Loading ...

Play interactive tourEdit tour

Analysis Report anchorDNS_x64.exe

Overview

General Information

Sample Name:anchorDNS_x64.exe
Analysis ID:381811
MD5:7160ac4abb26f0ca4c1b6dfba44f8d36
SHA1:3820ff0d04a233745c79932b77eccfe743a81d34
SHA256:9fdbd76141ec43b6867f091a2dca503edb2a85e4b98a4500611f5fe484109513
Infos:

Most interesting Screenshot:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Contains functionality to inject threads in other processes
Machine Learning detection for sample
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found evasive API chain (date check)
Found large amount of non-executed APIs
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Uses code obfuscation techniques (call, push, ret)

Classification

Startup

  • System is w10x64
  • anchorDNS_x64.exe (PID: 6344 cmdline: 'C:\Users\user\Desktop\anchorDNS_x64.exe' MD5: 7160AC4ABB26F0CA4C1B6DFBA44F8D36)
    • cmd.exe (PID: 6368 cmdline: cmd.exe /c timeout 3 && del C:\Users\user\Desktop\anchorDNS_x64.exe MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
      • conhost.exe (PID: 6384 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • timeout.exe (PID: 6424 cmdline: timeout 3 MD5: EB9A65078396FB5D4E3813BB9198CB18)
    • cmd.exe (PID: 6376 cmdline: cmd.exe /C PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe' MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
      • conhost.exe (PID: 6396 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • powershell.exe (PID: 6456 cmdline: PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe' MD5: 95000560239032BC68B4C2FDFCDEF913)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: anchorDNS_x64.exeVirustotal: Detection: 10%Perma Link
Source: anchorDNS_x64.exeReversingLabs: Detection: 25%
Machine Learning detection for sampleShow sources
Source: anchorDNS_x64.exeJoe Sandbox ML: detected
Source: anchorDNS_x64.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
Source: Binary string: Z:\D\GIT\anchorDns.llvm\Bin\x64\Release\anchorDNS_x64.pdbt source: anchorDNS_x64.exe
Source: Binary string: Z:\D\GIT\anchorDns.llvm\Bin\x64\Release\anchorDNS_x64.pdb source: anchorDNS_x64.exe
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC3D404 FindFirstFileExW,0_2_00007FF63EC3D404
Source: powershell.exe, 00000006.00000003.217179808.0000012B7D198000.00000004.00000001.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
Source: powershell.exe, 00000006.00000002.230782159.0000012B7D140000.00000004.00000001.sdmp, powershell.exe, 00000006.00000002.218129835.0000012B00210000.00000004.00000001.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
Source: powershell.exe, 00000006.00000002.217765028.0000012B00001000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: powershell.exe, 00000006.00000002.230782159.0000012B7D140000.00000004.00000001.sdmp, powershell.exe, 00000006.00000002.218129835.0000012B00210000.00000004.00000001.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpString found in binary or memory: https://contoso.com/
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpString found in binary or memory: https://contoso.com/Icon
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpString found in binary or memory: https://contoso.com/License
Source: powershell.exe, 00000006.00000002.230782159.0000012B7D140000.00000004.00000001.sdmp, powershell.exe, 00000006.00000002.218129835.0000012B00210000.00000004.00000001.sdmpString found in binary or memory: https://github.com/Pester/Pester
Source: powershell.exe, 00000006.00000002.224611933.0000012B01C61000.00000004.00000001.sdmpString found in binary or memory: https://go.micro
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpString found in binary or memory: https://nuget.org/nuget.exe
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2048A GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,CloseHandle,CreateDesktopA,Sleep,CloseDesktop,GetLastError,GetLastError,GetLastError,CloseHandle,0_2_00007FF63EC2048A
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0F1C70_2_00007FF63EC0F1C7
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC352C00_2_00007FF63EC352C0
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC042E40_2_00007FF63EC042E4
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2D00C0_2_00007FF63EC2D00C
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0F80E0_2_00007FF63EC0F80E
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1D0040_2_00007FF63EC1D004
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0777A0_2_00007FF63EC0777A
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1AFAE0_2_00007FF63EC1AFAE
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC327540_2_00007FF63EC32754
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2FF600_2_00007FF63EC2FF60
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0176B0_2_00007FF63EC0176B
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1890E0_2_00007FF63EC1890E
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0C0FC0_2_00007FF63EC0C0FC
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC289260_2_00007FF63EC28926
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0E8EC0_2_00007FF63EC0E8EC
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC020D80_2_00007FF63EC020D8
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2908C0_2_00007FF63EC2908C
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2E8940_2_00007FF63EC2E894
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC010940_2_00007FF63EC01094
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0C8B20_2_00007FF63EC0C8B2
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC236090_2_00007FF63EC23609
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0A5F60_2_00007FF63EC0A5F6
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC3EE180_2_00007FF63EC3EE18
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC08E1C0_2_00007FF63EC08E1C
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0C5BE0_2_00007FF63EC0C5BE
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC195A80_2_00007FF63EC195A8
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2F5B00_2_00007FF63EC2F5B0
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1CD360_2_00007FF63EC1CD36
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC035750_2_00007FF63EC03575
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC09F0A0_2_00007FF63EC09F0A
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC087160_2_00007FF63EC08716
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1BF220_2_00007FF63EC1BF22
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC066C40_2_00007FF63EC066C4
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC216CE0_2_00007FF63EC216CE
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0AED20_2_00007FF63EC0AED2
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC3B6E80_2_00007FF63EC3B6E8
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC3CEEC0_2_00007FF63EC3CEEC
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC06EEC0_2_00007FF63EC06EEC
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0B68A0_2_00007FF63EC0B68A
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0BE8E0_2_00007FF63EC0BE8E
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC07E980_2_00007FF63EC07E98
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC42E480_2_00007FF63EC42E48
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0CE640_2_00007FF63EC0CE64
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC254140_2_00007FF63EC25414
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC103FD0_2_00007FF63EC103FD
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC3D4040_2_00007FF63EC3D404
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC17C280_2_00007FF63EC17C28
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC22C2F0_2_00007FF63EC22C2F
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC06BCC0_2_00007FF63EC06BCC
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1C3C20_2_00007FF63EC1C3C2
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC073F40_2_00007FF63EC073F4
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1EBAA0_2_00007FF63EC1EBAA
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1A3AE0_2_00007FF63EC1A3AE
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1FBB40_2_00007FF63EC1FBB4
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0AB960_2_00007FF63EC0AB96
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC3FB640_2_00007FF63EC3FB64
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC27CCD0_2_00007FF63EC27CCD
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC27CCC0_2_00007FF63EC27CCC
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC144C30_2_00007FF63EC144C3
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC174C40_2_00007FF63EC174C4
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1B4E40_2_00007FF63EC1B4E4
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2048A0_2_00007FF63EC2048A
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC084760_2_00007FF63EC08476
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC3BC9C0_2_00007FF63EC3BC9C
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC09CA40_2_00007FF63EC09CA4
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0B45A0_2_00007FF63EC0B45A
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0BC620_2_00007FF63EC0BC62
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC152090_2_00007FF63EC15209
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC039FB0_2_00007FF63EC039FB
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC071F60_2_00007FF63EC071F6
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC279D80_2_00007FF63EC279D8
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0E1920_2_00007FF63EC0E192
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC089920_2_00007FF63EC08992
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2217C0_2_00007FF63EC2217C
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1F1480_2_00007FF63EC1F148
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1614C0_2_00007FF63EC1614C
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0693C0_2_00007FF63EC0693C
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0A16E0_2_00007FF63EC0A16E
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1DB2C0_2_00007FF63EC1DB2C
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC07B160_2_00007FF63EC07B16
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC1F31E0_2_00007FF63EC1F31E
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC012B60_2_00007FF63EC012B6
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0C2F20_2_00007FF63EC0C2F2
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC082480_2_00007FF63EC08248
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC282500_2_00007FF63EC28250
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2FA540_2_00007FF63EC2FA54
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC0BA3A0_2_00007FF63EC0BA3A
Source: anchorDNS_x64.exeStatic PE information: Number of sections : 11 > 10
Source: classification engineClassification label: mal56.evad.winEXE@11/4@0/0
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2048A GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,CloseHandle,CreateDesktopA,Sleep,CloseDesktop,GetLastError,GetLastError,GetLastError,CloseHandle,0_2_00007FF63EC2048A
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\Documents\20210405Jump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6396:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6384:120:WilError_01
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_0nn5oih2.opl.ps1Jump to behavior
Source: anchorDNS_x64.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\ac26e2af62f23e37e645b5e44068a025\mscorlib.ni.dllJump to behavior
Source: C:\Users\user\Desktop\anchorDNS_x64.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: anchorDNS_x64.exeVirustotal: Detection: 10%
Source: anchorDNS_x64.exeReversingLabs: Detection: 25%
Source: unknownProcess created: C:\Users\user\Desktop\anchorDNS_x64.exe 'C:\Users\user\Desktop\anchorDNS_x64.exe'
Source: C:\Users\user\Desktop\anchorDNS_x64.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /c timeout 3 && del C:\Users\user\Desktop\anchorDNS_x64.exe
Source: C:\Users\user\Desktop\anchorDNS_x64.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe'
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout 3
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe'
Source: C:\Users\user\Desktop\anchorDNS_x64.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /c timeout 3 && del C:\Users\user\Desktop\anchorDNS_x64.exeJump to behavior
Source: C:\Users\user\Desktop\anchorDNS_x64.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe'Jump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout 3 Jump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe'Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
Source: anchorDNS_x64.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: anchorDNS_x64.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: anchorDNS_x64.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: anchorDNS_x64.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: anchorDNS_x64.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: anchorDNS_x64.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: anchorDNS_x64.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: anchorDNS_x64.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
Source: anchorDNS_x64.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: Z:\D\GIT\anchorDns.llvm\Bin\x64\Release\anchorDNS_x64.pdbt source: anchorDNS_x64.exe
Source: Binary string: Z:\D\GIT\anchorDns.llvm\Bin\x64\Release\anchorDNS_x64.pdb source: anchorDNS_x64.exe
Source: anchorDNS_x64.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: anchorDNS_x64.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: anchorDNS_x64.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: anchorDNS_x64.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: anchorDNS_x64.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: anchorDNS_x64.exeStatic PE information: section name: .00cfg
Source: anchorDNS_x64.exeStatic PE information: section name: .addr
Source: anchorDNS_x64.exeStatic PE information: section name: .rand
Source: anchorDNS_x64.exeStatic PE information: section name: _RDATA
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 6_2_00007FFAEEE23767 push esp; retf 6_2_00007FFAEEE23768
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3590Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 5441Jump to behavior
Source: C:\Users\user\Desktop\anchorDNS_x64.exeEvasive API call chain: GetLocalTime,DecisionNodesgraph_0-19873
Source: C:\Users\user\Desktop\anchorDNS_x64.exeAPI coverage: 6.1 %
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6588Thread sleep count: 3590 > 30Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6592Thread sleep count: 5441 > 30Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6664Thread sleep time: -11068046444225724s >= -30000sJump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC3D404 FindFirstFileExW,0_2_00007FF63EC3D404
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC359E4 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF63EC359E4
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC39600 GetProcessHeap,0_2_00007FF63EC39600
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2A698 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF63EC2A698
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC359E4 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF63EC359E4
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2A284 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF63EC2A284
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC2A274 SetUnhandledExceptionFilter,0_2_00007FF63EC2A274

HIPS / PFW / Operating System Protection Evasion:

barindex
Contains functionality to inject threads in other processesShow sources
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC216CE VirtualAllocEx,WriteProcessMemory,CreateRemoteThread,CloseHandle,GetLastError,GetLastError,GetLastError,GetLastError,CloseHandle,0_2_00007FF63EC216CE
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout 3 Jump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe'Jump to behavior
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC42C60 cpuid 0_2_00007FF63EC42C60
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\anchorDNS_x64.exeCode function: 0_2_00007FF63EC03912 GetLocalTime,SystemTimeToFileTime,0_2_00007FF63EC03912

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsNative API1Create Account1Access Token Manipulation1Masquerading1OS Credential DumpingSystem Time Discovery1Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsProcess Injection111Virtualization/Sandbox Evasion21LSASS MemorySecurity Software Discovery2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Access Token Manipulation1Security Account ManagerProcess Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection111NTDSVirtualization/Sandbox Evasion21Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptObfuscated Files or Information1LSA SecretsApplication Window Discovery1SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonSteganographyCached Domain CredentialsFile and Directory Discovery1VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
External Remote ServicesScheduled TaskStartup ItemsStartup ItemsCompile After DeliveryDCSyncSystem Information Discovery22Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 381811 Sample: anchorDNS_x64.exe Startdate: 05/04/2021 Architecture: WINDOWS Score: 56 22 Multi AV Scanner detection for submitted file 2->22 24 Machine Learning detection for sample 2->24 7 anchorDNS_x64.exe 2->7         started        process3 signatures4 26 Contains functionality to inject threads in other processes 7->26 10 cmd.exe 1 7->10         started        12 cmd.exe 1 7->12         started        process5 process6 14 conhost.exe 10->14         started        16 timeout.exe 1 10->16         started        18 powershell.exe 19 12->18         started        20 conhost.exe 12->20         started       

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
anchorDNS_x64.exe10%VirustotalBrowse
anchorDNS_x64.exe5%MetadefenderBrowse
anchorDNS_x64.exe25%ReversingLabsWin64.Trojan.Bingoml
anchorDNS_x64.exe100%Joe Sandbox ML

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
http://pesterbdd.com/images/Pester.png0%URL Reputationsafe
http://pesterbdd.com/images/Pester.png0%URL Reputationsafe
http://pesterbdd.com/images/Pester.png0%URL Reputationsafe
http://pesterbdd.com/images/Pester.png0%URL Reputationsafe
https://go.micro0%URL Reputationsafe
https://go.micro0%URL Reputationsafe
https://go.micro0%URL Reputationsafe
https://go.micro0%URL Reputationsafe
https://contoso.com/0%URL Reputationsafe
https://contoso.com/0%URL Reputationsafe
https://contoso.com/0%URL Reputationsafe
https://contoso.com/0%URL Reputationsafe
https://contoso.com/License0%URL Reputationsafe
https://contoso.com/License0%URL Reputationsafe
https://contoso.com/License0%URL Reputationsafe
https://contoso.com/License0%URL Reputationsafe
https://contoso.com/Icon0%URL Reputationsafe
https://contoso.com/Icon0%URL Reputationsafe
https://contoso.com/Icon0%URL Reputationsafe
https://contoso.com/Icon0%URL Reputationsafe

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
http://nuget.org/NuGet.exepowershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpfalse
    high
    http://pesterbdd.com/images/Pester.pngpowershell.exe, 00000006.00000002.230782159.0000012B7D140000.00000004.00000001.sdmp, powershell.exe, 00000006.00000002.218129835.0000012B00210000.00000004.00000001.sdmpfalse
    • URL Reputation: safe
    • URL Reputation: safe
    • URL Reputation: safe
    • URL Reputation: safe
    unknown
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 00000006.00000002.217765028.0000012B00001000.00000004.00000001.sdmpfalse
      high
      http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 00000006.00000002.230782159.0000012B7D140000.00000004.00000001.sdmp, powershell.exe, 00000006.00000002.218129835.0000012B00210000.00000004.00000001.sdmpfalse
        high
        https://go.micropowershell.exe, 00000006.00000002.224611933.0000012B01C61000.00000004.00000001.sdmpfalse
        • URL Reputation: safe
        • URL Reputation: safe
        • URL Reputation: safe
        • URL Reputation: safe
        unknown
        https://github.com/Pester/Pesterpowershell.exe, 00000006.00000002.230782159.0000012B7D140000.00000004.00000001.sdmp, powershell.exe, 00000006.00000002.218129835.0000012B00210000.00000004.00000001.sdmpfalse
          high
          https://contoso.com/powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpfalse
          • URL Reputation: safe
          • URL Reputation: safe
          • URL Reputation: safe
          • URL Reputation: safe
          unknown
          https://nuget.org/nuget.exepowershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpfalse
            high
            https://contoso.com/Licensepowershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpfalse
            • URL Reputation: safe
            • URL Reputation: safe
            • URL Reputation: safe
            • URL Reputation: safe
            unknown
            https://contoso.com/Iconpowershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmpfalse
            • URL Reputation: safe
            • URL Reputation: safe
            • URL Reputation: safe
            • URL Reputation: safe
            unknown

            Contacted IPs

            No contacted IP infos

            General Information

            Joe Sandbox Version:31.0.0 Emerald
            Analysis ID:381811
            Start date:05.04.2021
            Start time:07:12:13
            Joe Sandbox Product:CloudBasic
            Overall analysis duration:0h 3m 41s
            Hypervisor based Inspection enabled:false
            Report type:full
            Sample file name:anchorDNS_x64.exe
            Cookbook file name:default.jbs
            Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
            Number of analysed new started processes analysed:11
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • HDC enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:MAL
            Classification:mal56.evad.winEXE@11/4@0/0
            EGA Information:
            • Successful, ratio: 50%
            HDC Information:
            • Successful, ratio: 100% (good quality ratio 88.2%)
            • Quality average: 66.5%
            • Quality standard deviation: 33.4%
            HCA Information:
            • Successful, ratio: 53%
            • Number of executed functions: 22
            • Number of non-executed functions: 112
            Cookbook Comments:
            • Adjust boot time
            • Enable AMSI
            • Found application associated with file extension: .exe
            • Stop behavior analysis, all processes terminated
            Warnings:
            Show All
            • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe
            • Execution Graph export aborted for target powershell.exe, PID 6456 because it is empty

            Simulations

            Behavior and APIs

            TimeTypeDescription
            07:13:02API Interceptor45x Sleep call for process: powershell.exe modified

            Joe Sandbox View / Context

            IPs

            No context

            Domains

            No context

            ASN

            No context

            JA3 Fingerprints

            No context

            Dropped Files

            No context

            Created / dropped Files

            C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
            Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
            File Type:data
            Category:dropped
            Size (bytes):64
            Entropy (8bit):0.9260988789684415
            Encrypted:false
            SSDEEP:3:Nlllulb/lj:NllUb/l
            MD5:13AF6BE1CB30E2FB779EA728EE0A6D67
            SHA1:F33581AC2C60B1F02C978D14DC220DCE57CC9562
            SHA-256:168561FB18F8EBA8043FA9FC4B8A95B628F2CF5584E5A3B96C9EBAF6DD740E3F
            SHA-512:1159E1087BC7F7CBB233540B61F1BDECB161FF6C65AD1EFC9911E87B8E4B2E5F8C2AF56D67B33BC1F6836106D3FEA8C750CC24B9F451ACF85661E0715B829413
            Malicious:false
            Reputation:high, very likely benign file
            Preview: @...e................................................@..........
            C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_0nn5oih2.opl.ps1
            Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
            File Type:very short file (no magic)
            Category:dropped
            Size (bytes):1
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:3:U:U
            MD5:C4CA4238A0B923820DCC509A6F75849B
            SHA1:356A192B7913B04C54574D18C28D46E6395428AB
            SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
            SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
            Malicious:false
            Reputation:high, very likely benign file
            Preview: 1
            C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_mmyrl5t1.x3u.psm1
            Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
            File Type:very short file (no magic)
            Category:dropped
            Size (bytes):1
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:3:U:U
            MD5:C4CA4238A0B923820DCC509A6F75849B
            SHA1:356A192B7913B04C54574D18C28D46E6395428AB
            SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
            SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
            Malicious:false
            Reputation:high, very likely benign file
            Preview: 1
            C:\Users\user\Documents\20210405\PowerShell_transcript.980108.ial1LKzt.20210405071301.txt
            Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
            File Type:UTF-8 Unicode (with BOM) text, with CRLF line terminators
            Category:dropped
            Size (bytes):3372
            Entropy (8bit):5.398935195102093
            Encrypted:false
            SSDEEP:96:BZ9uh8NvqDo1ZHrZ9Ph8NvqDo1ZHqq8NF8NF2LqZrr:hBToHiiamr
            MD5:62E57036AEB9786FD3F177050567D62F
            SHA1:988AD6610E949A985DC2598B4CAFECCCC573E812
            SHA-256:65B1BDE81C296B43C79EADB7F6E8ADEC632C4FF2DE6273CE8BF43AB36DCED0E8
            SHA-512:1750544293022954D6B80789AF398AD241460118D0168E9C323BE05A747AE05A16D57F61225D23FA4EDC27648B00AD42D04DCD1C11A1AF2409FEED0983DADDA3
            Malicious:false
            Reputation:low
            Preview: .**********************..Windows PowerShell transcript start..Start time: 20210405071301..Username: computer\user..RunAs User: computer\user..Configuration Name: ..Machine: 980108 (Microsoft Windows NT 10.0.17134.0)..Host Application: PowerShell Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe..Process ID: 6456..PSVersion: 5.1.17134.1..PSEdition: Desktop..PSCompatibleVersions: 1.0, 2.0, 3.0, 4.0, 5.0, 5.1.17134.1..BuildVersion: 10.0.17134.1..CLRVersion: 4.0.30319.42000..WSManStackVersion: 3.0..PSRemotingProtocolVersion: 2.3..SerializationVersion: 1.1.0.1..**********************..**********************..Command start time: 20210405071301..**********************..PS>Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe..**********************..Windows PowerShell transcript start..Start time: 20210405071739..Username: computer\user..RunAs User: computer\user..Configuration Name: ..Machine: 980108 (Microsoft Windows NT 10.0

            Static File Info

            General

            File type:PE32+ executable (GUI) x86-64, for MS Windows
            Entropy (8bit):6.560316865693318
            TrID:
            • Win64 Executable GUI (202006/5) 92.65%
            • Win64 Executable (generic) (12005/4) 5.51%
            • Generic Win/DOS Executable (2004/3) 0.92%
            • DOS Executable Generic (2002/1) 0.92%
            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
            File name:anchorDNS_x64.exe
            File size:347648
            MD5:7160ac4abb26f0ca4c1b6dfba44f8d36
            SHA1:3820ff0d04a233745c79932b77eccfe743a81d34
            SHA256:9fdbd76141ec43b6867f091a2dca503edb2a85e4b98a4500611f5fe484109513
            SHA512:d52fd1c50865aae16d63a1a7d00d29a2642ddece12b004cfa85e2abcfa25e178d1570aecdafaffefe4889906b81c92f2a2a7ca9032faabe73309f4ba33b70d93
            SSDEEP:6144:eC1p/6YfIQrMRU+YqwQR/off22+IJdxKgpCzl2Ac:vb3oK+r/oX22Tb6zl
            File Content Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d......_.........."......(...".................@..........................................`........................................

            File Icon

            Icon Hash:00828e8e8686b000

            Static PE Info

            General

            Entrypoint:0x14002ad04
            Entrypoint Section:.text
            Digitally signed:false
            Imagebase:0x140000000
            Subsystem:windows gui
            Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
            DLL Characteristics:TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
            Time Stamp:0x5FCA06FB [Fri Dec 4 09:52:59 2020 UTC]
            TLS Callbacks:
            CLR (.Net) Version:
            OS Version Major:6
            OS Version Minor:0
            File Version Major:6
            File Version Minor:0
            Subsystem Version Major:6
            Subsystem Version Minor:0
            Import Hash:e2450fb3cc5b1b7305e3193fe03f3369

            Entrypoint Preview

            Instruction
            dec eax
            sub esp, 28h
            call 00007F61C4D4A5E0h
            dec eax
            add esp, 28h
            jmp 00007F61C4D4A44Fh
            int3
            int3
            dec eax
            mov dword ptr [esp+20h], ebx
            push ebp
            dec eax
            mov ebp, esp
            dec eax
            sub esp, 20h
            dec eax
            mov eax, dword ptr [000273BCh]
            dec eax
            mov ebx, 2DDFA232h
            cdq
            sub eax, dword ptr [eax]
            add byte ptr [eax+3Bh], cl
            ret
            jne 00007F61C4D4A646h
            dec eax
            and dword ptr [ebp+18h], 00000000h
            dec eax
            lea ecx, dword ptr [ebp+18h]
            call dword ptr [00022906h]
            dec eax
            mov eax, dword ptr [ebp+18h]
            dec eax
            mov dword ptr [ebp+10h], eax
            call dword ptr [00022878h]
            mov eax, eax
            dec eax
            xor dword ptr [ebp+10h], eax
            call dword ptr [00022864h]
            mov eax, eax
            dec eax
            lea ecx, dword ptr [ebp+20h]
            dec eax
            xor dword ptr [ebp+10h], eax
            call dword ptr [0002296Ch]
            mov eax, dword ptr [ebp+20h]
            dec eax
            lea ecx, dword ptr [ebp+10h]
            dec eax
            shl eax, 20h
            dec eax
            xor eax, dword ptr [ebp+20h]
            dec eax
            xor eax, dword ptr [ebp+10h]
            dec eax
            xor eax, ecx
            dec eax
            mov ecx, FFFFFFFFh

            Data Directories

            NameVirtual AddressVirtual Size Is in Section
            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_IMPORT0x4d0300x8c.rdata
            IMAGE_DIRECTORY_ENTRY_RESOURCE0x5e0000x260.rsrc
            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x560000x25e0.pdata
            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
            IMAGE_DIRECTORY_ENTRY_BASERELOC0x5f0000x6d0.reloc
            IMAGE_DIRECTORY_ENTRY_DEBUG0x4cefe0x1c.rdata
            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
            IMAGE_DIRECTORY_ENTRY_TLS0x4a1700x28.rdata
            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x445b00x130.rdata
            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_IAT0x4d4580x398.rdata
            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

            Sections

            NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
            .text0x10000x426760x42800False0.550010279605data6.70629418853IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
            .rdata0x440000xd8040xda00False0.422717173165data5.15584786179IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .data0x520000x3a280xc00False0.167317708333data2.31158956423IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
            .pdata0x560000x25e00x2600False0.481907894737data5.68387884943IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .00cfg0x590000x280x200False0.05859375data0.42098230856IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .addr0x5a0000x840x200False0.0390625ASCII text, with no line terminators0.881747790692IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
            .rand0x5b0000x100x200False0.03125ASCII text, with no line terminators0.200622324313IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .tls0x5c0000x90x200False0.033203125data0.0203931352361IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
            _RDATA0x5d0000x940x200False0.208984375data1.42653530093IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .rsrc0x5e0000x2600x400False0.33203125data3.65313012836IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .reloc0x5f0000x6d00x800False0.55078125data5.07768877682IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

            Resources

            NameRVASizeTypeLanguageCountry
            RT_MANIFEST0x5e0600x1fbXML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminatorsEnglishUnited States

            Imports

            DLLImport
            USER32.dllCloseDesktop, CreateDesktopA
            OLEAUT32.dllSysAllocString, SysFreeString, VariantClear, VariantInit
            ADVAPI32.dllAdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken
            WS2_32.dllWSAGetLastError, freeaddrinfo, getaddrinfo, htonl
            RPCRT4.dllUuidCreate
            KERNEL32.dllCloseHandle, CreateEventW, CreateFileA, CreateFileW, CreateRemoteThread, CreateThread, DeleteCriticalSection, EncodePointer, EnterCriticalSection, ExitProcess, ExitThread, FileTimeToSystemTime, FindClose, FindFirstFileExW, FindNextFileW, FlushFileBuffers, FormatMessageA, FreeEnvironmentStringsW, FreeLibrary, FreeLibraryAndExitThread, GetACP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetConsoleCP, GetConsoleMode, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetEnvironmentStringsW, GetFileSize, GetFileType, GetLastError, GetLocalTime, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleExW, GetModuleHandleW, GetOEMCP, GetProcAddress, GetProcessHeap, GetStartupInfoW, GetStdHandle, GetStringTypeW, GetSystemTimeAsFileTime, GetTickCount, GetTickCount64, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, InitializeCriticalSectionAndSpinCount, InitializeSListHead, IsDebuggerPresent, IsProcessorFeaturePresent, IsValidCodePage, LCMapStringW, LeaveCriticalSection, LoadLibraryExW, LocalAlloc, LocalFree, MultiByteToWideChar, QueryPerformanceCounter, RaiseException, ResetEvent, RtlCaptureContext, RtlLookupFunctionEntry, RtlPcToFileHeader, RtlUnwindEx, RtlVirtualUnwind, SetEndOfFile, SetEvent, SetFilePointer, SetFilePointerEx, SetLastError, SetStdHandle, SetUnhandledExceptionFilter, Sleep, SystemTimeToFileTime, TerminateProcess, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, UnhandledExceptionFilter, VirtualAlloc, VirtualAllocEx, VirtualFree, WTSGetActiveConsoleSessionId, WaitForSingleObjectEx, WideCharToMultiByte, WriteConsoleW, WriteFile, WriteProcessMemory, lstrcmpA

            Possible Origin

            Language of compilation systemCountry where language is spokenMap
            EnglishUnited States

            Network Behavior

            No network behavior found

            Code Manipulations

            Statistics

            CPU Usage

            Click to jump to process

            Memory Usage

            Click to jump to process

            High Level Behavior Distribution

            Click to dive into process behavior distribution

            Behavior

            Click to jump to process

            System Behavior

            General

            Start time:07:12:59
            Start date:05/04/2021
            Path:C:\Users\user\Desktop\anchorDNS_x64.exe
            Wow64 process (32bit):false
            Commandline:'C:\Users\user\Desktop\anchorDNS_x64.exe'
            Imagebase:0x7ff63ec00000
            File size:347648 bytes
            MD5 hash:7160AC4ABB26F0CA4C1B6DFBA44F8D36
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low

            General

            Start time:07:12:59
            Start date:05/04/2021
            Path:C:\Windows\System32\cmd.exe
            Wow64 process (32bit):false
            Commandline:cmd.exe /c timeout 3 && del C:\Users\user\Desktop\anchorDNS_x64.exe
            Imagebase:0x7ff77d8b0000
            File size:273920 bytes
            MD5 hash:4E2ACF4F8A396486AB4268C94A6A245F
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:high

            General

            Start time:07:12:59
            Start date:05/04/2021
            Path:C:\Windows\System32\cmd.exe
            Wow64 process (32bit):false
            Commandline:cmd.exe /C PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe'
            Imagebase:0x7ff77d8b0000
            File size:273920 bytes
            MD5 hash:4E2ACF4F8A396486AB4268C94A6A245F
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:high

