sdmp, Offset: 00DCD000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_2_2_dcd000_wget.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: e781ad4a057d6511c50d3fa52fc309cb8e7c9c5410dec9f4d14fe675e6c93da4
              • Instruction ID: 7f4cf6b6afe6f9f31dde9a515abe715f4edfd691d70d01dbc0410fc63d6a3171
              • Opcode Fuzzy Hash: e781ad4a057d6511c50d3fa52fc309cb8e7c9c5410dec9f4d14fe675e6c93da4
              • Instruction Fuzzy Hash: 56427BA584E7D19FD7138B7088B56907FB1AE17228B5F41EBC0C0CF4B3E659494AC722
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000002.00000003.2242842095.0000000000DCB000.00000004.00000020.00020000.00000000.sdmp, Offset: 00DCB000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_2_3_dcb000_wget.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f759d89668bbb6748003e1e4c5fc84aed20e0bdbc6df4db3c086db5194dc5be9
              • Instruction ID: 7f4cf6b6afe6f9f31dde9a515abe715f4edfd691d70d01dbc0410fc63d6a3171
              • Opcode Fuzzy Hash: f759d89668bbb6748003e1e4c5fc84aed20e0bdbc6df4db3c086db5194dc5be9
              • Instruction Fuzzy Hash: 56427BA584E7D19FD7138B7088B56907FB1AE17228B5F41EBC0C0CF4B3E659494AC722
              Uniqueness

              Uniqueness Score: -1.00%

              Execution Graph

              Execution Coverage:5.8%
              Dynamic/Decrypted Code Coverage:0%
              Signature Coverage:2.6%
              Total number of Nodes:2000
              Total number of Limit Nodes:38
              execution_graph 102577 6cb680d6 102601 6cb69d41 102577->102601 102587 6cb68113 102588 6cb6813b GetShortPathNameW 102587->102588 102646 6cb6706e 102587->102646 102642 6cb69db6 102588->102642 102593 6cb68170 102595 6cb6694d error_info_injector RtlFreeHeap 102593->102595 102597 6cb6817b 102595->102597 102596 6cb68161 102596->102593 102600 6cb69049 19 API calls 102596->102600 102598 6cb6694d error_info_injector RtlFreeHeap 102597->102598 102599 6cb68186 102598->102599 102600->102593 102602 6cb680de 102601->102602 102603 6cb69d59 102601->102603 102610 6cb6694d 102602->102610 102604 6cb69d7c 102603->102604 102605 6cb69d65 102603->102605 102662 6cb66f63 102604->102662 102654 6cb69f92 102605->102654 102609 6cb6694d error_info_injector RtlFreeHeap 102609->102602 102611 6cb66964 102610->102611 102612 6cb6695c 102610->102612 102614 6cb68301 102611->102614 102679 6cb668c5 102612->102679 102682 6cb68f37 102614->102682 102617 6cb68327 GetPrivateProfileIntW GetPrivateProfileIntW GetPrivateProfileIntW GetPrivateProfileIntW GetPrivateProfileIntW 102621 6cb6839c 102617->102621 102618 6cb6842f 102691 6cb6fdfb 102618->102691 102619 6cb68f37 13 API calls 102619->102621 102621->102618 102621->102619 102624 6cb683f8 GetPrivateProfileIntW 102621->102624 102626 6cb6694d error_info_injector RtlFreeHeap 102621->102626 102623 6cb6694d error_info_injector RtlFreeHeap 102625 6cb680fb 102623->102625 102624->102621 102627 6cb6cc21 102625->102627 102626->102621 102628 6cb69d8f 102627->102628 102629 6cb6cc2d GetEnvironmentVariableW 102628->102629 102630 6cb6cc3e 102629->102630 102631 6cb6cc5a 102629->102631 102633 6cb6cc46 GetEnvironmentVariableW 102630->102633 102713 6cb781c1 GetLastError RaiseException Concurrency::wait 102631->102713 102635 6cb69db6 15 API calls 102633->102635 102634 6cb68108 102636 6cb69049 102634->102636 102635->102634 102637 6cb6905f 102636->102637 102638 6cb69081 102637->102638 102641 6cb6908b 102637->102641 102714 6cb69ad1 RaiseException 102637->102714 102715 6cb69a7a 102638->102715 102641->102587 102643 6cb69dc4 ___crtCompareStringW 102642->102643 102722 6cb66efc 102643->102722 102645 6cb68152 102645->102593 102653 6cb69ab0 RaiseException 102645->102653 102647 6cb6707f 102646->102647 102648 6cb67088 102647->102648 102651 6cb67092 102647->102651 102729 6cb67171 102648->102729 102650 6cb67090 102650->102588 102651->102650 102741 6cb67139 102651->102741 102653->102596 102655 6cb69f9d 102654->102655 102656 6cb69d6b 102655->102656 102657 6cb69fc1 102655->102657 102658 6cb69fdf 102655->102658 102656->102609 102666 6cb670c5 102657->102666 102670 6cb671db RaiseException 102658->102670 102663 6cb66f7b 102662->102663 102672 6cb66655 102663->102672 102667 6cb670fa _Yarn 102666->102667 102669 6cb670d7 ___scrt_fastfail 102666->102669 102667->102656 102669->102667 102671 6ccc958a 11 API calls 2 library calls 102669->102671 102678 6cb66640 RaiseException 102672->102678 102674 6cb66694 102675 6cb66655 RaiseException 102676 6cb666b0 102675->102676 102677 6cb66675 102677->102674 102677->102675 102678->102677 102680 6cb668ce RtlFreeHeap 102679->102680 102681 6cb668dc 102679->102681 102680->102681 102681->102611 102683 6cb68f6a 102682->102683 102684 6cb68f49 102682->102684 102697 6cb66e68 102683->102697 102694 6cb6e978 GetFileAttributesExW 102684->102694 102687 6cb68315 102687->102617 102687->102621 102689 6cb68f52 102690 6cb69f92 12 API calls 102689->102690 102690->102687 102692 6cb6fe11 GetSystemTimeAsFileTime 102691->102692 102693 6cb68434 102691->102693 102692->102693 102693->102623 102705 6ccb0e3b 102694->102705 102696 6cb68f4e 102696->102683 102696->102689 102698 6cb66e74 102697->102698 102699 6cb66ebc 102698->102699 102702 6cb66e7a 102698->102702 102700 6cb66655 RaiseException 102699->102700 102701 6cb66ec6 102700->102701 102703 6cb66f63 RaiseException 102702->102703 102704 6cb66e93 102702->102704 102703->102704 102704->102687 102706 6ccb0e46 IsProcessorFeaturePresent 102705->102706 102707 6ccb0e44 102705->102707 102709 6ccb1794 102706->102709 102707->102696 102712 6ccb1758 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 102709->102712 102711 6ccb1877 102711->102696 102712->102711 102713->102634 102714->102637 102716 6cb69aa1 102715->102716 102717 6cb69a89 102715->102717 102721 6cb6a060 19 API calls 102716->102721 102718 6cb69f92 12 API calls 102717->102718 102720 6cb69a96 102718->102720 102720->102641 102721->102720 102723 6cb66f06 102722->102723 102724 6cb66655 RaiseException 102723->102724 102725 6cb66f0d 102723->102725 102726 6cb66f26 102724->102726 102725->102645 102727 6cb66f4f 102726->102727 102728 6cb6706e 15 API calls 102726->102728 102727->102645 102728->102727 102730 6cb6718e 102729->102730 102748 6cb66a44 102730->102748 102732 6cb671d5 102752 6cb671db RaiseException 102732->102752 102734 6cb671a2 102736 6cb670c5 11 API calls 102734->102736 102737 6cb671b9 102736->102737 102738 6cb6694d error_info_injector RtlFreeHeap 102737->102738 102739 6cb671c9 102738->102739 102739->102650 102742 6cb6714d 102741->102742 102745 6cb6715c 102741->102745 102742->102745 102754 6cb66ab6 102742->102754 102746 6cb67160 102745->102746 102758 6cb671db RaiseException 102745->102758 102746->102650 102749 6cb66a89 102748->102749 102750 6cb66a52 102748->102750 102749->102732 102749->102734 102750->102749 102753 6cb668b0 RtlAllocateHeap 102750->102753 102753->102749 102755 6cb66ac1 102754->102755 102756 6cb66afc 102754->102756 102755->102756 102759 6cb668e0 102755->102759 102756->102745 102760 6cb668f3 102759->102760 102762 6cb668ea 102759->102762 102761 6cb66903 RtlReAllocateHeap 102760->102761 102760->102762 102761->102762 102762->102756 102763 6cb66bf4 102764 6cb66bff 102763->102764 102765 6cb69d41 13 API calls 102764->102765 102766 6cb66c0c 102765->102766 102767 6cb6694d error_info_injector RtlFreeHeap 102766->102767 102768 6cb66c18 102767->102768 102769 6cb69d41 13 API calls 102768->102769 102770 6cb66c49 102769->102770 102771 6cb6694d error_info_injector RtlFreeHeap 102770->102771 102772 6cb66c55 102771->102772 102773 6cb6f032 FindCloseChangeNotification 102774 6cb6f044 102773->102774 102775 6cb6f049 102773->102775 102777 6cb781c1 GetLastError RaiseException Concurrency::wait 102774->102777 102777->102775 102778 6cbe753a GetCurrentProcessId 102787 6cb7b487 102778->102787 102780 6cbe7558 102793 6cb7d80b InitOnceExecuteOnce 102780->102793 102782 6cbe7565 102794 6cbe73c0 102782->102794 102785 6cb6694d error_info_injector RtlFreeHeap 102786 6cbe75c8 102785->102786 102788 6cb7b498 102787->102788 102791 6cb7b4b4 102788->102791 102813 6ccb16cf 102788->102813 102790 6cb7b4ac 102823 6cb7b4fb 102790->102823 102791->102780 102793->102782 102795 6cb7b487 207 API calls 102794->102795 102796 6cbe73d1 102795->102796 102797 6cb76f8e 42 API calls 102796->102797 102798 6cbe73ec 102797->102798 102800 6cbe7475 102798->102800 103771 6cb6fa02 10 API calls 102798->103771 102800->102785 102801 6cbe740e 103772 6cb68d83 15 API calls ___scrt_fastfail 102801->103772 102803 6cbe7417 102804 6cbe742e 102803->102804 103773 6cb740f4 102803->103773 102806 6cbe7445 102804->102806 103791 6cb6fc6d RaiseException RtlFreeHeap error_info_injector 102804->103791 103792 6cbe7488 35 API calls 2 library calls 102806->103792 102809 6cbe745f 102810 6cb6694d error_info_injector RtlFreeHeap 102809->102810 102811 6cbe746d 102810->102811 102812 6cb6694d error_info_injector RtlFreeHeap 102811->102812 102812->102800 102816 6ccb16d4 102813->102816 102815 6ccb16ee 102815->102790 102816->102815 102819 6ccb16f0 Concurrency::cancel_current_task 102816->102819 102877 6cccd232 102816->102877 102881 6ccd104a EnterCriticalSection LeaveCriticalSection std::_Facet_Register 102816->102881 102818 6ccb1ef2 Concurrency::cancel_current_task 102883 6ccc7d95 RaiseException 102818->102883 102819->102818 102882 6ccc7d95 RaiseException 102819->102882 102822 6ccb1f0f 102822->102790 102884 6cb7a9f4 102823->102884 102826 6ccb16cf std::_Facet_Register 4 API calls 102827 6cb7b523 102826->102827 102828 6cb66e68 RaiseException 102827->102828 102829 6cb7b535 102828->102829 102830 6cb69f92 12 API calls 102829->102830 102831 6cb7b547 102830->102831 102832 6cb7a9f4 4 API calls 102831->102832 102833 6cb7b555 102832->102833 102888 6cb7f2fc 102833->102888 102836 6cb6694d error_info_injector RtlFreeHeap 102837 6cb7b566 102836->102837 102838 6ccb16cf std::_Facet_Register 4 API calls 102837->102838 102839 6cb7b56d 102838->102839 102840 6cb66e68 RaiseException 102839->102840 102841 6cb7b57f 102840->102841 102842 6cb69f92 12 API calls 102841->102842 102843 6cb7b591 102842->102843 102844 6cb7a9f4 4 API calls 102843->102844 102845 6cb7b59f 102844->102845 102846 6cb7f2fc 4 API calls 102845->102846 102847 6cb7b5a8 102846->102847 102848 6cb6694d error_info_injector RtlFreeHeap 102847->102848 102849 6cb7b5b0 102848->102849 102891 6cb72969 102849->102891 102851 6cb7b5c0 102852 6cb66e68 RaiseException 102851->102852 102853 6cb7b5de 102852->102853 102896 6cb7ab73 102853->102896 102856 6cb6694d error_info_injector RtlFreeHeap 102858 6cb7b5f8 102856->102858 102857 6cb66e68 RaiseException 102859 6cb7b632 102857->102859 102858->102857 102860 6cb7ab73 25 API calls 102859->102860 102861 6cb7b63c 102860->102861 102862 6cb6694d error_info_injector RtlFreeHeap 102861->102862 102863 6cb7b64c 102862->102863 102914 6cb76f8e 102863->102914 102878 6ccd7da5 RtlAllocateHeap 102877->102878 102880 6ccd7de1 102878->102880 102880->102816 102881->102816 102882->102818 102883->102822 102885 6cb7aa0f 102884->102885 102886 6ccb16cf std::_Facet_Register 4 API calls 102885->102886 102887 6cb7aa5b 102886->102887 102887->102826 102889 6ccb16cf std::_Facet_Register 4 API calls 102888->102889 102890 6cb7b55e 102889->102890 102890->102836 103015 6cb7287d VirtualQuery 102891->103015 102893 6cb72971 103016 6cb728f1 102893->103016 102897 6cb7ab88 102896->102897 102898 6cb7abc6 102897->102898 102899 6cb7abd4 102897->102899 102900 6cb69d41 13 API calls 102898->102900 103032 6cb6bdad 102899->103032 102902 6cb7abd2 102900->102902 102903 6cb7ac27 102902->102903 102904 6cb7ac0f PathAppendW 102902->102904 102906 6cb6706e 15 API calls 102902->102906 102905 6cb6694d error_info_injector RtlFreeHeap 102903->102905 102907 6cb69db6 15 API calls 102904->102907 102908 6cb7ac65 102905->102908 102909 6cb7ac0c 102906->102909 102910 6cb7ac23 102907->102910 102908->102856 102909->102904 102910->102903 102911 6cb66f63 RaiseException 102910->102911 102912 6cb7ac4a 102911->102912 102912->102903 103048 6cb6bca2 102912->103048 102915 6cb66e68 RaiseException 102914->102915 102916 6cb76fa7 102915->102916 103097 6cb77946 102916->103097 102919 6cb770d1 102921 6cb6694d error_info_injector RtlFreeHeap 102919->102921 102923 6cb770d9 102921->102923 102943 6cb7c4bf 102923->102943 102924 6cb76ff3 102927 6cb77062 102924->102927 102928 6cb76ff9 102924->102928 102925 6cb7707b 103137 6cb771f9 SHQueryValueExW 102925->103137 102926 6cb770ca RegCloseKey 102926->102919 103144 6cb770e0 SHQueryValueExW SHQueryValueExW 102927->103144 102931 6cb77054 102928->102931 102932 6cb76ffe 102928->102932 103135 6cb77187 SHQueryValueExW 102931->103135 102934 6cb77003 102932->102934 102935 6cb7701d 102932->102935 102937 6cb77008 102934->102937 103141 6cb771c0 SHQueryValueExW 102934->103141 103142 6cb770e0 SHQueryValueExW SHQueryValueExW 102935->103142 102938 6cb77092 RegCloseKey 102937->102938 102939 6cb7709f 102937->102939 102938->102939 102939->102919 102939->102926 102941 6cb7703d 102941->102937 103143 6cb7734f 19 API calls error_info_injector 102941->103143 102944 6cb7a9f4 4 API calls 102943->102944 102945 6cb7c4e2 102944->102945 103153 6cb6d808 102945->103153 102948 6cb7c504 103183 6cb774d5 102948->103183 102954 6cb7c556 102957 6cb7c59c 102954->102957 102960 6cb68a16 63 API calls 102954->102960 102955 6cb7c5a4 103210 6cb76d85 102955->103210 103196 6cb7b350 102957->103196 102962 6cb7c586 102960->102962 102965 6cb66b74 119 API calls 102962->102965 102965->102957 102967 6cb7c5f3 103220 6cb7adc4 42 API calls error_info_injector 102967->103220 102970 6cb7c9ed RegCloseKey 102970->102957 102972 6cb7c603 103221 6cb7f332 42 API calls 102972->103221 102974 6cb7c613 103222 6cb7f332 42 API calls 102974->103222 102976 6cb7c623 103223 6cb7f332 42 API calls 102976->103223 102978 6cb7c633 103224 6cb7f332 42 API calls 102978->103224 102980 6cb7c643 103225 6cb7f332 42 API calls 102980->103225 102982 6cb7c653 103226 6cb7adc4 42 API calls error_info_injector 102982->103226 102984 6cb7c663 103227 6cb7adc4 42 API calls error_info_injector 102984->103227 102986 6cb7c673 103228 6cb7adc4 42 API calls error_info_injector 102986->103228 102988 6cb7c683 102989 6cb76f8e 42 API calls 102988->102989 102990 6cb7c6a0 102989->102990 102991 6cb76f8e 42 API calls 102990->102991 102992 6cb7c6c8 102991->102992 102993 6cb76f8e 42 API calls 102992->102993 102994 6cb7c6f0 102993->102994 103229 6cb77b4e RegQueryInfoKeyW 102994->103229 102996 6cb7c5cc 102996->102957 102996->102970 102999 6cb6694d RtlFreeHeap error_info_injector 103010 6cb7c70a 102999->103010 103000 6cb6dd87 15 API calls 103000->103010 103001 6cb77187 SHQueryValueExW 103001->103010 103002 6cb68a16 63 API calls 103002->103010 103004 6cb7c82c lstrcmpiW 103005 6cb7c852 lstrcmpiW 103004->103005 103004->103010 103007 6cb7c879 lstrcmpiW 103005->103007 103005->103010 103006 6cb7c906 lstrcmpiW 103008 6cb7c92c lstrcmpiW 103006->103008 103006->103010 103007->103010 103008->103010 103009 6cb7f0d9 18 API calls 103009->103010 103010->102996 103010->102999 103010->103000 103010->103001 103010->103002 103010->103004 103010->103006 103010->103009 103011 6cb69d41 13 API calls 103010->103011 103012 6cb66b74 119 API calls 103010->103012 103230 6cb77b73 6 API calls _ValidateLocalCookies 103010->103230 103231 6cb6e1f0 15 API calls 103010->103231 103232 6cb77290 SHQueryValueExW 103010->103232 103011->103010 103012->103010 103015->102893 103017 6cb72900 103016->103017 103022 6cb73cd5 103017->103022 103020 6cb6694d error_info_injector RtlFreeHeap 103021 6cb72914 103020->103021 103021->102851 103023 6cb66e68 RaiseException 103022->103023 103024 6cb73ce7 103023->103024 103025 6cb73cf5 PathRemoveFileSpecW 103024->103025 103026 6cb69db6 15 API calls 103025->103026 103027 6cb73d06 103026->103027 103028 6cb69f92 12 API calls 103027->103028 103029 6cb73d11 103028->103029 103030 6cb6694d error_info_injector RtlFreeHeap 103029->103030 103031 6cb72909 103030->103031 103031->103020 103033 6cb6bdd4 103032->103033 103043 6cb6bdca 103032->103043 103070 6cb66ec7 103033->103070 103035 6cb6bddc ___scrt_fastfail 103038 6cb6bdf0 SHGetFolderPathW 103035->103038 103036 6ccb0e3b _ValidateLocalCookies 5 API calls 103037 6cb6be80 103036->103037 103037->102902 103039 6cb6be55 103038->103039 103040 6cb6be0a 103038->103040 103041 6cb66f63 RaiseException 103039->103041 103042 6cb6cc21 19 API calls 103040->103042 103040->103043 103041->103043 103044 6cb6be2e 103042->103044 103043->103036 103045 6cb69d41 13 API calls 103044->103045 103046 6cb6be36 103045->103046 103047 6cb6694d error_info_injector RtlFreeHeap 103046->103047 103047->103043 103049 6cb6bcb3 103048->103049 103050 6cb6bcd6 PathCanonicalizeW 103049->103050 103051 6cb6706e 15 API calls 103049->103051 103052 6cb69db6 15 API calls 103050->103052 103053 6cb6bcd3 103051->103053 103054 6cb6bcea 103052->103054 103053->103050 103055 6cb6bcee 103054->103055 103077 6cb6e020 103054->103077 103057 6cb6694d error_info_injector RtlFreeHeap 103055->103057 103058 6cb6bda7 103057->103058 103058->102903 103059 6cb6bd03 103062 6cb6bd3b CreateDirectoryW 103059->103062 103063 6cb6bd91 103059->103063 103067 6cb6bd7a 103059->103067 103068 6cb6694d error_info_injector RtlFreeHeap 103059->103068 103081 6cb6dd87 103059->103081 103088 6cb6e9b4 103059->103088 103062->103059 103064 6cb6bd48 GetLastError 103062->103064 103066 6cb6694d error_info_injector RtlFreeHeap 103063->103066 103065 6cb6e9b4 6 API calls 103064->103065 103065->103059 103066->103055 103069 6cb6694d error_info_injector RtlFreeHeap 103067->103069 103068->103059 103069->103055 103071 6cb66ed9 103070->103071 103076 6cb66ee6 103070->103076 103072 6cb66ede 103071->103072 103073 6cb66ee8 103071->103073 103074 6cb66efc 15 API calls 103072->103074 103075 6cb6694d error_info_injector RtlFreeHeap 103073->103075 103074->103076 103075->103076 103076->103035 103078 6cb6e07b 103077->103078 103079 6cb6e03b 103077->103079 103078->103059 103079->103078 103080 6cb66efc 15 API calls 103079->103080 103080->103078 103082 6cb6dd95 103081->103082 103083 6cb6ddb0 103082->103083 103084 6cb6dd9e 103082->103084 103094 6cb6e2c3 15 API calls 103083->103094 103085 6cb69f92 12 API calls 103084->103085 103087 6cb6dda6 103085->103087 103087->103059 103095 6ccc5fe0 103088->103095 103091 6cb6e9e9 103092 6ccb0e3b _ValidateLocalCookies 5 API calls 103091->103092 103093 6cb6e9ff 103092->103093 103093->103059 103094->103087 103096 6cb6e9d4 GetFileAttributesExW 103095->103096 103096->103091 103098 6cb77964 103097->103098 103099 6cb77993 103098->103099 103100 6cb77973 103098->103100 103102 6cb6dd87 15 API calls 103099->103102 103101 6cb69d41 13 API calls 103100->103101 103104 6cb7797c 103101->103104 103103 6cb7799f 103102->103103 103105 6cb69d41 13 API calls 103103->103105 103108 6cb66f63 RaiseException 103104->103108 103106 6cb779a8 103105->103106 103107 6cb6694d error_info_injector RtlFreeHeap 103106->103107 103109 6cb779b3 103107->103109 103110 6cb77991 103108->103110 103145 6cb6ddcc 103109->103145 103112 6cb779da lstrcmpiW 103110->103112 103114 6cb779f3 lstrcmpiW 103112->103114 103120 6cb77a87 103112->103120 103116 6cb77a03 lstrcmpiW 103114->103116 103114->103120 103115 6cb69d41 13 API calls 103117 6cb779cf 103115->103117 103119 6cb77a13 lstrcmpiW 103116->103119 103116->103120 103121 6cb6694d error_info_injector RtlFreeHeap 103117->103121 103118 6cb6694d error_info_injector RtlFreeHeap 103122 6cb76faf 103118->103122 103119->103120 103123 6cb77a23 lstrcmpiW 103119->103123 103120->103118 103121->103112 103122->102919 103131 6cb76d20 103122->103131 103123->103120 103124 6cb77a33 lstrcmpiW 103123->103124 103124->103120 103125 6cb77a3f lstrcmpiW 103124->103125 103125->103120 103126 6cb77a4b lstrcmpiW 103125->103126 103126->103120 103127 6cb77a57 lstrcmpiW 103126->103127 103127->103120 103128 6cb77a63 lstrcmpiW 103127->103128 103128->103120 103129 6cb77a6f lstrcmpiW 103128->103129 103129->103120 103130 6cb77a7b lstrcmpiW 103129->103130 103130->103120 103132 6cb76d40 RegOpenKeyExW 103131->103132 103133 6cb76d3e 103131->103133 103134 6cb76d63 103132->103134 103133->103132 103134->102924 103134->102925 103134->102939 103136 6cb771b4 103135->103136 103136->102937 103139 6cb77226 103137->103139 103138 6cb77278 103138->102937 103139->103138 103140 6cb7725b SHQueryValueExW 103139->103140 103140->103138 103141->102937 103142->102941 103143->102937 103144->102937 103146 6cb6dddb 103145->103146 103147 6cb6dde6 103146->103147 103148 6cb6ddf8 103146->103148 103149 6cb69f92 12 API calls 103147->103149 103152 6cb6e2c3 15 API calls 103148->103152 103150 6cb6ddee 103149->103150 103150->103115 103152->103150 103154 6cb6d82b 103153->103154 103155 6cb6d818 103153->103155 103157 6cb76f8e 42 API calls 103154->103157 103272 6cb73964 13 API calls 2 library calls 103155->103272 103159 6cb6d850 103157->103159 103158 6cb6d81d 103158->103154 103162 6cb6d857 103159->103162 103248 6cb6d6ac 103159->103248 103161 6cb6d88b 103161->102948 103168 6cb68a16 103161->103168 103162->103161 103163 6cb6d6ac 2 API calls 103162->103163 103164 6cb6d878 103163->103164 103164->103161 103253 6cb6d702 103164->103253 103288 6cb688a6 103168->103288 103171 6cb6fdfb GetSystemTimeAsFileTime 103172 6cb68a37 103171->103172 103173 6cb68a5f 103172->103173 103176 6cb68301 21 API calls 103172->103176 103174 6cb68a74 103173->103174 103175 6cb68a6d 103173->103175 103179 6cb68a72 103173->103179 103298 6cb68992 63 API calls _Fputc 103174->103298 103297 6cb6890e 63 API calls _Fputc 103175->103297 103176->103173 103180 6cb66b74 103179->103180 103408 6cb68bb2 103180->103408 103184 6cb66e68 RaiseException 103183->103184 103185 6cb774e6 103184->103185 103186 6cb77946 27 API calls 103185->103186 103187 6cb774ee 103186->103187 103188 6cb76d20 RegOpenKeyExW 103187->103188 103189 6cb7754d 103187->103189 103190 6cb77518 103188->103190 103191 6cb6694d error_info_injector RtlFreeHeap 103189->103191 103192 6cb77534 103190->103192 103193 6cb77521 RegCloseKey 103190->103193 103194 6cb77557 103191->103194 103192->103189 103195 6cb77544 RegCloseKey 103192->103195 103193->103192 103194->102954 103194->102955 103195->103189 103197 6cb7b36d 103196->103197 103198 6cb7b3c9 103196->103198 103200 6cb68a16 63 API calls 103197->103200 103761 6cb7b3da 17 API calls 103198->103761 103202 6cb7b383 103200->103202 103201 6cb7b3d4 103247 6cb7aa73 RtlFreeHeap _SyncOriginator error_info_injector 103201->103247 103750 6cb7a72f 103202->103750 103205 6cb66b74 119 API calls 103206 6cb7b3b0 103205->103206 103207 6cb6694d error_info_injector RtlFreeHeap 103206->103207 103208 6cb7b3be 103207->103208 103209 6cb6694d error_info_injector RtlFreeHeap 103208->103209 103209->103198 103211 6cb66e68 RaiseException 103210->103211 103212 6cb76d97 103211->103212 103213 6cb77946 27 API calls 103212->103213 103214 6cb76d9f 103213->103214 103215 6cb76d20 RegOpenKeyExW 103214->103215 103216 6cb76da6 103214->103216 103215->103216 103217 6cb6694d error_info_injector RtlFreeHeap 103216->103217 103218 6cb76dc4 103217->103218 103218->102996 103219 6cb7f332 42 API calls 103218->103219 103219->102967 103220->102972 103221->102974 103222->102976 103223->102978 103224->102980 103225->102982 103226->102984 103227->102986 103228->102988 103229->103010 103230->103010 103231->103010 103233 6cb772bd 103232->103233 103234 6cb77334 103233->103234 103235 6cb772d1 103233->103235 103246 6cb77331 103233->103246 103236 6cb66ec7 15 API calls 103234->103236 103237 6cb77344 103235->103237 103240 6cb772d8 103235->103240 103236->103246 103238 6cb66655 RaiseException 103237->103238 103239 6cb772f5 103240->103239 103242 6cb6706e 15 API calls 103240->103242 103242->103239 103246->103010 103249 6cb6d6ba NetGetJoinInformation 103248->103249 103252 6cb6d6e2 103248->103252 103250 6cb6d6d3 NetApiBufferFree 103249->103250 103251 6cb6d6ce 103249->103251 103250->103252 103251->103162 103252->103162 103254 6cb6d710 103253->103254 103256 6cb6d730 103253->103256 103273 6cb73630 103254->103273 103256->103161 103261 6cb6d758 103256->103261 103259 6cb6d723 103259->103256 103277 6cb6b149 103259->103277 103262 6cb6d76a 103261->103262 103266 6cb6d7f7 103261->103266 103263 6cb6d788 GetProcAddress 103262->103263 103267 6cb6d7ae 103262->103267 103264 6cb6d7b6 FreeLibrary 103263->103264 103265 6cb6d798 FreeLibrary 103263->103265 103264->103267 103265->103267 103266->103161 103267->103266 103269 6cb6d7e1 GetProcAddress 103267->103269 103270 6cb6d7f4 FreeLibrary 103269->103270 103271 6cb6d7f1 103269->103271 103270->103266 103271->103270 103272->103158 103283 6cb7329b 103273->103283 103276 6cb73651 7 API calls 2 library calls 103276->103259 103278 6cb6b157 103277->103278 103279 6cb6b164 GetProcAddress 103278->103279 103280 6cb6b15d 103278->103280 103279->103280 103281 6cb6b18f 103280->103281 103282 6cb6b188 FreeLibrary 103280->103282 103281->103256 103282->103281 103284 6ccc5fe0 ___scrt_fastfail 103283->103284 103285 6cb732e1 VerSetConditionMask VerSetConditionMask VerSetConditionMask VerifyVersionInfoW 103284->103285 103286 6ccb0e3b _ValidateLocalCookies 5 API calls 103285->103286 103287 6cb6d71a 103286->103287 103287->103256 103287->103276 103289 6cb688b5 103288->103289 103291 6cb688e1 103288->103291 103310 6cb6f4e1 Sleep _Fputc 103289->103310 103290 6cb688e7 103290->103171 103290->103179 103291->103290 103299 6cb687e0 103291->103299 103294 6cb688c9 OutputDebugStringW 103295 6cb6694d error_info_injector RtlFreeHeap 103294->103295 103296 6cb688dd 103295->103296 103296->103290 103297->103179 103298->103179 103300 6cb687ec _Fputc 103299->103300 103301 6cb68822 103300->103301 103302 6cb687fb 103300->103302 103304 6cb68301 21 API calls 103301->103304 103309 6cb68828 103301->103309 103325 6cb6f4e1 Sleep _Fputc 103302->103325 103305 6cb68844 103304->103305 103305->103309 103311 6cb6871e 103305->103311 103306 6cb6880f OutputDebugStringW 103307 6cb68820 103306->103307 103307->103309 103309->103290 103310->103294 103326 6cb68652 103311->103326 103313 6cb68726 103314 6cb6873d 103313->103314 103316 6ccb16cf std::_Facet_Register 4 API calls 103313->103316 103353 6cb73641 103314->103353 103316->103314 103318 6cb6875f 103321 6cb68778 103318->103321 103322 6ccb16cf std::_Facet_Register 4 API calls 103318->103322 103319 6cb6878c 103357 6cb68604 8 API calls std::_Facet_Register 103319->103357 103321->103309 103323 6cb68770 103322->103323 103356 6cb72eae 10 API calls _ValidateLocalCookies 103323->103356 103325->103306 103327 6cb68664 103326->103327 103328 6cb686ba 103326->103328 103327->103328 103358 6cb6855c 103327->103358 103328->103313 103331 6cb686b2 103333 6cb6694d error_info_injector RtlFreeHeap 103331->103333 103332 6cb73cd5 16 API calls 103334 6cb68691 103332->103334 103333->103328 103335 6cb6e978 6 API calls 103334->103335 103336 6cb6869b 103335->103336 103337 6cb686bc 103336->103337 103338 6cb6bca2 19 API calls 103336->103338 103339 6ccb16cf std::_Facet_Register 4 API calls 103337->103339 103341 6cb686a6 103338->103341 103340 6cb686c9 103339->103340 103376 6cb690c5 16 API calls error_info_injector 103340->103376 103341->103337 103343 6cb686aa 103341->103343 103345 6cb6694d error_info_injector RtlFreeHeap 103343->103345 103344 6cb686d5 103346 6cb686f7 103344->103346 103347 6cb686df 103344->103347 103345->103331 103349 6cb6694d error_info_injector RtlFreeHeap 103346->103349 103377 6cb6f4e1 Sleep _Fputc 103347->103377 103351 6cb686ff 103349->103351 103350 6cb686ed OutputDebugStringW 103350->103346 103352 6cb6694d error_info_injector RtlFreeHeap 103351->103352 103352->103328 103354 6cb7329b 9 API calls 103353->103354 103355 6cb6875b 103354->103355 103355->103318 103355->103319 103356->103321 103357->103321 103378 6cb68450 103358->103378 103361 6cb68572 103368 6cb6694d error_info_injector RtlFreeHeap 103361->103368 103362 6cb6858a 103363 6cb685ab PathAppendW 103362->103363 103364 6cb6706e 15 API calls 103362->103364 103365 6cb69db6 15 API calls 103363->103365 103366 6cb685a8 103364->103366 103367 6cb685c3 103365->103367 103366->103363 103369 6cb685c7 103367->103369 103370 6cb685df 103367->103370 103375 6cb68585 103368->103375 103373 6cb6694d error_info_injector RtlFreeHeap 103369->103373 103371 6cb69f92 12 API calls 103370->103371 103372 6cb685ea 103371->103372 103374 6cb6694d error_info_injector RtlFreeHeap 103372->103374 103373->103375 103374->103375 103375->103331 103375->103332 103376->103344 103377->103350 103379 6cb68460 103378->103379 103380 6cb68480 103379->103380 103381 6cb6706e 15 API calls 103379->103381 103382 6cb74525 8 API calls 103380->103382 103381->103380 103383 6cb68490 103382->103383 103384 6cb7297e 22 API calls 103383->103384 103385 6cb68499 103383->103385 103384->103385 103386 6cb66f63 RaiseException 103385->103386 103387 6cb684bf SHGetFolderPathW 103386->103387 103388 6cb68502 PathAppendW 103387->103388 103389 6cb684d0 103387->103389 103390 6cb68523 103388->103390 103391 6cb68511 103388->103391 103392 6cb66e68 RaiseException 103389->103392 103394 6cb69f92 12 API calls 103390->103394 103393 6cb66e68 RaiseException 103391->103393 103395 6cb684dd 103392->103395 103393->103395 103396 6cb6852e 103394->103396 103397 6cb6694d error_info_injector RtlFreeHeap 103395->103397 103398 6cb6694d error_info_injector RtlFreeHeap 103396->103398 103399 6cb684e8 103397->103399 103400 6cb6853e 103398->103400 103401 6cb69db6 15 API calls 103399->103401 103402 6cb69db6 15 API calls 103400->103402 103404 6cb684f2 103401->103404 103403 6cb68548 103402->103403 103405 6cb6694d error_info_injector RtlFreeHeap 103403->103405 103406 6cb6694d error_info_injector RtlFreeHeap 103404->103406 103407 6cb684fd 103405->103407 103406->103407 103407->103361 103407->103362 103409 6cb66b91 103408->103409 103410 6cb68bc7 103408->103410 103409->102948 103410->103409 103411 6cb68c87 103410->103411 103412 6cb68c1a Sleep 103410->103412 103422 6cb68ade 103411->103422 103412->103410 103413 6cb68c3f OutputDebugStringA OutputDebugStringW OutputDebugStringW 103412->103413 103415 6cb68ca1 103413->103415 103416 6cb68c69 103413->103416 103418 6cb6694d error_info_injector RtlFreeHeap 103415->103418 103417 6cb68ade 115 API calls 103416->103417 103419 6cb68c85 103417->103419 103420 6cb68cbb 103418->103420 103419->103415 103421 6cb6694d error_info_injector RtlFreeHeap 103420->103421 103421->103409 103423 6cb68aea _Fputc 103422->103423 103426 6cb68b24 103423->103426 103433 6cb69de2 103423->103433 103437 6cb67209 103423->103437 103427 6cb69db6 15 API calls 103426->103427 103428 6cb68b2e 103427->103428 103441 6cb67f7f 103428->103441 103434 6cb69df1 103433->103434 103435 6cb66efc 15 API calls 103434->103435 103436 6cb69dfd 103435->103436 103436->103423 103438 6cb6721e __vswprintf_c_l 103437->103438 103451 6cccd13b 103438->103451 103442 6cb67fe7 GetCurrentThreadId GetCurrentProcessId 103441->103442 103443 6cb68005 103442->103443 103444 6ccb0e3b _ValidateLocalCookies 5 API calls 103443->103444 103445 6cb68015 103444->103445 103446 6cb68ded 103445->103446 103447 6cb68df9 _Fputc 103446->103447 103448 6cb68b62 103447->103448 103470 6cb691ee 103447->103470 103488 6cb6984d 103447->103488 103448->103415 103454 6ccc9ca6 103451->103454 103453 6cb67228 103453->103423 103455 6ccc9cb2 103454->103455 103457 6ccc9cc7 103454->103457 103466 6ccc95ee 11 API calls _Deallocate 103455->103466 103459 6ccc9cd8 103457->103459 103461 6ccc9d0d 103457->103461 103462 6ccc9d3a 103457->103462 103465 6ccc9ce1 103459->103465 103469 6ccc95ee 11 API calls _Deallocate 103459->103469 103467 6ccc9f27 13 API calls 3 library calls 103461->103467 103468 6ccc9f27 13 API calls 3 library calls 103462->103468 103465->103453 103467->103459 103468->103459 103471 6cb691f7 103470->103471 103472 6cb6926f 103470->103472 103524 6cb6929d 103471->103524 103472->103447 103489 6cb69866 103488->103489 103490 6cb69861 103488->103490 103492 6cb699ce 103489->103492 103493 6cb699d7 3 API calls 103489->103493 103491 6cb691ee 100 API calls 103490->103491 103491->103489 103492->103447 103494 6cb69877 103493->103494 103494->103492 103495 6cb6987f SetFilePointer 103494->103495 103496 6cb698b3 SetFilePointer 103495->103496 103497 6cb6989e 103495->103497 103498 6cb69933 103496->103498 103499 6cb698d0 103496->103499 103497->103496 103500 6cb698a4 103497->103500 103504 6cb6999d WriteFile 103498->103504 103505 6cb69941 lstrlenW WriteFile 103498->103505 103506 6cb6995b 103498->103506 103502 6cb698d7 lstrlenW WriteFile 103499->103502 103503 6cb698f1 103499->103503 103747 6cb6964d CreateFileW WriteFile CloseHandle 103500->103747 103502->103498 103508 6cb66e68 RaiseException 103503->103508 103504->103492 103514 6cb699c5 ReleaseMutex 103504->103514 103505->103504 103509 6cb66e68 RaiseException 103506->103509 103507 6cb698ab 103507->103492 103507->103496 103510 6cb698fa 103508->103510 103512 6cb69964 103509->103512 103748 6cb70add RaiseException RtlFreeHeap 103510->103748 103749 6cb70add RaiseException RtlFreeHeap 103512->103749 103514->103492 103516 6cb69907 103518 6cb6694d error_info_injector RtlFreeHeap 103516->103518 103517 6cb69971 103519 6cb6694d error_info_injector RtlFreeHeap 103517->103519 103520 6cb69913 WriteFile 103518->103520 103521 6cb6997d WriteFile 103519->103521 103522 6cb6694d error_info_injector RtlFreeHeap 103520->103522 103523 6cb6694d error_info_injector RtlFreeHeap 103521->103523 103522->103498 103523->103504 103621 6cb69af3 103524->103621 103529 6cb69d41 13 API calls 103530 6cb692cd 103529->103530 103531 6cb6694d error_info_injector RtlFreeHeap 103530->103531 103532 6cb692d8 103531->103532 103533 6cb6694d error_info_injector RtlFreeHeap 103532->103533 103534 6cb692e3 103533->103534 103641 6cb6b338 103534->103641 103622 6cb69b08 103621->103622 103623 6cb69b47 103622->103623 103626 6cb69b0e 103622->103626 103624 6cb66655 RaiseException 103623->103624 103625 6cb69b51 103624->103625 103627 6cb69f44 15 API calls 103626->103627 103628 6cb692b9 103627->103628 103629 6cb67e49 103628->103629 103630 6cb67e63 103629->103630 103631 6cb67e68 103630->103631 103638 6cb67e77 103630->103638 103632 6cb69f92 12 API calls 103631->103632 103633 6cb67e70 103632->103633 103633->103529 103634 6cb67eb5 103635 6cb69f92 12 API calls 103634->103635 103636 6cb67ec3 103635->103636 103637 6cb6694d error_info_injector RtlFreeHeap 103636->103637 103637->103633 103638->103634 103639 6cb69ebd RaiseException 103638->103639 103640 6cb69e05 15 API calls 103638->103640 103639->103638 103640->103638 103642 6cb6b35c 103641->103642 103643 6cb6749c 16 API calls 103642->103643 103644 6cb6b36e 103643->103644 103645 6cb67884 23 API calls 103644->103645 103646 6cb6b383 103645->103646 103647 6cb6756d RtlFreeHeap 103646->103647 103648 6cb6b38b 103647->103648 103649 6cb6749c 16 API calls 103648->103649 103650 6cb6b3a2 103649->103650 103651 6cb67884 23 API calls 103650->103651 103747->103507 103748->103516 103749->103517 103751 6cb66e68 RaiseException 103750->103751 103759 6cb7a752 103751->103759 103752 6cb7a8fb 103753 6ccb0e3b _ValidateLocalCookies 5 API calls 103752->103753 103755 6cb7a909 103753->103755 103755->103205 103756 6cb66e68 RaiseException 103756->103759 103758 6cb6694d RtlFreeHeap error_info_injector 103758->103759 103759->103752 103759->103756 103759->103758 103762 6cb7a90d 12 API calls 103759->103762 103763 6cb6c532 103759->103763 103770 6cb7a95d RtlFreeHeap error_info_injector 103759->103770 103761->103201 103762->103759 103764 6cb6c555 ___scrt_fastfail 103763->103764 103765 6cb6c565 CharUpperW 103764->103765 103766 6cb66e68 RaiseException 103765->103766 103767 6cb6c57a 103766->103767 103768 6ccb0e3b _ValidateLocalCookies 5 API calls 103767->103768 103769 6cb6c588 103768->103769 103769->103759 103771->102801 103772->102803 103774 6cb74104 103773->103774 103793 6cb7425c 103774->103793 103776 6cb74113 __vswprintf_c_l 103777 6cb74184 103776->103777 103779 6cb74144 103776->103779 103778 6cb66655 RaiseException 103777->103778 103789 6cb7418e 103778->103789 103801 6cb6fadc RaiseException RtlFreeHeap 103779->103801 103781 6cb741bd 103781->102804 103782 6cb74150 103802 6cb6fbb5 RaiseException 103782->103802 103784 6cb74174 103785 6cb6694d error_info_injector RtlFreeHeap 103784->103785 103786 6cb7417f 103785->103786 103786->102804 103787 6cb74236 103788 6cb69db6 15 API calls 103787->103788 103788->103781 103789->103781 103789->103787 103790 6cb69db6 15 API calls 103789->103790 103790->103789 103791->102806 103792->102809 103800 6cb74275 _strlen 103793->103800 103794 6cb7428a 103794->103776 103796 6cb74301 103806 6cb72476 RaiseException __vswprintf_c_l 103796->103806 103800->103794 103800->103796 103803 6cb6fadc RaiseException RtlFreeHeap 103800->103803 103804 6cb74066 41 API calls __vswprintf_c_l 103800->103804 103805 6cb72476 RaiseException __vswprintf_c_l 103800->103805 103801->103782 103802->103784 103803->103800 103804->103800 103805->103800 103806->103794 103807 6cb8b2bc 103820 6cb7934e 103807->103820 103810 6cb7934e Concurrency::wait RaiseException 103811 6cb8b311 103810->103811 103816 6cb8b320 103811->103816 103824 6cb8abfe 388 API calls 2 library calls 103811->103824 103812 6cb68a16 63 API calls 103813 6cb8b2f2 103812->103813 103815 6cb66b74 119 API calls 103813->103815 103817 6cb8b307 103815->103817 103818 6cb6694d error_info_injector RtlFreeHeap 103816->103818 103817->103810 103819 6cb8b32f 103818->103819 103821 6cb79357 103820->103821 103822 6cb79368 103820->103822 103821->103822 103823 6cb7935b RaiseException 103821->103823 103822->103812 103822->103817 103823->103822 103824->103816 103825 53b496 103826 53b4a2 CallCatchBlock 103825->103826 103851 53b7af 103826->103851 103828 53b4a9 103829 53b5fc 103828->103829 103836 53b4d3 ___scrt_is_nonwritable_in_current_image ___scrt_release_startup_lock CallCatchBlock 103828->103836 103898 53baa0 IsProcessorFeaturePresent IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter ___scrt_fastfail 103829->103898 103831 53b603 103899 540873 23 API calls CallCatchBlock 103831->103899 103833 53b609 103900 540837 23 API calls CallCatchBlock 103833->103900 103835 53b611 103837 53b4f2 103836->103837 103838 53b573 103836->103838 103894 54084d 34 API calls 4 library calls 103836->103894 103862 53bbba 103838->103862 103840 53b579 103866 53aa5b GetModuleHandleW GetProcAddress 103840->103866 103852 53b7b8 103851->103852 103901 53bd7e IsProcessorFeaturePresent 103852->103901 103854 53b7c4 103902 53dc6c 10 API calls 2 library calls 103854->103902 103856 53b7c9 103861 53b7cd 103856->103861 103903 540e72 103856->103903 103858 53b7e4 103858->103828 103861->103828 103959 53d880 103862->103959 103865 53bbe0 103865->103840 103867 53aa95 GetCommandLineW 103866->103867 103868 53aa8e 103866->103868 103869 53aaa5 103867->103869 104035 539cb0 103867->104035 103868->103867 103961 53921b 103869->103961 103875 53aae9 GetProcAddress 103880 53ab2b 103875->103880 103881 53ab0b GetLastError 103875->103881 103876 53aabe 104039 53a9d0 41 API calls __ehhandler$___std_fs_get_stats@16 103876->104039 103879 53aac7 103885 53aadc 103879->103885 104040 539683 93 API calls 2 library calls 103879->104040 103890 6cb7b487 207 API calls 103880->103890 103995 6cb798f1 103880->103995 104001 6cb7d80b InitOnceExecuteOnce 103880->104001 104002 6cb66cb1 103880->104002 103881->103885 104041 5392b7 FreeLibrary 103885->104041 103890->103885 103894->103838 103898->103831 103899->103833 103900->103835 103901->103854 103902->103856 103907 543a81 103903->103907 103906 53dc8b 7 API calls 2 library calls 103906->103861 103908 543a91 103907->103908 103909 53b7d6 103907->103909 103908->103909 103911 542de8 103908->103911 103909->103858 103909->103906 103912 542df4 CallCatchBlock 103911->103912 103923 5417c8 EnterCriticalSection 103912->103923 103914 542dfb 103924 542a89 103914->103924 103916 542e0a 103922 542e19 103916->103922 103935 542c7e 17 API calls 103916->103935 103919 542e2a 103919->103908 103920 542e14 103936 542d34 GetStdHandle GetFileType 103920->103936 103937 542e3f LeaveCriticalSection CallCatchBlock 103922->103937 103923->103914 103925 542a95 CallCatchBlock 103924->103925 103926 542a9e 103925->103926 103927 542abf 103925->103927 103946 541a28 14 API calls _free 103926->103946 103938 5417c8 EnterCriticalSection 103927->103938 103930 542af7 103947 542b1e LeaveCriticalSection CallCatchBlock 103930->103947 103931 542acb 103931->103930 103939 5429d9 103931->103939 103934 542aa3 ___std_exception_copy 103934->103916 103935->103920 103936->103922 103937->103919 103938->103931 103948 541a3b 103939->103948 103941 5429f8 103956 541a98 14 API calls _free 103941->103956 103944 542a4d 103944->103931 103945 5429eb 103945->103941 103955 5438bf 6 API calls _free 103945->103955 103946->103934 103947->103934 103953 541a48 _free 103948->103953 103949 541a88 103958 541a28 14 API calls _free 103949->103958 103950 541a73 RtlAllocateHeap 103951 541a86 103950->103951 103950->103953 103951->103945 103953->103949 103953->103950 103957 53fd4a EnterCriticalSection LeaveCriticalSection _free 103953->103957 103955->103945 103956->103944 103957->103953 103958->103951 103960 53bbcd GetStartupInfoW 103959->103960 103960->103865 103962 53d880 ___scrt_fastfail 103961->103962 103963 53925c GetModuleFileNameW 103962->103963 103964 539276 103963->103964 103965 5392a4 103963->103965 104049 53a219 27 API calls 103964->104049 104042 53b187 103965->104042 103968 5392b3 103975 5395c7 103968->103975 103969 539289 104050 538447 16 API calls 103969->104050 103971 539290 104051 538be4 11 API calls ___scrt_uninitialize_crt 103971->104051 103973 539299 104052 539da9 103973->104052 104058 538e69 SHGetKnownFolderPath 103975->104058 103987 539da9 11 API calls 103989 539673 103987->103989 103991 53b187 __ehhandler$___std_fs_get_stats@16 5 API calls 103989->103991 103990 539635 LoadLibraryExW 103992 53964e 103990->103992 103993 539642 GetLastError 103990->103993 103994 539681 103991->103994 103992->103987 103993->103992 103994->103875 103994->103876 103996 6cb798fe GetProcAddress 103995->103996 103998 6cb798f7 103995->103998 103997 6cb7990e WerRegisterCustomMetadata 103996->103997 103996->103998 103997->103998 103999 6cb79926 103998->103999 104000 6cb7991f FreeLibrary 103998->104000 103999->103885 104000->103999 104001->103885 104003 6cb68a16 63 API calls 104002->104003 104004 6cb66cbb 104003->104004 104005 6cb66b74 119 API calls 104004->104005 104006 6cb66cde 104005->104006 104007 6cb66d39 104006->104007 104009 6cb68a16 63 API calls 104006->104009 104206 6cb6c8e7 GetCurrentProcess 104007->104206 104011 6cb66cf9 104009->104011 104200 6cb66b93 104011->104200 104012 6cb66e17 104015 6cb66e50 104012->104015 104017 6cb68a16 63 API calls 104012->104017 104014 6ccb16cf std::_Facet_Register 4 API calls 104019 6cb66d60 104014->104019 104015->103885 104020 6cb66e3c 104017->104020 104018 6cb66b74 119 API calls 104021 6cb66d2a 104018->104021 104229 6cb8a8b8 104019->104229 104023 6cb66b74 119 API calls 104020->104023 104024 6cb6694d error_info_injector RtlFreeHeap 104021->104024 104023->104015 104024->104007 104025 6cb66d71 _AnonymousOriginator 104026 6cb66e0e 104025->104026 104028 6cb68a16 63 API calls 104025->104028 104256 6cb8c9f1 GetTickCount SetEvent Sleep GetTickCount _AnonymousOriginator 104026->104256 104029 6cb66ddd 104028->104029 104030 6cb66b93 15 API calls 104029->104030 104031 6cb66ded 104030->104031 104032 6cb66b74 119 API calls 104031->104032 104033 6cb66dff 104032->104033 104034 6cb6694d error_info_injector RtlFreeHeap 104033->104034 104034->104026 104036 539cce 104035->104036 104036->104036 104328 539dd7 104036->104328 104038 539ce8 104038->103869 104039->103879 104040->103885 104043 53b192 IsProcessorFeaturePresent 104042->104043 104044 53b190 104042->104044 104046 53b1d4 104043->104046 104044->103968 104056 53b198 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 104046->104056 104048 53b2b7 104048->103968 104049->103969 104050->103971 104051->103973 104053 539db4 104052->104053 104055 539dc3 104052->104055 104057 53a6d0 11 API calls _Deallocate 104053->104057 104055->103965 104056->104048 104057->104055 104059 53a025 3 API calls 104058->104059 104060 538ea1 104059->104060 104062 538ee1 104060->104062 104144 53a9aa 27 API calls 104060->104144 104064 539da9 11 API calls 104062->104064 104066 538efe 104062->104066 104063 538ecf 104145 538c4f 104063->104145 104064->104066 104067 539cb0 27 API calls 104066->104067 104068 538f13 CoTaskMemFree 104067->104068 104069 53b187 __ehhandler$___std_fs_get_stats@16 5 API calls 104068->104069 104070 538f2b 104069->104070 104071 538d5f GetModuleFileNameW 104070->104071 104072 538d9b 104071->104072 104073 538e3f 104071->104073 104072->104073 104074 53a025 3 API calls 104072->104074 104075 539cb0 27 API calls 104073->104075 104076 538dae 104074->104076 104077 538e58 104075->104077 104177 53a219 27 API calls 104076->104177 104078 53b187 __ehhandler$___std_fs_get_stats@16 5 API calls 104077->104078 104080 538e67 104078->104080 104091 538cc1 104080->104091 104081 538dc7 104082 538c1b 48 API calls 104081->104082 104083 538de2 104082->104083 104090 538e11 104083->104090 104178 53a219 27 API calls 104083->104178 104085 538df9 104087 538c4f 48 API calls 104085->104087 104086 538e34 104089 539da9 11 API calls 104086->104089 104087->104090 104088 539da9 11 API calls 104088->104086 104089->104073 104090->104086 104090->104088 104094 538ccd 104091->104094 104100 538d30 104091->104100 104092 539da9 11 API calls 104093 538d52 104092->104093 104095 539da9 11 API calls 104093->104095 104094->104100 104179 53a1da 35 API calls 104094->104179 104097 538d5a 104095->104097 104101 5392d0 104097->104101 104098 538d00 104180 53a1da 35 API calls 104098->104180 104100->104092 104102 53a025 3 API calls 104101->104102 104103 5392f7 104102->104103 104104 538c4f 48 API calls 104103->104104 104105 53930b 104104->104105 104106 539311 104105->104106 104181 539cf0 27 API calls ___scrt_uninitialize_crt 104105->104181 104109 53b187 __ehhandler$___std_fs_get_stats@16 5 API calls 104106->104109 104108 53932f 104182 53a254 27 API calls __ehhandler$___std_fs_get_stats@16 104108->104182 104111 5393ee 104109->104111 104136 53a025 104111->104136 104112 53933d 104113 539da9 11 API calls 104112->104113 104114 53934e 104113->104114 104115 538c1b 48 API calls 104114->104115 104116 539359 104115->104116 104119 53935d 104116->104119 104183 5397da 28 API calls 2 library calls 104116->104183 104118 539376 104184 539cf0 27 API calls ___scrt_uninitialize_crt 104118->104184 104122 539da9 11 API calls 104119->104122 104121 53937f 104185 53a9aa 27 API calls 104121->104185 104122->104106 104124 53939e 104186 5382db 27 API calls 104124->104186 104126 5393ad 104127 539da9 11 API calls 104126->104127 104128 5393b7 104127->104128 104187 53a254 27 API calls __ehhandler$___std_fs_get_stats@16 104128->104187 104130 5393bf 104188 539cf0 27 API calls ___scrt_uninitialize_crt 104130->104188 104132 5393c7 104133 539da9 11 API calls 104132->104133 104134 5393cf 104133->104134 104135 539da9 11 API calls 104134->104135 104135->104119 104189 53c905 104136->104189 104139 538c1b 104140 538c4f 48 API calls 104139->104140 104141 538c2f 104140->104141 104142 538c3e 104141->104142 104143 53a025 3 API calls 104141->104143 104142->103990 104142->103992 104143->104142 104144->104063 104146 538c78 104145->104146 104153 53c400 104146->104153 104148 538c88 104149 53a025 3 API calls 104148->104149 104150 538ca0 104149->104150 104151 53b187 __ehhandler$___std_fs_get_stats@16 5 API calls 104150->104151 104152 538cbf 104151->104152 104152->104062 104157 53c46a 104153->104157 104154 53c46e 104155 53b187 __ehhandler$___std_fs_get_stats@16 5 API calls 104154->104155 104159 53c73a 104155->104159 104156 53c514 104174 53c743 CreateFileW GetLastError 104156->104174 104157->104154 104157->104156 104158 53c4bb GetFileAttributesExW 104157->104158 104161 53c4d7 104158->104161 104162 53c4cc GetLastError 104158->104162 104159->104148 104161->104154 104161->104156 104162->104154 104163 53c539 104171 53c666 104163->104171 104175 53bfad GetModuleHandleW GetProcAddress 104163->104175 104166 53c71d 104166->104154 104167 53c66d GetFileInformationByHandle 104168 53c680 104167->104168 104169 53c59e GetLastError 104167->104169 104170 53c6c7 FindFirstFileExW 104168->104170 104168->104171 104169->104171 104170->104169 104172 53c6ed FindClose 104170->104172 104176 53c0bd 35 API calls _unexpected 104171->104176 104172->104171 104173 53c562 104173->104167 104173->104169 104173->104171 104174->104163 104175->104173 104176->104166 104177->104081 104178->104085 104179->104098 104180->104100 104181->104108 104182->104112 104183->104118 104184->104121 104185->104124 104186->104126 104187->104130 104188->104132 104192 53cced 104189->104192 104193 53ccfb InitOnceExecuteOnce 104192->104193 104194 53cd13 104192->104194 104196 539612 104193->104196 104194->104196 104197 53cd30 SwitchToThread 104194->104197 104198 53cd6b SetLastError 104194->104198 104199 53cd49 104194->104199 104196->103992 104196->104139 104197->104194 104198->104196 104199->104196 104199->104198 104201 6cb66bb2 104200->104201 104202 6cb66baa 104200->104202 104204 6cb66e68 RaiseException 104201->104204 104257 6cb68ff4 15 API calls 104202->104257 104205 6cb66bb0 104204->104205 104205->104018 104258 6cb6ae6a 104206->104258 104209 6cb6c933 104279 6cb781c1 GetLastError RaiseException Concurrency::wait 104209->104279 104210 6cb6c93c 104262 6cb6e583 104210->104262 104212 6cb6c938 104275 6cb6aea7 104212->104275 104216 6cb6c962 104221 6cb6749c 16 API calls 104216->104221 104217 6cb6c959 104280 6cb781c1 GetLastError RaiseException Concurrency::wait 104217->104280 104218 6cb6c9af 104219 6ccb0e3b _ValidateLocalCookies 5 API calls 104218->104219 104222 6cb66d47 104219->104222 104224 6cb6c978 104221->104224 104222->104012 104222->104014 104223 6cb6c95e 104227 6cb6756d RtlFreeHeap 104223->104227 104281 6cb6a519 IsValidSid EqualSid 104224->104281 104226 6cb6c98b 104228 6cb6756d RtlFreeHeap 104226->104228 104227->104212 104228->104223 104230 6cb8a8cd 104229->104230 104284 6cb80525 EnterCriticalSection LeaveCriticalSection 104230->104284 104232 6cb8a911 104285 6cb74525 AllocateAndInitializeSid 104232->104285 104235 6cb8a91f 104290 6ccb2c0d 104235->104290 104238 6cb8a937 104239 6cb76f8e 42 API calls 104238->104239 104240 6cb8a963 104239->104240 104241 6cb7934e Concurrency::wait RaiseException 104240->104241 104242 6cb8a96f 104241->104242 104243 6ccb16cf std::_Facet_Register 4 API calls 104242->104243 104244 6cb8a982 104243->104244 104245 6cb8a9c0 CreateEventW 104244->104245 104246 6cb8a9a7 104244->104246 104248 6cb8a9e0 104245->104248 104250 6cb8a9ee 104245->104250 104298 6cbc54bb RaiseException CloseHandle 104246->104298 104249 6cb8a9e4 CloseHandle 104248->104249 104248->104250 104249->104250 104255 6cb8a9fc 104250->104255 104299 6cb781c1 GetLastError RaiseException Concurrency::wait 104250->104299 104251 6cb7934e Concurrency::wait RaiseException 104254 6cb8aa05 104251->104254 104252 6cb8a9ae _AnonymousOriginator 104252->104245 104254->104025 104255->104251 104256->104012 104257->104205 104259 6cb6ae77 GetCurrentProcess 104258->104259 104260 6cb6ae7d OpenProcessToken 104258->104260 104259->104260 104261 6cb6ae8f 104260->104261 104261->104209 104261->104210 104263 6cb6e5a5 GetTokenInformation GetLastError 104262->104263 104273 6cb6e633 104262->104273 104264 6cb6e5c5 104263->104264 104263->104273 104268 6cb6e5e2 ctype 104264->104268 104282 6cb6e083 RaiseException RtlAllocateHeap _Yarn 104264->104282 104265 6ccb0e3b _ValidateLocalCookies 5 API calls 104267 6cb6c955 104265->104267 104267->104216 104267->104217 104269 6cb6e620 104268->104269 104270 6cb6e5fd GetTokenInformation 104268->104270 104269->104273 104274 6ccc972c numpunct 2 API calls 104269->104274 104270->104269 104271 6cb6e616 104270->104271 104283 6cb6a4b8 21 API calls 104271->104283 104273->104265 104274->104269 104276 6cb6aeb0 104275->104276 104277 6cb6aecc FindCloseChangeNotification 104276->104277 104278 6cb6aed9 _AnonymousOriginator 104276->104278 104277->104278 104278->104218 104279->104212 104280->104223 104281->104226 104282->104268 104283->104269 104284->104232 104286 6cb7458b 104285->104286 104287 6cb74568 CheckTokenMembership FreeSid 104285->104287 104288 6ccb0e3b _ValidateLocalCookies 5 API calls 104286->104288 104287->104286 104289 6cb74599 104288->104289 104289->104235 104297 6cb7297e 22 API calls error_info_injector 104289->104297 104300 6ccb235b 104290->104300 104296 6ccb2c44 104296->104238 104297->104235 104298->104252 104299->104255 104301 6ccb236a 104300->104301 104302 6ccb2371 104300->104302 104319 6ccd1219 6 API calls std::_Lockit::_Lockit 104301->104319 104304 6ccb236f 104302->104304 104320 6cc43668 EnterCriticalSection 104302->104320 104306 6ccd10d3 104304->104306 104307 6ccd10df _Fputc 104306->104307 104321 6ccd11ba EnterCriticalSection 104307->104321 104309 6ccd10ea __Getctype 104322 6ccd1134 104309->104322 104312 6ccb23b3 104313 6ccb23bd 104312->104313 104314 6ccd1227 104312->104314 104315 6ccb23d0 104313->104315 104326 6cc436aa LeaveCriticalSection 104313->104326 104327 6ccd1202 LeaveCriticalSection 104314->104327 104315->104296 104318 6ccd122e 104318->104296 104319->104304 104320->104304 104321->104309 104325 6ccd1202 LeaveCriticalSection 104322->104325 104324 6ccb2c3b 104324->104312 104325->104324 104326->104315 104327->104318 104329 539e10 104328->104329 104331 539de5 __InternalCxxFrameHandler 104328->104331 104332 53a48e 27 API calls 2 library calls 104329->104332 104331->104038 104332->104331 104333 6cb8b5f3 104334 6cb8b6f1 104333->104334 104335 6cb8b606 104333->104335 104367 6cb8bcc7 104334->104367 104337 6cb8b77a 104335->104337 104338 6cb8b633 104335->104338 104339 6cb8b614 104335->104339 104340 6cb68a16 63 API calls 104337->104340 104345 6cb8b62c 104337->104345 104397 6cb93e58 InitializeCriticalSectionAndSpinCount GetLastError GetCurrentThreadId 104338->104397 104339->104337 104342 6cb8b625 104339->104342 104339->104345 104343 6cb8b7a0 104340->104343 104396 6cb8b982 382 API calls 2 library calls 104342->104396 104347 6cb66b74 119 API calls 104343->104347 104344 6cb8b644 104398 6cb93ee4 212 API calls 104344->104398 104347->104345 104349 6cb8b64b 104399 6cb8cea4 DecodePointer DeleteCriticalSection DeleteCriticalSection 104349->104399 104368 6cb8bcf8 104367->104368 104369 6cb8bd2b 104367->104369 104371 6cb68a16 63 API calls 104368->104371 104370 6cb69f92 12 API calls 104369->104370 104372 6cb8bd38 104370->104372 104373 6cb8bd14 104371->104373 104400 6cb8be7e 104372->104400 104375 6cb66b74 119 API calls 104373->104375 104375->104369 104376 6cb8bd88 104377 6cb8bd9d 104376->104377 104378 6cb8be10 104376->104378 104439 6cb8029d 267 API calls __aulldiv 104377->104439 104423 6cbd9dc5 104378->104423 104379 6cb8bd50 104379->104376 104385 6cb66f63 RaiseException 104379->104385 104382 6cb8be0a 104386 6cb7934e Concurrency::wait RaiseException 104382->104386 104383 6cb8bdc3 104383->104382 104384 6cbd9dc5 819 API calls 104383->104384 104387 6cb8bdfa 104384->104387 104385->104376 104388 6cb8be4c 104386->104388 104387->104382 104440 6cb8035b 210 API calls __aulldiv 104387->104440 104441 6cb8aa0e 12 API calls error_info_injector 104388->104441 104396->104345 104397->104344 104398->104349 104401 6cb69f92 12 API calls 104400->104401 104402 6cb8bedc 104401->104402 104403 6cb69f92 12 API calls 104402->104403 104404 6cb8beeb 104403->104404 104405 6cb69f92 12 API calls 104404->104405 104406 6cb8befa 104405->104406 104407 6cb69f92 12 API calls 104406->104407 104408 6cb8bf09 104407->104408 104409 6cb69f92 12 API calls 104408->104409 104410 6cb8bf18 104409->104410 104411 6cb69f92 12 API calls 104410->104411 104412 6cb8bf27 104411->104412 104413 6cb69f92 12 API calls 104412->104413 104414 6cb8bf36 104413->104414 104415 6cb69f92 12 API calls 104414->104415 104416 6cb8bf45 104415->104416 104417 6cb69f92 12 API calls 104416->104417 104418 6cb8bf54 104417->104418 104419 6cb69f92 12 API calls 104418->104419 104420 6cb8bf63 104419->104420 104442 6cb8bf7d 104420->104442 104475 6cb80525 EnterCriticalSection LeaveCriticalSection 104423->104475 104425 6cbd9ddc 104426 6cbd9dec 104425->104426 104547 6cb80525 EnterCriticalSection LeaveCriticalSection 104425->104547 104432 6cbd9e10 104426->104432 104548 6cb73620 104426->104548 104429 6cbd9eb4 104476 6cbd9665 104429->104476 104432->104429 104437 6cbd9e7f 104432->104437 104433 6cbd9eb2 104433->104382 104434 6cb74525 8 API calls 104435 6cbd9e02 104434->104435 104435->104432 104551 6cb80525 EnterCriticalSection LeaveCriticalSection 104435->104551 104437->104433 104552 6cbd9ba6 807 API calls 2 library calls 104437->104552 104439->104383 104440->104382 104443 6cb69f92 12 API calls 104442->104443 104444 6cb8bf97 104443->104444 104445 6cb69f92 12 API calls 104444->104445 104446 6cb8bfb3 104445->104446 104447 6cb69f92 12 API calls 104446->104447 104448 6cb8bfc5 104447->104448 104449 6cb69f92 12 API calls 104448->104449 104450 6cb8bfd4 104449->104450 104451 6cb69f92 12 API calls 104450->104451 104452 6cb8bfe3 104451->104452 104453 6cb69f92 12 API calls 104452->104453 104454 6cb8bff2 104453->104454 104455 6cb69f92 12 API calls 104454->104455 104456 6cb8c001 104455->104456 104457 6cb8bf74 104456->104457 104458 6cb8c04b 104456->104458 104459 6cb8c087 104456->104459 104457->104379 104465 6cb6a2e0 104458->104465 104473 6cb67441 11 API calls 104459->104473 104462 6cb8c054 104462->104457 104472 6cb8f1e3 12 API calls 104462->104472 104466 6cb6a2f6 104465->104466 104467 6cb6a2ed 104465->104467 104469 6cb6a302 104466->104469 104471 6ccb16cf std::_Facet_Register 4 API calls 104466->104471 104474 6cb67441 15 API calls 3 library calls 104467->104474 104469->104462 104470 6cb6a2f3 104470->104462 104471->104470 104472->104462 104474->104470 104475->104425 104477 6cbd96b6 104476->104477 104553 6cb6d40b 104477->104553 104479 6cbd96c1 104480 6cb66e68 RaiseException 104479->104480 104481 6cbd96dc 104480->104481 104563 6cb83628 104481->104563 104484 6cb6694d error_info_injector RtlFreeHeap 104485 6cbd96ff 104484->104485 104486 6cb69f92 12 API calls 104485->104486 104487 6cbd9720 104486->104487 104488 6cb6c532 7 API calls 104487->104488 104489 6cbd9731 104487->104489 104488->104489 104490 6cb69f92 12 API calls 104489->104490 104491 6cbd9775 104490->104491 104492 6cbd9795 104491->104492 104494 6cb6694d error_info_injector RtlFreeHeap 104491->104494 104493 6cbd97ac 104492->104493 104495 6cb6694d error_info_injector RtlFreeHeap 104492->104495 104496 6cbd99d5 104493->104496 104499 6cb74525 8 API calls 104493->104499 104494->104492 104495->104493 104497 6cbd99de lstrcmpiW 104496->104497 104498 6cbd9a13 104496->104498 104501 6cbd99f0 lstrcmpiW 104497->104501 104502 6cbd9a02 104497->104502 104507 6cbd9866 104498->104507 104574 6cc9d2b4 104498->104574 104500 6cbd97c0 104499->104500 104500->104496 104516 6cbd97c8 104500->104516 104501->104498 104501->104502 104633 6cbdaac8 118 API calls error_info_injector 104502->104633 104511 6cb6694d error_info_injector RtlFreeHeap 104507->104511 104513 6cbd9b71 104511->104513 104519 6cb6694d error_info_injector RtlFreeHeap 104513->104519 104517 6cbd9824 104516->104517 104533 6cbd97f7 104516->104533 104628 6cbd8895 192 API calls error_info_injector 104516->104628 104630 6cbd925d 564 API calls 2 library calls 104517->104630 104522 6cbd9b79 104519->104522 104525 6cb6694d error_info_injector RtlFreeHeap 104522->104525 104529 6cbd9b87 104525->104529 104526 6cbd9937 104528 6cb69f92 12 API calls 104526->104528 104530 6cbd9947 104528->104530 104531 6cb6694d error_info_injector RtlFreeHeap 104529->104531 104532 6cb8be7e 16 API calls 104530->104532 104534 6cbd9b95 104531->104534 104535 6cbd9961 104532->104535 104533->104507 104533->104526 104539 6cbd98c6 104533->104539 104629 6cbdabbd 113 API calls error_info_injector 104533->104629 104536 6ccb0e3b _ValidateLocalCookies 5 API calls 104534->104536 104631 6cbd81e1 16 API calls error_info_injector 104535->104631 104540 6cbd9ba4 104536->104540 104539->104517 104539->104526 104540->104433 104541 6cbd997d 104542 6cbd9665 815 API calls 104541->104542 104543 6cbd99b2 104542->104543 104632 6cb8aa0e 12 API calls error_info_injector 104543->104632 104547->104426 104549 6cb7329b 9 API calls 104548->104549 104550 6cb7362d 104549->104550 104550->104432 104550->104434 104551->104432 104552->104437 104554 6cb6d432 104553->104554 104555 6cb6d454 104554->104555 104556 6cb6c532 7 API calls 104554->104556 104557 6ccb0e3b _ValidateLocalCookies 5 API calls 104555->104557 104558 6cb6d441 104556->104558 104559 6cb6d462 104557->104559 104560 6cb69d41 13 API calls 104558->104560 104559->104479 104561 6cb6d449 104560->104561 104562 6cb6694d error_info_injector RtlFreeHeap 104561->104562 104562->104555 104638 6cb82aef 104563->104638 104566 6cb76d85 28 API calls 104567 6cb8365f 104566->104567 104568 6cb83673 104567->104568 104569 6cb77290 17 API calls 104567->104569 104570 6cb6694d error_info_injector RtlFreeHeap 104568->104570 104569->104568 104571 6cb8367e 104570->104571 104572 6cb83690 104571->104572 104573 6cb83687 RegCloseKey 104571->104573 104572->104484 104573->104572 104674 6cca4820 104574->104674 104576 6cc9d2d9 104677 6cca33be 104576->104677 104580 6cc9d32f 104683 6cbc773a 104580->104683 104582 6cc9d33a 104686 6cca4fc5 CreateSolidBrush 104582->104686 104584 6cc9d3b2 104585 6cb69d41 13 API calls 104584->104585 104586 6cc9d3bc 104585->104586 104587 6cb69d41 13 API calls 104586->104587 104588 6cc9d3c6 104587->104588 104687 6cbdacee 104588->104687 104628->104533 104629->104539 104630->104507 104631->104541 104633->104498 104639 6cb7b487 207 API calls 104638->104639 104640 6cb82afe 104639->104640 104641 6cb66e68 RaiseException 104640->104641 104642 6cb82b15 104641->104642 104647 6cb6c616 104642->104647 104645 6cb6694d error_info_injector RtlFreeHeap 104646 6cb82b2e 104645->104646 104646->104566 104648 6cb69f92 12 API calls 104647->104648 104652 6cb6c62e 104648->104652 104649 6cb6c64f 104651 6cb6dd87 15 API calls 104649->104651 104653 6cb6c65f 104651->104653 104652->104649 104672 6cb69ebd RaiseException 104652->104672 104654 6cb69d41 13 API calls 104653->104654 104655 6cb6c668 104654->104655 104656 6cb6694d error_info_injector RtlFreeHeap 104655->104656 104657 6cb6c673 104656->104657 104658 6cb69f92 12 API calls 104657->104658 104663 6cb6c680 104658->104663 104659 6cb6c6a5 104660 6cb6ddcc 15 API calls 104659->104660 104662 6cb6c6b7 104660->104662 104664 6cb69d41 13 API calls 104662->104664 104663->104659 104673 6cb69ebd RaiseException 104663->104673 104665 6cb6c6c0 104664->104665 104666 6cb6694d error_info_injector RtlFreeHeap 104665->104666 104667 6cb6c6cb 104666->104667 104668 6cb6694d error_info_injector RtlFreeHeap 104667->104668 104669 6cb6c6f0 104668->104669 104670 6cb6694d error_info_injector RtlFreeHeap 104669->104670 104671 6cb6c6f8 104670->104671 104671->104645 104672->104652 104673->104663 104694 6cca434f 104674->104694 104678 6ccb16cf std::_Facet_Register 4 API calls 104677->104678 104679 6cca33e2 104678->104679 104709 6cbb81d5 104679->104709 104682 6cb7319e InitializeCriticalSection 104682->104580 104725 6cb73254 104683->104725 104686->104584 104688 6cb69f92 12 API calls 104687->104688 104707 6cca3df1 CreateSolidBrush CreateSolidBrush 104694->104707 104696 6cca4389 104697 6cb69d41 13 API calls 104696->104697 104698 6cca43b1 104697->104698 104699 6cb6694d error_info_injector RtlFreeHeap 104698->104699 104700 6cca43bc 104699->104700 104701 6cca3df1 2 API calls 104700->104701 104702 6cca43c4 104701->104702 104703 6cb69d41 13 API calls 104702->104703 104704 6cca43ef 104703->104704 104705 6cb6694d error_info_injector RtlFreeHeap 104704->104705 104706 6cca43fa 104705->104706 104706->104576 104708 6cca3e3b 104707->104708 104708->104696 104710 6cbb81f0 104709->104710 104717 6cbb8217 104709->104717 104711 6cbb8249 104710->104711 104712 6cbb81f7 104710->104712 104723 6cb67441 11 API calls 104711->104723 104714 6cb6a2e0 15 API calls 104712->104714 104716 6cbb8203 104714->104716 104716->104717 104719 6cb6a110 104716->104719 104717->104682 104720 6cb6a12a _AnonymousOriginator 104719->104720 104721 6cb6a11d 104719->104721 104720->104717 104724 6cb67456 11 API calls 2 library calls 104721->104724 104724->104720 104730 6cb73073 104725->104730 104728 6cb73275 CreateEventW 104729 6cb73268 104728->104729 104729->104582 104731 6cb7307d 104730->104731 104732 6cb730c2 104731->104732 104733 6cb73620 9 API calls 104731->104733 104732->104728 104732->104729 104734 6cb7308b 104733->104734 104734->104732 104735 6cb7308f GetModuleHandleW 104734->104735 104735->104732 104736 6cb730a0 GetProcAddress GetProcAddress 104735->104736 104736->104732 107004 53ac5e 107005 53ac68 107004->107005 107008 53af18 107005->107008 107034 53ac79 107008->107034 107011 53af85 107041 53aeb6 6 API calls 2 library calls 107011->107041 107012 53afa9 107015 53b021 LoadLibraryExA 107012->107015 107016 53b082 107012->107016 107020 53b094 107012->107020 107023 53b150 107012->107023 107014 53af90 RaiseException 107029 53ac75 107014->107029 107015->107016 107017 53b034 GetLastError 107015->107017 107016->107020 107021 53b08d FreeLibrary 107016->107021 107018 53b05d 107017->107018 107025 53b047 107017->107025 107042 53aeb6 6 API calls 2 library calls 107018->107042 107019 53b0f2 GetProcAddress 107019->107023 107024 53b102 GetLastError 107019->107024 107020->107019 107020->107023 107021->107020 107044 53aeb6 6 API calls 2 library calls 107023->107044 107028 53b115 107024->107028 107025->107016 107025->107018 107026 53b068 RaiseException 107026->107029 107028->107023 107043 53aeb6 6 API calls 2 library calls 107028->107043 107031 53b136 RaiseException 107032 53ac79 ___delayLoadHelper2@8 6 API calls 107031->107032 107033 53b14d 107032->107033 107033->107023 107035 53ac85 107034->107035 107038 53aca6 107034->107038 107045 53ad1f GetModuleHandleW GetProcAddress GetProcAddress DloadGetSRWLockFunctionPointers 107035->107045 107037 53ac8a 107037->107038 107039 53ac9a 107037->107039 107038->107011 107038->107012 107046 53ae48 VirtualQuery GetSystemInfo VirtualProtect DloadObtainSection DloadMakePermanentImageCommit 107039->107046 107041->107014 107042->107026 107043->107031 107044->107029 107045->107037 107046->107038 107047 6ccc9b41 107048 6ccd7d48 107047->107048 107049 6ccd7d80 RtlAllocateHeap 107048->107049 107050 6ccd7d93 107048->107050 107049->107050 107051 6cb72b3a 107052 6cb72b58 4 API calls 107051->107052 107053 6cb72b41 107052->107053 107054 6cb6694d error_info_injector RtlFreeHeap 107053->107054 107055 6cb72b50 107054->107055 107056 6cb8b069 107057 6cb8b074 107056->107057 107058 6cb66f63 RaiseException 107057->107058 107059 6cb8b07e GetProcessShutdownParameters 107058->107059 107060 6cb8b0a1 SetProcessShutdownParameters 107059->107060 107061 6cb8b0b7 107059->107061 107060->107061 107062 6cb8b0bc 107060->107062 107163 6cb781c1 GetLastError RaiseException Concurrency::wait 107061->107163 107098 6cb8c7cc 107062->107098 107065 6cb8b0c1 107066 6cb73620 9 API calls 107065->107066 107067 6cb8b0c6 107066->107067 107068 6cb8b0ca HeapSetInformation 107067->107068 107069 6cb8b0df 107067->107069 107068->107069 107070 6cb8b0da 107068->107070 107110 6cb7fcf9 EnterCriticalSection LeaveCriticalSection 107069->107110 107164 6cb781c1 GetLastError RaiseException Concurrency::wait 107070->107164 107073 6cb8b0ff 107074 6cb8b163 107073->107074 107076 6cb68a16 63 API calls 107073->107076 107111 6cbe0810 107074->107111 107078 6cb8b125 107076->107078 107080 6cb66b93 15 API calls 107078->107080 107082 6cb8b139 107080->107082 107083 6cb66b74 119 API calls 107082->107083 107084 6cb8b155 107083->107084 107086 6cb6694d error_info_injector RtlFreeHeap 107084->107086 107086->107074 107165 6cb736df 7 API calls 2 library calls 107098->107165 107100 6cb8c7f3 107101 6cb8c7f9 107100->107101 107166 6cb7fcf9 EnterCriticalSection LeaveCriticalSection 107100->107166 107101->107065 107103 6cb8c810 107167 6cb7fcf9 EnterCriticalSection LeaveCriticalSection 107103->107167 107105 6cb8c820 107168 6cb7fcf9 EnterCriticalSection LeaveCriticalSection 107105->107168 107107 6cb8c830 107169 6cb7fcf9 EnterCriticalSection LeaveCriticalSection 107107->107169 107109 6cb8c840 107109->107065 107110->107073 107170 6cca5eb4 107111->107170 107113 6cbe0824 107183 6cca5f32 107113->107183 107116 6cbe087b 107293 6cca5f1c 107116->107293 107118 6ccb16cf std::_Facet_Register 4 API calls 107120 6cbe0842 107118->107120 107228 6cbf7778 107120->107228 107123 6cbe086d 107297 6cbf7764 RtlFreeHeap _AnonymousOriginator 107123->107297 107163->107062 107164->107069 107165->107100 107166->107103 107167->107105 107168->107107 107169->107109 107171 6ccb16cf std::_Facet_Register 4 API calls 107170->107171 107172 6cca5ec7 107171->107172 107298 6cc069c0 107172->107298 107176 6ccb16cf std::_Facet_Register 4 API calls 107178 6cca5ef1 107176->107178 107177 6cca5ee0 _AnonymousOriginator 107177->107176 107179 6cc069c0 4 API calls 107178->107179 107180 6cca5efb 107179->107180 107182 6cca5f0c _AnonymousOriginator 107180->107182 107302 6cc069e6 12 API calls _AnonymousOriginator 107180->107302 107182->107113 107184 6cb66e68 RaiseException 107183->107184 107185 6cca5f49 107184->107185 107303 6cb7250f 107185->107303 107187 6cca5ff6 CommandLineToArgvW 107188 6cca6019 107187->107188 107189 6cca600d 107187->107189 107223 6cca61e1 107188->107223 107309 6cca5cb9 12 API calls 107188->107309 107308 6cb781c1 GetLastError RaiseException Concurrency::wait 107189->107308 107191 6cca5fc3 107191->107187 107194 6cb69d41 13 API calls 107191->107194 107192 6cca6012 107201 6cb6694d error_info_injector RtlFreeHeap 107192->107201 107197 6cca5fe0 107194->107197 107195 6cca6207 LocalFree 107195->107192 107196 6cca6031 107310 6cca5cb9 12 API calls 107196->107310 107200 6cb6694d error_info_injector RtlFreeHeap 107197->107200 107198 6cca5f56 107198->107191 107307 6cb672c8 11 API calls 2 library calls 107198->107307 107202 6cca5feb 107200->107202 107203 6cbe082d 107201->107203 107205 6cb73e49 15 API calls 107202->107205 107203->107116 107203->107118 107207 6cca5ff3 107205->107207 107206 6cca5fb8 107208 6cb66efc 15 API calls 107206->107208 107207->107187 107208->107191 107209 6cca61d6 107210 6cb6694d error_info_injector RtlFreeHeap 107209->107210 107210->107223 107211 6cb66e68 RaiseException 107213 6cca603e 107211->107213 107212 6cb7250f 15 API calls 107212->107213 107213->107195 107213->107209 107213->107211 107213->107212 107215 6cca62df 16 API calls 107213->107215 107217 6cca6284 15 API calls 107213->107217 107222 6cca61e3 107213->107222 107224 6cb66efc 15 API calls 107213->107224 107225 6cb6ddcc 15 API calls 107213->107225 107226 6cb6694d RtlFreeHeap error_info_injector 107213->107226 107227 6cca5cd7 19 API calls 107213->107227 107311 6cb672c8 11 API calls 2 library calls 107213->107311 107312 6cca6224 RaiseException 107213->107312 107313 6cca5d20 19 API calls 107213->107313 107215->107213 107216 6cb6694d error_info_injector RtlFreeHeap 107218 6cca61f3 107216->107218 107217->107213 107221 6cb6694d error_info_injector RtlFreeHeap 107218->107221 107221->107223 107222->107216 107223->107195 107224->107213 107225->107213 107226->107213 107227->107213 107229 6ccb16cf std::_Facet_Register 4 API calls 107228->107229 107230 6cbf7788 107229->107230 107231 6ccb16cf std::_Facet_Register 4 API calls 107230->107231 107232 6cbf779c 107231->107232 107234 6cbf77bf _AnonymousOriginator 107232->107234 107324 6cca65dc RtlFreeHeap _AnonymousOriginator 107232->107324 107235 6cb66ec7 15 API calls 107234->107235 107236 6cbf77d9 107235->107236 107314 6cbf7c6b 107236->107314 107238 6cbf77e8 107239 6cbf7c6b 26 API calls 107238->107239 107240 6cbf7812 107239->107240 107241 6cbf7c6b 26 API calls 107240->107241 107242 6cbf7838 107241->107242 107243 6cbf7c6b 26 API calls 107242->107243 107244 6cbf7859 107243->107244 107245 6cbf7c6b 26 API calls 107244->107245 107246 6cbf787a 107245->107246 107247 6cbf7c6b 26 API calls 107246->107247 107248 6cbf789b 107247->107248 107249 6cbf7c6b 26 API calls 107248->107249 107250 6cbf78bc 107249->107250 107251 6cbf7c6b 26 API calls 107250->107251 107252 6cbf78dd 107251->107252 107253 6cbf7c6b 26 API calls 107252->107253 107254 6cbf78fe 107253->107254 107255 6cbf7c6b 26 API calls 107254->107255 107256 6cbf791f 107255->107256 107257 6cbf7c6b 26 API calls 107256->107257 107258 6cbf7930 107257->107258 107259 6cbf7c6b 26 API calls 107258->107259 107260 6cbf7941 107259->107260 107261 6cbf7c6b 26 API calls 107260->107261 107262 6cbf7952 107261->107262 107263 6cbf7c6b 26 API calls 107262->107263 107264 6cbf79a1 107263->107264 107265 6cbf7c6b 26 API calls 107264->107265 107266 6cbf79d0 107265->107266 107267 6cbf7c6b 26 API calls 107266->107267 107268 6cbf7a15 107267->107268 107269 6cbf7c6b 26 API calls 107268->107269 107270 6cbf7a4a 107269->107270 107271 6cbf7c6b 26 API calls 107270->107271 107272 6cbf7a76 107271->107272 107273 6cbf7c6b 26 API calls 107272->107273 107274 6cbf7a9d 107273->107274 107275 6cbf7c6b 26 API calls 107274->107275 107276 6cbf7ac3 107275->107276 107277 6cbf7c6b 26 API calls 107276->107277 107278 6cbf7ae5 107277->107278 107279 6cbf7c6b 26 API calls 107278->107279 107280 6cbf7b0a 107279->107280 107281 6cbf7c6b 26 API calls 107280->107281 107282 6cbf7b35 107281->107282 107283 6cbf7c6b 26 API calls 107282->107283 107284 6cbf7b5a 107283->107284 107285 6cbf7c6b 26 API calls 107284->107285 107286 6cbf7b7f 107285->107286 107287 6cbf7c6b 26 API calls 107286->107287 107288 6cbf7ba4 107287->107288 107289 6cbf7c6b 26 API calls 107288->107289 107290 6cbf7bcb 107289->107290 107291 6cb6694d error_info_injector RtlFreeHeap 107290->107291 107292 6cbe085c 107291->107292 107292->107123 107296 6cbf7bdd 16 API calls error_info_injector 107292->107296 107386 6cca63ad 12 API calls _AnonymousOriginator 107293->107386 107295 6cca5f27 107296->107123 107297->107116 107299 6ccb16cf std::_Facet_Register 4 API calls 107298->107299 107300 6cc069d1 107299->107300 107300->107177 107301 6cc069e6 12 API calls _AnonymousOriginator 107300->107301 107301->107177 107302->107182 107304 6cb72577 107303->107304 107305 6cb72520 107303->107305 107304->107198 107305->107304 107306 6cb66efc 15 API calls 107305->107306 107306->107304 107307->107206 107308->107192 107309->107196 107310->107213 107311->107213 107312->107213 107313->107213 107315 6cbf7c7c 107314->107315 107325 6cca66ed 107315->107325 107319 6cbf7cb8 107320 6cb6694d error_info_injector RtlFreeHeap 107319->107320 107321 6cbf7ccb 107320->107321 107322 6cb6694d error_info_injector RtlFreeHeap 107321->107322 107323 6cbf7cd6 107322->107323 107323->107238 107324->107234 107326 6cca5eb4 16 API calls 107325->107326 107327 6cca6700 107326->107327 107328 6cca5f32 26 API calls 107327->107328 107332 6cca670d 107328->107332 107329 6cca68ba 107330 6cca5f1c 12 API calls 107329->107330 107331 6cbf7ca8 