            General

            Start time:07:12:59
            Start date:05/04/2021
            Path:C:\Windows\System32\conhost.exe
            Wow64 process (32bit):false
            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Imagebase:0x7ff6b2800000
            File size:625664 bytes
            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:high

            General

            Start time:07:13:00
            Start date:05/04/2021
            Path:C:\Windows\System32\conhost.exe
            Wow64 process (32bit):false
            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Imagebase:0x7ff6b2800000
            File size:625664 bytes
            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:high

            General

            Start time:07:13:00
            Start date:05/04/2021
            Path:C:\Windows\System32\timeout.exe
            Wow64 process (32bit):false
            Commandline:timeout 3
            Imagebase:0x7ff6c1c10000
            File size:30720 bytes
            MD5 hash:EB9A65078396FB5D4E3813BB9198CB18
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:moderate

            General

            Start time:07:13:00
            Start date:05/04/2021
            Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
            Wow64 process (32bit):false
            Commandline:PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe'
            Imagebase:0x7ff785e30000
            File size:447488 bytes
            MD5 hash:95000560239032BC68B4C2FDFCDEF913
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:.Net C# or VB.NET
            Reputation:high

            Disassembly

            Code Analysis

            Reset < >

              Execution Graph

              Execution Coverage:2.7%
              Dynamic/Decrypted Code Coverage:0%
              Signature Coverage:27.9%
              Total number of Nodes:2000
              Total number of Limit Nodes:14

              Graph

              execution_graph 21661 7ff63ec34db8 21664 7ff63ec34de8 21661->21664 21671 7ff63ec395c8 EnterCriticalSection 21664->21671 17944 7ff63ec2ab90 17976 7ff63ec29d60 17944->17976 17947 7ff63ec2acdc 18084 7ff63ec2a284 IsProcessorFeaturePresent 17947->18084 17948 7ff63ec2abac __scrt_acquire_startup_lock 17950 7ff63ec2ace6 17948->17950 17951 7ff63ec2abca 17948->17951 17952 7ff63ec2a284 7 API calls 17950->17952 17961 7ff63ec2abeb __FrameHandler3::FrameUnwindToEmptyState __scrt_release_startup_lock 17951->17961 17984 7ff63ec3590c 17951->17984 17954 7ff63ec2acf1 17952->17954 18049 7ff63ec349ec 17954->18049 17957 7ff63ec2abef 17960 7ff63ec2ac75 17989 7ff63ec2a1d8 17960->17989 17961->17957 17961->17960 18060 7ff63ec34a24 17961->18060 17963 7ff63ec2ac7a 17992 7ff63ec35600 17963->17992 18102 7ff63ec2a6cc 17976->18102 17979 7ff63ec29d8f 18104 7ff63ec2c5a4 17979->18104 17980 7ff63ec29d8b 17980->17947 17980->17948 17985 7ff63ec3591f 17984->17985 17986 7ff63ec3593c 17985->17986 18147 7ff63ec298cc InitializeCriticalSectionAndSpinCount GetModuleHandleW 17985->18147 18161 7ff63ec2aaac 17985->18161 17986->17961 18682 7ff63ec2bf20 17989->18682 17993 7ff63ec39f04 40 API calls 17992->17993 17994 7ff63ec3560f 17993->17994 17995 7ff63ec2ac82 17994->17995 17996 7ff63ec3dae4 40 API calls 17994->17996 17997 7ff63ec0d0fe 17995->17997 17996->17994 18684 7ff63ec0df6c 17997->18684 17999 7ff63ec0d133 17999->17999 18693 7ff63ec0e192 17999->18693 18001 7ff63ec0d205 18002 7ff63ec0d232 18001->18002 18005 7ff63ec0d2eb 18001->18005 18003 7ff63ec0e192 66 API calls 18002->18003 18004 7ff63ec0d2c2 18003->18004 18007 7ff63ec0d2cc 18004->18007 18716 7ff63ec0f1c7 18004->18716 18005->18005 18008 7ff63ec0e192 66 API calls 18005->18008 18772 7ff63ec169fc 18007->18772 18011 7ff63ec0d379 18008->18011 18011->18011 18012 7ff63ec0e192 66 API calls 18011->18012 18013 7ff63ec0d3f9 18012->18013 18776 7ff63ec1945a 18013->18776 18016 7ff63ec0e192 66 API calls 18017 7ff63ec0d4ae 18016->18017 18018 7ff63ec1945a 9 API calls 18017->18018 18019 7ff63ec0d4b5 18018->18019 18020 7ff63ec0e192 66 API calls 18019->18020 18021 7ff63ec0d718 18020->18021 18782 7ff63ec05b21 18021->18782 18023 7ff63ec0d730 18786 7ff63ec0e56f 18023->18786 18025 7ff63ec0d8bf 18027 7ff63ec0e56f 32 API calls 18025->18027 18029 7ff63ec0d942 18027->18029 18028 7ff63ec0e56f 32 API calls 18031 7ff63ec0d852 18028->18031 18033 7ff63ec0d94b 18029->18033 18790 7ff63ec0e8ec 18029->18790 18031->18025 18032 7ff63ec0e56f 32 API calls 18031->18032 18035 7ff63ec0d8b7 18032->18035 18034 7ff63ec0e192 66 API calls 18033->18034 18034->18004 18035->18025 18036 7ff63ec0dd29 18035->18036 18828 7ff63ec0e66d 18036->18828 18039 7ff63ec0dd36 __scrt_get_show_window_mode 18042 7ff63ec05b21 8 API calls 18039->18042 18040 7ff63ec0de68 18041 7ff63ec0e192 66 API calls 18040->18041 18041->18033 18043 7ff63ec0dd5e 18042->18043 18043->18033 18044 7ff63ec05b21 8 API calls 18043->18044 18047 7ff63ec0ddba 18044->18047 18045 7ff63ec0de2d 18045->18033 18046 7ff63ec05b21 8 API calls 18045->18046 18046->18033 18047->18045 18842 7ff63ec0e78f 18047->18842 18050 7ff63ec34b1c 18049->18050 18051 7ff63ec34b39 GetModuleHandleW 18050->18051 18052 7ff63ec34b83 18050->18052 18051->18052 18058 7ff63ec34b46 18051->18058 20731 7ff63ec34c9c 18052->20731 18058->18052 20745 7ff63ec34a68 GetModuleHandleExW 18058->20745 18061 7ff63ec34a48 18060->18061 18062 7ff63ec34a5a 18060->18062 18061->17960 20759 7ff63ec37030 18062->20759 18085 7ff63ec2a2a9 _invalid_parameter_noinfo_noreturn __scrt_get_show_window_mode 18084->18085 18086 7ff63ec2a2c8 RtlCaptureContext RtlLookupFunctionEntry 18085->18086 18087 7ff63ec2a32d __scrt_get_show_window_mode 18086->18087 18088 7ff63ec2a2f1 RtlVirtualUnwind 18086->18088 18089 7ff63ec2a35f IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 18087->18089 18088->18087 18090 7ff63ec2a3b1 _invalid_parameter_noinfo_noreturn 18089->18090 18090->17950 18103 7ff63ec29d82 __scrt_dllmain_crt_thread_attach 18102->18103 18103->17979 18103->17980 18105 7ff63ec3a98c 18104->18105 18106 7ff63ec29d94 18105->18106 18114 7ff63ec39c48 18105->18114 18106->17980 18108 7ff63ec2b960 18106->18108 18109 7ff63ec2b968 18108->18109 18110 7ff63ec2b972 18108->18110 18126 7ff63ec377bc 18109->18126 18110->17980 18125 7ff63ec395c8 EnterCriticalSection 18114->18125 18127 7ff63ec2b96d 18126->18127 18128 7ff63ec377cb 18126->18128 18130 7ff63ec38eb4 18127->18130 18134 7ff63ec3e118 18128->18134 18131 7ff63ec38edf 18130->18131 18132 7ff63ec38ee3 18131->18132 18133 7ff63ec38ec2 DeleteCriticalSection 18131->18133 18132->18110 18133->18131 18138 7ff63ec3e260 18134->18138 18139 7ff63ec3e13f TlsFree 18138->18139 18144 7ff63ec3e2a3 try_get_function 18138->18144 18140 7ff63ec3e2d0 LoadLibraryExW 18142 7ff63ec3e347 18140->18142 18143 7ff63ec3e2f1 GetLastError 18140->18143 18141 7ff63ec3e367 GetProcAddress 18141->18139 18142->18141 18145 7ff63ec3e35e FreeLibrary 18142->18145 18143->18144 18144->18139 18144->18140 18144->18141 18146 7ff63ec3e313 LoadLibraryExW 18144->18146 18145->18141 18146->18142 18146->18144 18148 7ff63ec298fd GetModuleHandleW 18147->18148 18149 7ff63ec29912 GetProcAddress GetProcAddress 18147->18149 18148->18149 18150 7ff63ec29991 18148->18150 18151 7ff63ec2993a 18149->18151 18152 7ff63ec2994f CreateEventW 18149->18152 18154 7ff63ec2a284 7 API calls 18150->18154 18151->18152 18153 7ff63ec2993f 18151->18153 18152->18150 18152->18153 18180 7ff63ec29dd8 18153->18180 18156 7ff63ec2999b 18154->18156 18157 7ff63ec29974 18157->18150 18158 7ff63ec29978 18157->18158 18185 7ff63ec29c14 18158->18185 18162 7ff63ec2aabc 18161->18162 18203 7ff63ec35edc 18162->18203 18164 7ff63ec2aac8 18165 7ff63ec29dd8 7 API calls 18164->18165 18166 7ff63ec2aae0 _RTC_Initialize 18165->18166 18169 7ff63ec29c14 33 API calls 18166->18169 18178 7ff63ec2ab43 18166->18178 18167 7ff63ec2a284 7 API calls 18168 7ff63ec2ab61 18167->18168 18168->17985 18170 7ff63ec2aaf5 18169->18170 18209 7ff63ec34e58 18170->18209 18178->18167 18179 7ff63ec2ab51 18178->18179 18179->17985 18181 7ff63ec29de9 18180->18181 18184 7ff63ec29dee __scrt_acquire_startup_lock 18180->18184 18182 7ff63ec2a284 7 API calls 18181->18182 18181->18184 18183 7ff63ec29e62 18182->18183 18184->18157 18188 7ff63ec29c2c 18185->18188 18187 7ff63ec29984 18187->17985 18189 7ff63ec29c46 18188->18189 18191 7ff63ec29c3f 18188->18191 18192 7ff63ec3522c 18189->18192 18191->18187 18195 7ff63ec35588 18192->18195 18202 7ff63ec395c8 EnterCriticalSection 18195->18202 18204 7ff63ec35eed 18203->18204 18208 7ff63ec35ef5 18204->18208 18243 7ff63ec3b18c 18204->18243 18208->18164 18210 7ff63ec34e78 18209->18210 18231 7ff63ec2ab01 18209->18231 18211 7ff63ec34e96 18210->18211 18212 7ff63ec34e80 18210->18212 18363 7ff63ec39f04 18211->18363 18213 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18212->18213 18215 7ff63ec34e85 18213->18215 18217 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18215->18217 18216 7ff63ec34e9b 18367 7ff63ec3d8b0 GetModuleFileNameW 18216->18367 18217->18231 18224 7ff63ec34f0d 18226 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18224->18226 18225 7ff63ec34f25 18227 7ff63ec35040 40 API calls 18225->18227 18228 7ff63ec34f12 18226->18228 18229 7ff63ec34f41 18227->18229 18230 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18228->18230 18240 7ff63ec34f47 18229->18240 18391 7ff63ec3ceec 18229->18391 18230->18231 18231->18178 18242 7ff63ec2adcc InitializeSListHead 18231->18242 18233 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18233->18231 18235 7ff63ec34f8c 18238 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18235->18238 18236 7ff63ec34f73 18237 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18236->18237 18239 7ff63ec34f7c 18237->18239 18238->18240 18241 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18239->18241 18240->18233 18241->18231 18249 7ff63ec39804 GetLastError 18243->18249 18245 7ff63ec35f04 18246 7ff63ec3594c 18245->18246 18331 7ff63ec35b48 18246->18331 18250 7ff63ec39826 18249->18250 18251 7ff63ec3982b 18249->18251 18272 7ff63ec39030 18250->18272 18255 7ff63ec39833 SetLastError 18251->18255 18276 7ff63ec39078 18251->18276 18255->18245 18259 7ff63ec3987f 18262 7ff63ec39078 _invalid_parameter_noinfo 6 API calls 18259->18262 18260 7ff63ec3986f 18261 7ff63ec39078 _invalid_parameter_noinfo 6 API calls 18260->18261 18263 7ff63ec39876 18261->18263 18264 7ff63ec39887 18262->18264 18288 7ff63ec3a94c 18263->18288 18265 7ff63ec3989d 18264->18265 18266 7ff63ec3988b 18264->18266 18293 7ff63ec39958 18265->18293 18268 7ff63ec39078 _invalid_parameter_noinfo 6 API calls 18266->18268 18268->18263 18298 7ff63ec39370 18272->18298 18277 7ff63ec39370 try_get_function 5 API calls 18276->18277 18278 7ff63ec390a6 18277->18278 18279 7ff63ec390b8 TlsSetValue 18278->18279 18280 7ff63ec390b0 18278->18280 18279->18280 18280->18255 18281 7ff63ec3c4d8 18280->18281 18282 7ff63ec3c4e9 _invalid_parameter_noinfo 18281->18282 18283 7ff63ec3c51e RtlAllocateHeap 18282->18283 18284 7ff63ec3c53a 18282->18284 18308 7ff63ec34cd4 18282->18308 18283->18282 18285 7ff63ec39861 18283->18285 18286 7ff63ec3b18c _set_errno_from_matherr 12 API calls 18284->18286 18285->18259 18285->18260 18286->18285 18289 7ff63ec3a983 18288->18289 18290 7ff63ec3a951 HeapFree 18288->18290 18289->18255 18290->18289 18291 7ff63ec3a96c 18290->18291 18292 7ff63ec3b18c _set_errno_from_matherr 12 API calls 18291->18292 18292->18289 18317 7ff63ec39b20 18293->18317 18299 7ff63ec39057 TlsGetValue 18298->18299 18306 7ff63ec393cc try_get_function 18298->18306 18300 7ff63ec394b4 18300->18299 18303 7ff63ec394c2 GetProcAddress 18300->18303 18301 7ff63ec39400 LoadLibraryW 18302 7ff63ec39421 GetLastError 18301->18302 18301->18306 18302->18306 18304 7ff63ec394d3 18303->18304 18304->18299 18305 7ff63ec39499 FreeLibrary 18305->18306 18306->18299 18306->18300 18306->18301 18306->18305 18307 7ff63ec3945b LoadLibraryExW 18306->18307 18307->18306 18311 7ff63ec34d0c 18308->18311 18316 7ff63ec395c8 EnterCriticalSection 18311->18316 18329 7ff63ec395c8 EnterCriticalSection 18317->18329 18332 7ff63ec39804 _invalid_parameter_noinfo 13 API calls 18331->18332 18333 7ff63ec35b6d 18332->18333 18334 7ff63ec35965 18333->18334 18337 7ff63ec3599c IsProcessorFeaturePresent 18333->18337 18334->18208 18338 7ff63ec359af 18337->18338 18341 7ff63ec359e4 18338->18341 18342 7ff63ec35a1e _invalid_parameter_noinfo_noreturn __scrt_get_show_window_mode 18341->18342 18343 7ff63ec35a46 RtlCaptureContext RtlLookupFunctionEntry 18342->18343 18344 7ff63ec35ab6 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 18343->18344 18345 7ff63ec35a80 RtlVirtualUnwind 18343->18345 18348 7ff63ec35b08 _invalid_parameter_noinfo_noreturn 18344->18348 18345->18344 18349 7ff63ec29bf0 18348->18349 18350 7ff63ec29bfa 18349->18350 18351 7ff63ec2a4e0 IsProcessorFeaturePresent 18350->18351 18352 7ff63ec29c06 GetCurrentProcess TerminateProcess 18350->18352 18353 7ff63ec2a4f7 18351->18353 18358 7ff63ec2a624 RtlCaptureContext 18353->18358 18359 7ff63ec2a63e RtlLookupFunctionEntry 18358->18359 18360 7ff63ec2a50a 18359->18360 18361 7ff63ec2a654 RtlVirtualUnwind 18359->18361 18362 7ff63ec2a698 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 18360->18362 18361->18359 18361->18360 18364 7ff63ec39f40 18363->18364 18365 7ff63ec39f11 18363->18365 18364->18216 18414 7ff63ec3975c 18365->18414 18368 7ff63ec3d8f6 GetLastError 18367->18368 18369 7ff63ec3d90a 18367->18369 18514 7ff63ec3b1cc 18368->18514 18519 7ff63ec2c678 18369->18519 18373 7ff63ec3d949 18530 7ff63ec3d9d0 18373->18530 18374 7ff63ec29bf0 _handle_error 8 API calls 18377 7ff63ec34eb2 18374->18377 18379 7ff63ec35040 18377->18379 18378 7ff63ec3d903 18378->18374 18381 7ff63ec3507e 18379->18381 18383 7ff63ec350e4 18381->18383 18571 7ff63ec3dae4 18381->18571 18382 7ff63ec34eef 18385 7ff63ec34fe0 18382->18385 18383->18382 18384 7ff63ec3dae4 40 API calls 18383->18384 18384->18383 18386 7ff63ec34ff8 18385->18386 18390 7ff63ec34f05 18385->18390 18387 7ff63ec3c4d8 _invalid_parameter_noinfo 13 API calls 18386->18387 18386->18390 18388 7ff63ec35026 18387->18388 18389 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18388->18389 18389->18390 18390->18224 18390->18225 18392 7ff63ec3d1f8 18391->18392 18393 7ff63ec3d21e 18392->18393 18399 7ff63ec3d234 18392->18399 18394 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18393->18394 18395 7ff63ec3d223 18394->18395 18397 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18395->18397 18401 7ff63ec34f6d 18397->18401 18398 7ff63ec34fe0 13 API calls 18406 7ff63ec3d314 18398->18406 18400 7ff63ec3d2a1 18399->18400 18409 7ff63ec3d294 18399->18409 18575 7ff63ec415a0 18399->18575 18584 7ff63ec3d404 18399->18584 18400->18398 18401->18235 18401->18236 18402 7ff63ec3d389 18404 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18402->18404 18404->18409 18405 7ff63ec3d3ca 18408 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18405->18408 18406->18402 18406->18406 18411 7ff63ec3d3ec 18406->18411 18606 7ff63ec414c0 18406->18606 18407 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18407->18409 18408->18401 18409->18405 18409->18407 18412 7ff63ec3599c _invalid_parameter_noinfo_noreturn 17 API calls 18411->18412 18413 7ff63ec3d400 18412->18413 18415 7ff63ec3976d 18414->18415 18418 7ff63ec39772 18414->18418 18416 7ff63ec39030 _invalid_parameter_noinfo 6 API calls 18415->18416 18416->18418 18417 7ff63ec39078 _invalid_parameter_noinfo 6 API calls 18419 7ff63ec39791 18417->18419 18418->18417 18420 7ff63ec3977a 18418->18420 18419->18420 18422 7ff63ec3c4d8 _invalid_parameter_noinfo 13 API calls 18419->18422 18425 7ff63ec397f4 18420->18425 18439 7ff63ec3771c 18420->18439 18424 7ff63ec397a4 18422->18424 18426 7ff63ec397c2 18424->18426 18427 7ff63ec397b2 18424->18427 18425->18364 18429 7ff63ec39078 _invalid_parameter_noinfo 6 API calls 18426->18429 18428 7ff63ec39078 _invalid_parameter_noinfo 6 API calls 18427->18428 18430 7ff63ec397b9 18428->18430 18431 7ff63ec397ca 18429->18431 18434 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18430->18434 18432 7ff63ec397e0 18431->18432 18433 7ff63ec397ce 18431->18433 18436 7ff63ec39958 _invalid_parameter_noinfo 13 API calls 18432->18436 18435 7ff63ec39078 _invalid_parameter_noinfo 6 API calls 18433->18435 18434->18420 18435->18430 18437 7ff63ec397e8 18436->18437 18438 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18437->18438 18438->18420 18450 7ff63ec3aa68 18439->18450 18478 7ff63ec3ad04 18450->18478 18483 7ff63ec395c8 EnterCriticalSection 18478->18483 18515 7ff63ec39804 _invalid_parameter_noinfo 13 API calls 18514->18515 18516 7ff63ec3b1dd 18515->18516 18517 7ff63ec39804 _invalid_parameter_noinfo 13 API calls 18516->18517 18518 7ff63ec3b1f6 18517->18518 18518->18378 18520 7ff63ec2c697 18519->18520 18521 7ff63ec2c69c 18519->18521 18520->18373 18527 7ff63ec38f64 18520->18527 18521->18520 18522 7ff63ec39688 __FrameHandler3::FrameUnwindToEmptyState 40 API calls 18521->18522 18523 7ff63ec2c6b7 18522->18523 18544 7ff63ec3b680 18523->18544 18528 7ff63ec39370 try_get_function 5 API calls 18527->18528 18529 7ff63ec38f84 18528->18529 18529->18373 18531 7ff63ec3da0d 18530->18531 18539 7ff63ec3d9f4 18530->18539 18534 7ff63ec3da12 18531->18534 18568 7ff63ec3dc08 18531->18568 18536 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18534->18536 18534->18539 18536->18539 18539->18378 18545 7ff63ec2c6da 18544->18545 18546 7ff63ec3b695 18544->18546 18548 7ff63ec3b6b4 18545->18548 18546->18545 18552 7ff63ec3ce18 18546->18552 18549 7ff63ec3b6c9 18548->18549 18551 7ff63ec3b6dc 18548->18551 18549->18551 18565 7ff63ec39ee8 18549->18565 18551->18520 18553 7ff63ec39688 __FrameHandler3::FrameUnwindToEmptyState 40 API calls 18552->18553 18554 7ff63ec3ce27 18553->18554 18555 7ff63ec3ce70 18554->18555 18564 7ff63ec395c8 EnterCriticalSection 18554->18564 18555->18545 18566 7ff63ec39688 __FrameHandler3::FrameUnwindToEmptyState 40 API calls 18565->18566 18567 7ff63ec39ef1 18566->18567 18569 7ff63ec3dc24 WideCharToMultiByte 18568->18569 18572 7ff63ec3daf8 18571->18572 18573 7ff63ec2c678 40 API calls 18572->18573 18574 7ff63ec3db1c 18573->18574 18574->18381 18578 7ff63ec415da 18575->18578 18576 7ff63ec41696 18576->18399 18577 7ff63ec41a18 18615 7ff63ec2a4cc 18577->18615 18578->18399 18578->18576 18578->18577 18581 7ff63ec419af 18578->18581 18582 7ff63ec29bf0 _handle_error 8 API calls 18581->18582 18583 7ff63ec41a0e 18582->18583 18583->18399 18585 7ff63ec3d432 18584->18585 18585->18585 18586 7ff63ec3c4d8 _invalid_parameter_noinfo 13 API calls 18585->18586 18587 7ff63ec3d47d 18586->18587 18588 7ff63ec414c0 30 API calls 18587->18588 18589 7ff63ec3d4b3 18588->18589 18590 7ff63ec3599c _invalid_parameter_noinfo_noreturn 17 API calls 18589->18590 18591 7ff63ec3d58a 18590->18591 18592 7ff63ec2c678 40 API calls 18591->18592 18593 7ff63ec3d667 18592->18593 18594 7ff63ec38f64 5 API calls 18593->18594 18595 7ff63ec3d695 18594->18595 18628 7ff63ec3cef4 18595->18628 18598 7ff63ec3d718 18599 7ff63ec2c678 40 API calls 18598->18599 18600 7ff63ec3d74b 18599->18600 18601 7ff63ec38f64 5 API calls 18600->18601 18602 7ff63ec3d773 18601->18602 18650 7ff63ec3d06c 18602->18650 18605 7ff63ec3d404 45 API calls 18607 7ff63ec414d8 18606->18607 18609 7ff63ec414dd 18607->18609 18612 7ff63ec414f3 18607->18612 18613 7ff63ec41522 18607->18613 18608 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18610 7ff63ec414e7 18608->18610 18609->18608 18609->18612 18611 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18610->18611 18611->18612 18612->18406 18613->18612 18614 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18613->18614 18614->18610 18618 7ff63ec2a430 IsProcessorFeaturePresent 18615->18618 18619 7ff63ec2a446 18618->18619 18624 7ff63ec2a5b4 RtlCaptureContext RtlLookupFunctionEntry 18619->18624 18625 7ff63ec2a45a 18624->18625 18626 7ff63ec2a5e4 RtlVirtualUnwind 18624->18626 18627 7ff63ec2a698 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 18625->18627 18626->18625 18629 7ff63ec3cf1d 18628->18629 18630 7ff63ec3cf3f 18628->18630 18634 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18629->18634 18640 7ff63ec3cf2b FindFirstFileExW 18629->18640 18631 7ff63ec3cf98 18630->18631 18632 7ff63ec3cf43 18630->18632 18679 7ff63ec3ca88 18631->18679 18635 7ff63ec3cf57 18632->18635 18636 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18632->18636 18632->18640 18634->18640 18672 7ff63ec3b264 18635->18672 18636->18635 18640->18598 18651 7ff63ec3d0b7 18650->18651 18652 7ff63ec3d095 18650->18652 18653 7ff63ec3d0bc 18651->18653 18654 7ff63ec3d110 18651->18654 18656 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18652->18656 18658 7ff63ec3d0a3 18652->18658 18653->18658 18660 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18653->18660 18663 7ff63ec3d0d0 18653->18663 18655 7ff63ec3dc08 WideCharToMultiByte 18654->18655 18657 7ff63ec3d134 18655->18657 18656->18658 18659 7ff63ec3d13b GetLastError 18657->18659 18665 7ff63ec3d16b 18657->18665 18669 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18657->18669 18671 7ff63ec3d176 18657->18671 18658->18605 18662 7ff63ec3b1cc 13 API calls 18659->18662 18660->18663 18661 7ff63ec3b264 14 API calls 18661->18658 18664 7ff63ec3d148 18662->18664 18663->18661 18668 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18664->18668 18670 7ff63ec3b264 14 API calls 18665->18670 18666 7ff63ec3dc08 WideCharToMultiByte 18667 7ff63ec3d1c7 18666->18667 18667->18658 18667->18659 18668->18658 18669->18665 18670->18671 18671->18658 18671->18666 18673 7ff63ec3b2af 18672->18673 18677 7ff63ec3b273 _invalid_parameter_noinfo 18672->18677 18675 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18673->18675 18674 7ff63ec3b296 RtlAllocateHeap 18676 7ff63ec3b2ad 18674->18676 18674->18677 18675->18676 18676->18640 18677->18673 18677->18674 18678 7ff63ec34cd4 _invalid_parameter_noinfo 2 API calls 18677->18678 18678->18677 18680 7ff63ec3ca90 MultiByteToWideChar 18679->18680 18683 7ff63ec2a1ef GetStartupInfoW 18682->18683 18683->17963 18856 7ff63ec2984c 18684->18856 18686 7ff63ec0df9b 18865 7ff63ec36e78 18686->18865 18688 7ff63ec0dfd1 18689 7ff63ec0e0bf 18688->18689 18690 7ff63ec03d68 32 API calls 18688->18690 18691 7ff63ec170aa 32 API calls 18688->18691 18692 7ff63ec04059 30 API calls 18688->18692 18689->17999 18690->18688 18691->18688 18692->18688 18694 7ff63ec0e54b 18693->18694 18695 7ff63ec0e1dc 18693->18695 18696 7ff63ec29bf0 _handle_error 8 API calls 18694->18696 18887 7ff63ec2c784 18695->18887 18697 7ff63ec0e55b 18696->18697 18697->18001 18699 7ff63ec0e21e 18902 7ff63ec2c78c 18699->18902 18702 7ff63ec0e3be 18702->18702 18703 7ff63ec0e3cf GetCurrentProcessId 18702->18703 18913 7ff63ec03ce5 18703->18913 18706 7ff63ec05b21 8 API calls 18707 7ff63ec0e458 18706->18707 18708 7ff63ec05b21 8 API calls 18707->18708 18710 7ff63ec0e539 __vcrt_freefls 18707->18710 18709 7ff63ec0e4b9 18708->18709 18919 7ff63ec06bcc 18709->18919 18710->18694 18712 7ff63ec0e4e0 18713 7ff63ec06bcc 60 API calls 18712->18713 18714 7ff63ec0e50e 18713->18714 18715 7ff63ec05b21 8 API calls 18714->18715 18715->18710 18717 7ff63ec0f1d9 18716->18717 18718 7ff63ec05b21 8 API calls 18717->18718 18720 7ff63ec0f215 18718->18720 18719 7ff63ec0f73c 18719->18007 18720->18719 19429 7ff63ec16c24 18720->19429 18722 7ff63ec0f312 19443 7ff63ec16015 18722->19443 18727 7ff63ec0f3df 19455 7ff63ec098d2 18727->19455 18728 7ff63ec0f384 18730 7ff63ec05b21 8 API calls 18728->18730 18731 7ff63ec0f3a3 18730->18731 18732 7ff63ec05b21 8 API calls 18731->18732 18735 7ff63ec0f3cc 18732->18735 18734 7ff63ec0f4e2 18738 7ff63ec16c24 32 API calls 18734->18738 18735->18734 19470 7ff63ec04059 18735->19470 18740 7ff63ec0f566 18738->18740 18743 7ff63ec16015 43 API calls 18740->18743 18741 7ff63ec37050 30 API calls 18742 7ff63ec0f436 18741->18742 18744 7ff63ec08cfe 60 API calls 18742->18744 18746 7ff63ec0f591 18743->18746 18745 7ff63ec0f43b 18744->18745 18745->18735 18751 7ff63ec05b21 8 API calls 18745->18751 18747 7ff63ec08cfe 60 API calls 18746->18747 18748 7ff63ec0f596 CreateProcessW 18747->18748 18749 7ff63ec0f5ca 18748->18749 18750 7ff63ec0f625 18748->18750 18753 7ff63ec05b21 8 API calls 18749->18753 18752 7ff63ec098d2 60 API calls 18750->18752 18754 7ff63ec0f48e 18751->18754 18758 7ff63ec0f62a 18752->18758 18755 7ff63ec0f5e9 18753->18755 18757 7ff63ec05b21 8 API calls 18754->18757 18756 7ff63ec05b21 8 API calls 18755->18756 18759 7ff63ec0f612 18756->18759 18757->18735 18758->18759 18761 7ff63ec37050 30 API calls 18758->18761 18759->18719 18760 7ff63ec04059 30 API calls 18759->18760 18760->18719 18762 7ff63ec0f668 18761->18762 18763 7ff63ec37050 30 API calls 18762->18763 18764 7ff63ec0f67c 18763->18764 18765 7ff63ec37050 30 API calls 18764->18765 18766 7ff63ec0f690 18765->18766 18767 7ff63ec08cfe 60 API calls 18766->18767 18768 7ff63ec0f695 18767->18768 18768->18759 18769 7ff63ec05b21 8 API calls 18768->18769 18770 7ff63ec0f6e8 18769->18770 18771 7ff63ec05b21 8 API calls 18770->18771 18771->18759 18773 7ff63ec16a1b 18772->18773 18774 7ff63ec16a2e 18772->18774 18773->18774 19692 7ff63ec16a42 18773->19692 18777 7ff63ec19474 18776->18777 18778 7ff63ec0d400 18777->18778 18779 7ff63ec2999c _Init_thread_header 5 API calls 18777->18779 18778->18016 18780 7ff63ec1956d 18779->18780 18780->18778 18781 7ff63ec29a34 4 API calls 18780->18781 18781->18778 18783 7ff63ec05b32 18782->18783 18785 7ff63ec05b55 18782->18785 18783->18785 19696 7ff63ec05947 18783->19696 18785->18023 18787 7ff63ec0d7c0 18786->18787 18788 7ff63ec0e58e 18786->18788 18787->18025 18787->18028 18788->18787 19715 7ff63ec03d68 18788->19715 18791 7ff63ec05b21 8 API calls 18790->18791 18792 7ff63ec0e929 18791->18792 18793 7ff63ec05b21 8 API calls 18792->18793 18794 7ff63ec0e952 18793->18794 19726 7ff63ec0926e 18794->19726 18798 7ff63ec0e984 memcpy_s __scrt_get_show_window_mode 19738 7ff63ec03575 18798->19738 18801 7ff63ec05b21 8 API calls 18805 7ff63ec0eb0b 18801->18805 18802 7ff63ec0f198 18803 7ff63ec29bf0 _handle_error 8 API calls 18802->18803 18804 7ff63ec0f1b2 18803->18804 18804->18033 18805->18802 18806 7ff63ec05b21 8 API calls 18805->18806 18807 7ff63ec0eb4f 18806->18807 18808 7ff63ec0ef09 18807->18808 18810 7ff63ec0eb68 18807->18810 18809 7ff63ec05b21 8 API calls 18808->18809 18812 7ff63ec0ef21 18809->18812 18814 7ff63ec0e192 66 API calls 18810->18814 18811 7ff63ec05b21 8 API calls 18813 7ff63ec0f176 18811->18813 18815 7ff63ec05b21 8 API calls 18812->18815 18824 7ff63ec0ef04 18812->18824 18817 7ff63ec05b21 8 API calls 18813->18817 18814->18824 18816 7ff63ec0ef64 18815->18816 18820 7ff63ec0f119 18816->18820 19742 7ff63ec1890e 18816->19742 18817->18802 18819 7ff63ec0f0f0 18821 7ff63ec05b21 8 API calls 18819->18821 18822 7ff63ec05b21 8 API calls 18820->18822 18821->18820 18822->18824 18824->18811 18825 7ff63ec0e192 66 API calls 18826 7ff63ec0f0d1 18825->18826 18827 7ff63ec05b21 8 API calls 18826->18827 18827->18819 19810 7ff63ec0f80e 18828->19810 18830 7ff63ec0e687 19869 7ff63ec103fd 18830->19869 18832 7ff63ec0e690 18833 7ff63ec0e696 18832->18833 18834 7ff63ec0e6a5 18832->18834 20114 7ff63ec21e56 18833->20114 18837 7ff63ec0e192 66 API calls 18834->18837 18839 7ff63ec0e6a0 18837->18839 18840 7ff63ec29bf0 _handle_error 8 API calls 18839->18840 18841 7ff63ec0dd2e 18840->18841 18841->18039 18841->18040 18843 7ff63ec0e8b7 18842->18843 18844 7ff63ec0e7cb 18842->18844 18847 7ff63ec0e8c6 LocalFree 18843->18847 18848 7ff63ec0e8cc 18843->18848 20713 7ff63ec0aed2 18844->20713 18847->18848 18849 7ff63ec29bf0 _handle_error 8 API calls 18848->18849 18850 7ff63ec0e8dc 18849->18850 18850->18045 18851 7ff63ec0e87c 18851->18843 18853 7ff63ec0e8af LocalFree 18851->18853 18853->18843 18857 7ff63ec29857 18856->18857 18858 7ff63ec29870 18857->18858 18859 7ff63ec34cd4 _invalid_parameter_noinfo 2 API calls 18857->18859 18860 7ff63ec29876 18857->18860 18858->18686 18859->18857 18861 7ff63ec29881 18860->18861 18874 7ff63ec2a190 18860->18874 18878 7ff63ec2a1b0 18861->18878 18866 7ff63ec36e8f 18865->18866 18867 7ff63ec36e85 18865->18867 18868 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18866->18868 18867->18866 18869 7ff63ec36eaa 18867->18869 18873 7ff63ec36e96 18868->18873 18871 7ff63ec36ea2 18869->18871 18872 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18869->18872 18870 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18870->18871 18871->18688 18872->18873 18873->18870 18875 7ff63ec2a19e std::bad_alloc::bad_alloc 18874->18875 18882 7ff63ec2ae90 18875->18882 18877 7ff63ec2a1af 18879 7ff63ec2a1be 18878->18879 18880 7ff63ec2ae90 Concurrency::cancel_current_task 2 API calls 18879->18880 18881 7ff63ec2a1cf 18880->18881 18883 7ff63ec2aecc RtlPcToFileHeader 18882->18883 18884 7ff63ec2aeaf 18882->18884 18885 7ff63ec2aee4 18883->18885 18886 7ff63ec2aef3 RaiseException 18883->18886 18884->18883 18885->18886 18886->18877 18888 7ff63ec2c85c 18887->18888 18889 7ff63ec2c89b 18888->18889 18890 7ff63ec2c8bd 18888->18890 18891 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18889->18891 18892 7ff63ec2c678 40 API calls 18890->18892 18893 7ff63ec2c8a0 18891->18893 18895 7ff63ec2c8ce 18892->18895 18894 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18893->18894 18901 7ff63ec2c8ab 18894->18901 18925 7ff63ec2cacc 18895->18925 18897 7ff63ec29bf0 _handle_error 8 API calls 18898 7ff63ec2c9f5 18897->18898 18898->18699 18899 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 18899->18901 18901->18897 18903 7ff63ec2c7d6 18902->18903 18904 7ff63ec2c79a 18902->18904 18905 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18903->18905 18904->18903 18906 7ff63ec2c7a4 18904->18906 18907 7ff63ec2c7ce 18905->18907 19267 7ff63ec2da78 18906->19267 18909 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18907->18909 18911 7ff63ec0e262 GetLocalTime 18909->18911 18911->18702 18912 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18912->18907 18914 7ff63ec03d1b 18913->18914 18915 7ff63ec2c78c 45 API calls 18914->18915 18916 7ff63ec03d3a 18915->18916 18917 7ff63ec29bf0 _handle_error 8 API calls 18916->18917 18918 7ff63ec03d54 18917->18918 18918->18706 18920 7ff63ec06ced 18919->18920 19298 7ff63ec06480 18920->19298 18923 7ff63ec29bf0 _handle_error 8 API calls 18924 7ff63ec06edd 18923->18924 18924->18712 18926 7ff63ec2caef 18925->18926 18927 7ff63ec2ccc2 18925->18927 18928 7ff63ec2caf6 18926->18928 18938 7ff63ec2cb0d 18926->18938 18929 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18927->18929 18930 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18928->18930 18932 7ff63ec2ccc7 18929->18932 18933 7ff63ec2cafb 18930->18933 18931 7ff63ec2c96d 18931->18899 18934 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18932->18934 18935 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18933->18935 18934->18931 18935->18931 18938->18927 18938->18931 18941 7ff63ec2d00c 18938->18941 18957 7ff63ec2ce98 18938->18957 18979 7ff63ec2cdf4 18938->18979 18987 7ff63ec2ccd8 18938->18987 18942 7ff63ec2d093 18941->18942 18952 7ff63ec2d03d 18941->18952 18943 7ff63ec2d097 18942->18943 18944 7ff63ec2d112 18942->18944 18947 7ff63ec2d0f8 18943->18947 18949 7ff63ec2d09f 18943->18949 19013 7ff63ec2d43c 18944->19013 18946 7ff63ec2d075 18956 7ff63ec2d11b 18946->18956 18994 7ff63ec2d274 18946->18994 18998 7ff63ec2d81c 18947->18998 18954 7ff63ec2d084 18949->18954 18949->18956 19004 7ff63ec2d654 18949->19004 18952->18944 18952->18946 18952->18949 18953 7ff63ec2d069 18952->18953 18952->18954 18952->18956 18953->18944 18953->18946 18953->18954 18954->18956 19019 7ff63ec2d8f8 18954->19019 18956->18938 18958 7ff63ec2cebc 18957->18958 18959 7ff63ec2cea3 18957->18959 18961 7ff63ec2cee0 18958->18961 18962 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18958->18962 18960 7ff63ec2d093 18959->18960 18959->18961 18974 7ff63ec2d03d 18959->18974 18964 7ff63ec2d097 18960->18964 18965 