107330->107331 107355 6cbf8617 107331->107355 107332->107329 107334 6cca6751 107332->107334 107368 6cca6ae9 RaiseException 107332->107368 107369 6cca65ed 18 API calls _Deallocate 107334->107369 107336 6cca68a1 107337 6cb69d41 13 API calls 107336->107337 107338 6cca689f 107337->107338 107342 6cb6694d error_info_injector RtlFreeHeap 107338->107342 107341 6cca688f 107344 6cb6694d error_info_injector RtlFreeHeap 107341->107344 107342->107329 107344->107338 107348 6cca675c 107348->107341 107349 6cb6694d error_info_injector RtlFreeHeap 107348->107349 107352 6cca67d7 107348->107352 107370 6cca5da2 13 API calls 107348->107370 107371 6cca5de3 16 API calls error_info_injector 107348->107371 107372 6cca6685 18 API calls std::_Facet_Register 107348->107372 107349->107348 107350 6ccb16cf std::_Facet_Register 4 API calls 107350->107352 107351 6cb66e68 RaiseException 107351->107352 107352->107336 107352->107341 107352->107350 107352->107351 107354 6cb6694d error_info_injector RtlFreeHeap 107352->107354 107373 6cca5da2 13 API calls 107352->107373 107374 6cca5de3 16 API calls error_info_injector 107352->107374 107375 6cca6ae9 RaiseException 107352->107375 107376 6cca6c81 17 API calls 2 library calls 107352->107376 107354->107352 107377 6cb790ea 107355->107377 107359 6cbf869d 107384 6cb78d9f 15 API calls 107359->107384 107360 6cbf865a 107382 6cbf86a3 16 API calls std::_Facet_Register 107360->107382 107362 6cbf8642 107362->107359 107362->107360 107367 6cbf8646 107362->107367 107364 6cbf866e 107383 6cbb8ecf RtlFreeHeap _AnonymousOriginator error_info_injector 107364->107383 107367->107319 107368->107332 107369->107348 107370->107348 107371->107348 107372->107348 107373->107352 107374->107352 107375->107352 107376->107352 107378 6cb79132 107377->107378 107380 6cb79106 107377->107380 107378->107362 107381 6cb79161 RaiseException 107378->107381 107380->107378 107385 6cb79161 RaiseException 107380->107385 107381->107362 107382->107364 107383->107367 107385->107380 107386->107295 107611 6ccdc51c 107612 6ccdc528 _Fputc 107611->107612 107613 6ccdc560 107612->107613 107617 6ccd11ba EnterCriticalSection 107612->107617 107615 6ccdc539 107618 6ccdc570 LeaveCriticalSection std::_Lockit::~_Lockit 107615->107618 107617->107615 107618->107613 107619 6cb67f24 lstrcmpiW 107620 6cb67f34 107619->107620 107621 6cb67f58 107619->107621 107625 6cb69e32 15 API calls 107620->107625 107622 6cb6694d error_info_injector RtlFreeHeap 107621->107622 107623 6cb67f64 107622->107623 107624 6cb6694d error_info_injector RtlFreeHeap 107623->107624 107626 6cb67f6f 107624->107626 107627 6cb67f4a 107625->107627 107628 6cb69e32 15 API calls 107627->107628 107628->107621 107629 6cb8b50e 107630 6cb8b513 107629->107630 107631 6cb7934e Concurrency::wait RaiseException 107630->107631 107632 6cb8b530 107631->107632 107633 6cb68a16 63 API calls 107632->107633 107636 6cb8b56f 107632->107636 107634 6cb8b55d 107633->107634 107635 6cb66b74 119 API calls 107634->107635 107635->107636 107637 6cb8ae4f 107650 6cb8ae5b 107637->107650 107638 6cb7934e Concurrency::wait RaiseException 107639 6cb8aefc 107638->107639 107642 6cb8af04 107639->107642 107646 6cb8af14 107639->107646 107640 6cb8af64 _AnonymousOriginator 107654 6cb7934e Concurrency::wait RaiseException 107640->107654 107665 6cb8af90 107640->107665 107641 6cb8af12 107641->107640 107678 6cbb7afa 15 API calls _AnonymousOriginator 107641->107678 107676 6cb8c6d7 10 API calls 107642->107676 107645 6cb8af3e 107677 6cbe4bdd 261 API calls 107645->107677 107646->107641 107646->107645 107649 6cb74525 8 API calls 107646->107649 107647 6cb8af0b 107652 6cb7934e Concurrency::wait RaiseException 107647->107652 107648 6cb8af5d 107679 6cbb79da 6 API calls 2 library calls 107648->107679 107655 6cb8af3a 107649->107655 107657 6cb7934e Concurrency::wait RaiseException 107650->107657 107674 6cb8aee5 107650->107674 107652->107641 107658 6cb8af81 107654->107658 107655->107641 107655->107645 107656 6cb8afd6 107667 6cb8afea _AnonymousOriginator 107656->107667 107680 6cb92f81 RtlFreeHeap error_info_injector 107656->107680 107660 6cb8ae94 107657->107660 107663 6cb803d8 43 API calls 107658->107663 107658->107665 107675 6cbe5269 157 API calls error_info_injector 107660->107675 107662 6cb8ae9e 107664 6cb7934e Concurrency::wait RaiseException 107662->107664 107663->107665 107666 6cb8aea7 107664->107666 107665->107656 107672 6cb74525 8 API calls 107665->107672 107669 6cb68a16 63 API calls 107666->107669 107666->107674 107670 6cb8b035 _AnonymousOriginator 107667->107670 107681 6cb7b4cc 11 API calls error_info_injector 107667->107681 107671 6cb8aed3 107669->107671 107673 6cb66b74 119 API calls 107671->107673 107672->107656 107673->107674 107674->107638 107674->107646 107675->107662 107676->107647 107677->107641 107678->107648 107679->107640 107682 6cb6dbee 107683 6cb6dc49 107682->107683 107684 6cb6dbf8 107682->107684 107686 6cb6694d error_info_injector RtlFreeHeap 107683->107686 107685 6cb66e68 RaiseException 107684->107685 107687 6cb6dc01 107685->107687 107688 6cb6dc54 107686->107688 107689 6cb73c34 16 API calls 107687->107689 107690 6cb6dc10 107689->107690 107696 6cb6b1d1 107690->107696 107693 6cb6694d error_info_injector RtlFreeHeap 107694 6cb6dc3e 107693->107694 107695 6cb6694d error_info_injector RtlFreeHeap 107694->107695 107695->107683 107697 6cb6b1ed LoadLibraryExW 107696->107697 107698 6cb6b1fb 107696->107698 107697->107693 107704 6ccb0f69 6 API calls 107698->107704 107700 6cb6b207 107700->107697 107701 6cb6b211 GetModuleHandleW GetProcAddress 107700->107701 107705 6ccb0f1f EnterCriticalSection LeaveCriticalSection RtlWakeAllConditionVariable SetEvent ResetEvent 107701->107705 107703 6cb6b233 107703->107697 107704->107700 107705->107703 107706 6ccd03f7 107709 6ccd029d 107706->107709 107710 6ccd02bd 107709->107710 107711 6ccd02ab 107709->107711 107722 6ccd0163 107710->107722 107730 6ccd0343 GetModuleHandleW 107711->107730 107714 6ccd02b0 107714->107710 107731 6ccd0386 GetModuleHandleExW GetProcAddress FreeLibrary 107714->107731 107716 6ccd02f8 107732 6ccd0301 13 API calls std::locale::_Setgloballocale 107716->107732 107717 6ccd02f6 107721 6ccd02bc 107721->107710 107723 6ccd016f _Fputc 107722->107723 107733 6ccd11ba EnterCriticalSection 107723->107733 107725 6ccd0179 107734 6ccd01b0 107725->107734 107729 6ccd0192 107729->107716 107729->107717 107730->107714 107731->107721 107733->107725 107735 6ccd01bc _Fputc 107734->107735 107739 6ccd021d 107735->107739 107741 6ccd0186 107735->107741 107743 6ccd0ddd EnterCriticalSection LeaveCriticalSection RtlFreeHeap GetLastError std::locale::_Setgloballocale 107735->107743 107736 6ccd0fc8 std::locale::_Setgloballocale 18 API calls 107736->107741 107740 6ccd023a 107739->107740 107744 6ccd0fc8 107739->107744 107740->107736 107742 6ccd01a4 LeaveCriticalSection std::_Lockit::~_Lockit 107741->107742 107742->107729 107743->107739 107745 6ccd1008 107744->107745 107746 6ccd0fec 107744->107746 107745->107740 107746->107745 107748 6cb62943 107746->107748 107749 6cb62953 107748->107749 107750 6cb6a2e0 15 API calls 107749->107750 107751 6cb62982 _Yarn 107750->107751 107932 6cc0c7e8 107751->107932 107754 6cb7a585 18 API calls 107755 6cb629ea 107754->107755 107756 6cc0c7e8 4 API calls 107755->107756 107757 6cb629f8 107756->107757 107758 6cb6a2e0 15 API calls 107757->107758 107759 6cb62a2a _Yarn 107758->107759 107935 6cc0c82e 107759->107935 107761 6cb62a66 107762 6cb6a2e0 15 API calls 107761->107762 107763 6cb62a9b _Yarn 107762->107763 107764 6cc0c7e8 4 API calls 107763->107764 107765 6cb62ada 107764->107765 107766 6cb6a2e0 15 API calls 107765->107766 107767 6cb62b0f _Yarn 107766->107767 107768 6cc0c7e8 4 API calls 107767->107768 107769 6cb62b4e 107768->107769 107770 6cb6a2e0 15 API calls 107769->107770 107771 6cb62b83 _Yarn 107770->107771 107772 6cc0c82e 4 API calls 107771->107772 107773 6cb62bbf 107772->107773 107774 6cb6a2e0 15 API calls 107773->107774 107775 6cb62bf4 _Yarn 107774->107775 107776 6cc0c82e 4 API calls 107775->107776 107777 6cb62c30 107776->107777 107778 6cb6a2e0 15 API calls 107777->107778 107779 6cb62c65 _Yarn 107778->107779 107780 6cc0c7e8 4 API calls 107779->107780 107781 6cb62ca1 107780->107781 107782 6cb6a2e0 15 API calls 107781->107782 107783 6cb62cd6 _Yarn 107782->107783 107784 6cc0c7e8 4 API calls 107783->107784 107785 6cb62d11 107784->107785 107786 6cb6a2e0 15 API calls 107785->107786 107787 6cb62d46 _Yarn 107786->107787 107788 6cc0c7e8 4 API calls 107787->107788 107789 6cb62d82 107788->107789 107790 6cb7a585 18 API calls 107789->107790 107791 6cb62daf 107790->107791 107792 6cc0c7e8 4 API calls 107791->107792 107793 6cb62dbd 107792->107793 107794 6cb7a585 18 API calls 107793->107794 107795 6cb62de7 107794->107795 107796 6cc0c82e 4 API calls 107795->107796 107797 6cb62df5 107796->107797 107798 6cb6a2e0 15 API calls 107797->107798 107799 6cb62e27 _Yarn 107798->107799 107938 6cc09c59 RaiseException RtlAllocateHeap EnterCriticalSection LeaveCriticalSection 107799->107938 107801 6cb62e66 107802 6cb6a2e0 15 API calls 107801->107802 107803 6cb62e9b _Yarn 107802->107803 107804 6cc0c7e8 4 API calls 107803->107804 107805 6cb62ed7 107804->107805 107806 6cb6a2e0 15 API calls 107805->107806 107807 6cb62f0c _Yarn 107806->107807 107808 6cc0c7e8 4 API calls 107807->107808 107809 6cb62f4b 107808->107809 107810 6cb6a2e0 15 API calls 107809->107810 107811 6cb62f80 _Yarn 107810->107811 107812 6cc0c7e8 4 API calls 107811->107812 107813 6cb62fbc 107812->107813 107814 6cb6a2e0 15 API calls 107813->107814 107815 6cb62ff1 _Yarn 107814->107815 107816 6cc0c82e 4 API calls 107815->107816 107817 6cb6302d 107816->107817 107818 6cb7a585 18 API calls 107817->107818 107819 6cb6305c 107818->107819 107939 6cc0d609 18 API calls 107819->107939 107821 6cb63073 107940 6cb7a541 18 API calls 107821->107940 107823 6cb63084 107824 6cc0c7e8 4 API calls 107823->107824 107825 6cb63095 107824->107825 107941 6cc0d62f 18 API calls 107825->107941 107827 6cb630a3 107942 6cc0d64f 18 API calls 107827->107942 107829 6cb630b1 107943 6cc0c5ba 18 API calls 107829->107943 107831 6cb630d8 107944 6cc09d08 15 API calls 107831->107944 107833 6cb630f4 107834 6cb7a585 18 API calls 107833->107834 107835 6cb63120 107834->107835 107945 6cc0d66f 18 API calls 107835->107945 107837 6cb6312e 107946 6cc0d68f 18 API calls 107837->107946 107839 6cb63149 107947 6cc0d68f 18 API calls 107839->107947 107841 6cb63164 107948 6cc0d68f 18 API calls 107841->107948 107843 6cb6317f 107949 6cc0c5ba 18 API calls 107843->107949 107845 6cb631a6 107950 6cc09d08 15 API calls 107845->107950 107847 6cb631c2 107848 6cb7a585 18 API calls 107847->107848 107849 6cb631ef 107848->107849 107951 6cc0d68f 18 API calls 107849->107951 107851 6cb6320a 107952 6cc0d6b5 18 API calls 107851->107952 107853 6cb63218 107953 6cc0d68f 18 API calls 107853->107953 107855 6cb63233 107954 6cc0c5ba 18 API calls 107855->107954 107857 6cb6325a 107955 6cc09d08 15 API calls 107857->107955 107859 6cb63276 107860 6cb7a585 18 API calls 107859->107860 107861 6cb632a3 107860->107861 107956 6cc0d6d5 18 API calls 107861->107956 107863 6cb632c1 107957 6cc0d6d5 18 API calls 107863->107957 107865 6cb632db 107958 6cc0d68f 18 API calls 107865->107958 107867 6cb632f6 107959 6cc0d6f9 18 API calls 107867->107959 107869 6cb63308 107960 6cc0c5ba 18 API calls 107869->107960 107871 6cb6332f 107961 6cc09d08 15 API calls 107871->107961 107873 6cb6334b 107874 6cb7a585 18 API calls 107873->107874 107875 6cb63372 107874->107875 107962 6cc0d68f 18 API calls 107875->107962 107877 6cb6338d 107963 6cc0c5ba 18 API calls 107877->107963 107879 6cb633b4 107964 6cc09d08 15 API calls 107879->107964 107881 6cb633cd 107971 6cbfab8c 107932->107971 107936 6cbfab8c 4 API calls 107935->107936 107937 6cc0c858 107936->107937 107937->107761 107938->107801 107939->107821 107940->107823 107941->107827 107942->107829 107943->107831 107944->107833 107945->107837 107946->107839 107947->107841 107948->107843 107949->107845 107950->107847 107951->107851 107952->107853 107953->107855 107954->107857 107955->107859 107956->107863 107957->107865 107958->107867 107959->107869 107960->107871 107961->107873 107962->107877 107963->107879 107964->107881 107972 6ccb16cf std::_Facet_Register 4 API calls 107971->107972 107973 6cb629bd 107972->107973 107973->107754 107974 6cb7d82a 107975 6ccc5fe0 ___scrt_fastfail 107974->107975 107976 6cb7d850 GetComputerNameExW 107975->107976 107977 6cb7d877 107976->107977 107978 6cb7d889 107976->107978 107984 6cb70a00 lstrlenW lstrlenW 107977->107984 107981 6cb7d88e 107978->107981 107986 6cb82887 LoadLibraryExW 107978->107986 107982 6ccb0e3b _ValidateLocalCookies 5 API calls 107981->107982 107983 6cb7d8ae 107982->107983 107985 6cb70a22 107984->107985 107985->107978 107987 6cb828a8 GetProcAddress GetProcAddress 107986->107987 107988 6cb828f7 107986->107988 107990 6cb828ca 107987->107990 107988->107981 107989 6cb828f0 FreeLibrary 107989->107988 107990->107988 107990->107989 107991 6cb8b187 107992 6cb8b194 107991->107992 107993 6cb8b338 288 API calls 107992->107993 107994 6cb8b19b 107993->107994 107995 6cb7934e Concurrency::wait RaiseException 107994->107995 107996 6cb8b1a4 107995->107996 107997 6cb68a16 63 API calls 107996->107997 108003 6cb8b1e7 107996->108003 107998 6cb8b1d5 107997->107998 108000 6cb66b74 119 API calls 107998->108000 107999 6cb8b245 108001 6cb6694d error_info_injector RtlFreeHeap 107999->108001 108000->108003 108002 6cb8b32f 108001->108002 108003->107999 108004 6cb6694d error_info_injector RtlFreeHeap 108003->108004 108004->107999

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 640 6cc40ec8-6cc40ef0 call 6cbe440a 643 6cc40ef2-6cc40f0d call 6cb7b487 call 6cb7c3d4 640->643 644 6cc40f0f-6cc40f22 call 6cb7b487 call 6cb7b778 640->644 653 6cc40f2c-6cc40f40 call 6cb69f92 643->653 644->653 656 6cc40f50-6cc40f52 653->656 657 6cc40f42-6cc40f4b call 6cb6694d 653->657 659 6cc40f54-6cc40f5d call 6cb6694d 656->659 660 6cc40f62-6cc40f66 656->660 657->656 659->660 662 6cc40f72-6cc40fc0 call 6ccc5fe0 call 6cb66e68 call 6cb6dca8 FindFirstFileW 660->662 663 6cc40f68-6cc40f6d 660->663 675 6cc40fe0-6cc41049 call 6cb66e68 call 6cb66f27 PathStripPathW call 6cb69db6 call 6cb66e68 call 6cb66f27 PathStripPathW call 6cb69db6 662->675 676 6cc40fc2-6cc40fcc GetLastError 662->676 664 6cc411c2-6cc411da call 6cb6694d call 6ccb0e3b 663->664 691 6cc4104e-6cc4107f call 6cb66e68 call 6cb6dca8 675->691 677 6cc411b4-6cc411bd call 6cb6694d 676->677 678 6cc40fd2-6cc40fdb 676->678 677->664 678->677 696 6cc41081-6cc41090 call 6cccd38d 691->696 697 6cc41098-6cc410a7 call 6cccd1f2 691->697 702 6cc41118-6cc41136 call 6cb6694d FindNextFileW 696->702 704 6cc41096 696->704 697->702 703 6cc410a9-6cc410be call 6cccd1f2 697->703 702->691 711 6cc4113c-6cc41147 GetLastError 702->711 703->702 712 6cc410c0-6cc410d3 call 6cccd38d 703->712 707 6cc41111-6cc41113 call 6cb6c344 704->707 707->702 713 6cc41158-6cc4117c call 6cb7b487 call 6cb777a6 call 6cb7b487 711->713 714 6cc41149-6cc4114b 711->714 712->702 721 6cc410d5-6cc410eb call 6cccd38d 712->721 735 6cc41183-6cc4118a call 6cb777a6 713->735 736 6cc4117e 713->736 716 6cc41191-6cc411ae call 6cb6694d * 2 FindClose 714->716 717 6cc4114d-6cc41156 714->717 716->677 717->716 721->702 730 6cc410ed-6cc41103 call 6cccd38d 721->730 730->702 737 6cc41105-6cc4110f 730->737 739 6cc4118f 735->739 736->735 737->702 737->707 739->716
              APIs
                • Part of subcall function 6CB6DCA8: PathAppendW.SHLWAPI(00000001,00000000,00000002,00000000,?,6CB808A2,MicrosoftEdgeUpdate.exe,00000010,00000000,00000001,00000000,00000001,?,6CB80A72,00000001,00000000), ref: 6CB6DCD3
              • FindFirstFileW.KERNELBASE(00000000,?,*.*,00000010,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\), ref: 6CC40FB1
              • GetLastError.KERNEL32 ref: 6CC40FC2
              • PathStripPathW.SHLWAPI(00000000,00000000,Microsoft\EdgeUpdate\Download), ref: 6CC4100B
              • PathStripPathW.SHLWAPI(00000000,00000000,Microsoft\EdgeUpdate\Install,000000FF), ref: 6CC4103F
              • FindNextFileW.KERNELBASE(?,00000010,?,00000010,000000FF), ref: 6CC4112E
              • GetLastError.KERNEL32 ref: 6CC4113C
              • FindClose.KERNEL32(?), ref: 6CC411AE
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Path$Find$ErrorFileLastStrip$AppendCloseFirstNext
              • String ID: *.*$HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$MicrosoftEdgeUpdate.exe$Microsoft\EdgeUpdate\Download$Microsoft\EdgeUpdate\Install
              • API String ID: 3679874643-4167518834
              • Opcode ID: fa4a618e658968d2c9affcb7e88f41660e7c67d916438f1d118f76c302be049c
              • Instruction ID: 2850d5271f3b7689cf9053eeaf4cb202ae7ba4ddb4f0889e3acfccf6fe3671d8
              • Opcode Fuzzy Hash: fa4a618e658968d2c9affcb7e88f41660e7c67d916438f1d118f76c302be049c
              • Instruction Fuzzy Hash: 4281C231A042999BDF14DB75CC88BEDB378AF15328F2081A9D455E7A90EF309A89CF10
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1233 6cb81913-6cb81969 call 6cb76d85 1236 6cb8196f-6cb8198a call 6cb77bfd 1233->1236 1237 6cb81bc0-6cb81bd1 1233->1237 1243 6cb81bbe 1236->1243 1244 6cb81990-6cb819b0 call 6cb69d8f call 6cb77c22 1236->1244 1239 6cb81bdb-6cb81beb call 6ccb0e3b 1237->1239 1240 6cb81bd3-6cb81bd9 RegCloseKey 1237->1240 1240->1239 1243->1237 1250 6cb819c0-6cb819fb call 6cb76d20 1244->1250 1251 6cb819b2-6cb819bb 1244->1251 1257 6cb819fd-6cb81a0d 1250->1257 1258 6cb81a26-6cb81a4a call 6cb69d8f call 6cb77290 1250->1258 1253 6cb81b9e-6cb81bb8 call 6cb6694d 1251->1253 1253->1243 1253->1244 1260 6cb81b9b 1257->1260 1261 6cb81a13-6cb81a21 RegCloseKey 1257->1261 1266 6cb81a5c-6cb81aa4 call 6cb80433 CreateFileW 1258->1266 1267 6cb81a4c-6cb81a5a call 6cb6694d 1258->1267 1260->1253 1263 6cb81b91 1261->1263 1263->1260 1272 6cb81ab0-6cb81ae8 DeviceIoControl 1266->1272 1273 6cb81aa6-6cb81aab call 6cb781c1 1266->1273 1267->1257 1275 6cb81aea-6cb81af1 1272->1275 1276 6cb81b55-6cb81b5a call 6cb781c1 1272->1276 1281 6cb81b61-6cb81b80 call 6cb6694d 1273->1281 1275->1276 1279 6cb81af3-6cb81b53 call 6cb69d8f call 6cb70d13 call 6cb70510 call 6cb69a7a call 6cb6694d * 2 1275->1279 1285 6cb81b5b CloseHandle 1276->1285 1279->1285 1281->1260 1289 6cb81b82-6cb81b8a RegCloseKey 1281->1289 1285->1281 1289->1263
              APIs
              • RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards,00020019,00000000,HKLM\Software\Microsoft\EdgeUpdate\,?), ref: 6CB81BD9
                • Part of subcall function 6CB77BFD: RegQueryInfoKeyW.ADVAPI32(6CB76BD7,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,6CD3F7F0,?,6CB8C8CC,HKLM\Software\Microsoft\EdgeUpdate\ClientState\), ref: 6CB77C17
                • Part of subcall function 6CB77C22: RegEnumKeyExW.KERNELBASE(6CB76BD7,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6CB77C5E
              • RegCloseKey.ADVAPI32(?,ServiceName,?,00000000,?,00020019,00000000,?,HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards,00020019,00000000,HKLM\Software\Microsoft\EdgeUpdate\,?), ref: 6CB81A19
              Strings
              • HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards, xrefs: 6CB81941
              • \\.\%s, xrefs: 6CB81A68
              • ServiceName, xrefs: 6CB81A38
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CB8192E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$EnumInfoQuery
              • String ID: HKLM\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards$ServiceName$\\.\%s
              • API String ID: 1723547527-3249094225
              • Opcode ID: 3edf0eea02fbc785a6b62d6d6aeb65674f19f685eef3caac5034599c6aa33338
              • Instruction ID: f5fd39acda8a245db300409d621cf2e963767bf9a796444ee80253bb441ffe18
              • Opcode Fuzzy Hash: 3edf0eea02fbc785a6b62d6d6aeb65674f19f685eef3caac5034599c6aa33338
              • Instruction Fuzzy Hash: 48717071902268ABDB20DF94DC99BDDB774EF08714F1001D9E529B66A0EB349F88CF90
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1298 6cb6c9c6-6cb6c9df 1299 6cb6c9e1-6cb6c9e8 call 6cb73620 1298->1299 1300 6cb6ca1f-6cb6ca2f ShellExecuteExW 1298->1300 1299->1300 1310 6cb6c9ea call 6cb6b0fa 1299->1310 1302 6cb6ca35-6cb6ca3a 1300->1302 1303 6cb6cadc-6cb6cae2 GetLastError 1300->1303 1305 6cb6ca3c-6cb6ca54 call 6cb7562f 1302->1305 1306 6cb6ca99-6cb6caaa 1302->1306 1307 6cb6cae4-6cb6caea 1303->1307 1317 6cb6ca86-6cb6ca8d AllowSetForegroundWindow 1305->1317 1318 6cb6ca56-6cb6ca7e call 6cb68a16 call 6cb66b74 1305->1318 1306->1307 1311 6cb6caac-6cb6cada call 6cb68a16 call 6cb66b74 1306->1311 1308 6cb6caf3-6cb6caf7 1307->1308 1309 6cb6caec-6cb6caed DestroyWindow 1307->1309 1314 6cb6cafb-6cb6cb0c SetLastError 1308->1314 1309->1308 1319 6cb6c9ef-6cb6c9f3 1310->1319 1311->1307 1317->1307 1330 6cb6ca83 1318->1330 1322 6cb6ca8f-6cb6ca97 GetLastError 1319->1322 1323 6cb6c9f9-6cb6ca03 1319->1323 1322->1314 1323->1300 1326 6cb6ca05-6cb6ca16 call 6cccd38d 1323->1326 1326->1300 1332 6cb6ca18-6cb6ca19 SetForegroundWindow 1326->1332 1330->1317 1332->1300
              APIs
              • SetForegroundWindow.USER32(00000000), ref: 6CB6CA19
              • ShellExecuteExW.SHELL32(?), ref: 6CB6CA20
              • AllowSetForegroundWindow.USER32(00000000), ref: 6CB6CA87
              • GetLastError.KERNEL32(00000007,0000003C,?,?,?,?,?,?,?,6CB75E7D,?,?,00000001), ref: 6CB6CA8F
                • Part of subcall function 6CB6B0FA: KiUserCallbackDispatcher.NTDLL(?), ref: 6CB6B139
              • GetLastError.KERNEL32(?,?,?,?,?,?,?,6CB75E7D,?,?,00000001), ref: 6CB6CADC
              • DestroyWindow.USER32(?,?,?,?,?,?,?,6CB75E7D,?,?,00000001), ref: 6CB6CAED
              • SetLastError.KERNEL32(00000000,?,?,?,?,?,?,6CB75E7D,?,?,00000001), ref: 6CB6CAFC
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorLastWindow$Foreground$AllowCallbackDestroyDispatcherExecuteShellUser
              • String ID: [Started process][%u]$[Started process][PID unknown]$runas
              • API String ID: 2229796612-1668918608
              • Opcode ID: cefc6dab5cf8cb7180b404a956a5499e86e91f7299a60f4a05c593bc22d1b93e
              • Instruction ID: 40494c3a41fe68e5d1f31ab61531418fbb5045312c40059de80136bd44a262eb
              • Opcode Fuzzy Hash: cefc6dab5cf8cb7180b404a956a5499e86e91f7299a60f4a05c593bc22d1b93e
              • Instruction Fuzzy Hash: 9631E6716093819FDB04EF76D84056F7BE8DF8A285B10592EF5A9D2E50E730C5098762
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(kernel32.dll,SetDefaultDllDirectories), ref: 0053AA7D
              • GetProcAddress.KERNEL32(00000000), ref: 0053AA84
              • GetCommandLineW.KERNEL32 ref: 0053AA95
              • GetProcAddress.KERNEL32(?,DllEntry), ref: 0053AB01
              • GetLastError.KERNEL32 ref: 0053AB0B
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3518826290.0000000000531000.00000020.00000001.01000000.00000012.sdmp, Offset: 00530000, based on PE: true
              • Associated: 00000009.00000002.3518772049.0000000000530000.00000002.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518888720.000000000054A000.00000004.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518947315.000000000054C000.00000002.00000001.01000000.00000012.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_530000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressProc$CommandErrorHandleLastLineModule
              • String ID: DllEntry$SetDefaultDllDirectories$kernel32.dll
              • API String ID: 2270256407-3472957018
              • Opcode ID: 0ddf7fb56e4bf2d5e3d5744f600c6da37bcf10031b36f899c6906abeecfeb8c1
              • Instruction ID: 687f684875564f3fb6f829e40b4cd3343c094877f8bf6fc9d5131856047eba1f
              • Opcode Fuzzy Hash: 0ddf7fb56e4bf2d5e3d5744f600c6da37bcf10031b36f899c6906abeecfeb8c1
              • Instruction Fuzzy Hash: FB21B7779092129BC710ABA4DC1A99FBFA0BF94314F050519B8C5A7191DF70ED04D7D3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcess.KERNEL32(00001000,?,?,?,?,?,?,?,?,?,?,?,?,6CB74FC7), ref: 6CB75FD7
              • OpenProcessToken.ADVAPI32(00000000,00000028,?,?,?,?,?,?,?,?,?,?,?,?,?,6CB74FC7), ref: 6CB75FE4
              • LookupPrivilegeValueW.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6CB75FFE
              • AdjustTokenPrivileges.KERNELBASE(?,00000000,?,00000000,00000000,00000000), ref: 6CB7602D
              • FindCloseChangeNotification.KERNELBASE(00000000), ref: 6CB76047
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ProcessToken$AdjustChangeCloseCurrentFindLookupNotificationOpenPrivilegePrivilegesValue
              • String ID: SeDebugPrivilege
              • API String ID: 4140947299-2896544425
              • Opcode ID: 9fbb7c3948601ac96ad61d178ecd2fb4d796769b7f19f6d18fe683c3606f0d73
              • Instruction ID: aee47f492b0c690ca98dfc0099a83728213ca7ce368ba125c461109069178d19
              • Opcode Fuzzy Hash: 9fbb7c3948601ac96ad61d178ecd2fb4d796769b7f19f6d18fe683c3606f0d73
              • Instruction Fuzzy Hash: BA110DB0A01269ABEF119FA5C849AEFBFBCEF09745F000119EA11E2280D7749544CBA5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetFileInformationByHandle.KERNELBASE(?,?), ref: 6CB67E0E
              • GetLastError.KERNEL32(?,?), ref: 6CB67E18
              • OutputDebugStringW.KERNEL32(00000000,?,?), ref: 6CB67E2C
              Strings
              • LOG_SYSTEM: ERROR - [::GetFileInformationByHandle failed][%d], xrefs: 6CB67E1F
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DebugErrorFileHandleInformationLastOutputString
              • String ID: LOG_SYSTEM: ERROR - [::GetFileInformationByHandle failed][%d]
              • API String ID: 2968764131-979073235
              • Opcode ID: 4861b92d502b97ff068902854e32cdcc839a4914ffcb82483d1d48f5cd81c596
              • Instruction ID: 362608fd23c9e2b5bb41345ae53e930aab1e0d893a4b55fc5063080263a6014f
              • Opcode Fuzzy Hash: 4861b92d502b97ff068902854e32cdcc839a4914ffcb82483d1d48f5cd81c596
              • Instruction Fuzzy Hash: 20F09C71B04154BBE715AFA9D805EEE77BCDB07314F400519F501E7A80EBB4AD098795
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetLogicalDriveStringsW.KERNELBASE(00000104,?,?,?,0000000C), ref: 6CB791E2
              • QueryDosDeviceW.KERNEL32(?,?,00000104,?,?,?,?,?,0000000C), ref: 6CB79256
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DeviceDriveErrorLastLogicalQueryStrings
              • String ID: %s%s
              • API String ID: 3175585515-3252725368
              • Opcode ID: b502533aeadc78b5887377fe891770a4b433bc20caabf628261d7b7b2e016f85
              • Instruction ID: e48be1e5ac9b7c33b487973caa2753a77431c9265924f896010d96a9c32defa5
              • Opcode Fuzzy Hash: b502533aeadc78b5887377fe891770a4b433bc20caabf628261d7b7b2e016f85
              • Instruction Fuzzy Hash: C131AAB5F4025DAADB10ABA5CC45BEE73BCDF18704F4040A5EB15E7640FB309A498BB5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6E978: GetFileAttributesExW.KERNEL32(?,00000000,?,?,?,?,6CB68F4E,?,?,6CB68315,00000000,?,?,00000000,?), ref: 6CB6E99C
              • FindFirstFileW.KERNELBASE(?,?), ref: 6CB73BA7
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: File$AttributesFindFirst
              • String ID:
              • API String ID: 4185537391-0
              • Opcode ID: 8f0c539fe240c45671ffcf5c6e7862c521911946f39ae18b1b438a52cdb15aea
              • Instruction ID: dd6fb950792921f33fc2da6c56dc4ed651d91a8c2b7e4d32a75aa332a039f022
              • Opcode Fuzzy Hash: 8f0c539fe240c45671ffcf5c6e7862c521911946f39ae18b1b438a52cdb15aea
              • Instruction Fuzzy Hash: 5721A131A041989BDB20DF65DC889DEB3BCEF85318F5001A99816E3790EF319E48CB64
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • AllocateAndInitializeSid.ADVAPI32(00000001,00000002,00000020,00000220,00000000,00000000,00000000,00000000,00000000,00000000,6CB7B383,?,6CB7B383,00000007,00000001), ref: 6CB7455B
              • CheckTokenMembership.KERNELBASE(00000000,6CB7B383,00000007,?,6CB7B383,00000007,00000001), ref: 6CB74570
              • FreeSid.ADVAPI32(6CB7B383,?,6CB7B383,00000007,00000001), ref: 6CB74580
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AllocateCheckFreeInitializeMembershipToken
              • String ID:
              • API String ID: 3429775523-0
              • Opcode ID: 45d23dc6e9df0723b76e2a265f2f3314b7db1cc1b96cf67d33d40f2c1a0d136b
              • Instruction ID: f3d5e026590485b05a87ca2d28343903272495944c5a0c0c66b06a9d890454b5
              • Opcode Fuzzy Hash: 45d23dc6e9df0723b76e2a265f2f3314b7db1cc1b96cf67d33d40f2c1a0d136b
              • Instruction Fuzzy Hash: B801E870A0421EAFEF01DFE4C9899BEB7BDFB08605F514469A911E2281E774DA048B61
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 117 6cb7c4bf-6cb7c502 call 6cb7a9f4 call 6cb6d808 122 6cb7c504-6cb7c50d 117->122 123 6cb7c50f-6cb7c523 117->123 124 6cb7c548-6cb7c554 call 6cb774d5 122->124 123->124 125 6cb7c525-6cb7c541 call 6cb68a16 call 6cb66b74 123->125 131 6cb7c556-6cb7c56d 124->131 132 6cb7c5a4-6cb7c5ca call 6cb76d85 124->132 134 6cb7c546-6cb7c547 125->134 135 6cb7c573-6cb7c597 call 6cb68a16 call 6cb66b74 131->135 136 6cb7ca01-6cb7ca04 call 6cb7b350 131->136 141 6cb7c5dd-6cb7c6a5 call 6cb7f332 call 6cb7adc4 call 6cb7f332 * 5 call 6cb7adc4 * 3 call 6cb76f8e 132->141 142 6cb7c5cc-6cb7c5d3 132->142 134->124 152 6cb7c59c-6cb7c59f 135->152 140 6cb7ca09-6cb7ca24 call 6cb7aa73 call 6ccb0e3b 136->140 176 6cb7c6a7-6cb7c6aa 141->176 177 6cb7c6b0-6cb7c6cd call 6cb76f8e 141->177 145 6cb7c5d6-6cb7c5d8 142->145 146 6cb7c5d5 142->146 150 6cb7c9e0-6cb7c9eb 145->150 146->145 150->136 155 6cb7c9ed-6cb7c9fa RegCloseKey 150->155 152->136 155->136 176->177 180 6cb7c6cf-6cb7c6d2 177->180 181 6cb7c6d8-6cb7c6f5 call 6cb76f8e 177->181 180->181 184 6cb7c6f7-6cb7c6fb 181->184 185 6cb7c702-6cb7c714 call 6cb77b4e 181->185 184->185 188 6cb7c9db-6cb7c9de 185->188 189 6cb7c71a-6cb7c739 call 6cb69d8f call 6cb77b73 185->189 188->150 194 6cb7c746-6cb7c756 call 6cb6de83 189->194 195 6cb7c73b-6cb7c741 189->195 194->195 200 6cb7c758-6cb7c77e call 6cb6e1f0 194->200 197 6cb7c9c3-6cb7c9cf call 6cb6694d 195->197 197->189 203 6cb7c9d5 197->203 205 6cb7c9b5 200->205 206 6cb7c784-6cb7c791 200->206 203->188 207 6cb7c9b8-6cb7c9c0 call 6cb6694d 205->207 206->205 211 6cb7c797-6cb7c7ac call 6ccc630f 206->211 207->197 211->205 214 6cb7c7b2-6cb7c7c8 call 6cb6dd87 211->214 217 6cb7c7ce-6cb7c7d1 214->217 218 6cb7c8e9-6cb7c900 call 6cb69d8f call 6cb77290 214->218 220 6cb7c813-6cb7c826 call 6cb77187 217->220 221 6cb7c7d3-6cb7c7e4 217->221 237 6cb7c906-6cb7c914 lstrcmpiW 218->237 238 6cb7c99a-6cb7c9a0 call 6cb6694d 218->238 222 6cb7c9a5-6cb7c9b3 call 6cb6694d 220->222 232 6cb7c82c-6cb7c83a lstrcmpiW 220->232 221->222 223 6cb7c7ea-6cb7c80e call 6cb68a16 221->223 222->207 234 6cb7c8db-6cb7c8e4 call 6cb66b74 223->234 235 6cb7c852-6cb7c860 lstrcmpiW 232->235 236 6cb7c83c-6cb7c84d call 6cb7f0d9 232->236 234->222 242 6cb7c862-6cb7c874 call 6cb7f0d9 235->242 243 6cb7c879-6cb7c887 lstrcmpiW 235->243 236->222 244 6cb7c916-6cb7c92a call 6cb7f0d9 237->244 245 6cb7c92c-6cb7c93a lstrcmpiW 237->245 238->222 242->222 252 6cb7c8a0-6cb7c8b1 243->252 253 6cb7c889-6cb7c89b call 6cb7f0d9 243->253 261 6cb7c950-6cb7c958 call 6cb69d41 244->261 247 6cb7c93c-6cb7c94d call 6cb7f0d9 245->247 248 6cb7c95a-6cb7c96b 245->248 247->261 248->238 258 6cb7c96d-6cb7c997 call 6cb68a16 call 6cb66b74 248->258 252->222 256 6cb7c8b7-6cb7c8d6 call 6cb68a16 252->256 253->222 256->234 258->238 261->238
              APIs
              • RegCloseKey.ADVAPI32(00000000,?,?,?,?,?,?,00000068,6CD7CA54,00000000), ref: 6CB7C9F0
                • Part of subcall function 6CB77187: SHQueryValueExW.SHLWAPI(6CB76BD7,00000000,00000000,00000000,?,?,6CD3F7F0,6CD3F7F0,?,6CB77060,?,00000000,00000000,?), ref: 6CB771AA
              • lstrcmpiW.KERNEL32(?,Install,?,00000000,?,00000000,?,?,?,?,?,?,?,?,?,00000068), ref: 6CB7C832
              • lstrcmpiW.KERNEL32(?,Update,?,?,?,?,?,?,?,?,?,00000068,6CD7CA54,00000000), ref: 6CB7C858
              Strings
              • UpdaterExperimentationAndConfigurationServiceControl, xrefs: 6CB7C6E4
              • TargetVersionPrefix, xrefs: 6CB7C92C
              • [ConfigManager::LoadGroupPolicies][Unexpected Type for policy prefix encountered][%s][%d], xrefs: 6CB7C809
              • Update, xrefs: 6CB7C852
              • [ConfigManager::LoadGroupPolicies][Machine is not Enterprise Managed], xrefs: 6CB7C53B
              • TargetChannel, xrefs: 6CB7C906
              • [ConfigManager::LoadGroupPolicies][Unexpected DWORD policy prefix encountered][%s][%d], xrefs: 6CB7C8D6
              • HKLM\Software\Policies\Microsoft\EdgeUpdate\, xrefs: 6CB7C548, 6CB7C586, 6CB7C5B0, 6CB7C68D
              • PackageCacheLifeLimit, xrefs: 6CB7C619
              • ProxyPacUrl, xrefs: 6CB7C679
              • UpdatesSuppressedStartMin, xrefs: 6CB7C639
              • ProxyServer, xrefs: 6CB7C669
              • UpdateDefault, xrefs: 6CB7C6BC
              • Install, xrefs: 6CB7C82C
              • DownloadPreference, xrefs: 6CB7C5F9
              • [ConfigManager::LoadGroupPolicies][No Group Policies found under key][%s], xrefs: 6CB7C591
              • ProxyMode, xrefs: 6CB7C659
              • RollbackToTargetVersion, xrefs: 6CB7C879
              • PackageCacheSizeLimit, xrefs: 6CB7C609
              • AutoUpdateCheckPeriodMinutes, xrefs: 6CB7C5E9
              • [ConfigManager::LoadGroupPolicies][Unexpected String policy prefix encountered][%s][%s], xrefs: 6CB7C98C
              • InstallDefault, xrefs: 6CB7C692
              • UpdatesSuppressedStartHour, xrefs: 6CB7C629
              • UpdatesSuppressedDurationMin, xrefs: 6CB7C649
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$CloseQueryValue
              • String ID: AutoUpdateCheckPeriodMinutes$DownloadPreference$HKLM\Software\Policies\Microsoft\EdgeUpdate\$Install$InstallDefault$PackageCacheLifeLimit$PackageCacheSizeLimit$ProxyMode$ProxyPacUrl$ProxyServer$RollbackToTargetVersion$TargetChannel$TargetVersionPrefix$Update$UpdateDefault$UpdaterExperimentationAndConfigurationServiceControl$UpdatesSuppressedDurationMin$UpdatesSuppressedStartHour$UpdatesSuppressedStartMin$[ConfigManager::LoadGroupPolicies][Machine is not Enterprise Managed]$[ConfigManager::LoadGroupPolicies][No Group Policies found under key][%s]$[ConfigManager::LoadGroupPolicies][Unexpected DWORD policy prefix encountered][%s][%d]$[ConfigManager::LoadGroupPolicies][Unexpected String policy prefix encountered][%s][%s]$[ConfigManager::LoadGroupPolicies][Unexpected Type for policy prefix encountered][%s][%d]
              • API String ID: 269788063-4202166293
              • Opcode ID: c0686c886acbffed7138e823a68db2e1f6123685a86867213d51c98bf42f120f
              • Instruction ID: 6fff00d0feacf79931519d642ead93f23415449e5f2a0794e7e86532f346299c
              • Opcode Fuzzy Hash: c0686c886acbffed7138e823a68db2e1f6123685a86867213d51c98bf42f120f
              • Instruction Fuzzy Hash: 25F19571D002999BDB15DFA4CC81BEEB778AF05308F10416DD926B7B90EB349A49CB71
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 271 6cc40663-6cc4068f 272 6cc406b7-6cc406d6 call 6cb7b487 271->272 273 6cc40691-6cc406b0 call 6cb68a16 call 6cb66b74 271->273 279 6cc406dd-6cc406f4 call 6cb76c84 272->279 280 6cc406d8 272->280 281 6cc406b5-6cc406b6 273->281 284 6cc406f6-6cc40707 279->284 285 6cc4072c-6cc4073b call 6cb6d9ca 279->285 280->279 281->272 286 6cc4070d-6cc40727 call 6cb68a16 284->286 287 6cc409ef-6cc409fa 284->287 295 6cc4073d-6cc4074e 285->295 296 6cc4077a-6cc4077d 285->296 297 6cc409e0-6cc409ec call 6cb66b74 286->297 290 6cc40a05-6cc40a15 call 6ccb0e3b 287->290 291 6cc409fc-6cc409ff RegCloseKey 287->291 291->290 295->296 299 6cc40750-6cc40777 call 6cb68a16 call 6cb66b74 295->299 300 6cc407a4-6cc407c0 296->300 301 6cc4077f-6cc407a2 296->301 297->287 299->296 304 6cc407c7-6cc407c9 300->304 301->304 306 6cc407cc-6cc407dd call 6cb76cd2 304->306 312 6cc409b4-6cc409c5 306->312 313 6cc407e3-6cc407ed 306->313 312->287 315 6cc409c7-6cc409db call 6cb68a16 312->315 313->306 314 6cc407ef-6cc407f2 313->314 316 6cc407f4 call 6cc40a16 314->316 317 6cc40803-6cc40814 call 6cb80824 314->317 315->297 322 6cc407f9-6cc407fd 316->322 324 6cc409a5 317->324 325 6cc4081a-6cc40823 call 6cb6e978 317->325 322->287 322->317 326 6cc409aa-6cc409b2 call 6cb6694d 324->326 325->324 331 6cc40829-6cc40831 325->331 326->287 332 6cc40833 331->332 333 6cc40838-6cc4084e call 6cb76e35 331->333 332->333 333->326 336 6cc40854-6cc40876 call 6cb86d84 call 6cb87119 333->336 341 6cc4087d-6cc40897 call 6cb76e35 336->341 342 6cc40878 336->342 345 6cc40990-6cc409a3 call 6cb6694d call 6cb86deb 341->345 346 6cc4089d-6cc408a5 341->346 342->341 345->326 348 6cc408a7 346->348 349 6cc408ac-6cc408d2 call 6cb66e68 call 6cb76e35 346->349 348->349 357 6cc408d4-6cc408da 349->357 358 6cc408ea-6cc40901 call 6cb69d8f call 6cb6701a 349->358 359 6cc40985-6cc4098d call 6cb6694d 357->359 360 6cc408e0-6cc408e5 357->360 367 6cc40903-6cc40914 call 6ccc9869 call 6cb66f63 358->367 368 6cc40919-6cc4093b call 6cb76e35 358->368 359->345 360->359 367->368 373 6cc40942-6cc40967 call 6cb66e68 call 6cb76e35 368->373 374 6cc4093d 368->374 380 6cc40970-6cc40982 call 6cb6694d * 2 373->380 381 6cc40969-6cc4096b call 6cb818ad 373->381 374->373 380->359 381->380
              APIs
              • RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\EdgeUpdate\,?,?,000F003F,?,00000000,00000000,?,?), ref: 6CC409FF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKCU\Software\Microsoft\EdgeUpdate\ClientState\$HKCU\Software\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}$HKCU\Software\Microsoft\EdgeUpdate\Clients\$HKCU\Software\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}$HKLM\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\ClientState\$HKLM\Software\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}$HKLM\Software\Microsoft\EdgeUpdate\Clients\$HKLM\Software\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}$Microsoft Edge Update$UninstallCmdLine$[Failed to create reg keys][0x%08x]$[Failed to create update reg key][0x%08x]$[Failed to ensure all packages permissions on update reg key][0x%08x]$[SetupGoogleUpdate::InstallRegistryValues]$name$path
              • API String ID: 3535843008-882436788
              • Opcode ID: b8b600fb2cde5d744290ffa1c211a17bfb09a04a875387efab8bedb7e6e174f9
              • Instruction ID: b43987690d62f563ad6301023437be2ed7851393b9b019263482a43d057210e4
              • Opcode Fuzzy Hash: b8b600fb2cde5d744290ffa1c211a17bfb09a04a875387efab8bedb7e6e174f9
              • Instruction Fuzzy Hash: 64A10C71E44285ABEB14DFA1C852BEE7B74AF15308F10C129E511BBFD0EB745948CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              • lstrcmpiW.KERNEL32(00000000,?,brand,?,?,?,?,000F003F,?,00000000,?,?,?,6CB83246), ref: 6CB8338E
              • RegCloseKey.ADVAPI32(00000000,?,?,?,000F003F,?,00000000,?,?,?,6CB83246), ref: 6CB8349D
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Closelstrcmpi
              • String ID: GGLS$InstallSource$InstallTime$WULS$brand$client$reactivationbrand$referral$windowsupdate
              • API String ID: 3513065806-231249599
              • Opcode ID: 5701ca3500b5ff2a403b9a60d620da5682d1af9d515e30c664da0845e7720013
              • Instruction ID: dd21bd7f68de447ea595f5add0076db0a32ad6f32ff74cbba39f50188e71a011
              • Opcode Fuzzy Hash: 5701ca3500b5ff2a403b9a60d620da5682d1af9d515e30c664da0845e7720013
              • Instruction Fuzzy Hash: 6B517231A02195EFEB12CF95C885FEEB778EF01319F504058EA11B7A90DB709E08CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              • GlobalMemoryStatusEx.KERNELBASE(?,00000000,?,?,00000000,?,?,00C4E7D8,00000000,00C4EE10,00000000,00000000,3.0,00000000,?,?), ref: 6CBE5BEE
              • GetSystemInfo.KERNELBASE(?), ref: 6CBE5CA8
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: GlobalInfoMemoryStatusSystem
              • String ID: 3.0$@$HKCU\Software\Microsoft\EdgeUpdate\$HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation$HKLM\Software\Microsoft\EdgeUpdate\$LastECSETag$SystemManufacturer$SystemProductName$unknown$win
              • API String ID: 248183744-804105681
              • Opcode ID: 8da5bb877910edc4894148cd35e1f1fc1e3be1ab88d2dff1caaa0bb8bf9f69ea
              • Instruction ID: 480623d4d005e782b542c0d187825d54128764ab330780dcbf353659cff7146d
              • Opcode Fuzzy Hash: 8da5bb877910edc4894148cd35e1f1fc1e3be1ab88d2dff1caaa0bb8bf9f69ea
              • Instruction Fuzzy Hash: 9AD15F71D042989FDF15DF64C890BEDBBB5AF19304F1040DAD849AB791EB309A49CF62
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1118 6cc3e130-6cc3e150 1119 6cc3e152-6cc3e171 call 6cb68a16 call 6cb66b74 1118->1119 1120 6cc3e178-6cc3e1a3 1118->1120 1141 6cc3e176-6cc3e177 1119->1141 1122 6cc3e1a9-6cc3e1ba OpenProcess 1120->1122 1123 6cc3e3dd-6cc3e3e4 1120->1123 1127 6cc3e1c3-6cc3e1c8 1122->1127 1128 6cc3e1bc-6cc3e1c1 call 6cb781c1 1122->1128 1124 6cc3e3e6-6cc3e3f1 CloseHandle 1123->1124 1125 6cc3e3fd-6cc3e3ff 1123->1125 1131 6cc3e3f3 call 6cb781c1 1124->1131 1132 6cc3e3f8-6cc3e3fb 1124->1132 1134 6cc3e412-6cc3e418 1125->1134 1135 6cc3e401-6cc3e411 call 6cb6a110 1125->1135 1129 6cc3e1d4-6cc3e1e4 call 6cb6e64d 1127->1129 1130 6cc3e1ca-6cc3e1d2 1127->1130 1138 6cc3e1e7-6cc3e1fd 1128->1138 1129->1138 1130->1138 1131->1132 1132->1124 1132->1125 1135->1134 1138->1122 1144 6cc3e1ff-6cc3e20a 1138->1144 1141->1120 1144->1123 1146 6cc3e210-6cc3e25a QueryPerformanceCounter call 6cb6d5ee call 6cbc58de call 6cb7fd4b 1144->1146 1153 6cc3e27b-6cc3e27d 1146->1153 1154 6cc3e25c-6cc3e264 GetLastError 1146->1154 1153->1123 1157 6cc3e283-6cc3e294 1153->1157 1155 6cc3e270 1154->1155 1156 6cc3e266-6cc3e26e 1154->1156 1155->1123 1158 6cc3e276 1155->1158 1156->1155 1159 6cc3e296-6cc3e2c1 call 6cb68a16 call 6cb66b74 1157->1159 1160 6cc3e2c4-6cc3e2d2 1157->1160 1161 6cc3e391-6cc3e396 1158->1161 1159->1160 1163 6cc3e387-6cc3e38c call 6cb80525 1160->1163 1164 6cc3e2d8 1160->1164 1167 6cc3e3c4-6cc3e3d5 call 6cb6d5ee 1161->1167 1168 6cc3e398 1161->1168 1163->1161 1169 6cc3e2db-6cc3e2ea WaitForSingleObject 1164->1169 1167->1123 1182 6cc3e3d7 GetLastError 1167->1182 1172 6cc3e39a-6cc3e3a7 TerminateProcess 1168->1172 1173 6cc3e2f0-6cc3e2fd call 6cb7562f 1169->1173 1174 6cc3e375-6cc3e37e 1169->1174 1178 6cc3e3b7-6cc3e3ba 1172->1178 1179 6cc3e3a9-6cc3e3b1 call 6cb7562f GetLastError 1172->1179 1173->1174 1185 6cc3e2ff-6cc3e311 call 6cc3d32c 1173->1185 1174->1169 1176 6cc3e384 1174->1176 1176->1163 1178->1172 1181 6cc3e3bc-6cc3e3c1 1178->1181 1179->1178 1181->1167 1182->1123 1189 6cc3e313-6cc3e316 1185->1189 1190 6cc3e319-6cc3e31b 1185->1190 1189->1190 1191 6cc3e36b 1190->1191 1192 6cc3e31d-6cc3e322 1190->1192 1193 6cc3e370 call 6cb80525 1191->1193 1194 6cc3e364-6cc3e369 1192->1194 1195 6cc3e324-6cc3e327 1192->1195 1193->1174 1194->1193 1197 6cc3e329-6cc3e32b 1195->1197 1198 6cc3e35d-6cc3e362 1195->1198 1199 6cc3e356-6cc3e35b 1197->1199 1200 6cc3e32d-6cc3e32f 1197->1200 1198->1193 1199->1193 1201 6cc3e331-6cc3e333 1200->1201 1202 6cc3e34f-6cc3e354 1200->1202 1203 6cc3e335-6cc3e338 1201->1203 1204 6cc3e348-6cc3e34d 1201->1204 1202->1193 1205 6cc3e341-6cc3e346 1203->1205 1206 6cc3e33a-6cc3e33f 1203->1206 1204->1193 1205->1193 1206->1193
              APIs
              • OpenProcess.KERNEL32(00100401,00000000,?,?,00000000,00000000,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007), ref: 6CC3E1B2
              • QueryPerformanceCounter.KERNEL32(00000000,00000000,00000000,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CC3E214
              • GetLastError.KERNEL32(00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CC3E25C
              • WaitForSingleObject.KERNEL32(?,00000000,00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CC3E2DF
              • TerminateProcess.KERNEL32(?,000000FF,00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CC3E39F
              • GetLastError.KERNEL32(?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CC3E3B1
              • GetLastError.KERNEL32(00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CC3E3D7
              • CloseHandle.KERNEL32(00000000,?,00000000,00000000,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CC3E3E9
              • _Deallocate.LIBCONCRT ref: 6CC3E40B
              Strings
              • [Waiting for other instances to exit], xrefs: 6CC3E16B, 6CC3E1A9
              • [Other Omaha Update instances failed to shutdown in time][%u], xrefs: 6CC3E2B6
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorLast$Process$CloseCounterDeallocateHandleObjectOpenPerformanceQuerySingleTerminateWait
              • String ID: [Other Omaha Update instances failed to shutdown in time][%u]$[Waiting for other instances to exit]
              • API String ID: 2481869803-4051304655
              • Opcode ID: f68c0cf903651838a80276a2342caaef1d0b5ccd2e69aa125a7faefe1c333d04
              • Instruction ID: 2647f3a5732aa08e7539677b6a922138da6fff2da8ab93c19b259345ec9f576e
              • Opcode Fuzzy Hash: f68c0cf903651838a80276a2342caaef1d0b5ccd2e69aa125a7faefe1c333d04
              • Instruction Fuzzy Hash: 56919371A002299FDB04CFAAD9445EEB7B5FF45314B20552EE429EBB90EB34DD008BA0
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1207 6cbe2f7c-6cbe2fbf 1209 6cbe310f 1207->1209 1210 6cbe2fc5-6cbe3090 call 6ccc5fe0 VariantInit call 6ccc5fe0 VariantInit call 6ccc5fe0 VariantInit call 6ccc5fe0 VariantInit 1207->1210 1211 6cbe3112-6cbe3117 1209->1211 1222 6cbe3094-6cbe30b9 VariantClear * 4 1210->1222 1213 6cbe311f-6cbe3129 1211->1213 1214 6cbe3119-6cbe311b 1211->1214 1214->1213 1222->1209 1223 6cbe30bb-6cbe30ef call 6cb74325 1222->1223 1228 6cbe30f6-6cbe3101 1223->1228 1229 6cbe30f1-6cbe30f4 1223->1229 1230 6cbe3103-6cbe3105 1228->1230 1229->1230 1230->1211 1231 6cbe3107-6cbe310d 1230->1231 1231->1211
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Variant$ClearInit$FreeString
              • String ID: `)u
              • API String ID: 2380248875-4279031584
              • Opcode ID: f0e4aedf3f40006f4bd2f6c5d1b286a61ecd2fdd9078060be54fd0585b260939
              • Instruction ID: e9c098a6b9682400b35c9a5bfdbb0a1f1dfcb6d5f63535e526dbb632623a6d40
              • Opcode Fuzzy Hash: f0e4aedf3f40006f4bd2f6c5d1b286a61ecd2fdd9078060be54fd0585b260939
              • Instruction Fuzzy Hash: 67515AB2D00618ABDF01DFA4C845ADFBBB9EF4A710F110559ED04BB250E7B1AA49CB91
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1333 6cc3e41b-6cc3e455 call 6cb69d8f call 6cb74092 1338 6cc3e457-6cc3e46b call 6cb69f92 1333->1338 1339 6cc3e46d-6cc3e475 call 6cb6a060 1333->1339 1343 6cc3e47a-6cc3e4aa call 6cb74092 call 6cb69a7a call 6cb69d8f 1338->1343 1339->1343 1350 6cc3e4c5-6cc3e4eb call 6cb74f36 1343->1350 1351 6cc3e4ac-6cc3e4bd call 6cb7678c 1343->1351 1355 6cc3e4f0-6cc3e4f7 1350->1355 1356 6cc3e4c3 1351->1356 1357 6cc3e6fe-6cc3e719 call 6cb6694d * 2 1351->1357 1358 6cc3e6e4-6cc3e6e8 1355->1358 1359 6cc3e4fd-6cc3e522 call 6cc3eeac call 6cb7b487 1355->1359 1356->1350 1373 6cc3e747-6cc3e74d 1357->1373 1374 6cc3e71b-6cc3e720 1357->1374 1358->1357 1360 6cc3e6ea-6cc3e6fd call 6cb6a110 1358->1360 1371 6cc3e524-6cc3e55d call 6cb69d8f call 6cb66e68 call 6cb7ab73 call 6cb6694d 1359->1371 1372 6cc3e55f-6cc3e597 call 6cb69d8f call 6cb66e68 call 6cb7ab73 call 6cb6694d 1359->1372 1360->1357 1398 6cc3e598-6cc3e5a4 call 6cb69f92 1371->1398 1372->1398 1377 6cc3e722-6cc3e731 call 6cb6694d 1374->1377 1378 6cc3e736-6cc3e746 call 6cb6a110 1374->1378 1387 6cc3e733 1377->1387 1378->1373 1387->1378 1401 6cc3e5b1-6cc3e5b3 1398->1401 1402 6cc3e5a6-6cc3e5ac call 6cb6694d 1398->1402 1404 6cc3e5c0-6cc3e5e2 1401->1404 1405 6cc3e5b5-6cc3e5bb call 6cb6694d 1401->1405 1402->1401 1407 6cc3e696-6cc3e69e 1404->1407 1408 6cc3e5e8-6cc3e608 call 6cb69d8f call 6cb756c6 1404->1408 1405->1404 1409 6cc3e6b1-6cc3e6b5 1407->1409 1410 6cc3e6a0-6cc3e6ae 1407->1410 1422 6cc3e672 1408->1422 1423 6cc3e60a-6cc3e629 call 6cb721e7 call 6cb69d8f call 6cb6cb0d 1408->1423 1412 6cc3e6b7-6cc3e6c4 call 6cb6a110 1409->1412 1413 6cc3e6c5-6cc3e6d1 call 6cb6694d 1409->1413 1410->1409 1412->1413 1413->1358 1421 6cc3e6d3-6cc3e6e3 call 6cb6a110 1413->1421 1421->1358 1426 6cc3e675-6cc3e68a call 6cb6694d 1422->1426 1436 6cc3e665-6cc3e670 call 6cb6694d 1423->1436 1437 6cc3e62b-6cc3e63f call 6cb70fed 1423->1437 1426->1408 1433 6cc3e690-6cc3e693 1426->1433 1433->1407 1436->1426 1437->1436 1442 6cc3e641-6cc3e646 1437->1442 1443 6cc3e655-6cc3e662 call 6cb7597c 1442->1443 1444 6cc3e648-6cc3e653 1442->1444 1443->1436 1444->1436
              APIs
                • Part of subcall function 6CB7AB73: PathAppendW.SHLWAPI(?,00000000,00000068,00C4B988,811C9DC5,00000000,6CD7CA54,00000000,00000068,6CD7CA54,00C4B988), ref: 6CB7AC11
              • _Deallocate.LIBCONCRT ref: 6CC3E6BE
              • _Deallocate.LIBCONCRT ref: 6CC3E6DD
              • _Deallocate.LIBCONCRT ref: 6CC3E6F7
              • _Deallocate.LIBCONCRT ref: 6CC3E740
                • Part of subcall function 6CB756C6: OpenProcess.KERNEL32(00000410,00000000,?,?,?), ref: 6CB756EB
                • Part of subcall function 6CB756C6: CloseHandle.KERNEL32(00000000,?,?,?), ref: 6CB757FF
                • Part of subcall function 6CB721E7: CharLowerBuffW.USER32(00000000,?,?,00000000,?,6CB73D99,0000005C,00000000,00000000,00000000,?,00000001,?), ref: 6CB72203
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate$AppendBuffCharCloseHandleLowerOpenPathProcess
              • String ID: /%s $MicrosoftEdgeUpdate.exe$Microsoft\EdgeUpdate$install$registerproduct
              • API String ID: 1981852759-711970392
              • Opcode ID: f6c2aba0a9ded783264f4a87d7fabd509684fa90ed62030ceb32e7758836d0b1
              • Instruction ID: 7f3bfb9c1ad92fc462af3b6ac074700f94d2c25fda96b202549dec5b5a7fbe44
              • Opcode Fuzzy Hash: f6c2aba0a9ded783264f4a87d7fabd509684fa90ed62030ceb32e7758836d0b1
              • Instruction Fuzzy Hash: FAB15372D001599BDF14DFA9D8909EEBBB5FF44318F20452DE425A7B90EB30AD49CB90
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              • GetProcessShutdownParameters.KERNEL32(00000000,00000000,6CD7C950,00000000,6CD7C950,00000000,00000007,?,?,00000000), ref: 6CB8B094
              • SetProcessShutdownParameters.KERNEL32(00000000,00000000,?,?,?,00000000), ref: 6CB8B0AD
              • HeapSetInformation.KERNEL32(00000000,00000001,00000000,00000000,?,?,?,00000000), ref: 6CB8B0D0
              Strings
              • opt, xrefs: 6CB8B13E
              • Installation failed with error 0x%08x., xrefs: 6CB8B21C
              • [%s][version %s][%s][%s], xrefs: 6CB8B14A
              • [InitializeGoopdateAndLoadResources failed][0x%08x], xrefs: 6CB8B1DC
              • Omaha Installer, xrefs: 6CB8B22B
              • official, xrefs: 6CB8B139
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ParametersProcessShutdown$HeapInformation
              • String ID: Installation failed with error 0x%08x.$Omaha Installer$[%s][version %s][%s][%s]$[InitializeGoopdateAndLoadResources failed][0x%08x]$official$opt
              • API String ID: 2108867172-2614164889
              • Opcode ID: 1430b9f2281ffcfcf5754c758913872dfcaccb71cd98f13c407a15b35902d7b1
              • Instruction ID: 1572919fbc1eb5315046e63204da07b171bd89198a8ab536c90f5d0cce5fc548
              • Opcode Fuzzy Hash: 1430b9f2281ffcfcf5754c758913872dfcaccb71cd98f13c407a15b35902d7b1
              • Instruction Fuzzy Hash: 1351D671A05196ABDF00DF74CC409FE7B78EF15259F108529EA25D7F90EB309608CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SetFilePointer.KERNELBASE(?,00000000,00000000,00000002), ref: 6CB6988E
              • SetFilePointer.KERNELBASE(?,00000000,00000000,00000002), ref: 6CB698BA
              • lstrlenW.KERNEL32(?), ref: 6CB698D7
              • WriteFile.KERNELBASE(?,?,00000000,00000000,00000000), ref: 6CB698ED
              • WriteFile.KERNEL32(?,?,?,?,00000000,?), ref: 6CB69925
              • lstrlenW.KERNEL32(?), ref: 6CB69941
              • WriteFile.KERNELBASE(?,?,00000000,00000000,00000000), ref: 6CB69957
              • WriteFile.KERNEL32(?,?,?,?,00000000,?), ref: 6CB6998F
              • WriteFile.KERNELBASE(?,6CD3F0B0,00000002,?,00000000), ref: 6CB699BD
              • ReleaseMutex.KERNEL32(00000000), ref: 6CB699C8
                • Part of subcall function 6CB691EE: OutputDebugStringW.KERNEL32(00000000), ref: 6CB6922D
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: File$Write$Pointerlstrlen$DebugMutexOutputReleaseString
              • String ID:
              • API String ID: 2872164957-0
              • Opcode ID: 31eed569f53af026d74e12f1d91075feb625bfa64f2e077f92a660518bed8994
              • Instruction ID: 1798146fb657afc7db02b79cdf69440bfcb4a4108d89eb6ce26395fdd327ae36
              • Opcode Fuzzy Hash: 31eed569f53af026d74e12f1d91075feb625bfa64f2e077f92a660518bed8994
              • Instruction Fuzzy Hash: 57417131604385AFEB10DF26CC85F6EB7A9EF55348F00481DB5A296DE1DB70AD09CB62
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • QueryPerformanceCounter.KERNEL32(00000000,6CBDA393,?,?,6CC3DC35,-0000AFC9,00000000,?,?,?,6CC3D94E,?,?,00000000,00000000,6CBDA393), ref: 6CC3F138
              Strings
              • [Install files][moved not allowed, will copy][source_dir=%s], xrefs: 6CC3F111
              • [Failed to move/copy metainstaller][0x%08x], xrefs: 6CC3F313
              • [Install files][move_allowed=%u], xrefs: 6CC3F0C6
              • [source_dir=%s][install_dir=%s, xrefs: 6CC3F1BD
              • [Failed to move/copy core files][0x%08x], xrefs: 6CC3F240
              • [Failed to move/copy optional files][0x%08x], xrefs: 6CC3F385
              • [Failed to copy shell][0x%08x], xrefs: 6CC3F2A1
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CounterPerformanceQuery
              • String ID: [Failed to copy shell][0x%08x]$[Failed to move/copy core files][0x%08x]$[Failed to move/copy metainstaller][0x%08x]$[Failed to move/copy optional files][0x%08x]$[Install files][move_allowed=%u]$[Install files][moved not allowed, will copy][source_dir=%s]$[source_dir=%s][install_dir=%s
              • API String ID: 2783962273-2709891547
              • Opcode ID: 4bf2f98f111ea55d493b7f553b6453213cdc6e92131e7e52b4c9c01e10aa4ea9
              • Instruction ID: 98025f259febe68a6c51811afd77613dccdac1530eb137d7bdb91e518f028c5b
              • Opcode Fuzzy Hash: 4bf2f98f111ea55d493b7f553b6453213cdc6e92131e7e52b4c9c01e10aa4ea9
              • Instruction Fuzzy Hash: AEA12C71D00164AECF04DFA5D891EFDBBB8AF45318F14566AE815FBB90E7349908CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcAddress.KERNELBASE(00000000,NetGetAadJoinInformation), ref: 6CB6D78E
              • FreeLibrary.KERNEL32(00000000,?,?,?,6CB6D88B,?,00000000,00000000,00000068,6CD7CA54,00000000), ref: 6CB6D7A3
              • FreeLibrary.KERNEL32(00000000,?,?,?,6CB6D88B,?,00000000,00000000,00000068,6CD7CA54,00000000), ref: 6CB6D7B7
              • GetProcAddress.KERNEL32(00000000,NetFreeAadJoinInformation), ref: 6CB6D7E7
              • FreeLibrary.KERNEL32(00000000,?,?,?,6CB6D88B,?,00000000,00000000,00000068,6CD7CA54,00000000), ref: 6CB6D7F5
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeLibrary$AddressProc
              • String ID: NetApi32.dll$NetFreeAadJoinInformation$NetGetAadJoinInformation
              • API String ID: 1309337288-2909723663
              • Opcode ID: b76fc488b8ed0b1f68071bd9898b356a7851239db36a328d5a8d351d20b48281
              • Instruction ID: 6eaca1aeda00059a2668c07986e3789866b56e301a6213049ef86c26ae521fcd
              • Opcode Fuzzy Hash: b76fc488b8ed0b1f68071bd9898b356a7851239db36a328d5a8d351d20b48281
              • Instruction Fuzzy Hash: 8E119B34B02569ABAB128F7BDC409BFF6BCDF976587200358A525D7F80DB30C9024A66
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • LoadLibraryExW.KERNEL32(netapi32.dll,00000000,00000800,?,?,?,?,?,?,6CB7D897), ref: 6CB8289C
              • GetProcAddress.KERNEL32(00000000,NetGetAadJoinInformation), ref: 6CB828B4
              • GetProcAddress.KERNEL32(00000000,NetFreeAadJoinInformation), ref: 6CB828BF
              • FreeLibrary.KERNEL32(00000000,?,?,?,?,?,?,6CB7D897), ref: 6CB828F1
              Strings
              • NetFreeAadJoinInformation, xrefs: 6CB828B6
              • 72f988bf-86f1-41af-91ab-2d7cd011db47, xrefs: 6CB828D5
              • NetGetAadJoinInformation, xrefs: 6CB828AE
              • netapi32.dll, xrefs: 6CB82897
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressLibraryProc$FreeLoad
              • String ID: 72f988bf-86f1-41af-91ab-2d7cd011db47$NetFreeAadJoinInformation$NetGetAadJoinInformation$netapi32.dll
              • API String ID: 2256533930-532150908
              • Opcode ID: 9c09c43f2c2c6d009ccce4bbb3dfef0b253657a5b7cf2c0c5973c97e74c6f600
              • Instruction ID: fe022dab0c4bf01029109fc16e91d690a0a55f175faf9d569e71df3c7a13fc3f
              • Opcode Fuzzy Hash: 9c09c43f2c2c6d009ccce4bbb3dfef0b253657a5b7cf2c0c5973c97e74c6f600
              • Instruction Fuzzy Hash: 2401FE35E02759FFBF008BAD8C48DAF7BBCDE82555B20016EE510D3600DB70DD04A662
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBDA12A: __aulldiv.LIBCMT ref: 6CBDA14A
              • lstrcmpiW.KERNEL32(00000000,windowsupdate,?,?,?,?,00000010,00000010,?,00000000,?,?,?,{F3C4FE00-EFD5-403B-9569-398A20F1BA4A},?), ref: 6CBD85E2
              • lstrcmpiW.KERNEL32(00000000,windowsupdate_zdp,?,?,?,?,00000010,00000010,?,00000000,?,?,?,{F3C4FE00-EFD5-403B-9569-398A20F1BA4A},?), ref: 6CBD85F3
              • lstrcmpiW.KERNEL32(?,WUZP,?,?,?,?,00000010,00000010,?,00000000,?,?,?,{F3C4FE00-EFD5-403B-9569-398A20F1BA4A},?), ref: 6CBD8604
              Strings
              • [InstallApplications][Higher version exists for ZDP attempt][Will trigger an update check], xrefs: 6CBD8672
              • [InstallSelf failed][0x%08x], xrefs: 6CBD85B2
              • WUZP, xrefs: 6CBD85FC
              • windowsupdate, xrefs: 6CBD85DB
              • windowsupdate_zdp, xrefs: 6CBD85E8, 6CBD86BF
              • [InstallApplications failed][0x%08x], xrefs: 6CBD86AF
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$__aulldiv
              • String ID: WUZP$[InstallApplications failed][0x%08x]$[InstallApplications][Higher version exists for ZDP attempt][Will trigger an update check]$[InstallSelf failed][0x%08x]$windowsupdate$windowsupdate_zdp
              • API String ID: 3338331248-3850485355
              • Opcode ID: 61baf1c35b70432a8baa5b77a485214ead4e4b261197feba44c345821c1cab60
              • Instruction ID: 15fc80992bae97a9dfe7289f2899234e5ea55bd91afd63a1f7c096b29d063c18
              • Opcode Fuzzy Hash: 61baf1c35b70432a8baa5b77a485214ead4e4b261197feba44c345821c1cab60
              • Instruction Fuzzy Hash: DA512271D04289AEDF068F64C841AFE3FB4DB46319F15912AF811A7BA0D736A914CBD0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,Version,?,00000001,DisplayVersion,?,00000001,HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update,000F003F), ref: 6CB845D8
              Strings
              • Version, xrefs: 6CB8457C
              • [Failed to set ARP version], xrefs: 6CB845B5
              • [Failed to create ARP key][0x%08x], xrefs: 6CB8451B
              • [Failed to set ARP display version], xrefs: 6CB8456E
              • DisplayVersion, xrefs: 6CB84535
              • HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update, xrefs: 6CB844C8
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: DisplayVersion$HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update$Version$[Failed to create ARP key][0x%08x]$[Failed to set ARP display version]$[Failed to set ARP version]
              • API String ID: 3535843008-575114552
              • Opcode ID: f5ce291fde47f7f8c390f7e3b981577f0450cc8b39d3b69b5ffeaf7e42462cb8
              • Instruction ID: a0c8dba9af88a59627a153fcc79379954fdc733701e0f131de60f6eee763e016
              • Opcode Fuzzy Hash: f5ce291fde47f7f8c390f7e3b981577f0450cc8b39d3b69b5ffeaf7e42462cb8
              • Instruction Fuzzy Hash: FD31EA71D052A6AEDF169FA8D861AFE7BB8DB41315F10422EE521F6BD0D7344A04CF90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE2FE6
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE300A
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE302E
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE3055
                • Part of subcall function 6CCCF70F: GetSystemTimeAsFileTime.KERNEL32(00000000,?,?,?,6CBE4B0E,00000000,-7FFFFFFF,?,?,00000000,000F003F), ref: 6CCCF722
                • Part of subcall function 6CCCF70F: __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CCCF753
                • Part of subcall function 6CBE2422: _strftime.LIBCMT ref: 6CBE2464
              • VariantInit.OLEAUT32(?), ref: 6CBE3693
              • VariantInit.OLEAUT32(?), ref: 6CBE36BB
              • VariantInit.OLEAUT32(?), ref: 6CBE36E3
                • Part of subcall function 6CB74325: SysAllocString.OLEAUT32(00000000), ref: 6CB7433E
              • SysFreeString.OLEAUT32(?), ref: 6CBE3776
              • SysFreeString.OLEAUT32(?), ref: 6CBE377C
              • VariantClear.OLEAUT32(?), ref: 6CBE3789
              • VariantClear.OLEAUT32(?), ref: 6CBE3790
              • VariantClear.OLEAUT32(?), ref: 6CBE3797
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Variant$Init$ClearString$FreeTime$AllocFileSystemUnothrow_t@std@@@__ehfuncinfo$??2@_strftime
              • String ID:
              • API String ID: 2234857567-0
              • Opcode ID: c7bfad57d60b78081fe16fdda10b574624b03c308302af6398f1226d79abd3de
              • Instruction ID: f4ac9b6a27ed577e8e3d07467a759bc435c9d8249606b5c285e354eef4404a36
              • Opcode Fuzzy Hash: c7bfad57d60b78081fe16fdda10b574624b03c308302af6398f1226d79abd3de
              • Instruction Fuzzy Hash: 4E518A725043499FCB01DF64C844E9FB7EAFF89314F004819F9949B290EB75EA09CB92
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrlen
              • String ID: HKLM\SYSTEM\CurrentControlSet\Control\Session Manager$PendingFileRenameOperations$\??\
              • API String ID: 1659193697-62132483
              • Opcode ID: 41a24a6318e5ce4bf85e139f66d0b40e93b721c9009d58879014d89fe2bb0112
              • Instruction ID: 6388d06c7c943d0efcd2ba1669bef6638822ff414931ba852712a75e73c67907
              • Opcode Fuzzy Hash: 41a24a6318e5ce4bf85e139f66d0b40e93b721c9009d58879014d89fe2bb0112
              • Instruction Fuzzy Hash: CE71E135A0429ADFDF04CF99C8809EEB7B1FF89304B24416DE915ABB50DB319A45CBE1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6FDFB: GetSystemTimeAsFileTime.KERNEL32(?,6CD3E6AC,6CD3E6AC,?,6CB68434,00000000,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB6FE1B
              • __aulldiv.LIBCMT ref: 6CBDA14A
              • __aulldiv.LIBCMT ref: 6CBDA26A
              Strings
              • HKLM\Software\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}, xrefs: 6CBDA189
              • HKCU\Software\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}, xrefs: 6CBDA190, 6CBDA195
              • iid, xrefs: 6CBDA1C4
              • {F3C4FE00-EFD5-403B-9569-398A20F1BA4A}, xrefs: 6CBDA1E2, 6CBDA1EA, 6CBDA21B
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Time__aulldiv$FileSystem
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}$HKLM\Software\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}$iid${F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
              • API String ID: 1198726632-1907915243
              • Opcode ID: 87e10225cd877820ebfd3181e058e855652a5183bd762c23b09f884ac5e28482
              • Instruction ID: fbf64986452a9658dcaaba87d0d198507b83b740f65406353d0c9ee803a0acb1
              • Opcode Fuzzy Hash: 87e10225cd877820ebfd3181e058e855652a5183bd762c23b09f884ac5e28482
              • Instruction Fuzzy Hash: CF518E3190018AAFDF04DF64DC91FEF7B75AF55318F104158E911A6AD0EB70AA58CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetSecurityDescriptorDacl.ADVAPI32(00000000,?,?,?,?,?), ref: 6CB6DA37
              • RegSetKeySecurity.KERNELBASE(?,00000004,00000000,?,?,?,?), ref: 6CB6DAC1
              • GetSecurityDescriptorControl.ADVAPI32(00000000,00000000,?,?,?), ref: 6CB6DB19
              • GetSecurityDescriptorOwner.ADVAPI32(00000000,?,?,?,?), ref: 6CB6DB42
              • GetSecurityDescriptorGroup.ADVAPI32(00000000,?,?,?,?), ref: 6CB6DB62
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Security$Descriptor$ControlDaclGroupOwner
              • String ID:
              • API String ID: 1700517525-0
              • Opcode ID: 6f7359abbc730fa8625410d7dddcf871eea2d328c2fc60378cc5f3a795868d45
              • Instruction ID: 0f24d43a0a51b810b75aac4116f7ab0b797d8b835e9fb6f1c186c68e5125ba90
              • Opcode Fuzzy Hash: 6f7359abbc730fa8625410d7dddcf871eea2d328c2fc60378cc5f3a795868d45
              • Instruction Fuzzy Hash: BD516A32D052689BEF218BB1EC44BEEB7B8EF05304F20416AA615E7950DB319E48CF61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6F053: GetFileAttributesExW.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,?,?,6CB694EF), ref: 6CB6F080
              • CreateFileW.KERNELBASE(?,40000000,00000003,00000000,00000000,00000080,00000000), ref: 6CB69520
                • Part of subcall function 6CB696A6: OutputDebugStringW.KERNEL32(LOG_SYSTEM: trying to move log file to backup,?,?,?,?,?,6CB694FE), ref: 6CB696B4
                • Part of subcall function 6CB696A6: OutputDebugStringW.KERNEL32(LOG_SYSTEM: failed to move log file to backup,?,?,?,?,?,6CB694FE), ref: 6CB696E2
                • Part of subcall function 6CB73CD5: PathRemoveFileSpecW.SHLWAPI(00000000,?,00000000,00000000,00000068,00000068,?,6CB72909,00000068,00000068,?,6CB7297A,6CD7CA54,6CB7B5C0), ref: 6CB73CF6
                • Part of subcall function 6CB6EA01: GetFileAttributesExW.KERNEL32(00000000,00000000,?,?,00000000,?,?,?,?,?,?,?,6CB69553), ref: 6CB6EA29
              • GetLastError.KERNEL32(?,C0010000,00000000), ref: 6CB695D2
              • WriteFile.KERNELBASE(?,6CD1B678,00000002,00000000,00000000), ref: 6CB695F9
              • OutputDebugStringW.KERNEL32(00000000), ref: 6CB6961F
              • CloseHandle.KERNEL32(?), ref: 6CB69628
                • Part of subcall function 6CB6749C: GetSidLengthRequired.ADVAPI32(00000008,?,00000000,6CD3F770,?,?,?,?,?,?,?,?,6CB6C978,?,6CD3E5F4,00000001), ref: 6CB674F2
                • Part of subcall function 6CB6749C: InitializeSid.ADVAPI32(?,00000000,00000008,?,?,?,?,?,?,?,?,6CB6C978,?,6CD3E5F4,00000001,00000012), ref: 6CB67505
                • Part of subcall function 6CB6749C: GetSidSubAuthority.ADVAPI32(?,00000000,?,?,?,?,?,?,?,?,6CB6C978,?,6CD3E5F4,00000001,00000012,?), ref: 6CB67526
              Strings
              • LOG_SYSTEM: [%s]: ERROR - Log path %s has a reparse point, xrefs: 6CB69611
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: File$DebugOutputString$Attributes$AuthorityCloseCreateErrorHandleInitializeLastLengthPathRemoveRequiredSpecWrite
              • String ID: LOG_SYSTEM: [%s]: ERROR - Log path %s has a reparse point
              • API String ID: 3737642101-1149571711
              • Opcode ID: 44e507431532d2f75bf2ee8124fb7ada5413339d2fb309da9817772840353389
              • Instruction ID: 472103d3409ff7203472f03692bf9bfe405053c6aa8ceaf2506ac9bd896dda18
              • Opcode Fuzzy Hash: 44e507431532d2f75bf2ee8124fb7ada5413339d2fb309da9817772840353389
              • Instruction Fuzzy Hash: D441BF71A04298ABEB10CFB6CC84BEDB779FB12318F100519E116A7ED1DB70695DCB91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • PathGetDriveNumberW.SHLWAPI ref: 6CB75A97
              • CreateFileW.KERNELBASE(?,00000080,00000007,00000000,00000003,00000000,00000000,0000003A,00000041,\\.\), ref: 6CB75ADD
              • DeviceIoControl.KERNELBASE(00000000,002D1400,?,0000000C,?,0000000C,?,00000000), ref: 6CB75B16
              • DeviceIoControl.KERNEL32(00000000,002D1400,00000008,0000000C,?,0000000C,?,00000000), ref: 6CB75B54
              • CloseHandle.KERNEL32(00000000), ref: 6CB75B6D
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ControlDevice$CloseCreateDriveFileHandleNumberPath
              • String ID: \\.\
              • API String ID: 2714738250-2900601889
              • Opcode ID: 87b28217edb499bb287b6c6072adf4bf52244593ac28ce520848792546878813
              • Instruction ID: b5ffc79f78f76828fb46f13d6eb60d0302c773619692d651ec40fdd5a0a4efa8
              • Opcode Fuzzy Hash: 87b28217edb499bb287b6c6072adf4bf52244593ac28ce520848792546878813
              • Instruction Fuzzy Hash: CE313E71E01258BEEB10CFA9CC84EEEB7BCEB09754F104529E921E66D0D7705A0DCBA5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\EdgeUpdate\ClientState\,00020019,00000000,?,00000000), ref: 6CB8C92B
                • Part of subcall function 6CB77BFD: RegQueryInfoKeyW.ADVAPI32(6CB76BD7,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,6CD3F7F0,?,6CB8C8CC,HKLM\Software\Microsoft\EdgeUpdate\ClientState\), ref: 6CB77C17
                • Part of subcall function 6CB77C22: RegEnumKeyExW.KERNELBASE(6CB76BD7,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6CB77C5E
                • Part of subcall function 6CB7934E: RaiseException.KERNEL32(00000000,00000001,00000000,00000000,6CB781E7,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB79362
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\, xrefs: 6CB8C85D
              • HKCU\Software\Microsoft\EdgeUpdate\ClientState\, xrefs: 6CB8C885, 6CB8C896
              • eulaaccepted, xrefs: 6CB8C862
              • HKLM\Software\Microsoft\EdgeUpdate\ClientState\, xrefs: 6CB8C87C
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CB8C854
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseEnumExceptionInfoQueryRaise
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKCU\Software\Microsoft\EdgeUpdate\ClientState\$HKLM\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\ClientState\$eulaaccepted
              • API String ID: 3391589731-286986644
              • Opcode ID: 3cf68a82ed06588804d695376f4402357f3b5ee0355fc86f275820241e9f6990
              • Instruction ID: 958a10640742d275023da8fbe58300ed2be6e0af968d0e10a816b5e69bf3cd96
              • Opcode Fuzzy Hash: 3cf68a82ed06588804d695376f4402357f3b5ee0355fc86f275820241e9f6990
              • Instruction Fuzzy Hash: 1C2106B29421959BCB11EBA9C9517EEB3B4AF41359F1102A4CC12B7F90DB308E0987E2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • Sleep.KERNEL32(00000032), ref: 6CB68C2A
              • OutputDebugStringA.KERNEL32(LOG_SYSTEM: Couldn't acquire lock - ), ref: 6CB68C44
              • OutputDebugStringW.KERNEL32(?), ref: 6CB68C51
              • OutputDebugStringW.KERNEL32(6CD3EC20), ref: 6CB68C58
              Strings
              • LOG_SYSTEM: Couldn't acquire lock after max retries (this process will no longer log), xrefs: 6CB68C71
              • LOG_SYSTEM: Couldn't acquire lock - , xrefs: 6CB68C3F
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DebugOutputString$Sleep
              • String ID: LOG_SYSTEM: Couldn't acquire lock - $LOG_SYSTEM: Couldn't acquire lock after max retries (this process will no longer log)
              • API String ID: 3789842296-1639356730
              • Opcode ID: 6bb77bb4d134b659db2dcbc6d81799692804b1ceae3b0585ce90ac771eb2c8bb
              • Instruction ID: 87e13c7462a36a66c15ff783644feec0b22c0be0e23329be5811a3f10608335a
              • Opcode Fuzzy Hash: 6bb77bb4d134b659db2dcbc6d81799692804b1ceae3b0585ce90ac771eb2c8bb
              • Instruction Fuzzy Hash: E931B47160064BFBDB04CF15C984FEEB779FF4231CF10411AE92996A90EB31A958CB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.SECHOST(00000000,00000000,00000001,00000000,6CC05828,00000000,00000000,00000000,00000000,?,6CC05AD7,6CB8B8A8,6CB8B8A8,?,6CB8B8A8,?), ref: 6CBC4914
              • OpenServiceW.ADVAPI32(00000000,Schedule,00000004,00000000,?,6CC05AD7,6CB8B8A8,6CB8B8A8,?,6CB8B8A8,?), ref: 6CBC492A
              • QueryServiceStatus.ADVAPI32(00000000,?,00000000,?,6CC05AD7,6CB8B8A8,6CB8B8A8,?,6CB8B8A8,?), ref: 6CBC4946
              • CloseServiceHandle.ADVAPI32(00000000,6CC05AD7,6CB8B8A8,6CB8B8A8,?,6CB8B8A8,?), ref: 6CBC4966
              • CloseServiceHandle.ADVAPI32(?,?,6CC05AD7,6CB8B8A8,6CB8B8A8,?,6CB8B8A8,?), ref: 6CBC496F
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$ManagerQueryStatus
              • String ID: Schedule
              • API String ID: 2623946379-2739827629
              • Opcode ID: 724cdc7a55f8371c2931345c2c1e84358e3120f637bdf931b706b7a352019b1f
              • Instruction ID: f6ef13ccab55836756022efa6d9e93b4b1e2ea5306ec53f8dd52c4325a0908e8
              • Opcode Fuzzy Hash: 724cdc7a55f8371c2931345c2c1e84358e3120f637bdf931b706b7a352019b1f
              • Instruction Fuzzy Hash: C201C471B01268AFEF129BA48808AFF77BDDB4A619F100026E501B2540CB74DA04CE66
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB83628: RegCloseKey.KERNELBASE(00000000,?), ref: 6CB8368A
              • lstrcmpiW.KERNEL32(?,windowsonlinerepair,{F3C4FE00-EFD5-403B-9569-398A20F1BA4A},?,?,?), ref: 6CBD99E6
              • lstrcmpiW.KERNEL32(?,msionlinerepair,?,?), ref: 6CBD99F8
              Strings
              • msionlinerepair, xrefs: 6CBD99F0
              • {F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}, xrefs: 6CBD97C8
              • windowsonlinerepair, xrefs: 6CBD99DE
              • {F3C4FE00-EFD5-403B-9569-398A20F1BA4A}, xrefs: 6CBD96CC
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Close
              • String ID: msionlinerepair$windowsonlinerepair${F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}${F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
              • API String ID: 1559394795-3298470250
              • Opcode ID: b2911ce5a746e616b1af5df6e1271e150ebf918e4d65a87d7abcc2a884348525
              • Instruction ID: 6f15706457b61b7f308a1574bee7b4e91a1e5f78b7f8026b3686b10f9c584d14
              • Opcode Fuzzy Hash: b2911ce5a746e616b1af5df6e1271e150ebf918e4d65a87d7abcc2a884348525
              • Instruction Fuzzy Hash: 5FE11731A042A89FDF21CF64CCA0BEDB775AF06308F1141D9E549A7691DB31AE89CF52
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenProcess.KERNEL32(00000400,00000000,?,?,?,?,?,6CB75125,?), ref: 6CB75319
              • CloseHandle.KERNEL32(00000000,?,?,?,?,?,6CB75125,?), ref: 6CB754C1
                • Part of subcall function 6CB754D8: GetLongPathNameW.KERNEL32(?,?,00000104), ref: 6CB75516
              • OpenProcess.KERNEL32(00000410,00000000,?,?,?,?,?,?,?,6CB75125,?), ref: 6CB753B0
              • K32EnumProcessModules.KERNEL32(00000000,?,00000004,?), ref: 6CB753EC
              • K32GetModuleFileNameExW.KERNEL32(00000000,?,?,00000104), ref: 6CB75468