7ff63ec2d112 18960->18965 18961->18938 18963 7ff63ec2ced5 18962->18963 18966 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18963->18966 18969 7ff63ec2d0f8 18964->18969 18971 7ff63ec2d09f 18964->18971 18967 7ff63ec2d43c 41 API calls 18965->18967 18966->18961 18976 7ff63ec2d084 18967->18976 18968 7ff63ec2d075 18972 7ff63ec2d274 42 API calls 18968->18972 18978 7ff63ec2d11b 18968->18978 18970 7ff63ec2d81c 30 API calls 18969->18970 18970->18976 18973 7ff63ec2d654 31 API calls 18971->18973 18971->18976 18971->18978 18972->18976 18973->18976 18974->18965 18974->18968 18974->18971 18975 7ff63ec2d069 18974->18975 18974->18976 18974->18978 18975->18965 18975->18968 18975->18976 18977 7ff63ec2d8f8 42 API calls 18976->18977 18976->18978 18977->18978 18978->18938 18980 7ff63ec2ce1a 18979->18980 18981 7ff63ec2ce15 18979->18981 19203 7ff63ec3b2f0 18980->19203 18982 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18981->18982 18982->18980 18985 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18986 7ff63ec2ce57 18985->18986 18986->18938 19261 7ff63ec2cd4c 18987->19261 18990 7ff63ec3b18c _set_errno_from_matherr 13 API calls 18991 7ff63ec2cd39 18990->18991 18993 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 18991->18993 18992 7ff63ec2ccec 18992->18938 18993->18992 18996 7ff63ec2d285 18994->18996 18995 7ff63ec2d2e0 18995->18954 18996->18995 19025 7ff63ec3b4d0 18996->19025 19000 7ff63ec2d844 18998->19000 18999 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19001 7ff63ec2d84d 18999->19001 19000->18999 19003 7ff63ec2d858 19000->19003 19002 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19001->19002 19002->19003 19003->18954 19005 7ff63ec2d686 19004->19005 19006 7ff63ec2d6c1 19005->19006 19007 7ff63ec2d700 19005->19007 19008 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19006->19008 19012 7ff63ec2d6d1 19007->19012 19057 7ff63ec2df0c 19007->19057 19010 7ff63ec2d6c6 19008->19010 19011 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19010->19011 19011->19012 19012->18954 19014 7ff63ec2d454 19013->19014 19015 7ff63ec2df0c 14 API calls 19014->19015 19016 7ff63ec2d49a 19015->19016 19067 7ff63ec3b6e8 19016->19067 19018 7ff63ec2d560 19018->18954 19023 7ff63ec2d985 19019->19023 19024 7ff63ec2d91f 19019->19024 19020 7ff63ec29bf0 _handle_error 8 API calls 19022 7ff63ec2d9bd 19020->19022 19021 7ff63ec3b4d0 42 API calls 19021->19024 19022->18956 19023->19020 19024->19021 19024->19023 19028 7ff63ec3b4e4 19025->19028 19029 7ff63ec3b507 19028->19029 19030 7ff63ec3b4df 19029->19030 19031 7ff63ec3b52b 19029->19031 19032 7ff63ec3b541 19029->19032 19030->18995 19033 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19031->19033 19034 7ff63ec2c678 40 API calls 19032->19034 19035 7ff63ec3b530 19033->19035 19036 7ff63ec3b54e 19034->19036 19037 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19035->19037 19038 7ff63ec3b55d 19036->19038 19039 7ff63ec3b58b 19036->19039 19037->19030 19053 7ff63ec3f9cc 19038->19053 19040 7ff63ec3b595 19039->19040 19043 7ff63ec3dc08 WideCharToMultiByte 19039->19043 19042 7ff63ec3b5a3 __scrt_get_show_window_mode 19040->19042 19050 7ff63ec3b5e9 __scrt_get_show_window_mode 19040->19050 19042->19030 19047 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19042->19047 19045 7ff63ec3b62f 19043->19045 19045->19042 19046 7ff63ec3b644 GetLastError 19045->19046 19046->19042 19046->19050 19047->19030 19048 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19048->19030 19049 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19051 7ff63ec3b66f 19049->19051 19050->19030 19050->19049 19052 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19051->19052 19052->19030 19054 7ff63ec3f9e3 19053->19054 19055 7ff63ec3b572 19053->19055 19054->19055 19056 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19054->19056 19055->19030 19055->19048 19056->19055 19058 7ff63ec2df41 19057->19058 19059 7ff63ec2df32 19057->19059 19061 7ff63ec2df37 19058->19061 19062 7ff63ec3b264 14 API calls 19058->19062 19060 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19059->19060 19060->19061 19061->19012 19063 7ff63ec2df6e 19062->19063 19064 7ff63ec2df82 19063->19064 19065 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 19063->19065 19066 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 19064->19066 19065->19064 19066->19061 19068 7ff63ec3b70d 19067->19068 19069 7ff63ec3b725 19067->19069 19070 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19068->19070 19069->19068 19073 7ff63ec3b73c 19069->19073 19071 7ff63ec3b712 19070->19071 19072 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19071->19072 19082 7ff63ec3b71e 19072->19082 19076 7ff63ec3b84a 19073->19076 19088 7ff63ec3b784 19073->19088 19074 7ff63ec3b989 19155 7ff63ec3bc9c 19074->19155 19076->19074 19077 7ff63ec3b950 19076->19077 19078 7ff63ec3b8c3 19076->19078 19081 7ff63ec3b887 19076->19081 19085 7ff63ec3b879 19076->19085 19148 7ff63ec3bbc0 19077->19148 19105 7ff63ec3fb64 19078->19105 19095 7ff63ec3c150 19081->19095 19082->19018 19085->19077 19087 7ff63ec3b882 19085->19087 19087->19078 19087->19081 19088->19082 19090 7ff63ec36e78 __std_exception_copy 30 API calls 19088->19090 19089 7ff63ec3b91d 19089->19082 19145 7ff63ec3c00c 19089->19145 19091 7ff63ec3b839 19090->19091 19091->19082 19093 7ff63ec3599c _invalid_parameter_noinfo_noreturn 17 API calls 19091->19093 19094 7ff63ec3b9eb 19093->19094 19096 7ff63ec3fb64 30 API calls 19095->19096 19097 7ff63ec3c194 19096->19097 19098 7ff63ec3fa80 30 API calls 19097->19098 19100 7ff63ec3c1cd 19098->19100 19099 7ff63ec3c22a 19165 7ff63ec3b9ec 19099->19165 19100->19099 19101 7ff63ec3c1ed 19100->19101 19104 7ff63ec3c1d1 19100->19104 19103 7ff63ec3c00c 40 API calls 19101->19103 19103->19104 19104->19082 19108 7ff63ec3fbb2 fegetenv 19105->19108 19106 7ff63ec3fc13 19107 7ff63ec36e78 __std_exception_copy 30 API calls 19106->19107 19109 7ff63ec40d71 19107->19109 19108->19106 19120 7ff63ec3fc92 __scrt_get_show_window_mode 19108->19120 19110 7ff63ec40d80 19109->19110 19113 7ff63ec40d12 19109->19113 19111 7ff63ec3599c _invalid_parameter_noinfo_noreturn 17 API calls 19110->19111 19112 7ff63ec40d94 19111->19112 19114 7ff63ec29bf0 _handle_error 8 API calls 19113->19114 19115 7ff63ec3b8ed 19114->19115 19136 7ff63ec3fa80 19115->19136 19116 7ff63ec406a6 19193 7ff63ec2f5b0 19116->19193 19118 7ff63ec405bc 19118->19116 19184 7ff63ec2f400 19118->19184 19119 7ff63ec3fd40 memcpy_s 19127 7ff63ec406c2 memcpy_s __scrt_get_show_window_mode 19119->19127 19131 7ff63ec401d2 memcpy_s __scrt_get_show_window_mode 19119->19131 19120->19119 19122 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19120->19122 19123 7ff63ec401b2 19122->19123 19124 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19123->19124 19124->19119 19126 7ff63ec2f400 memcpy_s 30 API calls 19129 7ff63ec40ba0 19126->19129 19127->19116 19127->19118 19130 7ff63ec3b18c 13 API calls _set_errno_from_matherr 19127->19130 19135 7ff63ec3594c 30 API calls _invalid_parameter_noinfo 19127->19135 19128 7ff63ec3b18c 13 API calls _set_errno_from_matherr 19128->19131 19129->19113 19132 7ff63ec2f5b0 30 API calls 19129->19132 19134 7ff63ec2f400 memcpy_s 30 API calls 19129->19134 19130->19127 19131->19118 19131->19128 19133 7ff63ec3594c 30 API calls _invalid_parameter_noinfo 19131->19133 19132->19129 19133->19131 19134->19129 19135->19127 19137 7ff63ec3faad 19136->19137 19141 7ff63ec3fa95 19136->19141 19140 7ff63ec3fac7 19137->19140 19137->19141 19138 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19139 7ff63ec3fa9a 19138->19139 19143 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19139->19143 19142 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19140->19142 19141->19138 19144 7ff63ec3faa6 memcpy_s 19141->19144 19142->19139 19143->19144 19144->19089 19146 7ff63ec2c678 40 API calls 19145->19146 19147 7ff63ec3c03c memcpy_s __scrt_get_show_window_mode 19146->19147 19147->19082 19149 7ff63ec3fb64 30 API calls 19148->19149 19150 7ff63ec3bc0a 19149->19150 19151 7ff63ec3fa80 30 API calls 19150->19151 19152 7ff63ec3bc40 19151->19152 19153 7ff63ec3bc44 19152->19153 19154 7ff63ec3b9ec 40 API calls 19152->19154 19153->19082 19154->19153 19156 7ff63ec2c678 40 API calls 19155->19156 19157 7ff63ec3bcea 19156->19157 19158 7ff63ec3bd0a 19157->19158 19159 7ff63ec3bcf5 19157->19159 19162 7ff63ec3bbc0 40 API calls 19158->19162 19164 7ff63ec3bd05 __scrt_get_show_window_mode 19158->19164 19160 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19159->19160 19161 7ff63ec3bcfa 19160->19161 19163 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19161->19163 19162->19164 19163->19164 19164->19082 19166 7ff63ec3ba51 19165->19166 19167 7ff63ec3ba23 19165->19167 19169 7ff63ec2c678 40 API calls 19166->19169 19168 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19167->19168 19170 7ff63ec3ba28 19168->19170 19173 7ff63ec3ba63 memcpy_s 19169->19173 19171 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19170->19171 19172 7ff63ec3ba34 19171->19172 19172->19104 19174 7ff63ec36e78 __std_exception_copy 30 API calls 19173->19174 19177 7ff63ec3bafc memcpy_s 19174->19177 19175 7ff63ec3599c _invalid_parameter_noinfo_noreturn 17 API calls 19176 7ff63ec3bbbd 19175->19176 19178 7ff63ec3fb64 30 API calls 19176->19178 19177->19175 19179 7ff63ec3bc0a 19178->19179 19180 7ff63ec3fa80 30 API calls 19179->19180 19181 7ff63ec3bc40 19180->19181 19182 7ff63ec3bc44 19181->19182 19183 7ff63ec3b9ec 40 API calls 19181->19183 19182->19104 19183->19182 19188 7ff63ec2f41d memcpy_s 19184->19188 19189 7ff63ec2f421 __scrt_get_show_window_mode 19184->19189 19185 7ff63ec2f426 19186 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19185->19186 19187 7ff63ec2f42b 19186->19187 19191 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19187->19191 19188->19116 19189->19185 19189->19188 19190 7ff63ec2f461 19189->19190 19190->19188 19192 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19190->19192 19191->19188 19192->19187 19194 7ff63ec2f5d8 19193->19194 19202 7ff63ec2f61b 19193->19202 19195 7ff63ec2f5fc 19194->19195 19196 7ff63ec2f622 19194->19196 19194->19202 19197 7ff63ec2f400 memcpy_s 30 API calls 19195->19197 19198 7ff63ec2f627 19196->19198 19199 7ff63ec2f65d 19196->19199 19197->19202 19200 7ff63ec2f400 memcpy_s 30 API calls 19198->19200 19201 7ff63ec2f400 memcpy_s 30 API calls 19199->19201 19200->19202 19201->19202 19202->19126 19202->19129 19204 7ff63ec3b303 19203->19204 19207 7ff63ec36088 19204->19207 19208 7ff63ec360c9 19207->19208 19209 7ff63ec360b4 19207->19209 19208->19209 19211 7ff63ec360d7 19208->19211 19210 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19209->19210 19212 7ff63ec360b9 19210->19212 19213 7ff63ec2c678 40 API calls 19211->19213 19214 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19212->19214 19216 7ff63ec360e4 19213->19216 19225 7ff63ec2ce46 19214->19225 19218 7ff63ec36116 19216->19218 19228 7ff63ec2f388 19216->19228 19217 7ff63ec36181 19219 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19217->19219 19221 7ff63ec3627c 19217->19221 19218->19217 19220 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19218->19220 19223 7ff63ec36271 19219->19223 19224 7ff63ec361bd 19220->19224 19222 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19221->19222 19221->19225 19222->19225 19226 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19223->19226 19227 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19224->19227 19225->18985 19225->18986 19226->19221 19227->19217 19229 7ff63ec2f3ab 19228->19229 19230 7ff63ec2f3d4 19228->19230 19232 7ff63ec2f3b6 19229->19232 19234 7ff63ec3c364 19229->19234 19241 7ff63ec3c2c4 19230->19241 19232->19216 19235 7ff63ec2c678 40 API calls 19234->19235 19237 7ff63ec3c39d 19235->19237 19236 7ff63ec3c3a9 19238 7ff63ec29bf0 _handle_error 8 API calls 19236->19238 19237->19236 19246 7ff63ec3c8f8 19237->19246 19240 7ff63ec3c453 19238->19240 19240->19232 19242 7ff63ec39688 __FrameHandler3::FrameUnwindToEmptyState 40 API calls 19241->19242 19243 7ff63ec3c2cd 19242->19243 19244 7ff63ec3b680 40 API calls 19243->19244 19245 7ff63ec3c2e6 19244->19245 19245->19232 19247 7ff63ec2c678 40 API calls 19246->19247 19248 7ff63ec3c93a 19247->19248 19249 7ff63ec3ca88 MultiByteToWideChar 19248->19249 19250 7ff63ec3c970 19249->19250 19251 7ff63ec3c977 19250->19251 19253 7ff63ec3b264 14 API calls 19250->19253 19255 7ff63ec3c99c __scrt_get_show_window_mode 19250->19255 19252 7ff63ec29bf0 _handle_error 8 API calls 19251->19252 19254 7ff63ec3ca6b 19252->19254 19253->19255 19254->19236 19256 7ff63ec3ca88 MultiByteToWideChar 19255->19256 19257 7ff63ec3ca34 19255->19257 19258 7ff63ec3ca16 19256->19258 19257->19251 19259 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 19257->19259 19258->19257 19260 7ff63ec3ca1a GetStringTypeW 19258->19260 19259->19251 19260->19257 19262 7ff63ec2cd65 19261->19262 19263 7ff63ec2cce8 19262->19263 19264 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19262->19264 19263->18990 19263->18992 19265 7ff63ec2cdde 19264->19265 19266 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19265->19266 19266->19263 19268 7ff63ec2dab7 19267->19268 19269 7ff63ec2dacf 19267->19269 19270 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19268->19270 19269->19268 19271 7ff63ec2dad9 19269->19271 19272 7ff63ec2dabc 19270->19272 19273 7ff63ec2c678 40 API calls 19271->19273 19274 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19272->19274 19275 7ff63ec2daea 19273->19275 19280 7ff63ec2dac7 19274->19280 19282 7ff63ec2e1b8 19275->19282 19277 7ff63ec29bf0 _handle_error 8 API calls 19278 7ff63ec2c7bd 19277->19278 19278->18911 19278->18912 19279 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 19279->19280 19280->19277 19283 7ff63ec2e3bc 19282->19283 19284 7ff63ec2e1e1 19282->19284 19286 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19283->19286 19285 7ff63ec2e1e7 19284->19285 19293 7ff63ec2e1fe 19284->19293 19288 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19285->19288 19287 7ff63ec2e3c1 19286->19287 19290 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19287->19290 19291 7ff63ec2e1ec 19288->19291 19289 7ff63ec2db89 19289->19279 19290->19289 19292 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19291->19292 19292->19289 19293->19283 19293->19289 19294 7ff63ec2ccd8 30 API calls 19293->19294 19295 7ff63ec2cdf4 43 API calls 19293->19295 19296 7ff63ec2ce98 43 API calls 19293->19296 19297 7ff63ec2d00c 43 API calls 19293->19297 19294->19293 19295->19293 19296->19293 19297->19293 19317 7ff63ec06398 19298->19317 19302 7ff63ec35f50 40 API calls 19304 7ff63ec064b1 19302->19304 19304->19302 19309 7ff63ec06574 19304->19309 19316 7ff63ec06614 19304->19316 19305 7ff63ec2984c 4 API calls 19308 7ff63ec064d7 19305->19308 19306 7ff63ec065aa 19307 7ff63ec2984c 4 API calls 19306->19307 19312 7ff63ec065b4 19307->19312 19308->19304 19310 7ff63ec05b21 8 API calls 19308->19310 19309->19306 19311 7ff63ec35f50 40 API calls 19309->19311 19309->19316 19310->19304 19311->19309 19313 7ff63ec065f2 19312->19313 19314 7ff63ec06046 60 API calls 19312->19314 19315 7ff63ec05b21 8 API calls 19313->19315 19313->19316 19314->19313 19315->19316 19316->18923 19318 7ff63ec063a6 19317->19318 19326 7ff63ec063df 19317->19326 19319 7ff63ec2984c 4 API calls 19318->19319 19320 7ff63ec063b0 19319->19320 19320->19326 19346 7ff63ec2999c EnterCriticalSection 19320->19346 19326->19304 19327 7ff63ec06046 19326->19327 19354 7ff63ec05fb6 19327->19354 19330 7ff63ec060ca 19334 7ff63ec06104 19330->19334 19335 7ff63ec060e9 19330->19335 19392 7ff63ec35f50 19330->19392 19331 7ff63ec2984c 4 API calls 19333 7ff63ec06078 19331->19333 19336 7ff63ec05b21 8 API calls 19333->19336 19334->19304 19334->19305 19335->19334 19337 7ff63ec06106 19335->19337 19339 7ff63ec35f50 40 API calls 19335->19339 19338 7ff63ec060a8 19336->19338 19340 7ff63ec2984c 4 API calls 19337->19340 19364 7ff63ec042e4 19338->19364 19339->19335 19341 7ff63ec06110 19340->19341 19343 7ff63ec05b21 8 API calls 19341->19343 19344 7ff63ec06139 19343->19344 19345 7ff63ec042e4 60 API calls 19344->19345 19345->19334 19347 7ff63ec299b2 19346->19347 19348 7ff63ec299b7 LeaveCriticalSection 19347->19348 19351 7ff63ec29a94 19347->19351 19352 7ff63ec29aa8 19351->19352 19353 7ff63ec29ac5 LeaveCriticalSection WaitForSingleObjectEx EnterCriticalSection 19351->19353 19352->19353 19355 7ff63ec05fc4 19354->19355 19363 7ff63ec05ffd 19354->19363 19356 7ff63ec2984c 4 API calls 19355->19356 19357 7ff63ec05fce 19356->19357 19358 7ff63ec2999c _Init_thread_header 5 API calls 19357->19358 19357->19363 19359 7ff63ec06015 19358->19359 19360 7ff63ec29c14 33 API calls 19359->19360 19359->19363 19361 7ff63ec06038 19360->19361 19407 7ff63ec29a34 EnterCriticalSection LeaveCriticalSection 19361->19407 19363->19330 19363->19331 19365 7ff63ec05b21 8 API calls 19364->19365 19366 7ff63ec04337 19365->19366 19367 7ff63ec05b21 8 API calls 19366->19367 19368 7ff63ec043ae 19367->19368 19369 7ff63ec043b7 CreateFileA 19368->19369 19372 7ff63ec046b3 19368->19372 19370 7ff63ec043f0 19369->19370 19369->19372 19371 7ff63ec05b21 8 API calls 19370->19371 19375 7ff63ec0440e 19371->19375 19373 7ff63ec29bf0 _handle_error 8 API calls 19372->19373 19374 7ff63ec05684 19373->19374 19374->19330 19375->19375 19379 7ff63ec047ac 19375->19379 19411 7ff63ec09b74 19375->19411 19378 7ff63ec045e2 19417 7ff63ec09ca4 19378->19417 19379->19372 19380 7ff63ec05b21 8 API calls 19379->19380 19382 7ff63ec0566a 19380->19382 19382->19372 19384 7ff63ec0566f FindCloseChangeNotification 19382->19384 19384->19372 19385 7ff63ec04f60 19423 7ff63ec09f0a 19385->19423 19387 7ff63ec05b21 8 API calls 19389 7ff63ec0460b 19387->19389 19388 7ff63ec04f65 GetLastError 19388->19389 19389->19385 19389->19387 19389->19388 19390 7ff63ec0a16e 54 API calls 19389->19390 19391 7ff63ec050c4 GetLastError 19389->19391 19390->19389 19391->19389 19393 7ff63ec35f5d 19392->19393 19394 7ff63ec35f8a 19392->19394 19396 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19393->19396 19403 7ff63ec35f81 19393->19403 19395 7ff63ec35fad 19394->19395 19398 7ff63ec35fc9 19394->19398 19397 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19395->19397 19399 7ff63ec35f67 19396->19399 19400 7ff63ec35fb2 19397->19400 19401 7ff63ec2c678 40 API calls 19398->19401 19402 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19399->19402 19404 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19400->19404 19406 7ff63ec35fbd 19401->19406 19405 7ff63ec35f72 19402->19405 19403->19330 19404->19406 19405->19330 19406->19330 19408 7ff63ec29af8 19407->19408 19409 7ff63ec29b08 19408->19409 19410 7ff63ec29b1a SetEvent ResetEvent 19408->19410 19412 7ff63ec09bf3 19411->19412 19413 7ff63ec06480 60 API calls 19412->19413 19414 7ff63ec09c89 19413->19414 19415 7ff63ec29bf0 _handle_error 8 API calls 19414->19415 19416 7ff63ec045b8 CreateFileMappingA 19415->19416 19416->19378 19416->19379 19418 7ff63ec09d05 19417->19418 19419 7ff63ec06480 60 API calls 19418->19419 19420 7ff63ec09eeb 19419->19420 19421 7ff63ec29bf0 _handle_error 8 API calls 19420->19421 19422 7ff63ec045ea MapViewOfFile 19421->19422 19422->19379 19422->19389 19424 7ff63ec09f73 19423->19424 19425 7ff63ec06480 60 API calls 19424->19425 19426 7ff63ec0a150 19425->19426 19427 7ff63ec29bf0 _handle_error 8 API calls 19426->19427 19428 7ff63ec0a160 19427->19428 19428->19379 19430 7ff63ec16c3d 19429->19430 19433 7ff63ec16c4f memcpy_s 19429->19433 19431 7ff63ec16d87 19430->19431 19437 7ff63ec16ca0 19430->19437 19490 7ff63ec03eab 19431->19490 19433->18722 19434 7ff63ec16d31 19474 7ff63ec03ebc 19434->19474 19436 7ff63ec16d8c 19493 7ff63ec03f15 19436->19493 19437->19434 19437->19436 19440 7ff63ec16d39 memcpy_s 19441 7ff63ec16d72 19440->19441 19442 7ff63ec04059 30 API calls 19440->19442 19441->18722 19442->19441 19444 7ff63ec1604b 19443->19444 19512 7ff63ec2c714 19444->19512 19447 7ff63ec29bf0 _handle_error 8 API calls 19448 7ff63ec0f33d 19447->19448 19449 7ff63ec08cfe 19448->19449 19450 7ff63ec08d5f 19449->19450 19450->19450 19451 7ff63ec06480 60 API calls 19450->19451 19452 7ff63ec08e02 19451->19452 19453 7ff63ec29bf0 _handle_error 8 API calls 19452->19453 19454 7ff63ec08e12 CreateProcessW 19453->19454 19454->18727 19454->18728 19456 7ff63ec0997a 19455->19456 19457 7ff63ec06480 60 API calls 19456->19457 19458 7ff63ec09a32 19457->19458 19459 7ff63ec29bf0 _handle_error 8 API calls 19458->19459 19460 7ff63ec09a42 19459->19460 19460->18735 19461 7ff63ec37050 19460->19461 19463 7ff63ec37060 19461->19463 19465 7ff63ec3706a 19461->19465 19462 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19469 7ff63ec37072 19462->19469 19463->19465 19467 7ff63ec370a0 19463->19467 19464 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19466 7ff63ec0f422 19464->19466 19465->19462 19466->18741 19467->19466 19468 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19467->19468 19468->19469 19469->19464 19471 7ff63ec04066 19470->19471 19687 7ff63ec3596c 19471->19687 19475 7ff63ec03ed5 19474->19475 19482 7ff63ec03ec9 19474->19482 19476 7ff63ec03f0f 19475->19476 19477 7ff63ec03edf 19475->19477 19478 7ff63ec03f15 32 API calls 19476->19478 19479 7ff63ec2984c 4 API calls 19477->19479 19480 7ff63ec03f14 19478->19480 19481 7ff63ec03ee8 19479->19481 19481->19440 19483 7ff63ec03ed2 19482->19483 19484 7ff63ec34cd4 _invalid_parameter_noinfo 2 API calls 19482->19484 19485 7ff63ec29876 19482->19485 19483->19440 19484->19482 19486 7ff63ec29881 19485->19486 19487 7ff63ec2a190 Concurrency::cancel_current_task 2 API calls 19485->19487 19488 7ff63ec2a1b0 2 API calls 19486->19488 19487->19486 19489 7ff63ec29887 19488->19489 19498 7ff63ec29e98 19490->19498 19494 7ff63ec2ae90 Concurrency::cancel_current_task 2 API calls 19493->19494 19495 7ff63ec03f47 19494->19495 19496 7ff63ec2b858 __std_exception_copy 30 API calls 19495->19496 19497 7ff63ec03f75 19496->19497 19505 7ff63ec29f3c 19498->19505 19501 7ff63ec2ae90 Concurrency::cancel_current_task 2 API calls 19502 7ff63ec29eba 19501->19502 19508 7ff63ec2b858 19502->19508 19504 7ff63ec03ebb 19506 7ff63ec2b858 __std_exception_copy 30 API calls 19505->19506 19507 7ff63ec29ea9 19506->19507 19507->19501 19509 7ff63ec2b8ae __vcrt_freefls 19508->19509 19510 7ff63ec2b879 19508->19510 19509->19504 19510->19509 19511 7ff63ec36e78 __std_exception_copy 30 API calls 19510->19511 19511->19509 19513 7ff63ec2c728 19512->19513 19514 7ff63ec2c764 19512->19514 19513->19514 19516 7ff63ec2c732 19513->19516 19515 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19514->19515 19517 7ff63ec2c75c 19515->19517 19523 7ff63ec2dc44 19516->19523 19520 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19517->19520 19521 7ff63ec1606a 19520->19521 19521->19447 19522 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19522->19517 19524 7ff63ec2dc9b 19523->19524 19525 7ff63ec2dc83 19523->19525 19524->19525 19527 7ff63ec2dca5 19524->19527 19526 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19525->19526 19528 7ff63ec2dc88 19526->19528 19529 7ff63ec2c678 40 API calls 19527->19529 19530 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19528->19530 19531 7ff63ec2dcb6 19529->19531 19537 7ff63ec2dc93 19530->19537 19538 7ff63ec2e3d0 19531->19538 19533 7ff63ec29bf0 _handle_error 8 API calls 19534 7ff63ec2c74b 19533->19534 19534->19521 19534->19522 19535 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 19535->19537 19537->19533 19539 7ff63ec2e3f7 19538->19539 19540 7ff63ec2e644 19538->19540 19541 7ff63ec2e3fd 19539->19541 19550 7ff63ec2e414 19539->19550 19542 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19540->19542 19543 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19541->19543 19544 7ff63ec2e649 19542->19544 19546 7ff63ec2e402 19543->19546 19547 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19544->19547 19545 7ff63ec2dd59 19545->19535 19548 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19546->19548 19547->19545 19548->19545 19550->19540 19550->19545 19553 7ff63ec2e894 19550->19553 19571 7ff63ec2e6fc 19550->19571 19595 7ff63ec2e658 19550->19595 19554 7ff63ec2e93d 19553->19554 19565 7ff63ec2e8d8 19553->19565 19555 7ff63ec2e947 19554->19555 19556 7ff63ec2e9ce 19554->19556 19559 7ff63ec2e9b4 19555->19559 19561 7ff63ec2e953 19555->19561 19616 7ff63ec2ed4c 19556->19616 19558 7ff63ec2e91d 19570 7ff63ec2e9d7 19558->19570 19603 7ff63ec2eb60 19558->19603 19560 7ff63ec2d81c 30 API calls 19559->19560 19568 7ff63ec2e92e 19560->19568 19561->19568 19561->19570 19607 7ff63ec2ef88 19561->19607 19564 7ff63ec29bf0 _handle_error 8 API calls 19566 7ff63ec2eb40 19564->19566 19565->19556 19565->19558 19565->19561 19567 7ff63ec2e90d 19565->19567 19565->19568 19565->19570 19566->19550 19567->19556 19567->19558 19567->19568 19568->19570 19622 7ff63ec2f154 19568->19622 19570->19564 19572 7ff63ec2e70a 19571->19572 19573 7ff63ec2e723 19571->19573 19574 7ff63ec2e749 19572->19574 19576 7ff63ec2e93d 19572->19576 19589 7ff63ec2e8d8 19572->19589 19573->19574 19575 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19573->19575 19574->19550 19577 7ff63ec2e73e 19575->19577 19578 7ff63ec2e947 19576->19578 19579 7ff63ec2e9ce 19576->19579 19581 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19577->19581 19583 7ff63ec2e9b4 19578->19583 19585 7ff63ec2e953 19578->19585 19580 7ff63ec2ed4c 41 API calls 19579->19580 19592 7ff63ec2e92e 19580->19592 19581->19574 19582 7ff63ec2e91d 19586 7ff63ec2eb60 41 API calls 19582->19586 19594 7ff63ec2e9d7 19582->19594 19584 7ff63ec2d81c 30 API calls 19583->19584 19584->19592 19587 7ff63ec2ef88 31 API calls 19585->19587 19585->19592 19585->19594 19586->19592 19587->19592 19588 7ff63ec29bf0 _handle_error 8 API calls 19590 7ff63ec2eb40 19588->19590 19589->19579 19589->19582 19589->19585 19591 7ff63ec2e90d 19589->19591 19589->19592 19589->19594 19590->19550 19591->19579 19591->19582 19591->19592 19593 7ff63ec2f154 41 API calls 19592->19593 19592->19594 19593->19594 19594->19588 19596 7ff63ec2e681 19595->19596 19597 7ff63ec2e67c 19595->19597 19658 7ff63ec3b2c4 19596->19658 19599 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19597->19599 19599->19596 19601 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19602 7ff63ec2e6bc 19601->19602 19602->19550 19604 7ff63ec2eb97 19603->19604 19605 7ff63ec2ebc7 19604->19605 19626 7ff63ec3b350 19604->19626 19605->19568 19608 7ff63ec2efba 19607->19608 19609 7ff63ec2eff5 19608->19609 19610 7ff63ec2f034 19608->19610 19611 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19609->19611 19615 7ff63ec2f005 19610->19615 19648 7ff63ec2dff4 19610->19648 19613 7ff63ec2effa 19611->19613 19614 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19613->19614 19614->19615 19615->19568 19617 7ff63ec2ed70 19616->19617 19618 7ff63ec2df0c 14 API calls 19617->19618 19619 7ff63ec2edbe 19618->19619 19620 7ff63ec3b6e8 40 API calls 19619->19620 19621 7ff63ec2ee84 19620->19621 19621->19568 19624 7ff63ec2f1ff 19622->19624 19625 7ff63ec2f177 19622->19625 19623 7ff63ec3b350 41 API calls 19623->19625 19624->19570 19625->19623 19625->19624 19627 7ff63ec3b378 19626->19627 19628 7ff63ec3b386 19626->19628 19627->19628 19629 7ff63ec2c678 40 API calls 19627->19629 19628->19605 19630 7ff63ec3b3a4 19629->19630 19631 7ff63ec3b3d4 19630->19631 19632 7ff63ec3b3b2 19630->19632 19631->19628 19645 7ff63ec3f7cc 19631->19645 19642 7ff63ec3f818 19632->19642 19636 7ff63ec3b418 19638 7ff63ec3b44d 19636->19638 19640 7ff63ec3ca88 MultiByteToWideChar 19636->19640 19637 7ff63ec3b46a 19639 7ff63ec3ca88 MultiByteToWideChar 19637->19639 19638->19628 19641 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19638->19641 19639->19638 19640->19638 19641->19628 19643 7ff63ec41d54 21 API calls 19642->19643 19644 7ff63ec3f82b 19643->19644 19644->19628 19646 7ff63ec2c678 40 API calls 19645->19646 19647 7ff63ec3b414 19646->19647 19647->19636 19647->19637 19649 7ff63ec2e01a 19648->19649 19652 7ff63ec2e029 19648->19652 19650 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19649->19650 19651 7ff63ec2e01f 19650->19651 19651->19615 19652->19651 19653 7ff63ec3b264 14 API calls 19652->19653 19654 7ff63ec2e059 19653->19654 19655 7ff63ec2e06d 19654->19655 19656 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 19654->19656 19657 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 19655->19657 19656->19655 19657->19651 19659 7ff63ec3b2d7 19658->19659 19662 7ff63ec36680 19659->19662 19663 7ff63ec366a7 19662->19663 19664 7ff63ec366bc 19662->19664 19666 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19663->19666 19664->19663 19665 7ff63ec366ca 19664->19665 19667 7ff63ec2c678 40 API calls 19665->19667 19668 7ff63ec366ac 19666->19668 19671 7ff63ec366d7 19667->19671 19669 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19668->19669 19680 7ff63ec2e6ab 19669->19680 19672 7ff63ec3670a 19671->19672 19683 7ff63ec3c2f4 19671->19683 19673 7ff63ec3694d 19672->19673 19675 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19672->19675 19674 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19673->19674 19678 7ff63ec36c1d 19673->19678 19676 7ff63ec36c12 19674->19676 19677 7ff63ec36995 19675->19677 19681 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19676->19681 19682 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19677->19682 19679 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19678->19679 19678->19680 19679->19680 19680->19601 19680->19602 19681->19678 19682->19673 19684 7ff63ec3c30b 19683->19684 19686 7ff63ec3c315 19683->19686 19685 7ff63ec3c32a GetStringTypeW 19684->19685 19684->19686 19685->19686 19686->19671 19688 7ff63ec35b48 _invalid_parameter_noinfo 30 API calls 19687->19688 19689 7ff63ec35985 19688->19689 19690 7ff63ec3599c _invalid_parameter_noinfo_noreturn 17 API calls 19689->19690 19691 7ff63ec3599a 19690->19691 19693 7ff63ec16a60 19692->19693 19694 7ff63ec16a54 19692->19694 19695 7ff63ec04059 30 API calls 19694->19695 19695->19693 19697 7ff63ec05959 19696->19697 19698 7ff63ec05b21 8 API calls 19697->19698 19702 7ff63ec059e1 19697->19702 19699 7ff63ec059b5 19698->19699 19701 7ff63ec05b21 8 API calls 19699->19701 19699->19702 19700 7ff63ec05a07 19700->18785 19701->19702 19702->19700 19704 7ff63ec05879 19702->19704 19705 7ff63ec058ca 19704->19705 19708 7ff63ec0589a 19704->19708 19706 7ff63ec29bf0 _handle_error 8 API calls 19705->19706 19707 7ff63ec05939 19706->19707 19707->19700 19708->19705 19712 7ff63ec05c64 19708->19712 19710 7ff63ec058f8 19711 7ff63ec05947 8 API calls 19710->19711 19711->19705 19713 7ff63ec05b21 8 API calls 19712->19713 19714 7ff63ec05c88 19713->19714 19714->19710 19716 7ff63ec03d81 19715->19716 19720 7ff63ec03d93 memcpy_s 19715->19720 19717 7ff63ec03ea5 19716->19717 19718 7ff63ec03dd6 19716->19718 19719 7ff63ec03eab 32 API calls 19717->19719 19721 7ff63ec03ebc 32 API calls 19718->19721 19722 7ff63ec03eaa 19719->19722 19720->18787 19723 7ff63ec03e5c memcpy_s 19721->19723 19724 7ff63ec03e90 19723->19724 19725 7ff63ec04059 30 API calls 19723->19725 19724->18787 19725->19724 19727 7ff63ec09317 19726->19727 19728 7ff63ec06480 60 API calls 19727->19728 19729 7ff63ec093ae 19728->19729 19730 7ff63ec29bf0 _handle_error 8 API calls 19729->19730 19731 7ff63ec093be 19730->19731 19732 7ff63ec093c8 19731->19732 19733 7ff63ec0946b 19732->19733 19733->19733 19734 7ff63ec06480 60 API calls 19733->19734 19735 7ff63ec09502 19734->19735 19736 7ff63ec29bf0 _handle_error 8 API calls 19735->19736 19737 7ff63ec09512 19736->19737 19737->18798 19740 7ff63ec03727 19738->19740 19739 7ff63ec29bf0 _handle_error 8 API calls 19741 7ff63ec037ea 19739->19741 19740->19739 19741->18801 19761 7ff63ec19232 19742->19761 19746 7ff63ec29bf0 _handle_error 8 API calls 19747 7ff63ec0ef7b 19746->19747 19747->18819 19747->18825 19749 7ff63ec18af4 19750 7ff63ec18995 19749->19750 19785 7ff63ec347e0 19749->19785 19750->19746 19751 7ff63ec05b21 8 API calls 19757 7ff63ec18969 19751->19757 19753 7ff63ec189a7 GetLastError 19754 7ff63ec18abc 19753->19754 19754->19754 19758 7ff63ec0e192 66 API calls 19754->19758 19756 7ff63ec18b56 GetLastError 19759 7ff63ec191a3 19756->19759 19757->19749 19757->19753 19758->19749 19759->19759 19760 7ff63ec0e192 66 API calls 19759->19760 19760->19750 19762 7ff63ec1925b 19761->19762 19776 7ff63ec19388 19761->19776 19764 7ff63ec05b21 8 API calls 19762->19764 19763 7ff63ec29bf0 _handle_error 8 API calls 19765 7ff63ec18938 19763->19765 19766 7ff63ec19273 19764->19766 19765->19750 19777 7ff63ec1744e 19765->19777 19767 7ff63ec1938a 19766->19767 19769 7ff63ec1929a WSAGetLastError 19766->19769 19768 7ff63ec2999c _Init_thread_header 5 API calls 19767->19768 19767->19776 19770 7ff63ec193e3 19768->19770 19771 7ff63ec1936e 19769->19771 19772 7ff63ec29c14 33 API calls 19770->19772 19770->19776 19771->19771 19773 7ff63ec0e192 66 API calls 19771->19773 19774 7ff63ec193f8 19772->19774 19773->19776 19775 7ff63ec29a34 4 API calls 19774->19775 19775->19776 19776->19763 19778 7ff63ec1747f 19777->19778 19779 7ff63ec17473 19777->19779 19780 7ff63ec2999c _Init_thread_header 5 API calls 19778->19780 19779->19749 19779->19751 19781 7ff63ec1748b 19780->19781 19781->19779 19782 7ff63ec29c14 33 API calls 19781->19782 19783 7ff63ec174aa 19782->19783 19784 7ff63ec29a34 4 API calls 19783->19784 19784->19779 19786 7ff63ec347f9 19785->19786 19787 7ff63ec34810 19785->19787 19789 7ff63ec3b18c _set_errno_from_matherr 13 API calls 19786->19789 19803 7ff63ec348c0 19787->19803 19790 7ff63ec347fe 19789->19790 19792 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 19790->19792 19794 7ff63ec18b46 19792->19794 19793 7ff63ec34823 CreateThread 19795 7ff63ec34860 19793->19795 19796 7ff63ec34853 GetLastError 19793->19796 19794->19750 19794->19756 19795->19794 19798 7ff63ec34876 19795->19798 19799 7ff63ec34870 CloseHandle 19795->19799 19797 7ff63ec3b1cc 13 API calls 19796->19797 19797->19795 19800 7ff63ec3487f FreeLibrary 19798->19800 19801 7ff63ec34885 19798->19801 19799->19798 19800->19801 19802 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 19801->19802 19802->19794 19804 7ff63ec3c4d8 _invalid_parameter_noinfo 13 API calls 19803->19804 19805 7ff63ec348e2 19804->19805 19806 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 19805->19806 19807 7ff63ec348ec 19806->19807 19808 7ff63ec3481b 19807->19808 19809 7ff63ec348f3 GetModuleHandleExW 19807->19809 19808->19793 19808->19795 19809->19808 19811 7ff63ec0f84e 19810->19811 19812 7ff63ec103b0 19810->19812 19814 7ff63ec101d1 19811->19814 20172 7ff63ec15da0 19811->20172 19813 7ff63ec2999c _Init_thread_header 5 API calls 19812->19813 19815 7ff63ec103bc 19813->19815 19814->18830 19815->19811 19817 7ff63ec29c14 33 API calls 19815->19817 19818 7ff63ec103ec 19817->19818 19819 7ff63ec29a34 4 API calls 19818->19819 19819->19811 19820 7ff63ec0f861 19821 7ff63ec36e78 __std_exception_copy 30 API calls 19820->19821 19822 7ff63ec0f88b 19821->19822 20180 7ff63ec36d88 19822->20180 19825 7ff63ec05b21 8 API calls 19826 7ff63ec0f9c6 19825->19826 19827 7ff63ec0fa05 19826->19827 19830 7ff63ec0fdd6 19826->19830 20189 7ff63ec06eec 19827->20189 19831 7ff63ec05b21 8 API calls 19830->19831 19835 7ff63ec0fdee 19831->19835 19832 7ff63ec0fdab 19833 7ff63ec05b21 8 API calls 19832->19833 19834 7ff63ec0fdc3 19833->19834 20201 7ff63ec15209 19834->20201 19836 7ff63ec0e192 66 API calls 19835->19836 19836->19834 19838 7ff63ec0ff14 20238 7ff63ec169c4 19838->20238 19840 7ff63ec0fa48 20195 7ff63ec0693c 19840->20195 19843 7ff63ec05b21 8 API calls 19844 7ff63ec0ff53 19843->19844 19845 7ff63ec0ff92 19844->19845 19846 7ff63ec101e4 19844->19846 19847 7ff63ec0e192 66 API calls 19845->19847 19849 7ff63ec05b21 8 API calls 19846->19849 19850 7ff63ec1002b 19847->19850 19848 7ff63ec0fa7f 19851 7ff63ec0693c 60 API calls 19848->19851 19853 7ff63ec101fc 19849->19853 20242 7ff63ec066c4 19850->20242 19854 7ff63ec0fac0 19851->19854 19856 7ff63ec16c24 32 API calls 19854->19856 19858 7ff63ec0fafa 19856->19858 19860 7ff63ec0e192 66 API calls 19858->19860 19861 7ff63ec0fd9e 19860->19861 19863 7ff63ec05b21 8 API calls 19861->19863 19863->19814 19870 7ff63ec0f80e 68 API calls 19869->19870 19871 7ff63ec10438 19870->19871 19872 7ff63ec0e192 66 API calls 19871->19872 19873 7ff63ec10ad9 GetLocalTime 19872->19873 20375 7ff63ec03912 19873->20375 19878 7ff63ec36e78 __std_exception_copy 30 API calls 19881 7ff63ec10c26 19878->19881 19879 7ff63ec10d63 19880 7ff63ec05b21 8 API calls 19879->19880 19900 7ff63ec11989 19879->19900 19882 7ff63ec10d8e 19880->19882 19881->19879 20384 7ff63ec15f96 19881->20384 20390 7ff63ec0a85e 19882->20390 19886 7ff63ec11990 20408 7ff63ec15e0c 19886->20408 19887 7ff63ec10db3 19890 7ff63ec03ce5 45 API calls 19887->19890 19892 7ff63ec110c2 19890->19892 19891 7ff63ec0e192 66 API calls 20030 7ff63ec119bd 19891->20030 19893 7ff63ec0693c 60 API calls 19892->19893 19895 7ff63ec110c7 19893->19895 19897 7ff63ec03ce5 45 API calls 19895->19897 19899 7ff63ec114b9 19897->19899 19898 7ff63ec103fd 80 API calls 19898->19900 19901 7ff63ec0693c 60 API calls 19899->19901 19900->18832 19902 7ff63ec114be 19901->19902 20396 7ff63ec0a950 19902->20396 19907 7ff63ec11984 19911 7ff63ec11b12 19907->19911 19912 7ff63ec11aca 19907->19912 19913 7ff63ec11c03 19907->19913 19953 7ff63ec11b47 19907->19953 19908 7ff63ec115d0 VariantInit VariantInit VariantInit VariantInit 19914 7ff63ec1167c VariantClear VariantClear VariantClear VariantClear 19908->19914 19909 7ff63ec119c4 19910 7ff63ec15e0c 48 API calls 19909->19910 19963 7ff63ec119cd 19910->19963 19915 7ff63ec15e0c 48 API calls 19911->19915 19911->19953 19912->19911 19929 7ff63ec15e0c 48 API calls 19912->19929 19918 7ff63ec15e0c 48 API calls 19913->19918 19916 7ff63ec119d7 19914->19916 19917 7ff63ec116b8 19914->19917 19919 7ff63ec11bf9 19915->19919 19918->19919 19926 7ff63ec0e192 66 API calls 19919->19926 19923 7ff63ec11e8c 19927 7ff63ec15e0c 48 API calls 19923->19927 19924 7ff63ec11d13 19938 7ff63ec11f87 19924->19938 19994 7ff63ec11d31 19924->19994 19926->19953 19933 7ff63ec11e95 19927->19933 19928 7ff63ec11c52 19930 7ff63ec11ce5 19928->19930 19934 7ff63ec11c9a 19928->19934 19935 7ff63ec11f4e 19928->19935 19936 7ff63ec11aee 19929->19936 19937 7ff63ec11f3c 19930->19937 19944 7ff63ec11f98 19930->19944 19945 7ff63ec11ef1 19930->19945 19932 7ff63ec13909 19943 7ff63ec0e192 66 API calls 19933->19943 19934->19930 19959 7ff63ec15e0c 48 API calls 19934->19959 19939 7ff63ec15e0c 48 API calls 19935->19939 19940 7ff63ec0e192 66 API calls 19936->19940 19949 7ff63ec2984c 4 API calls 19937->19949 20092 7ff63ec1224b 19937->20092 19942 7ff63ec15e0c 48 API calls 19938->19942 19946 7ff63ec11f57 19939->19946 19940->19911 19942->19933 19943->19937 19947 7ff63ec15e0c 48 API calls 19944->19947 19945->19937 19968 7ff63ec15e0c 48 API calls 19945->19968 19952 7ff63ec0e192 66 API calls 19946->19952 19954 7ff63ec11fa1 19947->19954 19957 7ff63ec1204f SysAllocString 19949->19957 19952->19937 19953->19923 19953->19924 19953->19928 19961 7ff63ec0e192 66 API calls 19954->19961 19957->19932 19964 7ff63ec12081 19957->19964 19958 7ff63ec1244a 19965 7ff63ec0693c 60 API calls 19958->19965 19960 7ff63ec11cc1 19959->19960 19966 7ff63ec0e192 66 API calls 19960->19966 19961->19937 19962 7ff63ec11d8b VariantClear 19967 7ff63ec11fc7 19962->19967 19962->19994 19966->19930 19970 7ff63ec15e0c 48 API calls 19967->19970 19971 7ff63ec11f18 19968->19971 19970->19933 19973 7ff63ec0e192 66 API calls 19971->19973 19973->19937 19975 7ff63ec12823 19980 7ff63ec0e192 66 API calls 19975->19980 19977 7ff63ec11fd8 19984 7ff63ec15e0c 48 API calls 19977->19984 19984->19933 19991 7ff63ec15e0c 48 API calls 19991->19994 19994->19928 19994->19962 19994->19977 19994->19991 19998 7ff63ec0e192 66 API calls 19994->19998 19998->19994 20440 7ff63ec0ab96 20030->20440 20092->19958 20092->19975 20658 7ff63ec1a842 20114->20658 20117 7ff63ec1a842 64 API calls 20118 7ff63ec21e75 20117->20118 20119 7ff63ec0e192 66 API calls 20118->20119 20120 7ff63ec21f0d 20119->20120 20121 7ff63ec29bf0 _handle_error 8 API calls 20120->20121 20122 7ff63ec0e69b 20121->20122 20123 7ff63ec144c3 20122->20123 20124 7ff63ec144fb 20123->20124 20125 7ff63ec151be 20123->20125 20126 7ff63ec15052 20124->20126 20128 7ff63ec15da0 62 API calls 20124->20128 20127 7ff63ec2999c _Init_thread_header 5 API calls 20125->20127 20126->18839 20129 7ff63ec151ca 20127->20129 20132 7ff63ec1450e 20128->20132 20129->20124 20130 7ff63ec29c14 33 API calls 20129->20130 20131 7ff63ec151f8 20130->20131 20133 7ff63ec29a34 4 API calls 20131->20133 20134 7ff63ec36e78 __std_exception_copy 30 API calls 20132->20134 20133->20124 20135 7ff63ec14538 20134->20135 20136 7ff63ec36d88 30 API calls 20135->20136 20137 7ff63ec145ab 20136->20137 20138 7ff63ec05b21 8 API calls 20137->20138 20139 7ff63ec145ce 20138->20139 20140 7ff63ec1460e 20139->20140 20143 7ff63ec14a0d 20139->20143 20141 7ff63ec06eec 60 API calls 20140->20141 20142 7ff63ec14613 20141->20142 20145 7ff63ec149e2 20142->20145 20150 7ff63ec14649 20142->20150 20144 7ff63ec05b21 8 API calls 20143->20144 20147 7ff63ec14a25 20144->20147 20146 7ff63ec05b21 8 API calls 20145->20146 20148 7ff63ec149fa 20146->20148 20149 7ff63ec0e192 66 API calls 20147->20149 20151 7ff63ec03d68 32 API calls 20148->20151 20149->20148 20155 7ff63ec03d68 32 API calls 20150->20155 20152 7ff63ec14b74 20151->20152 20153 7ff63ec05b21 8 API calls 20152->20153 20158 7ff63ec1469d 20155->20158 20158->20158 20161 7ff63ec0e192 66 API calls 20158->20161 20169 7ff63ec149dd 20161->20169 20163 7ff63ec05b21 8 API calls 20163->20126 20169->20163 20252 7ff63ec16727 20172->20252 20175 7ff63ec15dc1 20266 7ff63ec166c7 20175->20266 20176 7ff63ec15db3 20260 7ff63ec160f1 20176->20260 20179 7ff63ec15db8 20179->19820 20182 7ff63ec36d98 20180->20182 20183 7ff63ec36da2 20180->20183 20181 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20184 7ff63ec36da9 20181->20184 20182->20183 20187 7ff63ec36dd4 20182->20187 20183->20181 20185 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20184->20185 20186 7ff63ec0f9a3 20185->20186 20186->19825 20187->20186 20188 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20187->20188 20188->20184 20190 7ff63ec06f31 20189->20190 20191 7ff63ec06480 60 API calls 20190->20191 20192 7ff63ec070cc 20191->20192 20193 7ff63ec29bf0 _handle_error 8 API calls 20192->20193 20194 7ff63ec070dc 20193->20194 20194->19832 20194->19840 20196 7ff63ec069b8 20195->20196 20197 7ff63ec06480 60 API calls 20196->20197 20198 7ff63ec06bb1 20197->20198 20199 7ff63ec29bf0 _handle_error 8 API calls 20198->20199 20200 7ff63ec06bc1 20199->20200 20200->19848 20202 7ff63ec15251 20201->20202 20202->20202 20203 7ff63ec36e78 __std_exception_copy 30 API calls 20202->20203 20204 7ff63ec15313 20203->20204 20205 7ff63ec36e78 __std_exception_copy 30 API calls 20204->20205 20206 7ff63ec15388 20205->20206 20207 7ff63ec36e78 __std_exception_copy 30 API calls 20206->20207 20208 7ff63ec153f2 20207->20208 20209 7ff63ec0693c 60 API calls 20208->20209 20210 7ff63ec153f7 20209->20210 20285 7ff63ec0a4f4 20210->20285 20213 7ff63ec1572b 20218 7ff63ec1573a 20213->20218 20332 7ff63ec0a5f6 20213->20332 20214 7ff63ec2984c 4 API calls 20215 7ff63ec154a9 20214->20215 20291 7ff63ec158db 20215->20291 20218->19838 20239 7ff63ec0ff23 20238->20239 20240 7ff63ec169d6 20238->20240 20239->19843 20241 7ff63ec04059 30 API calls 20240->20241 20241->20239 20253 7ff63ec16941 20252->20253 20254 7ff63ec16754 GetCommandLineW 20252->20254 20255 7ff63ec29bf0 _handle_error 8 API calls 20253->20255 20270 7ff63ec09a4c 20254->20270 20257 7ff63ec15da9 20255->20257 20257->20175 20257->20176 20258 7ff63ec1676d memcpy_s 20258->20253 20276 7ff63ec37108 20258->20276 20261 7ff63ec160fe 20260->20261 20262 7ff63ec16140 20260->20262 20263 7ff63ec16727 61 API calls 20261->20263 20262->20179 20264 7ff63ec16103 20263->20264 20264->20262 20265 7ff63ec1610d WideCharToMultiByte 20264->20265 20265->20262 20267 7ff63ec166ec __scrt_get_show_window_mode 20266->20267 20268 7ff63ec166d4 20266->20268 20267->20179 20269 7ff63ec05b21 8 API calls 20268->20269 20269->20267 20271 7ff63ec09ac9 20270->20271 20272 7ff63ec06480 60 API calls 20271->20272 20273 7ff63ec09b59 20272->20273 20274 7ff63ec29bf0 _handle_error 8 API calls 20273->20274 20275 7ff63ec09b69 20274->20275 20275->20258 20277 7ff63ec37115 20276->20277 20278 7ff63ec3711f 20276->20278 20277->20278 20281 7ff63ec3713b 20277->20281 20279 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20278->20279 20284 7ff63ec37127 20279->20284 20280 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20282 7ff63ec37133 20280->20282 20281->20282 20283 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20281->20283 20282->20258 20283->20284 20284->20280 20286 7ff63ec0a576 20285->20286 20287 7ff63ec06480 60 API calls 20286->20287 20288 7ff63ec0a5dd 20287->20288 20289 7ff63ec29bf0 _handle_error 8 API calls 20288->20289 20290 7ff63ec0a5ed 20289->20290 20290->20213 20290->20214 20292 7ff63ec1592a 20291->20292 20293 7ff63ec16c24 32 API calls 20292->20293 20296 7ff63ec15938 20293->20296 20294 7ff63ec15973 20338 7ff63ec15d2a 20294->20338 20296->20294 20298 7ff63ec16d92 32 API calls 20296->20298 20298->20294 20333 7ff63ec0a77d 20332->20333 20334 7ff63ec06480 60 API calls 20333->20334 20335 7ff63ec0a842 20334->20335 20336 7ff63ec29bf0 _handle_error 8 API calls 20335->20336 20337 7ff63ec0a852 20336->20337 20337->20218 20339 7ff63ec15d48 20338->20339 20340 7ff63ec15d5a 20339->20340 20341 7ff63ec15d8e 20339->20341 20376 7ff63ec0392c 20375->20376 20377 7ff63ec03936 GetLocalTime 20375->20377 20378 7ff63ec03941 SystemTimeToFileTime 20376->20378 20377->20378 20379 7ff63ec29bf0 _handle_error 8 API calls 20378->20379 20380 7ff63ec039ad 20379->20380 20381 7ff63ec039b7 FileTimeToSystemTime 20380->20381 20382 7ff63ec29bf0 _handle_error 8 API calls 20381->20382 20383 7ff63ec039f2 20382->20383 20383->19878 20385 7ff63ec15fc8 20384->20385 20446 7ff63ec2f488 20385->20446 20388 7ff63ec29bf0 _handle_error 8 API calls 20389 7ff63ec1600b 20388->20389 20389->19879 20391 7ff63ec0a8bd 20390->20391 20392 7ff63ec06480 60 API calls 20391->20392 20393 7ff63ec0a936 20392->20393 20394 7ff63ec29bf0 _handle_error 8 API calls 20393->20394 20395 7ff63ec0a946 20394->20395 20395->19886 20395->19887 20397 7ff63ec0a9d7 20396->20397 20398 7ff63ec06480 60 API calls 20397->20398 20399 7ff63ec0aa97 20398->20399 20400 7ff63ec29bf0 _handle_error 8 API calls 20399->20400 20401 7ff63ec0aaa7 20400->20401 20401->19907 20402 7ff63ec0aab2 20401->20402 20403 7ff63ec0ab1f 20402->20403 20404 7ff63ec06480 60 API calls 20403->20404 20405 7ff63ec0ab7d 20404->20405 20406 7ff63ec29bf0 _handle_error 8 API calls 20405->20406 20407 7ff63ec0ab8d 20406->20407 20407->19908 20407->19909 20643 7ff63ec15e96 20408->20643 20410 7ff63ec15e42 20411 7ff63ec36e78 __std_exception_copy 30 API calls 20410->20411 20412 7ff63ec15e56 20411->20412 20413 7ff63ec15e78 20412->20413 20414 7ff63ec15e72 LocalFree 20412->20414 20415 7ff63ec29bf0 _handle_error 8 API calls 20413->20415 20414->20413 20416 7ff63ec11999 20415->20416 20416->19891 20441 7ff63ec0ad38 20440->20441 20442 7ff63ec06480 60 API calls 20441->20442 20443 7ff63ec0aeb6 20442->20443 20444 7ff63ec29bf0 _handle_error 8 API calls 20443->20444 20445 7ff63ec0aec6 20444->20445 20445->19898 20445->19900 20447 7ff63ec2f4d6 20446->20447 20448 7ff63ec2f4be 20446->20448 20447->20448 20450 7ff63ec2f4db 20447->20450 20449 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20448->20449 20451 7ff63ec2f4c3 20449->20451 20453 7ff63ec2c678 40 API calls 20450->20453 20452 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20451->20452 20458 7ff63ec2f4ce 20452->20458 20454 7ff63ec2f4f7 __scrt_get_show_window_mode 20453->20454 20459 7ff63ec3252c 20454->20459 20455 7ff63ec29bf0 _handle_error 8 API calls 20456 7ff63ec15ffc 20455->20456 20456->20388 20458->20455 20460 7ff63ec32547 20459->20460 20461 7ff63ec3254d 20459->20461 20460->20461 20462 7ff63ec32565 20460->20462 20463 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20461->20463 20465 7ff63ec3257c 20462->20465 20466 7ff63ec3256c 20462->20466 20464 7ff63ec32552 20463->20464 20467 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20464->20467 20473 7ff63ec3259b 20465->20473 20476 7ff63ec32618 20465->20476 20485 7ff63ec31d90 20465->20485 20468 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20466->20468 20472 7ff63ec3255d 20467->20472 20475 7ff63ec32571 20468->20475 20470 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20470->20472 20472->20458 20473->20472 20474 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20473->20474 20474->20475 20475->20470 20477 7ff63ec32696 20476->20477 20478 7ff63ec3262d 20476->20478 20522 7ff63ec32b38 20477->20522 20479 7ff63ec3265d 20478->20479 20480 7ff63ec32632 20478->20480 20482 7ff63ec3263f 20479->20482 20519 7ff63ec326d0 20479->20519 20480->20482 20499 7ff63ec32754 20480->20499 20482->20465 20486 7ff63ec31da9 20485->20486 20498 7ff63ec31dcc 20485->20498 20486->20498 20608 7ff63ec3c46c 20486->20608 20489 7ff63ec31df4 20492 7ff63ec3c46c 43 API calls 20489->20492 20490 7ff63ec31e23 20491 7ff63ec31ee3 20490->20491 20493 7ff63ec31e39 20490->20493 20494 7ff63ec3c2c4 40 API calls 20491->20494 20495 7ff63ec31e03 20492->20495 20614 7ff63ec31ff4 20493->20614 20494->20498 20497 7ff63ec3c46c 43 API calls 20495->20497 20495->20498 20497->20495 20498->20465 20500 7ff63ec3276d 20499->20500 20501 7ff63ec327f4 20499->20501 20505 7ff63ec327b4 20500->20505 20506 7ff63ec32775 20500->20506 20509 7ff63ec3277a 20500->20509 20502 7ff63ec327f9 20501->20502 20501->20509 20503 7ff63ec327fe 20502->20503 20504 7ff63ec32853 20502->20504 20503->20505 20508 7ff63ec32803 20503->20508 20561 7ff63ec32a50 20504->20561 20513 7ff63ec327d8 20505->20513 20515 7ff63ec327c3 20505->20515 20506->20509 20510 7ff63ec327a5 20506->20510 20518 7ff63ec327af 20508->20518 20555 7ff63ec32ac0 20508->20555 20509->20518 20569 7ff63ec32998 20509->20569 20526 7ff63ec32874 20510->20526 20546 7ff63ec330e4 20513->20546 20515->20518 20535 7ff63ec332a0 20515->20535 20518->20482 20520 7ff63ec3c2c4 40 API calls 20519->20520 20521 7ff63ec326e5 20520->20521 20521->20482 20523 7ff63ec32b4d 20522->20523 20524 7ff63ec32b76 20523->20524 20525 7ff63ec2f388 43 API calls 20523->20525 20524->20482 20525->20523 20527 7ff63ec3289a 20526->20527 20528 7ff63ec3288d 20526->20528 20530 7ff63ec328c7 20527->20530 20531 7ff63ec328e0 20527->20531 20529 7ff63ec32b38 43 API calls 20528->20529 20529->20527 20533 7ff63ec328cd 20530->20533 20534 7ff63ec332a0 41 API calls 20530->20534 20532 7ff63ec330e4 30 API calls 20531->20532 20532->20533 20533->20518 20534->20533 20536 7ff63ec332c8 20535->20536 20544 7ff63ec33309 20535->20544 20537 7ff63ec332e0 20536->20537 20536->20544 20538 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20537->20538 20539 7ff63ec332e5 20538->20539 20541 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20539->20541 20540 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20542 7ff63ec332f0 20540->20542 20541->20542 20542->20518 20543 7ff63ec33327 20543->20540 20544->20542 20544->20543 20576 7ff63ec32900 20544->20576 20547 7ff63ec33110 20546->20547 20551 7ff63ec33159 20546->20551 20548 7ff63ec33128 20547->20548 20547->20551 20549 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20548->20549 20550 7ff63ec3312d 20549->20550 20552 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20550->20552 20553 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20551->20553 20554 7ff63ec33138 20551->20554 20552->20554 20553->20554 20554->20518 20556 7ff63ec32ae5 20555->20556 20560 7ff63ec32af5 20555->20560 20557 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20556->20557 20558 7ff63ec32aea 20557->20558 20559 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20558->20559 20559->20560 20560->20518 20562 7ff63ec32b38 43 API calls 20561->20562 20563 7ff63ec32a6a 20562->20563 20564 7ff63ec32a97 20563->20564 20565 7ff63ec32aab 20563->20565 20567 7ff63ec32a9d 20564->20567 20581 7ff63ec32c30 20564->20581 20588 7ff63ec32b8c 20565->20588 20567->20518 20570 7ff63ec32b38 43 API calls 20569->20570 20571 7ff63ec329c4 20570->20571 20595 7ff63ec32cd8 20571->20595 20574 7ff63ec32a20 20574->20518 20575 7ff63ec32ac0 30 API calls 20575->20574 20577 7ff63ec3c2c4 40 API calls 20576->20577 20578 7ff63ec32928 20577->20578 20579 7ff63ec3b350 41 API calls 20578->20579 20580 7ff63ec3296e 20579->20580 20580->20544 20582 7ff63ec33564 43 API calls 20581->20582 20583 7ff63ec32c7c 20582->20583 20584 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20583->20584 20585 7ff63ec32c8c 20583->20585 20586 7ff63ec32cad 20584->20586 20585->20567 20587 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20586->20587 20587->20585 20589 7ff63ec334bc 43 API calls 20588->20589 20590 7ff63ec32bd8 20589->20590 20591 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20590->20591 20592 7ff63ec32be8 20590->20592 20593 7ff63ec32c09 20591->20593 20592->20567 20594 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20593->20594 20594->20592 20596 7ff63ec32d06 20595->20596 20597 7ff63ec32d0c 20595->20597 20596->20597 20600 7ff63ec32d2e 20596->20600 20598 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20597->20598 20599 7ff63ec32d11 20598->20599 20602 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20599->20602 20601 7ff63ec2c678 40 API calls 20600->20601 20603 7ff63ec32d3b 20601->20603 20607 7ff63ec32a19 20602->20607 20604 7ff63ec2f388 43 API calls 20603->20604 20605 7ff63ec32d92 20603->20605 20604->20603 20606 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20605->20606 20605->20607 20606->20607 20607->20574 20607->20575 20609 7ff63ec3c483 20608->20609 20613 7ff63ec31dec 20608->20613 20610 7ff63ec2c678 40 API calls 20609->20610 20611 7ff63ec3c48f 20610->20611 20612 7ff63ec2f388 43 API calls 20611->20612 20612->20613 20613->20489 20613->20490 20615 7ff63ec32009 20614->20615 20617 7ff63ec32039 20615->20617 20618 7ff63ec3b31c 20615->20618 20617->20498 20619 7ff63ec3b32f 20618->20619 20622 7ff63ec36390 20619->20622 20623 7ff63ec363b7 20622->20623 20624 7ff63ec363cc 20622->20624 20625 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20623->20625 20624->20623 20626 7ff63ec363da 20624->20626 20627 7ff63ec363bc 20625->20627 20628 7ff63ec2c678 40 API calls 20626->20628 20629 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20627->20629 20631 7ff63ec363e7 20628->20631 20642 7ff63ec363c7 20629->20642 20630 7ff63ec2f388 43 API calls 20630->20631 20631->20630 20632 7ff63ec36417 20631->20632 20633 7ff63ec3647e 20632->20633 20634 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20632->20634 20635 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20633->20635 20637 7ff63ec36580 20633->20637 20636 7ff63ec364ba 20634->20636 20638 7ff63ec36575 20635->20638 20640 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20636->20640 20641 7ff63ec3b18c _set_errno_from_matherr 13 API calls 20637->20641 20637->20642 20639 7ff63ec3594c _invalid_parameter_noinfo 30 API calls 20638->20639 20639->20637 20640->20633 20641->20642 20642->20617 20644 7ff63ec15eb3 FormatMessageA 20643->20644 20646 7ff63ec15ea8 20643->20646 20645 7ff63ec15f2f LocalAlloc 20644->20645 20644->20646 20645->20646 20647 7ff63ec15f4a 20645->20647 20646->20410 20648 7ff63ec03ce5 45 API calls 20647->20648 20648->20646 20659 7ff63ec1a9fc 20658->20659 20663 7ff63ec1a87b 20658->20663 20661 7ff63ec2999c _Init_thread_header 5 API calls 20659->20661 20660 7ff63ec1a9ed 20660->20117 20662 7ff63ec1aa08 20661->20662 20662->20663 20665 7ff63ec29c14 33 API calls 20662->20665 20663->20660 20664 7ff63ec03d68 32 API calls 20663->20664 20666 7ff63ec1a8d4 20664->20666 20667 7ff63ec1aa36 20665->20667 20684 7ff63ec01718 20666->20684 20669 7ff63ec29a34 4 API calls 20667->20669 20669->20663 20671 7ff63ec04094 32 API calls 20672 7ff63ec1a8fa 20671->20672 20673 7ff63ec1a910 20672->20673 20674 7ff63ec04059 30 API calls 20672->20674 20675 7ff63ec04094 32 API calls 20673->20675 20674->20673 20676 7ff63ec1a969 20675->20676 20688 7ff63ec039fb 20676->20688 20685 7ff63ec01753 20684->20685 20686 7ff63ec03d68 32 API calls 20685->20686 20687 7ff63ec01761 20686->20687 20687->20671 20689 7ff63ec03a21 __scrt_get_show_window_mode 20688->20689 20706 7ff63ec015b0 20689->20706 20691 7ff63ec03a31 20692 7ff63ec03ce5 45 API calls 20691->20692 20693 7ff63ec03b13 __scrt_get_show_window_mode 20692->20693 20694 7ff63ec05b21 8 API calls 20693->20694 20695 7ff63ec03b47 20694->20695 20696 7ff63ec03ce5 45 API calls 20695->20696 20697 7ff63ec03bfc 20696->20697 20698 7ff63ec36d88 30 API calls 20697->20698 20707 7ff63ec016e8 20706->20707 20712 7ff63ec015e6 20706->20712 20708 7ff63ec29bf0 _handle_error 8 API calls 20707->20708 20710 7ff63ec01702 20708->20710 20709 7ff63ec0951c 60 API calls 20709->20712 20710->20691 20711 7ff63ec066c4 60 API calls 20711->20712 20712->20707 20712->20709 20712->20711 20714 7ff63ec0af55 20713->20714 20715 7ff63ec06480 60 API calls 20714->20715 20716 7ff63ec0b0e3 20715->20716 20717 7ff63ec29bf0 _handle_error 8 API calls 20716->20717 20718 7ff63ec0b0f3 20717->20718 20718->18851 20719 7ff63ec0b0fc 20718->20719 20720 7ff63ec0b167 20719->20720 20720->20720 20721 7ff63ec06480 60 API calls 20720->20721 20722 7ff63ec0b1d5 20721->20722 20723 7ff63ec29bf0 _handle_error 8 API calls 20722->20723 20724 7ff63ec0b1e5 20723->20724 20724->18851 20725 7ff63ec0b1ee 20724->20725 20726 7ff63ec0b271 20725->20726 20727 7ff63ec06480 60 API calls 20726->20727 20728 7ff63ec0b304 20727->20728 20729 7ff63ec29bf0 _handle_error 8 API calls 20728->20729 20751 7ff63ec395c8 EnterCriticalSection 20731->20751 20746 7ff63ec34aad 20745->20746 20747 7ff63ec34a8e GetProcAddress 20745->20747 20748 7ff63ec34ab7 FreeLibrary 20746->20748 20749 7ff63ec34abd 20746->20749 20747->20746 20750 7ff63ec34aa5 20747->20750 20748->20749 20749->18052 20750->20746 20760 7ff63ec39688 __FrameHandler3::FrameUnwindToEmptyState 40 API calls 20759->20760 20761 7ff63ec37039 20760->20761 20762 7ff63ec3771c __FrameHandler3::FrameUnwindToEmptyState 40 API calls 20761->20762 20763 7ff63ec3704f 20762->20763 22271 7ff63ec3a790 22286 7ff63ec395c8 EnterCriticalSection 22271->22286 22509 7ff63ec43558 22510 7ff63ec43567 22509->22510 22511 7ff63ec43571 22509->22511 22513 7ff63ec395e4 LeaveCriticalSection 22510->22513 22752 7ff63ec3b130 22753 7ff63ec3ad4c 70 API calls 22752->22753 22754 7ff63ec3b13b 22753->22754 22762 7ff63ec3f678 22754->22762 22775 7ff63ec395c8 EnterCriticalSection 22762->22775 22890 7ff63ec398d0 22891 7ff63ec398ea 22890->22891 22892 7ff63ec398d5 22890->22892 22896 7ff63ec39a28 22892->22896 22897 7ff63ec39a6a 22896->22897 22900 7ff63ec39a72 22896->22900 22898 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22897->22898 22898->22900 22899 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22901 7ff63ec39a7f 22899->22901 22900->22899 22902 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22901->22902 22903 7ff63ec39a8c 22902->22903 22904 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22903->22904 22905 7ff63ec39a99 22904->22905 22906 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22905->22906 22907 7ff63ec39aa6 22906->22907 22908 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22907->22908 22909 7ff63ec39ab3 22908->22909 22910 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22909->22910 22911 7ff63ec39ac0 22910->22911 22912 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22911->22912 22913 7ff63ec39acd 22912->22913 22914 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22913->22914 22915 7ff63ec39add 22914->22915 22916 7ff63ec3a94c Concurrency::details::SchedulerProxy::DeleteThis 13 API calls 22915->22916 22917 7ff63ec39aed 22916->22917 22922 7ff63ec39ba8 22917->22922 22936 7ff63ec395c8 EnterCriticalSection 22922->22936