              • CloseHandle.KERNEL32(00000000), ref: 6CB754AC
                • Part of subcall function 6CB7523B: K32GetProcessImageFileNameW.KERNEL32(?,?,00000104,?,?,00000000), ref: 6CB75286
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Process$Name$CloseFileHandleOpen$EnumImageLongModuleModulesPath
              • String ID:
              • API String ID: 812668778-0
              • Opcode ID: 4f25c23c9fc3b1b64edb449128cdc1c6a67727101bcbf0e7bb431d159c4465c0
              • Instruction ID: 0517c0ec8686756d6ab97efcfe4ab6f22f32441a45946a6ec528b0a799d44ea3
              • Opcode Fuzzy Hash: 4f25c23c9fc3b1b64edb449128cdc1c6a67727101bcbf0e7bb431d159c4465c0
              • Instruction Fuzzy Hash: EC51D575A4126DABDB20DF149C809DD7378AF49319F1001D9ED29E3690D7308EA98F69
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB81913: RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards,00020019,00000000,HKLM\Software\Microsoft\EdgeUpdate\,?), ref: 6CB81BD9
              • RegCloseKey.ADVAPI32(00000000,?,00000001,00000000,uid,HKLM\Software\Microsoft\EdgeUpdate\,?,HKLM\Software\Microsoft\EdgeUpdate\,?,6CB82427), ref: 6CB81EC4
                • Part of subcall function 6CB76B58: RegQueryValueExW.KERNELBASE(6CB76BD7,?,00000000,00000000,00000000,00000000,?,6CB77692,?,00000000,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\,?,?), ref: 6CB76B67
              • _Deallocate.LIBCONCRT ref: 6CB81F12
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$DeallocateQueryValue
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$uid
              • API String ID: 3590966819-900028657
              • Opcode ID: f113df3506e436b9d78460f724f246c12d59425d5d4088e627128e5e3a8a7988
              • Instruction ID: bb86cbcd1519794c41d8baf9634a741a3af155c0480c3cb4ada0a35d3ee350dc
              • Opcode Fuzzy Hash: f113df3506e436b9d78460f724f246c12d59425d5d4088e627128e5e3a8a7988
              • Instruction Fuzzy Hash: 5F41E472D0219A8BDF04DFA9C8909EEB7B5EF55318F180158C831B7B90DB319909CBB0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB83628: RegCloseKey.KERNELBASE(00000000,?), ref: 6CB8368A
              • WaitForSingleObject.KERNEL32(00000000,00000000,?,00000000,0000001E,{F3C4FE00-EFD5-403B-9569-398A20F1BA4A},?,00000000,00000000), ref: 6CBE1546
              • GetExitCodeProcess.KERNEL32(00000000,00000000), ref: 6CBE1559
              • TerminateProcess.KERNEL32(00000000,000000FF,?,?,?,?,?,?,?,?,?,?,?,6CBE0ED2,?,-00000001), ref: 6CBE1572
              • CloseHandle.KERNEL32(00000000,?,00000000,0000001E,{F3C4FE00-EFD5-403B-9569-398A20F1BA4A},?,00000000,00000000), ref: 6CBE1586
              Strings
              • {F3C4FE00-EFD5-403B-9569-398A20F1BA4A}, xrefs: 6CBE147C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseProcess$CodeExitHandleObjectSingleTerminateWait
              • String ID: {F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
              • API String ID: 2168239674-1834328584
              • Opcode ID: 3a6891c03147416f324bc2544412089572e1b9721791cc29892f90dfc857d8f9
              • Instruction ID: 823361a46ddda906f1631ce8de74b25430d05dc5f46048d694672c59dcaf27b6
              • Opcode Fuzzy Hash: 3a6891c03147416f324bc2544412089572e1b9721791cc29892f90dfc857d8f9
              • Instruction Fuzzy Hash: 9D418E31604189ABDB04DF65C890DED7778EF15358F248229E9229ABD1DF30AE4DCB91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • VariantClear.OLEAUT32(?), ref: 6CBC692F
              • SysFreeString.OLEAUT32(6CD1A2EC), ref: 6CBC6970
              • SysFreeString.OLEAUT32(00000000), ref: 6CBC6992
              • SysFreeString.OLEAUT32(6CD1A2EC), ref: 6CBC6997
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString$ClearVariant
              • String ID: `)u
              • API String ID: 3349467263-4279031584
              • Opcode ID: 8e557b9b1eea9bc418aaa4fbe0ca063b2859d7af3130f99b193308c6bdca5073
              • Instruction ID: d6112135ef031f73d87dc7e523dab8b65b9934febc3d0474928e4782076fb38b
              • Opcode Fuzzy Hash: 8e557b9b1eea9bc418aaa4fbe0ca063b2859d7af3130f99b193308c6bdca5073
              • Instruction Fuzzy Hash: 9D318032A01258EBCF09DFA8D900DAEBBB9EF49310B114569E805EB350D770EE00CB91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB7763B: RegCloseKey.KERNELBASE(00000000,?,00000000,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\,?,?), ref: 6CB7769C
                • Part of subcall function 6CB7763B: RegCloseKey.ADVAPI32(00000000,00000000,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\,?,?), ref: 6CB776BF
              • RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\EdgeUpdate\ClientState\,00020019,00000007,?), ref: 6CB7D049
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\ClientState\, xrefs: 6CB7CFB8, 6CB7CFCB
              • UsageStats, xrefs: 6CB7CF90
              • HKLM\Software\Microsoft\EdgeUpdateDev\, xrefs: 6CB7CF95
              • HKLM\Software\Microsoft\EdgeUpdate\ClientState\, xrefs: 6CB7CFB1
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\ClientState\$HKLM\Software\Microsoft\EdgeUpdateDev\$HKLM\Software\Microsoft\EdgeUpdate\ClientState\$UsageStats
              • API String ID: 3535843008-585309992
              • Opcode ID: 602e865917b140d36b084d13230f1d074a0cb274130f24f9049b21c500f41479
              • Instruction ID: 0a4d9b5519cc8d7dad5ac321e6bf36e8b1360d08901d799f389704caedf89cff
              • Opcode Fuzzy Hash: 602e865917b140d36b084d13230f1d074a0cb274130f24f9049b21c500f41479
              • Instruction Fuzzy Hash: F221F6319001989BCF11DFA8D8646EEB738EF42388F105069DD35A7B90D7318A0AC7B1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB7329B: VerSetConditionMask.KERNEL32(00000000,00000000,00000002,00000003,00000001,00000003,00000020,00000003,?,00000000,00000000), ref: 6CB73301
                • Part of subcall function 6CB7329B: VerSetConditionMask.KERNEL32(00000000), ref: 6CB73305
                • Part of subcall function 6CB7329B: VerSetConditionMask.KERNEL32(00000000), ref: 6CB73309
                • Part of subcall function 6CB7329B: VerifyVersionInfoW.KERNEL32(0000011C,00000023,00000000), ref: 6CB73330
              • GetModuleHandleW.KERNEL32(kernel32.dll,00000007,?,?,?,?,?,?,?,6CB6CA41,?), ref: 6CB75659
              • GetProcAddress.KERNEL32(00000000,GetProcessId), ref: 6CB75669
              • GetProcessId.KERNELBASE(?,00000007,?,?,?,?,?,?,?,6CB6CA41,?), ref: 6CB75687
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ConditionMask$AddressHandleInfoModuleProcProcessVerifyVersion
              • String ID: GetProcessId$kernel32.dll
              • API String ID: 1983903259-399901964
              • Opcode ID: 288f24a2d6b1a2e1e38b039fd8becc448fb2b6ee3827181c62c956e4703e120a
              • Instruction ID: 70b24ee331f4898b6fe0524bc3fe0fb10a65ab66a1da59b98a7f2eb3f1cb7691
              • Opcode Fuzzy Hash: 288f24a2d6b1a2e1e38b039fd8becc448fb2b6ee3827181c62c956e4703e120a
              • Instruction Fuzzy Hash: 7811C831F4126467EB319A769D04E9F7B7CDF42BA8B014015ED21F3A80E760E90987F9
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6929D: GetLastError.KERNEL32(?,10000000,00000000), ref: 6CB69335
                • Part of subcall function 6CB6929D: GetSecurityDescriptorControl.ADVAPI32(00000000,00000000,?,?,10000000,00000000), ref: 6CB69373
                • Part of subcall function 6CB6929D: GetSecurityDescriptorOwner.ADVAPI32(00000000,?,?), ref: 6CB69391
                • Part of subcall function 6CB6929D: GetSecurityDescriptorGroup.ADVAPI32(00000000,?,?), ref: 6CB693AB
                • Part of subcall function 6CB6929D: GetSecurityDescriptorDacl.ADVAPI32(00000000,00000001,?,?), ref: 6CB693C9
              • OutputDebugStringW.KERNEL32(00000000), ref: 6CB6922D
                • Part of subcall function 6CB694C6: CreateFileW.KERNELBASE(?,40000000,00000003,00000000,00000000,00000080,00000000), ref: 6CB69520
              • OutputDebugStringW.KERNEL32(00000000), ref: 6CB69256
              • ReleaseMutex.KERNEL32(00000000), ref: 6CB69269
              Strings
              • LOG_SYSTEM: [%s]: Could not create logging file %s, xrefs: 6CB69248
              • LOG_SYSTEM: [%s]: Could not acquire logging mutex %s, xrefs: 6CB6921F
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DescriptorSecurity$DebugOutputString$ControlCreateDaclErrorFileGroupLastMutexOwnerRelease
              • String ID: LOG_SYSTEM: [%s]: Could not acquire logging mutex %s$LOG_SYSTEM: [%s]: Could not create logging file %s
              • API String ID: 3573166423-2023621912
              • Opcode ID: 808567ac5e94605b05603401ca7bb03e33c2ac95a047434dcfa08d1bafed3cf3
              • Instruction ID: 2460d3fd7dd75534ba34251a59fb2c1af46f6c60993181b0a44603be348758e8
              • Opcode Fuzzy Hash: 808567ac5e94605b05603401ca7bb03e33c2ac95a047434dcfa08d1bafed3cf3
              • Instruction Fuzzy Hash: E601DF30908B909FEF316F66D4087CA7BB6AF02318F04890CE0AA02D91D7B6948CC792
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CloseHandle.KERNEL32(00000000,00000000,7591F360,00000001), ref: 6CBD887D
              Strings
              • [Waiting for application install to complete], xrefs: 6CBD87DA
              • [Handoff exited with error][0x%08x], xrefs: 6CBD8860
              • [Failed waiting for app install][0x%08x], xrefs: 6CBD882B
              • [Failed to launch installed instance][0x%08x], xrefs: 6CBD87A3
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle
              • String ID: [Failed to launch installed instance][0x%08x]$[Failed waiting for app install][0x%08x]$[Handoff exited with error][0x%08x]$[Waiting for application install to complete]
              • API String ID: 2962429428-3717851940
              • Opcode ID: f0f5861411aec05d384c83a5adeb286fe1a84bbaa6048bb5e154e086f3158d35
              • Instruction ID: 909975a8218630d3c7949ec08910b87df8e9585e69896679de7349ec21d77ab3
              • Opcode Fuzzy Hash: f0f5861411aec05d384c83a5adeb286fe1a84bbaa6048bb5e154e086f3158d35
              • Instruction Fuzzy Hash: CA412B71C04249AFCF05CF69D841AFE3B78EB82316F25121FA825A7B80D732A544C7E1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB73C34: PathAppendW.SHLWAPI(00000010,00C6AF34,00C6AF34,00C6AF30,00C6AF30,?,6CB93118,00000000,00C6AF30,00000000,00C6AF54,00C6AF30), ref: 6CB73C70
              • LoadLibraryExW.KERNELBASE(00000000,00000000,00000002,00000000,00C6AF30,00000000,00C6AF54,00C6AF30,?,?,?,?,?,?,?,6CB930CE), ref: 6CB93140
              • VerQueryValueW.VERSION(?,?,00C6AF30,00C6AF30,?,?,?,?,?,?,?,?,?,?,?,6CB930CE), ref: 6CB931EB
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AppendLibraryLoadPathQueryValue
              • String ID: LanguageId$\StringFileInfo\%08lx\%s
              • API String ID: 1104946767-2593208799
              • Opcode ID: 69526a3fc2f8c1a0e3ebb751fdb46a9b70999441789f4389d3b3ffa1a00d8de1
              • Instruction ID: 3e9f19afb0a128376c782076ac8a8a4dff855f62c15ff649ef55fe1b4398e8c6
              • Opcode Fuzzy Hash: 69526a3fc2f8c1a0e3ebb751fdb46a9b70999441789f4389d3b3ffa1a00d8de1
              • Instruction Fuzzy Hash: 1B817F71A00199EFCF04DFA5C8949EDB778FF45318F10456AD816ABB90EB30AA49CB91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • K32EnumProcesses.KERNEL32(?,00001000,00000000,00000000,?,00000000,00000000), ref: 6CB74FA3
              • GetCurrentProcessId.KERNEL32 ref: 6CB74FC7
              • ProcessIdToSessionId.KERNEL32(?,?), ref: 6CB75084
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Process$CurrentEnumErrorLastProcessesSession
              • String ID: S-1-5-18
              • API String ID: 3380253-4289277601
              • Opcode ID: a34a7cfe70c5a2a2ee67de82404443b6f399f1e568536d3fd5f2dd004633583b
              • Instruction ID: 89a71ec551b58a158b099b35b4a3630f52d7a1198b94d8d689e85685b7781ae3
              • Opcode Fuzzy Hash: a34a7cfe70c5a2a2ee67de82404443b6f399f1e568536d3fd5f2dd004633583b
              • Instruction Fuzzy Hash: 1F717E316493828FD724CF28C440A9EB7E9EF85358F10491DECB597A90DB31A94DCBA7
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • PathRemoveExtensionW.SHLWAPI(00000000,00000000,?,00000000,00000010,?), ref: 6CBD8DDC
              • CreateHardLinkW.KERNELBASE(?,?,00000000,000000FF), ref: 6CBD8E17
              • _Deallocate.LIBCONCRT ref: 6CBD8EA8
              Strings
              • [Copy failed][%s][%s][0x%08X], xrefs: 6CBD8F19
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CreateDeallocateExtensionHardLinkPathRemove
              • String ID: [Copy failed][%s][%s][0x%08X]
              • API String ID: 258837969-151291920
              • Opcode ID: 3fad20b5824b107323412fb3371c6e3d1a6b135cea9fa2ed1bc5593b2be9f84e
              • Instruction ID: 498c6aa4078e38ffad51c0f2cc544da563a7a1b0ad7061b8963355ddbf78c5e3
              • Opcode Fuzzy Hash: 3fad20b5824b107323412fb3371c6e3d1a6b135cea9fa2ed1bc5593b2be9f84e
              • Instruction Fuzzy Hash: 77616231D0019A9BCF04DFA9D8909EEB7B1FF59318B254619D822B7BD0EB316909CF91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6DCA8: PathAppendW.SHLWAPI(00000001,00000000,00000002,00000000,?,6CB808A2,MicrosoftEdgeUpdate.exe,00000010,00000000,00000001,00000000,00000001,?,6CB80A72,00000001,00000000), ref: 6CB6DCD3
              • PathRemoveFileSpecW.SHLWAPI(00000000,00000000,?,?,?,MicrosoftEdgeUpdate.exe,MicrosoftEdgeUpdate.exe,00000010,?,00000000,6CBDA393), ref: 6CC3F7B5
              • _Deallocate.LIBCONCRT ref: 6CC3F828
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Path$AppendDeallocateFileRemoveSpec
              • String ID: MicrosoftEdgeUpdate.exe
              • API String ID: 467717958-4032727653
              • Opcode ID: a831b53c7cabbd83f71d5fb6ca3262fc4af32c51d011aca6cf016c15b4cd4eb4
              • Instruction ID: 75f0e0fce9335a05a9c609587d029675d5da12b3f5f65a1c78ab46aeef89f6aa
              • Opcode Fuzzy Hash: a831b53c7cabbd83f71d5fb6ca3262fc4af32c51d011aca6cf016c15b4cd4eb4
              • Instruction Fuzzy Hash: 55616032D0415A9FCF04DFE9D8909EEB7B4AF09328F1005A9D955B7B90EB306A4DCB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE2FE6
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE300A
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE302E
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE3055
              • VariantClear.OLEAUT32(?), ref: 6CBE3C74
              • lstrcmpiW.KERNEL32(00000000,?,00000000), ref: 6CBE3CB9
              • SysFreeString.OLEAUT32(00000000), ref: 6CBE3D08
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Variant$Init$ClearFreeStringlstrcmpi
              • String ID: `)u
              • API String ID: 171864008-4279031584
              • Opcode ID: b40cd722d3f36df0a8ff7c700f775bea4d8649071dc145d286edb30ada6ef701
              • Instruction ID: 4ea6f39ac223b1bbeefadfe6d4114ff347dda200e0f418f10d813c4e9b6fda53
              • Opcode Fuzzy Hash: b40cd722d3f36df0a8ff7c700f775bea4d8649071dc145d286edb30ada6ef701
              • Instruction Fuzzy Hash: C0516B316093529FDB01CF24C884B5EBBE9EFC9B59F108A5CF8959B260D731D909CB92
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
                • Part of subcall function 6CB74525: AllocateAndInitializeSid.ADVAPI32(00000001,00000002,00000020,00000220,00000000,00000000,00000000,00000000,00000000,00000000,6CB7B383,?,6CB7B383,00000007,00000001), ref: 6CB7455B
                • Part of subcall function 6CB74525: CheckTokenMembership.KERNELBASE(00000000,6CB7B383,00000007,?,6CB7B383,00000007,00000001), ref: 6CB74570
                • Part of subcall function 6CB74525: FreeSid.ADVAPI32(6CB7B383,?,6CB7B383,00000007,00000001), ref: 6CB74580
              • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000), ref: 6CB8A9D0
              • CloseHandle.KERNEL32(?), ref: 6CB8A9E5
              Strings
              • HKLM\Software\Microsoft\EdgeUpdateDev\, xrefs: 6CB8A959
              • CrashIfSpecificError, xrefs: 6CB8A951
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$AllocateCheckCloseCreateEnterEventFreeHandleInitializeLeaveMembershipToken
              • String ID: CrashIfSpecificError$HKLM\Software\Microsoft\EdgeUpdateDev\
              • API String ID: 2920145018-4272353305
              • Opcode ID: 6da58a91c0d30a62c5734abed0b2052294a41e1a87e9e9bba9b3e64c485c81a9
              • Instruction ID: ffeba48d0ad1a75862560b17eff4de1e8763965de5816c032faf5592b4068166
              • Opcode Fuzzy Hash: 6da58a91c0d30a62c5734abed0b2052294a41e1a87e9e9bba9b3e64c485c81a9
              • Instruction Fuzzy Hash: C741C270A05686AFDB149F79C490BDDFBA4FF05218F10852DD869D7B81EB30A848CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SHGetFolderPathW.SHELL32(00000000,00000023,00000000,00000000,00000000,Microsoft\EdgeUpdate\Log,00000000,?,?,?,?,?,?,6CB68569,00000000), ref: 6CB684C6
              • PathAppendW.SHLWAPI(00000000,?,?,?,?,?,?,6CB68569,00000000,?,?,6CB6867D,00000000,?,?,00000000), ref: 6CB68507
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Path$AppendFolder
              • String ID: Microsoft\EdgeUpdate\Log$Temp
              • API String ID: 29327785-1646259884
              • Opcode ID: 18145a29f68e54ec83122c2fe02a3b508681be6694c122488aa2d4b1e86121c8
              • Instruction ID: 6bd64d8a5db938324aeb5bae38f8cf8b6c7224e11aa21efc6dcfe5cfe02719ea
              • Opcode Fuzzy Hash: 18145a29f68e54ec83122c2fe02a3b508681be6694c122488aa2d4b1e86121c8
              • Instruction Fuzzy Hash: 59316471604085EBDB04DBAADD54DFD7338EF52368B140669E512A7FD0EB31AE09C7A0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • QueryPerformanceCounter.KERNEL32(00000000,6CBDA393,?,?,00000000,?,?,?,6CC3D94E,?,?,00000000,00000000,6CBDA393,?), ref: 6CC3DD0F
              • lstrcmpiW.KERNEL32(?,windowsupdate,?,?,?,6CC3D94E,?,?,00000000,00000000,6CBDA393,?), ref: 6CC3DD5A
              Strings
              • windowsupdate, xrefs: 6CC3DD52
              • [StartCore skipped since in middle of Windows Update install], xrefs: 6CC3DD92
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CounterPerformanceQuerylstrcmpi
              • String ID: [StartCore skipped since in middle of Windows Update install]$windowsupdate
              • API String ID: 2421629024-2076500861
              • Opcode ID: 450ec5c868bfbd3e50718af6e21183c3e5c9fc9c09096fb1f9c42e8800b88deb
              • Instruction ID: ebf48e7d5e003d6030733f3cd3284fb8947717a6c5bc5b5df545e6c139580973
              • Opcode Fuzzy Hash: 450ec5c868bfbd3e50718af6e21183c3e5c9fc9c09096fb1f9c42e8800b88deb
              • Instruction Fuzzy Hash: 5F217771A042659FCF01EFB9E8509FE7BF4AF46219B10165DD4A6E7BD0EB3489088B70
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetFileVersionInfoSizeW.KERNELBASE(6CB9317C,?,00C6AF34,00000000,?,6CB9317C,00C6AF34,?,?,?,?,?,?,?,6CB930CE,?), ref: 6CB78B04
              • GetFileVersionInfoW.KERNELBASE(6CB9317C,?,00000000,00000000,?,6CB9317C,00C6AF34,?,?,?,?,?,?,?,6CB930CE,?), ref: 6CB78B21
              • VerQueryValueW.VERSION(?,\VarFileInfo\Translation,6CB9317C,00C6AF34,?,6CB9317C,00C6AF34,?,?,?,?,?,?,?,6CB930CE,?), ref: 6CB78B4D
              Strings
              • \VarFileInfo\Translation, xrefs: 6CB78B43
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FileInfoVersion$QuerySizeValue
              • String ID: \VarFileInfo\Translation
              • API String ID: 2179348866-675650646
              • Opcode ID: 1b70684f8046dd94a92105ee0a17d86963459a634b1613e6f0e8e88356e0ce6c
              • Instruction ID: 6862ebcd84addc597fce40eabe795709bdc3d4b55469d39599ae3c84b933c476
              • Opcode Fuzzy Hash: 1b70684f8046dd94a92105ee0a17d86963459a634b1613e6f0e8e88356e0ce6c
              • Instruction Fuzzy Hash: D8118F71900244EFEB218FA9C8048AEBBF9EF85344B10846FE891E3610E732C605DB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcAddress.KERNEL32(00000000,IsDeviceRegisteredWithManagement), ref: 6CB6B16A
              • FreeLibrary.KERNELBASE(00000000,?,?,?,?,6CB6D882,?,00000000,00000000,00000068,6CD7CA54,00000000), ref: 6CB6B189
              Strings
              • MDMRegistration.dll, xrefs: 6CB6B14D
              • IsDeviceRegisteredWithManagement, xrefs: 6CB6B164
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressFreeLibraryProc
              • String ID: IsDeviceRegisteredWithManagement$MDMRegistration.dll
              • API String ID: 3013587201-129496282
              • Opcode ID: 4229d27bbc87b4fe851bcbceff7ce61daddd0bdecc448062dff930cc11502645
              • Instruction ID: 1d82198610807244ee481d868c9c11db1be33d29f2cdfcca0941c520d695d5e9
              • Opcode Fuzzy Hash: 4229d27bbc87b4fe851bcbceff7ce61daddd0bdecc448062dff930cc11502645
              • Instruction Fuzzy Hash: 96E09B267D6562B3E121062B9C04B5A01799BC3660F160029B514EBF40DA34C80351AA
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcAddress.KERNEL32(?,WerRegisterCustomMetadata), ref: 6CB79904
              • WerRegisterCustomMetadata.KERNELBASE(?,?,?,WerRegisterCustomMetadata), ref: 6CB79910
              • FreeLibrary.KERNEL32(?,?,WerRegisterCustomMetadata), ref: 6CB79920
              Strings
              • WerRegisterCustomMetadata, xrefs: 6CB798FE
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressCustomFreeLibraryMetadataProcRegister
              • String ID: WerRegisterCustomMetadata
              • API String ID: 606598747-3340217272
              • Opcode ID: 8535bb658779c2e7c249075b9e5f6f68dcff107b358c86924c38940a1a707aed
              • Instruction ID: 80acad7092cfe68390cbd00dbc044a4c86507e4467d822a5666015b1c1155045
              • Opcode Fuzzy Hash: 8535bb658779c2e7c249075b9e5f6f68dcff107b358c86924c38940a1a707aed
              • Instruction Fuzzy Hash: 75E0CD26F87AA2977631152E080465A1159D9D36B67254135EE35D7E01DB18CA0503F9
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • WaitForSingleObject.KERNEL32(?,000000FF,?,00000000,?,?,?,?,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}), ref: 6CB6C41D
              • GetExitCodeProcess.KERNELBASE(?,00000000), ref: 6CB6C430
              • FindCloseChangeNotification.KERNELBASE(?), ref: 6CB6C447
              • CloseHandle.KERNEL32(?), ref: 6CB6C452
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$ChangeCodeExitFindHandleNotificationObjectProcessSingleWait
              • String ID:
              • API String ID: 2670690504-0
              • Opcode ID: fbb6c23d6446b938841d11510c0d939ae0f88e222884d4e74084ec000136a8bf
              • Instruction ID: e6a15e1310301786bdbf231ba42198c5af797f2e03a717f0ba7b0eddb9bca5fe
              • Opcode Fuzzy Hash: fbb6c23d6446b938841d11510c0d939ae0f88e222884d4e74084ec000136a8bf
              • Instruction Fuzzy Hash: 8001AC367055197FEB00EA99C904ABF737CEF45615F200115DA11E3540D7309D058677
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • WaitForInputIdle.USER32(00000000,000000FF), ref: 6CBD90D4
              • WaitForSingleObject.KERNEL32(00000000,000000FF,?,6CBD87FC,?,6CBD8628,00000000,7591F360,00000001), ref: 6CBD90F2
              • GetExitCodeProcess.KERNEL32(00000000,00000000), ref: 6CBD9106
              • GetLastError.KERNEL32(?,6CBD87FC,?,6CBD8628,00000000,7591F360,00000001), ref: 6CBD9119
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Wait$CodeErrorExitIdleInputLastObjectProcessSingle
              • String ID:
              • API String ID: 1351972774-0
              • Opcode ID: 7d5fb4cb64b05da7d83d5b2a27a1e2f4cd389d8cb9b9850c8306772720311d7e
              • Instruction ID: 73d4120d8df8bfc0e23bea37c2a79f3a7f9ab6b738e5ad501dc00bc1930fb25e
              • Opcode Fuzzy Hash: 7d5fb4cb64b05da7d83d5b2a27a1e2f4cd389d8cb9b9850c8306772720311d7e
              • Instruction Fuzzy Hash: DF014F31744154BBDB019E2ADC44B9A77ACEF47239F218215F938C62C4DB75D5018B66
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6E978: GetFileAttributesExW.KERNEL32(?,00000000,?,?,?,?,6CB68F4E,?,?,6CB68315,00000000,?,?,00000000,?), ref: 6CB6E99C
                • Part of subcall function 6CB6BCA2: PathCanonicalizeW.SHLWAPI(6CB7AC58,?,00000104,?,?,?,?,6CB7AC58,?,00000000), ref: 6CB6BCD8
              • _Deallocate.LIBCONCRT ref: 6CC3FE38
              • _Deallocate.LIBCONCRT ref: 6CC3FE76
              Strings
              • [MoveOrCopyFiles][Failed. Will copy][%s][%s][0x%08X], xrefs: 6CC3FD11
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate$AttributesCanonicalizeFilePath
              • String ID: [MoveOrCopyFiles][Failed. Will copy][%s][%s][0x%08X]
              • API String ID: 3122508939-3885751513
              • Opcode ID: 4e4c75bd91abfc74e110077171e9a9dad6f64ad1ff7c676425676ced26efa6c9
              • Instruction ID: 8a9107110b958d06bee5276c7b76aef6965ce643cbebaa5f2fe363abf806da92
              • Opcode Fuzzy Hash: 4e4c75bd91abfc74e110077171e9a9dad6f64ad1ff7c676425676ced26efa6c9
              • Instruction Fuzzy Hash: 4F913F31D001699FCF09DFA9E8948EDBBB1FF49318B144599E425B7B90EB30AD09CB50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
              • QueryPerformanceCounter.KERNEL32(6CC40500,00000000,?,?,?,?,?,6CC40500,6CBDA393,?,?), ref: 6CC40C8D
                • Part of subcall function 6CB7FD4B: EnterCriticalSection.KERNEL32(6CD7CA74,?,?,?,6CC3E254,00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000), ref: 6CB7FD58
                • Part of subcall function 6CB7FD4B: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CC3E254,00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CB7FDA2
              Strings
              • [Installing service], xrefs: 6CC40C7C
              • [Install service failed][0x%08x], xrefs: 6CC40D0E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$EnterLeave$CounterPerformanceQuery
              • String ID: [Install service failed][0x%08x]$[Installing service]
              • API String ID: 2312447539-811172613
              • Opcode ID: 89fa7ba8bb24cc9834e83abc84a0dc6ddcd796361b0dc2c6a9f295daf4d8d2af
              • Instruction ID: 3a13b5834889d10746cb27eb72bd028cab101a62dc332dacdd5ee3e8f500c204
              • Opcode Fuzzy Hash: 89fa7ba8bb24cc9834e83abc84a0dc6ddcd796361b0dc2c6a9f295daf4d8d2af
              • Instruction Fuzzy Hash: 93310B71E452959B8B049BF898929FE77B89F86214B10816FE512EBF90FB30D90847B1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB90E3D: QueryPerformanceCounter.KERNEL32(?,00000018,00000000,00000000,?,6CC06CE4,?,00000008,00000008,00000008,?,6CC07006,00000000,?,?,?), ref: 6CB90E49
              • QueryPerformanceCounter.KERNEL32(?,?,?,6CBD9FDA,?,00000000,?,?,?), ref: 6CC3D5EE
                • Part of subcall function 6CB7316B: WaitForSingleObject.KERNEL32(6CB73161,00000000,?,6CC3DE58,00000000,00000000,00000000,00000000,?,?,?,?,?,6CB8C50A,00000001), ref: 6CB73174
              • CloseHandle.KERNEL32(00000000,00000000,00000000,?,000003E8,?,6CBD9FDA,?,00000000,?,?,?), ref: 6CC3D680
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CounterPerformanceQuery$CloseHandleObjectSingleWait
              • String ID: [Failed to acquire setup lock]
              • API String ID: 1849427560-2624087370
              • Opcode ID: 8e6831874e2bd58ab7cbc6e1cb2b1351634472f00cacacb82ad06d2ccfe046e4
              • Instruction ID: 4329df97ae707309f08aa371c568671b1cb0ebfaa587bd73dce95b80fe30ce77
              • Opcode Fuzzy Hash: 8e6831874e2bd58ab7cbc6e1cb2b1351634472f00cacacb82ad06d2ccfe046e4
              • Instruction Fuzzy Hash: 8321E971E043199BDF149FA4E411AEE7BF4AF45308F10455DD519B7BC0EB349648CBA4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SHGetFolderPathW.SHELL32(00000000,0000001C,00000000,00000000,?,0000001C,00000001,00000000), ref: 6CB6BDFE
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FolderPath
              • String ID: LocalAppData$ProgramFiles
              • API String ID: 1514166925-2363656367
              • Opcode ID: 8077a59ac06e31eae084c2d2bf4aabcdacc32a5c41855524f433a56baf354242
              • Instruction ID: 1bf29bb98375c089df70ae48d9fe340239dc9686a2b305bded620ca673828e77
              • Opcode Fuzzy Hash: 8077a59ac06e31eae084c2d2bf4aabcdacc32a5c41855524f433a56baf354242
              • Instruction Fuzzy Hash: 32212771A001A89BCB24CB6ACC88EEF73BCDB85718F100969E515C7F40EB30DD49DA90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?,000F003F), ref: 6CB832D9
                • Part of subcall function 6CB77187: SHQueryValueExW.SHLWAPI(6CB76BD7,00000000,00000000,00000000,?,?,6CD3F7F0,6CD3F7F0,?,6CB77060,?,00000000,00000000,?), ref: 6CB771AA
              • __aulldiv.LIBCMT ref: 6CB832B3
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseQueryValue__aulldiv
              • String ID: InstallTime
              • API String ID: 3112161232-139409508
              • Opcode ID: 3f5952f4ea5d67441423bad8176960f4b62cc279baddc0052d8f5d63f1662f76
              • Instruction ID: 9a57be233522ac162c6f0cf18af5a299df1d79b6be4d2dd64f8592561bfe20e8
              • Opcode Fuzzy Hash: 3f5952f4ea5d67441423bad8176960f4b62cc279baddc0052d8f5d63f1662f76
              • Instruction Fuzzy Hash: 03118472D02269ABDB11DB98C905BFEB678EF54728F150154E911B3B90DB708E09C7E1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SetEvent.KERNEL32(?,?,?,?,?,?,6CC3E0B2,00000007,?,00000007,?,6CD7C950), ref: 6CC3E085
              Strings
              • [Stopping other instances], xrefs: 6CC3E045
              • {E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}, xrefs: 6CC3E060
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Event
              • String ID: [Stopping other instances]${E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}
              • API String ID: 4201588131-1976057958
              • Opcode ID: 1318a333f18edb840f5d732044cd890c21540acab3563c0d4449926d34d4ab8e
              • Instruction ID: adeae6debc48772b54ac19e6efa72643e99431d7477755eb6f2280e3a611e164
              • Opcode Fuzzy Hash: 1318a333f18edb840f5d732044cd890c21540acab3563c0d4449926d34d4ab8e
              • Instruction Fuzzy Hash: D7114832D04165ABCB14DF75D8119EEBBB8AF41318F00822EE615E7E90FB349909CBD0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM,00000000,?,?,00000000,?,00000000,80070003,?,?,?), ref: 6CB779E9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE,?,?), ref: 6CB779F9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU,?,?), ref: 6CB77A09
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER,?,?), ref: 6CB77A19
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU[64],?,?), ref: 6CB77A29
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER[64],?,?), ref: 6CB77A39
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKU,?,?), ref: 6CB77A45
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_USERS,?,?), ref: 6CB77A51
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCR,?,?), ref: 6CB77A5D
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CLASSES_ROOT,?,?), ref: 6CB77A69
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM[64],?,?), ref: 6CB77A75
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE[64],?,?), ref: 6CB77A81
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(00000000,00000000,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\,?,?), ref: 6CB776BF
                • Part of subcall function 6CB76B58: RegQueryValueExW.KERNELBASE(6CB76BD7,?,00000000,00000000,00000000,00000000,?,6CB77692,?,00000000,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\,?,?), ref: 6CB76B67
              • RegCloseKey.KERNELBASE(00000000,?,00000000,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\,?,?), ref: 6CB7769C
              Strings
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CB77643
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Close$OpenQueryValue
              • String ID: HKLM\Software\Microsoft\EdgeUpdate\
              • API String ID: 645971292-747449390
              • Opcode ID: b7fa2f81e04c47f2e95c0b0ef5d74279356aa722e4ef1dcf7687d640bbafb799
              • Instruction ID: 6f0a08cc91ea142474bba35f54548660da9e5081c211ca8c065e4caa96c395df
              • Opcode Fuzzy Hash: b7fa2f81e04c47f2e95c0b0ef5d74279356aa722e4ef1dcf7687d640bbafb799
              • Instruction Fuzzy Hash: 811182B190125AABEF15DF95C959AFFB778EF01308F2000589825B3B91DB709A08CBB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM,00000000,?,?,00000000,?,00000000,80070003,?,?,?), ref: 6CB779E9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE,?,?), ref: 6CB779F9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU,?,?), ref: 6CB77A09
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER,?,?), ref: 6CB77A19
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU[64],?,?), ref: 6CB77A29
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER[64],?,?), ref: 6CB77A39
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKU,?,?), ref: 6CB77A45
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_USERS,?,?), ref: 6CB77A51
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCR,?,?), ref: 6CB77A5D
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CLASSES_ROOT,?,?), ref: 6CB77A69
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM[64],?,?), ref: 6CB77A75
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE[64],?,?), ref: 6CB77A81
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(00000000,00000000,00000000,?,HKLM\Software\Policies\Microsoft\EdgeUpdate\,?,00000001), ref: 6CB77522
              • RegCloseKey.ADVAPI32(00000000,00000000,00000000,?,HKLM\Software\Policies\Microsoft\EdgeUpdate\,?,00000001), ref: 6CB77545
              Strings
              • HKLM\Software\Policies\Microsoft\EdgeUpdate\, xrefs: 6CB774DD
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Close$Open
              • String ID: HKLM\Software\Policies\Microsoft\EdgeUpdate\
              • API String ID: 1041768801-3734594055
              • Opcode ID: 24bb1d11444b21f5ec0f466200ae61183ed6d6b04bf7be31162fa1c0e81f0e97
              • Instruction ID: 487f4feb07741d71370a6ceb12db3c1aef69164537239c56f37e00de4a90a669
              • Opcode Fuzzy Hash: 24bb1d11444b21f5ec0f466200ae61183ed6d6b04bf7be31162fa1c0e81f0e97
              • Instruction Fuzzy Hash: 2C01B5B5901219ABEB14DF95C8966FFB778EF01308F10145C9425A2A90CB709A08CB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB76F8E: RegCloseKey.KERNELBASE(00000000,?,00000000,00000000,?,?,?,?,?,?), ref: 6CB77093
                • Part of subcall function 6CB76F8E: RegCloseKey.ADVAPI32(00000000,00000000,?,?,?,?,?,?), ref: 6CB770CB
                • Part of subcall function 6CB6FDFB: GetSystemTimeAsFileTime.KERNEL32(?,6CD3E6AC,6CD3E6AC,?,6CB68434,00000000,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB6FE1B
              • __aulldiv.LIBCMT ref: 6CB80411
              Strings
              • OemInstallTime, xrefs: 6CB803ED
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CB803F2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseTime$FileSystem__aulldiv
              • String ID: HKLM\Software\Microsoft\EdgeUpdate\$OemInstallTime
              • API String ID: 3399056632-2096400944
              • Opcode ID: 9a6d20469ba3edc2b7398308413458ca1df9ee1339d7b303a0ae5a6e2ae9b51a
              • Instruction ID: 710dde78281c87c3cf9df2810beacedb23b05ae567ffa99104bda52fe93f283b
              • Opcode Fuzzy Hash: 9a6d20469ba3edc2b7398308413458ca1df9ee1339d7b303a0ae5a6e2ae9b51a
              • Instruction Fuzzy Hash: 69F0EC95A51346B7DE0087A4DC07FAF236CCB81A8CF244564D701EFAC4E664D9044235
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?,000F003F), ref: 6CB83590
                • Part of subcall function 6CB76BA7: RegDeleteValueW.KERNELBASE(6CB76BD7,00000000,?,6CB77802,?,00000000,6CB8308D,?,00000001,00000000,00000000), ref: 6CB76BB0
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseDeleteValue
              • String ID: UpdateAvailableCount$UpdateAvailableSince
              • API String ID: 2831762973-2346225637
              • Opcode ID: 360bf61d181f8cebc6ce823c7c7595dac44f1904b5b13c14f514956af602af8d
              • Instruction ID: 96505d1e96bd7c1abbd034bf7ccd657642d856ee1799f52a15c03481aff15689
              • Opcode Fuzzy Hash: 360bf61d181f8cebc6ce823c7c7595dac44f1904b5b13c14f514956af602af8d
              • Instruction Fuzzy Hash: 71F08CB4C01258FBEF10EF90D809BEDBB34EF11308F108099D920B26A4DB744708CB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM,00000000,?,?,00000000,?,00000000,80070003,?,?,?), ref: 6CB779E9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE,?,?), ref: 6CB779F9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU,?,?), ref: 6CB77A09
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER,?,?), ref: 6CB77A19
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU[64],?,?), ref: 6CB77A29
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER[64],?,?), ref: 6CB77A39
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKU,?,?), ref: 6CB77A45
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_USERS,?,?), ref: 6CB77A51
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCR,?,?), ref: 6CB77A5D
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CLASSES_ROOT,?,?), ref: 6CB77A69
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM[64],?,?), ref: 6CB77A75
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE[64],?,?), ref: 6CB77A81
                • Part of subcall function 6CB76C03: RegCreateKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00000000,80070003,?,6CD3F7F0,?,6CB76E8D,00000000,?), ref: 6CB76C45
              • RegSetValueExW.KERNELBASE(00000000,00000000,00000000,00000003,00000000,00000000,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000,00000000), ref: 6CB76F0C
              • RegCloseKey.KERNELBASE(00000000,00000000,00000000,00000001,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000,00000000,?,00000004), ref: 6CB76F41
              • RegCloseKey.ADVAPI32(00000000,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000,00000000,?,00000004), ref: 6CB76F79
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Close$CreateValue
              • String ID:
              • API String ID: 2977736647-0
              • Opcode ID: 65ef8da0dc1d604a82dd2881aa579ef94fdc4f694b63c98fb2565c4cfa34bb66
              • Instruction ID: 50fb4c1a2cfbe92152448a5b3902afb227a9344f3c19e3990ac89accb2d969e3
              • Opcode Fuzzy Hash: 65ef8da0dc1d604a82dd2881aa579ef94fdc4f694b63c98fb2565c4cfa34bb66
              • Instruction Fuzzy Hash: F641D37255114AABDF168FA5CD54BBE7A75EB41308F200019E835EAA50DB30DA05CB31
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetNamedSecurityInfoW.ADVAPI32(?,?,00000004,00000000,00000000,?,00000000,?), ref: 6CB6BB90
              • SetLastError.KERNEL32(00000000,?,?,00000004,00000000,00000000,?,00000000,?), ref: 6CB6BB9B
              • LocalFree.KERNEL32(?,?,?,00000004,00000000,00000000,?,00000000,?), ref: 6CB6BBCB
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorFreeInfoLastLocalNamedSecurity
              • String ID:
              • API String ID: 2595515917-0
              • Opcode ID: a066c4f30d404669c3aed09514393ca44a0c42f3ccfe5e1c6a96437dfc1bf371
              • Instruction ID: 23a393d2fa67d159aae79776f150f303cc557198bd30512530fc8593e23287d7
              • Opcode Fuzzy Hash: a066c4f30d404669c3aed09514393ca44a0c42f3ccfe5e1c6a96437dfc1bf371
              • Instruction Fuzzy Hash: 24414D71A0025D9FDF15CFA6CC80AEEB778EF05308F60416AE555A7A51DB30AE08DF61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CC403C9: PathCanonicalizeW.SHLWAPI(6CBDA393,?,?,00000007,?,?,6CC402B6,?,?,00000007,6CBDA393), ref: 6CC403FF
              • lstrcmpiW.KERNEL32(?,?,00000000,?,?,?,00000007,6CBDA393), ref: 6CC4031C
                • Part of subcall function 6CB76E35: RegCloseKey.KERNELBASE(00000000,00000000,00000000,00000001,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000,00000000,?,00000004), ref: 6CB76F41
                • Part of subcall function 6CB76E35: RegCloseKey.ADVAPI32(00000000,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000,00000000,?,00000004), ref: 6CB76F79
              Strings
              • PendingFileRenameOperations, xrefs: 6CC4035B
              • HKLM\SYSTEM\CurrentControlSet\Control\Session Manager, xrefs: 6CC40360
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$CanonicalizePathlstrcmpi
              • String ID: HKLM\SYSTEM\CurrentControlSet\Control\Session Manager$PendingFileRenameOperations
              • API String ID: 1486456407-598882528
              • Opcode ID: e44463ea27846310dbd0f551e9d058b0ea30ddb086ab35420c05dec5fa2c606a
              • Instruction ID: bb9a00f3b59869f6616d2bc1f8f99686c7d253a563b7450c66decc2720b0045e
              • Opcode Fuzzy Hash: e44463ea27846310dbd0f551e9d058b0ea30ddb086ab35420c05dec5fa2c606a
              • Instruction Fuzzy Hash: 6531D831984599ABDB05DBA5C884BEE7B75EF6131CF10C1699C21E7B90FB309A0CCB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • PathCanonicalizeW.SHLWAPI(6CB7AC58,?,00000104,?,?,?,?,6CB7AC58,?,00000000), ref: 6CB6BCD8
              • CreateDirectoryW.KERNELBASE(?,00000000,?,08740008,0000005C,00000001,?,00000000,0000005C,00000000,?,?,00000000,000000FF,?,6CB7AC58), ref: 6CB6BD3E
              • GetLastError.KERNEL32(?,?,00000000,000000FF,?,6CB7AC58,?,00000000), ref: 6CB6BD48
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CanonicalizeCreateDirectoryErrorLastPath
              • String ID:
              • API String ID: 2188824337-0
              • Opcode ID: 8e41442c7409e21399c7a9bd8a0804128c145222c9cf47170c4b2dcdad559ed8
              • Instruction ID: 1dcdf1245e1d96ddec3ab1946d5261faea7ed49d4e6ba9995e7d7728da8160ed
              • Opcode Fuzzy Hash: 8e41442c7409e21399c7a9bd8a0804128c145222c9cf47170c4b2dcdad559ed8
              • Instruction Fuzzy Hash: 5831A8726001A4EBDB14DB66CD54EEDB379DF55328F200298A51297FC0DB705E09DA91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetTokenInformation.KERNELBASE(?,00000001(TokenIntegrityLevel),00000000,00000000,00000000,?,00000000,6CD3F770,00000008,00000000), ref: 6CB6E5B4
              • GetLastError.KERNEL32 ref: 6CB6E5BA
              • GetTokenInformation.KERNELBASE(?,TokenIntegrityLevel,00000000,00000000,00000000,00000000), ref: 6CB6E60C
                • Part of subcall function 6CCC972C: _free.LIBCMT ref: 6CCC973F
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: InformationToken$ErrorLast_free
              • String ID:
              • API String ID: 3302994184-0
              • Opcode ID: 1825516f1b3ca526d12c42be8f9e7d9db0ee5eb7c000e5af64fccf48a97285e6
              • Instruction ID: b24c981c46670549e75c3dbc3910a6935d4cff9f8ff7ed2abd5bf2375029f1ea
              • Opcode Fuzzy Hash: 1825516f1b3ca526d12c42be8f9e7d9db0ee5eb7c000e5af64fccf48a97285e6
              • Instruction Fuzzy Hash: 47219231A00198EFDF019FAACC45AEFBBB8EF45358F515059E511A7A90EB30AD05CBD1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(00000000,6CB76BD7,?,00750041,?), ref: 6CB778BC
              • RegEnumKeyExW.KERNELBASE(?,00000000,?,?,00000000,00000000,00000000,?,6CB76BD7,?,00750041,?), ref: 6CB7790C
              • RegCloseKey.ADVAPI32(?), ref: 6CB77920
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$EnumOpen
              • String ID:
              • API String ID: 138425441-0
              • Opcode ID: 9aa4fd290bdfc7660f7d0123a3ee1db2576585af901350000afe823277065da8
              • Instruction ID: 28cc0181678d62396a0e1abc984cd89cf76f998a27ee312f8560f4cd60e94105
              • Opcode Fuzzy Hash: 9aa4fd290bdfc7660f7d0123a3ee1db2576585af901350000afe823277065da8
              • Instruction Fuzzy Hash: 29217371509351AFD322DF51C844A6BBBE8EF89364F108A1DF8A9A2660D774D904CBE3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80A55: CloseHandle.KERNEL32(?), ref: 6CB80ACE
              • WaitForSingleObject.KERNEL32(?,000000FF,00000000,0000001F,?,?), ref: 6CC3DB8D
              • GetExitCodeProcess.KERNEL32(?,?), ref: 6CC3DB9F
              • CloseHandle.KERNEL32(?,00000000,0000001F,?,?), ref: 6CC3DBB6
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle$CodeExitObjectProcessSingleWait
              • String ID:
              • API String ID: 4116518844-0
              • Opcode ID: 41ecc80d8a8eb0ac22bef9a8dc842793ffe5acae5d1b68e7233380e686322948
              • Instruction ID: 5fde0a4e083071a80d41eb9353ddbd9abf03e84a8839d7413ae14b43d5162e49
              • Opcode Fuzzy Hash: 41ecc80d8a8eb0ac22bef9a8dc842793ffe5acae5d1b68e7233380e686322948
              • Instruction Fuzzy Hash: AE119635E15669EBDB00DFE5DC909EE777CEF06218B1042AED522A27C0EB309A09CB50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SetCurrentDirectoryW.KERNELBASE(?), ref: 6CB8B3CE
                • Part of subcall function 6CB7934E: RaiseException.KERNEL32(00000000,00000001,00000000,00000000,6CB781E7,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB79362
              Strings
              • [is machine: %d][Current dir][%s], xrefs: 6CB8B420
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CurrentDirectoryExceptionRaise
              • String ID: [is machine: %d][Current dir][%s]
              • API String ID: 500105548-2718016943
              • Opcode ID: 108abe1dd5bd2b92903ff5be31c423efb1bb320e9aecc47fb0a83c061c7c2390
              • Instruction ID: 3e886eadfeb7108dfd437c8163690a1c193807124620049c018797eb21b2817a
              • Opcode Fuzzy Hash: 108abe1dd5bd2b92903ff5be31c423efb1bb320e9aecc47fb0a83c061c7c2390
              • Instruction Fuzzy Hash: AA411570A021C5ABDB059FB5CC51AFEBBB5EF45308F24816AD465D7B90DF305908CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: _strftime
              • String ID: %Y-%m-%dT%H:%M:%S
              • API String ID: 1867682108-3293947673
              • Opcode ID: 030d6572563c9b1c685f0cd6eacda119e34b2db20fe6bea702f49b0ac9c809fc
              • Instruction ID: 380c5372f18fb82b56a2548a9f31544965ab280605be6169d6ba691851c31cd0
              • Opcode Fuzzy Hash: 030d6572563c9b1c685f0cd6eacda119e34b2db20fe6bea702f49b0ac9c809fc
              • Instruction Fuzzy Hash: 0B21A0B4A00219ABEB04DBA4CC84EEE77BCEF09358F504599E501EB640EB31EE44DB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • QueryPerformanceCounter.KERNEL32(00000001,00000000,00000000,?,?,?,?,?,6CC40518,00000001,6CBDA393,?,?), ref: 6CC40B6D
                • Part of subcall function 6CBC58DE: QueryPerformanceCounter.KERNEL32(?,?,?,00000000,?,?,?,?,6CC3E248,?,?,?,?,?,6CC3E0E1,00000000), ref: 6CBC58ED
                • Part of subcall function 6CBC58DE: __aulldiv.LIBCMT ref: 6CBC5930
                • Part of subcall function 6CB7FD4B: EnterCriticalSection.KERNEL32(6CD7CA74,?,?,?,6CC3E254,00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000), ref: 6CB7FD58
                • Part of subcall function 6CB7FD4B: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CC3E254,00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CB7FDA2
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
              Strings
              • [Install task failed][0x%08x], xrefs: 6CC40C09
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$CounterEnterLeavePerformanceQuery$__aulldiv
              • String ID: [Install task failed][0x%08x]
              • API String ID: 3177343107-585468084
              • Opcode ID: d8f5c137a49d37ac6b6f5d570a8d2fc278051d883c84a4188c5f20f84505bc50
              • Instruction ID: b9b1a77b5f9f90e057bf591cb05385a0c74b0dcc18dc823c55227a22a37d45ad
              • Opcode Fuzzy Hash: d8f5c137a49d37ac6b6f5d570a8d2fc278051d883c84a4188c5f20f84505bc50
              • Instruction Fuzzy Hash: 7E21F7B2D00199ABCB14DFF8C8519FEB7F8DF45658F10456AD511F7B90EB348A088BA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB73CD5: PathRemoveFileSpecW.SHLWAPI(00000000,?,00000000,00000000,00000068,00000068,?,6CB72909,00000068,00000068,?,6CB7297A,6CD7CA54,6CB7B5C0), ref: 6CB73CF6
                • Part of subcall function 6CB6E978: GetFileAttributesExW.KERNEL32(?,00000000,?,?,?,?,6CB68F4E,?,?,6CB68315,00000000,?,?,00000000,?), ref: 6CB6E99C
              • OutputDebugStringW.KERNEL32(00000000,00000001,?), ref: 6CB686F1
                • Part of subcall function 6CB6BCA2: PathCanonicalizeW.SHLWAPI(6CB7AC58,?,00000104,?,?,?,?,6CB7AC58,?,00000000), ref: 6CB6BCD8
              Strings
              • LOG_SYSTEM: [%s]: ERROR - Cannot create log writer to %s, xrefs: 6CB686E3
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FilePath$AttributesCanonicalizeDebugOutputRemoveSpecString
              • String ID: LOG_SYSTEM: [%s]: ERROR - Cannot create log writer to %s
              • API String ID: 250198402-2755948774
              • Opcode ID: 07fc6e2b7046fb5737805bee00d1619d720c4c26131bf9848adc50989f0ed066
              • Instruction ID: 551f33ee536c3f0e9952859fa5aaa943da9a3f4adccfd343637a48a0b9a3891f
              • Opcode Fuzzy Hash: 07fc6e2b7046fb5737805bee00d1619d720c4c26131bf9848adc50989f0ed066
              • Instruction Fuzzy Hash: 5C21D231600181AADB019FA7C890BEDB7B8EF5231CF04046AD8569BF91EB719A0DCB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB68301: GetPrivateProfileIntW.KERNEL32(LoggingSettings,EnableLogging,00000001,00000000), ref: 6CB68334
                • Part of subcall function 6CB68301: GetPrivateProfileIntW.KERNEL32(LoggingSettings,ShowTime,00000001,00000000), ref: 6CB6834B
                • Part of subcall function 6CB68301: GetPrivateProfileIntW.KERNEL32(LoggingSettings,LogToFile,00000001,00000000), ref: 6CB68362
                • Part of subcall function 6CB68301: GetPrivateProfileIntW.KERNEL32(LoggingSettings,LogToOutputDebug,00000000,00000000), ref: 6CB68379
                • Part of subcall function 6CB68301: GetPrivateProfileIntW.KERNEL32(LoggingSettings,AppendToFile,00000001,00000000), ref: 6CB68390
                • Part of subcall function 6CB68301: GetPrivateProfileIntW.KERNEL32(LoggingLevel,00000001,00000003,?), ref: 6CB68403
                • Part of subcall function 6CB6CC21: GetEnvironmentVariableW.KERNEL32(SystemDrive,00000000,00000000,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB6CC32
                • Part of subcall function 6CB6CC21: GetEnvironmentVariableW.KERNEL32(SystemDrive,00000000,00000000,00000000,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB6CC49
              • GetShortPathNameW.KERNELBASE(?,?,00000104), ref: 6CB68140
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: PrivateProfile$EnvironmentVariable$NamePathShort
              • String ID: USERPROFILE
              • API String ID: 125441260-2419442777
              • Opcode ID: f9abee5ed3bf0130ad21d7dd3ebcb3cb0a222c37c6b3a61d349f136f7334b168
              • Instruction ID: e544eb51064fac3c1109d36941082ee9fc17ce2bcf14f80ac245e5a45482b9a9
              • Opcode Fuzzy Hash: f9abee5ed3bf0130ad21d7dd3ebcb3cb0a222c37c6b3a61d349f136f7334b168
              • Instruction Fuzzy Hash: 3D113032A00194EBCF04EBAAC9A48EDB779EF95329B1001A8D562A7FD4DB315F0DD750
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB68450: SHGetFolderPathW.SHELL32(00000000,00000023,00000000,00000000,00000000,Microsoft\EdgeUpdate\Log,00000000,?,?,?,?,?,?,6CB68569,00000000), ref: 6CB684C6
              • PathAppendW.SHLWAPI(00000000,MicrosoftEdgeUpdate.log,?,00000000,?,?,6CB6867D,00000000,?,?,00000000,?,?,?,6CB68726), ref: 6CB685B1
              Strings
              • MicrosoftEdgeUpdate.log, xrefs: 6CB685AB
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Path$AppendFolder
              • String ID: MicrosoftEdgeUpdate.log
              • API String ID: 29327785-335696976
              • Opcode ID: a5be060a0b3a00ccdd718ced189e92764a8251f26319848058495865f3159eb1
              • Instruction ID: ba53a45955fe51067c71d172668525d1b1a02dd8aeb447d0fb2b46f5f33d9e5d
              • Opcode Fuzzy Hash: a5be060a0b3a00ccdd718ced189e92764a8251f26319848058495865f3159eb1
              • Instruction Fuzzy Hash: AE118231900458EBCB08EFAAC9549EDB375EF4232CB104258E9569BFD4DB30AF08CB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE2FE6
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE300A
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE302E
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE3055
              • SysFreeString.OLEAUT32(?), ref: 6CBE3172
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: InitVariant$FreeString
              • String ID: `)u
              • API String ID: 3892671615-4279031584
              • Opcode ID: 82a50cb487cee11d15632bc34c8cb4a064a9fc3cb6a04fa507001adcc666f497
              • Instruction ID: a9a71ec9b0911864bf45b53975a334734dd701b7b2c4a39afd5654d23bc75dd7
              • Opcode Fuzzy Hash: 82a50cb487cee11d15632bc34c8cb4a064a9fc3cb6a04fa507001adcc666f497
              • Instruction Fuzzy Hash: 991130B5E01219EF8B01DF98C88489EBBB8FF4DB44B1140ADE911A7310DB709E05DF91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateProcessW.KERNELBASE(00000000,00000000,00000000,00000000,00000000,00000400,00000001,00000000,6CB75BCC,00000000,00000000,6CB75BCC,00000000,?,00000001,00000048), ref: 6CB75BF9
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CreateProcess
              • String ID: [Started process][%u]
              • API String ID: 963392458-93102190
              • Opcode ID: 773e10070d704db6b0a5375f3e14f035c99e80d328c1b049c474b18331e527be
              • Instruction ID: d4fdf6b417091832b667978c1cbc3a319e5f95d4f7b9017c430a7d8ce173874d
              • Opcode Fuzzy Hash: 773e10070d704db6b0a5375f3e14f035c99e80d328c1b049c474b18331e527be
              • Instruction Fuzzy Hash: 7801A7F1E44255BEEF149FB58C01EBF3ABCEB45305F04842ABE25E6650E63095048775
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OutputDebugStringW.KERNEL32(00000000,?,00000000,?,?,?,6CB68A24,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB688CC
              Strings
              • LOG_SYSTEM: [%s]: ERROR - Calling the logging system after it has been shut down , xrefs: 6CB688BF
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DebugOutputString
              • String ID: LOG_SYSTEM: [%s]: ERROR - Calling the logging system after it has been shut down
              • API String ID: 1166629820-1171486310
              • Opcode ID: 23e7c86caa31f6e7e3e616d8bbf89ec55223c9b7809e5e2d3f81f0ab0614c1a1
              • Instruction ID: 92e735b5bdd227b64a71e4cacac89c033013579b9f8f370e1ee5f354302e8caa
              • Opcode Fuzzy Hash: 23e7c86caa31f6e7e3e616d8bbf89ec55223c9b7809e5e2d3f81f0ab0614c1a1
              • Instruction Fuzzy Hash: FDF0A4316042A4EFEB04DB65C8499EEB7ACEF03318B00055ED44253F90DBB2AD89C7A1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetComputerNameExW.KERNEL32(00000003,?,00000100), ref: 6CB7D86D
                • Part of subcall function 6CB70A00: lstrlenW.KERNEL32(?,?,?,6CD3E5FC,?,?,?,6CB70A96,00000000,?,?,00000000,?,?,6CB6EC41), ref: 6CB70A13
                • Part of subcall function 6CB70A00: lstrlenW.KERNEL32(6CD3E5FC,?,?,?,6CD3E5FC,?,?,?,6CB70A96,00000000,?,?,00000000,?,?,6CB6EC41), ref: 6CB70A19
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrlen$ComputerName
              • String ID: .corp.microsoft.com
              • API String ID: 703476150-2584639764
              • Opcode ID: cd738f790b310e5cb932636c1aee98182fcda85f4a9f186cb13834e76fa12107
              • Instruction ID: 72495dae464e24121e1b3e7e98c4ca6fb38876e66ba5b27aeb3a7120eac687d7
              • Opcode Fuzzy Hash: cd738f790b310e5cb932636c1aee98182fcda85f4a9f186cb13834e76fa12107
              • Instruction Fuzzy Hash: 3001F974A003499AEF20DBB08809FDE777C9B01308F4040A99A61EB6C1EB70DA48CB31
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB8353D: RegCloseKey.ADVAPI32(00000000,?,000F003F), ref: 6CB83590
              • __aulldiv.LIBCMT ref: 6CB834D8
                • Part of subcall function 6CB83501: __aulldiv.LIBCMT ref: 6CB83516
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: __aulldiv$Close
              • String ID: UpdateTime
              • API String ID: 1267261129-452415538
              • Opcode ID: 28dd74918394b26a641704756306448a32884b3e9f7b074c876e75b2559cfa30
              • Instruction ID: 6b27756b1c239001cd1b85398d570f67846b29f176157de7baf21a2708210b2c
              • Opcode Fuzzy Hash: 28dd74918394b26a641704756306448a32884b3e9f7b074c876e75b2559cfa30
              • Instruction Fuzzy Hash: 47F0A7B26462847FE6105660DC52BEE2B9CCB8169CF184419F5488BBC0EA629D4483A5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6AEEB: CreateWindowExW.USER32(?,0000003C,00000000,?,?,0096840F,44890000,7E891424,00000007,?,00000000,00000007), ref: 6CB6AF2D
                • Part of subcall function 6CB6AF3E: GetWindowLongW.USER32(?,000000F0), ref: 6CB6AF5D
                • Part of subcall function 6CB6AF3E: GetWindowRect.USER32(?,00000000), ref: 6CB6AF8D
                • Part of subcall function 6CB6AF3E: GetWindowLongW.USER32(0000003C,000000F0), ref: 6CB6AFA2
                • Part of subcall function 6CB6AF3E: MonitorFromWindow.USER32(?,00000002), ref: 6CB6AFBA
                • Part of subcall function 6CB6AF3E: GetMonitorInfoW.USER32(00000000,?), ref: 6CB6AFD0
              • KiUserCallbackDispatcher.NTDLL(?), ref: 6CB6B139
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Window$LongMonitor$CallbackCreateDispatcherFromInfoRectUser
              • String ID: STATIC
              • API String ID: 2419797638-1882779555
              • Opcode ID: f93435ead05adaa0e366e018124f785421c78f50cdffbe3aa76e722432730042
              • Instruction ID: fecc5b5a7fecfba4a2ae6d1b35fdccba00e2c99c00de2f3521163d5d1dc708bb
              • Opcode Fuzzy Hash: f93435ead05adaa0e366e018124f785421c78f50cdffbe3aa76e722432730042
              • Instruction Fuzzy Hash: 99F012B2611274BBDE149B46DD05ADF7B7CEF06650F100184B905A7A50D7706F04D6E5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6E978: GetFileAttributesExW.KERNEL32(?,00000000,?,?,?,?,6CB68F4E,?,?,6CB68315,00000000,?,?,00000000,?), ref: 6CB6E99C
              • _Deallocate.LIBCONCRT ref: 6CC3FFF5
                • Part of subcall function 6CB6BCA2: PathCanonicalizeW.SHLWAPI(6CB7AC58,?,00000104,?,?,?,?,6CB7AC58,?,00000000), ref: 6CB6BCD8
              • _Deallocate.LIBCONCRT ref: 6CC40033
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate$AttributesCanonicalizeFilePath
              • String ID:
              • API String ID: 3122508939-0
              • Opcode ID: e52454611ab274f507d2b1e51533886924feefb2e599cc39340480f2fcd4a3b9
              • Instruction ID: 15cd2a90619ecb2ad64ee969c6eef30ef0bc667509e663423f8dabd2e46c1580
              • Opcode Fuzzy Hash: e52454611ab274f507d2b1e51533886924feefb2e599cc39340480f2fcd4a3b9
              • Instruction Fuzzy Hash: F4511832D01169DFDF04DFA9D9909EDBBB0FF09318B244569D815B7A90EB31AE09CB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM,00000000,?,?,00000000,?,00000000,80070003,?,?,?), ref: 6CB779E9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE,?,?), ref: 6CB779F9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU,?,?), ref: 6CB77A09
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER,?,?), ref: 6CB77A19
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU[64],?,?), ref: 6CB77A29
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER[64],?,?), ref: 6CB77A39
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKU,?,?), ref: 6CB77A45
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_USERS,?,?), ref: 6CB77A51
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCR,?,?), ref: 6CB77A5D
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CLASSES_ROOT,?,?), ref: 6CB77A69
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM[64],?,?), ref: 6CB77A75
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE[64],?,?), ref: 6CB77A81
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.KERNELBASE(00000000,?,00000000,00000000,?,?,?,?,?,?), ref: 6CB77093
              • RegCloseKey.ADVAPI32(00000000,00000000,?,?,?,?,?,?), ref: 6CB770CB
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Close$Open
              • String ID:
              • API String ID: 1041768801-0
              • Opcode ID: a138145820b090326fc840faee9225b64c2108393c118af306bf4f626d538e29
              • Instruction ID: f7e4f9c298cddc9ce197dd24ec181b4b008eb13ea8bacd2af0ecb1a638de06ea
              • Opcode Fuzzy Hash: a138145820b090326fc840faee9225b64c2108393c118af306bf4f626d538e29
              • Instruction Fuzzy Hash: F141817690014AABDF12DBA4C858AEE7B7DEB40218F204159E925F3A50DB70DA09CBB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • _Deallocate.LIBCONCRT ref: 6CB93476
                • Part of subcall function 6CBE503A: lstrcmpiW.KERNEL32(00000068,6CD1A13C,00000000,?,00000000,?,?,?,6CBE519D,?,00000000,?,?,?,6CB8BBF2,?), ref: 6CBE505B
              • lstrcmpiW.KERNEL32(6CBDA393,6CC3D928,?,?,?,?,6CC3D928,?,00000000,00000000,6CBDA393,?), ref: 6CB933FC
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Deallocate
              • String ID:
              • API String ID: 3478940063-0
              • Opcode ID: c8d20f2bc51a68e1899a311016a0f7bdc2880b090aaed0fa15a8980c70ea1ea9
              • Instruction ID: 77f94af58a67d152de3cc140efd4e86d79d7c6eca96a2da5285bf490cf62478f
              • Opcode Fuzzy Hash: c8d20f2bc51a68e1899a311016a0f7bdc2880b090aaed0fa15a8980c70ea1ea9
              • Instruction Fuzzy Hash: 1631D632D0418A9FDF11DFA9C8446EEFB74EF06318F154169C865B3B80DB30A949CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              • SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,?,6CB7C8FE,?,?,?,00000000), ref: 6CB77313
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: QueryValue
              • String ID:
              • API String ID: 3660427363-0
              • Opcode ID: 83e65827fc9a0488c09d37b9cba669ad5b2705670f14e46fd74f3483c0401d37
              • Instruction ID: f565e1a8e9695b1c1b8ae1078ca987270dcafaa2263391d4d7d3659d4c0a43b5
              • Opcode Fuzzy Hash: 83e65827fc9a0488c09d37b9cba669ad5b2705670f14e46fd74f3483c0401d37
              • Instruction Fuzzy Hash: 3721D773A00164ABDB26CE94CC009AEB779EF45264B158229ED61FBB40D7B0ED4187E0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6C9C6: SetForegroundWindow.USER32(00000000), ref: 6CB6CA19
                • Part of subcall function 6CB6C9C6: ShellExecuteExW.SHELL32(?), ref: 6CB6CA20
                • Part of subcall function 6CB6C9C6: AllowSetForegroundWindow.USER32(00000000), ref: 6CB6CA87
                • Part of subcall function 6CB6C9C6: DestroyWindow.USER32(?,?,?,?,?,?,?,6CB75E7D,?,?,00000001), ref: 6CB6CAED
                • Part of subcall function 6CB6C9C6: SetLastError.KERNEL32(00000000,?,?,?,?,?,?,6CB75E7D,?,?,00000001), ref: 6CB6CAFC
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              • CloseHandle.KERNEL32(6CB80A93,?,?,00000001), ref: 6CB75EF3
              Strings
              • [Failed to ::ShellExecuteEx][%s][%s][0x%08x], xrefs: 6CB75EC5
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Window$ErrorForegroundLast$AllowCloseDestroyExecuteHandleShell
              • String ID: [Failed to ::ShellExecuteEx][%s][%s][0x%08x]
              • API String ID: 1589436413-972892863
              • Opcode ID: 053e937f95f75bbfa605ea269beb02bc8e7a44443e502c3b996a05b595e8c3de
              • Instruction ID: dd9edf2aad9fc028737ce17b91662cfeaede74c055525a6a2e2ec59fbe253eb4
              • Opcode Fuzzy Hash: 053e937f95f75bbfa605ea269beb02bc8e7a44443e502c3b996a05b595e8c3de
              • Instruction Fuzzy Hash: 0F21B3B1E00258AFDF14DFAACC45AEEBB78EF45318F10412DE915E6B90DB705908CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SHGetKnownFolderPath.SHELL32(00531060,00000000,00000000,?), ref: 00538E91
              • CoTaskMemFree.OLE32(?,?), ref: 00538F16
              Memory Dump Source
              • Source File: 00000009.00000002.3518826290.0000000000531000.00000020.00000001.01000000.00000012.sdmp, Offset: 00530000, based on PE: true
              • Associated: 00000009.00000002.3518772049.0000000000530000.00000002.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518888720.000000000054A000.00000004.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518947315.000000000054C000.00000002.00000001.01000000.00000012.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_530000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FolderFreeKnownPathTask
              • String ID:
              • API String ID: 969438705-0
              • Opcode ID: 54f59d2f63099666388226168e02942294be56efde5d1b7bd3e476d51b5fbfc7
              • Instruction ID: 0b3ea6cdcee668dd42d2488c38de7d267100d74fb7aa79496da80a105e9e991e
              • Opcode Fuzzy Hash: 54f59d2f63099666388226168e02942294be56efde5d1b7bd3e476d51b5fbfc7
              • Instruction Fuzzy Hash: 63217C7590020AAFCF09DFA4D8959FEBF79FB81304F044469E902A7251EA316A45DB54
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM,00000000,?,?,00000000,?,00000000,80070003,?,?,?), ref: 6CB779E9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE,?,?), ref: 6CB779F9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU,?,?), ref: 6CB77A09
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER,?,?), ref: 6CB77A19
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU[64],?,?), ref: 6CB77A29
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER[64],?,?), ref: 6CB77A39
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKU,?,?), ref: 6CB77A45
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_USERS,?,?), ref: 6CB77A51
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCR,?,?), ref: 6CB77A5D
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CLASSES_ROOT,?,?), ref: 6CB77A69
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM[64],?,?), ref: 6CB77A75
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE[64],?,?), ref: 6CB77A81
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(00000000,00000000,?,?,?,?,?,?), ref: 6CB77765
              • RegCloseKey.ADVAPI32(00000000,00000000,?,?,?,?,?,?), ref: 6CB7777F
                • Part of subcall function 6CB77843: RegCloseKey.ADVAPI32(00000000,6CB76BD7,?,00750041,?), ref: 6CB778BC
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Close$Open
              • String ID:
              • API String ID: 1041768801-0
              • Opcode ID: 1e9d9b9a91542c09c7091e1d3b665aff05e5972483cacade6ae5f1c0c460b240
              • Instruction ID: 938fbc2e9de48159fc1b3994cb505f1a91484b71da1b1178f58907ee1ea7ab1b
              • Opcode Fuzzy Hash: 1e9d9b9a91542c09c7091e1d3b665aff05e5972483cacade6ae5f1c0c460b240
              • Instruction Fuzzy Hash: 6F21A776900249ABDB11DBA5C885BEEB7B5EF51358F200454C831B3B50DB789B0CCBB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 00538E69: SHGetKnownFolderPath.SHELL32(00531060,00000000,00000000,?), ref: 00538E91
                • Part of subcall function 00538E69: CoTaskMemFree.OLE32(?,?), ref: 00538F16
                • Part of subcall function 00538D5F: GetModuleFileNameW.KERNEL32(00000000,?,00000104), ref: 00538D8D
              • LoadLibraryExW.KERNELBASE(?,00000000,00000000), ref: 00539638
              • GetLastError.KERNEL32 ref: 00539642
              Memory Dump Source
              • Source File: 00000009.00000002.3518826290.0000000000531000.00000020.00000001.01000000.00000012.sdmp, Offset: 00530000, based on PE: true
              • Associated: 00000009.00000002.3518772049.0000000000530000.00000002.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518888720.000000000054A000.00000004.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518947315.000000000054C000.00000002.00000001.01000000.00000012.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_530000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorFileFolderFreeKnownLastLibraryLoadModuleNamePathTask
              • String ID:
              • API String ID: 1629683262-0
              • Opcode ID: 877e8d82455f027fbd071fc0329000863f8cfb0d7e53f292283c0287ac743833
              • Instruction ID: c5bd64b9db878c2e1dcd841674cc6bdaeeab2b5fad39a661f29564010b5f9c50
              • Opcode Fuzzy Hash: 877e8d82455f027fbd071fc0329000863f8cfb0d7e53f292283c0287ac743833
              • Instruction Fuzzy Hash: 7011B775D02616DBCF00FBB5994A8EEBF78BF44704F400559E801BB242DB745D05C7A5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,?,00000000,?,6CD3F7F0,6CD3F7F0,?,6CB77087,?,00000000,00000000,?), ref: 6CB7721A
              • SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,6CB77087,?,00000000,00000000,?,?,?,?,?), ref: 6CB7726C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: QueryValue
              • String ID:
              • API String ID: 3660427363-0
              • Opcode ID: 80f3b67b1bd1f7dd8eceadbf1bab3781100936d0a4d1acea2889888cba9104a3
              • Instruction ID: 7963e56a426fed22296370273df95d46824ec68703fef0fc717a19fdb443af79
              • Opcode Fuzzy Hash: 80f3b67b1bd1f7dd8eceadbf1bab3781100936d0a4d1acea2889888cba9104a3
              • Instruction Fuzzy Hash: 80119477A10124BFDB16CB94C905AAEB7BCEF05350F11426ABD15FB650EB71DE018BA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNEL32(?,windowsupdate,?,?,?), ref: 6CBE0A3B
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi
              • String ID: windowsupdate
              • API String ID: 1586166983-1989081954
              • Opcode ID: 89a1ee3471d65dbcdd33eddc6d14bfdf7717bda50c0721ed9ba4aa490701d0a0
              • Instruction ID: af49d8e985b90632be768352a2e9a9ef0a49d249e89e3d350ec05527d9ba8008
              • Opcode Fuzzy Hash: 89a1ee3471d65dbcdd33eddc6d14bfdf7717bda50c0721ed9ba4aa490701d0a0
              • Instruction Fuzzy Hash: 1911EF3220519AAFDB04DF29D850AEEBB65FF05758F008029E8194BB80DF31A92CCB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateFileW.KERNELBASE(?,00000000,?,00000000,-00000003,10000000,00000000,?,00000000,00000000,?,?,?,6CB6C483,?,00000000), ref: 6CB6E93D
              • SetFileAttributesW.KERNEL32(?,00002000,?,?,?,6CB6C483,?,00000000,?,00000000), ref: 6CB6E95B
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: File$AttributesCreate
              • String ID:
              • API String ID: 415043291-0
              • Opcode ID: ecfa38c71c59bbe1d88509a8dad4f64513235821735a298b020408915864b6a8
              • Instruction ID: 7b7c5b3a56f6b4caf30bf860467152bccaf1636254f060527ef819fc8a50ca95
              • Opcode Fuzzy Hash: ecfa38c71c59bbe1d88509a8dad4f64513235821735a298b020408915864b6a8
              • Instruction Fuzzy Hash: DA01FC32289A953AE7008A36EC19BEA735CDF02268F148122F952D6EC1D765E80487F1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM,00000000,?,?,00000000,?,00000000,80070003,?,?,?), ref: 6CB779E9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE,?,?), ref: 6CB779F9
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU,?,?), ref: 6CB77A09
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER,?,?), ref: 6CB77A19
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCU[64],?,?), ref: 6CB77A29
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER[64],?,?), ref: 6CB77A39
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKU,?,?), ref: 6CB77A45
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_USERS,?,?), ref: 6CB77A51
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKCR,?,?), ref: 6CB77A5D
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_CLASSES_ROOT,?,?), ref: 6CB77A69
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKLM[64],?,?), ref: 6CB77A75
                • Part of subcall function 6CB77946: lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE[64],?,?), ref: 6CB77A81
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(00000000,00000000,6CB8308D,?,00000001,00000000,00000000), ref: 6CB7782F
                • Part of subcall function 6CB76BA7: RegDeleteValueW.KERNELBASE(6CB76BD7,00000000,?,6CB77802,?,00000000,6CB8308D,?,00000001,00000000,00000000), ref: 6CB76BB0
              • RegCloseKey.ADVAPI32(00000000,?,00000000,6CB8308D,?,00000001,00000000,00000000), ref: 6CB7780C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Close$DeleteOpenValue
              • String ID:
              • API String ID: 844453251-0
              • Opcode ID: 3b79b4a8799aaaf32f82de9b83dc27556aac2517bc346a470a27a0643832fbac
              • Instruction ID: 457a96d1a2b2972c81281173dc974212fe081733b72c28cae12f68822c998825
              • Opcode Fuzzy Hash: 3b79b4a8799aaaf32f82de9b83dc27556aac2517bc346a470a27a0643832fbac
              • Instruction Fuzzy Hash: 3F1177B190015AABDF11DFA6C945BEF77B9EF45315F1000689825F3650DB709B05CBB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • NetGetJoinInformation.NETAPI32(00000000,?,6CB6D864,?,?,?,6CB6D864,?,00000000,00000000,00000068,6CD7CA54,00000000), ref: 6CB6D6C4
              • NetApiBufferFree.NETAPI32(?,?,?,?,6CB6D864,?,00000000,00000000,00000068,6CD7CA54,00000000), ref: 6CB6D6D6
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: BufferFreeInformationJoin
              • String ID:
              • API String ID: 3807213042-0
              • Opcode ID: 32ebb20419b6e97f46248815c4a63e67039c00a54d10d0c449b129b67fc69481
              • Instruction ID: ec60eb1d72ac87bc2aa5b3acc8eb56aef8bd336c886d46d13bbf579e24ea2df2
              • Opcode Fuzzy Hash: 32ebb20419b6e97f46248815c4a63e67039c00a54d10d0c449b129b67fc69481
              • Instruction Fuzzy Hash: 5DF05470725155EBDB0ACB79E905E9AB7B8DB0272AF20035CE226525D0D770D641DA11
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SetNamedSecurityInfoW.ADVAPI32(?,?,00000004,00000000,00000000,00000000,00000000), ref: 6CB67DC6
              • SetLastError.KERNEL32(00000000,?,?,00000004,00000000,00000000,00000000,00000000), ref: 6CB67DCF
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorInfoLastNamedSecurity
              • String ID:
              • API String ID: 2346220347-0
              • Opcode ID: e77954e6ef749c40bcbcb8b8bd44a82d63d1a80b875162a9fa0676ab8eddeb04
              • Instruction ID: b73c2a8cdb77bd539e3914a8f782db9bed5ec76ac65d699ebfbc3459e7a3d1e2
              • Opcode Fuzzy Hash: e77954e6ef749c40bcbcb8b8bd44a82d63d1a80b875162a9fa0676ab8eddeb04
              • Instruction Fuzzy Hash: 63E04F7678573477E621156ACC16FAA266CCF83FA5F054116FB08ABA8086D05C0146F9
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateSolidBrush.GDI32(00727272), ref: 6CCA3E19
              • CreateSolidBrush.GDI32(00C1C1C1), ref: 6CCA3E27
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: BrushCreateSolid
              • String ID:
              • API String ID: 4168422804-0
              • Opcode ID: 5e3824b8ded778a7aa2b150a49217fcf1cd1216a7dac43ffc6fb7bcca46df930
              • Instruction ID: 46cbc1efea216cdbd66e612d3c8559f4e68cd0db12ad53b02182bff1156475a1
              • Opcode Fuzzy Hash: 5e3824b8ded778a7aa2b150a49217fcf1cd1216a7dac43ffc6fb7bcca46df930