              Executed Functions

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 0 7ff63ec042e4-7ff63ec0433a call 7ff63ec05b21 3 7ff63ec0434f-7ff63ec04368 0->3 4 7ff63ec0433c-7ff63ec04347 0->4 5 7ff63ec0436a-7ff63ec0438f 3->5 4->3 5->5 6 7ff63ec04391-7ff63ec043b1 call 7ff63ec05b21 5->6 9 7ff63ec046b3-7ff63ec04760 6->9 10 7ff63ec043b7-7ff63ec043ea CreateFileA 6->10 11 7ff63ec04763-7ff63ec04798 9->11 10->9 12 7ff63ec043f0-7ff63ec04411 call 7ff63ec05b21 10->12 11->11 13 7ff63ec0479a-7ff63ec047a7 11->13 18 7ff63ec04413-7ff63ec0441d 12->18 19 7ff63ec04420-7ff63ec04423 12->19 15 7ff63ec05674-7ff63ec05699 call 7ff63ec29bf0 13->15 18->19 20 7ff63ec047ac-7ff63ec047f3 19->20 21 7ff63ec04429-7ff63ec04580 19->21 24 7ff63ec047f5-7ff63ec04800 20->24 25 7ff63ec04582-7ff63ec045a9 21->25 24->24 26 7ff63ec04802-7ff63ec04807 24->26 25->25 27 7ff63ec045ab-7ff63ec045dc call 7ff63ec09b74 CreateFileMappingA 25->27 28 7ff63ec04b5a-7ff63ec04b5d 26->28 33 7ff63ec045e2-7ff63ec04605 call 7ff63ec09ca4 MapViewOfFile 27->33 34 7ff63ec0480c-7ff63ec04b22 27->34 31 7ff63ec0564d-7ff63ec05650 28->31 31->15 32 7ff63ec05652-7ff63ec0566d call 7ff63ec05b21 31->32 32->15 41 7ff63ec0566f-7ff63ec05672 FindCloseChangeNotification 32->41 42 7ff63ec04b62-7ff63ec04c00 33->42 43 7ff63ec0460b-7ff63ec04631 33->43 35 7ff63ec04b24-7ff63ec04b4b 34->35 35->35 38 7ff63ec04b4d-7ff63ec04b55 35->38 38->28 41->15 44 7ff63ec04c02-7ff63ec04c0e 42->44 45 7ff63ec04c1a-7ff63ec04c24 43->45 46 7ff63ec04637-7ff63ec04663 43->46 44->44 47 7ff63ec04c10-7ff63ec04c15 44->47 48 7ff63ec054da-7ff63ec055fb 45->48 49 7ff63ec04c2a-7ff63ec04c43 45->49 50 7ff63ec04665-7ff63ec04696 46->50 47->31 53 7ff63ec055fe-7ff63ec05634 48->53 51 7ff63ec04c45-7ff63ec04c51 49->51 50->50 52 7ff63ec04698-7ff63ec046ae 50->52 51->51 55 7ff63ec04c53-7ff63ec04c5d 51->55 56 7ff63ec04c64-7ff63ec04d3f call 7ff63ec0569a * 3 52->56 53->53 54 7ff63ec05636-7ff63ec0563e 53->54 57 7ff63ec05643-7ff63ec05648 call 7ff63ec09f0a 54->57 55->56 66 7ff63ec04d41-7ff63ec04d50 56->66 57->31 66->66 67 7ff63ec04d52-7ff63ec04d54 66->67 68 7ff63ec054ac-7ff63ec054b4 67->68 69 7ff63ec04d5a-7ff63ec04d6d 67->69 71 7ff63ec054bc-7ff63ec054c4 68->71 70 7ff63ec04d72-7ff63ec04de4 call 7ff63ec0569a * 3 call 7ff63ec0572f 69->70 82 7ff63ec04f50-7ff63ec04f5a 70->82 83 7ff63ec04dea-7ff63ec04e09 call 7ff63ec05b21 70->83 73 7ff63ec054cc-7ff63ec054d5 71->73 74 7ff63ec054c6-7ff63ec054ca 71->74 73->57 74->73 82->70 84 7ff63ec04f60 82->84 87 7ff63ec04e0f-7ff63ec04e32 83->87 88 7ff63ec04f4c 83->88 84->71 90 7ff63ec04f49 87->90 91 7ff63ec04e38-7ff63ec04e43 87->91 88->82 90->88 92 7ff63ec04e45-7ff63ec04e47 91->92 93 7ff63ec04e59-7ff63ec04e6c call 7ff63ec05bf9 91->93 94 7ff63ec04f44-7ff63ec04f47 92->94 95 7ff63ec04e4d-7ff63ec04e53 92->95 93->94 98 7ff63ec04e72-7ff63ec04eba 93->98 94->82 95->93 95->94 99 7ff63ec04ebd-7ff63ec04ede 98->99 99->99 100 7ff63ec04ee0-7ff63ec04f04 call 7ff63ec0a16e 99->100 104 7ff63ec04f65-7ff63ec05076 GetLastError 100->104 105 7ff63ec04f06-7ff63ec04f32 call 7ff63ec05ba3 call 7ff63ec0a16e 100->105 106 7ff63ec05079-7ff63ec050a8 104->106 114 7ff63ec050c4-7ff63ec05458 GetLastError 105->114 115 7ff63ec04f38-7ff63ec04f3f 105->115 106->106 108 7ff63ec050aa-7ff63ec050b2 106->108 110 7ff63ec050ba-7ff63ec050bf 108->110 110->82 116 7ff63ec0545b-7ff63ec05490 114->116 115->110 116->116 117 7ff63ec05492-7ff63ec054a7 116->117 117->88
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: File$CreateErrorLast$ChangeCloseFindMappingNotificationView
              • String ID: !$&$3:<KU$:$;$<$=$=$K$Z$a$p$q$w$z$|
              • API String ID: 22809042-863818155
              • Opcode ID: 7c483ff31ffa63e407df1a0290c0d0c56f73aff22cc9704d1455be2e97b2d163
              • Instruction ID: cc14da68fc9292169e81220f97bad3c1b0a77d7c7212c4dcf5c4dae144ec9294
              • Opcode Fuzzy Hash: 7c483ff31ffa63e407df1a0290c0d0c56f73aff22cc9704d1455be2e97b2d163
              • Instruction Fuzzy Hash: 5EB2706361D2C08BF7218638A0A13DBAF92D7A2364F249518D7D447BEBCA6EC50DDF11
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 201 7ff63ec0f1c7-7ff63ec0f218 call 7ff63ec29b80 call 7ff63ec05b21 206 7ff63ec0f73c-7ff63ec0f759 201->206 207 7ff63ec0f21e-7ff63ec0f235 201->207 207->206 209 7ff63ec0f23b-7ff63ec0f317 call 7ff63ec37170 call 7ff63ec16c24 207->209 214 7ff63ec0f319 209->214 215 7ff63ec0f320-7ff63ec0f382 call 7ff63ec16015 call 7ff63ec08cfe CreateProcessW 209->215 214->215 220 7ff63ec0f3df-7ff63ec0f3f1 call 7ff63ec098d2 215->220 221 7ff63ec0f384-7ff63ec0f3a6 call 7ff63ec05b21 215->221 230 7ff63ec0f3f7-7ff63ec0f3ff 220->230 231 7ff63ec0f4c1-7ff63ec0f4cc 220->231 226 7ff63ec0f3a8 221->226 227 7ff63ec0f3ad-7ff63ec0f3cf call 7ff63ec05b21 221->227 226->227 227->231 237 7ff63ec0f3d5-7ff63ec0f3da 227->237 233 7ff63ec0f40a 230->233 234 7ff63ec0f401-7ff63ec0f408 230->234 235 7ff63ec0f4ce-7ff63ec0f4dd call 7ff63ec04059 231->235 236 7ff63ec0f4e2-7ff63ec0f56b call 7ff63ec37170 call 7ff63ec16c24 231->236 239 7ff63ec0f411-7ff63ec0f46d call 7ff63ec37050 * 2 call 7ff63ec08cfe 233->239 234->239 235->236 248 7ff63ec0f56d 236->248 249 7ff63ec0f574-7ff63ec0f5c8 call 7ff63ec16015 call 7ff63ec08cfe CreateProcessW 236->249 237->231 239->231 258 7ff63ec0f46f-7ff63ec0f491 call 7ff63ec05b21 239->258 248->249 259 7ff63ec0f5ca-7ff63ec0f5ec call 7ff63ec05b21 249->259 260 7ff63ec0f625-7ff63ec0f637 call 7ff63ec098d2 249->260 267 7ff63ec0f498-7ff63ec0f4ba call 7ff63ec05b21 258->267 268 7ff63ec0f493 258->268 269 7ff63ec0f5ee 259->269 270 7ff63ec0f5f3-7ff63ec0f615 call 7ff63ec05b21 259->270 276 7ff63ec0f71b-7ff63ec0f726 260->276 277 7ff63ec0f63d-7ff63ec0f645 260->277 267->231 280 7ff63ec0f4bc 267->280 268->267 269->270 270->276 278 7ff63ec0f61b-7ff63ec0f620 270->278 276->206 279 7ff63ec0f728-7ff63ec0f737 call 7ff63ec04059 276->279 281 7ff63ec0f647-7ff63ec0f64e 277->281 282 7ff63ec0f650 277->282 278->276 279->206 280->231 284 7ff63ec0f657-7ff63ec0f6c7 call 7ff63ec37050 * 3 call 7ff63ec08cfe 281->284 282->284 284->276 295 7ff63ec0f6c9-7ff63ec0f6eb call 7ff63ec05b21 284->295 298 7ff63ec0f6ed 295->298 299 7ff63ec0f6f2-7ff63ec0f714 call 7ff63ec05b21 295->299 298->299 299->276 302 7ff63ec0f716 299->302 302->276
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CreateProcess
              • String ID: %s%s$%s%s"
              • API String ID: 963392458-3970236042
              • Opcode ID: 2c53f94690d710ff52d975b19985bc04d770dff98ea3af100831d4714eaa257a
              • Instruction ID: 1da70af0ae0dc801132f466a62d33affa99b52dff9f7dbfac9c5d06a06553bff
              • Opcode Fuzzy Hash: 2c53f94690d710ff52d975b19985bc04d770dff98ea3af100831d4714eaa257a
              • Instruction Fuzzy Hash: 9CE1D461A086D281FB718B68A8057FD23B0FFA4348F040235FE5D96B95DF7DE6899320
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: FreeHeap
              • String ID:
              • API String ID: 3298025750-0
              • Opcode ID: 392c3d8147f14a5988bd6e81e08928f6685ac7a6814d1fd57e6d66c548fd3368
              • Instruction ID: b4012be708b82a0df2024893c8d457b9050d4e9dac4c249e4aabbde9a27d7336
              • Opcode Fuzzy Hash: 392c3d8147f14a5988bd6e81e08928f6685ac7a6814d1fd57e6d66c548fd3368
              • Instruction Fuzzy Hash: B241B032714A5486EF48CF2ADD6416DA3B1AB58FD4B099037EE2DC7B69DE3CD4499300
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: AddressHandleModuleProc$CountCreateCriticalEventInitializeSectionSpin
              • String ID: SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
              • API String ID: 4003212759-3242537097
              • Opcode ID: c90e6321c21e8170757152ffd5828284882e8311bafeae04178b06d48b048fe3
              • Instruction ID: 09bd757905d4462c4cfb43c2fd8a90fdbb461089674fdfa0c4c118903e938d40
              • Opcode Fuzzy Hash: c90e6321c21e8170757152ffd5828284882e8311bafeae04178b06d48b048fe3
              • Instruction Fuzzy Hash: F8212120A09B0381FE16AB11F8555BC63B0AF78750F456436F97EC27A0EE2CE44CAA30
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_initialize_crt__scrt_is_managed_app__scrt_release_startup_lock
              • String ID: MZx
              • API String ID: 4144305933-2575928145
              • Opcode ID: 30e58f7d77d9314959c3941e1e81b958be870a7e3f97932d04362d4405c0f434
              • Instruction ID: e4af738eca6ee62e831547151c66241ded43aff0c512f9caf352dd2238a8281b
              • Opcode Fuzzy Hash: 30e58f7d77d9314959c3941e1e81b958be870a7e3f97932d04362d4405c0f434
              • Instruction Fuzzy Hash: 76311721A0C64246FE25AB6598513FD62B1AF75384F446435F96ECB3D3CE2EA84CB270
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Process$CurrentExitTerminate
              • String ID:
              • API String ID: 1703294689-0
              • Opcode ID: 3dd67f1416581bf9e0c8d03f5868528173d187c597f887881cfbb1e3b75360a8
              • Instruction ID: 5a59e3e5eeeaffa72236acc4a69168fa09c66c7f6c5c1eb262bfa412ad3e9bdc
              • Opcode Fuzzy Hash: 3dd67f1416581bf9e0c8d03f5868528173d187c597f887881cfbb1e3b75360a8
              • Instruction Fuzzy Hash: FDE04F20B0431582EB147B349C952BD2672AFA4B01F015439E82EC2396DE3DE85CA730
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 311 7ff63ec392d0-7ff63ec392f3 call 7ff63ec39370 313 7ff63ec392f8-7ff63ec392fb 311->313 314 7ff63ec392fd-7ff63ec3930c 313->314 315 7ff63ec39313-7ff63ec3931d 313->315 314->315
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: try_get_function
              • String ID: AppPolicyGetProcessTerminationMethod
              • API String ID: 2742660187-2031265017
              • Opcode ID: 0ee33bcf2f392076532c211148755c603bfa5807e7bb45c1ddf4ce0e1e4b9a82
              • Instruction ID: 6a654cf69ed04ce21a6cb4ff32874f05a1ba05695526336b65ac832d11363814
              • Opcode Fuzzy Hash: 0ee33bcf2f392076532c211148755c603bfa5807e7bb45c1ddf4ce0e1e4b9a82
              • Instruction Fuzzy Hash: 8BE04FD1E0850691FE154795A8015B8A2319F6C370E484732F93E863E19E3C999CEA60
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Initialize_invalid_parameter_noinfo_set_fmode
              • String ID:
              • API String ID: 3548387204-0
              • Opcode ID: 6e591508efc2d5365d5a76a1ad96f94e93c6647110e43ba5251986789219c34b
              • Instruction ID: bf6db059be7117e703cfc6711fcb31de78a6a2774a4fdba31e80610f91eec0f2
              • Opcode Fuzzy Hash: 6e591508efc2d5365d5a76a1ad96f94e93c6647110e43ba5251986789219c34b
              • Instruction Fuzzy Hash: B2115810E0920346FE1873B049562FC02B24FB0781F442834F92DDA7D3AD2EA899A632
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              • GetModuleHandleW.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF63EC37771,?,?,?,?,00007FF63EC3975B), ref: 00007FF63EC34B3B
                • Part of subcall function 00007FF63EC34A68: GetModuleHandleExW.KERNEL32 ref: 00007FF63EC34A84
                • Part of subcall function 00007FF63EC34A68: GetProcAddress.KERNEL32 ref: 00007FF63EC34A9A
                • Part of subcall function 00007FF63EC34A68: FreeLibrary.KERNEL32 ref: 00007FF63EC34AB7
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: HandleModule$AddressFreeLibraryProc
              • String ID:
              • API String ID: 3947729631-0
              • Opcode ID: ad0b6c8c18660d1b11e8c5c70b0d1bbfb5c01e0827e39ccbe49000612891cb51
              • Instruction ID: 431cb37934efb7d0fb4ad756568d7f773b24ee5c129ac23b4a896dcfd2bb718d
              • Opcode Fuzzy Hash: ad0b6c8c18660d1b11e8c5c70b0d1bbfb5c01e0827e39ccbe49000612891cb51
              • Instruction Fuzzy Hash: 7E216932E04A418AEB119F64C8403EC33B4FB5471CF04553AE62D82B89DF7DD589DBA0
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID:
              • API String ID: 3215553584-0
              • Opcode ID: 5f4a2476c7093d8de22d6614e3f9c9decae07cef510fc887f15bdf7dd5a96ddb
              • Instruction ID: e0882d90c6df31e39c410639cb2193b2daa5271b864eb93fb8620bad68f83180
              • Opcode Fuzzy Hash: 5f4a2476c7093d8de22d6614e3f9c9decae07cef510fc887f15bdf7dd5a96ddb
              • Instruction Fuzzy Hash: 7C115532A187428AE6109B15A88017DA3B4EBA0740F850535F6BDC77A2DE3CF919AB20
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              • RtlAllocateHeap.NTDLL(?,?,00000000,00007FF63EC39861,?,?,000000F8,00007FF63EC3B195,?,?,?,?,00007FF63EC3A971), ref: 00007FF63EC3C52D
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: AllocateHeap
              • String ID:
              • API String ID: 1279760036-0
              • Opcode ID: 50ee23321bb0392af5e36db0a14a67e004919aab705170532cb16fd1e2da9a79
              • Instruction ID: e5d63115faa7ce1ce6dd32859cddbbe281d13826e2be46feb9a7a7b1436d3f9e
              • Opcode Fuzzy Hash: 50ee23321bb0392af5e36db0a14a67e004919aab705170532cb16fd1e2da9a79
              • Instruction Fuzzy Hash: FAF06D44B0920681FE5556A66C21BFC12A05FA8B80F4C4530FD2EC63C2DE2CE889B230
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
              • RtlAllocateHeap.NTDLL(?,?,0000000100000002,00007FF63EC41B15,?,?,00000000,00007FF63EC3DBCF,?,?,0000000100000002,00007FF63EC35377,00000000,00000000,?,00007FF63EC355AD), ref: 00007FF63EC3B2A2
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: AllocateHeap
              • String ID:
              • API String ID: 1279760036-0
              • Opcode ID: 6da3bee6b59dccd8d17a81d4324de9a97876941589f4a15ec500e38210a561e7
              • Instruction ID: a193c86a76286cac55b3e034540cc2417d0f2cf74e18e0bdac58e6eb0dc0515f
              • Opcode Fuzzy Hash: 6da3bee6b59dccd8d17a81d4324de9a97876941589f4a15ec500e38210a561e7
              • Instruction Fuzzy Hash: F3F0F200F1D20381FE656AA25D416BD22A15FB97A0F090730F93EC63C2DE2DE898A630
              Uniqueness

              Uniqueness Score: -1.00%

              Control-flow Graph

              APIs
                • Part of subcall function 00007FF63EC3B264: RtlAllocateHeap.NTDLL(?,?,0000000100000002,00007FF63EC41B15,?,?,00000000,00007FF63EC3DBCF,?,?,0000000100000002,00007FF63EC35377,00000000,00000000,?,00007FF63EC355AD), ref: 00007FF63EC3B2A2
              • HeapReAlloc.KERNEL32(?,?,00000000,00007FF63EC3DBCF,?,?,0000000100000002,00007FF63EC35377,00000000,00000000,?,00007FF63EC355AD,?,?,000000F8,00007FF63EC3526E), ref: 00007FF63EC41B65
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Heap$AllocAllocate
              • String ID:
              • API String ID: 2177240990-0
              • Opcode ID: 185bad2c8ce41f127a627d581bddb9ac587d1fb32a341f829627fe44d33ae8b4
              • Instruction ID: 6238e92397e89958f5286757435308570bd0f73b60c2be3c8514a60f847a4b71
              • Opcode Fuzzy Hash: 185bad2c8ce41f127a627d581bddb9ac587d1fb32a341f829627fe44d33ae8b4
              • Instruction Fuzzy Hash: 1E014F90E0C24384FD666763A9412BD11701F757A0F084232F9BDC73D2ED2CE8586A20
              Uniqueness

              Uniqueness Score: -1.00%

              Non-executed Functions

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Variant$Clear$Init$FreeString$Local$AllocTime
              • String ID: %iM$@$AnchorDNS.cpp
              • API String ID: 2740604783-121187856
              • Opcode ID: 21d90337bb69b6b6baac76ed175b79abc14d48f35b04f2e97a9a73dbcba91590
              • Instruction ID: 7d0759be24ee10c66a08fa4cd50cc09819cf5f37c449a2e9a482128f57d74937
              • Opcode Fuzzy Hash: 21d90337bb69b6b6baac76ed175b79abc14d48f35b04f2e97a9a73dbcba91590
              • Instruction Fuzzy Hash: 2363E2236096C18FEB21CF38D4903EE3BB2EB66758F059125DA5987392DE39D60ED710
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: $$%$($)$*$+$,$-$.$/$3$7$D$E$F$H$I$J$K$L$M$N$O$P$Q$R$S$T$U$V$W$X$Y$Z$[$]$^$_$d$e$f$h$i$j$k$l$m$n$o$p$q$r$s$t$u$v$w$x$y$z${$}$~
              • API String ID: 0-1365822169
              • Opcode ID: 590e0402bee17ec44ebb9210a0617c2d0f30fdc08742d61b04fab8db75b1eb80
              • Instruction ID: 824f1778e576c6e5b4679570805aa310ed7af6184b336593c26a1d90cadfba2d
              • Opcode Fuzzy Hash: 590e0402bee17ec44ebb9210a0617c2d0f30fdc08742d61b04fab8db75b1eb80
              • Instruction Fuzzy Hash: 96915C5350D2C089E3128639A44839FFFA183B3358F0C5199E7D90BB9BC2AED449DF22
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Init_thread_header$CriticalEnterSection
              • String ID: !$6$<$?$Q$W$X$X$Y$Y$Z$[$^$e$h$j$k$m$n$o$p$p$r$r$s$t$u$v$w$x$z$z$z${$}$~
              • API String ID: 640747144-3305837859
              • Opcode ID: d289debaf4cabb33d861810eae78fdffde80523ce52a8c9c752a87a1d7701e8c
              • Instruction ID: a2ae06ab7dade61076e8fe8643392d4832ddf3930bec9a9d79bd4ccc98e1de81
              • Opcode Fuzzy Hash: d289debaf4cabb33d861810eae78fdffde80523ce52a8c9c752a87a1d7701e8c
              • Instruction Fuzzy Hash: DAC2CF63A092C18EE715CA3891843CE7FA2E373314F05A425D39487797DB6AEA2FD711
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: memcpy_s$_invalid_parameter_noinfo
              • String ID: $MZx
              • API String ID: 2880407647-1316729395
              • Opcode ID: bc193ee7fd2add63f8d1ef46771125166fe55af57fce5cc31dc074751e44201c
              • Instruction ID: 5ff72ee239c39e325cbb4beebc3d241739d752719f86193d54a377a9088e31d1
              • Opcode Fuzzy Hash: bc193ee7fd2add63f8d1ef46771125166fe55af57fce5cc31dc074751e44201c
              • Instruction Fuzzy Hash: E503E6B2A181928FD7758E24D8407FD37B5F7A878CF001135EA5A97B49DF3CAA089B50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ErrorLast$CloseHandle$AllocCreateMemoryProcessRemoteThreadVirtualWrite
              • String ID: *$1$@$H$W$Y$\$m$m$n$p$r$y
              • API String ID: 2672033360-2450132792
              • Opcode ID: 509527a9178011772fbb75b66973a6ae0779f64e2d2f48fec426633055b94f00
              • Instruction ID: 524ca1265d28a81b101889b1ef312625816160408e1b5e076d870be14a1e2b7c
              • Opcode Fuzzy Hash: 509527a9178011772fbb75b66973a6ae0779f64e2d2f48fec426633055b94f00
              • Instruction Fuzzy Hash: FFF14B1350E3C0C9D712877C645028EAFE197B3A48F2C8099E7D5077A6CAAFC51ADB76
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Sleep
              • String ID: ,$1$@$V$Y$Z$Z$b$c$k$m$o$t$t$u$v$w$y$z${$~
              • API String ID: 3472027048-1889956645
              • Opcode ID: b883412409f385da3dccdaedf41a5f72889cee189f3be9252496c239270b3145
              • Instruction ID: becf506b2f34c5a60e59b016b3b3a0e3b1b9732f32f3d588a8556f25fa39b074
              • Opcode Fuzzy Hash: b883412409f385da3dccdaedf41a5f72889cee189f3be9252496c239270b3145
              • Instruction Fuzzy Hash: AF23082365E2C18FE721CB3C90947CF7FA1D376318F29A558C791073A3C66A860ADB65
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: J$K$L$M$N$O$P$Q$R$S$T$U$V$W$X$Y$Z$[$\$]$^$_$`$a$b$c
              • API String ID: 0-709081789
              • Opcode ID: 95e4a524beecc5d3375392c90eb3e29f890008fe832452cbeb287093093b9316
              • Instruction ID: 5befff55eabf4d1d3c59964fb2b1b1ddab650d3d35693bc504f4217be43962dd
              • Opcode Fuzzy Hash: 95e4a524beecc5d3375392c90eb3e29f890008fe832452cbeb287093093b9316
              • Instruction Fuzzy Hash: 8F42F523B5E6914FFB01CA3494A53DF6B92C372328F19A529DB65077C7CA2D8A0DDB10
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CountCreateSleepTickUuidhtonl
              • String ID: -$d$i$n$o$q$u$v$v$w$x$y$~
              • API String ID: 3289394829-175494460
              • Opcode ID: 128d2acbc99dae409a441b2b5b9585aaca3754f24f26254c70192992c32f7fd9
              • Instruction ID: 746228a32930e15b4d5f09e8237f9a2050edf96cfe808915af51cf0adb975cc1
              • Opcode Fuzzy Hash: 128d2acbc99dae409a441b2b5b9585aaca3754f24f26254c70192992c32f7fd9
              • Instruction Fuzzy Hash: 57E1A82350C6C08AD721CA29A44039FBBA1F7B6794F185164EBD887BD9CE7CD409DF21
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
              • String ID: 1#IND$1#INF$1#QNAN$1#SNAN$MZx
              • API String ID: 808467561-2638907429
              • Opcode ID: d012cead53beefa769b0082b3f3d7855ca9d1f1ad9093c85bdf3b4fc5cd47282
              • Instruction ID: bad7f8aa8d68efe488ae8383e9c333679dbd8fa86b69c59ffc2127ccf49548ea
              • Opcode Fuzzy Hash: d012cead53beefa769b0082b3f3d7855ca9d1f1ad9093c85bdf3b4fc5cd47282
              • Instruction Fuzzy Hash: 74B20972A581828AE7768E24D4417FD37B1FB64388F501136EA2A97B85DF3CE908DF11
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Init_thread_header
              • String ID: -$5$C$W$]$m$m$p$t$t$u$u$v
              • API String ID: 3738618077-576874599
              • Opcode ID: bcbf8ffac54b1773aa721f673119574997edb21e1206f49bdf9cb5a6c40c426a
              • Instruction ID: 11f6da7a9bc0730765301125a582d25b96c1edb7b8fe1a22bace4be094e1e7bc
              • Opcode Fuzzy Hash: bcbf8ffac54b1773aa721f673119574997edb21e1206f49bdf9cb5a6c40c426a
              • Instruction Fuzzy Hash: E872062360E3C08AE711C738A4403DEAFA1D772758F188669E7A4477D7CA6ED50EDB21
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID: 1$3$4$7$8$f$g$g$m$n$p$q$r$s$u${$|$}$~
              • API String ID: 3215553584-3385196127
              • Opcode ID: a4fb933015b4370a8789d106c28e4a7b97fb32e8a639dea17fde7982e115794c
              • Instruction ID: 194d2b66e141250e58479cf1d80d614a8832be2716659c3da2b55badea8ed161
              • Opcode Fuzzy Hash: a4fb933015b4370a8789d106c28e4a7b97fb32e8a639dea17fde7982e115794c
              • Instruction Fuzzy Hash: A602AB2364E3C08EE722CA7890557CA7FA1D373304F0A945AD2C44B797D6BE950EDB22
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CloseErrorLast$DesktopHandleProcessToken$AdjustCreateCurrentLookupOpenPrivilegePrivilegesSleepValue
              • String ID: SeDebugPrivilege
              • API String ID: 424851636-2896544425
              • Opcode ID: 70dd4c4aaec2ce1fd2c9a64400d0de6192bb0fecf6f34e628cd92d7b906293ec
              • Instruction ID: eedad4c2ae2c1fa7dc507c0cdfe088e3f1d163f1dd63e9894e0ba31ac93479a2
              • Opcode Fuzzy Hash: 70dd4c4aaec2ce1fd2c9a64400d0de6192bb0fecf6f34e628cd92d7b906293ec
              • Instruction Fuzzy Hash: D5C213236092C08FEB15CE3884A57DE3FE2D332368F296919E754477DBCA2A850ED715