              • Instruction Fuzzy Hash: CEF0BCB6A01A06BFD7048FAAC6C0455FBB4FF49341390222EE10983E00DB70E5A4CFD4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB73073: GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6CB7325C,00000010,6CBC7752,0000001C,00000000,6CC071A1,0000002C,00000000,00000000), ref: 6CB73094
                • Part of subcall function 6CB73073: GetProcAddress.KERNEL32(00000000,CreateMutexExW), ref: 6CB730A6
                • Part of subcall function 6CB73073: GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 6CB730B7
              • CreateMutexExW.KERNELBASE(?,?,00000000,00100001,00000007,?,?,6CC3E9B8,?,6CD7C950,?,?,6CC3DE4E,00000000,00000000,00000000), ref: 6CB730E2
              • CreateMutexW.KERNEL32(?,00000000,?,00000007,?,?,6CC3E9B8,?,6CD7C950,?,?,6CC3DE4E,00000000,00000000,00000000), ref: 6CB730EA
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressCreateMutexProc$HandleModule
              • String ID:
              • API String ID: 56544078-0
              • Opcode ID: 8badef288a883618f67b4265e8652c1ffbbe9005a59c8ba4fb713ca35d6ad831
              • Instruction ID: 22708b4dbad82835b9310f27fc4275350621918f77b7affc76b219d0862e2968
              • Opcode Fuzzy Hash: 8badef288a883618f67b4265e8652c1ffbbe9005a59c8ba4fb713ca35d6ad831
              • Instruction Fuzzy Hash: 61D05B313855917AF535551A5C0DF8B556CCFC7B91F100059F615D35C0DFD2940142B5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CopyFileW.KERNELBASE(?,?,00000000), ref: 6CB6EBBB
              • GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CopyErrorFileLast
              • String ID:
              • API String ID: 374144340-0
              • Opcode ID: c4f06caf9f2c1b96a021241d59fd0924627c459228c11e52fa640cfc7ee8e630
              • Instruction ID: e452063d596764d1e964b27c04369571b916598842d3c4395d214db06202483a
              • Opcode Fuzzy Hash: c4f06caf9f2c1b96a021241d59fd0924627c459228c11e52fa640cfc7ee8e630
              • Instruction Fuzzy Hash: CCD02E62B8697027EA3006281C0076F0228AB45A42F02012AFC30FAEC4DB06CC0063F6
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • MoveFileExW.KERNELBASE(?,?,0000000B,6CB696D8,.bak,?,?,?,?,?,6CB694FE), ref: 6CB6EBD0
              • GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorFileLastMove
              • String ID:
              • API String ID: 55378915-0
              • Opcode ID: 797ca65c334adca80ff96222fad2eba6532b665bf365b4cbfc83fa192d7be00d
              • Instruction ID: f4fffb01ee3c22f34e2b2e2439249aa46543be35126bdde8be84734ed0bb5743
              • Opcode Fuzzy Hash: 797ca65c334adca80ff96222fad2eba6532b665bf365b4cbfc83fa192d7be00d
              • Instruction Fuzzy Hash: 9AD02E62B8657027EA3106380C00B6F1128FB4AA42F02052AFD30FAEC4CB06CC0063F2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrlenW.KERNEL32(00000000,?,?,6CB76F35,00000000,00000000,00000001,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000), ref: 6CB77410
              • RegSetValueExW.KERNELBASE(6CB76BD7,00000000,00000000,00000001,00000000,00000000,?,6CB76F35,00000000,00000000,00000001,00000000,?,00000000,00000000), ref: 6CB7742C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Valuelstrlen
              • String ID:
              • API String ID: 799288031-0
              • Opcode ID: 1f3c0c5bfc3f0712be5a9041efd0c16016b17b57335a1aa31c7f7879557aea48
              • Instruction ID: 7e4525914b15b1f7cc52ca6b7b70cfd110ede9628cf99d1637a78d5b0401f67e
              • Opcode Fuzzy Hash: 1f3c0c5bfc3f0712be5a9041efd0c16016b17b57335a1aa31c7f7879557aea48
              • Instruction Fuzzy Hash: 90E04F35100129FBDF215F51DD05F9A3F6DEB05760F408415FE1889120CB36D420DBB4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle
              • String ID:
              • API String ID: 2962429428-0
              • Opcode ID: c0a6d8e575108945af8096627280c5fdab1d432e58d2c62019faff224c189594
              • Instruction ID: c34ca6c2c671a79d69bb3faf79aabde8ecc22f5d8ae591310583a12a0e48cd9d
              • Opcode Fuzzy Hash: c0a6d8e575108945af8096627280c5fdab1d432e58d2c62019faff224c189594
              • Instruction Fuzzy Hash: FB110C7620B3856BD710DE29E840A5FB7E5EBD8264F00052DF95487791DB30990DC7A3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • PathAppendW.SHLWAPI(?,00000000,00000068,00C4B988,811C9DC5,00000000,6CD7CA54,00000000,00000068,6CD7CA54,00C4B988), ref: 6CB7AC11
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AppendPath
              • String ID:
              • API String ID: 3286331749-0
              • Opcode ID: 823d58fda1c2cf8502024b5d3af6d44d83c4c0226758fa0b25c8a4680a390ea8
              • Instruction ID: 3f429f705a0b0b020102a185fd7f11b29b6f6d788e936f8a4d380bbe4cadf343
              • Opcode Fuzzy Hash: 823d58fda1c2cf8502024b5d3af6d44d83c4c0226758fa0b25c8a4680a390ea8
              • Instruction Fuzzy Hash: D3310832E00064ABCB25DBBACD549DDB7B9DF44714B144165E825E7B80DB30DE04CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcess.KERNEL32(6CD7C950,?,00000007), ref: 6CB6C91D
                • Part of subcall function 6CB6AE6A: GetCurrentProcess.KERNEL32(00000000,?,6CB6C92F,00000008,00000000,?,00000007), ref: 6CB6AE77
                • Part of subcall function 6CB6AE6A: OpenProcessToken.ADVAPI32(00000000,?,00000000,00000000,?,6CB6C92F,00000008,00000000,?,00000007), ref: 6CB6AE85
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Process$Current$ErrorLastOpenToken
              • String ID:
              • API String ID: 952164762-0
              • Opcode ID: 65ff1e426b2ce0760ec1a6bd8789c769247a9725a7b90ee55352d63a2964a2af
              • Instruction ID: 737048f3aaf8920348af1fa71b5a96cce088f9fb2045f3295d73f738698b9533
              • Opcode Fuzzy Hash: 65ff1e426b2ce0760ec1a6bd8789c769247a9725a7b90ee55352d63a2964a2af
              • Instruction Fuzzy Hash: FB2165715183919BD710DF65C840ADEB7A8BB84308F400D2EF59AA3E90EB70590DCBA3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCreateKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00000000,80070003,?,6CD3F7F0,?,6CB76E8D,00000000,?), ref: 6CB76C45
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Create
              • String ID:
              • API String ID: 2289755597-0
              • Opcode ID: c0be9231eafa960b2a6ff072d1b76c697565ea8dcdcfe4791cce40682269ec15
              • Instruction ID: e4425e70a8e569cf2ffbe203a2748118a6c5fde4d5758e3da2006e5af7191a12
              • Opcode Fuzzy Hash: c0be9231eafa960b2a6ff072d1b76c697565ea8dcdcfe4791cce40682269ec15
              • Instruction Fuzzy Hash: 3C015BB6A00116AFEB09CF1AC8509BA7BBAEBD8314B15C22DFC15D7740DA30DD118BA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate
              • String ID:
              • API String ID: 1075933841-0
              • Opcode ID: 9f7f0bb6e85cde27177c106a39b4ddd7da1ee338b2532dda5c0efc973212806f
              • Instruction ID: 84994b116aedbd60d8806014bd5b02aac1ec6e85e21f1923e68dca568ba11e17
              • Opcode Fuzzy Hash: 9f7f0bb6e85cde27177c106a39b4ddd7da1ee338b2532dda5c0efc973212806f
              • Instruction Fuzzy Hash: D2018872D016659F8B10DFADCC405DDB7B4EF44224B2146ABC875B3744E7316E048BD1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • K32GetProcessImageFileNameW.KERNEL32(?,?,00000104,?,?,00000000), ref: 6CB75286
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FileImageNameProcess
              • String ID:
              • API String ID: 3017713154-0
              • Opcode ID: fe5abcd10ba47373e2a3f0d0ed4407fa93fdc3e2ee3a9fc38918c450195da93f
              • Instruction ID: a801d7a4c0745a953586ec010bf0aab6720d95df94e5ddf82eeda2c1389961a4
              • Opcode Fuzzy Hash: fe5abcd10ba47373e2a3f0d0ed4407fa93fdc3e2ee3a9fc38918c450195da93f
              • Instruction Fuzzy Hash: DB11E575A4025CABDB24DF64CC84AEE7378EF55314F1041A9992593781EB705E8CCF64
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 00541A3B: RtlAllocateHeap.NTDLL(00000008,?,00000000,?,005415F0,00000001,00000364,00000005,000000FF,?,00000000,?,0053F93A,00000000,?,0053F9B2), ref: 00541A7C
              • _free.LIBCMT ref: 00542A48
              Memory Dump Source
              • Source File: 00000009.00000002.3518826290.0000000000531000.00000020.00000001.01000000.00000012.sdmp, Offset: 00530000, based on PE: true
              • Associated: 00000009.00000002.3518772049.0000000000530000.00000002.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518888720.000000000054A000.00000004.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518947315.000000000054C000.00000002.00000001.01000000.00000012.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_530000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AllocateHeap_free
              • String ID:
              • API String ID: 614378929-0
              • Opcode ID: 2b189d8a3a8bd2b65707fd8ddeeef792c1bfeb7bc773aeff5f9515a7486dfa84
              • Instruction ID: a04107b5165071789f451dc0e27cd435846c3a885de09455fe64ded5ddf3ff98
              • Opcode Fuzzy Hash: 2b189d8a3a8bd2b65707fd8ddeeef792c1bfeb7bc773aeff5f9515a7486dfa84
              • Instruction Fuzzy Hash: 3A0162726003676BC321CF69C8859DAFF98FB443B4F440629F945A76C0E3B0A8118BA4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegEnumKeyExW.KERNELBASE(6CB76BD7,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6CB77C5E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Enum
              • String ID:
              • API String ID: 2928410991-0
              • Opcode ID: b712db86c65536ed7039b221a006d752dfc73f7db21dd85a31f378bc075686fc
              • Instruction ID: a69bbef86fc22735ae3ba6cd21fac4030f8f7af452e861e0c65a102ffc5cc5c9
              • Opcode Fuzzy Hash: b712db86c65536ed7039b221a006d752dfc73f7db21dd85a31f378bc075686fc
              • Instruction Fuzzy Hash: DC01ACB6A00128ABDB12DB65CD44DEFB7BCDB04214F014166FD55E7240DB70DD448BA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CC3E00C: SetEvent.KERNEL32(?,?,?,?,?,?,6CC3E0B2,00000007,?,00000007,?,6CD7C950), ref: 6CC3E085
              • _Deallocate.LIBCONCRT ref: 6CC3E0FA
                • Part of subcall function 6CC3E130: OpenProcess.KERNEL32(00100401,00000000,?,?,00000000,00000000,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007), ref: 6CC3E1B2
                • Part of subcall function 6CC3E130: QueryPerformanceCounter.KERNEL32(00000000,00000000,00000000,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CC3E214
                • Part of subcall function 6CC3E130: GetLastError.KERNEL32(00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CC3E25C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CounterDeallocateErrorEventLastOpenPerformanceProcessQuery
              • String ID:
              • API String ID: 3034481205-0
              • Opcode ID: f9390fc137e33f48844a9304025b5a8e67e36ec9be57284f6114f72fff45137e
              • Instruction ID: b10708a72a365a875dab5f1bb137f706b6cd5a3e8e8d5433610ce3d3fe7d672c
              • Opcode Fuzzy Hash: f9390fc137e33f48844a9304025b5a8e67e36ec9be57284f6114f72fff45137e
              • Instruction Fuzzy Hash: 7DF0A932E1163567DF1496B5E805BDE77AC9B40628F10416EA804E7780EB78DD0597D0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Open
              • String ID:
              • API String ID: 71445658-0
              • Opcode ID: 3325c51d919f47dd80d1197941c2c6ce5342215d0edefcd873242330e4c84b35
              • Instruction ID: 7044babeaaf1961cdb34d1a7f6093c6fa1d3133f48d7f475beacf148cdf60ccc
              • Opcode Fuzzy Hash: 3325c51d919f47dd80d1197941c2c6ce5342215d0edefcd873242330e4c84b35
              • Instruction Fuzzy Hash: 49F0F676B10124AFEB148F15CD01BA9B7F9EB54364F158229FD25D7390D770ED1087A4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB73C34: PathAppendW.SHLWAPI(00000010,00C6AF34,00C6AF34,00C6AF30,00C6AF30,?,6CB93118,00000000,00C6AF30,00000000,00C6AF54,00C6AF30), ref: 6CB73C70
              • LoadLibraryExW.KERNELBASE(00000000,00000000,?), ref: 6CB6DC2B
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AppendLibraryLoadPath
              • String ID:
              • API String ID: 1408929897-0
              • Opcode ID: eb6114ee2c7a8800df2d0a97c0d092c9982fe0397ad665e25c06d9e0879d2773
              • Instruction ID: 82252fc43735c76dbd939f191e0e5f264d943abc2e53d6cc23d2d0ea3385c9bf
              • Opcode Fuzzy Hash: eb6114ee2c7a8800df2d0a97c0d092c9982fe0397ad665e25c06d9e0879d2773
              • Instruction Fuzzy Hash: EBF06837A40059EBCB04DBB5DC409EDB3B4EF952297140269E862D77D0DB349A4DCB10
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RtlAllocateHeap.NTDLL(00000008,?,00000000,?,005415F0,00000001,00000364,00000005,000000FF,?,00000000,?,0053F93A,00000000,?,0053F9B2), ref: 00541A7C
              Memory Dump Source
              • Source File: 00000009.00000002.3518826290.0000000000531000.00000020.00000001.01000000.00000012.sdmp, Offset: 00530000, based on PE: true
              • Associated: 00000009.00000002.3518772049.0000000000530000.00000002.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518888720.000000000054A000.00000004.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518947315.000000000054C000.00000002.00000001.01000000.00000012.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_530000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AllocateHeap
              • String ID:
              • API String ID: 1279760036-0
              • Opcode ID: 39f1d9595315c7cf137f9d6eeee21e686d62280ff25e0cdf33f46d5d6c3b8012
              • Instruction ID: 6042bf45591182678e0afdacad52a739162617e8676f93e43461dbb6896bbd64
              • Opcode Fuzzy Hash: 39f1d9595315c7cf137f9d6eeee21e686d62280ff25e0cdf33f46d5d6c3b8012
              • Instruction Fuzzy Hash: D6F0E9316879256AEB215B239C09BDE3F49BF917B8B154521FC18AA180CF30DC8583E9
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RtlAllocateHeap.NTDLL(00000008,00000001,00000000,?,6CCD7C5E,00000001,00000364,00000008,000000FF,?,6CCCEE8B,00000000,00000000,00000000), ref: 6CCD7D89
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AllocateHeap
              • String ID:
              • API String ID: 1279760036-0
              • Opcode ID: bc5eb2feffd4dcd390816a716379fa8c371875efcc2c0641ed6492a67a6d843e
              • Instruction ID: ad2e68ba3230a9e9e9ae584a488f3c6dc568c603b5115590cf1891d7ae765fd9
              • Opcode Fuzzy Hash: bc5eb2feffd4dcd390816a716379fa8c371875efcc2c0641ed6492a67a6d843e
              • Instruction Fuzzy Hash: 20F02E3164522C67DB110F578804B7E77DCFB82770B128191EA145B688E730F800D7E0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateWindowExW.USER32(?,0000003C,00000000,?,?,0096840F,44890000,7E891424,00000007,?,00000000,00000007), ref: 6CB6AF2D
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CreateWindow
              • String ID:
              • API String ID: 716092398-0
              • Opcode ID: eb243a614fff3feafcb3d696c504e3c69788fbd6214bfb3391cb4395f3982ceb
              • Instruction ID: 4bb8e53ad60f92fdad3407fed237d737f34a0009303a64e46565a38e3852e50c
              • Opcode Fuzzy Hash: eb243a614fff3feafcb3d696c504e3c69788fbd6214bfb3391cb4395f3982ceb
              • Instruction Fuzzy Hash: A2F03076200215AFDF018F99CC04EA67FB9EF89710F058126FA089B260D771E820DBA4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.KERNELBASE(00000000,?), ref: 6CB8368A
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseQueryValue
              • String ID:
              • API String ID: 3356406503-0
              • Opcode ID: a2896ba3877dcd1ba52e7e9bb106f39226a945c10928e965439d1a79268a876b
              • Instruction ID: 4c3dc908d98f1ea5411cb5cd2447e6460e7824f70b3e5340f6a6bdecc0b9ac02
              • Opcode Fuzzy Hash: a2896ba3877dcd1ba52e7e9bb106f39226a945c10928e965439d1a79268a876b
              • Instruction Fuzzy Hash: 19F04971C0026EEBDF10EF94C858AEEBB75FF00318F104488D82562694DB745B08CF91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.KERNELBASE(00000000,?,?,?,000F003F,?,00000000), ref: 6CB76D14
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID:
              • API String ID: 3535843008-0
              • Opcode ID: 9b35907dda497ab36b9e08d9bba844a35d09c49649c0fac4e2fca32ce589f238
              • Instruction ID: 32d58d74f64a93133de4744eda3ee2659e787586b570d4c30e929f877090737a
              • Opcode Fuzzy Hash: 9b35907dda497ab36b9e08d9bba844a35d09c49649c0fac4e2fca32ce589f238
              • Instruction Fuzzy Hash: EEF0A7B1D10268BBDB259B99CC0ABAEBBB8DB40714F204198A810B6641D7B05A04CBE0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RtlAllocateHeap.NTDLL(00000000,?,?,?,6CCDDB85,00000220,00000100,?,00000000,?,?,?,6CCCA284,?,00000000,00000100), ref: 6CCD7DD7
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AllocateHeap
              • String ID:
              • API String ID: 1279760036-0
              • Opcode ID: 0429cbd58299fb0397d8a82e5d339b7ddceb96ccb824b0f3a9151b745715ee99
              • Instruction ID: f31c0db47d3993b75b921c8b28e05070c8fe6e21033627b9f6f7731c5eace866
              • Opcode Fuzzy Hash: 0429cbd58299fb0397d8a82e5d339b7ddceb96ccb824b0f3a9151b745715ee99
              • Instruction Fuzzy Hash: 81E0203118812867E6110C5F4804F76B6EDE7837B0F130190FF1417988A671B800D3D4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • FindCloseChangeNotification.KERNELBASE(00000000,00000000,6CB6C9AF,00000008,00000000,?,00000007), ref: 6CB6AECF
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ChangeCloseFindNotification
              • String ID:
              • API String ID: 2591292051-0
              • Opcode ID: fc41913218be017262338ff162a78de156b01e78be2ab0f5b1f075aa751d89fd
              • Instruction ID: 52da27364eabb18322538b52c479dfd31cb0bbe262c7c43ee1c7d1b696c79e6d
              • Opcode Fuzzy Hash: fc41913218be017262338ff162a78de156b01e78be2ab0f5b1f075aa751d89fd
              • Instruction Fuzzy Hash: ECF09231115B109FEB225B11D9097A2B7E4EB0172AF20C81DE1AB11CA0D7B5A894DE05
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • ReadFile.KERNELBASE(?,?,?,00000000,00000000,?,?,6CB6C51D,?,?,00000000,00000000,?,00000000,?), ref: 6CB6EF9F
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorFileLastRead
              • String ID:
              • API String ID: 1948546556-0
              • Opcode ID: d0d67ec246bb4da4cc140909e4a6b7e4a32c866dfb7138e2945a35b54c173b3e
              • Instruction ID: f531b8232643c64726212f63e9877180dbc6f8d4a32d504ab748039ed4c3f74e
              • Opcode Fuzzy Hash: d0d67ec246bb4da4cc140909e4a6b7e4a32c866dfb7138e2945a35b54c173b3e
              • Instruction Fuzzy Hash: D7E01A35245288FBEF01CFA2CC01F9EB7B9EF15308F208459B911DAA90D771DA109B92
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 52a58ede77fe17b205e5d41b63beb66e9832fabfd87cc65917576b0558569a35
              • Instruction ID: ffac5280a44c8a59532e7ff617fbf9bf1d01fbed00c6edeecdd55b17c9596606
              • Opcode Fuzzy Hash: 52a58ede77fe17b205e5d41b63beb66e9832fabfd87cc65917576b0558569a35
              • Instruction Fuzzy Hash: ECE0E530608248EFDB009F6AC848F497BB5EF4A715F24C068F9198A960C772D951AB91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SHQueryValueExW.SHLWAPI(6CB76BD7,00000000,00000000,00000000,?,?,6CD3F7F0,6CD3F7F0,?,6CB77060,?,00000000,00000000,?), ref: 6CB771AA
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: QueryValue
              • String ID:
              • API String ID: 3660427363-0
              • Opcode ID: 8d47fdf59cb5a4dcb3f6429500a8dc0b934a44a2a214850f83052b945428302d
              • Instruction ID: f19d727457488f8ecb418cdc6d8ba2652ff15ab1510bb659b2825fbe378104c1
              • Opcode Fuzzy Hash: 8d47fdf59cb5a4dcb3f6429500a8dc0b934a44a2a214850f83052b945428302d
              • Instruction Fuzzy Hash: 90E04F70110208BBEB01CF40CD05FEE7BBCEB01359F108058B904E5150D779D604DBB4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegDeleteValueW.KERNELBASE(6CB76BD7,00000000,?,6CB77802,?,00000000,6CB8308D,?,00000001,00000000,00000000), ref: 6CB76BB0
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DeleteValue
              • String ID:
              • API String ID: 1108222502-0
              • Opcode ID: dee6d4848ac9d46f7cb770cb645acd820d548c9547f86af9bd399871a6dd7da9
              • Instruction ID: 22ded65e62f907f7a59e3b243fb33e6302125973303b7c8824deca9b3d53cb5d
              • Opcode Fuzzy Hash: dee6d4848ac9d46f7cb770cb645acd820d548c9547f86af9bd399871a6dd7da9
              • Instruction Fuzzy Hash: 3BD0A735384095A6DB115AB1C90272A399CE703365F30C925E96DCD731D72BC49167F6
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegDeleteKeyW.ADVAPI32(6CB76BD7,?), ref: 6CB76B80
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Delete
              • String ID:
              • API String ID: 1035893169-0
              • Opcode ID: 1a50d7f0f9fe5e7f18aa7a16d7b2893253bcd16e850b0ab1307ca6484858eea0
              • Instruction ID: 51a2ab9e40991741794c74dd3ca07f76cd440c11800bcdd0686aa3d29a8f8be1
              • Opcode Fuzzy Hash: 1a50d7f0f9fe5e7f18aa7a16d7b2893253bcd16e850b0ab1307ca6484858eea0
              • Instruction Fuzzy Hash: 60D0A77119814596CF1119F1C9427297B9DDB02369F20C525E95DC8730D62BD09157F7
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate
              • String ID:
              • API String ID: 1075933841-0
              • Opcode ID: d99d753138053234281a048a9e51166d6a0bc9308436217efe886467ca4c1df7
              • Instruction ID: b99cff8bd82b54220abe86bd506528d932741505636c8435a6afe6dd634d0f47
              • Opcode Fuzzy Hash: d99d753138053234281a048a9e51166d6a0bc9308436217efe886467ca4c1df7
              • Instruction Fuzzy Hash: E2D067714196218EE764CF69E541656BBE4EF04310B20482EE4D9C3A54E7709880CB44
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegSetValueExW.KERNELBASE(6CB76BD7,00000000,00000000,00000004,00000000,00000004,?,6CB76EF5,00000000,00000000,00000000,?,00000000,00000000,?,00000000), ref: 6CB773C8
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Value
              • String ID:
              • API String ID: 3702945584-0
              • Opcode ID: 96fe67d40339a5b87ecee341bb11588ff54d87aa516c55ce18146e241df4f1ec
              • Instruction ID: 19daf0dfa41b8ef75142c23ecf729107a4dace454dede1491ccace7dc9c8339a
              • Opcode Fuzzy Hash: 96fe67d40339a5b87ecee341bb11588ff54d87aa516c55ce18146e241df4f1ec
              • Instruction Fuzzy Hash: 3CD0A7B534020877E7119951CE01F663B5CE700B10F10C011BB18CC1A0D7B6D45597B9
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegQueryValueExW.KERNELBASE(6CB76BD7,?,00000000,00000000,00000000,00000000,?,6CB77692,?,00000000,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\,?,?), ref: 6CB76B67
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: QueryValue
              • String ID:
              • API String ID: 3660427363-0
              • Opcode ID: 1fe0a11499876bb41f79383b17844189c5a7dc551f21bd0448ed271414355337
              • Instruction ID: 89166d21f9e1de1619c4cac2685c4bdd876c3d2a87894ff2c8a746c7a64a9e0d
              • Opcode Fuzzy Hash: 1fe0a11499876bb41f79383b17844189c5a7dc551f21bd0448ed271414355337
              • Instruction Fuzzy Hash: 8BC08CB12400187FFE010AB0CD02CB7BB2DD712A003008024BE09C1011C232CC22A6B0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • FindCloseChangeNotification.KERNELBASE(?,00000000,?,6CB6E8E7,00000000,6CB6C4BC,?,00000000,?,00000000), ref: 6CB6F03A
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ChangeCloseErrorFindLastNotification
              • String ID:
              • API String ID: 1687624791-0
              • Opcode ID: 23240dccd40c296eb255d51e5739b04fad56ce1666a3c49960634c8a67ccaf59
              • Instruction ID: 56d5d207059359a993271e125d9ca8670976f1b59c0eaeb72ae8eb58f17492df
              • Opcode Fuzzy Hash: 23240dccd40c296eb255d51e5739b04fad56ce1666a3c49960634c8a67ccaf59
              • Instruction Fuzzy Hash: 4BD012337040625757242E7FAC045CBBF69DF826B5316033AE920D35E0DB114C1187F0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • _free.LIBCMT ref: 6CCC973F
                • Part of subcall function 6CCD7D0E: RtlFreeHeap.NTDLL(00000000,00000000,?,6CCC9744,00000000,?,?,6CB671F5,?,00000000,8007000E,6CB67170,?,00000000,?,6CB670BF), ref: 6CCD7D24
                • Part of subcall function 6CCD7D0E: GetLastError.KERNEL32(?,?,6CCC9744,00000000,?,?,6CB671F5,?,00000000,8007000E,6CB67170,?,00000000,?,6CB670BF,?), ref: 6CCD7D36
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorFreeHeapLast_free
              • String ID:
              • API String ID: 1353095263-0
              • Opcode ID: 1bb3d11a30d50650f245f6d4d4ab19dc708df49a3c2d85c6dd6359192c687a27
              • Instruction ID: dcc37fc405f490bd04ca6cd2cb3458d59eaa75c9e5f6bef2d1b08f9516781b7d
              • Opcode Fuzzy Hash: 1bb3d11a30d50650f245f6d4d4ab19dc708df49a3c2d85c6dd6359192c687a27
              • Instruction Fuzzy Hash: FBC04C71500208BBDB059F45D90AA9E7BA9DB802A8F214098E51557650DBB1EE44A690
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RtlFreeHeap.NTDLL(?,00000000,00000000), ref: 6CB668D6
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeHeap
              • String ID:
              • API String ID: 3298025750-0
              • Opcode ID: 6fb74d41d8ae8d4607e0ab4c1a00479de8b35a6dacd8044a3c7fa51e2082da29
              • Instruction ID: 815a6ea900e1371a76e7b646f7f6362af21b10f025e28f4121ae10bf10a179c7
              • Opcode Fuzzy Hash: 6fb74d41d8ae8d4607e0ab4c1a00479de8b35a6dacd8044a3c7fa51e2082da29
              • Instruction Fuzzy Hash: 85C08C31101208FBDB011E40DD05B997F7CEB01305F20C025F708089A2C37394A0DBA8
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • ___delayLoadHelper2@8.DELAYIMP ref: 0053AC70
                • Part of subcall function 0053AF18: DloadReleaseSectionWriteAccess.DELAYIMP ref: 0053AF8B
                • Part of subcall function 0053AF18: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 0053AF9C
              Memory Dump Source
              • Source File: 00000009.00000002.3518826290.0000000000531000.00000020.00000001.01000000.00000012.sdmp, Offset: 00530000, based on PE: true
              • Associated: 00000009.00000002.3518772049.0000000000530000.00000002.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518888720.000000000054A000.00000004.00000001.01000000.00000012.sdmpDownload File
              • Associated: 00000009.00000002.3518947315.000000000054C000.00000002.00000001.01000000.00000012.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_530000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
              • String ID:
              • API String ID: 1269201914-0
              • Opcode ID: 731a6d88c096888dba059cc584fad31bf2b36eb7e4143b6cffc035cecaf346ff
              • Instruction ID: 044f5e543a899c306a0a378b48f9b1db309390211d901f3a3fe088bee31e2dff
              • Opcode Fuzzy Hash: 731a6d88c096888dba059cc584fad31bf2b36eb7e4143b6cffc035cecaf346ff
              • Instruction Fuzzy Hash: 84B012E52DC3067E330452012F4BC770F4CF0C0B19730441AB0C0C108094480C015473
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • InitOnceExecuteOnce.KERNELBASE(6CD7C5F4,6CB7D82A,00000000,00000000,6CB66C84), ref: 6CB7D819
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Once$ExecuteInit
              • String ID:
              • API String ID: 689400697-0
              • Opcode ID: 3720fdcaaa463e8a0ce48b8bccad603a47a26846ba78d16a812f533c6cfe5078
              • Instruction ID: e1cefa5524cee141021a158db2698d43a5352d18e2bfb66b304520eb0383b0e7
              • Opcode Fuzzy Hash: 3720fdcaaa463e8a0ce48b8bccad603a47a26846ba78d16a812f533c6cfe5078
              • Instruction Fuzzy Hash: D0C092303991932DFE2567304E06F543F34A783E22F2408807252BA8C19261210A8674
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RtlAllocateHeap.NTDLL(?,00000000,?), ref: 6CB668BB
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AllocateHeap
              • String ID:
              • API String ID: 1279760036-0
              • Opcode ID: 8160f81d442db922143ecf186011ae889f4e6d1a5f3b6fb89dfd74d946fc75a2
              • Instruction ID: 473c2e0a46a2e0de50caa6ecd6c295dc539abb85a40229a3f8fe4a805ca14b45
              • Opcode Fuzzy Hash: 8160f81d442db922143ecf186011ae889f4e6d1a5f3b6fb89dfd74d946fc75a2
              • Instruction Fuzzy Hash: 3DB09232244208FBEA111F95DC06F99BF2DEB1A761F10C025F708080A2C773E421AAA8
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNELBASE(?,?), ref: 6CB67F2A
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi
              • String ID:
              • API String ID: 1586166983-0
              • Opcode ID: 696f36404d94ab364feeb9ba754a1a88a82e523d46900a4ffd66e21f6e5ddfc1
              • Instruction ID: 59323305f128c154814b8aee96bdeea44a24ef297a560f1d5705f0e7b898e888
              • Opcode Fuzzy Hash: 696f36404d94ab364feeb9ba754a1a88a82e523d46900a4ffd66e21f6e5ddfc1
              • Instruction Fuzzy Hash: AAF01C75700085ABDF049B6AC8548EDFB79EFA5618B10005DE45297BE0DB719E0ADB50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetPrivateProfileIntW.KERNEL32(LoggingSettings,EnableLogging,00000001,00000000), ref: 6CB68334
              • GetPrivateProfileIntW.KERNEL32(LoggingSettings,ShowTime,00000001,00000000), ref: 6CB6834B
              • GetPrivateProfileIntW.KERNEL32(LoggingSettings,LogToFile,00000001,00000000), ref: 6CB68362
              • GetPrivateProfileIntW.KERNEL32(LoggingSettings,LogToOutputDebug,00000000,00000000), ref: 6CB68379
              • GetPrivateProfileIntW.KERNEL32(LoggingSettings,AppendToFile,00000001,00000000), ref: 6CB68390
              • GetPrivateProfileIntW.KERNEL32(LoggingLevel,00000001,00000003,?), ref: 6CB68403
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: PrivateProfile
              • String ID: AppendToFile$EnableLogging$LogToFile$LogToOutputDebug$LoggingLevel$LoggingSettings$ShowTime
              • API String ID: 1469295129-3729808974
              • Opcode ID: 8f74cc58a0decf40f1a219ed926c0e608dbde4e91f6bc6128d56e7f28b47b9c5
              • Instruction ID: b1264c9c78c621bd151be6eef983a5f65adb1f8f98b00861f9b3c53c99511f54
              • Opcode Fuzzy Hash: 8f74cc58a0decf40f1a219ed926c0e608dbde4e91f6bc6128d56e7f28b47b9c5
              • Instruction Fuzzy Hash: 3E41D634D02295EBEB00DF65C884F9EBFE4DF42314F0444A9EC149BA92D3759948CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetFileAttributesW.KERNEL32(?,80004005,?,00000000), ref: 6CB6C1A2
              • GetLastError.KERNEL32 ref: 6CB6C1AD
              • FindFirstFileW.KERNEL32(?,?,6CD3F348,00000000,?), ref: 6CB6C21E
              • GetLastError.KERNEL32 ref: 6CB6C22B
              • FindNextFileW.KERNEL32(00000000,00000010), ref: 6CB6C2E9
              • FindClose.KERNEL32(00000000), ref: 6CB6C2F8
              • RemoveDirectoryW.KERNEL32(?), ref: 6CB6C2FF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FileFind$ErrorLast$AttributesCloseDirectoryFirstNextRemove
              • String ID: :
              • API String ID: 1434622860-336475711
              • Opcode ID: e25a099d5ddd6f4e6e19a47bca305e1d5f477a88d3e159836e79e425eb81d1da
              • Instruction ID: ceaf37bc9fcfaea6b5820a7f6f7fbb25bc3b4ae9c58ee97dde2fcf481cef7bf9
              • Opcode Fuzzy Hash: e25a099d5ddd6f4e6e19a47bca305e1d5f477a88d3e159836e79e425eb81d1da
              • Instruction Fuzzy Hash: AF51F7323082815BDA00BF66D851AAF73A8EB56758F600529E962C7ED0EF319909C763
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • LoadLibraryExW.KERNEL32(?,00000000,00000060,00000104,00000022,000007D9), ref: 6CB88F83
              • LoadLibraryExW.KERNEL32(?,00000000,00000002), ref: 6CB88F91
              • FindResourceW.KERNEL32(00000000,?,?), ref: 6CB88FB2
              • LoadResource.KERNEL32(00000000,00000000), ref: 6CB88FCA
              • SizeofResource.KERNEL32(00000000,00000000), ref: 6CB88FD8
                • Part of subcall function 6CB67319: GetLastError.KERNEL32(6CB67628,?,?,?,6CB67B0C,?,00000000,?,6CB6A7D7,?,?,00000000,00000000,00000000,00000000,?), ref: 6CB67319
              • FreeLibrary.KERNEL32(00000000), ref: 6CB89077
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: LibraryLoadResource$ErrorFindFreeLastSizeof
              • String ID:
              • API String ID: 1885110938-0
              • Opcode ID: 898bd367dda1e73c65c489c662160fae76bb98d2883faf48b939986c2cd794bf
              • Instruction ID: 673fa4428ccef919e2dc8a2264461196800768cbbd971a2d62523b9844680e7f
              • Opcode Fuzzy Hash: 898bd367dda1e73c65c489c662160fae76bb98d2883faf48b939986c2cd794bf
              • Instruction Fuzzy Hash: C5410671A0215DABDF218F68CC44BEE77B9EF49318F0045AAE615E3680DB718DC08A59
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetLastError.KERNEL32(?,?,?,?), ref: 6CB7207B
              • SetLastError.KERNEL32(00000000), ref: 6CB72088
              • FormatMessageW.KERNEL32(00000500,00000000,00000000,00000000,00000000,00000000,?), ref: 6CB7209E
              • GetLastError.KERNEL32 ref: 6CB720A8
              • SetLastError.KERNEL32(?), ref: 6CB720B5
              • LocalFree.KERNEL32(00000000), ref: 6CB72161
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorLast$FormatFreeLocalMessage
              • String ID:
              • API String ID: 2740663437-0
              • Opcode ID: 398caf458d2783bd4fdc622551e6ab00fd86f1e00c21c737b15874881e36a5b5
              • Instruction ID: 5efa55f4be71929978976868325f09c8df90312111a9957f1d4d6e50c8490be9
              • Opcode Fuzzy Hash: 398caf458d2783bd4fdc622551e6ab00fd86f1e00c21c737b15874881e36a5b5
              • Instruction Fuzzy Hash: E431E175B00144EFDB149FAACC88AAEB779FF45708F204159EA2197F40EB71A9058B72
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • FindFirstFileW.KERNEL32(?,?,6CD3F344,00000000,0000005C,?,?,?,0000003A), ref: 6CB6C02D
              • GetLastError.KERNEL32 ref: 6CB6C03A
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              • DeleteFileW.KERNEL32(?,?,00000000,0000005C,?), ref: 6CB6C09E
              • FindNextFileW.KERNEL32(00000000,00000010), ref: 6CB6C0C7
              • GetLastError.KERNEL32 ref: 6CB6C0D1
              • FindClose.KERNEL32(00000000), ref: 6CB6C0E4
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorFileFindLast$CloseDeleteFirstNext
              • String ID:
              • API String ID: 325571491-0
              • Opcode ID: 62ab469c1b23ff2fb939dfea47d23af46834741507ad627d871844f213caab29
              • Instruction ID: 18796edb257ac569a854884928c4cf60a7a17f107ab36d13059af9a9af0f2b2e
              • Opcode Fuzzy Hash: 62ab469c1b23ff2fb939dfea47d23af46834741507ad627d871844f213caab29
              • Instruction Fuzzy Hash: D531A631604198AFDB10AB66DC88AEE777CEF45319F1001A9E556E3AC0EF705E48CF55
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • IsProcessorFeaturePresent.KERNEL32(0000000C,6CCE9DB3,00000000,?,6CCE9F4A,?,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000), ref: 6CCE9E99
              • GetProcessHeap.KERNEL32(00000008,00000008,00000000,00000000,0000000C,6CCE9DB3,00000000,?,6CCE9F4A,?,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F}), ref: 6CCE9EBF
              • HeapAlloc.KERNEL32(00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000,?), ref: 6CCE9EC6
              • InitializeSListHead.KERNEL32(00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000,?), ref: 6CCE9ED3
              • GetProcessHeap.KERNEL32(00000000,00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000), ref: 6CCE9EE8
              • HeapFree.KERNEL32(00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000,?), ref: 6CCE9EEF
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Heap$Process$AllocFeatureFreeHeadInitializeListPresentProcessor
              • String ID:
              • API String ID: 1475849761-0
              • Opcode ID: 139ac75989f731786b1f27733f79c05a21fdf126a5d981bbe11844648082b73f
              • Instruction ID: efbf157861f43d09de6b1d4d4903263b573ca68bf4b82a5c9ae19cdde3efa1a4
              • Opcode Fuzzy Hash: 139ac75989f731786b1f27733f79c05a21fdf126a5d981bbe11844648082b73f
              • Instruction Fuzzy Hash: CEF04F31705602ABFB119F7D8808B5A77FDEB8BA16F10442DEBA6D3680EF31C4008A60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6DCA8: PathAppendW.SHLWAPI(00000001,00000000,00000002,00000000,?,6CB808A2,MicrosoftEdgeUpdate.exe,00000010,00000000,00000001,00000000,00000001,?,6CB80A72,00000001,00000000), ref: 6CB6DCD3
              • FindFirstFileW.KERNEL32(?,?,*.*), ref: 6CB6BEDB
              • FindNextFileW.KERNEL32(00000000,?,?), ref: 6CB6BF62
              • GetLastError.KERNEL32 ref: 6CB6BF6C
              • FindClose.KERNEL32(00000000), ref: 6CB6BF90
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Find$ErrorFileLast$AppendCloseFirstNextPath
              • String ID: *.*
              • API String ID: 553947853-438819550
              • Opcode ID: 097189f771cff84ed6ceaa158e93991b12f8856d8475030ccc9780cda9f40fb7
              • Instruction ID: e36671f250daf091788e68073191c621a1c442f2e1057db407ac7287f64fb47f
              • Opcode Fuzzy Hash: 097189f771cff84ed6ceaa158e93991b12f8856d8475030ccc9780cda9f40fb7
              • Instruction Fuzzy Hash: DA3187722082855BD704DF65D8849AF73B9EF86268F10092EF965C3ED0EB30980DDA63
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • LoadLibraryW.KERNEL32(00000000,00000040,00000000,?,6CB93FF6,00000000,psmachine.dll,00000000,00000040,00000000,00000000,00000000,00000000,?,6CB941A4,00000000), ref: 6CB6C3AF
              • GetProcAddress.KERNEL32(00000000,DllRegisterServer), ref: 6CB6C3C6
              • FreeLibrary.KERNEL32(00000000,?,6CB93FF6,00000000,psmachine.dll,00000000,00000040,00000000,00000000,00000000,00000000,?,6CB941A4,00000000), ref: 6CB6C3E5
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Library$AddressErrorFreeLastLoadProc
              • String ID: DllRegisterServer
              • API String ID: 2540614322-1663957109
              • Opcode ID: 7019578f58bd58fe9996d003e9d7287d42f42d7a4328963a0b8ba4ee3bdbe88f
              • Instruction ID: 648503d718610005f37a9abf86f8ffb63ccee2535f68906a2f58b00593fa2eb9
              • Opcode Fuzzy Hash: 7019578f58bd58fe9996d003e9d7287d42f42d7a4328963a0b8ba4ee3bdbe88f
              • Instruction Fuzzy Hash: 07E0EC32349551A757113A6BC80455F396CEECB7B43054126FD25CBF00DB31C80182B5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 6CB74DA9
              • Process32FirstW.KERNEL32(00000000,0000022C), ref: 6CB74DDD
              • Process32NextW.KERNEL32(00000000,0000022C), ref: 6CB74E0A
              • CloseHandle.KERNEL32(00000000), ref: 6CB74E2C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Process32$CloseCreateFirstHandleNextSnapshotToolhelp32
              • String ID:
              • API String ID: 420147892-0
              • Opcode ID: 80938b0562e1a6638313f50ca299de7867ccf463745f71179ad0206ab3c03a31
              • Instruction ID: 0e41228540c9b250fe70febc1dbbed0fe3ded62868082101d57a6c68feaa01d5
              • Opcode Fuzzy Hash: 80938b0562e1a6638313f50ca299de7867ccf463745f71179ad0206ab3c03a31
              • Instruction Fuzzy Hash: EB11D231701168ABDB20EE25CC88A9E77B8EB46325F5001A9EE25D7280D7349A05CF72
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • FindFirstFileW.KERNEL32(00000000,?), ref: 6CBAFB6E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FileFindFirst
              • String ID:
              • API String ID: 1974802433-0
              • Opcode ID: c2decda53b8ca60d9bba056dad1b74db24fda541de13f8efe2f4b7a11f237816
              • Instruction ID: c12802169adb0403bca000400ced85f6a2542ff779dddb65719f7e3554c06b11
              • Opcode Fuzzy Hash: c2decda53b8ca60d9bba056dad1b74db24fda541de13f8efe2f4b7a11f237816
              • Instruction Fuzzy Hash: EE512F361082819BC704DF65C8948EEB7E9FFD5358F54092DF99687B90EB30A90ECB52
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • FindFirstFileW.KERNEL32(00000000,?,00000000,00000000,00000000), ref: 6CBAEF6B
              • FindClose.KERNEL32(00000000), ref: 6CBAEF93
              • FindNextFileW.KERNEL32(00000000,00000010), ref: 6CBAF0C8
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
                • Part of subcall function 6CB73C34: PathAppendW.SHLWAPI(00000010,00C6AF34,00C6AF34,00C6AF30,00C6AF30,?,6CB93118,00000000,00C6AF30,00000000,00C6AF54,00C6AF30), ref: 6CB73C70
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Find$File$AppendCloseErrorFirstLastNextPath
              • String ID:
              • API String ID: 2228626491-0
              • Opcode ID: 8a0d246b1d481c8e268f861b64dd862b53ef725d33a592f422d24dc282c8b8d4
              • Instruction ID: b165569dc40e602763de5b76f439c76fb6b97d5c095a2da39510983c06277059
              • Opcode Fuzzy Hash: 8a0d246b1d481c8e268f861b64dd862b53ef725d33a592f422d24dc282c8b8d4
              • Instruction Fuzzy Hash: 39415E3210C2C59BD714DFA5D88499EB7E5EF89358F140A2DF8D583AD0EB30990ACB93
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • FindFirstFileW.KERNEL32(00000000,?), ref: 6CB6EAB9
              • FindNextFileW.KERNEL32(00000000,00000080,?), ref: 6CB6EB2F
              • FindClose.KERNEL32(00000000), ref: 6CB6EB52
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Find$File$CloseErrorFirstLastNext
              • String ID:
              • API String ID: 819619735-0
              • Opcode ID: 3b2bd3d0e216bf42a5e0de394babd141a9c6625445ef1dd1520450a5831b567a
              • Instruction ID: e0b5b125d53c6a91018819beeb3d0b35a51ffe5d3e8927edf33ee77cf1084a68
              • Opcode Fuzzy Hash: 3b2bd3d0e216bf42a5e0de394babd141a9c6625445ef1dd1520450a5831b567a
              • Instruction Fuzzy Hash: DE31B331A042989BCB149F76CC88AED7379EF85318F1442A9D916A3AC0EB305E49CF61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • IsDebuggerPresent.KERNEL32 ref: 6CCC953A
              • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 6CCC9544
              • UnhandledExceptionFilter.KERNEL32(-00000328), ref: 6CCC9551
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ExceptionFilterUnhandled$DebuggerPresent
              • String ID:
              • API String ID: 3906539128-0
              • Opcode ID: b82fb0a5dd8f5e1ec7f4cc9798dae3b0a5c38af029e626e8c125235bd84c35da
              • Instruction ID: 927288bcc43c90ac7fe29e11062d35fdc4430e72e804768197ffbe3df57c416a
              • Opcode Fuzzy Hash: b82fb0a5dd8f5e1ec7f4cc9798dae3b0a5c38af029e626e8c125235bd84c35da
              • Instruction Fuzzy Hash: 8231A775A41218ABCB21DF68D9887CDBBB8BF08714F5042DAE51CA7290E7709B858F45
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcess.KERNEL32(?,?,6CCD0300,00000100,00000000,?,00000100,?,6CCCA284), ref: 6CCD0323
              • TerminateProcess.KERNEL32(00000000,?,6CCD0300,00000100,00000000,?,00000100,?,6CCCA284), ref: 6CCD032A
              • ExitProcess.KERNEL32 ref: 6CCD033C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Process$CurrentExitTerminate
              • String ID:
              • API String ID: 1703294689-0
              • Opcode ID: 0d55a4e6a0d4e4cbd5309e1eddb205c9a8d7a0450810d2f05131472d2c786587
              • Instruction ID: 65a43ff1c62db513b754e8acf73023862f798659a14758d53b47c02f9bcd4db4
              • Opcode Fuzzy Hash: 0d55a4e6a0d4e4cbd5309e1eddb205c9a8d7a0450810d2f05131472d2c786587
              • Instruction Fuzzy Hash: 47E08C31204148BFCF012F58C888A9D3B3CFF42245F41001CFA0586661EB35FD82CB80
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetSecurityDescriptorDacl.ADVAPI32(?,?,00000000,6CB6B77A,6CB6B77A,?,00000220,?,6CB6B77A), ref: 6CB6ABB5
              • SetSecurityDescriptorDacl.ADVAPI32(?,00000001,00000000,00000000,6CB6B77A,?,00000220,?,6CB6B77A), ref: 6CB6AC2A
                • Part of subcall function 6CB6AC65: GetSecurityDescriptorControl.ADVAPI32(00000000,?,?,00000000,00000000), ref: 6CB6AC89
                • Part of subcall function 6CB6AC65: MakeAbsoluteSD.ADVAPI32(00000000,00000000,?,00000000,?,00000000,?,00000000,?,00000000,?), ref: 6CB6ACCF
                • Part of subcall function 6CB6AC65: GetLastError.KERNEL32 ref: 6CB6ACD5
                • Part of subcall function 6CB6ADFD: InitializeSecurityDescriptor.ADVAPI32(00000000,00000001,00000000,00000000,6CB6AA46,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A,?,00000220,?,10000000,00000000), ref: 6CB6AE13
                • Part of subcall function 6CCC972C: _free.LIBCMT ref: 6CCC973F
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DescriptorSecurity$Dacl$AbsoluteControlErrorInitializeLastMake_free
              • String ID:
              • API String ID: 1300528458-0
              • Opcode ID: 4684c08dd7d56dee2ee6cd393bbebc708039c7823dfc9b01ff2dbd4970094e0c
              • Instruction ID: 9181b2d928c4273b624d68a36e775bcf05550aac98a70a7beae783f9760866c1
              • Opcode Fuzzy Hash: 4684c08dd7d56dee2ee6cd393bbebc708039c7823dfc9b01ff2dbd4970094e0c
              • Instruction Fuzzy Hash: F82124313002A4ABEF049BB7CC54AAF7BA9DF41B5CF204459E906DBE40EF30D9448AA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetVersionExW.KERNEL32(0000011C), ref: 6CB7399E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Version
              • String ID:
              • API String ID: 1889659487-0
              • Opcode ID: 07407562d6a91437810187af6336075799f7d5278c2205ad12e3c978b929a89c
              • Instruction ID: 874f064a15ee71719c1518d8e089524256fcf24ae9c040de1748d7085a8bfb67
              • Opcode Fuzzy Hash: 07407562d6a91437810187af6336075799f7d5278c2205ad12e3c978b929a89c
              • Instruction Fuzzy Hash: 5E31C431A561CD9ADF348A588897BDD7268DB0630CF604596DD73E3884F631CA848B73
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID: WinHttpAddRequestHeaders$WinHttpCheckPlatform$WinHttpCloseHandle$WinHttpConnect$WinHttpCrackUrl$WinHttpCreateUrl$WinHttpDetectAutoProxyConfigUrl$WinHttpGetDefaultProxyConfiguration$WinHttpGetIEProxyConfigForCurrentUser$WinHttpGetProxyForUrl$WinHttpOpen$WinHttpOpenRequest$WinHttpQueryAuthSchemes$WinHttpQueryDataAvailable$WinHttpQueryHeaders$WinHttpQueryOption$WinHttpReadData$WinHttpReceiveResponse$WinHttpSendRequest$WinHttpSetCredentials$WinHttpSetDefaultProxyConfiguration$WinHttpSetOption$WinHttpSetStatusCallback$WinHttpSetTimeouts$WinHttpWriteData$winhttp$winhttp5
              • API String ID: 0-2384385480
              • Opcode ID: 1342a9a055258e44e75e067cc82d60a6b0b56061e6409075a563adb3f2e4d1d8
              • Instruction ID: f2cebd571a687cf9b0717aa1ea550f03e3b90425d39f1723787c7e9e65687728
              • Opcode Fuzzy Hash: 1342a9a055258e44e75e067cc82d60a6b0b56061e6409075a563adb3f2e4d1d8
              • Instruction Fuzzy Hash: 88513E70601F56AAEB212F7A8D14A07FAE8BFA0644710583AD5D2D1E70EFB1E414CF17
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SetEvent.KERNEL32(00000000,?,?,?,00000000), ref: 6CBC2603
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Event
              • String ID: 0x%x$[%s]$[0x%08x]$[WinHttp status callback][%p][handle=%p]$connected$connecting$connection closed$connection closing$data available$handle closing$handle created$headers available$https failure$read complete$received$receiving$redirect$request error$resolved$resolving$send request complete$sending$sent$write complete
              • API String ID: 4201588131-2951660698
              • Opcode ID: 70dec19b8bba0f39fe66a4321a9e78fdc145e381c12b2c1d0f0c35d82934f163
              • Instruction ID: 862db5da5ef91fbcffee3e6f12d4a5335ebe45131458200232124bc4126a010b
              • Opcode Fuzzy Hash: 70dec19b8bba0f39fe66a4321a9e78fdc145e381c12b2c1d0f0c35d82934f163
              • Instruction Fuzzy Hash: 60A1C6B2F051C5ABDB04CF68D889BEE7764EB55308F015065EA11ABFA0D7389E48C763
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNEL32(?,HKLM,00000000,?,?,00000000,?,00000000,80070003,?,?,?), ref: 6CB779E9
              • lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE,?,?), ref: 6CB779F9
              • lstrcmpiW.KERNEL32(?,HKCU,?,?), ref: 6CB77A09
              • lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER,?,?), ref: 6CB77A19
              • lstrcmpiW.KERNEL32(?,HKCU[64],?,?), ref: 6CB77A29
              • lstrcmpiW.KERNEL32(?,HKEY_CURRENT_USER[64],?,?), ref: 6CB77A39
              • lstrcmpiW.KERNEL32(?,HKU,?,?), ref: 6CB77A45
              • lstrcmpiW.KERNEL32(?,HKEY_USERS,?,?), ref: 6CB77A51
              • lstrcmpiW.KERNEL32(?,HKCR,?,?), ref: 6CB77A5D
              • lstrcmpiW.KERNEL32(?,HKEY_CLASSES_ROOT,?,?), ref: 6CB77A69
              • lstrcmpiW.KERNEL32(?,HKLM[64],?,?), ref: 6CB77A75
              • lstrcmpiW.KERNEL32(?,HKEY_LOCAL_MACHINE[64],?,?), ref: 6CB77A81
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi
              • String ID: HKCR$HKCU$HKCU[64]$HKEY_CLASSES_ROOT$HKEY_CURRENT_USER$HKEY_CURRENT_USER[64]$HKEY_LOCAL_MACHINE$HKEY_LOCAL_MACHINE[64]$HKEY_USERS$HKLM$HKLM[64]$HKU
              • API String ID: 1586166983-3964746036
              • Opcode ID: 1365045ade5bcf731a2b496a97d66d4a0339288cb9584ccb908cecec39a8113a
              • Instruction ID: 6565769a153d1e669fd89102193d1d54587fb9ecabdf2be0dfc900546547678a
              • Opcode Fuzzy Hash: 1365045ade5bcf731a2b496a97d66d4a0339288cb9584ccb908cecec39a8113a
              • Instruction Fuzzy Hash: A541096170119576FF12A769CC40EDF62ADCF51688F100624ED21F3E90DF749B098BB5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • _strlen.LIBCMT ref: 6CBEFB1A
                • Part of subcall function 6CBF1670: _Deallocate.LIBCONCRT ref: 6CBF16B5
              Strings
              • {F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}, xrefs: 6CBEFA9B
              • %s_%S_%S_%S.exe, xrefs: 6CBEFB7C
              • MicrosoftEdgeUpdateSetup, xrefs: 6CBEFA3D, 6CBEFB19, 6CBEFB21
              • -full, xrefs: 6CBEFB2C
              • [TrimToApplicableFiles unknown multi-entity][0x%0x][%s], xrefs: 6CBEFAFE
              • %s_%S_%S.exe, xrefs: 6CBEFC40
              • {65C35B14-6C1D-4122-AC46-7148CC9D6497}, xrefs: 6CBEFA89
              • {F3C4FE00-EFD5-403B-9569-398A20F1BA4A}, xrefs: 6CBEFA2B
              • %s_%S_%S_%S-, xrefs: 6CBEFB97
              • {2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}, xrefs: 6CBEFA5D
              • MicrosoftEdge, xrefs: 6CBEFB14
              • %s_%S_%S-, xrefs: 6CBEFC59
              • [TrimToApplicableFiles found differential][%u][%S], xrefs: 6CBEFC1A
              • [TrimToApplicableFiles found full][%u][%S], xrefs: 6CBEFCE1
              • {0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}, xrefs: 6CBEFA73
              • {56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}, xrefs: 6CBEFA47
              • [TrimToApplicableFiles no known match][0x%0x][%s][%s], xrefs: 6CBEFD51
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate_strlen
              • String ID: %s_%S_%S-$%s_%S_%S.exe$%s_%S_%S_%S-$%s_%S_%S_%S.exe$-full$MicrosoftEdge$MicrosoftEdgeUpdateSetup$[TrimToApplicableFiles found differential][%u][%S]$[TrimToApplicableFiles found full][%u][%S]$[TrimToApplicableFiles no known match][0x%0x][%s][%s]$[TrimToApplicableFiles unknown multi-entity][0x%0x][%s]${0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}${2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}${56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}${65C35B14-6C1D-4122-AC46-7148CC9D6497}${F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}${F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
              • API String ID: 2475587941-1675744864
              • Opcode ID: f238ea9630b838b54e0558ce08db785bc228994951cf6ced8a7bdb19c41926ff
              • Instruction ID: 74543406c867699a1e357ff74fac3b176da248fcb9cdde145454ee496435a1b0
              • Opcode Fuzzy Hash: f238ea9630b838b54e0558ce08db785bc228994951cf6ced8a7bdb19c41926ff
              • Instruction Fuzzy Hash: 3CC19272D00159AFDF04DFA8E8819EE7BB9EF49354F24451AE511F7B90EB30A908CB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentThreadId.KERNEL32 ref: 6CC0587E
              • OpenEventW.KERNEL32(00100000,00000000,?), ref: 6CC058B7
              • WaitForSingleObject.KERNEL32(00000000,00000000), ref: 6CC058C5
                • Part of subcall function 6CBC55EB: CreateMutexW.KERNEL32(00000000,00000000,6CB918AF,00000000,00000000,00000000,6CC05963,?), ref: 6CBC55F7
                • Part of subcall function 6CBC55EB: CloseHandle.KERNEL32(6CB91C4C), ref: 6CBC560B
                • Part of subcall function 6CBC55EB: GetLastError.KERNEL32 ref: 6CBC561A
              • CloseHandle.KERNEL32(00000000,6CB8B8A8,6CB8B8A8,?,6CB8B8A8,?), ref: 6CC05C52
              • CloseHandle.KERNEL32(00000000,6CB8B8A8,6CB8B8A8,?,6CB8B8A8,?), ref: 6CC05C70
              Strings
              • core, xrefs: 6CC05B2D
              • HKCU\Software\Microsoft\EdgeUpdate\, xrefs: 6CC05A98
              • [Another core instance is already running], xrefs: 6CC0599A
              • {c1810bdb-a54b-4a98-a576-015e4b8605b6}, xrefs: 6CC058A1
              • [Exiting because an OEM is installing Windows], xrefs: 6CC0591A
              • {09E661D0-A0CE-4051-BB50-E021BA16FBFC}, xrefs: 6CC0593B
              • LastStartedAU, xrefs: 6CC05AA7
              • [Failed to start crash handler][0x%08x], xrefs: 6CC059F0
              • [Core][Will stay running], xrefs: 6CC05B08
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CC05A91
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle$CreateCurrentErrorEventLastMutexObjectOpenSingleThreadWait
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$LastStartedAU$[Another core instance is already running]$[Core][Will stay running]$[Exiting because an OEM is installing Windows]$[Failed to start crash handler][0x%08x]$core${09E661D0-A0CE-4051-BB50-E021BA16FBFC}${c1810bdb-a54b-4a98-a576-015e4b8605b6}
              • API String ID: 1286841718-1178353272
              • Opcode ID: f1208303aacdab0e0db29aa46ce23acca9bb5686e9c9b89242f47050dda41437
              • Instruction ID: b7d54cc8fa382c5a5a8dc424c8cc573d6bb3e1d2242c8b9d964e272109db2a6d
              • Opcode Fuzzy Hash: f1208303aacdab0e0db29aa46ce23acca9bb5686e9c9b89242f47050dda41437
              • Instruction Fuzzy Hash: 99C1E170A04249AFDF04CF74C891AED7BB5AF45308F14806AE955EBB91FB368948CB64
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetTickCount.KERNEL32 ref: 6CBBA36E
              • WaitForSingleObject.KERNEL32(?,000003E8,?,?,?,?,?,?,00002710,00000000), ref: 6CBBA43A
              • Sleep.KERNEL32(000003E8,?,?,?,?,?,?,00002710,00000000), ref: 6CBBA44A
                • Part of subcall function 6CBB984F: ResetEvent.KERNEL32(?,?), ref: 6CBB9869
              Strings
              • https, xrefs: 6CBBA4C2
              • [BitsRequest::DoSend][url %s][job %s][state %s], xrefs: 6CBBA2ED
              • BG_JOB_STATE_TRANSIENT_ERROR, xrefs: 6CBBA298
              • BG_JOB_STATE_TRANSFERRED, xrefs: 6CBBA2A6
              • [BITS job %s moved from transferring to queued][fail the job to fallback], xrefs: 6CBBA541
              • BG_JOB_STATE_CONNECTING, xrefs: 6CBBA28A
              • BG_JOB_STATE_ACKNOWLEDGED, xrefs: 6CBBA2B4
              • BG_JOB_STATE_QUEUED, xrefs: 6CBBA283, 6CBBA2C7
              • [BITS download was redirected][%s], xrefs: 6CBBA418
              • BG_JOB_STATE_ERROR, xrefs: 6CBBA29F
              • BG_JOB_STATE_CANCELLED, xrefs: 6CBBA2BB
              • BG_JOB_STATE_TRANSFERRING, xrefs: 6CBBA291
              • BG_JOB_STATE_SUSPENDED, xrefs: 6CBBA2AD
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CountEventObjectResetSingleSleepTickWait
              • String ID: BG_JOB_STATE_ACKNOWLEDGED$BG_JOB_STATE_CANCELLED$BG_JOB_STATE_CONNECTING$BG_JOB_STATE_ERROR$BG_JOB_STATE_QUEUED$BG_JOB_STATE_SUSPENDED$BG_JOB_STATE_TRANSFERRED$BG_JOB_STATE_TRANSFERRING$BG_JOB_STATE_TRANSIENT_ERROR$[BITS download was redirected][%s]$[BITS job %s moved from transferring to queued][fail the job to fallback]$[BitsRequest::DoSend][url %s][job %s][state %s]$https
              • API String ID: 2622541435-679955337
              • Opcode ID: 347603db7cc98bfae2a89ead2725042c45829f0e2053b02c233d05a3eba99110
              • Instruction ID: ef2d8b9d2adf30a3f397bb26d6fd47e9866b5f10c9177911fef2f52cee8e40ce
              • Opcode Fuzzy Hash: 347603db7cc98bfae2a89ead2725042c45829f0e2053b02c233d05a3eba99110
              • Instruction Fuzzy Hash: 4CA1AE70E04586ABDB04CB69C994ABDBBA5EF05308F148229E115FBFA0DF34E909CF51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcess.KERNEL32(00000000,00000000,00000000), ref: 6CB78358
              • OpenProcessToken.ADVAPI32(00000000,0000000A,?), ref: 6CB78366
              • CloseHandle.KERNEL32(?), ref: 6CB78580
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Process$CloseCurrentErrorHandleLastOpenToken
              • String ID: D
              • API String ID: 2767541406-2746444292
              • Opcode ID: 16868dab28ff42c697a8f8e5b706919f47921a25cc98e34129e0b3823343f820
              • Instruction ID: 6d6ee3dadbd981de50e6357dfb939c348383deae4a9b05685847be858f47dc8b
              • Opcode Fuzzy Hash: 16868dab28ff42c697a8f8e5b706919f47921a25cc98e34129e0b3823343f820
              • Instruction Fuzzy Hash: 73617E716093419FD710CF69C884A6FB7E4FF89718F100A1EF9A5A7690DB71D908CBA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6FDFB: GetSystemTimeAsFileTime.KERNEL32(?,6CD3E6AC,6CD3E6AC,?,6CB68434,00000000,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB6FE1B
              • __aulldiv.LIBCMT ref: 6CBDC6F9
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
              • __aulldiv.LIBCMT ref: 6CBDC7F1
              • Sleep.KERNEL32(00000000,?,?,00000000,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBDC96D
                • Part of subcall function 6CBDBFC0: lstrcmpiW.KERNEL32(?,windowsupdate_zdp,49EF6F00,00000000,?,?,?,6CBDC99A,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBDBFD0
                • Part of subcall function 6CBDC032: Sleep.KERNEL32(00001388,00000000,?,?,00000000,?,?,6CBDCA2D,?,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBDC0AC
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\, xrefs: 6CBDC7DD
              • [Another worker is already running. Exiting.], xrefs: 6CBDC7AC
              • [Applying update check jitter][%d], xrefs: 6CBDC95E
              • {56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}, xrefs: 6CBDC824
              • {8061D004-DAFE-413C-AEF6-A3D067FFA5D8}, xrefs: 6CBDC73B
              • [Skip update check for %s][Metered network], xrefs: 6CBDCA87
              • LastStartedAU, xrefs: 6CBDC812
              • [Skip update check for %s][CTA device], xrefs: 6CBDCA04
              • ZDP, xrefs: 6CBDC9B6, 6CBDC9BB
              • [Update check not needed at this time], xrefs: 6CBDC90C
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CBDC7D6
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSectionSleepTime__aulldiv$EnterFileLeaveSystemlstrcmpi
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$LastStartedAU$ZDP$[Another worker is already running. Exiting.]$[Applying update check jitter][%d]$[Skip update check for %s][CTA device]$[Skip update check for %s][Metered network]$[Update check not needed at this time]${56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}${8061D004-DAFE-413C-AEF6-A3D067FFA5D8}
              • API String ID: 2572624371-1090655612
              • Opcode ID: d7399ce3186dbfab4ef772fea299c479d7e316daeb711f1442f54794e1cf7219
              • Instruction ID: bfd636c8da0ecdc64a58fbb24ba78e840f9082796db12c55fabb4ac687516cc0
              • Opcode Fuzzy Hash: d7399ce3186dbfab4ef772fea299c479d7e316daeb711f1442f54794e1cf7219
              • Instruction Fuzzy Hash: 01C108B1D042D9AACF04DFF4C8919FEBBB4AF46348F144569D561B7B90DB306908CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6C8E7: GetCurrentProcess.KERNEL32(6CD7C950,?,00000007), ref: 6CB6C91D
              • WTSQueryUserToken.WTSAPI32(00000000,?,00000000,?,00000000), ref: 6CB785DA
              • CloseHandle.KERNEL32(00000000), ref: 6CB78837
              • CloseHandle.KERNEL32(?), ref: 6CB78844
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle$CurrentProcessQueryTokenUser
              • String ID: D
              • API String ID: 1368815553-2746444292
              • Opcode ID: 7b814cb7155faabfe1e899dac12a2b3bbce2916d34e1aa351c7f5af1230bf34e
              • Instruction ID: d4c6878ed49495ecbddc9e071f5686acb94f78bff1b3edbbac50c68848fb3828
              • Opcode Fuzzy Hash: 7b814cb7155faabfe1e899dac12a2b3bbce2916d34e1aa351c7f5af1230bf34e
              • Instruction Fuzzy Hash: AD81B3716083819FD711DF69C880A6FB7E4FF88718F500A2DF9A5A7690DB31D908CB66
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcAddress.KERNEL32(00000000,CryptUnprotectData), ref: 6CBBFCF1
              • GetProcAddress.KERNEL32(00000000,CredEnumerateW), ref: 6CBBFD21
              • GetProcAddress.KERNEL32(00000000,CredFree), ref: 6CBBFD37
              • LocalFree.KERNEL32(?), ref: 6CBBFE9B
              • FreeLibrary.KERNEL32(00000000,?,00000000), ref: 6CBBFF1A
              • FreeLibrary.KERNEL32(00000000,?,?,00000000), ref: 6CBBFF29
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressFreeProc$Library$Local
              • String ID: CredEnumerateW$CredFree$CryptUnprotectData$J$Microsoft_WinInet_$abe2869f-9b47-4cd9-a358-c22904dba7f7$advapi32.dll$crypt32.dll
              • API String ID: 2281628680-742279528
              • Opcode ID: 46f229756db0445f849a6a7fd58dd43519f152136d751d4a86c2717c57c7348d
              • Instruction ID: 8126833322d7e9798a0d66a09fe02fa8464413c5fade0c7ef0afee0c42599721
              • Opcode Fuzzy Hash: 46f229756db0445f849a6a7fd58dd43519f152136d751d4a86c2717c57c7348d
              • Instruction Fuzzy Hash: 2E611979A012699EEF24CB25DC40BEEB7B9BF46304F1040D9E549A7A41DF309E89CF61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\EdgeUpdate\,000F003F), ref: 6CB82530
              • ReleaseMutex.KERNEL32(?,HKLM\Software\Microsoft\EdgeUpdate\,000F003F), ref: 6CB8255D
              • CloseHandle.KERNEL32(?), ref: 6CB826EF
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
                • Part of subcall function 6CB77187: SHQueryValueExW.SHLWAPI(6CB76BD7,00000000,00000000,00000000,?,?,6CD3F7F0,6CD3F7F0,?,6CB77060,?,00000000,00000000,?), ref: 6CB771AA
                • Part of subcall function 6CB6FDFB: GetSystemTimeAsFileTime.KERNEL32(?,6CD3E6AC,6CD3E6AC,?,6CB68434,00000000,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB6FE1B
              • __aulldiv.LIBCMT ref: 6CB825AE
              • RegCloseKey.ADVAPI32(?), ref: 6CB826B8
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$QueryTimeValue$FileHandleMutexReleaseSystem__aulldiv
              • String ID: %s%s=%d$%s%s=%u$HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$age$cnt$old-uid$uid-create-time$uid-num-rotations
              • API String ID: 1912626927-2504260483
              • Opcode ID: a9ed199cc25db8cbee73fc79e745d6a1de7f66e05547c0786b3ecbdc166c3386
              • Instruction ID: c8033185f47f9b00feec7920e10e3531ea1c5e0b306f9778de375762409666e7
              • Opcode Fuzzy Hash: a9ed199cc25db8cbee73fc79e745d6a1de7f66e05547c0786b3ecbdc166c3386
              • Instruction Fuzzy Hash: 98618C71109381AFD700DF29C898AAEB7F5FF94318F40492CF5A5A7AA0DB30D909CB52
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB96D23
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$HKCU$HKROOT$ICONRESID$Microsoft Edge Update Update3Web$MicrosoftEdgeUpdate.Update3WebUser$MicrosoftEdgeUpdateOnDemand.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-1421999416
              • Opcode ID: a6c44be373c8132c79435afcb59df946fde272e0c0cfca610199afdc983d4d83
              • Instruction ID: 501735181367b3d882fa4998c8b0ae7e21c63480f9595b24c2bfd29fb3cb97cd
              • Opcode Fuzzy Hash: a6c44be373c8132c79435afcb59df946fde272e0c0cfca610199afdc983d4d83
              • Instruction Fuzzy Hash: F621AD70704184AFEA14DB649942DDE3765DB4721EB40493DB606BFFA1DB30980E8AB2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CBC2F33
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$Google Update Policy Status Class$HKLM$HKROOT$ICONRESID$MicrosoftEdgeUpdate.PolicyStatusSvc$MicrosoftEdgeUpdateOnDemand.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-3292529937
              • Opcode ID: 0ee191500fdc8b36e06a3d092499d50c47a6fff9273d74f7acee3cf3c18bce40
              • Instruction ID: e64976365795dbd2d2ccfa2bb8ec5dd84364b3fbb2f64021db98473497121fbc
              • Opcode Fuzzy Hash: 0ee191500fdc8b36e06a3d092499d50c47a6fff9273d74f7acee3cf3c18bce40
              • Instruction Fuzzy Hash: CC21AD713041946FEA14EF588946DDE33659B47619B404D38B206BFFA1EB709D0E8BB3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CBC3056
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$HKLM$HKROOT$ICONRESID$Microsoft Edge Update Update3Web$MicrosoftEdgeUpdate.Update3WebSvc$MicrosoftEdgeUpdateOnDemand.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-2844688446
              • Opcode ID: afc55238e5e88ff45488202708e3c4efaab0f9a0570ed400a4ba4cf6a5661cbf
              • Instruction ID: 94dd6a59733034f41bee7cca4eebfe85130856f8acc88efe90d54b8ff316cb72
              • Opcode Fuzzy Hash: afc55238e5e88ff45488202708e3c4efaab0f9a0570ed400a4ba4cf6a5661cbf
              • Instruction Fuzzy Hash: 5521C8B07041886FFA14DB588845DDE37A59B46219780493CB202BFFE0FB30980E87B2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB9695B
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$Google Update Policy Status Class$HKCU$HKROOT$ICONRESID$MicrosoftEdgeUpdate.PolicyStatusUser$MicrosoftEdgeUpdateOnDemand.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-663652078
              • Opcode ID: 7956e7969288a0c143b92fb158c9c0b1b2ac2fb79d0d95aa070a2854fc232869
              • Instruction ID: f29a7a78a735099b1e416dd22e0b199e239c8d1070920a5cf4de9e009955bbf5
              • Opcode Fuzzy Hash: 7956e7969288a0c143b92fb158c9c0b1b2ac2fb79d0d95aa070a2854fc232869
              • Instruction Fuzzy Hash: 53218670204180ABF614DBA48942DDE37A59B4721BB50493DF206BFFF0DB30D94E8AB2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB96A7E
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$HKCU$HKROOT$ICONRESID$Microsoft Edge Update Legacy On Demand$MicrosoftEdgeUpdate.OnDemandCOMClassUser$MicrosoftEdgeUpdateOnDemand.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-1687215270
              • Opcode ID: 464295e27baff6210341e253990200ce8846167874fc54fca855130cac6fd8ab
              • Instruction ID: ace60920bb7f973802cd670567b699f436b5a806f05f56bc7af2fb60599a5c93
              • Opcode Fuzzy Hash: 464295e27baff6210341e253990200ce8846167874fc54fca855130cac6fd8ab
              • Instruction Fuzzy Hash: 0D21D070204180AFEA14DB689845DDE37A9DB4721EB904C3DB206BFFA1DB70D80E4BB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB9620E
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$Google Update Policy Status Class$HKLM$HKROOT$ICONRESID$MicrosoftEdgeUpdate.PolicyStatusMachineFallback$MicrosoftEdgeUpdateOnDemand.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-1002649227
              • Opcode ID: c87032ad9f54936b688dee0d37b6412056825c98e2c09240dd87cc95abeb6713
              • Instruction ID: 380061dc0cfb9fe953cc4fffa160568cb0f236d76be63379b04f2a814ca9b0fd
              • Opcode Fuzzy Hash: c87032ad9f54936b688dee0d37b6412056825c98e2c09240dd87cc95abeb6713
              • Instruction Fuzzy Hash: 7221DA70744194AFF614DB648843DDF37A59B47219B80483AB702BFFA1DF30980E86B2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB96331
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$HKLM$HKROOT$ICONRESID$Microsoft Edge Update Update3Web$MicrosoftEdgeUpdate.Update3WebMachineFallback$MicrosoftEdgeUpdateOnDemand.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-2626335550
              • Opcode ID: 24c08f009d4aa5584afaea7ae9e001e1b237110e650abb3d7ccbc1ce43d57283
              • Instruction ID: be95c7fa42d0980321dbf3298b29b8152a94033f70ae825335b62f1978938ca6
              • Opcode Fuzzy Hash: 24c08f009d4aa5584afaea7ae9e001e1b237110e650abb3d7ccbc1ce43d57283
              • Instruction Fuzzy Hash: 10219570204184AFF614DB989845DDF73A59B8731EB904D3DB642BFFA1DB30980E86B2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB96454
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$HKLM$HKROOT$ICONRESID$Microsoft Edge Update Legacy On Demand$MicrosoftEdgeUpdate.OnDemandCOMClassMachineFallback$MicrosoftEdgeUpdateOnDemand.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-2933524159
              • Opcode ID: 7cff782e5b59036d5ed7e986063961615b0a1698586bbe0d54c47b1a12fe1ee5
              • Instruction ID: 14287076316395c787952ab097f37e7093e6076c1f0770cee7ea3f8ef77f1fc9
              • Opcode Fuzzy Hash: 7cff782e5b59036d5ed7e986063961615b0a1698586bbe0d54c47b1a12fe1ee5
              • Instruction Fuzzy Hash: 6F21DA70214180AFF615DB688942DDF33A99B47319B90493DF242BFFA1DF30980E86B2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNEL32(00000000,Delete,00000000,?,00000000,00000000,?,6CB89BD3,?,00000000,00000000,00000000,?), ref: 6CB89C61
              • lstrcmpiW.KERNEL32(00000000,ForceRemove,?,00000000,00000000,?,6CB89BD3,?,00000000,00000000,00000000,?), ref: 6CB89C76
              • lstrcmpiW.KERNEL32(00000000,NoRemove,00000000,?,00000000,00000000,?,6CB89BD3,?,00000000,00000000,00000000,?), ref: 6CB89D2F
              • lstrcmpiW.KERNEL32(00000000,Val,?,00000000,00000000,?,6CB89BD3,?,00000000,00000000,00000000,?), ref: 6CB89D57
              • RegDeleteValueW.ADVAPI32(?,?,?,00000000,00020006,00000000,?), ref: 6CB89E2F
              • RegCloseKey.ADVAPI32(?), ref: 6CB89E47
              • RegCloseKey.ADVAPI32(00000000,?,00000000,00020006,00000000,?), ref: 6CB8A10E
                • Part of subcall function 6CB89BF6: RegCloseKey.ADVAPI32(?,?,00000000,00000000), ref: 6CB8A089
              • RegCloseKey.ADVAPI32(?,00000000,?,00000000,00000000,?,6CB89BD3,?,00000000,00000000,00000000,?), ref: 6CB8A12B
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Closelstrcmpi$DeleteValue
              • String ID: Delete$ForceRemove$NoRemove$Val
              • API String ID: 3818462101-1781481701
              • Opcode ID: 12955afd8ce09100d806f9b1d301893c69707c5254b7cf310a78359139c89658
              • Instruction ID: daeebd1e13c6c3d51bb41de7c672755f709c1b3ac83c6f9fe2687c4e47c71168
              • Opcode Fuzzy Hash: 12955afd8ce09100d806f9b1d301893c69707c5254b7cf310a78359139c89658
              • Instruction Fuzzy Hash: B3E1A471A0B3929BDB11DF659890A6FB7F8EF85B58F00091DF95197A80D734C804CBA3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              • RegCloseKey.ADVAPI32(00000000,?,ping_freshness,?,?,?,DayOfLastRollCall,00000000,DayOfLastActivity,00000000,?,RollCallDayStartSec,00000000,ActivePingDayStartSec,00000000,client), ref: 6CB9C1F7
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseQueryValue
              • String ID: ActivePingDayStartSec$DayOfLastActivity$DayOfLastRollCall$RollCallDayStartSec$brand$client$iid$lang$name$ping_freshness$tttoken
              • API String ID: 3356406503-2414467127
              • Opcode ID: 2bbd49364290d2f78020b893769b2e4d951fd538aacf542d138f2abec9d7d38b
              • Instruction ID: cfc3e35f542fc387269b39d160d2ec712aefca8a2388b67a7e308a50761e3723
              • Opcode Fuzzy Hash: 2bbd49364290d2f78020b893769b2e4d951fd538aacf542d138f2abec9d7d38b
              • Instruction Fuzzy Hash: 53E17E71D002889BDF14DFE5C894AEDB7B9EF45308F104429E926ABB91EF30994DCB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CBC2E12
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1004$3000$DESCRIPTION$ICONRESID$Microsoft Edge Update Core Class$MicrosoftEdgeUpdate.CoreClass$MicrosoftEdgeUpdateOnDemand.exe$MicrosoftEdgeUpdateUpdateCoreClass$NAME$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-410758037
              • Opcode ID: 5c723166d394016b4c966f9f065a794621cbb76d28f53f47fe37cd26271c7df1
              • Instruction ID: 1b6ac944589401208b2419d4dfeca37957930fc00dfc9eb446b5dcc4c18e783c
              • Opcode Fuzzy Hash: 5c723166d394016b4c966f9f065a794621cbb76d28f53f47fe37cd26271c7df1
              • Instruction Fuzzy Hash: 8111C4B03550947FF514AB68AC15EDD12558B83319B548D38B202AAFB0EB30980E8BB3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB9673F
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1004$3000$DESCRIPTION$ICONRESID$Microsoft Edge Update Core Class$MicrosoftEdgeUpdate.CoreMachineClass$MicrosoftEdgeUpdateOnDemand.exe$MicrosoftEdgeUpdateUpdateCoreClass$NAME$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-2414390249
              • Opcode ID: dc69e03300295249bf2d4398768908471dd9be5ddd3d3ae8fd8c2ac29445d70b
              • Instruction ID: 0c05743d385756ba19fbf4f1386612ee990b2158fd77edb262537fcf1f9717f9
              • Opcode Fuzzy Hash: dc69e03300295249bf2d4398768908471dd9be5ddd3d3ae8fd8c2ac29445d70b
              • Instruction Fuzzy Hash: 8E11C470315090BEF2185B689C51EDF1265978321AB508A39F202BBFF0DF30584E46F2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • _Deallocate.LIBCONCRT ref: 6CB81253
              • _Deallocate.LIBCONCRT ref: 6CB81291
                • Part of subcall function 6CB756C6: OpenProcess.KERNEL32(00000410,00000000,?,?,?), ref: 6CB756EB
                • Part of subcall function 6CB756C6: CloseHandle.KERNEL32(00000000,?,?,?), ref: 6CB757FF
                • Part of subcall function 6CB721E7: CharLowerBuffW.USER32(00000000,?,?,00000000,?,6CB73D99,0000005C,00000000,00000000,00000000,?,00000001,?), ref: 6CB72203
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate$BuffCharCloseHandleLowerOpenProcess
              • String ID: &needsadmin=false$&needsadmin=prefers$&needsadmin=true$-Embedding$/%s$MicrosoftEdgeUpdate.exe$handoff$install$installelevated$update
              • API String ID: 3143101912-1503362479
              • Opcode ID: dfdfe5564d652d6d9af9e155f5bfc0c467354d6b80d96270c4993962674072bc
              • Instruction ID: dd1984b6149da7924aba98f5189f421b166a8b63380b19c99d7e2832fe3b3d50
              • Opcode Fuzzy Hash: dfdfe5564d652d6d9af9e155f5bfc0c467354d6b80d96270c4993962674072bc
              • Instruction Fuzzy Hash: 12917171D01199ABDF14DFE9D8409EEB778EF54318F144529E921F7A90EB30AA0DCBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80A55: CloseHandle.KERNEL32(?), ref: 6CB80ACE
              • OpenEventW.KERNEL32(00100000,00000000,?,?,00000000,0000000E,00000000,00000000,00000001), ref: 6CBD838E
              • GetLastError.KERNEL32 ref: 6CBD839A
              • CloseHandle.KERNEL32(00000000), ref: 6CBD8506
              • CloseHandle.KERNEL32(00000000), ref: 6CBD8519
              Strings
              • [Critical UA][finished], xrefs: 6CBD84E8
              • {c1810bdb-a54b-4a98-a576-015e4b8605b6}, xrefs: 6CBD8376
              • [Critical UA][Time limit for exceeded, stop blocking], xrefs: 6CBD84A8
              • [Critical UA][Start failed][0x%08x], xrefs: 6CBD8355