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ErrorLast
              • String ID: :$;$B$K$[$_$l$m$q$u$v$w$|
              • API String ID: 1452528299-116905044
              • Opcode ID: 0513b9e020c650c038df537f902685702b3668b7bf956292b96d5c65e824962a
              • Instruction ID: d6cab10637043864c9104e9e3fcfe329b673a8d6aa4020a6a5ba38ba2cd04a30
              • Opcode Fuzzy Hash: 0513b9e020c650c038df537f902685702b3668b7bf956292b96d5c65e824962a
              • Instruction Fuzzy Hash: EF52F41364E7C189EB22873C94403DE7FA0D736B48F2D9169D789073A3DA6AC60BD725
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ErrorLast
              • String ID: $6$O$S$]$a$h$i$r$s$u$y
              • API String ID: 1452528299-3945959020
              • Opcode ID: 15539a1ea54178624e94140e6e54b061f5b9f23d1ee489a3d026fef316606662
              • Instruction ID: d4163f75736f1eabc0fc01d74bc90aad077f6e73b13912a8e7ea2f8e0d5ada16
              • Opcode Fuzzy Hash: 15539a1ea54178624e94140e6e54b061f5b9f23d1ee489a3d026fef316606662
              • Instruction Fuzzy Hash: 3192AF2374F2C09ED722CA7C90902CE7FA1D777708F19A519D6C4477A3C66A860BEB25
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: C$E$W$a$c$d$g$hardWorker.cpp$i$k$m$s$thExecute$u$x$y
              • API String ID: 0-4044612007
              • Opcode ID: 528565641a5fa59965e7094b39c86091d7e099151dbf63dc0e9e00202449089f
              • Instruction ID: da231b36a499258c9a06879ba382431ccc6390a4e37ed66917aa034631f76d40
              • Opcode Fuzzy Hash: 528565641a5fa59965e7094b39c86091d7e099151dbf63dc0e9e00202449089f
              • Instruction Fuzzy Hash: 9002F22761D1C08FF715CA35A0E96DF7FA2C3B6364F156458E69103393CA2AC60EDB25
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: I$O$Q$V$[$i$k$l$n$q$u$v$w$z$}
              • API String ID: 0-1532506219
              • Opcode ID: 25f010a9121cdf5fe0438b17a91793d7a998d18be7759f3303dbe55dca6b5570
              • Instruction ID: 9576c908703423f6dbc276edefb3693aa1a46aba4fabdaf5ed96143dc1d4f8d3
              • Opcode Fuzzy Hash: 25f010a9121cdf5fe0438b17a91793d7a998d18be7759f3303dbe55dca6b5570
              • Instruction Fuzzy Hash: C8516F2361E2C08AE711C63D9584B8EAF62C3B3768F28D255D794177E7C26FD90B8B11
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Variant$ClearInitString$AllocFree
              • String ID:
              • API String ID: 1107635823-0
              • Opcode ID: 5dbce6b5678e906daa497a8fe069cedab797123d3a809188e671a20ac9afd09d
              • Instruction ID: afa1af70c2c23eec38c1295cb83bce0ad0f8aae8613324c07a70226d495e4c1e
              • Opcode Fuzzy Hash: 5dbce6b5678e906daa497a8fe069cedab797123d3a809188e671a20ac9afd09d
              • Instruction Fuzzy Hash: 51B1BF32A05B4686EB24DB65E9103AC23B0FF64B98F044132EE6D87785DF38E589D360
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CountCreateSleepTickUuidhtonl
              • String ID: %$d$o$q$u$v$x$y
              • API String ID: 3289394829-2334579308
              • Opcode ID: d322d65621f5a739180624087787dc2bb8428771ec4983662acf44e31363ed38
              • Instruction ID: 7b5293c18597e7fbdd68a79c577eb30a6885406828b8104bbcb42508ab5236a4
              • Opcode Fuzzy Hash: d322d65621f5a739180624087787dc2bb8428771ec4983662acf44e31363ed38
              • Instruction Fuzzy Hash: 0DB1C52360C6C08AD721CB29A4403AEABA1F7B5794F585134FBED87B99CE7CD409DB11
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: .$/$I$R$]$j$n$q$t$v${
              • API String ID: 0-3027042243
              • Opcode ID: e3f05266b6695d7b907c3ace667c789df552f0161a1971962b81a190934c847e
              • Instruction ID: 7963f061bc8bc52b730e17d7392fcc2a3e1ae0103382330df9ee8087e37c4289
              • Opcode Fuzzy Hash: e3f05266b6695d7b907c3ace667c789df552f0161a1971962b81a190934c847e
              • Instruction Fuzzy Hash: 80322C2375E2C14BEB21863891513CE6F92D7B2318F289424D795077E7C96ED60EDB21
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo$CurrentLocalProcessTime
              • String ID: 8$:H$=$>$n$z
              • API String ID: 479778610-3277947295
              • Opcode ID: 24e28aaa322a5534530b53c80a3b68297e011b316e398c9091511e55271d6754
              • Instruction ID: d03341d1501b3e841ac2ba4e42bc9060e63a50eb627209c39dac0483ddb9eb5b
              • Opcode Fuzzy Hash: 24e28aaa322a5534530b53c80a3b68297e011b316e398c9091511e55271d6754
              • Instruction Fuzzy Hash: 8191716360D3C189E7318B29B4517DFBFA0E7A6794F044129EAD847B8ACE2CD149DF21
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Init_thread_header
              • String ID: -$b$e$m$t$x
              • API String ID: 3738618077-2552193739
              • Opcode ID: 3ce5c1e8c2cf2fa098fabf7009a70737c3dc51f77ee7f6e113e094b2a62fa685
              • Instruction ID: d1f7cae6531a234c2413429e0bb9663bbc5094e550fd5e4aa0d7ba5247de5e5c
              • Opcode Fuzzy Hash: 3ce5c1e8c2cf2fa098fabf7009a70737c3dc51f77ee7f6e113e094b2a62fa685
              • Instruction Fuzzy Hash: D382F323A0E6C18AEB11873C90903CEAFA1D772758F289565D794073A3DA6BD60FD721
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: U$[$e$h$m$r$t$w$y$}
              • API String ID: 0-542650763
              • Opcode ID: 0c01565e325dbcbe6223db191ed4471ad8d579e6a0b63a32935b981ac56cb1b2
              • Instruction ID: 1cd8e95ecdd73986b445ffd04ec529339f365f5b50b28579aab8cd78212a503c
              • Opcode Fuzzy Hash: 0c01565e325dbcbe6223db191ed4471ad8d579e6a0b63a32935b981ac56cb1b2
              • Instruction Fuzzy Hash: 3151F11365E2C08AE711C73D95C47CEAF62D3B2728F28E204E695077E6D26BC60ECB11
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ErrorFileLastWrite$Console
              • String ID: MZx
              • API String ID: 786612050-2575928145
              • Opcode ID: 0e3544457a81fbf93e5bb65d93716f6e1bedc45cc0cd8151d53bc768b8010a5f
              • Instruction ID: b77531c3aba7b7fb8d1c45529ab6affd2ce4faf642241c2e562997e412d95840
              • Opcode Fuzzy Hash: 0e3544457a81fbf93e5bb65d93716f6e1bedc45cc0cd8151d53bc768b8010a5f
              • Instruction Fuzzy Hash: 25D11372B08B818AE710CB64D8502ED7BB1FB54788F540536EEAE97B99DE3CD11AD310
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
              • String ID:
              • API String ID: 3140674995-0
              • Opcode ID: f983b5067b0f2b30bdd97aa1616adc2b1c5e79f94750c729e5f29479b3610a46
              • Instruction ID: 80bf7010f1a153e5a4a4b5bbffac8ab04cd4bc61f326c5b3c32e3e5e183d03fe
              • Opcode Fuzzy Hash: f983b5067b0f2b30bdd97aa1616adc2b1c5e79f94750c729e5f29479b3610a46
              • Instruction Fuzzy Hash: 4C315E72609B8185EB609F60E8503ED7370FBA4348F44443AEA5E87B99DF38D648DB20
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: 3333$@$A$C$F$G$L$u
              • API String ID: 0-4267255643
              • Opcode ID: 73dff7867b47ab10b650259e415461b6b4d32505e36f3260bad87e8669f254a6
              • Instruction ID: d5e6b81a8d909cdc264dadbee57e4c1d0b556a2effa49b88abf24bc46b1e3411
              • Opcode Fuzzy Hash: 73dff7867b47ab10b650259e415461b6b4d32505e36f3260bad87e8669f254a6
              • Instruction Fuzzy Hash: 9F71F82360C2C085E7228729B44439FBFA0A7A6758F185065FFC947B86CBBDC548EB21
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: H$J$W$h$q$r$t$}
              • API String ID: 0-3791407899
              • Opcode ID: 9aed2382e2ba0e7ad63a2a422e1ebe0d9933e41efbd1733e4be22e9b2d0fc6df
              • Instruction ID: 9a0e701536716165bfad6a09f9f2e8826104aeddf2d7f959ebf563da61d346c0
              • Opcode Fuzzy Hash: 9aed2382e2ba0e7ad63a2a422e1ebe0d9933e41efbd1733e4be22e9b2d0fc6df
              • Instruction Fuzzy Hash: 3151911362E2C08AE751C739948478EBF62D3B3768F28A644E794077A7C56FC50ACB21
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: G$L$[$g$i$m$s$t
              • API String ID: 0-169899670
              • Opcode ID: 11ac5371ffa870e4faca0248cf03131fc468df5d6cd52eb90d4d4d9e5d353d9f
              • Instruction ID: 6b52192647d6c6e5823eeb03869918d01190181771edcc4ba4ea33a395894646
              • Opcode Fuzzy Hash: 11ac5371ffa870e4faca0248cf03131fc468df5d6cd52eb90d4d4d9e5d353d9f
              • Instruction Fuzzy Hash: 2251A01772A2C09AFB10863994C478EAF52C3A3728F28A204DB94177E6D62B850F9B51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
              • String ID:
              • API String ID: 1239891234-0
              • Opcode ID: 50b34b393fb9b7757b0067613f9e722e960c043d972149cb9b14dd6ea40172bd
              • Instruction ID: 47c0fabf46de4b6acbc43ca8e052d7821c7af8ed4b438416ac1f84b60f5a7431
              • Opcode Fuzzy Hash: 50b34b393fb9b7757b0067613f9e722e960c043d972149cb9b14dd6ea40172bd
              • Instruction Fuzzy Hash: 17317E36618F8186DB608F25E8502AE73B0FBA8754F500136FAAD83B99DF3CC159DB50
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: 9$b$o$s$t$y${
              • API String ID: 0-736560757
              • Opcode ID: 251a74e53f23efd72aa603942f4eb7effd551e4eadd4d008cea0898187d3afe5
              • Instruction ID: 62bd9ef6089bdfa57c5e5c4f05c6729f88dcdb22a71ecd2f0bb20a12fcc40e71
              • Opcode Fuzzy Hash: 251a74e53f23efd72aa603942f4eb7effd551e4eadd4d008cea0898187d3afe5
              • Instruction Fuzzy Hash: 4971F1A379A6908FFB14863AD4B13DBBF91D326724F1AAB19C395033C3C6598658CB14
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: G$S$b$e$j$m
              • API String ID: 0-2644272952
              • Opcode ID: 18027a6baadce9866acccfa7dfa98b205afd85bbf6caf8568a6b751ef114e9c8
              • Instruction ID: b36c9bcd7d62fed9568d8dce570a5ab6dff2f4434dc3bfe709d0bfebb840c4d6
              • Opcode Fuzzy Hash: 18027a6baadce9866acccfa7dfa98b205afd85bbf6caf8568a6b751ef114e9c8
              • Instruction Fuzzy Hash: 2951E42365A2C05AE711CB3885C43CEAF63D7A272CF29E214D695077E6D26BC60FCB50
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: L$]$l$r$x$|
              • API String ID: 0-2173852877
              • Opcode ID: b77aac4abaf3f98204d1b7f95a3a66f6a1c35ce1022cc6839706aae507d9a818
              • Instruction ID: 0a129a25f4771b7935de1a461b9fcfe6ffe770646a1acd698aa33119cf4cac2a
              • Opcode Fuzzy Hash: b77aac4abaf3f98204d1b7f95a3a66f6a1c35ce1022cc6839706aae507d9a818
              • Instruction Fuzzy Hash: 9F519E2362E2C09AE751C73994C4B8EBF52C7A3758F24E244EB94177A7C66BC50A8B11
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: N$]$i$u$|
              • API String ID: 0-306787487
              • Opcode ID: c75ba58e39de87408c9b2f7577236e2cf3a0bc3655436b331ba9798e8fd9d3a5
              • Instruction ID: 421e5eaaa581c06fb0e47dc8a28bffb8de974451f7d89358b98fe44d23a4f188
              • Opcode Fuzzy Hash: c75ba58e39de87408c9b2f7577236e2cf3a0bc3655436b331ba9798e8fd9d3a5
              • Instruction Fuzzy Hash: 95516F1322E2C09AE711C6399484A8EAF62C7B3768F28E654DB94177A7C16BC50ACF51
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Init_thread_header
              • String ID: 0.0.0.0$@
              • API String ID: 3738618077-4086448161
              • Opcode ID: 10443c0507e290efbba5fb0e161bc6cfcda90558624135c68c1676f3c4c44b19
              • Instruction ID: 94caeab5adafd8bfba54a6def90d6faec51e7f0128dcce0224b4b708ca9e8cac
              • Opcode Fuzzy Hash: 10443c0507e290efbba5fb0e161bc6cfcda90558624135c68c1676f3c4c44b19
              • Instruction Fuzzy Hash: 4D8216235092C18FE721CB78C8943DE3FA1D772368F159626D7695B7D7CA29920EC321
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CountCreateErrorLastTickUuidgetaddrinfo
              • String ID: .
              • API String ID: 649965334-248832578
              • Opcode ID: 51d7d7a1b873e9233772d54583de9425c2a44a9220ee525fc56a18a4e1e50fac
              • Instruction ID: 49a58692d6102391030d5805e030c6774df9bb5f3e0547e0653aa9fbe58f78f9
              • Opcode Fuzzy Hash: 51d7d7a1b873e9233772d54583de9425c2a44a9220ee525fc56a18a4e1e50fac
              • Instruction Fuzzy Hash: DEE1F8336086814AEA21CB25A4503FFB761FBA9784F445235FA9A93789DF3CD449DB10
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • _invalid_parameter_noinfo.LIBCMT ref: 00007FF63EC3D228
                • Part of subcall function 00007FF63EC3599C: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF63EC35BF5), ref: 00007FF63EC359A5
                • Part of subcall function 00007FF63EC3599C: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF63EC35BF5), ref: 00007FF63EC359CA
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CurrentFeaturePresentProcessProcessor_invalid_parameter_noinfo
              • String ID: *?$C:\Users\user\Desktop\anchorDNS_x64.exe
              • API String ID: 4036615347-4254306234
              • Opcode ID: c9df3f397fa8304feafd434982a4bc6d76a1b4192cfd87788eb276fbb3299915
              • Instruction ID: 6e11e0fd3e9a90358c3bf6a95e8baf4b7d1d013e675af28e43fb4a997f071b4a
              • Opcode Fuzzy Hash: c9df3f397fa8304feafd434982a4bc6d76a1b4192cfd87788eb276fbb3299915
              • Instruction Fuzzy Hash: 74511362B04B5685EF20CFA29C104BD6BB1FB68BD8B454531FE2D87B85EE3CD4499320
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ErrorLastfreeaddrinfogetaddrinfo
              • String ID:
              • API String ID: 1817844550-0
              • Opcode ID: 44f7346984cd6515759428d1e639b69ff0e5dfb8f6e93bb076f1a20633db3deb
              • Instruction ID: 474c601deef8591572c6fd1d34443abd381eee697a00f52b18ab55ff9d1c7da1
              • Opcode Fuzzy Hash: 44f7346984cd6515759428d1e639b69ff0e5dfb8f6e93bb076f1a20633db3deb
              • Instruction Fuzzy Hash: 092236A3B5E6D18FE7118A38C4903CBBF60E332724F1EA659D7A107393D669C598DB10
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: memcpy_s
              • String ID:
              • API String ID: 1502251526-0
              • Opcode ID: 89efa1099f50e7829e98c86f8bf3cc02ee95f86496c297bcc613a316ecd5c7a4
              • Instruction ID: deab54f74e08c39f956b956474dfb5d1035f74b1ba1e95c571e7709dc41beb9c
              • Opcode Fuzzy Hash: 89efa1099f50e7829e98c86f8bf3cc02ee95f86496c297bcc613a316ecd5c7a4
              • Instruction Fuzzy Hash: 86C1D672B182CA87EF24CF19E04466EB7A1F7A4B84F449135EB5AA3744DE3CE845DB40
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: 200$GET$WinHTTP loader/1.0
              • API String ID: 0-1079223383
              • Opcode ID: 4e184deaab9a70519047993a2d940f8846fc76a40cf1d86d5a6f7e43759051b7
              • Instruction ID: f3316b25620d7a9e214038191af2793cecae3b1cea961a1c07737af8ba95e122
              • Opcode Fuzzy Hash: 4e184deaab9a70519047993a2d940f8846fc76a40cf1d86d5a6f7e43759051b7
              • Instruction Fuzzy Hash: 8AC1B222F0961686FF18DBB5A4507BD22B0AF74748F145135FE2D97B85EE3CE509A320
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: /$o$u
              • API String ID: 0-955228073
              • Opcode ID: 10e4b9ce34a57c28bc8cbe426a657756e6018d26716f850741d3e10a9b08a4b7
              • Instruction ID: 109b91929ffd1ff20e67925c31d8076226cd84704e24b8e0b1efd01bcae38d36
              • Opcode Fuzzy Hash: 10e4b9ce34a57c28bc8cbe426a657756e6018d26716f850741d3e10a9b08a4b7
              • Instruction Fuzzy Hash: CD6137A37296E19BFB118B3A94A13DFAF90D332724F19A708DB65073C3C61A8595CF10
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: 4$t$z
              • API String ID: 0-2937284666
              • Opcode ID: 0c93368524399d751ecca10392dd4542f800fd49e21a11fd472218aeb3d1732c
              • Instruction ID: 580c563ad991bd5418280bee502720a6feb4cb02fee76fbfb585c7dfba37a41f
              • Opcode Fuzzy Hash: 0c93368524399d751ecca10392dd4542f800fd49e21a11fd472218aeb3d1732c
              • Instruction Fuzzy Hash: 9A61EFA379A6D08FF7068639A4B13CFAF91D372724F09AB09DB95033D3C6198659CB14
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID: gfffffff
              • API String ID: 3215553584-1523873471
              • Opcode ID: 39d8d324a5ed8ccc1c6ea7aacc02ab180607cb5763201971971ac6820e19807c
              • Instruction ID: 8bf5e3669f370c8ac197322816a5112b00dc50097661deb9764460053b4944f2
              • Opcode Fuzzy Hash: 39d8d324a5ed8ccc1c6ea7aacc02ab180607cb5763201971971ac6820e19807c
              • Instruction Fuzzy Hash: D3917967B097C686EF11CB29D8003BD77A4AB64B80F059032EA6D87395DE3DE90AD711
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • _invalid_parameter_noinfo.LIBCMT ref: 00007FF63EC3B719
                • Part of subcall function 00007FF63EC3599C: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF63EC35BF5), ref: 00007FF63EC359A5
                • Part of subcall function 00007FF63EC3599C: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF63EC35BF5), ref: 00007FF63EC359CA
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CurrentFeaturePresentProcessProcessor_invalid_parameter_noinfo
              • String ID: -
              • API String ID: 4036615347-2547889144
              • Opcode ID: 7f26510c5e6554bce16751d4058f303b2fede24bf5a348830ea5ec309e2d6b03
              • Instruction ID: 8cee87257b46b26c857cb40c2036defdd53c59db159a6175a61246896ec26879
              • Opcode Fuzzy Hash: 7f26510c5e6554bce16751d4058f303b2fede24bf5a348830ea5ec309e2d6b03
              • Instruction Fuzzy Hash: 7E81E532A0878585EA649B25990077EB7B1FB657D0F044235FAAD87BD9DF3CEC089720
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: C:\Users\user\Desktop\anchorDNS_x64.exe
              • API String ID: 0-4132411585
              • Opcode ID: 1652115602dfb63e67c9851bbdaec33a69702db4e1f3cc669f16178081a43772
              • Instruction ID: edc7cb47c8d8377ef6d6b64878f7b63ee2604e87617976d912eb8b71b0b9f153
              • Opcode Fuzzy Hash: 1652115602dfb63e67c9851bbdaec33a69702db4e1f3cc669f16178081a43772
              • Instruction Fuzzy Hash: 0951E122B0869184F7209B76AC105AE7BB0BB65BD8F144234FEAC87B89CF3CD509D710
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Sleep
              • String ID:
              • API String ID: 3472027048-0
              • Opcode ID: 75bb56789affa75da9325a087a0ddfb37c55b33460be0a2db31353ed10f0cc08
              • Instruction ID: 4c6fcbda49f3782d6066be4b36d6e7720c0ee9dd235b058729df2120575e3f5d
              • Opcode Fuzzy Hash: 75bb56789affa75da9325a087a0ddfb37c55b33460be0a2db31353ed10f0cc08
              • Instruction Fuzzy Hash: CD03C02379B2C08EEB31CF7888847CE3FA0E337708F19A559D6940B757C665960AE725
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ErrorLast
              • String ID:
              • API String ID: 1452528299-0
              • Opcode ID: 713c048b60c55eecbb66833d9fd3fc9b947a0fa7016a9b51d47dd0bfd0301b45
              • Instruction ID: 1af3d696da8d38f7d2d0b563df9e9e45f12d3c1875f3eca1e0d9cbcba19888ee
              • Opcode Fuzzy Hash: 713c048b60c55eecbb66833d9fd3fc9b947a0fa7016a9b51d47dd0bfd0301b45
              • Instruction Fuzzy Hash: 3942BD63B9B2C19EDB128B7C80902CE3FB1D337B0CB29A459D78547363D52A960BE715
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ExceptionRaise_clrfp
              • String ID:
              • API String ID: 15204871-0
              • Opcode ID: c20f8608ea0ecac529bd971984dccab8c2031a969faf6f7420bb3b580a637607
              • Instruction ID: 5ef10dca370238926aaae692259a0c3a9b27511cb558b8af9bcdabd9aee91676
              • Opcode Fuzzy Hash: c20f8608ea0ecac529bd971984dccab8c2031a969faf6f7420bb3b580a637607
              • Instruction Fuzzy Hash: 16B12877600B858BEB1ACF29C84636C77B0F784B48B158922EA6D877A4CF39E455DB10
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Time$FileLocalSystem
              • String ID:
              • API String ID: 704252544-0
              • Opcode ID: bf3cd042b41ec868c10890a1de2338d17c3fadf045592169deca63c2ccae9433
              • Instruction ID: 939c05eee45d4f91ca808e57acbd523b436ca4a4cc8673167f9ebbe20952074a
              • Opcode Fuzzy Hash: bf3cd042b41ec868c10890a1de2338d17c3fadf045592169deca63c2ccae9433
              • Instruction Fuzzy Hash: 73016B62B0978182FE218728A921269B370BF457F07009330ED6D57BD4DF2CE846C700
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Init_thread_header
              • String ID:
              • API String ID: 3738618077-0
              • Opcode ID: 335158fa714618bf8d6de331738153b690514691b205b343662470f5cbf59c13
              • Instruction ID: 4e6c43a9ef021991c4928ada23654bdfeb186516efa79141584dd1ec8ac34ba8
              • Opcode Fuzzy Hash: 335158fa714618bf8d6de331738153b690514691b205b343662470f5cbf59c13
              • Instruction Fuzzy Hash: 43E1D423A086818AFB14CB75E4903EE6B61EB62358F005135EA6D977D6CF2DD94ED320
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: 3:<KU
              • API String ID: 0-2596799183
              • Opcode ID: 5aa116ce32a1d24f05d0aae60a5d907adc89ad15d712247248ac259edc3f15ae
              • Instruction ID: 2f34b6147379ed05aeb8524297c1a4882e86b1f23d5176e9efb528ed1b5ae50d
              • Opcode Fuzzy Hash: 5aa116ce32a1d24f05d0aae60a5d907adc89ad15d712247248ac259edc3f15ae
              • Instruction Fuzzy Hash: 36A19FA37A76D09FFB018A39C5A17CEAF90D336724F29A709CB60177D3C21A9605DB10
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID: 7
              • API String ID: 0-1790921346
              • Opcode ID: bd684695b0b9009310375d860dea63871e4bb56076010b7dd2d901ca6ecf7f5b
              • Instruction ID: 0794c27d7a6a96b3cc9a794747ea586e3aa3dd7e3adbdcfeebb29f71956e7a35
              • Opcode Fuzzy Hash: bd684695b0b9009310375d860dea63871e4bb56076010b7dd2d901ca6ecf7f5b
              • Instruction Fuzzy Hash: 1B61EA637AA2804FDB31CA78A0916CB7BE0E37A308F092615F6D547B57C56CDA0BDB04
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID: 0
              • API String ID: 3215553584-4108050209
              • Opcode ID: d3cad61f5502d7106a1471d22457d203db06ea8473520b57dc9d58c1c2d2d2a1
              • Instruction ID: 56270ffc22f89034b7e072d362a4e13121f8dd29b4c88f819d05145a87d7a246
              • Opcode Fuzzy Hash: d3cad61f5502d7106a1471d22457d203db06ea8473520b57dc9d58c1c2d2d2a1
              • Instruction Fuzzy Hash: 0371EF15A182038AEEA5BA1540402BD26B0EF78744F847137FD6DA77D5CF2DE84BE325
              Uniqueness

              Uniqueness Score: -1.00%

              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID: 0
              • API String ID: 3215553584-4108050209
              • Opcode ID: 6d0a94d7c0469c5c6aeef568c5c81d7626709050d9262ba6b699d629f267a2f6
              • Instruction ID: 380a91b811383bf02b34251b726317943877d2c27dae9a9a7ff0409e4ccfabfe
              • Opcode Fuzzy Hash: 6d0a94d7c0469c5c6aeef568c5c81d7626709050d9262ba6b699d629f267a2f6
              • Instruction Fuzzy Hash: 5A61F511A0C242C6FE688A2950203BE1FB19F71754F543531FCA89BB99CE2DE84FB761
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: HeapProcess
              • String ID:
              • API String ID: 54951025-0
              • Opcode ID: e06ef351894c49f49f10d3e365f1dd25fc469adfcf509904f72e1a7b88f780e1
              • Instruction ID: c364131c51192ad20844f89bf15b2d563a3257ce3d73cfccd9d36d668f29cc0d
              • Opcode Fuzzy Hash: e06ef351894c49f49f10d3e365f1dd25fc469adfcf509904f72e1a7b88f780e1
              • Instruction Fuzzy Hash: 5CB09220F17A02C2EA092F126C8221C23B57F68700F958039D01D81320DE2C20AD6B20
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f4e7805e7cd11ea0290a49bbe4ff1756958a9c33e91ea1cf9ce81fb76ab44a9e
              • Instruction ID: 91746e700569dffbda7f9747e5114abdf2576de6d3bdec2da5ddacfefb6438bc
              • Opcode Fuzzy Hash: f4e7805e7cd11ea0290a49bbe4ff1756958a9c33e91ea1cf9ce81fb76ab44a9e
              • Instruction Fuzzy Hash: C9F1D82375A2804AEB10CA38D1947CE6F62D7A6718F28E515DB54073E3DA7BDA0FDB10
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 976c2c5f0d80b86eb54c4b415adca4402a94d225a663c7417f28d4740c029039
              • Instruction ID: d9f6f941d9e8e8eb44d553b66d5cbd929206c855293e6ca3a918df20514c37f2
              • Opcode Fuzzy Hash: 976c2c5f0d80b86eb54c4b415adca4402a94d225a663c7417f28d4740c029039
              • Instruction Fuzzy Hash: 11F149137093D18EFB11CA3984943DE2F62EB76358F099125DA585B7D3CA3A9A0FC720
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f8299c70641a8df5a701ed7c720cb2b4eabe6ad68e686a92389bed2a30eabf53
              • Instruction ID: 19d8ee4a336a45859903c8f67f93760cd14731b251a3b759abceefb4d2c128e4
              • Opcode Fuzzy Hash: f8299c70641a8df5a701ed7c720cb2b4eabe6ad68e686a92389bed2a30eabf53
              • Instruction Fuzzy Hash: FCD17963B09A918BFB148A35E4613DF7BA1E762320F199625DBA4437C3DF2CE519CB10
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 6f6270673994d2d44e56ce4c892c288cb6e2ac712818bb7fd2b09c4627ac11e9
              • Instruction ID: 7d7c638028403e88b6d57e1e51ae7857d5a32e26f5d852088dd02a4cfb19c2ab
              • Opcode Fuzzy Hash: 6f6270673994d2d44e56ce4c892c288cb6e2ac712818bb7fd2b09c4627ac11e9
              • Instruction Fuzzy Hash: 00D1F5B3B9BA914FF7158A39C4B13CB7F90D322734F1A9A198790073D3D2A98659DB04
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 35012a9d2a0d3de121f552b8a21dc0deb257bf598013a262d6ddb06e2d030171
              • Instruction ID: 73b2a593950cd8adce38ee67892696453148c5a0c840099db129a8dce07f99b1
              • Opcode Fuzzy Hash: 35012a9d2a0d3de121f552b8a21dc0deb257bf598013a262d6ddb06e2d030171
              • Instruction Fuzzy Hash: 9AD1D25378B2C19DE7128A3CC5403CD7F21E32276CF5D9A05EB680B7A7C66AD60AD721
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: d79bf101e1cb1d71bd93de8d60d67037ea81bd114c7ca3ec68f1b25a1872cf92
              • Instruction ID: c2ce33e375498e9255fa73a639c6146a7812bff822eb122ecae58476bb701c82
              • Opcode Fuzzy Hash: d79bf101e1cb1d71bd93de8d60d67037ea81bd114c7ca3ec68f1b25a1872cf92
              • Instruction Fuzzy Hash: B9F1FB23A087C189E732DB74D4443ED2B71EB75788F148236DA6D6B796CF6C914AC321
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: c57cc95f4931b256efc58b002dee48f865eb4f9e0c2bf45b7a3c8efa1cb09a14
              • Instruction ID: a4ce8cc879a586477e030b262c6642707a809e8302b834b9aadd7b64b2ddf0ca
              • Opcode Fuzzy Hash: c57cc95f4931b256efc58b002dee48f865eb4f9e0c2bf45b7a3c8efa1cb09a14
              • Instruction Fuzzy Hash: 6BB1D2A3F9EA914FE7118A39C4753DBBF90D322734F2AA6198791033D3D2698659DB00
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: ef6bbca805776271225df0ed00b302df016a04f48fcb2d3fdd1bc050fe8820e8
              • Instruction ID: 3bacbdd51474415d5177fd387a3702d78f795f909a76dc25185eaf515363f0e3
              • Opcode Fuzzy Hash: ef6bbca805776271225df0ed00b302df016a04f48fcb2d3fdd1bc050fe8820e8
              • Instruction Fuzzy Hash: 07B1C1A379B6905BFB01863AC5A1BCFBF90D332B24F1EAB098750073D3C22A5655DB10
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 15ee82f0324375bd0286e3819d9379f4f23836b73f508718769443e55e3ba1f4
              • Instruction ID: 20827e209ebda0bd5824dbfc29fdb49bb3d2c270ae1f5856089586f474b72c11
              • Opcode Fuzzy Hash: 15ee82f0324375bd0286e3819d9379f4f23836b73f508718769443e55e3ba1f4
              • Instruction Fuzzy Hash: CFC1B25379B2C09EE702CE78C5403CD6F21E33275CF09AA19EB64077E7C6699A0AD361
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 314c5662dd43dcf9a4efe6e617be60411b449d9ae8df324cc7177bd0b2a8f196
              • Instruction ID: e46f568baffd9b899a2e70ec89cd71fc044550cf0e121657f140e7089aad2ebb
              • Opcode Fuzzy Hash: 314c5662dd43dcf9a4efe6e617be60411b449d9ae8df324cc7177bd0b2a8f196
              • Instruction Fuzzy Hash: 1CA1EEA379B6914FFB018A39C4A13CABF91D326728F1EAB19CB81073D3C2594559DB14
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 14a30570f157cb874c8448727ff115599652c466b19802783eafbe6c7ec458cb
              • Instruction ID: 676bc02dd73edc6081b5b82b31556145e3d609e8884616eda86505e145f59ea7
              • Opcode Fuzzy Hash: 14a30570f157cb874c8448727ff115599652c466b19802783eafbe6c7ec458cb
              • Instruction Fuzzy Hash: 9EB1D16775A2C08EEB108A38C4C53CE2F22D77636DF19D615E664076E7DA6B8A0FC710
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 8887a72a06ff1f3cf4d1fff3008ed930b54223551018f895e853e46cafe80a5a
              • Instruction ID: 159d85863c07fe62976922fc3eaf61443dce3a94ac74ea264b02d107ddb22810
              • Opcode Fuzzy Hash: 8887a72a06ff1f3cf4d1fff3008ed930b54223551018f895e853e46cafe80a5a
              • Instruction Fuzzy Hash: C3A1F763B9EA914FEB118A38C4653CBBF50D322738F2A9719C791072C3D3698655DB14
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 48883f57f144b60095104683b0817eab8d4014c728ff544acee589e53995ce7b
              • Instruction ID: fe059cd466a91e9243402cfc3538a712563c13698c0e78630bd3fceb8f954260
              • Opcode Fuzzy Hash: 48883f57f144b60095104683b0817eab8d4014c728ff544acee589e53995ce7b
              • Instruction Fuzzy Hash: 7291F326B186CA46FE294E2590603BD16A0AF70794F142239EE7AF77D4DD3CE50DB720
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 0bcced82a9fc39749268dce212708de9f634a4c20f9562305c9dd238256050c3
              • Instruction ID: 9b527a75eb2a51b17f9a34207017ed9878a42540fe075a84c4fd87bfece5f645
              • Opcode Fuzzy Hash: 0bcced82a9fc39749268dce212708de9f634a4c20f9562305c9dd238256050c3
              • Instruction Fuzzy Hash: A291C5A37A66D15BFB108A3AC5A1BCFBF91D332B24F29A708CB10177D3C62A5515DB10
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 4952ae5759933c75596aded85a1ddf277fc04ef67cc9f5e4f6336edddaa2ff89
              • Instruction ID: 21310f7a883c819ff05095d12b0b31431d067dc9d2d7124d75e35890b1741dbf
              • Opcode Fuzzy Hash: 4952ae5759933c75596aded85a1ddf277fc04ef67cc9f5e4f6336edddaa2ff89
              • Instruction Fuzzy Hash: C391A4637AB2915BFB058B39C5A17CFBFA0D322B14F19BA08CB54177E3C12A5506DB10
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 56127f76e09d3cf7e3267041b2539f45eac0a4f7b53fb26ef29d6d276238d597
              • Instruction ID: c49bd54b7ea0331581ec3f8f6f7208b2252910867815ad41b4d7941175aab6ea
              • Opcode Fuzzy Hash: 56127f76e09d3cf7e3267041b2539f45eac0a4f7b53fb26ef29d6d276238d597
              • Instruction Fuzzy Hash: D691D2A379A6D08FF7058A3A94B13CFAF91D332724F19A708CB51073D3C66A8659CB10
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: e2be21167368d0aec7b1aaa393170c09ac45ce613934ddc63d7b13c691d41eac
              • Instruction ID: 3792c27f7254565f0ab89074d255386481b56e3ca84e0164a46a09f1d8dea5a9
              • Opcode Fuzzy Hash: e2be21167368d0aec7b1aaa393170c09ac45ce613934ddc63d7b13c691d41eac
              • Instruction Fuzzy Hash: 3881E6A365A9D08FF7068639C5B13CFAFA1D332724F1AE608CB91073E2C6698955CB15
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 7e824b1be318276a4f218bc02b5caad35eed48d32f8767ccbfd33c0245edd557
              • Instruction ID: a1ec6d9a500517f7d4febdfef6afcfd753c929bac11dbaffe0bedff5cf86a8a2
              • Opcode Fuzzy Hash: 7e824b1be318276a4f218bc02b5caad35eed48d32f8767ccbfd33c0245edd557
              • Instruction Fuzzy Hash: D981C1A375A2D04BF7058A3990A13CBBF91D322724F1DAA19D7900B3D3C5698959CB14
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 8338eacb1da919bc0758a0834f03e56040253e081b19d548c583f60c5738d566
              • Instruction ID: 80fa07068a87eb037b71d97a901f0e9f70c53ccc2519d38e439c7cbefc54f43f
              • Opcode Fuzzy Hash: 8338eacb1da919bc0758a0834f03e56040253e081b19d548c583f60c5738d566
              • Instruction Fuzzy Hash: F771BDA379A6D04FEB068A39D4B13DBAF91D332724F1DEA1AC790033C3C6598559CB25
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f2361c72efdc7f3a52c7feb93de8ab014e12f34eaa2f409d3711d24c901156cb
              • Instruction ID: 0f3a5b94d4b968601c077d8e1a22a2cff276e7021821d11d158c574039919b01
              • Opcode Fuzzy Hash: f2361c72efdc7f3a52c7feb93de8ab014e12f34eaa2f409d3711d24c901156cb
              • Instruction Fuzzy Hash: AB71B2A37296D18BFB058A3984617CFBF90D372B24F29E618CB50177D3C62A8556CF11
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 697b2aea62219f5656d0463c1d6019ec4f649fa0e743178984f72f014e872501
              • Instruction ID: ede8b3cde79ee9bfb23c563af45bb3eb752724434d2a48d9c866cfba9e906aea
              • Opcode Fuzzy Hash: 697b2aea62219f5656d0463c1d6019ec4f649fa0e743178984f72f014e872501
              • Instruction Fuzzy Hash: D571C45379B2D09AE7128A38C5507CEFFA0E332B48F1DE549C7841B7A3C26B9546DB20
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 09150db66445cdb8ba0e68dc58cccf0d7c85025506eec9a1dd7840658f9ab11a
              • Instruction ID: 1e24531514cbe5d69b33f4b27ac09c9f54d358aa64ffb7f8e4ba52e95339e1f8
              • Opcode Fuzzy Hash: 09150db66445cdb8ba0e68dc58cccf0d7c85025506eec9a1dd7840658f9ab11a
              • Instruction Fuzzy Hash: B371F663F083819AFB11DA71D0843EE6B72A736788F149031EB6857786DF29DA4ED350
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: cff41d978c402d529349cd5407b2f90b1250f9a8a7f3c751a69f93d097a0efe5
              • Instruction ID: bcdc1e8917d5e0c6bd2e4758d81a9af7f5e9fa9de12b242dbccb94b25d1ad3c9
              • Opcode Fuzzy Hash: cff41d978c402d529349cd5407b2f90b1250f9a8a7f3c751a69f93d097a0efe5
              • Instruction Fuzzy Hash: BB71E4236193C147E751CB34D1913EE6BA2E7A2384F449436EB8957786CE7DD50ECB20
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: a64d4fe42c95d8a1600ae97b39fa045c3e51a03c1baf22767e3357bd989eba79
              • Instruction ID: 6f4e17933ac47084c8a2e9527c58ceb4bf91a7dabc973fe1d8dd811a2bb8739f
              • Opcode Fuzzy Hash: a64d4fe42c95d8a1600ae97b39fa045c3e51a03c1baf22767e3357bd989eba79
              • Instruction Fuzzy Hash: 5E61E3A37296D18BFB058A3994A17CFAF91D362B24F29E708CB54173D3C62A8556CF10
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: ef4994529661a5766efd0df43838bd9f1a40f01a08a6aae2c8327f8a0e32095a
              • Instruction ID: fa1d558f22ec37614bbdd2807ed87902c42be24b9a7f9c76252568ff0759272e
              • Opcode Fuzzy Hash: ef4994529661a5766efd0df43838bd9f1a40f01a08a6aae2c8327f8a0e32095a
              • Instruction Fuzzy Hash: BF71223260C6C186EB148B65A105BAEABA0EBA57C4F048135FE9C87B85DF7DE849D710
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f98461015111f786cb5efd91b59de3e5a96522af605e586c029ecc9c820738a5
              • Instruction ID: de48e62978da9e189172acfc87f2cb5ea90a0977f8e969f7ccd9646639bc9246
              • Opcode Fuzzy Hash: f98461015111f786cb5efd91b59de3e5a96522af605e586c029ecc9c820738a5
              • Instruction Fuzzy Hash: 6271F4636292D28AEB119B3D800078EBF50E332B7CF599348CB511B3D3C62B9586CB61
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 33c5577041e6ce668c719d831cd7fa6753967c9562d2dd2e7ecab6254b21f170
              • Instruction ID: ec03a7f81d56ee20d3aa31a9edefedde7473d1e89be959d6833f1e5c690ac89e
              • Opcode Fuzzy Hash: 33c5577041e6ce668c719d831cd7fa6753967c9562d2dd2e7ecab6254b21f170
              • Instruction Fuzzy Hash: F661066375B2D29EE7019A39C40078EBF50D336B2CF5DD649CB901B393C56B858ADB60
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 1ebe79e67c4ec8947b93ef81d47635f775218e223c8e059032a373a62c30748c
              • Instruction ID: 22df5b6705a1c4362dcbfba40c0554c23e8cd62231d41f47d7ecb670bc6ca746
              • Opcode Fuzzy Hash: 1ebe79e67c4ec8947b93ef81d47635f775218e223c8e059032a373a62c30748c
              • Instruction Fuzzy Hash: 2461C55762A2D29AEB025A3C850134EBF60E332B7CF59D344CF552B3E2C52B9985CB51
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 094cde2e16e63eed1a97fa0366bcfea01b503ed13a26dbbaaf95698ef19e21f0
              • Instruction ID: 5864a372ed345d9bf8ddc1c8aeeab1e7e2ce85a29327bfe45ca28babd4addbe6
              • Opcode Fuzzy Hash: 094cde2e16e63eed1a97fa0366bcfea01b503ed13a26dbbaaf95698ef19e21f0
              • Instruction Fuzzy Hash: 2D61C56361A1D35AEB025B3D850134FBF60E322B7CF59A344CF562B3A2C53B9986C790
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 11a2500e24147bc94cf2ba161d99d97905934e842c8028e163fe22d2d9ef5768
              • Instruction ID: 0f67719982a160e07766b21f47fab3c05a443275888cbfabc237e2678f37621f
              • Opcode Fuzzy Hash: 11a2500e24147bc94cf2ba161d99d97905934e842c8028e163fe22d2d9ef5768
              • Instruction Fuzzy Hash: 5451D36379B3D09AE7118A38C450BCEFF50E332B18F1DE659CB941B393C26A8545DB21
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 814864bee3f53b4c06bb8eb1701532d171da2eb01eba70b8f1f9e221d3dbd06a
              • Instruction ID: f913d6f38f32e2a6023a710de6e8548d008e74b5c938e351b8142758e5972409
              • Opcode Fuzzy Hash: 814864bee3f53b4c06bb8eb1701532d171da2eb01eba70b8f1f9e221d3dbd06a
              • Instruction Fuzzy Hash: A95125537180D11FFB165A3044A27EFAFE287523D8F1AA030F6A987397CD2AD90D9350
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: b063f5835d7df482878bd6b6fc98aea5100d92c3071ce995fc2fb080e30ce592
              • Instruction ID: ca40d8d208a12fcc1473511a755e783b81604c1fb0d75d2c1c28c6eb95242989
              • Opcode Fuzzy Hash: b063f5835d7df482878bd6b6fc98aea5100d92c3071ce995fc2fb080e30ce592
              • Instruction Fuzzy Hash: 16414923B083D14AFB05CA7595902EE2B62E766798F049131EF78677C6CF29D94ED310
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: c9dda3d076260c3319880d8bbc1012172f9946e85fa5eeab6500ea4dbf244f5c
              • Instruction ID: bf8fe14448b5d6936aef26759f3432c9a09441f122812b22ed464a91d99047ce
              • Opcode Fuzzy Hash: c9dda3d076260c3319880d8bbc1012172f9946e85fa5eeab6500ea4dbf244f5c
              • Instruction Fuzzy Hash: A131C21372597613BF09483BDD502BBA1E26BD43A0F45E538ED65837E4DD3D88065200
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 7ddab7a796360b66ec20354cd96875d2fe32611bd170d5d19ef14e3db215dfac
              • Instruction ID: 393830447b20fdc2c5a9e5975a656c7edce8edfb46029001012e17b0ab5faf6f
              • Opcode Fuzzy Hash: 7ddab7a796360b66ec20354cd96875d2fe32611bd170d5d19ef14e3db215dfac
              • Instruction Fuzzy Hash: 20418C1364E3C089EB16873C514429A6FA2D332B4CF2DD1A9D7980B363D96AC15BD762
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 8990701b6120a7c83ef5e4eb0131d7695fbb9565f5dd60224c821d488128b677
              • Instruction ID: b876a627e4a5cdb4e660cf3bd627fa0d90bcf4a73a6f81ef3be385bf2adda7d4
              • Opcode Fuzzy Hash: 8990701b6120a7c83ef5e4eb0131d7695fbb9565f5dd60224c821d488128b677
              • Instruction Fuzzy Hash: AD316D33E1C24286FEAD5969CD5497D1272AFA2740E248030F23D81F99CD2EB44EB532
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 784b48e0997eee179a80e101ce4c513229386164b17c0dd4af8a97d850ba0fdd
              • Instruction ID: ce44e8c98ca594570e4a34c24c4b9212907ce138f004f8c6458b98139160eff1
              • Opcode Fuzzy Hash: 784b48e0997eee179a80e101ce4c513229386164b17c0dd4af8a97d850ba0fdd
              • Instruction Fuzzy Hash: 40F068717286558ADB948F2DA84363D77E0F718380F808039E69EC3F44DA3C90649F14
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 0210d77da61e30b27039753a39a2f2148efb687aa5e96026ff40c58e14571448
              • Instruction ID: 9b24a751f9a4be5a65438300c12bdb9baf2404c0b953e20413f529872c904e8d
              • Opcode Fuzzy Hash: 0210d77da61e30b27039753a39a2f2148efb687aa5e96026ff40c58e14571448
              • Instruction Fuzzy Hash: 0FA00129A18C02D0EA459B00A8600282730FB71750B415032F02E816A49E7CA508E621
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ErrorInit_thread_headerLast
              • String ID: ,$/$0$3$H$^$k$p$w$|
              • API String ID: 4025375154-253053246
              • Opcode ID: 7416f4ff0be6ec7eba57a9f441abc027175377b62e64652e372d29bfff532440
              • Instruction ID: 7c290d89981e65ff52688f01749282c248a5a44052a6de4431f49751c67cba5f
              • Opcode Fuzzy Hash: 7416f4ff0be6ec7eba57a9f441abc027175377b62e64652e372d29bfff532440
              • Instruction Fuzzy Hash: 1151821250E2C188E762C338B49029EAFB087B6344F5811A9F6DE477DACD6DD05CDB36
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Frame$BlockEstablisherHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
              • String ID: csm$csm$csm
              • API String ID: 3606184308-393685449
              • Opcode ID: d75e76c68253bcca0b94597d7b6e8bbe81b92c6df5baad666a6ded16b790c426
              • Instruction ID: 4fd20ff5e0f491e564f17944171efc350c8b16aa3b5d8c074fdf5f5fe5f67328
              • Opcode Fuzzy Hash: d75e76c68253bcca0b94597d7b6e8bbe81b92c6df5baad666a6ded16b790c426
              • Instruction Fuzzy Hash: BCE17E73A08B428AEB209B6598403AE37B0FB65798F100135FE9D97B95CF3CE498D750
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • LoadLibraryExW.KERNEL32(00000000,00000000,00000000,00007FF63EC3E0F5,?,?,00000000,00007FF63EC37784), ref: 00007FF63EC3E2E3
              • GetLastError.KERNEL32(?,?,00000000,00007FF63EC37784), ref: 00007FF63EC3E2F1
              • LoadLibraryExW.KERNEL32(?,?,00000000,00007FF63EC37784), ref: 00007FF63EC3E31B
              • FreeLibrary.KERNEL32(?,?,00000000,00007FF63EC37784), ref: 00007FF63EC3E361
              • GetProcAddress.KERNEL32(?,?,00000000,00007FF63EC37784), ref: 00007FF63EC3E36D
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Library$Load$AddressErrorFreeLastProc
              • String ID: MZx$api-ms-
              • API String ID: 2559590344-259127448
              • Opcode ID: 04355ff06001d2d6a683f0a034157a800ff914f5fcb14f6eb95f28767bf62b4d
              • Instruction ID: f56e3fc5c5d43a5be129dc06c5478ad8303510f00cd8d53d8c025a0b451e07a5
              • Opcode Fuzzy Hash: 04355ff06001d2d6a683f0a034157a800ff914f5fcb14f6eb95f28767bf62b4d
              • Instruction Fuzzy Hash: 1531C521B1AB42D5EE52DB12AC106BD63B4BF24B64F5A0535FD3D87390EE3CE4489720
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: File$ByteCharCloseCreateHandleModuleMultiNameSizeWide_invalid_parameter_noinfo
              • String ID: =$g$w
              • API String ID: 2869743477-3268570079
              • Opcode ID: 4a82ca26e9b12c163d29d0ee986f8d2af40302c703be63ebbdc4b3e78d14f6a9
              • Instruction ID: e103253df0fa3bfe3fa9991a24d49e82368839e280206ffb79ccde9b99518e4a
              • Opcode Fuzzy Hash: 4a82ca26e9b12c163d29d0ee986f8d2af40302c703be63ebbdc4b3e78d14f6a9
              • Instruction Fuzzy Hash: 58314B1170C38185F7819735A85436E6AA0ABA6754F049135FAAF87BD2CE3CD44DDB21
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
              • String ID: CONOUT$
              • API String ID: 3230265001-3130406586
              • Opcode ID: b3995c7a37e6925a60afd43ef683f5ac5acb67d9482e949a7e5944a38cb6630b
              • Instruction ID: 6e1c5bce46607a278ddd4255b33b8f52f7379718ac9d1981977bb3ff96fcb5cd
              • Opcode Fuzzy Hash: b3995c7a37e6925a60afd43ef683f5ac5acb67d9482e949a7e5944a38cb6630b
              • Instruction Fuzzy Hash: CB119331718B4186E7519B12E85472DA6B0FBA8FE4F050235FA2EC7B94CF3CD9588B50
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: File$ByteCharCloseCreateHandleModuleMultiNamePointerSizeWide_invalid_parameter_noinfo
              • String ID:
              • API String ID: 3914190426-0
              • Opcode ID: dceae1f6229362cc64b66fbe57b7f2deff865424649d4b32b4333f0f8ac6b727
              • Instruction ID: 1165180e57052b3393d37e61913700d21ad0d7748a80a9ccc8d55118f3dab4e8
              • Opcode Fuzzy Hash: dceae1f6229362cc64b66fbe57b7f2deff865424649d4b32b4333f0f8ac6b727
              • Instruction Fuzzy Hash: DE412B1360D38146F7519B24A4253AE3FA0ABA6794F088035FA9D477C1CE3DD40DD721
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: AddressFreeHandleLibraryModuleProc
              • String ID: CorExitProcess$mscoree.dll
              • API String ID: 4061214504-1276376045
              • Opcode ID: ecd63c3c4316c3c9fbdcfef5bf25d74ee47e5c971f69a65528fc7b8558aba146
              • Instruction ID: da8a42fa39d90633b9f3933070d4616dea2be693b4c018e50c2243442723a107
              • Opcode Fuzzy Hash: ecd63c3c4316c3c9fbdcfef5bf25d74ee47e5c971f69a65528fc7b8558aba146
              • Instruction Fuzzy Hash: 31F03A61B29A0281EB559B20E8943BD2770AFA8744F041436F47FC5760DF2CD49CEB20
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • _invalid_parameter_noinfo.LIBCMT ref: 00007FF63EC3EB7D
              • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF63EC3EAFB,?,?,?,00007FF63EC3ADEB), ref: 00007FF63EC3EC3C
              • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF63EC3EAFB,?,?,?,00007FF63EC3ADEB), ref: 00007FF63EC3ECBC
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ConsoleErrorLastMode_invalid_parameter_noinfo
              • String ID:
              • API String ID: 2210144848-0
              • Opcode ID: 07eeae94c06d92b8504f9e987bce4935aa044e86d40c3320ad466e40d74f921d
              • Instruction ID: 9160500876d24c9e8f2eae717cbf80608b251cfff960f4e16c7688361871ab27
              • Opcode Fuzzy Hash: 07eeae94c06d92b8504f9e987bce4935aa044e86d40c3320ad466e40d74f921d
              • Instruction Fuzzy Hash: DD81A122E1875289FB119B659C406FD26B0BF64B98F440136FE2ED3796DE3CA449E730
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ByteCharMultiWide$AllocString
              • String ID:
              • API String ID: 262959230-0
              • Opcode ID: d862167c056b2ad39305bc35e6b04559ab4bed8c119e56702c1ae49f8c288d9f
              • Instruction ID: a954ed596b09da6e6fec612a6c50f798ac3a36b52b68a0bc938bbc460000a792
              • Opcode Fuzzy Hash: d862167c056b2ad39305bc35e6b04559ab4bed8c119e56702c1ae49f8c288d9f
              • Instruction Fuzzy Hash: CD41B221A0868689EF549F3598103BD26B0AF74BB4F146A35F97ECA7D5DE3CE0496320
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CloseCreateErrorFreeHandleLastLibraryThread_invalid_parameter_noinfo
              • String ID:
              • API String ID: 2067211477-0
              • Opcode ID: e755e38ed2f8e5df5b331195f0aae42cec82dc5444c985b05eb8cf30841258e8
              • Instruction ID: 1bde31ce87af027e3e2d1e1be8cfda821c74fa85b5a0d45eb63aa57f86abcb06
              • Opcode Fuzzy Hash: e755e38ed2f8e5df5b331195f0aae42cec82dc5444c985b05eb8cf30841258e8
              • Instruction Fuzzy Hash: F821A121B0978286EE15DF61A8101BD63B0BFA4B94F084431FE6DC3B55DF3CE408A661
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: _set_statfp
              • String ID:
              • API String ID: 1156100317-0
              • Opcode ID: 2f5373d1ca46f5c3229c317260ef8bd11ef88d050e705646cdd7aa3137752530
              • Instruction ID: 8bf2642462eeef8c24c11acb90420a020c7d9a198f25ba25b3048ca167bdadfb
              • Opcode Fuzzy Hash: 2f5373d1ca46f5c3229c317260ef8bd11ef88d050e705646cdd7aa3137752530
              • Instruction Fuzzy Hash: 45118222E98A1301F67E1129D45737E25F06F74360F494637FE7E873D68E1C685AA930
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID: -$e+000$gfff
              • API String ID: 3215553584-2620144452
              • Opcode ID: fea700b4ae36ff7c529df643656e834d20fb0c31ee8ce0b254d5c322e6b27136
              • Instruction ID: bd0aff1ac0d29c792f2a5e3df22ecf0d6b4b7cf3de40c1378e8d2f331616313f
              • Opcode Fuzzy Hash: fea700b4ae36ff7c529df643656e834d20fb0c31ee8ce0b254d5c322e6b27136
              • Instruction Fuzzy Hash: 3D611862B187C586EB218F2599413AD77A1EB50B90F488231EBBC87BD9DF3CD849D710
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • EncodePointer.KERNEL32(?,?,?,?,00000000,00000000,?,00007FF63EC2B689,?,?,00007FF63EC38B1B), ref: 00007FF63EC38CB4
              • _CallSETranslator.LIBVCRUNTIME ref: 00007FF63EC38D03
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CallEncodePointerTranslator
              • String ID: MOC$RCC
              • API String ID: 3544855599-2084237596
              • Opcode ID: ba8a55b228979507f88b3c3f52684b91d840e4bed7c9b4b7db1ce7d12982141e
              • Instruction ID: df31fcdf317773c3475cab213f4ef51aa9a7644c4fc5589a97c8f516932a3dd9
              • Opcode Fuzzy Hash: ba8a55b228979507f88b3c3f52684b91d840e4bed7c9b4b7db1ce7d12982141e
              • Instruction Fuzzy Hash: 7D512737A08B858AEB208F65D8802ED77B0FB64B88F144526EE5957B98DF3CE059D710
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
              • String ID: csm$csm
              • API String ID: 3896166516-3733052814
              • Opcode ID: c1f9aeab5c56c4da10f37370f3e62ba49f3a1aa23b94188c6bc5adb2cffb70f5
              • Instruction ID: 6c7fb5aba72e8b39141b6c7eb71f227c1bc0efbd4cfff75c55d2ed173cd85c7a
              • Opcode Fuzzy Hash: c1f9aeab5c56c4da10f37370f3e62ba49f3a1aa23b94188c6bc5adb2cffb70f5
              • Instruction Fuzzy Hash: C8516F3390868286EF748B1599442AD77B0FB65B84F144135FAAD87BD6CF3CE458EB20
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: AllocFormatLocalMessage
              • String ID: IDispatch error #%d$Unknown error 0x%0lX
              • API String ID: 3960703613-2934499512
              • Opcode ID: 693297c9b66ce21f8298f55620efccc22f9a8bf88e228e71242208683c58015a
              • Instruction ID: 43fc841b9cbc419e81498c1cdba036ab104545fe609bd7ca2583d8729c98da41
              • Opcode Fuzzy Hash: 693297c9b66ce21f8298f55620efccc22f9a8bf88e228e71242208683c58015a
              • Instruction Fuzzy Hash: 1C210476B0C64182EF258B65E41437D27B1AFA5B94F544231EA2D83BD1CF3CE84AE360
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: AdjustPointer
              • String ID:
              • API String ID: 1740715915-0
              • Opcode ID: fa5bbb738a34b93a05ad879c9e0083a197e3b01216d23d5cd4cd7d0d0e826275
              • Instruction ID: 0711287271041d1deb03cd77bdca99ef4c8021abc1fcec3cf7820801c96c9267
              • Opcode Fuzzy Hash: fa5bbb738a34b93a05ad879c9e0083a197e3b01216d23d5cd4cd7d0d0e826275
              • Instruction Fuzzy Hash: C771D223A0964281FE65DB2199806BD63B0FF74B80F094536FE6D87BC5CE3CE449A760
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ClearVariant
              • String ID:
              • API String ID: 1473721057-0
              • Opcode ID: ab6e2a0be742cb0bde27c77b28ef8d64c4758e36f59ce557272be3e982f2d718
              • Instruction ID: 7f32e9bd4c4993e163fa9dba060519f2446dc21144b3f26913228d720d207c35
              • Opcode Fuzzy Hash: ab6e2a0be742cb0bde27c77b28ef8d64c4758e36f59ce557272be3e982f2d718
              • Instruction Fuzzy Hash: A8E012336109A8A8D711EF31FC109EC6B24F790768F454133EE5C82554AE34D6DBC310
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ErrorFileLastWrite
              • String ID: U
              • API String ID: 442123175-4171548499
              • Opcode ID: 8fade4a58e48830b81c384b6c6ba52233c11786accea551678c790b2d95991eb
              • Instruction ID: af6033b0cdda6755246b39bca7c7af4f569541e0f6a352679254848f746b51ae
              • Opcode Fuzzy Hash: 8fade4a58e48830b81c384b6c6ba52233c11786accea551678c790b2d95991eb
              • Instruction Fuzzy Hash: 8041B222B18A8182DB209F25E8443AD67B0FBA8794F904531EE9EC7798EF3CD449D750
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Stringtry_get_function
              • String ID: LCMapStringEx
              • API String ID: 2588686239-3893581201
              • Opcode ID: b0f2c5edf64f2378b63e45fc81fb072509f10715db6d83ca7f2293333b33c2e1
              • Instruction ID: 6258c1b31a025a4f3c125cb7fd648bf17e820e527cc0c7aeeec6ad0c493437c3
              • Opcode Fuzzy Hash: b0f2c5edf64f2378b63e45fc81fb072509f10715db6d83ca7f2293333b33c2e1
              • Instruction Fuzzy Hash: AA112936608B8186D760CB06B8402AEB7B0FBD9B80F544136FAAD93B59DF3CD4448B00
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,000000F8,00007FF63EC2A1CF), ref: 00007FF63EC2AED4
              • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,000000F8,00007FF63EC2A1CF), ref: 00007FF63EC2AF1A
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: ExceptionFileHeaderRaise
              • String ID: csm
              • API String ID: 2573137834-1018135373
              • Opcode ID: 0cca6d678f7393a148cf465ca776ec0841094c4d6af28f07bbd8ffb2a00a0908
              • Instruction ID: 756de27b824bb509980706c77ea5b6a8f06b5df7e000aa2b90319cc34b2e9684
              • Opcode Fuzzy Hash: 0cca6d678f7393a148cf465ca776ec0841094c4d6af28f07bbd8ffb2a00a0908
              • Instruction Fuzzy Hash: 2E114F32608B4182EB618F15E44026D77B1FBA8B94F185231EF9D47B68DF3CD556DB00
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: CountCriticalInitializeSectionSpintry_get_function
              • String ID: InitializeCriticalSectionEx
              • API String ID: 539475747-3084827643
              • Opcode ID: 8c987e7fc56b62dd683d011dab3348d6d6033c655efcd8cecba21263e958bef2
              • Instruction ID: f27c0072ac9dc85ae91648fd470215d514c8857da24c4fe25fb10dad085ab5ab
              • Opcode Fuzzy Hash: 8c987e7fc56b62dd683d011dab3348d6d6033c655efcd8cecba21263e958bef2
              • Instruction Fuzzy Hash: 6CF0BE26B0878181EB059B45B8004ADB330EF58BC0F444032FA3E53B99CF3CD889EB60
              Uniqueness

              Uniqueness Score: -1.00%

              APIs
              • try_get_function.LIBVCRUNTIME ref: 00007FF63EC390A1
              • TlsSetValue.KERNEL32(?,?,000000F8,00007FF63EC3984E,?,?,000000F8,00007FF63EC3B195,?,?,?,?,00007FF63EC3A971), ref: 00007FF63EC390B8
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.199573475.00007FF63EC01000.00000020.00020000.sdmp, Offset: 00007FF63EC00000, based on PE: true
              • Associated: 00000000.00000002.199569816.00007FF63EC00000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199609309.00007FF63EC44000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199621632.00007FF63EC52000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199625300.00007FF63EC54000.00000004.00020000.sdmp Download File
              • Associated: 00000000.00000002.199629425.00007FF63EC56000.00000002.00020000.sdmp Download File
              • Associated: 00000000.00000002.199635005.00007FF63EC5D000.00000002.00020000.sdmp Download File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff63ec00000_anchorDNS_x64.jbxd
              Similarity
              • API ID: Valuetry_get_function
              • String ID: FlsSetValue
              • API String ID: 738293619-3750699315
              • Opcode ID: 2214c7330c37fb0c43cf6c8910562a881b2b91213e701cb4f8b092eaac3225e3
              • Instruction ID: 0a647326b4684de278d71b9377d7eeb4b61d2e1e1ed9b1fff066b846d2b93cb0
              • Opcode Fuzzy Hash: 2214c7330c37fb0c43cf6c8910562a881b2b91213e701cb4f8b092eaac3225e3
              • Instruction Fuzzy Hash: 33E06561A18642D1EA055B55F8404FD7271AF5C790F485033F93E86799CE3CD89CEB21
              Uniqueness

              Uniqueness Score: -1.00%

              Executed Functions

              Strings
              Memory Dump Source
              • Source File: 00000006.00000002.232309945.00007FFAEEE20000.00000040.00000001.sdmp, Offset: 00007FFAEEE20000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_6_2_7ffaeee20000_powershell.jbxd
              Similarity
              • API ID:
              • String ID: m`_H
              • API String ID: 0-3858478043
              • Opcode ID: 0815186c7ad790360c8b30871c67800312cf4fb6636fb121feb508ea566d86a6
              • Instruction ID: f97affbf479ebaa43cb727f620694b6969815e21aa5333325c80e3c4cf57a320
              • Opcode Fuzzy Hash: 0815186c7ad790360c8b30871c67800312cf4fb6636fb121feb508ea566d86a6
              • Instruction Fuzzy Hash: D802F631A0CB4A8FEB88EF1CC495AA97BE1FF69300F154179D44DC7296DA64EC42CB81
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000006.00000002.232350184.00007FFAEEEE0000.00000040.00000001.sdmp, Offset: 00007FFAEEEE0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_6_2_7ffaeeee0000_powershell.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: d29413c37bd416ccbb614067fb7eb5f0ec9daddda95817821967b3187346e018
              • Instruction ID: 2dbf6ca2d78871f9741a19449ce7ab163a8ae87d90cfa4fb57cb88e811925388
              • Opcode Fuzzy Hash: d29413c37bd416ccbb614067fb7eb5f0ec9daddda95817821967b3187346e018
              • Instruction Fuzzy Hash: DBD1287190E7C92FD7569B3998556B57FE0EF53220B0A41FBD0CDC70A3DA589806C392
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000006.00000002.232350184.00007FFAEEEE0000.00000040.00000001.sdmp, Offset: 00007FFAEEEE0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_6_2_7ffaeeee0000_powershell.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 602f2aec9dfd82c127ee7c41bf4a206955505f9d26f2e504c028f5b5589470c7
              • Instruction ID: a6696d176450d4225ed66903844936b3e5442481a3eeb4e8f00215548d1e3906
              • Opcode Fuzzy Hash: 602f2aec9dfd82c127ee7c41bf4a206955505f9d26f2e504c028f5b5589470c7
              • Instruction Fuzzy Hash: 89D16B7290DBCA1FD766EB6898956B57FE0EF03310B0940FED08CCB1A3E9989805C352
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000006.00000002.232350184.00007FFAEEEE0000.00000040.00000001.sdmp, Offset: 00007FFAEEEE0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_6_2_7ffaeeee0000_powershell.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: a399939f2d60501299e77e65304ac63cb4302284ad3e1853f50248d050622fe5
              • Instruction ID: 5fe1a8c6ace43b3197209184141ccbcbe8b96af394e833436a5888b8c8006ea1
              • Opcode Fuzzy Hash: a399939f2d60501299e77e65304ac63cb4302284ad3e1853f50248d050622fe5
              • Instruction Fuzzy Hash: 25C1697190DB8A5FE7A5EB6988956B5BFE1EF46300B1940FED08CC71A3D958AC05C342
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000006.00000002.232350184.00007FFAEEEE0000.00000040.00000001.sdmp, Offset: 00007FFAEEEE0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_6_2_7ffaeeee0000_powershell.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: ab1e4f04ec4adfc98b431f3868842febbcd8179db22dedd61d468eb9df3b733f
              • Instruction ID: 07dbeee15674b91aa1ce9a2413440be639d78481e9d2a39916956433a4e2a61a
              • Opcode Fuzzy Hash: ab1e4f04ec4adfc98b431f3868842febbcd8179db22dedd61d468eb9df3b733f
              • Instruction Fuzzy Hash: F051C97190DAC65FE7A5DB694495278BBD1EF16300B1980FDC0CDCB2E3DD99AC448742
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000006.00000002.232309945.00007FFAEEE20000.00000040.00000001.sdmp, Offset: 00007FFAEEE20000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_6_2_7ffaeee20000_powershell.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: d3638d6b76ad5b7731dd8172b59b64784534c56dec3ed987e3d7118dd25656ac
              • Instruction ID: 4876bca0a380cb7cce15209c86b954c98a6e52c250a7448dcf2fcc9d423ed901
              • Opcode Fuzzy Hash: d3638d6b76ad5b7731dd8172b59b64784534c56dec3ed987e3d7118dd25656ac
              • Instruction Fuzzy Hash: 9601847131C9084FD74CEF1CE4A2AB573E1EB99320B5041AED48AC7697DA27B8438785
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000006.00000002.232309945.00007FFAEEE20000.00000040.00000001.sdmp, Offset: 00007FFAEEE20000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_6_2_7ffaeee20000_powershell.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 5921e71f07582a7c74abfbbba3be25ad186edaa7760d03d5a8c8591150ec97b9
              • Instruction ID: e196f62a1808101b51382a77f108dc383a73a1d4e31d2a516c248cd52d82db46
              • Opcode Fuzzy Hash: 5921e71f07582a7c74abfbbba3be25ad186edaa7760d03d5a8c8591150ec97b9
              • Instruction Fuzzy Hash: 7701677111CB0C4FD744EF0CE451AB6B7E0FB99364F10056DE58AC3651DA36E882CB46
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000006.00000002.232309945.00007FFAEEE20000.00000040.00000001.sdmp, Offset: 00007FFAEEE20000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_6_2_7ffaeee20000_powershell.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: b1c1dde451898f706a29055310619955e71ccc2704c66265bb05e3513016209f
              • Instruction ID: 8eb4a56a4e26158be636937e57820464d6c06f83e2bdd13e117d864d8d93df92
              • Opcode Fuzzy Hash: b1c1dde451898f706a29055310619955e71ccc2704c66265bb05e3513016209f
              • Instruction Fuzzy Hash: 8DF0373275C6054F974CAA0CF8435F573D1E789320B40017EE48AC2696E916B8428685
              Uniqueness

              Uniqueness Score: -1.00%

              Memory Dump Source
              • Source File: 00000006.00000002.232350184.00007FFAEEEE0000.00000040.00000001.sdmp, Offset: 00007FFAEEEE0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_6_2_7ffaeeee0000_powershell.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 0cf86fec42f953c605dfaad6690c9a6f09de4deda7c539eeeb7d58564bd8dc51
              • Instruction ID: 2a9551122573af0cf040cc20198bab3a6764560b2a01a88d0d492e432d6deaf3
              • Opcode Fuzzy Hash: 0cf86fec42f953c605dfaad6690c9a6f09de4deda7c539eeeb7d58564bd8dc51
              • Instruction Fuzzy Hash: 25F0B472A0D6884FE755EBACA8566F9BBD0EF59211F2801BFD04DD3193D81654018752
              Uniqueness

              Uniqueness Score: -1.00%

              Non-executed Functions