              • [Critical UA][Watchdog create failed][0x%08x], xrefs: 6CBD83E3
              • [Critical UA][Wait failed][0x%08x], xrefs: 6CBD845F
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle$ErrorEventLastOpen
              • String ID: [Critical UA][Start failed][0x%08x]$[Critical UA][Time limit for exceeded, stop blocking]$[Critical UA][Wait failed][0x%08x]$[Critical UA][Watchdog create failed][0x%08x]$[Critical UA][finished]${c1810bdb-a54b-4a98-a576-015e4b8605b6}
              • API String ID: 4076909282-522056904
              • Opcode ID: a4369d2102fcbcab341e7ae9a1a5519e84da0225d55da73a4eceabef7657e924
              • Instruction ID: b01933e8549de005c0c870363717db30e90c67209ee9952f691d6b71e2f3f36c
              • Opcode Fuzzy Hash: a4369d2102fcbcab341e7ae9a1a5519e84da0225d55da73a4eceabef7657e924
              • Instruction Fuzzy Hash: F261F6B1D04258AEDB09DFA5D891BFE7BB8EB46309F10512EE511F7BC0DB3455088BA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • EnterCriticalSection.KERNEL32(6CD7CA74), ref: 6CBFB79E
              • LeaveCriticalSection.KERNEL32(6CD7CA74), ref: 6CBFB7B7
              • EnterCriticalSection.KERNEL32(6CD7CA74), ref: 6CBFB7BE
              • LeaveCriticalSection.KERNEL32(6CD7CA74), ref: 6CBFB7D5
              • EnterCriticalSection.KERNEL32(6CD7CA74), ref: 6CBFB7DC
              • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CBFB7F9
              • LeaveCriticalSection.KERNEL32(6CD7CA74), ref: 6CBFB809
              • EnterCriticalSection.KERNEL32(6CD7CA74), ref: 6CBFB810
              • LeaveCriticalSection.KERNEL32(6CD7CA74), ref: 6CBFB81E
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$EnterLeave$Unothrow_t@std@@@__ehfuncinfo$??2@
              • String ID: :b=$:c=$:i=
              • API String ID: 3694375763-3878355487
              • Opcode ID: ee87697d61252724227fc342fb8e75cdd614fbce5356e038456e869d4e971249
              • Instruction ID: 7c6ab85e887848c8e65e3669e3c18247e5faa68bf851bd22fd6b342d266d8f35
              • Opcode Fuzzy Hash: ee87697d61252724227fc342fb8e75cdd614fbce5356e038456e869d4e971249
              • Instruction Fuzzy Hash: 22418631B00255AFCF10AFB9885486EBBF6FFC93147104429E5659BB64DB30ED058BA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,80000002,System\Setup,00020019), ref: 6CB6CD17
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              • lstrcmpiW.KERNEL32(?,IMAGE_STATE_UNDEPLOYABLE,ImageState,?,80000002,Software\Microsoft\Windows\CurrentVersion\Setup\State,00020019), ref: 6CB6CCDB
              • lstrcmpiW.KERNEL32(?,IMAGE_STATE_GENERALIZE_RESEAL_TO_AUDIT), ref: 6CB6CCE7
              • lstrcmpiW.KERNEL32(?,IMAGE_STATE_SPECIALIZE_RESEAL_TO_AUDIT), ref: 6CB6CCF3
              • RegCloseKey.ADVAPI32(00000000,AuditInProgress,00000000,80000002,System\Setup,00020019), ref: 6CB6CD62
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              Strings
              • IMAGE_STATE_SPECIALIZE_RESEAL_TO_AUDIT, xrefs: 6CB6CCED
              • System\Setup, xrefs: 6CB6CD24
              • ImageState, xrefs: 6CB6CCB5
              • IMAGE_STATE_UNDEPLOYABLE, xrefs: 6CB6CCD5
              • Software\Microsoft\Windows\CurrentVersion\Setup\State, xrefs: 6CB6CC96
              • IMAGE_STATE_GENERALIZE_RESEAL_TO_AUDIT, xrefs: 6CB6CCE1
              • AuditInProgress, xrefs: 6CB6CD3F
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Close$OpenQueryValue
              • String ID: AuditInProgress$IMAGE_STATE_GENERALIZE_RESEAL_TO_AUDIT$IMAGE_STATE_SPECIALIZE_RESEAL_TO_AUDIT$IMAGE_STATE_UNDEPLOYABLE$ImageState$Software\Microsoft\Windows\CurrentVersion\Setup\State$System\Setup
              • API String ID: 645971292-530895078
              • Opcode ID: 595270090f2553c5dd281af3a7c7f896ee274652e89019e23abd88eda1353dc7
              • Instruction ID: 39569753cc93f7b3e4ca3f7b03ef6d4206265cbcea03bafdf97748808336bde3
              • Opcode Fuzzy Hash: 595270090f2553c5dd281af3a7c7f896ee274652e89019e23abd88eda1353dc7
              • Instruction Fuzzy Hash: 40215171A0127DFBEF11EF96CD44BEEBBB8EF11349F1008659924A2D90D7708609CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB96E0B
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$ICONRESID$Microsoft Edge Update Broker Class Factory$MicrosoftEdgeUpdate.PolicyStatusMachine$MicrosoftEdgeUpdateBroker.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-1121720975
              • Opcode ID: c3eefcb7e90de5d2120e79c9799226035305f91a442137fca65e1d8a128a8600
              • Instruction ID: b6d8ec0841a6edb2df80fcfe12387315a4840d5f05805b3a968bed28099f4ca9
              • Opcode Fuzzy Hash: c3eefcb7e90de5d2120e79c9799226035305f91a442137fca65e1d8a128a8600
              • Instruction Fuzzy Hash: AF11C6313544A06EF61557689C43DDE23558B8321AB104A3AF716AFFF1CF30884E86F2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB96FD7
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$ICONRESID$Microsoft Edge Update Broker Class Factory$MicrosoftEdgeUpdate.OnDemandCOMClassMachine$MicrosoftEdgeUpdateBroker.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-3204057690
              • Opcode ID: 3f5571077dec6a749fdf6af8fe4ee9ef76a5e1d5631bb419517f1018a5dd1751
              • Instruction ID: c31397bd5f3eb45de8732bae7cb383dde5e8aee335ad41027b28fe714b17d9b1
              • Opcode Fuzzy Hash: 3f5571077dec6a749fdf6af8fe4ee9ef76a5e1d5631bb419517f1018a5dd1751
              • Instruction Fuzzy Hash: 6F11C6713644906EFA249758A845EDD22968B8721EB11483DB316BBFE0CF30C80E4AF2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB96EF1
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$1004$3000$DESCRIPTION$ICONRESID$Microsoft Edge Update Broker Class Factory$MicrosoftEdgeUpdate.Update3WebMachine$MicrosoftEdgeUpdateBroker.exe$PROGID$STRINGRESID$VERSION
              • API String ID: 1385522511-3403436760
              • Opcode ID: c9533e8464737a299084c0df6580e19740b236e309ec6d3ef80122433d61b825
              • Instruction ID: 23cd43cbf6e0be4807a2824641cfa4081e6d49f03bfa8f210b8f158c8890a109
              • Opcode Fuzzy Hash: c9533e8464737a299084c0df6580e19740b236e309ec6d3ef80122433d61b825
              • Instruction Fuzzy Hash: D011C2313144906FF6245758E852EDE22998B9721EB51493CF242BBFA0CB30D80E8AF2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CloseHandle.KERNEL32(00000000,?,?,C0100000,00000000,?,C0100000,00000000,?,?,?,C0100000,00000000,?,00000000,00000000), ref: 6CB76758
              • CloseHandle.KERNEL32(00000000,?,?,C0100000,00000000,?,C0100000,00000000,?,?,?,C0100000,00000000,?,00000000,00000000), ref: 6CB76769
                • Part of subcall function 6CB67234: GetLastError.KERNEL32(6CB6A7B3), ref: 6CB67234
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle$ErrorLast
              • String ID:
              • API String ID: 1798101686-0
              • Opcode ID: 73a738199c156fcc45159417be159d7ae5f3cc90849c2232a170a63c3a08f8ba
              • Instruction ID: f3478b3d8353b27c1e2f0aebecdaa80e73b85786942bbf57322478f7b4761aec
              • Opcode Fuzzy Hash: 73a738199c156fcc45159417be159d7ae5f3cc90849c2232a170a63c3a08f8ba
              • Instruction Fuzzy Hash: 08E10671901169DBEF258F51CD80BEEB778EF04344F1081EAA91DB2A50EB709E88DF61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • ___free_lconv_mon.LIBCMT ref: 6CCE0AAA
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2B8B
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2B9D
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2BAF
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2BC1
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2BD3
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2BE5
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2BF7
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2C09
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2C1B
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2C2D
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2C3F
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2C51
                • Part of subcall function 6CCE2B6E: _free.LIBCMT ref: 6CCE2C63
              • _free.LIBCMT ref: 6CCE0A9F
                • Part of subcall function 6CCD7D0E: RtlFreeHeap.NTDLL(00000000,00000000,?,6CCC9744,00000000,?,?,6CB671F5,?,00000000,8007000E,6CB67170,?,00000000,?,6CB670BF), ref: 6CCD7D24
                • Part of subcall function 6CCD7D0E: GetLastError.KERNEL32(?,?,6CCC9744,00000000,?,?,6CB671F5,?,00000000,8007000E,6CB67170,?,00000000,?,6CB670BF,?), ref: 6CCD7D36
              • _free.LIBCMT ref: 6CCE0AC1
              • _free.LIBCMT ref: 6CCE0AD6
              • _free.LIBCMT ref: 6CCE0AE1
              • _free.LIBCMT ref: 6CCE0B03
              • _free.LIBCMT ref: 6CCE0B16
              • _free.LIBCMT ref: 6CCE0B24
              • _free.LIBCMT ref: 6CCE0B2F
              • _free.LIBCMT ref: 6CCE0B67
              • _free.LIBCMT ref: 6CCE0B6E
              • _free.LIBCMT ref: 6CCE0B8B
              • _free.LIBCMT ref: 6CCE0BA3
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: _free$ErrorFreeHeapLast___free_lconv_mon
              • String ID:
              • API String ID: 161543041-0
              • Opcode ID: d6cdadda014675b61a4663acfe0ca2126cd92c0058bd4c9bcef77161666dc264
              • Instruction ID: 8a76280b58e545ab5ad23acf631c08017e22ed747a24669822d4869b277e29eb
              • Opcode Fuzzy Hash: d6cdadda014675b61a4663acfe0ca2126cd92c0058bd4c9bcef77161666dc264
              • Instruction Fuzzy Hash: ED317C316003449EEB22AE39D844B9A73E9FF06358F21955EE159D7A50FF70F884EB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBD7A9D: _strftime.LIBCMT ref: 6CBD7B01
              • _Deallocate.LIBCONCRT ref: 6CBD0991
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate_strftime
              • String ID: at offset $ exceeds maximum $-byte string at offset $D:\a\_work\1\omaha\src\third_party\breakpad\src\processor\minidump.cc$Invalid Minidump for ReadString$ReadString could not read $ReadString could not read string size at offset $ReadString could not seek to string at offset $ReadString found odd-sized $ReadString string length
              • API String ID: 979069416-579914582
              • Opcode ID: f03d5adcff7c2bc32ade44771257884494dc3333224bf00c08d75f1e01552544
              • Instruction ID: 936f0d9b0e71dfd4c9fe5f73331c7fad790646cd0ed9d4eeb07fd77a62622a2b
              • Opcode Fuzzy Hash: f03d5adcff7c2bc32ade44771257884494dc3333224bf00c08d75f1e01552544
              • Instruction Fuzzy Hash: C7512431B042C06BEF049B64DC95AED37629B85348F910428E511BFFE4DFB1BE4987A5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegQueryValueExW.ADVAPI32(00000000,version,00000000,00000000,00000000,00000000,?,00020019,HKLM\Software\Microsoft\EdgeUpdate\), ref: 6CB8C5DA
              • RegQueryValueExW.ADVAPI32(00000000,path,00000000,00000000,00000000,00000000), ref: 6CB8C5F0
              • RegCloseKey.ADVAPI32(00000000,?,00020019,HKLM\Software\Microsoft\EdgeUpdate\), ref: 6CB8C6B7
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: QueryValue$Close
              • String ID: ClientState$Clients$HKCU\Software\Microsoft\EdgeUpdate\$HKCU\Software\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}$HKLM\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}$path$version
              • API String ID: 1979452859-2642603773
              • Opcode ID: 570f63aeb31d636d12ea32f9ca609deac159375ce09e1dbb8dbd786d07acf8de
              • Instruction ID: 1c14dc8da9b9b9b686096a921a6e74c3bf13f75e05fc57bec357ee430f517c2d
              • Opcode Fuzzy Hash: 570f63aeb31d636d12ea32f9ca609deac159375ce09e1dbb8dbd786d07acf8de
              • Instruction Fuzzy Hash: 8441A7716012859BEF10EBA5C991AFEB778EF1030CF1005389915B7EA1EB705E0DCBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB93D79
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$DESCRIPTION$HKCU$HKLM$HKROOT$Microsoft Edge Update Process Launcher Class$MicrosoftEdgeUpdate.ProcessLauncher$MicrosoftEdgeUpdateOnDemand.exe$PROGID$VERSION
              • API String ID: 1385522511-3922973260
              • Opcode ID: 9035fe3a524d3fda59cb7ad47bc0631f0dae6d98c20f2e88e7f47cce0de9f751
              • Instruction ID: 59fac55d38c2b11cd1a8a5523c479846c0918d4f738f21299e409814a2ee7694
              • Opcode Fuzzy Hash: 9035fe3a524d3fda59cb7ad47bc0631f0dae6d98c20f2e88e7f47cce0de9f751
              • Instruction Fuzzy Hash: F72127712441806BF715AB69C841E9E63699B53318F40453DE206BBFA0CF31DC0E8672
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • NetWkstaUserGetInfo.NETAPI32(00000000,00000001,?), ref: 6CB77FB2
              • WTSEnumerateSessionsW.WTSAPI32(00000000,00000000,00000001,?,?), ref: 6CB77FE0
              • WTSQuerySessionInformationW.WTSAPI32(00000000,00000000,00000007,?,?), ref: 6CB78028
              • WTSQuerySessionInformationW.WTSAPI32(00000000,?,00000005,?,?), ref: 6CB78061
              • WTSFreeMemory.WTSAPI32(?), ref: 6CB78074
              • WTSFreeMemory.WTSAPI32(?), ref: 6CB780F8
              • WTSFreeMemory.WTSAPI32(?), ref: 6CB780FD
              • WTSFreeMemory.WTSAPI32(?), ref: 6CB78106
              • NetApiBufferFree.NETAPI32(?), ref: 6CB7810C
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Free$Memory$InformationQuerySession$BufferEnumerateErrorInfoLastSessionsUserWksta
              • String ID:
              • API String ID: 54666020-0
              • Opcode ID: 29c288fe512e160f8e2cd1f4a921cb52c4f97518a8f141eade92c73a06e45805
              • Instruction ID: c0ce35bf67b602ea32c8dfc6bbad6a01030da848fa7dc9e95c467dd95b368693
              • Opcode Fuzzy Hash: 29c288fe512e160f8e2cd1f4a921cb52c4f97518a8f141eade92c73a06e45805
              • Instruction Fuzzy Hash: 60510771E44249AFDF11CFA9CC84AEEBBB9EF49314F10406AE920B7650D7729A40CB61
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              • [DO][Failed to set DO status callback][%#08x], xrefs: 6CBBDB1B
              • [DO][Failed to create IDODownload][%#08x], xrefs: 6CBBD95B
              • [DO][Failed to get IDOManager][%#08x], xrefs: 6CBBD905
              • [DO][SetStringProperties failed][%#08x], xrefs: 6CBBD9B1
              • [DO][Setting ForegroundPriority failed][%#08x], xrefs: 6CBBDA6A
              • [DO][Setting NoProgressTimeoutSeconds failed][%#08x], xrefs: 6CBBDADD
              • [DO][SetExtendedProperties failed][%#08x], xrefs: 6CBBD9F3
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID: [DO][Failed to create IDODownload][%#08x]$[DO][Failed to get IDOManager][%#08x]$[DO][Failed to set DO status callback][%#08x]$[DO][SetExtendedProperties failed][%#08x]$[DO][SetStringProperties failed][%#08x]$[DO][Setting ForegroundPriority failed][%#08x]$[DO][Setting NoProgressTimeoutSeconds failed][%#08x]
              • API String ID: 0-3042039142
              • Opcode ID: 0ab392a0191be0e37d665b6b3825065fd708d70f8c54f7151880b2935154a295
              • Instruction ID: 229beac478089bcbda854ac7472543918db8026fbf2091fe7c06b5c324d97dce
              • Opcode Fuzzy Hash: 0ab392a0191be0e37d665b6b3825065fd708d70f8c54f7151880b2935154a295
              • Instruction Fuzzy Hash: 9BA1E3B1A04294AEDF19CFB4DC51EBE7BB4EFC6315B20462EE115FB694DB3885048B60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
              • DeleteFileW.KERNEL32(?,?,00000000), ref: 6CB98469
              • DeleteFileW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 6CB9847A
              Strings
              • MicrosoftEdgeUpdate.exe, xrefs: 6CB982A8
              • guid, xrefs: 6CB9830B
              • %s has encountered a fatal error.ver=%s;lang=%s;guid=%s;is_machine=%d;oop=%d;upload=%d;minidump=%s, xrefs: 6CB9838B
              • HKLM\Software\Microsoft\EdgeUpdateDev\, xrefs: 6CB982E5
              • ver, xrefs: 6CB98352
              • AlwaysAllowCrashUploads, xrefs: 6CB982E0
              • lang, xrefs: 6CB98332
              • [ReadParamsFromCustomInfoFile failed][%#08x], xrefs: 6CB9828C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalDeleteFileSection$EnterLeave
              • String ID: %s has encountered a fatal error.ver=%s;lang=%s;guid=%s;is_machine=%d;oop=%d;upload=%d;minidump=%s$AlwaysAllowCrashUploads$HKLM\Software\Microsoft\EdgeUpdateDev\$MicrosoftEdgeUpdate.exe$[ReadParamsFromCustomInfoFile failed][%#08x]$guid$lang$ver
              • API String ID: 4111867351-2419876452
              • Opcode ID: e14c7e5d2b4d130b993bb58a20cdc718eeac69bc07e6f9bebcde5fd46ceb526c
              • Instruction ID: ac5295e46762369b6d89be1b9d38bb8f856e647722113b1d0ce66e7809d01c52
              • Opcode Fuzzy Hash: e14c7e5d2b4d130b993bb58a20cdc718eeac69bc07e6f9bebcde5fd46ceb526c
              • Instruction Fuzzy Hash: 3E918E71D00149AFCF04DFA4C8919FDB7B5EF45318F14416AE512ABBE0EB316A08CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,6CD1A2EC,00000000,00000000,000F003F,\InProcServer32,00000000,?,00000000,\CLSID\,00000000,?,6CD1A2EC,00000001,00000000,000F003F), ref: 6CC0986C
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              • RegCloseKey.ADVAPI32(00000000,6CD1A2EC,00000000,00000000,000F003F,\InProcServer32,00000000,?,00000000,\CLSID\,00000000,?,6CD1A2EC,00000001,00000000,000F003F), ref: 6CC09840
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$QueryValue
              • String ID: HKCU$HKLM$[64]$\CLSID\$\InProcServer32$\Interface\$\ProxyStubClsid32$\SOFTWARE\Classes
              • API String ID: 2393043351-266242904
              • Opcode ID: 17d5863c852ffb1a9fefffa978d6f210706baf4d56476bb33cf896fc22425bdc
              • Instruction ID: f9f22a42912a6410f636bb1d0fda27ceaf35cd7dcc3191952cea041e509b7c60
              • Opcode Fuzzy Hash: 17d5863c852ffb1a9fefffa978d6f210706baf4d56476bb33cf896fc22425bdc
              • Instruction Fuzzy Hash: FC719272A001489BDF04DF69C895BFE7779BF55358F104059E811ABBA0EF31AA4DCBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetWindowLongW.USER32(?,000000F0), ref: 6CCA59FC
              • CreateSolidBrush.GDI32(00C67000), ref: 6CCA5A57
              • CreateSolidBrush.GDI32(00D27600), ref: 6CCA5A61
              • CreateSolidBrush.GDI32(00EFEFEF), ref: 6CCA5A74
              • CreateSolidBrush.GDI32(00F3F3F3), ref: 6CCA5A7E
              • CreateSolidBrush.GDI32(00F7F7F7), ref: 6CCA5A8A
              • CreateSolidBrush.GDI32(00000000), ref: 6CCA5AAE
              • CreateSolidBrush.GDI32(00000000), ref: 6CCA5AB8
              • CreateSolidBrush.GDI32(00000000), ref: 6CCA5AC2
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: BrushCreateSolid$LongWindow
              • String ID: Segoe UI
              • API String ID: 3533125719-2515502724
              • Opcode ID: 1e1141b72cb1ff0a87a8e5ebb7d96067d6148a5fc634ddc0c2a9e72e3b5a9bd8
              • Instruction ID: 392843407de8a4370f21a2ea9c808be990df56a12004056b3c0dc5d803687033
              • Opcode Fuzzy Hash: 1e1141b72cb1ff0a87a8e5ebb7d96067d6148a5fc634ddc0c2a9e72e3b5a9bd8
              • Instruction Fuzzy Hash: C7319F71F44354ABEF506FB58C8AB5A3FA8EF41B10F001196EA089F2C6E6B1C445CF60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB96838
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$DESCRIPTION$HKCU$HKROOT$Microsoft Edge Update CredentialDialog$MicrosoftEdgeUpdate.CredentialDialogUser$MicrosoftEdgeUpdateOnDemand.exe$PROGID$VERSION
              • API String ID: 1385522511-2522418078
              • Opcode ID: baa4eb8220140ee17f410b6fcc7895e3687b94191ade6225b02eafe39974e899
              • Instruction ID: fe6994b272d74896425241fa77db137f10c90470f21eb16f9b25179830a852a3
              • Opcode Fuzzy Hash: baa4eb8220140ee17f410b6fcc7895e3687b94191ade6225b02eafe39974e899
              • Instruction Fuzzy Hash: B411EB70604180AFE615DB688882DDE3365DB4731AB50483EBA06FFFA0DF30990D86F2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB960EB
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: 1.0$DESCRIPTION$HKLM$HKROOT$Microsoft Edge Update CredentialDialog$MicrosoftEdgeUpdate.CredentialDialogMachine$MicrosoftEdgeUpdateOnDemand.exe$PROGID$VERSION
              • API String ID: 1385522511-2275718165
              • Opcode ID: ed9ebceb763c226fc48580aae7012cd49f57986bf378ef24c2b64435e8374eb3
              • Instruction ID: a9cc5b6baed91b6a9c1d24e66516e1dbdb1146ce107fa51a626fdd6c6479bfb6
              • Opcode Fuzzy Hash: ed9ebceb763c226fc48580aae7012cd49f57986bf378ef24c2b64435e8374eb3
              • Instruction Fuzzy Hash: 3111EBB0204190AFE655DB689886DDE37A9DB4621DB50493DF602BFFA1DB30DC0D86F1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CC9CEF1: EnterCriticalSection.KERNEL32(6CD7E054,005D0065,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9CF00
                • Part of subcall function 6CC9CEF1: LeaveCriticalSection.KERNEL32(6CD7E054), ref: 6CC9D082
              • FindResourceW.KERNEL32(02A60001,005D0065,00000005,6CD67530,0069006B,00000000,02A60001,02A60001,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?), ref: 6CC9EB53
              • FindResourceW.KERNEL32(02A60001,005D0065,000000F0,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB6B
              • LoadResource.KERNEL32(02A60001,00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB77
              • LockResource.KERNEL32(00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB7E
              • LoadResource.KERNEL32(02A60001,6CC9F9B7,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB8A
              • LockResource.KERNEL32(00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB95
              • GetLastError.KERNEL32(?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EBC4
              • GlobalHandle.KERNEL32(6CC9F9B7), ref: 6CC9EBD6
              • GlobalFree.KERNEL32(00000000), ref: 6CC9EBDD
              • GetLastError.KERNEL32(?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EBE5
              • SetLastError.KERNEL32(00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EBF2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Resource$ErrorLast$CriticalFindGlobalLoadLockSection$EnterFreeHandleLeave
              • String ID:
              • API String ID: 1180024608-0
              • Opcode ID: 92b7241b259592253a8f70f556c866c124311343fbd8b32364dd7bdeac60b9ef
              • Instruction ID: fbc506153b8e6e38e6919f8788066290e6aebcd38dc2d33b22ce7840a7faed21
              • Opcode Fuzzy Hash: 92b7241b259592253a8f70f556c866c124311343fbd8b32364dd7bdeac60b9ef
              • Instruction Fuzzy Hash: 59115E71B05215BBAB111FB98C4CD6F3ABCEF57655B10042CFA16E2680EF70C9009AA8
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegQueryValueExW.ADVAPI32(00000000,ping_freshness,00000000,00000000,00000000,00000000,?,?), ref: 6CB9C348
                • Part of subcall function 6CB6C532: CharUpperW.USER32(?,?,?,?,?,?,?,6CB7A8B7,?,[rollback_to_target_version][%d],?,?,[target_version_prefix][%s],00000001,?,[target_channel][%s]), ref: 6CB6C569
                • Part of subcall function 6CB77407: lstrlenW.KERNEL32(00000000,?,?,6CB76F35,00000000,00000000,00000001,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000), ref: 6CB77410
                • Part of subcall function 6CB77407: RegSetValueExW.KERNELBASE(6CB76BD7,00000000,00000000,00000001,00000000,00000000,?,6CB76F35,00000000,00000000,00000001,00000000,?,00000000,00000000), ref: 6CB7742C
                • Part of subcall function 6CB76E35: RegCloseKey.KERNELBASE(00000000,00000000,00000000,00000001,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000,00000000,?,00000004), ref: 6CB76F41
                • Part of subcall function 6CB76E35: RegCloseKey.ADVAPI32(00000000,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000,00000000,?,00000004), ref: 6CB76F79
                • Part of subcall function 6CB773B5: RegSetValueExW.KERNELBASE(6CB76BD7,00000000,00000000,00000004,00000000,00000004,?,6CB76EF5,00000000,00000000,00000000,?,00000000,00000000,?,00000000), ref: 6CB773C8
              • RegCloseKey.ADVAPI32(00000000,?,?,?,000F003F,?,00000000,?,browser,00000000), ref: 6CB9C680
              • RegCloseKey.ADVAPI32(00000000,?,?), ref: 6CB9C6B9
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$Value$CharQueryUpperlstrlen
              • String ID: browser$eulaaccepted$lang$lastrun$oeminstall$ping_freshness
              • API String ID: 3988721204-1040517315
              • Opcode ID: 3af10d06c596c223512f31c219dd95fff8b268ddc4ed52be605cc734a589dbda
              • Instruction ID: 198bddd446a2fe91c562966a134030371973c4ebe5b4eed393f32aea8cec4a07
              • Opcode Fuzzy Hash: 3af10d06c596c223512f31c219dd95fff8b268ddc4ed52be605cc734a589dbda
              • Instruction Fuzzy Hash: 0EC15C719002999BDF05DFE4C898DEEB779FF45318F104429E916ABB90DB30A90DCB91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate
              • String ID: [GetForceInstallApps][is_machine][%d][%s]$[PolicyValue]$[conflict_source_][%s]$[conflict_value_][%s]$[source_][%s]$[value_][%s]
              • API String ID: 1075933841-1517127525
              • Opcode ID: 386c715eb683ed8e40f3164de4a5e824d5c4de907afeebf1e22f7275741f1644
              • Instruction ID: 30de9528420701321266e6c6727b7d982d901f4bb532c319b383bc74e521acc0
              • Opcode Fuzzy Hash: 386c715eb683ed8e40f3164de4a5e824d5c4de907afeebf1e22f7275741f1644
              • Instruction Fuzzy Hash: CDD13B72D002599FCF14DFA9C8808EDB7B5FF44318B15456DE866A7B90DB30AA49CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
              • __aulldiv.LIBCMT ref: 6CBBD4DD
              • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,-0000FDE9,00000000,?,00002710,00000000), ref: 6CBBD519
              • __aulldiv.LIBCMT ref: 6CBBD546
              • GetLastError.KERNEL32(00000007,000000FE,?,00002710,00000000), ref: 6CBBD6D5
              Strings
              • [DO][Failed to start the job][%#08x], xrefs: 6CBBD499
              • [DO][Failed to close the job][%#08x], xrefs: 6CBBD657
              • [DO][WaitForSingleObject failed][Result: %#x], xrefs: 6CBBD70B
              • [DO][Status error][%#08x], xrefs: 6CBBD5FD
              • [DO][WaitForSingleObject failed][Last error: %d], xrefs: 6CBBD6DC
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection__aulldiv$EnterErrorLastLeaveMultipleObjectsWait
              • String ID: [DO][Failed to close the job][%#08x]$[DO][Failed to start the job][%#08x]$[DO][Status error][%#08x]$[DO][WaitForSingleObject failed][Last error: %d]$[DO][WaitForSingleObject failed][Result: %#x]
              • API String ID: 3532012655-3578949827
              • Opcode ID: fb6e7bfd99dd10254994c2c512abfd9731a18a261e9486ed883a071aa5d87a92
              • Instruction ID: 3d2581e4c1cc190aa4c192eafcd1ab1adcebc00c37391bc0db4a1c46130de6a5
              • Opcode Fuzzy Hash: fb6e7bfd99dd10254994c2c512abfd9731a18a261e9486ed883a071aa5d87a92
              • Instruction Fuzzy Hash: E49106B1E042459BDB08CFB8D841ABEBBB6AFC5314F20862DE115F7B94DF3898048B51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBADC71: RegCloseKey.ADVAPI32(00000000,00000000,6CC05A2D,00000007,?,00000000), ref: 6CBADD1A
              • CloseHandle.KERNEL32(6CB8B8A8,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000000,00000000), ref: 6CB9801D
              • CloseHandle.KERNEL32(6CB8B8A8,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000000,00000000), ref: 6CB9802D
              • _Deallocate.LIBCONCRT ref: 6CB980C9
              • CloseHandle.KERNEL32(6CB8B8A8,?,?,6CB8B8A8,6CC05A59,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000000,00000000), ref: 6CB98152
              • _Deallocate.LIBCONCRT ref: 6CB981A6
              Strings
              • [AppCommand::Execute failed][%s][%d][%s][%#08x], xrefs: 6CB9813C
              • {56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}, xrefs: 6CB97F01, 6CB97F46, 6CB98134
              • [Finish browser replacement will not execute at this time. There are logged-on users.], xrefs: 6CB98004
              • [AppCommand::Execute][LaunchBrowserReplacementAppCommand], xrefs: 6CB98072, 6CB9808D
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$Handle$Deallocate
              • String ID: [AppCommand::Execute failed][%s][%d][%s][%#08x]$[AppCommand::Execute][LaunchBrowserReplacementAppCommand]$[Finish browser replacement will not execute at this time. There are logged-on users.]${56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
              • API String ID: 1293319391-3188817524
              • Opcode ID: 771ec9a9624702b44818843dfdb5a7d291bded98d99b7ee6f0ce63dd57abcbf2
              • Instruction ID: d80a4b78554fa1aa414475e9262fcaea3eca87ff7577fe3048691df8e3080c26
              • Opcode Fuzzy Hash: 771ec9a9624702b44818843dfdb5a7d291bded98d99b7ee6f0ce63dd57abcbf2
              • Instruction Fuzzy Hash: 6991B572D05299AFDF04DFA8D8919EDBBB5EF4A314F20016ED412B7B80DB315A08CB65
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegQueryInfoKeyW.ADVAPI32(?,00000000,00000000,00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000,80000000,?,00020019), ref: 6CB8A513
              • RegCloseKey.ADVAPI32(?), ref: 6CB8A524
              • RegQueryInfoKeyW.ADVAPI32(?,00000000,00000000,00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000,80000000,?,00020019), ref: 6CB8A5E0
              • RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,80000000,?,00020019), ref: 6CB8A5F1
              • RegCloseKey.ADVAPI32(?,80000000,?,00020019,?,?,?,?,?,?,?,?,?,80000000,?,00020019), ref: 6CB8A61E
              • RegCloseKey.ADVAPI32(80000000,80000000,?,00020019,?,?,?,?,?,?,?,?,?,80000000,?,00020019), ref: 6CB8A625
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$InfoQuery
              • String ID: CLSID\$\Implemented Categories$\Required Categories
              • API String ID: 852846383-4092563799
              • Opcode ID: dca8091feb21b421416997d2e19d9454c98f439899aa7020cecd046a2e2efd38
              • Instruction ID: fb4aa817202eb64b6d79162969daf5b0b61e4283087db3bf519369e37462d54b
              • Opcode Fuzzy Hash: dca8091feb21b421416997d2e19d9454c98f439899aa7020cecd046a2e2efd38
              • Instruction Fuzzy Hash: 22811F71A02268AFEB21DF558C84ADBB77CEF06308F5445E9E549E7A40D7309E848FA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE2FE6
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE300A
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE302E
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE3055
                • Part of subcall function 6CB6749C: GetSidLengthRequired.ADVAPI32(00000008,?,00000000,6CD3F770,?,?,?,?,?,?,?,?,6CB6C978,?,6CD3E5F4,00000001), ref: 6CB674F2
                • Part of subcall function 6CB6749C: InitializeSid.ADVAPI32(?,00000000,00000008,?,?,?,?,?,?,?,?,6CB6C978,?,6CD3E5F4,00000001,00000012), ref: 6CB67505
                • Part of subcall function 6CB6749C: GetSidSubAuthority.ADVAPI32(?,00000000,?,?,?,?,?,?,?,?,6CB6C978,?,6CD3E5F4,00000001,00000012,?), ref: 6CB67526
                • Part of subcall function 6CB74A63: ConvertSidToStringSidW.ADVAPI32(00000000,?), ref: 6CB74A7D
                • Part of subcall function 6CB74A63: LocalFree.KERNEL32(?,?,00000000,?,?,6CB76830,00000008,00000000), ref: 6CB74AA4
              • VariantInit.OLEAUT32(?), ref: 6CBE38D1
              • VariantInit.OLEAUT32(?), ref: 6CBE38F9
              • VariantInit.OLEAUT32(?), ref: 6CBE3921
                • Part of subcall function 6CB74325: SysAllocString.OLEAUT32(00000000), ref: 6CB7433E
              • SysFreeString.OLEAUT32(?), ref: 6CBE39A5
              • SysFreeString.OLEAUT32(?), ref: 6CBE39AB
              • VariantClear.OLEAUT32(?), ref: 6CBE39B8
              • VariantClear.OLEAUT32(?), ref: 6CBE39BF
              • VariantClear.OLEAUT32(?), ref: 6CBE39C6
              Strings
              • <?xml version="1.0" encoding="UTF-16"?><Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task"> <Re, xrefs: 6CBE3875
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Variant$Init$String$ClearFree$AllocAuthorityConvertInitializeLengthLocalRequired
              • String ID: <?xml version="1.0" encoding="UTF-16"?><Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task"> <Re
              • API String ID: 3815733561-2667174194
              • Opcode ID: 7d508738e57e1bdd1c9865a1073fab728441c706a007e13ceba6f594e45f1ae5
              • Instruction ID: 835321dd9f55e6bdef925851f5a7d751c18c4d7492824d7f3649d7a309322595
              • Opcode Fuzzy Hash: 7d508738e57e1bdd1c9865a1073fab728441c706a007e13ceba6f594e45f1ae5
              • Instruction Fuzzy Hash: 62615C725043459FCB01DF64C844A9FBBE9EF89355F404C1DF9899B260EB71EA09CB92
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              • HKU\, xrefs: 6CB8437E
              • LastLogonTime-User, xrefs: 6CB8440E, 6CB8441C
              • [Failed to set last logon time][%#08x], xrefs: 6CB84452
              • Software\Microsoft\EdgeUpdate\, xrefs: 6CB84360
              • LastLogonTime-Machine, xrefs: 6CB84405
              • [Failed to open/create user update key][%#08x], xrefs: 6CB843FE
              • [SetLastLogonTime][Failed to get user sid][%#08x], xrefs: 6CB84300
              • [SetLastLogonTime][user sid empty!], xrefs: 6CB84349
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle
              • String ID: HKU\$LastLogonTime-Machine$LastLogonTime-User$Software\Microsoft\EdgeUpdate\$[Failed to open/create user update key][%#08x]$[Failed to set last logon time][%#08x]$[SetLastLogonTime][Failed to get user sid][%#08x]$[SetLastLogonTime][user sid empty!]
              • API String ID: 2962429428-3144253710
              • Opcode ID: 3009efd5307dad576c5a3fbe33ed47041140af64f9f743f92e23de0009543b66
              • Instruction ID: 0813b69cec81bfa5588dec9af70cd58ad1af3ccfbb4821c38236828a70cbd8ff
              • Opcode Fuzzy Hash: 3009efd5307dad576c5a3fbe33ed47041140af64f9f743f92e23de0009543b66
              • Instruction Fuzzy Hash: 3551B571C04248AADF09DFA5D851AFE7BB8EB85315F24812AE525B7B90DB345508CB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetWindowLongW.USER32(?,000000F0), ref: 6CB6AF5D
              • GetWindow.USER32(?,00000004), ref: 6CB6AF7F
              • GetWindowRect.USER32(?,00000000), ref: 6CB6AF8D
              • GetWindowLongW.USER32(0000003C,000000F0), ref: 6CB6AFA2
              • MonitorFromWindow.USER32(?,00000002), ref: 6CB6AFBA
              • GetMonitorInfoW.USER32(00000000,?), ref: 6CB6AFD0
              • GetWindowRect.USER32(0000003C,00000080), ref: 6CB6AFFE
              • SetWindowPos.USER32(?,00000000,?,?,000000FF,000000FF,00000015), ref: 6CB6B0B0
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Window$LongMonitorRect$FromInfo
              • String ID: (
              • API String ID: 2882702216-3887548279
              • Opcode ID: 3022cd41105a37e3959da8607ba2d5ee76c900922281745c02290dbeb421bf66
              • Instruction ID: b8b5b7328994f6da0d8d4e926caff068507b8d494fd11d440de2466912b26b74
              • Opcode Fuzzy Hash: 3022cd41105a37e3959da8607ba2d5ee76c900922281745c02290dbeb421bf66
              • Instruction Fuzzy Hash: 5A517072A002299FDF11CEB9CD88ADEBBB9EB45315F151225FA55F7680D730A844CB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB8A14A: GetModuleFileNameW.KERNEL32(6CB60000,?,00000104), ref: 6CB8A1FF
                • Part of subcall function 6CB7934E: RaiseException.KERNEL32(00000000,00000001,00000000,00000000,6CB781E7,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB79362
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(00000000,?,?,EventMessageFile,?,00000001,6CB8CBED,?,?,000F003F,?,00000000,?,?,?), ref: 6CB8E19E
              • RegCloseKey.ADVAPI32(00000000,00000000,00000000,?,00000000,000F003F,?,00000000,80000000,AppID,00020006,00000001,00000000,?,?,?), ref: 6CB8E1C9
              • RegCloseKey.ADVAPI32(00000000,00000000,00000000,?,00000000,000F003F,?,00000000,80000000,AppID,00020006,00000001,00000000,?,?,?), ref: 6CB8E1E2
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$ExceptionFileModuleNameOpenRaise
              • String ID: /comsvc$AppID$EventMessageFile$HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\%s$LocalService$ServiceParameters
              • API String ID: 2561982856-2289412666
              • Opcode ID: 1ddd5d0bd25d6b9b50c5139849a3c11903fc1e78b01a2ad625cbc20dae8e4ae7
              • Instruction ID: 2236eb6d749f321305aeb3223c4f9fe121302f5a549d063da9d4a0297b8e876a
              • Opcode Fuzzy Hash: 1ddd5d0bd25d6b9b50c5139849a3c11903fc1e78b01a2ad625cbc20dae8e4ae7
              • Instruction Fuzzy Hash: C1418471D012A9ABEF25ABE4CC45BFEB675AF04719F110118E92177BA0DB740E08CBE1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB8A14A: GetModuleFileNameW.KERNEL32(6CB60000,?,00000104), ref: 6CB8A1FF
                • Part of subcall function 6CB7934E: RaiseException.KERNEL32(00000000,00000001,00000000,00000000,6CB781E7,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB79362
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(00000000,?,?,EventMessageFile,?,00000001,6CB8CDC6,?,?,000F003F,?,00000000,?,?,?), ref: 6CB8E401
              • RegCloseKey.ADVAPI32(00000000,00000000,00000000,?,00000000,000F003F,?,00000000,80000000,AppID,00020006,00000001,00000000,?,?,?), ref: 6CB8E42C
              • RegCloseKey.ADVAPI32(00000000,00000000,00000000,?,00000000,000F003F,?,00000000,80000000,AppID,00020006,00000001,00000000,?,?,?), ref: 6CB8E445
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$ExceptionFileModuleNameOpenRaise
              • String ID: /comsvc$AppID$EventMessageFile$HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\%s$LocalService$ServiceParameters
              • API String ID: 2561982856-2289412666
              • Opcode ID: 21e761e08f7675ba6582f110dd5b541da1f96c4060517a3710cb763848c4e5c0
              • Instruction ID: 9e5b23c2d1734aac70d2064ad9c5b27164113c494554fdb96acfdf8f6d0b2dd2
              • Opcode Fuzzy Hash: 21e761e08f7675ba6582f110dd5b541da1f96c4060517a3710cb763848c4e5c0
              • Instruction Fuzzy Hash: AA419F71D012A9ABEF219BE0CC45BFEB675AF04718F154118E92077BA0DBB40E088BE1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysStringLen.OLEAUT32(6CBC676C), ref: 6CBC6B97
              • SysStringLen.OLEAUT32(?), ref: 6CBC6B9E
              • _Deallocate.LIBCONCRT ref: 6CBC6C1C
              • SysFreeString.OLEAUT32(?), ref: 6CBC6C2C
              • SysFreeString.OLEAUT32(6CBC676C), ref: 6CBC6C31
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free$Deallocate
              • String ID: %d(%d) : error 0x%08lx: %s %s$<no reason>$<no source text>$`)u
              • API String ID: 3275992043-1946584697
              • Opcode ID: b7dbd70c4e9c28b115bb5a7397b5a477489f121a42a6506e493c789da1b906a5
              • Instruction ID: d3caf9c5ce80fb1ea4571593ed1fefb7b1dab7472b455e45d4df79903b7303e6
              • Opcode Fuzzy Hash: b7dbd70c4e9c28b115bb5a7397b5a477489f121a42a6506e493c789da1b906a5
              • Instruction Fuzzy Hash: 0A31D332A01929AF8F05DFA8CC41DAF7BB9EF482247110569E815E7750EB70EE018B91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegQueryValueExW.ADVAPI32(?,old-uid,00000000,00000000,00000000,00000000,HKLM\Software\Microsoft\EdgeUpdate\,000F003F), ref: 6CB81F9A
              • RegCloseKey.ADVAPI32(?,uid,old-uid), ref: 6CB82020
              • ReleaseMutex.KERNEL32(?,uid,old-uid), ref: 6CB82040
              • CloseHandle.KERNEL32(?), ref: 6CB8205C
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
                • Part of subcall function 6CB77407: lstrlenW.KERNEL32(00000000,?,?,6CB76F35,00000000,00000000,00000001,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000), ref: 6CB77410
                • Part of subcall function 6CB77407: RegSetValueExW.KERNELBASE(6CB76BD7,00000000,00000000,00000001,00000000,00000000,?,6CB76F35,00000000,00000000,00000001,00000000,?,00000000,00000000), ref: 6CB7742C
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Value$CloseQuery$HandleMutexReleaselstrlen
              • String ID: ; legacy$HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$old-uid$uid
              • API String ID: 34608818-2297772141
              • Opcode ID: 6961ecf5e427c1834e43a6adfbb716d6c90ecb0d5076a0a63e5849d59c960230
              • Instruction ID: 06a4f905774faeb1fbacf22cb7275aa1d507d45eeb63204f54cfc7e06694abf8
              • Opcode Fuzzy Hash: 6961ecf5e427c1834e43a6adfbb716d6c90ecb0d5076a0a63e5849d59c960230
              • Instruction Fuzzy Hash: C5318571901199EBDF10DBD9C849AEFFBB8EF51318F148155E921B3BA0D7309A48CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNEL32(?,0.0.0.0,00000000,?,00000007,?), ref: 6CBF0A4E
              • lstrcmpiW.KERNEL32(?,windowsupdate_zdp), ref: 6CBF0A76
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi
              • String ID: -critical$-win-$-zdp$0.0.0.0$msedge-$msedgeupdate-stable-win-$msedgewebview-stable-win-$windowsupdate_zdp
              • API String ID: 1586166983-2952741659
              • Opcode ID: eb317c1905d0aebecd57b293049c9f701718b986b2a21b58e0725090b67a946c
              • Instruction ID: d3a9ded704b58725ccc44a6e42c191c84a4c2a706b2491907d72f7bb6bbfe35f
              • Opcode Fuzzy Hash: eb317c1905d0aebecd57b293049c9f701718b986b2a21b58e0725090b67a946c
              • Instruction Fuzzy Hash: 4E717232D001899BDF04DFA9D890AEDB7B5EF15318F104569D46267BA0EF31AD0ECB51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNEL32(?,direct,00000000,00000000), ref: 6CBC0542
              • lstrcmpiW.KERNEL32(?,auto_detect), ref: 6CBC054E
              • lstrcmpiW.KERNEL32(?,pac_script), ref: 6CBC0562
              • lstrcmpiW.KERNEL32(?,fixed_servers), ref: 6CBC0582
              • lstrcmpiW.KERNEL32(?,system), ref: 6CBC05A4
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi
              • String ID: auto_detect$direct$fixed_servers$pac_script$system
              • API String ID: 1586166983-3951332089
              • Opcode ID: f78bac3aa3fae662fc65c0c2836ec657729a90969bb3fd47306ae7af74c012de
              • Instruction ID: 3f939955a4b5826b0c2614c763db3ba45420f89769a2d433d67e9b5f369986f6
              • Opcode Fuzzy Hash: f78bac3aa3fae662fc65c0c2836ec657729a90969bb3fd47306ae7af74c012de
              • Instruction Fuzzy Hash: 0F21C3B23042816BD704EB79DC90EAE72989F95258F01492CE951D7B90EF30DD0D8BB3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: __aulldvrm
              • String ID: :$f$f$f$p$p$p
              • API String ID: 1302938615-1434680307
              • Opcode ID: b003eb94a4b5f2e804f6b71e14d9b82d596d13265e73fead03cb56e449b89c9b
              • Instruction ID: ce27c8398ee26590ec9227bd22b58844549faa8d7cca43d5766e8fe877002191
              • Opcode Fuzzy Hash: b003eb94a4b5f2e804f6b71e14d9b82d596d13265e73fead03cb56e449b89c9b
              • Instruction Fuzzy Hash: 4D025075B01218CAEF208FA5D4466DDB7B2FB06B18FA4415ED414BBA80F7349D88CB93
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB77BFD: RegQueryInfoKeyW.ADVAPI32(6CB76BD7,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,6CD3F7F0,?,6CB8C8CC,HKLM\Software\Microsoft\EdgeUpdate\ClientState\), ref: 6CB77C17
                • Part of subcall function 6CB77C22: RegEnumKeyExW.KERNELBASE(6CB76BD7,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6CB77C5E
                • Part of subcall function 6CB721E7: CharLowerBuffW.USER32(00000000,?,?,00000000,?,6CB73D99,0000005C,00000000,00000000,00000000,?,00000001,?), ref: 6CB72203
              • RegCloseKey.ADVAPI32(00000000,aggregate,?,00020019,00000000,00000000,6CD3F7F0), ref: 6CB9BB12
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              • lstrcmpiW.KERNEL32(?,sum(),aggregate,?,00020019,00000000,00000000,6CD3F7F0), ref: 6CB9BB58
              • RegCloseKey.ADVAPI32(00000000), ref: 6CB9BBB8
                • Part of subcall function 6CB77B4E: RegQueryInfoKeyW.ADVAPI32(6CB76BD7,00000000,00000000,00000000,00000000,00000000,00000000,6CB7C70A,00000000,00000000,00000000,00000000,6CD3F7F0,?,6CB7C70A), ref: 6CB77B68
              • RegCloseKey.ADVAPI32(00000000,?), ref: 6CB9BD0A
              Strings
              • [ReadAppDefinedAttributeSubkeys]['%s' aggregate not supported], xrefs: 6CB9BB92
              • sum(), xrefs: 6CB9BB52
              • [ReadAppDefinedAttributeSubkeys][Type needs to be DWORD[%s], xrefs: 6CB9BC51
              • aggregate, xrefs: 6CB9BB31
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseQuery$Info$BuffCharEnumLowerValuelstrcmpi
              • String ID: [ReadAppDefinedAttributeSubkeys]['%s' aggregate not supported]$[ReadAppDefinedAttributeSubkeys][Type needs to be DWORD[%s]$aggregate$sum()
              • API String ID: 3690950962-1487008119
              • Opcode ID: 49bdafdfe897a9d5e64ac4f70d76c25361605df536abe9f9b3b7e689a7071306
              • Instruction ID: 3ace31d77e20a72ccbf193d6966ab5b2854d7babe7087a1b5b3ab9cd77cdfa16
              • Opcode Fuzzy Hash: 49bdafdfe897a9d5e64ac4f70d76c25361605df536abe9f9b3b7e689a7071306
              • Instruction Fuzzy Hash: 8981A471D00259ABDF14DFE4D895AEDB774FF42319F204129E921B7BA0EB345909CB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB803D8: __aulldiv.LIBCMT ref: 6CB80411
              • RegQueryValueExW.ADVAPI32(?,uid,00000000,00000000,00000000,00000000,HKLM\Software\Microsoft\EdgeUpdate\,?,?,000F003F,?,00000000), ref: 6CB8215D
              • RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\EdgeUpdate\,?,?,000F003F,?,00000000), ref: 6CB822B7
              • CloseHandle.KERNEL32(00000000,?,?,000F003F,?,00000000), ref: 6CB822E0
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$HandleQueryValue__aulldiv
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$old-uid$uid
              • API String ID: 2408594573-3495521444
              • Opcode ID: 5541b48133b48a2ab2ffdee41494b4301f2efa7ec52bcd7a7fdaa112601bab07
              • Instruction ID: dfa0e52c6aa01d87b5412646d8aebc9b089a4e0dfa8eab606185472a110cc48c
              • Opcode Fuzzy Hash: 5541b48133b48a2ab2ffdee41494b4301f2efa7ec52bcd7a7fdaa112601bab07
              • Instruction Fuzzy Hash: F0619E71E022599FDF00DFA9C888ADEBBB5EF88314F148129D911B7B51EB309905CF62
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CBAC83A
              • SysFreeString.OLEAUT32(?), ref: 6CBAC885
              • SysFreeString.OLEAUT32(?), ref: 6CBAC8C4
              • SysFreeString.OLEAUT32(?), ref: 6CBAC8ED
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: App$`)u$update3web
              • API String ID: 3341692771-4094339378
              • Opcode ID: f82739d6297536378de341c35efe4da53f9d5ab620e8375014ef8a119100d435
              • Instruction ID: 994100bc3cc0b8b3b676c0287cf8bd2e976e8c552ac5dc17f83e915b99b6f838
              • Opcode Fuzzy Hash: f82739d6297536378de341c35efe4da53f9d5ab620e8375014ef8a119100d435
              • Instruction Fuzzy Hash: CD418E36A00154EFCB01EF69C884C9D7BB5FF4936570241A8E94A9BB61DB31ED4ACF90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegOpenKeyExW.ADVAPI32(80000002,?,00000000,00020019,?,?,?), ref: 6CB6974E
              • RegQueryValueExW.ADVAPI32(?,PendingFileRenameOperations,00000000,?,00000000,?), ref: 6CB6977D
              • RegQueryValueExW.ADVAPI32(?,PendingFileRenameOperations,00000000,00000000,00000000,?), ref: 6CB697B9
              • lstrcmpW.KERNEL32(?,?), ref: 6CB69803
              • lstrlenW.KERNEL32(?), ref: 6CB69810
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: QueryValue$Openlstrcmplstrlen
              • String ID: PendingFileRenameOperations$SYSTEM\CurrentControlSet\Control\Session Manager$\??\
              • API String ID: 2090349685-3703331852
              • Opcode ID: 0907aee5ea3e24835def39901d37b68df0dfa92ef51e22ee260cbb3f4cfd7415
              • Instruction ID: 2d2c9f0c2a3b8735a755496209f38d28b564d3cb0946aad74a75ae757c1d3864
              • Opcode Fuzzy Hash: 0907aee5ea3e24835def39901d37b68df0dfa92ef51e22ee260cbb3f4cfd7415
              • Instruction Fuzzy Hash: 21416D71D0025DAFEF209FEACC809EEB7BCEF05759B204129E915A7A52E7309905CF91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB6537
              • CloseHandle.KERNEL32(00000000,?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB654D
              • QueueUserWorkItem.KERNEL32(6CBB6489,6CD7CB88,00000000,?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB6570
              • ResetEvent.KERNEL32(?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB6584
              • GetTickCount64.KERNEL32 ref: 6CBB6591
              • GetTickCount64.KERNEL32 ref: 6CBB65A4
              • WaitForSingleObject.KERNEL32(00000000,?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB65DB
              Strings
              • [NetworkCostAsync timeout][%u], xrefs: 6CBB6617
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Count64EventTick$CloseCreateHandleItemObjectQueueResetSingleUserWaitWork
              • String ID: [NetworkCostAsync timeout][%u]
              • API String ID: 2481315169-3807370346
              • Opcode ID: e97a9986056305e28cbca8ada32f124eaf4c1e106e6ea8cf3dfe4fd72989a397
              • Instruction ID: 727e080e5867dcbe7a839ce3cbe379aaca2b2e1057d8e51e60f8c5d990e16eae
              • Opcode Fuzzy Hash: e97a9986056305e28cbca8ada32f124eaf4c1e106e6ea8cf3dfe4fd72989a397
              • Instruction Fuzzy Hash: 4A419F747042659FEF15AF68C88897E7BBCEB86314B14462AF655E7790DB308C408BA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,InstallTime,00000000,DayOfInstall,00000000,referral,?,brand,?,lang,?,6CD44078,?,?,00020019,{8A69D345-D564-463c-AFF1-A69D9E530F96}), ref: 6CB83CCA
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: DayOfInstall$HKLM\Software\Google\Update\ClientState\$InstallTime$brand$lang$referral${8A69D345-D564-463c-AFF1-A69D9E530F96}
              • API String ID: 3535843008-1382647879
              • Opcode ID: 16385e43a0f48e72ac75e22d382d07771e749739f74d94ef85360a4188fe76cf
              • Instruction ID: 120b2a274bb424953f79d440cf1088951a5f259f144ee8ffa443c2b3aa49a35c
              • Opcode Fuzzy Hash: 16385e43a0f48e72ac75e22d382d07771e749739f74d94ef85360a4188fe76cf
              • Instruction Fuzzy Hash: 4A315C7190124AAFDF05CF94C852AEE7BB8FF15319F100514EA21B7AA0DB709A59CFA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • DecodePointer.KERNEL32(00000000,?,?,6CCEA033,6CD7BF84,?,?,?,6CBDD4CE,00000000,00000000,00000080,?,?,6CBDF2F9,00000000), ref: 6CCE9CA7
              • LoadLibraryExA.KERNEL32(atlthunk.dll,00000000,00000800,00000000,?,?,6CCEA033,6CD7BF84,?,?,?,6CBDD4CE,00000000,00000000,00000080,?), ref: 6CCE9CBC
              • DecodePointer.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,00000080,00000000,?,Software\Microsoft\EdgeUpdate\,LastChecked), ref: 6CCE9D38
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DecodePointer$LibraryLoad
              • String ID: AtlThunk_AllocateData$AtlThunk_DataToCode$AtlThunk_FreeData$AtlThunk_InitData$atlthunk.dll
              • API String ID: 1423960858-1745123996
              • Opcode ID: 0f31f27b50032daba9eb4f6afe0d8b5019400de31a7118cfacdc7431e41f7b7c
              • Instruction ID: f58028404a586305f83533b866870edb8384a3f50ec626c0e2fa5ee992655e71
              • Opcode Fuzzy Hash: 0f31f27b50032daba9eb4f6afe0d8b5019400de31a7118cfacdc7431e41f7b7c
              • Instruction Fuzzy Hash: 8301DB705055787BEB529B649C05BCD3B985B0794EF000094FC04BBDD5F722970CC595
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNEL32(-00000002,exe), ref: 6CBB161C
              • lstrcmpiW.KERNEL32(-00000002,msi), ref: 6CBB1668
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi
              • String ID: %s %s%s$/installerdata=$[No extension found in %s]$[Unsupported extension '%s' in %s]$exe$msi$msiexec
              • API String ID: 1586166983-3091714430
              • Opcode ID: 8b9859e70db48c252e79bcdea3a8eead11e553f90dd32c2c4405b60c8b29d205
              • Instruction ID: 385064dc7e8b0b5cd4df682d90cc4a05e2496d980501e905748a696dc6fd1314
              • Opcode Fuzzy Hash: 8b9859e70db48c252e79bcdea3a8eead11e553f90dd32c2c4405b60c8b29d205
              • Instruction Fuzzy Hash: 1E51C371A0414AEFDB04DFA5D880DFE77B8EF85308B148529E516E7B90DB309E08CB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CurrentThread$_xtime_get$Xtime_diff_to_millis2
              • String ID:
              • API String ID: 3943753294-0
              • Opcode ID: 6f3e333e44f3dc7f6858ee0bc876b0dc5af42dae85f108f366d81a18e4a3b781
              • Instruction ID: 411e05e21b1199ea198b974d190a9a47c0f813d2f44ca18e3b7c5aa42492f6af
              • Opcode Fuzzy Hash: 6f3e333e44f3dc7f6858ee0bc876b0dc5af42dae85f108f366d81a18e4a3b781
              • Instruction Fuzzy Hash: CE519030A0461ADFDF10DF68C4845A9BBB4FF4F719B248599D905EBA80E730EA41CFA4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,000F003F,?,?,00000000,?,?,6CB8D6E0,?,?,?,6CB8DEB7,?,?,00000000), ref: 6CBC47C0
              • OpenServiceW.ADVAPI32(00000000,00000000,00000024,?,?,6CB8D6E0,?,?,?,6CB8DEB7,?,?,00000000,?,00000000,?), ref: 6CBC47DE
              • QueryServiceStatus.ADVAPI32(00000000,6CB8D6E0,?,?,6CB8D6E0,?,?,?,6CB8DEB7,?,?,00000000,?,00000000,?), ref: 6CBC47FD
              • GetTickCount.KERNEL32 ref: 6CBC4846
              • GetTickCount.KERNEL32 ref: 6CBC4851
              • Sleep.KERNEL32(00000032,?,?,6CB8D6E0), ref: 6CBC485F
              • QueryServiceStatus.ADVAPI32(00000000,6CB8D6E0,?,?,?,?,?,6CB8D6E0), ref: 6CBC4879
              • CloseServiceHandle.ADVAPI32(00000000,?,?,6CB8D6E0,?,?,?,6CB8DEB7,?,?,00000000,?,00000000,?), ref: 6CBC48A4
              • CloseServiceHandle.ADVAPI32(?,?,?,6CB8D6E0,?,?,?,6CB8DEB7,?,?,00000000,?,00000000,?), ref: 6CBC48AD
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseCountHandleOpenQueryStatusTick$ErrorLastManagerSleep
              • String ID:
              • API String ID: 3789840665-0
              • Opcode ID: 82e2b51326655272e4098e13d90f6e69411e06f1a75211e24a893492d81d4f44
              • Instruction ID: d60597ee3349890af814a31458d0b6debcbc811865ba3287e167d6e45e97b942
              • Opcode Fuzzy Hash: 82e2b51326655272e4098e13d90f6e69411e06f1a75211e24a893492d81d4f44
              • Instruction Fuzzy Hash: AC316271B412999BEF019BA4CCC4AFE77BCEB09309B500525E611E6680DBB5DA058F62
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • EnterCriticalSection.KERNEL32(6CD7E054,005D0065,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9CF00
              • LeaveCriticalSection.KERNEL32(6CD7E054), ref: 6CC9D082
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$EnterLeave
              • String ID: 0$0$0$AtlAxWin140$AtlAxWinLic140$WM_ATLGETCONTROL$WM_ATLGETHOST
              • API String ID: 3168844106-2597313724
              • Opcode ID: 043566f88a31e176c89df131465631a945bfc26d70d792992ae7f61bf5826b4a
              • Instruction ID: c3851155ba08785c9871c644ecaa7f084dbc59cb8423bc3d91482d15aed09d9a
              • Opcode Fuzzy Hash: 043566f88a31e176c89df131465631a945bfc26d70d792992ae7f61bf5826b4a
              • Instruction Fuzzy Hash: 824128B1509321AFE701DF25C80965BBAF8EB89748F00491EF58897690D774D609CFE6
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcessId.KERNEL32 ref: 6CB74416
              • OpenProcess.KERNEL32(00000400,00000000), ref: 6CB7442E
              • OpenProcessToken.ADVAPI32(00000000,00000018,?), ref: 6CB74441
              • GetTokenInformation.ADVAPI32(?,00000019(TokenIntegrityLevel),00000000,00000000,?), ref: 6CB74459
              • LocalAlloc.KERNEL32(00000040,?), ref: 6CB74469
              • GetTokenInformation.ADVAPI32(?,00000019(TokenIntegrityLevel),00000000,?,?), ref: 6CB74482
              • LocalFree.KERNEL32(00000000), ref: 6CB7449A
              • CloseHandle.KERNEL32(?), ref: 6CB744A3
              • CloseHandle.KERNEL32(00000000), ref: 6CB744AA
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ProcessToken$CloseHandleInformationLocalOpen$AllocCurrentFree
              • String ID:
              • API String ID: 3791146967-0
              • Opcode ID: 55b10dd6e937d1660927697308d197d1519d283d62e30450ff2a1d6a680974b8
              • Instruction ID: 9c6c62ed4532ee960bfb5c3050bb84d2b26b4a0f2b0e9d91b396ecb94e8590d5
              • Opcode Fuzzy Hash: 55b10dd6e937d1660927697308d197d1519d283d62e30450ff2a1d6a680974b8
              • Instruction Fuzzy Hash: 4F214135A05128FBEB219F958808AEE7B7CEF06756F100059EE24A7640DB748A11EFB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
                • Part of subcall function 6CBADD27: RegCloseKey.ADVAPI32(00000000,00000000,00020019,HKLM\Software\Microsoft\EdgeUpdate\Clients\,00000000,00000000,00000000), ref: 6CBADE26
              • _Deallocate.LIBCONCRT ref: 6CC06809
              Strings
              • [LaunchAppCommandsOnLogon][AppCommand::Execute][%s], xrefs: 6CC06746
              • [LaunchAppCommandsOnLogon][AppCommand::Execute failed][%s][%d][%s][%#08x], xrefs: 6CC067B1
              • %I64u, xrefs: 6CC066AC
              • [LaunchAppCommandsOnLogon][EnumAllCommands failed][%#08x], xrefs: 6CC06530
              • OnLogonLaunchError, xrefs: 6CC067CC
              • [LaunchAppCommandsOnLogon][AppCommand::Load failed][%s][%d][%s][%#08x], xrefs: 6CC065CC
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$CloseDeallocateEnterLeave
              • String ID: %I64u$OnLogonLaunchError$[LaunchAppCommandsOnLogon][AppCommand::Execute failed][%s][%d][%s][%#08x]$[LaunchAppCommandsOnLogon][AppCommand::Execute][%s]$[LaunchAppCommandsOnLogon][AppCommand::Load failed][%s][%d][%s][%#08x]$[LaunchAppCommandsOnLogon][EnumAllCommands failed][%#08x]
              • API String ID: 2382417194-1099251645
              • Opcode ID: 3da1013c5c2ed3e92f0bbc1e0a7635c34520079932ed342eadf760314950c968
              • Instruction ID: 5ba2682fe3d0dcab237ff7c679be9a51d21298d25528debe6f5038b4e9cd841b
              • Opcode Fuzzy Hash: 3da1013c5c2ed3e92f0bbc1e0a7635c34520079932ed342eadf760314950c968
              • Instruction Fuzzy Hash: D6B1AF71E04259AFDF04DFA8D8919EDBBB5BF45318F200129E511F7B90EB31A949CB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ClearVariant
              • String ID: `)u
              • API String ID: 1473721057-4279031584
              • Opcode ID: e425a58a222f8cadf9fa6d3c10ea5c5a0b9ad55dc053b7111ee626b48c02ad41
              • Instruction ID: 36ffa658882e1029c6700c8f727d4909329f5f0e3f2cbed8b9587e1688ab532a
              • Opcode Fuzzy Hash: e425a58a222f8cadf9fa6d3c10ea5c5a0b9ad55dc053b7111ee626b48c02ad41
              • Instruction Fuzzy Hash: 74A167716043819FDB10CF64C844A5BBBE9EFC9759F10491DB8A9DB220EB31E905CFA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6C532: CharUpperW.USER32(?,?,?,?,?,?,?,6CB7A8B7,?,[rollback_to_target_version][%d],?,?,[target_version_prefix][%s],00000001,?,[target_channel][%s]), ref: 6CB6C569
                • Part of subcall function 6CB74BB1: CloseHandle.KERNEL32(00000000,00000000,6CB75015,?,00000000), ref: 6CB74BC3
              • _Deallocate.LIBCONCRT ref: 6CBB1BCD
              Strings
              • [Installer failed][%s][%s][%u], xrefs: 6CBB1B93
              • [Running installer][%s][%s][%s], xrefs: 6CBB193A
              • MicrosoftEdgeUpdateIsMachine, xrefs: 6CBB19C8
              • [p.Start fail][0x%08x][%s][%s], xrefs: 6CBB1AA2
              • MicrosoftEdgeUpdateUntrustedData, xrefs: 6CBB198C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CharCloseDeallocateHandleUpper
              • String ID: MicrosoftEdgeUpdateIsMachine$MicrosoftEdgeUpdateUntrustedData$[Installer failed][%s][%s][%u]$[Running installer][%s][%s][%s]$[p.Start fail][0x%08x][%s][%s]
              • API String ID: 2935067091-3262761591
              • Opcode ID: ce013e5dc244dcf490562f419fd4c234deff7802368a66aa5c14c6a27f07056f
              • Instruction ID: c7d6c997ddb7aa5da143ebf33fdfba3dddc97222e05e1126792097eab4c0c76d
              • Opcode Fuzzy Hash: ce013e5dc244dcf490562f419fd4c234deff7802368a66aa5c14c6a27f07056f
              • Instruction Fuzzy Hash: 39918072900189AFDF04DFA5DC91DEE7BB8FF49318B144129E915B7BA0DB31A909CB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateWellKnownSid.ADVAPI32(0000000B,00000000,?,?,?,?,?), ref: 6CBC4207
              • CheckTokenMembership.ADVAPI32(00000000,?,?,?,?,?), ref: 6CBC4223
              • GetFileAttributesExW.KERNEL32(?,00000000,?,\Google\Chrome\User Data\First Run,00000000,\Microsoft\Edge\User Data\First Run,00000000,?,?,?), ref: 6CBC4353
              • GetFileAttributesExW.KERNEL32(?,00000000,?,?,?,?,?), ref: 6CBC4382
              • CloseHandle.KERNEL32(00000000,?,?,?), ref: 6CBC4476
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AttributesFile$CheckCloseCreateHandleKnownMembershipTokenWell
              • String ID: \Google\Chrome\User Data\First Run$\Microsoft\Edge\User Data\First Run
              • API String ID: 628023025-4144525634
              • Opcode ID: 13323568182c6cccf1bb2b68e2ee97eb15e97859817fe0061250c7a287a4daeb
              • Instruction ID: 8238e379f0e39bccc5b5dab67ceef5428d632dfb8c934338938b4bd6d3e8be23
              • Opcode Fuzzy Hash: 13323568182c6cccf1bb2b68e2ee97eb15e97859817fe0061250c7a287a4daeb
              • Instruction Fuzzy Hash: 8C716671B002989EEB20CB65CC50BFE77B9EF46304F6005A99559A7A40DB745E89CF13
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CBDFC40
              • SysFreeString.OLEAUT32(?), ref: 6CBDFC73
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u
              • API String ID: 3341692771-4279031584
              • Opcode ID: 0dd27d2c592ef2b70102fe6036dbcf985da3766d3c21f89ef40a449706a8499b
              • Instruction ID: be97f779214226fdb4aaaac939eed0918f49be0813607d5b864994d094fcc2cd
              • Opcode Fuzzy Hash: 0dd27d2c592ef2b70102fe6036dbcf985da3766d3c21f89ef40a449706a8499b
              • Instruction Fuzzy Hash: CA718231E04299EFCB01DFA4C884A9EBB75FF89315B1645A9D811ABB10EB30F945CF90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(00000000), ref: 6CB90808
              • SysFreeString.OLEAUT32(00000000), ref: 6CB90822
              • VariantClear.OLEAUT32(?), ref: 6CB90934
              • VariantClear.OLEAUT32(?), ref: 6CB90959
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ClearFreeStringVariant
              • String ID: `)u
              • API String ID: 1438600931-4279031584
              • Opcode ID: 28d01d37f010f49f7439f70fa1ae50cc9410605ee0634fbc61ea8943934876a5
              • Instruction ID: 3cc6a967b7ab11f358492adf8c6687e074bbcd56c005e33370895b108debdd02
              • Opcode Fuzzy Hash: 28d01d37f010f49f7439f70fa1ae50cc9410605ee0634fbc61ea8943934876a5
              • Instruction Fuzzy Hash: B761D1716053959FEB04CF18D884B1BBBB8FF8A719F10852CF8599B640D770D904CB92
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • EnterCriticalSection.KERNEL32(6CD7E054,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,?,?,?,?,?,?,?,?,?,?,6CC0729F,6CD781F0), ref: 6CBDF064
              • LeaveCriticalSection.KERNEL32(6CD7E054), ref: 6CBDF0BD
              • swprintf.LIBCMT ref: 6CBDF12C
              • LeaveCriticalSection.KERNEL32(6CD7E054,?,?,?,?,?,?,?,?,?,?,6CC0729F,6CD781F0,00000000,?,-80000001), ref: 6CBDF18F
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$Leave$Enterswprintf
              • String ID: 0$ATL:%p${2D905E07-FC38-4b89-83E1-931D3630937F}
              • API String ID: 1255232340-53712622
              • Opcode ID: fb22868ea1f790cbb7da5b6d8ad53fe44cf94e064cbd7da896dacdba0d948b9e
              • Instruction ID: fd7912774cbc4479d13975416e736176e1097fe60234d86608070c0db8940aa0
              • Opcode Fuzzy Hash: fb22868ea1f790cbb7da5b6d8ad53fe44cf94e064cbd7da896dacdba0d948b9e
              • Instruction Fuzzy Hash: 4A51E475208382EFEB14CF15C88099B7BF9FF85354B11451EED548BA45E731E845CBA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
                • Part of subcall function 6CC3D43D: _Deallocate.LIBCONCRT ref: 6CC3D4BB
              • _Deallocate.LIBCONCRT ref: 6CC3D87A
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalDeallocateSection$EnterLeave
              • String ID: /%s$MicrosoftEdgeUpdate.exe$install$uninstall$update
              • API String ID: 1065795893-3468587603
              • Opcode ID: 1a360eb5543a467d38331507392feacf9f7faa6ee190bfd369b12077fc820b24
              • Instruction ID: 5ce4f912bf78cf069023b48d9a3379c5465ffa44a6bed41ac8649d2d062b1935
              • Opcode Fuzzy Hash: 1a360eb5543a467d38331507392feacf9f7faa6ee190bfd369b12077fc820b24
              • Instruction Fuzzy Hash: BC51D331D1015AABCB04DFB5D884AEEB774AF40318F200569D925A7BC0FB34BA0DCBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcAddress.KERNEL32(00000000,InternetInitializeAutoProxyDll), ref: 6CBB772A
              • FreeLibrary.KERNEL32(00000000,?,?,?,?,?,6CBB70EC,?,?), ref: 6CBB7742
              • FreeLibrary.KERNEL32(00000000,?,00000000,00000000,000000FF,?,00000000,00000000), ref: 6CBB7851
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeLibrary$AddressErrorLastProc
              • String ID: InternetInitializeAutoProxyDll$jsproxy.dll
              • API String ID: 1092183831-2726205570
              • Opcode ID: 088a41a467784499422f153dbadf997415d9df5cb4a722eb82eca5f1501cb2c9
              • Instruction ID: df5da1548cd35e98387803df3b4b153b3606ea17e779de4dfee6a4f17a786caa
              • Opcode Fuzzy Hash: 088a41a467784499422f153dbadf997415d9df5cb4a722eb82eca5f1501cb2c9
              • Instruction Fuzzy Hash: 38417231A0028AEFDB04DBAAC894AFD7774EF15319F204558952277BD0EF705E08CB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6FDFB: GetSystemTimeAsFileTime.KERNEL32(?,6CD3E6AC,6CD3E6AC,?,6CB68434,00000000,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB6FE1B
              • __aulldiv.LIBCMT ref: 6CBDC5A0
                • Part of subcall function 6CB7CCA2: __aulldiv.LIBCMT ref: 6CB7CCB4
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\, xrefs: 6CBDC5B5
              • RetryAfter, xrefs: 6CBDC5C4
              • HKLM\Software\Microsoft\EdgeUpdateDev\, xrefs: 6CBDC694
              • DisableUpdateAppsHourlyJitter, xrefs: 6CBDC68F
              • [ShouldCheckForUpdates returned 0][checks disabled], xrefs: 6CBDC62A
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CBDC5A5
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Time__aulldiv$FileSystem
              • String ID: DisableUpdateAppsHourlyJitter$HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdateDev\$HKLM\Software\Microsoft\EdgeUpdate\$RetryAfter$[ShouldCheckForUpdates returned 0][checks disabled]
              • API String ID: 1198726632-3543715990
              • Opcode ID: 8fb5d7fadb0686e72950afd2070f5c3a192474f417c8c897e0c20a190b391e6b
              • Instruction ID: f5121c2a94e18176e1e1ed7a235e095fb82882776ccc9d76befe9e8b53b4cf03
              • Opcode Fuzzy Hash: 8fb5d7fadb0686e72950afd2070f5c3a192474f417c8c897e0c20a190b391e6b
              • Instruction Fuzzy Hash: 7E412AB1D442886FDF05EFA488519FE7B78DF40348F04856EE515E7B40E7349E088B61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6FDFB: GetSystemTimeAsFileTime.KERNEL32(?,6CD3E6AC,6CD3E6AC,?,6CB68434,00000000,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB6FE1B
              • __aulldiv.LIBCMT ref: 6CB9D67C
              • RegCloseKey.ADVAPI32(00000000,6CD3F7F0,00000000,?,00989680,00000000,?), ref: 6CB9D7B6
                • Part of subcall function 6CB773B5: RegSetValueExW.KERNELBASE(6CB76BD7,00000000,00000000,00000004,00000000,00000004,?,6CB76EF5,00000000,00000000,00000000,?,00000000,00000000,?,00000000), ref: 6CB773C8
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Time$CloseFileSystemValue__aulldiv
              • String ID: ActivePingDayStartSec$DayOfLastActivity$DayOfLastRollCall$RollCallDayStartSec$ping_freshness
              • API String ID: 3192646957-3219260298
              • Opcode ID: da068cb1615b869ea0f26c2ae73509b09607771c7a0bfa2e40cae84c9ae820f8
              • Instruction ID: a29840d9c81f328354a7e635f9a86e6f46bd042954316ebb2dbeb85918efc49b
              • Opcode Fuzzy Hash: da068cb1615b869ea0f26c2ae73509b09607771c7a0bfa2e40cae84c9ae820f8
              • Instruction Fuzzy Hash: 1E419431A04289ABDF01DFF1D894BEE7B79EF5630CF000429E942A7A91DB74954DCBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?), ref: 6CB83800
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseQueryValue
              • String ID: InstallTime$brand$client$iid$lang$referral
              • API String ID: 3356406503-3631440621
              • Opcode ID: 443329e1fbb51c773dd708587dc37b0ed93f1347f12950733423e4010b313be1
              • Instruction ID: 747826f1ddd63afd3c5071ab0be71b37bd2158b930592b25258545cd8d786176
              • Opcode Fuzzy Hash: 443329e1fbb51c773dd708587dc37b0ed93f1347f12950733423e4010b313be1
              • Instruction Fuzzy Hash: 3841497180218EEBDF11CF94C954BEEB7B4EF1530DF200418E82473AA0DB749A88CB92
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CBE9C3A
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u$data$index$install$name$untrusted
              • API String ID: 3341692771-3583269115
              • Opcode ID: 940249d5cf70fbbc43bab020675c81588ac189270b0a82a2ce0323406a4b2db5
              • Instruction ID: a618842e22bd74bee4b20d3bc65bab2a3c9f94030611de3dc3e0aaf97bc1bf52
              • Opcode Fuzzy Hash: 940249d5cf70fbbc43bab020675c81588ac189270b0a82a2ce0323406a4b2db5
              • Instruction Fuzzy Hash: 16419136A01611AFDB05EF58C884EDE77F5EF89B65F218059E8009B751EB30ED48CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __aulldiv.LIBCMT ref: 6CB9E6B6
              • GetCurrentProcess.KERNEL32(80040512,?), ref: 6CB9E736
              • TerminateProcess.KERNEL32(00000000), ref: 6CB9E73D
              • GetLastError.KERNEL32(00000007,000000FE), ref: 6CB9E777
              Strings
              • InstallError, xrefs: 6CB9E6E2
              • [DownloadWatchdog][Timed out after %I64u milliseconds (%d rewaits). Collecting log , locking out downloader type '%s', and TERMIN, xrefs: 6CB9E6C1
              • [DownloadWatchdog - why didn't this process die?][0x%8x], xrefs: 6CB9E78E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Process$CurrentErrorLastTerminate__aulldiv
              • String ID: InstallError$[DownloadWatchdog - why didn't this process die?][0x%8x]$[DownloadWatchdog][Timed out after %I64u milliseconds (%d rewaits). Collecting log , locking out downloader type '%s', and TERMIN
              • API String ID: 809044789-76091786
              • Opcode ID: 0da89925db1504ac11d584e3c999a2542ec41c3ef083affde98fd92344b96d88
              • Instruction ID: 28098efb5ae4467da91654c34d155eb27d132f0d809293dc8f5c5e818a75fd09
              • Opcode Fuzzy Hash: 0da89925db1504ac11d584e3c999a2542ec41c3ef083affde98fd92344b96d88
              • Instruction Fuzzy Hash: 3131D571608380AFDB04DF75CC45DAE7BA8EF85219F008A2EB556D7B90EB34D5088BA5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB7763B: RegCloseKey.KERNELBASE(00000000,?,00000000,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\,?,?), ref: 6CB7769C
                • Part of subcall function 6CB7763B: RegCloseKey.ADVAPI32(00000000,00000000,00000000,?,HKLM\Software\Microsoft\EdgeUpdate\,?,?), ref: 6CB776BF
              • lstrcmpiW.KERNEL32(?,6CD2BE08,HKLM\Software\Microsoft\EdgeUpdate\,49EF6F00,00000000,?,?,?,?,?,?,?,6CBDC839,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010), ref: 6CBDC3CF
              Strings
              • [ImplicitlyAcceptEula][Failed to accept for EdgeUpdate][0x%08X], xrefs: 6CBDC521
              • [ImplicitlyAcceptEula][OS EULA acceptance will be propagated to app][%s], xrefs: 6CBDC486
              • [ImplicitlyAcceptEula][Failed to accept EULA for app][%s][0x%08X], xrefs: 6CBDC4DE
              • [ImplicitlyAcceptEula][Cannot read install source][0x%08X], xrefs: 6CBDC3B4
              • [ImplicitlyAcceptEula][Not preinstalled][%s], xrefs: 6CBDC412
              • [ImplicitlyAcceptEula][OS EULA not accepted][0x%08X], xrefs: 6CBDC552
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CBDC30E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$lstrcmpi
              • String ID: HKLM\Software\Microsoft\EdgeUpdate\$[ImplicitlyAcceptEula][Cannot read install source][0x%08X]$[ImplicitlyAcceptEula][Failed to accept EULA for app][%s][0x%08X]$[ImplicitlyAcceptEula][Failed to accept for EdgeUpdate][0x%08X]$[ImplicitlyAcceptEula][Not preinstalled][%s]$[ImplicitlyAcceptEula][OS EULA acceptance will be propagated to app][%s]$[ImplicitlyAcceptEula][OS EULA not accepted][0x%08X]
              • API String ID: 2522296566-1925029627
              • Opcode ID: fbbbd5b6420776222ac196d1e1a65726ddcc9a630d9bd3df5d7b20832a1c561d
              • Instruction ID: a205e5d66edc7e40a0ab5b72728acf6fcc50a9b1bd5a267b4ea5093640ec77a0
              • Opcode Fuzzy Hash: fbbbd5b6420776222ac196d1e1a65726ddcc9a630d9bd3df5d7b20832a1c561d
              • Instruction Fuzzy Hash: E66116B0D14299AADF04DFA9D852AFEBFB8EF46219F10011ED521F7B90D73456088BA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBC6E32: SysStringLen.OLEAUT32(00000000), ref: 6CBC6E4F
                • Part of subcall function 6CBC6E32: SysFreeString.OLEAUT32(00000000), ref: 6CBC6E85
              • lstrcmpiW.KERNEL32(?,6CD4A0D0), ref: 6CBE8993
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Freelstrcmpi
              • String ID: Version$arguments$codebase$hash$size$status$version
              • API String ID: 3883830792-2134052301
              • Opcode ID: 5c4ade8c6e273066e25e10c90f8928deceacbb0b04790cf70416707eadd375ba
              • Instruction ID: 2e7e677e759c15dd3c0527499a54e5ff144c20346a00f45aa6f4dab266e4fac7
              • Opcode Fuzzy Hash: 5c4ade8c6e273066e25e10c90f8928deceacbb0b04790cf70416707eadd375ba
              • Instruction Fuzzy Hash: E761A171A006898FCF04DFE8C8909EEB7B9EF58754F50416AD406EBA54EB31A94DCB50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB76913: CloseHandle.KERNEL32(00000000,?,?,00000000,?,00000000), ref: 6CB76975
              • Sleep.KERNEL32(00000064,00000000,?,-11E1A300,?,?,?,?,?,?,?,6CC0613A,00000000,00000000,00000000), ref: 6CB84134
              Strings
              • HKU\, xrefs: 6CB841E4
              • [GetLastLogonTime][Failed to get user sid][%#08x], xrefs: 6CB841C4
              • LastLogonTime-User, xrefs: 6CB84227
              • Software\Microsoft\EdgeUpdate\, xrefs: 6CB841D7
              • [GetLastLogonTime][user sid empty!], xrefs: 6CB84179
              • [Failed to get last logon time][%#08x], xrefs: 6CB8427C
              • LastLogonTime-Machine, xrefs: 6CB84220
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandleSleep
              • String ID: HKU\$LastLogonTime-Machine$LastLogonTime-User$Software\Microsoft\EdgeUpdate\$[Failed to get last logon time][%#08x]$[GetLastLogonTime][Failed to get user sid][%#08x]$[GetLastLogonTime][user sid empty!]
              • API String ID: 252777609-1982341691
              • Opcode ID: 1e0ea84b92f982f9cc3b0b7da3180a8e30ac45df97c835ca3b6a01802a5bd271
              • Instruction ID: e9151dbfeb6744b1d7c7ef1d5697c8c371499bd4b5ac3ed9d729a7a36dd5a48b
              • Opcode Fuzzy Hash: 1e0ea84b92f982f9cc3b0b7da3180a8e30ac45df97c835ca3b6a01802a5bd271
              • Instruction Fuzzy Hash: 5441F472D04248AADF08DFA5D851BFD7BB89B85328F24422ED121F7BD0DB349548CB65
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcessHeap.KERNEL32(00000008,0000000D,00000000,?,6CCE9F4A,?,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000), ref: 6CCE9DC5
              • HeapAlloc.KERNEL32(00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000,?), ref: 6CCE9DCC
                • Part of subcall function 6CCE9E97: IsProcessorFeaturePresent.KERNEL32(0000000C,6CCE9DB3,00000000,?,6CCE9F4A,?,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000), ref: 6CCE9E99
              • InterlockedPopEntrySList.KERNEL32(00000000,00000000,?,6CCE9F4A,?,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?), ref: 6CCE9DDC
              • VirtualAlloc.KERNEL32(00000000,00001000,00001000,00000040,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000), ref: 6CCE9E03
              • RaiseException.KERNEL32(C0000017,00000000,00000000,00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000), ref: 6CCE9E17
              • InterlockedPopEntrySList.KERNEL32(00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000,?), ref: 6CCE9E2A
              • VirtualFree.KERNEL32(00000000,00000000,00008000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080), ref: 6CCE9E3D
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AllocEntryHeapInterlockedListVirtual$ExceptionFeatureFreePresentProcessProcessorRaise
              • String ID:
              • API String ID: 2460949444-0
              • Opcode ID: 0439f4fcd2edf65bde47528437827d49296844f8e3b70027d55ff133c9c694a3
              • Instruction ID: cfdf6193ea5636c7b3f0ced754fef44ecc1c434c37078d0147e14e63fef1739a
              • Opcode Fuzzy Hash: 0439f4fcd2edf65bde47528437827d49296844f8e3b70027d55ff133c9c694a3
              • Instruction Fuzzy Hash: FA114F71745621BBFB211B695C48B9B767CEB4BB95F104429FB10D7680EB71CC0087A0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBC38D7: RegCloseKey.ADVAPI32(?,?,SOFTWARE\Clients\StartMenuInternet,00020019,?,?), ref: 6CBC3948
                • Part of subcall function 6CBC38D7: RegCloseKey.ADVAPI32(00000000,IEXPLORE.EXE,00000000,?,SOFTWARE\Clients\StartMenuInternet,00020019,?,?), ref: 6CBC39BE
              • lstrcmpiW.KERNEL32(?,IEXPLORE.EXE,?,6CBC3F58,?,00000000,00000000,?,6CBC3C35,?,?,?), ref: 6CBC39FB
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$lstrcmpi
              • String ID: CHROME.EXE$FIREFOX.EXE$Google Chrome$IEXPLORE.EXE
              • API String ID: 2522296566-42168918
              • Opcode ID: eea711acafaeea403e865dc2e901110834d6348079a0aca8ade4f960c7ae1e8b
              • Instruction ID: 7cd1e708042d397c4f1560f2a0cf7cd29823ce730d7aa3a06f23230129c26f6a
              • Opcode Fuzzy Hash: eea711acafaeea403e865dc2e901110834d6348079a0aca8ade4f960c7ae1e8b
              • Instruction Fuzzy Hash: B2018471745287EBEB40CF9ACC80ADEB7B8DF01388F500025E51197A50E774AA28C76A
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              • [DO][Failed to set download property][%d][%s][%#08x], xrefs: 6CBBE16B
              • [DO][Failed to remove non empty local path %d][%#08x], xrefs: 6CBBDE2E
              • [DO][Requried property empty][%d], xrefs: 6CBBE0FA
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ClearDeallocateVariant
              • String ID: [DO][Failed to remove non empty local path %d][%#08x]$[DO][Failed to set download property][%d][%s][%#08x]$[DO][Requried property empty][%d]
              • API String ID: 3834668905-4040969597
              • Opcode ID: 57e9ee824ec45479ddbe550459cc0a130547347a797dd43c730d17b83f2b93a3
              • Instruction ID: 9c604608a1af5d40c40460eea1218f53ea11b2930f0f4417166678a3ceb0187b
              • Opcode Fuzzy Hash: 57e9ee824ec45479ddbe550459cc0a130547347a797dd43c730d17b83f2b93a3
              • Instruction Fuzzy Hash: 48C16C71D042A99FEB24CB64CC41BEDB7B8FB44314F1446DAD509B7A90DB346A88CFA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GlobalAlloc.KERNEL32(00000000,00000000,02A60001,00000000,00000000,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530), ref: 6CC99611
              • SysStringLen.OLEAUT32(00000000), ref: 6CC9978C
              • SysAllocStringLen.OLEAUT32(00000000,?), ref: 6CC9979F
              • SysFreeString.OLEAUT32(00000000), ref: 6CC997ED
              • SysFreeString.OLEAUT32(00000000), ref: 6CC99804
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$AllocFree$Global
              • String ID: `)u
              • API String ID: 2028547557-4279031584
              • Opcode ID: 35d5ae84786788a1d06592bf32c4a16328b2ddd9fa08f007068a6ff0c29d8274
              • Instruction ID: 66498c3ebdd49d6e5022892cd37418dbf14ebbec536aa8f58ec29aaf7b1c2df1
              • Opcode Fuzzy Hash: 35d5ae84786788a1d06592bf32c4a16328b2ddd9fa08f007068a6ff0c29d8274
              • Instruction Fuzzy Hash: EFA1A371E0021A9FDB19CFA9C884AAEB7B8EF48714F1041ADE519E7640FB709E40CB94
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB7BEAB: _Deallocate.LIBCONCRT ref: 6CB7BF77
              • _Deallocate.LIBCONCRT ref: 6CBE054B
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate
              • String ID: `)u
              • API String ID: 1075933841-4279031584
              • Opcode ID: ca0df1b0e0108832b76eb5d7d8745ccb434d8a121f4cb36aa731a2d735f97dcd
              • Instruction ID: 2f25ee233a904fc5bac84d6650bd4168dab5111f0d691f91910c80a1a00d60a0
              • Opcode Fuzzy Hash: ca0df1b0e0108832b76eb5d7d8745ccb434d8a121f4cb36aa731a2d735f97dcd
              • Instruction Fuzzy Hash: 22A19E32D01199AFCF04DFA8E9909EEBBB5EF48754F214159E815BB740DB30AD05DBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(00000000), ref: 6CB90A4A
              • VariantInit.OLEAUT32(?), ref: 6CB90A9E
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeInitStringVariant
              • String ID: `)u
              • API String ID: 133326217-4279031584
              • Opcode ID: 36bc4efe15393399655f281e7d6ff13818af667ea35fe06606c75ebb553338a6
              • Instruction ID: ae6e3e76f12b49c68fc3396cf00fd6bd369ce3b09dfc18f6115a7e387a1c3196
              • Opcode Fuzzy Hash: 36bc4efe15393399655f281e7d6ff13818af667ea35fe06606c75ebb553338a6
              • Instruction Fuzzy Hash: 5C819C716053819FEB04CF64D884B6BB7F8EF8A718F10892DF9589B650E770D944CBA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB72844: GetCurrentThread.KERNEL32 ref: 6CB7284B
                • Part of subcall function 6CB72844: OpenThreadToken.ADVAPI32(00000000,00000000,00000001,75922EE0,?,6CB75A4C,00000008,6CD3F770,6CD3F770,00000000,6CB76278,?,00000000,00000000,75922EE0), ref: 6CB7285B
              • GetShortPathNameW.KERNEL32(?,?,00000104), ref: 6CB72C85
                • Part of subcall function 6CB6AEA7: FindCloseChangeNotification.KERNELBASE(00000000,00000000,6CB6C9AF,00000008,00000000,?,00000007), ref: 6CB6AECF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Thread$ChangeCloseCurrentFindNameNotificationOpenPathShortToken
              • String ID: %TEMP%$%TMP%$%USERPROFILE%$\Temp
              • API String ID: 4234862588-829844335
              • Opcode ID: 12044ee3413c50ad3e0fa2d9666b26c30129ec68c39573b45bc93056652cac47
              • Instruction ID: 3fa6f4306abfc5257d5e49e6c9ea1d0928a296436ed01563897c13741dc27475
              • Opcode Fuzzy Hash: 12044ee3413c50ad3e0fa2d9666b26c30129ec68c39573b45bc93056652cac47
              • Instruction Fuzzy Hash: 3A817E71E011A8EFCF04DFA9CA989EDB7B5EF55308F1001A8D952A7B94DB305E09CB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateFileW.KERNEL32(?,00000001,00000001,00000000,00000003,00000080,00000000,00100000,?,00000000,?,00000000), ref: 6CBC5A59
              • GetFileSizeEx.KERNEL32(00000000,6CBC5CAF,?,00000001,00000001,00000000,00000003,00000080,00000000,00100000,?,00000000,?,00000000), ref: 6CBC5A75
              • ReadFile.KERNEL32(00000000,?,?,00000000,00000000,?,00000001,00000001,00000000,00000003,00000080,00000000,00100000,?,00000000,?), ref: 6CBC5AC0
              • CloseHandle.KERNEL32(00000000,?,00000001,00000001,00000000,00000003,00000080,00000000,00100000,?,00000000,?,00000000), ref: 6CBC5AEB
              • CloseHandle.KERNEL32(00000000,?,00000001,00000001,00000000,00000003,00000080,00000000,00100000,?,00000000,?,00000000), ref: 6CBC5BD5
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: File$CloseHandle$CreateReadSize
              • String ID: [actual hash=%S]
              • API String ID: 3664964396-3643042611
              • Opcode ID: 79183962fba0022c4a03c07e851499c85e4a1cd4278b465f06d6d624c65e4dc8
              • Instruction ID: ffe092f7bf8e4ba402fe012d79b453d38545535ca4fd5a0166e63f6ac6e05d70
              • Opcode Fuzzy Hash: 79183962fba0022c4a03c07e851499c85e4a1cd4278b465f06d6d624c65e4dc8
              • Instruction Fuzzy Hash: 3E516371B00249AFDB04DFA9CC85EEEBBB4EF49304F104129E912E7790DB709949DB66
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6AE6A: GetCurrentProcess.KERNEL32(00000000,?,6CB6C92F,00000008,00000000,?,00000007), ref: 6CB6AE77
                • Part of subcall function 6CB6AE6A: OpenProcessToken.ADVAPI32(00000000,?,00000000,00000000,?,6CB6C92F,00000008,00000000,?,00000007), ref: 6CB6AE85
                • Part of subcall function 6CB6E3F5: GetTokenInformation.ADVAPI32(6CB6AEA7,00000004,00000000,00000000,00000000,6CD3F138,?,00000000,00000000,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}), ref: 6CB6E424
                • Part of subcall function 6CB6E3F5: GetLastError.KERNEL32 ref: 6CB6E42A
                • Part of subcall function 6CB6E3F5: GetTokenInformation.ADVAPI32(?,00000004,00000000,00000000,00000000,00000000), ref: 6CB6E47D
              • GetSecurityDescriptorControl.ADVAPI32(00000000,00000000,?,?,?,?,00000008,00000000,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},00000000,?), ref: 6CB6B5C0
              • GetSecurityDescriptorOwner.ADVAPI32(00000000,?,?,?,?,00000008,00000000,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},00000000,?), ref: 6CB6B5F2
              • GetSecurityDescriptorGroup.ADVAPI32(00000000,?,?,?,?,00000008,00000000,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},00000000,?), ref: 6CB6B618
              • GetSecurityDescriptorDacl.ADVAPI32(00000000,?,?,?,?,?,00000008,00000000,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},00000000,?), ref: 6CB6B645
              • GetSecurityDescriptorSacl.ADVAPI32(00000000,00000000,?,?,?,?,00000008,00000000,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},00000000,?), ref: 6CB6B67B
                • Part of subcall function 6CB6AA0E: GetSecurityDescriptorOwner.ADVAPI32(?,?,6CB6B77A,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A,?,00000220,?,10000000,00000000), ref: 6CB6AA33
                • Part of subcall function 6CB6AA0E: GetLengthSid.ADVAPI32(6CB6B77E,00000220,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AA5D
                • Part of subcall function 6CB6E4BC: GetTokenInformation.ADVAPI32(6CB6AEA7,00000005(TokenIntegrityLevel),00000000,00000000,00000000,6CD3F138,?,00000000,00000000,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}), ref: 6CB6E4EB
                • Part of subcall function 6CB6E4BC: GetLastError.KERNEL32 ref: 6CB6E4F1
                • Part of subcall function 6CB6E4BC: GetTokenInformation.ADVAPI32(?,00000005(TokenIntegrityLevel),00000000,00000000,00000000,00000000), ref: 6CB6E544
                • Part of subcall function 6CB6AACA: GetSecurityDescriptorGroup.ADVAPI32(?,00000000,6CB6B77A,6CB6B77A,00000000,?,?,?,80004005,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AAEF
                • Part of subcall function 6CB6AACA: GetLengthSid.ADVAPI32(6CB6B77E,00000220,6CB6B77A,00000000,?,?,?,80004005,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AB19
                • Part of subcall function 6CB6E324: GetTokenInformation.ADVAPI32(03333333,00000006,00000000,00000000,00000000,?,?,00000000,00000000,80070003), ref: 6CB6E353
                • Part of subcall function 6CB6E324: GetLastError.KERNEL32 ref: 6CB6E359
                • Part of subcall function 6CB6E324: GetTokenInformation.ADVAPI32(?,00000006,00000000,00000000,00000000,00000000), ref: 6CB6E3AC
                • Part of subcall function 6CB6E583: GetTokenInformation.KERNELBASE(?,00000001(TokenIntegrityLevel),00000000,00000000,00000000,?,00000000,6CD3F770,00000008,00000000), ref: 6CB6E5B4
                • Part of subcall function 6CB6E583: GetLastError.KERNEL32 ref: 6CB6E5BA
                • Part of subcall function 6CB6E583: GetTokenInformation.KERNELBASE(?,TokenIntegrityLevel,00000000,00000000,00000000,00000000), ref: 6CB6E60C
                • Part of subcall function 6CB6AB86: GetSecurityDescriptorDacl.ADVAPI32(?,?,00000000,6CB6B77A,6CB6B77A,?,00000220,?,6CB6B77A), ref: 6CB6ABB5
                • Part of subcall function 6CB6AB86: SetSecurityDescriptorDacl.ADVAPI32(?,00000001,00000000,00000000,6CB6B77A,?,00000220,?,6CB6B77A), ref: 6CB6AC2A
              Strings
              • {E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}, xrefs: 6CB6B440
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DescriptorSecurityToken$Information$ErrorLast$Dacl$GroupLengthOwnerProcess$ControlCurrentOpenSacl
              • String ID: {E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}
              • API String ID: 4171470565-1902337801
              • Opcode ID: d501a0c1bd0d542a0a9eaf6e899bee5f884a5a3757cfb0591cb1cf8d802035c7
              • Instruction ID: fc9866e5d70abe059d814c70106d565eb1c500f7a862feaa6d78d2872ea15985
              • Opcode Fuzzy Hash: d501a0c1bd0d542a0a9eaf6e899bee5f884a5a3757cfb0591cb1cf8d802035c7
              • Instruction Fuzzy Hash: D361FB728111689ADF26DF61CC94BEEB779EF09309F1041EAE509A6A60DB305F8CCF51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcessId.KERNEL32(?,00000000,6CB97978,?,?,?,6CBDB891,?,?), ref: 6CBE05BE
              • SysFreeString.OLEAUT32(?), ref: 6CBE06F4
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CurrentFreeProcessString
              • String ID: On Demand Bundle$`)u$lang$name
              • API String ID: 1388233386-182835584
              • Opcode ID: c92aac6f4da0e8efa9b330d47c057a5d8f21492fa10a8c45cadd9fdf27ab027f
              • Instruction ID: 5f313171324e09d40f3c51a0d7abc8a5b76d74238574f1b2f69755a363069d1b
              • Opcode Fuzzy Hash: c92aac6f4da0e8efa9b330d47c057a5d8f21492fa10a8c45cadd9fdf27ab027f
              • Instruction Fuzzy Hash: FE615735A0028A9FDB04DF95D894AEEBBB5BF58358F100068D812AB790DF71AE49CF50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CCCF70F: GetSystemTimeAsFileTime.KERNEL32(00000000,?,?,?,6CBE4B0E,00000000,-7FFFFFFF,?,?,00000000,000F003F), ref: 6CCCF722
                • Part of subcall function 6CCCF70F: __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CCCF753
              • _strftime.LIBCMT ref: 6CBD7B01
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Time$FileSystemUnothrow_t@std@@@__ehfuncinfo$??2@_strftime
              • String ID: %Y-%m-%d %H:%M:%S$CRITICAL$ERROR$INFO$UNKNOWN_SEVERITY
              • API String ID: 1658271636-1733567519
              • Opcode ID: 08da30c4e3b1e65165bb13fcccfc231aa9645914010d3244eff358009a99a972
              • Instruction ID: 81097338c04d830824a3ffbf63855e03e52ddfdc4898dfafd7fb7c9c197d77f6
              • Opcode Fuzzy Hash: 08da30c4e3b1e65165bb13fcccfc231aa9645914010d3244eff358009a99a972
              • Instruction Fuzzy Hash: 4A51B1716083819FC704CF64C8909EFB7E5EF88304F51491EF59597B80EB70E9098BA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80A55: CloseHandle.KERNEL32(?), ref: 6CB80ACE
              • WaitForSingleObject.KERNEL32(00000000,0003A980,?,00000004,00000001,00000007,00000000), ref: 6CCA7DA1
              • GetLastError.KERNEL32(00000007,000000FE), ref: 6CCA7DFB
              Strings
              • [Failed to create process][Mode: %d][0x%08x][Cmdline: %s, xrefs: 6CCA7D85
              • [Wait failed][Error: %d][Cmd line: %s], xrefs: 6CCA7E06
              • [Process timed out][Cmd line: %s], xrefs: 6CCA7E4B
              • [Wait abandonded][Cmd line: %s], xrefs: 6CCA7E8D
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseErrorHandleLastObjectSingleWait
              • String ID: [Failed to create process][Mode: %d][0x%08x][Cmdline: %s$[Process timed out][Cmd line: %s]$[Wait abandonded][Cmd line: %s]$[Wait failed][Error: %d][Cmd line: %s]
              • API String ID: 2173817864-1235966309
              • Opcode ID: 094858bf1f25dd288520e11687024adaa7f2f620aae02958f0f34b332a35f7e5
              • Instruction ID: af8000c9eff3f1c605fd41d63bcad5008bff66ecc9f3b6a86a30294d0539d0d1
              • Opcode Fuzzy Hash: 094858bf1f25dd288520e11687024adaa7f2f620aae02958f0f34b332a35f7e5
              • Instruction Fuzzy Hash: C941E7B2D04255AEDB14CBE5DC52AFE7BB8EB42314F20462BE125F6BD0E7344A049760
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6EA55: FindFirstFileW.KERNEL32(00000000,?), ref: 6CB6EAB9
                • Part of subcall function 6CB6EA55: FindClose.KERNEL32(00000000), ref: 6CB6EB52
              • CreateFileW.KERNEL32(?,00000001,00000001,00000000,00000003,?,00000000,?,00000000), ref: 6CB98B5F
              • DeleteFileW.KERNEL32(?), ref: 6CB98BFF
              • _Deallocate.LIBCONCRT ref: 6CB98C43
              Strings
              • ????????-????-????-????-????????????.dmp, xrefs: 6CB98AE2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: File$Find$CloseCreateDeallocateDeleteFirst
              • String ID: ????????-????-????-????-????????????.dmp
              • API String ID: 3464521203-2893526242
              • Opcode ID: c3c9cf73c14addc8254d0cb24ea6053717e6d668ef28e94c7a08b20d6837ed39
              • Instruction ID: 63e6eeea3d2c0b56fc8ae08b1704324b5a04287da6d4668c8d77a2dba0c121f0
              • Opcode Fuzzy Hash: c3c9cf73c14addc8254d0cb24ea6053717e6d668ef28e94c7a08b20d6837ed39
              • Instruction Fuzzy Hash: 8141B172E046689BDF148FA9C844B9DB7B8EB46720F25422EE915BB780DB716D04CB50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDFAF7
              • SysFreeString.OLEAUT32(?), ref: 6CBDFB43
              • SysFreeString.OLEAUT32(?), ref: 6CBDFB79
              • SysFreeString.OLEAUT32(?), ref: 6CBDFBA8
              • SysFreeString.OLEAUT32(?), ref: 6CBDFBD7
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u
              • API String ID: 3341692771-4279031584
              • Opcode ID: 19c5b1869cc141a60511eb1d35af35b2f1d502bda529746c8db97076ab630c4c
              • Instruction ID: c479f75976b890294c5d85a88c8a44984938fa6b8a05c1250ffbb9ee81d602c6
              • Opcode Fuzzy Hash: 19c5b1869cc141a60511eb1d35af35b2f1d502bda529746c8db97076ab630c4c
              • Instruction Fuzzy Hash: 42419E31601250AFCB028F60C888FAE3F75EF49365B1640A9EC159B660E735ED94DFA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • _ValidateLocalCookies.LIBCMT ref: 6CCC61B7
              • ___except_validate_context_record.LIBVCRUNTIME ref: 6CCC61BF
              • _ValidateLocalCookies.LIBCMT ref: 6CCC6248
              • __IsNonwritableInCurrentImage.LIBCMT ref: 6CCC6273
              • _ValidateLocalCookies.LIBCMT ref: 6CCC62C8
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
              • String ID: csm
              • API String ID: 1170836740-1018135373
              • Opcode ID: 83498b01076fd91a41beaaaaa5c32750226097dfc691887e08fea510b570537d
              • Instruction ID: 61bb5ce9ba34b4e4ea224c777b9bd9c87e8a9ceb0a8e56cf332d9cfd7c2db7fb
              • Opcode Fuzzy Hash: 83498b01076fd91a41beaaaaa5c32750226097dfc691887e08fea510b570537d
              • Instruction Fuzzy Hash: 8D419334B00608ABDF10DF69C984AEEBBB5FF46328F108155E919DBB51E731DA05CB92
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,000F003F,00000000,?,?), ref: 6CC3EDFD
              • OpenServiceW.ADVAPI32(00000000,?,00000014), ref: 6CC3EE26
              • QueryServiceStatus.ADVAPI32(00000000,?), ref: 6CC3EE49
              • CloseServiceHandle.ADVAPI32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,6CC3E77E), ref: 6CC3EE81
              • CloseServiceHandle.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,6CC3E77E), ref: 6CC3EE95
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$ErrorLastManagerQueryStatus
              • String ID: [StartService]
              • API String ID: 3744063808-3617437598
              • Opcode ID: 9be7e2e4e9a54318ffe39f60deb7df92d791d6cca8afefac94e77ab8b7d4468d
              • Instruction ID: 69557e9aa94f7e701c88da1615cbd6572c86e98cbaeb9a9e628f5a98820eeb1b
              • Opcode Fuzzy Hash: 9be7e2e4e9a54318ffe39f60deb7df92d791d6cca8afefac94e77ab8b7d4468d
              • Instruction Fuzzy Hash: 1231D631B012789FEF129BB5D8449FE77B8AF09718B00152EE905F2A90EB348D04CBB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetSecurityDescriptorControl.ADVAPI32(00000000,00000000,?,00000000,?,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},?,00000000,00000000), ref: 6CB6B822
              • GetSecurityDescriptorGroup.ADVAPI32(00000000,?,00000000,?,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},?,00000000,00000000), ref: 6CB6B85E
              • GetSecurityDescriptorDacl.ADVAPI32(00000000,?,?,00000000,?,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},?,00000000,00000000), ref: 6CB6B87C
              • GetSecurityDescriptorSacl.ADVAPI32(00000000,00000000,?,00000000,?,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},?,00000000,00000000), ref: 6CB6B8A0
              • GetSecurityDescriptorOwner.ADVAPI32(00000000,6CB8BB8F,00000000,?,{E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9},?,00000000,00000000), ref: 6CB6B844
                • Part of subcall function 6CCC972C: _free.LIBCMT ref: 6CCC973F
              Strings
              • {E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}, xrefs: 6CB6B7E7
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DescriptorSecurity$ControlDaclGroupOwnerSacl_free
              • String ID: {E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}
              • API String ID: 62099665-1902337801
              • Opcode ID: 3749b813681fd8b93dbd210ac314edc9fed04dc38913227caf83bbd4b5fb4709
              • Instruction ID: d21505498d38521f337a2f352a28639458295f1f94232023b0f204a85552975b
              • Opcode Fuzzy Hash: 3749b813681fd8b93dbd210ac314edc9fed04dc38913227caf83bbd4b5fb4709
              • Instruction Fuzzy Hash: E931D77291011CEBEF02DBE1DC44AEEBBBEFF08215F104066E611B2560EB359A58DF61
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID: api-ms-$ext-ms-
              • API String ID: 0-537541572
              • Opcode ID: 58ef96e3dba3de13dcba09f2a078b349befb536598db93ab305661b62298b72b
              • Instruction ID: 83152e10f381586c8d1c04d3e69d0348f86ee402f77aad3e3ce32ffd5b7fb98d
              • Opcode Fuzzy Hash: 58ef96e3dba3de13dcba09f2a078b349befb536598db93ab305661b62298b72b
              • Instruction Fuzzy Hash: E921DB71F46220BBDB214A299C44A4A3768AFD2F75F270515EF15A7AD0F731F900C6D0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\EdgeUpdate\,000F003F), ref: 6CB823A2
              • CloseHandle.KERNEL32(00000000), ref: 6CB823CC
                • Part of subcall function 6CB74525: AllocateAndInitializeSid.ADVAPI32(00000001,00000002,00000020,00000220,00000000,00000000,00000000,00000000,00000000,00000000,6CB7B383,?,6CB7B383,00000007,00000001), ref: 6CB7455B
                • Part of subcall function 6CB74525: CheckTokenMembership.KERNELBASE(00000000,6CB7B383,00000007,?,6CB7B383,00000007,00000001), ref: 6CB74570
                • Part of subcall function 6CB74525: FreeSid.ADVAPI32(6CB7B383,?,6CB7B383,00000007,00000001), ref: 6CB74580
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$AllocateCheckFreeHandleInitializeMembershipToken
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$old-uid$uid
              • API String ID: 3938284221-3495521444
              • Opcode ID: 836c80f7e6336d476b8daa30330a8643272553092a7fcb0c6a20b7ae3c0bfb84
              • Instruction ID: 67ea7722bbc2391df7012b8afc9d0d9890126a72386e50303094ce59c3f77261
              • Opcode Fuzzy Hash: 836c80f7e6336d476b8daa30330a8643272553092a7fcb0c6a20b7ae3c0bfb84
              • Instruction Fuzzy Hash: 9021AC71902259EFCB04DBD4C95ABEFB774AF11319F108154DA2077AA0D7309B08CBA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,000F003F,?,?,00000000,?,?,?,6CB8D2E8,?,00000000,?,?,?,6CB8CB63), ref: 6CB8DC2F
              • GetLastError.KERNEL32(?,6CB8D2E8,?,00000000,?,?,?,6CB8CB63,00000000,00000000,00000000), ref: 6CB8DC3B
              • GetLastError.KERNEL32(?,6CB8D2E8,?,00000000,?,?,?,6CB8CB63,00000000,00000000,00000000), ref: 6CB8DC8E
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D2E8,?,00000000,?,?,?,6CB8CB63,00000000,00000000,00000000), ref: 6CB8DCBF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorLast$CloseHandleManagerOpenService
              • String ID: RPCSS
              • API String ID: 2833319856-1590974804
              • Opcode ID: f895aba250bec31b270ebd3396f799bf9a71ea5ef20aa78e500fbb020a39c626
              • Instruction ID: a198cb325cc0864ac7ce688a79ebf6fe48f65b5c5ce4a66003d0d5fddf992bb5
              • Opcode Fuzzy Hash: f895aba250bec31b270ebd3396f799bf9a71ea5ef20aa78e500fbb020a39c626
              • Instruction Fuzzy Hash: C911C136340196B7EB11576ADC48EAF763DEFC2754F10001AF61593780DBB089059A71
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,000F003F,?,?,00000000,?,?,?,6CB8D616,?,00000000,?,?,?,6CB8CD3C), ref: 6CB8DF77
              • GetLastError.KERNEL32(?,6CB8D616,?,00000000,?,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CB8DF83
              • GetLastError.KERNEL32(?,6CB8D616,?,00000000,?,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CB8DFD6
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D616,?,00000000,?,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CB8E007
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorLast$CloseHandleManagerOpenService
              • String ID: RPCSS
              • API String ID: 2833319856-1590974804
              • Opcode ID: 30eb983da3636cb2e4efe96d842bb48f05ac8b0deef52f2ff652f983726b5bb3
              • Instruction ID: f75610857b17bdf495bcf51cf174012a4c06d96a4422749edc7a030e4db34bcf
              • Opcode Fuzzy Hash: 30eb983da3636cb2e4efe96d842bb48f05ac8b0deef52f2ff652f983726b5bb3
              • Instruction Fuzzy Hash: 0911CE36340196B7DB2187AACC49FAF363DEFC2758F00041AB61592680EF709905E6B5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB73433: VerSetConditionMask.KERNEL32(00000000,00000000,00000002,00000003,00000000,00000000,00000000), ref: 6CB7348B
                • Part of subcall function 6CB73433: VerSetConditionMask.KERNEL32(00000000,?,00000001,00000003), ref: 6CB73493
                • Part of subcall function 6CB73433: VerSetConditionMask.KERNEL32(00000000,?,00000004,00000003,?,00000001,00000003), ref: 6CB7349B
                • Part of subcall function 6CB73433: VerifyVersionInfoW.KERNEL32(?,00000007,00000000), ref: 6CB734A8
                • Part of subcall function 6CB76F8E: RegCloseKey.KERNELBASE(00000000,?,00000000,00000000,?,?,?,?,?,?), ref: 6CB77093
                • Part of subcall function 6CB76F8E: RegCloseKey.ADVAPI32(00000000,00000000,?,?,?,?,?,?), ref: 6CB770CB
              • LoadLibraryExW.KERNEL32(webio.dll,00000000,00000800), ref: 6CB7E410
              • FreeLibrary.KERNEL32(00000000), ref: 6CB7E43A
              Strings
              • EnableDeliveryOptimization, xrefs: 6CB7E3C6
              • HKLM\Software\Microsoft\EdgeUpdateDev\, xrefs: 6CB7E3CE
              • webio.dll, xrefs: 6CB7E40B
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ConditionMask$CloseLibrary$FreeInfoLoadVerifyVersion
              • String ID: EnableDeliveryOptimization$HKLM\Software\Microsoft\EdgeUpdateDev\$webio.dll
              • API String ID: 3553668821-3017028358
              • Opcode ID: 770bbeb1fe76be300df5ba77effd7097b4afb4a70590f20bd7d6a74f453a92ec
              • Instruction ID: 0f1af466a112ccc67f92aad4971cf169536e5b3c9c4ca812bb274ff9cc6febdf
              • Opcode Fuzzy Hash: 770bbeb1fe76be300df5ba77effd7097b4afb4a70590f20bd7d6a74f453a92ec
              • Instruction Fuzzy Hash: 9111AF207011D0ABDE306B6998086EE2719DF8330CF544029DE362BFC0CB248A2A83F7
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CCE3299: _free.LIBCMT ref: 6CCE32BE
              • _free.LIBCMT ref: 6CCE359B
                • Part of subcall function 6CCD7D0E: RtlFreeHeap.NTDLL(00000000,00000000,?,6CCC9744,00000000,?,?,6CB671F5,?,00000000,8007000E,6CB67170,?,00000000,?,6CB670BF), ref: 6CCD7D24
                • Part of subcall function 6CCD7D0E: GetLastError.KERNEL32(?,?,6CCC9744,00000000,?,?,6CB671F5,?,00000000,8007000E,6CB67170,?,00000000,?,6CB670BF,?), ref: 6CCD7D36
              • _free.LIBCMT ref: 6CCE35A6
              • _free.LIBCMT ref: 6CCE35B1
              • _free.LIBCMT ref: 6CCE3605
              • _free.LIBCMT ref: 6CCE3610
              • _free.LIBCMT ref: 6CCE361B
              • _free.LIBCMT ref: 6CCE3626
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: _free$ErrorFreeHeapLast
              • String ID:
              • API String ID: 776569668-0
              • Opcode ID: fad18345b12ed86bc48d1f1179b3d2a175b1a7d40dbcd26402e17eeb4005d8bb
              • Instruction ID: e1b2ba5705bf87047648d4929d42fc346b52b73a0904fc3ef2a3c7dd5863992c
              • Opcode Fuzzy Hash: fad18345b12ed86bc48d1f1179b3d2a175b1a7d40dbcd26402e17eeb4005d8bb
              • Instruction Fuzzy Hash: A9117CB1540B08AAE631ABB0CC09FDB77DDAF0E714F445818A2D9A7A61FB74F50C9750
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?,00020019,?,?), ref: 6CB9C79A
                • Part of subcall function 6CB77187: SHQueryValueExW.SHLWAPI(6CB76BD7,00000000,00000000,00000000,?,?,6CD3F7F0,6CD3F7F0,?,6CB77060,?,00000000,00000000,?), ref: 6CB771AA
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseQueryValue
              • String ID: InstallerError$InstallerExtraCode1$InstallerResult$InstallerResultUIString$InstallerSuccessLaunchCmdLine
              • API String ID: 3356406503-454640295
              • Opcode ID: b1e495627f646b4df96a6cccb009afd6e7292a87e2efbfa235845b416874ffb8
              • Instruction ID: e7e24b0ab2743be23d60bbeecdc3ff5c0ffadd9e98ec7b0dde0f87936e4512b5
              • Opcode Fuzzy Hash: b1e495627f646b4df96a6cccb009afd6e7292a87e2efbfa235845b416874ffb8
              • Instruction Fuzzy Hash: 4D219A3180024FEBDF11EFD0C844AEEBB75EF11319F004019EA2172A60DB749A08CFA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenMutexW.KERNEL32(00100000,00000000,Global\_MSIExecute,00000000,00000000,6CB8C4E3,00000000,00000000,?,?,?,?,?,6CB8B81B), ref: 6CB6CBAA
              • GetLastError.KERNEL32(?,?,?,?,?,6CB8B81B), ref: 6CB6CBB6
              • WaitForSingleObject.KERNEL32(00000000,000493E0,?,?,?,?,?,6CB8B81B), ref: 6CB6CBD6
              • CloseHandle.KERNEL32(00000000,?,?,?,?,?,6CB8B81B), ref: 6CB6CC16
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseErrorHandleLastMutexObjectOpenSingleWait
              • String ID: Global\_MSIExecute
              • API String ID: 2975704449-1795258645
              • Opcode ID: 33771c73fe6c3e2e352c25e3a938195c785ab61d297d5ccb7b97ab209cb31bed
              • Instruction ID: b369a884e7ddaa5583494d14fbf4e14341fa18bdb074d664fc75da0ba2c3a666
              • Opcode Fuzzy Hash: 33771c73fe6c3e2e352c25e3a938195c785ab61d297d5ccb7b97ab209cb31bed
              • Instruction Fuzzy Hash: D5F0F43134A4D566EE213A2FCC08B4B2529DBC339DB250529F932D6EC0C728C48285F7
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetConsoleOutputCP.KERNEL32(00000000,00000000,?), ref: 6CCE5B47
              • __fassign.LIBCMT ref: 6CCE5D2C
              • __fassign.LIBCMT ref: 6CCE5D49
              • WriteFile.KERNEL32(?,6CCE26E7,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 6CCE5D91
              • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 6CCE5DD1
              • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 6CCE5E79
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FileWrite__fassign$ConsoleErrorLastOutput
              • String ID:
              • API String ID: 1735259414-0
              • Opcode ID: 90cef811da2fe1cf6b2d7e6c443ba1883180b7468eb2664f9a1a4716cb55d111
              • Instruction ID: 3e6f1155c6a87518ae2815a7742b0368b3061e1aa6a9005e004ff849386fdf09
              • Opcode Fuzzy Hash: 90cef811da2fe1cf6b2d7e6c443ba1883180b7468eb2664f9a1a4716cb55d111
              • Instruction Fuzzy Hash: 23C19E71D052589FDB01CFA8C8809EDBBB5FF0A318F28416AE855B7741E735AA46CF60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBDD581: SysStringLen.OLEAUT32(00000000), ref: 6CBDD59D
                • Part of subcall function 6CBDD581: SysFreeString.OLEAUT32(00000000), ref: 6CBDD5BD
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDDA86
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDDA8F
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDDA98
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDDAAF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free
              • String ID: `)u
              • API String ID: 1391021980-4279031584
              • Opcode ID: 9b0522d5c5bd228751881b866081e6f7cb19e2ec7b7a876d45d906cf9fb41030
              • Instruction ID: 071bfcea3022efe89e3d9246cde73cc7b8338f0fb088a6ec3ee127da985f8fb2
              • Opcode Fuzzy Hash: 9b0522d5c5bd228751881b866081e6f7cb19e2ec7b7a876d45d906cf9fb41030
              • Instruction Fuzzy Hash: 66F10735A012459FCB04CFB8D844AAE7BB5EF85718F218258E855ABB40DB31FD05CFA1
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: HKCU\SOFTWARE\Clients\StartMenuInternet$HKLM\SOFTWARE\Clients\StartMenuInternet$HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command$IEXPLORE.EXE$\shell\open\command
              • API String ID: 3535843008-1594232684
              • Opcode ID: f1a24a8881a7c49f3f549981a9a2a5f60924697b91c1c03cd131af283d4e2347
              • Instruction ID: 3bb64a09eab6c068693c502f340030dcabc64b3e99a042bbdb3db23a4e90968f
              • Opcode Fuzzy Hash: f1a24a8881a7c49f3f549981a9a2a5f60924697b91c1c03cd131af283d4e2347
              • Instruction Fuzzy Hash: BC615131F002969FDF04DBA5C8949FEB378EF54218F504469D412A7B90EF30AE09CB52
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBB64F9: CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB6537
                • Part of subcall function 6CBB64F9: CloseHandle.KERNEL32(00000000,?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB654D
                • Part of subcall function 6CBB64F9: QueueUserWorkItem.KERNEL32(6CBB6489,6CD7CB88,00000000,?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB6570
                • Part of subcall function 6CBB64F9: ResetEvent.KERNEL32(?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB6584
                • Part of subcall function 6CBB64F9: GetTickCount64.KERNEL32 ref: 6CBB6591
                • Part of subcall function 6CBB64F9: WaitForSingleObject.KERNEL32(00000000,?,?,?,6CBDCA54,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBB65DB
              • Sleep.KERNEL32(00001388,?,?,00000000,?,?,?,?,?,?,6CBDCA4A), ref: 6CBDC1F6
              Strings
              • [WaitForOOBEConnectivity][GetOOBEState failed][0x%08X], xrefs: 6CBDC2ED
              • [WaitForOOBEConnectivity][Connected], xrefs: 6CBDC279
              • [WaitForOOBEConnectivity][Waiting][%d], xrefs: 6CBDC1E7
              • [WaitForOOBEConnectivity][OOBE complete], xrefs: 6CBDC2A9
              • [WaitForOOBEConnectivity][Timeout], xrefs: 6CBDC238
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Event$CloseCount64CreateHandleItemObjectQueueResetSingleSleepTickUserWaitWork
              • String ID: [WaitForOOBEConnectivity][Connected]$[WaitForOOBEConnectivity][GetOOBEState failed][0x%08X]$[WaitForOOBEConnectivity][OOBE complete]$[WaitForOOBEConnectivity][Timeout]$[WaitForOOBEConnectivity][Waiting][%d]
              • API String ID: 3505220456-533431129
              • Opcode ID: 4e1ec1c3d79a52631295724e1967de02eb490f9503e46b2d1eb90e233ec7603d
              • Instruction ID: dbf1800a5aaacb677797e9f61d73a13699e5288c545e35c4971e8793a34f2061
              • Opcode Fuzzy Hash: 4e1ec1c3d79a52631295724e1967de02eb490f9503e46b2d1eb90e233ec7603d
              • Instruction Fuzzy Hash: 3841F9B1D042955EDF08DFB9D852AFEBBB8EB46305F11422ED512F3B90DB3855048BA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • InitializeCriticalSection.KERNEL32(00000018,?,?,00000008,00000008,00000008,?,6CC07006,00000000,?,?,?), ref: 6CC06D36
              • InitializeCriticalSection.KERNEL32(00000000,?,?,00000008,00000008,00000008,?,6CC07006,00000000,?,?,?), ref: 6CC06D39
              • QueryPerformanceCounter.KERNEL32(?,?,?,00000008,00000008,00000008,?,6CC07006,00000000,?,?,?), ref: 6CC06D68
              • EnterCriticalSection.KERNEL32(00000000,?,?,00000008,00000008,00000008,?,6CC07006,00000000,?,?,?), ref: 6CC06D7A
              • CreateTimerQueueTimer.KERNEL32(00000044,?,6CCA6E7B,00000000,?,00000000,00000008,?,?,00000008,00000008,00000008,?,6CC07006,00000000,?), ref: 6CC06DA5
              • LeaveCriticalSection.KERNEL32(00000000,?,?,00000008,00000008,00000008,?,6CC07006,00000000,?,?,?), ref: 6CC06DB5
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$InitializeTimer$CounterCreateEnterLeavePerformanceQueryQueue
              • String ID:
              • API String ID: 236182683-0
              • Opcode ID: db6eef512fabd1c8984ae2c9c9c9219aff1cb3a3317361e8143e713f85812c7d
              • Instruction ID: 062d6b7236bf23abb2c14a6edf0e6684f0c832fac1a82bb5ddd2f0b0a4728d83
              • Opcode Fuzzy Hash: db6eef512fabd1c8984ae2c9c9c9219aff1cb3a3317361e8143e713f85812c7d
              • Instruction Fuzzy Hash: 844171B1A01B11AFDB04DF69D480A9ABBF8FF48714B14805EE919DBB44EB31E854CF90
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID: %s%s %s %s<B> </B>$%s%s %s<B> </B>
              • API String ID: 0-3375248285
              • Opcode ID: 48f8d0979ae13051f5edf0edad0828fad63f8d01bae5acce80057bb5e34e4b07
              • Instruction ID: d37ad9924fb4472397410bb828875b0bf5a3c1e1607d010ddb54df6aef97db54
              • Opcode Fuzzy Hash: 48f8d0979ae13051f5edf0edad0828fad63f8d01bae5acce80057bb5e34e4b07
              • Instruction Fuzzy Hash: 33D14A72D01199ABDF04DFA9D8909EDB7B5FF14318F214529E465B7A80DB30BA08CFA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateFileW.KERNEL32(?,40000000,00000000,00000000,00000000,00000080,00000000,00000000,?,00000001,?,?,6CBBB85B,?), ref: 6CBBBAB1
              • GetFileSize.KERNEL32(00000000,00000000,?,6CBBB85B,?,?,?,00002710,00000000,00000000,?,00002710,00000000), ref: 6CBBBACF
              • CreateFileW.KERNEL32(?,40000000,00000000,00000000,00000002,00000080,00000000,?,6CBBB85B,?,?,?,00002710,00000000,00000000), ref: 6CBBBB12
              • CloseHandle.KERNEL32(00000000,?,6CBBB85B,?,?,?,00002710,00000000,00000000,?,00002710,00000000), ref: 6CBBBB1F
              • SetFilePointerEx.KERNEL32(00000000,00000000,00000000,00000000,00000000,?,6CBBB85B,?,?,?,00002710,00000000,00000000,?,00002710,00000000), ref: 6CBBBB32
              • CloseHandle.KERNEL32(00000000,?,6CBBB85B,?,?,?,00002710,00000000,00000000,?,00002710,00000000), ref: 6CBBBB50
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: File$CloseCreateHandle$PointerSize
              • String ID:
              • API String ID: 2656607781-0
              • Opcode ID: 3b12fde200da00f4fc26e3b43ceff019390f0cb5e83a9400e3c1dd4ab3249de2
              • Instruction ID: d11afd1cb689f6fdcb0110df908ccae3e290adfbe955a0bcc8654871539b7817
              • Opcode Fuzzy Hash: 3b12fde200da00f4fc26e3b43ceff019390f0cb5e83a9400e3c1dd4ab3249de2
              • Instruction Fuzzy Hash: 6E21A631201140ABDB209E69CCC4E9B7A79FBC6724F514269FA21AB6D5DB308841C7A5
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ManagerOpen
              • String ID:
              • API String ID: 1889721586-0
              • Opcode ID: aeb9c6d81f6ff3a0a38227bc8dc5c8739c4c89afcf5a6c4d6fffa00fd8c3a732
              • Instruction ID: 593807e47fcddcadb62371a9a78988444029244c36edab47f289aebd743a27b4
              • Opcode Fuzzy Hash: aeb9c6d81f6ff3a0a38227bc8dc5c8739c4c89afcf5a6c4d6fffa00fd8c3a732
              • Instruction Fuzzy Hash: 56112931706766ABDF021BB85CC4B6E36BDDF06719F000267FA11A2780DB70CD049272
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ManagerOpen
              • String ID:
              • API String ID: 1889721586-0
              • Opcode ID: 34615fd85da1266eb73c30ab60bedebac4a3c2dfd8256286840cec8c55a7b875
              • Instruction ID: 598f58f9f00e83e4bbe3a88f34ad73a46d2db76823328ef65b691dbe5a3990c8
              • Opcode Fuzzy Hash: 34615fd85da1266eb73c30ab60bedebac4a3c2dfd8256286840cec8c55a7b875
              • Instruction Fuzzy Hash: A4110F35702766ABDB021BF5AC84BAF367CDF05B59F00022BFA11D6780DFA0CD4446A5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6CB8EEC0
              • CreateThread.KERNEL32(00000000,00000000,6CB8F045,00000000,00000000,00000000), ref: 6CB8EEDD
              • CloseHandle.KERNEL32(?), ref: 6CB8EEEC
                • Part of subcall function 6CB7934E: RaiseException.KERNEL32(00000000,00000001,00000000,00000000,6CB781E7,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB79362
              • SetEvent.KERNEL32(?), ref: 6CB8EF0C
              • WaitForSingleObject.KERNEL32(00000000,?), ref: 6CB8EF19
              • CloseHandle.KERNEL32(00000000), ref: 6CB8EF20
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseCreateEventHandle$ExceptionObjectRaiseSingleThreadWait
              • String ID:
              • API String ID: 1018276921-0
              • Opcode ID: d68ac3b4d8431fa54d01396dbe4fe03273a7836e8361b5d93031df32e1ca3b5c
              • Instruction ID: 92d0d2eb810c339940adb3b04ecbc1f8e2bd3279ed21cb085814b79f04fc4bb8
              • Opcode Fuzzy Hash: d68ac3b4d8431fa54d01396dbe4fe03273a7836e8361b5d93031df32e1ca3b5c
              • Instruction Fuzzy Hash: ED1190797162D6BFFB515FA88C8895E76BCFB062597400539FA1292A41EB70CC0087F1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6CB8EFC3
              • CreateThread.KERNEL32(00000000,00000000,6CB8F045,00000000,00000000,00000000), ref: 6CB8EFE0
              • CloseHandle.KERNEL32(?), ref: 6CB8EFEF
                • Part of subcall function 6CB7934E: RaiseException.KERNEL32(00000000,00000001,00000000,00000000,6CB781E7,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB79362
              • SetEvent.KERNEL32(?), ref: 6CB8F00F
              • WaitForSingleObject.KERNEL32(00000000,?), ref: 6CB8F01C
              • CloseHandle.KERNEL32(00000000), ref: 6CB8F023
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseCreateEventHandle$ExceptionObjectRaiseSingleThreadWait
              • String ID:
              • API String ID: 1018276921-0
              • Opcode ID: fed2e7a42f6576697500fbc0ff19eb59fd2ec6800a020c803b83039424dc1611
              • Instruction ID: 9a60b7870285125118aae8bf01d4ed6f9707dafd6cab394d39475195884a928c
              • Opcode Fuzzy Hash: fed2e7a42f6576697500fbc0ff19eb59fd2ec6800a020c803b83039424dc1611
              • Instruction Fuzzy Hash: B41160B5716296BFFB115FA88C8895E76BCFB06259344013DFA0192A41EB70DC1487A5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,6CB972BC,00000000,00000000,00000000,00000000,6CB93F21), ref: 6CB9544D
              • CreateThread.KERNEL32(00000000,00000000,6CB97AAA,00000000,00000000,00000000), ref: 6CB95467
              • CloseHandle.KERNEL32(?,?,6CB972BC,00000000,00000000,00000000,00000000,6CB93F21,?,00000000,?,6CB8B868,?), ref: 6CB95476
              • SetEvent.KERNEL32(?,?,6CB972BC,00000000,00000000,00000000,00000000,6CB93F21,?,00000000,?,6CB8B868,?), ref: 6CB95495
              • WaitForSingleObject.KERNEL32(00000000,?,?,6CB972BC,00000000,00000000,00000000,00000000,6CB93F21,?,00000000,?,6CB8B868,?), ref: 6CB954A2
              • CloseHandle.KERNEL32(00000000,?,6CB972BC,00000000,00000000,00000000,00000000,6CB93F21,?,00000000,?,6CB8B868,?), ref: 6CB954A9
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseCreateEventHandle$ObjectSingleThreadWait
              • String ID:
              • API String ID: 414154005-0
              • Opcode ID: a7cb3eabcaa4213bd514b58e616c6350b4b781221eaa06aef8a7deceeb527840
              • Instruction ID: e0a019adfe7a1fba7e1b3f108616fe9366752811308ca241370dd8c5f65f4962
              • Opcode Fuzzy Hash: a7cb3eabcaa4213bd514b58e616c6350b4b781221eaa06aef8a7deceeb527840
              • Instruction Fuzzy Hash: FD11B472344645BFAB515B79CC8882B76BDEF8325B314063DB60683B45EB30DC049629
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • VerSetConditionMask.KERNEL32(00000000,00000000,00000002,6CC060C2,00000000,00000000,00000000,?,?,6CC060C2,00000001), ref: 6CB73AE1
              • VerSetConditionMask.KERNEL32(00000000,?,00000001,6CC060C2,?,6CC060C2,00000001), ref: 6CB73AE8
              • VerSetConditionMask.KERNEL32(00000000,?,00000020,6CC060C2,?,00000001,6CC060C2,?,6CC060C2,00000001), ref: 6CB73AEF
              • VerSetConditionMask.KERNEL32(00000000,?,00000010,6CC060C2,?,00000020,6CC060C2,?,00000001,6CC060C2,?,6CC060C2,00000001), ref: 6CB73AF6
              • VerSetConditionMask.KERNEL32(00000000,?,00000004,6CC060C2,?,00000010,6CC060C2,?,00000020,6CC060C2,?,00000001,6CC060C2,?,6CC060C2,00000001), ref: 6CB73AFD
              • VerifyVersionInfoW.KERNEL32(00000001,00000033,00000000), ref: 6CB73B05
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ConditionMask$InfoVerifyVersion
              • String ID:
              • API String ID: 2793162063-0
              • Opcode ID: 5254447817c0a4cb2b0cad4341a8634eae3c17f8dcae455d67ad3bd7bf2d2ce8
              • Instruction ID: 9192f10d741cd8705cd19dc6eae3c9206955819f6989c7c758f5690d247fe979
              • Opcode Fuzzy Hash: 5254447817c0a4cb2b0cad4341a8634eae3c17f8dcae455d67ad3bd7bf2d2ce8
              • Instruction Fuzzy Hash: 94F012F1B403587EFA3056A64C0EFBB6E3CDBC6FA0F00841E7604AA1C1C6B5AC0089B0
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CurrentThread$OpenProcessToken
              • String ID: `)u
              • API String ID: 3143553470-4279031584
              • Opcode ID: 199f5e2cd254e430acd18de8ab1aa64b079b738730709611f60aedefe6fe1abf
              • Instruction ID: 6c4631d097361fca6f65c9f3008720c3ec5fa4eab402f7141c8c5618183335a6
              • Opcode Fuzzy Hash: 199f5e2cd254e430acd18de8ab1aa64b079b738730709611f60aedefe6fe1abf
              • Instruction Fuzzy Hash: C3914A78A0124A9FDF04DFA9D884AEEBBB5EF49308F104169E911B7B60DB30D945CB61
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID: SetupDisplayedEula$Sysnative\license.rtf$license.rtf
              • API String ID: 0-4196223558
              • Opcode ID: fe3fb29f7967fbca6c87e64245916dc5fcb02f42bf590597438b0fa8b02bb4e0
              • Instruction ID: 88298b4f336aca3eaf95854a8daf7e3f28fb176bdf5dce74752498dedb6584fa
              • Opcode Fuzzy Hash: fe3fb29f7967fbca6c87e64245916dc5fcb02f42bf590597438b0fa8b02bb4e0
              • Instruction Fuzzy Hash: 9B917C32A54398D9EF20CBE0DC51BEDB331FF54714F20145AD518EB6A0EBB11A88CB5A
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              • [AppCommand::Execute][LaunchAppCommandsOnOSUpgrade], xrefs: 6CC06368, 6CC06381
              • [AppCommand::Execute failed][%s][%d][%s][%#08x], xrefs: 6CC063D0
              • OnOsUpgradeLaunchError, xrefs: 6CC063EB
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$CloseEnterLeave
              • String ID: OnOsUpgradeLaunchError$[AppCommand::Execute failed][%s][%d][%s][%#08x]$[AppCommand::Execute][LaunchAppCommandsOnOSUpgrade]
              • API String ID: 1066824034-1371786042
              • Opcode ID: cf36854b7dc929afda2bfb47d18a653cbde224fbecbf0d79a13eef3650509e10
              • Instruction ID: aa026282f0dd041b40aa629b4656b6c594dca63cc5f433861f196a214c06ed57
              • Opcode Fuzzy Hash: cf36854b7dc929afda2bfb47d18a653cbde224fbecbf0d79a13eef3650509e10
              • Instruction Fuzzy Hash: D881AF71E04259AFDF04DFE8D891AEEB7B5EF44318F204529D411E7B90EB31A949CB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNEL32(00000000,6CD1F190,00000000,?,6CBDB589), ref: 6CBDB496
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDB4C3
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDB4EA
              Strings
              • `)u, xrefs: 6CBDB4C3, 6CBDB4EA
              • [DoInstallApps result override. Higher version exits][Original HRESULT: 0x%08X][Override HRESULT: 0x%08X], xrefs: 6CBDB5EF
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString$lstrcmpi
              • String ID: [DoInstallApps result override. Higher version exits][Original HRESULT: 0x%08X][Override HRESULT: 0x%08X]$`)u
              • API String ID: 3563800057-1257719363
              • Opcode ID: 88b16f23c4cc5ff23772f8bfaf9db7e8921ca605cce21309feb3cc1ff5cb2e1c
              • Instruction ID: daf01c30a930881602ad8cdfffa85ef8390bf7655c60fe9089bb55fcce223dff
              • Opcode Fuzzy Hash: 88b16f23c4cc5ff23772f8bfaf9db7e8921ca605cce21309feb3cc1ff5cb2e1c
              • Instruction Fuzzy Hash: 2361C271A01249AFDB04CF99C894AEEBBB8EF49719F214069E915E7790D730AA04CB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?,00020019,?,00000000,?), ref: 6CBE181A
                • Part of subcall function 6CB77BFD: RegQueryInfoKeyW.ADVAPI32(6CB76BD7,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,6CD3F7F0,?,6CB8C8CC,HKLM\Software\Microsoft\EdgeUpdate\ClientState\), ref: 6CB77C17
              • RegCloseKey.ADVAPI32(00000000,?,?,PersistedPingString,6CBE1A7E,?,00000000,?), ref: 6CBE18CC
                • Part of subcall function 6CB77C22: RegEnumKeyExW.KERNELBASE(6CB76BD7,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6CB77C5E
              • RegCloseKey.ADVAPI32(00000000,?,00000000,?), ref: 6CBE17D4
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$Query$EnumInfoValue
              • String ID: PersistedPingString$PersistedPingTime
              • API String ID: 3029881642-1149038743
              • Opcode ID: 6c8ace020d926ab9008062d89930f9366fa58597e5fe27cb735e36a88c875e24
              • Instruction ID: ffb3fc4f7e5baf462cfaaa8e728b9630fe748a9af43385c3d7b253c85306cf11
              • Opcode Fuzzy Hash: 6c8ace020d926ab9008062d89930f9366fa58597e5fe27cb735e36a88c875e24
              • Instruction Fuzzy Hash: 68716C71D00299DBCF04DFA9C8909EDF7B5FF58758F240129D425A7BA1EB30AA09CB50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • Sleep.KERNEL32(000001F4), ref: 6CBB5E0B
              • SysStringLen.OLEAUT32(00000000), ref: 6CBB5E62
              • SysFreeString.OLEAUT32(00000000), ref: 6CBB5EFA
              Strings
              • `)u, xrefs: 6CBB5EFA
              • [AppStateWaitingToInstall::Install][Failed to write install source][0x%8x], xrefs: 6CBB5ED9
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$FreeSleep
              • String ID: [AppStateWaitingToInstall::Install][Failed to write install source][0x%8x]$`)u
              • API String ID: 936229675-69365893
              • Opcode ID: 660e56934a9449850c1eaf73af9e88f34c5545984e8a7c2e4dca8f1aab638041
              • Instruction ID: d5e3609a0154a8eb840df0b2f1ee725dfb8fc876fa7931910c0c894f1f5af2f6
              • Opcode Fuzzy Hash: 660e56934a9449850c1eaf73af9e88f34c5545984e8a7c2e4dca8f1aab638041
              • Instruction Fuzzy Hash: 93515F715082819BCB04DF65D9948BEB7A9AFD5718F00092DB89697B90EF30DD0DCBA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNEL32(00000000,IEXPLORE.EXE), ref: 6CBC3586
                • Part of subcall function 6CB75816: OpenProcess.KERNEL32(00000400,00000000,?,?,?), ref: 6CB75835
              • lstrcmpiW.KERNEL32(?,?), ref: 6CBC3546
              • VariantClear.OLEAUT32(?), ref: 6CBC35D8
              • VariantClear.OLEAUT32(?), ref: 6CBC3618
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ClearVariantlstrcmpi$OpenProcess
              • String ID: IEXPLORE.EXE
              • API String ID: 3911090576-4141687035
              • Opcode ID: e2d82482c8a7ae441724683d484497d4cb519f02e1e74f2f789ae4b38f54e85d
              • Instruction ID: 5bc2957eec2c0322ffdafcdb48a78f10de731777f11a0dfa3e686e0e02aa63b6
              • Opcode Fuzzy Hash: e2d82482c8a7ae441724683d484497d4cb519f02e1e74f2f789ae4b38f54e85d
              • Instruction Fuzzy Hash: 5A6139316093829FD710DF25C848AAAB7E9EF89719F50491CF895DB690DB30ED09CB93
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • QueryPerformanceCounter.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,6CC3E943), ref: 6CC3E75D
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
                • Part of subcall function 6CC3EDA5: OpenSCManagerW.ADVAPI32(00000000,00000000,000F003F,00000000,?,?), ref: 6CC3EDFD
                • Part of subcall function 6CBC58DE: QueryPerformanceCounter.KERNEL32(?,?,?,00000000,?,?,?,?,6CC3E248,?,?,?,?,?,6CC3E0E1,00000000), ref: 6CBC58ED
                • Part of subcall function 6CBC58DE: __aulldiv.LIBCMT ref: 6CBC5930
                • Part of subcall function 6CB7FD4B: EnterCriticalSection.KERNEL32(6CD7CA74,?,?,?,6CC3E254,00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000), ref: 6CB7FD58
                • Part of subcall function 6CB7FD4B: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CC3E254,00000000,?,?,?,?,?,?,6CC3E0E1,00000000,00000000,00000000,00000007,?), ref: 6CB7FDA2
              Strings
              • [Start scheduled task failed][0x%08x], xrefs: 6CC3E90D
              • [Service started], xrefs: 6CC3E7CA
              • [run scheduled task succeeded], xrefs: 6CC3E8C9
              • [Start service failed][0x%08x], xrefs: 6CC3E822
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$CounterEnterLeavePerformanceQuery$ManagerOpen__aulldiv
              • String ID: [Service started]$[Start scheduled task failed][0x%08x]$[Start service failed][0x%08x]$[run scheduled task succeeded]
              • API String ID: 4192412962-307983686
              • Opcode ID: f1d0045fb4c7f301c2e45343a92a118d491853df86c0331fefc2f44455c1a205
              • Instruction ID: e0c5a49ce497296527a6393ad371f5ebdb28041cb89207dbe26d37113ebc8891
              • Opcode Fuzzy Hash: f1d0045fb4c7f301c2e45343a92a118d491853df86c0331fefc2f44455c1a205
              • Instruction Fuzzy Hash: DE51A8B1D00168ABDF08DFF9D8919FE77F8AB45214B10112EE516F7B90EB3499048BB5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,lang,?,?,6CD44078,?,00000000,?,?,?,?), ref: 6CB9CAE7
              Strings
              • [Installer did not create key][%s], xrefs: 6CB9C9D0
              • [Installer did not write version][%s], xrefs: 6CB9CA6C
              • lang, xrefs: 6CB9CAA5
              • [Installer did not register][%s], xrefs: 6CB9CA35
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: [Installer did not create key][%s]$[Installer did not register][%s]$[Installer did not write version][%s]$lang
              • API String ID: 3535843008-3017318218
              • Opcode ID: 2ca08e2884d272ff145f237c191d95fec289de33943c26f08e3bd63579812c21
              • Instruction ID: da9234ed7b32dc4c523b55d5cad2d8ef4a19583d4e0e49d5d8f600ad30a895ee
              • Opcode Fuzzy Hash: 2ca08e2884d272ff145f237c191d95fec289de33943c26f08e3bd63579812c21
              • Instruction Fuzzy Hash: 3651A371D042599BDF04DFA4C891AFEBBB8EF4A319F10413AE512F2B90DB345909CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB666B1: InitializeCriticalSectionAndSpinCount.KERNEL32(?,00000000,00000104,8007000E,?,-C000001E,00000001,?,6CB66F62,80070057,00000000,?,6CB728CB,00000104,00000001,00000000), ref: 6CB666B6
                • Part of subcall function 6CB666B1: GetLastError.KERNEL32(?,00000000,00000104,8007000E,?,-C000001E,00000001,?,6CB66F62,80070057,00000000,?,6CB728CB,00000104,00000001,00000000), ref: 6CB666C0
              • GetModuleFileNameW.KERNEL32(6CB60000,?,00000104), ref: 6CB8A1FF
              • GetModuleHandleW.KERNEL32(00000000), ref: 6CB8A257
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Module$CountCriticalErrorFileHandleInitializeLastNameSectionSpin
              • String ID: Module$Module_Raw$REGISTRY
              • API String ID: 237688075-549000027
              • Opcode ID: 544a300a66f8b4a8ab42d8af13daf2d5998c384d89f0f3522f4447c745edb864
              • Instruction ID: d68a887314d8116309d5883b76401fc118f06561aec8f2a11bac1f53a55db30d
              • Opcode Fuzzy Hash: 544a300a66f8b4a8ab42d8af13daf2d5998c384d89f0f3522f4447c745edb864
              • Instruction Fuzzy Hash: 15519671A023689BDB20DF54DC40BDE77BCAF45314F4404A6E905E7A80EB359E84CF62
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID: `)u
              • API String ID: 0-4279031584
              • Opcode ID: 3a38d67b224dd69d52174ae88fd307a1c770d303942cae8492b5f1ac06f00a38
              • Instruction ID: acb24278cdaf586553262b294cb8b5eeca745e038959fcfae22e3b7b73be3cc8
              • Opcode Fuzzy Hash: 3a38d67b224dd69d52174ae88fd307a1c770d303942cae8492b5f1ac06f00a38
              • Instruction Fuzzy Hash: 7241D375602255ABDB00DF68C888DDB7B7CEF86754B208515FA05DBA90EB30DE40CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysStringLen.OLEAUT32 ref: 6CB78C80
              • SysAllocStringLen.OLEAUT32(00000000), ref: 6CB78CDB
              • SysStringLen.OLEAUT32(00000000), ref: 6CB78CF7
              • SysFreeString.OLEAUT32(00000000), ref: 6CB78D87
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$AllocFree
              • String ID: `)u
              • API String ID: 344208780-4279031584
              • Opcode ID: 4d9713661f80930c0dcfe2116a0ade5981583b89864a51d0aaf36b4d0ca7c418
              • Instruction ID: ce159c2dca2c62b4f9547107aa81f5fbb151d88a90e3029bb1ae8563be6d4fd0
              • Opcode Fuzzy Hash: 4d9713661f80930c0dcfe2116a0ade5981583b89864a51d0aaf36b4d0ca7c418
              • Instruction Fuzzy Hash: 97411971701265EBDF209F69CA8469E77B4EF55314F10411FED25BB6A0EB328A008BB2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80525: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000000,6CB8A911,6CD7C950,00000000,00000007,00000000,?,6CB66D71,00000000,00000000), ref: 6CB8052F
                • Part of subcall function 6CB80525: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB66D71,00000000,00000000), ref: 6CB8053E
              • CreateEventW.KERNEL32(?,00000001,00000000,?), ref: 6CBB3664
              • WaitForSingleObject.KERNEL32(00000000,000000FF), ref: 6CBB366F
              • CloseHandle.KERNEL32(00000000), ref: 6CBB367A
                • Part of subcall function 6CB7A5CE: __vswprintf_c_l.LEGACY_STDIO_DEFINITIONS ref: 6CB7A601
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$CloseCreateEnterEventHandleLeaveObjectSingleWait__vswprintf_c_l
              • String ID: %s. %s${4BE2111F-14A3-46E1-B5A0-5D59A5DBB471}
              • API String ID: 901288888-722585009
              • Opcode ID: 30dac090b30236329ac3edd84c2343783abfef8dfdfd66fed2f845d946ba16eb
              • Instruction ID: e11cf2c95018a867d0d403b64e3d827705df91dcaa01e83cdd5581e6e82ad5bb
              • Opcode Fuzzy Hash: 30dac090b30236329ac3edd84c2343783abfef8dfdfd66fed2f845d946ba16eb
              • Instruction Fuzzy Hash: 38416E31108282ABC704DF64C890DEEB3A8EF85358F40092DB59257BE1EF31E90DCB92
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?,?,?,00000006,?,?,00000000,uid,HKLM\Software\Microsoft\EdgeUpdate\), ref: 6CB81D5E
              • CloseHandle.KERNEL32(00000000,?,?,00000006,?,?,00000000,uid,HKLM\Software\Microsoft\EdgeUpdate\), ref: 6CB81D90
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close$Handle
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$uid
              • API String ID: 187904097-900028657
              • Opcode ID: 553275278a1a6bedda6e3847944de1e456bc70616d2b3945df98d35f4061d18d
              • Instruction ID: ccbc1ffbccb75353280d3110b9b7e63df39ae00a9811ca19fe5bcb958b91f343
              • Opcode Fuzzy Hash: 553275278a1a6bedda6e3847944de1e456bc70616d2b3945df98d35f4061d18d
              • Instruction Fuzzy Hash: C6418331A0125AAFDF04DF95C895BEEB775EF14318F104118D521BBAA0DB70AA49CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB7319E: InitializeCriticalSection.KERNEL32(6CD7C9AC,6CD7C9A4,6CB68043), ref: 6CB731AB
              • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?), ref: 6CBC0EA3
                • Part of subcall function 6CBA439E: CloseHandle.KERNEL32(00000008,00000000,00000000,6CBC5750,?,?,?,6CC05B92,00000000,00000000,?,?,6CB8B8A8,?), ref: 6CBA43AF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseCreateCriticalEventHandleInitializeSection
              • String ID: HKLM\Software\Microsoft\EdgeUpdateDev\$X-MID$X-Old-UID$mid
              • API String ID: 41435760-1527748961
              • Opcode ID: c33f3cb1a17049bc7d6871345509daa6c1a3cfac8b084205ff35583afa7c3cb9
              • Instruction ID: f6ee35de68e9e63cf5a1d893b117e0cea5924ba539c5520b71dd08f4be27c831
              • Opcode Fuzzy Hash: c33f3cb1a17049bc7d6871345509daa6c1a3cfac8b084205ff35583afa7c3cb9
              • Instruction Fuzzy Hash: 8C4108B1A00A86AFC708DF2AC5905EDFBB4FF54248B90452ED51997F90DB30B968CF90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CBDF9FF
                • Part of subcall function 6CB74325: SysAllocString.OLEAUT32(00000000), ref: 6CB7433E
              • SysFreeString.OLEAUT32(?), ref: 6CBDFA25
              • SysFreeString.OLEAUT32(?), ref: 6CBDFA47
              • SysFreeString.OLEAUT32(?), ref: 6CBDFA8D
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free$Alloc
              • String ID: `)u
              • API String ID: 986138563-4279031584
              • Opcode ID: e5f02143503ed3bd70dd8d9611a9f5effdcf3799a26cd2420fdce3352f345f12
              • Instruction ID: 00efb4b59dcbc91e5d194e409b4767c3db5da501c30b1fca793d4c22cb8a9ed5
              • Opcode Fuzzy Hash: e5f02143503ed3bd70dd8d9611a9f5effdcf3799a26cd2420fdce3352f345f12
              • Instruction Fuzzy Hash: 9C314976900166AFCB11CFA8D884CAE3BB4EF4962574205A9FC04AB720D730AD14EFB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • WideCharToMultiByte.KERNEL32(6CBE487D,00000000,?,00000003,?,00000001,00000000,00000000,EdgeUpdate,?,?,?,?,6CBE487D,EdgeUpdate,00000003), ref: 6CBE4D14
              • GetLastError.KERNEL32(?,6CBE487D,EdgeUpdate,00000003,00000000,00000000,?), ref: 6CBE4D21
              • WideCharToMultiByte.KERNEL32(6CBE487D,00000000,?,00000003,00000000,00000000,00000000,00000000,?,6CBE487D,EdgeUpdate,00000003,00000000,00000000,?), ref: 6CBE4D3D
              • WideCharToMultiByte.KERNEL32(6CBE487D,00000000,?,00000003,?,00000000,00000000,00000000,?,6CBE487D,EdgeUpdate,00000003,00000000,00000000,?), ref: 6CBE4D60
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ByteCharMultiWide$ErrorLast
              • String ID: EdgeUpdate
              • API String ID: 1717984340-3078434615
              • Opcode ID: 179210efdec87a0389306cde06d9a2df54bf0a5dba64843edc0dca154640d60f
              • Instruction ID: 9151fbb4dee4fa356a7cba15910c0c5a7a68fee615a57bbd45b0e53290b1d440
              • Opcode Fuzzy Hash: 179210efdec87a0389306cde06d9a2df54bf0a5dba64843edc0dca154640d60f
              • Instruction Fuzzy Hash: F221EBB2604219BFBB044FA5DC80CBF7BADFF48294310452AF914C7640EB719D148BA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(?,?,SOFTWARE\Clients\StartMenuInternet,00020019,?,?), ref: 6CBC3948
              • RegCloseKey.ADVAPI32(00000000,IEXPLORE.EXE,00000000,?,SOFTWARE\Clients\StartMenuInternet,00020019,?,?), ref: 6CBC39BE
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: HKLM\SOFTWARE\Clients\StartMenuInternet$IEXPLORE.EXE$SOFTWARE\Clients\StartMenuInternet
              • API String ID: 3535843008-1943179258
              • Opcode ID: a2964165b66f3a55e25f3f7146e844fba4773d64aed334ba0edb9779ed063dae
              • Instruction ID: 2758bef55f6b4fbe1e9ce6d48657319bc1979f37867e883beee1c2355992ecb0
              • Opcode Fuzzy Hash: a2964165b66f3a55e25f3f7146e844fba4773d64aed334ba0edb9779ed063dae
              • Instruction Fuzzy Hash: CB217371B001599BDB00DB56C984BEEB7B9EF81318F60006DD416A7B60DBB49E088BA2
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID: %c%c%c%s$gui
              • API String ID: 0-417229336
              • Opcode ID: 98e756b58a863dda1443ba0d3cb5ab09d9070150839ce2aa67c74f8f1d1c376d
              • Instruction ID: 909ceeee4997d82c6be145991bdd1a8c0946cfc31f7fd63b260e52b52a890c4d
              • Opcode Fuzzy Hash: 98e756b58a863dda1443ba0d3cb5ab09d9070150839ce2aa67c74f8f1d1c376d
              • Instruction Fuzzy Hash: 6F219431B41185FBCB10DBAACC48EDEB779EF85318F184568E561A7AD0DB309A09CB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetLastError.KERNEL32(?,00000100,?,6CCCAA77,00000100,00000000,00000000,?,6CCCA284,?,00000000,00000100,000000FE), ref: 6CCD7AC1
              • _free.LIBCMT ref: 6CCD7B1E
              • _free.LIBCMT ref: 6CCD7B54
              • SetLastError.KERNEL32(00000000,00000008,000000FF,?,6CCCA284,?,00000000,00000100,000000FE), ref: 6CCD7B5F
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorLast_free
              • String ID: PG3
              • API String ID: 2283115069-2679599617
              • Opcode ID: 39c6a10fc27483b0738dbd15ed95e283b313d6bbbbf3ff8070fe4d4f02adf7e3
              • Instruction ID: c0327a400ff8f5800cf2679c3781d973c8c91e24934e40d232ecd7eaa3b6d13b
              • Opcode Fuzzy Hash: 39c6a10fc27483b0738dbd15ed95e283b313d6bbbbf3ff8070fe4d4f02adf7e3
              • Instruction Fuzzy Hash: EF11AB713047117EE60356695C44E6B216EABC226CB370268F73896AD8FB31E81CE731
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentThreadId.KERNEL32 ref: 6CB8E927
              • GetModuleHandleW.KERNEL32(Mscoree.dll), ref: 6CB8E994
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CurrentHandleModuleThread
              • String ID: Handler not installed$Mscoree.dll$Service stopped
              • API String ID: 2752942033-1381189583
              • Opcode ID: c457c83a4f1d5bced2d07ebe1b88900a25e8c8502d3a54a7a30db2adc43642a9
              • Instruction ID: ca26486ce230a498232a82ba5b32fe7673db43d25e20bc2497823c5cc9b4f987
              • Opcode Fuzzy Hash: c457c83a4f1d5bced2d07ebe1b88900a25e8c8502d3a54a7a30db2adc43642a9
              • Instruction Fuzzy Hash: 9311C87460AFD1AAF7605F354888B8F77E8FF05309F10092EE19685E80EBB5A44487E6
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentThreadId.KERNEL32 ref: 6CB8EA8C
              • GetModuleHandleW.KERNEL32(Mscoree.dll), ref: 6CB8EAF9
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CurrentHandleModuleThread
              • String ID: Handler not installed$Mscoree.dll$Service stopped
              • API String ID: 2752942033-1381189583
              • Opcode ID: c22f3e74f5ec3fc34b0d47fb8932922fba87501e040c6ae4d8a7de50fa1dd554
              • Instruction ID: 75d09a5c686221c1ea2100e9b54f733e4c5c39d61ea3b8d996df967189d065a0
              • Opcode Fuzzy Hash: c22f3e74f5ec3fc34b0d47fb8932922fba87501e040c6ae4d8a7de50fa1dd554
              • Instruction Fuzzy Hash: A111C87460ABD1AAF7205F7588CCA8FB7E8FF05709F14081EE15785E80EB71A5448BA5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CreateEventW.KERNEL32(?,00000001,00000000,?,?,?,?,?,?,?,?,?,6CBB5DAD), ref: 6CBC467F
              • WaitForSingleObject.KERNEL32(00000000,000000FF,?,?,?,?,?,?,?,?,6CBB5DAD), ref: 6CBC4697
              • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,6CBB5DAD), ref: 6CBC469F
              • CloseHandle.KERNEL32(00000000,?,?,?,?,?,?,?,?,6CBB5DAD), ref: 6CBC46BE
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Strings
              • {B03AF14C-1ABD-442B-8A15-6F3FEE7CE2F6}, xrefs: 6CBC4666
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorLast$CloseCreateEventHandleObjectSingleWait
              • String ID: {B03AF14C-1ABD-442B-8A15-6F3FEE7CE2F6}
              • API String ID: 243137184-475658951
              • Opcode ID: f8b6df34fb2f98e3cc0c43222f82fa4fac5fddbffd327637e80367b0123cef49
              • Instruction ID: f43ac0d2f0cb3f1db4743101879010fbee0e91c287fa8f558b56c0a118c30e79
              • Opcode Fuzzy Hash: f8b6df34fb2f98e3cc0c43222f82fa4fac5fddbffd327637e80367b0123cef49
              • Instruction Fuzzy Hash: BA01DD3170829567D610AE798C449EF76ECDB86368F000679FE70C7BD4EF51C6099AA3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • LoadLibraryExW.KERNEL32(kernelbase.dll,00000000,00000800,?,?,00000000,?,?,6CB6EC0C,?,00000000,00000000,?,6CB6BF41,?), ref: 6CB72AC6
              • GetProcAddress.KERNEL32(00000000,GetTempPath2W), ref: 6CB72AD6
              • GetTempPathW.KERNEL32(00000104,00000000,00000104,?,6CB6EC0C,?,00000000,00000000,?,6CB6BF41,?), ref: 6CB72B05
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressLibraryLoadPathProcTemp
              • String ID: GetTempPath2W$kernelbase.dll
              • API String ID: 1686214323-1418961652
              • Opcode ID: 1e3a8687fd57bb65e0c99990216e0b017f46d274ab29f752c3d5a2d57ddd4a0c
              • Instruction ID: a46a7fba63977c9233f558877ef4539b01bede971f340c06dffd71f94440111d
              • Opcode Fuzzy Hash: 1e3a8687fd57bb65e0c99990216e0b017f46d274ab29f752c3d5a2d57ddd4a0c
              • Instruction Fuzzy Hash: 7F01F771B04190FFAF309BBA8C89DBF75BCDB82685B014429A921E3A40DB749D0496B2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(Advapi32.dll,00000000,?,?,6CB88B3F,?,6CB89EC3,?,?,6CB89EC3,?,00000000), ref: 6CB8881A
              • GetProcAddress.KERNEL32(00000000,RegCreateKeyTransactedW), ref: 6CB8882A
              • RegCreateKeyExW.ADVAPI32(?,6CB88B3F,00000000,00000000,00000000,0002001F,00000000,?,?,00000000,?,?,6CB88B3F,?,6CB89EC3,?), ref: 6CB8886A
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressCreateHandleModuleProc
              • String ID: Advapi32.dll$RegCreateKeyTransactedW
              • API String ID: 1964897782-2994018265
              • Opcode ID: a8e777a409836749856d5132d5969725a4cd0bfb1a44428c463a61a559e70afd
              • Instruction ID: 76168ca1cb3e44f4fe4443c4d115757068a107e08e34531ca918c031c14bdf93
              • Opcode Fuzzy Hash: a8e777a409836749856d5132d5969725a4cd0bfb1a44428c463a61a559e70afd
              • Instruction Fuzzy Hash: 93011231201184FBEF221E968C08C977FBDEBCAB55750852AFA6991411D732C450DB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetLocalTime.KERNEL32(?), ref: 6CB67FA9
              • GetCurrentThreadId.KERNEL32 ref: 6CB67FE7
              • GetCurrentProcessId.KERNEL32 ref: 6CB67FEF
              Strings
              • [%02d/%02d/%02d %02d:%02d:%02d.%03d], xrefs: 6CB67FD9
              • [%s][%u:%u], xrefs: 6CB67FFA
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Current$LocalProcessThreadTime
              • String ID: [%02d/%02d/%02d %02d:%02d:%02d.%03d]$[%s][%u:%u]
              • API String ID: 2750998906-1978067781
              • Opcode ID: 3f929b4015a86a3ce28af53e57b871fa8c49f06b915f134a30c8f21e52d5d560
              • Instruction ID: f5261ceabc2052e4dd75c930d66a759d1e9b6fee42c8d4db89aaa1afd113bc4b
              • Opcode Fuzzy Hash: 3f929b4015a86a3ce28af53e57b871fa8c49f06b915f134a30c8f21e52d5d560
              • Instruction Fuzzy Hash: AB012CA2A00114B9EB505BE9CC099FFB7BDEF4D602B00481AFB55E1180E6398989D774
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • WaitForSingleObject.KERNEL32(?,000000FF), ref: 6CB74730
              • GetExitCodeProcess.KERNEL32(?,?), ref: 6CB74738
              • CloseHandle.KERNEL32(?), ref: 6CB74743
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseCodeExitHandleObjectProcessSingleWait
              • String ID: <$runas
              • API String ID: 179817009-1187129395
              • Opcode ID: d71790f6d5b5b92d65d5d92cb3cd949475d9fefbd8f0d23f36e768f108e96204
              • Instruction ID: e5255d44d727ab3d2363d97c1a0d87c3d9f99ef40b8a3b08fcdef89e8ada2e79
              • Opcode Fuzzy Hash: d71790f6d5b5b92d65d5d92cb3cd949475d9fefbd8f0d23f36e768f108e96204
              • Instruction Fuzzy Hash: 0E016971E01658AACF009FA9C8486CEBBB8EF56318F20411AED24B7780E73486058FA5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB8E911
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: APPID$DESCRIPTION$FILENAME$ServiceModule
              • API String ID: 1385522511-3953441269
              • Opcode ID: e12f841375494963b2f0ce47df581b58cfec638b9fb479af695799b02c2a227d
              • Instruction ID: 9424d1d1c4eaee269610613acc2407359b982141fc4a2faa5784f1f9f640bf2f
              • Opcode Fuzzy Hash: e12f841375494963b2f0ce47df581b58cfec638b9fb479af695799b02c2a227d
              • Instruction Fuzzy Hash: 4F01A2753050909FE5119B58D855EDD3369DB8232AF54053AE6006BFE0EB30484E9AF2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • __Init_thread_footer.LIBCMT ref: 6CB8EA76
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Init_thread_footer
              • String ID: APPID$DESCRIPTION$FILENAME$ServiceModule
              • API String ID: 1385522511-3953441269
              • Opcode ID: 7fce7f32b9bd8009fd1144606487e59f9aa92c769294554eb8c4c3656676f2e0
              • Instruction ID: aa3402b8dc7deef7b737edba14a4eb415bbe66390770799d05364085e77fd2b4
              • Opcode Fuzzy Hash: 7fce7f32b9bd8009fd1144606487e59f9aa92c769294554eb8c4c3656676f2e0
              • Instruction Fuzzy Hash: 5E01A2713190D09FF511AB18D818FDC3369EB43729B94492AF6006AFD0DB34584A8AB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(Advapi32.dll,?,6CB8A4F1,?,6CB88B9C,?,80000000,?,6CB8A4F1,00000000,?,00000080,?,?,6CB8A4F1,80000000), ref: 6CB887B7
              • GetProcAddress.KERNEL32(00000000,RegOpenKeyTransactedW), ref: 6CB887C7
              • RegOpenKeyExW.ADVAPI32(?,80000000,00000000,?,?,?,6CB8A4F1,?,6CB88B9C,?,80000000,?,6CB8A4F1,00000000,?,00000080), ref: 6CB887F7
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressHandleModuleOpenProc
              • String ID: Advapi32.dll$RegOpenKeyTransactedW
              • API String ID: 1337834000-3913318428
              • Opcode ID: fb4f937617603702d957727c948d688b805fc415698ef10f40407dc78f2af4ee
              • Instruction ID: 18e59d64f3468e3b8cb2d550d0f5080c7d9c0f9b3ae1a222f67c616d1bfeb887
              • Opcode Fuzzy Hash: fb4f937617603702d957727c948d688b805fc415698ef10f40407dc78f2af4ee
              • Instruction Fuzzy Hash: E9F0493620214AFBEF120F96CC09C9B3F7EEF96751710842AFA6590420DB33C461EB65
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OutputDebugStringW.KERNEL32(LOG_SYSTEM: trying to move log file to backup,?,?,?,?,?,6CB694FE), ref: 6CB696B4
                • Part of subcall function 6CB6EBCC: MoveFileExW.KERNELBASE(?,?,0000000B,6CB696D8,.bak,?,?,?,?,?,6CB694FE), ref: 6CB6EBD0
              • OutputDebugStringW.KERNEL32(LOG_SYSTEM: failed to move log file to backup,?,?,?,?,?,6CB694FE), ref: 6CB696E2
                • Part of subcall function 6CB69711: RegOpenKeyExW.ADVAPI32(80000002,?,00000000,00020019,?,?,?), ref: 6CB6974E
                • Part of subcall function 6CB69711: RegQueryValueExW.ADVAPI32(?,PendingFileRenameOperations,00000000,?,00000000,?), ref: 6CB6977D
                • Part of subcall function 6CB69711: RegQueryValueExW.ADVAPI32(?,PendingFileRenameOperations,00000000,00000000,00000000,?), ref: 6CB697B9
                • Part of subcall function 6CB69711: lstrcmpW.KERNEL32(?,?), ref: 6CB69803
                • Part of subcall function 6CB69711: lstrlenW.KERNEL32(?), ref: 6CB69810
              Strings
              • .bak, xrefs: 6CB696BD
              • LOG_SYSTEM: failed to move log file to backup, xrefs: 6CB696DD
              • LOG_SYSTEM: trying to move log file to backup, xrefs: 6CB696AD
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DebugOutputQueryStringValue$FileMoveOpenlstrcmplstrlen
              • String ID: .bak$LOG_SYSTEM: failed to move log file to backup$LOG_SYSTEM: trying to move log file to backup
              • API String ID: 691347042-3505153176
              • Opcode ID: 3a03568532663ad6a8c3563e8174d52f91c46a3b10b5d9e2f4c40c04c30daa31
              • Instruction ID: 228a483dc236e353bfec85134735aa0aedf0047b9b2171d02986d56c8b6ee770
              • Opcode Fuzzy Hash: 3a03568532663ad6a8c3563e8174d52f91c46a3b10b5d9e2f4c40c04c30daa31
              • Instruction Fuzzy Hash: A2F02B35B101D09BBB049F6ADC908DE7369EF972183140428D40297FD0DFB19D0ECB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(Advapi32.dll,?,?,6CB8A619,?,?,?,?,?,?,?,?,?,?,80000000,?), ref: 6CB88AA8
              • GetProcAddress.KERNEL32(00000000,RegDeleteKeyExW), ref: 6CB88AB8
                • Part of subcall function 6CB8887B: GetModuleHandleW.KERNEL32(Advapi32.dll,7508EB20,?,?,6CB88A98,?,6CB8A619,?,?,6CB8A619,?), ref: 6CB8888D
                • Part of subcall function 6CB8887B: GetProcAddress.KERNEL32(00000000,RegDeleteKeyTransactedW), ref: 6CB8889D
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressHandleModuleProc
              • String ID: Advapi32.dll$RegDeleteKeyExW
              • API String ID: 1646373207-2191092095
              • Opcode ID: 9c2c0771a50269aa750c836f5fe48370c40dd931cf5d9f14ca3c5a893eb0e043
              • Instruction ID: adfae8c2ede216244148a4fe30c0bf315c30a86ef3a4781bbd66cb0f441cd247
              • Opcode Fuzzy Hash: 9c2c0771a50269aa750c836f5fe48370c40dd931cf5d9f14ca3c5a893eb0e043
              • Instruction Fuzzy Hash: BD016D34306351FFFF129F55C804A567BBEEB16341B00841AF699919A0C7B7D450DB66
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(kernel32.dll,?,?,?,?,6CB73816,?,?,?,?,?,?,?,?,6CB739D1), ref: 6CB73872
              • GetProcAddress.KERNEL32(00000000,IsWow64Process2), ref: 6CB73882
              • GetCurrentProcess.KERNEL32(00000000,6CB73816), ref: 6CB7389E
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressCurrentHandleModuleProcProcess
              • String ID: IsWow64Process2$kernel32.dll
              • API String ID: 4190356694-2577318745
              • Opcode ID: 89f95a17ffcb8068be569859a75df7132118c555bde6f2fc34b28f94e0d3eb82
              • Instruction ID: de2abd1afdd15605350fde265fb37ed6d53f58c5859df1e721d2faf9979cfaea
              • Opcode Fuzzy Hash: 89f95a17ffcb8068be569859a75df7132118c555bde6f2fc34b28f94e0d3eb82
              • Instruction Fuzzy Hash: 57F08271A0121AB7FF209BA5CD08B9F7A7CEF02296F100055AD21E3540E774DA0487B4
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,6CCD0338,?,?,6CCD0300,00000100,00000000,?), ref: 6CCD039B
              • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 6CCD03AE
              • FreeLibrary.KERNEL32(00000000,?,?,6CCD0338,?,?,6CCD0300,00000100,00000000,?), ref: 6CCD03D1
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressFreeHandleLibraryModuleProc
              • String ID: CorExitProcess$mscoree.dll
              • API String ID: 4061214504-1276376045
              • Opcode ID: 62cd2031ae9c27fecd4868d2c1c66249b01f9e85f942c49aef0882b08514740f
              • Instruction ID: 4914f4005fdcc26d4deba7f2227add26302f0f9fd6e8007a3d641ba251a3ae22
              • Opcode Fuzzy Hash: 62cd2031ae9c27fecd4868d2c1c66249b01f9e85f942c49aef0882b08514740f
              • Instruction Fuzzy Hash: 7AF0823070521DFBEF019F59C809B9D7F78EB01759F214054EA11E1590DB30DA08DA94
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CloseHandle.KERNEL32(00000000,?,?,?,?,?,6CBE0EE6,?,?), ref: 6CBE1E10
              Strings
              • [Ping::SendString EcsSyncClient.RefreshDataFromServer failed][0x%08x][Non-fatal], xrefs: 6CBE1D8E
              • EcsError, xrefs: 6CBE1DBD
              • [Ping::SendString failed][%s][0x%08x], xrefs: 6CBE1CDB
              • [Ping::SendString EcsSyncClient.Initialize failed][0x%08x][Non-fatal], xrefs: 6CBE1D51
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle
              • String ID: EcsError$[Ping::SendString EcsSyncClient.Initialize failed][0x%08x][Non-fatal]$[Ping::SendString EcsSyncClient.RefreshDataFromServer failed][0x%08x][Non-fatal]$[Ping::SendString failed][%s][0x%08x]
              • API String ID: 2962429428-2742154148
              • Opcode ID: b61e279f0b6106de69a67c14e3ff1288a35156555aeeddcc286a0b55ce8750bb
              • Instruction ID: 83fdeaf47b6db564d92ab41f12422eabe01d4391a6f8c52c17eb7444fa475523
              • Opcode Fuzzy Hash: b61e279f0b6106de69a67c14e3ff1288a35156555aeeddcc286a0b55ce8750bb
              • Instruction Fuzzy Hash: CC51E571E001599BDF08DBA4D851AFD7774AF89368B24422DE532F7BD0DB309909CB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetSecurityDescriptorControl.ADVAPI32(?,?,?), ref: 6CB6B9B0
              • GetSecurityDescriptorOwner.ADVAPI32(?,?,?), ref: 6CB6B9DA
              • GetSecurityDescriptorGroup.ADVAPI32(?,?,?), ref: 6CB6B9F8
              • GetSecurityDescriptorDacl.ADVAPI32(00008000,?,?,?), ref: 6CB6BA1B
              • GetSecurityDescriptorSacl.ADVAPI32(00008000,?,?,?), ref: 6CB6BA44
                • Part of subcall function 6CB6749C: GetSidLengthRequired.ADVAPI32(00000008,?,00000000,6CD3F770,?,?,?,?,?,?,?,?,6CB6C978,?,6CD3E5F4,00000001), ref: 6CB674F2
                • Part of subcall function 6CB6749C: InitializeSid.ADVAPI32(?,00000000,00000008,?,?,?,?,?,?,?,?,6CB6C978,?,6CD3E5F4,00000001,00000012), ref: 6CB67505
                • Part of subcall function 6CB6749C: GetSidSubAuthority.ADVAPI32(?,00000000,?,?,?,?,?,?,?,?,6CB6C978,?,6CD3E5F4,00000001,00000012,?), ref: 6CB67526
                • Part of subcall function 6CB6AA0E: GetSecurityDescriptorOwner.ADVAPI32(?,?,6CB6B77A,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A,?,00000220,?,10000000,00000000), ref: 6CB6AA33
                • Part of subcall function 6CB6AA0E: GetLengthSid.ADVAPI32(6CB6B77E,00000220,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AA5D
                • Part of subcall function 6CB6AACA: GetSecurityDescriptorGroup.ADVAPI32(?,00000000,6CB6B77A,6CB6B77A,00000000,?,?,?,80004005,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AAEF
                • Part of subcall function 6CB6AACA: GetLengthSid.ADVAPI32(6CB6B77E,00000220,6CB6B77A,00000000,?,?,?,80004005,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AB19
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DescriptorSecurity$Length$GroupOwner$AuthorityControlDaclInitializeRequiredSacl
              • String ID:
              • API String ID: 783460827-0
              • Opcode ID: 96108636842dca66d616abfd43d20224e4ccb8c5ffca9c33695b249e35cce496
              • Instruction ID: 461fbbd6a58f11a0ad62dfbbe52aa1556863c99a8b42da1d77cacc1f5cf5daac
              • Opcode Fuzzy Hash: 96108636842dca66d616abfd43d20224e4ccb8c5ffca9c33695b249e35cce496
              • Instruction Fuzzy Hash: CA415C72108345AFD701DF61C884DAFB7FDFF84358F40492EB299929A0DB30DA098B62
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetTokenInformation.ADVAPI32(00000000,00000001(TokenIntegrityLevel),00000000,00000000,?,00000000,?,?,?,6CB76943,?,?,00000000,?,00000000), ref: 6CB769FD
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              • GetTokenInformation.ADVAPI32(00000000,00000001(TokenIntegrityLevel),00000000,?,?,?,?,?,6CB76943,?,?,00000000,?,00000000), ref: 6CB76A3D
              • IsValidSid.ADVAPI32(00000000,?,?,6CB76943,?,?,00000000,?,00000000), ref: 6CB76A5B
              • ConvertSidToStringSidW.ADVAPI32(00000000,6CB76943), ref: 6CB76A72
              • LocalFree.KERNEL32(6CB76943,?,00000000,?,?,6CB76943,?,?), ref: 6CB76B37
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: InformationToken$ConvertErrorFreeLastLocalStringValid
              • String ID:
              • API String ID: 2014794619-0
              • Opcode ID: 8b673149257e5d2dc933edea3792eae2a69b37353db6132deaff7c4c2b24b9ee
              • Instruction ID: b5cf1b8ea4e0181148807d950f412b2584f800a025ad5f09e2b9a2be4628621c
              • Opcode Fuzzy Hash: 8b673149257e5d2dc933edea3792eae2a69b37353db6132deaff7c4c2b24b9ee
              • Instruction Fuzzy Hash: E741B671B04145AFDF248FDAC8859AEBBB9EF46318B244069E821E7B40EB3099448B71
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenProcess.KERNEL32(00000410,00000000,?,?,?), ref: 6CB756EB
              • CloseHandle.KERNEL32(00000000,?,?,?), ref: 6CB757FF
                • Part of subcall function 6CB755F3: GetModuleHandleW.KERNEL32(ntdll.dll,00000000,6CB75698,00000007,?,?,?,?,?,?,?,6CB6CA41,?), ref: 6CB75604
              • ReadProcessMemory.KERNEL32(00000000,?,?,00000004,?), ref: 6CB75775
              • ReadProcessMemory.KERNEL32(00000000,?,?,00000290,?), ref: 6CB757A8
              • ReadProcessMemory.KERNEL32(00000000,?,00000000,00001000,?,00001000), ref: 6CB757DC
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Process$MemoryRead$Handle$CloseModuleOpen
              • String ID:
              • API String ID: 3402956034-0
              • Opcode ID: 3ae60f45e803399de2cc22da1ff96233accf05abb46e27febdd743ea362b546c
              • Instruction ID: 16dc20d7f2d3228ea0c28bfa38f41e771d09169bb74d333558a345c9dcbf9f70
              • Opcode Fuzzy Hash: 3ae60f45e803399de2cc22da1ff96233accf05abb46e27febdd743ea362b546c
              • Instruction Fuzzy Hash: 2A319271A01669AFEB20DA558C88FEF737CEF45344F5000A9A918D2280DB34DE888B76
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetTokenInformation.ADVAPI32(?,00000019(TokenIntegrityLevel),00000000,00000000,6CB78635,?,75922EE0,?,?,?,6CB78635), ref: 6CB7828A
              • LocalAlloc.KERNEL32(00000040,6CB78635,?,?,6CB78635), ref: 6CB782AA
              • GetTokenInformation.ADVAPI32(?,00000019(TokenIntegrityLevel),00000000,6CB78635,?,?,6CB78635), ref: 6CB782CB
              • LocalFree.KERNEL32(00000000,?,6CB78635), ref: 6CB78334
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              • GetSidSubAuthority.ADVAPI32(00000000,?,?,6CB78635), ref: 6CB782F7
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: InformationLocalToken$AllocAuthorityErrorFreeLast
              • String ID:
              • API String ID: 3568956055-0
              • Opcode ID: 8c28567cc68e80d5bc357139acb42fb50558f7d690d5763377e712e5937a439c
              • Instruction ID: 4832363d9806b61bbad88983d484ff7aff27abaf60cf4c233a64b0d40e290f19
              • Opcode Fuzzy Hash: 8c28567cc68e80d5bc357139acb42fb50558f7d690d5763377e712e5937a439c
              • Instruction Fuzzy Hash: B721D634744255FBFB310A6A8C08EAB3A7DEF42799B160016FD21FA941E776C9009772
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetSecurityDescriptorControl.ADVAPI32(00000000,00000000,?,?), ref: 6CB67C34
              • GetSecurityDescriptorGroup.ADVAPI32(00000000,?,6CB8BBC5), ref: 6CB67C70
              • GetSecurityDescriptorDacl.ADVAPI32(00000000,00000000,?,6CB8BBC5), ref: 6CB67C8E
              • GetSecurityDescriptorSacl.ADVAPI32(00000000,00000000,?,6CB8BBC5), ref: 6CB67CB2
              • GetSecurityDescriptorOwner.ADVAPI32(00000000,?,6CB8BBC5), ref: 6CB67C56
                • Part of subcall function 6CCC972C: _free.LIBCMT ref: 6CCC973F
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DescriptorSecurity$ControlDaclGroupOwnerSacl_free
              • String ID:
              • API String ID: 62099665-0
              • Opcode ID: 6d27b1bb8b75f74ea5df0dd50ec03830812946bbe872936b7265f826b8b4420c
              • Instruction ID: ee3e545c9e7c509bb00af0a3a2e8557186d313da0be81cb8af1ccbfd2851ad80
              • Opcode Fuzzy Hash: 6d27b1bb8b75f74ea5df0dd50ec03830812946bbe872936b7265f826b8b4420c
              • Instruction Fuzzy Hash: C7211D72801508EFDF029F91D945AEFB7BDEF04319F10406AE126A1860EB74AA58DB51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrcmpiW.KERNEL32(?,windowsupdate_zdp,49EF6F00,00000000,?,?,?,6CBDC99A,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBDBFD0
              • lstrcmpiW.KERNEL32(6CBDC99A,0.0.0.0,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},?,6CBDC99A,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBDC016
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi
              • String ID: 0.0.0.0$windowsupdate_zdp${56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
              • API String ID: 1586166983-2334691273
              • Opcode ID: 59114c73dde35e8b363516822d71738d0d26d93ed958b1d379475bb5b5c785e2
              • Instruction ID: 98a288b91af4f328a9c8d6735aa51355b456e099ddf68265da5bbd306635c93e
              • Opcode Fuzzy Hash: 59114c73dde35e8b363516822d71738d0d26d93ed958b1d379475bb5b5c785e2
              • Instruction Fuzzy Hash: 0DF0AF35284058FFAB00DFA5CC918DEB778EF123187100969E152A3B90EB716A0DDA50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • lstrlenW.KERNEL32(?,?,?,6CB6F697), ref: 6CB78206
              • GlobalAlloc.KERNEL32(00002002,00000000,?,?,6CB6F697), ref: 6CB7822E
              • GlobalLock.KERNEL32(00000000,?,?,6CB6F697), ref: 6CB78237
              • GlobalUnlock.KERNEL32(00000000,?,?,6CB6F697), ref: 6CB7824D
              • GlobalFree.KERNEL32(00000000), ref: 6CB78261
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Global$AllocFreeLockUnlocklstrlen
              • String ID:
              • API String ID: 4276610554-0
              • Opcode ID: 16626d1fdbd731cfe822f1446b981e7add7bc048f6174b252b448db582a0ca78
              • Instruction ID: 455b3db60b06f4ebf06aa7dc92c3235a6ff378e957aaad56c8ee6720fa1719f8
              • Opcode Fuzzy Hash: 16626d1fdbd731cfe822f1446b981e7add7bc048f6174b252b448db582a0ca78
              • Instruction Fuzzy Hash: 27F04F71305114BFFA112F76AC8DBAF7A7CEB46757F000029F715D1191DB74880586B1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • EnterCriticalSection.KERNEL32(?,?,?,3FFFFFFF,?,?,?,?,6CCA6B74,?,?,?,?,?,6CCA6642,?), ref: 6CCA6DD7
              • DeleteTimerQueueTimer.KERNEL32(?,?,000000FF,?,6CCA6B74,?,?,?,?,?,6CCA6642,?,0000000C,00000000,00000000,00000000), ref: 6CCA6DEC
              • LeaveCriticalSection.KERNEL32(?,?,6CCA6B74,?,?,?,?,?,6CCA6642,?,0000000C,00000000,00000000,00000000,00000000), ref: 6CCA6E0B
              • DeleteCriticalSection.KERNEL32(?,?,6CCA6B74,?,?,?,?,?,6CCA6642,?,0000000C,00000000,00000000,00000000,00000000), ref: 6CCA6E18
              • DeleteCriticalSection.KERNEL32(?,?,?,6CCA6B74,?,?,?,?,?,6CCA6642,?,0000000C,00000000,00000000,00000000,00000000), ref: 6CCA6E1B
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$Delete$Timer$EnterLeaveQueue
              • String ID:
              • API String ID: 3006977580-0
              • Opcode ID: 51f00aff7ebec60b02ed97d0faf60cd358a1fb5374a354b3bde27d9dd487b938
              • Instruction ID: 94269a8cd8522ce80aff2274a680f45ae7400b9b49e17a51353d68aeb0b7ea50
              • Opcode Fuzzy Hash: 51f00aff7ebec60b02ed97d0faf60cd358a1fb5374a354b3bde27d9dd487b938
              • Instruction Fuzzy Hash: 35F0E7B1A01B20AFD7308F5E89C4457FBF8FF4A661390192EE29692A50C771B4418F50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: __aulldiv
              • String ID: .%d$[DO][TLU expired, download took > 24h]
              • API String ID: 3732870572-3266067434
              • Opcode ID: 76dacbbe94dee933b9a9118ef693b855a67616d038b0dce6aacf530ec83a05ea
              • Instruction ID: 9957e2f6858a359622d032aee3d734355e0201241eb5f9a0f519ef72276522a6
              • Opcode Fuzzy Hash: 76dacbbe94dee933b9a9118ef693b855a67616d038b0dce6aacf530ec83a05ea
              • Instruction Fuzzy Hash: 14E1A1716052419FCB05DF68C880EFE77A4FF44318F14456EE859ABB85EB30E949CBA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: __freea
              • String ID: a/p$am/pm
              • API String ID: 240046367-3206640213
              • Opcode ID: c2f47f9bcc8267b5fa78aec015aeb7bc93163924ef7bebce3ccbcff5e0509ea5
              • Instruction ID: b926d406f3ab57e5e51cfd3d62b0b40baeb5ffb9b75fbb20e5a956e135fd5789
              • Opcode Fuzzy Hash: c2f47f9bcc8267b5fa78aec015aeb7bc93163924ef7bebce3ccbcff5e0509ea5
              • Instruction Fuzzy Hash: 05C1E470941A16CBDB008F69C990BAAB7B0FF06708F26494AE654EBB54F335F942CB51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: __aulldiv
              • String ID: DownloadProgressPercent$DownloadTimeRemainingMs$StateValue
              • API String ID: 3732870572-1478549859
              • Opcode ID: f645b3a8ed0221a984b7b6fd1749de3e91f76f7316d16ca09227ca94adcca024
              • Instruction ID: c13e3ed48639e9787338f672990efe30880d972e66dcce6199a238c7e4166f8e
              • Opcode Fuzzy Hash: f645b3a8ed0221a984b7b6fd1749de3e91f76f7316d16ca09227ca94adcca024
              • Instruction Fuzzy Hash: 96A10B715083809FC714CF95C894AAFBBE9FB89218F10492EFA9997760DB31D909CB52
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBDF9C7: SysFreeString.OLEAUT32(?), ref: 6CBDF9FF
                • Part of subcall function 6CBDF9C7: SysFreeString.OLEAUT32(?), ref: 6CBDFA25
                • Part of subcall function 6CBDF9C7: SysFreeString.OLEAUT32(?), ref: 6CBDFA47
                • Part of subcall function 6CBDF9C7: SysFreeString.OLEAUT32(?), ref: 6CBDFA8D
              • SysFreeString.OLEAUT32(?), ref: 6CBE011B
              • SysFreeString.OLEAUT32(?), ref: 6CBE0212
              • SysFreeString.OLEAUT32(?), ref: 6CBE025B
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u
              • API String ID: 3341692771-4279031584
              • Opcode ID: 214139832443c116688c15ff017b7944575b7320960ff9db5c37767c388dee0b
              • Instruction ID: 7f0917a44416201c4dbde9dc77f1c37c4fb2781c92bd46fc47bdd77b0f8238fe
              • Opcode Fuzzy Hash: 214139832443c116688c15ff017b7944575b7320960ff9db5c37767c388dee0b
              • Instruction Fuzzy Hash: 42816931E0129A9FCF05DFA8D890AEEBBB5EF48B54F114099D811BB750DB30AD49DB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate
              • String ID: BITS$DeliveryOptimization$winhttp
              • API String ID: 1075933841-2604196685
              • Opcode ID: fcbf690f9ed1f6e75b66b6ed4222cc963c145fbd5f1ccedfa0e88c0860879716
              • Instruction ID: bc0a4c419bb800f91520badb3b18c563390bfc7dde16934613784e437abbfcec
              • Opcode Fuzzy Hash: fcbf690f9ed1f6e75b66b6ed4222cc963c145fbd5f1ccedfa0e88c0860879716
              • Instruction Fuzzy Hash: 3C815B71D042899FCF04CFA4E490AEEB7B4FF49318F14855DD496ABA50DB30A94ACFA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(?,6CD3F944,00000000,80000002,?,00000101,?,?,00000000), ref: 6CC017B1
                • Part of subcall function 6CB77157: SHQueryValueExW.SHLWAPI(?,?,00000000,?,00000000,00000000), ref: 6CB7716B
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: QueryValue$CloseOpen
              • String ID: MachineId$SOFTWARE\Microsoft\SQMClient$}
              • API String ID: 1586453840-1206568148
              • Opcode ID: 1c89b99417fdb7b821d4bc2bd14fda8b69373ba0d6493e3572fabd37c841f025
              • Instruction ID: 297b68416268ac483befd3d64a90714d324ec69d3ed5634157324776d2fb50fc
              • Opcode Fuzzy Hash: 1c89b99417fdb7b821d4bc2bd14fda8b69373ba0d6493e3572fabd37c841f025
              • Instruction Fuzzy Hash: 8E712A71A0026CDFDB64CF68CC80AEEB7B9BF45308F5000A9D419A7655EB71AA49CF61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBE1674: RegCloseKey.ADVAPI32(00000000,?,00000000,?), ref: 6CBE17D4
                • Part of subcall function 6CBE1674: RegCloseKey.ADVAPI32(00000000,?,00020019,?,00000000,?), ref: 6CBE181A
              • __aulldiv.LIBCMT ref: 6CBE1AC5
              • __aulldiv.LIBCMT ref: 6CBE1AE7
              • _Deallocate.LIBCONCRT ref: 6CBE1BBF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close__aulldiv$Deallocate
              • String ID: X-RequestAge
              • API String ID: 3198432504-490694700
              • Opcode ID: 920c05b30a060ab92bb920f9dbc5856e2f3ace8e304899e83127e1ce89d5e35e
              • Instruction ID: 3ec178a4164a0fb3309baa09e03ea8a6c39c61186713c476800cd158b3d2cdde
              • Opcode Fuzzy Hash: 920c05b30a060ab92bb920f9dbc5856e2f3ace8e304899e83127e1ce89d5e35e
              • Instruction Fuzzy Hash: 2751C772D042699FCB04DFF9DC809EDB7B8EF48B54B244519E410F7B91EB3499098B91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6C532: CharUpperW.USER32(?,?,?,?,?,?,?,6CB7A8B7,?,[rollback_to_target_version][%d],?,?,[target_version_prefix][%s],00000001,?,[target_channel][%s]), ref: 6CB6C569
              • RegCloseKey.ADVAPI32(00000000,6CD1A2EC,00000000,?,000F003F,\LocalServer32,00000000,?,00000000,HKCR\CLSID\,?,?,?), ref: 6CC095CC
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CharCloseUpper
              • String ID: HKCR\CLSID\$\InprocServer32$\LocalServer32
              • API String ID: 2269005397-1190808103
              • Opcode ID: cf6bb30e279316c82b05f66b8fe962a884d31b04f792d90af36d0b9ab8f00aa4
              • Instruction ID: f1d17f74ebbdb73f446f986cff55443544bd6c4df721dc474011c88cb9684ec8
              • Opcode Fuzzy Hash: cf6bb30e279316c82b05f66b8fe962a884d31b04f792d90af36d0b9ab8f00aa4
              • Instruction Fuzzy Hash: 9A51A371A00145AFDF04DBA9C895AFEB779AF55308F600058D812A7FA0EF31AE0DCB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,HKU\,00020019,00000000,00000001,00000000), ref: 6CBAEA09
                • Part of subcall function 6CB77BFD: RegQueryInfoKeyW.ADVAPI32(6CB76BD7,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,6CD3F7F0,?,6CB8C8CC,HKLM\Software\Microsoft\EdgeUpdate\ClientState\), ref: 6CB77C17
                • Part of subcall function 6CB77C22: RegEnumKeyExW.KERNELBASE(6CB76BD7,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6CB77C5E
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseEnumInfoQuery
              • String ID: HKU\$Software\Microsoft\EdgeUpdate\ClientState\$Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER
              • API String ID: 914269332-3072547768
              • Opcode ID: af1f009fe3529ee4cd4b829881d80a36b3c238a52d94f9b08d5bfb5bfc1bf668
              • Instruction ID: 30d6fb02462fb8732d26123f747fb7c826ff1fe49342c148ba7de2eef4bdf9a6
              • Opcode Fuzzy Hash: af1f009fe3529ee4cd4b829881d80a36b3c238a52d94f9b08d5bfb5bfc1bf668
              • Instruction Fuzzy Hash: AC51FD3690018EEBCF09DF95D894DEEB775EF54318B104469D412A7AE0EF306A4DCB94
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6C735: LocalFree.KERNEL32(00000000), ref: 6CB6C8C7
              • RegCloseKey.ADVAPI32(00000000,?,00020019), ref: 6CB83A8E
              • _Deallocate.LIBCONCRT ref: 6CB83AEF
              Strings
              • Software\Microsoft\EdgeUpdate\ClientState\, xrefs: 6CB839AC
              • lastrun, xrefs: 6CB83A17
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseDeallocateFreeLocal
              • String ID: Software\Microsoft\EdgeUpdate\ClientState\$lastrun
              • API String ID: 883457007-1965450367
              • Opcode ID: e841a9e3a20936be0c4a8ec9b874f7133fe21e6800e375a91d55d49687818a6d
              • Instruction ID: 4fb6111dd5bec5fd7ae76c2ca6a03df1ed18cc237055f25de1905d92469fc137
              • Opcode Fuzzy Hash: e841a9e3a20936be0c4a8ec9b874f7133fe21e6800e375a91d55d49687818a6d
              • Instruction Fuzzy Hash: 5B514672E012599BDF04DF98D8909EDFBB5FF48318F244169D812B7B90EB34AA49CB50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?,?,?), ref: 6CB9D03E
              • RegCloseKey.ADVAPI32(00000000,?,?,?), ref: 6CB9D05B
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: [Synchronized client and client_state versions]$lang
              • API String ID: 3535843008-3599109095
              • Opcode ID: 3f5d55c2dc454d11f2f771f21d7b85a6ba96e4e9502c74abc0995c98bd55dead
              • Instruction ID: ca2060bff61ba44e4f8ae6615b4b984fc5b3ca8e89a61c245d3826f26d3142e5
              • Opcode Fuzzy Hash: 3f5d55c2dc454d11f2f771f21d7b85a6ba96e4e9502c74abc0995c98bd55dead
              • Instruction Fuzzy Hash: 4E5192729002599FDF01DFA5C895BFEBBB8EF05319F104029E912B7B90DB745A49CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(00000000), ref: 6CB8FDE5
              • SysStringLen.OLEAUT32(00000000), ref: 6CB8FDF1
              • SysFreeString.OLEAUT32(?), ref: 6CB8FE11
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free
              • String ID: `)u
              • API String ID: 1391021980-4279031584
              • Opcode ID: c4fdac7cb54a42d967b7970d2014a0c8bf945d5b4f2ec834055ab8b676286e3f
              • Instruction ID: be1805c15b2c9d5cb147def3b697066465a67acdeacf7a28ce79f9c73f51dadc
              • Opcode Fuzzy Hash: c4fdac7cb54a42d967b7970d2014a0c8bf945d5b4f2ec834055ab8b676286e3f
              • Instruction Fuzzy Hash: D8416075A01215AFDB08CF68C989DAEBBF8FF88315B20855DE505DB650E734DA40CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcAddress.KERNEL32(00000000,CredUIPromptForCredentialsW), ref: 6CBAD5BF
              • FreeLibrary.KERNEL32(00000000), ref: 6CBAD6F3
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressFreeLibraryProc
              • String ID: CredUIPromptForCredentialsW$credui.dll
              • API String ID: 3013587201-1624824753
              • Opcode ID: 4ca1e5693bd11ad260e335de10c2acfce7e2f9137a522213cd9307575e0ed267
              • Instruction ID: bb32f37356789382d5088ac0ff96ac89c0286be9a28e0075dbb142df1f820a64
              • Opcode Fuzzy Hash: 4ca1e5693bd11ad260e335de10c2acfce7e2f9137a522213cd9307575e0ed267
              • Instruction Fuzzy Hash: DF4180B1A0021C9EDB20DF68CC44BCAB7B9EB88314F0041E6A648E7290EB719F958F55
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?,?), ref: 6CB9B68A
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
              • SysFreeString.OLEAUT32(?), ref: 6CB9B64F
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseFreeQueryStringValue
              • String ID: RegistrationUpdateHook$`)u
              • API String ID: 2475856476-1006801279
              • Opcode ID: 571d314763a1af978c698d031988e130d9304a5909c94cb2a8d4389a68d5503d
              • Instruction ID: 6757b163fa28a5ce3406c77443c8b9239678302527cc95601a4b4efdaf85b167
              • Opcode Fuzzy Hash: 571d314763a1af978c698d031988e130d9304a5909c94cb2a8d4389a68d5503d
              • Instruction Fuzzy Hash: 4D418B725087519FC711CF64C884A9FB7E8AF8A714F01092DF995A7660D770E909CBE2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\Clients\, xrefs: 6CBB2F7B
              • omaha::fsm::AppBundleStateInitialized::CreateAllInstalledApps, xrefs: 6CBB2F3A
              • HKLM\Software\Microsoft\EdgeUpdate\Clients\, xrefs: 6CBB2F74
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\Clients\$HKLM\Software\Microsoft\EdgeUpdate\Clients\$omaha::fsm::AppBundleStateInitialized::CreateAllInstalledApps
              • API String ID: 1075933841-1809452419
              • Opcode ID: c883d276ee0688b34868cfe8a78591ce314e0985451091a29455ada0dfcab6b2
              • Instruction ID: a4282ab26d402d149e79bf5369957ada349b6d530b4f75cc89865d57a002abcd
              • Opcode Fuzzy Hash: c883d276ee0688b34868cfe8a78591ce314e0985451091a29455ada0dfcab6b2
              • Instruction Fuzzy Hash: 4931E572A093918F9B04DF69888456FB7E8EF85218F050A2DF995A7B41DF30DD08C7A3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\, xrefs: 6CB92B55
              • RetryAfter, xrefs: 6CB92B64
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CB92B4B
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: __aulldiv
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$RetryAfter
              • API String ID: 3732870572-788114745
              • Opcode ID: 8effb1221e732763152f3585ff478c44017913cad249e0867db7907da07f8380
              • Instruction ID: f8ed97cd2ec89b6d13af57d89262d90ad6c083776556789d6d70134f4f4f797d
              • Opcode Fuzzy Hash: 8effb1221e732763152f3585ff478c44017913cad249e0867db7907da07f8380
              • Instruction Fuzzy Hash: 7031D471A00295AF8F05DFA4C4A4CFE7BA9EF863487048068ED199FB50DB30DC49C7A1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(00000000,00000000,00000001,-7FFFFE01,Software\Microsoft\EdgeUpdate\DownloaderLockout,00020006), ref: 6CB7E6A7
                • Part of subcall function 6CB76C03: RegCreateKeyExW.KERNELBASE(00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00000000,80070003,?,6CD3F7F0,?,6CB76E8D,00000000,?), ref: 6CB76C45
                • Part of subcall function 6CB773B5: RegSetValueExW.KERNELBASE(6CB76BD7,00000000,00000000,00000004,00000000,00000004,?,6CB76EF5,00000000,00000000,00000000,?,00000000,00000000,?,00000000), ref: 6CB773C8
              Strings
              • Software\Microsoft\EdgeUpdate\DownloaderLockout, xrefs: 6CB7E5C8, 6CB7E5EE
              • [SetDownloaderLockout ensure][%s][0x%08x], xrefs: 6CB7E63F
              • [SetDownloaderLockout set][%s][0x%08x], xrefs: 6CB7E68A
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseCreateOpenValue
              • String ID: Software\Microsoft\EdgeUpdate\DownloaderLockout$[SetDownloaderLockout ensure][%s][0x%08x]$[SetDownloaderLockout set][%s][0x%08x]
              • API String ID: 776291540-989563529
              • Opcode ID: 9061e0e40aca5d1461a96152689c30c6b32a624fe1ad552e08aa03c3a433d6fa
              • Instruction ID: cc14e957ce14584f14c49830cbfe70236c65c0f356242b0eb305db381e414854
              • Opcode Fuzzy Hash: 9061e0e40aca5d1461a96152689c30c6b32a624fe1ad552e08aa03c3a433d6fa
              • Instruction Fuzzy Hash: AF31C4B1D002A9AEEF249FA4CC91BFE7B75EB45314F10452DEA25B6790D7744A048BE0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenEventW.KERNEL32(00100000,00000000,?,00000001,?,00000000,?,?,0000000B,?,?,?), ref: 6CBC4AAD
              • WaitForMultipleObjectsEx.KERNEL32(?,00000000,00000000,00000000,00000000,?,?,?), ref: 6CBC4B15
              • CloseHandle.KERNEL32(00000000,?,?,?), ref: 6CBC4B3A
              Strings
              • {B03AF14C-1ABD-442B-8A15-6F3FEE7CE2F6}, xrefs: 6CBC4A97
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseEventHandleMultipleObjectsOpenWait
              • String ID: {B03AF14C-1ABD-442B-8A15-6F3FEE7CE2F6}
              • API String ID: 3311957596-475658951
              • Opcode ID: 974b67ac5a4893b3422862d89900a9676f771854369818ac7044c7e08c83472a
              • Instruction ID: 5b6d64320a782c674e6b6c8213a7fd97f075ee029bd04266c704a193e1415e66
              • Opcode Fuzzy Hash: 974b67ac5a4893b3422862d89900a9676f771854369818ac7044c7e08c83472a
              • Instruction Fuzzy Hash: 7421E132B00244AFDB249FADD885EAEBBF8EF89311B04402DF606E7A50DB30D9408B51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Variant$ClearFreeInitString
              • String ID: `)u
              • API String ID: 2508483829-4279031584
              • Opcode ID: a0ba9ea540ab7099cfc436bb46400116f09310e0e8fb72d0accd8f704fbe103f
              • Instruction ID: 9c01c56508b58177ae6f0a87da9c02a309ce9c001e372515c8433b22aa124f9c
              • Opcode Fuzzy Hash: a0ba9ea540ab7099cfc436bb46400116f09310e0e8fb72d0accd8f704fbe103f
              • Instruction Fuzzy Hash: 01317E72E10219ABDF10DFA4C848EAEBBB8EF48719F154494E901EB650E771DD41CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?,00020019), ref: 6CBC046F
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
                • Part of subcall function 6CB77187: SHQueryValueExW.SHLWAPI(6CB76BD7,00000000,00000000,00000000,?,?,6CD3F7F0,6CD3F7F0,?,6CB77060,?,00000000,00000000,?), ref: 6CB771AA
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: QueryValue$Close
              • String ID: %s:%d$ProxyHost$ProxyPort
              • API String ID: 1979452859-997896475
              • Opcode ID: 244f6e8d62b9718220afaf362cb8ffb9bd20dd2a5880b3e5e4de788534ea5b83
              • Instruction ID: 1c1284f441e90507ce1a023abc762a86d94a1de2bd7a5df0ac19a8d14ac01f50
              • Opcode Fuzzy Hash: 244f6e8d62b9718220afaf362cb8ffb9bd20dd2a5880b3e5e4de788534ea5b83
              • Instruction Fuzzy Hash: 5021B576900149ABDB00DBA4DC94AEFB7B9EF84314F204428E515B7B90EF749E0DCBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,?,00000200,?,?,HKLM\Software\Microsoft\EdgeUpdate\ClientState\,00000000,00000000,00000050,?), ref: 6CB9B8EB
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\ClientState\, xrefs: 6CB9B860, 6CB9B865
              • HKLM\Software\Microsoft\EdgeUpdate\ClientStateMedium\, xrefs: 6CB9B84A
              • HKLM\Software\Microsoft\EdgeUpdate\ClientState\, xrefs: 6CB9B859
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\ClientState\$HKLM\Software\Microsoft\EdgeUpdate\ClientStateMedium\$HKLM\Software\Microsoft\EdgeUpdate\ClientState\
              • API String ID: 3535843008-1835237214
              • Opcode ID: e9a2cfec316315fa1a5469c33508b419cd96d4e2bae5f99f34758f0072a3c1e6
              • Instruction ID: 46851cf5a5633ccef3be9685f320fe23660b88b4aad8f075521b4587020daefc
              • Opcode Fuzzy Hash: e9a2cfec316315fa1a5469c33508b419cd96d4e2bae5f99f34758f0072a3c1e6
              • Instruction Fuzzy Hash: A2217131C002A9EBDF21DFA4C8847EEB774AF06319F104569D550BBB50DB748A48CBE1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(00000000), ref: 6CBE9F7C
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u$gupdate$response
              • API String ID: 3341692771-839356773
              • Opcode ID: cf89c8334c7e18f553cd2f7fcb51c4a7bafd965ceda1d7bc847079fbd4cddcf7
              • Instruction ID: 57b45cce47938d6d9e85c596625de757aba29f5e2612f1fccec01f534c6cd13e
              • Opcode Fuzzy Hash: cf89c8334c7e18f553cd2f7fcb51c4a7bafd965ceda1d7bc847079fbd4cddcf7
              • Instruction Fuzzy Hash: BE11B631E11180BBCF10DB95C844AED77BADF89BD9F1401A8A805EB750DB71AE0DCAD1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • WTSQuerySessionInformationW.WTSAPI32(00000000,00000000,00000018,00000000,00000000,00000000,00000000,?,?,6CC06102,00000000,00000000,00000000,?,?,6CC05A64), ref: 6CB761A8
              • WTSFreeMemory.WTSAPI32(00000000,?,?,6CC06102,00000000,00000000,00000000,?,?,6CC05A64,6CB8B8A8,?), ref: 6CB761C6
              • GetLastError.KERNEL32(00000007,000000FE,?,?,6CC06102,00000000,00000000,00000000,?,?,6CC05A64,6CB8B8A8,?), ref: 6CB761FC
              Strings
              • [GetLogonTime WTSQuerySessionInformation failed][0x%x], xrefs: 6CB76206
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorFreeInformationLastMemoryQuerySession
              • String ID: [GetLogonTime WTSQuerySessionInformation failed][0x%x]
              • API String ID: 2233521960-2940940335
              • Opcode ID: a61699b1760e3163f8830693a86fe8e7882dc72bbc1b5d8a1f08c2955813c0b3
              • Instruction ID: ef79b62a003a6d8dc9c7075371d2d8897f007a987f41bb43088cba95c5aadafc
              • Opcode Fuzzy Hash: a61699b1760e3163f8830693a86fe8e7882dc72bbc1b5d8a1f08c2955813c0b3
              • Instruction Fuzzy Hash: 1511E971F44124ABEF148FA9CC459EE7BBCEB45615F204229EE24E7680E7309A0487F1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6CC65: lstrcmpiW.KERNEL32(?,IMAGE_STATE_UNDEPLOYABLE,ImageState,?,80000002,Software\Microsoft\Windows\CurrentVersion\Setup\State,00020019), ref: 6CB6CCDB
                • Part of subcall function 6CB6CC65: lstrcmpiW.KERNEL32(?,IMAGE_STATE_GENERALIZE_RESEAL_TO_AUDIT), ref: 6CB6CCE7
                • Part of subcall function 6CB6CC65: lstrcmpiW.KERNEL32(?,IMAGE_STATE_SPECIALIZE_RESEAL_TO_AUDIT), ref: 6CB6CCF3
                • Part of subcall function 6CB6CC65: RegCloseKey.ADVAPI32(00000000,AuditInProgress,00000000,80000002,System\Setup,00020019), ref: 6CB6CD62
                • Part of subcall function 6CB74525: AllocateAndInitializeSid.ADVAPI32(00000001,00000002,00000020,00000220,00000000,00000000,00000000,00000000,00000000,00000000,6CB7B383,?,6CB7B383,00000007,00000001), ref: 6CB7455B
                • Part of subcall function 6CB74525: CheckTokenMembership.KERNELBASE(00000000,6CB7B383,00000007,?,6CB7B383,00000007,00000001), ref: 6CB74570
                • Part of subcall function 6CB74525: FreeSid.ADVAPI32(6CB7B383,?,6CB7B383,00000007,00000001), ref: 6CB74580
                • Part of subcall function 6CB6FDFB: GetSystemTimeAsFileTime.KERNEL32(?,6CD3E6AC,6CD3E6AC,?,6CB68434,00000000,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB6FE1B
              • __aulldiv.LIBCMT ref: 6CB802DE
              Strings
              • [Beginning OEM install][%u], xrefs: 6CB80319
              • OemInstallTime, xrefs: 6CB8033E
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CB80343
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi$Time$AllocateCheckCloseFileFreeInitializeMembershipSystemToken__aulldiv
              • String ID: HKLM\Software\Microsoft\EdgeUpdate\$OemInstallTime$[Beginning OEM install][%u]
              • API String ID: 1753574721-3584341452
              • Opcode ID: 5bc93af9060dd98b61eeddb49615bdb0d2b986c3a688f8e4eeb4419de2b0dfa2
              • Instruction ID: 72478e9e7a3681519d99e447b7ac97fa8e590c5bbeefb5b058c4a46be54d1949
              • Opcode Fuzzy Hash: 5bc93af9060dd98b61eeddb49615bdb0d2b986c3a688f8e4eeb4419de2b0dfa2
              • Instruction Fuzzy Hash: 57112CB1E422C4BBCB009BB59C41BFE376C9B4674DF1441259A51FBB91D73085084B72
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(kernel32.dll,?,?,00000000,00000000,?,6CB6861E,00000040,?,6CB68793,?,6CB68851,6CD6C3B0,00000010,6CB688FE,?), ref: 6CB6F71F
              • GetProcAddress.KERNEL32(00000000,RtlCaptureStackBackTrace), ref: 6CB6F72F
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressHandleModuleProc
              • String ID: RtlCaptureStackBackTrace$kernel32.dll
              • API String ID: 1646373207-94782561
              • Opcode ID: d4e3973f3b5487be3e55d0b603a58ab2e0f20fc2cdf6f955b5cbe9448714432c
              • Instruction ID: 46c3de3c42305a3d9bfde650dfe6c36f5214b3478aa43ce1c5894f336bb54e62
              • Opcode Fuzzy Hash: d4e3973f3b5487be3e55d0b603a58ab2e0f20fc2cdf6f955b5cbe9448714432c
              • Instruction Fuzzy Hash: 4111C4B2604214ABEB148F19DDC1B567BACEF1A310B1044AEFD09DF755D3B0D444CBA8
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ExitProcess
              • String ID: Exception$Exception %x in %s %s %u%hs:%d$base\logging.cc
              • API String ID: 621844428-1730742759
              • Opcode ID: 75f7c1c99579e158160b7bf671405294d3e3bcb136c873b31c23bb9c4ce111f0
              • Instruction ID: df6364855d2203d8fbed71d9917c5ea75b2a47fe3f42ae803cf7e482a4fa0771
              • Opcode Fuzzy Hash: 75f7c1c99579e158160b7bf671405294d3e3bcb136c873b31c23bb9c4ce111f0
              • Instruction Fuzzy Hash: E111C431600168AADB50DF75CC49FDE77B8FB05318F408595A559A29D0DF709A8CDBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcAddress.KERNEL32(00000000,RtlGetVersion), ref: 6CB73915
              • FreeLibrary.KERNEL32(00000000,?,0000011C,?,?,?,6CB840B5,?,?,00000000), ref: 6CB73957
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressFreeLibraryProc
              • String ID: RtlGetVersion$ntdll.dll
              • API String ID: 3013587201-1489217083
              • Opcode ID: 7809d6c393422a5ccc39bb932e2257bef27352f98e49f2728d0dc2744eac281c
              • Instruction ID: 88741bdb4f3ef8af425f447bd31feff0e9c89062bd4dee4baa71d276ff9e758e
              • Opcode Fuzzy Hash: 7809d6c393422a5ccc39bb932e2257bef27352f98e49f2728d0dc2744eac281c
              • Instruction Fuzzy Hash: 15F0F631701696B7E72157AA8C45A8F3A6CCF82798B150035FE21E7B80DB60CD0543B6
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              • [Reset OEM install state][%u], xrefs: 6CB803B4
              • OemInstallTime, xrefs: 6CB803C7
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CB803CC
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: __aulldiv
              • String ID: HKLM\Software\Microsoft\EdgeUpdate\$OemInstallTime$[Reset OEM install state][%u]
              • API String ID: 3732870572-2489048847
              • Opcode ID: 9b8d3cc5939f5d5fdb7ec6bd589018d4192f27a55a53b4bb083b24e04ee3b64b
              • Instruction ID: e17ef3ff728de6003254e2857ea0762f3f68a2bac467e59350dfe20b38434956
              • Opcode Fuzzy Hash: 9b8d3cc5939f5d5fdb7ec6bd589018d4192f27a55a53b4bb083b24e04ee3b64b
              • Instruction Fuzzy Hash: C5F0C8B1E052846BDB04A7B59C03BBE36B89B8160CF14C52D9655F7F80E73495044765
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenEventW.KERNEL32(00000002,00000000,?), ref: 6CBC4761
              • SetEvent.KERNEL32(00000000), ref: 6CBC4775
              • CloseHandle.KERNEL32(00000000), ref: 6CBC478B
              Strings
              • {B03AF14C-1ABD-442B-8A15-6F3FEE7CE2F6}, xrefs: 6CBC474D
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Event$CloseHandleOpen
              • String ID: {B03AF14C-1ABD-442B-8A15-6F3FEE7CE2F6}
              • API String ID: 1560313832-475658951
              • Opcode ID: e1543e7d198a6a84cb82b3ee2ac3530dc98f33355d62aad9f3cd9f89f120a3dd
              • Instruction ID: 69d909cecd48f59ec23d9e0205d7e676655053a54f7ca343f0e423fcc138766c
              • Opcode Fuzzy Hash: e1543e7d198a6a84cb82b3ee2ac3530dc98f33355d62aad9f3cd9f89f120a3dd
              • Instruction Fuzzy Hash: 20F0FC327446553796216A2ACC0499F3BBDDFD3764F05021AFD5497B90EF20C6198EE3
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetSystemTimeAsFileTime.KERNEL32(00000000,?,00000000,edgeupdate), ref: 6CB80C68
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\, xrefs: 6CB80C97
              • %s%x%x, xrefs: 6CB80C80
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CB80C8E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Time$FileSystem
              • String ID: %s%x%x$HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\
              • API String ID: 2086374402-724791884
              • Opcode ID: 4af63544dd3f168575be68e16e3d1f96fb2535e3223606132e6824585839ff90
              • Instruction ID: ecb904e611aef30231ba053c3c1fa9104ae707368568740bcd10dec7931ddeb0
              • Opcode Fuzzy Hash: 4af63544dd3f168575be68e16e3d1f96fb2535e3223606132e6824585839ff90
              • Instruction Fuzzy Hash: FBF0A472E00158BBCF109BE9CC05BDE7B78AF01259F044564EA15A77D0E77096198BE1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6FDFB: GetSystemTimeAsFileTime.KERNEL32(?,6CD3E6AC,6CD3E6AC,?,6CB68434,00000000,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB6FE1B
              • __aulldiv.LIBCMT ref: 6CB816D8
                • Part of subcall function 6CB7FCF9: EnterCriticalSection.KERNEL32(6CD7CA74,00000000,00000001,?,6CB8C810,?,?,?,?,?,?,?,?,6CB8B0C1), ref: 6CB7FD06
                • Part of subcall function 6CB7FCF9: LeaveCriticalSection.KERNEL32(6CD7CA74,?,6CB8C810,?,?,?,?,?,?,?,?,6CB8B0C1), ref: 6CB7FD19
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\, xrefs: 6CB816FE
              • LastChecked, xrefs: 6CB81710
              • HKLM\Software\Microsoft\EdgeUpdate\, xrefs: 6CB816F5
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSectionTime$EnterFileLeaveSystem__aulldiv
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\$HKLM\Software\Microsoft\EdgeUpdate\$LastChecked
              • API String ID: 2616483452-961544728
              • Opcode ID: e0c50a2947bba00fe23d5146f9a244c99bc5d508a5aea4273e0c4cd33b8268b5
              • Instruction ID: e130deadaa377c8244a917cbdf271813ad85e4900fb61e5a835d98e083572533
              • Opcode Fuzzy Hash: e0c50a2947bba00fe23d5146f9a244c99bc5d508a5aea4273e0c4cd33b8268b5
              • Instruction Fuzzy Hash: C1F0B4A16953417BE51056614C07FEB369CDB81658F04052DFF609BFC0EB51E90943F6
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcAddress.KERNEL32(00000000,InternetGetProxyInfo), ref: 6CBB7657
              • FreeLibrary.KERNEL32(00000000,?,6CBB77C9,00000000,084D8B10,00000000,00000000,084D8B10,00000000,?,000000FF,00000104,?,00000000,00000000), ref: 6CBB767C
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressFreeLibraryProc
              • String ID: InternetGetProxyInfo$jsproxy.dll
              • API String ID: 3013587201-4097758111
              • Opcode ID: be6f0e3c4bb8e2077f858544716e4833725adabf8b2a3aada2da36d0ff42d25d
              • Instruction ID: b6f18dbe6ae3588b616dd89ac9a2ecab0a653e416fb383f65c17068735d22fcc
              • Opcode Fuzzy Hash: be6f0e3c4bb8e2077f858544716e4833725adabf8b2a3aada2da36d0ff42d25d
              • Instruction Fuzzy Hash: 87F0E2323056967B6B120E7F9C00CAB3A6EDBCA3A03014025FE29F2A10CEB1C91153B9
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(Advapi32.dll,7508EB20,?,?,6CB88A98,?,6CB8A619,?,?,6CB8A619,?), ref: 6CB8888D
              • GetProcAddress.KERNEL32(00000000,RegDeleteKeyTransactedW), ref: 6CB8889D
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressHandleModuleProc
              • String ID: Advapi32.dll$RegDeleteKeyTransactedW
              • API String ID: 1646373207-2168864297
              • Opcode ID: 598d27ab23edd8c5c5a8fada934ebd56e12f0501f530f7ba6dab58b03ec41bcf
              • Instruction ID: 1eeec1eb07d1a35b44bf783bd673c461911ecf26c04e2760c30700d752ae27f4
              • Opcode Fuzzy Hash: 598d27ab23edd8c5c5a8fada934ebd56e12f0501f530f7ba6dab58b03ec41bcf
              • Instruction Fuzzy Hash: 92F08232342540BBAB611EAA9C04C677BADEBC2767350843BF664C1894E632C080C671
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenEventW.KERNEL32(00100000,00000000,?,?,00000000,?,?,?,?,?,00000000,00000000,0000000C,00000000), ref: 6CB8BB9B
              • WaitForSingleObject.KERNEL32(00000000,00000000,?,?,?,?,?,00000000,00000000,0000000C,00000000), ref: 6CB8BBA9
              • CloseHandle.KERNEL32(00000000,?,?,?,?,?,00000000,00000000,0000000C,00000000), ref: 6CB8BBB7
              Strings
              • {E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}, xrefs: 6CB8BB85
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseEventHandleObjectOpenSingleWait
              • String ID: {E1CCA4D5-F56C-40AB-879F-7586DBEBF0D9}
              • API String ID: 1727428665-1902337801
              • Opcode ID: b4df056a65cf08aeb6254f59311555a1e96c733bd39985576bf48a18f6b68f0b
              • Instruction ID: d3c5c5ae286efd5a2caeabae75d66fdbb74b4addabad633fbbd5c49d31809d9e
              • Opcode Fuzzy Hash: b4df056a65cf08aeb6254f59311555a1e96c733bd39985576bf48a18f6b68f0b
              • Instruction Fuzzy Hash: 6FF0BE3164515E6FEB01ABA8CC96EFF7BBCEF06648F000065FA9297680EB505C4D87E0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB73867: GetModuleHandleW.KERNEL32(kernel32.dll,?,?,?,?,6CB73816,?,?,?,?,?,?,?,?,6CB739D1), ref: 6CB73872
                • Part of subcall function 6CB73867: GetProcAddress.KERNEL32(00000000,IsWow64Process2), ref: 6CB73882
                • Part of subcall function 6CB73867: GetCurrentProcess.KERNEL32(00000000,6CB73816), ref: 6CB7389E
              • GetModuleHandleW.KERNEL32(kernel32,?,?,?,?,?,?,?,?,6CB739D1), ref: 6CB7382A
              • GetProcAddress.KERNEL32(00000000,GetNativeSystemInfo), ref: 6CB73836
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressHandleModuleProc$CurrentProcess
              • String ID: GetNativeSystemInfo$kernel32
              • API String ID: 565683799-3846845290
              • Opcode ID: b818976f3c25591f950a65279ab995ae5ef7a53fe71385bf7d59874c5276159f
              • Instruction ID: ad053a578a1555f09a78fa537ba05b773a5fc0f287be64bd08d5894bae2e88db
              • Opcode Fuzzy Hash: b818976f3c25591f950a65279ab995ae5ef7a53fe71385bf7d59874c5276159f
              • Instruction Fuzzy Hash: B3F0BB71F14285AAEF119BBFD54449FB2FCDB553057108526EA22D7980EB34D444CF71
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB80B0C: lstrcmpiW.KERNEL32(?,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}), ref: 6CB80B13
              • OpenEventW.KERNEL32(00000002,00000000,?), ref: 6CBDAF9E
              • SetEvent.KERNEL32(00000000), ref: 6CBDAFA7
              • CloseHandle.KERNEL32(00000000), ref: 6CBDAFB2
              Strings
              • {4BE2111F-14A3-46E1-B5A0-5D59A5DBB471}, xrefs: 6CBDAF8B
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Event$CloseHandleOpenlstrcmpi
              • String ID: {4BE2111F-14A3-46E1-B5A0-5D59A5DBB471}
              • API String ID: 3558631851-3387239447
              • Opcode ID: 5982db3f10f101841f348e146778908a720ceed7fe7fa433279f8aa099b8e483
              • Instruction ID: 710cfd5d3d17301e52c430323b5c63cbe7343a8188df6db6107b796e39bd0b29
              • Opcode Fuzzy Hash: 5982db3f10f101841f348e146778908a720ceed7fe7fa433279f8aa099b8e483
              • Instruction Fuzzy Hash: 7EF0E9312056547BCA10BF28C845BEE7778EF52658F00010CFE5556BD1DF205959C7E7
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenEventW.KERNEL32(00100000,00000000,?), ref: 6CBC4707
              • GetLastError.KERNEL32 ref: 6CBC4711
              • CloseHandle.KERNEL32(00000000), ref: 6CBC471A
              Strings
              • {B03AF14C-1ABD-442B-8A15-6F3FEE7CE2F6}, xrefs: 6CBC46F0
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseErrorEventHandleLastOpen
              • String ID: {B03AF14C-1ABD-442B-8A15-6F3FEE7CE2F6}
              • API String ID: 116272808-475658951
              • Opcode ID: 978db71d8c57b989fff3c1a9dbde1588a34de5f0efa2ef8ba50fd2968b2bb3f3
              • Instruction ID: 42b1654e4090823322c4dcfaf525af24679c04a83e008ca2949672e51e8582f8
              • Opcode Fuzzy Hash: 978db71d8c57b989fff3c1a9dbde1588a34de5f0efa2ef8ba50fd2968b2bb3f3
              • Instruction Fuzzy Hash: 34F027303482087FD600AF68CC85A9A77BCEB17258F400519F5A882AE0EF218948C953
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcAddress.KERNEL32(00000000,InternetDeInitializeAutoProxyDll), ref: 6CBB76A8
              • FreeLibrary.KERNEL32(00000000,?,6CBB7843,00000000,00000000,?,00000000,00000000,000000FF,?,00000000,00000000), ref: 6CBB76C5
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressFreeLibraryProc
              • String ID: InternetDeInitializeAutoProxyDll$jsproxy.dll
              • API String ID: 3013587201-1471023202
              • Opcode ID: 4415bdb0c6a6149a98caad94e6817faab935864bcb5a38a3e91a432c347e1a5b
              • Instruction ID: 8277316404fd61096a775c7c0ff4e70c50fa2f166f6aab1c96173961d99b569b
              • Opcode Fuzzy Hash: 4415bdb0c6a6149a98caad94e6817faab935864bcb5a38a3e91a432c347e1a5b
              • Instruction Fuzzy Hash: E7E065327455966B5712167F9C0495B3959DFC26A03014024FE29F6B50DEB0CA0181B5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(ntdll.dll,00000000,6CB75698,00000007,?,?,?,?,?,?,?,6CB6CA41,?), ref: 6CB75604
              • GetProcAddress.KERNEL32(00000000,NtQueryInformationProcess), ref: 6CB7561A
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressHandleModuleProc
              • String ID: NtQueryInformationProcess$ntdll.dll
              • API String ID: 1646373207-2906145389
              • Opcode ID: a54b029d3d318cde2dfe2982439fdc45db3a44b296ad79754bb7d66cd3a27d51
              • Instruction ID: 61a51443b688e81482adb68287ddda58461c3b052439a39636a41b5ed13840eb
              • Opcode Fuzzy Hash: a54b029d3d318cde2dfe2982439fdc45db3a44b296ad79754bb7d66cd3a27d51
              • Instruction Fuzzy Hash: C9E0C27574826397BB224F3A9C4444636BCEB27355304452AEE60E2940FB71C4048778
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OutputDebugStringA.KERNEL32(Unexpected exception in: omaha::Logging::InternalLogMessageMaskedVA), ref: 6CB68B81
              • OutputDebugStringW.KERNEL32(?), ref: 6CB68B90
              • OutputDebugStringW.KERNEL32(6CD3EC20), ref: 6CB68B97
              Strings
              • Unexpected exception in: omaha::Logging::InternalLogMessageMaskedVA, xrefs: 6CB68B7C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DebugOutputString
              • String ID: Unexpected exception in: omaha::Logging::InternalLogMessageMaskedVA
              • API String ID: 1166629820-3049550389
              • Opcode ID: d45e07e12fa56a551d6a2ac43fca41fa54eba20cf98321e63c1480e893e69a73
              • Instruction ID: 24b3677d417edeac3f4c10d602c29917aec89383b32a6f8a5b67362e11a0b19a
              • Opcode Fuzzy Hash: d45e07e12fa56a551d6a2ac43fca41fa54eba20cf98321e63c1480e893e69a73
              • Instruction Fuzzy Hash: F1D0CD73E04118DBFF108F98D80158D7F30E746220F10451BD922535D087311810CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(api-ms-win-core-featurestaging-l1-1-0.dll,?,6CB9EF16,?), ref: 6CBFC0E3
              • GetProcAddress.KERNEL32(00000000,GetFeatureEnabledState), ref: 6CBFC100
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressHandleModuleProc
              • String ID: GetFeatureEnabledState$api-ms-win-core-featurestaging-l1-1-0.dll
              • API String ID: 1646373207-4274850341
              • Opcode ID: 028691725ebceb62944d4635fa8d536cb8c3fd8c144e51133bfa182e4d49c0a8
              • Instruction ID: 6cdd314c08b2eaa8b75e7df60183aeffb7d142e46f393f2b298545100b041e45
              • Opcode Fuzzy Hash: 028691725ebceb62944d4635fa8d536cb8c3fd8c144e51133bfa182e4d49c0a8
              • Instruction Fuzzy Hash: 81D0C9213091B2A76D202B3E7808ADE266CDB461593054055F927E1A44EB1588C785A9
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(kernel32.dll,6CB760E2,00000000,00000000,00000000,00000000,00000000,00000000,?,6CB7886D,?,00000000), ref: 6CB76061
              • GetProcAddress.KERNEL32(00000000,WTSGetActiveConsoleSessionId), ref: 6CB7606D
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AddressHandleModuleProc
              • String ID: WTSGetActiveConsoleSessionId$kernel32.dll
              • API String ID: 1646373207-2743965321
              • Opcode ID: 7e4119ed31267a2c305c6335e030f9bc9d9f60d31f5b4d73b4e6fc4e46c75d8d
              • Instruction ID: 9100ceee03b497b7125121b9100b27dbb68714d00ada89ec263ffcec4aacf3d2
              • Opcode Fuzzy Hash: 7e4119ed31267a2c305c6335e030f9bc9d9f60d31f5b4d73b4e6fc4e46c75d8d
              • Instruction Fuzzy Hash: 25C04C64748141A6BD241F7A890C50A393CA9573B53948F48AA36D09D0E76580044665
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcess.KERNEL32(?,00000000,00000020,?,?,?,00000000,00000000,?,?,?,?,6CC05493,?,?,?), ref: 6CBAE219
                • Part of subcall function 6CB78341: GetCurrentProcess.KERNEL32(00000000,00000000,00000000), ref: 6CB78358
                • Part of subcall function 6CB78341: OpenProcessToken.ADVAPI32(00000000,0000000A,?), ref: 6CB78366
                • Part of subcall function 6CB78341: CloseHandle.KERNEL32(?), ref: 6CB78580
              • CloseHandle.KERNEL32(00000000,?,00000000,00000020,?,?,?,00000000,00000000,?,?,?,?,6CC05493,?,?), ref: 6CBAE291
              • CloseHandle.KERNEL32(00000000,?,00000000,00000020,?,?,?,00000000,00000000,?,?,?,?,6CC05493,?,?), ref: 6CBAE29C
              • CloseHandle.KERNEL32(00000000,?,00000000,00000020,?,?,?,00000000,00000000,?,?,?,?,6CC05493,?,?), ref: 6CBAE2B2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle$Process$Current$OpenToken
              • String ID:
              • API String ID: 2846586177-0
              • Opcode ID: a671921b7a4bf4dd1d8028850fd7a00b3dcfcd9335fce0ea771d1f663ba0da74
              • Instruction ID: d7e71ad34dbe5ffbb87415aef081b69c88df47cbde9fc382ece7e97191d37989
              • Opcode Fuzzy Hash: a671921b7a4bf4dd1d8028850fd7a00b3dcfcd9335fce0ea771d1f663ba0da74
              • Instruction Fuzzy Hash: 2F61A571A052999FDF04CFE9C894AEEB7B4FF55318F10415DD851AB690DB30DA09CB90
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: bdd1c33176b11dbac6c3ad613c60d51a15ace8d494c79ea9fb9a58fbea28d3ac
              • Instruction ID: 3e658780cbf7c063268fc61def7294a6d03196c4a3e85c0427322339131b6c34
              • Opcode Fuzzy Hash: bdd1c33176b11dbac6c3ad613c60d51a15ace8d494c79ea9fb9a58fbea28d3ac
              • Instruction Fuzzy Hash: DC5182B16053919FDB04DF29D984A6AB7F8FF88714F00896DF955EB680DB30E904CB92
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 2c293a08c2d366fe695b61665421bcb3e3431ce47471e773f03a081324fdfb1c
              • Instruction ID: 1bda62fda49d0b5092a24809542e464d635460eb52bdc45a98e301a273000105
              • Opcode Fuzzy Hash: 2c293a08c2d366fe695b61665421bcb3e3431ce47471e773f03a081324fdfb1c
              • Instruction Fuzzy Hash: 22515AB26053819FDB04DF18D884A5AB7F8BF8D715F108A6EFA59DB640E730D904CB52
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetSecurityDescriptorControl.ADVAPI32(00000000,?,?,00000000,00000000), ref: 6CB6AC89
              • MakeAbsoluteSD.ADVAPI32(00000000,00000000,?,00000000,?,00000000,?,00000000,?,00000000,?), ref: 6CB6ACCF
              • GetLastError.KERNEL32 ref: 6CB6ACD5
                • Part of subcall function 6CCCD232: RtlAllocateHeap.NTDLL(00000000,?,?,?,6CCDDB85,00000220,00000100,?,00000000,?,?,?,6CCCA284,?,00000000,00000100), ref: 6CCD7DD7
              • MakeAbsoluteSD.ADVAPI32(00000000,00000000,?,00000000,?,00000000,?,?,00000000,?,00000000), ref: 6CB6AD99
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: AbsoluteMake$AllocateControlDescriptorErrorHeapLastSecurity
              • String ID:
              • API String ID: 4123424157-0
              • Opcode ID: 2e60f71bbb49bfb97ebcaf9c5451cf290cb5a25de7bd78981c2cf6fa0b56c5e6
              • Instruction ID: 79b44fcd5b29b7fdddae37561a5953ba631df2a67fee0ea07ed0d114b35afceb
              • Opcode Fuzzy Hash: 2e60f71bbb49bfb97ebcaf9c5451cf290cb5a25de7bd78981c2cf6fa0b56c5e6
              • Instruction Fuzzy Hash: 48512CB5902179EBDF01DF96D944AEFBBBDEF05309F204065E815A2A50DB309A44CFA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • Sleep.KERNEL32(00001388,00000000,?,?,00000000,?,?,6CBDCA2D,?,ZDP,{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062},00000000,00000010,00000000), ref: 6CBDC0AC
              Strings
              • [WaitForEULAAccepted][Timeout], xrefs: 6CBDC0EE
              • [WaitForEULAAccepted][Waiting][%d], xrefs: 6CBDC09D
              • [WaitForEULAAccepted][OS EULA accepted], xrefs: 6CBDC12E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Sleep
              • String ID: [WaitForEULAAccepted][OS EULA accepted]$[WaitForEULAAccepted][Timeout]$[WaitForEULAAccepted][Waiting][%d]
              • API String ID: 3472027048-1925420256
              • Opcode ID: 70aaf23f5df182c7d5557083f922fce3c843636ef098c33a631a31d45ee09b57
              • Instruction ID: 43d50f0c41463df1f9afce2a0ef2ff230057fbb7affa312098ab34a0c1061c43
              • Opcode Fuzzy Hash: 70aaf23f5df182c7d5557083f922fce3c843636ef098c33a631a31d45ee09b57
              • Instruction Fuzzy Hash: C431C1B1E042856FDB08EFB9C8429BEBBB8DB45309F10452E9651E7B80E73455448BA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001,?,00000000,?,6CB8DB5F,?,?,00000000,?,00000000,?,?,?,6CB8CB63), ref: 6CB8E55F
              • OpenServiceW.ADVAPI32(00000000,?,00000001,?,?,6CB8DB5F,?,?,00000000,?,00000000,?,?,?,6CB8CB63,00000000), ref: 6CB8E58A
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8DB5F,?,?,00000000,?,00000000,?,?,?,6CB8CB63,00000000,00000000,00000000), ref: 6CB8E62A
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8DB5F,?,?,00000000,?,00000000,?,?,?,6CB8CB63,00000000,00000000,00000000), ref: 6CB8E63F
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$ErrorLastManager
              • String ID:
              • API String ID: 3671606724-0
              • Opcode ID: 8c8a5e1b41a3b0e8252733d752d008e81cd87867765cfc531130a71f63d55ebf
              • Instruction ID: 7be679184ecd267d26a2509e962784d52f211aa78ba41ef57d697a5e7be520cf
              • Opcode Fuzzy Hash: 8c8a5e1b41a3b0e8252733d752d008e81cd87867765cfc531130a71f63d55ebf
              • Instruction Fuzzy Hash: 3621EB75A423A5DBFB158B608C88AEE737DDF45318F0005A9E91592681DB30DD84CFA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001,?,00000000,?,6CB8DEA7,?,?,00000000,?,00000000,?,?,?,6CB8CD3C), ref: 6CB8E6DF
              • OpenServiceW.ADVAPI32(00000000,?,00000001,?,?,6CB8DEA7,?,?,00000000,?,00000000,?,?,?,6CB8CD3C,00000000), ref: 6CB8E70A
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8DEA7,?,?,00000000,?,00000000,?,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CB8E7AA
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8DEA7,?,?,00000000,?,00000000,?,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CB8E7BF
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$ErrorLastManager
              • String ID:
              • API String ID: 3671606724-0
              • Opcode ID: 3b26a9e5f91bc3a3fb63908e426554e2e61365c6ffd5bd026c34ed6b9a2e5517
              • Instruction ID: e2f208ae1a03502a60cf5b149d2b3bb4b25ccdaf9b777d1744861193b97c46bf
              • Opcode Fuzzy Hash: 3b26a9e5f91bc3a3fb63908e426554e2e61365c6ffd5bd026c34ed6b9a2e5517
              • Instruction Fuzzy Hash: 9421EE39A423A49BFF158B50CC88BFE737DDF05718F1005A9D915A2681DB30DD84CAA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001,?,?,?,6CB8D3D4,?,?,6CB8CDA1,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DCED
              • OpenServiceW.ADVAPI32(00000000,?,00000001,?,?,6CB8D3D4,?,?,6CB8CDA1,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DD18
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D3D4,?,?,6CB8CDA1,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DD96
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D3D4,?,?,6CB8CDA1,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DDAB
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$ErrorLastManager
              • String ID:
              • API String ID: 3671606724-0
              • Opcode ID: 6b1fbf34680aeb4d3b33dcad6f1c494f07ef7b0d7f70c961f222bf4d42fb7598
              • Instruction ID: 708de691148e722b95779c2817a56071eae40f1382418ce31fcd1abb02c8896e
              • Opcode Fuzzy Hash: 6b1fbf34680aeb4d3b33dcad6f1c494f07ef7b0d7f70c961f222bf4d42fb7598
              • Instruction Fuzzy Hash: 0821B2716423659AFB169B749C88BEE737DEF45704F00019BA905A2681DB70DD88CB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001,?,?,?,6CB8D0A6,?,?,6CB8CBC8,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8D9A5
              • OpenServiceW.ADVAPI32(00000000,?,00000001,?,?,6CB8D0A6,?,?,6CB8CBC8,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8D9D0
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D0A6,?,?,6CB8CBC8,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DA4E
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D0A6,?,?,6CB8CBC8,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DA63
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$ErrorLastManager
              • String ID:
              • API String ID: 3671606724-0
              • Opcode ID: e85d9a164d2d0778463e142ba80391d9c70d87462b2fa755bf698bbd724d83df
              • Instruction ID: efc2f9ef744a8de1ca27045dcf4f27e784a398adbfb35e6c2dccf4443d347187
              • Opcode Fuzzy Hash: e85d9a164d2d0778463e142ba80391d9c70d87462b2fa755bf698bbd724d83df
              • Instruction Fuzzy Hash: 3B21F7316423659BFF158B70DC88EEE737DEF45B08F10019BAA06A2681DB74DD48CA61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CloseHandle.KERNEL32(?,00000000,00000000,?,6CBB2A0A,00000000,6CC05493,?,?,6CBAE25B,?,6CC05493,?,?,?,6CC05493), ref: 6CBB28C9
              • CloseHandle.KERNEL32(?,00000000,00000000,?,6CBB2A0A,00000000,6CC05493,?,?,6CBAE25B,?,6CC05493,?,?,?,6CC05493), ref: 6CBB28E1
              • CreateThread.KERNEL32(00000000,00000000,6CBB2C0F,00000000,00000000,00000000), ref: 6CBB2926
              • CloseHandle.KERNEL32(?,?,6CBB2A0A,00000000,6CC05493,?,?,6CBAE25B,?,6CC05493,?,?,?,6CC05493,?,?), ref: 6CBB293A
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandle$CreateThread
              • String ID:
              • API String ID: 395514555-0
              • Opcode ID: f7473a554617ac1353231c004985d6730d3983a38656136a2837f44a5be4a054
              • Instruction ID: 7efb88f8cb1f31f7709b93a7dc6f010b4ae548378bd532a1fb7f35fc74a89680
              • Opcode Fuzzy Hash: f7473a554617ac1353231c004985d6730d3983a38656136a2837f44a5be4a054
              • Instruction Fuzzy Hash: 162162353027459F97248F5AC95C96BB7F9FF89615320452DEC9AD7B04CB30E801CA62
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetLengthSid.ADVAPI32(6CB6B77E,00000220,6CB6B77A,00000000,?,?,?,80004005,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AB19
                • Part of subcall function 6CB6AC65: GetSecurityDescriptorControl.ADVAPI32(00000000,?,?,00000000,00000000), ref: 6CB6AC89
                • Part of subcall function 6CB6AC65: MakeAbsoluteSD.ADVAPI32(00000000,00000000,?,00000000,?,00000000,?,00000000,?,00000000,?), ref: 6CB6ACCF
                • Part of subcall function 6CB6AC65: GetLastError.KERNEL32 ref: 6CB6ACD5
              • GetSecurityDescriptorGroup.ADVAPI32(?,00000000,6CB6B77A,6CB6B77A,00000000,?,?,?,80004005,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AAEF
                • Part of subcall function 6CB67319: GetLastError.KERNEL32(6CB67628,?,?,?,6CB67B0C,?,00000000,?,6CB6A7D7,?,?,00000000,00000000,00000000,00000000,?), ref: 6CB67319
                • Part of subcall function 6CCC972C: _free.LIBCMT ref: 6CCC973F
              • CopySid.ADVAPI32(6CB6B77A,00000000,6CB6B77E,?,?,?,80004005,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AB3B
              • SetSecurityDescriptorGroup.ADVAPI32(?,00000000,00000000,?,?,80004005,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AB4C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DescriptorSecurity$ErrorGroupLast$AbsoluteControlCopyLengthMake_free
              • String ID:
              • API String ID: 4151187831-0
              • Opcode ID: 7b7e4c9b2fcc9d6c50beb60b979f94421014e8387d18739a3e8c58903350db30
              • Instruction ID: f6bc8809a6d958adc61bce99b7fb58aefb28f35116d995ead76a7546c1eb711d
              • Opcode Fuzzy Hash: 7b7e4c9b2fcc9d6c50beb60b979f94421014e8387d18739a3e8c58903350db30
              • Instruction Fuzzy Hash: 0A110631200260ABEF059BF6CC48EAF77AEDF41668B144019E505E2E40EFB0E804CEB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetLengthSid.ADVAPI32(6CB6B77E,00000220,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A), ref: 6CB6AA5D
                • Part of subcall function 6CB6AC65: GetSecurityDescriptorControl.ADVAPI32(00000000,?,?,00000000,00000000), ref: 6CB6AC89
                • Part of subcall function 6CB6AC65: MakeAbsoluteSD.ADVAPI32(00000000,00000000,?,00000000,?,00000000,?,00000000,?,00000000,?), ref: 6CB6ACCF
                • Part of subcall function 6CB6AC65: GetLastError.KERNEL32 ref: 6CB6ACD5
              • GetSecurityDescriptorOwner.ADVAPI32(?,?,6CB6B77A,00000000,6CD3E5F4,00000000,00000000,?,6CB6B77A,?,00000220,?,10000000,00000000), ref: 6CB6AA33
                • Part of subcall function 6CB67319: GetLastError.KERNEL32(6CB67628,?,?,?,6CB67B0C,?,00000000,?,6CB6A7D7,?,?,00000000,00000000,00000000,00000000,?), ref: 6CB67319
                • Part of subcall function 6CCC972C: _free.LIBCMT ref: 6CCC973F
              • CopySid.ADVAPI32(6CB6B77A,00000000,6CB6B77E,?,6CB6B77A), ref: 6CB6AA7F
              • SetSecurityDescriptorOwner.ADVAPI32(?,00000000,00000000,6CB6B77A), ref: 6CB6AA90
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DescriptorSecurity$ErrorLastOwner$AbsoluteControlCopyLengthMake_free
              • String ID:
              • API String ID: 491665698-0
              • Opcode ID: 6d4cd8f4fa7e68ccd6a941c5c94a3ee00e6856a6734f00a60974fe34dc9b6303
              • Instruction ID: d5b5b8283a667c99a02a2447af958634256916364aeee2fa9230512ffea7db55
              • Opcode Fuzzy Hash: 6d4cd8f4fa7e68ccd6a941c5c94a3ee00e6856a6734f00a60974fe34dc9b6303
              • Instruction Fuzzy Hash: 7211D3322002A4BBEF019BA6CE48EAF77ADDF41658B10401EB515E6E80EF70D904CEB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • WaitForMultipleObjects.KERNEL32(?,?,00000001,6CC3E23C,?,?,?,?,6CC3E23C,00000000,?,?,?,?,?,6CC3E0E1), ref: 6CB6D609
              • GetTickCount.KERNEL32 ref: 6CB6D615
              • WaitForMultipleObjects.KERNEL32(?,6CC3E23C,00000001,6CC3E23C,?,?,6CC3E23C,00000000,?,?,?,?,?,6CC3E0E1,00000000,00000000), ref: 6CB6D644
              • GetTickCount.KERNEL32 ref: 6CB6D675
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CountMultipleObjectsTickWait
              • String ID:
              • API String ID: 2792316827-0
              • Opcode ID: 29b3e0b893522781b6fe3be87ef86154e5b31239cf07bf0bfe9ac83593d4106e
              • Instruction ID: b2fd92639f4072d2460a19acb81dc1132d2b14975cc4d4e95e320ed5a140bb5b
              • Opcode Fuzzy Hash: 29b3e0b893522781b6fe3be87ef86154e5b31239cf07bf0bfe9ac83593d4106e
              • Instruction Fuzzy Hash: 5F21F331704284AFDF009F7DD884BAC7BB9EF46358F204129F16A979C0D77185858B56
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • QueryUnbiasedInterruptTime.KERNEL32(00000000), ref: 6CBE7937
              • WaitForSingleObject.KERNEL32(?,?), ref: 6CBE794E
              • QueryUnbiasedInterruptTime.KERNEL32(00000000), ref: 6CBE798D
              • Concurrency::cancel_current_task.LIBCPMT ref: 6CBE79C1
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: InterruptQueryTimeUnbiased$Concurrency::cancel_current_taskObjectSingleWait
              • String ID:
              • API String ID: 3236327365-0
              • Opcode ID: af59255d3e1513c22d9c47baa18ed9d9e8d8406c657769df7ad7db4a50e22d83
              • Instruction ID: 87a61dc1b07d6871585f1c71a7a6f8d0a2fdab00f469e8ade29d797b9a67bbf8
              • Opcode Fuzzy Hash: af59255d3e1513c22d9c47baa18ed9d9e8d8406c657769df7ad7db4a50e22d83
              • Instruction Fuzzy Hash: 27218479A0124AFFDF00DF98C544BEEBBB8FF49749F244059D850A7641D774AA08CBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,6CBC5639), ref: 6CBC5673
              • LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,6CBC5639), ref: 6CBC56B1
              • UnregisterWaitEx.KERNEL32(?,000000FF,?,?,?,?,?,6CBC5639), ref: 6CBC56C0
              • CloseHandle.KERNEL32(?,?,?,?,?,6CBC5639), ref: 6CBC56EF
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$CloseEnterHandleLeaveUnregisterWait
              • String ID:
              • API String ID: 776973864-0
              • Opcode ID: 2efce34245ddaec1ab9eb79889359a330dd2035971629d4de3e231821751329a
              • Instruction ID: 23ca8bb32d6a6f15022f2b368254716b9cc755a3f169594f68f071c8d7a21bf1
              • Opcode Fuzzy Hash: 2efce34245ddaec1ab9eb79889359a330dd2035971629d4de3e231821751329a
              • Instruction Fuzzy Hash: DF21F371704600EFDB08CF1CD84485AB7B8EF45328334866DE4199BB91DB31EC01DBA6
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001,?,?,?,6CB8D503,?,?,?,?,?,6CB8CDB4,?,?,00000BB8), ref: 6CB8DDE1
              • OpenServiceW.ADVAPI32(00000000,?,00000001,?,?,6CB8D503,?,?,?,?,?,6CB8CDB4,?,?,00000BB8,00000000), ref: 6CB8DE0C
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D503,?,?,?,?,?,6CB8CDB4,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DE68
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D503,?,?,?,?,?,6CB8CDB4,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DE7D
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$ErrorLastManager
              • String ID:
              • API String ID: 3671606724-0
              • Opcode ID: 14b89bc1d9dd523ebb46fb26cd41ce2e32b47f3048ac4e6371be0bc830e36fb2
              • Instruction ID: c8f56f5f8f8748bb26b99baad27032ffffbcdd8c8445ea777bdec875d7c21193
              • Opcode Fuzzy Hash: 14b89bc1d9dd523ebb46fb26cd41ce2e32b47f3048ac4e6371be0bc830e36fb2
              • Instruction Fuzzy Hash: 7911D631A413689BFF129B64DCC8EEE737DDF45719F0000A7A605A2681DB30DD44CA72
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001,?,?,?,6CB8D1D5,?,?,?,?,?,6CB8CBDB,?,?,00000BB8), ref: 6CB8DA99
              • OpenServiceW.ADVAPI32(00000000,?,00000001,?,?,6CB8D1D5,?,?,?,?,?,6CB8CBDB,?,?,00000BB8,00000000), ref: 6CB8DAC4
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D1D5,?,?,?,?,?,6CB8CBDB,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DB20
              • CloseServiceHandle.ADVAPI32(00000000,?,6CB8D1D5,?,?,?,?,?,6CB8CBDB,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8DB35
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$ErrorLastManager
              • String ID:
              • API String ID: 3671606724-0
              • Opcode ID: c0be37189733754dc9f23924f09726bf4f411c8e44f385989fd7300bb6dab2d3
              • Instruction ID: 37ab7c8111dfbc319640c4f19e045b3659a663cbf165fd6e0135675a9da1261c
              • Opcode Fuzzy Hash: c0be37189733754dc9f23924f09726bf4f411c8e44f385989fd7300bb6dab2d3
              • Instruction Fuzzy Hash: 1D119631A413659BFB169BA49C88FEE737CEF45B18F0001A7A605A2681DB70DD44CA71
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB7605C: GetModuleHandleW.KERNEL32(kernel32.dll,6CB760E2,00000000,00000000,00000000,00000000,00000000,00000000,?,6CB7886D,?,00000000), ref: 6CB76061
                • Part of subcall function 6CB7605C: GetProcAddress.KERNEL32(00000000,WTSGetActiveConsoleSessionId), ref: 6CB7606D
              • WTSQuerySessionInformationW.WTSAPI32(00000000,00000000,00000008,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,6CB7886D,?,00000000), ref: 6CB760FF
              • WTSFreeMemory.WTSAPI32(?), ref: 6CB7610F
              • WTSEnumerateSessionsW.WTSAPI32(00000000,00000000,00000001,00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,?,6CB7886D,?,00000000), ref: 6CB76131
              • WTSFreeMemory.WTSAPI32(?), ref: 6CB7615F
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeMemory$AddressEnumerateHandleInformationModuleProcQuerySessionSessions
              • String ID:
              • API String ID: 413563643-0
              • Opcode ID: aaddbfff79a7040f840dd3c459dc85dfc6b1851860e07cb278f02ed3a888c2e3
              • Instruction ID: 5dd2fcc1fb2e520ae0b5cba8b1cbb813ba8bb9b009687b3f227d942fdc815b5f
              • Opcode Fuzzy Hash: aaddbfff79a7040f840dd3c459dc85dfc6b1851860e07cb278f02ed3a888c2e3
              • Instruction Fuzzy Hash: C4119671B41518ABDB20DF99C84899FBBBCEB45754F104169E921D7A42D730DA04CBB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SetLastError.KERNEL32(00000000,?,?,UpdaterRunning), ref: 6CB80674
                • Part of subcall function 6CB8144E: CreateEventW.KERNEL32(?,00000001,00000000,?,?,6CC3E07C,?,?,?,?,?,6CC3E0B2,00000007,?,00000007,?), ref: 6CB8145B
                • Part of subcall function 6CB8144E: GetLastError.KERNEL32(?,?,6CC3E0B2,00000007,?,00000007,?,6CD7C950), ref: 6CB81468
              • GetLastError.KERNEL32 ref: 6CB8068D
              • CloseHandle.KERNEL32(?), ref: 6CB806A1
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ErrorLast$CloseCreateEventHandle
              • String ID: UpdaterRunning
              • API String ID: 1050354699-138061397
              • Opcode ID: bbaa604e3a6a0f038dc9b0997e08a914000925ef79e72858acc9e4561e0e6dd3
              • Instruction ID: 39d22a187886f48fb1232ffe5deb995c16885d0881d19e8dd6dcab0665db1865
              • Opcode Fuzzy Hash: bbaa604e3a6a0f038dc9b0997e08a914000925ef79e72858acc9e4561e0e6dd3
              • Instruction Fuzzy Hash: 7911AF36A01288AFDF04DFA9C8A4ADCB7B4EFA5318F100469D512A7B94DF309E0DCB11
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • std::_Lockit::_Lockit.LIBCPMT ref: 6CBA5AFB
              • int.LIBCPMT ref: 6CBA5B0E
                • Part of subcall function 6CB847E1: std::_Lockit::_Lockit.LIBCPMT ref: 6CB847F2
                • Part of subcall function 6CB847E1: std::_Lockit::~_Lockit.LIBCPMT ref: 6CB8480C
              • std::_Facet_Register.LIBCPMT ref: 6CBA5B41
              • std::_Lockit::~_Lockit.LIBCPMT ref: 6CBA5B57
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
              • String ID:
              • API String ID: 459529453-0
              • Opcode ID: 422ecae361fb9d8971b2b001ead9f9fcfefb264abb9e0050f01b45b55b945349
              • Instruction ID: 542b747a6537b44e00d9fb0d878e6e1a864d4ea3179fcd07f4f76966746a33cd
              • Opcode Fuzzy Hash: 422ecae361fb9d8971b2b001ead9f9fcfefb264abb9e0050f01b45b55b945349
              • Instruction Fuzzy Hash: 25112932504558BBCB059FD4D814CDD776CDF40764B100204F915ABB90EB30EF0A8B95
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB8DDC2: OpenSCManagerW.ADVAPI32(00000000,00000000,00000001,?,?,?,6CB8D503,?,?,?,?,?,6CB8CDB4,?,?,00000BB8), ref: 6CB8DDE1
              • OpenSCManagerW.ADVAPI32(00000000,00000000,000F003F,?,?,?,?,?,6CB8CDB4,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8D510
              • OpenServiceW.ADVAPI32(00000000,6CB8CDB4,00000002,?,?,6CB8CDB4,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8D533
              • CloseServiceHandle.ADVAPI32(00000000,?,?,6CB8CDB4,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8D563
              • CloseServiceHandle.ADVAPI32(00000000,?,?,6CB8CDB4,?,?,00000BB8,00000000,00000000,00000000), ref: 6CB8D575
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: OpenService$CloseHandleManager$ErrorLast
              • String ID:
              • API String ID: 347107144-0
              • Opcode ID: e55ce75563c1af6714b2f72953b3f66588afc150a6b0f7f4e3138e425204aec8
              • Instruction ID: fb086e3361452c9cf4850f80507f5859ccd5198e764a35ef890662e65ecd36f7
              • Opcode Fuzzy Hash: e55ce75563c1af6714b2f72953b3f66588afc150a6b0f7f4e3138e425204aec8
              • Instruction Fuzzy Hash: 6E018875742296ABDB029BB49884AEE377CDF4575DF100067AA01A3A80DB70CE099662
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: lstrcmpi
              • String ID: arm64$x64$x86
              • API String ID: 1586166983-280937049
              • Opcode ID: 483f51dd30f43a8c6decafadd2a62de7649a8296de4581c13eb976f0a9f235c5
              • Instruction ID: d47baa414adf61705815079f9e690a0629a82c48c42a4e4a28f2b02ac66cb27d
              • Opcode Fuzzy Hash: 483f51dd30f43a8c6decafadd2a62de7649a8296de4581c13eb976f0a9f235c5
              • Instruction Fuzzy Hash: 7E01F732649172AAB7045EAEDC00CCF7369DF0226D330952AD590E6E50FF219C1A8AA6
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • VerSetConditionMask.KERNEL32(00000000,00000000,00000002,00000001,00000000,00000000,00000000), ref: 6CB735EC
              • VerSetConditionMask.KERNEL32(00000000,?,00000001,00000001), ref: 6CB735F2
              • VerSetConditionMask.KERNEL32(00000000,?,00000004,00000001,?,00000001,00000001), ref: 6CB735F9
              • VerifyVersionInfoW.KERNEL32(?,00000007,00000000), ref: 6CB73606
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ConditionMask$InfoVerifyVersion
              • String ID:
              • API String ID: 2793162063-0
              • Opcode ID: 7d44c71a9c8aa1abd5ee05d2dc8158a7b8e23aea3631548470544ff2a09501ae
              • Instruction ID: b41c738543c769c639c2d21bd5aa2b2c56b2f36a233714ce378b6a750ab3ebcd
              • Opcode Fuzzy Hash: 7d44c71a9c8aa1abd5ee05d2dc8158a7b8e23aea3631548470544ff2a09501ae
              • Instruction Fuzzy Hash: 3B0129B1F002187EEB209F669C49FEBBBBCEBC5754F40449EB505D3140DA749D548EA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcess.KERNEL32 ref: 6CB745B9
              • OpenProcessToken.ADVAPI32(00000000,00000008,?), ref: 6CB745C6
              • GetTokenInformation.ADVAPI32(?,00000012(TokenIntegrityLevel),00000001,00000004,?), ref: 6CB745E9
              • CloseHandle.KERNEL32(00000000), ref: 6CB7461A
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ProcessToken$CloseCurrentHandleInformationOpen
              • String ID:
              • API String ID: 215268677-0
              • Opcode ID: 8bf5a6b7de3694dddfb04c0ce85fb9f45765b1963ba8325ce2c9f961a5dbc129
              • Instruction ID: 1ff7beccc1a57ed0d53a53cecfde91e3a88b231521f7230af859e464d42c92e0
              • Opcode Fuzzy Hash: 8bf5a6b7de3694dddfb04c0ce85fb9f45765b1963ba8325ce2c9f961a5dbc129
              • Instruction Fuzzy Hash: 5D116530A45248FFEF209FA48945BEDBBB8EF0634AF1004A99961E3591D770CA44DF71
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenProcess.KERNEL32(00000400,00000000), ref: 6CBC36AD
              • OpenProcessToken.ADVAPI32(00000000,00000008,00000000), ref: 6CBC36D4
              • CloseHandle.KERNEL32(00000000), ref: 6CBC3728
              • CloseHandle.KERNEL32(?), ref: 6CBC372D
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandleOpenProcess$Token
              • String ID:
              • API String ID: 2894334456-0
              • Opcode ID: b5f9fe675d6683c5f5d83e445d84726c990b199b9879029ab161a08134c399a6
              • Instruction ID: 97aff2fd11bb5b69469ceb0eb769a97e4c63e29b351747299df1e479d6fd0348
              • Opcode Fuzzy Hash: b5f9fe675d6683c5f5d83e445d84726c990b199b9879029ab161a08134c399a6
              • Instruction Fuzzy Hash: 2111AD71B04248FBEF00ABA5CC84FEDB779EFA4309F504568D501A7A90EB309E09CB55
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • VerSetConditionMask.KERNEL32(00000000,00000000,00000002,00000003,00000000,00000000,00000000), ref: 6CB7348B
              • VerSetConditionMask.KERNEL32(00000000,?,00000001,00000003), ref: 6CB73493
              • VerSetConditionMask.KERNEL32(00000000,?,00000004,00000003,?,00000001,00000003), ref: 6CB7349B
              • VerifyVersionInfoW.KERNEL32(?,00000007,00000000), ref: 6CB734A8
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ConditionMask$InfoVerifyVersion
              • String ID:
              • API String ID: 2793162063-0
              • Opcode ID: ed2e5253d6450cc464bc285cccd06ef5e5b3cbe2db335148cdc45797d417c00c
              • Instruction ID: 07b15384422414502b80b00b8df14a14257db832169d92d66def45692c4bd355
              • Opcode Fuzzy Hash: ed2e5253d6450cc464bc285cccd06ef5e5b3cbe2db335148cdc45797d417c00c
              • Instruction Fuzzy Hash: 370156B0F403187AFB209A659C45FEBBA7CDB45754F40009AB604A71C0D6B49E448AA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,000F003F,00000000,00000000,?,?,6CB8D5D1,?,00000000,?,?,?,6CB8CD3C,00000000,00000000), ref: 6CB8D46B
              • OpenServiceW.ADVAPI32(00000000,00000000,00010002,?,?,?,6CB8D5D1,?,00000000,?,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CB8D491
              • CloseServiceHandle.ADVAPI32(00000000,?,?,6CB8D5D1,?,00000000,?,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CB8D4D4
              • CloseServiceHandle.ADVAPI32(00000000,?,?,6CB8D5D1,?,00000000,?,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CB8D4DB
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$ErrorLastManager
              • String ID:
              • API String ID: 3671606724-0
              • Opcode ID: 1d0cc71dc4b9c28da1dafe01218bac00825178b0544f863352b74c21269a7e00
              • Instruction ID: 658b371fce5e0763d0ddc83f88cbd6fe9ce623dac3f35aebf5b1ea4788aa9650
              • Opcode Fuzzy Hash: 1d0cc71dc4b9c28da1dafe01218bac00825178b0544f863352b74c21269a7e00
              • Instruction Fuzzy Hash: EB01FC313811A1ABE71217B59C88AEE3578DF4A75DB14012BEE06E7B40DB619C048272
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenProcess.KERNEL32(00000440,00000001,00000000,?,00000000,?,00000000,?,6CB789FA,?,00000000,?,6CB7692A,?,?), ref: 6CB758F5
              • OpenProcessToken.ADVAPI32(00000000,0000000A,00000000,?,6CB789FA,?,00000000,?,6CB7692A,?,?), ref: 6CB75916
              • CloseHandle.KERNEL32(00000000,?,6CB789FA,?,00000000,?,6CB7692A,?,?), ref: 6CB7594B
              • CloseHandle.KERNEL32(00000000,?,6CB789FA,?,00000000,?,6CB7692A,?,?), ref: 6CB7594E
                • Part of subcall function 6CB781C1: GetLastError.KERNEL32(?,6CB6CC5F,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB781C2
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseHandleOpenProcess$ErrorLastToken
              • String ID:
              • API String ID: 2985633847-0
              • Opcode ID: 42ef0bc5e33630bead04b1310cfb560a8757864b302b73061ce6893cb8add7df
              • Instruction ID: 917ec9a0ac834ef66fef445921f47e61d2bde003272692c7ddef3ec176f6ca80
              • Opcode Fuzzy Hash: 42ef0bc5e33630bead04b1310cfb560a8757864b302b73061ce6893cb8add7df
              • Instruction Fuzzy Hash: A701AD30740259BBEB215A668C8AFAF3A7DDF867A9F100024FA10A6580EBB18D049375
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • std::_Lockit::_Lockit.LIBCPMT ref: 6CB868E0
              • int.LIBCPMT ref: 6CB868F3
                • Part of subcall function 6CB847E1: std::_Lockit::_Lockit.LIBCPMT ref: 6CB847F2
                • Part of subcall function 6CB847E1: std::_Lockit::~_Lockit.LIBCPMT ref: 6CB8480C
              • std::_Facet_Register.LIBCPMT ref: 6CB86926
              • std::_Lockit::~_Lockit.LIBCPMT ref: 6CB8693C
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
              • String ID:
              • API String ID: 459529453-0
              • Opcode ID: e8003ab6cba8cec23dcbbe91ac5b76d8484ee762e0d93bca3bfb5c3bd7e4a2f1
              • Instruction ID: fffb05a182c40d686697bc19a780fb7054db871358ac126fd1522c867c3818c5
              • Opcode Fuzzy Hash: e8003ab6cba8cec23dcbbe91ac5b76d8484ee762e0d93bca3bfb5c3bd7e4a2f1
              • Instruction Fuzzy Hash: 8F01F772901064ABCB059B94C9149DE777CDF85628B200118E915ABB80FB30DE05CBD1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • std::_Lockit::_Lockit.LIBCPMT ref: 6CB86867
              • int.LIBCPMT ref: 6CB8687A
                • Part of subcall function 6CB847E1: std::_Lockit::_Lockit.LIBCPMT ref: 6CB847F2
                • Part of subcall function 6CB847E1: std::_Lockit::~_Lockit.LIBCPMT ref: 6CB8480C
              • std::_Facet_Register.LIBCPMT ref: 6CB868AD
              • std::_Lockit::~_Lockit.LIBCPMT ref: 6CB868C3
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
              • String ID:
              • API String ID: 459529453-0
              • Opcode ID: 6df5326ae79307708a9f36a8ee6d7ccbbb94e3b447252882162a332afe7ffb5b
              • Instruction ID: cf184602732490fee7cba82f2a494d2c32ad81e99323a84ab2b18bd58768d5d7
              • Opcode Fuzzy Hash: 6df5326ae79307708a9f36a8ee6d7ccbbb94e3b447252882162a332afe7ffb5b
              • Instruction Fuzzy Hash: 80012632A01124ABCB058BA4D958DDE777CDF41768F20011AE915EBB80FF30EE4A8BD1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • std::_Lockit::_Lockit.LIBCPMT ref: 6CBD46C4
              • int.LIBCPMT ref: 6CBD46D7
                • Part of subcall function 6CB847E1: std::_Lockit::_Lockit.LIBCPMT ref: 6CB847F2
                • Part of subcall function 6CB847E1: std::_Lockit::~_Lockit.LIBCPMT ref: 6CB8480C
              • std::_Facet_Register.LIBCPMT ref: 6CBD470A
              • std::_Lockit::~_Lockit.LIBCPMT ref: 6CBD4720
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
              • String ID:
              • API String ID: 459529453-0
              • Opcode ID: 31f6ba5bdccbc770608c4510c8b1719c4f623a11f26b2c9e98fe8fcee7b1b5ed
              • Instruction ID: ddc13b8415903a3aef4d4592e97aa0678e1a2c438b893a28864b22069fae37cb
              • Opcode Fuzzy Hash: 31f6ba5bdccbc770608c4510c8b1719c4f623a11f26b2c9e98fe8fcee7b1b5ed
              • Instruction Fuzzy Hash: 3D012632901168ABCB059B94D854CDE77BCEF42768B210158E912BBB80EB30FE06CFD1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • std::_Lockit::_Lockit.LIBCPMT ref: 6CB867D9
              • int.LIBCPMT ref: 6CB867EC
                • Part of subcall function 6CB847E1: std::_Lockit::_Lockit.LIBCPMT ref: 6CB847F2
                • Part of subcall function 6CB847E1: std::_Lockit::~_Lockit.LIBCPMT ref: 6CB8480C
              • std::_Facet_Register.LIBCPMT ref: 6CB8681F
              • std::_Lockit::~_Lockit.LIBCPMT ref: 6CB86835
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_Register
              • String ID:
              • API String ID: 459529453-0
              • Opcode ID: 0330eb410798ce5f7436bd319f9449f9ed8fa544321c264409d856911966e17f
              • Instruction ID: da4e671dd4a4d15ccdf66fa30cf5f4c739bcb46653794a1bdf9f314067ac4724
              • Opcode Fuzzy Hash: 0330eb410798ce5f7436bd319f9449f9ed8fa544321c264409d856911966e17f
              • Instruction Fuzzy Hash: 85012632902168ABCB058B94C8258DE7BBCDF81368F600119E815ABB80FF30EE45CBD1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetTickCount.KERNEL32 ref: 6CB8ABAD
              • SetEvent.KERNEL32(?,?,6CB8AA98,?,00000000,6CB66D84,00000000,00000000), ref: 6CB8ABB9
              • Sleep.KERNEL32(00000001,?,6CB8AA98,?,00000000,6CB66D84,00000000,00000000), ref: 6CB8ABC9
              • GetTickCount.KERNEL32 ref: 6CB8ABD5
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CountTick$EventSleep
              • String ID:
              • API String ID: 1938429519-0
              • Opcode ID: f28c931b6d589041a6fac97161ae4f015c2b44c447d94c59873a39d11e1d3308
              • Instruction ID: 51e265c8bb9cc8a75d9947e94211a7b68cb79708be7fb05bfd1d7d3d77dac671
              • Opcode Fuzzy Hash: f28c931b6d589041a6fac97161ae4f015c2b44c447d94c59873a39d11e1d3308
              • Instruction Fuzzy Hash: 8001A431709205AFDF148FF8C848A6D77FAEF86725F14862DE696936C0DB749881CE11
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcess.KERNEL32 ref: 6CB744CC
              • OpenProcessToken.ADVAPI32(00000000,00020008,?), ref: 6CB744DC
              • GetTokenInformation.ADVAPI32(?,00000012(TokenIntegrityLevel),00000001,00000004,?), ref: 6CB744FF
              • CloseHandle.KERNEL32(00000000), ref: 6CB7451A
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ProcessToken$CloseCurrentHandleInformationOpen
              • String ID:
              • API String ID: 215268677-0
              • Opcode ID: 4c1f910a4f619045f2581c6ee01574a6ceaee738b4707dcf29675db922a3c3bc
              • Instruction ID: bdff61f01ec76e9cf2476ee7cd928cae5ea99939d77144c57cd43c1fcb3ba6ac
              • Opcode Fuzzy Hash: 4c1f910a4f619045f2581c6ee01574a6ceaee738b4707dcf29675db922a3c3bc
              • Instruction Fuzzy Hash: 97011274A01208FFEF109F90CD85BEDB778EB0530AF105099EA21A2581D7719B44DF21
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • WTSQuerySessionInformationW.WTSAPI32(00000000,000000FF,00000004,00000000,00000000,00000000,00000000), ref: 6CB7609C
              • WTSFreeMemory.WTSAPI32(?), ref: 6CB760AF
              • GetCurrentProcessId.KERNEL32(000000FF), ref: 6CB760BE
              • ProcessIdToSessionId.KERNEL32(00000000), ref: 6CB760C5
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ProcessSession$CurrentFreeInformationMemoryQuery
              • String ID:
              • API String ID: 1981977830-0
              • Opcode ID: 21f54802a9f19f23789aad455b40d1664fcf740fc54e45ab8fd7e7c0252263e0
              • Instruction ID: 3cd7af4b4e57fdc725ae777aa3f19fbe3556e7faa16f6fcf5354e61f6bbda17d
              • Opcode Fuzzy Hash: 21f54802a9f19f23789aad455b40d1664fcf740fc54e45ab8fd7e7c0252263e0
              • Instruction Fuzzy Hash: 3DF0ECB0A04208BBDF04DFB9D94999DBBBCEB09368B10869DE625E22D0D770D7058B15
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CloseHandle.KERNEL32(?,00000000,?,6CCA76ED,?,00000004,?,00000000,?,6CC0727F,-80000001,?,?,?,Software\Microsoft\EdgeUpdate\Clients\,-80000001), ref: 6CBC77CB
              • ResetEvent.KERNEL32(?,00000000,?,6CCA76ED,?,00000004,?,00000000,?,6CC0727F,-80000001,?,?,?,Software\Microsoft\EdgeUpdate\Clients\,-80000001), ref: 6CBC77D4
              • CreateThread.KERNEL32(00000000,00000000,6CBC7777,00000000,00000000,00000004), ref: 6CBC77EE
              • WaitForSingleObject.KERNEL32(?,000000FF,?,6CCA76ED,?,00000004,?,00000000,?,6CC0727F,-80000001,?,?,?,Software\Microsoft\EdgeUpdate\Clients\,-80000001), ref: 6CBC7804
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseCreateEventHandleObjectResetSingleThreadWait
              • String ID:
              • API String ID: 2727261149-0
              • Opcode ID: ab7a772ea4434aad70f7278aeb58819a4603c472bea88cc1f3b02a6ad188e101
              • Instruction ID: 0697514ba1b65c395ddde92282fc07269d8795e8284eec92188d4a3c04f7a30d
              • Opcode Fuzzy Hash: ab7a772ea4434aad70f7278aeb58819a4603c472bea88cc1f3b02a6ad188e101
              • Instruction Fuzzy Hash: 42F09A31304619BFEB104F39CC48DA77BACEB123617108A2AF6A6D29A0DB70A450CA51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • WriteConsoleW.KERNEL32(00000000,00000020,00000000,00000000,00000000,?,6CCE77C6,00000000,00000001,00000000,00000000,?,6CCE5ED6,?,00000000,00000000), ref: 6CCE8DDD
              • GetLastError.KERNEL32(?,6CCE77C6,00000000,00000001,00000000,00000000,?,6CCE5ED6,?,00000000,00000000,?,00000000,?,6CCE6422,6CCE26E7), ref: 6CCE8DE9
                • Part of subcall function 6CCE8DAF: CloseHandle.KERNEL32(FFFFFFFE,6CCE8DF9,?,6CCE77C6,00000000,00000001,00000000,00000000,?,6CCE5ED6,?,00000000,00000000,?,00000000), ref: 6CCE8DBF
              • ___initconout.LIBCMT ref: 6CCE8DF9
                • Part of subcall function 6CCE8D71: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,6CCE8DA0,6CCE77B3,00000000,?,6CCE5ED6,?,00000000,00000000,?), ref: 6CCE8D84
              • WriteConsoleW.KERNEL32(00000000,00000020,00000000,00000000,?,6CCE77C6,00000000,00000001,00000000,00000000,?,6CCE5ED6,?,00000000,00000000,?), ref: 6CCE8E0E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
              • String ID:
              • API String ID: 2744216297-0
              • Opcode ID: c12704ff6358b3dfa73afafc34b09f95727bc903291bb3a091590805265acd8b
              • Instruction ID: 7dbcd9707bda7edf450a4dacd89c6d46ab2d2f8755fc56692ea55e163deb1dfa
              • Opcode Fuzzy Hash: c12704ff6358b3dfa73afafc34b09f95727bc903291bb3a091590805265acd8b
              • Instruction Fuzzy Hash: EDF01C36204129BBDF121F99CC04D893F7AFB4B3B4F144565FA199A560D7328960DBA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001,?,?,?,6CB8D5A3,?,00000000,?,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CBC48CF
              • OpenServiceW.ADVAPI32(00000000,?,00000001,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CBC48DF
              • CloseServiceHandle.ADVAPI32(00000000,?,00000001,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CBC48F0
              • CloseServiceHandle.ADVAPI32(00000000,?,00000001,?,?,6CB8CD3C,00000000,00000000,00000000), ref: 6CBC48F5
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Service$CloseHandleOpen$Manager
              • String ID:
              • API String ID: 4196757001-0
              • Opcode ID: 65387b62d53e82bc3c35bae481b5688d4fd7ed9edec22f1a53dc2809bcf33fc9
              • Instruction ID: ad7fe75a41d8a86f76f4a8bef03425e3b40dcdddb7c3c33f4ccb762094d7e819
              • Opcode Fuzzy Hash: 65387b62d53e82bc3c35bae481b5688d4fd7ed9edec22f1a53dc2809bcf33fc9
              • Instruction Fuzzy Hash: 9DE086757426712AF91216664CCCEBB166DDFC2A66B151026F614D3240CEA5C84189B1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentThread.KERNEL32 ref: 6CB77EE5
              • OpenThreadToken.ADVAPI32(00000000,?,?,6CB77DE7), ref: 6CB77EEC
              • GetLastError.KERNEL32(?,?,6CB77DE7), ref: 6CB77EF6
              • CloseHandle.KERNEL32(000000FF,?,?,6CB77DE7), ref: 6CB77F10
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Thread$CloseCurrentErrorHandleLastOpenToken
              • String ID:
              • API String ID: 844391580-0
              • Opcode ID: 64e07dedeeb337548133e714d4205edcc1f538483ba9fb49f8a08e34f812e9d1
              • Instruction ID: 62616dba2e2a44926a7ce2acce7356c8f525dc122333aaa1172a8849331e332a
              • Opcode Fuzzy Hash: 64e07dedeeb337548133e714d4205edcc1f538483ba9fb49f8a08e34f812e9d1
              • Instruction Fuzzy Hash: 14E0ED30705248FBEF219FA4CA09B5A767CEB0676DF600794E632E61D1E7709601EB25
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SleepConditionVariableCS.KERNELBASE(?,6CCB0F8E,00000064), ref: 6CCB1014
              • LeaveCriticalSection.KERNEL32(6CD7B10C,00C4EE10,?,6CCB0F8E,00000064,?,6CB669A5,6CD7C588,?,?,6CB69D97,kernel32.dll,6CB72A76,00C4EE10,kernel32.dll,EdgeUpdateDllVersion), ref: 6CCB101E
              • WaitForSingleObjectEx.KERNEL32(00C4EE10,00000000,?,6CCB0F8E,00000064,?,6CB669A5,6CD7C588,?,?,6CB69D97,kernel32.dll,6CB72A76,00C4EE10,kernel32.dll,EdgeUpdateDllVersion), ref: 6CCB102F
              • EnterCriticalSection.KERNEL32(6CD7B10C,?,6CCB0F8E,00000064,?,6CB669A5,6CD7C588,?,?,6CB69D97,kernel32.dll,6CB72A76,00C4EE10,kernel32.dll,EdgeUpdateDllVersion,6CB6DBEE), ref: 6CCB1036
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CriticalSection$ConditionEnterLeaveObjectSingleSleepVariableWait
              • String ID:
              • API String ID: 3269011525-0
              • Opcode ID: d266e908505e279570ba0ba6da073cfbe069f9e5f1995a99493c6822f61e871b
              • Instruction ID: 5cf80f53beae58859515b8efdecc95c58e2c2ff37951c8fa3cbbe1829146a456
              • Opcode Fuzzy Hash: d266e908505e279570ba0ba6da073cfbe069f9e5f1995a99493c6822f61e871b
              • Instruction Fuzzy Hash: 51E01231745524BBEE122F98DC08A8A3F3CEB0B661B800017FF4566691C73159519BE5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CBB099B
              • SysFreeString.OLEAUT32(?), ref: 6CBB09A0
              • SysFreeString.OLEAUT32(?), ref: 6CBB09A5
              • SysFreeString.OLEAUT32(?), ref: 6CBB09AA
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID:
              • API String ID: 3341692771-0
              • Opcode ID: 5f9a34cc8f4a1d9911fb3cd9a9a6524c45291eaa84d2649382e973e6ff11fcc3
              • Instruction ID: 30fc94fc989906cd9e9bd0a2414080d272e96bf76cc54535b61ead105d9532b9
              • Opcode Fuzzy Hash: 5f9a34cc8f4a1d9911fb3cd9a9a6524c45291eaa84d2649382e973e6ff11fcc3
              • Instruction Fuzzy Hash: DDD09E3650046ABBDB525B26ED05889FF69FF9927131040379114428309BB1B831EFD0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CB90222
              • SysFreeString.OLEAUT32(?), ref: 6CB90227
              • SysFreeString.OLEAUT32(?), ref: 6CB9022C
              • SysFreeString.OLEAUT32(?), ref: 6CB90231
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID:
              • API String ID: 3341692771-0
              • Opcode ID: 11672fe75b297b87cbd72640595abfdaeee32b2646dfb6354bb3975f8138e845
              • Instruction ID: 117f7263137f969ab05d50574c3ca89827c762f400ab548a4085b3536fb7f0c5
              • Opcode Fuzzy Hash: 11672fe75b297b87cbd72640595abfdaeee32b2646dfb6354bb3975f8138e845
              • Instruction Fuzzy Hash: CAD09E3661047ABBDA565B25ED058C9FF69FF952713405037D10442C309BB1B830DFD0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBA4E50: lstrcmpiW.KERNEL32(?,?), ref: 6CBA4E84
              • SysFreeString.OLEAUT32(?), ref: 6CBA4FE6
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeStringlstrcmpi
              • String ID: `)u$untrusted
              • API String ID: 1602765415-924011904
              • Opcode ID: e002b61c18dcee76f80d9a64085b92a501c37b1b9c10f71186425eefb02c6092
              • Instruction ID: 6e9d091beb5bd123714c2752d2e69048a7d369eac147bf76a306fa6d43d5a099
              • Opcode Fuzzy Hash: e002b61c18dcee76f80d9a64085b92a501c37b1b9c10f71186425eefb02c6092
              • Instruction Fuzzy Hash: B5A1AE329041959FCF04DFA8C8909EDB7B5EF44318B154069D856ABB90DF31EE0ECB91
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: __aulldvrm
              • String ID: +$-
              • API String ID: 1302938615-2137968064
              • Opcode ID: 161a09eff6b3ed1a0f7e4755718eb057f39716fab9f8bac8abe7887edf0302c9
              • Instruction ID: 6636f6a64bc5f7341ef67be7516bc63c14fea01337e713584e4090253b36b137
              • Opcode Fuzzy Hash: 161a09eff6b3ed1a0f7e4755718eb057f39716fab9f8bac8abe7887edf0302c9
              • Instruction Fuzzy Hash: 8B91F470B052599EDF10CEAAC8527EDBB74EF47328F14825EE870A7B91E33095058BD2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBDD3CA: GetCurrentThreadId.KERNEL32 ref: 6CBDD3DF
                • Part of subcall function 6CBDD3CA: EnterCriticalSection.KERNEL32(6CD7E054,?,6CBDF31E,?,?,?,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000), ref: 6CBDD3EE
                • Part of subcall function 6CBDD3CA: LeaveCriticalSection.KERNEL32(6CD7E054,?,6CBDF31E,?,?,?,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000), ref: 6CBDD403
                • Part of subcall function 6CC9EB39: FindResourceW.KERNEL32(02A60001,005D0065,00000005,6CD67530,0069006B,00000000,02A60001,02A60001,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?), ref: 6CC9EB53
                • Part of subcall function 6CC9EB39: FindResourceW.KERNEL32(02A60001,005D0065,000000F0,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB6B
                • Part of subcall function 6CC9EB39: LoadResource.KERNEL32(02A60001,00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB77
                • Part of subcall function 6CC9EB39: LockResource.KERNEL32(00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB7E
                • Part of subcall function 6CC9EB39: LoadResource.KERNEL32(02A60001,6CC9F9B7,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB8A
                • Part of subcall function 6CC9EB39: LockResource.KERNEL32(00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB95
                • Part of subcall function 6CC9EB39: GetLastError.KERNEL32(?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EBC4
                • Part of subcall function 6CC9EB39: GlobalHandle.KERNEL32(6CC9F9B7), ref: 6CC9EBD6
                • Part of subcall function 6CC9EB39: GlobalFree.KERNEL32(00000000), ref: 6CC9EBDD
                • Part of subcall function 6CC9EB39: SetLastError.KERNEL32(00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EBF2
              • DestroyWindow.USER32(?,00000000,?,00000000,?,?,00000001), ref: 6CC9FEA3
              • SetLastError.KERNEL32(?), ref: 6CC9FEAC
                • Part of subcall function 6CCA4868: GetWindowLongW.USER32(?,000000F0), ref: 6CCA48F1
                • Part of subcall function 6CB90E3D: QueryPerformanceCounter.KERNEL32(?,00000018,00000000,00000000,?,6CC06CE4,?,00000008,00000008,00000008,?,6CC07006,00000000,?,?,?), ref: 6CB90E49
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Resource$ErrorLast$CriticalFindGlobalLoadLockSectionWindow$CounterCurrentDestroyEnterFreeHandleLeaveLongPerformanceQueryThread
              • String ID: Segoe UI
              • API String ID: 2971571548-2515502724
              • Opcode ID: 3310bd3302d008c9cf4d467afde5e32eeb170cf696e702fcf34f41df620eb66b
              • Instruction ID: 5a8c8fa89098dad46432cd614f911c6a45be3aecdbc349c8d76f3067a6dcb356
              • Opcode Fuzzy Hash: 3310bd3302d008c9cf4d467afde5e32eeb170cf696e702fcf34f41df620eb66b
              • Instruction Fuzzy Hash: 92719571600215BFEB05ABB4CD45FDDBB79FF09300F000654F219A6990EBB0A928DB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CBDEA85
              • SysFreeString.OLEAUT32(?), ref: 6CBDEB43
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u
              • API String ID: 3341692771-4279031584
              • Opcode ID: 0cda1b2d6d895dab232cfa187cdafa732db430b42e89c2c238623f994e00d11a
              • Instruction ID: 54c47ca7c81fddc5e0185008c8833cb2488e7beb42c9477619bf28e14685a5ad
              • Opcode Fuzzy Hash: 0cda1b2d6d895dab232cfa187cdafa732db430b42e89c2c238623f994e00d11a
              • Instruction Fuzzy Hash: 1C7116715083819FC305CF29C4909AFFBE5FBC9608F114A6DF49A97690EB70E909CB92
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID:
              • String ID: PingXml$Xml
              • API String ID: 0-1367272966
              • Opcode ID: 9c21d1d01f80368aa78e1872b0f9f85bd97ddfa1fe1cf545e3da2963fa85c6f6
              • Instruction ID: 0ee68ca1fc20026207bfc7cbfc249308c016f6567ff9bbe7455f632589b3cb95
              • Opcode Fuzzy Hash: 9c21d1d01f80368aa78e1872b0f9f85bd97ddfa1fe1cf545e3da2963fa85c6f6
              • Instruction Fuzzy Hash: 63516A75E001698BDB24DF68CC80BDDB7B4AF45208F204099D56AA7751EF30AE8DCF61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(00000001), ref: 6CBDE4D9
              • SysFreeString.OLEAUT32(00000001), ref: 6CBDE54B
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u
              • API String ID: 3341692771-4279031584
              • Opcode ID: 81e4d096ba0db9fde204f1462947850e610fbae8f76b6ab7e1b2c905c11cd0b5
              • Instruction ID: 9f2337bce42b82c565459a1ce361189954ce62c97337a3f95b65d1646e8513aa
              • Opcode Fuzzy Hash: 81e4d096ba0db9fde204f1462947850e610fbae8f76b6ab7e1b2c905c11cd0b5
              • Instruction Fuzzy Hash: 63511735A0018AEFCF04DFA9C9948AEF7B5FF49318B1105A9E416A7750DB30BE15DB90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • PathFindFileNameW.SHLWAPI(?,6CD500D0,00000000,?,7508EB20,?,SOFTWARE\Clients\StartMenuInternet,00020019,?,?), ref: 6CBC3862
                • Part of subcall function 6CB6E978: GetFileAttributesExW.KERNEL32(?,00000000,?,?,?,?,6CB68F4E,?,?,6CB68315,00000000,?,?,00000000,?), ref: 6CB6E99C
                • Part of subcall function 6CB6E9B4: GetFileAttributesExW.KERNEL32(?,00000000,?,?,?,?,?,00000000,0000005C,00000000,?,?,00000000,000000FF,?,6CB7AC58), ref: 6CB6E9DE
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: File$Attributes$FindNamePath
              • String ID: .exe$HKCR\http\shell\open\command
              • API String ID: 2791384807-493838116
              • Opcode ID: 0f02aab358eba649ecf8f0121c92743fab3ee438a63040eafe77f9f78e6cdb2f
              • Instruction ID: 3efd2950a9a4b46c5ce7283d0c54d647a3ea0e7c7c91dcfdad9d39f876a13df4
              • Opcode Fuzzy Hash: 0f02aab358eba649ecf8f0121c92743fab3ee438a63040eafe77f9f78e6cdb2f
              • Instruction Fuzzy Hash: E941A331B00185DBDF04DBA9C8909ED7376EF8525DBA40169D412ABF90EF309E09C792
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBDD3CA: GetCurrentThreadId.KERNEL32 ref: 6CBDD3DF
                • Part of subcall function 6CBDD3CA: EnterCriticalSection.KERNEL32(6CD7E054,?,6CBDF31E,?,?,?,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000), ref: 6CBDD3EE
                • Part of subcall function 6CBDD3CA: LeaveCriticalSection.KERNEL32(6CD7E054,?,6CBDF31E,?,?,?,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000), ref: 6CBDD403
                • Part of subcall function 6CC9EB39: FindResourceW.KERNEL32(02A60001,005D0065,00000005,6CD67530,0069006B,00000000,02A60001,02A60001,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?), ref: 6CC9EB53
                • Part of subcall function 6CC9EB39: FindResourceW.KERNEL32(02A60001,005D0065,000000F0,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB6B
                • Part of subcall function 6CC9EB39: LoadResource.KERNEL32(02A60001,00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB77
                • Part of subcall function 6CC9EB39: LockResource.KERNEL32(00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB7E
                • Part of subcall function 6CC9EB39: LoadResource.KERNEL32(02A60001,6CC9F9B7,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB8A
                • Part of subcall function 6CC9EB39: LockResource.KERNEL32(00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EB95
                • Part of subcall function 6CC9EB39: GetLastError.KERNEL32(?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EBC4
                • Part of subcall function 6CC9EB39: GlobalHandle.KERNEL32(6CC9F9B7), ref: 6CC9EBD6
                • Part of subcall function 6CC9EB39: GlobalFree.KERNEL32(00000000), ref: 6CC9EBDD
                • Part of subcall function 6CC9EB39: SetLastError.KERNEL32(00000000,?,6CCA08F5,0069006B,?,?,6CD67538,6CD67530,?,6CD67530,6CD67530,6CD67530,?,6CC9F9B7), ref: 6CC9EBF2
              • DestroyWindow.USER32(?,?,?,00000000,?,?,6CD46550,00000010,00000000), ref: 6CCA047D
              • SetLastError.KERNEL32(?), ref: 6CCA0486
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Resource$ErrorLast$CriticalFindGlobalLoadLockSection$CurrentDestroyEnterFreeHandleLeaveThreadWindow
              • String ID: Segoe UI
              • API String ID: 304936100-2515502724
              • Opcode ID: 13a7f976f5609944f8f44d2cbdf4f18556263f5fac6d91ae3d14f7a80eba89f5
              • Instruction ID: 60e40bddbea7760ac7629a009fa18eeb3a8bb6f39957dfc039ff18a8e3409269
              • Opcode Fuzzy Hash: 13a7f976f5609944f8f44d2cbdf4f18556263f5fac6d91ae3d14f7a80eba89f5
              • Instruction Fuzzy Hash: 77417C71600145AFDF05DFA4CD89EDA7BB8FF09344F148168E90AAB691EB71ED09CB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: ClearVariant
              • String ID: `)u
              • API String ID: 1473721057-4279031584
              • Opcode ID: eddeefcfdb998d597cdcb5fc1a8873a0224c8baedda25dccec86ccb7ba27ff2c
              • Instruction ID: 57f10d9938bd0dddb1a39af8956bda3e332094afb38accadf46906e96a41b534
              • Opcode Fuzzy Hash: eddeefcfdb998d597cdcb5fc1a8873a0224c8baedda25dccec86ccb7ba27ff2c
              • Instruction Fuzzy Hash: 0941F479202255EBEF01DFA8C880E9E7BB8EF96364F208155F616DB690E730C942CB50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB77407: lstrlenW.KERNEL32(00000000,?,?,6CB76F35,00000000,00000000,00000001,00000000,?,00000000,00000000,?,00000000,00000000,00000001,00000000), ref: 6CB77410
                • Part of subcall function 6CB77407: RegSetValueExW.KERNELBASE(6CB76BD7,00000000,00000000,00000001,00000000,00000000,?,6CB76F35,00000000,00000000,00000001,00000000,?,00000000,00000000), ref: 6CB7742C
              • RegCloseKey.ADVAPI32(00000000,?), ref: 6CB9CDA4
                • Part of subcall function 6CB6C532: CharUpperW.USER32(?,?,?,?,?,?,?,6CB7A8B7,?,[rollback_to_target_version][%d],?,?,[target_version_prefix][%s],00000001,?,[target_channel][%s]), ref: 6CB6C569
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CharCloseUpperValuelstrlen
              • String ID: iid$lang
              • API String ID: 3247377250-63042105
              • Opcode ID: 317fd2951b0aaed46772bd5817f992c093a624872f66f088bef0f8b1abc8b677
              • Instruction ID: 0ba28b64aee3f29334b0ea4f6fc23f5cbc5ccf8f6217f4d6c1cc4c9091caf0c7
              • Opcode Fuzzy Hash: 317fd2951b0aaed46772bd5817f992c093a624872f66f088bef0f8b1abc8b677
              • Instruction Fuzzy Hash: CB4112712083859BCB05DF65C894EAEB7E9EF94308F40085DF99697BA1DB30990DCB92
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBADC71: RegCloseKey.ADVAPI32(00000000,00000000,6CC05A2D,00000007,?,00000000), ref: 6CBADD1A
              • _Deallocate.LIBCONCRT ref: 6CBDBF56
              Strings
              • MicrosoftEdgeUpdateBrowserReplacementTask, xrefs: 6CBDBEEC
              • {56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}, xrefs: 6CBDBE33, 6CBDBE7E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseDeallocate
              • String ID: MicrosoftEdgeUpdateBrowserReplacementTask${56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
              • API String ID: 1375891477-2776931268
              • Opcode ID: 240a67d6f3d173dc833d8e27b23918dfc95bae2e512cdde56098c4710604d492
              • Instruction ID: aaf43733fdd8c40230f861e26ee779604b69511a9df33575bc4eaf2959dab27e
              • Opcode Fuzzy Hash: 240a67d6f3d173dc833d8e27b23918dfc95bae2e512cdde56098c4710604d492
              • Instruction Fuzzy Hash: 7A41C433D01155ABCB04DBA8D4509EE77B5EF49728F210659D916B7BC0EB307E09CBA2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE2FE6
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE300A
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE302E
                • Part of subcall function 6CBE2F7C: VariantInit.OLEAUT32(?), ref: 6CBE3055
              • VariantClear.OLEAUT32(?), ref: 6CBE3B13
              • SysFreeString.OLEAUT32(00000000), ref: 6CBE3B75
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Variant$Init$ClearFreeString
              • String ID: `)u
              • API String ID: 3537580372-4279031584
              • Opcode ID: f4d8f9e7746b4b85e757560b2a343ff31eb0fae09bc6e980caacbf465d4c1d07
              • Instruction ID: 4b931335819ecffeabe93064ec07c0eb9fe58eef66b495eaf5cd6cd3667cb844
              • Opcode Fuzzy Hash: f4d8f9e7746b4b85e757560b2a343ff31eb0fae09bc6e980caacbf465d4c1d07
              • Instruction Fuzzy Hash: CF415B316043529FC701DF64C844A6BB7E9FFC8B65F108A5DF8959B260DB70E909CB92
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,00000000,00020019,HKLM\Software\Microsoft\EdgeUpdate\Clients\,00000000,00000000,00000000), ref: 6CBADE26
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\Clients\, xrefs: 6CBADD43, 6CBADD48
              • HKLM\Software\Microsoft\EdgeUpdate\Clients\, xrefs: 6CBADD3A
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\Clients\$HKLM\Software\Microsoft\EdgeUpdate\Clients\
              • API String ID: 3535843008-3607893972
              • Opcode ID: d941caca041d921df188b5f02a5ebaa66b027256fd87b49942e496fbbb8c05ac
              • Instruction ID: a5c4e8bbc89ab26573f783d7ae2fea82236b5a90b6251037282304457f49ad55
              • Opcode Fuzzy Hash: d941caca041d921df188b5f02a5ebaa66b027256fd87b49942e496fbbb8c05ac
              • Instruction Fuzzy Hash: 8E31B4329001599BCF00DFE8D850AEEB3B5EF55318F100169D861B7B90DB309E0ECBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DeallocateFreeString
              • String ID: `)u
              • API String ID: 1187328086-4279031584
              • Opcode ID: 94ee05ca25dca5840b83f3c28d5f9939e3aa377737149ab9a88193c502db44e4
              • Instruction ID: cd046fe63da9098dae33f25eb534ba08c740032b4f25aa070a053dcaafcaee2a
              • Opcode Fuzzy Hash: 94ee05ca25dca5840b83f3c28d5f9939e3aa377737149ab9a88193c502db44e4
              • Instruction Fuzzy Hash: CD31D771E04145AFDF04CFA9C8818AEB7B9EF89218B15017EE512E3B90EB31A904CB51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • QueryPerformanceCounter.KERNEL32(00000000,6CD7C950,?,6CBAF7D7,00000000,00000010,00000010,00000014,00000000,00000000,6CD219D0,00000000,?,?,?,00000000), ref: 6CBB0022
              Strings
              • [PackageCache::VerifyMicrosoftSignatureConditionally skipped due to override], xrefs: 6CBB000A
              • [PackageCache::VerifyMicrosoftSignatureConditionally][Failed for Win7SP1 or older][0x%08X][%s][Trusting by hash], xrefs: 6CBB007A
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CounterPerformanceQuery
              • String ID: [PackageCache::VerifyMicrosoftSignatureConditionally skipped due to override]$[PackageCache::VerifyMicrosoftSignatureConditionally][Failed for Win7SP1 or older][0x%08X][%s][Trusting by hash]
              • API String ID: 2783962273-1471585141
              • Opcode ID: 010357dd06eea49fdd0fa4821669c479264af4db12192f33daa3882e7eac59e5
              • Instruction ID: 5012a3fafb3037331ee3ece7d120db9ebf81f06f4b81f6fe0090efec19901233
              • Opcode Fuzzy Hash: 010357dd06eea49fdd0fa4821669c479264af4db12192f33daa3882e7eac59e5
              • Instruction Fuzzy Hash: A0213871D041D9AADF08DBB5D8429FD7B789F41318B14462DD521F3BD0DB348A088761
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CBACA70
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u$update3web-newapps
              • API String ID: 3341692771-2775769743
              • Opcode ID: cb93f3923286f275b23f2d18d7a4761050775e1cbbc5f5760a6a12b7be642629
              • Instruction ID: a5f451a87eb2a5be2c7f0a9804140b3a92ed25f9d6813c3c75d4edaf30fced28
              • Opcode Fuzzy Hash: cb93f3923286f275b23f2d18d7a4761050775e1cbbc5f5760a6a12b7be642629
              • Instruction Fuzzy Hash: 52218136A02515AFCB11DF98C454A9E7BB8FF497A472142A8F805EB720CB31DD06DBD0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDE691
                • Part of subcall function 6CBDD581: SysStringLen.OLEAUT32(00000000), ref: 6CBDD59D
                • Part of subcall function 6CBDD581: SysFreeString.OLEAUT32(00000000), ref: 6CBDD5BD
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDE688
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free
              • String ID: `)u
              • API String ID: 1391021980-4279031584
              • Opcode ID: dc16f699e994b727f945a96b6f1595d076f4a2665472e0a44e6e52e170e1c5d4
              • Instruction ID: 6824496495691cafb5f8877492ac1dbf5805a7943818d57045a2c30b32f741b0
              • Opcode Fuzzy Hash: dc16f699e994b727f945a96b6f1595d076f4a2665472e0a44e6e52e170e1c5d4
              • Instruction Fuzzy Hash: 60213C31A0015AEFCF04DFA4C894DEEBBB5FF59319F104558E416AB650DB30AE09CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\EdgeUpdate\ClientState\,00020019), ref: 6CB83F83
              Strings
              • HKCU\Software\Microsoft\EdgeUpdate\ClientState\, xrefs: 6CB83EE7
              • HKLM\Software\Microsoft\EdgeUpdate\ClientState\, xrefs: 6CB83EDE, 6CB83EF1
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: HKCU\Software\Microsoft\EdgeUpdate\ClientState\$HKLM\Software\Microsoft\EdgeUpdate\ClientState\
              • API String ID: 3535843008-3973816535
              • Opcode ID: e49c5a093c0a193095e6226fd28969db6786fba779d0b96324973e91b6d076d6
              • Instruction ID: 713d81f52bc1358ec81c05fd4361d01401c33e4dcb339f839a56bf95309dbbe6
              • Opcode Fuzzy Hash: e49c5a093c0a193095e6226fd28969db6786fba779d0b96324973e91b6d076d6
              • Instruction Fuzzy Hash: AE219272901159DBCB11DBE8C955AEEB778EF41358F200168D912B7BA0DB309E49CBE0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetExitCodeProcess.KERNEL32(00000000,00000000), ref: 6CC09BD8
              • CloseHandle.KERNEL32(00000000,?,?,00000007,?,?,?,?,?,6CC051AB), ref: 6CC09C4D
              Strings
              • [The /regserver process exited with error code][%d], xrefs: 6CC09C1E
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseCodeExitHandleProcess
              • String ID: [The /regserver process exited with error code][%d]
              • API String ID: 3771676846-3213322479
              • Opcode ID: c264cdf1e103da7536c038e79af0ce5bada918e329344dafb6d7b2b034015790
              • Instruction ID: fb5b4e1d1146db63aa17c83138d91b668b6360e66c9b37a067620cc3a78851db
              • Opcode Fuzzy Hash: c264cdf1e103da7536c038e79af0ce5bada918e329344dafb6d7b2b034015790
              • Instruction Fuzzy Hash: 3621EB71F49158BADF158FB998557FEBBFCFB06208F20416AD521E2A90E6324604C791
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(00000000), ref: 6CBC68AF
              • SysFreeString.OLEAUT32(00000000), ref: 6CBC68B4
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u
              • API String ID: 3341692771-4279031584
              • Opcode ID: 03ee73602155c7b65dd032035232cd67bdd40f4242b4c556580ecaf7c6b18a9f
              • Instruction ID: 15f7ae6ab402d914feb2e41b756891d205645f28612f1e234694ed1ccf60bb26
              • Opcode Fuzzy Hash: 03ee73602155c7b65dd032035232cd67bdd40f4242b4c556580ecaf7c6b18a9f
              • Instruction Fuzzy Hash: 0111E136A00458AFCB11DBA5CC94EEF77B8EF8061AF15007AE811E3640EF30DE04CA61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegCloseKey.ADVAPI32(00000000,?,?,?,Software\Microsoft\EdgeUpdate\DownloaderLockout,00020019), ref: 6CB7E589
              Strings
              • Software\Microsoft\EdgeUpdate\DownloaderLockout, xrefs: 6CB7E4EC
              • [GetDownloaderLockout][%s][0x%08x], xrefs: 6CB7E553
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseOpen
              • String ID: Software\Microsoft\EdgeUpdate\DownloaderLockout$[GetDownloaderLockout][%s][0x%08x]
              • API String ID: 47109696-1212337728
              • Opcode ID: 02722b0a0c352e637fbfc00ebb666f877986f7de7104446927b9ee4a1bab1f49
              • Instruction ID: 334d0900c8ea5179de5da89a5ac0412d2cf1e529c7d341c720c987a6e0cfaaba
              • Opcode Fuzzy Hash: 02722b0a0c352e637fbfc00ebb666f877986f7de7104446927b9ee4a1bab1f49
              • Instruction Fuzzy Hash: 4F216671D0025DBEDF11DF99C895AEE7FB8EF45318F10816AE924A7650D3348A44CBE0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,00000000,?,?,000F003F,?,00000000), ref: 6CB83EAC
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: hint$name
              • API String ID: 3535843008-3456818227
              • Opcode ID: efab054630340f2e3abf41cbbb92bca1f3a9dce0edb20a296391faf27436f97c
              • Instruction ID: a667b625931771b50d6cacb08d837821ebf3cef170ea353cec3f789b31223a94
              • Opcode Fuzzy Hash: efab054630340f2e3abf41cbbb92bca1f3a9dce0edb20a296391faf27436f97c
              • Instruction Fuzzy Hash: 5C110371A01259BBDF129FD4C885AEDBB74EF04319F008098FA1477AA0DBB05958CBB0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcess.KERNEL32(000000FF,000000FF,0000002C,00000000,?,?,?,?,?,6CC05C25,00000030,00000000,?,6CB8B8A8,?), ref: 6CC05DEA
              • SetProcessWorkingSetSize.KERNEL32(00000000), ref: 6CC05DF1
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Process$CurrentSizeWorking
              • String ID: [Core::DoRun]
              • API String ID: 2122760700-3414246237
              • Opcode ID: d44047b606beeadcd2b75e1f974cdd25bb129ba34337d7bccada71ada586897c
              • Instruction ID: bfbc53a56c5126d2f28cacdf6327af87697e80db471b07758216e11a80ce48e3
              • Opcode Fuzzy Hash: d44047b606beeadcd2b75e1f974cdd25bb129ba34337d7bccada71ada586897c
              • Instruction Fuzzy Hash: B311C672B0C2246B9F149BF99C089AFBBBCDB46225714062AE575E36C0FB34950087A0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Deallocate
              • String ID: /%s$MicrosoftEdgeUpdate.exe
              • API String ID: 1075933841-2270142193
              • Opcode ID: dc24d5767b675c61e1c63d9cf510c2e5e3c94afbbc9c6ae36cc4e4b3ae581f89
              • Instruction ID: a1a963805390e4270a92269c3d8895ec50291e099a53499f976e8d9acf021765
              • Opcode Fuzzy Hash: dc24d5767b675c61e1c63d9cf510c2e5e3c94afbbc9c6ae36cc4e4b3ae581f89
              • Instruction Fuzzy Hash: 0D118672D102346FDB14DF9DDC858FEB778EF90224B11065DD82667B85EB707D048AA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,6CD44078,?,?,00020019,{8A69D345-D564-463c-AFF1-A69D9E530F96},00000000,HKLM\Software\Google\Update\ClientState\), ref: 6CB83B97
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Close
              • String ID: HKLM\Software\Google\Update\ClientState\${8A69D345-D564-463c-AFF1-A69D9E530F96}
              • API String ID: 3535843008-3791611456
              • Opcode ID: 351cbf4ee2eef05844cb6e04beb7208cf6ae1c43ccb878f25048348197f58eb9
              • Instruction ID: b34f09629c316c353b8556cfabd351767958e6403c223ecf810f5a0fd9a3c05b
              • Opcode Fuzzy Hash: 351cbf4ee2eef05844cb6e04beb7208cf6ae1c43ccb878f25048348197f58eb9
              • Instruction Fuzzy Hash: D9118F71842258EFEF00DB95C956BEEB778EF11749F104498D421A7AA0EB746B0CCF90
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB76D20: RegOpenKeyExW.KERNELBASE(?,?,00000000,?,00000000,80070003,?,6CB78DC3,?,6CB76FDD,00000000,?,?,?,?,?), ref: 6CB76D59
              • RegQueryInfoKeyW.ADVAPI32(00000007,00000000,00000000,00000000,6CD7C950,00000000,00000000,00000000,00000000,00000000,00000000,00000000,-7FFFFFFF,Software\Microsoft\EdgeUpdate\Clients\,00020019,00000007), ref: 6CB835EC
              • RegCloseKey.ADVAPI32(00000007,-7FFFFFFF,Software\Microsoft\EdgeUpdate\Clients\,00020019,00000007,?,00000000), ref: 6CB8361B
              Strings
              • Software\Microsoft\EdgeUpdate\Clients\, xrefs: 6CB835AC
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseInfoOpenQuery
              • String ID: Software\Microsoft\EdgeUpdate\Clients\
              • API String ID: 2142960691-1066890600
              • Opcode ID: e3618bbe75071d2bdb3a110314719bd393e04c4305a9c1f22013a4194946b600
              • Instruction ID: 7374a602b3a0e931e729af1589a45a3303ff0bf41e805eca1ddd9cc1fb396272
              • Opcode Fuzzy Hash: e3618bbe75071d2bdb3a110314719bd393e04c4305a9c1f22013a4194946b600
              • Instruction Fuzzy Hash: 2F0156B2D05279AFDB119FDD98859AEBBBCEB04364F114165E914F7750D7308D048BA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,00000000), ref: 6CB83DF4
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,00000000,6CD3F7F0,6CD3F7F0,?,6CB7C8FE,?,?,?,00000000), ref: 6CB772B1
                • Part of subcall function 6CB77290: SHQueryValueExW.SHLWAPI(6CB76BD7,?,00000000,?,00000000,00000000,?,?,6CB7C8FE,?,?,?,00000000), ref: 6CB77313
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: QueryValue$Close
              • String ID: hint$name
              • API String ID: 1979452859-3456818227
              • Opcode ID: 5820297b430d1bcaaeeaf013a6eb504d89ca72795dee64c531916b6fff747aac
              • Instruction ID: 9dfb6efd231412eb39e05d180af9d7bf378ec13f422238f71d70eb20224338d1
              • Opcode Fuzzy Hash: 5820297b430d1bcaaeeaf013a6eb504d89ca72795dee64c531916b6fff747aac
              • Instruction Fuzzy Hash: 0611AC7680016DEBDB11EF94C880AEEBBB8FF41318F104458E821637A0DB719A09CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentProcessId.KERNEL32(00000000,00000000,00000000,?,6CBDBE03,00000010,0000000E,?,00000000,00000010,00000000,?,6CBDC72C,00000000,?,00002710), ref: 6CBE7545
                • Part of subcall function 6CB7D80B: InitOnceExecuteOnce.KERNELBASE(6CD7C5F4,6CB7D82A,00000000,00000000,6CB66C84), ref: 6CB7D819
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Once$CurrentExecuteInitProcess
              • String ID: %s$%s.pid=%d, ver=%s, machine=%d, extern=%d
              • API String ID: 1192189232-1608761309
              • Opcode ID: 26a25b6ab47b87c0f0f3b13cfa3b93483b5ca13c7e8d854415b08d5cf8979070
              • Instruction ID: b641342831072d6c24739c80bc6fb0ab0f2c57a3d9fe06d64bbddac93553de7d
              • Opcode Fuzzy Hash: 26a25b6ab47b87c0f0f3b13cfa3b93483b5ca13c7e8d854415b08d5cf8979070
              • Instruction Fuzzy Hash: 8201AD71900144ABCF00EBA9DC88DEFBBBCEF84259B0484A9E811E7741D7709E58CBB1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(qmgrprxy.dll,?,?,6CBB9783), ref: 6CBB97BE
              • CloseHandle.KERNEL32(?,?,?,6CBB9783), ref: 6CBB97F1
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Handle$CloseModule
              • String ID: qmgrprxy.dll
              • API String ID: 125232103-4102015800
              • Opcode ID: e1e7c2de8d91121bce89da22e3340db977744ffb568c9a0ccd8fd8a76a2d3c1b
              • Instruction ID: ef55e2cb13de6e88dab04174efd083eaa5d85e0a12064f4aab57e52a7c1f67fa
              • Opcode Fuzzy Hash: e1e7c2de8d91121bce89da22e3340db977744ffb568c9a0ccd8fd8a76a2d3c1b
              • Instruction Fuzzy Hash: A7116D32200A808BD729AF3AC5949BEB7F5BFA5618710491DD1E796FA0DF30A849DB01
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: _strlen
              • String ID: proxy
              • API String ID: 4218353326-3318096647
              • Opcode ID: 016c890e02b75bc8f701d4f504889d9609d601740c053f4a7981c01350cf85c7
              • Instruction ID: a10ac9e8b19a2e08929419565f36c08470adca178a4b959a6cd5da7d6eb481ce
              • Opcode Fuzzy Hash: 016c890e02b75bc8f701d4f504889d9609d601740c053f4a7981c01350cf85c7
              • Instruction Fuzzy Hash: A1F0C832B4A9A35A933205299C00ABB569D8B867E8755052BE855F7E40FF33C80983E2
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetModuleHandleW.KERNEL32(Mscoree.dll,?,6CB93F21,?,00000000,?,6CB8B868,?), ref: 6CB955CF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: HandleModule
              • String ID: Mscoree.dll
              • API String ID: 4139908857-4150509846
              • Opcode ID: 348048ac2149478d4531bc44eb1cbd89a9abafac58c7c23d512c2affc19f48e7
              • Instruction ID: 3b15334afef423a2694dadd02e22a0bb2d58e71eef326f13632aab0d7ce7e5be
              • Opcode Fuzzy Hash: 348048ac2149478d4531bc44eb1cbd89a9abafac58c7c23d512c2affc19f48e7
              • Instruction Fuzzy Hash: E0014C71B9C0A1BBEF10476A8804B9E7A799B4332BF640339E50193AC0DB704C0887BE
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CBACADA
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u$update3web-ondemand
              • API String ID: 3341692771-468389399
              • Opcode ID: 620f37eb5e105de89da56890283445978e7429eb6a2a379ec5527d4e66d7b9b1
              • Instruction ID: 081b97e38bfb96dde39af62ef7f0cd06744bf4dbbd1361a5f08c4295f0f4973c
              • Opcode Fuzzy Hash: 620f37eb5e105de89da56890283445978e7429eb6a2a379ec5527d4e66d7b9b1
              • Instruction Fuzzy Hash: 7D01A232605159AFCB00DF99C88099EBBB8FF497B47154269E808EBB10D771EE05CBD0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(00000000), ref: 6CBE8F0C
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: <?xml version="1.0" encoding="UTF-8"?>$`)u
              • API String ID: 3341692771-2765958075
              • Opcode ID: 03305f78029487a8d0210c36eed1232feef90f5b7c7e8764e40601cd09f4a6e6
              • Instruction ID: b7aba85e873cdc338111e056f316d35bce6e2054e52716a69b902dfa5cac7069
              • Opcode Fuzzy Hash: 03305f78029487a8d0210c36eed1232feef90f5b7c7e8764e40601cd09f4a6e6
              • Instruction Fuzzy Hash: B5F08132A01524BBCB15DBA5DC44EDE77689F49BA8F104059F809EBB50DB319E0487E9
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • CloseHandle.KERNEL32(00000000,6CD67530,6CD67534,00000000,00720070,?,6CCA0C65), ref: 6CCA5825
                • Part of subcall function 6CB812B5: SetEnvironmentVariableW.KERNEL32(?,?), ref: 6CB81336
                • Part of subcall function 6CB812B5: GetLastError.KERNEL32(?,?), ref: 6CB81340
              • SetEvent.KERNEL32(00000000,6CD67530,6CD67534,00000000,00720070,?,6CCA0C65), ref: 6CCA5835
              Strings
              • EDGE_UPDATE_UI_DISPLAYED_EVENT_NAME, xrefs: 6CCA57F1
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseEnvironmentErrorEventHandleLastVariable
              • String ID: EDGE_UPDATE_UI_DISPLAYED_EVENT_NAME
              • API String ID: 78715891-3927402446
              • Opcode ID: 1a3c74d228b7f2733470d0a1a2c6fdcb97cf1841c42e490ac57de05c5e8b856a
              • Instruction ID: 9abe729a88bb8b066ddd6f7d62f6867489742a50a99acdb52b20d04ea3b3dda3
              • Opcode Fuzzy Hash: 1a3c74d228b7f2733470d0a1a2c6fdcb97cf1841c42e490ac57de05c5e8b856a
              • Instruction Fuzzy Hash: F2F02832754111ABDB04EBAAC84C9DF73BCAB92774B248528E501EBB50FB70CD09CB61
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysStringLen.OLEAUT32(00000000), ref: 6CBC6D71
              • SysFreeString.OLEAUT32(00000000), ref: 6CBC6DB7
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free
              • String ID: `)u
              • API String ID: 1391021980-4279031584
              • Opcode ID: 0638e759b5dba2b85fe7a2420815d2fd26b47a0c0a2f6d5b39a1a1bd513cc370
              • Instruction ID: 668db42cedf998d7f4885d855563e76bc00e1aa36f1173893db2b0026eb0e526
              • Opcode Fuzzy Hash: 0638e759b5dba2b85fe7a2420815d2fd26b47a0c0a2f6d5b39a1a1bd513cc370
              • Instruction Fuzzy Hash: 6BF0A436A00154BBDF109BA5CD19CDE7B7AEF85269F210558E805A3750EF309E09D6A0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysStringLen.OLEAUT32(00000000), ref: 6CBC6D02
              • SysFreeString.OLEAUT32(00000000), ref: 6CBC6D47
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free
              • String ID: `)u
              • API String ID: 1391021980-4279031584
              • Opcode ID: 46276ed9a0ca0f36f945f536d9caa0fb54c93afd786963d8698534bc1a8a9cb2
              • Instruction ID: 8b636902c3f96393860808f2d1a0092ac68fcb614601a7f1eeb0bbc9298fdf15
              • Opcode Fuzzy Hash: 46276ed9a0ca0f36f945f536d9caa0fb54c93afd786963d8698534bc1a8a9cb2
              • Instruction Fuzzy Hash: A0F04436A01154BBCF109BA5CD198DE7B7AEFC566AF210464D805A7750EB309E0D96A0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysStringLen.OLEAUT32(00000000), ref: 6CBC6DE1
              • SysFreeString.OLEAUT32(00000000), ref: 6CBC6E26
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free
              • String ID: `)u
              • API String ID: 1391021980-4279031584
              • Opcode ID: 0c7e9085b1daffcd40239dc9c8a550a517c7260ac645d37eaf29a1b1874f25fb
              • Instruction ID: 2381e3f504a05ae9c5e4c9e6f8d000829f1ca541337ea75861913e1177ca3c2a
              • Opcode Fuzzy Hash: 0c7e9085b1daffcd40239dc9c8a550a517c7260ac645d37eaf29a1b1874f25fb
              • Instruction Fuzzy Hash: E3F0A436A00154BBCF009BA5CD188DE7B7AEFC422AF210464D805A3740EB309B0D96A0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RegCloseKey.ADVAPI32(00000000,HKLM\Software\Microsoft\Windows\CurrentVersion\MicrosoftEdge,00000001,00000000,00000000,6CB73B38), ref: 6CB7351D
                • Part of subcall function 6CB77187: SHQueryValueExW.SHLWAPI(6CB76BD7,00000000,00000000,00000000,?,?,6CD3F7F0,6CD3F7F0,?,6CB77060,?,00000000,00000000,?), ref: 6CB771AA
              Strings
              • OSIntegrationLevel, xrefs: 6CB734F8
              • HKLM\Software\Microsoft\Windows\CurrentVersion\MicrosoftEdge, xrefs: 6CB734DD
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CloseQueryValue
              • String ID: HKLM\Software\Microsoft\Windows\CurrentVersion\MicrosoftEdge$OSIntegrationLevel
              • API String ID: 3356406503-1052164878
              • Opcode ID: c92bbc2702c30da964fe0c79a060e6b3ce36e00ec5656661984289430c9b920f
              • Instruction ID: 7d91babc762e13140d2f7dee5c1a1022fe5b1c5f50adf7bc6fc15c8eb8914d51
              • Opcode Fuzzy Hash: c92bbc2702c30da964fe0c79a060e6b3ce36e00ec5656661984289430c9b920f
              • Instruction Fuzzy Hash: 68F04F75D41228ABEB10DF95CD556EEBB78EB00348F1044A9D82162A50D3719B08CBA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysStringLen.OLEAUT32(00000000), ref: 6CBC6E4F
              • SysFreeString.OLEAUT32(00000000), ref: 6CBC6E85
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free
              • String ID: `)u
              • API String ID: 1391021980-4279031584
              • Opcode ID: 581fd5598023b04cf59f99b0701a0874fb9a60b92bff80e4dde49debf7497fd8
              • Instruction ID: 36c215bc807261a58c6f48dcd17f6d219abc61261733b93bd0011037be84ba7c
              • Opcode Fuzzy Hash: 581fd5598023b04cf59f99b0701a0874fb9a60b92bff80e4dde49debf7497fd8
              • Instruction Fuzzy Hash: BEF0F972900169BBDF149BA5CD09DDE7B79EF05669F100194A901A6690EB709E089BA0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • std::_Lockit::_Lockit.LIBCPMT ref: 6CB84714
              • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 6CB8474A
                • Part of subcall function 6CCB266C: _Yarn.LIBCPMT ref: 6CCB268B
                • Part of subcall function 6CCB266C: _Yarn.LIBCPMT ref: 6CCB26AF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Yarnstd::_$Locinfo::_Locinfo_ctorLockitLockit::_
              • String ID: bad locale name
              • API String ID: 1908188788-1405518554
              • Opcode ID: 2ddd711e54534dd6bc39dcc4ea569e4bebd25e67235753bcc6ea00188ddd0062
              • Instruction ID: 9c16311c0dd3c7b1fde874fd148f4694e4a33bb7e274d25e270e00602a676e82
              • Opcode Fuzzy Hash: 2ddd711e54534dd6bc39dcc4ea569e4bebd25e67235753bcc6ea00188ddd0062
              • Instruction Fuzzy Hash: 12F01271505B849E83258FAA9490483FBE8BE292543508A2FD19ED3E11D730E548CBA9
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB6FDFB: GetSystemTimeAsFileTime.KERNEL32(?,6CD3E6AC,6CD3E6AC,?,6CB68434,00000000,?,?,00000000,?,?,6CB7B383,00000007,00000001,?), ref: 6CB6FE1B
              • __aulldiv.LIBCMT ref: 6CB82080
                • Part of subcall function 6CB773B5: RegSetValueExW.KERNELBASE(6CB76BD7,00000000,00000000,00000004,00000000,00000004,?,6CB76EF5,00000000,00000000,00000000,?,00000000,00000000,?,00000000), ref: 6CB773C8
                • Part of subcall function 6CB77187: SHQueryValueExW.SHLWAPI(6CB76BD7,00000000,00000000,00000000,?,?,6CD3F7F0,6CD3F7F0,?,6CB77060,?,00000000,00000000,?), ref: 6CB771AA
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: TimeValue$FileQuerySystem__aulldiv
              • String ID: uid-create-time$uid-num-rotations
              • API String ID: 2700563484-461279828
              • Opcode ID: 6615ae84d29d353fb322f01c397be15d8029608976aa41e3077bedd99b780f7d
              • Instruction ID: 34015b1b4bef884f55dca7697224d0b7d21df64062e5fe6d45d04f9703265030
              • Opcode Fuzzy Hash: 6615ae84d29d353fb322f01c397be15d8029608976aa41e3077bedd99b780f7d
              • Instruction Fuzzy Hash: 85F037A1B401547BDA149765CC05FFF657CCBD1968F11445AB901E7B50DAB0AE0583B0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysFreeString.OLEAUT32(?), ref: 6CBACC41
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: FreeString
              • String ID: `)u$update3web-components
              • API String ID: 3341692771-324883571
              • Opcode ID: 10d3184a3f24bab74be0813c439478f3dea1d96a2765197e68e22a83955f134c
              • Instruction ID: aca2479ce90abeb1cc77989a415d6f6de28dd0ab44876fa0852b969b82c153cc
              • Opcode Fuzzy Hash: 10d3184a3f24bab74be0813c439478f3dea1d96a2765197e68e22a83955f134c
              • Instruction Fuzzy Hash: 79F03A36600154EBCB119F99C888D9A7F69FF497617054165FD088B621D732E910DBE0
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetEnvironmentVariableW.KERNEL32(SystemDrive,00000000,00000000,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB6CC32
              • GetEnvironmentVariableW.KERNEL32(SystemDrive,00000000,00000000,00000000,?,6CD7C9A4,00000001,6CB68F99,?,?,?,6CB6807C,6CD7C9D8), ref: 6CB6CC49
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: EnvironmentVariable
              • String ID: SystemDrive
              • API String ID: 1431749950-1672058545
              • Opcode ID: 808e2955b16bfa044a8f1a4261a530d302b183a29e22744248558c73abbb92bb
              • Instruction ID: 42a6e3f6fcd5049fc3cba37228cf5f5c91b7e1bc191efdd89be3db334e126ade
              • Opcode Fuzzy Hash: 808e2955b16bfa044a8f1a4261a530d302b183a29e22744248558c73abbb92bb
              • Instruction Fuzzy Hash: 2BE04F713445A076E92427AFCC44FAE956DCFC6A6AF20022AB626D2FD18F648C0101F5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • SysStringLen.OLEAUT32(00000000), ref: 6CBDD59D
              • SysFreeString.OLEAUT32(00000000), ref: 6CBDD5BD
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: String$Free
              • String ID: `)u
              • API String ID: 1391021980-4279031584
              • Opcode ID: 53bd3923943f68a5419b334e47df4d85d2daeb6b206863b91b37708eadd07bb8
              • Instruction ID: a602216ede176b515b6e6c29a35db6db8e04c176823eea75a228ec7408ecf97a
              • Opcode Fuzzy Hash: 53bd3923943f68a5419b334e47df4d85d2daeb6b206863b91b37708eadd07bb8
              • Instruction Fuzzy Hash: 6EF0E531310124FBEF019F64DE04A9D7778EF0561AF110158E402E2610DB70EF00EB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • IsDebuggerPresent.KERNEL32(?,?,6CB68B76), ref: 6CB6F4A8
              • OutputDebugStringW.KERNEL32(**SehSendMinidump**,?,?,6CB68B76), ref: 6CB6F4B7
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DebugDebuggerOutputPresentString
              • String ID: **SehSendMinidump**
              • API String ID: 4086329628-2587082360
              • Opcode ID: e50fcdaa84b10a4334642b349ea5f3cb8570a8118d473ba0f3868e500e074e6f
              • Instruction ID: 2206ba17dbd1bc1fe1e4844989323ffc5ba005de67665e320c176127d81c6642
              • Opcode Fuzzy Hash: e50fcdaa84b10a4334642b349ea5f3cb8570a8118d473ba0f3868e500e074e6f
              • Instruction Fuzzy Hash: EDE0923136A090AFF7042B6ADC48F567778DB83306B214079A911D3D40D76098018569
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • WaitForSingleObject.KERNEL32(00000000,000001F4,?,6CB69215), ref: 6CB699EC
              • OutputDebugStringW.KERNEL32(00000000), ref: 6CB69A11
              Strings
              • LOG_SYSTEM: [%s]: Could not acquire logging mutex %s, xrefs: 6CB69A03
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: DebugObjectOutputSingleStringWait
              • String ID: LOG_SYSTEM: [%s]: Could not acquire logging mutex %s
              • API String ID: 3023325665-3861772780
              • Opcode ID: c4504cc590262db231b68243da019b7ce7fbb043fb8ad93248639959b306e24b
              • Instruction ID: 081cdc10c203944684000c28bbe4dc998dc96edad9e959407bc877c1cf180035
              • Opcode Fuzzy Hash: c4504cc590262db231b68243da019b7ce7fbb043fb8ad93248639959b306e24b
              • Instruction Fuzzy Hash: 23E0D831A04750ABEF302F29E804BC77BF5FF02304F00491AE1A691DD0D7709449DB51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
                • Part of subcall function 6CB666B1: InitializeCriticalSectionAndSpinCount.KERNEL32(?,00000000,00000104,8007000E,?,-C000001E,00000001,?,6CB66F62,80070057,00000000,?,6CB728CB,00000104,00000001,00000000), ref: 6CB666B6
                • Part of subcall function 6CB666B1: GetLastError.KERNEL32(?,00000000,00000104,8007000E,?,-C000001E,00000001,?,6CB66F62,80070057,00000000,?,6CB728CB,00000104,00000001,00000000), ref: 6CB666C0
              • IsDebuggerPresent.KERNEL32(?,?,?,6CB6642E), ref: 6CCB0D9D
              • OutputDebugStringW.KERNEL32(ERROR : Unable to initialize critical section in CAtlBaseModule,?,?,?,6CB6642E), ref: 6CCB0DAC
              Strings
              • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 6CCB0DA7
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: CountCriticalDebugDebuggerErrorInitializeLastOutputPresentSectionSpinString
              • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
              • API String ID: 450123788-631824599
              • Opcode ID: b69de3b4d22f20c4ce92f62194155bbca5d8a1775375df131e536c77da2ba8fc
              • Instruction ID: 27e1c86f1c8c2a4fc9b4ee98c9afab19e2752e6102836d0e81ccccf69e65eea0
              • Opcode Fuzzy Hash: b69de3b4d22f20c4ce92f62194155bbca5d8a1775375df131e536c77da2ba8fc
              • Instruction Fuzzy Hash: CAE0E570304B90DFE7209FB9D504796BAF4AF05304F00895DD496D6F90EB75E4448BA1
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetCurrentThreadId.KERNEL32 ref: 6CB67FE7
              • GetCurrentProcessId.KERNEL32 ref: 6CB67FEF
              Strings
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Current$ProcessThread
              • String ID: [%s][%u:%u]
              • API String ID: 2063062207-1063403612
              • Opcode ID: 4e30d2b6268dc2362b5ab14f012d045794d0fb813ab77d6323c775a617b7c292
              • Instruction ID: 746a866b9739e08007a0a81cbaf5a04ff3deb55503570f6c4e37325bee80c8fc
              • Opcode Fuzzy Hash: 4e30d2b6268dc2362b5ab14f012d045794d0fb813ab77d6323c775a617b7c292
              • Instruction Fuzzy Hash: A2E0BF75A04218BBAF10AFEA8C88CABBFFCEF0A6457408418BA1897641D73559458FB5
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • GetProcessHeap.KERNEL32(00000008,00000008,?,6CBDD4BB,?,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?), ref: 6CCE9F07
              • HeapAlloc.KERNEL32(00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000,?), ref: 6CCE9F0E
              • GetProcessHeap.KERNEL32(00000000,00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000), ref: 6CCE9F54
              • HeapFree.KERNEL32(00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000,?), ref: 6CCE9F5B
                • Part of subcall function 6CCE9DA1: GetProcessHeap.KERNEL32(00000008,0000000D,00000000,?,6CCE9F4A,?,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000), ref: 6CCE9DC5
                • Part of subcall function 6CCE9DA1: HeapAlloc.KERNEL32(00000000,?,6CBDF2F9,00000000,00000000,?,{2D905E07-FC38-4b89-83E1-931D3630937F},?,6CC072BC,00000000,00000000,?,00000000,00000080,00000000,?), ref: 6CCE9DCC
              Memory Dump Source
              • Source File: 00000009.00000002.3521019812.000000006CB61000.00000020.00000001.01000000.0000000D.sdmp, Offset: 6CB60000, based on PE: true
              • Associated: 00000009.00000002.3520978845.000000006CB60000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521299592.000000006CD0B000.00000002.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521358944.000000006CD74000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521454316.000000006CD78000.00000008.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521517698.000000006CD7A000.00000004.00000001.01000000.0000000D.sdmpDownload File
              • Associated: 00000009.00000002.3521561944.000000006CD7F000.00000002.00000001.01000000.0000000D.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_9_2_6cb60000_MicrosoftEdgeUpdate.jbxd
              Similarity
              • API ID: Heap$Process$Alloc$Free
              • String ID:
              • API String ID: 1864747095-0
              • Opcode ID: c65f1915f3b780f2ac1654eb4c3991eb512e33b45f4ed3e95ee9ca1680925b38
              • Instruction ID: a34434075567b5a5e03f8ad57a27b72c4c7d9f4b02da1e495f2bdee1974e5e6f
              • Opcode Fuzzy Hash: c65f1915f3b780f2ac1654eb4c3991eb512e33b45f4ed3e95ee9ca1680925b38
              • Instruction Fuzzy Hash: 39F09072748612A7EA202FBDA80C98E2ABDAF8BB96705451CF655C6680EF20C40187A4
              Uniqueness

              Uniqueness Score: -1.00%